Identity authentication method, system, equipment, medium and product based on scheduling business

Through multi-factor identity authentication combined with passwords, hardware tokens, biometrics and digital certificates, blockchain records authentication information, the problem of low identity authentication security in scheduling services is solved, and effective identification of malicious attacks and security guarantees of the power grid are achieved.

CN120090876BActive Publication Date: 2025-08-12INNOVATION & INNOVATION CENT OF STATE GRID ZHEJIANG ELECTRIC POWER CO LTD +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510560367.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-12
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

The existing scheduling services have a single identity authentication method, low security, and are vulnerable to malicious attacks, affecting the safe and stable operation of the power grid.

Method used

A multi-factor identity authentication method is adopted, combining passwords, hardware tokens, biometric identification and digital certificates, and authentication information is recorded through blockchain, and the behavioral characteristics of the authentication information are analyzed to identify malicious attacks.

Benefits of technology

Improve the security of identity authentication, effectively identify malicious attacks, and ensure the safe and stable operation of the power grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090876B_ABST
    Figure CN120090876B_ABST
Patent Text Reader

Abstract

The present invention discloses an identity authentication method, system, device, medium and product based on a scheduling service. The method includes: if an account number and password input by a target user are received, the first identity information of the target user is obtained based on the account number and password, and the account number and password authentication is performed based on the first identity information; when the account number and password authentication is successful, the hardware token, biometrics and digital certificate authentication are performed in sequence; after the two authentications are passed, the identity of the target user is confirmed and the authentication process is terminated, the authentication information of the failed authentication is analyzed for failure, and the failure analysis result is sent to the user terminal; if only the account number and password authentication is passed, the target user's account is detected for malicious attacks. The method can combine multi-factor identity authentication of passwords, hardware tokens, biometrics and digital certificates, record authentication information through blockchain, analyze the behavioral characteristics of the authentication information, effectively identify malicious attack behaviors, and improve the security of identity authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and in particular to an identity authentication method, system, equipment, medium and product based on scheduling services. Background Art

[0002] Dispatchers and operating unit staff performing dispatching operations must pass certification training and qualification assessments organized by the organization and obtain the required qualifications before they can perform dispatching operations. Currently, dispatching operations are generally conducted by phone, and identity verification is carried out over the phone. Misrepresenting the dispatcher's identity, contacting the wrong dispatcher, or performing the wrong grid dispatching task can pose a significant security risk and potentially affect the safe and stable operation of the power grid. Alternatively, the dispatcher's identity can be confirmed through voiceprint authentication, which is relatively simple and less secure. Summary of the Invention

[0003] The present invention provides an identity authentication method, system, device, medium and product based on scheduling business. By combining multi-factor identity authentication with passwords, hardware tokens, biometric identification and digital certificates, the authentication information is recorded on the blockchain, and the behavioral characteristics of the authentication information are analyzed. This can effectively identify malicious attack behaviors and improve the security of identity authentication.

[0004] To achieve the above objectives, an embodiment of the present invention provides a scheduling service-based identity authentication method, which is applied to a server terminal. The method includes:

[0005] If the target user inputs an account and password, the target user's first identity information is obtained based on the account and password, and the account and password authentication is performed based on the first identity information;

[0006] When the account and password authentication is successful, the second identity information of the hardware token is read from the hardware token of the target user; and the hardware token is authenticated according to the first identity information and the second identity information;

[0007] If the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and the target user is biometrically authenticated;

[0008] If the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and the digital certificate authentication of the target user is performed;

[0009] If the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the target user's account.

[0010] As an improvement to the above solution, after performing hardware token authentication according to the first identity information and the second identity information, the method further includes:

[0011] If the hardware token authentication is successful, the identity authentication process of the target user is ended;

[0012] After performing biometric authentication on the target user, the method further includes:

[0013] If the biometric authentication is successful, the identity authentication process of the target user is terminated, and after the token authentication information is analyzed for failure, the token failure analysis result is sent to the user terminal;

[0014] After performing digital certificate authentication on the target user, the method further includes:

[0015] If the digital certificate authentication is successful, the identity authentication process of the target user is ended, and after failure analysis of the token authentication information and the biometric authentication information is performed, the token failure analysis result and the biometric failure analysis result are sent to the user terminal.

[0016] As an improvement to the above solution, the scheduling service-based identity authentication method further includes:

[0017] When the account and password authentication fails, the account authentication information of the account and password authentication is written into the blockchain, and the target user is authenticated by biometrics and digital certificate;

[0018] If only the biometric authentication fails or only the digital certificate authentication fails, the biometric authentication information or the certificate authentication information is written into the blockchain, and the target user is re-authenticated with the account and password;

[0019] If the new account and password authentication fails, the new account authentication information is written into the blockchain, and the target user's account is tested for malicious attacks;

[0020] If the biometric authentication fails and the digital certificate authentication fails, the biometric authentication information and the certificate authentication information are written into the blockchain, and a malicious attack detection is performed on the target user's account.

[0021] As an improvement to the above solution, after performing biometric authentication and digital certificate authentication on the target user, the method further includes:

[0022] If the biometric authentication is successful and the digital certificate authentication is successful, the identity authentication process of the target user is terminated, and after the failure analysis of the account authentication information is performed, the account failure analysis result is sent to the user terminal;

[0023] After re-authenticating the target user's account and password, the method further includes:

[0024] If the new account and password authentication is successful, the identity authentication process of the target user is ended, and after the failure analysis of the biometric authentication information or the certificate authentication information, and the account authentication information, the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result are sent to the user terminal.

[0025] As an improvement to the above solution, performing hardware token authentication according to the first identity information and the second identity information includes:

[0026] matching the first identity information with the second identity information;

[0027] If the first identity information and the second identity information are the same, the hardware token authentication is successful;

[0028] If the first identity information and the second identity information are different, the hardware token authentication fails.

