Identity verification method and system
Through a trusted token-based identity verification system, combined with trusted information and biometric identification, the risks of identity impersonation and tampering in existing identity verification methods are solved, and a high security and convenient identity verification experience is achieved.
Patent Information
- Application Number
- CN202510279316.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-05-09
AI Technical Summary
Existing identity verification methods pose the risk of identity impersonation and tampering, and often require users to cooperate on site or through additional hardware devices, affecting the user experience.
An identity verification system based on a trusted token is adopted to obtain trusted information and identity information, generate data to be verified, and after the verification party passes the trusted information, the identity information is used for business verification. The system may also optionally perform biometric authentication and generate data to be verified in a secure environment, and perform encryption processing to ensure the security of the information.
This greatly improves the security of identity verification, reduces the risk of identity impersonation and tampering, and improves the user experience, so that users can complete identity authentication without carrying additional devices.
Smart Images

Figure CN119966638A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity verification, and in particular to an identity verification method and system. Background Art
[0002] In many areas such as financial services, hotel check-in, transportation, etc., ensuring the authenticity of user identities is the key to preventing identity theft and fraud.
[0003] Existing identity verification methods, such as smart card authentication, ID card registration, manual verification, self-service device verification, etc., although they provide security to a certain extent, still have the risk of identity fraud and tampering. In addition, these methods often require users to cooperate on site or use additional hardware equipment, which affects the user experience.
[0004] Therefore, it is hoped that there will be a new identity verification method and system that can overcome the above problems. Summary of the invention
[0005] In view of the above problems, the purpose of the present invention is to provide an identity verification method and system, in particular, an identity verification system based on a trusted token, so as to ensure the security of identity verification.
[0006] According to one aspect of the present invention, there is provided an identity verification method, comprising:
[0007] Get credible information;
[0008] Generate data to be verified based on the trusted information and identity information;
[0009] Send the data to be verified to the verification party,
[0010] After the verification of the trusted information by the verification party, the identity information is used for business verification.
[0011] Optionally, the identity verification method further includes:
[0012] Conduct biometric authentication;
[0013] After the biometric feature recognition authentication is passed, the trusted information is obtained and the data to be verified is generated according to the trusted information and the identity information.
[0014] Optionally, the trusted information includes at least one selected from trusted time, trusted location, device health status and trusted device identification.
[0015] Optionally, the verification party includes a remote trusted service platform server;
[0016] The identity verification method further includes:
[0017] Encrypting the data to be verified using an encryption key to obtain encrypted data to be verified;
[0018] Sending the encrypted data to be verified to the remote trusted service platform server;
[0019] The remote trusted service platform server uses a decryption key to decrypt the encrypted data to be verified to obtain the data to be verified, and verifies the trusted information.
[0020] Optionally, the encryption key includes a token encryption subkey;
[0021] The identity verification method further includes:
[0022] Sign the data to be verified using the private key of the user device certificate to obtain signed data to be verified;
[0023] Encrypt the signature data to be verified using the token encryption subkey to obtain the encrypted data to be verified;
[0024] The remote trusted service platform server obtains the token encryption subkey according to the token encryption master key, and decrypts the encrypted data to be verified according to the token encryption subkey to obtain the signature data to be verified;
[0025] The remote trusted service platform server extracts the user device certificate and verifies it using the CA root key;
[0026] The remote trusted service platform server verifies the signature of the data to be verified using the public key of the user device certificate to obtain the data to be verified.
[0027] The verification result of the trusted information includes passing the risk control check of the trusted information by the remote trusted service platform server.
[0028] Optionally, the verification party includes a remote trusted service platform server; the remote trusted service platform server generates a platform key pair, the platform key pair includes a platform private key and a platform public key; the remote trusted service platform server stores the platform private key;
[0029] The identity verification method further includes:
[0030] Encrypt the data to be verified using the platform public key to obtain encrypted data to be verified;
[0031] Sending the encrypted data to be verified to the remote trusted service platform server;
[0032] The remote trusted service platform server uses the platform private key to decrypt the encrypted data to be verified to obtain the data to be verified.
