Identity authentication method based on multiple authentication factors, medium, equipment and product

By aggregating the private and public keys of multiple authentication factors and calculating the data to be verified in combination with temporary public keys and random numbers, simultaneous verification of multi-factor authentication is realized, solving the problem of inefficiency in the existing technology, improving authentication efficiency and reducing resource consumption.

CN119945686APending Publication Date: 2025-05-06BEIJING CERTIFICATE AUTHORITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510148568.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing multi-factor authentication technology needs to perform their respective verification processes during the verification process, resulting in increased resource consumption and extended user waiting time, which is inefficient.

Method used

By obtaining the aggregated private keys and public keys corresponding to multiple authentication factors, combining temporary public keys and random numbers to calculate the data to be verified, and sending it to the server for verification, so as to achieve simultaneous verification of multiple factors in the identity authentication process.

Benefits of technology

Improve the efficiency of multi-factor authentication and reduce system resource consumption and user waiting time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945686A_ABST
    Figure CN119945686A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security, and particularly provides an identity authentication method based on multiple authentication factors, a medium, equipment and a product, and the method can comprise the steps: obtaining key data based on an identifier and multiple authentication factors; wherein the key data comprises an aggregation private key and an aggregation public key corresponding to the multiple authentication factors, and the identifier is a client identifier, or the client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; a temporary public key, a second random number and the secret key data are calculated, data to be verified are obtained, and the second random number is obtained from the server side; and sending the to-be-verified data to the server, so that the server verifies the to-be-verified data and confirms a verification result of the client. According to some embodiments of the invention, verification of multiple authentication factors can be realized in one identity authentication process at the same time, and the verification efficiency and security are high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and in particular to a method, medium, device and product for identity authentication based on multiple authentication factors. Background Art

[0002] Multi-Factor Authentication (MFA) is an advanced and widely adopted security measure that aims to greatly enhance the security of accounts and systems by requiring users to provide two or more different types of authentication factors when logging in or performing sensitive operations.

[0003] At present, in the process of multi-factor authentication, the terminal usually needs to perform verification on each authentication factor in turn. For example, in one verification process, it is necessary to first execute the password authentication protocol to verify the information entered by the user, and then verify the dynamic password (OTP) entered by the user. Although the user can be required to enter these two verification factors at the same time, the verification mechanisms they adopt are usually quite different, and their respective verification processes need to be executed separately, which significantly increases the resource consumption of the terminal system, increases the waiting time of the user, and reduces the efficiency of multi-factor authentication.

[0004] Therefore, how to provide a technical solution for an efficient method of identity authentication with multiple authentication factors has become a technical problem that needs to be solved urgently. Summary of the invention

[0005] The purpose of some embodiments of the present application is to provide a method, medium, device and product for identity authentication based on multiple authentication factors. Through the technical solution of the embodiments of the present application, multiple factors can be authenticated simultaneously in a single identity authentication process, thereby improving the efficiency of multi-factor authentication and reducing system resource consumption and user waiting time.

[0006] In a first aspect, some embodiments of the present application provide a method for identity authentication based on multiple authentication factors, including: obtaining key data based on an identifier and multiple authentication factors; wherein the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; a temporary public key, a second random number and the key data are calculated to obtain data to be verified, wherein the second random number is obtained from the server; the data to be verified is sent to the server so that the server can verify the data to be verified and confirm the verification result of the client.

[0007] Some embodiments of the present application use key data corresponding to the aggregation of multiple authentication factors, combined with a temporary public key and a second random number to calculate the data to be verified, and send it to the server for verification to obtain a verification result of the client identity. Some embodiments of the present application select multiple authentication factors to combine and aggregate key data, and the data to be verified is subsequently calculated based on the key data, so that multiple authentication factors in the data to be verified can be verified simultaneously in one identity authentication process, thereby improving the efficiency of multi-factor authentication and reducing system resource consumption and user waiting time.

[0008] In some embodiments, obtaining key data based on an identifier and multiple authentication factors includes: calculating the identifier and each of the multiple authentication factors to obtain a private key corresponding to each authentication factor; calculating the private key corresponding to each authentication factor to obtain a public key corresponding to each authentication factor; and calculating the private key corresponding to each authentication factor and the public key corresponding to each authentication factor according to preset rules to obtain the aggregated private key and the aggregated public key.

[0009] Some embodiments of the present application obtain the private key and public key corresponding to each authentication factor, and then obtain the aggregated private key and aggregated public key according to preset rules, so as to achieve aggregation of multiple authentication factors and provide data support for subsequent simultaneous multi-factor verification.

[0010] In some embodiments, before obtaining the key data based on the identifier and multiple authentication factors, the method also includes: generating a first random number, and generating the temporary public key based on the first random number; sending the client identifier and the temporary public key to the server so that the server can generate the second random number; and receiving the second random number sent by the server.

[0011] Some embodiments of the present application determine a temporary public key by generating a first random number, and obtain a second random number generated by a server, to provide data support for subsequent calculation of the data to be verified.

[0012] In some embodiments, before obtaining key data based on the identifier and multiple authentication factors, the method also includes: constructing at least one authentication factor set, wherein the types of authentication factors in each authentication factor set in the at least one authentication factor set are not completely the same; generating a set private key and a set public key corresponding to each authentication factor set; and sending the set public key corresponding to each authentication factor set to the server, so that the server can bind the set public key corresponding to each authentication factor set to the identifier to complete subsequent verification of the data to be verified.

[0013] Some embodiments of the present application can realize flexible combination of authentication factors by constructing an authentication factor set and binding the set public key corresponding to each authentication factor set with an identifier and storing it on the server side, and subsequently realize accurate identity and authority verification of clients with different authentication factor combinations.

[0014] In some embodiments, generating a set private key and a set public key corresponding to each authentication factor set includes: obtaining an authentication private key and an authentication public key corresponding to each authentication factor in each authentication factor set; and calculating the authentication private key and the authentication public key corresponding to each authentication factor according to an aggregation rule to obtain the set private key and the set public key.

