Authentication method, authentication device, request device, computing device and medium

By actively generating and pre-sending encrypted authentication files on the authentication side, the problems of large service delay, low security and poor user experience in the prior art are solved, and lower latency, higher security and better user experience are achieved.

CN120110756APending Publication Date: 2025-06-06CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510269077.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The existing authentication methods have problems such as large service delay, low security and poor user experience.

Method used

By actively generating an encrypted authentication file on the authentication side and sending the file to the requesting side in advance, the requesting side can directly use the locally stored encrypted authentication file for authentication when it is necessary to start the service. This encrypted authentication file contains user information, permission information and validity period, ensuring that it is only allowed to use within the validity period.

Benefits of technology

Reduce service delays, improve user experience, and improve security through limiting validity periods to prevent unauthorized use of services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110756A_ABST
    Figure CN120110756A_ABST
Patent Text Reader

Abstract

The invention relates to an authentication method, an authentication device, a request device, a computing device and a medium, the authentication method applied to an authentication end comprises the following steps: actively generating authentication information, and generating an encrypted authentication file by using the authentication information, the authentication information comprising user information, authority information and a valid period; sending the encrypted authentication file to a request end indicated by the user information, so that the request end stores the encrypted authentication file, and sending the encrypted authentication file when a service needs to be started; and after the encrypted authentication file is received, analyzing the encrypted authentication file, verifying whether the permission information of the request end is valid or not according to the valid period obtained through analysis, and providing the application service allowed by the permission information for the request end under the condition that the permission information is valid. By implementing the authentication method provided by the invention, the problems of relatively large service delay, relatively low security, poor user experience and the like in the prior art can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of authentication technology, and in particular to an authentication method, an authentication device, a request device, a computing device and a medium. Background Art

[0002] In areas such as software distribution and cloud services, ensuring the legal use of services, preventing unauthorized access, and managing user permission information are critical issues.

[0003] In this regard, an authentication method based on an encrypted authentication file can be adopted. For example, when the requester starts the service, it first requests the authentication file of the authentication service provider. The authentication service provider generates an encrypted authentication file in response to the requester's request and sends the encrypted authentication file to the service requester. After the service requester obtains the encrypted authentication file, it uses the authentication file for authentication and service request.

[0004] Although this method improves security issues to a certain extent, it still has problems such as large service delay, low security and poor user experience. Summary of the invention

[0005] Based on this, the present application provides an authentication method, an authentication device, a request device, a computing device and a medium, which can improve problems such as large service delay, low security and poor user experience.

[0006] In the first aspect, the present application provides an authentication method, which is applied to an authentication end, and the authentication method includes: actively generating authentication information, and using the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, permission information, and validity period; sending the encrypted authentication file to the requesting end indicated by the user information, so that the requesting end stores the encrypted authentication file and feeds back the encrypted authentication file when the service needs to be started; after receiving the encrypted authentication file, parsing the encrypted authentication file, and verifying whether the permission information of the requesting end is valid based on the validity period obtained from the parsing, and if the permission information is valid, providing the requesting end with application services allowed by the permission information.

[0007] In combination with the first aspect, in a first possible implementation mode of the first aspect, the aforementioned active generation of authentication information and use of the authentication information to generate an encrypted authentication file includes: generating authentication information including user information, authority information and validity period according to a preset data structure, and serializing the authentication information to obtain serialized authentication information; encrypting the serialized authentication information using a preset encryption algorithm; generating a digital signature based on the encrypted authentication information, and encapsulating the encrypted authentication information and the digital signature to obtain an encrypted authentication file, wherein the digital signature is used to verify the integrity of the authentication information.

[0008] In combination with the first aspect, in a second possible implementation mode of the first aspect, the aforementioned parsing of the encrypted authentication file and verifying whether the permission information of the requesting end is valid based on the parsed validity period includes: parsing the encrypted authentication file to separate the encrypted authentication information; decrypting the encrypted authentication information according to a preset encryption algorithm; judging whether the current timestamp is within the validity period based on the validity period in the decrypted authentication information, and if so, determining that the permission information of the requesting end is valid.

[0009] In combination with the first aspect, in a third possible implementation of the first aspect, the aforementioned method also includes: monitoring changes in the permission information and / or validity period of the requesting end, and if changes are monitored, updating the authentication information, and generating a new encrypted authentication file using the updated authentication information; sending the new encrypted authentication file to the requesting end, so that the requesting end replaces the stored encrypted authentication file with the new encrypted authentication file, so that the next time the service needs to be started, authentication can be obtained by sending the new encrypted authentication file to the authentication end.

[0010] In the second aspect, the present application provides an authentication method, which is applied to the requesting end, and the authentication method includes: after receiving the encrypted authentication file, storing the encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and validity period; when the service needs to be started, sending the encrypted authentication file to the authentication end, so that the authentication end parses the validity period of the encrypted authentication file, and verifies whether the permission information is valid based on the validity period, and if the permission information is valid, provides application services allowed by the permission information.

[0011] In a third aspect, the present application provides an authentication system, which includes an authentication device and a requesting device, wherein the authentication device is used to execute the authentication method of the first aspect or any one of the implementations of the first aspect, and the requesting device is used to execute the second aspect or any one of the implementations of the second aspect.

[0012] In a fourth aspect, the present application provides an authentication device, which includes: a generation unit, which is used to actively generate authentication information and use the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, permission information and a validity period; a sending unit, which is used to send the encrypted authentication file to the requesting end indicated by the user information, so that the requesting end stores the encrypted authentication file and feeds back the encrypted authentication file when the service needs to be started; an authentication unit, which is used to parse the encrypted authentication file after receiving the encrypted authentication file, and verify whether the permission information of the requesting end is valid based on the validity period obtained by the analysis, and if the permission information is valid, provide the requesting end with application services allowed by the permission information.

[0013] In a fifth aspect, the present application provides a request device, which includes: a receiving unit, used to receive an encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and a validity period; a storage unit, used to store the encrypted authentication file; a sending unit, used to send the encrypted authentication file to the authentication end when the service needs to be started, so that the authentication end parses the validity period of the encrypted authentication file, verifies whether the permission information is valid based on the validity period, and provides application services permitted by the permission information when the permission information is valid.

