A multi-factor authentication method, device, apparatus and storage medium
By encrypting the application code and establishing a binding relationship in the multi-factor authentication system, and using encrypted transmission keys, the problem of key leakage is solved, the authentication accuracy and security are improved, and the user experience is enhanced.
Patent Information
- Application Number
- CN202411698453.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2044-11-25
AI Technical Summary
In existing multi-factor authentication, keys are transmitted in plain text, leading to leakage, which affects authentication accuracy and information security.
By encrypting the application code plain text into application code cipher text in the terminal device, establishing a binding relationship between the multi-factor authentication platform and the identity authentication platform, and using encrypted transmission keys for authentication, the security of the key during the communication process is ensured.
It improves the accuracy and information security of multi-factor authentication, avoids key leakage, and enhances user experience and convenience.
Smart Images

Figure CN119520127B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of computer, and particularly relate to a multi-factor authentication method and device, equipment and storage medium. BACKGROUND
[0002] Multi-Factor Authentication (MFA) is an identity verification mechanism, which is used to verify the identity of a user and log in when logging in or accessing resources. The computer system requires the user to provide two or more different combinations of identity verification to verify the identity of the user and log in. MFA provides a high-security verification method, because even if one identity verification is compromised, an unauthorized user will not be able to access the computer system if they cannot meet the requirements of the second identity verification.
[0003] Under the related technology, after the user end applies for MFA authentication to the application system, the application system returns a key to the user end. When the user logs in to the application system, the user needs to generate a dynamic password based on the key, and log in to the application system based on the dynamic password.
[0004] However, in the above verification process, the key is usually transmitted in plaintext between the user end and the application system, which may cause the key to be leaked during communication, thereby affecting the accuracy of multi-factor authentication and the security of information. SUMMARY
[0005] Embodiments of the present application provide a multi-factor authentication method, device, equipment and storage medium, which are used to improve the accuracy of multi-factor authentication and the security of information.
[0006] In one aspect, the present application provides a multi-factor authentication method, applied to an application system, comprising:
[0007] Receiving a multi-factor authentication binding application sent by a terminal device that has accessed an identity authentication platform;
[0008] Returning an application code plaintext and a first user identifier of an operation user in the application system to the terminal device, so that the terminal device encrypts the application code plaintext into an application code ciphertext, and sends the application code ciphertext and the first user identifier to the multi-factor authentication platform;
[0009] Receiving an application code plaintext, a first user identifier and a second user identifier of an operation user in the multi-factor authentication platform obtained by decrypting the application code ciphertext by the identity authentication platform and sent by the multi-factor authentication platform;
[0010] When the application code plaintext is verified, a binding relationship between the first user identifier and the second user identifier is established;
[0011] Based on the binding relationship, the multi-factor authentication platform and the identity authentication platform call an encryption transmission key, and use the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result.
[0012] In one aspect, the embodiments of the present application provide a multi-factor authentication method, applied to a multi-factor authentication platform, and including the following steps.
[0013] Receiving an application code ciphertext and a first user identifier of an operation user in an application system, which are sent by a terminal device that has accessed an identity authentication platform, wherein the application code ciphertext is obtained by encrypting an application code plaintext by the terminal device, and the application code plaintext and the first user identifier are returned by the application system when the terminal device sends a multi-factor authentication binding application to the application system;
[0014] Decrypting the application code ciphertext by the identity authentication platform to obtain the application code plaintext;
[0015] Sending the application code plaintext, the first user identifier and a second user identifier of the operation user in the multi-factor authentication platform to the application system, so that the application system establishes a binding relationship between the first user identifier and the second user identifier when the application code plaintext is verified to be correct, and based on the binding relationship, the multi-factor authentication platform and the identity authentication platform call an encryption transmission key, and use the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result.
[0016] In one aspect, the embodiments of the present application provide a multi-factor authentication method, applied to a terminal device that has accessed an identity authentication platform, and including the following steps.
[0017] Sending a multi-factor authentication binding application to an application system;
[0018] Receiving an application code plaintext and a first user identifier of an operation user in the application system, which are returned by the application system;
[0019] Encrypting the application code plaintext to obtain an application code ciphertext;
[0020] send the application code ciphertext and the first user identifier to the multi-factor authentication platform, so that the multi-factor authentication platform decrypts the application code ciphertext through the identity authentication platform to obtain an application code plaintext; send the application code plaintext, the first user identifier, and a second user identifier of the operation user on the multi-factor authentication platform to the application system; when the application code plaintext is verified by the application system, establish a binding relationship between the first user identifier and the second user identifier; and based on the binding relationship, call an encryption transmission key of the multi-factor authentication platform and the identity authentication platform, and use the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result.
[0021] In one aspect, the embodiments of the present application provide a multi-factor authentication device, applied to an application system, comprising:
[0022] A first receiving module is configured to receive a multi-factor authentication binding application sent by a terminal device that has accessed an identity authentication platform;
[0023] A first sending module is configured to return an application code plaintext and a first user identifier of an operation user on the application system to the terminal device, so that the terminal device encrypts the application code plaintext into an application code ciphertext, and sends the application code ciphertext and the first user identifier to the multi-factor authentication platform;
[0024] The first receiving module is further configured to receive an application code plaintext, a first user identifier, and a second user identifier of the operation user on the multi-factor authentication platform, which are obtained by decrypting the application code ciphertext through the identity authentication platform and sent by the multi-factor authentication platform;
[0025] A processing module is configured to, when the application code plaintext is verified, establish a binding relationship between the first user identifier and the second user identifier;
[0026] The processing module is further configured to, based on the binding relationship, call an encryption transmission key of the multi-factor authentication platform and the identity authentication platform, and use the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result.
