Enhanced application method, system and device based on FIDO biological recognition standard
By using digital certificates in the FIDO server to authenticate the FIDO authentication response packets and bind them to third-party CA digital certificates, the problem of insufficient authentication of the FIDO standard in financial fields and other scenarios is solved, and user authentication with higher security and compliance is achieved.
Patent Information
- Application Number
- CN202411913296.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing FIDO standards have limitations when combined with digital certificates and PKI systems, and fail to effectively verify the user's true identity, resulting in restrictions in specific application scenarios such as the financial field.
By authenticating the FIDO authentication response message using pre-stored digital certificates in the FIDO server and binding it with a third-party CA digital certificate, an enhanced application method, system and device based on the FIDO biometric standard is realized.
It enhances the security and compliance of FIDO authentication methods, realizes real authentication of user identity, expands the application scenarios of FIDO authentication, and has higher applicability in the financial field.
Smart Images

Figure CN119945724A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of user authentication, and in particular to an enhanced application method, system and device based on the FIDO biometric standard. Background Art
[0002] The FIDO (Fast Identity Online) standard is an international standard designed to improve the security and convenience of online identity authentication. FIDO aims to replace the traditional password authentication mechanism with public key cryptography to provide a more secure and easy-to-use authentication method. Its standard specifies the protocol process between FIDO clients, FIDO authenticators and FIDO servers, involving cryptographic operations such as private key signatures and public key authentication. In the FIDO system, the user's identity is authenticated through public key cryptography, thus avoiding the risks in traditional password systems, such as password leakage and phishing attacks. The core goal of FIDO is to improve the security of identity authentication and enhance the user experience by eliminating the use of passwords, and to support a wider range of device and platform interoperability.
[0003] However, the existing FIDO standard also has certain limitations, especially in terms of integration with existing digital certificates and PKI (public key infrastructure) systems. The FIDO standard itself does not combine key management with digital certificates and lacks true authentication of user identity. This means that FIDO authentication does not verify the true identity of the user, but only verifies the key pair of a device or authenticator. In China, since third-party CA digital certificates are particularly important in the financial field, many financial institutions (such as banks) rely on CA authentication to confirm the legitimacy of user identities. However, the FIDO standard does not involve authentication at this level, which has led to its being restricted in some specific application scenarios, such as in the financial field such as banks. Summary of the invention
[0004] The embodiments of the present disclosure at least provide an enhanced application method, system and device based on the FIDO biometric standard, which realizes the binding of the biometric authentication service based on the FIDO standard with the third-party CA digital certificate, and enhances the security and compliance of the FIDO authentication method.
[0005] The embodiment of the present disclosure provides an enhanced application method based on the FIDO biometrics standard, which is applied to a FIDO server, including:
[0006] In response to the application authentication request, generate a FIDO authentication request message, and send the FIDO authentication request message to the FIDO client;
[0007] Receive a FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message; and use a pre-stored digital certificate to authenticate the FIDO authentication response message to determine an authentication result corresponding to the application authentication request.
[0008] In some possible embodiments, before responding to the application authentication request, the step includes:
[0009] In response to the application registration request, a FIDO authentication policy message is generated, and the FIDO authentication policy message is sent to the FIDO client, so that the FIDO client performs biometric identification based on the FIDO authentication policy message, and returns a FIDO registration information response message if the biometric identification passes; wherein the FIDO authentication policy message includes a digital certificate identification; and the FIDO registration information response message includes user key information, a signature value, and registration information;
[0010] Receive the FIDO registration information response message; and send the registration information to a third-party CA system;
[0011] Receive and store the digital certificate generated by the third-party CA system according to the registration information; wherein the digital certificate is stored in the database of the FIDO server.
[0012] In some possible embodiments, the user key information includes a user private key and a user public key; wherein the user private key is stored in the FIDO client, and the user public key is stored in a database of the FIDO server;
[0013] The registration information includes the user information and the user public key signed with the user private key;
[0014] The digital certificate includes a public key and a private key, wherein the public key is the same as the user's public key, and the private key is the same as the user's private key.