[0015] Some embodiments of the present application obtain the authentication private key and the authentication public key of each authentication factor in each authentication factor set, and then calculate the set private key and the set public key according to the aggregation rule, so as to provide data support for subsequent client verification and realize simultaneous verification of multiple factors.

[0016] In some embodiments, the authentication factor includes a static factor and a dynamic factor; the static factor is a fixed value, and the dynamic factor is generated by the server and / or the client before each authentication stage.

[0017] Some embodiments of the present application support multiple different forms of authentication factors, are suitable for identity and authority verification in different scenarios, and are highly practical.

[0018] In a second aspect, some embodiments of the present application provide a method for identity authentication based on multiple authentication factors, comprising: receiving data to be verified sent by a client, wherein the data to be verified is obtained by key data obtained by the client based on an identifier and multiple authentication factors, a temporary public key generated by the client, and a second random number; the key data comprises: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier being a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; obtaining an authentication factor set associated with the multiple authentication factors, wherein the authentication factor set is stored in binding with the identifier; verifying the data to be verified by using a set public key corresponding to the authentication factor set to obtain a verification result for the client.

[0019] On the third aspect, some embodiments of the present application provide an identity authentication device based on multiple authentication factors, including: an acquisition module, used to acquire key data based on an identifier and multiple authentication factors; wherein the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; a calculation module, used to calculate a temporary public key, a second random number and the key data to obtain data to be verified, wherein the second random number is obtained from the server; a sending module, used to send the data to be verified to the server, so that the server can verify the data to be verified and confirm the verification result of the client.

[0020] In a fourth aspect, some embodiments of the present application provide an identity authentication device based on multiple authentication factors, comprising: a receiving module, used to receive data to be verified sent by a client, wherein the data to be verified is obtained by the client based on an identifier and multiple authentication factors. The key data obtains a temporary public key generated by the client and a second random number; the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; a retrieval module, used to obtain an authentication factor set associated with the multiple authentication factors, wherein the authentication factor set is bound to the identifier and stored; a verification module, used to verify the data to be verified through the set public key corresponding to the authentication factor set, and obtain a verification result for the client.

[0021] In a fifth aspect, some embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.

[0022] In a sixth aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement a method as described in any embodiment of the first aspect.

[0023] In a seventh aspect, some embodiments of the present application provide a computer program product, wherein the computer program product comprises a computer program, wherein the computer program, when executed by a processor, can implement the method described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the drawings required for use in some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0025] Figure 1 A system diagram of identity authentication based on multiple authentication factors provided for some embodiments of the present application;

[0026] Figure 2 One of the flow charts of the method for identity authentication based on multiple authentication factors provided in some embodiments of the present application;

[0027] Figure 3 A second flow chart of a method for identity authentication based on multiple authentication factors provided in some embodiments of the present application;

[0028] Figure 4 One of the block diagrams of the device composition for identity authentication based on multiple authentication factors provided in some embodiments of the present application;

[0029] Figure 5 The second block diagram of the device composition for identity authentication based on multiple authentication factors provided in some embodiments of the present application;

[0030] Figure 6 A schematic diagram of an electronic device is provided for some embodiments of the present application. DETAILED DESCRIPTION

[0031] The technical solutions in some embodiments of the present application will be described below in conjunction with the drawings in some embodiments of the present application.

[0032] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0033] In the related technologies, multi-factor authentication (MFA) usually introduces additional verification factors based on the traditional username and password. These additional verification factors usually include knowledge factors (such as passwords), ownership factors (such as mobile phones, hardware tokens), and biometric factors (such as fingerprints, facial recognition), etc. By comprehensively using these different types of verification factors, MFA can significantly improve the complexity and security of identity authentication, and effectively resist network attacks and identity theft. Therefore, MFA has become an important means to protect account security. Multi-factor authentication can use many user-related identity authentication factors, including PIN passwords (such as 6-digit passwords), biometric factors (fingerprints, facial features, etc.), item factors (such as SMS verification codes, email verification links, hardware dynamic tokens, etc.), location factors (such as IP ranges), time factors, etc. Multi-factor authentication must be two or more different types of authentication factors to achieve user identity authentication. The typical common scenario is that the user has a memorized password (PIN password) and receives a SMS verification code (OTP) through a mobile terminal.

[0034] In actual application scenarios, when users log in to a business system, it is usually necessary to execute an identity authentication protocol between the client and the server to enable the business system to identify the user's real identity / virtual identity, and then implement access control to system resources. To identify the user's identity, the server usually requires the user to enter a verification factor (such as a password) on the client, or the client collects the user's biometric factor. However, this process must ensure that sensitive information (such as a password) entered by the user is not leaked, which requires the use of a reasonably designed cryptographic protocol. The various entity authentication protocols given in the current standard can achieve one-way or two-way authentication, and the cryptographic protocols under the standard also provide strong support for key generation and signing. However, under the support of the above cryptographic protocols, in the process of verifying user identity and permissions, if multi-factor authentication is used, each factor needs to be independently verified in turn, which is inefficient and increases system resource consumption.

[0035] In view of this, some embodiments of the present application provide a method for identity authentication based on multiple authentication factors, which can randomly select multiple authentication factor combinations, and obtain the data to be verified by calculating the key data obtained from the multiple authentication factor combinations and identifiers, the temporary public key generated by the client, and the second random number of the server; the data to be verified is verified by the server in combination with the relevant data bound to the identifier, thereby obtaining the verification result of the client. Some embodiments of the present application can support the system to arbitrarily select several of the multiple identity authentication factors (i.e., authentication factors) for combination, and simultaneously realize the authentication of multiple factors in one identity authentication process, thereby improving the efficiency of multi-factor verification.

[0036] In the process of identity authentication, users need to control the user key pair (USK) hosted on the cloud signature platform, and usually need to implement a multi-factor authentication mechanism to perform remote key operations while verifying the user's identity. Multi-factor authentication (MFA) is a security authentication process that requires users to provide two or more different types of authentication factors to prove their identity, including passwords, fingerprints, SMS verification codes, smart cards, biometrics, and other combinations of factors, thereby improving the security and reliability of user accounts.