[0027] In one aspect, the embodiments of the present application provide a multi-factor authentication device, applied to a multi-factor authentication platform, comprising:
[0028] A second receiving module is configured to receive an application code ciphertext and a first user identifier of an operation user on an application system, which are sent by a terminal device that has accessed an identity authentication platform, the application code ciphertext being obtained by encrypting an application code plaintext by the terminal device, and the application code plaintext and the first user identifier being returned by the application system when the terminal device sends a multi-factor authentication binding application to the application system;
[0029] authentication module configured to decrypt the application code ciphertext by the identity authentication platform to obtain the application code plaintext;
[0030] a second sending module configured to send the application code plaintext, the first user identifier and the second user identifier of the operation user to the application system, so that the application system establishes a binding relationship between the first user identifier and the second user identifier when the application code plaintext is verified to be correct, and calls an encryption transmission key of the multi-factor authentication platform and the identity authentication platform based on the binding relationship, and performs multi-factor authentication on the login request of the terminal device by using the key to obtain an authentication result.
[0031] In one aspect, the embodiment of the present application provides a multi-factor authentication device applied to a terminal device having accessed an identity authentication platform, and the device comprises:
[0032] a third sending module configured to send a multi-factor authentication binding application to an application system;
[0033] a third receiving module configured to receive an application code plaintext and a first user identifier of an operation user returned by the application system;
[0034] an encryption module configured to encrypt the application code plaintext to obtain an application code ciphertext;
[0035] The third sending module is further configured to send the application code ciphertext and the first user identifier to the multi-factor authentication platform, so that the multi-factor authentication platform decrypts the application code ciphertext by the identity authentication platform to obtain the application code plaintext, and sends the application code plaintext, the first user identifier and a second user identifier of the operation user to the application system; the application system establishes a binding relationship between the first user identifier and the second user identifier when the application code plaintext is verified to be correct, and calls an encryption transmission key of the multi-factor authentication platform and the identity authentication platform based on the binding relationship, and performs multi-factor authentication on the login request of the terminal device by using the key to obtain an authentication result.
[0036] In one aspect, the embodiment of the present application provides a computer device comprising a memory, a processor and a computer program stored in the memory and capable of running on the processor, and the processor implements the steps of the multi-factor authentication method when executing the program.
[0037] In one aspect, the embodiment of the present application provides a computer readable storage medium, which stores a computer program executable by a computer device, and when the program runs on the computer device, the computer device executes the steps of the multi-factor authentication method.
[0038] In one aspect, the embodiment of the present application provides a computer program product, which comprises a computer program stored on a computer readable storage medium, and the computer program comprises program instructions, and when the program instructions are executed by a computer device, the computer device executes the steps of the multi-factor authentication method.
[0039] In the embodiment of the present application, the terminal device pre-completes device access on the identity authentication platform, and when the terminal device receives the application code plaintext sent by the application system and the first user identifier of the operation user on the application system, the terminal device encrypts the application code plaintext into application code ciphertext, and sends the application code ciphertext and the first user identifier to the multi-factor authentication platform to apply for multi-factor authentication binding. After the multi-factor authentication platform decrypts and verifies the application code ciphertext with the help of the identity authentication platform, the first user identifier and the second user identifier of the operation user on the multi-factor authentication platform are allowed to be bound, a trusted connection relationship between the multi-factor authentication platform, the application system and the identity authentication platform is established, and therefore the application system can call the multi-factor authentication platform and the identity authentication platform to encrypt the transmission key based on the binding relationship, and the key is used for multi-factor authentication of the login request of the terminal device to obtain an authentication result, so that the key is prevented from being leaked in the communication process, and the accuracy of the multi-factor authentication and the security of the information are greatly improved. BRIEF DESCRIPTION OF DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0041] Figure 1 A structural schematic diagram of a system architecture provided by the embodiment of the present application;
[0042] Figure 2 A flowchart of a multi-factor authentication method provided by the embodiment of the present application Figure One ;
[0043] Figure 3 A flowchart of a multi-factor authentication method provided by the embodiment of the present application Figure Two ;
[0044] Figure 4 A flowchart of a multi-factor authentication method provided by the embodiment of the present applicationFigure Three ;
[0045] Figure 5 A structure diagram of a multi-factor authentication device provided for an embodiment of the present application Figure One ;
[0046] Figure 6 A structure diagram of a multi-factor authentication device provided for an embodiment of the present application Figure Two ;
[0047] Figure 7 A structure diagram of a multi-factor authentication device provided for an embodiment of the present application Figure Three ;
[0048] Figure 8 A structure diagram of a computer device provided for an embodiment of the present application. DETAILED DESCRIPTION
[0049] In order to make the objectives, technical solutions and beneficial effects of the present application clearer, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0050] Reference Figure 1 , which is a system architecture diagram applicable to an embodiment of the present application, the system architecture at least includes a terminal device 101, an identity authentication platform 102, a multi-factor authentication platform 103 and an application system 104.
[0051] The number of terminal devices 101 can be one or more, and the number of multi-factor authentication platforms 103 and application systems 104 can also be one or more. The number of terminal devices 101, multi-factor authentication platforms 103 and application systems 104 is not specifically limited by the present application.
[0052] The terminal device 101 is pre-installed with a business application and a multi-factor authentication application. The business application and the multi-factor authentication application can be two independent applications. At this time, the business application and the multi-factor authentication application can be installed on different terminal devices, or can be installed on the same terminal device. The multi-factor authentication application can also be embedded in the business application. The present application does not make specific limitations in this regard. The terminal device 101 can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart voice interaction device, a smart vehicle-mounted device, etc., but is not limited thereto.