[0015] In some possible embodiments, sending the registration information to a third-party CA system includes:
[0016] The signature value in the FIDO registration information response message is verified using the user public key, and if the signature value verification is successful, the registration information is sent to a third-party CA system.
[0017] In some possible embodiments, the FIDO authentication request message includes a random number, and the FIDO authentication response message is obtained by the FIDO client using a user private key to authenticate and sign the random number.
[0018] In some possible embodiments, the authenticating the FIDO authentication response message using a pre-stored digital certificate includes:
[0019] The FIDO authentication response message is authenticated using the public key in the pre-stored digital certificate to obtain the authentication result.
[0020] The disclosed embodiment provides an enhanced application system based on the FIDO biometric standard, including a FIDO client and a FIDO server;
[0021] The FIDO server generates a FIDO authentication request message in response to the application authentication request, and sends the FIDO authentication request message to the FIDO client;
[0022] The FIDO client generates a FIDO authentication response message according to the FIDO authentication request message, and sends the FIDO authentication response message to the FIDO server;
[0023] The FIDO server uses a pre-stored digital certificate to authenticate the FIDO authentication response message and determines an authentication result corresponding to the application authentication request.
[0024] The embodiment of the present disclosure provides an enhanced application device based on the FIDO biometrics standard, which is applied to a FIDO server, including:
[0025] A message generation module, configured to generate a FIDO authentication request message in response to an application authentication request, and send the FIDO authentication request message to a FIDO client;
[0026] The message authentication module is used to receive a FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message; and use a pre-stored digital certificate to authenticate the FIDO authentication response message to determine an authentication result corresponding to the application authentication request.
[0027] In some possible embodiments, the message generation module is further used to:
[0028] In response to the application registration request, a FIDO authentication policy message is generated, and the FIDO authentication policy message is sent to the FIDO client, so that the FIDO client performs biometric identification based on the FIDO authentication policy message, and returns a FIDO registration information response message if the biometric identification passes; wherein the FIDO authentication policy message includes a digital certificate identification; and the FIDO registration information response message includes user key information, a signature value, and registration information;
[0029] Receive the FIDO registration information response message; and send the registration information to a third-party CA system;
[0030] Receive and store the digital certificate generated by the third-party CA system according to the registration information; wherein the digital certificate is stored in the database of the FIDO server.
[0031] In some possible embodiments, the user key information includes a user private key and a user public key; wherein the user private key is stored in the FIDO client, and the user public key is stored in a database of the FIDO server;
[0032] The registration information includes the user information and the user public key signed with the user private key;
[0033] The digital certificate includes a public key and a private key, wherein the public key is the same as the user's public key, and the private key is the same as the user's private key.
[0034] In some possible embodiments, the message generation module is further used to:
[0035] The signature value in the FIDO registration information response message is verified using the user public key, and if the signature value verification is successful, the registration information is sent to a third-party CA system.
[0036] In some possible embodiments, the FIDO authentication request message includes a random number, and the FIDO authentication response message is obtained by the FIDO client using a user private key to authenticate and sign the random number.
[0037] In some possible embodiments, the message authentication module is specifically used to:
[0038] The FIDO authentication response message is authenticated using the public key in the pre-stored digital certificate to obtain the authentication result.
[0039] An embodiment of the present disclosure provides a computer device, including: a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the computer device is running, the processor communicates with the memory via the bus, and when the machine-readable instructions are executed by the processor, an enhanced application method based on the FIDO biometric standard as described in any possible implementation manner described above is performed.
[0040] An embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the enhanced application method based on the FIDO biometric standard as described in any possible implementation manner described above is implemented.
[0041] The enhanced application method, system and device based on the FIDO biometric standard provided in the embodiments of the present disclosure use a pre-stored digital certificate to authenticate the FIDO authentication response message during the authentication process, thereby realizing the binding of the biometric authentication service based on the FIDO standard with the third-party CA digital certificate, and enhancing the security and compliance of the FIDO authentication method.
