Secret third-party authentication login method and system based on quantum key distribution network

Through the quantum key distribution network's secret third-party authentication login method, session keys are generated and login information is verified, which solves the security issues of existing third-party authentication login methods and achieves higher information security and identity authentication reliability.

CN119583067BActive Publication Date: 2025-09-23CHINA TELECOM QUANTUM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411544743.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2025-09-23
Estimated Expiration
2044-10-31

AI Technical Summary

Technical Problem

Existing third-party authentication login methods are vulnerable to brute force attacks and man-in-the-middle attacks, leading to user information leakage and insufficient security.

Method used

The MeSign third-party authentication login method based on the quantum key distribution network is adopted. Through the quantum key distribution and encryption and decryption process between the MeSign server, the secret service platform and the user terminal, the session key is generated and the correctness of the login information is verified to ensure the security of information transmission.

Benefits of technology

It improves the security of third-party authentication login, prevents information leakage, and enhances the reliability of user identity verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583067B_ABST
    Figure CN119583067B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention provide a secret third-party authentication and login method and system based on a quantum key distribution network. The method includes: receiving a secret authentication request from a third-party application server; generating a session key distribution request and sending it to a secret service platform; the session key distribution request is used to request the secret service platform to generate an encrypted session key and distribute it to a user terminal; the user terminal is used to extract a pre-filled key from a preset key security medium, decrypt the encrypted session key to obtain the session key, and generate encrypted login information based on the session key; decrypt the encrypted login information to obtain decrypted login information; if the decrypted login information is correct, an authentication success message is sent to the third-party application server. Based on the quantum key distribution network and a pre-filled key preset in the key security medium, information can be securely transmitted between the user terminal and the secret server for identity verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network communication technology, and in particular to a secret third-party authentication login method based on a quantum key distribution network, a secret third-party authentication login system based on a quantum key distribution network, an electronic device, and a computer-readable medium. Background Art

[0002] With the rapid development of information technology, network security issues are becoming increasingly prominent. User identity verification is a critical component of information security, particularly in the mobile communications sector. Currently, most mobile applications utilize third-party authentication login methods that rely on traditional cryptographic techniques, including symmetric and asymmetric encryption algorithms. These methods provide a certain degree of security for user information. However, existing password login methods are vulnerable to brute force attacks and can be exploited by man-in-the-middle attacks to intercept user login information and impersonate the user, leading to the leakage of user information. Summary of the Invention

[0003] An embodiment of the present invention provides a secret third-party authentication login method and system, electronic device, and computer-readable storage medium based on a quantum key distribution network to improve the security of third-party application login.

[0004] The embodiment of the present invention discloses a secret message third-party authentication login method based on a quantum key distribution network, which is applied to a secret message server. The secret message server is respectively connected to a user terminal, a third-party application server, and a secret service platform. The secret service platform is deployed in the quantum key distribution network. The method includes:

[0005] Receiving a secret authentication request sent by the third-party application server; wherein the secret authentication request is generated by the third-party application server based on the secret login request sent by the user terminal;

[0006] Generate a session key delivery request and send it to the secret service platform; the session key delivery request is used to request the secret service platform to generate an encrypted session key and distribute it to the user terminal; the user terminal is used to extract a pre-filled key from a preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain a session key, and generate encrypted login information based on the session key;

[0007] receiving the encrypted login information sent by the user terminal, and decrypting the encrypted login information to obtain decrypted login information;

[0008] Verify whether the decrypted login information is correct;

[0009] If the decrypted login information is correct, an authentication success message is sent to the third-party application server; the authentication success message is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0010] Optionally, the step of generating a session key delivery request and sending the request to the secret service platform includes:

[0011] Generate a session key based on the secret authentication request;

[0012] Based on the session key, a session key delivery request is generated and sent to the secret service platform.

[0013] Optionally, the step of receiving the encrypted login information sent by the user terminal and decrypting the encrypted login information to obtain the decrypted login information includes:

[0014] Receiving encrypted login information sent by the user terminal;

[0015] The encrypted login information is decrypted using the session key to obtain decrypted login information.

