A Cross-Platform Password-Free Login Method and System for SM2 Cryptography Channel Based on UKey
Through the cross-platform password-free login method combined with UKey and China Secret Channel, the complexity and security of cross-platform login are solved, and fast and secure cross-platform login is achieved. It is suitable for a diverse cloud environment and improves login efficiency and security.
Patent Information
- Application Number
- CN202510264894.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-03-07
AI Technical Summary
The existing technology has problems such as user memory of complex passwords, insufficient security and cumbersome operations when logging in across platforms. Especially when different cloud native manufacturers lack a unified secure password-free login mechanism, it is difficult to meet the needs of both convenience and security.
The cross-platform password-free login method based on UKey is adopted, and cross-platform password-free login is achieved through technical means such as front-end verification of the CPCS system, SM2 public key encryption and decryption of the secret platform, Bayesian model environment judgment, and dual password verification.
It realizes fast and secure cross-platform login under different operating systems and cloud service architectures, improves work efficiency and identity authentication reliability, enhances data transmission security, and has the ability to deal with password blasting and UKey loss.
Smart Images

Figure CN119814335B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security communication technology, and more specifically, to a cross-platform passwordless login method and system based on UKey for national cryptography channels. Background Art
[0002] With the rapid development of information technology, cloud native technology has been widely applied. Many enterprises and institutions have migrated their businesses to cloud platforms, and various cloud native vendors have provided a rich variety of password platform pages for users to access. However, there are many problems in cross-platform login.
[0003] Currently, most traditional login methods rely on the combination of username and password. This method not only requires users to remember multiple complex passwords, which is prone to forgetting or misremembering, but also has security risks, such as passwords may be stolen or subjected to brute force attacks. At the same time, the password platforms of different cloud native vendors lack a unified secure passwordless login docking mechanism, making it cumbersome and inefficient for users to operate when accessing across platforms, and unable to log in to different platforms conveniently and securely to obtain corresponding services. In addition, although hardware security devices such as UKEY have been applied in identity authentication in some fields, they have not been fully integrated into the cross-platform passwordless login process, and it is difficult to meet the current login requirements that balance convenience and security in the cloud environment.
[0004] Therefore, how to provide a cross-platform passwordless login method and system based on UKey for national cryptography channels is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0005] In view of this, the present invention provides a cross-platform passwordless login method and system based on UKey for national cryptography channels, which can realize cross-platform passwordless login operations. In actual working scenarios, employees do not need to repeatedly enter cumbersome passwords between different platforms, greatly improving work efficiency. At the same time, the login method based on certificates and UKey also greatly improves security.
[0006] To achieve the above object, the present invention adopts the following technical solutions:
[0007] A cross-platform passwordless login method based on UKey for national cryptography channels, comprising:
[0008] The front end of the CPCS system verifies the UKey login. After passing the verification, the UKey serial number is obtained, and the back end of the CPCS system encrypts the UKey serial number with the SM2 public key of the cipher management platform;
[0009] The cipher management platform decrypts the UKey serial number with the SM2 private key of the cipher management platform and performs verification. After passing the verification, a session ID and a random number are generated;
[0010] The front end of the CPCS system signs the random number by calling the UKey control signature method, obtains the network information and hardware information of the current device. The back end of the CPCS system encrypts the signature value, network information and hardware information with the SM2 public key of the cipher management platform and then calls the cipher management platform. The cipher management platform obtains the UKey serial number through the session ID, extracts the UKey certificate, and verifies the signature value;
[0011] After the signature verification passes, the cipher management platform generates a login authorization code, decrypts the network information and hardware information with the SM2 private key of the cipher management platform, and then judges whether it is an operation in a common environment. If it is an uncommon environment, double password verification is triggered. Otherwise, the login authorization code is returned to the back end of the CPCS system;
[0012] The back end of the CPCS system signs the URL address parameters with the SM2 private key, splices the address signature value into the URL address of the cipher management platform, and calls the cipher management platform to verify the URL address parameters with the SM2 public key to generate a page token.
[0013] Preferably, the UKey login is verified through the front end of the CPCS system, which specifically includes:
[0014] Insert the UKey device, enter the UKey password, and call the UKey to verify the UKey password. If the UKey password input fails more than five times, the UKey is locked for ten minutes. If it exceeds fifteen times, the certificate is cleared.
