A Multi-Factor Enhanced Authentication Method and Device Applicable to a Trusted Fingerprint Mouse
Through the multi-factor authentication method of trusted fingerprint mouse, the user name, password and biological information combined with SM2 algorithm is used to solve the security risks of traditional single-factor authentication, and high security and convenient identity authentication are achieved to ensure the security management of the information system.
Patent Information
- Application Number
- CN202411545487.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-31
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-10-31
AI Technical Summary
The existing traditional single-factor authentication methods have security risks such as weak passwords and password blasting, and cannot meet the security needs of key information systems.
Multi-factor enhanced authentication is performed using a trusted fingerprint mouse. After the user name and password is initially authenticated, biological information is obtained and digital certificates are retrieved for signatures. The signature value is encrypted and decrypted using the SM2 algorithm, and the validity of the signature value is judged through the unified identity authentication system to determine the user's application permissions.
It improves the security and convenience of identity authentication, prevents security risks caused by loss of equipment or password leakage, and realizes the protection of user information and the security management of information systems.
Smart Images

Figure CN119494126B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly relates to a multi-factor enhanced authentication method and device applicable to a trusted fingerprint mouse. Background Art
[0002] A trusted fingerprint mouse is a mouse product that combines fingerprint recognition technology and security authentication functions. By using the user's fingerprint as a means of identity verification, it provides a high-security level identity authentication method, which is applicable to application scenarios that require high security, such as e-government, network identity authentication, etc. This kind of mouse not only improves the convenience of use, but also enhances data security and privacy protection.
[0003] At present, the authentication method of the information system is the key to determining the security of the system. Traditional identity authentication technology is based on password verification technology composed of numbers, characters, etc. Due to security risks such as weak passwords and password cracking in traditional single-factor authentication, it can no longer meet the requirements of critical information systems.
[0004] Therefore, how to invent a method for multi-factor enhanced authentication based on computer external devices has become an urgent problem to be solved. Summary of the Invention
[0005] For this reason, the present invention provides a multi-factor enhanced authentication method and device applicable to a trusted fingerprint mouse, which solves the problem that traditional single-factor authentication cannot meet the security requirements of critical information systems due to security risks such as weak passwords and password cracking.
[0006] To achieve the above object, the present invention provides the following technical solution: A multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, including:
[0007] When a target user logs in to a set system through a username and a password, the trusted fingerprint mouse performs a preliminary identity authentication on the target user through the username and the password;
[0008] After the preliminary identity authentication is passed, the trusted fingerprint mouse obtains the biological information of the target user; according to the biological information, the trusted fingerprint mouse retrieves the digital certificate corresponding to the biological information, and signs the digital certificate to obtain a signature value;
[0009] The trusted fingerprint mouse judges the validity of the signature value, and performs enhanced identity authentication on the target user according to the validity of the signature value; after the target user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the digital certificate, and enables the application permissions within the application permission range for the target user.
[0010] As a preferred solution of a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, the digital certificate includes the biometric information and identity information of the target user; the biometric information is biometric fingerprint information; the identity information includes: name, email, institution name, department name, and usage permission information.
[0011] As a preferred solution of a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, in the process of the trusted fingerprint mouse signing the digital certificate to obtain a signature value, the trusted fingerprint mouse encrypts, decrypts, and signs the digital certificate through the SM2 algorithm.
[0012] As a preferred solution of a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, in the process of the trusted fingerprint mouse judging the validity of the signature value, the trusted fingerprint mouse sends the signature value to the unified identity authentication system, and the unified identity authentication system judges the validity of the signature value.
[0013] As a preferred solution of a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, when the preliminary identity authentication fails, when the corresponding digital certificate cannot be retrieved from the obtained biometric information, or when the signature value is invalid, it is considered that the identity authentication of the target user fails.
