Identity authentication method and apparatus, and electronic device
By using private key shards to decrypt dynamic passwords on the server and client, the complex and high cost of identity authentication in the prior art is solved, and a simplified identity authentication process and improved efficiency are achieved, while ensuring the security of the key.
Patent Information
- Application Number
- CN202311594746.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
The prior art relies on digital certificates and smart password keys in the identification of information systems, resulting in the complex and high cost of identity authentication, and requires a lot of integration and transformation work, which is inefficient.
By decrypting the password ciphertext of the dynamic password using the first private key shard on the server, the intermediate ciphertext is obtained and sent to the client. The client uses the second private key shard to obtain the dynamic password, thereby performing identity authentication.
The identity authentication process is simplified, the difficulty and cost of identity authentication is reduced, the efficiency is improved, and the security of the key is ensured through key segmentation, avoiding the risk of private key leakage.
Smart Images

Figure CN120050051A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular, to a method, device, and electronic device for identity authentication. Background Art
[0002] With the advancement of national cryptography applications, many information systems, such as government affairs information systems, have further improved the security requirements for networks and information. Currently, the security assessment of the passwords of information systems mainly focuses on identity authentication.
[0003] Currently, digital certificates and smart cryptographic keys (USBKeys) under the PKI (Public Key Infrastructure) / CA (Certificate Authority) system are generally used for identity authentication. This poses complex and difficult challenges to the transformation of application systems and the integrated settings of user terminals. Although there has emerged a method of using a mobile password module on the mobile side with mobile integers, by avoiding the inconvenience brought by carrying USBKeys, to simplify identity authentication. However, since digital certificates still need to be used, it is necessary to integrate a mobile terminal password module on the mobile phone terminal in cooperation with the signature system and configure a mobile digital certificate. The integration and transformation work involved includes: integrating the collaborative signature client SDK to implement mobile key management and digital signature functions; integrating the certificate management interface of the digital certificate authentication system for operations such as downloading, updating, and invalidating certificates... It can be seen that the current method of identity authentication still needs to be simplified to avoid problems such as low authentication efficiency and high costs brought by relevant integration work. Summary of the Invention
[0004] This application provides a method, device, and electronic device for identity authentication, which simplifies the identity authentication method by avoiding the use of digital certificates and thus avoiding related integration and transformation work, thereby reducing the difficulty of identity authentication and improving the efficiency of identity authentication while ensuring password security.
[0005] In a first aspect, an embodiment of this application provides a method for identity authentication, which is applied to a server, and the method includes:
[0006] Determine a password ciphertext; wherein, the password ciphertext includes a dynamic password;
[0007] Based on a first private key shard, decrypt the password ciphertext to obtain an intermediate ciphertext;
[0008] Send the intermediate ciphertext to the client;
[0009] Receive an identity authentication request and authenticate the client that sent the identity authentication request; wherein, the identity authentication request includes the dynamic password, and the dynamic password is obtained by the client based on the intermediate ciphertext.
[0010] In a possible implementation, the password ciphertext is obtained by encrypting the dynamic password with a public key, and the public key is obtained according to the server intermediate value corresponding to the first private key shard and the client intermediate value corresponding to the second private key shard.
[0011] In a possible implementation, determining the password ciphertext includes:
[0012] Generate a dynamic password;
[0013] Encrypt the dynamic password with the public key to obtain the password ciphertext; wherein, the dynamic password corresponds to the client.
[0014] In a possible implementation, the public key is obtained by the following method:
[0015] Receive the client intermediate value and determine the server intermediate value based on the first private key shard;
[0016] Determine the public key based on the client intermediate value and the server intermediate value.
[0017] In a possible implementation, before determining the password ciphertext, it further includes:
[0018] Determine the intermediate signature;
[0019] Send the intermediate signature to the client so that the client determines the target signature based on the intermediate signature;
[0020] Receive the target signature;
[0021] In response to the target signature being verified successfully, determine to generate a dynamic password.
[0022] In a possible implementation, determining the intermediate signature includes:
[0023] Generate a first random number;
[0024] Send the first random number to enable the client to determine a signature request based on the first random number and the second private key shard;
[0025] Receive the signature request;
[0026] Encrypt the signature request with the first private key shard to obtain the intermediate signature.
