Client identity authentication and evaluation method, device and program product
By crawling and verifying the random number challenge value and signature value during the client login process, the risk items in client identity authentication based on the "challenge-response" mechanism are detected, which solves the problem that attackers may use illegal random number challenge value to deceive and replay attacks, and improves the security of commercial password applications.
Patent Information
- Application Number
- CN202510482587.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
There are risks in client identity authentication based on the "challenge-response" mechanism, including that the attacker may deceive the server with random number challenge values from illegal sources, resulting in backdoor attacks, and the server does not verify the source of random number challenge values, which may lead to replay attacks.
By crawling the random number challenge value and signature value of interaction between the server and the client during the client login process, calling the password product for verification, and determining whether the client locally generates the random number challenge value and whether the server uses a fixed random number challenge value based on the crawled data.
The risk items in client identity authentication based on the "challenge-response" mechanism are detected to prevent attack tools from spoofing the server by generating or intercepting random number challenge values, improving the security of commercial password applications.
Smart Images

Figure CN119996094A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of commercial cryptographic application security assessment, and in particular to a client identity authentication and assessment method, device and program product. Background Art
[0002] In the work of commercial cryptographic application security assessment (referred to as "cryptographic assessment"), in terms of application and data security assessment, the most basic assessment work is client identity authentication. At present, the client identity authentication work adopts the "challenge-response" mechanism. The client identity authentication process based on the "challenge-response" mechanism generally includes the following steps: When logging in, the client sends a random number request to the server, and the server sends a random number request to a cryptographic product such as a signature verification server or a server cryptographic machine. After receiving the request from the server, the called cryptographic product sends a random number challenge value to the server; The server temporarily stores the random number challenge value and returns the random number challenge value to the client; The client calls the USB Key and uses the private key in the USB Key to sign the received random number to obtain the signature value; After the client obtains the signature value, it sends the random number challenge value, signature value and signature certificate to the server; The server calls the cryptographic product to verify the received random number challenge value. If the verification passes, the login is successful. If the verification fails, the login fails.
[0003] The above client identity authentication method based on the "challenge-response" mechanism has the following risks: In the signature verification phase, the random challenge value used by the server is only the data fed back by the client. As long as the signature certificate is legal and the signature value is the same as the random challenge value after being decrypted by the public key, the signature verification may pass. In some scenarios with the configured "challenge-response" mechanism, the source of the client's random challenge value is not verified during the server's signature verification phase. Attackers may deceive the server with random challenge values from illegal sources and then implant backdoors to launch attacks. However, the current client identity authentication assessment based on the "challenge-verification" mechanism cannot detect this risk; In addition, the server may not generate a new random number in response to each random number request. It may adopt a mechanism to periodically update the random number to respond to the client's random number request. That is, within a certain period of time, the random number sent by the server may be the same. If the authentication mechanism is exposed, the attacker can intercept the system message to obtain the random number challenge value, thereby launching a replay attack on the server. Summary of the invention
[0004] The purpose of the present invention is to provide a client identity authentication evaluation method, device and program product to detect at least one risk item in client identity authentication based on a "challenge-response" mechanism in order to address all or part of the above-mentioned problems.
[0005] The technical solution adopted by the present invention is as follows: A client identity authentication and evaluation method is applied to a commercial cryptographic application security evaluation scenario; the method comprises: During each client login process, capture the first random number challenge value generated by the server calling the password product ; Grab the second random number challenge value sent by the server to the client ; Capture the third random number challenge value sent by the client to the server , first signature value and the first signing certificate , the first signature value The third random number challenge value is the private key of the client Signature obtained.
[0006] Call the cryptographic product to use the third random number challenge value captured during the client login process at least once , first signature value and the first signing certificate Verify the client's identity; if the verification fails, the assessment fails.
[0007] At least based on the data captured by the client during a login process, determine whether the client generates the third random number challenge value locally ,If so, the evaluation fails; Also, based on the data captured by the client during at least two login processes, it is determined whether the server uses a fixed random number challenge value. If so, the evaluation fails.
