Multi-factor authentication method and system based on SM2 cryptographic algorithm

By constructing a signature algorithm under the framework of Guose SM2 algorithm, encrypting and signing multi-factor authentication messages, and combining multiple authentication factors to verify user identity, the problem of relying on foreign algorithms and computing in the existing technology is solved, and an efficient and secure multi-factor authentication solution is realized.

CN119945675AActive Publication Date: 2025-05-06NANKAI UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510118636.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-06
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

The existing multi-factor authentication scheme relies on foreign cryptographic algorithm standards, which violates the national development strategy of autonomous and controllable cyberspace security. At the same time, the direct deployment of the State Secret SM2 algorithm will lead to high computing overhead and communication costs, and reduce operational efficiency.

Method used

Under the framework of the National Secret SM2 encryption and signature algorithm, the signature algorithm based on National Secret SM2 is constructed, and the registration messages and authentication messages are encrypted and signed, ciphertexts and signatures are generated, and the user identity is verified based on multiple authentication factors.

Benefits of technology

It realizes that while improving the security and reliability of identity authentication, it reduces the computing overhead and communication cost of multi-factor authentication solutions, and improves the operating efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945675A_ABST
    Figure CN119945675A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-factor authentication method and system based on SM2. A key generation end generates a user end key, an authentication gateway end key and a server end key; the user side generates a user side registration request, a user side smart card, a user side login authentication request and a session key; the server side generates a server side authentication response and a session key; and the authentication gateway end generates an authentication gateway end registration response and an authentication gateway end authentication request. Compared with the prior art, the multi-factor authentication method has the advantages that 1) a key generation end, a user end, an authentication gateway end and a server end based on network connection use an SM2 signcryption algorithm to realize multi-factor authentication, meanwhile, the confidentiality and integrity of messages are ensured, and the calculation overhead is reduced; 2) session keys are generated at the user side and the server side at the same time, and communication between the user side and the server side is facilitated;
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of Internet security technology, and specifically relates to an authentication method and system based on the national secret SM2 algorithm. Background Art

[0002] Identity authentication is the first line of defense to ensure the security of information systems. It can effectively prevent unauthorized access and has been widely deployed and applied in important fields such as smart homes, autonomous driving and national defense. In identity authentication, three types of information are usually used to verify the user's identity: 1) known information, such as passwords; 2) biometric information, such as irises and fingerprints; 3) physical information held, such as smart cards. Multi-factor authentication uses two or more authentication factors to verify the user's identity, and can ensure the security and reliability of authentication even when some of the authentication factors are leaked. The current design of multi-factor authentication schemes often relies on foreign cryptographic algorithm standards, which does not conform to the national cyberspace security independent and controllable development strategy. As the international situation becomes increasingly severe, how to maintain cyberspace security sovereignty and achieve independent control of core technologies is an urgent problem to be solved. Constructing a multi-factor authentication scheme based on the national secret SM2 algorithm meets the development needs of independent and controllable core technologies, but directly deploying the SM2 algorithm will result in expensive computational overhead and communication costs for the multi-factor authentication scheme, which reduces the scheme's operating efficiency. Therefore, how to construct a multi-factor authentication scheme based on the national secret SM2 algorithm to improve the scheme's security while ensuring the scheme's operating efficiency is a key issue to be solved. Summary of the invention

[0003] In view of the defects of the prior art, the present invention aims to propose a multi-factor authentication method and system based on the national secret SM2 algorithm, construct a signcryption algorithm based on the national secret SM2 under the framework of the national secret SM2 encryption and signature algorithm, encrypt and sign the registration message and authentication message at the same time, generate the registration message and authentication message ciphertext and signature, which can ensure the confidentiality and integrity of the message at the same time; use multiple authentication factors to authenticate the user's identity, thereby improving the security and reliability of identity authentication.

[0004] In order to achieve the above-mentioned object of the invention, the present invention implements the following technical solutions:

[0005] In the first aspect, the present invention proposes a multi-factor authentication method based on the national secret SM2 algorithm, which is characterized by comprising the following process:

[0006] Step S1: input security parameters from the server end to the key generation end, obtain public parameters according to the security parameters received from the server end, input the user end identifier, the authentication gateway end identifier and the server end identifier from the user end, the authentication gateway end identifier and the server end identifier to the key generation end respectively, receive the user end identifier, the authentication gateway end identifier and the server end identifier, and then combine the public parameters to generate the user end key, the authentication gateway end key and the server end key, and output the user end key, the authentication gateway end key and the server end key;

[0007] Step S2: After the user terminal generates the user terminal key from the key generation end, the user terminal receives the public parameters, the user port command, the user terminal identifier, the user terminal biometrics, and the user terminal key, and generates a user terminal registration request, a user terminal login authentication request, and a session key according to the public parameters and the user terminal key received from the key generation end combined with the user port command, the user terminal identifier, and the user terminal biometrics, and outputs the user terminal registration request;

[0008] Step S3: After receiving the user authentication request from the user, the authentication gateway receives the user registration request, public parameters, and the authentication gateway key, generates an authentication gateway registration response and an authentication gateway authentication request according to the public parameters and the authentication gateway key received from the key generation end, and outputs the authentication gateway registration response;

[0009] Step S4: The user terminal receives the public parameters, the registration response of the authentication gateway terminal, and the user terminal key from the authentication gateway terminal, and outputs the user terminal smart card;

[0010] Step S5: The user terminal receives the user port command, the user terminal identifier, the user terminal biometric feature, the user terminal identifier and the user terminal key, and outputs a user terminal login authentication request;

[0011] Step S6: The authentication gateway receives the authentication request from the user, the authentication gateway key and the public parameters, and outputs the authentication gateway authentication request;

[0012] Step S7: The server receives the authentication gateway authentication request, the server key and the public parameters from the authentication gateway, generates a server authentication response and a session key, and outputs the server authentication response and the session key;

[0013] Step S8: The client receives the server authentication response, the client key and the public parameters from the server, and outputs the session key.

[0014] In some implementations, step S1 specifically includes the following process:

[0015] Step S1.1: Generate a large prime number p and an elliptic curve E from the security parameter λ on the server, where |p|=λ, |p| is the absolute value of p, and randomly select a q-order base point on the elliptic curve E to obtain a graph representation of the base point G=(x G ,y G ),in, Among them, x G ,y G Respectively represent the abscissa and ordinate of point G; represents the set {1,2,…,p-1} consisting of integers 1,2,…,p-1;

[0016] Step S1.2: Select three cryptographic hash functions H1: {0,1} * →{0,1} * , H3:{0,1} * →{0,1} v ; Among them, H1 will be {0,1} * The elements on are mapped to {0,1} * Random elements on; H2 will be {0,1} * The elements on are mapped to elements on; H3 will {0,1} * The elements on are mapped to {0,1} v Elements on {0,1} * Represents a string of arbitrary length, v represents the length of the session key, {0,1} v represents a string of length v; select the fuzzy extraction function (Gen(·), Rep(·)), where Gen() and Rep() convert {0,1} * The elements are mapped to {0,1} * , let public parameters params = {G, p, H1, H2, H3, Gen (·), Rep (·)};

[0017] Step S1.3: Input public parameters params = {G, p, H1, H2, H3, Gen (·), Rep (·)} and user terminal ID to the key generation end UE , Authentication gateway ID AG and the server-side ID SR , randomly selected Calculate the user key PK UE =d UE G=(x UE ,y UE ), authentication gateway key PK AG =d AG G=(x AG ,yAG ) and the server-side key PK SR =d SR G=(x SR ,y SR ), output the user key (PK UE ,SK UE )=((x UE ,y UE ),d UE ), authentication gateway key (PK AG ,SK AG )=((x AG ,y AG ),d AG ) and the server-side key (PK SR ,SK SR )=((x SR ,y SR ),d SR ); let params = {G, p, H1, H2, H3, PK UE ,PK AG ,PK SR}; where d UE ,d AG ,d SR They represent integers randomly selected from the set {1,2,…,p-1}; x UE ,y UE Respectively represent point d UE The horizontal and vertical coordinates of G; x AG ,y AG Respectively represent point d AG The horizontal and vertical coordinates of G; x SR ,y SR Respectively represent point d SR The horizontal and vertical coordinates of G.

[0018] In some implementations, step S2 specifically includes the following process:

[0019] Step S2.1: The user receives the user key (PK UE ,SK UE ), fuzzy extraction function (Gen, Rep) and public parameters params, the biometric feature is mapped to Elements on;

[0020] Step S2.2: Perform fuzzy extraction on the user side to obtain the user-side biometric Gen(BIO UE )=(σ UE ,θ UE ), user port command hash password HPWUE =H1(PW UE ||σ UE ), user identification hash password MID UE =H1(ID UE ||σ UE ) is calculated, where σ UE Indicates biometrics BIO UE The secret string obtained after the fuzzy extraction function Gen(·) is calculated, θ UE Indicates biometrics BIO UE The public string obtained after the fuzzy extraction function Gen(·) is used; PW UE ||σ UE Indicates the password PW UE With the secret string σ UE The value after cascade operation, HPW UE Indicates PW UE ||σ UE The hash value obtained after the hash function H1 operation, ID UE ||σ UE Indicates ID UE With the secret string σ UE Cascade operation of MID UE Representation ID UE ||σ UE The hash value obtained after the hash function H1 is used; ∥ indicates a cascade operation;

[0021] Step S2.3: Randomly select Y UE ∈{0,1} * , Let M1 = Y UE ||MID UE ||HPW UE , calculate e1=H3(M1,r1), C1=r1G=(x1,y1), k1=(e1+x1)mod p, s1=(1+d UE ) -1 (r1-k1d UE )mod p,r1PK AG =(x A1 ,y A1 ), t1=H2(x A1 ||y A1 ,p), Where T1 represents the current timestamp; let CT1 = C1||C2||C3, MT1 = {CT1, k1, s1, T1}; where Y UE Represents the set {0,1} *Any length string randomly selected from the set An integer randomly selected from, M1 represents Y UE 、MID UE and HPW UE The value after the cascade operation, e1 represents the value of M1 and r1 after the hash function H3 operation, C1 represents the point on the elliptic curve, x1, y1 represent the horizontal coordinate and vertical coordinate of point C1 respectively, k1 represents the value of the sum of e1 and x1 after the modulo p operation, s1 represents the sum of 1 and d UE The inverse element of the sum and (r1-k1d UE ) after multiplication and modulo p operation, x A1 ,y A1 Respectively represent the points r1PK AG The horizontal and vertical coordinates of t1 represent x A1 and A1 The concatenation value of M1 and T1 and the value after the hash function H2 is used to calculate p. C2 represents the concatenation value of M1 and T1 and the value after the XOR operation of t1. H2(x A1 ||M1||y A1 ) represents x A1 , M1 and y A1 The cascade operation value is the value after the hash function H2 is operated. C3 represents the hash value H2(x A1 ||M1||y A1 ) and e1 after XOR operation, CT1 represents the value after C1, C2 and C3 are cascaded. represents XOR operation, and mod represents modulo operation.