[0033] Optionally, the verification party includes an authentication device; the authentication device stores a token encryption master key and a CA root key;
[0034] The identity verification method further includes:
[0035] Sign the data to be verified using the private key of the user device certificate to obtain signed data to be verified;
[0036] Encrypt the signature data to be verified using the token encryption subkey to obtain the encrypted data to be verified;
[0037] Sending the encrypted data to be verified to the authentication device;
[0038] The authentication device obtains the token encryption subkey according to the token encryption master key, and decrypts the encrypted data to be verified according to the token encryption subkey to obtain the signature data to be verified;
[0039] The authentication device extracts the user device certificate and verifies it using the CA root key;
[0040] The authentication device verifies the signature of the data to be verified using the public key of the user device certificate to obtain the data to be verified.
[0041] Wherein, the verification result of the trusted information includes the risk control check of the trusted information by the authentication device;
[0042] After the trusted information is verified, the authentication device uses the identity information to perform business verification.
[0043] Optionally, the identity verification method includes:
[0044] The data to be verified is generated in a secure environment according to the trusted information and the identity information; the secure environment includes at least one selected from a SE environment, a TEE environment, and a system keystore.
[0045] According to another aspect of the present invention, there is provided an identity verification method, comprising:
[0046] Obtaining credible information and identity information to be verified;
[0047] Verifying the trusted information to be verified;
[0048] After the trusted information is verified, the identity information is used for business verification.
[0049] According to another aspect of the present invention, there is provided an identity verification system, comprising:
[0050] The device side obtains the trusted information and generates the data to be verified based on the trusted information and the identity information; the device side sends the data to be verified to the verification party, and after the verification party verifies the trusted information, the identity information is used for business verification.
[0051] The identity verification method and system provided by the present invention combine credible information for identity verification, thereby greatly ensuring the security of identity verification.
[0052] Furthermore, before generating the data to be verified, biometric identification authentication is performed, which improves the security and convenience of identity authentication.
[0053] Furthermore, the data to be verified is generated based on the trusted information and identity information in a secure environment, thereby ensuring the security of information data during the identity verification process.
[0054] Furthermore, encryption is performed during the transmission of the data to be verified, thereby ensuring information security during the identity verification process. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] The above and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings, in which:
[0056] Figure 1 A method flow chart of an identity verification method according to Embodiment 1 of the present invention is shown;
[0057] Figure 2 An interactive flow chart of an identity verification method according to Embodiment 2 of the present invention is shown;
[0058] Figure 3 An interactive flow chart of an identity verification method according to Embodiment 3 of the present invention is shown;
[0059] Figure 4 An interactive flow chart of identity token activation according to Embodiment 4 of the present invention is shown;
[0060] Figure 5 A method flow chart of an identity verification method according to Embodiment 5 of the present invention is shown;
[0061] Figure 6 A schematic structural diagram of an identity verification system according to an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0062] Various embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. In each of the accompanying drawings, identical elements are represented by identical or similar reference numerals. For the sake of clarity, the various parts in the accompanying drawings are not drawn to scale. In addition, some well-known parts may not be shown in the drawings.
[0063] The specific implementation of the present invention is further described in detail below in conjunction with the accompanying drawings and examples. Many specific details of the present invention, such as the structure, materials, dimensions, processing technology and techniques of the components are described below to provide a clearer understanding of the present invention. However, as those skilled in the art will appreciate, the present invention may be implemented without following these specific details.
[0064] It should be understood that when describing the structure of a component, when a layer or a region is referred to as being "on" or "over" another layer or another region, it may mean that it is directly on the other layer or another region, or that other layers or regions are included between it and the other layer or another region. Moreover, if the component is turned over, the layer or a region will be "below" or "beneath" another layer or another region.
[0065] Figure 1 FIG. 1 is a flowchart of an identity verification method according to Embodiment 1 of the present invention. Figure 1 As shown, the identity verification method according to the first embodiment of the present invention is performed by a device (smartphone, smart watch, etc.), and specifically includes the following steps:
[0066] In step S101, obtaining trusted information;
[0067] In the process of identity verification, trusted information is obtained. The trusted information is used, for example, to enhance the security of identity verification. Optionally, the trusted information includes at least one selected from trusted time, trusted location, device health status, and trusted device identification.
[0068] In step S102, data to be verified is generated according to the trusted information and identity information;
[0069] The data to be verified is generated based on the trusted information and the identity information. The identity information is, for example, the electronic identity information of the user to be verified.
[0070] In step S103, the data to be verified is sent to a verification party.
[0071] The device sends the data to be verified to the verification party. After the verification party verifies the trusted information, the identity information is used for business verification. Optionally, the verification party includes at least one of an authentication device and a remote trusted service platform server.
