Cross-platform identity authentication and access control system
By designing a cross-platform identity authentication and access control system, the complex problems of identity authentication and permission management in a cross-platform environment are solved, efficient identity authentication and access control are achieved, and security and defense capabilities are significantly improved.
Patent Information
- Application Number
- CN202510088861.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-06-06
AI Technical Summary
It is difficult for existing technologies to achieve seamless authentication and permission management in a cross-platform environment, especially in the context of emerging technologies such as cloud computing, the Internet of Things, and big data, the requirements of identity authentication and access control have become complicated.
A cross-platform identity authentication and access control system is designed, including user identity management module, authentication management module, permission control module, encryption module, log and audit module, and gateway and identity authentication interface module. The system synchronously updates user identity information through the application program interface, uses two-factor authentication and security analysis methods to generate access policies dynamically, and uses symmetric encryption technology and surface fitting operations to encrypt during user access.
It realizes unified identity authentication and access control across platforms, improves defense capabilities, reduces the risk of account being attacked, and ensures user's personal privacy and data security.
Smart Images

Figure CN120110709A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity management and information security, and in particular to a cross-platform identity authentication and access control system. Background Art
[0002] With the rapid development of information technology, more and more enterprises and users need to access and use various applications and services on different devices and platforms. Traditional identity authentication and access control technologies usually rely on single platform or single application solutions, and cannot effectively perform seamless identity authentication and permission management across multiple platforms and devices. Especially in cross-platform environments, such as web applications, mobile devices, desktop applications, etc., when performing identity authentication and access control between multiple terminals, existing technologies face many challenges.
[0003] Existing authentication methods, such as authentication based on username and password, authentication based on hardware tokens, etc., can meet basic security needs, but in cross-platform application scenarios, they cannot flexibly manage access rights between different platforms. Especially in the context of emerging technologies such as cloud computing, the Internet of Things, and big data, the needs for identity authentication and access control have become more complex.
[0004] In addition, although traditional access control models, such as role-based access control (RBAC) and attribute-based access control (ABAC), meet the needs of permission management to a certain extent, in a diversified cross-platform environment, they often require a lot of customization work based on different scenarios and platforms, resulting in increased system complexity and higher operation and maintenance costs.
[0005] Therefore, how to provide a cross-platform identity authentication and access control system is a problem that needs to be solved urgently. Summary of the invention
[0006] The embodiment of the present invention provides a cross-platform identity authentication and access control system to solve the problems in the prior art.
[0007] In order to have a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. This summary is not intended to be a general review, nor is it intended to identify key / important components or to delineate the scope of protection of these embodiments. Its only purpose is to present some concepts in a simple form as a preface to the detailed description that follows.
[0008] According to a first aspect of an embodiment of the present invention, a cross-platform identity authentication and access control system is provided.
[0009] In one embodiment, a cross-platform identity authentication and access control system includes:
[0010] User identity management module, used to obtain and store the identity information of users on different platforms, and synchronously update the user identity information through the application program interface;
[0011] The authentication management module is used to obtain the identity information of the user who logs in, and authenticate the user's identity information through a two-factor authentication method to obtain an authentication result;
[0012] The permission control module is used to obtain the user's login environment information, and use the security analysis method to evaluate the security of the login environment, and dynamically generate the user's access policy based on the evaluation results;
[0013] The encryption module is used to encrypt the user's identity information and access data through symmetric encryption technology during the user access process;
[0014] The log and audit module is used to record all login, access and operation behaviors of users, and conduct abnormal audits on user behaviors;
[0015] The gateway and identity authentication interface module is used to provide a unified cross-platform authentication entry, process identity authentication requests from different platforms, and interact with the user identity management module and the authentication management module.
[0016] In one embodiment, the authentication management module includes:
[0017] The user name matching submodule is used to obtain the user name and static password entered by the user on the login interface of different platforms, and match the stored password pre-stored in the database according to the user name. If the user name does not exist, the login fails; if the user name exists, a static password comparison is performed;
[0018] The matching verification submodule is used to perform encrypted hash matching verification on the static password entered by the user and the stored password in the database. If the verification succeeds, dynamic password verification is performed; if the verification fails, the login fails and a failure log is recorded;
[0019] The dynamic password generation submodule is used to generate a dynamic password based on a time synchronization algorithm after the static password is successfully verified, and send it to the user end through a secure channel, and guide the user to enter the dynamic password within a preset time;
[0020] The dynamic password verification submodule is used to obtain the dynamic password input by the user, parse the username and timestamp parts of the dynamic password, and verify the validity of the username and the timeliness of the timestamp respectively. If both are verified successfully, the authentication is successful; otherwise, the authentication fails.