[0014] In a sixth aspect, the present application provides an authentication method, which is applied to a computing device, and the computing device includes an authentication module and a request module. The authentication module is the authentication end in the first aspect, and the request module is the request end in the second aspect. The authentication method includes the authentication method implemented by the authentication end in the first aspect or any one of the implementation methods of the first aspect and the authentication method implemented by the request end in the second aspect or any one of the implementation methods of the second aspect. Specifically: the authentication module actively generates authentication information, and uses the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, permission information and a validity period; the authentication module sends the encrypted authentication file to the request end indicated by the user information; after receiving the encrypted authentication file, the request module stores the encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and a validity period; when the request module needs to start a service, the request module sends the encrypted authentication file to the authentication end; after receiving the encrypted authentication file, the authentication module parses the encrypted authentication file, and verifies whether the permission information of the request end is valid according to the validity period obtained by the parsing, and when the permission information is valid, provides the application service allowed by the permission information to the request end.

[0015] In a seventh aspect, the present application provides a computing device comprising an authentication module and a request module, wherein the authentication module is used for the authentication method of the first aspect or any one of the embodiments of the first aspect, and the request module is used to execute the second aspect or any one of the embodiments of the second aspect.

[0016] In an eighth aspect, the present application also provides a computing device, comprising a processor, a transceiver and a memory, wherein the processor, the transceiver and the memory are connected via a bus; the processor is used to execute multiple instructions; the transceiver is used to exchange data with other devices; the memory is used to store multiple instructions, wherein the instructions are suitable for being loaded by the processor and executing an authentication method such as the first aspect or any one of the embodiments of the first aspect, or executing the second aspect or any one of the embodiments of the second aspect, or executing the sixth aspect or any one of the embodiments of the sixth aspect.

[0017] In the ninth aspect, the present application also provides a computer-readable storage medium, in which a plurality of instructions are stored, and the instructions are suitable for being loaded by a processor and executing an authentication method such as the first aspect or any one of the embodiments of the first aspect, or executing the second aspect or any one of the embodiments of the second aspect.

[0018] In summary, the present application provides an authentication method, an authentication device, a requesting device, a computing device and a medium, wherein the authentication end actively generates encrypted authentication information before the requesting end requests a service, and sends the encrypted authentication information to the requesting end in advance, so that the requesting end stores the encrypted authentication file locally, and when the service needs to be started, the locally stored encrypted authentication information is directly used for authentication. There is no need to first request the encrypted authentication file, thereby reducing service latency and improving user experience. At the same time, since the encrypted authentication information also adds a validity period, even if the requesting end obtains the encrypted authentication information in advance, it cannot request services without restriction, thereby improving security. In general, by implementing the technical solution of the present application, service latency can be reduced, and security and user experience can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 A flowchart of an authentication method based on an authentication terminal in an embodiment of the present application; Figure 2 A flowchart of an authentication method based on a requesting end in an embodiment of the present application; Figure 3 A flowchart of an authentication method based on an authentication system in an embodiment of the present application; Figure 4 A schematic block diagram of an authentication device in an embodiment of the present application; Figure 5 A schematic block diagram of a requesting device in an embodiment of the present application; Figure 6 A structural block diagram of a computing device in one embodiment of the present application. DETAILED DESCRIPTION

[0020] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0021] In response to the problems of large service delay and poor user experience in current authentication methods, the present application proposes an authentication method, wherein the authentication method applied to the authentication end actively generates an encrypted authentication file, and sends the encrypted authentication file to the requesting end in advance before the requesting end requests the encrypted authentication file, so that the requesting end stores the pre-received encrypted authentication file locally, and when the service needs to be started, the encrypted authentication information is directly obtained from the local storage, and the encrypted authentication file is sent to the authenticator without having to request the encrypted authentication file from the authentication end, thereby reducing service delay and improving user experience.

[0022] At the same time, the current authentication method still has security issues, especially when the authentication end sends the encrypted authentication file to the requesting end in advance, the security problem may be aggravated, and the encrypted authentication file provided by the present application is a time-limited encrypted authentication file, which ensures that the authorization is only valid within a specific time period and automatically expires after it expires, thereby improving the dynamic security of the system. Therefore, the present application can improve the problem of low security when the encrypted authentication file is sent in advance by limiting the validity period of the encrypted authentication file. Even if the requesting end obtains the encrypted authentication file in advance, it cannot use the encrypted authentication file without restriction, and service permission cannot be obtained when the validity period is not met.

[0023] It should be noted that the authentication end and the requesting end proposed in the present application can be integrated in a computing device. For example, the authentication end and the requesting end can be two modules in a computing device. In addition, the authentication end and the requesting end can also be two independent devices, that is, the authentication end is the authentication device, and the requesting end is the requesting device. The computing device, the authentication device and the requesting device can be servers, terminal devices, etc. In addition, the computing device, the authentication device and the requesting device can exchange data with other servers, terminal devices, etc., and execute the authentication method proposed in the present application.

[0024] In order to better understand the authentication method applied to the authentication end proposed in this application, this application also provides an embodiment, such as Figure 1 As shown, next, this application takes the authentication end as the execution subject and describes the method in detail: 110: The authentication end actively generates authentication information, and uses the authentication information to generate an encrypted authentication file; 120: the authenticator sends the encrypted authentication file to the requester indicated by the user information, so that the requester stores the encrypted authentication file and feeds back the encrypted authentication file when it is necessary to start the service; 130: After receiving the encrypted authentication file, the authenticator parses the encrypted authentication file and verifies whether the permission information of the requester is valid according to the validity period obtained by the parsing. If the permission information is valid, the authenticator provides the application service permitted by the permission information to the requester.

