Identity authentication method and system based on intercommunication and mutual recognition of login identities
By adopting an identity authentication method based on login identity communication and mutual recognition in the tax system, the problem of taxpayers' repeated registration and login in different systems is solved, seamless coordination between systems is achieved, and tax payment experience is improved.
Patent Information
- Application Number
- CN202411939518.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-26
AI Technical Summary
In the existing tax system, taxpayers need to repeatedly register and log in in different systems, resulting in poor tax payment experience and insufficient coordination and complementary capabilities between systems.
An identity authentication method and system based on login identity mutual communication and mutual recognition is proposed. Through the steps of sending, verifying, encryption and decrypting token information, the user's identity is mutual communication and mutual recognition, and ensures that the user's login status is consistent among different systems.
It realizes seamless login between different tax systems, reduces the steps of repeated registration and login, improves the tax payment experience, and enhances the coordination and complementarity between systems.
Smart Images

Figure CN119945736A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication, and more specifically, to an identity authentication method and system based on mutual communication and recognition of login identities. Background Art
[0002] In order to continuously improve the business collaboration capabilities among various tax systems, continuously enhance taxpayers' tax handling experience, avoid repeated registration and login of the same taxpayer in different tax systems, and realize the intelligent, convenient and seamless business handling of various business systems under the tax system.
[0003] Therefore, considering taxpayers' ease, convenience of use, improved experience, and coordination and complementarity between systems, it is an urgent issue to plan to achieve interoperability and mutual recognition of identity information and identity authentication between the unified identity management platform and the natural person electronic tax bureau.
[0004] Therefore, an identity authentication method based on mutual communication and recognition of login identities is needed. Summary of the invention
[0005] The present invention proposes an identity authentication method and system based on mutual communication and mutual recognition of login identities to solve the problem of how to achieve mutual communication and mutual recognition of identities.
[0006] In order to solve the above problem, according to one aspect of the present invention, an identity authentication method based on mutual communication and mutual recognition of login identities is provided, the method comprising:
[0007] When the request recipient triggers an identity intercommunication and mutual recognition request, the token information is sent to the request recipient;
[0008] The request receiving party verifies the token information, authenticates the account authentication information input by the user when the token information is verified, logs in when the authentication is passed, and returns the user identity information of the user to the request sending party;
[0009] The request sender encrypts the user identity information and returns the ciphertext information to the request receiver;
[0010] The request receiving party decrypts the ciphertext and determines whether the user is a real-name registered user who meets level 4 based on the decrypted user identity information;
[0011] When the request receiver determines that the user is a real-name registered user who meets level 4 requirements, it creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request reception and allows the user to log in to the system.
[0012] Preferably, the method further comprises:
[0013] When a user is required to log in to the natural person electronic tax bureau based on the unified identity management platform, and the natural person electronic tax bureau trusts the unified identity management platform, the request sender is the natural person electronic tax bureau, and the request receiver is the unified identity management platform;
[0014] When the user needs to log in to the unified identity management platform based on the natural person electronic tax bureau and the unified identity management platform trusts the natural person electronic tax bureau, the request sender is the unified identity management platform and the request receiver is the natural person electronic tax bureau.
[0015] Preferably, the token information is an access token Access Token in the OAuth 2.0 authorization mechanism; the token information includes: the source of the request, a preliminary user identifier temporarily obtained by the request sender, security verification information, a timestamp and a callback address.
[0016] Preferably, the encryption method is SM2 or JWT Token.