[0029] As an improvement to the above solution, the malicious attack detection on the target user's account includes:

[0030] Obtaining authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp, and failure reason;

[0031] constructing a two-dimensional vector of the authentication information based on the authentication information, and using the two-dimensional vector as a behavioral feature of the target user;

[0032] Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated. Based on the probability of the behavior feature, it is determined whether the target user's account has malicious attack behavior.

[0033] As an improvement to the above solution, the digital certificate authentication of the target user includes:

[0034] Obtain the public key of the certificate authority and the signature of the digital certificate uploaded by the target user;

[0035] Verify the signature according to the public key; if the signature is valid and within the validity period, the digital certificate authentication is successful;

[0036] If the signature is invalid or out of validity, the digital certificate authentication fails.

[0037] To achieve the above objectives, an embodiment of the present invention provides an identity authentication system based on a scheduling service, comprising:

[0038] An account and password authentication module, configured to, upon receiving an account and password input by a target user, obtain the first identity information of the target user based on the account and password, and perform account and password authentication based on the first identity information;

[0039] A hardware token authentication module is configured to read the second identity information of the hardware token from the hardware token connected to the target user after the account and password authentication is successful; and perform hardware token authentication based on the first identity information and the second identity information;

[0040] A biometric authentication module, configured to write the token authentication information of the hardware token authentication into the blockchain if the hardware token authentication fails, and to perform biometric authentication on the target user;

[0041] A digital certificate authentication module, configured to write the biometric authentication information of the biometric authentication into the blockchain if the biometric authentication fails, and to perform digital certificate authentication on the target user;

[0042] The first malicious attack detection module is used to write the certificate authentication information of the digital certificate authentication into the blockchain if the digital certificate authentication fails, and perform malicious attack detection on the target user's account.

[0043] As an improvement to the above solution, the scheduling service-based identity authentication system further includes:

[0044] An identity authentication ending module, configured to end the identity authentication process of the target user if the hardware token authentication is successful;

[0045] A token failure analysis module, configured to terminate the identity authentication process of the target user if the biometric authentication is successful, and after performing a failure analysis on the token authentication information, send the token failure analysis result to the user terminal;

[0046] The authentication information analysis module is used to end the identity authentication process of the target user if the digital certificate authentication is successful, and after performing failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

[0047] As an improvement to the above solution, the scheduling service-based identity authentication system further includes:

[0048] A biometric certificate authentication module, which is used to write the account authentication information of the account and password authentication into the blockchain when the account and password authentication fails, and to perform biometric authentication and digital certificate authentication on the target user;

[0049] An account re-authentication module, configured to write the biometric authentication information or the certificate authentication information into the blockchain if only the biometric authentication or the digital certificate authentication fails, and to re-authenticate the target user's account and password;

[0050] A second malicious attack detection module is used to write the new account authentication information into the blockchain if the new account password authentication fails, and to detect malicious attacks on the target user's account;

[0051] The third malicious detection module is used to write the biometric authentication information and the certificate authentication information into the blockchain if the biometric authentication fails and the digital certificate authentication fails, and to perform malicious attack detection on the target user's account.

[0052] As an improvement to the above solution, the scheduling service-based identity authentication system further includes:

[0053] An account failure analysis module, configured to terminate the target user's identity authentication process if both the biometric authentication and the digital certificate authentication are successful, and to perform a failure analysis on the account authentication information and send the account failure analysis result to the user terminal;

[0054] The authentication failure analysis module is used to end the identity authentication process of the target user if the new account and password authentication is successful, and after performing failure analysis on the biometric authentication information or the certificate authentication information, as well as the account authentication information, the biometric failure analysis result or the certificate failure analysis result, as well as the account failure analysis result, is sent to the user terminal.

[0055] As an improvement to the above solution, performing hardware token authentication according to the first identity information and the second identity information includes:

[0056] matching the first identity information with the second identity information;

[0057] If the first identity information and the second identity information are the same, the hardware token authentication is successful;

[0058] If the first identity information and the second identity information are different, the hardware token authentication fails.

[0059] As an improvement to the above solution, the malicious attack detection on the target user's account includes:

[0060] Obtaining authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp, and failure reason;

[0061] constructing a two-dimensional vector of the authentication information based on the authentication information, and using the two-dimensional vector as a behavioral feature of the target user;

[0062] Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated. Based on the probability of the behavior feature, it is determined whether the target user's account has malicious attack behavior.

[0063] As an improvement to the above solution, the digital certificate authentication of the target user includes:

[0064] Obtain the public key of the certificate authority and the signature of the digital certificate uploaded by the target user;

[0065] Verify the signature according to the public key; if the signature is valid and within the validity period, the digital certificate authentication is successful;

[0066] If the signature is invalid or out of validity, the digital certificate authentication fails.

[0067] In order to achieve the above-mentioned purpose, an embodiment of the present invention provides an identity authentication device based on scheduling service, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, it implements the above-mentioned identity authentication method based on scheduling service.

[0068] In order to achieve the above-mentioned purpose, an embodiment of the present invention further provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned scheduling service-based identity authentication method.

[0069] To achieve the above object, an embodiment of the present invention further provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the above scheduling service-based identity authentication method.