[0016] Optionally, the step of verifying whether the decrypted login information is correct includes:

[0017] Extracting account information and password information from the decrypted login information;

[0018] Verify whether the account information and password information are correct.

[0019] Optionally, the method further includes:

[0020] After sending an authentication success message to the third-party application server, the session key is updated.

[0021] An embodiment of the present invention further provides a secret third-party authentication login method based on a quantum key distribution network, which is applied to a secret service platform. The secret service platform is respectively connected to a user terminal, a third-party application server, and a secret service server. The secret service platform is deployed in the quantum key distribution network. The method includes:

[0022] Receiving a session key issuance request sent by the Secret Message server; the session key issuance request is generated by the Secret Message server based on a Secret Message authentication request sent by a third-party application server; the Secret Message authentication request is generated by the third-party application server based on a Secret Message login request sent by the user terminal;

[0023] Generate an encrypted session key based on the pre-filled key corresponding to the user terminal;

[0024] The encrypted session key is distributed to the user terminal; the user terminal is used to extract the pre-filled key from the preset key security medium, and decrypt the encrypted session key based on the pre-filled key to obtain the session key, and generate encrypted login information based on the session key and send it to the secret letter server; the secret letter server is used to receive the encrypted login information sent by the user terminal, decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, send authentication success information to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0025] An embodiment of the present invention further provides a secret third-party authentication login method based on a quantum key distribution network, which is applied to a user terminal, wherein the user terminal is respectively connected to a secret service platform, a third-party application server, and a secret service server, and the secret service platform is deployed in the quantum key distribution network. The method includes:

[0026] Sending a secret message login request to the third-party application server; the secret message login request is used to request the third-party application server to generate a secret message authentication request based on the secret message login request sent by the user terminal and send it to the secret message server; the secret message authentication request is used to request the secret message server to generate a session key request and send it to the secret service platform;

[0027] Receiving the encrypted session key distributed by the cryptographic service platform;

[0028] Extracting a pre-filled key from a preset key security medium;

[0029] Decrypting the encrypted session key based on the pre-filled key to obtain a session key;

[0030] Encrypted login information is generated based on the session key and sent to the secret message server; the secret message server is used to decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, authentication success information is sent to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0031] The embodiment of the present invention further provides a secret third-party authentication login system based on the quantum key distribution network, the secret third-party authentication login system includes a user terminal, a secret service platform, a third-party application server, and a secret server, and the secret service platform is deployed in the quantum key distribution network;

[0032] The user terminal is used to send a secret letter login request to the third-party application server;

[0033] The third-party application server is used to generate a secret authentication request based on the secret login request sent by the user terminal and send it to the secret server;

[0034] The secret message server is used to generate a session key delivery request and send it to the secret service platform;

[0035] The cryptographic service platform generates an encrypted session key based on the session key issuance request and distributes it to the user terminal;

[0036] The user terminal is used to extract the pre-filled key from the preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain the session key, and generate encrypted login information based on the session key and send it to the secret message server;

[0037] The secret letter server is used to decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, send an authentication success message to the third-party application server;

[0038] The third-party application server is used to allow the user terminal to log in to the third-party application.

[0039] An embodiment of the present invention further discloses an electronic device, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0040] The memory is used to store computer programs;

[0041] The processor is configured to implement the method described in the embodiment of the present invention when executing the program stored in the memory.

[0042] The embodiments of the present invention further disclose one or more computer-readable media having instructions stored thereon. When executed by one or more processors, the processors are enabled to perform the method according to the embodiments of the present invention.

