An identity authentication method and system based on login identity interconnection and mutual recognition
By using an identity authentication method and system based on mutual recognition of login identities, and leveraging token information and encryption technology, mutual recognition of user identities among multiple application systems has been achieved. This solves the problem of taxpayers repeatedly registering and logging in to different tax systems, and improves user experience and business collaboration capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- AISINO CORPORATION
- Filing Date
- 2024-12-26
- Publication Date
- 2026-07-21
AI Technical Summary
In existing technologies, taxpayers need to register and log in repeatedly in different tax systems, resulting in insufficient business collaboration capabilities and a poor user experience.
By using an identity authentication method and system based on interoperable login identity, and using token information for identity verification, the system achieves interoperability and mutual recognition of user identity information, ensuring that users only need to register once to log in across multiple application systems. It uses SM2 or JWT tokens for encryption and decryption to determine whether the user is a real-name registered user who meets the Level 4 requirement, and establishes a session association to trust the login status.
It enables seamless login for users across multiple systems, reduces repeated registration and login operations, enhances business collaboration capabilities, and simplifies the operational process for taxpayers.
Smart Images

Figure CN119945736B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity authentication technology, and more specifically, to an identity authentication method and system based on mutual recognition of login identities. Background Technology
[0002] To continuously improve the business collaboration capabilities among various tax systems, enhance the taxpayer's tax filing experience, avoid the same taxpayer repeatedly registering and logging in to different tax systems, and achieve intelligent, convenient, and seamless business processing across various business systems within the tax system.
[0003] Therefore, considering factors such as ease of use for taxpayers, improved user experience, and inter-system synergy and complementarity, the plan to achieve mutual recognition and interoperability of identity information and authentication between the unified identity management platform and the electronic tax bureau for natural persons is an urgent issue to be addressed.
[0004] Therefore, an identity authentication method based on mutual recognition of login identities is needed. Summary of the Invention
[0005] This invention proposes an identity authentication method and system based on mutual recognition of login identities to solve the problem of how to achieve mutual recognition of identities.
[0006] To address the aforementioned problems, according to one aspect of the present invention, an identity authentication method based on interoperable and mutually recognized login identities is provided, the method comprising:
[0007] When the requesting recipient triggers an identity interoperability and mutual recognition request, a token message is sent to the requesting recipient.
[0008] The request recipient verifies the token information. Once the token information is verified, it verifies the account authentication information entered by the user. Once the authentication is successful, the user logs in and returns the user's identity information to the request sender.
[0009] The request sender encrypts the user's identity information and returns the ciphertext information to the request receiver.
[0010] The request recipient decrypts the ciphertext and determines whether the user is a registered user who meets the Level 4 real-name registration requirement based on the decrypted user identity information.
[0011] When the request recipient determines that the user is a real-name registered user who meets the level four requirement, it creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
[0012] Preferably, the method further includes:
[0013] When a user is required to log in to the Natural Person Electronic Tax Bureau based on the unified identity management platform, and the Natural Person Electronic Tax Bureau trusts the unified identity management platform, the request sender is the Natural Person Electronic Tax Bureau, and the request receiver is the unified identity management platform.
[0014] When a user needs to log in to the unified identity management platform based on the Natural Person Electronic Tax Bureau, and the unified identity management platform trusts the Natural Person Electronic Tax Bureau, the request sender is the unified identity management platform, and the request receiver is the Natural Person Electronic Tax Bureau.
[0015] Preferably, the token information is an Access Token in the OAuth 2.0 authorization mechanism; the token information includes: request source, preliminary user identifier temporarily obtained by the request sender, security verification information, timestamp, and callback address.
[0016] Preferably, the encryption method is SM2 or JWT Token.
[0017] Preferably, the step of the request recipient creating its own session and associating it with the session ID of the request sender when the request recipient determines that the user is a registered user meeting the Level 4 real-name authentication requirement, thereby enabling the request sender to trust the request recipient and allow the user to log in to the system, includes:
[0018] When the request recipient determines that the user is a registered user who meets the Level 4 real-name registration requirement, it determines whether it is an enterprise account. If it is an enterprise account, it performs permission and personal identity information conversion. If it is not an enterprise account, it establishes a token correspondence relationship and returns its own token to the request sender, so that the request sender can suggest a binding relationship based on the token, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
[0019] According to another aspect of the present invention, an identity authentication system based on interoperable and mutually recognized login identities is provided, the system comprising:
[0020] The token information sending unit is used to send token information to the requesting recipient when the requesting recipient triggers an identity interoperability and mutual recognition request.