[0008] In view of the above problems, the present application also provides a client identity authentication and evaluation device, which includes: The first module is used to capture the first random number challenge value generated by the server calling the password product during each client login process ; Grab the second random number challenge value sent by the server to the client ; Capture the third random number challenge value sent by the client to the server , first signature value and the first signing certificate , the first signature value The third random number challenge value is the private key of the client Signature obtained; The second module is used to call the third random number challenge value captured by the client login process using the password product at least once , first signature value and the first signing certificate Verify the client's identity; The third module is used to determine whether the client generates the third random number challenge value locally based on at least the data captured by the client during a login process. , and, determining whether the server adopts a fixed random number challenge value based on data captured by the client during at least two login processes; The fourth module is used to output the evaluation results; if the signature verification in the second module fails, the evaluation fails; if any judgment result in the third module is yes, the evaluation fails.
[0009] In addition, on another aspect, the present application also provides another client identity authentication and evaluation device, which includes a processor and a storage medium, wherein the storage medium stores computer instructions, and the processor runs the computer instructions to execute the above-mentioned client identity authentication and evaluation method.
[0010] In response to the above problem, the present application also provides a computer program product, including a computer program, which executes the above client identity authentication and evaluation method when executed by a processor.
[0011] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: This application retains the current process of client identity authentication based on the "challenge-verification" mechanism for evaluation, and also uses the data captured during the client login process (the first random number challenge value , Second random number challenge value , the third random number challenge value , first signature value and the first signing certificate ) to detect the third random number challenge value of the signature verification request Whether it is generated locally by the client, and whether the client uses a fixed random number challenge value, improves the comprehensiveness of the security assessment of commercial cryptographic applications. Detecting this risk item can prevent attack tools from deceiving the server by generating random number challenge values by themselves or intercepting legal identification data, thereby implanting a backdoor. In addition, the evaluation method for this risk item in this application is relatively simple, and it can be achieved using the data to be generated during the original evaluation, without the need to generate new data, and it will hardly increase the burden of the evaluation tool. In addition, due to the abuse of the "challenge-response" mechanism, the server may not verify the source of the received random number challenge value, but directly call the cryptographic product to verify its signature, so even if the client launches a "replay attack", the server may still pass the signature verification. This application also detects this risk item. In addition, this application also evaluates the risk of attacks by third parties, and can detect the risk item that a third party simulates the generation of a random number challenge value and encrypts it by itself to deceive the server. In general, this application can detect the risk item of the client generating a random number challenge value by itself, and effectively prevent the risk of "replay attack" and the risk of third-party attack. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The present invention will now be described by way of example with reference to the accompanying drawings, in which: Figure 1 It is a data flow diagram of the client identity authentication process based on the known "challenge-response" mechanism.
[0013] Figure 2 It is a flow chart of the client identity authentication and evaluation method provided in this application.
[0014] Figure 3 This is a data flow diagram of capturing data in one embodiment of the client identity authentication and evaluation method provided by the present application.
[0015] Figure 4 This is a data flow diagram of a client identity authentication and evaluation method provided by the present application in one implementation.
[0016] Figure 5 It is a data flow diagram of another implementation of the client identity authentication and evaluation method provided by the present application.
[0017] Figure 6 This is a flow chart of the client identity authentication and evaluation method provided in the embodiment of the present application for performing third-party attack evaluation.
[0018] Figure 7 It is a flow chart of the client identity authentication and evaluation method provided in the embodiment of the present application for performing a “replay attack” evaluation.
[0019] Figure 8 It is a structural diagram of the client identity authentication and evaluation device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0020] All features disclosed in this specification, or steps in all methods or processes disclosed, except mutually exclusive features and / or steps, can be combined in any manner.
[0021] Any feature disclosed in this specification (including any additional claims and abstract), unless otherwise stated, may be replaced by other alternative features that are equivalent or have similar purposes. That is, unless otherwise stated, each feature is only an example of a series of equivalent or similar features.
[0022] like Figure 1 The figure shows a data flow diagram of the client identity authentication process based on the known "challenge-response" mechanism. In this scenario, the server does not verify the random challenge value returned by the client, but directly calls the signature verification server and other cryptographic products for verification. For this scenario, the evaluation work is only to call the cryptographic product to verify the random challenge value returned by the client. It is impossible to detect the situation where the client generates a random challenge value for signing, and the situation where the server uses a fixed random challenge value. This leaves a large risk loophole in the effectiveness detection of cryptographic products.
[0023] In response to the problem that current evaluation work cannot detect whether the client generates random numbers for signing on its own, the present application provides a client identity authentication evaluation method, device and program product, which aims to detect the risk items in the client identity authentication link in scenarios where the "challenge-response" mechanism is abused or improperly deployed.
[0024] The client identity authentication evaluation method provided in this application is applied in the commercial cryptographic application security assessment scenario to detect risk items of client identity authentication, thereby improving the effectiveness of commercial cryptographic applications.