[0021] In one embodiment, the encrypted hash matching verification of the static password input by the user and the stored password in the database includes:
[0022] Based on the encrypted hash algorithm, the static password entered by the user during registration is encrypted and hashed in advance to generate a storage hash value, and the storage hash value is stored in the database as the storage password;
[0023] Use the encrypted hash algorithm to perform encrypted hash calculation on the static password entered by the user to generate a password hash value;
[0024] Using a similarity algorithm, the hash value generated by the static password entered by the user is compared and verified with the hash value stored in the database.
[0025] In one embodiment, the step of performing cryptographic hash calculation on the static password input by the user using a cryptographic hash algorithm to generate a cryptographic hash value includes:
[0026] Preprocessing the static password input by the user, the preprocessing includes removing redundant spaces and character encoding conversion;
[0027] Use the MD5 algorithm to perform preliminary hash calculation on the preprocessed password and generate an initial hash value;
[0028] A salt value is generated by a random number generator and combined with the initial hash value to obtain a password hash value.
[0029] In one embodiment, using a similarity algorithm to compare and verify the hash value generated by the static password input by the user with the hash value stored in the database includes:
[0030] Decoding the hash value generated by the static password input by the user and the hash value stored in the database to obtain a decoded hash value;
[0031] According to the decoded hash value, the character difference between the user input hash value and the stored hash value is calculated using the minimum edit distance to obtain the edit distance;
[0032] The edit distance is converted into a similarity score, and a preset similarity threshold is used to determine whether the password entered by the user matches the stored password.
[0033] In one embodiment, after the static password verification is successful, generating a dynamic password based on a time synchronization algorithm, sending it to the user end through a secure channel, and guiding the user to enter the dynamic password within a preset time includes:
[0034] After the static password verification is successful, the current timestamp is obtained, the current timestamp is divided by the preset time window, and the password seed is obtained by rounding the current timestamp.
[0035] The password seed is combined with the user's identity information to generate a dynamic password through a dynamic password generation algorithm;
[0036] The dynamic password is sent to the user end based on a pre-set secure channel, and the user is prompted to enter the dynamic password within a preset time window.
[0037] In one embodiment, the permission control module includes:
[0038] The environmental data collection and processing submodule is used to collect the environmental data of the user when currently logged in, and perform data cleaning on the collected environmental data;
[0039] The security scoring submodule is used to conduct security assessment on environmental data after data cleaning and obtain the security score of each data;
[0040] The access policy generation submodule is used to comprehensively evaluate the security of the login environment based on the security scores of various data, and dynamically generate and apply the user's access policy based on the security assessment results.
[0041] In one embodiment, the environmental data includes browser type, version, device brand, model, operating system version, IP address, and login time.
[0042] In one embodiment, the encryption module includes:
[0043] The data division and encryption submodule is used to divide the user's identity information and access data into multiple information blocks, encrypt each information block using multiple symmetric encryption algorithms, and obtain the ciphertext data and key of each information block;
[0044] The fitting operation submodule is used to construct a data matrix according to the ciphertext data and key of each information block, with the key as a row vector and the ciphertext data as a column vector, and generate a three-dimensional surface and a surface fitting equation by performing a surface fitting operation on the data matrix;
[0045] The data storage submodule is used to store and process the generated ciphertext data, corresponding keys, data matrices, and surface fitting equations to form a complete encryption domain.
[0046] In one embodiment, the symmetric encryption algorithm includes: Triple Data Encryption Standard algorithm, Blowing Fish algorithm, Reeves Cipher 2 algorithm, Reeves Cipher 4 algorithm and Triple Data Encryption algorithm.
