A method and device for identity authentication of Hongmeng application
By providing a Hongmeng application identity authentication method that includes registration and authentication processes in the Hongmeng Next system, the problem of lack of user identity authentication in the system is solved, and the secure and convenient authentication of user identity is achieved.
Patent Information
- Application Number
- CN202510059021.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-15
AI Technical Summary
The lack of a user identity authentication system suitable for Hongmeng applications in the Hongmeng Next system makes it difficult for users to ensure identity legality and security when logging in and trading in the system.
Provides an identity authentication method for Hongmeng application, including registration process and authentication process. The registration process generates a registration request and interacts with the authentication server, obtains authentication policies and challenge values, sets user authentication methods, and uses key pairs to sign. The authentication process generates authentication requests, parses authentication policies and challenge values, verifies the user's identity, and signs with the user key pair.
It realizes safe and convenient login and transactions in the Hongmeng Next system, and enhances the legality and security of user identity by supporting different authentication methods and levels.
Smart Images

Figure CN119475317B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to an identity authentication method and device for Hongmeng applications. Background Art
[0002] The Hongmeng Next system only supports the Hongmeng kernel and Hongmeng system applications, and is no longer compatible with Android applications. After the release of the Hongmeng Next system, it is urgent to access the user identity authentication system suitable for Hongmeng applications to ensure that users can log in to Hongmeng applications or conduct transactions and authentication in the Hongmeng system safely and conveniently. How to ensure the legitimacy of user identities in Hongmeng applications is an urgent problem to be solved. Summary of the invention
[0003] The purpose of the present invention is to overcome the shortcomings of the prior art and provide an identity authentication method and device for Hongmeng applications.
[0004] In a first aspect, an embodiment of the present invention provides an identity authentication method for a Hongmeng application, including a registration process and an authentication process, wherein the registration process includes:
[0005] Step A1: When the Hongmeng application receives the user's registration operation information, it generates a registration request according to the user name, the preset Hongmeng application identifier, the preset authenticator identifier and the preset device identifier in the registration operation information and sends it to the authentication server;
[0006] Step A2: the Hongmeng application receives the registration request response returned by the authentication server and parses it to obtain the authentication policy and the first challenge value, obtains the authentication level and the authenticator identifier in the authentication policy, and confirms the corresponding authentication method according to the obtained authenticator identifier, wherein there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level;
[0007] Step A3: the Hongmeng application sets the Hongmeng application user identity authentication method according to the authentication method and the authentication level;
[0008] Step A4: the Hongmeng application generates a user key pair and a key identifier and saves them corresponding to the user name, generates registration data according to the user public key in the user key pair and the first challenge value, signs the registration data using the saved authenticator private key to obtain a first signature result, generates a registration confirmation request according to the key identifier, the registration data and the first signature result, and sends it to the authentication server;
[0009] Step A5: the Hongmeng application receives the registration result returned by the authentication server and prompts the user;
[0010] The authentication process includes:
[0011] Step B1: when the Hongmeng application receives the user's authentication operation information, it generates an authentication request according to the user name, the preset Hongmeng application identifier, the preset authenticator identifier and the preset device identifier in the authentication operation information and sends it to the authentication server;
[0012] Step B2: the Hongmeng application receives the authentication request response returned by the authentication server and parses it to obtain the authentication policy and the second challenge value, obtains the authentication level, authenticator identifier and key identifier in the authentication policy, and confirms the corresponding authentication method according to the obtained authenticator identifier, where there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level;
[0013] Step B3: the Hongmeng application determines the Hongmeng application user identity authentication method according to the authentication method and the authentication level, verifies the user identity according to the Hongmeng application user identity authentication method, and executes step B4 if the verification passes, and reports an error if the verification fails;
[0014] Step B4: the Hongmeng application obtains the corresponding saved key identifier according to the user name, and determines whether the obtained key identifier matches the key identifier obtained in the authentication policy. If so, step B5 is executed, otherwise an error is reported;
[0015] Step B5: the Hongmeng application generates a first random number, obtains a saved user key pair according to the key identifier, generates authentication data according to the first random number and the second challenge value, signs the authentication data using the user private key in the user key pair to obtain a second signature result, and sends the authentication data and the second signature result to the authentication server;
[0016] Step B6: The Hongmeng application receives the authentication result returned by the authentication server and prompts the user.
[0017] In a second aspect, an embodiment of the present invention further provides an identity authentication device for a Hongmeng application, including a registration module and an authentication module, wherein the registration module includes:
[0018] A first generating and sending unit is used to generate a registration request and send it to an authentication server according to the user name, preset Hongmeng application identifier, preset authenticator identifier and preset device identifier in the registration operation information when receiving the user's registration operation information;
[0019] A first parsing and determining unit is used to receive the registration request response returned by the authentication server and parse to obtain the authentication policy and the first challenge value, obtain the authentication level and the authenticator identifier in the authentication policy, and confirm the corresponding authentication method according to the obtained authenticator identifier, wherein there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level;
[0020] A first setting unit is used to set a Hongmeng application user identity authentication method according to the authentication method and the authentication level;
[0021] The first signature sending unit is used to generate a user key pair and a key identifier and save them corresponding to the user name, generate registration data according to the user public key in the user key pair and the first challenge value, sign the registration data using the saved authenticator private key to obtain a first signature result, generate a registration confirmation request according to the key identifier, the registration data and the first signature result, and send it to the authentication server;
[0022] A first receiving and prompting unit, configured to receive the registration result returned by the authentication server and prompt the user;
[0023] The authentication module comprises:
[0024] A second generating and sending unit is used to generate an authentication request according to the user name, preset Hongmeng application identifier, preset authenticator identifier and preset device identifier in the authentication operation information when receiving the user's authentication operation information, and send it to the authentication server;
[0025] A second parsing and determining unit is configured to receive the authentication request response returned by the authentication server and parse to obtain the authentication policy and the second challenge value, obtain the authentication level, the authenticator identifier and the key identifier in the authentication policy, and confirm the corresponding authentication method according to the authenticator identifier, wherein there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level;
[0026] A first verification unit, configured to determine a Hongmeng application user identity authentication method according to the authentication method and the authentication level, and verify the user identity according to the Hongmeng application user identity authentication method, and trigger an acquisition judgment unit if the verification is passed, and report an error if the verification fails;
[0027] The acquisition and judgment unit is used to obtain the corresponding saved key identifier according to the user name, and judge whether the obtained key identifier matches the key identifier obtained in the authentication policy, and trigger the second signature sending unit if it matches, otherwise an error is reported;
[0028] The second signature sending unit is used to generate a first random number, obtain a saved user key pair according to the key identifier, generate authentication data according to the first random number and the second challenge value, sign the authentication data using a user private key in the user key pair to obtain a second signature result, and send the authentication data and the second signature result to the authentication server;
[0029] The second receiving and prompting unit is used to receive the authentication result returned by the authentication server and prompt the user.
[0030] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, wherein the at least one processor executes the instructions to implement any of the methods described above.
[0031] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium includes a computer program, and when the computer program runs on an electronic device, the electronic device executes any one of the methods described above.
[0032] In a fifth aspect, an embodiment of the present invention further provides a computer program product, including a computer program / instruction, which implements any of the methods described above when executed by a processor.