[0015] Preferably, it is judged whether it is a common environment according to the Bayesian model, and the specific process is as follows:
[0016] Obtain the features in the hardware information and network information;
[0017] Statistical prior probabilities of historical data in common environments and prior probabilities of historical data in uncommon environments in historical data;
[0018] Calculate the probability of each feature appearing in common and uncommon environments respectively;
[0019] Calculate the probability of all feature combinations in the common environment based on the probability of each feature appearing in the common environment, and calculate the probability of all feature combinations in the uncommon environment based on the probability of each feature appearing in the uncommon environment;
[0020] Calculate the posterior probability of the common environment and the posterior probability of the uncommon environment based on the prior probability of historical data in the common environment, the prior probability of historical data in the uncommon environment, the probability of all feature combinations in the common environment, and the probability of all feature combinations in the uncommon environment;
[0021] Compare whether the posterior probability of the common environment is greater than or equal to the posterior probability of the uncommon environment. If it is satisfied, it is a common environment, otherwise it is an uncommon environment.
[0022] Preferably, the dual - factor authentication includes:
[0023] Input the user password, and the back - end of the CPCS system encrypts the user password through the SM2 public key of the cipher management platform;
[0024] After receiving the encrypted user password, the cipher management platform decrypts it through the SM2 private key of the cipher management platform and verifies whether the user password is consistent with the stored user hash password.
[0025] Preferably, it further includes:
[0026] A user configures multiple certificates, including a primary certificate and a backup certificate. When the UKey is lost and the UKey with the configured backup certificate is enabled, the primary certificate automatically becomes invalid:
[0027] When logging in with the UKey device inserted with the backup certificate, the cipher management platform determines that the current UKey is configured with a backup certificate, and then invalidates the primary certificate.
[0028] A national cipher channel cross - platform password - free login system based on UKey, including:
[0029] Login verification module: The front - end of the CPCS system verifies the UKey login. After passing the verification, it obtains the UKey serial number, and the back - end of the CPCS system encrypts the UKey serial number through the SM2 public key of the cipher management platform;
[0030] Serial number verification module: The cipher management platform decrypts the UKey serial number through the SM2 private key of the cipher management platform and conducts verification. After passing the verification, it generates a session ID and a random number;
[0031] Signature verification module: The front - end of the CPCS system signs the random number by calling the UKey control signature method, obtains the network information and hardware information of the current device. The back - end of the CPCS system encrypts the signature value, network information and hardware information through the SM2 public key of the cipher management platform and then calls the cipher management platform. The cipher management platform obtains the UKey serial number through the session ID, extracts the UKey certificate, and verifies the signature value;
[0032] Authorization code generation module: After passing the signature verification, the cipher management platform generates a login authorization code. After decrypting the network information and hardware information through the SM2 private key of the cipher management platform, it determines whether it is an operation in a common environment. If it is an operation in an uncommon environment, it triggers dual - factor authentication. Otherwise, it returns the login authorization code to the back - end of the CPCS system;
[0033] Page token acquisition module: The back - end of the CPCS system signs the URL address parameters through the SM2 private key, splices the address signature value into the URL address of the cipher management platform, and calls the cipher management platform to conduct SM2 public key verification on the URL address parameters to generate a page token.
[0034] Preferably, the CPCS system front-end is used to verify the UKey login, which specifically includes:
[0035] Insert the UKey device, enter the UKey password, and call the UKey to verify the UKey password. If the UKey password input fails more than five times, the UKey will be locked for ten minutes. If it fails more than fifteen times, the certificate will be cleared.
[0036] Preferably, a Bayesian model is used to determine whether it is a common environment. The specific process is as follows:
[0037] Obtain the features in the hardware information and network information;
[0038] Statistically analyze the prior probabilities of the common environments and non-common environments of the historical data in the historical data;
[0039] Calculate the probabilities of the appearance of each feature in the common environment and non-common environment respectively;
[0040] Based on the probabilities of the appearance of each feature in the common environment, calculate the combined probability of all features in the common environment. Based on the probabilities of the appearance of each feature in the non-common environment, calculate the combined probability of all features in the non-common environment;
[0041] Based on the prior probability of the common environment of the historical data, the prior probability of the non-common environment of the historical data, the combined probability of all features in the common environment, and the combined probability of all features in the non-common environment, calculate the posterior probability of the common environment and the posterior probability of the non-common environment;
[0042] Compare whether the posterior probability of the common environment is greater than or equal to the posterior probability of the non-common environment. If it is satisfied, it is a common environment; otherwise, it is a non-common environment.