[0053] The multi-factor authentication platform 103, also known as the MFA scenario platform, is the background server of the multi-factor authentication application. The factor authentication platform 103 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0054] Application system 104 is the backend server for business applications. Application system 104 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0055] Any two devices among the terminal device 101, the identity authentication platform 102, the multi-factor authentication platform 103, and the application system 104 can be directly or indirectly connected via wired or wireless communication; this application does not impose any restrictions on this.
[0056] based on Figure 1 The system architecture diagram shown in the embodiment of the present application provides a process of a multi-factor authentication method, such as Figure 2 As shown, the process of this method is interactively executed by the terminal device, the identity authentication platform, the multi-factor authentication platform, and the application system, and includes the following steps:
[0057] Step 201: The terminal device sends a multi-factor authentication binding application to the application system.
[0058] Specifically, the terminal device is pre-installed with a business application and a multi-factor authentication application. The operating user can operate in the business application to select an application system from multiple application systems for login.
[0059] For example, if the business application is a payment application, the payment application provides multiple payment channels, each corresponding to an application system. The operating user can select a payment channel in the payment application to select an application system from multiple application systems for login.
[0060] Before the multi-factor authentication is performed, the terminal device pre-completes device access on the identity authentication platform, and meanwhile, the identity authentication platform issues a working key (i.e., working key initialization). The application system needs to access the multi-factor authentication platform, and provide information of the application system and a communication key for obtaining the multi-factor authentication platform API.
[0061] In some embodiments, before the terminal device sends the multi-factor authentication binding application to the application system, the terminal device sends an authentication request carrying login information to the application system, where the login information includes a username and a password. The application system authenticates the login information, and returns an authentication pass message to the terminal device when the authentication is passed.
[0062] Step 202, the terminal device receives the application code plaintext and the first user identifier of the operating user on the application system returned by the application system.
[0063] Specifically, the application system generates the application code plaintext, and returns the application code plaintext, the application system identifier and the first user identifier to the terminal device.
[0064] Step 203, the terminal device encrypts the application code plaintext to obtain the application code ciphertext.
[0065] Specifically, the user inputs the application code plaintext, the application system identifier and the first user identifier into the multi-factor authentication application. The application code plaintext, the application system identifier and the first user identifier can be input by scanning a code and the like. The multi-factor authentication application in the terminal device encrypts the application code plaintext by using the working key of the terminal device to obtain the application code ciphertext. The working key of the terminal device is issued by the identity authentication platform when the terminal device accesses the identity authentication platform. The working key saved by the terminal device is a symmetric key with the working key saved by the identity authentication platform.
[0066] Step 204, the terminal device sends the application code ciphertext and the first user identifier to the multi-factor authentication platform.
[0067] Specifically, the terminal device sends the application code ciphertext, the application system identifier and the first user identifier to the multi-factor authentication platform.
[0068] Step 205, the multi-factor authentication platform decrypts the application code ciphertext by the identity authentication platform to obtain the application code plaintext.
[0069] Specifically, the multi-factor authentication platform sends the device identifier of the terminal device and the application code ciphertext to the identity authentication platform. The identity authentication platform obtains the initialized working key based on the device identifier of the terminal device. The application code ciphertext is decrypted by using the initialized working key to obtain the application code plaintext, and the application code plaintext is returned to the multi-factor authentication platform.
[0070] In step 206, the multi-factor authentication platform sends the plaintext application code, the first user identifier and the second user identifier of the operation user on the multi-factor authentication platform to the application system.
[0071] Specifically, the multi-factor authentication platform and the application system belong to a service-to-service interface, and the interface performs data transmission and verification through a pre-agreed encryption key and an HTTPS mode to ensure the security of data transmission.
[0072] In step 207, when the application system verifies the plaintext application code, a binding relationship between the first user identifier and the second user identifier is established.
[0073] In step 208, the application system calls the multi-factor authentication platform and the identity authentication platform to encrypt the transmission key based on the binding relationship, and performs multi-factor authentication on the login request of the terminal device using the key to obtain an authentication result.
[0074] In the embodiment of the application, the terminal device completes device access in the identity authentication platform in advance. When the terminal device receives the plaintext application code and the first user identifier of the operation user sent by the application system, the terminal device encrypts the plaintext application code into ciphertext, and sends the ciphertext and the first user identifier to the multi-factor authentication platform to apply for multi-factor authentication binding. After the multi-factor authentication platform decrypts and verifies the ciphertext with the help of the identity authentication platform, the first user identifier and the second user identifier of the operation user on the multi-factor authentication platform are allowed to be bound, a trusted connection relationship between the multi-factor authentication platform, the application system and the identity authentication platform is established, and therefore the application system can call the multi-factor authentication platform and the identity authentication platform to encrypt the transmission key based on the binding relationship, and perform multi-factor authentication on the login request of the terminal device using the key to obtain an authentication result, thereby avoiding the leakage of the key in the communication process, and further greatly improving the accuracy and security of multi-factor authentication.
[0075] In some embodiments, the related art adopts a Time-Based One-Time Password (TOTP) for multi-factor authentication. There are mainly two kinds of authentication methods. The first kind is that after the user applies for MFA authentication, the application system sends the key to the user, the user inputs the key into a local application supporting TOTP, and the user generates a dynamic password using the local application when logging in to the system. This is the MFA authentication method of most websites at present. The second kind is that the application system fills the key into a dynamic password device, and provides the device to the user, and binds the device serial number with the user account. The user needs to use the dynamic password device to obtain a dynamic password when logging in. This method is mainly used in personal online banking and other applications with high security requirements.