[0033] Compared with the prior art, the present invention has the following advantages: the technical solution of the present invention can be used in the Hongmeng Next system to ensure the security, ease of use and scalability of Hongmeng applications; it supports the use of different authentication methods to verify user identity and supports different authentication levels, which can further ensure the legitimacy and security of user identity. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 A flowchart of an identity authentication method for a Hongmeng application provided in Example 1 of the present invention;
[0035] Figure 2 A flow chart of the registration process in an identity authentication method for a Hongmeng application provided in Embodiment 2 of the present invention;
[0036] Figure 3 A flowchart of the authentication process in an identity authentication method for a Hongmeng application provided in Embodiment 2 of the present invention;
[0037] Figure 4 A flowchart of the logout process in an identity authentication method for a HarmonyOS application provided in Example 2 of the present invention. DETAILED DESCRIPTION
[0038] This application proposes an identity authentication method and device for Hongmeng applications. The specific implementation methods of this application are described in detail below in conjunction with the accompanying drawings. Examples of the embodiments are shown in the accompanying drawings. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and cannot be interpreted as limitations on this application.
[0039] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as generally understood by those skilled in the art to which this application belongs. It should also be understood that terms such as those defined in common dictionaries should be understood to have meanings consistent with the meanings in the context of the prior art, and will not be interpreted with idealized or overly formal meanings unless specifically defined as here.
[0040] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0041] In order to make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention are further described in detail below with reference to the accompanying drawings.
[0042] The Harmony application in this embodiment refers to a full-function application developed based on the Harmony system, which can run independently on a Harmony device. Embodiment 1
[0043] Embodiment 1 of the present invention provides an identity authentication method for a Hongmeng application, including a registration process and an authentication process, such as Figure 1 As shown, the registration process includes:
[0044] Step A1: When the Hongmeng application receives the user's registration operation information, it generates a registration request according to the user name, the preset Hongmeng application identifier, the preset authenticator identifier and the preset device identifier in the registration operation information and sends it to the authentication server;
[0045] In this embodiment, between step A1 and step A2, it also includes: the authentication server parses the received registration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, determines whether the corresponding authenticator identifier and device identifier are set, and if so, obtains the authentication level according to the user name and Hongmeng application identifier, generates an authentication policy according to the authenticator identifier and the authentication level, generates and saves a first challenge value, generates a registration request response according to the authentication policy and the first challenge value and returns it to the Hongmeng application, otherwise returns an error message to the Hongmeng application;
[0046] Or, the authentication server parses the received registration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set. If yes, it obtains the authentication level according to the user name and Hongmeng application identifier, generates an authentication policy according to the authenticator identifier, generates and saves a first challenge value, generates a registration request response according to the authentication policy and the first challenge value, and returns it to the Hongmeng application; otherwise, it returns an error message to the Hongmeng application;
[0047] Step A2: The Hongmeng application receives the registration request response returned by the authentication server and parses it to obtain the authentication policy and the first challenge value, obtains the authentication level and the authenticator identifier in the authentication policy, and confirms the corresponding authentication method according to the obtained authenticator identifier;
[0048] In this embodiment, there are one or more authenticator identifiers in the authentication policy, and they correspond to the authentication levels one by one; the authenticator identifiers include: PIN code module identifier, gesture password module identifier, fingerprint module identifier, and face recognition module identifier;
[0049] Step A3: The Hongmeng application sets the Hongmeng application user identity authentication method according to the authentication method and authentication level;
[0050] In this embodiment, the authentication method includes fingerprint authentication and / or face recognition authentication, and step A3 includes:
[0051] Step T1: The Hongmeng application uses the authentication method and authentication level as parameters to call the first interface provided by the Hongmeng user authentication service, and determines whether the Hongmeng system device has enabled the corresponding supported authentication method according to the authentication method and authentication level. If yes, execute step T2, otherwise report an error;
[0052] Step T2: The Hongmeng application uses the generated identity challenge value, all authentication methods enabled by the Hongmeng system device, the authentication level, and the authentication control interface configuration as parameters to call the second interface provided by the Hongmeng user authentication service to obtain the authentication object;
[0053] Step T3: The Hongmeng application uses the authentication object to call the third interface provided by the Hongmeng user authentication service to subscribe to the setting result;
[0054] Step T4: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service to initiate authentication, and receives the setting result returned by the fourth interface;
[0055] If the authentication method is fingerprint authentication, step T4 includes: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service, and the Hongmeng system prompts the user to scan the face in a pop-up box, and determines whether the scanned face information is consistent with the face information saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the fourth interface, otherwise, the Hongmeng application receives the failure information returned by the fourth interface;
[0056] If the authentication method is fingerprint authentication, step T4 includes: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service, and the Hongmeng system pops up a window to prompt the user to enter the fingerprint, and determines whether the fingerprint entered by the user is consistent with the fingerprint saved by the Hongmeng system device. If so, the Hongmeng application receives the success information returned by the fourth interface, otherwise the Hongmeng application receives the failure information returned by the fourth interface.
[0057] Optionally, step A3 in this embodiment may be replaced by: the Hongmeng application sets the Hongmeng application user identity authentication method according to the authentication method;
[0058] Accordingly, the authentication method in this step includes: PIN code authentication and / or gesture password authentication;
[0059] The Hongmeng application sets the Hongmeng application user identity authentication method according to the authentication method, specifically: the Hongmeng application prompts the user to set the PIN code through the authentication module corresponding to the PIN code module identifier, and after receiving the PIN code entered by the user, prompts the user to enter the PIN code again, and determines whether the PIN codes entered twice are consistent. If so, calculates and saves the summary value of the PIN code, otherwise reports an error; and / or
[0060] The Hongmeng application prompts the user to enter the gesture password through the authentication module corresponding to the gesture password module identifier, and determines whether the gesture password entered by the user is compliant. If so, the user is prompted to enter the gesture password again, and determines whether the gesture passwords entered twice are consistent. If so, the digest value of the gesture password is calculated and saved, otherwise an error is reported.