[0025] like Figure 2 As shown, the client identity authentication and evaluation method provided in the embodiment of the present application includes the following process: S1. During each login process of the client, the server calls the signature verification server (i.e., the password product, which is used in the following text to represent the password product) to generate the first random number challenge value. ; Grab the second random number challenge value sent by the server to the client ; Capture the third random number challenge value sent by the client to the server , first signature value and the first signing certificate Among them, the first signature value The third random number challenge value is the client's private key The client's private key is usually obtained from a USB Key, which is a product that has passed the commercial cryptographic product test. The USB Key stores the user's private key and signature certificate.
[0026] like Figure 3 As shown, each time the client logs in, it first sends a random number request to the server to obtain a random number challenge value for signing. After receiving the random number request, the server calls the signature verification server to generate a random number challenge value, and then grabs the random number challenge value as the first random number challenge value. The server obtains the random number challenge value from the signature verification server for temporary storage and sends it to the client. At this time, the sent random number challenge value is captured as the second random number challenge value. After the client receives the random number challenge value sent by the server, it retrieves the private key and signature certificate from the USB Key, signs the random number challenge value with the private key, obtains the signature value, and sends the random number challenge value, signature value, and signature certificate to the server. At this time, the random number challenge value, signature value, and signature certificate sent are captured as the third random number challenge value. , first signature value and the first signing certificate .
[0027] S2. Call the signature verification server to use the third random number challenge value captured during the client login process at least once , first signature value and the first signing certificate The client identity is verified; if the verification fails, the assessment fails. Failure of the assessment means that it does not comply with security regulations and there is a security risk.
[0028] As an optional implementation, during each login process of the client, the third random number challenge value captured during the login process is used , first signature value and the first signing certificate Verify the client's identity. That is, the server will send the third random number challenge value sent by the client every time it logs in. , first signature value and the first signing certificate The signature verification server is used to verify the signature. The signature verification server verifies the signature using the public key. Decrypted and then challenged with a third random number If the comparison is the same, the signature verification is passed, and the first signature certificate The server verifies the legitimacy of the signature certificate. If the verification is successful, the signature verification is successful. , first signature value and the first signing certificate The signature verification method is a conventional technology and will not be explained in depth here.
[0029] S3: Determine whether the client generates a third random number challenge value locally based on at least the data captured by the client during a login process. , if so, the evaluation fails.
[0030] In addition, step S3 may also include: judging whether the server uses a fixed random number challenge value based on data captured by the client during at least two login processes, and if so, the evaluation fails.
[0031] In the embodiment of the present application, only the first random number challenge value captured by the client during a login process may be used. , Second random number challenge value , the third random number challenge value , first signature value and the first signing certificate All or part of the data in the client is used to determine whether the client generates a third random number challenge value locally. It is also possible to use part or all of the above data captured by the client during each login process to determine whether the client generates a third random number challenge value locally. .
[0032] As an optional implementation, Figure 4 As shown, the third random number challenge value captured by the client during at least two login processes can be compared. The server uses the same random number challenge value to determine whether the server uses a fixed random number challenge value. If the comparison is the same, it means that the server uses a fixed random number challenge value to respond to the client's random number request.
[0033] The random challenge value generated by the signature verification server each time is random. For an ideal identity authentication process, each time the client requests a random number, the server requests the signature verification server to generate a different random challenge value. Under normal circumstances, the random challenge value returned by the client to the server is the random challenge value generated by the signature verification server, so it is also different. However, in some feasible identity authentication schemes, the server periodically calls the signature verification server to generate a random challenge value. During the period between two calls, the previously generated random challenge value is always used to respond to the client's random number request during this period. Since identity authentication is a black box mechanism, the public is unaware of its authentication procedures. Therefore, in terms of authentication effect, there is no difference from calling the signature verification server to generate a random challenge value for each random number request.
[0034] If the third random number challenge value sent to the server during the two logins of the client If the two random number challenges are equal, it can be determined that the random number challenge values used by the server in the two random number requests are the same, and thus it can be determined that the server uses a fixed random number challenge value. For the security of commercial cryptographic applications, this phenomenon is not allowed, otherwise criminals can obtain a legitimate random number challenge value and signature value through the previous access, and use the signature verification data obtained in the previous access to deceive the server, and take the opportunity to implant a backdoor and launch an attack on the server.
