User entity authentication method and device based on Internet of Things
By establishing a mutual trust mechanism based on the Internet of Things in the online payment settlement business of public and physical authentication, users are subject to physical authentication, and the problem of repeated authentication of users is solved, convenient identity authentication is achieved, user experience is improved and system security is ensured.
Patent Information
- Application Number
- CN202410223118.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-28
- Publication Date
- 2025-05-13
AI Technical Summary
In the online payment settlement business of public online payment, users need to repeatedly conduct physical authentication, resulting in high operational redundancy, poor user experience and inability to guarantee system security.
By establishing a mutual trust mechanism based on the Internet of Things, users are physically authenticated, and entity authentication element information sent by the user terminal of the user to be authenticated is obtained, consistency verification and timeliness verification are performed. If passed, the user password will be encrypted through the user's public key and physical authentication will be performed through the private key decryption, authentication results will be generated and business processing will be performed within the mutual trust time limit.
It reduces the redundancy of user operations, reduces user operation steps, improves the convenience of user operations, saves time and costs, optimizes user experience, and ensures system security.
Smart Images

Figure CN119991127A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, in particular to the field of artificial intelligence technology, and more particularly to a user entity authentication method and device based on the Internet of Things. Background Art
[0002] In the field of public online payment and settlement business, enterprises need to undergo entity authentication for related operations. Common entity authentication tools used in the banking industry include physical media such as U-Shield. In actual use, users have to repeat identity authentication multiple times in multiple operation steps and interface switching processes, which results in high redundancy and poor user experience. In related technologies, the number of identity authentications is controlled by monitoring the interface refresh time, but this method can only reduce the number of identity authentications on the same interface, and there is a certain loss in security. When users operate on different interfaces, they still have to repeat entity authentication multiple times. The operation steps have high redundancy, the operation is complicated, the time cost is high, the user experience is poor, and the system security cannot be guaranteed. Summary of the invention
[0003] One object of the present invention is to provide a user entity authentication method based on the Internet of Things, by establishing a mutual trust mechanism to authenticate the user entity, in the subsequent interaction process, the user does not need to repeat the identity authentication multiple times, reducing the operation redundancy, reducing the user operation steps, improving the convenience of user operation, saving time cost, optimizing user experience, and ensuring system security. Another object of the present invention is to provide a user entity authentication device based on the Internet of Things. Another object of the present invention is to provide a computer readable medium. Another object of the present invention is to provide a computer device.
[0004] In order to achieve the above objectives, the present invention discloses, on one hand, a user entity authentication method based on the Internet of Things, comprising:
[0005] Obtain entity authentication factor information sent by a user terminal of the user to be authenticated;
[0006] Through the preset mutual trust mechanism, the entity authentication factor information is verified for consistency and timeliness. If both the consistency verification and timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password.
[0007] Decrypt the user's encrypted password through the stored user private key and perform entity authentication to generate an authentication result;
[0008] The authentication result is sent to the user terminal and the business is processed within the mutual trust period.
[0009] Preferably, the entity authentication factor information is verified for consistency and timeliness through a preset mutual trust mechanism, including:
[0010] The consistency of entity authentication factor information is verified through hash encryption algorithm;
[0011] If the consistency verification is passed, the corresponding mutual trust validity and certificate validity are queried according to the user ID of the user to be authenticated;
[0012] Determine whether the current time is within the mutual trust period and certificate period;
[0013] If both are yes, it is determined that the timeliness verification has passed;
[0014] If at least one of them is no, it is determined that the timeliness verification has failed.
[0015] Preferably, the entity authentication factor information is verified for consistency through a hash encryption algorithm, including:
[0016] The entity authentication factor information is hashed and encrypted by a hash encryption algorithm to obtain the encrypted factor information to be authenticated;
[0017] According to the user ID of the user to be authenticated, the corresponding standard encryption element information is queried;
[0018] Determine whether the encryption element information to be authenticated is consistent with the standard encryption element information;
[0019] If so, it is determined that the consistency verification has passed;
[0020] If not, it is determined that the consistency verification has failed.
[0021] Preferably, the user encrypted password is decrypted by the stored user private key and entity authentication is performed to generate an authentication result, including:
[0022] Through the decryption algorithm, the user's encrypted password is decrypted according to the user's private key to generate a user's decrypted password;
[0023] Through the preset risk detection model, the user ID and user decryption password of the authenticated user are subjected to risk detection;
[0024] If the risk detection passes, an authentication result indicating that the entity authentication has passed is generated;
[0025] If the risk detection fails, an authentication result indicating entity authentication failure is generated.
