Challenge code authentication method, device and system and storage medium
By combining timestamps and device identification in IT devices to generate challenge codes, and using TOTP algorithms and shared keys to generate response codes, the security risks of existing response code solutions are solved, and a higher intensity of secure encryption and convenient input methods are achieved.
Patent Information
- Application Number
- CN202510032190.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-23
AI Technical Summary
The existing response code schemes have security risks, such as the same response code may be reused between multiple IT devices, and the response code generated by self-developed codec algorithms is easily cracked.
The challenge code generated based on timestamps and device identification is used, and the response code is generated through the TOTP algorithm in combination with the shared key, and the shared key is transmitted through the public key encryption. Only the authorized platform can decrypt and obtain it.
The challenge code generated each time is not repeated, and the response code is fixed to six digits, which is convenient to input and not easy to be cracked, improving the security of the system background.
Smart Images

Figure CN120034311A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of identity authentication, and particularly to a challenge code authentication method, apparatus, system, and storage medium. Background Art
[0002] After an IT (Information Technology) device is sold to a customer, to ensure the stability of the IT device operation, the data and configuration of the IT device are managed through the system background. The system background functions are usually not open to customers. When problems occur with the IT device, maintenance personnel enter the system background to perform information collection, fault debugging, and other tasks. To protect the system background from unauthorized access, the identity of those entering the system background is authenticated through a challenge code.
[0003] This authentication process generally includes: when attempting to log in to the system background of the IT device, the system background generates a random challenge code (5 - 10 digits or English characters), displays it to the maintenance personnel, and prompts for the input of a response code; the maintenance personnel submit this challenge code to the device manufacturer, and the device manufacturer generates a response code (5 - 10 digits or English characters) based on this challenge code; the maintenance personnel input the response code into the system background, and if the verification passes, they can log in to the background.
[0004] Currently, some manufacturers adopt a general response code scheme based on a time period. For example, there is a unique response code every day, which can be used on all IT devices with normal clock settings. Some manufacturers develop their own encoding and decoding algorithms to generate corresponding response codes based on random challenge codes.
[0005] In the response code scheme based on a time period, the same response code may be reused among multiple IT devices, thus bringing security risks. In the self-developed encoding and decoding algorithms, since the challenge code and the response usually need to be manually entered, from the perspective of usability, the lengths of the challenge code and the response code are short (usually required to be no more than 10 visible characters). However, the length of the ciphertext generated by the general encryption algorithms proven to be secure in the industry exceeds this limit. And the encryption algorithms adjusted to reduce the length are not secure and are extremely easy to crack. After being cracked, all IT devices are no longer secure. Thus, it can be seen that the current response code scheme has insecure technical problems. Summary of the Invention
[0006] In the embodiments of this application, a challenge code authentication method, apparatus, system, and storage medium are provided to solve the insecure technical problems existing in the current response code scheme.
[0007] To achieve the above object, the embodiments of this application adopt the following technical solutions:
[0008] In a first aspect, an embodiment of the present application provides a challenge code authentication method, which is applied to an authorization platform, wherein the authorization platform stores a private key, and the method includes:
[0009] The authorization platform receives a challenge code generated by the system background. If the authorization platform stores a shared key, the challenge code is generated by the system background after receiving a login request based on the current timestamp of the electronic device and the device identification of the electronic device. The challenge code is transmitted to the authorization platform by the user; the authorization platform obtains the shared key based on the device identification in the challenge code. The shared key is randomly generated by the electronic device, and the key length of the shared key is not less than 160 bits.
[0010] The authorization platform generates a response code by combining the shared key and the timestamp through the TOTP algorithm. The response code is transmitted by the user to the system background for the system background to verify the challenge code and obtain a verification result.
[0011] In combination with the first aspect, in a possible design manner, when the authorization platform stores a shared key, before receiving a challenge code generated by a system background, the method further includes:
[0012] The authorization platform receives an encrypted file generated by the electronic device, where the encrypted file is obtained by the electronic device encrypting the shared key using a public key;
[0013] The authorization platform uses the private key to decrypt the encrypted file and obtain the shared key in the encrypted file;
[0014] The authorization platform establishes an association relationship between the acquired shared key and the device identification of the electronic device, and stores the association relationship in a database.