[0042] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required to be cited in the embodiments. The drawings herein are incorporated into the specification and constitute a part of the specification. These drawings illustrate embodiments consistent with the present disclosure and are used together with the specification to illustrate the technical solutions of the present disclosure. It should be understood that the following drawings only illustrate certain embodiments of the present disclosure and should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0044] Figure 1 A flowchart of an enhanced application method based on the FIDO biometric standard provided by an embodiment of the present disclosure is shown;
[0045] Figure 2 A flowchart of a FIDO-based application registration method provided by an embodiment of the present disclosure is shown;
[0046] Figure 3 A schematic diagram of a FIDO-based application registration method provided by an embodiment of the present disclosure is shown;
[0047] Figure 4 A schematic diagram of a FIDO-based application authentication method provided by an embodiment of the present disclosure is shown;
[0048] Figure 5 A schematic diagram of the structure of an enhanced application system based on the FIDO biometric standard provided by an embodiment of the present disclosure is shown;
[0049] Figure 6 A schematic diagram of the structure of an enhanced application device based on the FIDO biometrics standard provided by an embodiment of the present disclosure is shown;
[0050] Figure 7 A schematic diagram of the structure of a computer device provided by an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0051] In order to make the purpose, technical scheme and advantages of the embodiments of the present disclosure clearer, the technical scheme in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all of the embodiments. The components of the embodiments of the present disclosure generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present disclosure provided in the drawings is not intended to limit the scope of the present disclosure for protection, but merely represents the selected embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present disclosure.
[0052] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, further definition and explanation thereof is not required in subsequent drawings.
[0053] The term "and / or" herein only describes an association relationship, indicating that three relationships may exist. For example, A and / or B may represent the following three situations: A exists alone, A and B exist at the same time, and B exists alone. In addition, the term "at least one" herein represents any combination of at least two of any one or more of a plurality of. For example, including at least one of A, B, and C may represent including any one or more elements selected from the set consisting of A, B, and C.
[0054] FIDO (Fast Identity Online) is an international standard designed to improve the security and convenience of online identity authentication. Its core goal is to provide a more secure and easy-to-use identity authentication method by eliminating the use of traditional password mechanisms. The design of the FIDO standard is based on public key encryption technology to replace the traditional password verification system to avoid security risks such as password leakage and phishing attacks.
[0055] Research has found that although the FIDO standard has achieved remarkable results in improving the security and convenience of identity authentication, it also has certain limitations, especially in terms of integration with existing digital certificates and public key infrastructure (PKI) systems. The FIDO standard itself does not closely integrate key management with digital certificates, and lacks comprehensive authentication of user identities. Specifically, the FIDO authentication mechanism does not verify the real identity of the user, it only verifies the key pair of a device or authenticator. Although this authentication method can effectively prevent password leaks and phishing attacks, it does not involve in-depth verification of user identities and lacks sufficient confirmation of user identities.
[0056] In China, especially in the financial sector, third-party CA digital certificates still play a vital role. Many financial institutions (such as banks) rely on CA certification to confirm the legitimacy of user identities to ensure the security of transactions and operations. However, the FIDO standard fails to cover this digital certificate-based identity authentication requirement, so in some specific application scenarios, especially in financial fields such as banks, the application of the FIDO standard is subject to certain restrictions.
[0057] Based on the above research, an enhanced application method, system and device based on the FIDO biometric standard are provided in an embodiment of the present disclosure. The method is applied to a FIDO server, including: generating a FIDO authentication request message in response to an application authentication request, and sending the FIDO authentication request message to a FIDO client; receiving a FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message; and authenticating the FIDO authentication response message using a pre-stored digital certificate to determine an authentication result corresponding to the application authentication request.