[0076] However, in the first scheme, the TOTP is transmitted in plaintext form such as a two-dimensional code or Base32, which may lead to key leakage if not properly handled during communication or by the user. In the second scheme, each device can only be used for one account of one application system, and if there are many application systems or accounts, the user needs to keep multiple dynamic password devices and record the correspondence between the dynamic password device and the application system and the account, which brings many inconveniences to the user.
[0077] In view of this, after establishing the binding relationship between the first user identifier and the second user identifier, the following implementation is adopted: based on the binding relationship, the multi-factor authentication platform and the identity authentication platform are called to encrypt the transmission key, and the key is used for multi-factor authentication of the login request of the terminal device, as shown in Figure 3 As shown in the following steps:
[0078] Step 301, the application system calls the multi-factor authentication platform and the identity authentication platform to issue an encryption key to the terminal device based on the binding relationship.
[0079] Specifically, the encryption key can be a TOTP ciphertext or other types of encrypted keys.
[0080] In some embodiments, the process of the application system issuing the encryption key includes the following steps 3011 to 3016.
[0081] Step 3011, the terminal device sends a key application carrying the first user identifier to the application system.
[0082] Step 3012, the application system obtains the second user identifier bound to the first user identifier from the binding relationship.
[0083] Step 3013, the application system sends the second user identifier and the generated key plaintext to the multi-factor authentication platform.
[0084] Specifically, the application system sends the key plaintext to the multi-factor authentication platform through the interface provided by the multi-factor authentication platform.
[0085] Step 3014, when the multi-factor authentication platform verifies the second user identifier, the multi-factor authentication platform sends the key plaintext to the identity authentication platform.
[0086] Step 3015, the identity authentication platform encrypts the key plaintext to obtain the encryption key.
[0087] Specifically, the identity authentication platform not only obtains the key plaintext, but also obtains the second user identifier. When the second user identifier is verified, the key plaintext is encrypted using the working key to obtain the encryption key.
[0088] Step 3016, the identity authentication platform sends the encrypted key to the terminal device.
[0089] Step 302, the terminal device decrypts the encrypted key to obtain the key plaintext.
[0090] Specifically, the terminal device decrypts the encrypted key using the working key issued by the identity authentication platform when accessing the identity authentication platform to obtain the key plaintext, wherein the working key saved by the terminal device is a symmetric key as the working key saved by the identity authentication platform.
[0091] The terminal device saves the key plaintext in a trusted execution environment or a secure element. In a specific implementation, the specific storage environment of the key plaintext can be determined according to the device type of the terminal device. When the device type of the terminal device is to support a trusted execution environment, the key plaintext is saved in the trusted execution environment. When the device type of the terminal device is to support a secure element, the key plaintext is saved in the secure element. When the device type of the terminal device is to support other secure environments, the key plaintext is saved in the other secure environments, thereby improving the security of the key.
[0092] Step 303, the terminal device sends a login request carrying login information to an application system.
[0093] Step 304, when the login information is authenticated by the application system, the application system returns a multi-factor authentication instruction.
[0094] Step 305, the terminal device generates a dynamic password based on the key plaintext.
[0095] Specifically, the terminal device obtains the key plaintext from the trusted execution environment or the secure element and generates a dynamic password based on the key plaintext.
[0096] Step 306, the application system sends the dynamic password to the terminal device.
[0097] Step 307, the application system authenticates the dynamic password to obtain an authentication result.
[0098] Specifically, the application system parses the key plaintext (such as TOTP) from the dynamic password. When the decrypted key plaintext is consistent with the key plaintext issued to the terminal device, the authentication result is passed, otherwise the authentication result is not passed.
[0099] When the authentication result is passed, the login request is completed and a login success message is returned. When the authentication result is not passed, the login request is terminated and a login failure message is returned.
[0100] In the embodiments of the present application, the key for multi-factor authentication is transmitted through multi-factor authentication platform and identity authentication platform encryption, and the key is stored in a secure environment such as TEE, effectively preventing key leakage, thereby improving the accuracy and security of multi-factor authentication. Secondly, a terminal device can save the key plaintext corresponding to the account of each application system. Compared with the method of using dynamic password device to encapsulate the key, the use convenience is improved, which is more helpful for wide promotion.
[0101] In some embodiments, the related technology performs multi-factor authentication based on the way of short message verification code. First, the user's mobile phone number needs to be bound to the user's account. When the user accesses the application system, the application system generates a one-time verification code and sends it to the user's mobile phone through short message as a dynamic password for login.
[0102] However, the sending of the short message verification code has different degrees of delay, and the user needs to wait for a period of time to receive the verification code. In the case of congestion of the short message network, the user may receive the verification code when the verification code has already expired, resulting in poor user experience. In addition, if a fake application software is installed on the user's mobile phone, the user's short message verification code may be intercepted by malicious software, and the security is poor.
[0103] Therefore, after establishing the binding relationship between the first user identifier and the second user identifier, the following implementation is adopted: the multi-factor authentication platform and the identity authentication platform are called to transmit the key based on the binding relationship, and the key is used for multi-factor authentication of the login request of the terminal device, as shown in Figure 4 The method comprises the following steps:
[0104] Step 401, the terminal device sends a login request carrying login information to the application system.
[0105] Specifically, the login information includes a username and a password.
[0106] Step 402, when the login information is authenticated by the application system, the second user identifier is obtained from the binding relationship based on the first user identifier associated with the login information.
[0107] Specifically, when the login information is authenticated by the application system, an online multi-factor authentication process is initiated.