[0015] In combination with the first aspect, in a possible design manner, the method further includes:
[0016] When the authorization platform does not store the shared key, the challenge code is generated by the system background using the public key, encrypting the current timestamp of the electronic device and the shared key, and the challenge code is transmitted to the authorization platform by the user; the authorization platform uses the private key to decrypt the challenge code to obtain the shared key in the challenge code.
[0017] In combination with the first aspect, in a possible design, when the challenge code is generated by encrypting the current timestamp of the electronic device and the shared key using the public key of the system background,
[0018] The challenge code is displayed in the form of an automatic identification code, so that a code scanning device transmits the challenge code to the authorization platform after scanning the challenge code.
[0019] In conjunction with the first aspect, in a possible design manner, the receiving an encrypted file generated by the electronic device includes:
[0020] The authorization platform establishes a communication connection with the electronic device, and receives the encrypted file generated and transmitted by the electronic device when registering a contract with the electronic device; or
[0021] Receive an encrypted file generated by the electronic device during offline registration and transmitted by the user through a code scanning device.
[0022] In conjunction with the first aspect, in a possible design manner, the receiving an encrypted file generated by the electronic device includes:
[0023] Scanning the encrypted file in the form of an automatic identification code generated by the electronic device using a code scanning device;
[0024] The authorization platform receives the encrypted file transmitted after scanning by the code scanning device.
[0025] In combination with the first aspect, in a possible design manner, verifying the response code includes:
[0026] The system background generates a verification result by combining the shared key stored in the system background, the current timestamp of the electronic device and the received response code.
[0027] In a second aspect, an embodiment of the present application provides a challenge code authentication device, the device stores a private key, and the device includes:
[0028] A challenge code receiving module, used to receive a challenge code generated by the system background. When the authorization platform stores a shared key, the challenge code is generated by the system background after receiving the login request based on the current timestamp of the electronic device and the device identification of the electronic device. The challenge code is transmitted to the authorization platform by the user;
[0029] A shared key acquisition module, used to acquire the shared key based on the device identification in the challenge code, wherein the shared key is randomly generated by the electronic device, and the key length of the shared key is not less than 160 bits;
[0030] A response code generation module is used to generate a response code by combining the shared key and the timestamp through the TOTP algorithm. The response code is transmitted by the user to the system background, and the system background verifies the challenge code to obtain a verification result.
[0031] In a third aspect, the present application embodiment provides a challenge code authentication system, 9. including a system background and an authorization platform for managing data and configuration of electronic devices,
[0032] The system backend is configured to generate a challenge code based on the current timestamp of the electronic device and the device identification of the electronic device after receiving a login request when the shared key is stored in the authorization platform, and the challenge code is transmitted by the user to the authorization platform;
[0033] The authorization platform is configured to store a private key, receive a challenge code generated by a system background, obtain a shared key based on the challenge code, the shared key is randomly generated by the electronic device, and the key length of the shared key is not less than 160 bits; generate a response code by combining the shared key and the timestamp through a TOTP algorithm, and the response code is transmitted by the user to the system background;
[0034] The system backend is also configured to verify the response code to obtain a verification result.
[0035] In a fourth aspect, an embodiment of the present application provides a storage medium, in which a computer program is stored, wherein the computer program is configured to execute the method of the first aspect and its possible design manner when running.
[0036] In a fifth aspect, an embodiment of the present application provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the method of the first aspect and possible design methods thereof.
[0037] Compared with the prior art, the challenge code authentication method, device, system and storage medium provided in the embodiment of the present application are combined with the timestamp and the device identification of the electronic device to generate the challenge code, so that the challenge code generated each time will not be repeated, and the challenge code can only be valid within a certain period, and the challenge code has one-time validity and device uniqueness, so that the background system can be prevented from being attacked by replay. In addition, a response code based on a timestamp and a shared key is generated by the TOTP algorithm, and the response code is fixed to six digits, which is convenient to input. Although the length of the response code is very short, because the response code contains a shared key, the shared key is very long and the shared key is only shared between the device side and the manufacturer side, and the transmission of the shared key is encrypted by the public key, and only the authorized platform can obtain it by decrypting the private key, so it is very good to avoid the shared key from being attacked, so the response code obtained by encryption in combination with the shared key meets the high-intensity security encryption and is not easy to be cracked; and because the response code generated by the TOTP algorithm is fixed to six characters, it can reduce the number of characters entered manually and improve the accuracy of manual input. Therefore, the method provided by the embodiment of the present application solves the technical problem of insecurity in the current response code solution. Using the challenge code and response code generated by the embodiment of the present application to perform login authentication on the backend system can provide more secure protection for the backend system.