[0072] In an optional embodiment of the present invention, the identity verification method further includes:
[0073] Perform biometric authentication (for users who are undergoing identity verification); biometric authentication includes, for example, at least one of fingerprint recognition, facial recognition, iris recognition, and palm print recognition.
[0074] After the biometric authentication is passed, the trusted information is obtained and the data to be verified is generated based on the trusted information and identity information.
[0075] In an optional embodiment of the present invention, the identity verification method includes:
[0076] Generate data to be verified based on trusted information and identity information in a secure environment (secure carrier). The secure environment includes at least one selected from a SE (Secure Element) environment, a TEE (trusted execution environment) environment, and a system keystore.
[0077] According to the identity authentication method of the embodiment of the present invention, by adding trusted information (trusted location, trusted time, trusted device status, trusted device identification and other risk control data) to the token, the trusted token attributes are made more comprehensive, and the risk control investigation ability of the application party (scenario) is enhanced. For example, when applied in location-sensitive access control scenarios, it can prevent users from providing QR codes to others for authentication; use reliable security carriers TEE and / or SE to protect the management and use of user information data and keys (user data and processing process); allow users to use the local biometric features of the device to bind the identity token to unlock, and only need to use a smartphone without carrying additional devices to meet the identity authentication needs, thereby improving user experience In some application modes, identity authentication and decryption can be achieved without equipment modification, such as the offline decryption mode of real-name authentication. Sensitive information is stored in a secure environment and will be encrypted and displayed only when required with user authorization. There is no need to upload biometric data to the server, which strengthens privacy protection. Flexible deployment and application can meet real-name / anonymous, offline / online and other scenarios. Trusted tokens issued after verification by authoritative organizations meet compliance requirements, and authentication is more authentic and reliable. Even anonymous authentication has a traceability function. Token calls are bound to biometric functions and can be flexibly called, which improves user convenience. In scenarios where real-name authentication is not required, anonymous authentication can be performed to avoid exposure of user identity information.
[0078] In an optional embodiment of the present invention, the verification party includes a remote trusted service platform server. The identity verification method also includes:
[0079] Encrypt the data to be verified using the encryption key to obtain encrypted data to be verified;
[0080] Send the encrypted data to be verified to the remote trusted service platform server;
[0081] The remote trusted service platform server uses the decryption key to decrypt the encrypted data to be verified to obtain the data to be verified, and verifies the trusted information.
[0082] It should be noted that the remote trusted service platform server does not refer to a specific server, but is a general term for services involved in the operation of identity token services, including but not limited to: authoritative identity authentication services, certificate issuance services, identity token verification services, activation management services, application access services, etc., and also includes related background services of terminal equipment manufacturers.
[0083] Optionally, the encryption key includes a token encryption subkey. The identity verification method also includes:
[0084] Use the private key of the user device certificate to sign the data to be verified, and obtain the signed data to be verified;
[0085] The signature data to be verified is encrypted using the token encryption subkey to obtain the encrypted data to be verified;
[0086] The remote trusted service platform server obtains the token encryption subkey according to the token encryption master key, and decrypts the encrypted data to be verified according to the token encryption subkey to obtain the signed data to be verified;
[0087] The remote trusted service platform server extracts the user device certificate and verifies it using the CA root key;
[0088] The remote trusted service platform server uses the user device certificate public key to verify the signature of the data to be verified and obtains the data to be verified.
[0089] Among them, the verification result of the trusted information passes the risk control check of the trusted information by the remote trusted service platform server.
[0090] Furthermore, combined with Figure 2 The specific embodiment shown, in the identity verification method, includes the following steps:
[0091] Step 1: Initiate identity display;
[0092] The user (Actor) operates the management application 130 to initiate identity (token) presentation.
[0093] Step 1.1: Call the identity token;
[0094] The management application 130 calls the secure carrier (secure environment) 110 to call the identity token.
[0095] Step 1.1.1: User authentication;
[0096] The secure element 110 pops up a user authentication prompt, and the user performs local biometric authentication or PIN authentication.
[0097] Step 1.1.2: Obtain trusted data (trusted information);
[0098] After the user passes the local biometric authentication or PIN authentication, the secure element 110 collects trusted data such as trusted time, trusted location, device health status, and trusted device identification.