[0014] The present invention also provides a multi-factor enhanced authentication device applicable to a trusted fingerprint mouse. Based on the above multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, it includes:
[0015] A preliminary identity authentication module, configured to, when a target user logs in to a set system through a username and password, the trusted fingerprint mouse performs preliminary identity authentication on the target user through the username and the password;
[0016] A digital certificate retrieval module, configured to, after the preliminary identity authentication is passed, the trusted fingerprint mouse obtains the biometric information of the target user; according to the biometric information, the trusted fingerprint mouse retrieves the digital certificate corresponding to the biometric information, and signs the digital certificate to obtain a signature value;
[0017] An enhanced identity authentication module, configured to the trusted fingerprint mouse judge the validity of the signature value, and perform enhanced identity authentication on the target user according to the validity of the signature value; after the target user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the digital certificate, and enables the application permissions within the application permission range for the target user.
[0018] As a preferred solution for a multi-factor enhanced authentication device applicable to a trusted fingerprint mouse, in the digital certificate retrieval module, the digital certificate includes the biological information and identity information of the target user; the biological information is biological fingerprint information; the identity information includes: name, email, institutional name, department name, and usage permission information.
[0019] As a preferred solution for a multi-factor enhanced authentication device applicable to a trusted fingerprint mouse, in the digital certificate retrieval module, during the process of the trusted fingerprint mouse signing the digital certificate to obtain a signature value, the trusted fingerprint mouse performs encryption, decryption, and signature processing on the digital certificate through the SM2 algorithm.
[0020] As a preferred solution for a multi-factor enhanced authentication device applicable to a trusted fingerprint mouse, in the enhanced identity authentication module, during the process of the trusted fingerprint mouse judging the validity of the signature value, the trusted fingerprint mouse sends the signature value to the unified identity authentication system, and the unified identity authentication system judges the validity of the signature value.
[0021] As a preferred solution for a multi-factor enhanced authentication device applicable to a trusted fingerprint mouse, in the preliminary identity authentication module, the digital certificate retrieval module, and the enhanced identity authentication module, when the preliminary identity authentication fails, when the corresponding digital certificate cannot be retrieved for the obtained biological information, or when the signature value is invalid, it is considered that the identity authentication of the target user fails.
[0022] The present invention has the following advantages: The present invention uses a mouse as a fingerprint acquisition device, fully integrating the traditional USBKEY identity authentication function (or username and password), fingerprint identification technology with the mouse. It has both the function of identifying the uniqueness of identity and improves the convenience and usability of use. During the identity authentication process, it is necessary to identify the characteristics of a living fingerprint to avoid the security risks brought by the loss of the device or the leakage of the password when the user uses an ordinary USBKEY. In order to strengthen the protection of user information, the user uses their own biometric characteristics to authenticate their identity, preventing unauthorized user access and the use of unauthorized resources, and ensuring information security. By using a multi-factor authentication service, it integrates the device fingerprint, biometric fingerprint, and mobile security technology in a traditional mobile terminal with domestic cryptographic algorithms, digital certificates, and identity authentication technology to implement a compliant password security module for the mobile terminal. Through integration with the user management and information system, it realizes user identity authentication, data integrity protection, data confidentiality, and user behavior non-repudiation. The present invention uses a two-factor authentication technology of username + password + fingerprint biometric characteristics, and adopts a dedicated security chip to protect sensitive information, avoiding information leakage, and applying the SM2 algorithm to encrypt data to ensure the confidentiality of data during transmission and storage. In response to security management and related security requirements such as identity authentication, data integrity, and data confidentiality, a unified security architecture is adopted to construct the identity authentication and password security basic services, providing comprehensive security services such as unified user management, authorization and authentication, digital certificates, password services, and trusted data security access control for information-based networks and systems, further forming corresponding security management and integration standards, and laying a security foundation for future information-based construction. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only exemplary, and for those of ordinary skill in the art, without creative efforts, other implementation drawings can also be obtained based on the provided drawings.
[0024] The structures, proportions, sizes, etc. illustrated in this specification are only used to cooperate with the content disclosed in the specification for those familiar with this technology to understand and read, and are not used to limit the limited conditions under which the present invention can be implemented. Therefore, they do not have a substantial technical meaning. Any modification of the structure, change in the proportional relationship, or adjustment of the size, without affecting the effects that the present invention can produce and the purposes that can be achieved, should still fall within the scope covered by the technical content disclosed in the present invention.