[0038] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0040] Figure 1 A schematic diagram of a challenge code authentication system provided in an embodiment of the present application is shown;
[0041] Figure 2 A flowchart of a challenge code authentication method provided in an embodiment of the present application is shown;
[0042] Figure 3 A flowchart of another challenge code authentication method provided in an embodiment of the present application is shown;
[0043] Figure 4 A structural block diagram of a challenge code authentication device provided in an embodiment of the present application is shown;
[0044] Figure 5 A hardware structure block diagram of a computer device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0045] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0046] Unless otherwise defined, the technical terms or scientific terms involved in this application shall have the general meaning understood by people with ordinary skills in the technical field to which this application belongs. The words "one", "a", "a", "the", "these" and the like in this application do not represent quantitative restrictions, and they can be singular or plural. The terms "include", "comprise", "have" and any variants thereof involved in this application are intended to cover non-exclusive inclusions; for example, a process, method and system, product or device comprising a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent to these processes, methods, products or devices. The words "connect", "connected", "coupled" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether directly or indirectly. The "multiple" involved in this application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, "A and / or B" can mean: A exists alone, A and B exist at the same time, and B exists alone. Usually, the character " / " indicates that the objects associated with each other are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific ordering of the objects.
[0047] Before describing the method provided in the embodiments of the present application, the technical terms that may be involved are first explained.
[0048] Challenge is a widely used mechanism in computer security, mainly used for identity authentication and preventing replay attacks. Its core idea is to generate a random number or string (i.e., challenge code) and require the user or device to respond to it to verify its identity.
[0049] A QR code is a special two-dimensional barcode that records data on a plane through a combination of black and white squares for machine reading. The design of a QR code enables it to be read in two directions, and compared to traditional one-dimensional barcodes, a QR code can store more information.
[0050] TOTP (Time-based One-Time Password) is a dynamic password generation algorithm widely used in two-factor authentication (2FA). It generates a dynamic verification code by combining a shared key and the current time to improve security.
[0051] Asymmetric encryption algorithm is a technology that uses a pair of keys (public key and private key) to encrypt and decrypt data. Its basic principle is: data encrypted with a public key can only be decrypted with a private key; and data encrypted with a private key can only be decrypted with a public key. Because there is a specific mathematical relationship between the two keys, data encrypted with a public (private) key can only be decrypted by the corresponding private (public) key, thereby enhancing data security. Asymmetric encryption algorithms include RSA, ECC, and SM2.
[0052] The method provided in the embodiments of the present application is described below.
[0053] From a security perspective, the challenge code and response code need to meet the following requirements:
[0054] 1. Randomness and validity within a certain time range: The challenge code generated each time will not be repeated; the response code corresponding to the challenge code needs to be valid within a certain period of time, and it will automatically become invalid after expiration.
[0055] 2. One-time validity and device uniqueness: The response code can only be used successfully once; and cannot be mixed between different devices.
[0056] 3. The length of the challenge code and response code should be short, because too long codes will increase the complexity of input and reduce the accuracy of manual input.
[0057] Therefore, the embodiment of the present application provides a challenge code authentication method, which combines the timestamp and the device identification of the electronic device to generate the challenge code, so that the challenge code generated each time will not be repeated, and the challenge code can only be valid within a certain period, and the challenge code has one-time validity and device uniqueness, so that the background system can be prevented from being attacked by replay. In addition, a response code based on a timestamp and a shared key is generated by the TOTP algorithm, and the response code is fixed to six digits, which is convenient to input. Although the length of the response code is very short, since the response code contains a shared key, the shared key is very long and the shared key is only shared between the device side and the manufacturer side, and the transmission of the shared key is encrypted by the public key, and only the authorized platform can obtain it by decrypting the private key, so it is very good to avoid the shared key from being attacked, so the response code obtained by encrypting the shared key meets the high-intensity security encryption and is not easy to be cracked; and because the response code generated by the TOTP algorithm is fixed to six characters, it can reduce the number of characters entered manually and improve the accuracy of manual input. Therefore, the method provided by the embodiment of the present application solves the unsafe technical problems existing in the current response code scheme, and the challenge code and the response code generated by the embodiment of the present application are used to log in and authenticate the background system, which can play a more secure protection role for the background system.