[0047] According to a second aspect of an embodiment of the present invention, a cross-platform identity authentication and access control method is provided, comprising the following steps:
[0048] Obtain and store the identity information of users on different platforms, and synchronously update the user's identity information through the application program interface;
[0049] Obtain the user's login identity information, and authenticate the user's identity information through a two-factor authentication method to obtain an authentication result;
[0050] Obtain the user's login environment information, and use security analysis methods to evaluate the security of the login environment, and dynamically generate the user's access policy based on the evaluation results;
[0051] During the user access process, the user's identity information and access data are encrypted using symmetric encryption technology;
[0052] Record all login, access and operation behaviors of users, and conduct abnormal audits on user behaviors.
[0053] According to a third aspect of an embodiment of the present invention, a computer device is provided.
[0054] In some embodiments, the computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.
[0055] According to a fourth aspect of embodiments of the present invention, a computer-readable storage medium is provided.
[0056] In one embodiment, the computer-readable storage medium stores a computer program, and the computer program implements the steps of the above method when executed by a processor.
[0057] The technical solution provided by the embodiment of the present invention may have the following beneficial effects:
[0058] The present invention encrypts user identity information to ensure that the user identity information cannot be stolen during transmission. Even if the data transmission path is attacked, the user password can be prevented from being leaked. The information is transmitted through encrypted transmission, which ensures the confidentiality and integrity of the data transmission process. By introducing a two-factor authentication mechanism, the authentication level is increased, the defense capability is significantly improved, the risk of account attacks is reduced, and the user's personal privacy and data security are effectively protected.
[0059] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0061] Figure 1is a principle block diagram of a cross-platform identity authentication and access control system according to an exemplary embodiment;
[0062] Figure 2 is a flow chart of a cross-platform identity authentication and access control method according to an exemplary embodiment;
[0063] Figure 3 It is a flowchart of user identity authentication and authentication token generation in a cross-platform identity authentication and access control system according to an exemplary embodiment;
[0064] Figure 4 The figure is a schematic diagram showing the structure of a computer device according to an exemplary embodiment. DETAILED DESCRIPTION
[0065] The following description and accompanying drawings fully illustrate the specific embodiments of this article so that those skilled in the art can practice them. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. The scope of the embodiments of this article includes the entire scope of the claims, as well as all available equivalents of the claims. Herein, the terms "first", "second", etc. are only used to distinguish one element from another, without requiring or implying any actual relationship or order between these elements. In fact, the first element can also be called the second element, and vice versa. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that the structure, device or equipment including a series of elements includes not only those elements, but also other elements that are not explicitly listed, or also include elements inherent to such structure, device or equipment. In the absence of more restrictions, the elements defined by the sentence "including one..." do not exclude the existence of other identical elements in the structure, device or equipment including the elements. Each embodiment is described in a progressive manner herein, and each embodiment focuses on the differences from other embodiments, and the same and similar parts between the embodiments can be referred to each other.
[0066] The terms "longitudinal", "lateral", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc. in this document indicate the orientation or position relationship based on the orientation or position relationship shown in the drawings, and are only for the convenience of describing this document and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operate in a specific orientation, and therefore cannot be understood as a limitation on the present invention. In the description of this document, unless otherwise specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a mechanical connection or an electrical connection, it can also be the internal communication of two elements, it can be a direct connection, or it can be an indirect connection through an intermediate medium. For ordinary technicians in this field, the specific meanings of the above terms can be understood according to specific circumstances.
[0067] As used herein, the term "plurality" means two or more than two, unless otherwise specified.
[0068] In this document, the character " / " indicates that the preceding and following objects are in an "or" relationship. For example, A / B means: A or B.
[0069] In this article, the term "and / or" is a description of the association relationship between objects, indicating that three relationships may exist. For example, A and / or B means: A or B, or, A and B.
[0070] It should be understood that, although the various steps in the flow chart are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0071] Each module in the device or system of the present application can be implemented in whole or in part by software, hardware, or a combination thereof. The above modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to the above modules.
[0072] In the absence of conflict, the embodiments of the present invention and the features of the embodiments may be combined with each other.
[0073] Figure 1An embodiment of the cross-platform identity authentication and access control system of the present invention is shown.