[0017] Preferably, when the request receiving party determines that the user is a real-name registered user who meets the fourth level, it creates its own session and associates it with the session ID of the request sending party, so that the request sending party trusts the request reception and allows the user to enter the system in a logged-in state, including:
[0018] When the request recipient determines that the user is a real-name registered user who meets the fourth level, it determines whether it is a corporate account. If it is a corporate account, it converts the permissions and personal identity information. If it is not a corporate account, it establishes a token correspondence and returns its own token to the request sender, so that the request sender recommends a binding relationship based on the token, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
[0019] According to another aspect of the present invention, there is provided an identity authentication system based on mutual communication and recognition of login identities, the system comprising:
[0020] A token information sending unit, used to send token information to the request receiving party when the request receiving party triggers the identity intercommunication and mutual recognition request;
[0021] An authentication and login unit, used for the request receiving party to verify the token information, authenticate the account authentication information input by the user when the token information is verified, log in when the authentication is passed, and return the user identity information of the user to the request sending party;
[0022] An encryption unit, used for the request sender to encrypt the user identity information and return the ciphertext information to the request receiver;
[0023] A level judgment unit, configured for the request receiving party to decrypt the ciphertext and judge whether the user is a real-name registered user meeting level 4 based on the decrypted user identity information;
[0024] The trusted login unit is used to create its own session and associate it with the session ID of the request sender when the request receiver determines that the user is a real-name registered user who meets the fourth level, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
[0025] Preferably, the system further comprises:
[0026] When a user is required to log in to the natural person electronic tax bureau based on the unified identity management platform, and the natural person electronic tax bureau trusts the unified identity management platform, the request sender is the natural person electronic tax bureau, and the request receiver is the unified identity management platform;
[0027] When the user needs to log in to the unified identity management platform based on the natural person electronic tax bureau and the unified identity management platform trusts the natural person electronic tax bureau, the request sender is the unified identity management platform and the request receiver is the natural person electronic tax bureau.
[0028] Preferably, the token information is an access token Access Token in the OAuth 2.0 authorization mechanism; the token information includes: the source of the request, a preliminary user identifier temporarily obtained by the request sender, security verification information, a timestamp and a callback address.
[0029] Preferably, the encryption method is SM2 or JWT Token.
[0030] Preferably, the trust login unit, when the request receiving party determines that the user is a real-name registered user who meets the fourth level, creates its own session and associates it with the session ID of the request sending party, so that the request sending party trusts the request reception and allows the user to enter the system in a logged-in state, including:
[0031] When the request recipient determines that the user is a real-name registered user who meets the fourth level, it determines whether it is a corporate account. If it is a corporate account, it converts the permissions and personal identity information. If it is not a corporate account, it establishes a token correspondence and returns its own token to the request sender, so that the request sender recommends a binding relationship based on the token, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
[0032] The present invention provides an identity authentication method and system based on mutual communication and recognition of login identities, comprising: when a request receiving party triggers a request for mutual communication and recognition of identities, sending token information to the request receiving party; the request receiving party verifies the token information, authenticates the account authentication information input by the user after the token information verification is passed, logs in after the authentication is passed, and returns the user identity information of the user to the request sending party; the request sending party encrypts the user identity information and returns the ciphertext information to the request receiving party; the request receiving party decrypts the ciphertext and determines whether the user is a real-name registered user who meets level four based on the decrypted user identity information; when the request receiving party determines that the user is a real-name registered user who meets level four, creates its own session and associates it with the session ID of the request sending party, so that the request sending party trusts the request receiving and allows the user to enter the system in a logged-in state. The present invention aims at users logging into multiple application systems at the same time to avoid repeated registration and repeated login, and proposes a solution for mutual communication and recognition of login identity and login status. It can verify the authorization channel and user information through trust transmission to complete the system login and realize "one-time registration, mutual recognition of two systems". Login can be completed without repeated registration. Taxpayers can handle electronic tax bureau and natural person electronic tax bureau business collaboratively across systems, reducing the taxpayers' repeated registration / change operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:
[0034] Figure 1 It is a flow chart of an identity authentication method 100 based on mutual communication and mutual recognition of login identities according to an embodiment of the present invention;
[0035] Figure 2 A schematic diagram of the interaction between a request sender and a request receiver according to an embodiment of the present invention;
[0036] Figure 3 It is a structural diagram of an identity authentication system 300 based on mutual communication and mutual recognition of login identities according to an embodiment of the present invention;
[0037] Figure 4 is a schematic diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0038] Now, exemplary embodiments of the present invention are described with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely and to fully convey the scope of the present invention to those skilled in the art. The terms used in the exemplary embodiments shown in the accompanying drawings are not intended to limit the present invention. In the accompanying drawings, the same units / elements are marked with the same reference numerals.