[0025] Among them, the authentication information includes user information, permission information and validity period. After actively generating authentication information, the authentication end uses the authentication information to generate an encrypted authentication file. Actively generating authentication information and encrypted authentication files means that the authentication end spontaneously generates authentication information and encrypted authentication files, rather than passively triggering the generation of authentication information and encrypted authentication files after the request end requests to obtain encrypted authentication information. Encrypted authentication information is obtained through encryption, combination, encapsulation and other operations, and its security, integrity and transportability can be effectively guaranteed. By encrypting authentication files, the confidentiality of sensitive information during storage and transmission is ensured to prevent unauthorized access and theft by others.

[0026] Regarding the process of generating authentication information in step 110, in a specific practicable manner, the step of actively generating authentication information includes: the authentication end generates authentication information including user information, authority information, and validity period according to a preset data structure, and serializes the authentication information to obtain serialized authentication information. The serialized authentication information is a byte stream, and the authentication information is serialized so that the serialized authentication information can be subsequently encrypted.

[0027] For example, define the data structure: use the data structure of the Java class (such as LicenseInfo) to define the structure of the authentication information, including fields such as user ID (ID, Identification), service ID (ID, Identification), and validity period. In this data structure, the user ID is used to represent user information, and the service ID is used to represent permission information. The permission information includes the services that the requesting end can obtain from the authenticating end; create an object: instantiate the LicenseInfo object and set the corresponding field values; select a serialization framework: select a serialization framework and use a JSON library (such as Jackson or Gson) to serialize the LicenseInfo object into a string in JSON format; convert to a byte stream: convert a string in JSON format into a byte stream to complete serialization to create the authentication information.

[0028] With respect to the process of generating an encrypted authentication file using authentication information in step 110, in one possible implementation method, the step of generating an encrypted authentication file using authentication information includes: the authentication end encrypts the serialized authentication information using a preset encryption algorithm; generates a digital signature based on the encrypted authentication information, and encapsulates the encrypted authentication information and the digital signature to obtain an encrypted authentication file, wherein the digital signature is used to verify the integrity of the authentication information.

[0029] The preset encryption algorithm is used to ensure that the authentication information is not leaked, while the digital signature can ensure the integrity and authenticity of the data and prevent the file from being maliciously tampered with during transmission or storage. Adding a digital signature allows the requesting end to verify the digital signature after receiving the encrypted authentication file to identify whether the encrypted authentication file is complete, authentic, and has not been tampered with. If the verification is successful, the encrypted authentication file is stored, otherwise the encrypted authentication file is discarded.

[0030] Encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and encryption algorithms combining symmetric encryption and asymmetric encryption. For example, symmetric encryption algorithms include Advanced Encryption Standard (AES) algorithms, asymmetric encryption algorithms include RSA (Rivest-Shamir-Adleman) algorithms, and encryption algorithms combining asymmetric encryption include Dual Keystream Encryption Algorithm (DKEA), etc. In addition, encryption algorithms also include Attribute-Based Encryption (ABE) algorithms, or blockchain-based authentication mechanisms.

[0031] The AES algorithm is a symmetric encryption algorithm that uses the same key for encryption and decryption. The AES algorithm is efficient and highly secure, and can resist a variety of known cryptographic attacks, such as differential attacks and linear attacks. It is particularly suitable for the encryption of large amounts of data, such as network communications and data storage. The RSA algorithm is an asymmetric encryption algorithm. The RSA encryption algorithm uses public and private keys for encryption and decryption respectively. The public key is used to encrypt data, and the private key is used to decrypt data. As long as the private key is not leaked, the data is safe. The DKEA algorithm is a customized encryption algorithm that combines the characteristics of symmetric encryption and asymmetric encryption. The algorithm uses two independent key streams to encrypt data. One key stream is generated by the user's private key to enhance security, and the other key stream is generated by the server's public key and the user's private key to ensure data integrity and non-repudiation. The ABE algorithm allows encrypted data to be access controlled based on user attributes (such as roles, permission information, etc.). Users can only decrypt data when they meet a specific set of attributes. The algorithm provides more fine-grained access control, without the need to generate independent keys for each user, reducing the complexity of key management. It is particularly suitable for scenarios that require complex access control policies, such as cloud computing and the Internet of Things. The blockchain-based authentication mechanism takes advantage of the immutability and decentralization of the blockchain to store authentication information and authorization credentials on the blockchain. Users can prove their identity and access corresponding resources through private keys. This mechanism improves the security and credibility of data and reduces dependence on centralized institutions. It is particularly suitable for scenarios that require high security and transparency, such as finance and supply chain management.

[0032] In order to better understand the aforementioned encryption process, this application uses an encryption algorithm combining a symmetric encryption algorithm and an asymmetric encryption algorithm as a preset encryption algorithm to illustrate the encryption process by example, specifically: When the preset algorithm is an asymmetric encryption algorithm, the aforementioned step of encrypting the serialized authentication information using the preset encryption algorithm includes: the authentication end generates a key pair using the asymmetric encryption algorithm, and encrypts the serialized authentication information using the public key of the key pair to obtain encrypted authentication information, wherein the key pair includes a public key and a private key; confidentially stores the private key of the key pair, and discloses the public key of the key pair.

[0033] In addition, when decrypting, the authentication end can use the private key to decrypt the encrypted authentication information. Only the authentication end that has the authentication end's private key can correctly encrypt and decrypt data.

[0034] For example, when encrypting, the authenticator uses Java's KeyPairGenerator class to generate an RSA key pair, including a public key and a private key, and then uses Java's Cipher class, configured in RSA encryption mode, and uses the public key to encrypt the serialized authentication information. When decrypting, the private key is used for decryption.

[0035] In the case where the preset algorithm is the DKEA algorithm, the aforementioned step of encrypting the serialized authentication information using the preset encryption algorithm includes: the authentication end and the server respectively generate a pair of key pairs, and publish the public key and store the private key confidentially; the authentication end uses the private key of the authentication end to randomly generate a private key key stream: the authentication end combines the public key of the requesting end with the private key of the authentication end, and uses a preset complex function (a combination of a preset complex function such as a hash function and a key expansion algorithm) to process the combined key to obtain a mixed key stream; the serialized authentication information is encrypted using the private key key stream and the mixed key stream to obtain the encrypted authentication information. In addition, when decrypting the authentication information, the authentication information can be decrypted using the private key key stream and the mixed key stream. Only the authentication end that has the private key of the authentication end and the public key of the requesting end can correctly generate two key streams to encrypt and decrypt data.