[0058] The method can be performed in a challenge code authentication system. Figure 1 A schematic diagram of a challenge code authentication system provided in an embodiment of the present application is shown. Figure 1 As shown, the challenge code authentication system includes a system background 101 on the device side, an authorization platform 102 on the manufacturer side, and a code scanning device 103 with a code scanning function. The system background 101 generates a challenge code based on the current IT device running time combined with the device identification. The authorization platform 102 generates a TOTP login password (equivalent to a response code) based on the challenge code and the shared key corresponding to the IT device. The TOTP login password is entered in the system background 101, and you can log in to the system background after verification. The code scanning device 103 is configured to scan the code and extract the information therein and transmit it to the authorization platform 102. For example, when the IT device is not authorized or the authorization process cannot transmit the shared key to the manufacturer, the code scanning device 103 can scan it in the form of a QR code and send it to the authorization platform 102 on the manufacturer side; for another example, when the system background 101 displays the challenge code in the form of a QR code, the code scanning device 103 can scan it in the form of a QR code and send it to the authorization platform 102 on the manufacturer side.
[0059] The embodiments of the present application can be applied to identity authentication scenarios, not only to the identity authentication of maintenance personnel in the system background of IT equipment, but also to the identity authentication between any multiple devices, platforms, servers, and websites. The response code obtained by using the embodiments of the present application is shorter and cannot be cracked by people who do not have the private key, so it has high security.
[0060] Figure 2 A flowchart of a challenge code authentication method provided in an embodiment of the present application is shown. Figure 2 As shown, the method includes steps S201 to S208. In this embodiment, the authorization platform stores a shared key in advance before receiving the challenge code, so the challenge code is generated based on the device identification and the current timestamp.
[0061] Step S201: The electronic device uses a public key to encrypt a randomly generated shared key to generate an encrypted file.
[0062] When electronic devices (equivalent to the IT equipment mentioned above) leave the factory, the manufacturer presets a key pair of asymmetric encryption algorithm, which is used to encrypt and decrypt data when exchanging information with the manufacturer. Before using the challenge code, the electronic device needs to generate a shared key, encrypt the shared key with the public key and pass it to the manufacturer. Sharing means sharing between the device side and the manufacturer side, and the shared key is encrypted and transmitted. Therefore, except for the manufacturer side that has the private key, other devices cannot obtain the shared key.
[0063] As an example, during the electronic device license authorization registration process, the electronic device executes step S201. Specifically, the electronic device license is a contractual form of authorization between a supplier and a customer regarding the scope of use, functions, and duration of a product. During this process, the electronic device communicates with the manufacturer to transmit encrypted files.
[0064] In this step, the electronic device can generate a shared key through a random number to ensure that the shared key generated by each electronic device is different. Alternatively, the electronic device scans the user's fingerprint and encrypts the user's fingerprint through a hash function to generate a shared key. It is understandable that the length of the shared key is greater than 6 bits of the challenge code, which can achieve a safer effect than the original challenge code authentication method. However, for security reasons, the key length of the shared key is long, such as greater than 160 bits (bit) or 20 bytes. As an example, the shared key has 256 bits.
[0065] As another example, the electronic device generates a shared key at any time, and after encrypting the shared key, generates an automatic identification code containing the encrypted file, which is scanned and sent to the manufacturer side by means of an automatic identification code. Among them, the automatic identification code (Automatic Identification and Data Capture, AIDC) refers to a code that can be read by automated equipment, including barcodes, QR codes, RFID (Radio Frequency Identification, radio frequency identification), etc. The scanning device can be a mobile phone. The shared key is very long, at least 160 bits as mentioned above, and it is difficult to input manually. The problem of transmission difficulty is solved by scanning the code to transmit the shared key.
[0066] Step S202: The electronic device sends the encrypted file to the authorization platform.