[0058] During the authentication process, this embodiment uses a pre-stored digital certificate to authenticate the FIDO authentication response message, thereby implementing the binding of the FIDO standard-based biometric authentication service with a third-party CA digital certificate, and enhancing the security and compliance of the FIDO authentication method.
[0059] To facilitate understanding of this embodiment, the execution subject of the enhanced application method based on the FIDO biometric standard provided by the embodiment of the present disclosure is first introduced in detail. The execution subject of the enhanced application method based on the FIDO biometric standard provided by the embodiment of the present disclosure is a computer device. The computer device can be a server. Among them, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, big data and artificial intelligence platforms.
[0060] The following is a detailed description of the enhanced application method based on the FIDO biometrics standard provided by the embodiment of the present application in conjunction with the accompanying drawings. Figure 1 As shown, it is a flowchart of an enhanced application method based on the FIDO biometric standard provided by an embodiment of the present disclosure, and the method includes the following S101-S102:
[0061] S101, in response to an application authentication request, generating a FIDO authentication request message, and sending the FIDO authentication request message to a FIDO client.
[0062] It is understandable that a FIDO server is a server-side system specially designed to process authentication requests. It follows the standard protocol established by the FIDO Alliance and supports multiple authentication methods, such as biometrics, PIN codes, etc. A FIDO client refers to a user's device (such as a smartphone, tablet, or laptop), which has client software that supports the FIDO protocol installed on it, can receive authentication requests from a FIDO server, and interact with the user to complete the authentication process.
[0063] Specifically, after the FIDO server receives the authentication request generated by the application, it will generate a FIDO authentication request message, which contains the authentication requirements for the FIDO client. Among them, the FIDO authentication request message may include a random number, an authentication method indication (such as a biometric method), and context information related to authentication (such as a user session identifier). After the FIDO authentication request message, the FIDO server sends it to the FIDO client to enable the FIDO client to implement biometric authentication according to the FIDO authentication request message.
[0064] For example, refer to Figure 2 As shown, before responding to the application authentication request, it is also necessary to implement a FIDO-based application registration process, including the following steps S201 to S203:
[0065] S201, in response to an application registration request, generate a FIDO authentication policy message, and send the FIDO authentication policy message to the FIDO client, so that the FIDO client performs biometric identification based on the FIDO authentication policy message, and returns a FIDO registration information response message if the biometric identification passes.
[0066] It is understandable that after the FIDO server receives the registration request from the application, it will generate a FIDO authentication policy message and send it to the FIDO client. The FIDO authentication policy message includes information such as authentication policy, random number and digital certificate identification. Among them, the authentication policy is used to inform the rules of how to execute authentication, such as what authentication method to use (such as biometrics, PIN code, etc.); the random number is used to enhance the security of the message and prevent replay attacks, that is, to ensure that each authentication request is unique and cannot be maliciously resent to defraud authentication; the digital certificate identification is used to inform the FIDO client that it needs to apply for a digital certificate.
[0067] Exemplarily, after sending the FIDO authentication policy message to the FIDO client, the FIDO client executes the corresponding identity authentication process according to the instructions in the message, usually confirming the user's identity through biometric technology (such as fingerprint recognition, facial recognition, etc.). Here, the purpose of biometrics is to ensure that only legitimate users can complete the registration and enhance the security of identity authentication. After the biometric process is passed, the FIDO client will generate and return a FIDO registration information response message, which contains not only the user key information, but also a signature value generated using the FIDO preset device private key. Among them, the user key information includes the user public key and the user private key. The user public key is closely related to the user's identity information. The user public key will be sent to the FIDO server and stored in its database for use in future authentication processes. The user private key is stored in a secure environment of the FIDO client to ensure that only the client can use it to sign the authentication request, thereby providing strong identity protection.