[0036] For example, in the process of encrypting authentication information, the authenticator divides the serialized authentication information into multiple data blocks, performs operations (such as XOR operations, addition operations, etc.) on each data block and the corresponding parts of the two key streams (private key stream and mixed key stream) to obtain encrypted data blocks, and then combines the encrypted data blocks into an encrypted authentication file.

[0037] In addition, in order to better understand the aforementioned process of generating an encrypted authentication file based on the encrypted authentication information, this application describes the generation of a digital signature and the encapsulation of an encrypted authentication file, specifically: The aforementioned step of encrypting the serialized authentication information using a preset encryption algorithm includes: calculating the encrypted authentication information using a preset encryption algorithm, or performing hash calculation on the encrypted authentication information, calculating the hash value of the encrypted authentication information using a preset encryption algorithm, and converting the calculation result into a byte stream to obtain a digital signature.

[0038] For example, the authentication end creates a signature object, for example, using Java's Signature class, configured with an RSA signature algorithm (such as SHA256withRSA) to create a signature object; using a private key to initialize the signature object; passing the encrypted authentication information or the hash value of the encrypted authentication information to the signature object for update; calling the sign method of the signature object to generate a digital signature and convert it into a byte stream.

[0039] The aforementioned step of generating a digital signature based on the encrypted authentication information and encapsulating the encrypted authentication information and the digital signature to obtain an encrypted authentication file includes: combining the encrypted authentication information and the digital signature and writing them into a file to obtain an encrypted authentication file, for example, using Java's IO class (such as FileOutputStream) to write the combined data into the authentication file, the written data content can be json, xml, etc., and the file suffix name can be customized with any suffix name to ensure information security.

[0040] In an implementable manner, the present application also uses code obfuscation technology to improve the security of encrypted authentication files, especially when the authentication end and the request end are integrated in a computing device. By using code obfuscation technology, the security risks existing in the integrated solution can be greatly improved. Because compared with the remote independent deployment solution, the authentication encrypted file has a greater risk of human decryption in the integrated solution. In order to reduce the risk of exposure of the authentication service, the present application can greatly increase the difficulty of decrypting the authentication encrypted file by using obfuscation technology. Specifically, select an obfuscation tool: use a Java code obfuscation tool (such as ProGuard or yGuard); configure obfuscation rules: write an obfuscation rule file to specify which classes, methods or fields need to retain their original names and which need to be obfuscated; run the obfuscation tool: use Java source code or compiled bytecode as input; run the obfuscation tool to generate obfuscated code; replace the original code: replace the obfuscated code into the project to ensure that the obfuscated code is used when generating the encrypted authentication file. Among them, the obfuscation rule is usually a .pro or .pg extension, for example: #Specify input jar, war, ear package or directory -injars bin / classes -outjars bin / classes-processed.jar #Specify classes and members that are not obfuscated

[0041] # Keep the main class and its main method from being confused

[0042] # Keep enum classes from being obfuscated

[0043] Accordingly, when restoring an encrypted authentication file that uses obfuscation technology, you can obtain the mapping file generated by the obfuscation tool. The file records the correspondence between the codes before and after obfuscation. By using the mapping file, you can restore the obfuscated code, or you can use the de-obfuscation function to restore the obfuscated code. For example, ProGuard provides a tool called ReTrace, which can use the mapping file to restore the obfuscated stack trace information.

[0044] For step 120, the authenticating end sends an encrypted authentication file to the requesting end, allowing the requesting end to feedback the encrypted authentication file for authentication when the service is determined by the demand, and after the authentication is passed, the authenticating end provides the requesting end with the application service permitted by the permission information in the encrypted authentication file within the validity period of the encrypted authentication service. After receiving the encrypted authentication file, the requesting end stores the encrypted authentication file locally, and can also verify the integrity and authenticity of the authentication information based on the digital signature when the encrypted authentication file includes a digital signature to prevent tampering by a third party, and only after the verification is passed will the verified encrypted authentication file be stored locally.

[0045] For step 130, after receiving the encrypted authentication file, the authenticating end parses out the user information, permission information and validity period therein, and authenticates the requesting end based on the parsed information, including determining whether the user information is consistent with the user information of the requesting end, identifying the services allowed to be provided to the requesting end in the permission information, and determining whether the current timestamp is within the validity period. If the current timestamp is not within the validity period, it is determined that the permission information of the requesting end is invalid. If the current timestamp is within the validity period, it is determined that the permission information of the requesting end is valid. If the user information is consistent with the user information of the requesting end and the permission information is valid, the application services permitted by the permission information are provided to the requesting end.

[0046] In a specific implementable manner, the aforementioned parsing of the encrypted authentication file and verifying whether the permission information of the requesting end is valid based on the parsed validity period includes: parsing the encrypted authentication file to separate the encrypted authentication information; decrypting the encrypted authentication information according to a preset encryption algorithm; judging whether the current timestamp is within the validity period based on the validity period in the decrypted authentication information, and if so, determining that the permission information of the requesting end is valid.

[0047] Among them, after receiving the encrypted authentication file, the authentication end uses, for example, Java's IO class (such as FileInputStream) to read the encrypted authentication file, and then parses the encrypted authentication file to separate the encrypted authentication information, and uses the encryption algorithm used during encryption to decrypt the encrypted authentication information to obtain the user information, permission information and validity period in the encrypted information. For example, Java's Cipher class is used, configured in RSA decryption mode, and the encrypted authentication information is decrypted using a private key, and the decrypted authentication information is deserialized into a LicenseInfo object, and then it is determined whether the current timestamp is within the validity period based on the limited period in the LicenseInfo object. If it is within the validity period, it is determined that the permission information of the requesting end is valid, otherwise it is invalid.