[0043] The embodiments of the present invention include the following advantages:

[0044] A secret third-party authentication login method based on a quantum key distribution network is used to receive a secret authentication request from a third-party application server; wherein the secret authentication request is generated by the third-party application server based on the secret login request from the user terminal; a session key distribution request is generated and sent to the secret service platform; the session key distribution request is used to request the secret service platform to generate an encrypted session key and distribute it to the user terminal; the user terminal is used to extract a pre-filled key from a preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain a session key, and generate encrypted login information based on the session key; receive the encrypted login information from the user terminal, decrypt the encrypted login information to obtain decrypted login information; verify whether the decrypted login information is correct; if the decrypted login information is correct, send an authentication success message to the third-party application server; the authentication success message is used to notify the third-party application server that the user terminal is allowed to log in to the third-party application. Based on the quantum key distribution network and a pre-filled key preset in the key security medium, information can be securely transmitted between the user terminal and the secret server for identity authentication, effectively improving the security of third-party authentication login. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 This is a schematic diagram of a MiXin third-party authentication login system based on a quantum key distribution network provided in an embodiment of the present invention;

[0046] Figure 2 This is a flowchart of the steps of a secret third-party authentication login method based on a quantum key distribution network provided in an embodiment of the present invention;

[0047] Figure 3 This is a flowchart of a secret third-party authentication login method based on a quantum key distribution network provided in an embodiment of the present invention;

[0048] Figure 4 is a block diagram of an electronic device provided in an embodiment of the present invention;

[0049] Figure 5 is a schematic diagram of a computer-readable medium provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0050] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0051] Reference Figure 1 , showing a schematic diagram of a secret third-party authentication login system based on a quantum key distribution network provided in an embodiment of the present invention.

[0052] Among them, a secret message third-party authentication login system based on quantum key distribution network includes a secret message server 101, a secret message service platform 102, a user terminal 103, and a third-party application server 104.

[0053] The secret service platform 102 can be deployed in a quantum key distribution network (QKD). The QKD network includes several service nodes for distributing and managing quantum keys. As part of the service nodes in the QKD network, the secret service platform 102 is deployed in the QKD network. Thus, the secret service platform 102 can distribute quantum keys and process data based on quantum keys.

[0054] In an embodiment of the present invention, a secret message server 101 can be provided for the third-party login function of the third-party application to provide an authentication function for the user's account information when the user terminal logs into the third-party application.

[0055] In an embodiment of the present invention, the user terminal 103 may have the function of encrypting and decrypting quantum keys, thereby enabling encrypted transmission of information using quantum keys during the third-party authentication login process.

[0056] Specifically, the user terminal 103 may be provided with a key security medium, in which a quantum key may be pre-stored. Thus, when the cryptographic service platform 102 needs to perform encrypted communication with the user terminal 103, the cryptographic service platform 102 may pre-store the quantum key corresponding to the user terminal 103 and implement encrypted communication with the user terminal 103 based on the quantum key.

[0057] The third-party application server 104 can provide the function of third-party authentication login. Thus, the quantum key-based secret message login method can be connected to the third-party application server 104 as a third-party authentication login method. When secret message login is required, the third-party application server 104 can request the secret message server 101 to complete the corresponding login authentication process.

[0058] Reference Figure 2 , shows a flowchart of the steps of a secret message third-party authentication login method based on a quantum key distribution network provided in an embodiment of the present invention, which is applied to a secret message server, and the secret message server is respectively connected to the user terminal, the third-party application server, and the secret service platform, and the secret service platform is deployed in the quantum key distribution network. The method may specifically include the following steps:

[0059] Step 201: Receive a secret authentication request from the third-party application server; wherein the secret authentication request is generated by the third-party application server based on the secret login request sent by the user terminal;

[0060] Specifically, when a user terminal needs to log in to a third-party application, it can send a MeSign login request to the third-party application server, requesting to log in to the third-party application through MeSign login. Subsequently, the third-party application server can generate a MeSign authentication request based on the MeSign login request sent by the user terminal and send it to the MeSign server, requesting the MeSign server to authenticate the user terminal and confirm whether to allow login to the third-party application.