[0037] The user key pair (USK) is hosted on the cloud platform. The password (PIN password) and SMS verification code (OTP) can be used as authentication factors for remote proxy signatures. The user's life cycle management of the hosted key pair is achieved by designing relevant cryptographic protocol processes. When the electronic certification service agency (CA agency for short) issues a digital certificate for the public key of the USK and binds the certificate to the user's private key on the cloud signature platform (that is, the server, referred to as the cloud platform), the user can remotely call the hosted private key through PIN+OTP to execute the process of generating an electronic signature. In the cloud signature platform, the PIN is manually injected by the user in the signature terminal, and a client private key sk of the SM2 algorithm is derived on the client based on the PIN, and then the corresponding public key P is calculated. sk As identity authentication data, the cloud platform needs to provide password protocol processes such as PIN establishment, PIN verification, PIN reset, and PIN destruction to ensure the security of the PIN.

[0038] The following is combined with Figure 1 The overall composition structure of a system for identity authentication based on multiple authentication factors provided by some embodiments of the present application is exemplified.

[0039] like Figure 1 As shown, some embodiments of the present application provide a system for identity authentication based on multiple authentication factors, and the system for identity authentication based on multiple authentication factors includes: a client 100 and a server 200. Among them, the client 100 includes the mobile Internet terminal itself and the application (APP) running inside it, which can derive the client's temporary private key component based on the PIN, and is used to control the signature private key of the server 200. The user is the holder of the mobile Internet terminal, who can be responsible for setting the initial PIN during the initialization process of the mobile Internet terminal and for entering the private key PIN during the remote proxy signing process. The server 200 can be a cloud signature platform or a cryptographic service management system, which is used to create a signature private key for the user and provide relevant processes for key lifecycle management.

[0040] Specifically, Figure 1The server 200 in the process of identity authentication can perform user identity recognition when the user logs in to the server 200 through the client 100, and can also be used to verify that the user has control over the escrow private key when calling the user private key hosted by the cloud signature platform. The identity authentication protocol of the client 100 and the server 200 includes components such as key generation (KeyGen), verification binding (ValidationBinding), zero-knowledge verification (ZeroKnowledgeValidation), key reset (KeyReset) and key revocation (KeyDestroy). These components have a fixed design pattern, and different public key cryptographic operations can be selected as needed to implement them. The public key cryptographic operations involved in the relevant processes in the embodiments of the present application can all adopt a pre-selected elliptic curve cryptographic system. Various types of ECC cryptographic systems can also be used in the embodiments of the present application, including ECDSA, EdDSA, SM2, GOST R34.10, etc.

[0041] The following first briefly introduces the functions of these components.

[0042] The key generation component usually derives a temporary private key sk based on the authentication factor, and then calculates the public key P corresponding to sk according to the specified cryptographic algorithm system. sk . When generating a key pair (sk,P sk ), the user must first complete the user registration process on the cloud platform. The cloud platform assigns a user identifier (UserID) to the user. If the key pair is also used to verify the control of the managed private key, the cloud signature platform is required to also assign a key identifier (KeyID) to the managed private key. To generate a temporary private key sk, the client 100 usually uses a password-based key derivation function (PBKDF), at which time the authentication factor data π needs to be input into the PBKDF function. For different types of authentication factors, the method of generating authentication factor data π is different, and the PBKDF function used can also be different. For example, for biometric factors, the biometrics can be converted into authentication factor data π through technical means such as "fuzzy extraction".

[0043] The verification binding component is used to use the public key derived from the relevant authentication factor as the identity authentication material of the server. That is, the public key calculated by the client 100 is submitted to the server 200 and bound to the user identifier UserKey and the key identifier KeyID. Different verification binding strategies can be adopted for different types of authentication factors. The public keys of some factors can be generated in advance and stored on the server, while other factors (such as dynamic passwords) need to be temporarily generated in each authentication process and dynamically bound on the server as identity authentication materials. In order to realize multi-factor authentication, the embodiment of the present application allows the client 100 and the server 200 to arbitrarily combine multiple identity authentication materials (i.e., multiple authentication factors), that is, select m from N identity authentication materials, and allow different modes to be used for combination (addition, multiplication, mixed mode, etc.), see the following embodiment for details.

[0044] The zero-knowledge verification component mainly uses digital signatures based on public key cryptography to implement zero-knowledge verification. The protocol process requires the client 100 and the server 200 to generate and exchange the first random number R c And Rs, then the client 100 signs the constructed message (ie, the data to be verified) and submits it to the server 200, and then the server 200 verifies whether the signature is valid to confirm that the client 100 holds the private key sk corresponding to the relevant authentication factor.

[0045] The key reset component is used to perform a key reset process to update the identity authentication material when the user loses the authentication factor (such as PIN).

[0046] The key revocation component is used to execute the key revocation process and delete the identity authentication materials related to multi-factor authentication when revoking a digital certificate or canceling a user account.

[0047] The following is combined with Figure 2 The implementation process of identity authentication based on multiple authentication factors performed by the client 100 provided in some embodiments of the present application is exemplified.

[0048] Please see attached Figure 2 , Figure 2 A flowchart of a method for identity authentication based on multiple authentication factors is provided for some embodiments of the present application. It can be understood that before identity authentication is performed, it is first necessary to bind and store identity authentication materials related to the identity authentication of the client 100 on the server 200. Therefore, when executing Figure 2 Before S210 in the above, the method for identity authentication based on multiple authentication factors may further include (not shown in the figure):

[0049] S201: Construct at least one authentication factor set, wherein the types of authentication factors in each authentication factor set in the at least one authentication factor set are not completely the same.

[0050] For example, in some embodiments of the present application, in order to allow the server 200 to arbitrarily select a number of authentication factors for aggregation, it is necessary to enumerate all possible sets of multiple authentication factors, and calculate the corresponding set private key and set public key for each possible combination. That is, according to fixed rules, multiple combinations of multiple authentication factors are determined, and an authentication factor set containing one or more selected authentication factors is constructed. Each authentication factor set U = {F1, F2, ...}, where F1 and F2 represent different types of authentication factors. For example, F1 represents a password, F2 represents a fingerprint, etc.

[0051] S202: Generate a set private key and a set public key corresponding to each authentication factor set.