[0061] In this embodiment, the authenticator identifier in the authentication policy may be a PIN code module identifier and / or a gesture password module identifier and / or a fingerprint module identifier and / or a face recognition module identifier, and the fingerprint module identifier and / or the face recognition module identifier corresponds one-to-one to the corresponding authentication level;
[0062] Step A4: the Hongmeng application generates a user key pair and a key identifier and saves them in correspondence with the user name, generates registration data according to the user public key in the user key pair and the first challenge value, signs the registration data with the saved authenticator private key to obtain a first signature result, generates a registration confirmation request according to the key identifier, the registration data and the first signature result, and sends it to the authentication server;
[0063] In this embodiment, between step A4 and step A5, it also includes: the authentication server parses the received registration confirmation request to obtain the key identifier, registration data and the first signature result, and verifies the first signature result using the saved authenticator public key, the first challenge value and the registration data; if the verification is successful, the user name, the Hongmeng application identifier, the authentication level, the authenticator identifier and the device identifier, the user public key and the key identifier in the registration data are correspondingly saved, and the registration result is returned to the Hongmeng application as success, and step A5 is executed; if the verification fails, the registration result is returned to the Hongmeng application as failure, and step A5 is executed;
[0064] Specifically, verifying the first signature result using the stored authenticator public key and registration data includes:
[0065] Step K1: The authentication server uses the saved authenticator public key to decrypt the first signature result, performs hash calculation on the registration data, and determines whether the decryption result matches the hash calculation result. If so, step K2 is executed, otherwise the verification fails;
[0066] Step K2: the authentication server determines whether the saved first challenge value is consistent with the first challenge value in the registration data, if yes, the authentication succeeds, otherwise the authentication fails;
[0067] Step A5: The Hongmeng application receives the registration result returned by the authentication server and prompts the user;
[0068] like Figure 1 As shown, the authentication process includes:
[0069] Step B1: When the Hongmeng application receives the user's authentication operation information, it generates an authentication request according to the user name, the preset Hongmeng application identifier, the preset authenticator identifier and the preset device identifier in the authentication operation information and sends it to the authentication server;
[0070] In this embodiment, between step B1 and step B2, it also includes: the authentication server parses the received authentication request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set. If yes, the authentication level and key identifier are obtained according to the user name and Hongmeng application identifier, and the authentication policy is generated according to the authenticator identifier, the authentication level and the key identifier, and the second challenge value is generated and saved. The authentication request response is generated according to the generated authentication policy and the second challenge value and returned to the Hongmeng application, otherwise an error message is returned to the Hongmeng application, or the authentication server parses the received authentication request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set. If yes, the key identifier is obtained according to the user name and Hongmeng application identifier, and the authentication policy is generated according to the authenticator identifier and the key identifier, and the second challenge value is generated and saved. The authentication request response is generated according to the generated authentication policy and the second challenge value and returned to the Hongmeng application, otherwise an error message is returned to the Hongmeng application;
[0071] Step B2: The Hongmeng application receives the authentication request response returned by the authentication server and parses it to obtain the authentication policy and the second challenge value, obtains the authentication level, authenticator identifier and key identifier in the authentication policy, and confirms the corresponding authentication method according to the authenticator identifier;
[0072] Optionally, in this embodiment, the step of obtaining the authentication level, authenticator identifier and key identifier in the authentication policy in step B2 is replaced by: obtaining the authenticator identifier and key identifier in the authentication policy, where the authenticator identifier includes a PIN code module identifier and / or a gesture password module identifier;
[0073] Step B3: The Hongmeng application determines the Hongmeng application user identity authentication method according to the authentication method and the authentication level, and verifies the user identity according to the Hongmeng application user identity authentication method. If the verification passes, step B4 is executed; if the verification fails, an error is reported;
[0074] Optionally, the user identity is verified according to the Hongmeng application user identity authentication method in this embodiment, including:
[0075] Step P1: The Hongmeng application uses the authentication method and authentication level as parameters to call the first interface provided by the Hongmeng user authentication service, and determines whether the Hongmeng system device has enabled the corresponding supported authentication method according to the authentication method and authentication level. If yes, execute step P2, otherwise report an error;
[0076] Step P2: The Hongmeng application uses the generated identity challenge value, all authentication methods enabled by the Hongmeng system device, the authentication level, and the configuration authentication control interface as parameters to call the second interface provided by the Hongmeng user authentication service to obtain the authentication object;
[0077] Step P3: The Hongmeng application uses the authentication object to call the third interface provided by the Hongmeng user authentication service to subscribe to the authentication result;
[0078] Step P4: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service to initiate user identity authentication, and receives the verification result returned by the fourth interface;
[0079] If the determined Hongmeng application user identity authentication method is face recognition authentication, step P4 includes: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service, and the Hongmeng system pops up a box to prompt the user to scan the face, and determines whether the scanned face information is consistent with the face information saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the fourth interface, otherwise, the Hongmeng application receives the failure information returned by the fourth interface;
[0080] If the determined Hongmeng application user identity authentication method is fingerprint authentication, step P4 includes: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service, prompts the user to enter a fingerprint through the Hongmeng system pop-up box, and determines whether the fingerprint entered by the user is consistent with the fingerprint saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the fourth interface, otherwise, the Hongmeng application receives the failure information returned by the fourth interface;
[0081] Optionally, if the corresponding authentication method is confirmed as PIN code authentication and / or gesture password authentication according to the authenticator identifier, step B3 may be replaced by: the Hongmeng application prompts the user to enter the PIN code through the authentication module corresponding to the PIN code module identifier, performs a summary calculation on the PIN code received from the user, and determines whether the calculated PIN code summary value is consistent with the saved PIN code summary value. If so, the PIN code user identity authentication is passed, otherwise the PIN code user identity authentication is failed; and / or
[0082] The Hongmeng application prompts the user to enter the gesture password through the authentication module corresponding to the gesture password module identifier, calculates the digest of the gesture password received from the user, and determines whether the calculated gesture password summary value is consistent with the saved gesture password summary value. If so, the gesture password user identity authentication passes, otherwise the gesture password user identity authentication fails.
[0083] Step B4: The Hongmeng application obtains the corresponding saved key identifier according to the user name, and determines whether the obtained key identifier matches the key identifier obtained in the authentication policy. If so, execute step B5, otherwise an error is reported;
[0084] Step B5: the Hongmeng application generates a first random number, obtains a saved user key pair according to the key identifier, generates authentication data according to the first random number and the second challenge value, signs the authentication data using the user private key in the user key pair to obtain a second signature result, and sends the authentication data and the second signature result to the authentication server;
[0085] In this implementation, the steps between step B5 and step B6 also include: the authentication server receives the authentication data and the second signature result sent by the Hongmeng application, searches for the corresponding user public key according to the obtained key identifier, verifies the second signature result using the user public key, the saved second challenge value, and the authentication data, and returns the authentication result of success to the Hongmeng application if the verification is successful, and executes step B6; if the verification fails, returns the authentication result of failure to the Hongmeng application, and executes step B6;
[0086] Specifically, the second signature result is verified using the user public key, the saved second challenge value, and the authentication data, including:
[0087] Step M1: The authentication server uses the user's public key to decrypt the second signature result, performs hash calculation on the authentication data, and determines whether the decryption result matches the hash calculation result. If so, step M2 is executed, otherwise the verification fails;
[0088] Step M2: the authentication server determines whether the saved second challenge value is consistent with the second challenge value in the authentication data, if so, the authentication succeeds, otherwise the authentication fails;
[0089] Step B6: The Hongmeng application receives the authentication result returned by the authentication server and prompts the user.
[0090] Optionally, the method of this embodiment further includes a logout process, and the logout process includes:
[0091] Step C1: When the Hongmeng application receives the user's logout operation information, it generates a logout request according to the user name, Hongmeng application identifier, authenticator identifier and device identifier in the logout operation information, and sends the logout request to the authentication server;
[0092] In this embodiment, between step C1 and step C2, the following further includes: the authentication server parses the received deregistration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, searches for the corresponding key identifier and user public key according to the user name, Hongmeng application identifier, authenticator identifier and device identifier, and if found, generates a successful deregistration result according to the key identifier and returns it to the Hongmeng application, deletes and saves the key identifier and user public key, and executes step C2, if not found, returns the user non-existence information to the Hongmeng application;
[0093] Step C2: The Hongmeng application receives the successful deregistration result returned by the authentication server, and deletes the corresponding saved user key pair and key identifier according to the key identifier in the successful deregistration result.