[0026] Preferably, risk detection is performed on the user identification and user decryption password of the user to be authenticated through a preset risk detection model, including:
[0027] Determining whether the stored abnormal user list includes the user identifier;
[0028] If so, it is determined that the risk detection has failed;
[0029] If not, query the corresponding user password according to the user ID;
[0030] Determine whether the user decryption password is consistent with the user password;
[0031] If they are consistent, it is determined that the risk detection is successful;
[0032] If they are inconsistent, it is determined that the risk detection has failed.
[0033] Preferably, it also includes:
[0034] Receive standard element information, user password, mutual trust validity period and certificate validity period sent by the user terminal of the user to be authenticated;
[0035] Through the user ID of the user to be authenticated, the mutual trust mechanism is established to verify the standard element information and user password;
[0036] If the verification is successful, the public-private key pair corresponding to the user to be authenticated is generated through an asymmetric encryption algorithm. The public-private key pair includes the user's public key and the user's private key.
[0037] The standard element information is hashed and encrypted by a hash encryption algorithm to obtain the standard encrypted element information;
[0038] Stores standard encryption element information, user public key, user private key, user password, mutual trust period and certificate period.
[0039] Preferably, a public-private key pair corresponding to the user to be authenticated is generated through an asymmetric encryption algorithm, the public-private key pair including a user public key and a user private key, including:
[0040] Randomly generate a first prime number and a second prime number;
[0041] Generate a key length according to the first prime number and the second prime number;
[0042] According to the key length, construct the Euler function;
[0043] Generate a key random number according to the Euler function;
[0044] Generate modular inverse elements based on the key random number and Euler function;
[0045] Determine the key length and the modulus inverse element as the user's private key;
[0046] The key length and key random number are determined as the user's public key.
[0047] The present invention also discloses a user entity authentication device based on the Internet of Things, comprising:
[0048] An acquiring unit, used for acquiring entity authentication factor information sent by a user terminal of a user to be authenticated;
[0049] The element verification unit is used to perform consistency verification and timeliness verification on the entity authentication element information through a preset mutual trust mechanism; if both the consistency verification and timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password;
[0050] The entity authentication unit is used to decrypt the user's encrypted password through the stored user private key and perform entity authentication to generate an authentication result;
[0051] The sending unit is used to send the authentication result to the user terminal and perform business processing within the mutual trust time limit.
[0052] The present invention also discloses a computer-readable medium on which a computer program is stored. When the program is executed by a processor, the method described above is implemented.
[0053] The present invention also discloses a computer device, including a memory and a processor, wherein the memory is used to store information including program instructions, the processor is used to control the execution of program instructions, and the processor implements the above method when executing the program.
[0054] The present invention also discloses a computer program product, including a computer program / instruction, and the method described above is implemented when the computer program / instruction is executed by a processor.
[0055] The present invention obtains entity authentication factor information sent by a user terminal of a user to be authenticated; performs consistency verification and timeliness verification on the entity authentication factor information through a preset mutual trust mechanism; if both the consistency verification and timeliness verification are passed, encrypts the stored user password through the user public key corresponding to the user to be authenticated to obtain the user encrypted password; decrypts the user encrypted password through the stored user private key and performs entity authentication to generate an authentication result; sends the authentication result to the user terminal, and performs business processing within the mutual trust time limit. By establishing a mutual trust mechanism, the user is physically authenticated. In the subsequent interaction process, the user does not need to perform multiple repeated identity authentications, which reduces operation redundancy, reduces user operation steps, improves the convenience of user operation, saves time cost, optimizes user experience, and ensures system security at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0057] Figure 1 A flowchart of a user entity authentication method based on the Internet of Things provided by an embodiment of the present invention;
[0058] Figure 2 A flow chart of a mechanism for establishing mutual trust among users provided by an embodiment of the present invention;
[0059] Figure 3 A flowchart of another method for user entity authentication based on the Internet of Things provided by an embodiment of the present invention;
[0060] Figure 4 A schematic diagram of the structure of a user entity authentication device based on the Internet of Things provided by an embodiment of the present invention;
[0061] Figure 5 A schematic diagram of the structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0062] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0063] It should be noted that the user entity authentication method and device based on the Internet of Things disclosed in the present application can be used in the field of artificial intelligence technology, and can also be used in any field outside the field of artificial intelligence technology. The application field of the user entity authentication method and device based on the Internet of Things disclosed in the present application is not limited.
[0064] In order to facilitate the understanding of the technical solution provided by this application, the relevant contents of the technical solution of this application are first explained below. This application is about a public online payment mutual trust mechanism based on the Internet of Things provided to corporate users in the field of public payment and settlement business of the banking financial technology sector. It solves the problem that public enterprises need to repeat entity authentication many times when performing operations such as corporate online banking, online transactions, and transfers. Through the Internet of Things and encryption algorithms, more convenient identity entity authentication is achieved. This application encrypts the user's entity authentication element information through a hash encryption algorithm to establish a mutual trust mechanism. In the mutual trust mechanism, users can choose the time limit of mutual trust by themselves, improve operational convenience, and optimize customer experience.