[0052] For example, in some embodiments of the present application, for each authentication factor set U, the client 100 calculates the set private key sk agg and the collective public key P agg .sk agg =G 1 (sk i ,sk j ...), P agg =G 2 (P sk[i] , P sk[j] ...). Among them, the function G 1 and G 2 Must match and satisfy the key pair relationship, that is, P agg =[sk agg ]G, where G is the base point of the elliptic curve. Different aggregation rules can be used to form a collective private key between the private keys sk of different factors, such as addition, multiplication or hybrid algorithm.

[0053] In some embodiments of the present application, S202 may include: obtaining the authentication private key and the authentication public key corresponding to each authentication factor in each authentication factor set; calculating the authentication private key and the authentication public key corresponding to each authentication factor according to the aggregation rule to obtain the set private key and the set public key.

[0054] For example, in some embodiments of the present application, by calculating the authentication private key sk corresponding to each authentication factor in an authentication factor set i and the authentication public key P sk[i] Then, according to the aggregation rule, the sk corresponding to the entire authentication factor set is calculated. agg and P agg .

[0055] In one embodiment, when the additive aggregation rule is used, G 1 =ski +sk j +...mod n, and correspondingly take G 2 =P sk[i] +P sk[j] +... For the operation of elliptic curve points, the symbol "+" represents the point addition operation, and n is the order of the base point G.

[0056] In another embodiment, when the multiplication aggregation rule is adopted, G 1 =sk i *sk j *...mod n, and correspondingly take G 2 =[sk i *sk j *...mod n]G. For the operation of elliptic curve points, the symbol "*" represents modular multiplication operation, and the symbol "[]" represents multiple point operation.

[0057] In another embodiment, when the addition and multiplication mixed aggregation rule is adopted, G 1 =sk i *sk j *(sk l +sk m +...)...mod n, and correspondingly take G 2 =[sk i *sk j *...mod n](P sk[l] +P sk[m] +...). For the operation of elliptic curve points, the symbol "*" represents modular multiplication operation, "+" represents point addition operation, for G1, "+" represents modular addition operation, and the symbol "[]" represents multiple point operation. If "+" is within the symbol "[]", it represents modular addition operation. Whether "+" represents point addition operation or modular addition operation can be determined according to the operation of the algorithm actually selected, and the embodiment of the present application does not make specific limitations here.

[0058] For aggregation involving multiplication, if the dynamic factors are involved in the operation, the client 100 needs to calculate the collective public key of all static factors and their combinations, and the multiple point operation involving dynamic factors needs to be completed by the server 200, that is, the order in which dynamic factors participate in the operation should be after static factors. Since dynamic factors change in each authentication, they cannot be pre-calculated, and it is reasonable to apply these factors to the collective private key at the end.

[0059] The following is an example of a key pair of a single authentication factor in an authentication set, namely, the authentication private key sk and the authentication public key P sk The calculation process.

[0060] Specifically, ① after the server 200 obtains the identifier ID (ID = UserID, or ID = UserID || KeyID), it selects a 128-bit random number as the salt value salt associated with the ID. ② The server 200 sends the identifier ID and the salt value salt to the client 100. ③ The client 100 obtains the authentication factor data π. ④ The client 100 calculates the authentication private key sk = F kdf (ID, salt, π). ⑤ The client 100 uses sk as the input value and performs multiple point operations on the elliptic curve according to the pre-selected elliptic curve cryptography to obtain the authentication public key corresponding to sk: P sk =[sk]G, where G is the base point of the elliptic curve.

[0061] It should be noted that in step ④, the appropriate klen can be selected according to different cryptographic systems, and the corresponding PBKDF function can be selected. At the same time, the original text of the PBKDF input can contain data such as UserID, KeyID, salt, π, etc. Their order is not fixed, and only part of the data can be used, or other secret data jointly held by the client 100 and the server 200 can be added. If the calculation form of sk is changed, the same calculation formula must be used when restoring the private key component sk of the client 100 in the subsequent "verification process" step.

[0062] In addition, the input parameters of key derivation can also introduce an optional parameter "authentication factor type (T)", that is, the derivation function is changed to sk = F kdf (ID, salt, T, π), so that when multiple authentication factor data are completely consistent (for example, the password and the SMS OTP are exactly the same), the derived result sk is also different. Specifically, the data input to the PBKDF function can be determined according to the actual application scenario, and the embodiment of this application is not specifically limited here.

[0063] In the multi-authentication factor verification process, for different types of authentication factors, the way to generate authentication factor data π is different. For example, for the one-time verification code OTP sent by the server 200, π=OTP can be set. For biometric factors, the biometrics can be converted into authentication factor data π through technical means such as "fuzzy extraction", and then input into the PBKDF function to obtain sk.

[0064] After obtaining different types of authentication factor data, a key derivation function can be used to calculate sk = F kdf (ID, salt, π). Then, sk is used as the input value, and the multiple point operation of the elliptic curve is performed according to the pre-selected elliptic curve cryptography system to obtain the P corresponding to sk. sk :P sk=[sk]G, where G is the base point of the elliptic curve. This allows us to get the sk corresponding to different types of authentication factors. i ,sk j ,sk l ,sk m etc., and then we get P sk[i] , P sk[j] , P sk[l] , P sk[m] wait.

[0065] S203, sending the set public key corresponding to each authentication factor set to the server, so that the server binds the set public key corresponding to each authentication factor set with the identifier to complete subsequent verification of the data to be verified.

[0066] For example, in some embodiments of the present application, the client 100 can obtain the sk corresponding to each authentication factor set U by calculation: agg and P agg , then P agg Send to the server 200, the server 200 can agg Bind and store with UserID and KeyID. Identity authentication data V π =P agg If N authentication factors are used in U, the server 200 will assign an independent number 1 to n to each authentication factor, and inform the client 100 of the meaning of each number. The server 200 will store the corresponding identity authentication data V π1 、V π2 ,…,V πn .

[0067] In some embodiments of the present application, the authentication factor includes a static factor and a dynamic factor; the static factor is a fixed value, and the dynamic factor is generated by the server and / or the client before each authentication stage.