[0070] Compared with the prior art, the embodiment of the present invention discloses an identity authentication method, system, device, medium and product based on the scheduling service. If the account and password input by the target user are received, the first identity information of the target user is obtained according to the account and password, and the account and password authentication is performed according to the first identity information; when the account and password authentication is successful, the second identity information of the hardware token connected to the target user is read from the hardware token; the hardware token authentication is performed according to the first identity information and the second identity information; if the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and the target user is biometrically authenticated; if the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and the target user is digitally authenticated; if the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the target user's account. It can combine multi-factor identity authentication of passwords, hardware tokens, biometric identification and digital certificates, record authentication information through blockchain, analyze the behavioral characteristics of authentication information, effectively identify malicious attack behavior, and improve the security of identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0071] Figure 1 This is a flow chart of an identity authentication method based on a scheduling service provided by an embodiment of the present invention;

[0072] Figure 2 This is a schematic diagram of the structure of an identity authentication system based on a scheduling service provided by an embodiment of the present invention;

[0073] Figure 3 This is a structural diagram of an identity authentication device based on a scheduling service provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0074] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0075] It should be noted that the terms "comprises" and "specifically" and any variations thereof in the present invention are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or are inherent to these processes, methods, products or apparatuses.

[0076] See also Figure 1 , Figure 1 1 is a flow chart of an identity authentication method based on a scheduling service provided by an embodiment of the present invention. The identity authentication method based on a scheduling service is applied to a server terminal. The method includes:

[0077] S1, if the target user inputs an account and password, obtain the target user's first identity information based on the account and password, and perform account and password authentication based on the first identity information;

[0078] S2, when the account and password authentication is successful, reading the second identity information of the hardware token from the hardware token connected to the target user; and performing hardware token authentication based on the first identity information and the second identity information;

[0079] S3, if the hardware token authentication fails, writing the token authentication information of the hardware token authentication into the blockchain, and performing biometric authentication on the target user;

[0080] S4, if the biometric authentication fails, writing the biometric authentication information into the blockchain, and performing digital certificate authentication on the target user;

[0081] S5. If the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and a malicious attack detection is performed on the target user's account.

[0082] Furthermore, after performing hardware token authentication according to the first identity information and the second identity information, the method further includes:

[0083] S6, if the hardware token authentication is successful, then the identity authentication process of the target user is ended;

[0084] After performing biometric authentication on the target user, the method further includes:

[0085] S7, if the biometric authentication is successful, then the identity authentication process of the target user is ended, and after the token authentication information is analyzed for failure, the token failure analysis result is sent to the user terminal;

[0086] After performing digital certificate authentication on the target user, the method further includes:

[0087] S8. If the digital certificate authentication is successful, the identity authentication process of the target user is ended, and after failure analysis of the token authentication information and the biometric authentication information is performed, the token failure analysis result and the biometric failure analysis result are sent to the user terminal.

[0088] Exemplarily, the scheduling service-based identity authentication method described in an embodiment of the present invention can be implemented by an identity authentication server. The identity authentication server (authentication terminal) is capable of interacting with the target user and the blockchain. Upon receiving the target user's account and password, the identity authentication server retrieves the target user's primary identity information (e.g., personal information, responsibilities, permissions, accessible functions, data range, and operation type) from a data center based on the account and password. The server analyzes the primary identity information to determine whether the target user has the responsibilities and permissions to perform scheduling services, thereby performing account and password authentication. It is worth noting that the data center stores the hardware token's hardware token number and identity information, and associates the token number with the identity information. The data center also records the target user's latest identity information. If the target user's identity information, such as responsibilities or permissions, changes, the data center will synchronously update the target user's identity information. When the hardware token is connected to the authentication terminal, the data center reads the hardware token's token number and writes the token number and access time into the access record. When the account and password authentication is successful, the second identity information of the hardware token (such as personal information, responsibilities, permissions, accessible functions, data range and operation type, etc.) is read from the hardware token connected to the target user; if the first identity information matches the second identity information, the hardware token authentication is successful, the identity of the target user is confirmed and the identity authentication process is ended; if the first identity information does not match the second identity information, for example, the responsibilities of the first identity information are different from those of the second identity information, the hardware token authentication fails. The reason for this situation may be that the responsibilities of the target user have changed, but the identity information of the hardware token has not been updated in time, or it has been attacked maliciously. The token authentication information of the hardware token authentication is written into the blockchain, and the target user is subjected to biometric authentication (such as existing voice recognition, fingerprint recognition, face recognition, etc.); if the biometric authentication is successful, the identity of the target user is ended. The identity authentication process is completed, and after the failure analysis is performed on the token authentication information, the token failure analysis result is sent to the user terminal; if the biometric authentication also fails, the biometric authentication information of the biometric authentication is written into the blockchain, and the digital certificate authentication is performed on the target user; if the digital certificate authentication is successful, the identity authentication process is ended, and after the failure analysis is performed on the token authentication information and the biometric authentication information, the token failure analysis result and the biometric failure analysis result are sent to the user terminal, and the target user can solve the corresponding problem according to the failure analysis result so that the authentication can be successfully performed next time; if the digital certificate authentication also fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and the target user's account is detected for malicious attacks (for example, feature extraction and analysis are performed on the token authentication information, the biometric authentication information and the certificate authentication information, and according to the analysis results, it is determined whether the target user's account has been maliciously attacked).This embodiment of the present invention utilizes a multi-factor authentication method that combines passwords, hardware tokens, biometrics, and digital certificates, effectively resisting malicious attacks and significantly improving authentication security. If a problem arises with one authentication method, other methods can be used, ensuring authentication flexibility and business continuity. This facilitates authentication management and improves overall operational efficiency and reliability.

[0089] Furthermore, the scheduling service-based identity authentication method further includes:

[0090] S9, when the account and password authentication fails, writing the account authentication information of the account and password authentication into the blockchain, and performing biometric authentication and digital certificate authentication on the target user;

[0091] S10, if only the biometric authentication fails or only the digital certificate authentication fails, the biometric authentication information or the certificate authentication information is written into the blockchain, and the target user's account and password authentication is re-performed;

[0092] S11, if the new account and password authentication fails, the new account authentication information is written into the blockchain, and malicious attack detection is performed on the target user's account;

[0093] S12: If the biometric authentication fails and the digital certificate authentication fails, the biometric authentication information and the certificate authentication information are written into the blockchain, and a malicious attack detection is performed on the target user's account.