[0025] Figure 1 It is a schematic flow chart of a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse provided in Embodiment 1 of the present invention;
[0026] Figure 2 Schematic diagram of the structure of a trusted fingerprint mouse in the multi-factor enhanced authentication method applicable to the trusted fingerprint mouse provided in Embodiment 1 of the present invention;
[0027] Figure 3 Schematic diagram of the architecture of a multi-factor enhanced authentication device applicable to the trusted fingerprint mouse provided in Embodiment 2 of the present invention. Detailed implementation manners
[0028] The following specific embodiments illustrate the implementation manners of the present invention. Those skilled in the art can easily understand the other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0029] Embodiment 1
[0030] Refer to Figure 1 , the present invention provides an embodiment 1 of an embodied intelligence execution and training method based on an edge-cloud collaborative large model, including the following steps:
[0031] S1. When the target user logs in to the set system through the username and password, the trusted fingerprint mouse performs a preliminary identity authentication on the target user through the username and the password;
[0032] S2. After the preliminary identity authentication is passed, the trusted fingerprint mouse obtains the biological information of the target user; according to the biological information, the trusted fingerprint mouse retrieves the digital certificate corresponding to the biological information and signs the digital certificate to obtain a signature value;
[0033] S3. The trusted fingerprint mouse judges the validity of the signature value and performs enhanced identity authentication on the target user according to the validity of the signature value; after the target user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the digital certificate and enables the application permissions within the application permission range for the target user.
[0034] In this embodiment, as Figure 2 shown, the trusted fingerprint mouse includes: a mouse chip, a fingerprint sensor, a national cryptography security chip, and a 2.4G transmitter.
[0035] Among them, the mouse chip is used to perform preliminary identity authentication on the target user;
[0036] The fingerprint sensor is used to obtain the target fingerprint information of the target user after the initial identity authentication of the target user is passed, and upload the target fingerprint information to the national cryptography security chip;
[0037] The national cryptography security chip is used to perform enhanced identity authentication on the target user according to the target biological fingerprint information;
[0038] The 2.4G transmitter is used to send the transmission data generated by the mouse chip and the secure transmission data generated by the national cryptography security chip to the PC after the enhanced identity authentication of the target user is passed; the transmission data and the secure transmission data are used to drive the wireless security mouse driver program of the PC.
[0039] Among them, the 2.4G transmitter communicates with the 2.4G receiver installed on the PC through the 2.4G communication channel. The 2.4G transmitter transmits the transmission data and the secure transmission data to the 2.4G receiver through the 2.4G communication channel, and through the 2.4G receiver, transmits the transmission data and the secure transmission data to the trusted fingerprint mouse driver program of the PC;
[0040] The 2.4G transmitter communicates with the 2.4G receiver through the 2.4G channel upward to receive the application data of the PC host computer, and realizes data interaction with the national cryptography secondary fingerprint module through the UART serial port downward. In addition, the main control chip of the 2.4G transmitter also realizes the data reporting function of the wireless mouse.
[0041] In this embodiment, the 2.4G receiver is innovatively defined as a USB composite device. In addition to realizing the data transmission level data reporting function of the traditional wireless mouse, another USB custom device is virtualized to share the 2.4G channel to realize data interaction between the PC driver program and the national cryptography secondary fingerprint module in the wireless fingerprint mouse. The 2.4G receiver communicates with the windowshello driver program upward and communicates with the 2.4G transmitter through the 2.4G channel downward.
[0042] In this embodiment, the national cryptography secondary fingerprint module is composed of a national cryptography secondary security chip and a high-performance low-power fingerprint sensor, and adopts the MOC (matc on chip) working mode, that is, all fingerprint data acquisition, processing, storage, comparison, management, etc. are realized within the national cryptography secondary security chip to ensure the full-cycle security of personal biometric data. The national cryptography secondary fingerprint module interacts with the 2.4G transmitter through the UART serial port to realize two-way data exchange.