[0068] When the server 200 of the present application verifies the binding process of the set public key, there are differences in the binding process of the static factor and the dynamic factor. The following is an example of the verification and binding process of a single authentication factor on the server 200.

[0069] For a static factor, a fixed authentication factor data π (as a specific example of a fixed value) can be obtained, and the verification binding process includes:

[0070] ① The server 200 identifies the user's identity. Usually, the user enters the mobile phone number through the user interface of the client 100, and then performs SMS verification. If the SMS verification fails, the process ends. ② The server 200 and the client 100 cooperate to perform the relevant steps of the "Key Generation (KeyGen) process", so that the client 100 obtains the salt value salt sent by the server 200, and calculates sk and P sk ③ Client 100 sends ID and public key P sk Sent to the server 200. ④ The server 200 stores the identity authentication data V of the user private key USK π =P sk , and establish a binding relationship with UserID and KeyID so that it can be retrieved and used in the subsequent verification process.

[0071] For dynamic factors, since the authentication factor data π is different in each verification process, the binding process cannot be performed in advance, but is dynamically bound before each verification process (i.e., each authentication stage). The verification binding process occurs in each verification process and mainly includes the following steps:

[0072] ① The server 200 identifies the user, usually by the user entering a mobile phone number through the client's user interface, and then performing SMS verification. If the SMS verification fails, the process ends. ② The server 200 generates a one-time authentication factor data π for this authentication, obtains the salt value salt associated with the identifier ID, and then calculates sk and the corresponding P sk ③ The server 200 stores the identity authentication data V of the user private key USK π =P sk , and establish a binding relationship with UserID and KeyID in the cache system so that it can be retrieved and used in the subsequent verification process.

[0073] It is understandable that the dynamic binding process must meet a condition that the server 200 and the client 100 can obtain the one-time authentication factor data π independently. A typical scenario is that the server 200 generates a random one-time password and then sends it to the client 100 through out-of-band communication (such as SMS), or the client 100 has a token that generates a dynamic password based on hardware, and can generate a one-time password consistent with the dynamic password system, thereby obtaining the dynamic authentication factor data π.

[0074] After executing the above embodiment, the server 200 obtains and stores the identity authentication data V π1 、V π2 ,…,V πn Afterwards, the following verification process can be performed to confirm that the client 100 has the corresponding π. Figure 2 The implementation process of the identity authentication method based on multiple authentication factors is shown.

[0075] In some embodiments of the present application, before executing S210, the method of identity authentication based on multiple authentication factors may also include: generating a first random number, and generating the temporary public key based on the first random number; sending the client identifier and the temporary public key to the server so that the server can generate the second random number; and receiving the second random number sent by the server.

[0076] For example, in some embodiments of the present application, the client 100 uses the service interface of the local operating system to obtain the first random number R c ∈[1,n-1], and R c As the input value, calculate the multiple points of the elliptic curve according to the pre-selected elliptic curve cryptography system to obtain the temporary public key: P RC =[R c ]G, where G is the base point of the elliptic curve. Then, the client 100 sends the identifier ID and the temporary public key P RC The server 200 receives the temporary public key P sent by the client 100. RC Afterwards, the server 200 generates a 128-bit random number R through the random number generator provided by the cryptographic device. S ∈[1,n-1] (as a specific example of the second random number). The corresponding salt value salt is retrieved according to the ID sent by the client 100. The server 200 converts R S and salt value salt are sent to the signing client 100.

[0077] S210, obtaining key data based on an identifier and multiple authentication factors; wherein the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type.

[0078] For example, in some embodiments of the present application, after obtaining the identifier ID, the client 100 can calculate the aggregate private key sk by combining the selected multiple authentication factors. agg and the aggregate public key P agg. Among them, ID can be ID=UserID, or ID=UserID||KeyID, wherein UserID is the client identifier and KeyID is the key identifier. If the authentication process is only to authenticate the client identity, then ID=UserID; if the client's key authority needs to be verified, then ID=UserID||KeyID. Based on the user's input, the client 100 can select several authentication factors (usually 2, such as PIN+OTP) from n authentication factors, and obtain the set selected for this multi-factor authentication according to pre-established rules: W={F1,F2,...} (as a specific example of multiple authentication factors). Alternatively, the client 100 and the server 200 can jointly negotiate to select a set W.

[0079] In some embodiments of the present application, S210 may include:

[0080] S211, calculating the identifier and each of the multiple authentication factors to obtain a private key corresponding to each authentication factor.

[0081] For example, in some embodiments of the present application, since the authentication factor data π of each authentication factor input does not meet the randomness requirement of the cryptographic operation, the client 100 needs to perform a key derivation step to derive the private key sk of the client 100. That is, the authentication factor data π of the i-th authentication factor is obtained. i , the client 100 calculates the private key sk of the i-th authentication factor i =F kdf (ID,π i ). The i-th authentication factor is any one of the multiple authentication factors.

[0082] S212, calculating the private key corresponding to each authentication factor to obtain the public key corresponding to each authentication factor.

[0083] For example, in some embodiments of the present application, based on sk i Calculate the public key corresponding to the i-th authentication factor: P sk[i] =[sk i ]G, where G is the base point of the elliptic curve.

[0084] S213: Calculate the private key corresponding to each authentication factor and the public key corresponding to each authentication factor according to a preset rule to obtain the aggregated private key and the aggregated public key.

[0085] For example, in some embodiments of the present application, the client 100 calculates the aggregate private key sk according to the preset rule (ie, the above aggregation rule) agg =G 1 (sk i ,skj ,...), and calculate the corresponding aggregate public key: P agg =G 2 (P sk[i] ,P sk[j] ,...). The aggregation rule can be selected according to the actual application scenario, and the present application embodiment does not specifically limit it. It should be noted that if the client 100 is capable of storing security-sensitive parameters, the client 100 can calculate P in the identity authentication data injection process. sk[i] And stored locally, no need to recalculate in this step.

[0086] S220, calculating the temporary public key, the second random number and the key data to obtain the data to be verified, wherein the second random number is obtained from the server.