[0094] The method of this embodiment can be used in the Hongmeng Next system to ensure the security, ease of use and scalability of Hongmeng applications; it supports the use of different authentication methods to verify user identity and supports different authentication levels, which can further ensure the legitimacy and security of user identity. Embodiment 2
[0095] Embodiment 2 of the present invention provides an identity authentication method for Hongmeng applications, which is applicable to Hongmeng applications in Hongmeng system devices. SDK is pre-set in Hongmeng applications. Users operate Hongmeng applications in Hongmeng system devices. The method includes a registration process and an authentication process. The method of this embodiment is as follows: Figure 2 and Figure 3 As shown, including:
[0096] Step 100: When the Hongmeng application receives the user operation information, it determines the operation type. If it is a registration operation, it executes step 101; if it is an authentication operation, it executes step 108;
[0097] Step 101: The Hongmeng application generates a registration request according to the preset Hongmeng application identifier, the user name in the registration operation information, the authenticator identifier and the device identifier preset in the SDK, and sends the registration request to the authentication server;
[0098] Optionally, the device identifier in this embodiment is a unique identifier randomly generated when the SDK is set in the Hongmeng application, and the SDK is used for FIDO authentication and / or smart key device authentication; the authenticator identifier is set in the SDK, including: a PIN code module identifier and / or a gesture password module identifier and / or a fingerprint module identifier and / or a face recognition module identifier;
[0099] Step 102: The authentication server parses the received registration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set. If yes, the authentication level is obtained according to the user name and Hongmeng application identifier, an authentication policy is generated according to the authenticator identifier and the authentication level, a first challenge value is generated and saved, a registration request response is generated according to the authentication policy and the first challenge value, and the registration request response is returned to the Hongmeng application. Otherwise, an error message is returned to the Hongmeng application.
[0100] In this embodiment, a one-to-one correspondence list of user name, Hongmeng application identifier, device identifier, authentication level and authenticator identifier is pre-set in the authentication server;
[0101] Step 103: The Hongmeng application receives the registration request response and parses it to obtain the authentication policy and the first challenge value, obtains the authentication level and the authenticator identifier in the authentication policy, and confirms the corresponding authentication method according to the authenticator identifier;
[0102] In this embodiment, the authentication methods include: face, fingerprint, PIN code, gesture password; among them, face authentication and fingerprint authentication both use Hongmeng User Authentication Kit (Chinese full name: User Authentication Service), and the authentication levels from high to low include: ATL (English full name: AuthTrustLevel) 4, ATL3, ATL2, ATL1; the authentication process of PIN code and gesture password is implemented by SDK, and the summary value of PIN code and gesture password data is stored locally to ensure that the password does not leave the Hongmeng application, which is safe and reliable; this embodiment specifically takes face and fingerprint as examples for explanation;
[0103] Among them, if the authentication level is ATL4, it means that it can identify individual users with high precision and has strong liveness detection capabilities, such as 6-digit or above PIN code authentication with a secure keyboard and fingerprint and 3D face authentication with special security enhancements, and application scenarios such as small payments; the authentication level is ATL3, which means that it can accurately identify individual users and has strong liveness detection capabilities, such as 2D face authentication with special security enhancements, and application scenarios such as device unlocking; the authentication level is ATL2, which means that it can accurately identify individual users and has certain liveness detection capabilities, such as 2D face authentication using ordinary cameras to capture images, and application scenarios such as maintaining the unlocked state of the device; the authentication level is ATL1, which means that it can identify individual users and has certain liveness detection capabilities, such as voiceprint authentication, and application scenarios such as business risk control, accurate recommendations, and personalized services;
[0104] Optionally, the Hongmeng application parses the received registration request response to obtain an authentication policy and a first challenge value; the authentication policy may include one or more authenticator identifiers and authentication levels, and the authenticator identifiers and authentication levels correspond one to one;
[0105] Step 104: The Hongmeng application sets the Hongmeng application user identity authentication method according to the authentication method and authentication level;
[0106] Optionally, in this embodiment, the Hongmeng application completes setting the user authentication method to fingerprint authentication or face recognition authentication by calling the interfaces provided by the User Authentication Kit (userAuth.getAvailableStatus, getUserAuthInstance, userAuthInstance.on, and userAuthInstance.start);
[0107] Specifically, step 104 includes:
[0108] Step 104-1: The Hongmeng application calls the userAuth.getAvailableStatus interface with the authentication method and authentication level as parameters, and determines whether the Hongmeng system device has enabled the corresponding supported authentication method according to the authentication method and authentication level. If yes, execute step 104-2, otherwise report an error;
[0109] In this embodiment, the same authentication method may have different authentication levels. For example, the authentication levels corresponding to the face recognition method include ATL4 (3D face authentication), ATL3 (2D face authentication with special security enhancement), and ATL2 (2D face authentication using an ordinary camera to capture images). If the authentication method is face recognition authentication and the authentication level is ATL3, the Hongmeng system device does not turn on face recognition or the Hongmeng system device turns on face recognition and the authentication level set in the device is not ATL3, then in step 104-1, the Hongmeng application will determine whether to report an error;
[0110] Step 104-2: The Hongmeng application generates an identity challenge value, and uses the generated identity challenge value, the corresponding authentication method enabled by the Hongmeng system device, the authentication level, and the authentication control interface configuration as parameters to call getUserAuthInstance to obtain the authentication object;
[0111] Step 104-3: The Hongmeng application uses the authentication object to call the userAuthInstance.on interface to subscribe to the setting result;
[0112] Step 104-4: The Hongmeng application uses the authentication object to call the userAuthInstance.start interface to initiate authentication, and receives the setting result returned by the userAuthInstance.start interface;
[0113] In this embodiment, if the authentication method is fingerprint authentication, step 104-4 includes: the Hongmeng application uses the authentication object to call the userAuthInstance.start interface, the system pops up a box to prompt the user to enter the fingerprint, and determines whether the fingerprint entered by the user is consistent with the fingerprint saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the userAuthInstance.start interface, otherwise, the Hongmeng application receives the failure information returned by the userAuthInstance.start interface;
[0114] If the authentication method is fingerprint authentication, step 104-4 includes: the Hongmeng application uses the authentication object to call the userAuthInstance.start interface, and the system prompts the user to scan the face in a pop-up window, and determines whether the scanned face information is consistent with the face information saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the userAuthInstance.start interface, otherwise, the Hongmeng application receives the failure information returned by the userAuthInstance.start interface;
[0115] Optionally, if there are multiple authenticator identifiers and authentication levels in the authentication policy, then in step 104, the Hongmeng application user identity authentication method needs to be set in turn according to the authentication method and the corresponding authentication level. For example, if the authenticator identifier in the authentication policy is a PIN code module identifier and a fingerprint module identifier (authentication level ATL4), then the Hongmeng application user identity authentication method set in step 104 is PIN code verification and fingerprint verification;
[0116] Step 105: The Hongmeng application generates a user key pair and a key identifier and stores them in a secure area corresponding to the user name in the operation information, generates registration data according to the user public key in the user key pair and the first challenge value, signs the registration data using the stored authenticator private key to obtain a first signature result, generates a registration confirmation request according to the key identifier, the registration data and the first signature result, and sends the registration confirmation request to the authentication server;
[0117] In this embodiment, the user key pair includes a user public key and a user private key, the security area may be a key-value database (KV-Store), the user key pair and the key identifier correspond one to one, and one user name may correspond to multiple key identifiers and user key pairs;
[0118] In this embodiment, the SDK of Hongmeng application is pre-set with the authenticator public-private key pair (including the authenticator public key and the authenticator private key). Different authenticators may correspond to different authenticator public-private key pairs, or may correspond to the same authenticator public-private key pair.