[0099] Step 1.1.3: Assemble token data (data to be verified) and sign with UDC-SK;
[0100] The security element 110 synthesizes token data using the user device certificate, trusted data, identity information, etc., and signs the token data using UDC-SK (user device certificate private key).
[0101] Step 1.1.4: Encrypt token data using TEK-DK;
[0102] Use TEK-DK (token encryption subkey) to encrypt the token data and signature, add a token identifier, and output it as encrypted token data (encrypted data to be verified).
[0103] Step 1.1.5: Token data transmission;
[0104] The secure element 110 is presented or transmitted (encrypted data to be verified) to the authentication device using a TUI QR code, Bluetooth or other methods.
[0105] Step 1.1.5.1: Request token verification;
[0106] The authentication device 500 sends the encrypted token data (encrypted data to be verified) to the trusted token server 300 .
[0107] Step 1.1.5.1.1: Disperse TEK-DK according to TEK-MK;
[0108] The token server (remote trusted service platform server) 300 uses TEK-MK (token encryption master key) and the token identifier to derive TEK-DK (token encryption subkey).
[0109] Step 1.1.5.1.2: Decrypt the token data using TEK-DK;
[0110] Decrypt the token data (encrypted data to be verified) using TEK-DK (token encryption subkey).
[0111] Step 1.1.5.1.3: Extract the user device certificate and verify it using CA-ROOT;
[0112] Find the user device certificate based on the token identifier and verify it using CA-ROOT (CA root key).
[0113] Step 1.1.5.1.4: Verify token data using UDC-PK;
[0114] Use UDC-PK (User Device Certificate Public Key) to verify the token data signature (signature to be verified data).
[0115] Step 1.1.5.1.5: Trusted data risk control check;
[0116] Perform risk control checks on the trusted data, and send the decrypted identity information and risk control data to the authentication device 500.
[0117] Step 1.1.5.2: Use identity information for business verification.
[0118] The authentication device 500 performs checks based on the identity information and risk control data.
[0119] Optionally, during the identity authentication process, TUI (Trusted UI) technology is used to protect key data display and user PIN input, etc., to provide a high level of security.
[0120] In an optional embodiment of the present invention, the verifier includes a remote trusted service platform server. The remote trusted service platform server generates a platform key pair, the platform key pair includes a platform private key and a platform public key; the remote trusted service platform server stores the platform private key. The identity verification method also includes:
[0121] Use the platform public key to encrypt the data to be verified to obtain the encrypted data to be verified;
[0122] Send the encrypted data to be verified to the remote trusted service platform server;
[0123] The remote trusted service platform server uses the platform private key to decrypt the encrypted data to be verified to obtain the data to be verified.
[0124] Reference Figure 2 As shown, the security carrier 110 uses the RTSP-TK (platform key) public key of the trusted token server 300 to encrypt the token data (data to be verified), and the trusted token server 300 uses the RTSP-TK (platform key) private key to decrypt. In this embodiment, the authentication device only needs to access the trusted token server 300 to complete the identity authentication, which is simple to deploy and can even be achieved by installing the authentication App on a smartphone (the App needs to be recognized and authorized by the trusted token server 300).
[0125] In an optional embodiment of the present invention, the verification party includes an authentication device; the authentication device stores a token encryption master key and a CA root key. The identity verification method also includes:
[0126] Use the private key of the user device certificate to sign the data to be verified, and obtain the signed data to be verified;
[0127] The signature data to be verified is encrypted using the token encryption subkey to obtain the encrypted data to be verified;
[0128] Sending the encrypted data to be verified to the authentication device;
[0129] The authentication device obtains the token encryption subkey according to the token encryption master key, and decrypts the encrypted data to be verified according to the token encryption subkey to obtain the signature data to be verified;
[0130] The authentication device extracts the user device certificate and verifies it using the CA root key;
[0131] The authentication device uses the public key of the user device certificate to verify the signature of the data to be verified and obtains the data to be verified.
[0132] The verification result of the trusted information includes a risk control check of the trusted information by an authentication device.
[0133] Furthermore, combined with Figure 3 The specific embodiment shown, in the identity verification method, includes the following steps:
[0134] Step 1: Initiate identity display;
[0135] The user (Actor) operates the management application 130 to initiate identity (token) presentation.
[0136] Step 1.1: Call the identity token;
[0137] The management application 130 calls the secure carrier (secure environment) 110 to call the identity token.