[0087] For example, in some embodiments of the present application, the client 100 obtains the aggregate private key sk agg , temporary public key P RC and the server random number R S After that, the following process is performed to obtain the data to be verified to prove to the server 200 that it holds the private key sk agg , and the server 200 uses the identity authentication data V injected in the establishment process π To verify the zero-knowledge proof submitted by the client 100. Specifically, the process of obtaining the data to be verified z is as follows: the client 100 calculates the data to be verified z, z = F zk (sk agg ,R S ,P agg ,P RC ), where the appropriate function F can be selected according to different cryptographic systems zk .

[0088] For example, taking the entity authentication protocol using the zero-knowledge proof mechanism, the Schnorr scheme based on the SM2 elliptic curve cryptography system is adopted, and the client 100 and the server 200 perform multiple stages of interaction to achieve the goal of the client 100 proving to the server 200 that it has the authentication factor data π as an example, the acquisition process of z is exemplified:

[0089]

[0090] Among them, H 256 The SHA256 hash algorithm may be used, or the SM3 hash algorithm specified in the GB / T 32905-2016 standard may be used.

[0091] S230, sending the data to be verified to the server, so that the server can verify the data to be verified and confirm the verification result of the client.

[0092] For example, in some embodiments of the present application, the client 100 sends z to the server 200. After receiving the data to be verified, the server obtains the authentication factor number selected this time according to the authentication factor set W received in the above stage, and then retrieves the identity authentication data corresponding to each authentication factor respectively, and calculates the corresponding aggregate public key for verification: P agg1 =G 2 (P sk[i] ,P sk[j] ,...). Alternatively, since the types of authentication factors are usually limited, the server 200 can pre-calculate and store the aggregated public keys corresponding to different authentication factor combinations and store them securely. Finally, the server 200 uses all the data received previously to execute the verification function H=F VERIFY (z,P RC ,P agg1 ,R S ) to check whether these data meet the pre-set conditions and verify the data according to the verification function F VERIFY The output result of F is used to determine whether the verification of the client 100 is passed. For example, function F VERIFY The verification passes if the relevant input parameters satisfy the specific equation, otherwise the verification fails.

[0093] For example, taking the above-mentioned Schnorr scheme as an example, after receiving z, the server 200 calculates P agg1 Then, calculate Q 1 =P agg1 +P RC =(x,y),c 1 =H 256 (R S ||x||y); then determine whether [z]G is equal to P RC +[c 1 ]P agg1 If they are equal, the verification passes, otherwise the verification fails.

[0094] It is understandable that, in addition to using the Schnorr scheme in the above scheme for calculating and verifying the data to be verified, any of the following schemes may be used: a scheme based on SM2 signature, performing multiple point operations of the SM2 elliptic curve in accordance with the provisions of the GB / T 32918.1-2016 standard; a scheme based on ECDSA signature, performing multiple point operations of the ECDSA elliptic curve in accordance with the provisions of the FIPS186-5 standard; a scheme based on EdDSA signature, performing multiple point operations of the EdDSA elliptic curve in accordance with the provisions of the FIPS186-5 standard; a scheme based on GHOST 34.10 signature, performing multiple point operations of the GOST R 34.10 elliptic curve in accordance with the provisions of the RFC 7091 standard, etc. The embodiments of the present application are not specifically limited here.

[0095] For example, in the SM2 signature-based scheme, taking a single authentication factor as an example, the calculation process of z includes: the client sets the signature original msg = R c ||R S ||KeyID, then calculate (r,s)=SIGN according to the SM2 digital signature algorithm specified in the GB / T32918.2-2016 standard sk (msg), and then set z = (r, s). Among them, r = (e + x R ) mod n, s = (1 + sk) -1 (kr*sk)mod n. The process of the server verifying whether z is valid is as follows: verify whether z is valid according to the SM2 digital signature algorithm specified in the GB / T 32918.2-2016 standard, that is, calculate (x',y')=[s]G+[r+s]P sk , and check whether the following result is true: whether r is equal to x'+H v (msg). Where e=H v (msg), hash algorithm H v The SM3 hash algorithm specified in the GB / T32905-2016 standard is used. If there are multiple authentication factors in the application scenario, the sk in the above formula is sk agg , P sk Then P agg1 .

[0096] For example, in a scheme based on ECDSA signature, taking a single authentication factor as an example, the calculation process of z includes: the client sets the signature original msg = Rc||R S ||KeyID, then calculate (r, s) = SIGN according to the ECDSA digital signature algorithm specified in the FIPS186-5 standard sk (msg), then set z = (r, s). Where r = x Rmod n,s=k -1 (e+r*sk)mod n. The process of the server verifying whether z is valid is as follows: verify whether z is valid according to the ECDSA digital signature algorithm specified in the FIPS186-5 standard, that is, calculate (x',y') = [e*s -1 ]G+[r*s -1 ]P sk , and check whether the following result is true: whether r is equal to x'+H v (msg). Where e=H v (msg), hash algorithm H v The SHA-256 cryptographic hash algorithm specified in the FIPS180-4 standard is used. If there are multiple authentication factors in the application scenario, the sk in the above formula is sk agg , P sk Then P agg1 .

[0097] For example, in a scheme based on EdDSA signature, taking a single authentication factor as an example, the calculation process of z includes: the client sets the signature original msg = R c ||R S ||KeyID, and then calculate (R, s) = SIGN according to the EdDSA digital signature algorithm specified in the FIPS186-5 standard sk (msg), and then set z = (R, s). Among them, R = [r] G, s = (r + digest * sk) mod n. The process of the server verifying whether z is valid is as follows: Verify whether z is valid according to the EdDSA digital signature algorithm specified in the FIPS186-5 standard, that is, calculate and check whether the following results are true: [s] G is equal to R + [digest] P SK If there are multiple authentication factors in the application scenario, then sk in the above formula is sk agg , P sk Then P agg1 .