[0048] In addition, when the encrypted authentication information includes a digital signature, the authentication end needs to separate the digital signature in the encrypted authentication file when parsing the encrypted authentication file, and verify the integrity and authenticity of the encrypted authentication information based on the digital signature. For example, use Java's Signature class, configured with the same encryption algorithm as when generating the digital signature; use the public key to initialize the signature object; pass the encrypted authentication information or the hash value of the encrypted authentication information to the signature object for updating; call the verify method of the signature object to verify the digital signature. If the verification passes, it means that the encrypted authentication information is complete, authentic and has not been tampered with. Otherwise, it is incomplete and authentic.

[0049] It should be noted that the validity period can be a time period or a duration. If the validity period is a time period, the authentication end determines whether the permission information is valid by determining whether the current time period is within the validity period during authentication. If the current timestamp is within the validity period, the permission information is determined to be valid. If the current timestamp is not within the validity period, the permission information is determined to be invalid. If the validity period is a duration, when the authentication end generates an encrypted authentication file using the authentication information, the timestamp when the encrypted authentication file is generated is encapsulated in the encrypted authentication file, so that when the authentication file is authenticated, the timestamp of the encrypted authentication file is used as the starting point to determine whether the current timestamp is within the time period from the timestamp of the encrypted authentication file. If so, the permission information is determined to be valid. If not, the permission information is determined to be invalid.

[0050] In the case where the validity period is a certain period of time, in an implementable manner, this application uses a dynamic sliding window time verification mechanism (DSWTV) to verify whether the permission information of the requesting end is valid. DSWTV is a time control mechanism based on the concept of timestamp and sliding window, which is used to verify the validity of encrypted authentication files. Different from the traditional fixed validity period verification, DSWTV allows the validity period to be dynamically adjusted within a certain range to adapt to different application scenarios and needs, specifically: The aforementioned step of generating an encrypted authentication file using authentication information includes: the authentication end generates a timestamp for indicating the time point when the encrypted authentication file is generated, and encapsulates the timestamp with the encrypted authentication information and the digital signature to obtain the encrypted authentication file; The aforementioned steps of parsing the encrypted authentication file to separate the encrypted authentication information and decrypting the encrypted authentication information according to a preset encryption algorithm include: after receiving the encrypted authentication file, the authentication end parses the encrypted authentication file according to a preset encryption algorithm to separate the timestamp and the encrypted authentication information in the encrypted authentication file, and then decrypts the encrypted authentication information to obtain the user information, the authority information and the validity period; The aforementioned step of judging whether the current timestamp is within the validity period according to the validity period in the authentication information obtained by decryption, and if so, determining that the permission information of the requesting end is valid, includes: using a sliding window to represent the validity period in the encrypted authentication file, the validity period is, for example, 1 hour, 1 day, etc., the authenticating end compares the current timestamp with the timestamp of the encrypted authentication file, if the current timestamp is within the range of the timestamp of the encrypted authentication file and the sum of the sliding window size, the encrypted authentication file is considered valid, if the timestamp exceeds this range, the encrypted authentication file is considered invalid.

[0051] It should be noted that the size of the sliding window can be adjusted dynamically. Administrators can adjust the size of the sliding window by modifying the validity period of the authentication information to adapt to different security requirements and business scenarios. For example, shorten the window size during sensitive operations to improve security, and extend the window size during routine operations to improve user experience.

[0052] It can be seen that since the authenticator provides the requester with a time-limited encrypted authentication file, the security of the authentication can be improved. However, due to time limitations, the same encrypted authentication file cannot be applied to all situations. After the requester's permission information and validity period change, the requester cannot obtain correct authentication using the outdated encrypted authentication file previously received, resulting in increased service delay.

[0053] For example, after the permission information and validity period of the requesting end change, the requesting end sends an outdated encrypted authentication file to the authenticating end when it needs to request a service. After the authenticating end finds that the encrypted authentication file sent by the requesting end fails the authentication and that the encrypted authentication file is outdated, the authenticating end can update the authentication information, and then use the updated authentication information to generate a new encrypted authentication file, and send the new encrypted authentication file to the requesting end, so that the requesting end resends the new encrypted authentication file to the authenticating end for authentication, and starts the service after the new encrypted authentication file passes the authentication. Therefore, if the authenticating end finds that the encrypted authentication file is outdated when the requesting end needs to start the device, it will cause a large service delay.

[0054] Based on this, in order to further reduce service delays while ensuring security, the present application provides a specific implementation method to achieve real-time updating of encrypted authentication files. The authentication method applied to the authentication end also includes: monitoring changes in the permission information and / or validity period of the requesting end. If changes are detected, the authentication information is updated and a new encrypted authentication file is generated using the updated authentication information; the new encrypted authentication file is sent to the requesting end, so that the requesting end replaces the stored encrypted authentication file with the new encrypted authentication file, so that the next time the service needs to be started, authentication can be obtained by sending the new encrypted authentication file to the authentication end.

[0055] Among them, the authentication end monitors the changes in the service information or validity period of the requesting end in real time. If the service information or validity period of the requesting end changes, the authentication information is actively updated, and a new encrypted authentication file is generated using the updated authentication information, and then the new encrypted authentication file is sent to the requesting end, so that the requesting end replaces the outdated encrypted authentication file with the new encrypted authentication file to complete the real-time update of the encrypted authentication file. When the requesting end needs to start the service at any time after the update, it directly obtains the new encrypted authentication file from the local storage for authentication, eliminating the process of authentication failure and regeneration of new encrypted authentication files, thereby shortening the service delay.

[0056] Compared with some other authentication methods, the authentication method used in this application takes into account the advantages of security, low service latency, flexibility, stability, simple implementation and low cost. Specifically: Enhanced security: The encrypted authentication file is encrypted using a preset encryption algorithm. Especially when the encrypted authentication file uses asymmetric encryption technology, key leakage can be prevented. The private key is kept securely by the service provider, and the public key is used to encrypt the authentication information. In this way, even if the encrypted authentication file is stolen, it cannot be decrypted without the private key, which greatly reduces the risk of key leakage. Prevent tampering, and the encrypted authentication file uses hash functions and digital signature technology to ensure that the information in the authentication file is not tampered with during transmission and storage.