[0138] Step 1.1.1: User authentication;
[0139] The secure element 110 pops up a user authentication prompt, and the user performs local biometric authentication or PIN authentication.
[0140] Step 1.1.2: Obtain trusted data (trusted information);
[0141] After the user passes the local biometric authentication or PIN authentication, the secure element 110 collects trusted data such as trusted time, trusted location, device health status, and trusted device identification.
[0142] Step 1.1.3: Assemble token data (data to be verified) and sign with UDC-SK;
[0143] The security element 110 synthesizes token data using the user device certificate, trusted data, identity information, etc., and signs the token data using UDC-SK (user device certificate private key).
[0144] Step 1.1.4: Encrypt token data using TEK-DK;
[0145] Use TEK-DK (token encryption subkey) to encrypt the token data and signature, add a token identifier, and output it as encrypted token data (encrypted data to be verified).
[0146] Step 1.1.5: Token data transmission;
[0147] The secure element 110 is presented or transmitted (encrypted data to be verified) to the authentication device using a TUI QR code, Bluetooth or other methods.
[0148] Step 1.1.5.1: Disperse TEK-DK according to TEK-MK;
[0149] The authentication device 500 uses TEK-MK (Token Encryption Master Key) and the token identifier to derive TEK-DK (Token Encryption Subkey).
[0150] Step 1.1.5.2: Decrypt the token data using TEK-DK;
[0151] The authentication device 500 decrypts the token data (encrypted data to be verified) using TEK-DK (token encryption subkey).
[0152] Step 1.1.5.3: Extract the user device certificate and verify it using CA-ROOT;
[0153] Find the user device certificate based on the token identifier and verify it using CA-ROOT (CA root key).
[0154] Step 1.1.5.4: Verify token data using UDC-PK;
[0155] Use UDC-PK (User Device Certificate Public Key) to verify the token data signature (signature to be verified data).
[0156] Step 1.1.5.5: Trusted data risk control check;
[0157] Conduct risk control checks on trusted data.
[0158] Step 1.1.5.6: Use identity information for business verification.
[0159] The authentication device 500 performs checks based on the identity information and risk control data.
[0160] In the above-mentioned embodiment of the present invention, the data displayed by the trusted token does not require identity information and data encryption. The authentication device holds a CA-ROOT certificate, uses CA-ROOT to verify the identity token data, and performs identity processing according to the token identifier.
[0161] Figure 4 FIG. 4 shows an interactive flow chart of identity token activation according to Embodiment 4 of the present invention. Figure 4 As shown, the identity token provisioning interaction according to the embodiment of the present invention occurs between the user, the management application 130 , the secure element 110 and the remote trusted service platform server 300 .
[0162] First, the terms that may be involved in the identity token activation interaction (the identity verification method and system described in this application) are uniformly explained:
[0163] Identity Token refers to the identity proof data used in this product to present to the authenticator.
[0164] Identity Token System is a technical system that supports the operation of identity token products.
[0165] The remote trusted service platform (RTSP), that is, the trusted token server (remote trusted service platform server) 300 .
[0166] The Certificate Authority (CA) server, which is part of RTSP, is responsible for issuing, managing, storing and revoking digital certificates.
[0167] User Device Cert (UDC), a digital certificate issued by RTSP to a user's trusted device.
[0168] User Device Identifier (UDI): RTSP is an identification number associated with both the user and the trusted device generated by the user's trusted device according to rules. The UDI of the same user on different devices is also different. The UDI is bound to the user's device certificate.
[0169] Trusted Device Key (TDK) is a trusted device authentication key deployed by the device manufacturer to the device. It can be called through the TEE interface and use TDK to sign data to ensure that the data comes from a legitimate device trusted by the device manufacturer.
[0170] The trusted device authentication server, which is part of RTSP, is responsible for verifying the data signed by TDK in the device to ensure that the data comes from a legitimate device trusted by the device manufacturer.
[0171] A unified description of the keys that may be involved in this application:
[0172] The trusted device key (TDK for short) is a trusted device authentication key deployed by the device manufacturer to the device. The TDK is used to sign the data through the TEE interface to ensure that the data comes from a legitimate device trusted by the device manufacturer. The trusted device key is generated or preset in the secure element 110. The secure element 110 holds the private key of the trusted device key, and RTSP holds the public key or certificate of the trusted device key.