[0022] In some implementations, step S3 specifically includes the following process:

[0023] Step S3.1: The authentication gateway receives the user registration request MT1, and the authentication gateway key (PK AG ,SK AG ) and public parameters params;

[0024] Step S3.2: Verify whether T1 is fresh through the authentication gateway; if T1 does not meet the freshness requirement, the authentication gateway rejects the user's registration request MT1; otherwise, calculate d AG C1=(x A1 ,y A1 ), t1=H2(x A1 ||y A1 ,p), w1=(k1+s1)mod p,(x1,y1)=s1G+w1PK UE , where t1 represents xA1 The concatenated value of M1 and the hash value of p after the hash function H2 is applied. e1 represents the hash value H2(x A1 ||M1||y A1 ) is the value after XOR operation with C3, w1 is the value after modulo p operation of the sum of k1 and s1, (x1, y1) is the point s1G+w1PK UE The horizontal and vertical coordinates of

[0025] Step S3.3: Verify whether the equation k1 = (e1 + x1) mod p holds through the authentication gateway. If the equation holds, {M1, k1, s1} is successfully restored. The authentication gateway randomly selects a UE ,PID UE ∈{0,1} * , calculate Among them, a UE ,PID UE Respectively represent from the set {0,1} * A string of any length randomly selected from the set An integer randomly selected from H1(MID UE ) indicates MID UE The hash value after the hash function H1 is calculated, H1(HPW UE ) indicates HPW UE The hash value after the hash function H1 is calculated, CR1 represents the hash value H1 (MID UE ) and hash value H1(HPW UE ) after XOR operation and modulo n p The calculated value is the value after the hash function H1 is calculated again, and CR2 represents a UE The value after XOR operation with CR1;

[0026] Step S3.4: Create an identifier MID through the authentication gateway UE List UE ={MID UE ,a UE , Honeyword={}}, let M2=CR1||CR2, randomly select Calculate e2 = H3 (M2, r3), C4 = r3G = (x2, y2), k2 = (e2 + x2) mod p, s2 = (1 + d AG ) -1 (r3-k2d AG )mod p,r3PK UE =(x U1 ,y U1), t2=H2(x U1 ||y U1 ,p), Where T2 represents the current timestamp; let CT2 = C4||C5||C6, MT2 = {CT2, k2, s2, T2}, where M2 represents the value after cascade operation of CR1 and CR2, r3 represents the value from the set An integer randomly selected from the matrix, e2 represents the value of M2 and r3 after the hash function H3 is applied, x2 and y2 represent the horizontal and vertical coordinates of point C4 respectively, k2 represents the value of the sum of e2 and x2 modulo p, and s2 represents the sum of 1 and d AG The inverse element of the sum and (r1-k1d UE ) after multiplication and modulo p operation, x U1 ,y U1 Representation point r3PK UE The horizontal and vertical coordinates of t2 represent x U1 With y U1 The concatenated value of M1 and T2 and the hash value of p after the hash function H2 is used. C5 represents the concatenated value of M1 and T2 and the value after the XOR operation of t2. H2(x U1 ||M2||y U1 ) represents x U1 , M2 and y U1 The cascade operation value of is the value after the hash function H2 is operated. C6 represents the hash value H2(x A1 ||M1||y A1 ) is the value after XOR operation with e2, and CT2 is the value after cascade operation of C4, C5 and C6.

[0027] 1. According to claim 1, a multi-factor authentication method based on the national secret SM2 algorithm is characterized in that the step S4 specifically includes the following process:

[0028] Step S4.1: The user receives the authentication gateway registration response MT2, public parameters params and the user key (PK UE ,SK UE );

[0029] Step S4.2: The user terminal verifies whether T2 is fresh. If T2 does not meet the freshness requirement, the user terminal rejects the registration response. Otherwise, calculate d UE C4=(x U1 ,y U1 ), t2=H2(x U1 ||y U1 ,p), w2=(k2+s2)mod p,(x2,y2)=s2G+w2PKAG , where x U1 ,y U1 Respectively represent point d UE The horizontal and vertical coordinates of C4, t2 represents x U1 With y U1 The concatenated value of and the hash value of p after the hash function H2 is calculated. M2||T2 represents the value after the XOR operation of C5 and t2. H2(x U1 ||M2||y U1 ) represents x U1 , M2 and y U1 The cascade operation value of is the value after the hash function H2 is operated, and e2 represents the hash value H2(x U1 ||M2||y U1 ) is the value after XOR operation with C6, w2 is the value after modulo p operation of the sum of k2 and s2, x2, y2 are the points s2G+w2PK AG The horizontal and vertical coordinates of

[0030] Step S4.3: The user terminal verifies whether the equation k2 = (e2 + x2) mod p holds. If the equation holds, M2 is successfully recovered. The user terminal calculates SC UE ={M2,N UE ,θ UE ,Gen(·),Rep(·)}, where k1 represents the value of the sum of e2 and x2 after modulo p operation, M2 represents the message transmitted from the authentication gateway to the user, and H1(HPW UE ||ID UE ||σ UE ) indicates HPW UE 、ID UE With σ UE The cascade operation value of is the value after the hash function H1 operation, N UE Indicates MID UE With hash value H1(HPW UE ||ID UE ||σ UE ) after XOR operation, θ UE Indicates biometrics BIO UE The public string is obtained after the fuzzy extraction function Gen(·) is used to calculate. Gen(·), Rep(·) represents the fuzzy extraction function, SC UE Indicates the user's smart card ID.

[0031] In some implementations, step S5 specifically includes the following process:

[0032] Step S5.1: The user terminal receives the user terminal identification ID UE∈{0,1} * , User port command PW UE ∈{0,1} * , User-side biometrics BIO UE ∈{0,1} * , User-side smart card identification SC UE 、User key (PK UE ,SK UE ) and public parameters params;

[0033] Step S5.2: Calculate σ by the user end UE =Rep(BIO UE ,θ UE ), HPW UE =H1(PW UE ||σ UE ), Among them, δ UE Indicates biometrics BIO UE The secret string obtained after the fuzzy extraction function Rep(·) is calculated, HPW UE Indicates PW UE With σ UE The cascade operation value of is the value after the hash function H1 is operated, H1 (HPW UE |‖ID UE ‖|σ UE ) indicates HPW UE 、ID UE and σ UE The cascade operation value of MID is the value after the hash function H1 is used to operate. UE Indicates smart card parameter N UE With hash value H1(HPW UE ||ID UE ||σ UE ) after XOR operation, H1(MID UE ) indicates MID UE The hash value after the hash function H1 is calculated, H1(HPW UE ) indicates HPW UE The hash value after the hash function H1 operation is: Indicates the hash value H1(MID UE ) and hash value H1(HPW UE ) after XOR operation and modulo n p The calculated value is the value after the hash function H1 is used again;

[0034] Step S5.3: User-side verification equation If not, the login request is rejected; otherwise, the user terminal randomly selects Let M3 = MID UE ||r3||ID SR , where r3 represents the An integer randomly selected from the UE , r3 and ID SR The value after the cascade operation;

[0035] Step S5.4: The user terminal calculates e3 = H3 (M3, r3), C7 = r3G = (x3, y3), k3 = (e3 + x3) mod p, s3 = (1 + d UE ) -1 (r3-k3d UE )mod p,r3PK AG =(x A2 ,y A2 ), t3=H2(x A2 ||y A2 ,p), Where T3 represents the current timestamp; let CT3 = C7||C8||C9, MT3 = {CT3, k3, s3, T3}; where e3 represents the value of M3 and r3 after the hash function H3 operation, x3, y3 represent the horizontal and vertical coordinates of point C7 respectively, k3 represents the value of the sum of e3 and x3 after the modulo p operation, s3 represents the sum of 1 and d UE The inverse element of the sum and (r3-k3d UE ) after multiplication and modulo p operation, x A2 ,y A2 Representation point r3PK AG The horizontal and vertical coordinates of t3 represent x A2 With y A2 The concatenated value of M3 and T3 and the hash value of p after the hash function H2 is used. C8 represents the concatenated value of M3 and T3 and the value after the XOR operation of t3. A2 ||M3||y A2 ) represents x A2 , M3 and y A2 The cascade operation value of is the value after the hash function H2 is operated. C9 represents the hash value H2(x A2 ||M3||y A2 ) is the value after XOR operation with e3, CT3 is the value after cascade operation of C7, C8 and C9, and MT3 is the set consisting of CT3, k3, s3 and T3.

[0036] In some implementations, step S6 specifically includes the following process:

[0037] Step S6.1: The authentication gateway receives the authentication request MT3 from the user, and the authentication gateway key (PK AG ,SK AG ), public parameters params;

[0038] Step S6.2: The authentication gateway verifies whether T3 is fresh. If T3 does not meet the freshness requirement, the authentication gateway rejects the user's authentication request. Otherwise, calculate d AG C7=(x A2 ,y A2 ), t3=H2(x A2 ||y A2 ,p), w3=(k3+s3)mod p,(x3,y3)=s3G+w3PK UE , where x A2 ,y A2 Respectively represent point d AG The horizontal and vertical coordinates of C7, t3 represents x A2 With y A2 The concatenated value of and the hash value of p after the hash function H2 is calculated. M3||T3 represents the value after the XOR operation of C8 and t3. H2(x A2 ||M3||y A2 ) represents x A2 , M3 and y A2 The cascade operation value of is the value after the hash function H2 is operated, and e3 represents the hash value H2(x A2 ||M3||y A2 ) and C9 after XOR operation, w3 represents the value after modulo p operation of the sum of k3 and s3, x3, y3 represent the point s2G+w2PK AG The horizontal and vertical coordinates of

[0039] Step S6.3: The authentication gateway verifies whether the equation k3 = (e3 + x3) mod p holds. If not, the authentication request is rejected; otherwise, the authentication gateway successfully recovers M3, where k3 represents the value of the sum of e3 and x3 after the modulo p operation, and M3 represents the message transmitted by the user end to the authentication gateway end;

[0040] Step S6.4: Authentication gateway randomly selects Let M4 = MID UE ||r4||ID SR , calculate e4 = H3 (M4, r4), C 10 =r4G=(x4,y4), k4=(e4+x4)mod p, s4=(1+d AG ) -1 (r4-k4dAG )mod p,r4PK SR =(x S1 ,y S1 ), t4=H2(x S1 ||y S1 ,p), Where T4 represents the current timestamp; let CT4 = C 10 |‖C 11 ‖|C 12 , MT4={CT4,k4,s4,T4}; where r4 represents the An integer randomly selected from the UE , r4 and ID SR The value after the cascade operation, e4 represents the value of M4 and r4 after the hash function H3 operation, x4, y4 represent the point C 10 The horizontal and vertical coordinates of the , k4 represents the value of the sum of e4 and x4 after the modulo p operation, s4 represents the sum of 1 and d AG The inverse element of the sum and (r4-k4d AG ) after multiplication and modulo p operation, x S1 ,y S1 Indicates point r4PK SR The horizontal and vertical coordinates of t4 represent x S1 With y S1 The concatenated value of p and the hash value of p after the hash function H2 is calculated, C 11 It represents the value after XOR operation of the cascade operation value of M4 and T4 and t4, H2(x S1 ||M4||y S1 ) represents x S1 , M4 and y S1 The value after the cascade is calculated by the hash function H2, C 12 Represents the hash value H2(x S1 ||M4||y S1 ) and e4 after XOR operation, CT4 represents C 10 , C 11 and C 12 After the cascade operation, the value in MT4 is represented by the set consisting of CT4, k4, s4, and T4.