[0119] Step 106: the authentication server parses the registration confirmation request to obtain the key identifier, registration data and the first signature result, and verifies the first signature result using the saved authenticator public key, the first challenge value and the registration data. If the verification is successful, the user name, Hongmeng application identifier, the authentication level and the authenticator identifier are correspondingly saved with the device identifier, the user public key and the key identifier in the registration data, and a registration result of success is returned to the Hongmeng application, and step 107 is executed. If the verification fails, a registration result of failure is returned to the Hongmeng application, and step 107 is executed;
[0120] Optionally, the user name, Hongmeng application identifier, authentication level and authenticator identifier are saved in correspondence with the device identifier, the user public key and the key identifier in the registration data, including: according to the user name, Hongmeng application identifier, authentication level and authenticator identifier, the device identifier, the user public key and the key identifier in the registration data are saved in corresponding positions of the relationship table;
[0121] Specifically, in this embodiment, the first signature result is verified using the saved authenticator public key, the first challenge value, and the registration data, including:
[0122] Step 1061: the authentication server uses the stored authenticator public key to decrypt the first signature result, performs hash calculation on the registration data, and determines whether the decryption result matches the hash calculation result. If so, step 1062 is executed, otherwise the verification fails;
[0123] Step 1062: The authentication server determines whether the saved first challenge value is consistent with the first challenge value in the registration data, if yes, the authentication succeeds, otherwise the authentication fails;
[0124] Step 107: The Hongmeng application receives the registration result and displays it;
[0125] Step 108: The Hongmeng application generates an authentication request according to the preset Hongmeng application identifier, the user name in the authentication operation information, the authenticator identifier and the device identifier preset in the SDK, and sends the authentication request to the authentication server;
[0126] Step 109: The authentication server parses the received authentication request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set. If yes, the authentication level and key identifier are obtained according to the user name and Hongmeng application identifier, an authentication policy is generated according to the authenticator identifier, the authentication level and the key identifier, a second challenge value is generated and saved, an authentication request response is generated according to the authentication policy and the second challenge value, and the authentication request response is returned to the Hongmeng application. Otherwise, an error message is returned to the Hongmeng application.
[0127] Step 110: The Hongmeng application parses the received authentication request response to obtain the authentication policy and the second challenge value, obtains the authentication level, authenticator identifier and key identifier in the authentication policy, and confirms the authentication method according to the authenticator identifier;
[0128] Step 111: The Hongmeng application determines the Hongmeng application user identity authentication method according to the authentication method and the authentication level, and verifies the user identity according to the Hongmeng application user identity authentication method. If the verification passes, step 112 is executed, and if the verification fails, an error is reported;
[0129] In this embodiment, if the determined user identity authentication method of the HarmonyOS application is fingerprint authentication or face recognition authentication, the HarmonyOS application completes the user identity authentication by calling the interfaces (userAuth.getAvailableStatus, getUserAuthInstance, userAuthInstance.on, and userAuthInstance.start) provided by the User Authentication Kit;
[0130] Specifically, the user identity is verified according to the Hongmeng application user identity authentication method in step 111, including:
[0131] Step 111-1: The Hongmeng application calls the userAuth.getAvailableStatus interface with the authentication method and authentication level as parameters, and determines whether the Hongmeng system device has enabled the corresponding supported authentication method according to the authentication method and authentication level. If yes, execute step 111-2, otherwise report an error;
[0132] Step 111-2: The Hongmeng application generates an identity challenge value, and uses the generated identity challenge value, the corresponding authentication method enabled by the Hongmeng system device, the authentication level, and the authentication control interface configuration as parameters to call getUserAuthInstance to obtain the authentication object;
[0133] Step 111-3: Hongmeng application uses the authentication object to call the userAuthInstance.on interface to subscribe to the authentication result;
[0134] Step 111-4: The Hongmeng application uses the authentication object to call the userAuthInstance.start interface to initiate user identity authentication and receives the verification result returned by the userAuthInstance.start interface;
[0135] In this embodiment, if the determined user identity authentication method of the Hongmeng application is fingerprint authentication, step 111-4 includes: the Hongmeng application uses the authentication object to call the userAuthInstance.start interface, and the system prompts the user to enter a fingerprint in a pop-up box, and determines whether the fingerprint entered by the user is consistent with the fingerprint saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the userAuthInstance.start interface, otherwise, the Hongmeng application receives the failure information returned by the userAuthInstance.start interface;
[0136] If the authentication method is determined and the user identity authentication method of the Hongmeng application is face recognition authentication, step 111-4 includes: the Hongmeng application uses the authentication object to call the userAuthInstance.start interface, and the system pops up a box to prompt the user to scan the face, and determines whether the scanned face information is consistent with the face information saved by the Hongmeng system device. If so, the Hongmeng application receives the success information returned by the userAuthInstance.start interface, otherwise, the Hongmeng application receives the failure information returned by the userAuthInstance.start interface;
[0137] Optionally, if there are multiple Hongmeng application user identity authentication methods determined in step 111, the Hongmeng application user identity needs to be verified according to each determined Hongmeng application user identity authentication method in turn, and if the verifications are all passed, step 112 is executed;
[0138] For example, in this embodiment, the authentication method includes fingerprint authentication (authentication level is ATL4) and PIN code authentication, then step 111 includes: the Hongmeng application uses the authentication module to prompt the user to enter the PIN code, performs a summary calculation on the PIN code received from the user, and determines whether the calculated PIN code summary value is consistent with the saved PIN code summary value, if they are consistent, executes steps 111-1 to 111-4, if the authentication result is a success message, the user identity authentication is passed, if the authentication result is a failure message, the user identity authentication is not passed, if they are inconsistent, the user identity authentication is not passed; or, the Hongmeng application executes steps 111-1 to 111-4, if the Hongmeng application uses the authentication module to prompt the user to enter the PIN code after receiving the success message, performs a summary calculation on the PIN code received from the user, and determines whether the calculated PIN code summary value is consistent with the saved PIN code summary value, if they are consistent, the user identity authentication is passed, if they are inconsistent, the user identity authentication is not passed, if the Hongmeng application receives a failure message, the user identity authentication is not passed;
[0139] Step 112: The Hongmeng application obtains the corresponding key identifier according to the user name, and determines whether the obtained key identifier matches the key identifier obtained in the authentication policy. If so, step 113 is executed, otherwise an error is reported;
[0140] Step 113: The Hongmeng application generates a first random number, obtains a user key pair stored in the security area according to the key identifier, generates authentication data according to the first random number and the second challenge value, signs the authentication data using the user private key in the user key pair to obtain a second signature result, and sends the authentication data and the second signature result to the authentication server;
[0141] Step 114: The authentication server receives the authentication data and the second signature result sent by the Hongmeng application, searches for the corresponding user public key according to the key identifier, and verifies the second signature result using the user public key, the saved second challenge value, and the authentication data. If the verification is successful, the authentication result is returned to the Hongmeng application as success, and step 115 is executed. If the verification fails, the authentication result is returned to the Hongmeng application as failure, and step 115 is executed.
[0142] Specifically, in this embodiment, the second signature result is verified using the user public key, the saved second challenge value, and the authentication data, including:
[0143] Step 114-1: The authentication server uses the user's public key to decrypt the second signature result, performs hash calculation on the authentication data, and determines whether the decryption result matches the hash calculation result. If yes, step 114-2 is executed, otherwise the authentication fails.
[0144] Step 114-2: The authentication server determines whether the saved second challenge value is consistent with the second challenge value in the authentication data. If so, the authentication succeeds; otherwise, the authentication fails.
[0145] Step 115: The Hongmeng application receives the authentication result and displays it.