[0043] During the data exchange process, the data protocol is divided into request data and response data. Among them, the request data is the security and fingerprint application requests sent from the PC to the national cryptography level 2 fingerprint module, and the response data is the security and fingerprint service results returned by the fingerprint module to the upper PC. The specific definitions are shown in Table 1 and Table 2 below:
[0044]
[0045] Table 1 Security and fingerprint application request data sent from the PC to the national cryptography level 2 fingerprint module
[0046]
[0047] Table 2 Security and fingerprint service result data returned by the fingerprint module to the upper PC
[0048] In this embodiment, in the overall architecture of the trusted fingerprint mouse, the security chip is connected to the fingerprint sensor to complete the security functions of the secure fingerprint mouse. The specific functions include: driving the fingerprint sensor to collect fingerprint images, executing fingerprint algorithms to complete functions such as fingerprint entry, comparison, deletion, etc., completing the storage of fingerprint templates, completing the secure storage of keys, certificates, and sensitive data, and completing the operation functions of cryptographic algorithms such as encryption, decryption, signature, verification signature, and digest. The fingerprint sensor generally selects a capacitive fingerprint sensor, which is used for the collection of fingerprint images and is also the only electronic component that needs to be exposed on the surface of the device in the entire system.
[0049] In this embodiment, in step S1, when the target user logs in to the set system through the username and password, the trusted fingerprint mouse performs a preliminary identity authentication on the target user through the username and the password;
[0050] Specifically, when the target user logs in to the set system through the username and password, the trusted fingerprint mouse performs a preliminary identity authentication on the target user through the mouse chip.
[0051] In this embodiment, in step S2, when the preliminary identity authentication is passed, the trusted fingerprint mouse obtains the biological information of the target user; according to the biological information, the trusted fingerprint mouse retrieves the digital certificate corresponding to the biological information and signs the digital certificate to obtain a signature value;
[0052] Specifically, when the preliminary identity authentication is passed, the trusted fingerprint mouse obtains the biological fingerprint information of the target user through the fingerprint sensor; according to the biological fingerprint information of the target user, the trusted fingerprint mouse compares the obtained target fingerprint information with the stored fingerprint information. If there is fingerprint information that is the same as the target fingerprint information, the digital certificate corresponding to the fingerprint information is retrieved. The digital certificate is decrypted and signed through the SM2 algorithm to obtain a signature value.
[0053] Among them, the digital certificate includes the biological information and identity information of the target user; the biological information is biological fingerprint information; the identity information includes: name, email, institution name, department name, and usage permission information.
[0054] Among them, the SM2 algorithm is the SM2 elliptic curve public key cryptography algorithm, a public key cryptography algorithm independently designed in China, including the SM2-1 elliptic curve digital signature algorithm, the SM2-2 elliptic curve key exchange protocol, and the SM2-3 elliptic curve public key encryption algorithm, which are respectively used to implement functions such as digital signature, key negotiation, and data encryption.
[0055] In this embodiment, in step S3, the trusted fingerprint mouse judges the validity of the signature value and performs enhanced identity authentication on the target user according to the validity of the signature value; after the target user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the digital certificate and enables the application permissions within the application permission range for the target user.
[0056] Specifically, the trusted fingerprint mouse sends the signature value to the unified identity authentication system, and the unified identity authentication system judges the validity of the signature value. After confirming that the signature value is valid, the enhanced identity authentication of the target user is completed; after the user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the usage permission information in the digital certificate and enables the application permissions within the application permission range for the target user.
[0057] In this embodiment, when the initial identity authentication fails, when the corresponding digital certificate cannot be retrieved from the obtained biological information, or when the signature value is invalid, it is considered that the identity authentication of the target user fails.