[0021] The authentication login unit is used by the request recipient to verify the token information. After the token information is verified, the unit authenticates the account authentication information entered by the user. After the authentication is successful, the unit logs in and returns the user's identity information to the request sender.
[0022] An encryption unit is used by the request sender to encrypt the user identity information and return the ciphertext information to the request receiver.
[0023] The level determination unit is used by the request recipient to decrypt the ciphertext and determine whether the user is a real-name registered user who meets the level four requirement based on the decrypted user identity information.
[0024] The trusted login unit is used to create its own session when the request receiver determines that the user is a real-name registered user who meets the level four requirement, and associate it with the session ID of the request sender, so that the request sender trusts the request receiver and allows the user to enter the system in a logged-in state.
[0025] Preferably, the system further includes:
[0026] When a user is required to log in to the Natural Person Electronic Tax Bureau based on the unified identity management platform, and the Natural Person Electronic Tax Bureau trusts the unified identity management platform, the request sender is the Natural Person Electronic Tax Bureau, and the request receiver is the unified identity management platform.
[0027] When a user needs to log in to the unified identity management platform based on the Natural Person Electronic Tax Bureau, and the unified identity management platform trusts the Natural Person Electronic Tax Bureau, the request sender is the unified identity management platform, and the request receiver is the Natural Person Electronic Tax Bureau.
[0028] Preferably, the token information is an Access Token in the OAuth 2.0 authorization mechanism; the token information includes: request source, preliminary user identifier temporarily obtained by the request sender, security verification information, timestamp, and callback address.
[0029] Preferably, the encryption method is SM2 or JWT Token.
[0030] Preferably, the trusted login unit, when the request recipient determines that the user is a real-name registered user meeting Level 4, creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state, includes:
[0031] When the request recipient determines that the user is a registered user who meets the Level 4 real-name registration requirement, it determines whether it is an enterprise account. If it is an enterprise account, it performs permission and personal identity information conversion. If it is not an enterprise account, it establishes a token correspondence relationship and returns its own token to the request sender, so that the request sender can suggest a binding relationship based on the token, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
[0032] This invention provides an identity authentication method and system based on interoperable login identity recognition, comprising: when a request receiver triggers an identity interoperability recognition request, sending token information to the request receiver; the request receiver verifying the token information, and upon successful verification of the token information, authenticating the account authentication information entered by the user, and upon successful authentication, logging in, and returning the user's user identity information to the request sender; the request sender encrypting the user identity information and returning ciphertext information to the request receiver; the request receiver decrypting the ciphertext and determining whether the user is a Level 4 real-name registered user based on the decrypted user identity information; when the request receiver determines that the user is a Level 4 real-name registered user, creating its own session and associating it with the session ID of the request sender, so that the request sender trusts the request receiver and allows the user to enter the system in a logged-in state. This invention addresses the issue of users simultaneously logging into multiple application systems, avoiding duplicate registrations and logins. It proposes a solution for mutual recognition of login identity and login status, which verifies authorization channels and user information through trust transmission to complete system login, achieving "one-time registration, dual-system mutual recognition." Login can be completed without repeated registration, and taxpayers can collaboratively handle e-tax bureau and individual e-tax bureau business across systems, reducing the need for taxpayers to perform repeated registration / change operations. Attached Figure Description
[0033] Exemplary embodiments of the present invention can be more fully understood by referring to the following figures:
[0034] Figure 1 This is a flowchart of an identity authentication method 100 based on mutual recognition of login identities according to an embodiment of the present invention;
[0035] Figure 2 This is a schematic diagram illustrating the interaction between a request sender and a request receiver according to an embodiment of the present invention.
[0036] Figure 3 This is a schematic diagram of the structure of an identity authentication system 300 based on mutual recognition of login identities according to an embodiment of the present invention;
[0037] Figure 4 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0038] Exemplary embodiments of the invention will now be described with reference to the accompanying drawings. However, the invention may be embodied in many different forms and is not limited to the embodiments described herein. These embodiments are provided to fully and completely disclose the invention and to fully convey its scope to those skilled in the art. The terminology used in the exemplary embodiments illustrated in the drawings is not intended to limit the invention. In the drawings, the same units / elements are referred to by the same reference numerals.