[0041] In some implementations, step S7 specifically includes the following process:

[0042] Step S7.1: The server receives the authentication request from the authentication gateway MT4, and the server key (PK SR ,SK SR ), and public parameters params;

[0043] Step S7.2: The server verifies whether T3 is fresh. If T3 does not meet the freshness requirement, the server rejects the authentication request from the authentication gateway. Otherwise, calculate d SR C 10 =(x S1 ,y S1 ), t4=H2(x S1 ||y S1 ,p), w4=(k4+s4)mod p,(x4,y4)=s4G+w4PK AG , where x S1 ,y S1 Respectively represent point d SR C 10 The horizontal and vertical coordinates of t4 represent x S1 With y S1 The concatenated value of p and the hash value of p after the hash function H2 is calculated. M4||T4 represents C 11 The value after XOR operation with t4, H2(x S1 ||M4||y S1 ) represents x S1 , M4 and y S1 The cascade operation value of is the value after the hash function H2 is operated. e4 represents the hash value H2(x S1 |‖M4‖|y S1 ) and C 12 The value after XOR operation, w4 represents the value after modulo p operation of the sum of k4 and s4, x4, y4 represent the point s2G+w2PK AG The horizontal and vertical coordinates of

[0044] Step S7.3: The server verifies whether the equation k4 = (e4 + x4) mod p holds. If not, the authentication request is rejected; otherwise, the server successfully recovers M4, where k4 represents the value of the sum of e4 and x4 after the modulo p operation, and M4 represents the message transmitted by the authentication gateway to the server;

[0045] Step S7.4: Random selection by the server Let M5 = MID UE ||r5||ID SR , calculate e5 = H3 (M5, r5), C 13 =r5G=(x5,y5), k5=(e5+x5)modp, s5=(1+d SR ) -1 (r5-k5d SR )mod p,r5PK UE=(x U2 ,y U2 ), t5=H2(x U2 ||y U2 ,p), Among them, T5 represents the current timestamp, r5 represents the An integer randomly selected from the UE , r5 and ID SR The value after the cascade operation, e5 represents the value of M5 and r5 after the hash function H3 operation, x5, y5 represent the point C 13 The horizontal and vertical coordinates of the , k5 represents the value of the sum of e5 and x5 after the modulo p operation, s5 represents the sum of 1 and d SR The inverse element of the sum and (r5-k5d SR ) after multiplication and modulo p operation, x U2 ,y U2 Indicates point r5PK UE The horizontal and vertical coordinates of t5 represent x U2 With y U2 The concatenated value of p and the hash value of p after the hash function H2 is calculated, C 14 It represents the value after XOR operation of the cascade operation value of M5 and T5 and t5, H2(x U2 ||M5||y U2 ) represents x U2 , M5 and y U2 The cascade operation value of is the value after the hash function H2 is operated, C 15 Represents the hash value H2(x U2 ||M5||y U2 ) and the value after XOR operation with e5;

[0046] Step S7.5: The server calculates the session key SK=H1(r3||r5||ID SR ||MID UE ,p), let CT5=C 13 ||C 14 ||C 15 , MT5={CT5,k5,s5,T5}, where CT5 represents C 13 , C 14 and C 15 After the cascade operation, the value of MT5 is represented by the set consisting of CT5, k5, s5, and T5.

[0047] In some implementations, step S8 specifically includes the following process:

[0048] Step S8.1: The client receives the server authentication response MT5, the client key (PK UE ,SK UE ), and public parameters params;

[0049] Step S8.2: The user verifies whether T5 is fresh: If T5 does not meet the freshness requirement, the user rejects the server authentication response; otherwise, calculate d UE C 13 =(x U2 ,y U2 ), t5=H2(x U2 ||y U2 ,p), w5=(k5+s5)mod p,(x5,y5)=s5G+w5PK SR , where x U2 ,y U2 Respectively represent point d UE C 13 The horizontal and vertical coordinates of t5 represent x U2 With y U2 The concatenated value of p and the hash value of p after the hash function H2 is calculated. M5||T5 represents C 14 The value after XOR operation with t5, H2(x U2 |‖M5‖|y U2 ) represents x U2 , M5 and y U2 The cascade operation value of is the value after the hash function H2 is operated, and e5 represents the hash value H2 (x U2 |‖M5‖|y U2 ) and C 15 The value after XOR operation, w5 represents the value after modulo p operation of the sum of k5 and s5, x5, y5 represents the point s5G+w5PK SR The horizontal and vertical coordinates of

[0050] Step S8.3: The user end verifies whether the equation k5=(e5+x5) mod p holds. If the equation holds, the message M5 is successfully recovered. The user end calculates the session key SK=H1(r3||r5||ID SR ||MID UE ,p), where k5 represents the value of the sum of e5 and x5 after modulo p operation, and M5 represents the message transmitted from the server to the user.

[0051] In the second aspect, the present invention proposes a multi-factor authentication system based on the national secret SM2 algorithm, and implements a multi-factor authentication method based on the national secret SM2 algorithm. The system includes a key generation end, a user end, an authentication gateway end and a server end connected to the network; the key generation end and the user end are respectively connected to the server end, the server end is connected to the authentication gateway end, and the user end is connected to the authentication gateway end;

[0052] The key generation end is used to obtain public parameters according to the security parameters received from the server end, and receives the user end identifier, the authentication gateway end identifier and the server end identifier from the user end, the authentication gateway end and the server end respectively, and then combines the public parameters to generate the user end key, the authentication gateway end key and the server end key, and outputs them; specifically, the user end key is composed of the public parameters and the user end identifier, the authentication gateway end key is composed of the public parameters and the authentication gateway end identifier, and the server end key is composed of the public parameters and the server end identifier;

[0053] The user end is used to generate a user end registration request, a user end smart card, a user end login authentication request and a session key according to the public parameters and the user end key received from the key generation end, combined with the user end identifier, the user end biometric features, the user end key and the public parameters after receiving the server end authentication response from the server end, and output them; specifically, the user end registration request is composed of the user end identifier, the user end identifier, the user end biometric features, the user end key and the public parameters; the user end smart card is composed of the authentication gateway end registration response, the user end key and the public parameters; the user end login authentication request is composed of the user end identifier, the user end identifier, the user end biometric features, the user end key, the user end smart card and the public parameters; the session key is composed of the public parameters, the server end authentication response and the user end key;

[0054] The server is used to generate a server-side authentication response and a session key after receiving an authentication request from an authentication gateway, a server-side key and public parameters from an authentication gateway, and output them; specifically, the server-side authentication response is at least composed of the authentication request from the authentication gateway, the server-side key and the public parameters; the session key is composed of the public parameters, the server-side authentication response and the user-side key;

[0055] The authentication gateway is used to generate an authentication gateway registration response and an authentication gateway authentication request based on the public parameters and the authentication gateway key received from the key generation end after receiving a user authentication request from the user end, and output them; specifically, the authentication gateway registration response consists of the user registration request, the authentication gateway key and the public parameters, and the authentication gateway authentication request consists of the user authentication request, the authentication gateway key and the public parameters.

[0056] Compared with the prior art, the advantages of this application are:

[0057] 1) The key generation end, user end, authentication gateway end and server end based on network connection use SM2 signcryption algorithm to implement multi-factor authentication, while ensuring the confidentiality and integrity of the message and reducing the computational overhead.

[0058] 2) The session key is generated simultaneously on the user side and the server side, which is beneficial to the communication between the user side and the server side. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 This is an overall flow chart of a multi-factor authentication method based on the national secret SM2 of the present invention;

[0060] Figure 2 This is a multi-factor authentication system architecture diagram based on the national secret SM2 of the present invention;

[0061] Figure 3 This is an algorithm block diagram of an embodiment of a multi-factor authentication system and method based on the national encryption SM2 of the present invention. DETAILED DESCRIPTION

[0062] The technical solution of the present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0063] like Figure 1 As shown, a multi-factor authentication method based on the national secret SM2 of the present invention specifically includes the following processes:

[0064] Step S1: input security parameters to the key generation end, receive the security parameters through the key generation end, output public parameters, input the public parameters, user terminal identifier, authentication gateway terminal identifier and server terminal identifier to the key generation end again, generate and output the user terminal key, authentication gateway terminal key and server terminal key, and generate the user terminal key (PK) through the key generation end UE ,SK UE ), authentication gateway key (PK AG ,SK AG ) and the server key (PK SR ,SK SR ); Specifically, the user-side key (PK UE ,SK UE ) consists of at least public parameters params and client ID UE The authentication gateway key (PK AG ,SK AG ) at least consists of public parameters params and authentication gateway ID AG The server-side key (PKSR ,SK SR ) consists of at least public parameters params and server-side identifier ID SR Further, the generated public parameter params is composed of at least a security parameter λ; wherein λ represents the bit length of the system input value; step S1 specifically comprises the following steps:

[0065] Step S1.1: The key generation end receives the security parameter λ from the server end, generates a large prime number p and an elliptic curve E, where |p|=λ, |p| is the absolute value of p, and randomly selects a q-order base point on the elliptic curve E to obtain a base point graph representation G=(x G ,y G ),in, Among them, x G ,y G Respectively represent the abscissa and ordinate of point G; represents the set {1,2,…,p-1} consisting of integers 1,2,…,p-1. G ,y G denote the horizontal and vertical coordinates of point G respectively, Represents the set {1,2,…,p-1} consisting of the integers 1,2,…,p-1.