[0058] In summary, when a target user logs in to the set system through a username and password, the trusted fingerprint mouse performs a preliminary identity authentication on the target user through the username and the password; when the preliminary identity authentication is passed, the trusted fingerprint mouse acquires the biological information of the target user; according to the biological information, the trusted fingerprint mouse retrieves the digital certificate corresponding to the biological information, signs the digital certificate, and obtains a signature value; the trusted fingerprint mouse determines the validity of the signature value, and performs enhanced identity authentication on the target user according to the validity of the signature value; after the target user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the digital certificate, and enables the application permissions within the application permission range for the target user. The present invention uses a mouse as a fingerprint collection device, fully combines the traditional USBKEY identity authentication function (or username and password), fingerprint identification technology with the mouse, has both the identification function of identity uniqueness and improves the convenience and usability of use. During the identity authentication process, it is necessary to identify the live fingerprint features to avoid the security risks brought by the loss of the device or the leakage of the password when the user uses an ordinary USBKEY. In order to strengthen user information protection, use one's own biological characteristics to authenticate one's own identity, prevent unauthorized user access and the use of unauthorized resources, and ensure information security. By using the multi-factor authentication service, the device fingerprint, biological fingerprint, and mobile security technology in the traditional mobile terminal are integrated with the domestic cryptographic algorithm, digital certificate, and identity authentication technology to implement a compliant password security module for the mobile terminal. Through the integration with the user management and information system, user identity authentication, data integrity protection, data confidentiality, and user behavior non-repudiation are realized. The present invention uses the two-factor authentication technology of username and password + fingerprint biological characteristics, and adopts a dedicated security chip to protect sensitive information, avoiding information leakage, and applying the SM2 algorithm to encrypt data, ensuring the confidentiality of data during transmission and storage. For the relevant security requirements such as security management, identity authentication, data integrity, and data confidentiality, a unified security architecture is adopted to build the identity authentication and password security basic services, providing comprehensive security services such as unified user management, authorization and authentication, digital certificate, password service, and data trusted security access control for the information network and system, and further forming corresponding security management and integration standards, laying a security foundation for future informatization construction.
[0059] It should be noted that the method of the embodiments of the present disclosure can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In this case of a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiments of the present disclosure, and these multiple devices will interact with each other to complete the described method.
[0060] It should be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the above embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0061] Embodiment 2
[0062] Referring to Figure 3 , Embodiment 2 of the present invention also provides a multi-factor enhanced authentication device applicable to a trusted fingerprint mouse, including:
[0063] A preliminary identity authentication module 001, configured to perform preliminary identity authentication on a target user by the trusted fingerprint mouse through the user name and password when the target user logs in to a set system through the user name and password;
[0064] A digital certificate retrieval module 002, configured to, after the preliminary identity authentication is passed, the trusted fingerprint mouse obtain the biological information of the target user; according to the biological information, the trusted fingerprint mouse retrieve the digital certificate corresponding to the biological information, and sign the digital certificate to obtain a signature value;
[0065] An enhanced identity authentication module 003, configured to the trusted fingerprint mouse determine the validity of the signature value, and perform enhanced identity authentication on the target user according to the validity of the signature value; after the target user passes the enhanced identity authentication, the trusted fingerprint mouse determine the application permission range of the target user according to the digital certificate, and enable the application permissions within the application permission range for the target user.
[0066] In this embodiment, in the digital certificate retrieval module 002, the digital certificate includes the biological information and identity information of the target user; the biological information is biological fingerprint information; the identity information includes: name, email, institution name, department name, and usage permission information.
[0067] In this embodiment, in the digital certificate retrieval module 002, during the process that the trusted fingerprint mouse signs the digital certificate to obtain a signature value, the trusted fingerprint mouse performs encryption, decryption, and signature processing on the digital certificate through the SM2 algorithm.
[0068] In this embodiment, in the enhanced identity authentication module 003, during the process of the trusted fingerprint mouse judging the validity of the signature value, the trusted fingerprint mouse sends the signature value to the unified identity authentication system, and the unified identity authentication system judges the validity of the signature value.
[0069] In this embodiment, in the preliminary identity authentication module 001, the digital certificate retrieval module 002, and the enhanced identity authentication module 003, when the preliminary identity authentication fails, when the corresponding digital certificate cannot be retrieved for the obtained biometric information, or when the signature value is invalid, it is considered that the identity authentication of the target user fails.