[0039] Unless otherwise stated, the terms used herein (including technical terms) have their common meaning as understood by one of ordinary skill in the art. Furthermore, it is understood that terms defined in commonly used dictionaries should be understood to have a meaning consistent with the context of their relevant field, and not to be interpreted as having an idealized or overly formal meaning.
[0040] Figure 1 This is a flowchart of an identity authentication method 100 based on mutual recognition of login identities according to an embodiment of the present invention. Figure 1 As shown, the identity authentication method based on mutual recognition of login identities provided by the embodiments of the present invention avoids repeated registration and login when users log in to multiple application systems simultaneously. It proposes a scheme for mutual recognition of login identities and login status, and verifies authorization channels and user information through trust transmission to complete system login, achieving "one-time registration, dual-system mutual recognition." Login can be completed without repeated registration, allowing taxpayers to collaboratively handle e-tax bureau and individual e-tax bureau business across systems, reducing the need for taxpayers to perform repeated registration / change operations. The identity authentication method 100 based on mutual recognition of login identities provided by the embodiments of the present invention begins at step 101. In step 101, when the requesting recipient triggers an identity mutual recognition request, token information is sent to the requesting recipient.
[0041] Preferably, the token information is an Access Token in the OAuth 2.0 authorization mechanism; the token information includes: request source, preliminary user identifier temporarily obtained by the request sender, security verification information, timestamp, and callback address.
[0042] In step 102, the request recipient verifies the token information. After the token information is verified, the recipient verifies the account authentication information entered by the user. After successful authentication, the recipient logs in and returns the user's identity information to the request sender.
[0043] In step 103, the request sender encrypts the user identity information and returns the encrypted information to the request receiver.
[0044] Preferably, the encryption method is SM2 or JWT Token.
[0045] In step 104, the request recipient decrypts the ciphertext and determines whether the user is a registered user who meets the Level 4 real-name registration requirement based on the decrypted user identity information.
[0046] In step 105, when the request recipient determines that the user is a real-name registered user who meets the level 4 requirement, it creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
[0047] Preferably, the method further includes:
[0048] When a user is required to log in to the Natural Person Electronic Tax Bureau based on the unified identity management platform, and the Natural Person Electronic Tax Bureau trusts the unified identity management platform, the request sender is the Natural Person Electronic Tax Bureau, and the request receiver is the unified identity management platform.
[0049] When a user needs to log in to the unified identity management platform based on the Natural Person Electronic Tax Bureau, and the unified identity management platform trusts the Natural Person Electronic Tax Bureau, the request sender is the unified identity management platform, and the request receiver is the Natural Person Electronic Tax Bureau.
[0050] Preferably, the step of the request recipient creating its own session and associating it with the session ID of the request sender when the request recipient determines that the user is a registered user meeting the Level 4 real-name authentication requirement, thereby enabling the request sender to trust the request recipient and allow the user to log in to the system, includes:
[0051] When the request recipient determines that the user is a registered user who meets the Level 4 real-name registration requirement, it determines whether it is an enterprise account. If it is an enterprise account, it performs permission and personal identity information conversion. If it is not an enterprise account, it establishes a token correspondence relationship and returns its own token to the request sender, so that the request sender can suggest a binding relationship based on the token, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
[0052] This invention provides an identity authentication method based on mutual recognition of login identities. To address the issue of users logging into multiple application systems simultaneously and avoiding duplicate registration and login, a scheme is proposed for mutual recognition of login identities and login status. Furthermore, to ensure consistent data quality, all login users transmitted by each system are required to have reached Level 4 real-name authentication.
[0053] In this invention, when the Individual Electronic Tax Bureau trusts the Unified Identity Management Platform, the request sender is the Individual Electronic Tax Bureau, and the request receiver is the Unified Identity Management Platform. The interoperable identity authentication process includes: adding an "Electronic Tax Bureau" account login link to the Individual Electronic Tax Bureau's web interface; after the user clicks "Login with Electronic Tax Bureau Account," the Unified Identity Management Platform login interface is loaded and displayed; after the user enters and verifies their Unified Identity Management Platform account information, the Unified Identity Management Platform transmits the user's identity information and login authentication status to the Individual Electronic Tax Bureau; the Individual Electronic Tax Bureau receives and trusts the login user information and status from the Unified Identity Management Platform and enters the Individual Electronic Tax Bureau system in a logged-in state.