[0027] A possible implementation manner, authenticating the client that sends the identity authentication based on the identity authentication request, includes:
[0028] Determine the first moment when the identity authentication request is received, query the second moment when the dynamic password in the identity authentication request is generated, and the target identity identifier corresponding to the dynamic password;
[0029] In response to the identity identifier to be verified in the identity authentication request being consistent with the target identity identifier, and the time interval between the first moment and the second moment being less than a preset threshold, determine that the identity authentication status is successful.
[0030] In a second aspect, an embodiment of the present application provides a method for identity authentication, which is applied to a client and includes:
[0031] Receive an intermediate ciphertext; wherein, the intermediate ciphertext is sent by the server;
[0032] Use the second private key shard to decrypt the intermediate ciphertext to obtain a dynamic password;
[0033] Based on the dynamic password, determine an identity authentication request, and send the identity authentication request to the server; wherein, the identity authentication request includes the dynamic password and the identity identifier of the client.
[0034] A possible implementation manner, before receiving the intermediate ciphertext, further includes:
[0035] Determine a signature request, and send the signature request to the server;
[0036] Receive an intermediate signature; wherein, the intermediate signature is sent by the server;
[0037] Use the second private key shard to encrypt the intermediate signature to obtain the target signature;
[0038] Send the target signature so that the server verifies the client based on the target signature.
[0039] In a third aspect, an embodiment of the present application provides an identity authentication device, which is applied to a server, and the device includes:
[0040] A password unit, configured to determine a password ciphertext; wherein, the password ciphertext is obtained by encrypting a dynamic password;
[0041] A first decryption unit, configured to decrypt the password ciphertext based on a first private key shard to obtain an intermediate ciphertext;
[0042] A sending unit, configured to send the intermediate ciphertext to the client;
[0043] An authentication unit, configured to receive an identity authentication request and authenticate the client that sends the identity authentication request; wherein, the identity authentication request includes the dynamic password, and the dynamic password is obtained by the client based on the intermediate ciphertext.
[0044] A possible implementation, the password unit is specifically configured to generate a dynamic password; encrypt the dynamic password using the public key to obtain the password ciphertext; wherein, the dynamic password corresponds to the client.
[0045] A possible implementation, the device further includes a public key unit, configured to receive the client intermediate value, and determine the server intermediate value based on the first private key shard; determine the public key based on the client intermediate value and the server intermediate value.
[0046] A possible implementation, the device further includes a verification unit, configured to determine an intermediate signature; send the intermediate signature to the client so that the client determines the target signature based on the intermediate signature; receive the target signature; in response to the target signature being verified successfully, determine to generate a dynamic password.
[0047] A possible implementation, the verification unit is further configured to generate a first random number; send the first random number so that the client determines a signature request based on the first random number and the second private key shard; receive the signature request; encrypt the signature request using the first private key shard to obtain the intermediate signature.
[0048] A possible implementation, the authentication unit is specifically configured to determine the first moment when the identity authentication request is received, query the second moment when the dynamic password in the identity authentication request is generated, and the target identity identifier corresponding to the dynamic password; in response to the identity identifier to be verified in the identity authentication request being consistent with the target identity identifier, and the time interval between the first moment and the second moment being less than a preset threshold, determine that the identity authentication status is successful.
[0049] In a fourth aspect, an embodiment of the present application provides an identity authentication device, which is applied to a client, and the device includes:
[0050] A ciphertext unit, configured to receive an intermediate ciphertext; wherein, the intermediate ciphertext is sent by the server;
[0051] A second decryption unit, configured to decrypt the intermediate ciphertext using the second private key shard to obtain a dynamic password;
[0052] A request unit, configured to determine an identity authentication request based on the dynamic password and send the identity authentication request to the server; wherein, the identity authentication request includes the dynamic password and the identity identifier of the client.
[0053] A possible implementation, the device further includes a signature unit, configured to determine a signature request and send the signature request to the server; receive an intermediate signature; wherein, the intermediate signature is sent by the server; encrypt the intermediate signature with a second private key shard to obtain the target signature; and send the target signature, so that the server verifies the client based on the target signature.
[0054] In a fifth aspect, an embodiment of the present application provides a readable storage medium, including,
[0055] a memory,
[0056] The memory is used to store a computer program, and when the computer program is executed by a processor, the device including the readable storage medium completes the method described in the first aspect and any possible implementation.
[0057] In a sixth aspect, an embodiment of the present application provides an electronic device, including:
[0058] a memory for storing a computer program;
[0059] a processor for implementing the method described in the first aspect and any possible implementation when executing the computer program stored on the memory.