[0035] In the above method, the third random number challenge value captured during each two consecutive client logins may be compared. , or it can be a third random number challenge value captured during each consecutive multiple client logins In addition, it can also be compared with the third random number challenge value captured during non-adjacent logins. .
[0036] In another optional embodiment, as Figure 5 As shown, the first random number challenge value captured by the client during each login process can be compared , Second random number challenge value and the third random number challenge value Whether the third random number challenge value is generated locally by the client If the comparison is different, it means that the client has generated a third random number challenge value locally. .
[0037] As mentioned above, in theory, during each client login process, the random number challenge value exchanged between the server and the client is a unique random number challenge value generated by the signature verification server for the current random number request, so it should be the same everywhere during the login process. , Second random number challenge value and the third random number challenge value If there is a difference, it means that there is an abnormality in the random number challenge value in a certain link, or the second random number challenge value sent by the server is rewritten, either by the third random number challenge value uploaded by the client It is generated locally by the client. For the signature verification of the server, it represents the third random number challenge value uploaded by the client. If a rewrite occurs, it is considered that the client generates the third random number challenge value locally. .
[0038] The above detection work is mainly aimed at the client generating a third random number challenge value locally The signature is sent to the server for verification, and the private key used for the signature may still be legitimate.
[0039] In addition, the client may also try to log in to the server without the help of a legitimate private key, and directly use the random number challenge value generated by itself and sign it with its own private key, and then send the generated data together with the signature certificate to the server for verification. If the server passes the verification, it means that the identity authentication process does not comply with security regulations and there is a security risk.
[0040] As an optional implementation, Figure 6 As shown in the figure, the assessment process for the above risks includes: S4-1. During any client login process, use the first attack tool to generate a fourth random number challenge value , and use the private key of the first attack tool to challenge the fourth random number value Sign to get the second signature value .
[0041] Due to the limitations of the communication protocol between the client and the server, the four random number challenge values uploaded by the client to the server The data format must be consistent with the corresponding data format before it can be sent to the server. Considering this, in some optional implementations, the first attack tool generates a fourth random number challenge value The methods include: Use the first attack tool to record the third random number challenge value captured during any login process of the client ; Use the first attack tool to imitate the recorded third random number challenge value , to generate the fourth random number challenge value The data recorded by the first attack tool has been captured in the previous step S1, so there is no need to capture other data. The items simulated by the first attack tool can be the length and statistical rules of the random number challenge value, thereby ensuring the basic requirements such as the format of the random number challenge value.
[0042] S4-2, use the first attack tool to challenge the fourth random number , second signature value And the second signature certificate of the first attack tool Sent to the server so that the server can call the signature verification server using the fourth random number challenge value , second signature value And the second signing certificate Verify the client's identity. The second signature certificate here In some feasible implementations, the third random number challenge value may be recorded The first signature certificate recorded together The signature verification process is the same as above.
[0043] S4-3. Receive the signature verification result from the server. If the verification result indicates that the signature verification is successful, the evaluation fails. Evaluation failure indicates that there is a security risk.
[0044] In addition, the "challenge-response" mechanism is abused and the server does not receive the third random number challenge value. In the identity authentication process for verification, there is a risk of "replay attack". In some optional implementations of the present application, the evaluation work also includes the detection of the "replay attack" risk item.
[0045] As an optional implementation, Figure 7 As shown, the evaluation method of this application also includes: S5-1. Use the second attack tool to record the third random number challenge value captured by the client during any login process. , first signature value and the first signing certificate .
[0046] The data recorded in this step has also been captured in the previous step S1, so the second attack tool also does not need to capture additional data. The second attack tool is configured with an agent to support encryption algorithms, such as the national encryption algorithm.
[0047] S5-2, using the second attack tool to log in to the client and then , first signature value and the first signing certificate Resend to the server so that the server calls the cryptographic product using the third random number challenge value , first signature value and the first signing certificate Verify the client's identity.
[0048] S5-3. Receive the signature verification result from the server. If the verification result indicates that the verification is successful, the evaluation fails.
[0049] Theoretically, the first random number challenge value generated by the signature verification server when the client logs in twice Therefore, when the client logs in twice, the third random number challenge value uploaded to the server is different. It is also different, corresponding to the first signature value If the server does not design a protection mechanism against "replay attacks", the third random number challenge value of the previous login will be used when logging in later. , first signature value and the first signing certificate It is very likely that you can successfully log in to the server. Therefore, the evaluation method designed in this application can detect risk items with "replay attack" vulnerabilities.