[0065] The following takes the user entity authentication device based on the Internet of Things as an example of the execution subject to illustrate the implementation process of the user entity authentication method based on the Internet of Things provided by the embodiment of the present invention. It can be understood that the execution subject of the user entity authentication method based on the Internet of Things provided by the embodiment of the present invention includes but is not limited to the user entity authentication device based on the Internet of Things.
[0066] Figure 1 A flowchart of a user entity authentication method based on the Internet of Things provided by an embodiment of the present invention, such as Figure 1 As shown, the method includes:
[0067] Step 101: Obtain entity authentication factor information sent by a user terminal of a user to be authenticated.
[0068] Step 102: Through the preset mutual trust mechanism, the entity authentication factor information is verified for consistency and timeliness; if both the consistency verification and timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password.
[0069] Step 103: Decrypt the user's encrypted password using the stored user private key and perform entity authentication to generate an authentication result.
[0070] Step 104: Send the authentication result to the user terminal and perform business processing within the mutual trust period.
[0071] In the technical solution provided by the embodiment of the present invention, entity authentication factor information sent by the user terminal of the user to be authenticated is obtained; through a preset mutual trust mechanism, the entity authentication factor information is verified for consistency and timeliness; if both the consistency verification and the timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password; the user encrypted password is decrypted by the stored user private key and entity authentication is performed to generate an authentication result; the authentication result is sent to the user terminal, and business processing is performed within the mutual trust time limit. By establishing a mutual trust mechanism, the user is authenticated for entity authentication. In the subsequent interaction process, the user does not need to perform multiple repeated identity authentications, which reduces operation redundancy, reduces user operation steps, improves user operation convenience, saves time cost, optimizes user experience, and ensures system security at the same time.
[0072] Figure 2 A flowchart of a mutual trust mechanism for users provided in an embodiment of the present invention is shown in FIG. Figure 2 As shown, the method includes:
[0073] Step 201: Receive standard element information, user password, mutual trust time limit and certificate time limit sent by the user terminal of the user to be authenticated.
[0074] In the embodiment of the present invention, each step is performed by a user entity authentication device based on the Internet of Things.
[0075] In the embodiment of the present invention, the standard element information includes but is not limited to the media number, certificate number, certificate password, computer physical address and network address (IP address) of the U-shield entered by the user for the first time; the user password is the identity authentication password of the user to enter the server; the mutual trust time limit is the validity period of the entity authentication of the currently established mutual trust mechanism; the certificate time limit is the validity period of the certificate.
[0076] It is worth mentioning that the mutual trust period can be selected by users according to their actual needs.
[0077] Step 202: Use the user ID of the user to be authenticated to establish a mutual trust mechanism for the standard element information and the user password. If the verification is successful, execute step 203; if the verification fails, the process ends.
[0078] In the embodiment of the present invention, the user identifier can uniquely identify a user.
[0079] In the embodiment of the present invention, the server locally stores the user identification and the corresponding user information, and the user information includes the media number, certificate number, certificate password and user password of the U-shield. Specifically, the server determines whether the media number, certificate number, certificate password and user password of the U-shield entered by the user are consistent with the media number, certificate number, certificate password and user password of the U-shield stored locally. If they are all consistent, it indicates that the information of the user to be authenticated has been verified, and a mutual trust mechanism can be established for the user. The verification is successful, and step 203 is continued; if there is at least one inconsistency, it indicates that the information of the user to be authenticated has failed to be verified, the verification has failed, and a mutual trust mechanism cannot be established for the user, and the process ends.
[0080] Furthermore, if the verification fails, a verification failure message is sent to the user terminal, and the mutual trust mechanism is refused to be established for the user to be authenticated.
[0081] Step 203: Generate a public-private key pair corresponding to the user to be authenticated through an asymmetric encryption algorithm, where the public-private key pair includes a user public key and a user private key.
[0082] In the embodiment of the present invention, step 203 specifically includes:
[0083] Step 2031, randomly generate a first prime number and a second prime number.
[0084] Step 2032: Generate a key length according to the first prime number and the second prime number.
[0085] In the embodiment of the present invention, the first prime number and the second prime number are multiplied to obtain the key length, that is, n=pq, wherein n is the key length, p is the first prime number, and q is the second prime number.
[0086] Step 2033: Construct the Euler function according to the key length.
[0087] Specifically, the Euler function φ(n) of key length n is constructed.
[0088] Step 2034: Generate a key random number according to the Euler function.
[0089] In the embodiment of the present invention, a key random number e is randomly selected, and the range of the key random number e is between 1 and the Euler function φ(n) of n, and is relatively prime to the Euler function φ(n) of n, that is: gcd(e,φ(n))=1.