[0108] Step 403, the application system sends the second user identifier and the application system identifier to the multi-factor authentication platform.
[0109] Step 404, when the second user identifier is verified by the multi-factor authentication platform, a serial number and an online key are generated.
[0110] The serial number is used to represent the uniqueness of the online key to avoid repeated authentication of the online key.
[0111] Step 405, the multi-factor authentication platform sends an authentication application carrying the application system identifier, the serial number and the online key to the identity authentication platform.
[0112] Step 406, the identity authentication platform sends the authentication application to the terminal device.
[0113] Step 407, the terminal device signs the online key to obtain a signature result.
[0114] In some embodiments, the terminal device signs the online key to obtain a signature result in response to a confirmation operation in the multi-factor authentication application for the authentication application.
[0115] Specifically, the confirmation manner is implemented by the multi-factor authentication application, such as user click, fingerprint recognition, face recognition, PIN code, etc.
[0116] After the user confirms, the online key is signed by the private key of the terminal device to obtain a signature result. The private key of the terminal device is a working key issued by the identity authentication platform when the terminal device accesses the identity authentication platform. The private key saved by the terminal device and the public key saved by the identity authentication platform are asymmetric keys.
[0117] Step 408, the terminal device sends the signature result to the multi-factor authentication platform.
[0118] Step 409, the multi-factor authentication platform sends the signature result to the identity authentication platform.
[0119] Specifically, the terminal device sends the signature result to the multi-factor authentication platform, and also sends the application system identifier and the serial number. The multi-factor authentication platform checks the received serial number and application system identifier, and when the check passes, sends a signature verification request to the identity authentication platform, wherein the signature verification request carries the identifier of the terminal device and the signature result.
[0120] Step 410, the identity authentication platform checks the signature result to obtain an authentication result.
[0121] Step 411, the identity authentication platform returns the authentication result.
[0122] Specifically, the identity authentication platform checks the signature result using the public key. After the check passes, an authentication result of authentication passing is returned. After the check fails, an authentication result of authentication failing is returned.
[0123] Step 412, the multi-factor authentication platform sends the authentication result to the application system.
[0124] Specifically, the multi-factor authentication platform sends not only the authentication result but also the second user ID and serial number. If the authentication result is a pass, the login request is completed and a login success message is returned. If the authentication result is a fail, the login request is terminated and a login failure message is returned.
[0125] In an embodiment of the present application, when a user logs in to an application system, the application system initiates an online multi-factor authentication process to a designated operating user through a multi-factor authentication platform. The multi-factor authentication platform generates an online key and pushes it to the terminal device bound to the multi-factor authentication application through the identity authentication platform. If the operating user confirms logging into the application system, the multi-factor authentication application confirms the online key using the private key in the terminal device and sends it to the multi-factor authentication platform. After the identity authentication platform verifies the signature, the authentication result is returned to the application system. The issuance of the online key through the multi-factor authentication platform and the identity authentication platform improves the security of the online key. Secondly, compared to the SMS verification code method, the delay in issuing the verification code is reduced, thereby improving the user experience. In addition, after the online key is issued to the terminal device, the operating user needs to confirm (i.e., verify again) in the multi-factor authentication application before the subsequent signing and verification process is executed. In this way, even if the online key is intercepted by malware, the security of the multi-factor authentication can be guaranteed.
[0126] Based on the same technical concept, the embodiment of the present application provides a structural diagram of a multi-factor authentication device, which is applied to an application system, such as Figure 5 As shown, the multi-factor authentication device 500 includes:
[0127] The first receiving module 501 is configured to receive a multi-factor authentication binding application sent by a terminal device that has accessed the identity authentication platform;
[0128] A first sending module 502 is configured to return a plaintext application code and a first user identifier of the operating user in the application system to the terminal device, so that the terminal device encrypts the plaintext application code into a ciphertext application code and sends the ciphertext application code and the first user identifier to the multi-factor authentication platform;
[0129] The first receiving module 501 is further configured to receive the plaintext application code, the first user identifier, and the second user identifier of the operating user on the multi-factor authentication platform, which are obtained by decrypting the ciphertext application code on the identity authentication platform.
[0130] Processing module 503, configured to establish a binding relationship between the first user identifier and the second user identifier when the plain text verification of the application code passes;
[0131] The processing module 503 is further configured to call the multi-factor authentication platform and the identity authentication platform to encrypt a transmission key based on the binding relationship, and to perform multi-factor authentication on a login request of the terminal device by using the key to obtain an authentication result.
[0132] Optionally, the first receiving module 501 is further configured to receive an authentication request carrying login information sent by a terminal device that has accessed an identity authentication platform before receiving a multi-factor authentication binding application sent by the terminal device.
[0133] The processing module 503 is further configured to authenticate the login information, and return an authentication pass message to the terminal device when the authentication is passed.
[0134] Optionally, the first sending module 502 is specifically configured to:
[0135] return an application code plaintext, an application system identifier and the first user identifier to the terminal device, so that the terminal device encrypts the application code plaintext to obtain an application code ciphertext, and sends the application code ciphertext, the application system identifier and the first user identifier to the multi-factor authentication platform.
[0136] Optionally, the processing module 503 is specifically configured to:
[0137] call the multi-factor authentication platform and the identity authentication platform to issue an encryption key to the terminal device based on the binding relationship;
[0138] receive a login request carrying login information sent by the terminal device;
[0139] when the authentication of the login information is passed, return a multi-factor authentication instruction, so that the terminal device generates a dynamic password based on a key plaintext, the key plaintext being obtained by decrypting the encryption key by the terminal device;
[0140] receive the dynamic password sent by the terminal device, and authenticate the dynamic password to obtain the authentication result.