[0050] Based on the design idea of this application, this application also provides a client identity authentication and evaluation device, such as Figure 8 As shown, the device comprises: The first module is used to capture the first random number challenge value generated by the server calling the password product during each client login process ; Grab the second random number challenge value sent by the server to the client ; Capture the third random number challenge value sent by the client to the server , first signature value and the first signing certificate . First signature value The third random number challenge value is the client's private key Signature obtained.
[0051] The second module is used to call the signature verification server to use at least the third random number challenge value captured by the client during a login process , first signature value and the first signing certificate Verify the client's identity.
[0052] The third module is used to at least capture the data captured by the client during a login process (the first random number challenge value , Second random number challenge value , the third random number challenge value , first signature value and the first signing certificate to determine whether the client generates the third random number challenge value locally. And, judging whether the server adopts a fixed random number challenge value based on the data captured by the client during at least two login processes.
[0053] The fourth module is used to output the evaluation results. If the signature verification in the second module fails, the evaluation fails. If any judgment result in the third module is yes, the evaluation fails.
[0054] As an optional implementation, the third module determines whether the server uses a fixed random number challenge value according to the following configuration: Compare the third random number challenge value captured by the client during at least two login processes Are they the same? If they are the same, it means that the server uses a fixed random number challenge value.
[0055] As an optional implementation, the third module determines whether the client generates a third random number challenge value locally according to the following configuration: : Compare the first random number challenge value captured by the client during each login process , Second random number challenge value and the third random number challenge value Are they the same? If not, it means that the client generates the third random number challenge value locally. .
[0056] The above two methods determine whether the client generates a third random number challenge value locally. The configuration methods can be used separately or simultaneously. Although the effects of the two are similar, they are not exactly the same and do not conflict.
[0057] In addition, the data configured in the first module, the second module and the third module in the client identity authentication and evaluation device provided in the embodiment of the present application can refer to the features introduced in steps S1, S2 and S3 in the client identity authentication and evaluation method in the previous embodiment.
[0058] In addition, as an optional implementation, the client identity authentication and evaluation device further includes a fifth module, which is used to generate a fourth random number challenge value using the first attack tool during any client login process. , and use the private key of the first attack tool to challenge the fourth random number value Sign to get the second signature value Use the first attack tool to challenge the fourth random number , second signature value And the second signature certificate of the first attack tool Sent to the server so that the server can call the signature verification server using the fourth random number challenge value , second signature value And the second signing certificate Verify the client's identity. Receive the verification result from the server. If the verification result indicates that the verification is successful, the assessment fails.
[0059] In some optional implementations, the fifth module connects to the first module to obtain the third random number challenge value captured by the first module during the client login process. , first signature value and the first signing certificate The fifth module then uses the first attack tool to imitate the recorded third random number challenge value. , to generate the fourth random number challenge value .
[0060] As an optional implementation, the client identity authentication and evaluation device further includes a sixth module, which is used to use the second attack tool to record the third random number challenge value captured by the client during any login process. , first signature value and the first signing certificate . Use the second attack tool to record the third random number challenge value during the client login process , first signature value and the first signing certificate Resend to the server so that the server can call the signature verification server using the third random number challenge value , first signature value and the first signing certificate Verify the client's identity. Receive the verification result from the server. If the verification result indicates that the verification is successful, the assessment fails.
[0061] In some feasible implementations, the sixth module connects to the first module to obtain the third random number challenge value captured by the first module during the client login process. , first signature value and the first signing certificate The sixth module then records the third random number challenge value , first signature value and the first signing certificate As replay parameters, write them into the corresponding position of the second attack tool, launch a replay attack by running the second attack tool, and send the replay parameters to the server for signature verification. The second attack tool needs to be configured with a proxy to support encryption algorithms, thereby imitating the function of normal client login.
[0062] In addition, the present application also provides another client identity authentication and evaluation device, which includes a processor and a storage medium, wherein the storage medium stores computer instructions, and the processor runs the computer instructions to execute the client identity authentication and evaluation method of the above embodiment.
[0063] The present application also provides a computer program product, including a computer program, which, when executed by a processor, executes the client identity authentication and evaluation method of the above embodiment.
[0064] The present invention is not limited to the above-mentioned specific embodiments, but extends to any new features or any new combination disclosed in this specification, as well as any new method or process steps or any new combination disclosed.