[0066] Step S1.2: The key generation end selects three cryptographic hash functions H1: {0,1} * →{0,1} * , H3:{0,1} * →{0,1} v ; Among them, H1 will be {0,1} * The elements on are mapped to {0,1} * Random elements on; H2 will be {0,1} * The elements on are mapped to elements on; H3 will {0,1} * The elements on are mapped to {0,1} v Elements on {0,1} * Represents a string of arbitrary length, v represents the length of the session key, {0,1} v represents a string of length v; select the fuzzy extraction function (Gen(·), Rep(·)), where Gen() and Rep() convert {0,1} * The elements are mapped to {0,1} * Let public parameters params = {G, p, H1, H2, H3, Gen (·), Rep (·)};

[0067] Step S1.3: Input public parameters params = {G, p, H1, H2, H3, Gen (·), Rep (·)} and user terminal ID to the key generation end UE , Authentication gateway ID AG and the server-side ID SR , randomly selected Calculate the user key PK UE =d UE G=(x UE ,y UE ), authentication gateway key PK AG =d AG G=(x AG ,y AG ) and the server-side key PK SR =d SR G=(x SR ,y SR ), output the user key (PK UE ,SK UE )=((x UE ,y UE ),d UE ), authentication gateway key (PK AG ,SK AG )=((x AG ,y AG ),d AG ) and the server-side key (PK SR ,SK SR )=((x SR ,y SR ),d SR ); let params = {G, p, H1, H2, H3, PK UE ,PK AG ,PK SR}; where d UE ,d AG ,d SR They represent integers randomly selected from the set {1,2,…,p-1}; x UE ,y UE Respectively represent point d UE The horizontal and vertical coordinates of G; x AG ,y AG Respectively represent point d AG The horizontal and vertical coordinates of G; x SR ,y SR Respectively represent point d SR The horizontal and vertical coordinates of G;

[0068] Step S1.4: The key generation end outputs public parameters params = {G, p, H1, H2, H3, Gen (·), Rep (·)} to the user end, and the user end key (PK UE ,SK UE ), authentication gateway key (PK AG ,SK AG ) and the server key (PK SR ,SK SR );

[0069] Step S2: Receive the public parameters params and the client key (PK) from the client UE ,SK UE ) after which the user terminal registration request MT1 is output to the authentication gateway terminal; specifically, the user terminal key (PK UE ,SK UE ) contains at least the client ID UE ∈{0,1} * , User port command PW UE ∈{0,1} * and user-side biometrics BIO UE ∈{0,1} * , step S2 specifically includes the following steps:

[0070] Step S2.1: The user receives the user key (PK UE ,SK UE ), fuzzy extraction function (Gen, Rep) and public parameters params, the fuzzy extraction function (Gen, Rep) is used to map the biometric features to The user key (PK UE ,SK UE ) contains at least the client ID UE ∈{0,1} * , User port command PW UE ∈{0,1} * , User-side biometrics BIO UE ∈{0,1} * ;

[0071] Step S2.2: Perform fuzzy extraction on the user side to obtain the user-side biometric Gen(BIO UE )=(σ UE ,θ UE ), user port command hash password HPW UE =H1(PW UE ||σ UE ), user identification hash password MID UE =H1(IDUE ||σ UE ) is calculated, where σ UE Indicates biometrics BIO UE The secret string obtained after the fuzzy extraction function Gen(·) is calculated, θ UE Indicates biometrics BIO UE The public string obtained after the fuzzy extraction function Gen(·) is used; PW UE ||σ UE Indicates the password PW UE With the secret string σ UE The value after cascade operation, HPW UE Indicates PW UE ||σ UE The hash value obtained after the hash function H1 operation, ID UE ||σ UE Indicates ID UE With the secret string σ UE Cascade operation of MID UE Representation ID UE ||σ UE The hash value obtained after the hash function H1 is used; ∥ indicates a cascade operation;

[0072] Step S2.3: Randomly select Y UE ∈{0,1} * , Let M1 = Y UE ||MID UE ||HPW UE , calculate e1=H3(M1,r1), C1=r1G=(x1,y1), k1=(e1+x1)mod p, s1=(1+d UE ) -1 (r1-k1d UE )mod p,r1PK AG =(x A1 ,y A1 ), t1=H2(x A1 ||y A1 ,p), Where T1 represents the current timestamp; let CT1 = C1||C2||C3, MT1 = {CT1, k1, s1, T1}; where Y UE Represents the set {0,1} * Any length string randomly selected from the set An integer randomly selected from, M1 represents Y UE 、MID UE and HPWUE The value after the cascade operation, e1 represents the value of M1 and r1 after the hash function H3 operation, C1 represents the point on the elliptic curve, x1, y1 represent the horizontal coordinate and vertical coordinate of point C1 respectively, k1 represents the value of the sum of e1 and x1 after the modulo p operation, s1 represents the sum of 1 and d UE The inverse element of the sum and (r1-k1d UE ) after multiplication and modulo p operation, x A1 ,y A1 Respectively represent the points r1PK AG The horizontal and vertical coordinates of t1 represent x A1 and A1 The concatenation value of M1 and T1 and the value after the hash function H2 is used to calculate p. C2 represents the concatenation value of M1 and T1 and the value after the XOR operation of t1. H2(x A1 ||M1||y A1 ) represents x A1 , M1 and y A1 The cascade operation value is the value after the hash function H2 is operated. C3 represents the hash value H2(x A1 ||M1||y A1 ) and e1 after XOR operation, CT1 represents the value after C1, C2 and C3 are cascaded. represents XOR operation, mod represents modulo operation;

[0073] Step S2.3: The user terminal sends the user terminal registration request MT1 and the authentication gateway terminal key (PK AG ,SK AG ) and public parameters params;

[0074] Step S3: Receive the user registration request MT1 and the authentication gateway key (PK) through the authentication gateway. AG ,SK AG ) and public parameters params, output the authentication gateway registration response MT2 to the user end; step S3 specifically includes the following steps:

[0075] Step S3.1: The authentication gateway receives the user registration request MT1, and the authentication gateway key (PK AG ,SK AG ) and public parameters params;

[0076] Step S3.2: Verify whether T1 is fresh through the authentication gateway; if T1 does not meet the freshness requirement, the authentication gateway rejects the user's registration request MT1; otherwise, calculate d AG C1=(x A1 ,y A1 ), t1=H2(xA1 ||y A1 ,p), w1=(k1+s1)mod p,(x1,y1)=s1G+w1PK UE , where t1 represents x A1 The concatenated value of M1 and the hash value of p after the hash function H2 is applied. e1 represents the hash value H2(x A1 ||M1||y A1 ) is the value after XOR operation with C3, w1 is the value after modulo p operation of the sum of k1 and s1, (x1, y1) is the point s1G+w1PK UE The horizontal and vertical coordinates of

[0077] Step S3.3: Verify whether the equation k1 = (e1 + x1) mod p holds through the authentication gateway. If the equation holds, {M1, k1, s1} is successfully restored. The authentication gateway randomly selects a UE ,PID UE ∈{0,1} * , calculate Among them, a UE ,PID UE Respectively represent from the set {0,1} * A string of any length randomly selected from the set An integer randomly selected from H1(MID UE ) indicates MID UE The hash value after the hash function H1 is calculated, H1(HPW UE ) indicates HPW UE The hash value after the hash function H1 is calculated, CR1 represents the hash value H1 (MID UE ) and hash value H1(HPW UE ) after XOR operation and modulo n p The calculated value is the value after the hash function H1 is calculated again, and CR2 represents a UE The value after XOR operation with CR1;

[0078] Step S3.4: Create an identifier MID through the authentication gateway UE List UE ={MID UE ,a UE , Honeyword={}}, let M2=CR1||CR2, randomly select Calculate e2 = H3 (M2, r3), C4 = r3G = (x2, y2), k2 = (e2 + x2) mod p, s2 = (1 + d AG ) -1 (r3-k2d AG )mod p,r3PK UE =(x U1 ,y U1 ), t2=H2(x U1 ||y U1 ,p), Where T2 represents the current timestamp; let CT2 = C4||C5||C6, MT2 = {CT2, k2, s2, T2}, where M2 represents the value after cascade operation of CR1 and CR2, r3 represents the value from the set An integer randomly selected from the matrix, e2 represents the value of M2 and r3 after the hash function H3 is applied, x2 and y2 represent the horizontal and vertical coordinates of point C4 respectively, k2 represents the value of the sum of e2 and x2 modulo p, and s2 represents the sum of 1 and d AG The inverse element of the sum and (r1-k1d UE ) after multiplication and modulo p operation, x U1 ,y U1 Representation point r3PK UE The horizontal and vertical coordinates of t2 represent x U1 With y U1 The concatenated value of M1 and T2 and the hash value of p after the hash function H2 is used. C5 represents the concatenated value of M1 and T2 and the value after the XOR operation of t2. H2(x U1 ||M2||y U1 ) represents x U1 , M2 and y U1 The cascade operation value of is the value after the hash function H2 is operated. C6 represents the hash value H2(x A1 ||M1||y A1 ) is the value after XOR operation with e2, and CT2 is the value after cascade operation of C4, C5 and C6;

[0079] Step S3.5: The authentication gateway outputs the authentication gateway registration response MT2 and the user's key (PK UE ,SK UE ) and public parameters params;

[0080] Step S4: The user receives the public parameter params, the authentication gateway registration response MT2, and the user key (PK UE ,SK UE ) and then output the user-side smart card SC UE(the user terminal device is, for example, a smart card); step S4 specifically includes the following steps:

[0081] Step S4.1: The user receives the authentication gateway registration response MT2, public parameters params and the user key (PK UE ,SK UE );

[0082] Step S4.2: The user terminal verifies whether T2 is fresh. If T2 does not meet the freshness requirement, the user terminal rejects the registration response. Otherwise, calculate d UE C4=(x U1 ,y U1 ), t2=H2(x U1 ||y U1 ,p), w2=(k2+s2)mod p,(x2,y2)=s2G+w2PK AG , where x U1 ,y U1 Respectively represent point d UE The horizontal and vertical coordinates of C4, t2 represents x U1 With y U1 The concatenated value of and the hash value of p after the hash function H2 is calculated. M2||T2 represents the value after the XOR operation of C5 and t2. H2(x U1 ||M2||y U1 ) represents x U1 , M2 and y U1 The cascade operation value of is the value after the hash function H2 is operated, and e2 represents the hash value H2(x U1 ||M2||y U1 ) is the value after XOR operation with C6, w2 is the value after modulo p operation of the sum of k2 and s2, x2, y2 are the points s2G+w2PK AG The horizontal and vertical coordinates of