[0067] The authorization platform is deployed on the manufacturer side. This step corresponds to the electronic device mentioned above being able to establish communication with the manufacturer side and transmit encrypted files. It should be noted that in addition to sending encrypted files to the manufacturer side during the electronic device license authorization registration process, the electronic device can also send encrypted files at any time when establishing communication with the manufacturer side, such as when filling out a repair form for the electronic device, sending encrypted files when the electronic device receives an authorization authentication request, etc.
[0068] Step S203: The authorization platform decrypts the encrypted file using the private key to obtain a shared key.
[0069] It can be understood that this step uses asymmetric encryption algorithm technology to protect the security of shared key transmission. After the shared key is encrypted by the public key, the public key will be released with the electronic device, while the private key will be kept by the manufacturer. The authorization platform will decrypt the encrypted file based on the kept private key, enter and retain the shared key corresponding to the electronic device. Exemplarily, the authorization platform will establish an association relationship between the obtained shared key and the device identification of the electronic device and store it in the database.
[0070] Step S204: When receiving a login request, the system background generates a challenge code based on the current timestamp of the electronic device and the device identification of the electronic device.
[0071] The system background is deployed on the device side and is configured to verify the identity of the access object (such as maintenance personnel). The verification is successful if the access object is authorized by the manufacturer. Therefore, if the verification is successful, it is safe for the system background to accept control to manage the data and configuration of the electronic device.
[0072] The system background combines TOTP technology to generate a challenge code based on the timestamp and device identification. TOTP technology combines the device identification so that the challenge code generated for each electronic device will not be repeated, and combines the timestamp so that the challenge code is only valid within a certain period. Then the challenge code has one-time validity and device uniqueness, which can prevent the background system from being attacked by replay.
[0073] In some of the embodiments, the authorization platform pre-stores the device identification and shared key. When a login request is received, a challenge code can be generated based on the electronic device based on the TOTP algorithm combined with the device identification and timestamp. Unlike traditional static passwords, the challenge code is temporary and expires at regular intervals (for example, 30 seconds or 60 seconds), thereby enhancing security.
[0074] If the electronic device keeps the clock synchronized with the Internet, the timestamp does not need to be stored in the challenge code. The core idea of TOTP is to generate a short-term verification code based on the current timestamp, so that each password has a limited validity period (usually 30 seconds or 60 seconds), and then automatically expires, ensuring the timeliness of the verification code and synchronization with the standard time. If you are not sure whether the electronic device keeps the clock synchronized with the Internet, you can store the timestamp in the challenge code every time. Exemplarily, the electronic device is a factory device. When the usage time reaches a certain value, the clock of the electronic device is no longer synchronized with the standard time, so the challenge code authentication method for the electronic device can adopt the method of storing the timestamp in the challenge code.
[0075] Step S205: The authorization platform receives the challenge code.
[0076] As an example, the authorization platform provides an input port to receive a challenge code input by a maintenance person. If the challenge code is six characters, the maintenance person inputs the challenge code into the authorization platform, and the authorization platform obtains the challenge code.
[0077] As another example, the challenge code is displayed in the system background as an automatic identification code. The maintenance personnel scans the automatic identification code and transmits it to the authorization platform, so that the authorization platform identifies the automatic identification code and obtains the challenge code.
[0078] S206. The authorization platform combines the timestamp obtained based on the challenge code with the shared key through the TOTP algorithm to generate a response code corresponding to the challenge code.
[0079] In this embodiment, the challenge code includes a timestamp and a device identifier, so in this step, the authorization platform first obtains the timestamp and device identifier in the challenge code, and then queries the shared key corresponding to the device identifier from the database. Then, a response code corresponding to the challenge code is generated based on the acquired timestamp and device identifier. After that, the authorization platform displays the response code, and the maintenance personnel enters the response code into the system background for verification. Among them, the response code can be directly displayed on the interface, or converted into an automatic identification code so that the maintenance personnel can read it through a code scanning device and send it to the system background. For the relevant TOTP algorithm, refer to the RFC6238 algorithm.
[0080] S207: The system background receives a response code.
[0081] The system backend provides an entry for inputting the response code. The maintenance personnel can input the response code into the system backend, and the authorization platform will obtain the response code. The maintenance personnel can also use a code scanning device to send the read automatic identification code to the system backend, so that the system backend can identify the automatic identification code and obtain the response code.
[0082] S208. The system background verifies the response code and obtains a verification result.