[0090] Step 2035: Generate a modular inverse element according to the key random number and the Euler function.
[0091] In the embodiment of the present invention, the modular inverse element d of the Euler function φ(n) of the key random number e with respect to n is calculated, that is, (d×e)modφ(n)=1. Wherein, e is the key random number, φ(n) is the Euler function, n is the key length, and d is the modular inverse element.
[0092] Step 2036: Determine the key length and the modulus inverse element as the user's private key.
[0093] Specifically, the user private key is a key length n and a modulo inverse element d.
[0094] Step 2037: Determine the key length and the key random number as the user public key.
[0095] Specifically, the user public key is a key length n and a key random number e.
[0096] Step 204: hash and encrypt the standard element information using a hash encryption algorithm to obtain standard encrypted element information.
[0097] Specifically, multiple standard element information are concatenated to obtain a standard element information string x; the standard element information string is supplemented bit by bit so that the number of bits of the supplemented standard element information string x satisfies the formula xmod512=448; a 64-bit data is supplemented, which represents the length of the original element information, so that (x+64)mod512=0; for the supplemented data, each 512 bits of data is taken as a unit, and logical processing is performed using nonlinear functions respectively; each segment of the processed unit data is superimposed to obtain standard encrypted element information; and the standard encrypted element information is output.
[0098] Step 205: Store standard encryption element information, user public key, user private key, user password, mutual trust time limit and certificate time limit.
[0099] In an embodiment of the present invention, standard encryption element information, user public key, user private key, user password, mutual trust time limit and certificate time limit are stored accordingly according to each user identification, so as to facilitate the verification of the mutual trust mechanism during subsequent user use.
[0100] In the embodiment of the present invention, the mutual trust mechanism can monitor the user authentication information by encrypting and storing the standard element information input by the user through the hash encryption algorithm. When a certain element information of the user changes, it can prompt and interrupt the mutual trust in time. At the same time, due to the complexity and irreversibility of the hash encryption algorithm, the encrypted information is more secure.
[0101] It is worth noting that the mutual trust mechanism can be integrated into the server side, or it can exist independently of the server side as a mutual trust server to verify the user identity.
[0102] In the scheme of the embodiment of the present invention, entity authentication factor information sent by the user terminal of the user to be authenticated is obtained; through a preset mutual trust mechanism, the entity authentication factor information is verified for consistency and timeliness; if both the consistency verification and the timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password; the user encrypted password is decrypted by the stored user private key and entity authentication is performed to generate an authentication result; the authentication result is sent to the user terminal, and business processing is performed within the mutual trust time limit. By establishing a mutual trust mechanism, the user is authenticated for entity authentication. In the subsequent interaction process, the user does not need to perform multiple repeated identity authentications, which reduces operation redundancy, reduces user operation steps, improves user operation convenience, saves time cost, optimizes user experience, and ensures system security at the same time.
[0103] Figure 3 A flowchart of another method for user entity authentication based on the Internet of Things provided by an embodiment of the present invention is as follows: Figure 3 As shown, the method includes:
[0104] Step 301: Obtain entity authentication factor information sent by a user terminal of a user to be authenticated.
[0105] In the embodiment of the present invention, each step is performed by a user entity authentication device based on the Internet of Things.
[0106] In the embodiment of the present invention, after the user to be authenticated establishes a mutual trust mechanism, entity authentication factor information needs to be performed once in the subsequent use process. After the authentication is passed, there is no need to repeat the authentication in subsequent operations.
[0107] In the embodiment of the present invention, the entity authentication factor information includes but is not limited to the media number, certificate number, certificate password, computer physical address and IP address of the USB shield.
[0108] Step 302: Perform consistency verification on the entity authentication factor information through a hash encryption algorithm. If the consistency verification passes, execute step 303; if the consistency verification fails, the process ends.
[0109] In the embodiment of the present invention, step 302 specifically includes:
[0110] Step 3021: Use a hash encryption algorithm to hash and encrypt the entity authentication element information to obtain the encrypted element information to be authenticated.
[0111] Specifically, multiple entity authentication factor information are concatenated to obtain an entity authentication factor information string x'; the entity authentication factor information string is supplemented bit by bit so that the number of bits of the supplemented entity authentication factor information string x' satisfies the formula x'mod512=448; a 64-bit data is supplemented, which represents the length of the original factor information, so that (x'+64)mod512=0; for the supplemented data, each 512-bit data is taken as a unit and logically processed using nonlinear functions; each segment of the processed unit data is superimposed to obtain the encrypted factor information to be authenticated.
[0112] Step 3022: According to the user ID of the user to be authenticated, query the corresponding standard encryption element information.
[0113] In the embodiment of the present invention, the mutual trust mechanism locally stores the standard encryption element information corresponding to the user identification; and queries the standard encryption element information corresponding to the user identification.