[0060] One or more technical solutions provided in the embodiments of the present invention have at least the following technical effects:
[0061] In the method provided in the embodiment of the present application, the password ciphertext obtained by encrypting the dynamic password with the first private key shard of the server is decrypted to obtain an intermediate ciphertext, and then sent to the client, so that the client can continue to decrypt the intermediate ciphertext with its second private key shard to obtain the dynamic password for identity authentication. In this way, the security of the key storage of the server and the client is ensured through key splitting. The method does not involve the complete private key, effectively eliminating the risk of private key leakage.
[0062] At the same time, the identity verification and authentication only need to be completed by the server, without the need to modify the application software in the client, significantly reducing the difficulty of identity authentication.
[0063] When verifying the signature, the "challenge-response" mechanism is adopted, and based on the digital signature value of the public key cryptography algorithm, the target signature is generated through two consecutive signatures by the server and the client. In this way, the uniqueness and security of the digital signature obtained each time are improved, effectively improving the accuracy of the identification result of the client's identity legitimacy.
[0064] Other features and advantages of the present application will be described in the following specification, and in part will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written specification, claims, and drawings. It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.
[0066] Figure 1 A flowchart of a method for identity authentication provided by an embodiment of the present application;
[0067] Figure 2 A flowchart of a method for identity authentication provided by an embodiment of the present application;
[0068] Figure 3 A schematic diagram of a usage scenario of a method for identity authentication provided by an embodiment of the present application;
[0069] Figure 4 A schematic diagram of the interaction between a client and a server when generating a dynamic password provided by an embodiment of the present application;
[0070] Figure 5 A schematic diagram of the structure of a device for identity authentication provided by an embodiment of the present application;
[0071] Figure 6 A schematic diagram of the structure of a device for identity authentication provided by an embodiment of the present application;
[0072] Figure 7 A schematic diagram of the structure of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0073] In view of the problem that the current identity authentication method needs to be simplified, an embodiment of the present application provides an identity authentication method. After decrypting the password ciphertext with the first private key shard on the server side, the intermediate ciphertext obtained by the aforementioned decryption is sent to the client, so that the client continues to decrypt the intermediate ciphertext to obtain the dynamic password. In this way, the security of the dynamic password is guaranteed through encryption on the server side and two consecutive decryptions on the server side and the client side, and the identity authentication process can be significantly simplified. According to the foregoing method, the server sends the intermediate ciphertext containing the dynamic password to the client during the interaction process, and after receiving the client's identity authentication request, it performs a one-step verification, avoiding the high cost and low efficiency problems caused by a large number of integration and transformation works on the server side and the client side.
[0074] To better understand the above technical solution, the technical solution of the present application will be described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application. Without conflict, the technical features in the embodiments of the present application and the embodiments can be combined with each other.
[0075] The terms "first" and "second" in the specification, claims and drawings of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the term "including" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices. "Multiple" in the present application may represent at least two, for example, it may be two, three or more, and the embodiments of the present application do not make limitations.
[0076] Please refer to Figure 1 , the present application proposes an identity authentication method to avoid the low efficiency and high cost problems caused by a large number of integration and modification works on the server side and the client side. The method specifically includes the following implementation steps:
[0077] Step 101: Determine the password ciphertext.
[0078] Among them, the password ciphertext is obtained from the dynamic password ciphertext.
[0079] Specifically, first, a dynamic password is generated. The dynamic password is generated after receiving the password request sent by the client.
[0080] The dynamic password is the initial encryption object and also the ciphertext that the client finally uses to request identity authentication.
[0081] Then, use the public key to encrypt the dynamic password to obtain the encrypted password text. The dynamic password corresponds to the client. Specifically, a cipher machine can be called or a preset encryption algorithm can be used to generate it based on a random number as a seed. The above random number can be a true random number or a pseudo-random number. Preferably, a true random number is generated by a cipher machine.
[0082] Further, the determination of the public key is described below:
[0083] First, receive the client intermediate value, and determine the server intermediate value based on the first private key shard. The client intermediate value is obtained by the client encrypting the second private key shard. The server intermediate value is obtained by the server encrypting the first private key shard.
[0084] Then, the public key can be determined based on the client intermediate value and the server intermediate value. Specifically, a preset algorithm can be used to process the client intermediate value and the server intermediate value to obtain the public key. The public key corresponds to the client. For example, the public key and the client are in one-to-one correspondence. And this correspondence relationship is recorded and stored after the public key is determined.