[0141] Optionally, the processing module 503 is specifically configured to:
[0142] receive a key application sent by the terminal device carrying the first user identifier;
[0143] obtain the second user identifier bound with the first user identifier from the binding relationship;
[0144] send the second user identifier and the generated key plaintext to the multi-factor authentication platform, so that the multi-factor authentication platform, when the second user identifier is verified, encrypts the key plaintext through the identity authentication platform to obtain an encrypted key, and sends the encrypted key to the terminal device.
[0145] Optionally, the terminal device stores the key plaintext in a trusted execution environment or a secure element.
[0146] Optionally, the processing module 503 is specifically configured to:
[0147] receive a login request carrying login information sent by the terminal device;
[0148] when the login information is authenticated, obtain the second user identifier from the binding relationship based on the first user identifier associated with the login information;
[0149] send the second user identifier and an application system identifier to the multi-factor authentication platform, so that the multi-factor authentication platform, when the second user identifier is verified, generates a serial number and an online key; and send an authentication application carrying the application system identifier, the serial number and the online key to the terminal device through the identity authentication platform;
[0150] receive an authentication result sent by the multi-factor authentication platform, the authentication result being obtained by the multi-factor authentication platform through the identity authentication platform by verifying a signature result; the signature result being obtained by the terminal device by signing the online key and sending to the multi-factor authentication platform.
[0151] Optionally, the signature result is obtained by the terminal device in response to a confirmation operation in the multi-factor authentication application for the authentication application.
[0152] Based on the same technical concept, the embodiments of the present application provide a structural diagram of a multi-factor authentication device, which is applied to a multi-factor authentication platform, as shown in the figure, the multi-factor authentication device 600 comprises: Figure 6
[0153] a second receiving module 601, configured to receive an application code ciphertext and an operation user's first user identifier in an application system sent by a terminal device that has accessed an identity authentication platform, the application code ciphertext being obtained by the terminal device by encrypting an application code plaintext, and the application code plaintext and the first user identifier being returned by the application system when the terminal device sends a multi-factor authentication binding application to the application system;
[0154] an authentication module 602, configured to decrypt the application code ciphertext through the identity authentication platform to obtain an application code plaintext;
[0155] The second sending module 603 is configured to send the application code plaintext, the first user identifier, and a second user identifier of the operation user on the multi-factor authentication platform to the application system, so that the application system establishes a binding relationship between the first user identifier and the second user identifier when the application code plaintext is verified by the application system, and calls an encryption transmission key of the multi-factor authentication platform and the identity authentication platform based on the binding relationship, and uses the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result.
[0156] Based on the same technical concept, the embodiment of the present application provides a structural diagram of a multi-factor authentication device, which is applied to a terminal device that has accessed an identity authentication platform. Figure 7 As shown in the figure, the multi-factor authentication device 700 comprises:
[0157] The third sending module 701 is configured to send a multi-factor authentication binding application to an application system.
[0158] The third receiving module 702 is configured to receive an application code plaintext and a first user identifier of an operation user on the application system returned by the application system.
[0159] The encryption module 703 is configured to encrypt the application code plaintext to obtain an application code ciphertext.
[0160] The third sending module 701 is further configured to send the application code ciphertext and the first user identifier to the multi-factor authentication platform, so that the multi-factor authentication platform decrypts the application code ciphertext through the identity authentication platform to obtain an application code plaintext; send the application code plaintext, the first user identifier, and a second user identifier of the operation user on the multi-factor authentication platform to the application system; when the application code plaintext is verified by the application system, establish a binding relationship between the first user identifier and the second user identifier; and call an encryption transmission key of the multi-factor authentication platform and the identity authentication platform based on the binding relationship, and use the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result.
[0161] In an embodiment of the present application, the terminal device completes device access in advance on the identity authentication platform. When the terminal device receives the application code plain text sent by the application system and the first user ID of the operating user in the application system, it encrypts the application code plain text into an application code ciphertext, and sends the application code ciphertext and the first user ID to the multi-factor authentication platform to apply for multi-factor authentication binding. After the multi-factor authentication platform decrypts and verifies the application code ciphertext with the help of the identity authentication platform, it allows the first user ID and the operating user's second user ID on the multi-factor authentication platform to be bound, thereby establishing a trusted connection relationship between the multi-factor authentication platform, the application system, and the identity authentication platform. Therefore, the application system can call the multi-factor authentication platform and the identity authentication platform based on the binding relationship to encrypt and transmit the key, and use the key to perform multi-factor authentication on the terminal device's login request to obtain the authentication result, thereby avoiding the key from being leaked during the communication process, thereby greatly improving the accuracy of multi-factor authentication and the security of information.
[0162] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0163] Based on the same technical concept, the embodiment of the present application provides a computer device, which can be Figure 1 Any device shown, such as Figure 8 As shown, it includes at least one processor 801 and a memory 802 connected to the at least one processor. The specific connection medium between the processor 801 and the memory 802 is not limited in the embodiment of the present application. Figure 8 For example, the processor 801 and the memory 802 are connected via a bus. The bus can be divided into an address bus, a data bus, a control bus, and the like.
[0164] In the embodiment of the present application, the memory 802 stores instructions that can be executed by at least one processor 801. The at least one processor 801 can perform the steps of the above-mentioned multi-factor authentication method by executing the instructions stored in the memory 802.
[0165] The processor 801 is the control center of the computer device, can connect various parts of the computer device by using various interfaces and lines, and implement the multi-factor authentication by running or executing instructions stored in the memory 802 and calling data stored in the memory 802. Optionally, the processor 801 can include one or more processing units, and the processor 801 can integrate an application processor and a modem processor, where the application processor mainly processes an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 801. In some embodiments, the processor 801 and the memory 802 can be implemented on the same chip, and in some embodiments, they can also be respectively implemented on independent chips.