[0061] Step 202: Generate a session key delivery request and send it to the secret service platform; the session key delivery request is used to request the secret service platform to generate an encrypted session key and distribute it to the user terminal; the user terminal is used to extract a pre-filled key from a preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain a session key, and generate encrypted login information based on the session key;

[0062] Afterwards, the secret message server can generate a session key distribution request and send it to the secret service platform, requesting the secret service platform to distribute the session key required for the authentication login process to the user terminal through a secure quantum encryption method, so that the user terminal can obtain the session key in a secure manner, avoiding the leakage of user information due to the interception of the session key.

[0063] After receiving the session key issuance request, the cryptographic service platform can determine the pre-filled key corresponding to the user terminal based on the user terminal information, and use the pre-filled key to encrypt the session key, obtain the encrypted session key and distribute it to the user terminal.

[0064] In a specific implementation, a user terminal can be pre-configured with a key security medium. This key security medium can be pre-charged with a pre-charged key. Specifically, the key security medium can be a SIM card (Subscriber Identity Module). The quantum key can be written into the key security medium in advance using a quantum server cryptographic machine (QHSM) in a quantum key distribution network. After the user places the key security medium in the user terminal, the user terminal can extract the quantum key from the key security medium for information encryption and decryption, thereby effectively improving user information security.

[0065] Therefore, after obtaining the encrypted session key, the user terminal can extract the pre-filled key from the preset key security medium, and decrypt the encrypted session key based on the pre-filled key to obtain the session key.

[0066] Afterwards, the user terminal can use the session key to encrypt the login information required for authentication login, generate encrypted login information and send it to the secret message server.

[0067] Step 203: receiving the encrypted login information sent by the user terminal, decrypting the encrypted login information to obtain decrypted login information;

[0068] In the embodiment of the present invention, the session key may be generated by the secret message server. Thus, the secret message server may receive the encrypted login information sent by the user terminal, decrypt the encrypted login information, and obtain the decrypted login information.

[0069] Step 204: Verify whether the decrypted login information is correct;

[0070] Afterwards, the MeSince server can verify whether the decrypted login information is correct to determine whether the user can be allowed to log in to the third-party application.

[0071] Step 205: If the decrypted login information is correct, an authentication success message is sent to the third-party application server; the authentication success message is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0072] If the decrypted login information is correct, the user can be allowed to log in to the third-party application and send an authentication success message to the third-party application server. After obtaining the authentication success message, the third-party application server can allow the user terminal to log in to the third-party application.

[0073] In one embodiment of the present invention, the step of generating a session key request and sending the request to the secret service platform includes:

[0074] S11, generating a session key based on the secret authentication request;

[0075] S12: Generate a session key delivery request based on the session key and send it to the secret service platform.

[0076] Specifically, after receiving the MeSince authentication request, the MeSince server can generate a session key for this authentication and login process. Afterwards, it can send a session key request containing the generated session key to the MeSince platform, so that the MeSince platform can encrypt the session key and improve the security of the authentication and login process.

[0077] In one embodiment of the present invention, the step of receiving the encrypted login information sent by the user terminal and decrypting the encrypted login information to obtain the decrypted login information includes:

[0078] S21, receiving encrypted login information sent by the user terminal;

[0079] S22: Decrypt the encrypted login information using the session key to obtain decrypted login information.

[0080] Specifically, the encrypted login information sent by the user terminal can be received. Subsequently, the Secret Message Server can use the session key generated by itself to decrypt the encrypted login information, thereby obtaining the decrypted login information, and verify the decrypted login information to determine whether the user terminal can log in to the third-party application.

[0081] In one embodiment of the present invention, the step of verifying whether the decrypted login information is correct includes:

[0082] S31, extracting account information and password information from the decrypted login information;

[0083] S32: Verify whether the account information and the password information are correct.

[0084] In a specific implementation, the login information sent by the user terminal may include account information and password information. After obtaining the decrypted login information, the MeSign server can extract the account information and password information, and compare the account information and password information with the account information and password information stored by itself to determine whether the account information and password information are correct, so as to determine whether to allow the user terminal to log in to the third-party application.

[0085] In one embodiment of the present invention, the method further includes:

[0086] S41: After sending an authentication success message to the third-party application server, update the session key.