[0173] The RTSP platform key (RTSP-TK for short) is created or preset by RTSP. RTSP holds the private key of the RTSP platform key, and the security element 110 presets the public key of the RTSP platform key.
[0174] The CA root key (CA-ROOT for short) is the key used by the certificate issuing server in RTSP to issue certificates. The CA root key is generated or preset by RTSP. RTSP stores the private key and certificate of the CA root key; the CA-ROOT certificate is also distributed to the authentication device 500.
[0175] The application service authentication key public key or public key certificate (ABA-PK for short) is used to verify the real person information service authorization package submitted by the general application 120 when calling the security carrier 100. The authorization package is signed by RTSP using the corresponding private key. The application service authentication key public key or public key certificate is preset by RTSP or dynamically generates an application authorization verification key pair, and the public key is preset or synchronized (stored) to the security carrier 110.
[0176] The application authorization verification key private key (ABA-SK for short) is stored in RTSP. RTSP uses this key to authorize the application's submission of real-person information services.
[0177] The token encryption master key (TEK-MK for short) is used to disperse the master key of each identity token encryption key. The token encryption master key is created or preset by RTSP and synchronized to the authentication device 500. The token encryption master key is stored in RTSP / authentication device 500.
[0178] The token encryption subkey (TEK-DK for short) is used to encrypt the identity token data on the user device side. The token encryption subkey is dispersed by RTSP and transmitted (stored) to the secure element 110.
[0179] The secure channel key group (SCKs, including the encryption key SCK-ENC and the verification key SCK-HMAC) is used to establish a secure channel between the secure element 110 and the RTSP, and is created during the user device certificate activation process. The secure channel key group is randomly generated by RTSP and synchronized to the secure element 110. The secure channel key group is stored in the RTSP / secure element 110.
[0180] The user equipment certificate key pair (including the user equipment certificate private key UDC-SK and the user equipment certificate public key UDC-PK) is created and generated (randomly generated) by the security carrier 110, and the public key is exported to RTSP for issuing the user equipment certificate (UDC-PK is exported and sent to RTSP), the private key is used for service confirmation signature, and the public key is used for signature verification. The security carrier 110 stores UDC-SK and UDC issued by RTSP; RTSP stores UDC.
[0181] The identity information submission temporary asymmetric encryption key (IEK) is used to encrypt the identity information when submitting it to the application, and is generated by the application server 200 and synchronized to the security carrier 110 through RTSP authentication. The application server 200 caches or stores the private key of the identity information submission temporary asymmetric encryption key.
[0182] Specifically, the user sends a function activation request to the management application 130 (the user operates the management application 130 to activate it); the management application 130 collects identity information and on-site face from the user (takes a face photo), and the user provides the identity information to the management application 130 and takes a photo of the on-site face.
[0183] The secure element 110 obtains the face information ciphertext from the management application 130, calculates and saves the face feature template (calculates and saves the face feature data calculated using the face photo), and encrypts the identity information and the face photo using the RTSP-TK public key, where RTSP-TK is, for example, a remote trusted service platform server key. The secure element 110 sends the identity information ciphertext to the management application 130.
[0184] The management application 130 submits the real person verification to the remote trusted service platform server 300. The submitted real person verification includes the identity information ciphertext (user identity information and face ciphertext). The remote trusted service platform server 300 uses the RTSP-TK private key to decrypt the identity information and photo (user identity and face data), and performs an authority service database check (face). The remote trusted service platform server 300 returns the comparison result to the management application 130.
[0185] The management application 130 calls the secure element 110 to create an activation request. The secure element 110 performs a device status security check, creates a UDC-SK key pair (the generation of the UDC-SK key has the property of one private key and one secret key), assembles the activation request data (including at least the public key of the security key pair, the device identifier, and the self-signature), and uses the TDK (Trusted Device Key) to (secondarily) sign the activation request data. The secure element 110 requests the user to set a key PIN code (a TUI pops up for the user to set a PIN code). The secure element 110 returns the activation request data to the management application 130.
[0186] The management application 130 sends an activation request to the remote trusted service platform server 300, and the activation request includes the activation request data. The remote trusted service platform server 300 uses the TDK public key to verify the activation request data, generate UDI, issue UDC (generate user device identification UDI based on user information and issue user device certificate UDC), generate SCKs, use TEK-MK (for user device identification) to disperse the subkey TEK-DK, and use SCKs to encrypt UDC, TEK-DK, UDI and user identity information, and use UDC-PK to encrypt SCKs. The remote trusted service platform server 300 sends the activation response data (including the above data) to the management application 130.