[0166] The processor 801 can be a general-purpose processor, for example, a central processing unit (CPU), a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, and can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as hardware processor execution or executed by a combination of hardware and software modules in the processor.
[0167] The memory 802, as a non-volatile computer readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 802 can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. The memory 802 is any other medium capable of carrying or storing desired program codes in the form of instructions or data structures and capable of being accessed by a computer device, but is not limited thereto. The memory 802 in the embodiments of the present application can also be a circuit or any other device capable of realizing a storage function, used to store program instructions and / or data.
[0168] Based on the same inventive concept, the embodiments of the present application provide a computer readable storage medium storing a computer program executable by a computer device, which, when executed on the computer device, causes the computer device to perform the steps of the multi-factor authentication method.
[0169] Based on the same inventive concept, the embodiments of the present application provide a computer program product, which comprises a computer program stored on a computer readable storage medium, the computer program comprising program instructions, which, when executed by a computer device, cause the computer device to perform the steps of the multi-factor authentication method.
[0170] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) containing computer-usable program code.
[0171] The present application is described in reference to the flowchart illustrations and / or block diagrams according to the methods, apparatus (systems) and computer program products of embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams.
[0172] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the functions specified in the flowchart illustrations and / or block diagrams. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams.
[0173] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams.
[0174] While the preferred embodiments of the application have been described, additional variations and modifications can be made to the embodiments by those of skill in the art once they have the benefit of the present disclosure without departing from the spirit and scope of the application. Accordingly, the attached claims are intended to cover all such variations and modifications as falling within the scope of the application.
[0175] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A multi-factor authentication method, characterized in that: Applied to application systems, including: Receive multi-factor authentication binding applications sent by terminal devices that have been connected to the identity authentication platform; Returning the plaintext application code and the first user identifier of the operating user in the application system to the terminal device, so that the terminal device encrypts the plaintext application code into a ciphertext application code, and sends the ciphertext application code and the first user identifier to the multi-factor authentication platform; Receiving, from the multi-factor authentication platform, a plaintext application code obtained by decrypting the ciphertext application code via the identity authentication platform, the first user identifier, and a second user identifier of the operating user on the multi-factor authentication platform; When the plain text verification of the application code passes, a binding relationship between the first user identifier and the second user identifier is established; The multi-factor authentication platform and the identity authentication platform are called to encrypt and transmit a key based on the binding relationship, and the key is used to perform multi-factor authentication on the login request of the terminal device to obtain an authentication result.
2. The method according to claim 1, wherein Before receiving the multi-factor authentication binding application sent by the terminal device connected to the identity authentication platform, the method further includes: Receiving an authentication request carrying login information sent by the terminal device; The login information is authenticated, and when the authentication is successful, an authentication success message is returned to the terminal device.
3. The method according to claim 1, wherein The step of returning the plaintext application code and the first user identifier of the operating user in the application system to the terminal device, so that the terminal device encrypts the plaintext application code into a ciphertext application code, and sends the ciphertext application code and the first user identifier to the multi-factor authentication platform, includes: Return the application code plaintext, the application system identifier, and the first user identifier to the terminal device, so that the terminal device encrypts the application code plaintext to obtain the application code ciphertext, and sends the application code ciphertext, the application system identifier, and the first user identifier to the multi-factor authentication platform.
4. The method according to any one of claims 1 to 3, characterized in that The step of calling the multi-factor authentication platform and the identity authentication platform to encrypt and transmit a key based on the binding relationship, and using the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result includes: Based on the binding relationship, calling the multi-factor authentication platform and the identity authentication platform to issue an encryption key to the terminal device; Receiving a login request carrying login information sent by the terminal device; When the login information is authenticated, a multi-factor authentication instruction is returned to enable the terminal device to generate a dynamic password based on a key plaintext, where the key plaintext is obtained by the terminal device decrypting the encryption key; The dynamic password sent by the terminal device is received, and the dynamic password is authenticated to obtain the authentication result.
5. The method according to claim 4, wherein The calling the multi-factor authentication platform and the identity authentication platform to issue an encryption key to the terminal device based on the binding relationship includes: receiving a key application carrying the first user identifier sent by the terminal device; Acquire the second user identifier bound to the first user identifier from the binding relationship; The second user identifier and the generated key plaintext are sent to the multi-factor authentication platform, so that when the multi-factor authentication platform verifies the second user identifier, the key plaintext is encrypting through the identity authentication platform to obtain an encryption key, and the encryption key is sent to the terminal device.
6. The method according to claim 4, wherein The terminal device stores the key in plain text in a trusted execution environment or a secure element.
7. The method according to any one of claims 1 to 3, characterized in that: The step of calling the multi-factor authentication platform and the identity authentication platform to encrypt and transmit a key based on the binding relationship, and using the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result includes: Receiving a login request carrying login information sent by the terminal device; When the login information is authenticated, obtaining the second user identifier from the binding relationship based on the first user identifier associated with the login information; sending the second user identifier and the application system identifier to the multi-factor authentication platform, so that the multi-factor authentication platform generates a serial number and an online key when the second user identifier is successfully verified; and sending an authentication application carrying the application system identifier, the serial number, and the online key to the terminal device through the identity authentication platform; Receive an authentication result sent by the multi-factor authentication platform, where the authentication result is obtained by the multi-factor authentication platform through verification of a signature result by the identity authentication platform; the signature result is obtained by the terminal device signing the online key and sending the signature result to the multi-factor authentication platform.