[0074] In this optional embodiment, the cross-platform identity authentication and access control system includes:
[0075] User identity management module 101, used to obtain and store identity information of users on different platforms, and synchronously update the identity information of users through application program interfaces;
[0076] It should be noted that each platform needs to provide an API interface for obtaining identity information (such as RESTful API or GraphQL), and call these interfaces regularly or in real time to obtain user identity information.
[0077] The identity information that needs to be obtained includes: user name, email address, mobile phone number, role, permission information, etc.
[0078] Use standard authentication protocols (such as OAuth 2.0, OpenID Connect, SAML, etc.) to integrate with the platform.
[0079] The authentication management module 102 is used to obtain the identity information of the user who logs in, and authenticate the user's identity information through a two-factor authentication method to obtain an authentication result;
[0080] It should be noted that the authentication service uses a Token mechanism to manage and transmit authentication information, ensuring that users do not need to log in repeatedly when accessing across platforms, while ensuring security and data integrity.
[0081] In this optional embodiment, the authentication management module 102 includes:
[0082] The user name matching submodule is used to obtain the user name and static password entered by the user on the login interface of different platforms, and match the stored password pre-stored in the database according to the user name. If the user name does not exist, the login fails; if the user name exists, a static password comparison is performed;
[0083] The matching verification submodule is used to perform encrypted hash matching verification on the static password entered by the user and the stored password in the database. If the verification succeeds, dynamic password verification is performed; if the verification fails, the login fails and a failure log is recorded;
[0084] In this optional embodiment, the encrypted hash matching verification of the static password input by the user and the stored password in the database includes:
[0085] Based on the encrypted hash algorithm, the static password entered by the user during registration is encrypted and hashed in advance to generate a storage hash value, and the storage hash value is stored in the database as the storage password;
[0086] Use the encrypted hash algorithm to perform encrypted hash calculation on the static password entered by the user to generate a password hash value;
[0087] In this optional embodiment, the step of performing cryptographic hash calculation on the static password input by the user using a cryptographic hash algorithm to generate a cryptographic hash value includes:
[0088] Preprocessing the static password input by the user, the preprocessing includes removing redundant spaces and character encoding conversion;
[0089] Use the MD5 algorithm to perform preliminary hash calculation on the preprocessed password and generate an initial hash value;
[0090] It should be noted that MD5 (Message Digest Algorithm 5) is a widely used cryptographic hash algorithm for converting input of any length into a fixed-length 128-bit (16-byte) hash value. Its main purpose is to generate a unique fingerprint for the input data.
[0091] A salt value is generated by a random number generator and combined with the initial hash value to obtain a password hash value.
[0092] Specifically, the preprocessed password is used as input and the MD5 algorithm is used for hash calculation. The MD5 algorithm will perform a series of complex operations on the input data, including padding, initialization, and loop compression functions, and finally generate a 128-bit hash value. The 128-bit hash value output by the MD5 algorithm is converted into hexadecimal representation, that is, a 32-character string is obtained, which is the initial hash value of the password.
[0093] Using a similarity algorithm, the hash value generated by the static password entered by the user is compared and verified with the hash value stored in the database.
[0094] In this optional embodiment, using a similarity algorithm to compare and verify the hash value generated by the static password input by the user with the hash value stored in the database includes:
[0095] Decoding the hash value generated by the static password input by the user and the hash value stored in the database to obtain a decoded hash value;
[0096] It should be noted that hash values are usually stored or transmitted in the form of hexadecimal strings. The purpose of decoding is to convert these hexadecimal strings into standard byte representations for further character-level or byte-level comparison and processing.
[0097] Hash values are usually hexadecimal strings (such as 482c811da5d5b4bc6d497ffa98491e38), and the decoding process is to convert these strings into raw byte data.
[0098] Hash value format:
[0099] Hexadecimal string: Every two characters represent one byte (range 00 to FF).
[0100] After conversion, it is converted into a byte sequence (Bytes): each byte is represented in binary form.
[0101] According to the decoded hash value, the character difference between the user input hash value and the stored hash value is calculated using the minimum edit distance to obtain the edit distance;
[0102] The edit distance is converted into a similarity score, and a preset similarity threshold is used to determine whether the password entered by the user matches the stored password.
