Ukey-based identity verification system and method
Through the system and method based on Ukey authentication, certificate login and encryption is used using Ukey key and multiple password chips, the security risk of encryption of login mode in the prior art is solved, and a high security and reliability login process is achieved.
Patent Information
- Application Number
- CN202510145189.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, the login method of the business system has the security risk of encryption being cracked by entering the user name and password, resulting in a threat to data security.
The system and method based on Ukey authentication is adopted, and certificate login is used to use the Ukey key, and encryption and identity verification is carried out through multiple password chips (such as DES, AES, SM4, RSA, ECC, SM2, SHA, SM3), personal ID number information is obtained and matched with the system user information to achieve login.
Through the Ukey encryption and authentication mechanism, the security of the network is significantly improved, privacy protection is enhanced, and a variety of login methods are provided, which simplifies the authentication process and improves the reliability of operations.
Smart Images

Figure CN119995985A_ABST
Abstract
Description
Technical Field
[0001] The present invention discloses a system and method based on Ukey identity authentication, and relates to the technical field of information security. Background Art
[0002] With the continuous development of Internet technology, the information security requirements of various business systems are getting higher and higher. In the field of network security, the existing system login method is to enter the username and password, and the user information is stored in redis or database. In order to ensure the security of user information, sensitive information is encrypted and stored through SM2 national encryption. However, the existing login method has certain security risks. If the encryption method is cracked, the data of the business system will be at security risk. Summary of the invention
[0003] In view of the problems of the prior art, the present invention provides a system and method based on Ukey identity authentication, which has the characteristics of strong versatility and simple implementation, and has broad application prospects.
[0004] The specific scheme proposed by the present invention is:
[0005] The present invention also provides a Ukey-based identity authentication method, comprising:
[0006] Use the Ukey key to enter the CA login page and enter the password to verify the validity of the signature: log in to the certificate according to the Ukey key, obtain the certificate list, export the certificate signature, and obtain personal ID number information.
[0007] If the personal ID number information is not obtained successfully, the verification fails and a prompt appears: verification failed; if the personal ID number information is obtained successfully, the verification passes, and the extended information of the CA interface is obtained and matched with the system user information. If the match fails, a prompt appears: the user account is not found. If the match succeeds, the user logs in to the business system.
[0008] Furthermore, in the Ukey identity authentication method, multiple cryptographic chips are placed in the Ukey key. The cryptographic chips involve symmetric encryption algorithms, asymmetric encryption algorithms and hash algorithms. The symmetric encryption algorithms include DES, AES, and SM4. The asymmetric encryption algorithms include RSA, ECC, and SM2. The hash algorithms include SHA and SM3.
[0009] Furthermore, the Ukey identity authentication method is used to verify the validity of the signature, specifically including: reading data according to the Ukey key, calling the onBatch_Login interface to obtain the signature, after successful acquisition, calling the onBatch_GetUserList interface to log in with the certificate, obtain the certificate list, calling the onBatch_ExportUserCert interface to export the certificate signature, after successful export, calling the onBatch_GetCertInfoByOid interface to obtain personal ID number information, and the signature verification process ends.
[0010] The present invention also provides a Ukey-based identity authentication system, including a verification management module and a matching module.
[0011] The verification management module uses the Ukey key to enter the CA login page and enter the password to verify the validity of the signature: log in to the certificate according to the Ukey key, obtain the certificate list, export the certificate signature, and obtain personal ID number information.
[0012] If the personal ID number information is not obtained successfully, the verification fails and a prompt appears: verification failed; if the personal ID number information is obtained successfully, the verification passes, and the matching module obtains the extended information of the CA interface and matches it with the system user information. If the match fails, a prompt appears: the user account is not found; if the match succeeds, the user logs in to the business system.
[0013] Furthermore, the verification management module in the Ukey identity authentication system embeds multiple cryptographic chips in the Ukey key, and the cryptographic chips involve symmetric encryption algorithms, asymmetric encryption algorithms and hash algorithms. The symmetric encryption algorithms include DES, AES, and SM4, the asymmetric encryption algorithms include RSA, ECC, and SM2, and the hash algorithms include SHA and SM3.
[0014] Furthermore, the method of verifying the validity of a signature based on the verification management module in the Ukey identity authentication system specifically includes: reading data according to the Ukey key, calling the onBatch_Login interface to obtain the signature, and after successful acquisition, calling the onBatch_GetUserList interface to log in with the certificate, obtain the certificate list, and calling the onBatch_ExportUserCert interface to export the certificate signature. After successful export, calling the onBatch_GetCertInfoByOid interface to obtain personal ID number information, and the signature verification process ends.
[0015] The present invention also provides a Ukey-based identity authentication device, comprising: at least one memory and at least one processor;
[0016] The at least one memory is used to store a machine-readable program;
[0017] The at least one processor is used to call the machine-readable program to execute the Ukey-based identity authentication method.