[0070] It should be noted that the information interaction, execution process, etc. between the above system modules, since they are based on the same concept as the method embodiment in Embodiment 1 of this application, the technical effects brought by them are the same as those of the method embodiment of this application. For the specific content, reference can be made to the description in the method embodiment shown above in this application, and details will not be repeated here.
[0071] Embodiment 3
[0072] Embodiment 3 of the present invention provides a non-transitory computer-readable storage medium, in which there is stored program code for a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, and the program code includes instructions for executing a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse according to Embodiment 1 or any possible implementation thereof.
[0073] The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center integrating one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive (SSD)).
[0074] Embodiment 4
[0075] Embodiment 4 of the present invention provides an electronic device, including: a memory and a processor;
[0076] The processor and the memory communicate with each other through a bus; the memory stores program instructions executable by the processor, and the processor can execute a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse according to Embodiment 1 or any possible implementation thereof by invoking the program instructions.
[0077] Specifically, the processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor that realizes its functions by reading software code stored in a memory. The memory can be integrated in the processor or exist independently outside the processor.
[0078] In the above embodiments, they can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable systems. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means.
[0079] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general computing system. They can be concentrated on a single computing system or distributed on a network composed of multiple computing systems. Optionally, they can be implemented by program code executable by the computing system. Thus, they can be stored in a storage system and executed by the computing system. And in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules respectively, or multiple modules or steps among them can be made into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.
[0080] Although the present invention has been described in detail above with general descriptions and specific embodiments, based on the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.
Claims
1. A multi-factor enhanced authentication method applicable to a trusted fingerprint mouse, characterized in that, Including: When a target user logs in to a set system through a username and a password, a trusted fingerprint mouse performs a preliminary identity authentication on the target user through the username and the password; After the preliminary identity authentication is passed, the trusted fingerprint mouse obtains the biological information of the target user; according to the biological information, the trusted fingerprint mouse retrieves a digital certificate corresponding to the biological information, signs the digital certificate, and obtains a signature value; The trusted fingerprint mouse determines the validity of the signature value, and performs enhanced identity authentication on the target user according to the validity of the signature value; After the target user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the digital certificate, and enables the application permissions within the application permission range for the target user; The trusted fingerprint mouse includes: a mouse chip, a fingerprint sensor, a national cryptography security chip, and a 2.4G transmitter; the mouse chip is used to perform preliminary identity authentication on the target user; the fingerprint sensor is used to obtain the target fingerprint information of the target user after the preliminary identity authentication of the target user is passed, and upload the target fingerprint information to the national cryptography security chip; the national cryptography security chip is used to perform enhanced identity authentication on the target user according to the target biological fingerprint information; the 2.4G transmitter is used to send the transmission data generated by the mouse chip and the secure transmission data generated by the national cryptography security chip to the PC side after the target user passes the enhanced identity authentication; the transmission data and the secure transmission data are used to drive the trusted fingerprint mouse driver program of the PC side; The 2.4G transmitter communicates with a 2.4G receiver installed on the PC side through a 2.4G communication channel. The 2.4G transmitter transmits the transmission data and the secure transmission data to the 2.4G receiver through the 2.4G communication channel, and through the 2.4G receiver, transmits the transmission data and the secure transmission data to the trusted fingerprint mouse driver program of the PC side; the 2.4G receiver is defined as a USB composite device. In addition to implementing the reporting function of the trusted fingerprint mouse transmission data, another USB custom device is virtualized for sharing the 2.4G channel to realize data interaction between the trusted fingerprint mouse driver program and the national cryptography secondary fingerprint module in the trusted fingerprint mouse; the 2.4G receiver communicates with the windows hello driver program upward and communicates with the 2.4G transmitter through the 2.4G channel downward; The 2.4G transmitter communicates with the 2.4G receiver through the 2.4G channel upward, receives the application data of the PC host, and realizes data interaction with the national cryptography secondary fingerprint module through the UART serial port downward; The national cryptographic level 2 fingerprint module consists of a national cryptographic level 2 security chip and a high-performance and low-power fingerprint sensor. It adopts the MOC working mode, and the acquisition, processing, storage, comparison, and management of all fingerprint data are realized within the national cryptographic level 2 security chip. The national cryptographic level 2 fingerprint module interacts with the 2.4G transmitter through the UART serial port to achieve two-way data exchange; during the data exchange process, the data protocol is divided into request data and response data. Among them, the request data is the security and fingerprint application requests sent from the PC to the national cryptographic level 2 fingerprint module, and the response data is the security and fingerprint service results returned by the fingerprint module to the upper PC.