[0085] Since the above intermediate values (client intermediate value and server intermediate value) are both obtained based on the one-way hashing algorithm, the method of sending the intermediate value to determine the public key as described above can not only ensure the security of the public key, but also ensure the security of the private key shard.
[0086] Further, before generating the dynamic password, signature verification can be performed to perform the first verification of the client's identity to confirm whether the client is a user who has registered their identity. The following is a detailed description:
[0087] First, determine the intermediate signature. The way to determine the intermediate signature can be: first generate a first random number. Send the first random number to the client so that the client can determine the signature request based on the first random number and its second private key shard. For example, a preset algorithm can be used to process the first random number and the second private key shard to obtain the signature request.
[0088] Receive the signature request sent by the client. Encrypt the signature request with its first private key shard to obtain the intermediate signature. The signature request may include the client's identity identifier, such as ID, etc. The signature request may also include a request to obtain the dynamic password.
[0089] Then, send the intermediate signature to the client so that the client can determine the target signature based on the intermediate signature. The target signature is the final complete digital signature. The target signature can specifically be obtained by the client encrypting the intermediate signature with its second private key shard.
[0090] Next, receive the target signature
[0091] Finally, verify the target signature. Specifically, the target signature can be decrypted using the public key corresponding to the client to obtain the first digest. Then, perform a digest operation on the first random number to obtain the second digest. Compare the first digest with the second digest. When they are the same, it can be determined that the target signature verification is passed.
[0092] Then, in response to the passing of the target signature verification, determine to generate a dynamic password.
[0093] Alternatively, in response to the failure of the target signature verification, send a notification message of signature verification failure to the client.
[0094] Step 102: Decrypt the password ciphertext based on the first private key shard to obtain the intermediate ciphertext.
[0095] The first private key shard is a random number generated by the server.
[0096] Combined with the method for determining the public key described in the previous step 101, it should be understood that although the private key shards in the embodiments of the present application are the same as the private key: the first private key shard and the second private key shard are generated by different entities: the server and the client respectively. The difference is that the public key does not correspond one-to-one with the private key at either end, but corresponds to the private key shards at both ends simultaneously. Therefore, the first private key shard and the second private key shard in the embodiments of the present application are both logically equivalent to the private key, but not exactly the same as the private key.
[0097] Step 103: Send the intermediate ciphertext to the client.
[0098] Step 104: Receive an identity authentication request and authenticate the client that sends the identity authentication request.
[0099] Among them, the identity authentication request includes a dynamic password, and the dynamic password is obtained by the client based on the intermediate ciphertext.
[0100] Specifically, it can be first determined that the moment when the identity authentication request is received is the first moment. And since the server saves the generation time and the corresponding relationship between the dynamic password and the client every time a dynamic password is generated, the second moment of the dynamic password in the identity authentication request can also be queried at the same time, as well as the target identity identifier of the client corresponding to the dynamic password in the query.
[0101] Then, compare the identity identifier to be verified in the identity authentication request, that is, the identity identifier of the client that sends the identity authentication request, with the target identity identifier corresponding to the dynamic password saved by the server. At the same time, compare whether the time interval between the time when the dynamic password is generated and the time when the dynamic password is received (that is, the time when the identity authentication request is received) meets the requirements. To complete the identity authentication. That is:
[0102] Determine that the identity authentication status is successful in response to the identity identifier to be verified in the identity authentication request matching the target identity identifier and the time interval between the first moment and the second moment being less than the preset threshold.
[0103] Otherwise, determine that the identity authentication status is failed.
[0104] Based on the same inventive concept, an embodiment of the present application further provides an identity authentication method, which is applied to a client. Please refer to Figure 2 , and the method includes the following implementation steps:
[0105] Step 201: Receive the intermediate ciphertext.
[0106] Among them, the intermediate ciphertext is sent by the server.
[0107] The intermediate ciphertext is obtained by the server decrypting the password ciphertext in slices using the first private key, and the password ciphertext is encrypted by the server using the public key.
[0108] Specifically, the reason for receiving the intermediate ciphertext is that the client sends a corresponding request to the server. For example, it is a signature request. The signature request includes a request for obtaining a dynamic password.