8. The method according to claim 7, wherein The signature result is obtained by the terminal device signing the online key in response to a confirmation operation on the authentication application in a multi-factor authentication application.
9. A multi-factor authentication method, characterized in that: Applied to multi-factor authentication platforms, including: Receive an encrypted application code and a first user identifier of an operating user in an application system, sent by a terminal device connected to the identity authentication platform. The encrypted application code is obtained by encrypting a plain text application code by the terminal device. The plain text application code and the first user identifier are returned by the application system when the terminal device sends a multi-factor authentication binding application to the application system. Decrypting the ciphertext of the application code through the identity authentication platform to obtain the plaintext of the application code; The plain text application code, the first user identifier, and the second user identifier of the operating user on the multi-factor authentication platform are sent to the application system, so that when the application system passes the plain text verification of the application code, a binding relationship between the first user identifier and the second user identifier is established; and based on the binding relationship, the multi-factor authentication platform and the identity authentication platform are called to encrypt and transmit a key, and the key is used to perform multi-factor authentication on the login request of the terminal device to obtain an authentication result.
10. A multi-factor authentication method, characterized in that: Applicable to terminal devices connected to the identity authentication platform, including: Send a multi-factor authentication binding request to the application system; Receiving the plain text application code and the first user identifier of the operating user in the application system returned by the application system; Encrypting the application code plaintext to obtain the application code ciphertext; The application code ciphertext and the first user identifier are sent to a multi-factor authentication platform, so that the multi-factor authentication platform decrypts the application code ciphertext through the identity authentication platform to obtain the application code plaintext; and the multi-factor authentication platform sends the application code plaintext, the first user identifier and the second user identifier of the operating user on the multi-factor authentication platform to the application system; when the application system verifies the application code plaintext, a binding relationship between the first user identifier and the second user identifier is established; and based on the binding relationship, the multi-factor authentication platform and the identity authentication platform are called to encrypt and transmit a key, and the key is used to perform multi-factor authentication on the login request of the terminal device to obtain an authentication result.
11. A multi-factor authentication device, characterized in that: Applied to application systems, including: A first receiving module is used to receive a multi-factor authentication binding application sent by a terminal device that has been connected to the identity authentication platform; a first sending module, configured to return a plaintext application code and a first user identifier of the operating user in the application system to the terminal device, so that the terminal device encrypts the plaintext application code into a ciphertext application code, and sends the ciphertext application code and the first user identifier to the multi-factor authentication platform; The first receiving module is further configured to receive the application code plaintext obtained by decrypting the application code ciphertext via the identity authentication platform, the first user identifier, and the second user identifier of the operating user on the multi-factor authentication platform, sent by the multi-factor authentication platform; a processing module, configured to establish a binding relationship between the first user identifier and the second user identifier when the plain text verification of the application code passes; The processing module is further configured to call the multi-factor authentication platform and the identity authentication platform to encrypt and transmit a key based on the binding relationship, and use the key to perform multi-factor authentication on a login request of the terminal device to obtain an authentication result.
12. A multi-factor authentication device, characterized in that: Applied to multi-factor authentication platforms, including: a second receiving module, configured to receive an application code ciphertext and a first user identifier of an operating user in an application system, sent by a terminal device that has accessed the identity authentication platform. The application code ciphertext is obtained by encrypting the application code plaintext by the terminal device. The application code plaintext and the first user identifier are returned by the application system when the terminal device sends a multi-factor authentication binding application to the application system; An authentication module, configured to decrypt the ciphertext of the application code through the identity authentication platform to obtain the plaintext of the application code; The second sending module is used to send the plain text of the application code, the first user identifier and the second user identifier of the operating user on the multi-factor authentication platform to the application system, so that when the application system passes the plain text verification of the application code, a binding relationship between the first user identifier and the second user identifier is established; and based on the binding relationship, the multi-factor authentication platform and the identity authentication platform are called to encrypt and transmit a key, and the key is used to perform multi-factor authentication on the login request of the terminal device to obtain an authentication result.
13. A multi-factor authentication device, characterized in that: Applicable to terminal devices connected to the identity authentication platform, including: The third sending module is used to send a multi-factor authentication binding application to the application system; A third receiving module is used to receive the plain text application code returned by the application system and the first user identifier of the operating user in the application system; An encryption module, used to encrypt the application code plain text to obtain the application code cipher text; The third sending module is further configured to send the application code ciphertext and the first user identifier to the multi-factor authentication platform, so that the multi-factor authentication platform decrypts the application code ciphertext through the identity authentication platform to obtain the application code plaintext; and enables the multi-factor authentication platform to send the application code plaintext, the first user identifier and the second user identifier of the operating user on the multi-factor authentication platform to the application system; when the application system verifies the application code plaintext, a binding relationship between the first user identifier and the second user identifier is established; and based on the binding relationship, the multi-factor authentication platform and the identity authentication platform are called to encrypt and transmit a key, and the key is used to perform multi-factor authentication on the login request of the terminal device to obtain an authentication result.
14. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.
15. A computer-readable storage medium, characterized in that It stores a computer program that can be executed by a computer device. When the computer program is run on the computer device, the computer device executes the steps of any one of the methods described in claims 1 to 10.
16. A computer program product, characterized in that The computer program product comprises a computer program stored on a computer-readable storage medium, wherein the computer program comprises program instructions. When the program instructions are executed by a computer device, the computer device is caused to perform the steps of the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Multi-factor authentication certificate generation and verification method
CN117375824A
Government affair system two-factor identity authentication method and system based on TOTP
CN118585989A