[0043] Preferably, the dual password verification includes:
[0044] Enter the user password, and the back-end of the CPCS system encrypts the user password through the public key of the SM2 algorithm of the secret management platform;
[0045] After receiving the encrypted user password, the secret management platform decrypts it through the SM2 private key of the secret management platform and verifies whether the user password is consistent with the stored user hash password.
[0046] Preferably, it further includes:
[0047] A user configures multiple certificates, including a primary certificate and a backup certificate. When the UKey is lost and the UKey with the configured backup certificate is enabled, the primary certificate will automatically become invalid:
[0048] When a UKey device with a backup certificate is inserted for logging in, the key management platform determines that the current UKey is configured with a backup certificate and invalidates the primary certificate.
[0049] It can be seen from the above technical solution that, compared with the prior art, the present invention discloses a cross-platform password-free login method and system based on UKey national secret channel, which has the following advantages:
[0050] 1) The password platform page can be quickly connected to the cloud vendor page to ensure smooth application in diverse cross-platform environments such as different operating systems and different cloud service architectures, thereby achieving decoupling of business platform functions and password-free login.
[0051] 2) Use national secret channels to further ensure data transmission security.
[0052] 3) Innovative use of machine learning algorithms to judge common environments, further ensure security, and improve the reliability of identity authentication.
[0053] 4) The control adds processing logic after password input fails, providing a solution to password blasting
[0054] 5) Provide a primary and backup certificate solution. When the backup certificate is enabled, the primary certificate will automatically become invalid, which can deal with the possibility of identity fraud caused by the loss of UKey. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0056] Figure 1 A flow chart of a cross-platform password-free login method for a national secret channel based on UKey provided by the present invention.
[0057] Figure 2 A schematic diagram of a cross-platform password-free login system for a national secret channel based on UKey provided by the present invention. DETAILED DESCRIPTION
[0058] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0059] An embodiment of the present invention discloses a method for cross-platform passwordless login based on a UKey. Here, the UKey is a hardware device for identity authentication, which usually needs to be inserted and the password is entered for operation. In the present invention, it is mainly used for identity verification of cross-platform secure login. The interaction between data is carried out based on the SSL / TLS protocol of the national standard SM2 algorithm of elliptic curve cryptography (ECC). In the SSL / TLS protocol, the SM2 algorithm is used to implement encrypted communication of two-way channels, mainly to ensure the security and reliability of data during transmission. For example, Figure 1 as shown, it includes:
[0060] Before the user logs in using the UKey, it is necessary to install the UKey control on the user-side browser first. And import the certificate into the UKey through the UKey control, and configure the certificate for the corresponding user on the secret management platform. The secret management platform generates an SM2 key pair after deployment is completed.
[0061] The front end of the CPCS system verifies the UKey login. After passing the verification, it obtains the UKey serial number and sends the UKey serial number to the back end of the CPCS system. The back end of the CPCS (Cloud Platform Cryptosystem Service) system encrypts the UKey serial number with the SM2 public key of the secret management platform and sends it to the secret management platform after encryption.
[0062] The secret management platform decrypts the UKey serial number with the SM2 private key of the secret management platform and performs verification to verify whether the serial number is legal. After passing the verification, a session ID and a random number are generated. Among them, the session ID is bound to the UKey serial number and the random number. After the secret management platform generates the random number and returns it to the back end of the CPCS system, it is then returned to the front end of the CPCS system through the back end of the CPCS system, and the session information is stored in Redis (including validity period verification). The present invention generates a session ID to identify the user login session and verifies whether the session ID is valid, which can ensure the legality and security of the login session. The session ID is the unique identifier used to identify the user login session.
[0063] The front end of the CPCS system signs the random number by calling the UKey control signature method, obtains the network information and hardware information of the current device, and sends the signature value, network information and hardware information to the back end of the CPCS system. The back end of the CPCS system encrypts the signature value, network information and hardware information with the SM2 public key of the secret management platform and then calls the UKey login interface of the secret management platform. The secret management platform obtains the UKey serial number through the session ID, extracts the UKey certificate, and verifies the signature value; among them, the network information includes IP and MAC addresses, and the hardware information includes device fingerprints, etc.