[0094] Furthermore, after performing biometric authentication and digital certificate authentication on the target user, the method further includes:

[0095] S13, if the biometric authentication is successful and the digital certificate authentication is successful, then the identity authentication process of the target user is terminated, and after performing a failure analysis on the account authentication information, the account failure analysis result is sent to the user terminal;

[0096] S14. If the new account and password authentication is successful, the identity authentication process of the target user is ended, and after performing failure analysis on the biometric authentication information or the certificate authentication information, and the account authentication information, the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result are sent to the user terminal.

[0097] For example, if the target user inputs an incorrect password due to a mistake or other reasons, resulting in account and password authentication failure, since the hardware token authentication requires the first identity information of the target user, and the first identity information needs to be obtained based on the correct account and password, when the account and password authentication fails, the hardware token authentication cannot be initiated, and the target user needs to perform identity authentication through other channels, such as biometric authentication and digital certificate authentication. If both biometric authentication and digital certificate authentication are successful, the identity authentication process is terminated, and after the account authentication information is analyzed for failure, the account failure analysis result is sent to the user terminal. If the biometric authentication is successful and the digital certificate authentication fails, or the biometric authentication fails, the target user will be automatically authenticated. If the authentication fails and the digital certificate authentication succeeds, the authentication information of the failed authentication will be written into the blockchain, and the target user's account and password authentication will be re-performed. If the new account and password authentication is successful, the identity authentication process will be terminated, and the biometric authentication information or the certificate authentication information will be analyzed for failure. After the account authentication information is analyzed for failure, the biometric failure analysis result or the certificate failure analysis result, as well as the account failure analysis result, will be sent to the user terminal. If the new account and password authentication fails, the authentication information of the failed authentication (new account authentication information, biometric authentication information or the certificate authentication information) will be written into the blockchain, and malicious attack detection will be performed on the target user's account.

[0098] In the specific implementation, user A mistakenly enters the wrong password, and the authentication terminal determines that the account and password authentication fails. Although the hardware token is connected successfully, the authentication terminal does not initiate hardware token authentication due to the wrong password; user A performs fingerprint authentication, and due to a fingerprint sensor failure, biometric authentication fails. User A uploads the digital certificate, uses the CA public key to verify the validity of the certificate signature, extracts the user public key, generates a random number, encrypts the public key and sends it to user A's user terminal, so that user A uses the private key to decrypt the public key. If the decryption is successful, the digital certificate authentication is successful. Since only the digital certificate authentication is passed, the authentication terminal requires a second verification of the account and password: user A re-enters the correct password, and the new account and password authentication is successful, then the identity authentication process ends, allowing user A to access the basic scheduling function. The blockchain records the failure of the initial account and password authentication and the success of the digital certificate authentication. The record format is as follows: "User Terminal Number": "R14", "Account and Password Authentication": "Failed", "Digital Certificate Authentication": "Successful", "Timestamp": "20250101T10:05:00", "Token Number": "UserA2025-001". Security analysis result: Common error (incorrect password input), no risk operation.

[0099] Specifically, performing hardware token authentication according to the first identity information and the second identity information includes:

[0100] matching the first identity information with the second identity information;

[0101] If the first identity information and the second identity information are the same, the hardware token authentication is successful;

[0102] If the first identity information and the second identity information are different, the hardware token authentication fails.

[0103] For example, a target user enters their account and password on an authentication terminal and connects a hardware token to the authentication terminal. The authentication terminal then obtains the target user's first identity information based on the entered account and password and authenticates the target user. If the first identity information contains insufficient permissions or incorrect responsibilities, the account and password authentication fails; otherwise, the account and password authentication succeeds. The first identity information includes the target user's personal information, responsibilities, permissions, accessible functions, data ranges, and operation types, and can be stored in a cloud server or local storage for the authentication terminal to match the identity. After successful account and password authentication, the authentication terminal uses the token number to read the second identity information in the hardware token. If the second identity information does not match the first identity information obtained from the data center using the account and password, the hardware token authentication fails. If they do, the hardware token authentication succeeds. Once both the account and password authentication and the hardware token authentication pass, the authentication terminal unlocks the corresponding data ranges and functions based on the target user's responsibilities, corresponding functions, and data ranges, and no further authentication is performed. The hardware token's processor records the status of the account and password and hardware token authentication processes in a timetable.

[0104] It's worth noting that hardware tokens have memory and a processor. The memory stores the target user's identity information and a timetable for the processor to read and write. Each hardware token has a unique, unchangeable token number assigned upon manufacture, which can be parsed and read by the terminal. Setting the token number prevents counterfeiting and enhances the security of hardware tokens. Identity information includes personal information, responsibilities, permissions, accessible functions, data ranges, and operation types. The timetable includes status information such as the terminal to which the hardware token is connected, timestamps, and status. For example, "20250101, 09:13 AM, R14, Failed (Code 0011)" is a data entry in the timetable. The terminal number to which the token was connected is R14, the time of access is 9:13 AM on January 1, 2025, the access failed, and the code for the failure is 0011.

[0105] In another embodiment, a random number generator and a timer can also be integrated into the hardware token. When the hardware token is connected to the authentication terminal, it receives instructions from the authentication terminal and generates a random number. The timer records the system time and generates a time parameter at the same time as the random number, which is used to record the current time. The random number and time parameter are encrypted, and a password is generated and displayed to the target user. The password is encrypted and output to the authentication terminal. The authentication terminal synchronizes the time with the hardware token and counts according to the time parameter. The target user enters the encrypted password on the authentication terminal, and the authentication terminal decrypts the encrypted password and compares the encrypted password entered by the target user with the password entered by the hardware token. If they are the same, the account and password authentication is successful; otherwise, if the password is not entered or is entered incorrectly before the time threshold is reached, the account and password authentication fails. When the account and password authentication is successful, the authentication terminal reads the identity information in the hardware token. If the identity information does not match the identity information obtained from the data center through the account and password, the hardware token authentication fails. If they match, the hardware token authentication is successful.