[0083] The system backend and the authorization platform agree on a method for encoding the response code or challenge code. For example, if they agree to encrypt it using the TOTP algorithm, the system backend can encrypt the timestamp and shared key using the TOTP algorithm, and compare the encrypted result with the response code to obtain the verification result.
[0084] Specifically, the method includes: the input of the system background includes the shared key stored in the system background, the timestamp of the electronic device and the received response code, and the output is the verification result. The system background combines the shared key and the timestamp through the TOTP algorithm to generate a verification code, and verifies the response code through the comparison result between the verification code and the response code.
[0085] The response code of the authorization platform is generated based on a shared key and a timestamp, where the shared key is shared by the authorization platform and the system background. Other devices cannot obtain the shared key, so the response code generated by other devices cannot pass the verification. When the verification code is consistent with the response code, the verification result is passed, then the maintenance personnel can enter the system background to manage the data and configuration of the electronic equipment. It can be understood that the verification here refers to whether the access object is authorized by the manufacturer. Passing the verification means that the access object is authorized by the manufacturer, and not providing the verification means that the access object is not authorized by the manufacturer. In other words, if the system background receives an abnormal response code sent by other untrusted devices, it will also verify it. If the verification result is failed, then the person cannot enter the system background, that is, the existence of the shared key prevents attackers from forging response codes and entering the device system background.
[0086] In the embodiments provided by the above steps S201 to S208, only the authorization platform has a private key, and the authorization platform and the system backend both store a shared key. When the authorization platform obtains the challenge code generated by the system backend, the authorization platform generates a response code using the shared key and the timestamp in the challenge code. The system backend verifies the response code to obtain a verification result. In other embodiments, the authorization platform can also verify with the system backend without storing the shared key, as described below.
[0087] Figure 3 The flowchart of another challenge code authentication method provided by an embodiment of the present application is shown. In this embodiment, the authorization platform does not store the shared key before receiving the challenge code, so the challenge code is generated based on the shared key and the current timestamp. Figure 3 As shown, perform the following steps:
[0088] Step S301: When a login request is received, the system background uses a public key to encrypt the current timestamp of the electronic device and the shared key to generate a challenge code.
[0089] Step S205: The authorization platform receives the challenge code.
[0090] Step S302: The authorization platform uses the private key to decrypt the challenge code to obtain the timestamp and shared key in the challenge code.
[0091] Step S303: The authorization platform combines the timestamp and the shared key in the challenge code through the TOTP algorithm to generate a response code corresponding to the challenge code.
[0092] Step S207: The system background receives a response code.
[0093] Step S208: The system background verifies the response code and obtains a verification result.
[0094] In this embodiment, the system background does not send the device identification, but directly sends the shared key. Therefore, the authorization platform does not need to store the shared key in advance, nor does it need to query the shared key corresponding to the device identification, so the response speed is fast.
[0095] It is worth mentioning that when the challenge code does not contain the shared key, the challenge code is short, so the challenge code can be entered into the authorization platform manually. When the challenge code contains the shared key, the challenge code is long, so the challenge code is displayed in the form of an automatic identification code, so that the scanning device can scan the challenge code and transmit it to the authorization platform.
[0096] It should be noted that the transmission of the shared key in the embodiment of the present application is achieved through public key encryption and private key decryption. The purpose is to ensure that only the manufacturer with the private key can obtain the shared key. Since the length of the shared key is very long, the response code generated based on the shared key is not easy to be forged or cracked even if it is short, thereby protecting the security of access to the system background.
[0097] The embodiment of the present application also provides a challenge code authentication device, which stores a private key. Figure 4 A structural block diagram of a challenge code authentication device provided in an embodiment of the present application is shown. Figure 4 As shown, the device comprises:
[0098] The challenge code receiving module 41 is used to receive the challenge code generated by the system background. When the authorization platform stores a shared key, the challenge code is generated by the system background after receiving the login request based on the current timestamp of the electronic device and the device identification of the electronic device. The challenge code is transmitted to the authorization platform by the user.
[0099] A shared key acquisition module 42, used to obtain a shared key from the device identification in the challenge code, where the shared key is randomly generated by the electronic device and has a key length of no less than 160 bits;
[0100] A response code generation module 43 is configured to generate a response code by combining a shared key and a timestamp through the TOTP algorithm. The response code is transmitted by the user to the system background for the system background to verify the challenge code and obtain a verification result.