[0057] Improved usability: Seamless integration: the verification process of the authentication file can be seamlessly integrated into the service startup process, and users can enjoy the service without additional operations. This reduces the burden on users and improves user experience; cross-platform support: encrypted authentication files can be used on different operating systems and platforms, without the need to develop authentication mechanisms for each platform separately; fast response: by optimizing the authorization verification process, user waiting time can be reduced, and the response speed and performance of the application can be improved.

[0058] Implement time limit: Flexible authorization strategy. The encrypted authentication file can contain information such as timestamp and validity period to limit the use time of the service. This provides users with more flexible and accurate authorization strategies and meets the needs of different scenarios. In addition, this method is simple and stable to implement and is not easily affected by network connection conditions.

[0059] Reduce costs: Reduce hardware costs. Compared with hardware lock solutions, encrypted authentication files do not require additional hardware equipment, which reduces user costs. Reduce maintenance costs. Software-based authentication mechanisms are easier to update and maintain, reducing maintenance costs for service providers.

[0060] Improve the flexibility of authorization management: Flexible authorization supports multiple authorization strategies, such as role-based access control (RBAC) and attribute-based access control (ABAC), to meet the authorization requirements of different application scenarios; dynamic adjustment, administrators can remotely update or revoke authorization without redeploying applications, which improves the flexibility and response speed of authorization management; multi-user support supports simultaneous access by multiple users, and allocates independent permission information to each user through encrypted authentication files to achieve fine-grained permission information control.

[0061] Simplified deployment and maintenance: One-click deployment integrates authorization information in encrypted authentication files, which simplifies the application deployment process and reduces deployment difficulty and cost; centralized management, through centralized management of encrypted authentication files, can easily achieve unified application authorization and permission information changes, reducing maintenance costs; compatibility, supports multiple operating systems and Java versions, with good compatibility and scalability.

[0062] Compliance with regulatory requirements: Compliance, meeting industry standards and regulatory requirements, such as GDPR, HIPAA, etc., to ensure the privacy protection and compliance of user data; audit tracking, providing detailed audit logs to record key information in the authorization verification process to facilitate subsequent security audits and compliance checks.

[0063] Some other authentication methods, for example: in the authentication method based on simple key verification, the user starts the service by purchasing or obtaining a key. However, the security of this method is relatively low because the key is easy to be copied or leaked. In addition, this method cannot implement complex functions such as time limit; in the authentication method based on hardware lock, a hardware lock (such as a USB dongle) is used to verify the user's authorization. Although this method improves security to a certain extent, it increases the burden and cost of the user and is not flexible enough; in the authentication method based on software registration code, the user activates the service by entering the software registration code. However, the registration code may also be cracked or shared, resulting in unauthorized access. The security of this method is relatively low. In addition, this method is also difficult to implement complex functions such as time limit; in the authentication method based on network, the user needs to connect to the service provider's server through the Internet for authentication. Although this method can implement more complex authentication logic and time limit functions, it relies on network connection and may be affected by network delays or interruptions, and there are problems of complex and unstable implementation.

[0064] In order to better understand the authentication method applied to the requesting end proposed in this application, this application also provides an embodiment, such as Figure 2 As shown, next, this application takes the request end as the execution subject and describes the method in detail: 210: After receiving the encrypted authentication file sent by the authenticator, the requester stores the encrypted authentication file; 220: When the requesting end needs to start the service, the requesting end sends the encrypted authentication file to the authenticating end, so that the authenticating end parses the validity period in the encrypted authentication file, verifies whether the permission information is valid according to the validity period, and provides the application service permitted by the permission information if the permission information is valid.

[0065] Among them, the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and validity period. After receiving the encrypted authentication information, the requesting end stores the encrypted authentication information locally, obtains the encrypted authentication information from the local storage when the service needs to be started, and sends the encrypted authentication information to the authentication end. After the authentication is passed by the authentication end, the application service allowed in the permission information is requested.

[0066] In one feasible method, if the encrypted authentication information also includes a digital signature, then after receiving the encrypted authentication file, the requesting end parses the digital signature and the encrypted authentication information before storing the encrypted authentication information locally, and uses the digital signature to verify the integrity and authenticity of the encrypted authentication information to prevent tampering by a third party, and only after the verification is passed will the verified encrypted authentication file be stored locally.

[0067] In one feasible manner, after receiving the new information encrypted authentication file, the requesting end replaces the stored encrypted authentication file with the new encrypted authentication file, so that the next time the service needs to be started, the new permission information and / or validity period can be obtained by sending the new encrypted authentication file to the authenticating end.

[0068] The present application also provides an authentication system, which includes an authentication device and a requesting device, wherein the authentication device is used to execute the aforementioned authentication method applied to the authentication end, and the requesting device executes the aforementioned authentication method applied to the authentication end.

[0069] For example, if Figure 3 As shown, the authentication server (authentication device) generates an authentication information containing user information, permission information, validity period and other data, and then uses a predefined encryption algorithm (such as AES, RSA, etc.) and a key to encrypt the authentication information, and encapsulates the encrypted authentication information together with a timestamp, a digital signature, etc. into an encrypted authentication file. After encapsulation, the encrypted authentication file is sent to the requesting end (requesting device), such as a user device, a client application, etc. The requesting end verifies the integrity of the file. When the encrypted authentication file includes a digital signature, the digital signature is verified. After the verification is passed, the encrypted authentication file is securely stored locally (such as encrypted storage, a security chip, etc.). The requesting end sends the encrypted authentication file to the authentication server before starting the service; the authentication server uses a predefined decryption algorithm and key to decrypt the encrypted authentication file, and verifies whether the authentication file is within the validity period. If the verification is passed, the user information, permission information, etc. are extracted, and they are used for subsequent identity authentication and authorization processes. In addition, if the encrypted authentication file is updated, the authentication server sends the updated encrypted authentication file to the requesting end, so that the requesting end stores the updated encrypted authentication file securely locally for use when the service needs to be started later.