[0068] Specifically, since there is a digital certificate identification identifier in the FIDO authentication policy message, this means that an application for a digital certificate is required during this registration process. At this time, the FIDO client will generate registration information according to the PKCS#10 standard, namely a digital certificate application (P10 application for short); PKCS stands for Public-Key Cryptography Standards, and #10 is the 10th specification in the standard. PKCS#10 describes the structure of a standard certificate request message, namely the syntax of a certificate signing request (CSR), which is mainly used to apply for a digital certificate. In the structure of the P10 application, the client will write user information, such as customer number, ID number or enterprise unique identifier, which is used to identify the applicant. At the same time, the public key part of the P10 application is the user public key generated by the FIDO client; the private key is the user private key generated by the FIDO client.
[0069] Here, in order to ensure the integrity and authenticity of the registration information (P10 application), the FIDO client will also use the user's private key to sign the P10 application. As the core part of the P10 request, it can prove that the application is indeed issued by the FIDO client and that the data has not been tampered with during transmission. Through the signature, the FIDO client provides strong security protection for the P10 application, ensuring the integrity of the request and the validity of the authentication.
[0070] In this way, the security and reliability of FIDO authentication are ensured, allowing users to confirm their identity through the authentication mechanism when registering, while ensuring the security of data during storage and transmission.
[0071] S202, receiving the FIDO registration information response message; and sending the registration information to a third-party CA system.
[0072] It is understandable that when the FIDO server receives the FIDO registration information response message, the FIDO server uses the user's public key to verify the signature value in the message to confirm that the response message is indeed generated by the relevant user in the registration process, ensuring the integrity of the message and the authenticity of the source. If the signature value verification is successful, the FIDO server will send the registration information to a third-party certification authority (CA) system to implement the application for a digital certificate. Among them, the third-party CA (Certification Authority) system is a system for issuing and managing digital certificates. Its main function is to verify and ensure the security, integrity and authenticity of data and communications transmitted on the Internet.
[0073] S203: Receive and store the digital certificate generated by the third-party CA system according to the registration information.
[0074] It is understandable that after the third-party CA system receives the registration information, it will generate a digital certificate based on the registration information, and then send it to the FIDO server and store it in the database of the FIDO server for use in the subsequent authentication process. Here, this digital certificate is the proof of the user's identity in the FIDO system.
[0075] In order to better understand the application registration process proposed in this disclosure, Figure 3 For detailed description, refer to Figure 3As shown, first, after receiving the registration request from the application, the FIDO server generates a FIDO authentication policy message and sends it to the FIDO client. The message contains information such as authentication policy, random number and digital certificate identification. Then, after receiving the authentication policy message, the FIDO client performs identity authentication according to the content of the message, usually using biometric technology (such as fingerprint recognition or facial recognition) to confirm the user's identity. After the verification is passed, the FIDO client generates and returns a FIDO registration information response message, which includes the user's public key and private key. The user's public key is associated with the identity information. The public key will be sent to the FIDO server, and the private key will be saved in the client's environment for subsequent authentication signatures. Here, the FIDO client will also generate digital certificate application information according to the PKCS#10 standard based on the digital certificate identification in the FIDO authentication policy message. This information includes user identification information (such as customer number, ID number, etc.) and public key information, and the user's private key is used to sign the application information to ensure the integrity and authenticity of the information. After receiving the registration information response message, the FIDO server verifies the signature through the user's public key to ensure the source and integrity of the message. After successful verification, the server sends the user registration information to a third-party certification authority (CA) system to apply for a digital certificate. Finally, the third-party CA system generates a digital certificate based on the registration information and returns it to the FIDO server, which stores it in the database as proof of the user's identity for subsequent identity authentication.
[0076] The present disclosure completes the strong binding relationship between the FIDO user key and the digital certificate during the registration process, and FIDO has the function of authenticating the real identity. Among them, the FIDO user private key is the digital certificate private key, which is stored in the FIDO client environment, and the FIDO user public key is the public key in the digital certificate, which is stored in the database of the FIDO server, and the digital certificate is also stored in the database of the FIDO server.
[0077] S102, receiving a FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message; and authenticating the FIDO authentication response message using a pre-stored digital certificate to determine an authentication result corresponding to the application authentication request.