[0109] Before sending the request for receiving the intermediate ciphertext, a digital signature can also be sent to the server to enable the server to verify whether the client identity is legal. Specifically, a signature request can be determined first and sent to the server. The signature request is obtained by processing the received first random number and the second private key in slices. The signature request may include the client identity identifier, so that the server can encrypt the signature request using the first private key in slices to obtain the intermediate signature.
[0110] Then, receive the intermediate signature sent by the server.
[0111] Next, encrypt the intermediate signature using the second private key in slices to obtain the target signature.
[0112] Finally, send the target signature to the server to enable the server to verify the client based on the target signature.
[0113] Step 202: Decrypt the intermediate ciphertext using the second private key in slices to obtain the dynamic password.
[0114] Step 203: Determine the identity authentication request based on the dynamic password, and send the identity authentication request to the server, so that the server performs identity authentication based on the dynamic password.
[0115] Then receive the status of the identity authentication sent by the server. The status of the identity authentication includes success and failure.
[0116] Specifically, the above identity authentication request includes the dynamic password and the identity identifier of the client.
[0117] In the foregoing steps 101-104, encryption can be implemented by a server cipher machine, so the server side can integrate: a server cipher machine for encryption. The server side can also integrate an application server, which is used to notify the client whether the login is successful or failed according to the identity authentication status (success or failure) described in step 103. The client can be a mobile token or a mobile phone. Please refer to Figure 3 。
[0118] The following provides an embodiment of the interaction between the client and the server to obtain the dynamic password:
[0119] As Figure 4 shown, in the pair in parentheses, the first letter represents the indication key, and the second letter represents the indication object to be encrypted. For example, (Ks, Qr) means that the signature request is encrypted using the key Ks.
[0120] Moreover, before the client requests the dynamic password from the server, the client may have completed the identity registration on the server: the server encrypts its first private key shard Ks to obtain an intermediate value Ws, and at the same time receives the intermediate value Wa from the client, which is obtained by the client encrypting its second private key shard Ka. The intermediate values Ws and Wa are encrypted to obtain the public key Kp. The server records and stores the record relationship among the user ID, the first private key shard, and the public key Kp of the client to complete the registration.
[0121] Please continue to refer to Figure 4 , the client sends a dynamic password generation request Qa to the server so that the server can authenticate the client based on the "challenge-response" mechanism. Qa contains the user ID of the client.
[0122] After receiving Qa, the server sends a random number Ra to the client according to Qa.
[0123] Then, after receiving the random number Ra generated by the server, the client generates a signature request Qr based on its second private key shard Ka and the random number Ra and sends it to the server.
[0124] Next, after receiving the signature request Qr, the server encrypts Qr using its second private key shard Ks to obtain an intermediate signature, that is, the server signature S1. And the server signature is sent to the client.
[0125] After receiving S1, the client continues to encrypt S1 using its second private key shard Ka to obtain the target signature: the client signature Sa. And the client signature Sa is sent to the server.
[0126] The server uses the public key corresponding to the client to verify the client signature Sa. When the digital signature verification passes, the server generates a dynamic password pw1, and encrypts pw1 using the public key Kp to generate a password ciphertext Cp. Then, the first private key shard Ks is used to decrypt Cp to obtain an intermediate ciphertext, that is, the intermediate value Cs of the password ciphertext. Send Cs to the client.
[0127] After the client receives Cs, it decrypts Cs using the second private key shard Ka to obtain the dynamic password pw1. Then, it sends a message indicating the successful acquisition of the dynamic password to the server.
[0128] Based on the same inventive concept, an identity authentication device is provided in an embodiment of the present application. The device is used for the server and corresponds to the identity authentication method shown above. For the specific implementation of the device, reference can be made to the description in the method embodiment part above. Repeated parts will not be elaborated. Refer to Figure 1 Figure 5 Figure 5 This device includes:
[0129] A password unit 501, configured to determine a password ciphertext; wherein, the password ciphertext is obtained by encrypting a dynamic password.
[0130] Specifically, the password unit 501 is configured to generate a dynamic password; encrypt the dynamic password using a public key to obtain the password ciphertext; wherein, the dynamic password corresponds to the client.
[0131] The device further includes a public key unit, configured to receive a client intermediate value, and determine a server intermediate value based on the first private key shard; determine the public key based on the client intermediate value and the server intermediate value.
[0132] The device further includes a verification unit, configured to determine an intermediate signature; send the intermediate signature to the client so that the client determines the target signature based on the intermediate signature; receive the target signature; in response to the successful verification of the target signature, determine to generate a dynamic password.