[0114] Step 3023, determine whether the encryption element information to be authenticated is consistent with the standard encryption element information. If so, execute step 303; if not, the process ends.
[0115] In the embodiment of the present invention, if the encryption element information to be authenticated is consistent with the standard encryption element information, it is determined that the consistency verification is passed and step 303 is continued; if the encryption element information to be authenticated is inconsistent with the standard encryption element information, it is determined that the consistency verification fails and the process ends.
[0116] Furthermore, if the consistency verification fails, a consistency verification failure message is sent to the user terminal, the user entity authentication fails, and the service request of the user is refused to be responded.
[0117] Step 303: According to the user ID of the user to be authenticated, the corresponding mutual trust validity period and certificate validity period are queried.
[0118] In the embodiment of the present invention, the mutual trust mechanism locally stores the mutual trust time limit and the certificate time limit corresponding to the user identifier; and queries the mutual trust time limit and the certificate time limit corresponding to the user identifier.
[0119] Step 304: determine whether the current time is within the mutual trust period and the certificate period. If both are yes, execute step 305; if at least one of them is no, the process ends.
[0120] In an embodiment of the present invention, if the current time is within the mutual trust period and the current time is within the certificate period, it indicates that the mutual trust mechanism is valid and the user's certificate is valid, and it is determined that the timeliness verification is passed, and step 305 is continued; if the current time is not within the mutual trust period and / or the current time is not within the certificate period, it indicates that the mutual trust mechanism is invalid and / or the user's certificate is invalid, and it is determined that the timeliness verification fails, and the process ends.
[0121] Furthermore, if the validity verification fails, a validity verification failure message is sent to the user terminal, the user entity authentication fails, and the service request of the user is refused to be responded.
[0122] Step 305: Encrypt the stored user password using the user public key corresponding to the user to be authenticated to obtain the user encrypted password.
[0123] Specifically, the mutual trust mechanism is implemented through the encryption algorithm c=E(m)=m e modn, encrypts the stored user password according to the user public key to obtain the user encrypted password. Among them, c is the user encrypted password, E(m) is the encryption algorithm, e is the key random number, n is the key length, and m is the user password.
[0124] Step 306: Decrypt the user encrypted password according to the user private key through a decryption algorithm to generate a user decrypted password.
[0125] Specifically, the server at the service end uses the decryption algorithm m=D(n)=c d modn, decrypts the user's encrypted password according to the user's private key to generate the user's decrypted password. Among them, m is the user's decrypted password, D(n) is the decryption algorithm, d is the modular inverse element, n is the key length, and c is the user's encrypted password.
[0126] Step 307 , using a preset risk detection model, perform risk detection on the user ID and user decryption password of the user to be authenticated. If the risk detection passes, execute step 308 ; if the risk detection fails, execute step 309 .
[0127] In the embodiment of the present invention, the risk detection model is constructed according to the actual needs of the user. As an optional solution, the risk detection model includes an abnormal user list and normal user login information. Among them, the abnormal user list is a user identification list of medium and high risk users; the normal user login information includes the user identification and corresponding user password of the normal user.
[0128] In the embodiment of the present invention, step 307 specifically includes:
[0129] Step 3071, determine whether the stored abnormal user list includes the user identifier, if so, execute step 3072; if not, step 3073.
[0130] In the embodiment of the present invention, the user identifier is matched with the user identifier in the stored abnormal user list. If the match is successful, it indicates that the abnormal user list includes the user identifier, and the user to be authenticated is a medium- or high-risk user, and step 3072 is continued; if the match fails, it indicates that the abnormal user list does not include the user identifier, and the user to be authenticated is a normal user, and step 3073 is continued.
[0131] Step 3072: Determine that risk detection has failed.
[0132] In the embodiment of the present invention, if the user to be authenticated is a medium or high risk user, the risk detection fails, a risk detection failure message is sent to the user terminal, the user entity authentication fails, and the service request of the user is refused.
[0133] Furthermore, to ensure the safety of user funds, the mutual trust mechanism of users who fail risk detection becomes invalid, and the server can refuse to establish a mutual trust mechanism for the user.
[0134] Step 3073: Query the corresponding user password according to the user ID.
[0135] In the embodiment of the present invention, the user identification is matched with the user identification in the stored normal user login information to query the corresponding user password.
[0136] Step 3074: determine whether the user decryption password is consistent with the user password. If they are consistent, execute step 3075; if they are inconsistent, execute step 3076.
[0137] In this embodiment of the present invention, if the user decrypted password is consistent with the user password, it indicates that the user password is correct and the user has not modified the password, and step 3075 is continued; if the user decrypted password is inconsistent with the user password, it indicates that the user password is wrong and the user has modified the password, and step 3076 is continued.
[0138] Step 3075: Determine that the risk detection is successful.