[0064] After the signature verification is passed, the secure management platform calls the dynamic token service to generate a one-time login authorization code. After decrypting the network information and hardware information with the SM2 private key of the secure management platform, it determines whether it is an operation in a common environment. If it is an uncommon environment, double password verification is triggered. Otherwise, after the secure management platform passes the verification, it returns the login authorization code and splices the login authorization code into the URL of the secure management platform, and the user automatically jumps to the platform page; The present invention generates a one-time dynamic password based on time or events, which is used to generate a login authorization code after the signature verification is passed in the present invention, ensuring the uniqueness, reliability, and security of the authorization code.
[0065] (6)The front-end of the CPCS system calls the back-end of the CPCS system for SM2 private key signature. Specifically, the back-end of the CPCS system splices the login authorization code returned by the secure management platform on the URL address of the secure management platform, and then signs the entire URL address with its own SM2 private key of the CPCS system back-end to obtain a signature value, which is then spliced onto the URL address and returned to the front-end of the CPCS system. The front-end of the CPCS system accesses the address of the secure management platform. After receiving the request, the secure management platform verifies whether the login authorization code is valid and uses the SM2 public key of the CPCS system back-end to perform public key signature verification on the URL address parameters. After the signature verification is passed, it generates a token for the secure management platform page. A token is a credential used for authentication and authorization.
[0066] The user accesses the secure management platform with the token to complete the login process.
[0067] All business calls in the present invention are uniformly carried out using a national cryptography channel. In the present invention, the national cryptography channel is constructed based on openSSL and national cryptography algorithms. The commonly used encryption method in traditional SSL is RSA encryption. Different from this, the present invention selects the SM2 encryption algorithm, which can play an important role in the data transmission process and further enhance the security of data transmission. Moreover, for the back-end of the CPCS system and the secure management platform, the configuration work of national cryptography certificates needs to be completed, aiming to achieve two-way SSL authentication.
[0068] In this embodiment, the secure management platform determines whether it is a common environment according to the Bayesian model. The specific process is as follows:
[0069] 1) Select feature information. The features in device hardware information and network information mainly include: IP address, MAC address, network connection name, CPU name and main frequency, total system memory, system hard disk information, motherboard information.
[0070] 2) Statistically analyze the prior probabilities of common environments and uncommon environments in historical data. The prior probability of the common environment in historical data and the prior probability of the uncommon environment in historical data , the number of logins in the common environment is , the number of logins in the non - common environment is , the total number of logins is A.
[0071]
[0072] When there is no prior knowledge about "common environment" and "non - common environment", the non - informative prior assumption in Bayesian estimation can be adopted. A common method is to use the uniform distribution as the prior probability distribution, that is .
[0073] 3) For each feature , calculate the probability of the feature appearing in the "common environment" and "non - common environment" respectively. The number of times in the common environment is , the non - common environment the number of times is .
[0074]
[0075] When logging in for the first time, based on the initial assumption after Laplace smoothing, set , where represents the probability that the feature appears in the common environment, represents the probability that the feature appears in the non - common environment.
[0076] 4) Calculate the posterior probabilities of the common environment and the non - common environment . First, calculate the probability of the current feature combination in the common environment : , n is the number of features:
[0077]
[0078] Calculate the probability of the current feature combination in the non - common environment : :
[0079]
[0080] Then calculate the posterior probability of the common environment and the posterior probability of the non - common environment :
[0081]
[0082] Among them, k takes values of 1, 2.
[0083] 5) Finally, compare the posterior probabilities of the common environment and the posterior probability of the non - common environment in terms of magnitude. If it is greater than or equal to , it is a common environment; if it is less, it is a non - common environment. Subsequently, update the prior probability dynamically according to the frequencies of the common environment and the non - common environment.
[0084] If it is determined to be a non - common environment, the user needs to enter the user password for double - factor authentication, and then set this environment as a common environment. If it is a common environment, the secret management platform generates a unique login authorization code by calling the dynamic token service. The double - factor password authentication specifically includes:
[0085] The front - end page of the CPCS system in the non - common environment will prompt the user to enter the user password. After the user enters the user password, the back - end of the CPCS system encrypts the user password using the public key of the SM2 algorithm of the secret management platform. After receiving the encrypted user password, the secret management platform decrypts it using the private key of the SM2 algorithm of the secret management platform, and then verifies whether the password entered by the user matches the stored user hashed password through the matching of PBKDF2 (a password - based key derivation function used to securely store passwords by hashing multiple times).