[0087] Specifically, after sending the authentication success message to the third-party application server, the authentication login process has been completed. In order to improve the security of information transmission, the session key can be updated regularly and sent to the user terminal through the secret service platform to further improve the security of subsequent communications between the user terminal and the Secret Service Server.

[0088] Optionally, the secret service platform can also detect whether there are abnormal conditions in the quantum channel, such as increased channel noise or increased quantum bit error rate, to confirm whether the current quantum channel is secure. In the event of an abnormality, a security alert can be issued, further improving the security of the MeSign third-party authentication login method based on the quantum key distribution network.

[0089] A secret third-party authentication login method based on a quantum key distribution network is used to receive a secret authentication request from a third-party application server; wherein the secret authentication request is generated by the third-party application server based on the secret login request from the user terminal; a session key distribution request is generated and sent to the secret service platform; the session key distribution request is used to request the secret service platform to generate an encrypted session key and distribute it to the user terminal; the user terminal is used to extract a pre-filled key from a preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain a session key, and generate encrypted login information based on the session key; receive the encrypted login information from the user terminal, decrypt the encrypted login information to obtain decrypted login information; verify whether the decrypted login information is correct; if the decrypted login information is correct, send an authentication success message to the third-party application server; the authentication success message is used to notify the third-party application server that the user terminal is allowed to log in to the third-party application. Based on the quantum key distribution network and a pre-filled key preset in the key security medium, information can be securely transmitted between the user terminal and the secret server for identity authentication, effectively improving the security of third-party authentication login.

[0090] An embodiment of the present invention further provides a secret third-party authentication login method based on a quantum key distribution network, which is applied to a secret service platform. The secret service platform is respectively connected to a user terminal, a third-party application server, and a secret service server. The secret service platform is deployed in the quantum key distribution network. The method includes:

[0091] Receiving a session key issuance request sent by the Secret Message server; the session key issuance request is generated by the Secret Message server based on a Secret Message authentication request sent by a third-party application server; the Secret Message authentication request is generated by the third-party application server based on a Secret Message login request sent by the user terminal;

[0092] Generate an encrypted session key based on the pre-filled key corresponding to the user terminal;

[0093] The encrypted session key is distributed to the user terminal; the user terminal is used to extract the pre-filled key from the preset key security medium, and decrypt the encrypted session key based on the pre-filled key to obtain the session key, and generate encrypted login information based on the session key and send it to the secret letter server; the secret letter server is used to receive the encrypted login information sent by the user terminal, decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, send authentication success information to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0094] An embodiment of the present invention further provides a secret third-party authentication login method based on a quantum key distribution network, which is applied to a user terminal, wherein the user terminal is respectively connected to a secret service platform, a third-party application server, and a secret service server, and the secret service platform is deployed in the quantum key distribution network. The method includes:

[0095] The step sends a secret letter login request to the third-party application server; the secret letter login request is used to request the third-party application server to generate a secret letter authentication request based on the secret letter login request sent by the user terminal and send it to the secret letter server; the secret letter authentication request is used to request the secret letter server to generate a session key request and send it to the secret service platform;

[0096] Receiving the encrypted session key distributed by the cryptographic service platform;

[0097] Extracting a pre-filled key from a preset key security medium;

[0098] Decrypting the encrypted session key based on the pre-filled key to obtain a session key;

[0099] Encrypted login information is generated based on the session key and sent to the secret message server; the secret message server is used to decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, authentication success information is sent to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0100] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0101] Figure 3 This is a flow chart of a secret third-party authentication login method based on a quantum key distribution network provided in an embodiment of the present invention.

[0102] The embodiment of the present invention further provides a secret third-party authentication login system based on the quantum key distribution network. The secret third-party authentication login system includes a user terminal 301, a third-party application server 302, a secret service platform 304, and a secret service server 303. The secret service platform 304 is deployed in the quantum key distribution network.