[0139] In the embodiment of the present invention, if the user to be authenticated is a normal user and the password has not been modified, the user does not pose a risk, and the risk detection is successful.
[0140] Step 3076: Determine that risk detection has failed.
[0141] In the embodiment of the present invention, if the user to be authenticated is an abnormal user and / or the password has been modified, the user is at risk and the risk detection fails.
[0142] Step 308 , generate an authentication result indicating that the entity has passed authentication, and proceed to step 310 .
[0143] In the embodiment of the present invention, if the mutual trust mechanism passes the consistency verification and timeliness verification of the user's entity authentication factor information and the server successfully detects the risk of the user, it indicates that the entity authentication is passed, and an authentication result of the entity authentication passing is generated.
[0144] Step 309: Generate an authentication result of entity authentication failure.
[0145] In the embodiment of the present invention, if any one of the consistency verification and timeliness verification of the user's entity authentication factor information by the mutual trust mechanism fails or the server fails the risk detection of the user, it indicates that the entity authentication has failed and an authentication result of entity authentication failure is generated.
[0146] Step 310: Send the authentication result to the user terminal.
[0147] In the embodiment of the present invention, if the entity authentication of the user is passed, the server does not need to re-authenticate the user for subsequent service requests and service operations sent by the authenticated user within the mutual trust period and the certificate period.
[0148] In the embodiment of the present invention, if the entity authentication of the user fails, the service request of the user is rejected.
[0149] Furthermore, to ensure the safety of user funds, the mutual trust mechanism for users who fail entity authentication becomes invalid. At the same time, the server can refuse to establish a mutual trust mechanism for the user based on actual needs.
[0150] It is worth noting that in order to ensure the safety of user funds, the mutual trust mechanism needs to be rebuilt when the following situations occur:
[0151] (1) The current time is not within the validity period of the mutual trust period and / or the certificate period;
[0152] (2) Any of the USB Shield's media number, certificate number, computer physical address, and IP address changes;
[0153] (3) Certificate expiration;
[0154] It is worth noting that if the user risk detection fails or the account is frozen by the judiciary, the mutual trust mechanism will become invalid directly, and the server can refuse to establish the mutual trust mechanism.
[0155] The present invention establishes a mutual trust mechanism between the bank service end and the user, thereby reducing the need for the user to input the certificate password multiple times and frequently perform identity confirmation during use, thereby reducing the user operation steps, improving the convenience of user operation, saving user time, and optimizing user experience.
[0156] It is worth noting that the acquisition, storage, use, and processing of data in the technical solution of this application are in compliance with the relevant provisions of laws and regulations. The user information in the embodiments of this application is obtained through legal and compliant channels, and the acquisition, storage, use, and processing of user information are authorized and agreed by the customer.
[0157] It is worth noting that the information collected in this application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of relevant countries and regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0158] It is worth noting that the technical solution provided in this application provides users with corresponding operation entrances for them to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered.
[0159] In the technical solution of the user entity authentication method based on the Internet of Things provided by the embodiment of the present invention, entity authentication factor information sent by the user terminal of the user to be authenticated is obtained; through a preset mutual trust mechanism, the entity authentication factor information is verified for consistency and timeliness; if both the consistency verification and the timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password; the user encrypted password is decrypted by the stored user private key and entity authentication is performed to generate an authentication result; the authentication result is sent to the user terminal, and business processing is performed within the mutual trust time limit. By establishing a mutual trust mechanism to perform entity authentication on the user, in the subsequent interaction process, the user does not need to perform multiple repeated identity authentications, which reduces operation redundancy, reduces user operation steps, improves user operation convenience, saves time cost, optimizes user experience, and ensures system security at the same time.
[0160] Figure 4 A schematic diagram of the structure of a user entity authentication device based on the Internet of Things provided by an embodiment of the present invention, the device is used to execute the user entity authentication method based on the Internet of Things, such as Figure 4 As shown, the device includes: an acquisition unit 11, a factor verification unit 12, an entity authentication unit 13 and a sending unit 14.
[0161] The acquisition unit 11 is used to acquire entity authentication factor information sent by a user terminal of a user to be authenticated.
[0162] The factor verification unit 12 is used to perform consistency verification and timeliness verification on the entity authentication factor information through a preset mutual trust mechanism; if both the consistency verification and timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password.
[0163] The entity authentication unit 13 is used to decrypt the user encrypted password through the stored user private key and perform entity authentication to generate an authentication result.
[0164] The sending unit 14 is used to send the authentication result to the user terminal and perform business processing within the mutual trust period.
[0165] In an embodiment of the present invention, the factor verification unit 12 is specifically used to perform consistency verification on the entity authentication factor information through a hash encryption algorithm; if the consistency verification passes, the corresponding mutual trust period and certificate period are queried according to the user identifier of the user to be authenticated; it is determined whether the current time is within the mutual trust period and the certificate period; if both are yes, it is determined that the timeliness verification passes; if at least one of them is no, it is determined that the timeliness verification fails.