Claims
1. A client identity authentication and evaluation method, applied to the commercial cryptographic application security evaluation scenario; characterized in that: Methods include: During each client login process, capture the first random number challenge value generated by the server calling the password product ; Capture the second random number challenge value sent by the server to the client ; Capture the third random number challenge value sent by the client to the server , first signature value and the first signing certificate , the first signature value The third random number challenge value is the private key of the client Signature obtained; Call the cryptographic product to use the third random number challenge value captured during the client login process at least once , first signature value and the first signing certificate Verify the client's identity; if the verification fails, the assessment fails; At least based on the data captured by the client during a login process, determine whether the client generates the third random number challenge value locally ,If so, the evaluation fails; Also, based on the data captured by the client during at least two login processes, it is determined whether the server uses a fixed random number challenge value. If so, the evaluation fails.
2. The client identity authentication and evaluation method according to claim 1, characterized in that: The determining whether the server adopts a fixed random number challenge value based on data captured by the client during at least two login processes includes: Compare the third random number challenge value captured by the client during at least two login processes Are they the same? If they are the same, it means that the server uses a fixed random number challenge value.
3. The client identity authentication and evaluation method according to claim 1, characterized in that: The method of determining whether the client generates the third random number challenge value locally is based at least on the data captured by the client during a login process. ,include: Compare the first random number challenge value captured by the client during each login process , Second random number challenge value and the third random number challenge value Are they the same? If not, it means that the client generates the third random number challenge value locally. .
4. The client identity authentication and evaluation method according to claim 1, characterized in that: The calling of the cryptographic product uses the third random number challenge value captured during the client login process at least once , first signature value and the first signing certificate Verify the client identity, including: Call the password product to use the third random number challenge value captured by the client during each login process , first signature value and the first signing certificate Verify the client's identity.
5. The client identity authentication and evaluation method according to claim 1, characterized in that: Also includes: During any client login process, the fourth random number challenge value is generated using the first attack tool and use the private key of the first attack tool to challenge the fourth random number value Sign to get the second signature value ; Use the first attack tool to challenge the fourth random number , second signature value And the second signature certificate of the first attack tool Send to the server so that the server calls the cryptographic product using the fourth random number challenge value , second signature value And the second signing certificate Verify the client's identity; Receive the signature verification result from the server. If the verification result indicates that the verification is successful, the evaluation fails.
6. The client identity authentication and evaluation method according to claim 5, characterized in that: The fourth random number challenge value is generated by using the first attack tool ,include: Use the first attack tool to record the third random number challenge value captured during any login process of the client ; Use the first attack tool to imitate the recorded third random number challenge value , to generate the fourth random number challenge value .
7. The client identity authentication and evaluation method according to claim 1, characterized in that: Also includes: Use the second attack tool to record the third random number challenge value captured by the client during any login process , first signature value and the first signing certificate ; Use the second attack tool to log in to the client and then , first signature value and the first signing certificate Resend to the server so that the server calls the cryptographic product using the third random number challenge value , first signature value and the first signing certificate Verify the client's identity; Receive the signature verification result from the server. If the verification result indicates that the verification is successful, the evaluation fails.
8. A client identity authentication and evaluation device, characterized in that: include: The first module is used to capture the first random number challenge value generated by the server calling the password product during each client login process ; Capture the second random number challenge value sent by the server to the client ; Capture the third random number challenge value sent by the client to the server , first signature value and the first signing certificate , the first signature value The third random number challenge value is the private key of the client Signature obtained; The second module is used to call the password product to use at least the third random number challenge value captured by the client in a login process , first signature value and the first signing certificate Verify the client's identity; The third module is used to determine whether the client generates the third random number challenge value locally based on at least the data captured by the client during a login process. , and, judging whether the server uses a fixed random number challenge value based on the data captured by the client during at least two login processes, if so, the evaluation fails; The fourth module is used to output the evaluation results; if the signature verification in the second module fails, the evaluation fails; if any judgment result in the third module is yes, the evaluation fails.
9. A client identity authentication and evaluation device, comprising a processor and a storage medium, wherein the storage medium stores computer instructions, characterized in that: The processor runs the computer instructions to execute the client identity authentication and evaluation method as described in any one of claims 1-7.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by the processor, the client identity authentication and evaluation method as described in any one of claims 1 to 7 is executed.
Citation Information
Patent Citations
One-time password (OTP) based mobile terminal identity authentication method and system
CN102026195A
Identity authentication server and identity authentication token
CN108092776A
Identity authentication method, identity authentication equipment and readable storage medium
CN116866093A