[0018] The present invention also provides a computer-readable medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the processor executes the method based on the Ukey identity authentication method.
[0019] The benefits of the present invention are:
[0020] 1. The present invention can improve security and greatly improve the security of the network through Ukey encryption and identity authentication mechanism.
[0021] 2. The present invention can enhance privacy protection, effectively protect user information and enhance confidentiality.
[0022] 3. The present invention provides a variety of login methods for individual business systems and reduces the pressure on confidentiality assessment work.
[0023] 4. The present invention can provide high efficiency and reliability. The design of Ukey simplifies the identity authentication process, improves efficiency, and ensures the reliability of operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is a schematic flow chart of the method of the present invention.
[0025] Figure 2 It is a schematic diagram of the verification process of the present invention. DETAILED DESCRIPTION
[0026] The present invention is further described below in conjunction with the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it, but the embodiments are not intended to limit the present invention.
[0027] Example 1
[0028] The present invention also provides a Ukey-based identity authentication method, comprising:
[0029] A variety of cryptographic chips can be placed in the Ukey key. The cryptographic chips involve symmetric encryption algorithms, asymmetric encryption algorithms and hash algorithms. Symmetric encryption algorithms include DES, AES, and SM4, asymmetric encryption algorithms include RSA, ECC, and SM2, and hash algorithms include SHA and SM3.
[0030] Use the Ukey key to enter the CA login page and enter the password to verify the validity of the signature: log in to the certificate according to the Ukey key, obtain the certificate list, export the certificate signature, and obtain personal ID number information.
[0031] If the personal ID number information is not obtained successfully, the verification fails and a prompt appears: verification failed; if the personal ID number information is obtained successfully, the verification passes, and the extended information of the CA interface is obtained and matched with the system user information. If the match fails, a prompt appears: the user account is not found. If the match succeeds, the user logs in to the business system.
[0032] Specifically, it includes: reading data according to the Ukey key, calling the onBatch_Login interface to obtain the signature, and after successful acquisition, calling the onBatch_GetUserList interface to log in with the certificate, obtain the certificate list, and calling the onBatch_ExportUserCert interface to export the certificate signature. After successful export, calling the onBatch_GetCertInfoByOid interface to obtain personal ID number information, and the signature verification process ends.
[0033] Example 2
[0034] The present invention also provides a Ukey-based identity authentication system, including a verification management module and a matching module.
[0035] The verification management module uses the Ukey key to enter the CA login page and enter the password to verify the validity of the signature: log in to the certificate according to the Ukey key, obtain the certificate list, export the certificate signature, and obtain personal ID number information.
[0036] If the personal ID number information is not obtained successfully, the verification fails and a prompt appears: verification failed; if the personal ID number information is obtained successfully, the verification passes, and the matching module obtains the extended information of the CA interface and matches it with the system user information. If the match fails, a prompt appears: the user account is not found; if the match succeeds, the user logs in to the business system.
[0037] As the information interaction and execution process between the modules in the above-mentioned system are based on the same concept as the embodiment of the method of the present invention, the specific contents can be found in the description of the embodiment of the method of the present invention and will not be repeated here.
[0038] Likewise, the benefits of the system of the present invention are:
[0039] It can improve security and greatly improve the security of the network through Ukey encryption and identity authentication mechanism.
[0040] It can enhance privacy protection and effectively protect user information and enhance confidentiality.
[0041] Provide multiple login methods for each business system and reduce the pressure of doing confidentiality assessment work.
[0042] It can provide high efficiency and reliability. Ukey's design simplifies the identity authentication process, improves efficiency and ensures operational reliability.
[0043] It should be noted that not all steps and modules in the above-mentioned processes and device structures are necessary, and some steps or modules can be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structure described in the above-mentioned embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities, or some components in multiple independent devices may be implemented together.
[0044] The present invention also provides a Ukey-based identity authentication device, comprising: at least one memory and at least one processor;
[0045] The at least one memory is used to store a machine-readable program;
[0046] The at least one processor is used to call the machine-readable program to execute the Ukey-based identity authentication method.
[0047] As the information interaction, execution of readable program process and other contents of the processor in the above-mentioned device are based on the same concept as the embodiment of the method of the present invention, the specific contents can be found in the description of the embodiment of the method of the present invention and will not be repeated here.
[0048] Likewise, the benefits of the device of the present invention are:
[0049] 1. It can improve security and greatly improve the security of the network through Ukey encryption and identity authentication mechanism.
[0050] 2. It can enhance privacy protection and effectively protect user information and enhance confidentiality.
[0051] 3. Provide multiple login methods for each business system and reduce the pressure of confidentiality assessment work.