[0101] In some embodiments, the challenge code receiving module 41 is further configured to establish a communication connection with an electronic device and receive an encrypted file generated and transmitted by the electronic device during contract registration with the electronic device; or in the case where the electronic device performs offline registration, receive an encrypted file generated by the electronic device during offline registration and transmitted by the user through a scanning device.
[0102] In some embodiments, the challenge code receiving module 41 is further configured to scan an encrypted file in the form of an automatic identification code generated by the electronic device through a scanning device; and receive the encrypted file transmitted after the scanning device scans.
[0103] In some embodiments, the shared key acquisition module 42 is further configured to decrypt the challenge code to obtain a device identifier in the challenge code; and query a shared key corresponding to the device identifier from a database.
[0104] In some embodiments, the shared key acquisition module 42 is further configured to decrypt the challenge code using a private key to obtain the shared key in the challenge code.
[0105] In this embodiment, a computer device is further provided. Figure 5 The hardware structure block diagram of a computer device provided by an embodiment of the present application is shown. As Figure 5 shown, the computer device may include one or more ( Figure 5 only one is shown in the figure) processors 502 and a memory 504 for storing data. The processor 502 may include, but is not limited to, a processing device such as a microprocessor MCU or a field programmable gate array FPGA. The above computer device may further include a transmission device 506 for communication functions and an input / output device 508. Those of ordinary skill in the art can understand that Figure 5 the structure shown is only schematic and does not limit the structure of the above computer device. For example, the computer device may further include more or fewer components than Figure 5 shown in the figure, or have a different configuration from Figure 5 shown in the figure.
[0106] The memory 504 can be used to store computer programs, for example, software programs and modules of application software. The processor 502 executes various functional applications and data processing by running the computer programs stored in the memory 504, that is, to implement the above method. The memory 504 can be used to store data, such as key pairs, shared keys, etc. The memory 504 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 504 may further include a memory remotely arranged relative to the processor 502, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0107] The transmission device 506 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer device. In one example, the transmission device 506 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 506 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0108] Optionally, in this embodiment, the processor may be configured to execute the following steps S1 to S3 through a computer program.
[0109] S1. Receive the challenge code generated by the system background. When the authorization platform stores the shared key, the challenge code is generated by the system background after receiving the login request based on the current timestamp of the electronic device and the device identification of the electronic device. The challenge code is transmitted by the user to the authorization platform.
[0110] S2. Obtain a shared key based on the device identification in the challenge code. The shared key is randomly generated by the electronic device, and the key length of the shared key is not less than 160 bits.
[0111] S3. A response code is generated by combining the shared key and timestamp through the TOTP algorithm. The response code is transmitted by the user to the system background, which is used by the system background to verify the challenge code and obtain the verification result.
[0112] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation modes, and will not be repeated in this embodiment.
[0113] In addition, in combination with the method provided in the above embodiment, a storage medium may be provided in this embodiment to implement the method. The storage medium stores a computer program; when the computer program is executed by a processor, any challenge code authentication method in the above embodiment is implemented.
[0114] The embodiment of the present application also provides a computer program product. When the computer program product is run on a computer, the computer executes each function or step executed by the processor in the above method embodiment.
[0115] It should be understood that the specific embodiments described herein are only used to explain the application, rather than to limit it. Based on the embodiments provided in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the protection scope of this application.
[0116] Obviously, the drawings are only some examples or embodiments of the present application. For ordinary technicians in the field, the present application can also be applied to other similar situations based on these drawings without creative work. In addition, it is understandable that although the work done in this development process may be complicated and lengthy, for ordinary technicians in the field, certain changes in design, manufacturing or production based on the technical content disclosed in this application are only conventional technical means and should not be regarded as insufficient content disclosed in this application.
[0117] The term "embodiment" in this application refers to a specific feature, structure or characteristic described in conjunction with the embodiment that can be included in at least one embodiment of the present application. The appearance of this phrase in various locations in the specification does not necessarily mean the same embodiment, nor does it mean that it is mutually exclusive with other embodiments and is independent or optional. It is clearly or implicitly understood by those of ordinary skill in the art that the embodiments described in this application can be combined with other embodiments without conflict.
[0118] The above embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of patent protection. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the attached claims.