[0103] The user terminal 301 is used to send a secret letter login request to the third-party application server;

[0104] The third-party application server 302 is used to generate a secret authentication request based on the secret login request sent by the user terminal and send it to the secret server;

[0105] The secret message server 303 is used to generate a session key delivery request and send it to the secret service platform;

[0106] The cryptographic service platform 304 generates an encrypted session key based on the session key issuance request and distributes it to the user terminal;

[0107] The user terminal 301 is used to extract the pre-filled key from the preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain the session key, and generate encrypted login information based on the session key and send it to the secret message server;

[0108] The secret letter server 303 is used to decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, it sends an authentication success message to the third-party application server;

[0109] The third-party application server 302 is used to allow the user terminal to log in to a third-party application.

[0110] When a user terminal needs to log in to a third-party application, it can send a secret login request to the third-party application server, requesting to log in to the third-party application through secret login.

[0111] Afterwards, the third-party application server can generate a MeSince authentication request based on the MeSince login request sent by the user terminal and send it to the MeSince server, requesting the MeSince server to authenticate the user terminal and confirm whether to allow login to the third-party application.

[0112] The secret message server can generate a session key distribution request and send it to the secret service platform, requesting the secret service platform to distribute the session key required for the authentication login process to the user terminal through a secure quantum encryption method, so that the user terminal can obtain the session key in a secure manner, avoiding the leakage of user information due to the interception of the session key.

[0113] After receiving the session key issuance request, the cryptographic service platform can determine the pre-filled key corresponding to the user terminal based on the user terminal information, and use the pre-filled key to encrypt the session key, obtain the encrypted session key and distribute it to the user terminal.

[0114] In a specific implementation, a user terminal can be pre-configured with a key security medium. This key security medium can be pre-charged with a pre-charged key. Specifically, the key security medium can be a SIM card (Subscriber Identity Module). The quantum key can be written into the key security medium in advance using a quantum server cryptographic machine (QHSM) in a quantum key distribution network. After the user places the key security medium in the user terminal, the user terminal can extract the quantum key from the key security medium for information encryption and decryption, thereby effectively improving user information security.

[0115] Therefore, after obtaining the encrypted session key, the user terminal can extract the pre-filled key from the preset key security medium, and decrypt the encrypted session key based on the pre-filled key to obtain the session key.

[0116] Afterwards, the user terminal can use the session key to encrypt the login information required for authentication login, generate encrypted login information and send it to the secret message server.

[0117] In the embodiment of the present invention, the session key may be generated by the secret message server. Thus, the secret message server may receive the encrypted login information sent by the user terminal, decrypt the encrypted login information, and obtain the decrypted login information.

[0118] Afterwards, the MeSince server can verify whether the decrypted login information is correct to determine whether the user can be allowed to log in to the third-party application.

[0119] If the decrypted login information is correct, the user can be allowed to log in to the third-party application and send an authentication success message to the third-party application server. After obtaining the authentication success message, the third-party application server can allow the user terminal to log in to the third-party application.

[0120] In addition, an embodiment of the present invention further provides an electronic device, such as Figure 4 As shown, it includes a processor 401, a communication interface 402, a memory 403 and a communication bus 404, wherein the processor 401, the communication interface 402, and the memory 403 communicate with each other through the communication bus 404.

[0121] Memory 403, used for storing computer programs;

[0122] The processor 401 is configured to execute the program stored in the memory 403 by performing the following steps:

[0123] Receiving a secret authentication request sent by the third-party application server; wherein the secret authentication request is generated by the third-party application server based on the secret login request sent by the user terminal;

[0124] Generate a session key delivery request and send it to the secret service platform; the session key delivery request is used to request the secret service platform to generate an encrypted session key and distribute it to the user terminal; the user terminal is used to extract a pre-filled key from a preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain a session key, and generate encrypted login information based on the session key;

[0125] receiving the encrypted login information sent by the user terminal, and decrypting the encrypted login information to obtain decrypted login information;

[0126] Verify whether the decrypted login information is correct;

[0127] If the decrypted login information is correct, an authentication success message is sent to the third-party application server; the authentication success message is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0128] Optionally, the step of generating a session key delivery request and sending the request to the secret service platform includes:

[0129] Generate a session key based on the secret authentication request;

[0130] Based on the session key, a session key delivery request is generated and sent to the secret service platform.