[0146] Optionally, in this embodiment, if the operation type is determined to be a logout operation in step 100, the logout process is performed, such as Figure 4 As shown, the logout process includes:
[0147] Step 401: The Hongmeng application generates a logout request according to the preset Hongmeng application identifier, the user name in the logout operation information, the authenticator identifier and the device identifier preset in the SDK, and sends the logout request to the authentication server;
[0148] Step 402: The authentication server parses the received deregistration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, searches for the corresponding key identifier and user public key according to the user name, Hongmeng application identifier, authenticator identifier and device identifier, generates a successful deregistration result according to the key identifier if found, returns the successful deregistration result to the Hongmeng application, deletes the saved key identifier and user public key, and executes step 403; if not found, returns the user non-existence information to the Hongmeng application;
[0149] Step 403: The Hongmeng application deletes the corresponding saved user key pair and key identifier based on the key identifier received in the successful logout result. Embodiment 3
[0150] Embodiment 3 of the present invention provides an identity authentication device for a Hongmeng application, including a registration module and an authentication module, wherein the registration module includes:
[0151] A first generating and sending unit is used to generate a registration request and send it to the authentication server according to the user name, preset Hongmeng application identifier, preset authenticator identifier and preset device identifier in the registration operation information when receiving the user's registration operation information;
[0152] A first parsing and determining unit, configured to receive a registration request response returned by the authentication server and parse to obtain an authentication policy and a first challenge value, obtain an authentication level and an authenticator identifier in the authentication policy, and confirm a corresponding authentication method according to the obtained authenticator identifier;
[0153] A first setting unit is used to set a Hongmeng application user identity authentication method according to an authentication method and an authentication level;
[0154] In this embodiment, the implementation process of the first setting unit in this embodiment is the same as step A3 in the first embodiment, and will not be repeated here;
[0155] A first signature sending unit is used to generate a user key pair and a key identifier and save them in correspondence with the user name in the operation information, generate registration data according to the user public key in the user key pair and the first challenge value, sign the registration data using the saved authenticator private key to obtain a first signature result, generate a registration confirmation request according to the key identifier, the registration data and the first signature result, and send it to the authentication server;
[0156] A first receiving and prompting unit, used to receive the registration result returned by the authentication server and prompt the user;
[0157] The certification modules include:
[0158] A second generating and sending unit is used to generate an authentication request according to the user name, preset Hongmeng application identifier, preset authenticator identifier and preset device identifier in the authentication operation information when receiving the user's authentication operation information, and send it to the authentication server;
[0159] A second parsing and determining unit is used to receive the authentication request response returned by the authentication server and parse to obtain the authentication policy and the second challenge value, obtain the authentication level, authenticator identifier and key identifier in the authentication policy, and confirm the corresponding authentication method according to the authenticator identifier;
[0160] A first verification unit is used to determine a Hongmeng application user identity authentication method according to the authentication method and the authentication level, and verify the user identity according to the Hongmeng application user identity authentication method, and trigger the acquisition judgment unit if the verification passes, and report an error if the verification fails;
[0161] In this embodiment, the implementation process of the first verification unit in this embodiment is the same as step B3 in the first embodiment, and will not be repeated here;
[0162] An acquisition judgment unit is used to obtain a corresponding saved key identifier according to the user name, and judge whether the obtained key identifier matches the key identifier obtained in the authentication policy. If yes, the second signature sending unit is triggered, otherwise an error is reported;
[0163] A second signature sending unit is used to generate a first random number, obtain a saved user key pair according to the key identifier, generate authentication data according to the first random number and the second challenge value, sign the authentication data using the user private key in the user key pair to obtain a second signature result, and send the authentication data and the second signature result to the authentication server;
[0164] The second receiving and prompting unit is used to receive the authentication result returned by the authentication server and prompt the user.
[0165] In this embodiment, the first generation and sending unit in the registration module sends the registration request to the authentication server and the first signature sending unit sends the registration confirmation request to the authentication server. The operation process of the authentication server receiving the registration request and the registration confirmation request can refer to the implementation process of Example 1 and will not be repeated here.
[0166] In this embodiment, the second generation and sending unit in the authentication module sends the authentication request to the authentication server and the first signature sending unit sends the authentication data and the second signature result to the authentication server. The operation process of the authentication server receiving the authentication request, authentication data and the second signature result can refer to the implementation process of Example 1 and will not be repeated here.
[0167] Optionally, the device of this embodiment further includes a logout module, and the logout module includes:
[0168] A third generating and sending unit is used to generate a logout request according to the user name, Hongmeng application identifier, authenticator identifier and device identifier in the logout operation information when receiving the logout operation information of the user, and send the logout request to the authentication server;
[0169] The receiving and deleting unit is used to receive the successful deregistration result returned by the authentication server, and delete the corresponding saved user key pair and key identifier according to the key identifier in the successful deregistration result.
[0170] In this embodiment, after the first generating and sending unit sends the logout request to the authentication server, the authentication server parses the received logout request to obtain the user name, HarmonyOS application identifier, authenticator identifier and device identifier, and searches for the corresponding key identifier and user public key based on the user name, HarmonyOS application identifier, authenticator identifier and device identifier. If found, a successful logout result is generated based on the key identifier and returned to the HarmonyOS application, and the saved key identifier and user public key are deleted. If not found, the user does not exist information is returned to the HarmonyOS application.
[0171] Optionally, an embodiment of the present application also provides an electronic device, which includes at least one processor, a memory, and instructions stored in the memory and executable by at least one processor, and at least one processor executes the instructions to implement an identity authentication method for a Harmony application in the above embodiment.
[0172] An embodiment of the present invention provides a computer program product, including a computer program / instructions, wherein when the computer program / instructions are executed by a processor, an identity authentication method for a Harmony application in the above-mentioned embodiment is implemented.
[0173] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs. When a computer program is loaded and executed on an electronic device, the process or function described in the embodiment of the present application is generated in whole or in part. The computer program can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a base station, electronic device, server or data center to another base station, electronic device, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that can be accessed by an electronic device or a data storage device such as a server or data center that contains one or more media that can be integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)), etc. In the embodiment of the present application, the electronic device may include the device described above.
[0174] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "one" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in a claim. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0175] Although the present application has been described in conjunction with specific features and embodiments thereof, it is obvious that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely exemplary illustrations of the present application as defined by the appended claims, and are deemed to have covered any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A method for identity authentication of Hongmeng applications, characterized in that: The registration process includes a registration process and an authentication process. The registration process includes: Step A1: When the Hongmeng application receives the user's registration operation information, it generates a registration request according to the user name, the preset Hongmeng application identifier, the preset authenticator identifier and the preset device identifier in the registration operation information and sends it to the authentication server; Step A2: the Hongmeng application receives the registration request response returned by the authentication server and parses it to obtain the authentication policy and the first challenge value, obtains the authentication level and the authenticator identifier in the authentication policy, and confirms the corresponding authentication method according to the obtained authenticator identifier, wherein there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level; Step A3: the Hongmeng application sets the Hongmeng application user identity authentication method according to the authentication method and the authentication level; Step A4: the Hongmeng application generates a user key pair and a key identifier and saves them corresponding to the user name, generates registration data according to the user public key in the user key pair and the first challenge value, signs the registration data using the saved authenticator private key to obtain a first signature result, generates a registration confirmation request according to the key identifier, the registration data and the first signature result, and sends it to the authentication server; Step A5: the Hongmeng application receives the registration result returned by the authentication server and prompts the user; The authentication process includes: Step B1: when the Hongmeng application receives the user's authentication operation information, it generates an authentication request according to the user name, the preset Hongmeng application identifier, the preset authenticator identifier and the preset device identifier in the authentication operation information and sends it to the authentication server; Step B2: the Hongmeng application receives the authentication request response returned by the authentication server and parses it to obtain the authentication policy and the second challenge value, obtains the authentication level, authenticator identifier and key identifier in the authentication policy, and confirms the corresponding authentication method according to the obtained authenticator identifier, where there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level; Step B3: the Hongmeng application determines the Hongmeng application user identity authentication method according to the authentication method and the authentication level, verifies the user identity according to the Hongmeng application user identity authentication method, and executes step B4 if the verification passes, and reports an error if the verification fails; Step B4: the Hongmeng application obtains the corresponding saved key identifier according to the user name, and determines whether the obtained key identifier matches the key identifier obtained in the authentication policy. If so, step B5 is executed, otherwise an error is reported; Step B5: the Hongmeng application generates a first random number, obtains a saved user key pair according to the key identifier, generates authentication data according to the first random number and the second challenge value, signs the authentication data using the user private key in the user key pair to obtain a second signature result, and sends the authentication data and the second signature result to the authentication server; Step B6: The Hongmeng application receives the authentication result returned by the authentication server and prompts the user.