[0106] It is understandable that the first identity information is updated in real time by the data center, but the hardware token needs to be carried by the target user. Therefore, when the data center updates the first identity information and the target user has not updated the second identity information in the hardware token, the hardware token authentication will fail. At this time, the target user can perform biometric identification. If the account password authentication is passed and the biometric identification authentication is passed, the target user can enter the system normally. In other words, among the three authentications of password authentication, hardware token and biometric identification, the target user must pass at least two authentications before entering the terminal to perform scheduling services. Biometric identification includes voiceprint recognition, fingerprint recognition, facial recognition, etc. The target user's biometrics can be collected through an acquisition device, such as a camera collecting the target user's facial features, a microphone collecting the target user's voiceprint, a fingerprint sensor collecting the target user's fingerprint, etc.

[0107] In the implementation, User A enters their account number (UserA001) and correct password. The authentication terminal retrieves their primary identity information from the data center and confirms their permissions as a dispatcher (with access to grid topology data and circuit breaker operation). Account and password authentication is successful. User A connects to a hardware token (token number: UserA2025-001), and the authentication terminal reads the secondary identity information stored in the token. Because the data center recently updated User A's permissions (adding "emergency operation" permissions), but the hardware token has not been updated synchronously, the token permissions do not match those of the data center (failure code 0011: identity information expired), and hardware token authentication fails. The hardware token schedule reads 20250101, 09:13AM, R14, failure (0011). User A uses fingerprint recognition to match the biometric template stored in the data center. Biometric authentication succeeds, and the overall judgment confirms that User A has passed authentication. The authentication terminal grants permissions: displaying grid topology data, but hiding the "emergency operation" function (because the token has not been updated). The blockchain records successful account and password authentication, failed hardware token authentication, and successful biometric authentication. The record format is as follows: "User Terminal Number": "R14", "Account and Password Authentication": "Success", "Hardware Token Authentication": "Failure (0011)", "Biometric Authentication": "Success", "Timestamp": "20250101T09:13:00", "Hardware Token Number": "User A2025-001". Security analysis results: The reason for the extraction failure is 0011, which is marked as a general error (authority not synchronized). A notification is automatically sent to the user terminal, requiring the hardware token information to be updated.

[0108] Specifically, the malicious attack detection on the target user's account includes:

[0109] Obtaining authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp, and failure reason;

[0110] constructing a two-dimensional vector of the authentication information based on the authentication information, and using the two-dimensional vector as a behavioral feature of the target user;

[0111] Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated. Based on the probability of the behavior feature, it is determined whether the target user's account has malicious attack behavior.

[0112] For example, the authentication terminal writes the authentication information into the blockchain, which includes the password authentication result, hardware token authentication result, timestamp, token number, failure reason, etc. By obtaining the authentication information from the blockchain, the authentication information of failed authentication is filtered and a two-dimensional vector is constructed. , Indicates the Group failure information, Indicates the The timestamp of the group failure information, which includes the failure reason and token number. As behavioral characteristics ,Will Enter a In the self-attention mechanism, each self-attention mechanism pays attention to the input user behavior features. Perform linear changes. The construction formula is:

[0113] ,

[0114] ,

[0115] ,

[0116] Calculate the query vector in the self-attention mechanism , key vector Sum vector , where To generate a query vector The weight matrix of To generate a key vector The weight matrix of To generate a value vector The weight matrix of .

[0117] And according to the formula:

[0118] ,

[0119] Calculating attention scores , where is the factor of the model feature size and the number of attention mechanisms, is the transposition symbol. By concatenating all the output attention scores, we get the attention weight vector, which is consistent with the behavior feature. The product of is the behavioral feature encoding .

[0120] Encode key behaviors based on preset high-priority behaviors through the Transformer encoder Extraction, using a convolution kernel with a large receptive field to encode behavioral features Perform convolution operations to capture global information and obtain global features The size of the receptive field can be adjusted to The size of the convolution kernel is similar or slightly smaller to capture most of the global information, and the convolution kernel with a smaller receptive field is used to encode the key behaviors. Perform convolution operations to capture local information. Consider using multiple convolution kernels and taking the maximum response at each position as the local feature to obtain local features. ; The global features and local features Splicing: , achieving comprehensive extraction of behavioral characteristics; using analytical algorithms such as neural networks and logistic regression, the probabilities of different behaviors are calculated, and the behavior with the highest probability is selected as the behavioral judgment result. Behaviors include illegal operations, routine errors, and malicious attacks. Based on the preset handling method and judgment results, the security system outputs the judgment result and treatment to the user terminal. By judging the target user's behavior, the authentication terminal's operating status can be timely understood, allowing for timely response to malicious attacks.

[0121] Specifically, the digital certificate authentication of the target user includes:

[0122] Obtain the public key of the certificate authority and the signature of the digital certificate uploaded by the target user;

[0123] Verify the signature according to the public key; if the signature is valid and within the validity period, the digital certificate authentication is successful;

[0124] If the signature is invalid or out of validity, the digital certificate authentication fails.

[0125] For example, if the target user has only passed one of the three authentications, namely account and password authentication, hardware token and biometric identification authentication, the target user can also upload a digital certificate to the authentication terminal. The authentication terminal obtains the corresponding public key from the certificate authority (CA) based on the input digital certificate, and verifies the signature of the digital certificate based on the public key of the certificate authority. If the signature is valid and within the validity period, the user public key corresponding to the target user is extracted from the signature, a random number is generated and encrypted with the user public key, and the encrypted result is sent to the target user for parsing. The target user decrypts the random number with the private key and writes the decrypted result into the authentication terminal. The authentication terminal obtains the random number input by the target user. If it is the same as the generated random number, the digital certificate authentication is passed, otherwise the digital certificate authentication fails.