[0083] Step S4.3: The user terminal verifies whether the equation k2 = (e2 + x2) mod p holds. If the equation holds, M2 is successfully recovered. The user terminal calculates SC UE ={M2,N UE ,θ UE ,Gen(·),Rep(·)}, where k1 represents the value of the sum of e2 and x2 after modulo p operation, M2 represents the message transmitted from the authentication gateway to the user, and H1(HPW UE ||ID UE ||σ UE ) indicates HPW UE 、ID UEWith σ UE The cascade operation value of is the value after the hash function H1 operation, N UE Indicates MID UE With hash value H1(HPW UE ||ID UE ||σ UE ) after XOR operation, θ UE Indicates biometrics BIO UE The public string is obtained after the fuzzy extraction function Gen(·) is used to calculate. Gen(·), Rep(·) represents the fuzzy extraction function, SC UE Indicates the user's smart card ID;

[0084] Step S5: Receive the user terminal ID through the user terminal UE ∈{0,1} * , User port command PW UE ∈{0,1} * , User-side biometrics BIO UE ∈{0,1} * , User-side smart card identification SC UE 、User key (PK UE ,SK UE ) and public parameters params, generate a user-side login and authentication request MT3; step S5 specifically includes the following steps:

[0085] Step S5.1: The user terminal receives the user terminal identification ID UE ∈{0,1} * , user port order PW UE ∈{0,1} * , user-side biometrics BIO UE ∈{0,1} * , user-side smart card identification SC UE , the user key (PK UE ,SK UE ), and public parameters params;

[0086] Step S5.2: Calculate σ by the user end UE =Rep(BIO UE ,θ UE ),HPW UE =H1(PW UE ||σ UE ), Among them, σ UE Indicates biometrics BIO UE The secret string obtained after the fuzzy extraction function Rep(·) is calculated, HPW UE Indicates PW UEWith σ UE The cascade operation value of is the value after the hash function H1 is operated, H1 (HPW UE ||ID UE ||σ UE ) indicates HPW UE 、ID UE and σ UE The cascade operation value of MID is the value after the hash function H1 is used to operate. UE Indicates smart card parameter N UE With hash value H1(HPW UE ||ID UE ||σ UE ) after XOR operation, H1(MID UE ) indicates MID UE The hash value after the hash function H1 is calculated, H1(HPW UE ) indicates HPW UE The hash value after the hash function H1 operation is: Indicates the hash value H1(MID UE ) and hash value H1(HPW UE ) after XOR operation and modulo n p The calculated value is the value after the hash function H1 is used again;

[0087] Step S5.3: User-side verification equation If not, the login request is rejected; otherwise, the user terminal randomly selects Let M3 = MID UE |‖r3||ID SR , where r3 represents the An integer randomly selected from the UE , r3 and ID SR The value after the cascade operation;

[0088] Step S5.4: The user terminal calculates e3 = H3 (M3, r3), C7 = r3G = (x3, y3), k3 = (e3 + x3) mod p, s3 = (1 + d UE ) -1 (r3-k3d UE )mod p,r3PK AG =(x A2 ,y A2 ), t3=H2(x A2 ||y A2 ,p), Where T3 represents the current timestamp; let CT3 = C7|‖C8||C9, MT3 = {CT3, k3, s3, T3}; where e3 represents the value of M3 and r3 after the hash function H3 operation, x3, y3 represent the horizontal and vertical coordinates of point C7 respectively, k3 represents the value of the sum of e3 and x3 after the modulo p operation, s3 represents the sum of 1 and d UE The inverse element of the sum and (r3-k3d UE ) after multiplication and modulo p operation, x A2 ,y A2 Representation point r3PK AG The horizontal and vertical coordinates of t3 represent x A2 With y A2 The concatenated value of M3 and T3 and the hash value of p after the hash function H2 is used. C8 represents the concatenated value of M3 and T3 and the value after the XOR operation of t3. A2 ||M3||y A2 ) represents x A2 , M3 and y A2 The cascade operation value of is the value after the hash function H2 is operated. C9 represents the hash value H2(x A2 |‖M3‖|y A2 ) represents the value after XOR operation with e3, CT3 represents the value after cascade operation of C7, C8 and C9, and MT3 represents the set consisting of CT3, k3, s3 and T3;

[0089] Step S5.5: Outputting the user terminal authentication request MT3 to the authentication gateway terminal through the user terminal;

[0090] Step S6: The authentication gateway receives the user authentication request MT3 and the authentication gateway key (PK AG ,SK AG ) and public parameters params, output the authentication gateway end authentication request MT4; step S6 specifically includes the following steps:

[0091] Step S6.1: The authentication gateway receives the authentication request MT3 from the user, and the authentication gateway key (PK AG ,SK AG ), public parameters params;

[0092] Step S6.2: The authentication gateway verifies whether T3 is fresh. If T3 does not meet the freshness requirement, the authentication gateway rejects the user's authentication request; otherwise, calculate d AG C7=(x A2 ,y A2 ), t3=H2(x A2 ||y A2 ,p), w3=(k3+s3)mod p,(x3,y3)=s3G+w3PK UE , where x A2 ,y A2 Respectively represent point d AG The horizontal and vertical coordinates of C7, t3 represents x A2 With y A2 The concatenated value of and the hash value of p after the hash function H2 is calculated. M3||T3 represents the value after the XOR operation of C8 and t3. H2(x A2 ||M3‖|y A2 ) represents x A2 , M3 and y A2 The cascade operation value of is the value after the hash function H2 is operated, and e3 represents the hash value H2(x A2 |‖M3‖|y A2 ) and C9 after XOR operation, w3 represents the value after modulo p operation of the sum of k3 and s3, x3, y3 represent the point s2G+w2PK AG The horizontal and vertical coordinates of

[0093] Step S6.3: The authentication gateway verifies whether the equation k3 = (e3 + x3) mod p holds. If not, the authentication request is rejected; otherwise, the authentication gateway successfully recovers M3, where k3 represents the value of the sum of e3 and x3 after the modulo p operation, and M3 represents the message transmitted by the user end to the authentication gateway end;

[0094] Step S6.4: Authentication gateway randomly selects Let M4 = MID UE ||r4||ID SR , calculate e4 = H3 (M4, r4), C 10 =r4G=(x4,y4), k4=(e4+x4)mod p, s4=(1+d AG ) -1 (r4-k4d AG )mod p,r4PK SR =(x S1 ,y S1 ), t4=H2(x S1 ||y S1 ,p), Where T4 represents the current timestamp; let CT4 = C 10 ||C 11 ||C 12 , MT4={CT4,k4,s4,T4}; where r4 represents the An integer randomly selected from the UE, r4 and ID SR The value after the cascade operation, e4 represents the value of M4 and r4 after the hash function H3 operation, x4, y4 represent the point C 10 The horizontal and vertical coordinates of the , k4 represents the value of the sum of e4 and x4 after the modulo p operation, s4 represents the sum of 1 and d AG The inverse element of the sum and (r4-k4d AG ) after multiplication and modulo p operation, x S1 ,y S1 Indicates point r4PK SR The horizontal and vertical coordinates of t4 represent x S1 With y S1 The concatenated value of p and the hash value of p after the hash function H2 is calculated, C 11 It represents the value after XOR operation of the cascade operation value of M4 and T4 and t4, H2(x S1 ||M4||y S1 ) represents x S1 , M4 and y S1 The value after the cascade is calculated by the hash function H2, C 12 Represents the hash value H2(x S1 ||M4||y S1 ) and e4 after XOR operation, CT4 represents C 10 , C 11 and C 12 After the cascade operation, the value in MT4 is represented by a set consisting of CT4, k4, s4, and T4;

[0095] Step S6.5: The authentication gateway outputs the authentication gateway authentication request MT4 to the server;

[0096] Step S7: The server receives the authentication gateway authentication request MT4, the server key (PK SR ,SK SR ) and public parameters params, output the server-side authentication response MT5 and session key SK; step S7 specifically includes the following steps:

[0097] Step S7.1: The server receives the authentication request from the authentication gateway MT4, and the server key (PK SR ,SK SR ), and public parameters params;

[0098] Step S7.2: The server verifies whether T3 is fresh. If T3 does not meet the freshness requirement, the server rejects the authentication request from the authentication gateway. Otherwise, calculate d SR C 10 =(x S1 ,y S1), t4=H2(x S1 ||y S1 ,p), w4=(k4+s4)mod p,(x4,y4)=s4G+w4PK AG , where x S1 ,y S1 Respectively represent point d SR C 10 The horizontal and vertical coordinates of t4 represent x S1 With y S1 The concatenated value of p and the hash value of p after the hash function H2 is calculated. M4||T4 represents C 11 The value after XOR operation with t4, H2(x S1 ||M4||y S1 ) represents x S1 , M4 and y S1 The cascade operation value of is the value after the hash function H2 is operated. e4 represents the hash value H2(x S1 ||M4||y S1 ) and C 12 The value after XOR operation, w4 represents the value after modulo p operation of the sum of k4 and s4, x4, y4 represent the point s2G+w2PK AG The horizontal and vertical coordinates of the server; Step S7.3: The server verifies whether the equation k4 = (e4 + x4) mod p holds. If not, the authentication request is rejected; otherwise, the server successfully recovers M4, where k4 represents the value of the sum of e4 and x4 after the modulo p operation, and M4 represents the message transmitted by the authentication gateway to the server;

[0099] Step S7.4: Random selection by the server Let M5 = MID UE ||r5||ID SR , calculate e5 = H3 (M5, r5), C 13 =r5G=(x5,y5), k5=(e5+x5)modp, s5=(1+d SR ) -1 (r5-k5d SR )mod p,r5PK UE =(x U2 ,y U2 ), t5=H2(x U2 ||y U2 ,p), Among them, T5 represents the current timestamp, r5 represents the An integer randomly selected from the UE, r5 and ID SR The value after the cascade operation, e5 represents the value of M5 and r5 after the hash function H3 operation, x5, y5 represent the point C 13 The horizontal and vertical coordinates of the , k5 represents the value of the sum of e5 and x5 after the modulo p operation, s5 represents the sum of 1 and d SR The inverse element of the sum and (r5-k5d SR ) after multiplication and modulo p operation, x U2 ,y U2 Indicates point r5PK UE The horizontal and vertical coordinates of t5 represent x U2 With y U2 The concatenated value of p and the hash value of p after the hash function H2 is calculated, C 14 It represents the value after XOR operation of the cascade operation value of M5 and T5 and t5, H2(x U2 ||M5||y U2 ) represents x U2 , M5 and y U2 The cascade operation value of is the value after the hash function H2 is operated, C 15 Represents the hash value H2(x U2 ||M5||y U2 ) and the value after XOR operation with e5;

[0100] Step S7.5: The server calculates the session key SK=H1(r3||r5||ID SR ||MID UE ,p), let CT5=C 13 ||C 14 ||C 15 , MT5={CT5,k5,s5,T5}, where CT5 represents C 13 , C 14 and C 15 After the cascade operation, the value of MT5 is represented by the set consisting of CT5, k5, s5, and T5;