2. The identity authentication method of Hongmeng application as claimed in claim 1, characterized in that: The step A3 comprises: Step T1: the Hongmeng application uses the authentication method and the authentication level as parameters to call the first interface provided by the Hongmeng user authentication service, and determines whether the Hongmeng system device has enabled the corresponding supported authentication method according to the authentication method and the authentication level. If yes, execute step T2, otherwise report an error; Step T2: the Hongmeng application uses the generated identity challenge value, all authentication methods enabled by the determined Hongmeng system device, the authentication level and the authentication control interface configuration as parameters to call the second interface provided by the Hongmeng user authentication service to obtain the authentication object; Step T3: the Hongmeng application uses the authentication object to call the third interface provided by the Hongmeng user authentication service to subscribe to the setting result; Step T4: The Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service to initiate authentication, and receives the setting result returned by the fourth interface.
3. The identity authentication method of Hongmeng application as claimed in claim 2, characterized in that: If the authentication method is face recognition authentication, the step T4 includes: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service, and the Hongmeng system pops up a window to prompt the user to scan the face, and determines whether the scanned face information is consistent with the face information saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the fourth interface, otherwise, the Hongmeng application receives the failure information returned by the fourth interface; If the authentication method is fingerprint authentication, the step T4 includes: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service, and the Hongmeng system pops up a window to prompt the user to enter a fingerprint, and determines whether the fingerprint entered by the user is consistent with the fingerprint saved by the Hongmeng system device. If so, the Hongmeng application receives the success information returned by the fourth interface, otherwise, the Hongmeng application receives the failure information returned by the fourth interface.
4. The identity authentication method of Hongmeng application as claimed in claim 1, characterized in that: The step A2 of obtaining the authentication level and the authenticator identifier in the authentication policy is replaced by: obtaining the authenticator identifier in the authentication policy, wherein the authenticator identifier includes a PIN code module identifier and / or a gesture password module identifier; Step A3 is replaced by: the Hongmeng application prompts the user to set a PIN code through the authentication module corresponding to the PIN code module identifier, and after receiving the PIN code entered by the user, prompts the user to enter the PIN code again, and determines whether the two PIN codes entered are consistent. If yes, calculates and saves the summary value of the PIN code, otherwise reports an error; and / or The Hongmeng application prompts the user to enter a gesture password through the authentication module corresponding to the gesture password module identifier, and determines whether the gesture password entered by the user is compliant. If so, the user is prompted to enter the gesture password again, and determines whether the gesture passwords entered twice are consistent. If so, the summary value of the gesture password is calculated and saved, otherwise an error is reported.
5. The identity authentication method of Hongmeng application as claimed in claim 1, characterized in that: The step A1 and the step A2 also include: the authentication server parses the received registration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, determines whether the corresponding authenticator identifier and device identifier are set, and if so, obtains the authentication level according to the user name and the Hongmeng application identifier, generates an authentication policy according to the authenticator identifier and the authentication level, generates and saves a first challenge value, generates a registration request response according to the authentication policy and the first challenge value and returns it to the Hongmeng application, otherwise returns an error message to the Hongmeng application; Or, the authentication server parses the received registration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set. If so, it obtains the authentication level according to the user name and the Hongmeng application identifier, generates an authentication policy according to the authenticator identifier, generates and saves a first challenge value, generates a registration request response according to the authentication policy and the first challenge value and returns it to the Hongmeng application, otherwise, returns an error message to the Hongmeng application.
6. The identity authentication method of Hongmeng application as claimed in claim 5, characterized in that: Between step A4 and step A5, it also includes: the authentication server parses the received registration confirmation request to obtain the key identifier, registration data and the first signature result, and uses the saved authenticator public key, the first challenge value and the registration data to verify the first signature result; if the verification is successful, the user name, the Hongmeng application identifier, the authentication level, the authenticator identifier and the device identifier, the user public key and the key identifier in the registration data are saved accordingly, and a registration result of success is returned to the Hongmeng application, and step A5 is executed; if the verification fails, a registration result of failure is returned to the Hongmeng application, and step A5 is executed.
7. The identity authentication method of Hongmeng application as claimed in claim 6, characterized in that: The verifying the first signature result using the stored authenticator public key and the registration data includes: Step K1: the authentication server uses the stored authenticator public key to decrypt the first signature result, performs hash calculation on the registration data, and determines whether the decryption result matches the hash calculation result. If yes, step K2 is executed, otherwise the verification fails; Step K2: the authentication server determines whether the saved first challenge value is consistent with the first challenge value in the registration data, if so, the verification is successful, otherwise the verification fails.
8. The identity authentication method of Hongmeng application as claimed in claim 1, characterized in that: The step B3 of verifying the user identity according to the Hongmeng application user identity authentication method includes: Step P1: the Hongmeng application uses the authentication method and the authentication level as parameters to call the first interface provided by the Hongmeng user authentication service, and determines whether the Hongmeng system device has enabled the corresponding supported authentication method according to the authentication method and the authentication level. If yes, execute step P2, otherwise report an error; Step P2: the Hongmeng application uses the generated identity challenge value, all authentication methods enabled by the determined Hongmeng system device, the authentication level and the configuration authentication control interface as parameters to call the second interface provided by the Hongmeng user authentication service to obtain the authentication object; Step P3: the Hongmeng application uses the authentication object to call the third interface provided by the Hongmeng user authentication service to subscribe to the authentication result; Step P4: The Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service to initiate user identity authentication, and receives the verification result returned by the fourth interface.
9. The identity authentication method of Hongmeng application as claimed in claim 8, characterized in that: If the determined Hongmeng application user identity authentication method is face recognition verification, the step P4 includes: the Hongmeng application uses the authentication object to call the fourth interface provided by the Hongmeng user authentication service, and the Hongmeng system pops up a box to prompt the user to scan the face, and determines whether the scanned face information is consistent with the face information saved by the Hongmeng system device. If yes, the Hongmeng application receives the success information returned by the fourth interface, otherwise, the Hongmeng application receives the failure information returned by the fourth interface; If the determined user identity authentication method of the HarmonyOS application is fingerprint verification, the step P4 includes: the HarmonyOS application uses the authentication object to call the fourth interface provided by the HarmonyOS user authentication service, prompts the user to enter a fingerprint through a pop-up window of the HarmonyOS system, and determines whether the fingerprint entered by the user is consistent with the fingerprint saved by the HarmonyOS system device. If so, the HarmonyOS application receives the success information returned by the fourth interface, otherwise, the HarmonyOS application receives the failure information returned by the fourth interface.