[0078] Here, after receiving the request, the FIDO client will generate an authentication response message according to the requirements in the request. The response message is usually obtained by the FIDO client using the user's private key to authenticate the random number. By signing the random number, the authenticity and integrity of the response message are ensured, and tampering is also prevented.
[0079] Specifically, after the FIDO server receives the FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message, the FIDO server will use the pre-stored digital certificate to verify it. Specifically, the FIDO response message is authenticated using the public key in the pre-stored digital certificate to ensure that the message is indeed generated by the FIDO client and has not been tampered with, and to confirm that the identity information provided by the client matches the pre-stored certificate information, thereby avoiding identity forgery or replay attacks. Through the above method, the FIDO server can determine whether the user identity is authentic and valid, and ultimately obtain the authentication result corresponding to the application authentication request. If the digital signature verification is successful, it means that the user's identity has been effectively confirmed and the authentication is passed; otherwise, the authentication request fails, and the system will take corresponding measures, such as denying access or requiring re-authentication.
[0080] The identity authentication process disclosed in the present invention is authenticated through a digital certificate public key, which adds real identity authentication to the FIDO authentication method, enhances security and compliance, and expands the application scenarios of FIDO authentication.
[0081] In order to better understand the application authentication process proposed in this disclosure, Figure 4 For detailed description. Figure 4 As shown, during the FIDO application authentication process, after receiving the application authentication request, the FIDO server generates a FIDO authentication request message containing the authentication requirements. The message includes a random number, an authentication method indication (such as biometrics), and related context information (such as a user session identifier). Subsequently, the FIDO server sends the authentication request to the FIDO client, and the FIDO client interacts with the user to complete the authentication process based on the message content. After the FIDO client receives the authentication request, it generates a FIDO authentication response message according to the requirements in the request. The response message has been digitally signed by the user's private key for the random number in the request to ensure the authenticity and integrity of the response and prevent tampering in the middle. Finally, after the FIDO server receives the response message, it uses the public key in the pre-stored digital certificate to verify it, confirming that the message is generated by the FIDO client and has not been tampered with, thereby verifying whether the identity information matches the stored certificate information to prevent identity forgery or replay attacks.
[0082] The enhanced application method, system and device based on the FIDO biometric standard provided in the embodiments of the present disclosure use a pre-stored digital certificate to authenticate the FIDO authentication response message during the authentication process, thereby realizing the binding of the biometric authentication service based on the FIDO standard with the third-party CA digital certificate, and enhancing the security and compliance of the FIDO authentication method.
[0083] Those skilled in the art will appreciate that, in the above method of specific implementation, the order in which the steps are written does not imply a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of the steps should be determined by their functions and possible internal logic.
[0084] Based on the same inventive concept, the embodiments of the present disclosure also provide an enhanced application system based on the FIDO biometric standard corresponding to the enhanced application method based on the FIDO biometric standard. Since the principle of solving the problem by the device in the embodiments of the present disclosure is similar to the enhanced application method based on the FIDO biometric standard mentioned above in the embodiments of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0085] Reference Figure 5 As shown, an enhanced application system based on the FIDO biometric standard provided by an embodiment of the present disclosure includes a FIDO client and a FIDO server;
[0086] The FIDO server is configured to generate a FIDO authentication request message in response to the application authentication request, and send the FIDO authentication request message to the FIDO client;
[0087] The FIDO client is used to generate a FIDO authentication response message according to the FIDO authentication request message, and send the FIDO authentication response message to the FIDO server;
[0088] The FIDO server is further configured to authenticate the FIDO authentication response message using a pre-stored digital certificate to determine an authentication result corresponding to the application authentication request.