[0039] Unless otherwise specified, the terms (including technical terms) used herein have the commonly understood meanings to those skilled in the art. In addition, it is understood that the terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.
[0040] Figure 1 FIG. 1 is a flow chart of an identity authentication method 100 based on mutual recognition of login identities according to an embodiment of the present invention. Figure 1 As shown, the identity authentication method based on mutual communication and recognition of login identities provided by the embodiment of the present invention allows users to log in to multiple application systems at the same time, avoiding repeated registration and repeated login, and proposes a solution for mutual communication and recognition of login identities and login status. It can verify the authorization channel and user information through trust transmission, complete the system login, and realize "one-time registration, mutual recognition of two systems". Login can be completed without repeated registration. Taxpayers can handle electronic tax bureau and natural person electronic tax bureau business across systems, reducing taxpayers' repeated registration / change operations. The identity authentication method 100 based on mutual communication and recognition of login identities provided by the embodiment of the present invention starts from step 101. In step 101, when the request recipient triggers the identity mutual communication and recognition request, token information is sent to the request recipient.
[0041] Preferably, the token information is an access token Access Token in the OAuth 2.0 authorization mechanism; the token information includes: the source of the request, a preliminary user identifier temporarily obtained by the request sender, security verification information, a timestamp and a callback address.
[0042] In step 102, the request receiver verifies the token information, authenticates the account authentication information input by the user when the token information is verified, logs in when the authentication is passed, and returns the user identity information of the user to the request sender.
[0043] In step 103, the request sender encrypts the user identity information and returns the ciphertext information to the request receiver.
[0044] Preferably, the encryption method is SM2 or JWT Token.
[0045] In step 104, the request recipient decrypts the ciphertext and determines whether the user is a real-name registered user who meets level 4 requirements based on the decrypted user identity information.
[0046] In step 105, when the request receiver determines that the user is a real-name registered user who meets the fourth level, it creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
[0047] Preferably, the method further comprises:
[0048] When a user is required to log in to the natural person electronic tax bureau based on the unified identity management platform, and the natural person electronic tax bureau trusts the unified identity management platform, the request sender is the natural person electronic tax bureau, and the request receiver is the unified identity management platform;
[0049] When the user needs to log in to the unified identity management platform based on the natural person electronic tax bureau and the unified identity management platform trusts the natural person electronic tax bureau, the request sender is the unified identity management platform and the request receiver is the natural person electronic tax bureau.
[0050] Preferably, when the request receiving party determines that the user is a real-name registered user who meets the fourth level, it creates its own session and associates it with the session ID of the request sending party, so that the request sending party trusts the request reception and allows the user to enter the system in a logged-in state, including:
[0051] When the request recipient determines that the user is a real-name registered user who meets the fourth level, it determines whether it is a corporate account. If it is a corporate account, it converts the permissions and personal identity information. If it is not a corporate account, it establishes a token correspondence and returns its own token to the request sender, so that the request sender recommends a binding relationship based on the token, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
[0052] The present invention provides an identity authentication method based on mutual communication and recognition of login identities. It aims at users logging into multiple application systems at the same time to avoid repeated registration and repeated login, and proposes a scheme for mutual communication and recognition of login identities and login states. In addition, in order to ensure that the quality of transmitted data remains consistent, it is required that the login users transmitted by each system reach the fourth level of real-name level.
[0053] In the present invention, when the natural person electronic tax bureau trusts the unified identity management platform, the request sender is the natural person electronic tax bureau, and the request receiver is the unified identity management platform. The mutual communication and mutual recognition identity authentication process includes: adding an "electronic tax bureau" account login link on the natural person electronic tax bureau WEB terminal, after the user clicks [Log in with the electronic tax bureau account], the unified identity management platform login interface is loaded and displayed, and after the unified identity management platform account information is entered and verified, the unified identity management platform transmits the user identity information and login authentication status to the natural person electronic tax bureau, the natural person electronic tax bureau receives and trusts the login user information and status of the unified identity management platform, and will enter the natural person electronic tax bureau system in a logged-in state.