[0054] In this invention, when the unified identity management platform trusts the Individual Electronic Tax Bureau, the request sender is the unified identity management platform, and the request receiver is the Individual Electronic Tax Bureau. The interoperable identity authentication process includes: integrating a "Individual Electronic Tax Bureau" login link into the unified identity management platform's login page; after the user clicks the "Individual Electronic Tax Bureau" button, the Individual Electronic Tax Bureau login page is loaded and displayed. After the Individual Electronic Tax Bureau account information is entered and verified, the Individual Electronic Tax Bureau transmits the user's identity information and login authentication status to the unified identity management platform. The unified identity management platform receives and trusts the login user information and status of the Individual Electronic Tax Bureau and enters the electronic tax bureau system in a logged-in state.
[0055] Combination Figure 2 As shown, in this invention, the interaction between the sender and receiver is implemented within the tax intranet. The identity authentication process, starting from obtaining the other party's token, includes:
[0056] 1. The requesting recipient (Unified Identity Management Platform / Natural Person Electronic Tax Bureau) obtained the requesting sender's token;
[0057] 2. The requesting recipient obtains the requesting sender's user information via a token;
[0058] 3. The sender requests that the user (identity) information for this login be returned to the receiver using a decryptable encryption method (SM2);
[0059] 4. The receiver determines whether the user has completed Level 4 real-name registration; if not, the request is rejected.
[0060] 5. The receiver creates its own session and associates it with the session ID of the request sender;
[0061] 6. The recipient (mainly the individual electronic tax bureau) determines whether the current identity is a company. If it is a company, it performs permission and personal identity conversion.
[0062] In this invention, identity login mutual recognition refers to both parties acknowledging the login result of a real user. Through trust transfer (Authorized Login OAuth2.0), the authorization channel and user information are verified to complete the login process. This invention enables mutual recognition of identity information and authentication between the unified identity management platform and the Individual Electronic Tax Bureau. It supports the synchronization of identity information data and mutual recognition of identity information authentication for newly registered taxpayers, achieving "one-time registration, dual-system mutual recognition." Login can be completed without repeated registration, allowing taxpayers to collaboratively handle business across the electronic tax bureau and the individual electronic tax bureau. This reduces the need for repeated registration / change operations for taxpayers, enabling the construction of two-way empowerment capabilities while achieving the goals of identity and authentication mutual recognition.
[0063] Figure 3 This is a schematic diagram of the structure of an identity authentication system 300 based on mutual recognition of login identities according to an embodiment of the present invention. Figure 3 As shown, the identity authentication system 300 based on mutual recognition of login identity according to the embodiment of the present invention includes: a token information sending unit 301, an authentication login unit 302, an encryption unit 303, a level judgment unit 304, and a trust login unit 305.
[0064] Preferably, the token information sending unit 301 is used to send token information to the requesting recipient when the requesting recipient triggers an identity interoperability and mutual recognition request.
[0065] Preferably, the token information is an Access Token in the OAuth 2.0 authorization mechanism; the token information includes: request source, preliminary user identifier temporarily obtained by the request sender, security verification information, timestamp, and callback address.
[0066] Preferably, the authentication login unit 302 is used by the request recipient to verify the token information, and after the token information is verified, to authenticate the account authentication information entered by the user, and after the authentication is successful, to log in and return the user's user identity information to the request sender.
[0067] Preferably, the encryption unit 303 is used by the request sender to encrypt the user identity information and return the encrypted information to the request receiver.
[0068] Preferably, the encryption method is SM2 or JWT Token.
[0069] Preferably, the level determination unit 304 is used for the request recipient to decrypt the ciphertext and determine whether the user is a real-name registered user who meets the level four requirement based on the decrypted user identity information.
[0070] Preferably, the trusted login unit 305 is used to create its own session and associate it with the session ID of the request sender when the request receiver determines that the user is a real-name registered user who meets the level four requirement, so that the request sender trusts the request receiver and allows the user to enter the system in a logged-in state.