[0131] Optionally, the step of receiving the encrypted login information sent by the user terminal and decrypting the encrypted login information to obtain the decrypted login information includes:

[0132] Receiving encrypted login information sent by the user terminal;

[0133] The encrypted login information is decrypted using the session key to obtain decrypted login information.

[0134] Optionally, the step of verifying whether the decrypted login information is correct includes:

[0135] Extracting account information and password information from the decrypted login information;

[0136] Verify whether the account information and password information are correct.

[0137] Optionally, the method further includes:

[0138] After sending an authentication success message to the third-party application server, the session key is updated.

[0139] The processor 401, when used to execute the program stored in the memory 403, further implements the following steps:

[0140] Sending a secret message login request to the third-party application server; the secret message login request is used to request the third-party application server to generate a secret message authentication request based on the secret message login request sent by the user terminal and send it to the secret message server; the secret message authentication request is used to request the secret message server to generate a session key request and send it to the secret service platform;

[0141] Receiving the encrypted session key distributed by the cryptographic service platform;

[0142] Extracting a pre-filled key from a preset key security medium;

[0143] Decrypting the encrypted session key based on the pre-filled key to obtain a session key;

[0144] Encrypted login information is generated based on the session key and sent to the secret message server; the secret message server is used to decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, authentication success information is sent to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0145] The processor 401, when used to execute the program stored in the memory 403, further implements the following steps:

[0146] Receiving a session key issuance request sent by the Secret Message server; the session key issuance request is generated by the Secret Message server based on a Secret Message authentication request sent by a third-party application server; the Secret Message authentication request is generated by the third-party application server based on a Secret Message login request sent by the user terminal;

[0147] Generate an encrypted session key based on the pre-filled key corresponding to the user terminal;

[0148] The encrypted session key is distributed to the user terminal; the user terminal is used to extract the pre-filled key from the preset key security medium, and decrypt the encrypted session key based on the pre-filled key to obtain the session key, and generate encrypted login information based on the session key and send it to the secret letter server; the secret letter server is used to receive the encrypted login information sent by the user terminal, decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, send authentication success information to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

[0149] The communication bus mentioned in the terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.

[0150] The communication interface is used for communication between the above terminal and other devices.

[0151] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.

[0152] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0153] like Figure 5 As shown, in another embodiment provided by the present invention, a computer-readable storage medium 501 is also provided, which stores instructions. When the computer-readable storage medium 501 is run on a computer, it enables the computer to execute the secret third-party authentication login method based on the quantum key distribution network described in the above embodiment.

[0154] In another embodiment provided by the present invention, a computer program product containing instructions is also provided. When the computer is run on the computer, the computer executes the secret third-party authentication login method based on the quantum key distribution network described in the above embodiment.

[0155] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0156] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0157] Each embodiment in this specification is described in a related manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiment is generally similar to the method embodiment, so the description is relatively simple. For related parts, refer to the description of the method embodiment.

[0158] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included in the scope of protection of the present invention.

Claims

1. A third-party authentication login method based on quantum key distribution network, characterized in that: It is applied to a secret message server, which is respectively connected to a user terminal, a third-party application server, and a secret service platform, and the secret service platform is deployed in a quantum key distribution network. The method includes: Receiving a secret authentication request sent by the third-party application server; wherein the secret authentication request is generated by the third-party application server based on the secret login request sent by the user terminal; Generate a session key delivery request and send it to the secret service platform; the session key delivery request is used to request the secret service platform to generate an encrypted session key and distribute it to the user terminal; the user terminal is used to extract a pre-filled key from a preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain a session key, and generate encrypted login information based on the session key; receiving the encrypted login information sent by the user terminal, and decrypting the encrypted login information to obtain decrypted login information; Verify whether the decrypted login information is correct; If the decrypted login information is correct, sending authentication success information to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application; The step of generating a session key request and sending the request to the secret service platform includes: Generate a session key based on the secret authentication request; Based on the session key, a session key delivery request is generated and sent to the secret service platform.