[0052] 4. It can provide high efficiency and reliability. The design of Ukey simplifies the identity authentication process, improves efficiency and ensures the reliability of operations.
[0053] Example 4
[0054] The present invention also provides a computer-readable medium, on which a computer instruction is stored, and when the computer instruction is executed by a processor, the processor executes the method based on the Ukey identity authentication method. Specifically, a system or device equipped with a storage medium can be provided, on which a software program code that implements the functions of any of the above embodiments is stored, and a computer (or CPU or MPU) of the system or device reads and executes the program code stored in the storage medium.
[0055] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute a part of the present invention.
[0056] The storage medium embodiments for providing the program code include a floppy disk, a hard disk, a magneto-optical disk, an optical disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), a magnetic tape, a non-volatile memory card, and a ROM. Alternatively, the program code can be downloaded from a server computer by a communication network.
[0057] In addition, it should be clear that the functions of any of the above embodiments can be implemented not only by executing the program code read by the computer, but also by enabling an operating system operating on the computer to complete part or all of the actual operations based on instructions from the program code.
[0058] In addition, it can be understood that the program code read from the storage medium is written to a memory provided in an expansion board inserted into the computer or written to a memory provided in an expansion unit connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or the expansion unit is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above-mentioned embodiments.
[0059] The above-described embodiments are only preferred embodiments for fully illustrating the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or changes made by those skilled in the art based on the present invention are within the protection scope of the present invention. The protection scope of the present invention shall be subject to the claims.
Claims
1. A Ukey-based identity authentication method, characterized by include: Use the Ukey key to enter the CA login page and enter the password to verify the validity of the signature: log in to the certificate according to the Ukey key, obtain the certificate list, export the certificate signature, and obtain personal ID number information. If the personal ID number information is not obtained successfully, the verification fails and the verification fails; If the personal ID number information is successfully obtained, the verification is passed, and the extended information of the CA interface is obtained and matched with the system user information. If the match is unsuccessful, it will be prompted that the user account is not found. If the match is successful, the user will log in to the business system.
2. According to claim 1, a Ukey-based identity authentication method is characterized in that A variety of cryptographic chips are embedded in the Ukey key. The cryptographic chips involve symmetric encryption algorithms, asymmetric encryption algorithms and hash algorithms. Symmetric encryption algorithms include DES, AES, and SM4. Asymmetric encryption algorithms include RSA, ECC, and SM2. Hash algorithms include SHA and SM3.
3. A Ukey-based identity authentication method according to claim 1 or 2, characterized in that Verify the validity of the signature, specifically including: reading data according to the Ukey key, calling the onBatch_Login interface to obtain the signature, after successful acquisition, calling the onBatch_GetUserList interface to log in with the certificate, obtain the certificate list, calling the onBatch_ExportUserCert interface to export the certificate signature, after successful export, calling the onBatch_GetCertInfoByOid interface to obtain the personal ID number information, and the signature verification process ends.
4. A Ukey-based identity authentication system, characterized by Including verification management module and matching module, The verification management module uses the Ukey key to enter the CA login page and enter the password to verify the validity of the signature: log in to the certificate according to the Ukey key, obtain the certificate list, export the certificate signature, and obtain personal ID number information. If the personal ID number information is not obtained successfully, the verification fails and a prompt appears: verification failed; if the personal ID number information is obtained successfully, the verification passes, and the matching module obtains the extended information of the CA interface and matches it with the system user information. If the match fails, a prompt appears: the user account is not found; if the match succeeds, the user logs in to the business system.
5. According to claim 4, a Ukey-based identity authentication system is characterized in that The verification management module embeds a variety of cryptographic chips in the Ukey key. The cryptographic chips involve symmetric encryption algorithms, asymmetric encryption algorithms and hash algorithms. Symmetric encryption algorithms include DES, AES, and SM4, asymmetric encryption algorithms include RSA, ECC, and SM2, and hash algorithms include SHA and SM3.
6. According to claim 4, a Ukey-based identity authentication system is characterized in that The verification management module verifies the validity of the signature, specifically including: reading data according to the Ukey key, calling the onBatch_Login interface to obtain the signature, and after successful acquisition, calling the onBatch_GetUserList interface to log in with the certificate, obtain the certificate list, and calling the onBatch_ExportUserCert interface to export the certificate signature. After successful export, calling the onBatch_GetCertInfoByOid interface to obtain personal ID number information, and the signature verification process ends.
7. A Ukey-based identity authentication device, characterized by include: at least one memory and at least one processor; The at least one memory is used to store a machine-readable program; The at least one processor is used to call the machine-readable program to execute a Ukey-based identity authentication method as described in any one of claims 1 to 3.
8. A computer readable medium, characterized in that The computer-readable medium stores computer instructions, which, when executed by a processor, cause the processor to execute a Ukey-based identity authentication method as described in any one of claims 1 to 3.