[0071] Preferably, the system further includes:
[0072] When a user is required to log in to the Natural Person Electronic Tax Bureau based on the unified identity management platform, and the Natural Person Electronic Tax Bureau trusts the unified identity management platform, the request sender is the Natural Person Electronic Tax Bureau, and the request receiver is the unified identity management platform.
[0073] When a user needs to log in to the unified identity management platform based on the Natural Person Electronic Tax Bureau, and the unified identity management platform trusts the Natural Person Electronic Tax Bureau, the request sender is the unified identity management platform, and the request receiver is the Natural Person Electronic Tax Bureau.
[0074] Preferably, the trusted login unit 305, when the request recipient determines that the user is a real-name registered user meeting Level 4, creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state, includes:
[0075] When the request recipient determines that the user is a registered user who meets the Level 4 real-name registration requirement, it determines whether it is an enterprise account. If it is an enterprise account, it performs permission and personal identity information conversion. If it is not an enterprise account, it establishes a token correspondence relationship and returns its own token to the request sender, so that the request sender can suggest a binding relationship based on the token, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
[0076] The identity authentication system 300 based on mutual recognition of login identity in an embodiment of the present invention corresponds to the identity authentication method 100 based on mutual recognition of login identity in another embodiment of the present invention, and will not be described again here.
[0077] Figure 4 This is the structure of an electronic device provided in an exemplary embodiment of the present invention. The electronic device may be either or both of a first device and a second device, or a standalone device independent of them, which may communicate with the first device and the second device to receive acquired input signals from them. Figure 4 A block diagram of an electronic device according to an embodiment of the present disclosure is shown. Figure 4 As shown, the electronic device 400 includes one or more processors 401 and memory 402.
[0078] The processor 401 may be a central processing unit (CPU) or other form of processing unit with data processing and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.
[0079] The memory 402 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 401 may execute the program instructions to implement the authentication method based on login identity interoperability and mutual recognition of the software program of the various embodiments of this disclosure described above, and / or other desired functions. In one example, the electronic device may also include an input device 403 and an output device 404, these components being interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0080] In addition, the input device 403 may also include, for example, a keyboard, a mouse, etc.
[0081] The output device 404 can output various information to the outside. The output device 604 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.
[0082] Of course, for the sake of simplicity, Figure 4 Only some of the components of the electronic device relevant to this disclosure are shown, omitting components such as buses, input / output interfaces, etc. In addition, the electronic device may include any other suitable components depending on the specific application.
[0083] Exemplary computer program products and computer-readable storage media
[0084] In addition to the methods and devices described above, embodiments of this disclosure may also be computer program products, including computer program instructions that, when executed by a processor, cause the processor to perform the steps in the identity authentication methods based on login identity interoperability and mutual recognition according to various embodiments of this disclosure as described in the "Exemplary Methods" section of this specification.
[0085] The computer program product can be written in any combination of one or more programming languages to perform the operations of the embodiments of this disclosure. The programming languages include object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on a user's computing device, partially on a user's computing device, as a standalone software package, partially on a user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0086] Furthermore, embodiments of this disclosure may also be computer-readable storage media storing computer program instructions that, when executed by a processor, cause the processor to perform the steps in the identity authentication method based on login identity interoperability and mutual recognition according to various embodiments of this disclosure as described in the "Exemplary Methods" section above.
[0087] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0088] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.
[0089] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For system embodiments, since they largely correspond to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0090] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.
[0091] The methods and apparatus of this disclosure may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the methods is for illustrative purposes only, and the steps of the methods of this disclosure are not limited to the order specifically described above unless otherwise specifically stated. Furthermore, in some embodiments, this disclosure may also be implemented as a program recorded on a recording medium, the program including machine-readable instructions for implementing the methods according to this disclosure. Thus, this disclosure also covers recording media storing programs for performing the methods according to this disclosure.
[0092] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps are decomposable and / or recombinable. Such decomposition and / or recombination should be considered equivalent to the present disclosure. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.