[0101] Step S7.6: The server outputs the session key SK and the server authentication response MT5 to the user;

[0102] Step S8: The client receives the server authentication response MT5, the client key (PK UE ,SK UE ) and public parameters params, output the session key SK; step S8 specifically includes the following steps:

[0103] Step S8.1: The client receives the server authentication response MT5, the client key (PK UE ,SKUE ), and public parameters params;

[0104] Step S8.2: The user verifies whether T5 is fresh: If T5 does not meet the freshness requirement, the user rejects the server authentication response; otherwise, calculate d UE C 13 =(x U2 ,y U2 ), t5=H2(x U2 ||y U2 ,p), w5=(k5+s5)mod p,(x5,y5)=s5G+w5PK SR , where x U2 ,y U2 Respectively represent point d UE C 13 The horizontal and vertical coordinates of t5 represent x U2 With y U2 The concatenated value of p and the hash value of p after the hash function H2 is calculated. M5||T5 represents C 14 The value after XOR operation with t5, H2(x U2 ||M5||y U2 ) represents x U2 , M5 and y U2 The cascade operation value of is the value after the hash function H2 is operated, and e5 represents the hash value H2 (x U2 ||M5‖|y U2 ) and C 15 The value after XOR operation, w5 represents the value after modulo p operation of the sum of k5 and s5, x5, y5 represents the point s5G+w5PK SR The horizontal and vertical coordinates of

[0105] Step S8.3: The user end verifies whether the equation k5=(e5+x5) mod p holds. If the equation holds, the message M5 is successfully recovered. The user end calculates the session key SK=H1(r3||r5||ID SR ||MID UE ,p), where k5 represents the value of the sum of e5 and x5 after modulo p operation, and M5 represents the message transmitted from the server to the user;

[0106] Step S8.4: The user terminal outputs the session key SK to the server terminal.

[0107] Embodiment 2:

[0108] like Figure 2As shown, a multi-factor authentication system based on the national secret SM2 of the present invention performs a multi-factor authentication method based on the national secret SM2 of the present invention in embodiment 1, and the system includes an authentication gateway end, a server end, a user end, and a key generation end arranged at the user end; wherein, the system includes a key generation end 100, a user end 200, an authentication gateway end 300, and a server end 400 connected via a network. wherein, the key generation end 100 and the user end 200 are respectively connected to the server end 400, the server end 400 is connected to the authentication gateway end 300, and the user end 200 is connected to the authentication gateway end 400.

[0109] The key generation end is used to obtain the public parameters according to the security parameters received from the server end, and receives the user end identifier, the authentication gateway end identifier and the server end identifier from the user end, the authentication gateway end and the server end respectively, and then combines the public parameters to generate the user end key (PK UE ,SK UE ), authentication gateway key (PK AG ,SK AG ) and the server key (PK SR ,SK SR ), and output, specifically, the user-side key (PK UE ,SK UE ) consists of at least public parameters params and client ID UE The authentication gateway key (PK AG ,SK AG ) at least consists of public parameters params and authentication gateway ID AG The server-side key (PK SR ,SK SR ) consists of at least public parameters params and server-side identifier ID SR Composition; further, the generated public parameter params is composed of at least a security parameter λ; wherein λ represents the bit length of the system input value.

[0110] The user terminal 200 is used to generate a user terminal key from the key generation end, and then generate a user terminal registration request MT1 and a user terminal smart card SC according to the public parameters received from the key generation end and the user terminal key combined with the user port command, the user terminal identifier, and the user terminal biometrics. UE , the user terminal login authentication request MT3 and the session key SK; Specifically, the user terminal registration request MT1 at least consists of the user terminal identification ID UE , User port command PW UE , User-side biometrics BIO UE 、User key (PK UE,SK UE ) and public parameters params, the user end smart card SC UE At least the authentication gateway registration response MT2, the user key (PK UE ,SK UE ) and public parameters params, the user end login authentication request MT3 at least consists of the user end identification ID UE , User port command PW UE , User-side biometrics BIO UE 、User key (PK UE ,SK UE ), user-side smart card identification SC UE and public parameters params; the session key SK is composed of at least public parameters params, server-side authentication response MT5 and user-side key (PK UE ,SK UE )composition.

[0111] The server 300 is used to generate a server authentication response MT5 and a session key SK after receiving an authentication request from the authentication gateway, a server key and public parameters, and output them. Specifically, the server authentication response MT5 is composed of at least an authentication request from the authentication gateway MT4, a server key (PK SR ,SK SR ) and public parameters params. Among them, the server-side authentication response MT5 is generated according to the authentication gateway-side authentication request MT4; the server-side generates a session key SK according to the authentication gateway-side authentication request MT4 and the server-side authentication response MT5; the session key is composed of public parameters params, server-side authentication response MT5 and user-side key SK. The session key SK is generated at the user-side and server-side at the same time and is used for communication between the user-side and the server-side.

[0112] The authentication gateway 400 is used to generate an authentication gateway registration response MT2 and an authentication gateway authentication request MT4 according to the public parameters received from the key generation end and the authentication gateway key after receiving the user end authentication request from the user end, and output them; specifically, the authentication gateway registration response MT2 is at least composed of the user end registration request MT1, the authentication gateway key (PK AG ,SK AG ) and public parameters params, the authentication gateway authentication request MT4 at least consists of the user end authentication request MT3, the authentication gateway key (PK AG ,SK AG) and public parameters params; specifically, the authentication gateway registration response is composed of a user-side registration request, an authentication gateway key and public parameters, and the authentication gateway authentication request is composed of a user-side authentication request, an authentication gateway key and public parameters.

[0113] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present application and are not intended to limit it. Although the present application is described in detail with reference to the embodiments, a person skilled in the art should understand that any modification or equivalent replacement of the technical solution of the present application does not depart from the spirit and scope of the technical solution of the present application and should be included in the scope of the claims of the present application.

Claims

1. A multi-factor authentication method based on the national secret SM2 algorithm, characterized in that: The process includes: Step S1: input security parameters from the server end to the key generation end, obtain public parameters according to the security parameters received from the server end, input the user end identifier, the authentication gateway end identifier and the server end identifier from the user end, the authentication gateway end identifier and the server end identifier to the key generation end respectively, receive the user end identifier, the authentication gateway end identifier and the server end identifier, and then combine the public parameters to generate the user end key, the authentication gateway end key and the server end key, and output the user end key, the authentication gateway end key and the server end key; Step S2: After the user terminal generates the user terminal key from the key generation end, it receives the public parameters, the user port command, the user terminal identifier, the user terminal biometrics, and the user terminal key, generates a user terminal registration request, a user terminal login authentication request, and a session key according to the public parameters and the user terminal key received from the key generation end combined with the user port command, the user terminal identifier, and the user terminal biometrics, and outputs the user terminal registration request; Step S3: After receiving the user authentication request from the user, the authentication gateway receives the user registration request, public parameters, and the authentication gateway key, generates an authentication gateway registration response and an authentication gateway authentication request according to the public parameters and the authentication gateway key received from the key generation end, and outputs the authentication gateway registration response; Step S4: The user terminal receives the public parameters, the registration response of the authentication gateway terminal, and the user terminal key from the authentication gateway terminal, and outputs the user terminal smart card; Step S5: The user terminal receives the user port command, the user terminal identifier, the user terminal biometric feature, the user terminal identifier and the user terminal key, and outputs a user terminal login authentication request; Step S6: The authentication gateway receives the user authentication request, the authentication gateway key and the public parameters from the user, and outputs the authentication gateway authentication request; Step S7: The server receives the authentication gateway authentication request, the server key and the public parameters from the authentication gateway, generates a server authentication response and a session key, and outputs the server authentication response and the session key; Step S8: The client receives the server authentication response, the client key and the public parameters from the server, and outputs the session key.

2. According to claim 1, a multi-factor authentication method based on the national secret SM2 algorithm is characterized in that: The step S1 specifically includes the following process: Step S1.1: Generate a large prime number p and an elliptic curve E from the security parameter λ on the server side, where |p|=λ, |p| is the absolute value of p, and randomly select a q-order base point on the elliptic curve E to obtain a graph representation of the base point G=(x G ,y G ),in, Among them, x G ,y G Respectively represent the abscissa and ordinate of point G; represents the set {1,2,…,p-1} consisting of integers 1,2,…,p-1; Step S1.2: Select three cryptographic hash functions H1: {0,1} * →{0,1} * , H3:{0,1} * →{0,1} v ; Among them, H1 will be {0,1} * The elements on are mapped to {0,1} * Random elements on H2 will be {0,1} * The elements on are mapped to elements on; H3 will {0,1} * The elements on are mapped to {0,1} v Elements on {0,1} * Represents a string of arbitrary length, v represents the length of the session key, {0,1} v represents a string of length v; select the fuzzy extraction function (Gen(·), Rep(·)), where Gen(·) and Rep(·) convert {0,1} * The elements are mapped to {0,1} * , let public parameters params = {G, p, H1, H2, H3, Gen (·), Rep (·)}; Step S1.3: Input public parameters params = {G, p, H1, H2, H3, Gen (·), Rep (·)} and user terminal ID to the key generation end UE , Authentication gateway ID AG and the server-side ID SR , randomly select d UE ,d AG , Calculate the user key PK UE =d UE G=(x UE ,y UE ), authentication gateway key PK AG =d AG G=(x AG ,y AG ) and the server-side key PK SR =d SR G=(x SR ,y SR ), output the user key (PK UE ,SK UE )=((x UE ,y UE ),d UE ), authentication gateway key (PK AG ,SK AG) =((x AG ,y AG ),d AG ) and the server-side key (PK SR ,SK SR )=((x SR ,y SR ),d SR ); let params = {G, p, H1, H2, H3, PK UE ,PK AG ,PK SR }; where d UE ,d AG ,d SR They represent integers randomly selected from the set {1,2,…,p-1}; x UE ,y UE Respectively represent point d UE The horizontal and vertical coordinates of G; x AG ,y AG Respectively represent point d AG The horizontal and vertical coordinates of G; x SR ,y SR Respectively represent point d SR The horizontal and vertical coordinates of G.