[0054] In the present invention, when the unified identity management platform trusts the natural person electronic tax bureau, the request sender is the unified identity management platform, and the request receiver is the natural person electronic tax bureau. The mutual identity authentication process includes: integrating the "natural person electronic tax bureau" login link on the unified identity management platform login page, and after the user clicks the [natural person electronic tax bureau] button, the natural person electronic tax bureau login page is loaded and displayed. After entering the natural person electronic tax bureau account information and passing the verification, the natural person electronic tax bureau transmits the user identity information and login authentication status to the unified identity management platform. The unified identity management platform receives and trusts the login user information and status of the natural person electronic tax bureau, and enters the electronic tax bureau system in the login state.
[0055] Combination Figure 2 As shown, in the present invention, the interaction between the sender and the receiver is implemented in the tax-specific network. Starting from obtaining the token of the other party, the process of identity authentication includes:
[0056] 1. The request receiver (unified identity management platform / natural person electronic tax bureau) obtains the token of the request sender;
[0057] 2. The request recipient obtains the user information of the request sender through the token;
[0058] 3. Request the sender to return the user (identity) information of this login to the receiver in a decryptable encrypted form (SM2);
[0059] 4. The recipient determines whether the user has registered with Level 4 real name. If not, the request is rejected;
[0060] 5. The receiver creates its own session and associates it with the session ID of the request sender;
[0061] 6. The recipient (mainly the electronic tax bureau for natural persons) determines whether the current identity is an enterprise. If it is an enterprise, it converts the authority and personal identity.
[0062] In the present invention, identity login mutual recognition means that both parties recognize the login result of the real person user, and verify the authorization channel and user information through trust transmission (authorized login OAUTH2.0) to complete the login of this system. The present invention can realize the mutual communication and recognition of the identity information and identity authentication of the unified identity management platform and the natural person electronic tax bureau. It supports the synchronization of identity information data and mutual recognition of identity information authentication of newly registered taxpayers, realizes "one-time registration, dual-system mutual recognition", and can complete the login without repeated registration. Taxpayers can coordinate the electronic tax bureau and natural person electronic tax bureau business across systems, which reduces the taxpayers' repeated registration / change operations, can build two-way empowerment capabilities, and achieve the goals of identity mutual recognition and authentication mutual recognition at the same time.
[0063] Figure 3 FIG. 3 is a schematic diagram of the structure of an identity authentication system 300 based on mutual communication and mutual recognition of login identities according to an embodiment of the present invention. Figure 3 As shown, the identity authentication system 300 based on mutual communication and recognition of login identities adopted in the embodiment of the present invention includes: a token information sending unit 301, an authentication login unit 302, an encryption unit 303, a level judgment unit 304 and a trust login unit 305.
[0064] Preferably, the token information sending unit 301 is used to send token information to the request receiving party when the request receiving party triggers the identity intercommunication and mutual recognition request.
[0065] Preferably, the token information is an access token Access Token in the OAuth 2.0 authorization mechanism; the token information includes: the source of the request, a preliminary user identifier temporarily obtained by the request sender, security verification information, a timestamp and a callback address.
[0066] Preferably, the authentication login unit 302 is used for the request recipient to verify the token information, authenticate the account authentication information input by the user after the token information is verified, log in after the authentication is passed, and return the user identity information of the user to the request sender.
[0067] Preferably, the encryption unit 303 is used for the request sender to encrypt the user identity information and return the ciphertext information to the request receiver.
[0068] Preferably, the encryption method is SM2 or JWT Token.
[0069] Preferably, the level judgment unit 304 is used for the request recipient to decrypt the ciphertext and judge whether the user is a real-name registered user who meets the fourth level based on the decrypted user identity information.
[0070] Preferably, the trusted login unit 305 is used to create its own session and associate it with the session ID of the request sender when the request receiver determines that the user is a real-name registered user who meets the fourth level, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
[0071] Preferably, the system further comprises:
[0072] When a user is required to log in to the natural person electronic tax bureau based on the unified identity management platform, and the natural person electronic tax bureau trusts the unified identity management platform, the request sender is the natural person electronic tax bureau, and the request receiver is the unified identity management platform;
[0073] When the user needs to log in to the unified identity management platform based on the natural person electronic tax bureau and the unified identity management platform trusts the natural person electronic tax bureau, the request sender is the unified identity management platform and the request receiver is the natural person electronic tax bureau.