[0126] In one specific implementation, an attacker uses a stolen account, User A001, and password to connect to a forged hardware token (token number: TKN-illegal). The attacker enters the account (User A001) and the correct password. The authentication terminal obtains the primary identity information of the account from the data center and confirms that the authority is a dispatcher (with access to grid topology data and operation of circuit breakers). The account and password authentication succeeds. The authentication terminal reads the forged token number TKN-illegal, which the data center does not have. The hardware token authentication fails (failure code 0022: invalid token). The attacker cannot pass fingerprint verification, and the blockchain records frequent failures. The same account attempts multiple times on terminals R14 and R15 within a short period of time, such as: (1) "Timestamp": "20250101T11:00:00", "Terminal": "R14", "Failure reason": "0022"; (2) "Timestamp": "20250101T11:00:01", "Terminal": "R14", "Failure reason": "0022"; (3) "Timestamp": "20250101T11:01:00", "Terminal": "R15", "Failure reason": "0022"; (4) "Timestamp": "20250101T11:01:01", "Terminal": "R15", "Failure reason": "0022"; Security analysis results: Global features ( ): high-frequency failure across terminals with short time intervals; local features ( ): The token number is illegal and logins have failed continuously, which is determined to be a malicious attack (98% probability). The account: User A001 is automatically locked and an alert is sent: A malicious attack against the account: User A001 has been detected. Please check terminals R14 and R15 immediately.

[0127] The embodiment of the present invention discloses an identity authentication method based on a scheduling service. If an account number and password input by a target user are received, the first identity information of the target user is obtained according to the account number and password, and the account number and password authentication is performed according to the first identity information; when the account number and password authentication is successful, the second identity information of the hardware token connected to the target user is read from the hardware token; the hardware token authentication is performed according to the first identity information and the second identity information; if the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and the target user is biometrically authenticated; if the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and the target user is digitally authenticated; if the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the target user's account. The method can combine multi-factor identity authentication of passwords, hardware tokens, biometric identification and digital certificates, record authentication information through the blockchain, analyze the behavioral characteristics of the authentication information, effectively identify malicious attack behaviors, and improve the security of identity authentication.

[0128] See also Figure 2 , Figure 2 1 is a schematic diagram of a structure of an identity authentication system 10 based on a scheduling service provided by an embodiment of the present invention. The identity authentication system 10 based on a scheduling service includes:

[0129] The account and password authentication module 11 is configured to, upon receiving an account and password input by a target user, obtain the first identity information of the target user based on the account and password, and perform account and password authentication based on the first identity information;

[0130] The hardware token authentication module 12 is configured to read the second identity information of the hardware token from the hardware token of the target user after the account and password authentication is successful; and perform hardware token authentication based on the first identity information and the second identity information;

[0131] A biometric authentication module 13 is configured to write the token authentication information of the hardware token authentication into the blockchain if the hardware token authentication fails, and to perform biometric authentication on the target user;

[0132] A digital certificate authentication module 14 is configured to write the biometric authentication information of the biometric authentication into the blockchain if the biometric authentication fails, and to perform digital certificate authentication on the target user;

[0133] The first malicious attack detection module 15 is used to write the certificate authentication information of the digital certificate authentication into the blockchain if the digital certificate authentication fails, and perform malicious attack detection on the target user's account.

[0134] Furthermore, the scheduling service-based identity authentication system 10 further includes:

[0135] An identity authentication ending module, configured to end the identity authentication process of the target user if the hardware token authentication is successful;

[0136] A token failure analysis module, configured to terminate the identity authentication process of the target user if the biometric authentication is successful, and after performing a failure analysis on the token authentication information, send the token failure analysis result to the user terminal;

[0137] The authentication information analysis module is used to end the identity authentication process of the target user if the digital certificate authentication is successful, and after performing failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

[0138] Furthermore, the scheduling service-based identity authentication system 10 further includes:

[0139] A biometric certificate authentication module, which is used to write the account authentication information of the account and password authentication into the blockchain when the account and password authentication fails, and to perform biometric authentication and digital certificate authentication on the target user;

[0140] An account re-authentication module, configured to write the biometric authentication information or the certificate authentication information into the blockchain if only the biometric authentication or the digital certificate authentication fails, and to re-authenticate the target user's account and password;

[0141] A second malicious attack detection module is used to write the new account authentication information into the blockchain if the new account password authentication fails, and to detect malicious attacks on the target user's account;

[0142] The third malicious detection module is used to write the biometric authentication information and the certificate authentication information into the blockchain if the biometric authentication fails and the digital certificate authentication fails, and to perform malicious attack detection on the target user's account.

[0143] Furthermore, the scheduling service-based identity authentication system 10 further includes:

[0144] An account failure analysis module, configured to terminate the target user's identity authentication process if both the biometric authentication and the digital certificate authentication are successful, and to perform a failure analysis on the account authentication information and send the account failure analysis result to the user terminal;

[0145] The authentication failure analysis module is used to end the identity authentication process of the target user if the new account and password authentication is successful, and after performing failure analysis on the biometric authentication information or the certificate authentication information, as well as the account authentication information, the biometric failure analysis result or the certificate failure analysis result, as well as the account failure analysis result, is sent to the user terminal.

[0146] Specifically, performing hardware token authentication according to the first identity information and the second identity information includes:

[0147] matching the first identity information with the second identity information;

[0148] If the first identity information and the second identity information are the same, the hardware token authentication is successful;

[0149] If the first identity information and the second identity information are different, the hardware token authentication fails.