2. The multi-factor enhanced authentication method for a trusted fingerprint mouse according to claim 1, wherein, The digital certificate includes the biometric information and identity information of the target user; the biometric information is biometric fingerprint information; the identity information includes: name, email, institution name, department name, and usage permission information.
3. The multi-factor enhanced authentication method for a trustworthy fingerprint mouse according to claim 2, characterized in that During the process that the trusted fingerprint mouse signs the digital certificate to obtain the signature value, the trusted fingerprint mouse encrypts, decrypts, and signs the digital certificate through the SM2 algorithm.
4. The multi-factor enhanced authentication method for a trusted fingerprint mouse according to claim 3, wherein During the process that the trusted fingerprint mouse judges the validity of the signature value, the trusted fingerprint mouse sends the signature value to the unified identity authentication system, and the unified identity authentication system judges the validity of the signature value.
5. The multi-factor enhanced authentication method for a trusted fingerprint mouse according to claim 4, wherein When the preliminary identity authentication fails, when the corresponding digital certificate cannot be retrieved from the obtained biometric information, or when the signature value is invalid, it is considered that the identity authentication of the target user fails.
6. A multi-factor enhanced authentication device applicable to a trusted fingerprint mouse, which adopts a multi-factor enhanced authentication method applicable to a trusted fingerprint mouse according to any one of claims 1-5, characterized in that, Including: A preliminary identity authentication module, which is used for when the target user logs in to the set system through the username and password, the trusted fingerprint mouse conducts preliminary identity authentication on the target user through the username and the password; A digital certificate retrieval module, which is used for when the preliminary identity authentication is passed, the trusted fingerprint mouse obtains the biometric information of the target user; according to the biometric information, the trusted fingerprint mouse retrieves the digital certificate corresponding to the biometric information, and signs the digital certificate to obtain the signature value; An enhanced identity authentication module, which is used for the trusted fingerprint mouse to judge the validity of the signature value, and conduct enhanced identity authentication on the target user according to the validity of the signature value; After the target user passes the enhanced identity authentication, the trusted fingerprint mouse determines the application permission range of the target user according to the digital certificate, and enables the application permissions within the application permission range for the target user.
7. The multi-factor enhanced authentication device for a trusted fingerprint mouse according to claim 6, characterized in that In the digital certificate retrieval module, the digital certificate includes the biometric information and identity information of the target user; the biometric information is biometric fingerprint information; the identity information includes: name, email, institution name, department name, and usage permission information.
8. The multi-factor enhanced authentication device applicable to a trusted fingerprint mouse according to claim 7, wherein, In the digital certificate retrieval module, during the process that the trusted fingerprint mouse signs the digital certificate to obtain the signature value, the trusted fingerprint mouse encrypts, decrypts, and signs the digital certificate through the SM2 algorithm.
9. The multi-factor enhanced authentication device applicable to a trusted fingerprint mouse according to claim 8, wherein, In the enhanced identity authentication module, during the process of the trusted fingerprint mouse judging the validity of the signature value, the trusted fingerprint mouse sends the signature value to the unified identity authentication system, and the unified identity authentication system judges the validity of the signature value.
10. The multi-factor enhanced authentication device for a trusted fingerprint mouse according to claim 9, characterized in that, In the preliminary identity authentication module, the digital certificate retrieval module, and the enhanced identity authentication module, when the preliminary identity authentication fails, when the corresponding digital certificate cannot be retrieved from the obtained biometric information, or when the signature value is invalid, it is considered that the identity authentication of the target user fails.
Citation Information
Patent Citations
User identity authentication method and device, electronic equipment and storage medium
CN116541817A