[0086] This invention is based on Bayes' theorem and determines the common login environment through a Bayesian model. It collects multi - dimensional data such as network information (such as IP address, network name) and hardware information (such as device model, serial number) during historical logins as features, calculates the probabilities of each feature appearing in the common and non - common environments, constructs a Bayesian model, and assists in the password - free login decision, improving security and convenience.
[0087] In this embodiment, a user can configure multiple certificates, and the certificates have the concept of primary and backup. The primary - backup certificate type is automatically selected when the user imports the certificate. The user initially uses the UKey configured with the primary certificate for password - free login. When using the UKey configured with the backup certificate for login, it is defaulted that the UKey is lost. Specifically, when the UKey is lost and the UKey configured with the backup certificate is enabled, the primary certificate automatically becomes invalid. When logging in with the UKey device inserted with the backup certificate, the secret management platform determines that the current UKey is configured with the backup certificate, and then invalidates the primary UKey.
[0088] This invention can be applied in many fields, such as:
[0089] Application field of this patent
[0090] I. Enterprise - level cloud service platform
[0091] In various cloud service platforms used within an enterprise, employees need to frequently log in to different cloud application systems. Through the cross-platform secure passwordless login method based on UKey, employees only need to insert the UKey and enter the password to quickly and securely log in to the password platforms of various cloud-native manufacturers' pages, without having to remember multiple complex passwords, improving work efficiency and enhancing the security of enterprise data. For example, the enterprise's financial cloud system, human resources cloud system, etc. can all adopt this login method to ensure that sensitive business data is not illegally accessed.
[0092] II. Financial Technology Field
[0093] When financial institutions such as banks and securities conduct online business, it involves a large number of user fund transactions and sensitive information interactions. This patented technology can be applied to the customer login systems and internal employee operation platforms of financial institutions. For customers, using UKey for cross-platform secure passwordless login can effectively prevent account theft and fund theft; for internal employees of financial institutions, when operating the core business system, this secure login method can ensure the confidentiality, integrity, and non-repudiation of financial transaction data, meeting the strict security supervision requirements of the financial industry.
[0094] III. Government Affairs Cloud Platform
[0095] In the process of the government departments promoting digital government affairs construction, many government affairs application systems are deployed on the cloud platform. The login method of the present invention can be used for unified identity authentication of the government affairs cloud platform. When government staff handle government affairs documents, citizen information management, etc., through secure passwordless login with UKey, they can not only access different government affairs systems conveniently and quickly, but also prevent the leakage of government affairs data, safeguard national secrets and citizen privacy security, and improve the security and convenience of government affairs services.
[0096] IV. Medical Informatization System
[0097] In the medical industry, the information management systems within hospitals (such as HIS, LIS, PACS, etc.) and regional medical information sharing platforms all involve a large amount of patient privacy information. When medical staff, management personnel, and authorized medical research personnel access these systems, by using the cross-platform secure passwordless login technology based on UKey, it can ensure that only legitimate authorized personnel can log in to the system, prevent the illegal acquisition and abuse of patient information, and safeguard the security of medical data and the normal development of medical services.
[0098] The embodiment of the present invention discloses a cross-platform passwordless login system based on the national secret channel of UKey, as Figure 2 shown, including:
[0099] Login Verification Module: The front end of the CPCS system verifies the UKey login. After successful verification, the UKey serial number is obtained, and the back end of the CPCS system encrypts the UKey serial number with the SM2 public key of the Secret Management Platform;
[0100] Serial Number Verification Module: The Secret Management Platform decrypts the UKey serial number with the SM2 private key of the Secret Management Platform and performs verification. After passing the verification, a session ID and a random number are generated;
[0101] Signature Verification Module: The front end of the CPCS system signs the random number by calling the UKey control signature method, obtains the network information and hardware information of the current device. The back end of the CPCS system encrypts the signature value, network information and hardware information with the SM2 public key of the Secret Management Platform and then calls the Secret Management Platform. The Secret Management Platform obtains the UKey serial number through the session ID, extracts the UKey certificate, and verifies the signature value;
[0102] Authorization Code Generation Module: After passing the signature verification, the Secret Management Platform generates a login authorization code. After decrypting the network information and hardware information with the SM2 private key of the Secret Management Platform, it judges whether it is an operation in a common environment. If it is an operation in an uncommon environment, double password verification is triggered. Otherwise, the login authorization code is returned to the back end of the CPCS system;
[0103] Page Token Acquisition Module: The back end of the CPCS system signs the URL address parameters with the SM2 private key, splices the address signature value into the URL address of the Secret Management Platform, and calls the Secret Management Platform to verify the URL address parameters with the SM2 public key to generate a page token.