[0166] In an embodiment of the present invention, the factor verification unit 12 is specifically used to perform hash encryption on the entity authentication factor information through a hash encryption algorithm to obtain the encrypted factor information to be authenticated; query the corresponding standard encrypted factor information according to the user identifier of the user to be authenticated; determine whether the encrypted factor information to be authenticated is consistent with the standard encrypted factor information; if so, determine that the consistency verification is passed; if not, determine that the consistency verification has failed.
[0167] In an embodiment of the present invention, the factor verification unit 12 is specifically used to decrypt the user's encrypted password according to the user's private key through a decryption algorithm to generate a user's decrypted password; perform risk detection on the user identifier and the user's decrypted password of the user to be authenticated through a preset risk detection model; if the risk detection passes, generate an authentication result of entity authentication passing; if the risk detection fails, generate an authentication result of entity authentication failing.
[0168] In an embodiment of the present invention, the factor verification unit 12 is specifically used to determine whether the stored abnormal user list includes a user identifier; if so, determine that the risk detection has failed; if not, query the corresponding user password based on the user identifier; determine whether the user decryption password is consistent with the user password; if they are consistent, determine that the risk detection is successful; if not, determine that the risk detection has failed.
[0169] In the embodiment of the present invention, the device further includes: a receiving unit 15 , a mutual trust mechanism establishment verification unit 16 , a key generation unit 17 , a hash encryption unit 18 and a storage unit 19 .
[0170] The receiving unit 15 is used to receive standard element information, user password, mutual trust time limit and certificate time limit sent by the user terminal of the user to be authenticated.
[0171] The mutual trust mechanism establishment verification unit 16 is used to verify the mutual trust mechanism establishment of the standard element information and the user password through the user identification of the user to be authenticated.
[0172] The key generation unit 17 is used to generate a public-private key pair corresponding to the user to be authenticated through an asymmetric encryption algorithm if the verification is successful. The public-private key pair includes a user public key and a user private key.
[0173] The hash encryption unit 18 is used to perform hash encryption on the standard element information through a hash encryption algorithm to obtain standard encrypted element information.
[0174] The storage unit 19 is used to store standard encryption element information, user public key, user private key, user password, mutual trust time limit and certificate time limit.
[0175] In the embodiment of the present invention, the key generation unit 17 is specifically used to randomly generate a first prime number and a second prime number; generate a key length according to the first prime number and the second prime number; construct an Euler function according to the key length; generate a key random number according to the Euler function; generate a modular inverse element according to the key random number and the Euler function; determine the key length and the modular inverse element as a user private key; determine the key length and the key random number as a user public key.
[0176] In the scheme of the embodiment of the present invention, entity authentication factor information sent by the user terminal of the user to be authenticated is obtained; through a preset mutual trust mechanism, the entity authentication factor information is verified for consistency and timeliness; if both the consistency verification and the timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password; the user encrypted password is decrypted by the stored user private key and entity authentication is performed to generate an authentication result; the authentication result is sent to the user terminal, and business processing is performed within the mutual trust time limit. By establishing a mutual trust mechanism, the user is authenticated for entity authentication. In the subsequent interaction process, the user does not need to perform multiple repeated identity authentications, which reduces operation redundancy, reduces user operation steps, improves user operation convenience, saves time cost, optimizes user experience, and ensures system security at the same time.
[0177] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer device, and specifically, the computer device may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0178] An embodiment of the present invention provides a computer device, including a memory and a processor, the memory is used to store information including program instructions, the processor is used to control the execution of the program instructions, and when the program instructions are loaded and executed by the processor, the steps of the embodiment of the above-mentioned user entity authentication method based on the Internet of Things are implemented. For a specific description, please refer to the embodiment of the above-mentioned user entity authentication method based on the Internet of Things.
[0179] Reference below Figure 5 , which shows a schematic diagram of the structure of a computer device 600 suitable for implementing an embodiment of the present application.
[0180] like Figure 5 As shown, the computer device 600 includes a central processing unit (CPU) 601, which can perform various appropriate operations and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage part 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the computer device 600 are also stored. The CPU 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0181] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal feedback device (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed, so that a computer program read therefrom is installed as needed as the storage section 608.
[0182] In particular, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product, which includes a computer program tangibly contained on a machine-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication part 609, and / or installed from the removable medium 611.
[0183] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0184] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0185] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0186] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0187] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0188] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0189] The acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.