[0150] Specifically, the malicious attack detection on the target user's account includes:

[0151] Obtaining authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp, and failure reason;

[0152] constructing a two-dimensional vector of the authentication information based on the authentication information, and using the two-dimensional vector as a behavioral feature of the target user;

[0153] Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated. Based on the probability of the behavior feature, it is determined whether the target user's account has malicious attack behavior.

[0154] Specifically, the digital certificate authentication of the target user includes:

[0155] Obtain the public key of the certificate authority and the signature of the digital certificate uploaded by the target user;

[0156] Verify the signature according to the public key; if the signature is valid and within the validity period, the digital certificate authentication is successful;

[0157] If the signature is invalid or out of validity, the digital certificate authentication fails.

[0158] An identity authentication system 10 based on scheduling services provided by an embodiment of the present invention can implement all processes of the identity authentication method based on scheduling services in the above-mentioned embodiment. The functions of each module in the system and the technical effects achieved are respectively the same as the functions and technical effects achieved by the identity authentication method based on scheduling services in the above-mentioned embodiment, and will not be repeated here.

[0159] See also Figure 3 , Figure 3 The diagram is a schematic diagram of the structure of a scheduling service-based identity authentication device 20 provided in an embodiment of the present invention. The scheduling service-based identity authentication device 20 in this embodiment includes a processor 21, a memory 22, and a computer program stored in the memory 22 and executable on the processor 21. When the processor 21 executes the computer program, it implements the steps of the aforementioned scheduling service-based identity authentication method embodiment. Alternatively, when the processor 21 executes the computer program, it implements the functions of the various modules in the aforementioned scheduling service-based identity authentication device embodiment.

[0160] Exemplarily, the computer program may be divided into one or more modules, which are stored in the memory 22 and executed by the processor 21 to implement the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the scheduling service-based identity authentication device 20.

[0161] The scheduling service-based identity authentication device 20 can be a computing device such as a desktop computer, laptop, PDA, or cloud server. The scheduling service-based identity authentication device 20 can include, but is not limited to, a processor 21 and a memory 22. Those skilled in the art will appreciate that the schematic diagram is merely an example of a scheduling service-based identity authentication device 20 and does not limit the scheduling service-based identity authentication device 20. The scheduling service-based identity authentication device 20 can include more or fewer components than shown, or a combination of certain components, or different components. For example, the scheduling service-based identity authentication device 20 can also include input / output devices, network access devices, buses, and the like.

[0162] The processor 21 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor. The processor 21 is the control center of the scheduling service-based identity authentication device 20, and utilizes various interfaces and lines to connect various parts of the entire scheduling service-based identity authentication device 20.

[0163] The memory 22 can be used to store the computer programs and / or modules. The processor 21 implements the various functions of the dispatch service-based identity authentication device 20 by running or executing the computer programs and / or modules stored in the memory 22 and accessing the data stored in the memory 22. The memory 22 may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function or an image playback function); the data storage area may store data generated based on the use of the mobile phone (such as audio data, a phone book, etc.). Furthermore, the memory 22 may include high-speed random access memory (RAM) and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.

[0164] If the module integrated into the scheduling service-based identity authentication device 20 is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention can implement all or part of the process steps in the above-mentioned method embodiments by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When executed by the processor 21, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunications signal, and a software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practices in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practices, computer-readable media do not include electrical carrier signals and telecommunication signals.

[0165] It should be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art can understand and implement the present invention without inventive effort.

[0166] An embodiment of the present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the identity authentication method based on scheduling services as described in the above embodiment.

[0167] In addition, an embodiment of the present invention further provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the scheduling service-based identity authentication method of the above embodiment.

[0168] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. An identity authentication method based on a scheduling service, characterized in that: Applied to a server terminal, the method includes: If the target user inputs an account and password, the target user's first identity information is obtained based on the account and password, and the account and password authentication is performed based on the first identity information; When the account and password authentication is successful, the second identity information of the hardware token is read from the hardware token of the target user; and the hardware token is authenticated according to the first identity information and the second identity information; If the hardware token authentication fails, the token authentication information of the hardware token authentication is written into the blockchain, and the target user is biometrically authenticated; If the biometric authentication fails, the biometric authentication information of the biometric authentication is written into the blockchain, and the digital certificate authentication of the target user is performed; If the digital certificate authentication fails, the certificate authentication information of the digital certificate authentication is written into the blockchain, and malicious attack detection is performed on the target user's account; When the account and password authentication fails, the account authentication information of the account and password authentication is written into the blockchain, and the target user is authenticated by biometrics and digital certificate; If only the biometric authentication fails or only the digital certificate authentication fails, the biometric authentication information or the certificate authentication information is written into the blockchain, and the target user is re-authenticated with the account and password; If the new account and password authentication fails, the new account authentication information is written into the blockchain, and the target user's account is tested for malicious attacks; If the biometric authentication fails and the digital certificate authentication fails, the biometric authentication information and the certificate authentication information are written to the blockchain, and the target user's account is tested for malicious attacks; The malicious attack detection on the target user's account includes: Obtaining authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp, and failure reason; constructing a two-dimensional vector of the authentication information based on the authentication information, and using the two-dimensional vector as a behavioral feature of the target user; Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated. Based on the probability of the behavior feature, it is determined whether the target user's account has malicious attack behavior.

2. The identity authentication method based on scheduling service according to claim 1, characterized in that: After performing hardware token authentication according to the first identity information and the second identity information, the method further includes: If the hardware token authentication is successful, the identity authentication process of the target user is ended; After performing biometric authentication on the target user, the method further includes: If the biometric authentication is successful, the identity authentication process of the target user is terminated, and after the token authentication information is analyzed for failure, the token failure analysis result is sent to the user terminal; After performing digital certificate authentication on the target user, the method further includes: If the digital certificate authentication is successful, the identity authentication process of the target user is ended, and after failure analysis of the token authentication information and the biometric authentication information is performed, the token failure analysis result and the biometric failure analysis result are sent to the user terminal.