[0104] The specific details of the system of the present invention are the same as those of the above method and will not be elaborated here. Refer to the method part for details.
[0105] In this specification, each embodiment is described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple. Refer to the method part for relevant details.
[0106] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A cross-platform password-free login method for the national cryptography channel based on UKey, characterized in that, Including: The back end of the CPCS system and the cipher management platform complete the configuration of the national cipher certificate; The front end of the CPCS system verifies the UKey login. After successful verification, the UKey serial number is obtained. The back end of the CPCS system encrypts the UKey serial number with the SM2 public key of the cipher management platform; The cipher management platform decrypts the UKey serial number with the SM2 private key of the cipher management platform and performs verification. After passing the verification, a session ID and a random number are generated. The session ID is bound to the UKey serial number and the random number. After the cipher management platform generates the random number and returns it to the back end of the CPCS system, it is then returned to the front end of the CPCS system through the back end of the CPCS system; The front end of the CPCS system signs the random number by calling the UKey control signature method, obtains the network information and hardware information of the current device. The back end of the CPCS system encrypts the signature value, network information and hardware information with the SM2 public key of the cipher management platform and then calls the cipher management platform. The cipher management platform obtains the UKey serial number through the session ID, extracts the UKey certificate, and verifies the signature value; After passing the signature verification, the cipher management platform generates a login authorization code. The login authorization code is a one-time dynamic password. After decrypting the network information and hardware information with the SM2 private key of the cipher management platform, it is judged whether it is an operation in a common environment. If it is an uncommon environment, double password verification is triggered. Otherwise, the login authorization code is returned to the back end of the CPCS system; The back end of the CPCS system concatenates the login authorization code on the URL address of the cipher management platform, signs the entire concatenated URL address with its own SM2 private key of the back end of the CPCS system, splices the address signature value into the URL address of the cipher management platform, and calls the cipher management platform to perform SM2 public key verification on the URL address parameters of the back end of the CPCS system to generate a page token.
2. The cross-platform passwordless login method for the national cryptography channel based on UKey according to claim 1, wherein Verifying the UKey login through the front end of the CPCS system specifically includes: Insert the UKey device, enter the UKey password, and call the UKey to verify the UKey password. If the UKey password input fails more than five times, the UKey is locked for ten minutes. If it exceeds fifteen times, the certificate is cleared.
3. A cross-platform passwordless login method for the national cryptography channel based on UKey according to claim 1, characterized in that Judging whether it is a common environment according to the Bayesian model. The specific process is as follows: Obtain the features in the hardware information and network information; Statistical prior probabilities of historical data in common environments and prior probabilities of historical data in uncommon environments in historical data; Calculate the probabilities of each feature appearing in common environments and uncommon environments respectively; Calculate the probability of all feature combinations in the common environment based on the probability of each feature appearing in the common environment, and calculate the probability of all feature combinations in the uncommon environment based on the probability of each feature appearing in the uncommon environment; Calculate the posterior probability of the common environment and the posterior probability of the uncommon environment based on the prior probability of historical data in the common environment, the prior probability of historical data in the uncommon environment, the probability of all feature combinations in the common environment, and the probability of all feature combinations in the uncommon environment; Compare whether the posterior probability of the common environment is greater than or equal to the posterior probability of the uncommon environment. If it is satisfied, it is a common environment. Otherwise, it is an uncommon environment.
4. A cross-platform passwordless login method for the national cryptographic channel based on UKey according to claim 3, characterized in that, Double password verification includes: Enter the user password, and the CPCS system backend encrypts the user password with the SM2 public key of the cipher management platform; After receiving the encrypted user password, the cipher management platform decrypts it with the SM2 private key of the cipher management platform and verifies whether the user password is consistent with the stored user hash password.
5. A cross-platform passwordless login method for the national cryptographic channel based on UKey according to claim 1, characterized in that, It also includes: A user can configure multiple certificates, including a primary certificate and a backup certificate. When a UKey is lost and the UKey with the backup certificate configured is enabled, the primary certificate automatically becomes invalid: When logging in with the UKey device inserted with the backup certificate, the cipher management platform determines that the current UKey is configured with a backup certificate and invalidates the primary certificate.