[0190] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0191] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0192] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0193] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A user entity authentication method based on the Internet of Things, characterized in that: The method comprises: Obtain entity authentication factor information sent by a user terminal of the user to be authenticated; Through a preset mutual trust mechanism, the entity authentication factor information is verified for consistency and timeliness; if both the consistency verification and timeliness verification are passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password; Decrypt the user encrypted password using the stored user private key and perform entity authentication to generate an authentication result; The authentication result is sent to the user terminal, and business processing is performed within the mutual trust period.
2. The user entity authentication method based on the Internet of Things according to claim 1 is characterized in that: The consistency verification and timeliness verification of the entity authentication factor information are performed through a preset mutual trust mechanism, including: Performing consistency verification on the entity authentication factor information through a hash encryption algorithm; If the consistency verification is passed, the corresponding mutual trust validity period and certificate validity period are queried according to the user ID of the user to be authenticated; Determine whether the current time is within the mutual trust period and the certificate period; If both are yes, it is determined that the timeliness verification has passed; If at least one of them is no, it is determined that the timeliness verification has failed.
3. The user entity authentication method based on the Internet of Things according to claim 2 is characterized in that: The consistency verification of the entity authentication factor information by using a hash encryption algorithm includes: The entity authentication element information is hashed and encrypted by a hash encryption algorithm to obtain encrypted element information to be authenticated; According to the user identification of the user to be authenticated, the corresponding standard encryption element information is queried; Determine whether the encryption element information to be authenticated is consistent with the standard encryption element information; If so, determining that the consistency verification passes; If not, it is determined that the consistency verification has failed.
4. The user entity authentication method based on the Internet of Things according to claim 2 is characterized in that: The method of decrypting the user encrypted password by using the stored user private key and performing entity authentication to generate an authentication result includes: Decrypt the user encrypted password according to the user private key through a decryption algorithm to generate a user decrypted password; Perform risk detection on the user ID and user decryption password of the user to be authenticated through a preset risk detection model; If the risk detection passes, an authentication result indicating that the entity authentication passes is generated; If the risk detection fails, an authentication result indicating entity authentication failure is generated.
5. The method for user entity authentication based on the Internet of Things according to claim 4, characterized in that: The risk detection of the user identification and the user decryption password of the user to be authenticated by using a preset risk detection model includes: Determining whether the stored abnormal user list includes the user identifier; If so, it is determined that the risk detection has failed; If not, query the corresponding user password according to the user identification; Determine whether the user decryption password is consistent with the user password; If they are consistent, it is determined that the risk detection is successful; If they are inconsistent, it is determined that the risk detection has failed.
6. The method for user entity authentication based on the Internet of Things according to claim 1, characterized in that: Also includes: Receiving standard element information, user password, mutual trust validity period and certificate validity period sent by the user terminal of the user to be authenticated; Using the user ID of the user to be authenticated, the standard element information and the user password are verified by a mutual trust mechanism; If the verification is successful, a public-private key pair corresponding to the user to be authenticated is generated through an asymmetric encryption algorithm, and the public-private key pair includes a user public key and a user private key; The standard element information is hashed and encrypted by a hash encryption algorithm to obtain standard encrypted element information; Store the standard encryption element information, user public key, user private key, user password, mutual trust time limit and certificate time limit.
7. The method for user entity authentication based on the Internet of Things according to claim 6, characterized in that: The public-private key pair corresponding to the user to be authenticated is generated by an asymmetric encryption algorithm, wherein the public-private key pair includes a user public key and a user private key, including: Randomly generate a first prime number and a second prime number; Generate a key length according to the first prime number and the second prime number; Constructing an Euler function according to the key length; Generate a key random number according to the Euler function; Generate a modular inverse element according to the key random number and the Euler function; Determine the key length and the module inverse element as the user private key; The key length and the key random number are determined as the user public key.
8. A user entity authentication device based on the Internet of Things, characterized in that: The device comprises: An acquiring unit, used for acquiring entity authentication factor information sent by a user terminal of a user to be authenticated; The element verification unit is used to perform consistency verification and timeliness verification on the entity authentication element information through a preset mutual trust mechanism; if the consistency verification and timeliness verification are both passed, the stored user password is encrypted by the user public key corresponding to the user to be authenticated to obtain the user encrypted password; An entity authentication unit, used to decrypt the user encrypted password by using a stored user private key and perform entity authentication to generate an authentication result; The sending unit is used to send the authentication result to the user terminal and perform business processing within the mutual trust time limit.
9. A computer readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the user entity authentication method based on the Internet of Things as described in any one of claims 1 to 7 is implemented.
10. A computer device comprising a memory and a processor, wherein the memory is used to store information including program instructions, and the processor is used to control the execution of the program instructions, characterized in that: When the program instructions are loaded and executed by the processor, the user entity authentication method based on the Internet of Things according to any one of claims 1 to 7 is implemented.
11. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the method for user entity authentication based on the Internet of Things as described in any one of claims 1 to 7 is implemented.