[0089] Based on the same inventive concept, the embodiments of the present disclosure also provide an enhanced application device based on the FIDO biometric standard corresponding to the enhanced application method based on the FIDO biometric standard. Since the principle of solving the problem by the device in the embodiments of the present disclosure is similar to the enhanced application method based on the FIDO biometric standard mentioned above in the embodiments of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0090] Reference Figure 6 FIG. 6 is a schematic diagram of an enhanced application device 600 based on the FIDO biometric standard provided by an embodiment of the present disclosure, wherein the device is applied to a FIDO server and includes:
[0091] The message generation module 601 is used to generate a FIDO authentication request message in response to the application authentication request, and send the FIDO authentication request message to the FIDO client;
[0092] The message authentication module 602 is used to receive a FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message; and use a pre-stored digital certificate to authenticate the FIDO authentication response message to determine an authentication result corresponding to the application authentication request.
[0093] In some possible embodiments, the message generation module 601 is further used to:
[0094] In response to the application registration request, a FIDO authentication policy message is generated, and the FIDO authentication policy message is sent to the FIDO client, so that the FIDO client performs biometric identification based on the FIDO authentication policy message, and returns a FIDO registration information response message if the biometric identification passes; wherein the FIDO authentication policy message includes a digital certificate identification; and the FIDO registration information response message includes user key information, a signature value, and registration information;
[0095] Receive the FIDO registration information response message; and send the registration information to a third-party CA system;
[0096] Receive and store the digital certificate generated by the third-party CA system according to the registration information; wherein the digital certificate is stored in the database of the FIDO server.
[0097] In some possible embodiments, the user key information includes a user private key and a user public key; wherein the user private key is stored in the FIDO client, and the user public key is stored in a database of the FIDO server;
[0098] The registration information includes the user information and the user public key signed with the user private key;
[0099] The digital certificate includes a public key and a private key, wherein the public key is the same as the user's public key, and the private key is the same as the user's private key.
[0100] In some possible embodiments, the message generation module 601 is further used to:
[0101] The signature value in the FIDO registration information response message is verified using the user public key, and if the signature value verification is successful, the registration information is sent to a third-party CA system.
[0102] In some possible embodiments, the FIDO authentication request message includes a random number, and the FIDO authentication response message is obtained by the FIDO client using a user private key to authenticate and sign the random number.
[0103] In some possible embodiments, the message authentication module 602 is specifically used to:
[0104] The FIDO authentication response message is authenticated using the public key in the pre-stored digital certificate to obtain the authentication result.
[0105] Based on the same technical concept, the embodiment of the present disclosure also provides a computer device. Figure 7 , which is a schematic diagram of the structure of a computer device 700 provided in an embodiment of the present disclosure, including a processor 701, a memory 702, and a bus 703. The memory 702 is used to store execution instructions, including a memory 7021 and an external memory 7022; the memory 7021 is also called an internal memory, which is used to temporarily store the operation data in the processor 701 and the data exchanged with the external memory 7022 such as a hard disk. The processor 701 exchanges data with the external memory 7022 through the memory 7021.
[0106] In the embodiment of the present application, the memory 702 is specifically used to store the application code for executing the solution of the present application, and the execution is controlled by the processor 701. That is, when the computer device 700 is running, the processor 701 communicates with the memory 702 through the bus 703, so that the processor 701 executes the application code stored in the memory 702, and then executes the method described in any of the above embodiments.
[0107] Among them, the memory 702 can be, but is not limited to, random access memory (Random Access Memory, RAM), read only memory (Read Only Memory, ROM), programmable read-only memory (Programmable Read-Only Memory, PROM), erasable programmable read-only memory (Erasable Programmable Read-Only Memory, EPROM), electrically erasable read-only memory (Electric Erasable Programmable Read-Only Memory, EEPROM), etc.
[0108] Processor 701 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present invention may be implemented or executed. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0109] It is to be understood that the structure illustrated in the embodiment of the present application does not constitute a specific limitation on the computer device 700. In other embodiments of the present application, the computer device 700 may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0110] The present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the enhanced application method based on the FIDO biometric standard described in the above method embodiment are executed. The storage medium can be a volatile or non-volatile computer-readable storage medium.