2. The method according to claim 1, characterized in that The step of receiving the encrypted login information sent by the user terminal and decrypting the encrypted login information to obtain the decrypted login information includes: Receiving encrypted login information sent by the user terminal; The encrypted login information is decrypted using the session key to obtain decrypted login information.

3. The method according to claim 1, characterized in that The step of verifying whether the decrypted login information is correct includes: Extracting account information and password information from the decrypted login information; Verify whether the account information and password information are correct.

4. The method according to claim 1, wherein The method further comprises: After sending an authentication success message to the third-party application server, the session key is updated.

5. A secret third-party authentication login method based on quantum key distribution network, characterized in that: It is applied to a secret service platform, which is respectively connected to a user terminal, a third-party application server, and a secret letter server. The secret service platform is deployed in a quantum key distribution network. The method includes: Receive a session key issuance request sent by the secret message server; the session key issuance request is generated by the secret message server based on a secret message authentication request sent by a third-party application server and is generated based on the session key; the secret message authentication request is generated by the third-party application server based on a secret message login request sent by the user terminal; Generate an encrypted session key based on the pre-filled key corresponding to the user terminal; The encrypted session key is distributed to the user terminal; the user terminal is used to extract the pre-filled key from the preset key security medium, and decrypt the encrypted session key based on the pre-filled key to obtain the session key, and generate encrypted login information based on the session key and send it to the secret letter server; the secret letter server is used to receive the encrypted login information sent by the user terminal, decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, send authentication success information to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

6. A secret third-party authentication login method based on quantum key distribution network, characterized in that: The method is applied to a user terminal, wherein the user terminal is respectively connected to a secret service platform, a third-party application server, and a secret letter server. The secret service platform is deployed in a quantum key distribution network. The method includes: Sending a secret message login request to the third-party application server; the secret message login request is used to request the third-party application server to generate a secret message authentication request based on the secret message login request sent by the user terminal and send it to the secret message server; the secret message authentication request is used to request the secret message server to generate a session key, and based on the session key, generate a session key issuance request and send it to the secret service platform; Receiving the encrypted session key distributed by the cryptographic service platform; Extracting a pre-filled key from a preset key security medium; Decrypting the encrypted session key based on the pre-filled key to obtain a session key; Encrypted login information is generated based on the session key and sent to the secret message server; the secret message server is used to decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, authentication success information is sent to the third-party application server; the authentication success information is used to notify the third-party application server to allow the user terminal to log in to the third-party application.

7. A secret third-party authentication login system based on quantum key distribution network, characterized by: The Secret Message third-party authentication login system includes a user terminal, a secret service platform, a third-party application server, and a Secret Message server. The secret service platform is deployed in the quantum key distribution network. The user terminal is used to send a secret letter login request to the third-party application server; The third-party application server is used to generate a secret authentication request based on the secret login request sent by the user terminal and send it to the secret server; The secret message server is used to generate a session key, and based on the session key, generate a session key delivery request and send it to the secret service platform; The cryptographic service platform generates an encrypted session key based on the session key issuance request and distributes it to the user terminal; The user terminal is used to extract the pre-filled key from the preset key security medium, decrypt the encrypted session key based on the pre-filled key to obtain the session key, and generate encrypted login information based on the session key and send it to the secret message server; The secret letter server is used to decrypt the encrypted login information, obtain the decrypted login information and verify whether the decrypted login information is correct; if the decrypted login information is correct, send an authentication success message to the third-party application server; The third-party application server is used to allow the user terminal to log in to the third-party application.

8. An electronic device, characterized in that: comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; The memory is used to store computer programs; The processor is configured to implement the method according to any one of claims 1 to 6 when executing a program stored in the memory.

9. A computer-readable medium having instructions stored thereon, which, when executed by one or more processors, cause the processors to perform the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Secure login system, secure login method, login server and authentication server

    CN105391734A

  • Verification information sending method and device

    CN116233832A