[0070] The present application also provides an authentication device and a request device. The embodiments of the present application can divide the functional modules of the device according to the above method examples. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiments of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0071] like Figure 4As shown, the authentication device specifically includes: a generating unit 410, which is used to actively generate authentication information and generate an encrypted authentication file using the authentication information, wherein the authentication information includes user information, permission information and validity period; a sending unit 420, which is used to send the encrypted authentication file to the requesting end indicated by the user information, so that the requesting end stores the encrypted authentication file and feeds back the encrypted authentication file when the service needs to be started; an authentication unit 430, which is used to parse the encrypted authentication file after receiving the encrypted authentication file, and verify whether the permission information of the requesting end is valid according to the validity period obtained by the parsing, and if the permission information is valid, provide the requesting end with the application service allowed by the permission information.

[0072] In an implementable manner, the aforementioned generation unit 410 is specifically used to: generate authentication information including user information, permission information and validity period according to a preset data structure, and serialize the authentication information to obtain serialized authentication information; encrypt the serialized authentication information using a preset encryption algorithm; generate a digital signature based on the encrypted authentication information, and encapsulate the encrypted authentication information and the digital signature to obtain an encrypted authentication file, wherein the digital signature is used to verify the integrity of the authentication information.

[0073] In one implementable manner, the aforementioned authentication unit 430 is specifically used to: parse the encrypted authentication file to separate the encrypted authentication information; decrypt the encrypted authentication information according to a preset encryption algorithm; determine whether the current timestamp is within the validity period based on the validity period in the decrypted authentication information, and if so, determine that the permission information of the requesting end is valid.

[0074] In one implementable manner, the aforementioned generation unit 410 is also used to monitor changes in the permission information and / or validity period of the requesting end. If changes are detected, the authentication information is updated and a new encrypted authentication file is generated using the updated authentication information; the aforementioned sending unit 420 is also used to send the new encrypted authentication file to the requesting end, so that the requesting end replaces the stored encrypted authentication file with the new encrypted authentication file, so that the next time the service needs to be started, authentication can be obtained by sending the new encrypted authentication file to the authentication end.

[0075] like Figure 5 As shown, the requesting device specifically includes: a receiving unit 510, which is used to receive an encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and validity period; a storage unit 520, which is used to store the encrypted authentication file; a sending unit 530, which is used to send the encrypted authentication file to the authentication end when the service needs to be started, so that the authentication end parses the validity period of the encrypted authentication file, verifies whether the permission information is valid based on the validity period, and provides application services permitted by the permission information when the permission information is valid.

[0076] The present application also provides an authentication method, which is applied to a computing device, wherein the computing device includes an authentication module and a request module, wherein the authentication module is the aforementioned authentication end, and the request module is the aforementioned request end. The authentication method includes the aforementioned authentication end and the authentication method implemented by the request end, specifically: the authentication module actively generates authentication information, and uses the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, permission information and a validity period; the authentication module sends the encrypted authentication file to the request end indicated by the user information; after receiving the encrypted authentication file, the request module stores the encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and a validity period; when the service needs to be started, the request module sends the encrypted authentication file to the authentication end; after receiving the encrypted authentication file, the authentication module parses the encrypted authentication file, and verifies whether the permission information of the request end is valid based on the validity period obtained by the parsing, and when the permission information is valid, provides the application service allowed by the permission information to the request end.

[0077] The present application also provides a computing device, which includes an authentication module and a request module, the authentication module is the aforementioned authentication end, and the request module is the aforementioned request end, wherein the authentication module is used to execute the authentication method executed by the authentication end in any of the aforementioned implementation modes, and the request module is used to execute the authentication method executed by the request end in any of the aforementioned implementation modes, specifically: the authentication module is used to actively generate authentication information, and use the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, authority information and validity period, and sends the encrypted authentication file to the request end indicated by the user information, so that the request end stores the encrypted authentication file and feeds back the encrypted authentication file when the service needs to be started, and upon receiving the encrypted authentication file After encrypting the authentication file, the encrypted authentication file is parsed, and the validity of the permission information of the requesting end is verified based on the validity period obtained by the parsing. If the permission information is valid, the application service permitted by the permission information is provided to the requesting end; a request module is used to store the encrypted authentication file after receiving it, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and a validity period. When the service needs to be started, the encrypted authentication file is sent to the authentication end, so that the authentication end parses the validity period of the encrypted authentication file, verifies whether the permission information is valid based on the validity period, and provides the application service permitted by the permission information if the permission information is valid.

[0078] The present application also provides a computing device, which may include: a processor 610, a transceiver 620 and a memory 630. The above-mentioned processor and memory are connected via a bus 640. The processor 610 is used to execute multiple instructions; the transceiver 620 is used to exchange data with other devices; the memory 630 is used to store multiple instructions, and the instructions are suitable for being loaded by the processor and executing the aforementioned authentication method. Among them, the processor 610 can be an electronic control unit (Electronic Control Unit, ECU), a central processing unit (central processing unit, CPU), a general processor, a coprocessor, a digital signal processor (digital signal processor, DSP), an application-specific integrated circuit (application-specific integrated circuit, ASIC), a field programmable gate array (field programmable gate array, FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The processor 610 can also be a combination that realizes computing functions, such as a combination of one or more microprocessors, a combination of 5SP and a microprocessor, etc. In this embodiment, the processor can use a single-chip microcomputer, and various control functions can be realized by programming the single-chip microcomputer. The processor has the advantages of powerful computing power and fast processing.

[0079] When the computing device is used to implement the authentication method of the authentication end, the processor 610 of the computing device is specifically used to execute the function of the generation unit 410, which is used to actively generate authentication information and use the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, permission information and validity period; the processor 610 is also used to execute the function of the authentication unit 430, which is used to parse the encrypted authentication file after receiving the encrypted authentication file, and verify whether the permission information of the request end is valid according to the validity period obtained by the parsing, and if the permission information is valid, provide the request end with the application service allowed by the permission information. The transceiver 620 is used to execute the function of the sending unit 420, which is used to send the encrypted authentication file to the request end indicated by the user information, so that the request end stores the encrypted authentication file and feeds back the encrypted authentication file when the service needs to be started.