[0074] Preferably, the trust login unit 305, when the request receiving party determines that the user is a real-name registered user who meets the fourth level, creates its own session and associates it with the session ID of the request sending party, so that the request sending party trusts the request reception and allows the user to enter the system in a logged-in state, including:
[0075] When the request recipient determines that the user is a real-name registered user who meets the fourth level, it determines whether it is a corporate account. If it is a corporate account, it converts the permissions and personal identity information. If it is not a corporate account, it establishes a token correspondence and returns its own token to the request sender, so that the request sender recommends a binding relationship based on the token, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
[0076] The identity authentication system 300 based on mutual communication and recognition of login identities in the embodiment of the present invention corresponds to the identity authentication method 100 based on mutual communication and recognition of login identities in another embodiment of the present invention, and will not be described in detail herein.
[0077] Figure 4 The electronic device provided by an exemplary embodiment of the present invention may be any one or both of the first device and the second device, or a stand-alone device independent of them, and the stand-alone device may communicate with the first device and the second device to receive the collected input signals from them. Figure 4 FIG. 1 is a block diagram of an electronic device according to an embodiment of the present disclosure. Figure 4 As shown, the electronic device 400 includes one or more processors 401 and a memory 402 .
[0078] The processor 401 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.
[0079] The memory 402 may include one or more computer program products, and the computer program product may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 401 may run the program instructions to implement the method of the identity authentication method based on the mutual communication and mutual recognition of login identities of the software program of each embodiment of the present disclosure described above and / or other desired functions. In one example, the electronic device may also include: an input device 403 and an output device 404, which are interconnected by a bus system and / or other forms of connection mechanisms (not shown).
[0080] In addition, the input device 403 may also include, for example, a keyboard, a mouse, and the like.
[0081] The output device 404 can output various information to the outside. The output device 604 can include, for example, a display, a speaker, a printer, a communication network and its connected remote output device, etc.
[0082] Of course, to simplify, Figure 4 Only some of the components related to the present disclosure in the electronic device are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, according to specific application situations, the electronic device may further include any other appropriate components.
[0083] Exemplary computer program products and computer-readable storage media
[0084] In addition to the above-mentioned methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to execute the steps of the identity authentication method based on mutual communication and recognition of login identities according to various embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.
[0085] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the disclosed embodiments, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0086] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, enables the processor to execute the steps of the identity authentication method based on mutual communication and recognition of login identities according to various embodiments of the present disclosure described in the above “Exemplary Method” section of this specification.
[0087] The computer readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can include, for example, but is not limited to, a system, device or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0088] The basic principles of the present disclosure are described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, strengths, effects, etc. are required by each embodiment of the present disclosure. In addition, the specific details disclosed above are only for the purpose of illustration and ease of understanding, and are not limitations. The above details do not limit the present disclosure to the necessity of adopting the above specific details to be implemented.
[0089] Each embodiment in this specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system embodiment, since it basically corresponds to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0090] The block diagrams of the devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including," "comprising," "having," and the like are open words, referring to "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or," and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.
[0091] The method and apparatus of the present disclosure may be implemented in many ways. For example, the method and apparatus of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above, unless otherwise specifically stated. In addition, in some embodiments, the present disclosure may also be implemented as a program recorded in a recording medium, which includes machine-readable instructions for implementing the method according to the present disclosure. Therefore, the present disclosure also covers a recording medium storing a program for executing the method according to the present disclosure.
[0092] It should also be noted that in the apparatus, equipment and method of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present disclosure. The above description of the disclosed aspects is provided to enable any technician in the field to make or use the present disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown here, but to the widest scope consistent with the principles and novel features disclosed herein.
[0093] The above description has been given for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.
Claims
1. An identity authentication method based on mutual communication and recognition of login identities, characterized in that: The method comprises: When the request recipient triggers an identity intercommunication and mutual recognition request, the token information is sent to the request recipient; The request receiving party verifies the token information, authenticates the account authentication information input by the user when the token information is verified, logs in when the authentication is passed, and returns the user identity information of the user to the request sending party; The request sender encrypts the user identity information and returns the ciphertext information to the request receiver; The request receiving party decrypts the ciphertext and determines whether the user is a real-name registered user who meets level 4 based on the decrypted user identity information; When the request receiver determines that the user is a real-name registered user who meets level 4 requirements, it creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request reception and allows the user to log in to the system.