Claims
1. A challenge code authentication method, characterized in that: Applied to an authorization platform, the authorization platform stores a private key, the method comprises: The authorization platform receives a challenge code generated by the system background. If the authorization platform stores a shared key, the challenge code is generated by the system background after receiving a login request based on the current timestamp of the electronic device and the device identification of the electronic device. The challenge code is transmitted to the authorization platform by the user; the authorization platform obtains the shared key based on the device identification in the challenge code. The shared key is randomly generated by the electronic device, and the key length of the shared key is not less than 160 bits. The authorization platform generates a response code by combining the shared key and the timestamp through the TOTP algorithm. The response code is transmitted by the user to the system background for the system background to verify the challenge code and obtain a verification result.
2. The challenge code authentication method according to claim 1, characterized in that: In the case where the authorization platform stores a shared key, before receiving the challenge code generated by the system background, the method further includes: The authorization platform receives an encrypted file generated by the electronic device, where the encrypted file is obtained by the electronic device encrypting the shared key using a public key; The authorization platform uses the private key to decrypt the encrypted file and obtain the shared key in the encrypted file; The authorization platform establishes an association relationship between the acquired shared key and the device identification of the electronic device, and stores the association relationship in a database.
3. The challenge code authentication method according to claim 1, characterized in that: The method further comprises: When the authorization platform does not store the shared key, the challenge code is generated by the system background using the public key, encrypting the current timestamp of the electronic device and the shared key, and the challenge code is transmitted to the authorization platform by the user; the authorization platform uses the private key to decrypt the challenge code to obtain the shared key in the challenge code.
4. The challenge code authentication method according to claim 3, characterized in that: In the case where the challenge code is generated by encrypting the current timestamp of the electronic device and the shared key using the public key of the system background, The challenge code is displayed in the form of an automatic identification code, so that a code scanning device transmits the challenge code to the authorization platform after scanning the challenge code.
5. The challenge code authentication method according to claim 2, characterized in that: The receiving the encrypted file generated by the electronic device comprises: The authorization platform establishes a communication connection with the electronic device, and receives the encrypted file generated and transmitted by the electronic device when registering a contract with the electronic device; or Receive an encrypted file generated by the electronic device during offline registration and transmitted by the user through a code scanning device.
6. The challenge code authentication method according to claim 2, characterized in that: The receiving the encrypted file generated by the electronic device comprises: Scanning the encrypted file in the form of an automatic identification code generated by the electronic device using a code scanning device; The authorization platform receives the encrypted file transmitted after scanning by the code scanning device.
7. The challenge code authentication method according to claim 1, characterized in that: The verifying the response code includes: The system background generates a verification result by combining the shared key stored in the system background, the current timestamp of the electronic device and the received response code.
8. A challenge code authentication device, characterized in that: The device stores a private key, and includes: A challenge code receiving module, used to receive a challenge code generated by the system background. When the authorization platform stores a shared key, the challenge code is generated by the system background after receiving the login request based on the current timestamp of the electronic device and the device identification of the electronic device. The challenge code is transmitted to the authorization platform by the user; A shared key acquisition module, used to acquire the shared key based on the device identification in the challenge code, wherein the shared key is randomly generated by the electronic device, and the key length of the shared key is not less than 160 bits; A response code generation module is used to generate a response code by combining the shared key and the timestamp through the TOTP algorithm. The response code is transmitted by the user to the system background, and the system background verifies the challenge code to obtain a verification result.
9. A challenge code authentication system, characterized in that: Including the system background and authorization platform for managing the data and configuration of electronic devices, The system backend is configured to generate a challenge code based on the current timestamp of the electronic device and the device identification of the electronic device after receiving a login request when the shared key is stored in the authorization platform, and the challenge code is transmitted by the user to the authorization platform; The authorization platform is configured to store a private key, receive a challenge code generated by a system background, obtain a shared key based on the challenge code, the shared key is randomly generated by the electronic device, and the key length of the shared key is not less than 160 bits; generate a response code by combining the shared key and the timestamp through a TOTP algorithm, and the response code is transmitted by the user to the system background; The system backend is also configured to verify the response code to obtain a verification result.
10. A storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program is configured to execute the challenge code authentication method according to any one of claims 1 to 7 when running.
Citation Information
Cited By
Equipment authentication method and device, storage medium and electronic equipment
CN120509025A