[0187] The management application 130 imports the activation response (activation response data) to the secure element 110. The secure element 110 uses the UDC-SK to decrypt the SCKs, and then uses the SCKs to decrypt and save the UDC, UDI, TEK-DK and user identity information. The secure element 110 binds the local biometric feature. If the binding is successful, the local biometric feature verification can be used to unlock the trusted token.
[0188] After the identity token is activated, the identity token can be used for identity verification of this application. Figure 2 and Figure 3 As shown, after the user initiates identity presentation, the management application 130 requests the secure element 110 to call the identity token.
[0189] Figure 5 A method flow chart of an identity verification method according to Embodiment 5 of the present invention is shown. Figure 5 As shown, the identity verification method according to the fifth embodiment of the present invention is performed by, for example, an authentication device and / or a remote trusted platform server, and specifically includes the following steps:
[0190] In step S201, the trusted information and identity information to be verified are obtained;
[0191] Obtain the trusted information and identity information to be verified.
[0192] In step S202, the trusted information to be verified is verified;
[0193] Verify the trusted information to be verified (risk control check).
[0194] In step S203, after the trusted information is verified, the identity information is used to perform business verification.
[0195] After the trusted information is verified, (the authentication device) uses the identity information to verify the business.
[0196] According to another aspect of the present invention, an identity verification system is provided. The identity verification system includes a device end (smartphone, smart watch, etc.). The device end obtains trusted information and generates data to be verified based on the trusted information and identity information. The device end sends the data to be verified to the verification party, and after the verification party verifies the trusted information, the identity information is used for business verification.
[0197] Figure 6 FIG. 2 shows a schematic diagram of the structure of an identity verification system according to an embodiment of the present invention. The identity verification system according to an embodiment of the present invention is used, for example, to implement the identity verification method described above. Figure 6 As shown, the identity verification system according to an embodiment of the present invention includes at least one of the following components:
[0198] The terminal device (mobile terminal / device end) 100 is a terminal device held by a user, such as a smart phone, a smart watch, etc. A security element (such as TEE or SE or both) is integrated on the terminal device 100 .
[0199] The security carrier 110 is a software and hardware module on the terminal device 100. It implements the security function interface by accessing TEE\SE internally, and provides the interface to external applications. Among them, the security carrier access service program 111 provides an entity program for the external interface of the security carrier 110, accesses TEE\SE to implement the functional interface encapsulation of the identity token, and provides external calls. TEE (Trusted Execution Environment) 112 is a security carrier, which is a logical security isolation area of the system SOC and can execute security applications. SE (Secure Element) 112 is generally an independent encryption chip. Due to its independent isolation characteristics, it has a higher security level than TEE. Calling the SE interface in TEE can further ensure business security.
[0200] The general application 120 calls the secure element 110 to call the application of various functions of the identity token. The management application 130 calls the secure element 110 to perform identity token provisioning management.
[0201] The trusted token server (remote trusted service platform server) 300 is a general term for services involved in the operation of identity token services, including but not limited to: authoritative identity authentication services, certificate issuance services, identity token verification services, activation management services, application access services, etc., and also includes terminal equipment manufacturer-related background services.
[0202] The application server 200 is a background service of the common application 120 and processes authentication requests of the common application 120 .
[0203] The (near field) authentication device 500 is a device used to verify and authenticate the identity token generated by the terminal device.
[0204] The identity verification method and system according to the embodiment of the present invention provide a higher level of security protection by combining multi-factor authentication (trusted location, trusted time, etc.) and trusted execution environment (TEE) / SE to store private keys; dynamically generated signatures and multi-dimensional data verification further enhance the security of the system to ensure that private keys and sensitive data are not illegally accessed or tampered with; identity verification can be completed using a smartphone without carrying additional cards or devices. Through local biometric recognition and digital signatures, users can quickly and conveniently complete identity authentication, reducing waiting time and operation steps; simplifying application access, and only a small amount of technical adaptation or only adding data receiving devices or even reusing existing smart devices is required according to the demand scenario. It is not only applicable to traditional fields such as finance, medical care, and government services, but can also be expanded to multiple emerging fields such as the Internet of Things, travel hotels, and government services. It supports online verification and near-field verification (such as NFC, Bluetooth, WIFI, etc.), and is suitable for different network environments and usage scenarios, with a wider range of applicability. Through local verification and data encryption, it reduces the transmission and storage of sensitive data, reduces the risk of data leakage, and users can decide when and where to share their identity information, thereby enhancing control over personal data. After authorization by the user, authentication collects and provides real device status, trusted time, location and other data through the device side. The application party uses this data for sophisticated risk control management, such as preventing substitution and device simulation.