6. A cross-platform passwordless login system with a national cryptographic channel based on UKey, characterized in that, It includes: National cipher certificate configuration module: used for the CPCS system backend and the cipher management platform to complete the configuration of the national cipher certificate; Login verification module: The CPCS system front-end verifies the UKey login. After successful verification, it obtains the UKey serial number, and the CPCS system backend encrypts the UKey serial number with the SM2 public key of the cipher management platform; Serial number verification module: The cipher management platform decrypts the UKey serial number with the SM2 private key of the cipher management platform and performs verification. After passing the verification, it generates a session ID and a random number. The session ID is bound to the UKey serial number and the random number. After the cipher management platform generates a random number and returns it to the CPCS system backend, it is then returned to the CPCS system front-end through the CPCS system backend; Signature verification module: The CPCS system front-end signs the random number by calling the UKey control signature method, obtains the network information and hardware information of the current device. The CPCS system backend encrypts the signature value, network information and hardware information with the SM2 public key of the cipher management platform and then calls the cipher management platform. The cipher management platform obtains the UKey serial number through the session ID, extracts the UKey certificate, and verifies the signature value; Authorization code generation module: After passing the signature verification, the cipher management platform generates a login authorization code. The login authorization code is a one-time dynamic password. After decrypting the network information and hardware information with the SM2 private key of the cipher management platform, it judges whether it is an operation in a common environment. If it is an operation in an uncommon environment, double password verification is triggered. Otherwise, the login authorization code is returned to the CPCS system backend; Page token acquisition module: The CPCS system backend concatenates the login authorization code on the URL address of the cipher management platform, signs the entire concatenated URL address with its own SM2 private key of the CPCS system backend, splices the address signature value into the URL address of the cipher management platform, and calls the cipher management platform to perform SM2 public key verification on the URL address parameters of the CPCS system backend to generate a page token.
7. A cross-platform passwordless login system for the national cryptographic channel based on UKey according to claim 6, characterized in that, Verify the UKey login through the CPCS system front-end, specifically including: Insert the UKey device, enter the UKey password, and call the UKey to verify the UKey password. If the UKey password input fails more than five times, the UKey is locked for ten minutes. If it exceeds fifteen times, the certificate is cleared.
8. The cross-platform passwordless login system for the national cryptographic channel based on UKey according to claim 6, wherein, Judge whether it is a common environment according to the Bayesian model. The specific process is as follows: Obtain the features in the hardware information and network information; Statistical prior probabilities of the historical data in the common environment and the historical data in the uncommon environment in the historical data; Calculate the probability of each feature occurring in the common environment and the non - common environment respectively; Calculate the probability of all feature combinations in the common environment based on the probability of each feature occurring in the common environment, and calculate the probability of all feature combinations in the non - common environment based on the probability of each feature occurring in the non - common environment; Calculate the posterior probability of the common environment and the posterior probability of the non - common environment based on the prior probability of the common environment in historical data, the prior probability of the non - common environment in historical data, the probability of all feature combinations in the common environment, and the probability of all feature combinations in the non - common environment; Compare whether the posterior probability of the common environment is greater than or equal to the posterior probability of the non - common environment. If it is satisfied, it is the common environment; otherwise, it is the non - common environment.
9. The cross-platform passwordless login system for the national cryptography channel based on UKey according to claim 8, characterized in that, The dual - password verification includes: Input the user password, and the backend of the CPCS system encrypts the user password with the public key of the SM2 algorithm of the secret management platform; After receiving the encrypted user password, the secret management platform decrypts it with the SM2 private key of the secret management platform and verifies whether the user password is consistent with the stored user hash password.
10. A cross-platform passwordless login system for the national cryptographic channel based on UKey according to claim 6, characterized in that, It also includes: A user configures multiple certificates, including the primary certificate and the backup certificate. When the UKey with the backup certificate is enabled due to the loss of the UKey, the primary certificate automatically becomes invalid: When logging in with the UKey device inserted with the backup certificate, the secret management platform determines that the current UKey is configured with a backup certificate, and then invalidates the primary certificate.
Citation Information
Patent Citations
Government affair cloud encryption login verification method based on national secret certificate and storage medium
CN115225350A
Cloud management platform two-factor identity authentication method and system based on national secret Ukey
CN115459925A