3. The identity authentication method based on scheduling service according to claim 1, characterized in that: After performing biometric authentication and digital certificate authentication on the target user, the method further includes: If the biometric authentication is successful and the digital certificate authentication is successful, the identity authentication process of the target user is terminated, and after the failure analysis of the account authentication information is performed, the account failure analysis result is sent to the user terminal; After re-authenticating the target user's account and password, the method further includes: If the new account and password authentication is successful, the identity authentication process of the target user is ended, and after the failure analysis of the biometric authentication information or the certificate authentication information, and the account authentication information, the biometric failure analysis result or the certificate failure analysis result, and the account failure analysis result are sent to the user terminal.

4. The identity authentication method based on scheduling service according to claim 1, characterized in that: The performing hardware token authentication according to the first identity information and the second identity information includes: matching the first identity information with the second identity information; If the first identity information and the second identity information are the same, the hardware token authentication is successful; If the first identity information and the second identity information are different, the hardware token authentication fails.

5. The identity authentication method based on scheduling service according to claim 1, characterized in that: The digital certificate authentication of the target user includes: Obtain the public key of the certificate authority and the signature of the digital certificate uploaded by the target user; Verify the signature according to the public key; if the signature is valid and within the validity period, the digital certificate authentication is successful; If the signature is invalid or out of validity, the digital certificate authentication fails.

6. An identity authentication system based on scheduling services, characterized in that: include: An account and password authentication module, configured to, upon receiving an account and password input by a target user, obtain the first identity information of the target user based on the account and password, and perform account and password authentication based on the first identity information; A hardware token authentication module is used to read the second identity information of the hardware token from the hardware token connected to the target user after the account and password authentication is successful; Performing hardware token authentication according to the first identity information and the second identity information; A biometric authentication module, configured to write the token authentication information of the hardware token authentication into the blockchain if the hardware token authentication fails, and to perform biometric authentication on the target user; A digital certificate authentication module, configured to write the biometric authentication information of the biometric authentication into the blockchain if the biometric authentication fails, and to perform digital certificate authentication on the target user; A first malicious attack detection module is configured to write the certificate authentication information of the digital certificate authentication into the blockchain if the digital certificate authentication fails, and perform malicious attack detection on the target user's account; A biometric certificate authentication module, which is used to write the account authentication information of the account and password authentication into the blockchain when the account and password authentication fails, and to perform biometric authentication and digital certificate authentication on the target user; An account re-authentication module, configured to write the biometric authentication information or the certificate authentication information into the blockchain if only the biometric authentication or the digital certificate authentication fails, and to re-authenticate the target user's account and password; A second malicious attack detection module is used to write the new account authentication information into the blockchain if the new account password authentication fails, and to detect malicious attacks on the target user's account; A third malicious attack detection module is configured to write the biometric authentication information and the certificate authentication information into the blockchain if both the biometric authentication and the digital certificate authentication fail, and to perform malicious attack detection on the target user's account; The malicious attack detection on the target user's account includes: Obtaining authentication information corresponding to the authentication failure from the blockchain; wherein the authentication information includes the authentication result, timestamp, and failure reason; constructing a two-dimensional vector of the authentication information based on the authentication information, and using the two-dimensional vector as a behavioral feature of the target user; Feature extraction is performed on the behavior feature, and based on the feature extraction result, the probability of the behavior feature is calculated. Based on the probability of the behavior feature, it is determined whether the target user's account has malicious attack behavior.

7. The identity authentication system based on scheduling service according to claim 6, characterized in that: Also includes: An identity authentication ending module, configured to end the identity authentication process of the target user if the hardware token authentication is successful; A token failure analysis module, configured to terminate the identity authentication process of the target user if the biometric authentication is successful, and after performing a failure analysis on the token authentication information, send the token failure analysis result to the user terminal; The authentication information analysis module is used to end the identity authentication process of the target user if the digital certificate authentication is successful, and after performing failure analysis on the token authentication information and the biometric authentication information, send the token failure analysis result and the biometric failure analysis result to the user terminal.

8. The identity authentication system based on scheduling service according to claim 6, characterized in that: Also includes: An account failure analysis module, configured to terminate the target user's identity authentication process if both the biometric authentication and the digital certificate authentication are successful, and to perform a failure analysis on the account authentication information and send the account failure analysis result to the user terminal; The authentication failure analysis module is used to end the identity authentication process of the target user if the new account and password authentication is successful, and after performing failure analysis on the biometric authentication information or the certificate authentication information, as well as the account authentication information, the biometric failure analysis result or the certificate failure analysis result, as well as the account failure analysis result, is sent to the user terminal.

9. The identity authentication system based on scheduling service according to claim 6, characterized in that: The performing hardware token authentication according to the first identity information and the second identity information includes: matching the first identity information with the second identity information; If the first identity information and the second identity information are the same, the hardware token authentication is successful; If the first identity information and the second identity information are different, the hardware token authentication fails.

10. The identity authentication system based on scheduling service according to claim 6, characterized in that: The digital certificate authentication of the target user includes: Obtain the public key of the certificate authority and the signature of the digital certificate uploaded by the target user; Verify the signature according to the public key; if the signature is valid and within the validity period, the digital certificate authentication is successful; If the signature is invalid or out of validity, the digital certificate authentication fails.

11. An identity authentication device based on a scheduling service, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the identity authentication method based on the scheduling service as described in any one of claims 1 to 5 is implemented.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the scheduling service-based identity authentication method according to any one of claims 1 to 5.

13. A computer program product, characterized in that The computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the scheduling service-based identity authentication method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Operation authentication method and device, storage medium and electronic device

    CN111582876A

  • Drug traceability management method and system based on block chain technology

    CN112184268A

  • Account management method and device based on block chain technology

    CN116545725A