[0205] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0206] According to the embodiments of the present invention as described above, these embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and changes can be made based on the above description. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can make good use of the present invention and the modified use based on the present invention. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. An identity verification method, comprising: Get credible information; Generate data to be verified based on the trusted information and identity information; Send the data to be verified to the verification party, After the verification of the trusted information by the verification party, the identity information is used for business verification.
2. The identity verification method according to claim 1, wherein: The identity verification method further includes: Perform biometric authentication; After the biometric feature recognition authentication is passed, the trusted information is obtained and the data to be verified is generated according to the trusted information and the identity information.
3. The identity verification method according to claim 1, wherein: The trusted information includes at least one selected from trusted time, trusted location, device health status, and trusted device identification.
4. The identity verification method according to claim 1, wherein: The verification party includes a remote trusted service platform server; The identity verification method further includes: Encrypting the data to be verified using an encryption key to obtain encrypted data to be verified; Sending the encrypted data to be verified to the remote trusted service platform server; The remote trusted service platform server uses a decryption key to decrypt the encrypted data to be verified to obtain the data to be verified, and verifies the trusted information.
5. The identity verification method according to claim 4, wherein: The encryption key includes a token encryption subkey; The identity verification method further includes: Sign the data to be verified using the private key of the user device certificate to obtain signed data to be verified; Encrypt the signature data to be verified using the token encryption subkey to obtain the encrypted data to be verified; The remote trusted service platform server obtains the token encryption subkey according to the token encryption master key, and decrypts the encrypted data to be verified according to the token encryption subkey to obtain the signature data to be verified; The remote trusted service platform server extracts the user device certificate and verifies it using the CA root key; The remote trusted service platform server verifies the signature of the data to be verified using the public key of the user device certificate to obtain the data to be verified. The verification result of the trusted information includes passing the risk control check of the trusted information by the remote trusted service platform server.
6. The identity verification method according to claim 1, wherein: The verification party includes a remote trusted service platform server; the remote trusted service platform server generates a platform key pair, and the platform key pair includes a platform private key and a platform public key; The remote trusted service platform server stores the platform private key; The identity verification method further includes: Encrypt the data to be verified using the platform public key to obtain encrypted data to be verified; Sending the encrypted data to be verified to the remote trusted service platform server; The remote trusted service platform server uses the platform private key to decrypt the encrypted data to be verified to obtain the data to be verified.
7. The identity verification method according to claim 1, wherein: The verification party includes an authentication device; The authentication device stores a token encryption master key and a CA root key; The identity verification method further includes: Sign the data to be verified using the private key of the user device certificate to obtain signed data to be verified; Encrypt the signature data to be verified using the token encryption subkey to obtain the encrypted data to be verified; Sending the encrypted data to be verified to the authentication device; The authentication device obtains the token encryption subkey according to the token encryption master key, and decrypts the encrypted data to be verified according to the token encryption subkey to obtain the signature data to be verified; The authentication device extracts the user device certificate and verifies it using the CA root key; The authentication device verifies the signature of the data to be verified using the public key of the user device certificate to obtain the data to be verified. Wherein, the verification result of the trusted information includes the risk control check of the trusted information by the authentication device; After the trusted information is verified, the authentication device uses the identity information to perform business verification.
8. The identity verification method according to claim 1, wherein: The identity verification method includes: The data to be verified is generated in a secure environment according to the trusted information and the identity information; the secure environment includes at least one selected from a SE environment, a TEE environment, and a system keystore.
9. An identity verification method, comprising: Obtaining credible information and identity information to be verified; Verifying the trusted information to be verified; After the trusted information is verified, the identity information is used for business verification.
10. An identity verification system, comprising: The device side obtains the trusted information and generates the data to be verified according to the trusted information and the identity information; The device sends the data to be verified to the verification party, and after the verification party verifies the trusted information, the identity information is used to perform business verification.