[0133] The verification unit is further configured to generate a first random number; send the first random number so that the client determines a signature request based on the first random number and the second private key shard; receive the signature request; encrypt the signature request using the first private key shard to obtain the intermediate signature.
[0134] A first decryption unit 502, configured to decrypt the password ciphertext based on the first private key shard to obtain an intermediate ciphertext;
[0135] A sending unit 503, configured to send the intermediate ciphertext to the client;
[0136] An authentication unit 504, configured to receive an identity authentication request and authenticate the client that sends the identity authentication request.
[0137] Wherein, the identity authentication request includes the dynamic password, and the dynamic password is obtained by the client based on the intermediate ciphertext.
[0138] The authentication unit 504 is specifically configured to determine a first moment when the identity authentication request is received, query a second moment when the dynamic password in the identity authentication request is generated, and the target identity identifier corresponding to the dynamic password; in response to the identity identifier to be verified in the identity authentication request being consistent with the target identity identifier, and the time interval between the first moment and the second moment being less than a preset threshold, determine that the identity authentication status is successful.
[0139] Based on the same inventive concept, an identity authentication device is provided in an embodiment of the present application. The device is used for a client, and this device corresponds to the Figure 2 identity authentication method shown above. The specific implementation manner of this device can refer to the description in the method embodiment part above. For repeated parts, they will not be elaborated here. Refer to Figure 6 , and this device includes:
[0140] A ciphertext unit 601, configured to receive an intermediate ciphertext.
[0141] Wherein, the intermediate ciphertext is sent by the server.
[0142] A second decryption unit 602, configured to decrypt the intermediate ciphertext by using a second private key shard to obtain a dynamic password.
[0143] A request unit 603, configured to determine an identity authentication request based on the dynamic password and send the identity authentication request to the server.
[0144] Wherein, the identity authentication request includes the dynamic password and the identity identifier of the client.
[0145] The device further includes a signature unit, configured to determine a signature request and send the signature request to the server; receive an intermediate signature; wherein, the intermediate signature is sent by the server; encrypt the intermediate signature by using a second private key shard to obtain the target signature; send the target signature so that the server verifies the client based on the target signature.
[0146] Based on the same inventive concept, an embodiment of the present application further provides a readable storage medium, including:
[0147] A memory,
[0148] The memory is used to store a computer program. When the computer program is executed by a processor, it enables the device including the readable storage medium to complete the identity authentication method as described above.
[0149] Based on the same inventive concept as the above identity authentication method, an electronic device is further provided in an embodiment of the present application. The electronic device can implement the functions of the foregoing identity authentication method. Please refer to Figure 7 , the electronic device includes:
[0150] At least one processor 701, and a memory 702 connected to the at least one processor 701. In the embodiment of the present application, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 In Figure 7 , it is taken as an example that the processor 701 and the memory 702 are connected through a bus 700. The bus 700 is represented by a thick line in Figure 7 . The connection manners between other components are only for illustrative purposes and are not limited thereto. The bus 700 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation,
[0151] In the embodiment of the present application, the memory 702 stores instructions executable by the at least one processor 701. The at least one processor 701 can execute the instructions stored in the memory 702 to execute the identity authentication method described above. The processor 701 can implement Figure 5 and / or Figure 6 the functions of each module in the device shown in
[0152] Among them, the processor 701 is the control center of the device. It can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 702 and calling the data stored in the memory 702, various functions of the device and process data, so as to monitor the device as a whole.
[0153] In a possible design, the processor 701 may include one or more processing units. The processor 701 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above modem processor may not be integrated into the processor 701. In some embodiments, the processor 701 and the memory 702 can be implemented on the same chip. In some embodiments, they can also be separately implemented on independent chips.
[0154] The processor 701 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the identity authentication method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0155] The memory 702, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 702 may include at least one type of storage medium, for example, it may include flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (RAM), a static random access memory (SRAM), a programmable read-only memory (PROM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic memory, a magnetic disk, an optical disk, etc. The memory 702 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 702 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0156] By designing and programming the processor 701, the code corresponding to the identity authentication method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 1 and / or Figure 2 the steps of the identity authentication method shown. How to design and program the processor 701 is a well-known technology to those skilled in the art and will not be elaborated here.
[0157] Those skilled in the art can clearly understand that for the convenience and conciseness of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. For the specific working processes of the system, device, and unit described above, reference can be made to the corresponding processes in the foregoing method embodiments, which will not be elaborated here.