3. According to claim 1, a multi-factor authentication method based on the national secret SM2 algorithm is characterized in that: The step S2 specifically includes the following process: Step S2.1: The user receives the user key (PK UE ,SK UE ), fuzzy extraction function (Gen, Rep) and public parameters params, the fuzzy extraction function (Gen, Rep) is used to map the biometric features to Elements on; Step S2.2: Perform fuzzy extraction on the user side to obtain the user-side biometric Gen(BIO UE) =(σ UE ,θ UE ), user port command hash password HPW UE =H1(PW UE ||σ UE ), user identification hash password MID UE =H1(ID UE ||σ UE ) is calculated, where σ UE Indicates biometrics BIO UE The secret string obtained after the fuzzy extraction function Gen(·) is calculated, θ UE Indicates biometrics BIO UE The public string obtained after the fuzzy extraction function Gen(·) is used; PW UE ||σ UE Indicates the password PW UE With the secret string σ UE The value after cascade operation, HPW UE Indicates PW UE ||σ UE The hash value obtained after the hash function H1 operation, ID UE ||σ UE Indicates ID UE With the secret string σ UE Cascade operation of MID UE Representation ID UE ||σ UE The hash value obtained after the hash function H1 is used; ∥ indicates a cascade operation; Step S2.3: Randomly select Y UE ∈{0,1} * , Let M1 = Y UE ||MID UE ||HPW UE , calculate e1=H3(M1,r1), C1=r1G=(x1,y1), k1=(e1+x1)mod p, s1=(1+d UE ) -1 (r1-k1d UE )mod p,r1PK AG =(x A1 ,y A1 ), t1=H2(x A1 ||y A1 ,p), Where T1 represents the current timestamp; let CT1 = C1||C2||C3, MT1 = {CT1, k1, s1, T1}; where Y UE Represents the set {0,1} * Any length string randomly selected from the set An integer randomly selected from, M1 represents Y UE 、MID UE and HPW UE The value after the cascade operation, e1 represents the value of M1 and r1 after the hash function H3 operation, C1 represents the point on the elliptic curve, x1, y1 represent the horizontal coordinate and vertical coordinate of point C1 respectively, k1 represents the value of the sum of e1 and x1 after the modulo p operation, s1 represents the sum of 1 and d UE The inverse element of the sum and (r1-k1d UE ) after multiplication and modulo p operation, x A1 ,y A1 Respectively represent the points r1PK AG The horizontal and vertical coordinates of t1 represent x A1 and A1 The concatenation value of M1 and T1 and the value after the hash function H2 is used to calculate p. C2 represents the concatenation value of M1 and T1 and the value after the XOR operation of t1. H2(x A1 ||M1||y A1 ) represents x A1 , M1 and y A1 The cascade operation value is the value after the hash function H2 is operated. C3 represents the hash value H2(x A1 ||M1||y A1 ) and e1 after XOR operation, CT1 represents the value after C1, C2 and C3 are cascaded. represents XOR operation, and mod represents modulo operation.

4. According to claim 1, a multi-factor authentication method based on the national secret SM2 algorithm is characterized in that: The step S3 specifically includes the following process: Step S3.1: The authentication gateway receives the user registration request MT1, and the authentication gateway key (PK AG ,SK AG ) and public parameters params; Step S3.2: Verify whether T1 is fresh through the authentication gateway; if T1 does not meet the freshness requirement, the authentication gateway rejects the user's registration request MT1; otherwise, calculate d AG C1=(x A1 ,y A1 ), t1=H2(x A1 ||y A1 ,p), w1=(k1+s1)mod p,(x1,y1)=s1G+w1PK UE , where t1 represents x A1 The concatenated value of M1 and the hash value of p after the hash function H2 is applied. e1 represents the hash value H2(x A1 ||M1||y A1 ) is the value after XOR operation with C3, w1 is the value after modulo p operation of the sum of k1 and s1, (x1,y 1) Represents point s1G+w1PK UE The horizontal and vertical coordinates of Step S3.3: Verify whether the equation k1 = (e1 + x1) mod p holds through the authentication gateway. If the equation holds, {M1, k1, s1} is successfully restored. The authentication gateway randomly selects a UE ,PID UE ∈{0,1} * , calculate Among them, a UE ,PID UE Respectively represent from the set {0,1} * A string of any length randomly selected from the set An integer randomly selected from H1(MID UE ) indicates MID UE The hash value after the hash function H1 is calculated, H1(HPW UE ) indicates HPW UE The hash value after the hash function H1 is calculated, CR1 represents the hash value H1 (MID UE ) and hash value H1(HPW UE ) after XOR operation and modulo n p The calculated value is the value after the hash function H1 is calculated again, and CR2 represents a UE The value after XOR operation with CR1; Step S3.4: Create an identifier MID through the authentication gateway UE List UE ={MID UE ,a UE , Honeyword={}}, let M2=CR1||CR2, randomly select Calculate e2 = H3 (M2, r3), C4 = r3G = (x2, y2), k2 = (e2 + x2) mod p, s2 = (1 + d AG ) -1 (r3-k2d AG )mod p,r3PK UE =(x U1 ,y U1 ), t2=H2(x U1 ||y U1 ,p), Where T2 represents the current timestamp; let CT2 = C4||C5||C6, MT2 = {CT2, k2, s2, T2}, where M2 represents the value after cascade operation of CR1 and CR2, r3 represents the value from the set An integer randomly selected from the matrix, e2 represents the value of M2 and r3 after the hash function H3 is applied, x2 and y2 represent the horizontal and vertical coordinates of point C4 respectively, k2 represents the value of the sum of e2 and x2 modulo p, and s2 represents the sum of 1 and d AG The inverse element of the sum and (r1-k1d UE ) after multiplication and modulo p operation, x U1 ,y U1 Representation point r3PK UE The horizontal and vertical coordinates of t2 represent x U1 With y U1 The concatenated value of M1 and T2 and the hash value of p after the hash function H2 is used. C5 represents the concatenated value of M1 and T2 and the value after the XOR operation of t2. H2(x U1 ||M2||y U1 ) represents x U1 , M2 and y U1 The cascade operation value of is the value after the hash function H2 is operated. C6 represents the hash value H2(x A1 ||M1||y A1 ) is the value after XOR operation with e2, and CT2 is the value after cascade operation of C4, C5 and C6.

5. According to claim 1, a multi-factor authentication method based on the national secret SM2 algorithm is characterized in that: The step S4 specifically includes the following process: Step S4.1: The user receives the authentication gateway registration response MT2, public parameters params and the user key (PK UE ,SK UE ); Step S4.2: The user terminal verifies whether T2 is fresh. If T2 does not meet the freshness requirement, the user terminal rejects the registration response. Otherwise, calculate d UE C4=(x U1 ,y U1 ), t2=H2(x U1 ||y U1 ,p), w2=(k2+s2)mod p,(x2,y2)=s2G+w2PK AG , where x U1 ,y U1 Respectively represent point d UE The horizontal and vertical coordinates of C4, t2 represents x U1 With y U1 The concatenated value of and the hash value of p after the hash function H2 is calculated. M2||T2 represents the value after the XOR operation of C5 and t2. H2(x U1 ||M2||y U1 ) represents x U1 , M2 and y U1 The cascade operation value of is the value after the hash function H2 is operated, and e2 represents the hash value H2(x U1 ||M2||y U1 ) is the value after XOR operation with C6, w2 is the value after modulo p operation of the sum of k2 and s2, x2, y2 are the points s2G+w2PK AG The horizontal and vertical coordinates of Step S4.3: The user terminal verifies whether the equation k2 = (e2 + x2) mod p holds. If the equation holds, M2 is successfully recovered. The user terminal calculates SC UE ={M2,N UE ,θ UE ,Gen(·),Rep(·)}, where k1 represents the value of the sum of e2 and x2 after modulo p operation, M2 represents the message transmitted from the authentication gateway to the user, and H1(HPW UE ||ID UE ||σ UE ) indicates HPW UE 、ID UE With σ UE The cascade operation value of is the value after the hash function H1 operation, N UE Indicates MID UE With hash value H1(HPW UE ||ID UE ||σ UE ) after XOR operation, θ UE Indicates biometrics BIO UE The public string is obtained after the fuzzy extraction function Gen(·) is used to calculate. Gen(·), Rep(·) represents the fuzzy extraction function, SC UE Indicates the user's smart card ID.

6. A multi-factor authentication method based on the national secret SM2 algorithm according to claim 1, characterized in that: The step S5 specifically includes the following process: Step S5.1: The user terminal receives the user terminal identification ID UE ∈{0,1} * , User port command PW UE ∈{0,1} * , User-side biometrics BIO UE ∈{0,1} * , User-side smart card identification SC UE 、User key (PK UE ,SK UE ) and public parameters params; Step S5.2: Calculate σ by the user end UE =Rep(BIO UE ,θ UE ), HPW UE =H1(PW UE ||σ UE ), Among them, σ UE Indicates biometrics BIO UE The secret string obtained after the fuzzy extraction function Rep(·) is calculated, HPW UE Indicates PW UE With σ UE The cascade operation value of is the value after the hash function H1 is operated, H1 (HPW UE ||ID UE ||σ UE ) indicates HPW UE 、ID UE and σ UE The cascade operation value of MID is the value after the hash function H1 is used to operate. UE Indicates smart card parameter N UE With hash value H1(HPW UE ||ID UE ||σ UE ) after XOR operation, H1(MID UE ) indicates MID UE The hash value after the hash function H1 is calculated, H1(HPW UE ) indicates HPW UE The hash value after the hash function H1 operation is: Indicates the hash value H1(MID UE ) and hash value H1(HPW UE ) after XOR operation and modulo n p The calculated value is the value after the hash function H1 is used again; Step S5.3: User side verifies the equation If not, the login request is rejected; otherwise, the user terminal randomly selects Let M3 = MID UE ||r3||ID SR , where r3 represents the An integer randomly selected from the UE , r3 and ID SR The value after the cascade operation; Step S5.4: The user terminal calculates e3 = H3 (M3, r3), C7 = r3G = (x3, y3), k3 = (e3 + x3) mod p, s3 = (1 + d UE ) -1 (r3-k3d UE )mod p,r3PK AG =(x A2 ,y A2 ), t3=H2(x A2 ||y A2 ,p), Where T3 represents the current timestamp; let CT3 = C7||C8||C9, MT3 = {CT3, k3, s3, T3}; where e3 represents the value of M3 and r3 after the hash function H3 operation, x3, y3 represent the horizontal and vertical coordinates of point C7 respectively, k3 represents the value of the sum of e3 and x3 after the modulo p operation, s3 represents the sum of 1 and d UE The inverse element of the sum and (r3-k3d UE ) after multiplication and modulo p operation, x A2 ,y A2 Representation point r3PK AG The horizontal and vertical coordinates of t3 represent x A2 With y A2 The concatenated value of M3 and T3 and the hash value of p after the hash function H2 is used. C8 represents the concatenated value of M3 and T3 and the value after the XOR operation of t3. H2(x A2 ||M3||y A2 ) represents x A2 , M3 and y A2 The cascade operation value of is the value after the hash function H2 is operated. C9 represents the hash value H2(x A2 ||M3||y A2 ) is the value after XOR operation with e3, CT3 is the value after cascade operation of C7, C8 and C9, and MT3 is the set consisting of CT3, k3, s3 and T3.