[0103] The dynamic password generation submodule is used to generate a dynamic password based on a time synchronization algorithm after the static password is successfully verified, and send it to the user end through a secure channel, and guide the user to enter the dynamic password within a preset time;
[0104] In this optional embodiment, after the static password verification is successful, generating a dynamic password based on a time synchronization algorithm, sending it to the user end through a secure channel, and guiding the user to enter the dynamic password within a preset time includes:
[0105] After the static password verification is successful, the current timestamp is obtained, the current timestamp is divided by the preset time window, and the password seed is obtained by rounding the current timestamp.
[0106] It should be noted that the core idea of generating dynamic passwords based on time synchronization algorithms is that the dynamic passwords are jointly driven by timestamps and user identity information; the timestamps are segmented by preset time windows to generate a predictable but short-term seed; the dynamic passwords are only valid within the current time window to ensure security.
[0107] Time window: usually set to 30 seconds (default value, commonly used in TOTP algorithm), that is, a new password seed is generated every 30 seconds. Calculation formula: Password seed = timestamp ÷ time window.
[0108] The password seed is combined with the user's identity information to generate a dynamic password through a dynamic password generation algorithm;
[0109] The dynamic password is sent to the user end based on a pre-set secure channel, and the user is prompted to enter the dynamic password within a preset time window.
[0110] Specifically, sending the dynamic password to the user end based on a pre-set secure channel includes:
[0111] SMS: Send the dynamic password to the mobile phone number bound by the user.
[0112] Email: Send the dynamic password via the email address bound by the user.
[0113] Mobile app push: Send dynamic passwords via encrypted push services such as Firebase or Apple Push.
[0114] Encrypted instant messaging tools: Use end-to-end encrypted chat apps (such as WhatsApp, Signal) to transmit passwords.
[0115] The dynamic password verification submodule is used to obtain the dynamic password input by the user, parse the username and timestamp parts of the dynamic password, and verify the validity of the username and the timeliness of the timestamp respectively. If both are verified successfully, the authentication is successful; otherwise, the authentication fails.
[0116] In addition, if Figure 3 As shown in the figure, during the user authentication process, after the authentication user identity information is correct, an authentication token will be generated. The specific process is:
[0117] Start: The user initiates an authentication request.
[0118] Get authentication policy: Determine the current authentication method.
[0119] Determine two-factor authentication: Check whether two-factor authentication is enabled.
[0120] User input information: If two-factor authentication is not enabled, the user enters an identity.
[0121] System encryption information: Encrypt the identity information entered by the user.
[0122] Verify identity: Send the encrypted information to the unified identity authentication service for verification.
[0123] Processing verification results: If verification fails, return authentication failure information. If verification succeeds, further check whether the identity information is correct.
[0124] Generate token: When the identity information is correct, generate an authentication token.
[0125] Return Token: Returns the authentication token to the client.
[0126] Client-Stored Token: The client stores the token for later use.
[0127] End: The authentication process ends.
[0128] The authority control module 103 is used to obtain the user's login environment information, and use the security analysis method to evaluate the security of the login environment, and dynamically generate the user's access policy according to the evaluation results;
[0129] In this optional embodiment, the authority control module 103 includes:
[0130] The environmental data collection and processing submodule is used to collect the environmental data of the user when currently logged in, and perform data cleaning on the collected environmental data;
[0131] In this optional embodiment, the environmental data includes browser type, version, device brand, model, operating system version, IP address and login time.
[0132] The security scoring submodule is used to conduct security assessment on environmental data after data cleaning and obtain the security score of each data;
[0133] The access policy generation submodule is used to comprehensively evaluate the security of the login environment based on the security scores of various data, and dynamically generate and apply the user's access policy based on the security assessment results.
[0134] In addition, when dynamically generating access policies, the attribute-based access control (ABAC) model can also be used. By defining dynamic access control policies, user permissions are not only dependent on roles (RBAC), but are dynamically determined by user attributes, request context, and platform information. User permissions can be flexibly adjusted based on factors such as time, location, and device type; access policies can be dynamically generated based on environmental variables at the time of the request (such as device information, IP address, time, etc.), thereby achieving more fine-grained permission control and ensuring flexibility and security in cross-platform scenarios.