2. The method according to claim 1, characterized in that The method further comprises: When a user is required to log in to the natural person electronic tax bureau based on the unified identity management platform, and the natural person electronic tax bureau trusts the unified identity management platform, the request sender is the natural person electronic tax bureau, and the request receiver is the unified identity management platform; When the user is required to log in to the unified identity management platform based on the natural person electronic tax bureau and the unified identity management platform trusts the natural person electronic tax bureau, the request sender is the unified identity management platform and the request receiver is the natural person electronic tax bureau.
3. The method according to claim 1, characterized in that: The token information is the access token Access Token in the OAuth2.0 authorization mechanism; The token information includes: the request source, the preliminary user identification temporarily obtained by the request sender, security verification information, a timestamp and a callback address.
4. The method according to claim 1, characterized in that The encryption method is SM2 or JWT Token.
5. The method according to claim 1, characterized in that When the request receiving party determines that the user is a real-name registered user who meets the fourth level, it creates its own session and associates it with the session ID of the request sending party, so that the request sending party trusts the request reception and allows the user to enter the system in a logged-in state, including: When the request recipient determines that the user is a real-name registered user who meets the fourth level, it determines whether it is a corporate account. If it is a corporate account, it converts the permissions and personal identity information. If it is not a corporate account, it establishes a token correspondence and returns its own token to the request sender, so that the request sender recommends a binding relationship based on the token, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
6. An identity authentication system based on mutual communication and recognition of login identities, characterized in that: The system comprises: A token information sending unit, used to send token information to the request receiving party when the request receiving party triggers the identity intercommunication and mutual recognition request; An authentication and login unit, used for the request receiving party to verify the token information, authenticate the account authentication information input by the user when the token information is verified, log in when the authentication is passed, and return the user identity information of the user to the request sending party; An encryption unit, used for the request sender to encrypt the user identity information and return the ciphertext information to the request receiver; A level judgment unit, configured for the request receiving party to decrypt the ciphertext and judge whether the user is a real-name registered user meeting level 4 based on the decrypted user identity information; The trusted login unit is used to create its own session and associate it with the session ID of the request sender when the request receiver determines that the user is a real-name registered user who meets the fourth level, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
7. The system according to claim 6, characterized in that The system further comprises: When a user is required to log in to the natural person electronic tax bureau based on the unified identity management platform, and the natural person electronic tax bureau trusts the unified identity management platform, the request sender is the natural person electronic tax bureau, and the request receiver is the unified identity management platform; When the user needs to log in to the unified identity management platform based on the natural person electronic tax bureau and the unified identity management platform trusts the natural person electronic tax bureau, the request sender is the unified identity management platform and the request receiver is the natural person electronic tax bureau.
8. The system according to claim 6, characterized in that The token information is the access token Access Token in the OAuth2.0 authorization mechanism; the token information includes: the request source, the preliminary user identification temporarily obtained by the request sender, security verification information, timestamp and callback address.
9. The system according to claim 6, characterized in that The encryption method is SM2 or JWT Token.
10. The system according to claim 6, characterized in that The trusted login unit, when the request receiving party determines that the user is a real-name registered user who meets the fourth level, creates its own session and associates it with the session ID of the request sending party, so that the request sending party trusts the request reception and allows the user to enter the system in a logged-in state, including: When the request recipient determines that the user is a real-name registered user who meets the fourth level, it determines whether it is a corporate account. If it is a corporate account, it converts the permissions and personal identity information. If it is not a corporate account, it establishes a token correspondence and returns its own token to the request sender, so that the request sender recommends a binding relationship based on the token, so that the request sender trusts the request reception and allows the user to enter the system in a logged-in state.
Citation Information
Patent Citations
Asymmetrical group encryption / decryption method based on user identity identification
CN101867472A
Authentication device and / or method
US20070088952A1