[0093] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. An identity authentication method based on interoperable and mutually recognized login identities, characterized in that, The method includes: When the requesting recipient triggers an identity interoperability and mutual recognition request, a token message is sent to the requesting recipient. The request recipient verifies the token information. Once the token information is verified, it verifies the account authentication information entered by the user. Once the authentication is successful, the user logs in and returns the user's identity information to the request sender. The request sender encrypts the user's identity information and returns the ciphertext information to the request receiver. The request recipient decrypts the ciphertext and determines whether the user is a registered user who meets the Level 4 real-name registration requirement based on the decrypted user identity information. When the request recipient determines that the user is a real-name registered user who meets the level four requirement, it creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
2. The method according to claim 1, characterized in that, The method further includes: When a user is required to log in to the Natural Person Electronic Tax Bureau based on the unified identity management platform, and the Natural Person Electronic Tax Bureau trusts the unified identity management platform, the request sender is the Natural Person Electronic Tax Bureau, and the request receiver is the unified identity management platform. When a user needs to log in to the unified identity management platform based on the Natural Person Electronic Tax Bureau, and the unified identity management platform trusts the Natural Person Electronic Tax Bureau, the request sender is the unified identity management platform, and the request receiver is the Natural Person Electronic Tax Bureau.
3. The method according to claim 1, characterized in that, The token information is an Access Token in the OAuth2.0 authorization mechanism; The token information includes: the request source, the preliminary user identifier temporarily obtained by the request sender, security verification information, timestamp, and callback address.
4. The method according to claim 1, characterized in that, The encryption method is SM2 or JWT Token.
5. The method according to claim 1, characterized in that, When the request recipient determines that the user is a registered user meeting Level 4 real-name authentication, it creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request recipient and allows the user to log in to the system, including: When the request recipient determines that the user is a registered user who meets the Level 4 real-name registration requirement, it determines whether it is an enterprise account. If it is an enterprise account, it performs permission and personal identity information conversion. If it is not an enterprise account, it establishes a token correspondence relationship and returns its own token to the request sender, so that the request sender can suggest a binding relationship based on the token, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.
6. An identity authentication system based on mutual recognition of login identities, characterized in that, The system includes: The token information sending unit is used to send token information to the requesting recipient when the requesting recipient triggers an identity interoperability and mutual recognition request. The authentication login unit is used by the request recipient to verify the token information. After the token information is verified, the unit authenticates the account authentication information entered by the user. After the authentication is successful, the unit logs in and returns the user's identity information to the request sender. An encryption unit is used by the request sender to encrypt the user identity information and return the ciphertext information to the request receiver. The level determination unit is used by the request recipient to decrypt the ciphertext and determine whether the user is a real-name registered user who meets the level four requirement based on the decrypted user identity information. The trusted login unit is used to create its own session when the request receiver determines that the user is a real-name registered user who meets the level four requirement, and associate it with the session ID of the request sender, so that the request sender trusts the request receiver and allows the user to enter the system in a logged-in state.
7. The system according to claim 6, characterized in that, The system also includes: When a user is required to log in to the Natural Person Electronic Tax Bureau based on the unified identity management platform, and the Natural Person Electronic Tax Bureau trusts the unified identity management platform, the request sender is the Natural Person Electronic Tax Bureau, and the request receiver is the unified identity management platform. When a user needs to log in to the unified identity management platform based on the Natural Person Electronic Tax Bureau, and the unified identity management platform trusts the Natural Person Electronic Tax Bureau, the request sender is the unified identity management platform, and the request receiver is the Natural Person Electronic Tax Bureau.
8. The system according to claim 6, characterized in that, The token information is the Access Token in the OAuth2.0 authorization mechanism; the token information includes: the request source, the preliminary user identifier temporarily obtained by the request sender, security verification information, timestamp, and callback address.
9. The system according to claim 6, characterized in that, The encryption method is SM2 or JWT Token.
10. The system according to claim 6, characterized in that, The trusted login unit, when the request receiver determines that the user is a real-name registered user meeting Level 4 requirements, creates its own session and associates it with the session ID of the request sender, so that the request sender trusts the request receiver and allows the user to enter the system in a logged-in state, including: When the request recipient determines that the user is a registered user who meets the Level 4 real-name registration requirement, it determines whether it is an enterprise account. If it is an enterprise account, it performs permission and personal identity information conversion. If it is not an enterprise account, it establishes a token correspondence relationship and returns its own token to the request sender, so that the request sender can suggest a binding relationship based on the token, so that the request sender trusts the request recipient and allows the user to enter the system in a logged-in state.