10. The identity authentication method of Hongmeng application as claimed in claim 1, characterized in that: The step of obtaining the authentication level, authenticator identifier and key identifier in the authentication policy in step B2 is replaced by: obtaining the authenticator identifier and key identifier in the authentication policy, wherein the authenticator identifier includes a PIN code module identifier and / or a gesture password module identifier; The step B3 is replaced by: the Hongmeng application prompts the user to enter a PIN code through the authentication module corresponding to the PIN code module identifier, performs a summary calculation on the PIN code received from the user, and determines whether the calculated PIN code summary value is consistent with the saved PIN code summary value. If so, the PIN code user identity authentication is passed, otherwise, the PIN code user identity authentication is failed; and / or The Hongmeng application prompts the user to enter a gesture password through the authentication module corresponding to the gesture password module identifier, calculates a summary of the gesture password received from the user, and determines whether the calculated gesture password summary value is consistent with the saved gesture password summary value. If so, the gesture password user identity authentication is passed; otherwise, the gesture password user identity authentication is failed.
11. The identity authentication method of Hongmeng application as claimed in claim 1, characterized in that: The step B1 and the step B2 also include: The authentication server parses the received authentication request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set; if so, obtains the authentication level and key identifier according to the user name and the Hongmeng application identifier, generates an authentication policy according to the authenticator identifier, the authentication level and the key identifier, generates and saves a second challenge value, generates an authentication request response according to the generated authentication policy and the second challenge value and returns it to the Hongmeng application; otherwise, returns an error message to the Hongmeng application; Or, the authentication server parses the received authentication request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, and determines whether the corresponding authenticator identifier and device identifier are set. If so, it obtains the key identifier according to the user name and the Hongmeng application identifier, generates an authentication policy according to the authenticator identifier and the key identifier, generates and saves a second challenge value, generates an authentication request response according to the generated authentication policy and the second challenge value and returns it to the Hongmeng application, otherwise returns an error message to the Hongmeng application.
12. The identity authentication method of Hongmeng application as claimed in claim 11, characterized in that: The step B5 and the step B6 also include: The authentication server receives the authentication data and the second signature result sent by the Harmony application, searches for the corresponding user public key according to the key identifier, and verifies the second signature result using the user public key, the saved second challenge value, and the authentication data; if the verification is successful, the authentication result of success is returned to the Harmony application, and step B6 is executed; if the verification fails, the authentication result of failure is returned to the Harmony application, and step B6 is executed.
13. The identity authentication method of Hongmeng application as claimed in claim 12, characterized in that: The verifying the second signature result by using the user public key, the saved second challenge value, and the authentication data includes: Step M1: The authentication server uses the user public key to decrypt the second signature result, performs hash calculation on the authentication data, and determines whether the decryption result matches the hash calculation result. If so, step M2 is executed; otherwise, verification fails. Step M2: the authentication server determines whether the saved second challenge value is consistent with the second challenge value in the authentication data, if so, the authentication succeeds, otherwise the authentication fails.
14. The identity authentication method of Hongmeng application as claimed in claim 1, characterized in that: Also included is a deregistration process, the deregistration process comprising: Step C1: when the Hongmeng application receives the user's logout operation information, it generates a logout request according to the user name, the preset Hongmeng application identifier, the preset authenticator identifier and the preset device identifier in the logout operation information, and sends the logout request to the authentication server; Step C2: The Hongmeng application receives a successful deregistration result returned by the authentication server, and deletes the corresponding saved user key pair and key identifier according to the key identifier in the successful deregistration result.
15. The identity authentication method of Hongmeng application as claimed in claim 14, characterized in that: Between step C1 and step C2, it also includes: the authentication server parses the received deregistration request to obtain the user name, Hongmeng application identifier, authenticator identifier and device identifier, searches for the corresponding key identifier and user public key according to the user name, the Hongmeng application identifier, the authenticator identifier and the device identifier, and if found, generates a successful deregistration result according to the key identifier and returns it to the Hongmeng application, deletes the found key identifier and user public key, and executes step C2; if not found, returns the user non-existence information to the Hongmeng application.
16. An identity authentication device for Hongmeng applications, characterized in that: It includes a registration module and an authentication module, and the registration module includes: A first generating and sending unit is used to generate a registration request and send it to an authentication server according to the user name, preset Hongmeng application identifier, preset authenticator identifier and preset device identifier in the registration operation information when receiving the user's registration operation information; A first parsing and determining unit is used to receive the registration request response returned by the authentication server and parse to obtain the authentication policy and the first challenge value, obtain the authentication level and the authenticator identifier in the authentication policy, and confirm the corresponding authentication method according to the obtained authenticator identifier, wherein there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level; A first setting unit is used to set a Hongmeng application user identity authentication method according to the authentication method and the authentication level; a first signature sending unit, configured to generate a user key pair and a key identifier and save them in correspondence with the user name, generate registration data according to the user public key in the user key pair and the first challenge value, sign the registration data using the saved authenticator private key to obtain a first signature result, generate a registration confirmation request according to the key identifier, the registration data and the first signature result, and send the request to the authentication server; A first receiving and prompting unit, configured to receive the registration result returned by the authentication server and prompt the user; The authentication module comprises: A second generating and sending unit is used to generate an authentication request according to the user name, preset Hongmeng application identifier, preset authenticator identifier and preset device identifier in the authentication operation information when receiving the user's authentication operation information, and send it to the authentication server; A second parsing and determining unit is configured to receive the authentication request response returned by the authentication server and parse to obtain the authentication policy and the second challenge value, obtain the authentication level, the authenticator identifier and the key identifier in the authentication policy, and confirm the corresponding authentication method according to the authenticator identifier, wherein there are one or more authenticator identifiers in the authentication policy, and they correspond one to one with the authentication level; A first verification unit, configured to determine a Hongmeng application user identity authentication method according to the authentication method and the authentication level, and verify the user identity according to the Hongmeng application user identity authentication method, and trigger an acquisition judgment unit if the verification is passed, and report an error if the verification fails; The acquisition and judgment unit is used to obtain the corresponding saved key identifier according to the user name, and judge whether the obtained key identifier matches the key identifier obtained in the authentication policy, and trigger the second signature sending unit if it matches, otherwise an error is reported; The second signature sending unit is used to generate a first random number, obtain a saved user key pair according to the key identifier, generate authentication data according to the first random number and the second challenge value, sign the authentication data using a user private key in the user key pair to obtain a second signature result, and send the authentication data and the second signature result to the authentication server; The second receiving and prompting unit is used to receive the authentication result returned by the authentication server and prompt the user.
17. An electronic device, characterized in that: The electronic device includes at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, and the at least one processor executes the instructions to implement the method according to any one of claims 1 to 15.
18. A computer-readable storage medium, characterized in that: The computer-readable storage medium comprises a computer program, and when the computer program is executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 15.
19. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the method according to any one of claims 1 to 15 is implemented.
Citation Information
Patent Citations
XFS implementation method, device and equipment based on swan gap system and readable storage medium
CN115344401A
Terminal identity authentication method, device and equipment based on swan monk system, and medium
CN115361134A