[0111] The embodiments of the present disclosure also provide a computer program product, which carries a program code. The instructions included in the program code can be used to execute the steps of the enhanced application method based on the FIDO biometric standard described in the above method embodiment. For details, please refer to the above method embodiment, which will not be repeated here.
[0112] The computer program product may be implemented in hardware, software or a combination thereof. In one optional embodiment, the computer program product is implemented as a computer storage medium. In another optional embodiment, the computer program product is implemented as a software product, such as a software development kit (SDK).
[0113] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the system and device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here. In the several embodiments provided in the present disclosure, it should be understood that the disclosed system and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0114] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0115] In addition, each functional unit in each embodiment of the present disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0116] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0117] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present disclosure, which are used to illustrate the technical solutions of the present disclosure, rather than to limit them. The protection scope of the present disclosure is not limited thereto. Although the present disclosure is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed in the present disclosure, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.
Claims
1. An enhanced application method based on the FIDO biometric standard, characterized in that: Applicable to FIDO servers, including: In response to the application authentication request, generate a FIDO authentication request message, and send the FIDO authentication request message to the FIDO client; Receive a FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message; and use a pre-stored digital certificate to authenticate the FIDO authentication response message to determine an authentication result corresponding to the application authentication request.
2. The method according to claim 1, characterized in that Before responding to the application authentication request, the method includes: In response to the application registration request, a FIDO authentication policy message is generated, and the FIDO authentication policy message is sent to the FIDO client, so that the FIDO client performs biometric identification based on the FIDO authentication policy message, and returns a FIDO registration information response message if the biometric identification passes; wherein the FIDO authentication policy message includes a digital certificate identification; and the FIDO registration information response message includes user key information, a signature value, and registration information; Receive the FIDO registration information response message; and send the registration information to a third-party CA system; Receive and store the digital certificate generated by the third-party CA system according to the registration information; wherein the digital certificate is stored in the database of the FIDO server.
3. The method according to claim 2, characterized in that The user key information includes a user private key and a user public key; wherein the user private key is stored in the FIDO client, and the user public key is stored in the database of the FIDO server; The registration information includes the user information and the user public key signed with the user private key; The digital certificate includes a public key and a private key, wherein the public key is the same as the user's public key, and the private key is the same as the user's private key.
4. The method according to claim 3, characterized in that The sending the registration information to the third-party CA system includes: The signature value in the FIDO registration information response message is verified using the user public key, and if the signature value verification is successful, the registration information is sent to a third-party CA system.
5. The method according to claim 1, characterized in that The FIDO authentication request message includes a random number, and the FIDO authentication response message is obtained by the FIDO client using a user private key to authenticate and sign the random number.
6. The method according to claim 5, characterized in that The using a pre-stored digital certificate to authenticate the FIDO authentication response message includes: The FIDO authentication response message is authenticated using the public key in the pre-stored digital certificate to obtain the authentication result.
7. An enhanced application system based on the FIDO biometric standard, characterized in that: The system includes a FIDO client and a FIDO server; The FIDO server generates a FIDO authentication request message in response to the application authentication request, and sends the FIDO authentication request message to the FIDO client; The FIDO client generates a FIDO authentication response message according to the FIDO authentication request message, and sends the FIDO authentication response message to the FIDO server; The FIDO server uses a pre-stored digital certificate to authenticate the FIDO authentication response message and determines an authentication result corresponding to the application authentication request.
8. An enhanced application device based on the FIDO biometric standard, characterized in that: Applicable to FIDO servers, including: A message generation module, configured to generate a FIDO authentication request message in response to an application authentication request, and send the FIDO authentication request message to a FIDO client; The message authentication module is used to receive a FIDO authentication response message generated by the FIDO client according to the FIDO authentication request message; and use a pre-stored digital certificate to authenticate the FIDO authentication response message to determine an authentication result corresponding to the application authentication request.
9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Identity authentication method and identity authentication system
CN112953970A
A FIDO authentication device capable of identity confirmation or non-repudiation and the method thereof
KR1020180087739A