[0158] In several embodiments provided by the present invention, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical functional division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.
[0159] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0160] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0161] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as Universal Serial Bus flash disks, mobile hard disks, Read-Only Memory (ROM), Random Access Memory (RAM), magnetic disks, or optical discs.
[0162] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application also intends to include these changes and modifications.
Claims
1. A method for identity authentication, characterized in that, applied to a server, the method includes: Determine the password ciphertext; wherein, the password ciphertext includes a dynamic password; Decrypt the password ciphertext based on the first private key shard to obtain an intermediate ciphertext; Send the intermediate ciphertext to the client; Receive an identity authentication request and authenticate the client that sends the identity authentication request; wherein, the identity authentication request includes the dynamic password, and the dynamic password is obtained by the client based on the intermediate ciphertext.
2. The method according to claim 1, characterized in that, The determining the password ciphertext includes: Generate a dynamic password; Encrypt the dynamic password using a public key to obtain the password ciphertext; wherein, the dynamic password corresponds to the client.
3. The method according to claim 2, characterized in that, The public key is obtained by the following method: Receive the client intermediate value and determine the server intermediate value based on the first private key shard; Determine the public key based on the client intermediate value and the server intermediate value.
4. The method according to any one of claims 1-3, characterized in that, Before determining the password ciphertext, it further includes: Determine an intermediate signature; Send the intermediate signature to the client so that the client determines the target signature based on the intermediate signature; Receive the target signature; In response to the target signature being verified successfully, determine to generate a dynamic password.
5. The method according to claim 4, characterized in that, The determining the intermediate signature includes: Generate a first random number; Send the first random number so that the client determines a signature request based on the first random number and the second private key shard; Receive the signature request; Encrypt the signature request using the first private key shard to obtain the intermediate signature.
6. The method according to any one of claims 1-3, 5, characterized in that, The authenticating the client that sends the identity authentication based on the identity authentication request includes: Determine the first moment when the identity authentication request is received, query the second moment when the dynamic password in the identity authentication request is generated, and the target identity identifier corresponding to the dynamic password; In response to the identity identifier to be verified in the identity authentication request being consistent with the target identity identifier, and the time interval between the first moment and the second moment being less than a preset threshold, determine that the identity authentication status is successful.
7. A method for identity authentication, characterized in that, applied to a client, the method includes: Receive the intermediate ciphertext; wherein, the intermediate ciphertext is sent by the server; Decrypt the intermediate ciphertext using the second private key shard to obtain a dynamic password; Determine an identity authentication request based on the dynamic password and send the identity authentication request to the server; wherein, the identity authentication request includes the dynamic password and the identity identifier of the client.
8. The method according to claim 7, characterized in that, Before receiving the intermediate ciphertext, it further includes: Determine a signature request and send the signature request to the server; Receive the intermediate signature; wherein, the intermediate signature is sent by the server; Encrypt the intermediate signature using the second private key shard to obtain the target signature; Send the target signature so that the server can verify the client based on the target signature.
9. An identity authentication device, Characterized in that, Applied to the server, the device includes: A password unit for determining a password ciphertext; wherein, the password ciphertext is obtained by encrypting a dynamic password; A first decryption unit for decrypting the password ciphertext based on the first private key shard to obtain an intermediate ciphertext; A sending unit for sending the intermediate ciphertext to the client; An authentication unit for receiving an identity authentication request and authenticating the identity of the client that sends the identity authentication request; wherein, the identity authentication request includes the dynamic password, and the dynamic password is obtained by the client based on the intermediate ciphertext.
10. An identity authentication device, Characterized in that, Applied to the client, the device includes: A ciphertext unit for receiving an intermediate ciphertext; wherein, the intermediate ciphertext is sent by the server; A second decryption unit for decrypting the intermediate ciphertext using the second private key shard to obtain a dynamic password; A request unit for determining an identity authentication request based on the dynamic password and sending the identity authentication request to the server; wherein, the identity authentication request includes the dynamic password and the identity identifier of the client.
11. A readable storage medium, Characterized in that, Includes, A memory, The memory is used to store a computer program, and when the computer program is executed by a processor, it enables the device including the readable storage medium to complete the method described in any one of claims 1-8.
12. An electronic device, Characterized in that, Includes: A memory for storing a computer program; A processor for implementing the method described in any one of claims 1-8 when executing the computer program stored on the memory.