[0135] The encryption module 104 is used to encrypt the user's identity information and access data through symmetric encryption technology during the user's access process;
[0136] In this optional embodiment, the encryption module 104 includes:
[0137] The data division and encryption submodule is used to divide the user's identity information and access data into multiple information blocks, encrypt each information block using multiple symmetric encryption algorithms, and obtain the ciphertext data and key of each information block;
[0138] In this optional embodiment, the symmetric encryption algorithm includes: Triple Data Encryption Standard Algorithm, Blowing Fish Algorithm, Reeves Cipher 2 Algorithm, Reeves Cipher 4 Algorithm and Triple Data Encryption Algorithm.
[0139] The fitting operation submodule is used to construct a data matrix according to the ciphertext data and key of each information block, with the key as a row vector and the ciphertext data as a column vector, and generate a three-dimensional surface and a surface fitting equation by performing a surface fitting operation on the data matrix;
[0140] It should be noted that ciphertext data is encrypted information, and the key is used to decrypt the ciphertext data. Through the surface fitting operation, the relationship between the ciphertext data and the key is converted into a complex three-dimensional surface, which increases the difficulty of data cracking. The generated three-dimensional surface and surface fitting equation can be used for subsequent data decryption, verification or analysis operations, providing flexibility and convenience.
[0141] The data storage submodule is used to store and process the generated ciphertext data, corresponding keys, data matrices, and surface fitting equations to form a complete encryption domain.
[0142] The log and audit module 105 is used to record all login behaviors, access behaviors and operation behaviors of users, and to conduct abnormal audits on the behaviors of users;
[0143] The gateway and identity authentication interface module 106 is used to provide a unified cross-platform authentication entry, process identity authentication requests from different platforms, and interact with the user identity management module and the authentication management module.
[0144] Figure 2 An embodiment of the cross-platform identity authentication and access control method of the present invention is shown.
[0145] In this optional embodiment, the cross-platform identity authentication and access control method includes the following steps:
[0146] Step 201, obtaining and storing identity information of users on different platforms, and synchronously updating the identity information of users through an application programming interface;
[0147] Step 202, obtaining the identity information of the user logging in, and authenticating the user's identity information through a two-factor authentication method to obtain an authentication result;
[0148] Step 203, obtaining the user's login environment information, and using the security analysis method to evaluate the security of the login environment, and dynamically generating the user's access policy based on the evaluation results;
[0149] Step 204, during the user access process, encrypt the user's identity information and access data using symmetric encryption technology;
[0150] Step 205, record all login behaviors, access behaviors and operation behaviors of the user, and conduct abnormal audit on the user's behaviors.
[0151] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store static information and dynamic information data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in the above method embodiment are implemented.
[0152] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0153] In addition, the present invention also provides a computer device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above method embodiment when executing the computer program.
[0154] In addition, the present invention further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiment are implemented.
[0155] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided by the present invention can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0156] The present invention is not limited to the structures which have been described above and shown in the drawings, and various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
Claims
1. A cross-platform identity authentication and access control system, characterized in that: include: User identity management module, used to obtain and store the identity information of users on different platforms, and synchronously update the user identity information through the application program interface; The authentication management module is used to obtain the identity information of the user who logs in, and authenticate the user's identity information through a two-factor authentication method to obtain an authentication result; The permission control module is used to obtain the user's login environment information, and use the security analysis method to evaluate the security of the login environment, and dynamically generate the user's access policy based on the evaluation results; The encryption module is used to encrypt the user's identity information and access data through symmetric encryption technology during the user access process; The log and audit module is used to record all login, access and operation behaviors of users, and conduct abnormal audits on user behaviors; The gateway and identity authentication interface module is used to provide a unified cross-platform authentication entry, process identity authentication requests from different platforms, and interact with the user identity management module and the authentication management module.
2. The cross-platform identity authentication and access control system according to claim 1, characterized in that: The authentication management module includes: The user name matching submodule is used to obtain the user name and static password entered by the user on the login interface of different platforms, and match the stored password pre-stored in the database according to the user name. If the user name does not exist, the login fails; if the user name exists, a static password comparison is performed; The matching verification submodule is used to perform encrypted hash matching verification on the static password entered by the user and the stored password in the database. If the verification succeeds, dynamic password verification is performed; if the verification fails, the login fails and a failure log is recorded; The dynamic password generation submodule is used to generate a dynamic password based on a time synchronization algorithm after the static password is successfully verified, and send it to the user end through a secure channel, and guide the user to enter the dynamic password within a preset time; The dynamic password verification submodule is used to obtain the dynamic password input by the user, parse the username and timestamp parts of the dynamic password, and verify the validity of the username and the timeliness of the timestamp respectively. If both are verified successfully, the authentication is successful; otherwise, the authentication fails.