[0098] For example, in the scheme based on GHOST 34.10 signature, taking a single authentication factor as an example, the calculation process of z includes: the client sets the signature original text msg = R c ||R S ||KeyID, then execute the GOST R34.10 digital signature algorithm according to the provisions of RFC 7091 standard to calculate (r, s) = SIGN sk (msg), then set z = (r, s). Where r = x Rmod n, s = (r*sk + k*e) mod n. The process of the server verifying whether z is valid is as follows: According to the provisions of RFC 7091 standard, the GOSTR 34.10 digital signature algorithm is executed to verify whether z is valid, that is, (x', y') = [s*e -1 ]G+[-r*e -1 ]P sk , and check whether the following result is true: whether r is equal to x'. Where e=H v (msg), hash algorithm H v The GOSTR 34.11 cryptographic hash algorithm specified in the RFC 6986 standard is used. If there are multiple authentication factors in the application scenario, the sk in the above formula is sk agg , P sk Then P agg1 .

[0099] In some embodiments of the present application, in a method for identity authentication based on multiple authentication factors, the server is used to receive data to be verified sent by the client, wherein the data to be verified is obtained by the client based on an identifier and multiple authentication factors. The key data is obtained by the client based on key data, a temporary public key generated by the client, and a second random number; the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; an authentication factor set associated with the multiple authentication factors is obtained, wherein the authentication factor set is bound to the identifier and stored; the data to be verified is verified by using a set public key corresponding to the authentication factor set to obtain a verification result for the client.

[0100] It should be understood that the specific verification process of the server can refer to the method embodiment provided above and will not be repeated here.

[0101] In addition, in some embodiments of the present application, the reset and revocation of the identity authentication data on the server 200 side can also be supported. For example, if the user forgets some authentication factors (such as the certificate PIN), the key reset process can be used to regain control of the escrow private key. The key reset process is basically the same as the above verification binding establishment process, but there is no need to perform the step of generating USK. The server 200 will update the identity authentication data V associated with the USK. π . Update the identity authentication data V π, which means that the control of the escrow private key may change. In order to ensure the security of the escrow private key, the identity verification step must be performed before the key reset process. The identity of the user can be verified by sending a random verification code to the contact information (mobile phone number) associated with the USK. In order to further improve security, users can be required to perform an identity authentication process based on biometric recognition (such as face recognition) before resetting the key. The key destruction (revocation) process usually occurs at the stage of revoking a certificate or canceling a user's account. In addition to deleting the USK stored in the database, the identity authentication data V associated with the USK should also be deleted. π .

[0102] It should be understood that the parameters used in the above-mentioned related calculation formulas can be appropriately increased or decreased as long as it can be proved that the above-mentioned parameters are consistent with the above-mentioned parameters. sk The equation must hold true if the public and private keys match. In addition, the client generates a random number R c The step of sending the temporary public key can return the random number R on the server side. S In other embodiments, the client may initiate an authentication process to the server, and then send a temporary public key in the zero-knowledge verification step. Although the server may authenticate the identity of the client, the client may authenticate the identity of the server, and the embodiments of the present application are not limited to this.

[0103] The following is combined with Figure 3 The specific process of identity authentication based on multiple authentication factors provided by some embodiments of the present application is exemplified.

[0104] Please see attached Figure 3 , Figure 3 A flow chart of a method for identity authentication based on multiple authentication factors is provided for some embodiments of the present application.

[0105] The following uses the two authentication factors of certificate PIN and one-time password (OTP) (these two authentication factors can be considered to form an authentication factor set) to calculate the aggregate public key by addition, where the certificate PIN is a static authentication factor and OTP is a dynamic authentication factor as an example to illustrate the zero-knowledge verification process of the key. It can be understood that before verification, the server has stored the following content: static factor data π PIN The corresponding public key storage P PIN-SK , as the identity authentication data V PIN , and establish a binding relationship with UserID and KeyID; dynamic factor data π OTP The corresponding public key P OTP-SK Calculated and dynamically bound during each authentication process.

[0106] S301, after the client selects the authentication factor set, it generates a random number R c , and calculate the temporary public key.

[0107] For example, the temporary public key P Rc =[R c ]G.

[0108] S302, the client sends the key identifier KeyID and P Rc Sent to the server.

[0109] S303, the server generates a random number R S and retrieve the corresponding salt value salt through KeyID.

[0110] S304, the server sends R S and salt to the client.

[0111] S305: The client obtains static factor data and dynamic factor data in the authentication factor set.

[0112] For example, π PIN =PIN,π OTP =OTP.

[0113] S306: The client calculates the private key and public key corresponding to the static factor and the dynamic factor respectively based on the static factor data and the dynamic factor data.

[0114] For example, if klen=256, the private key sk corresponding to the static factor and the dynamic factor is calculated according to the following formula: PIN and sk OTP 、Public key P PIN-SK and P OTP-SK :sk=PBKDF(UserID||salt||π,klen),P SK =[sk]G.

[0115] S307, the client calculates the aggregated private key and the aggregated public key corresponding to the two authentication factors.

[0116] For example, the aggregate private key sk agg0 =sk PIN +sk OTP mod 2, aggregate public key P agg0 =P PIN-SK +P OTP-SK

[0117] S308, the client calculates the data z to be verified based on the temporary public key, the aggregated private key and the aggregated public key, and sends it to the server.

[0118] Among them, the specific calculation method of z and the signature scheme used can be selected according to the actual application scenario, and the embodiment of the present application does not make any specific limitations here.

[0119] For example, z is calculated as follows:

[0120]

[0121] S309, the server calculates the aggregate public key P for verification based on the pre-bound stored data agg1 .

[0122] S310, the server is based on P agg1 Verify z and obtain the verification result of the client.

[0123] The way the server verifies z corresponds to the signature scheme used in the specific calculation of z, thereby achieving accurate identification of the client's identity.

[0124] For example, the verification standard data V is first calculated according to the following formula:

[0125]

[0126] Let L = [z]G, and determine whether L and V are equal. If so, the verification passes, otherwise the verification fails.

[0127] It should be noted that when the authentication factor changes, the identity authentication data changes, the identity authentication data V can be updated or deleted. PIN The specific selection can be made according to the actual situation, and the embodiments of the present application are not limited thereto.

[0128] It should be understood that the specific implementation process of S301 to S310 can refer to the method embodiment provided above, and in order to avoid repetition, the detailed description is appropriately omitted here.