7. A multi-factor authentication method based on the national secret SM2 algorithm according to claim 1, characterized in that: The step S6 specifically includes the following process: Step S6.1: The authentication gateway receives the authentication request MT3 from the user, and the authentication gateway key (PK AG ,SK AG ), public parameters params; Step S6.2: The authentication gateway verifies whether T3 is fresh. If T3 does not meet the freshness requirement, the authentication gateway rejects the authentication request from the user. Otherwise, calculate d AG C7=(x A2 ,y A2 ), t3=H2(x A2 ||y A2 ,p), w3=(k3+s3)mod p,(x3,y3)=s3G+w3PK UE , where x A2 ,y A2 Respectively represent point d AG The horizontal and vertical coordinates of C7, t3 represents x A2 With y A2 The concatenated value of and the hash value of p after the hash function H2 is calculated. M3||T3 represents the value after the XOR operation of C8 and t3. H2(x A2 ||M3||y A2 ) represents x A2 , M3 and y A2 The cascade operation value of is the value after the hash function H2 is operated, and e3 represents the hash value H2(x A2 ||M3||y A2 ) and C9 after XOR operation, w3 represents the value after modulo p operation of the sum of k3 and s3, x3, y3 represent the point s2G+w2PK AG The horizontal and vertical coordinates of Step S6.3: The authentication gateway verifies whether the equation k3=(e3+x3) mod p holds; if not, the authentication request is rejected; otherwise, the authentication gateway successfully recovers M3, where k3 represents the value of the sum of e3 and x3 after the modulo p operation, and M3 represents the message transmitted by the user end to the authentication gateway end; Step S6.4: Authentication gateway randomly selects Let M4 = MID UE ||r4||ID SR , calculate e4 = H3 (M4, r4), C 10 =r4G=(x4,y4), k4=(e4+x4)mod p, s4=(1+d AG ) -1 (r4-k4d AG )mod p,r4PK SR =(x S1 ,y S1 ), t4=H2(x S1 ||y S1 ,p), Where T4 represents the current timestamp; let CT4 = C 10 ||C 11 ||C 12 , MT4={CT4,k4,s4,T4}; where r4 represents the An integer randomly selected from the UE , r4 and ID SR The value after the cascade operation, e4 represents the value of M4 and r4 after the hash function H3 operation, x4, y4 represent the point C 10 The horizontal and vertical coordinates of the , k4 represents the value of the sum of e4 and x4 after the modulo p operation, s4 represents the sum of 1 and d AG The inverse element of the sum and (r4-k4d AG ) after multiplication and modulo p operation, x S1 ,y S1 Indicates point r4PK SR The horizontal and vertical coordinates of t4 represent x S1 With y S1 The concatenated value of p and the hash value of p after the hash function H2 is calculated, C 11 It represents the value after XOR operation of the cascade operation value of M4 and T4 and t4, H2(x S1 ||M4||y S1 ) represents x S1 , M4 and y S1 The value after the cascade is calculated by the hash function H2, C 12 Represents the hash value H2(x S1 ||M4||y S1 ) and e4 after XOR operation, CT4 represents C 10 , C 11 and C 12 After the cascade operation, the value in MT4 is represented by the set consisting of CT4, k4, s4, and T4.

8. A multi-factor authentication method based on the national secret SM2 algorithm according to claim 1, characterized in that: The step S7 specifically includes the following process: Step S7.1: The server receives the authentication request from the authentication gateway MT4, and the server key (PK SR ,SK SR ), and public parameters params; Step S7.2: The server verifies whether T3 is fresh; if T3 does not meet the freshness requirement, the server rejects the authentication request from the authentication gateway; otherwise, calculate d SR C 10 =(x S1 ,y S1 ), t4=H2(x S1 ||y S1 ,p), w4=(k4+s4)mod p,(x4,y4)=s4G+w4PK AG , where x S1 ,y S1 Respectively represent point d SR C 10 The horizontal and vertical coordinates of t4 represent x S1 With y S1 The concatenated value of p and the hash value of p after the hash function H2 is calculated. M4||T4 represents C 11 The value after XOR operation with t4, H2(x S1 ||M4||y S1 ) represents x S1 , M4 and y S1 The cascade operation value of is the value after the hash function H2 is operated. e4 represents the hash value H2(x S1 ||M4||y S1 ) and C 12 The value after XOR operation, w4 represents the value after modulo p operation of the sum of k4 and s4, x4, y4 represent the point s2G+w2PK AG The horizontal and vertical coordinates of Step S7.3: The server verifies whether the equation k4=(e4+x4) mod p holds; if not, the authentication request is rejected; otherwise, the server successfully recovers M4, where k4 represents the value of the sum of e4 and x4 after the modulo p operation, and M4 represents the message transmitted by the authentication gateway to the server; Step S7.4: Random selection by the server Let M5 = MID UE ||r5||ID SR , calculate e5 = H3 (M5, r5), C 13 =r5G=(x5,y5), k5=(e5+x5)modp, s5=(1+d SR ) -1 (r5-k5d SR )mod p,r5PK UE =(x U2 ,y U2 ), t5=H2(x U2 ||y U2 ,p), Among them, T5 represents the current timestamp, r5 represents the An integer randomly selected from the UE , r5 and ID SR The value after the cascade operation, e5 represents the value of M5 and r5 after the hash function H3 operation, x5, y5 represent the point C 13 The horizontal and vertical coordinates of the , k5 represents the value of the sum of e5 and x5 after the modulo p operation, s5 represents the sum of 1 and d SR The inverse element of the sum and (r5-k5d SR ) after multiplication and modulo p operation, x U2 ,y U2 Indicates point r5PK UE The horizontal and vertical coordinates of t5 represent x U2 With y U2 The concatenated value of p and the hash value of p after the hash function H2 is calculated, C 14 It represents the value after XOR operation of the cascade operation value of M5 and T5 and t5, H2(x U2 ||M5||y U2 ) represents x U2 , M5 and y U2 The cascade operation value of is the value after the hash function H2 is operated, C 15 Represents the hash value H2(x U2 ||M5||y U2 ) and the value after XOR operation with e5; Step S7.5: The server calculates the session key SK=H1(r3||r5||ID SR ||MID UE ,p), let CT5=C 13 ||C 14 ||C 15 , MT5={CT5,k5,s5,T5}, where CT5 represents C 13 , C 14 and C 15 After the cascade operation, the value of MT5 is represented by the set consisting of CT5, k5, s5, and T5.

9. A multi-factor authentication method based on the national secret SM2 algorithm according to claim 1, characterized in that: The step S8 specifically includes the following process: Step S8.1: The client receives the server authentication response MT5, the client key (PK UE ,SK UE ), and public parameters params; Step S8.2: The user verifies whether T5 is fresh: If T5 does not meet the freshness requirement, the user rejects the server authentication response; otherwise, calculate d UE C 13 =(x U2 ,y U2 ), t5=H2(x U2 ||y U2 ,p), w5=(k5+s5)mod p, ( x5,y 5) =s5G+w5PK SR , where x U2 ,y U2 Respectively represent point d UE C 13 The horizontal and vertical coordinates of t5 represent x U2 With y U2 The concatenated value of p and the hash value of p after the hash function H2 is calculated. M5||T5 represents C 14 The value after XOR operation with t5, H2(x U2 ||M5||y U2 ) represents x U2 , M5 and y U2 The cascade operation value of is the value after the hash function H2 is operated, and e5 represents the hash value H2 (x U2 ||M5||y U2 ) and C 15 The value after XOR operation, w5 represents the value after modulo p operation of the sum of k5 and s5, x5, y5 represents the point s5G+w5PK SR The horizontal and vertical coordinates of Step S8.3: The user end verifies whether the equation k5=(e5+x5) mod p holds. If the equation holds, the message M5 is successfully recovered. The user end calculates the session key SK=H1(r3||r5||ID SR ||MID UE ,p), where k5 represents the value of the sum of e5 and x5 after modulo p operation, and M5 represents the message transmitted from the server to the user.

10. A multi-factor authentication system based on the national secret SM2 algorithm, implementing the multi-factor authentication method based on the national secret SM2 algorithm according to any one of claims 1 to 1, characterized in that: The system comprises a key generation end, a user end, an authentication gateway end and a server end connected to a network; the key generation end and the user end are respectively connected to the server end, the server end is connected to the authentication gateway end, and the user end is connected to the authentication gateway end; The key generation end is used to obtain public parameters according to the security parameters received from the server end, and receives the user end identifier, the authentication gateway end identifier and the server end identifier from the user end, the authentication gateway end and the server end respectively, and then combines the public parameters to generate the user end key, the authentication gateway end key and the server end key, and outputs them; specifically, the user end key is composed of the public parameters and the user end identifier, the authentication gateway end key is composed of the public parameters and the authentication gateway end identifier, and the server end key is composed of the public parameters and the server end identifier; The user end is used to generate a user registration request, a user smart card, a user login authentication request and a session key according to the public parameters and the user key received from the key generation end, combined with the user port command, the user identification, and the user biometrics, and output them after receiving the server authentication response from the server end; specifically, the user registration request is composed of the user identification, the user port command, the user biometrics, the user key and the public parameters; the user smart card is composed of the authentication gateway registration response, the user key and the public parameters; the user login authentication request is composed of the user identification, the user port command, the user biometrics, the user key, the user smart card and the public parameters; the session key is composed of the public parameters, the server authentication response and the user key; The server is used to generate a server-side authentication response and a session key after receiving an authentication request from an authentication gateway, a server-side key, a user-side key and public parameters from an authentication gateway, and output them; specifically, the server-side authentication response is composed of at least the authentication request from the authentication gateway, the server-side key and the public parameters; the session key is composed of the public parameters, the server-side authentication response and the user-side key; The authentication gateway is used to generate an authentication gateway registration response and an authentication gateway authentication request based on the public parameters and the authentication gateway key received from the key generation end after receiving a user authentication request from the user end, and output them; specifically, the authentication gateway registration response consists of the user registration request, the authentication gateway key and the public parameters, and the authentication gateway authentication request consists of the user authentication request, the authentication gateway key and the public parameters.

Citation Information

Patent Citations

  • Identity-free three-factor remote user authentication method

    CN105871553A

  • Single sign-on authentication method based on inadvertent pseudo-random function and signcryption

    CN110784305A

  • PUF-based three-factor anonymous user authentication protocol method in Internet of Things

    CN111818039A

  • Multi-factor authentication key negotiation method for intelligent equipment communication

    CN114125833A

  • Security authentication method for intelligent greenhouse sensor equipment

    CN114710290A