3. The cross-platform identity authentication and access control system according to claim 2, characterized in that: The encrypted hash matching verification of the static password input by the user and the stored password in the database includes: Based on the encrypted hash algorithm, the static password entered by the user during registration is encrypted and hashed in advance to generate a storage hash value, and the storage hash value is stored in the database as the storage password; Use the encrypted hash algorithm to perform encrypted hash calculation on the static password entered by the user to generate a password hash value; Using a similarity algorithm, the hash value generated by the static password entered by the user is compared and verified with the hash value stored in the database.
4. The cross-platform identity authentication and access control system according to claim 3, characterized in that: The method of using a cryptographic hash algorithm to perform cryptographic hash calculation on a static password input by a user to generate a cryptographic hash value includes: Preprocessing the static password input by the user, the preprocessing includes removing redundant spaces and character encoding conversion; Use the MD5 algorithm to perform preliminary hash calculation on the preprocessed password and generate an initial hash value; A salt value is generated by a random number generator and combined with the initial hash value to obtain a password hash value.
5. The cross-platform identity authentication and access control system according to claim 3, characterized in that: The method of comparing and verifying the hash value generated by the static password input by the user with the hash value stored in the database by using a similarity algorithm includes: Decoding the hash value generated by the static password input by the user and the hash value stored in the database to obtain a decoded hash value; According to the decoded hash value, the character difference between the user input hash value and the stored hash value is calculated using the minimum edit distance to obtain the edit distance; The edit distance is converted into a similarity score, and a preset similarity threshold is used to determine whether the password entered by the user matches the stored password.
6. The cross-platform identity authentication and access control system according to claim 3, characterized in that: After the static password verification is successful, the dynamic password is generated based on the time synchronization algorithm, and sent to the user end through a secure channel, and the user is guided to enter the dynamic password within a preset time. The method includes: After the static password verification is successful, the current timestamp is obtained, the current timestamp is divided by the preset time window, and the password seed is obtained by rounding the current timestamp. The password seed is combined with the user's identity information to generate a dynamic password through a dynamic password generation algorithm; The dynamic password is sent to the user end based on a pre-set secure channel, and the user is prompted to enter the dynamic password within a preset time window.
7. The cross-platform identity authentication and access control system according to claim 1, characterized in that: The authority control module includes: The environmental data collection and processing submodule is used to collect the environmental data of the user when currently logged in, and perform data cleaning on the collected environmental data; The security scoring submodule is used to conduct security assessment on environmental data after data cleaning and obtain the security score of each data; The access policy generation submodule is used to comprehensively evaluate the security of the login environment based on the security scores of various data, and dynamically generate and apply the user's access policy based on the security assessment results.
8. The cross-platform identity authentication and access control system according to claim 7, characterized in that: The environmental data includes browser type, version, device brand, model, operating system version, IP address and login time.
9. The cross-platform identity authentication and access control system according to claim 7, characterized in that: The encryption module comprises: The data division and encryption submodule is used to divide the user's identity information and access data into multiple information blocks, encrypt each information block using multiple symmetric encryption algorithms, and obtain the ciphertext data and key of each information block; The fitting operation submodule is used to construct a data matrix according to the ciphertext data and key of each information block, with the key as a row vector and the ciphertext data as a column vector, and generate a three-dimensional surface and a surface fitting equation by performing a surface fitting operation on the data matrix; The data storage submodule is used to store and process the generated ciphertext data, corresponding keys, data matrices, and surface fitting equations to form a complete encryption domain.
10. The cross-platform identity authentication and access control system according to claim 9, characterized in that: The symmetric encryption algorithms include: triple data encryption standard algorithm, blowing fish algorithm, Reeves cipher 2 algorithm, Reeves cipher 4 algorithm and triple data encryption algorithm.