[0129] Through some of the above-mentioned embodiments of the present application, it can be seen that the multi-factor identity authentication scheme proposed in the present application can realize the simultaneous verification of any multiple authentication factors in a single identity authentication process, and adopts a standard signature algorithm (such as the SM2 algorithm) as the underlying module, which improves the efficiency of multi-factor identity authentication and is conducive to ensuring the compliance of the algorithm implementation.

[0130] Please refer to Figure 4 , Figure 4The block diagram of the composition of the device for identity authentication based on multiple authentication factors provided by some embodiments of the present application is shown. It should be understood that the device for identity authentication based on multiple authentication factors corresponds to the above method embodiment and can execute each step involved in the above method embodiment. The specific functions of the device for identity authentication based on multiple authentication factors can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.

[0131] Figure 4 The device for identity authentication based on multiple authentication factors includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the device for identity authentication based on multiple authentication factors. The device for identity authentication based on multiple authentication factors is applied to a client, including: an acquisition module 410, used to acquire key data based on an identifier and multiple authentication factors; wherein the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; a calculation module 420, used to calculate a temporary public key, a second random number and the key data to obtain data to be verified, wherein the second random number is obtained from the server; a sending module 430, used to send the data to be verified to the server, so that the server can verify the data to be verified and confirm the verification result of the client.

[0132] Please refer to Figure 5 , Figure 5 The block diagram of the composition of the device for identity authentication based on multiple authentication factors provided by some embodiments of the present application is shown. It should be understood that the device for identity authentication based on multiple authentication factors corresponds to the above method embodiment and can execute each step involved in the above method embodiment. The specific functions of the device for identity authentication based on multiple authentication factors can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.

[0133] Figure 5The device for identity authentication based on multiple authentication factors includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the device for identity authentication based on multiple authentication factors. The device for identity authentication based on multiple authentication factors is applied to a server, including: a receiving module 510, used to receive data to be verified sent by a client, wherein the data to be verified is obtained by key data obtained by the client based on an identifier and multiple authentication factors, a temporary public key generated by the client, and a second random number; the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; a retrieval module 520, used to obtain an authentication factor set associated with the multiple authentication factors, wherein the authentication factor set is stored in binding with the identifier; a verification module 530, used to verify the data to be verified through a set public key corresponding to the authentication factor set, and obtain a verification result for the client.

[0134] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0135] Some embodiments of the present application further provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the operations of the method corresponding to any of the above methods provided in the above embodiments.

[0136] Some embodiments of the present application further provide a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the operations corresponding to any of the above methods provided in the above embodiments.

[0137] like Figure 6 As shown, some embodiments of the present application provide an electronic device 600, which includes: a memory 610, a processor 620, and a computer program stored in the memory 610 and executable on the processor 620, wherein the processor 620 can implement a method as described in any of the above embodiments when reading the program from the memory 610 through a bus 630 and executing the program.

[0138] Processor 620 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 620 can be a microprocessor.

[0139] The memory 610 may be used to store instructions executed by the processor 620 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 620 of the disclosed embodiment may be used to execute instructions in the memory 610 to implement the method shown above. The memory 610 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.

[0140] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0141] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0142] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

Claims

1. A method for identity authentication based on multiple authentication factors, characterized in that: include: Based on the identifier and multiple authentication factors, key data is obtained; wherein the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; Calculate the temporary public key, the second random number and the key data to obtain the data to be verified, wherein the second random number is obtained from the server; The data to be verified is sent to the server so that the server can verify the data to be verified and confirm the verification result of the client.

2. The method according to claim 1, characterized in that The obtaining of key data based on the identifier and multiple authentication factors includes: Calculating the identifier and each of the multiple authentication factors to obtain a private key corresponding to each authentication factor; Calculate the private key corresponding to each authentication factor to obtain the public key corresponding to each authentication factor; The private key corresponding to each authentication factor and the public key corresponding to each authentication factor are calculated respectively according to preset rules to obtain the aggregated private key and the aggregated public key.

3. The method according to claim 1 or 2, characterized in that Before obtaining key data based on the identifier and the multiple authentication factors, the method further includes: Generate a first random number, and generate the temporary public key based on the first random number; Sending the client identifier and the temporary public key to the server so that the server can generate the second random number; Receive the second random number sent by the server.

4. The method according to claim 1 or 2, characterized in that: Before obtaining key data based on the identifier and the multiple authentication factors, the method further includes: Constructing at least one authentication factor set, wherein the types of authentication factors in each authentication factor set in the at least one authentication factor set are not completely the same; Generate a set private key and a set public key corresponding to each authentication factor set; The set public key corresponding to each authentication factor set is sent to the server, so that the server can bind the set public key corresponding to each authentication factor set with the identifier to complete the subsequent verification of the data to be verified.

5. The method according to claim 4, characterized in that The generating of a set private key and a set public key corresponding to each authentication factor set includes: Obtain the authentication private key and authentication public key corresponding to each authentication factor in each authentication factor set; The authentication private key and the authentication public key corresponding to each authentication factor are calculated according to the aggregation rule to obtain the collective private key and the collective public key.

6. The method according to any one of claims 1, 2 and 5, characterized in that: The authentication factor includes a static factor and a dynamic factor; the static factor is a fixed value, and the dynamic factor is generated by the server and / or the client before each authentication phase.

7. A method for identity authentication based on multiple authentication factors, characterized in that: include: Receive data to be verified sent by a client, wherein the data to be verified is obtained by key data obtained by the client based on an identifier and multiple authentication factors, a temporary public key generated by the client, and a second random number; the key data includes: an aggregated private key and an aggregated public key corresponding to the multiple authentication factors, the identifier is a client identifier, or a client identifier and a key identifier; one authentication factor corresponds to one identity authentication type; Acquire an authentication factor set associated with the multiple authentication factors, wherein the authentication factor set is stored in binding with the identifier; The data to be verified is verified by using the set public key corresponding to the authentication factor set to obtain a verification result for the client.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program executes the method according to any one of claims 1 to 7 when executed by a processor.

9. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the computer program executes the method according to any one of claims 1 to 7 when being run by the processor.

10. A computer program product, characterized in that The computer program product comprises a computer program, wherein the computer program executes the method according to any one of claims 1 to 7 when executed by a processor.