[0080] In one implementable manner, the processor 610 is specifically used to: generate authentication information including user information, permission information and validity period according to a preset data structure, and serialize the authentication information to obtain serialized authentication information; encrypt the serialized authentication information using a preset encryption algorithm; generate a digital signature based on the encrypted authentication information, and encapsulate the encrypted authentication information and the digital signature to obtain an encrypted authentication file, wherein the digital signature is used to verify the integrity of the authentication information.

[0081] In one implementable manner, the processor 610 is specifically used to: parse the encrypted authentication file to separate the encrypted authentication information; decrypt the encrypted authentication information according to a preset encryption algorithm; determine whether the current timestamp is within the validity period based on the validity period in the decrypted authentication information, and if so, determine that the permission information of the requesting end is valid.

[0082] In one implementable manner, the processor 610 is also used to monitor changes in the permission information and / or validity period of the requesting end. If changes are detected, the authentication information is updated and a new encrypted authentication file is generated using the updated authentication information; the transceiver 620 is also used to send the new encrypted authentication file to the requesting end, so that the requesting end replaces the stored encrypted authentication file with the new encrypted authentication file, so that the next time the service needs to be started, authentication can be obtained by sending the new encrypted authentication file to the authentication end.

[0083] When the computing device is used to implement the authentication method of the requesting end, the transceiver 620 of the computing device is used to execute the function of the receiving unit 510, which is used to receive the encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and validity period; it is also used to execute the function of the sending unit, which is used to send the encrypted authentication file to the authentication end when the service needs to be started, so that the authentication end can parse the validity period of the encrypted authentication file, and verify whether the permission information is valid according to the validity period, and if the permission information is valid, provide the application service allowed by the permission information. The memory 520 is also used to execute the function of the storage unit, which is used to store the encrypted authentication file. The processor 610 is used to perform integrity verification based on the encrypted authentication file.

[0084] When the computing device is used to implement the authentication method of the authentication end and the requesting end, the processor 610 of the computer is used to execute the function of the authentication module, which is used to actively generate authentication information and use the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, permission information and a validity period, and send the encrypted authentication file to the requesting end indicated by the user information. After receiving the encrypted authentication file, the encrypted authentication file is parsed, and whether the permission information of the requesting end is valid according to the validity period obtained by the parsing is verified. If the permission information is valid, the application service allowed by the permission information is provided to the requesting end; the processor 610 is also used to execute the function of the requesting module, which is used to store the encrypted authentication file after receiving the encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, permission information and a validity period. When a service needs to be started, the encrypted authentication file is sent to the authentication end, so that the authentication end parses the validity period of the encrypted authentication file, verifies whether the permission information is valid according to the validity period, and provides the application service allowed by the permission information if the permission information is valid.

[0085] In one embodiment, the present application also provides a computer-readable storage medium, in which a plurality of instructions are stored, and the instructions are suitable for being loaded by a processor and executing the method in any of the foregoing embodiments. The processor is used to execute the plurality of instructions; the memory is used to store the plurality of instructions, and the instructions are loaded by the processor and execute the authentication method in the foregoing embodiment.

[0086] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0087] The above embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.

Claims

1. An authentication method, applied to an authentication end, characterized in that: include: Actively generate authentication information, and use the authentication information to generate an encrypted authentication file, wherein the authentication information includes user information, authority information, and validity period; Sending the encrypted authentication file to the requesting end indicated by the user information, so that the requesting end stores the encrypted authentication file and feeds back the encrypted authentication file when a service needs to be started; After receiving the encrypted authentication file, the encrypted authentication file is parsed, and whether the permission information of the requesting end is valid is verified according to the validity period obtained by the parsing. If the permission information is valid, the application service permitted by the permission information is provided to the requesting end.

2. The method according to claim 1, characterized in that: The actively generating authentication information and using the authentication information to generate an encrypted authentication file includes: Generate authentication information including user information, authority information and validity period according to a preset data structure, and serialize the authentication information to obtain serialized authentication information; Encrypting the serialized authentication information using a preset encryption algorithm; A digital signature is generated according to the encrypted authentication information, and the encrypted authentication information and the digital signature are encapsulated to obtain an encrypted authentication file, wherein the digital signature is used to verify the integrity of the authentication information.

3. The method according to claim 1, characterized in that The step of parsing the encrypted authentication file and verifying whether the permission information of the requesting end is valid according to the parsed validity period includes: Parsing the encrypted authentication file to separate the encrypted authentication information; Decrypting the encrypted authentication information according to a preset encryption algorithm; It is determined whether the current timestamp is within the validity period according to the validity period in the authentication information obtained by decryption. If it is within the validity period, it is determined that the permission information of the requesting end is valid.

4. The method according to claim 1, characterized in that The method further comprises: Monitor changes in the permission information and / or validity period of the requesting end, and if changes are detected, update the authentication information and generate a new encrypted authentication file using the updated authentication information; The new encrypted authentication file is sent to the requesting end, so that the requesting end replaces the stored encrypted authentication file with the new encrypted authentication file, so that when the service needs to be started next time, the authentication is obtained by sending the new encrypted authentication file to the authenticating end.

5. An authentication method, applied to a requesting end, characterized in that: include: After receiving the encrypted authentication file, storing the encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, authority information and validity period; When the service needs to be started, the encrypted authentication file is sent to the authentication end, so that the authentication end parses the validity period of the encrypted authentication file, verifies whether the permission information is valid according to the validity period, and provides the application service allowed by the permission information if the permission information is valid.

6. An authentication system, characterized in that: The authentication system comprises an authentication device and a requesting device, wherein the authentication device is used to execute the authentication method according to any one of claims 1 to 4, and the requesting device is used to execute the authentication method according to claim 5.

7. An authentication device, characterized in that: The authentication device is an authentication terminal, which specifically includes: A generating unit, used to actively generate authentication information, and generate an encrypted authentication file using the authentication information, wherein the authentication information includes user information, authority information, and validity period; a sending unit, configured to send the encrypted authentication file to the requesting end indicated by the user information, so that the requesting end stores the encrypted authentication file and feeds back the encrypted authentication file when a service needs to be started; The authentication unit is used to parse the encrypted authentication file after receiving it, and verify whether the permission information of the requesting end is valid according to the validity period obtained by the parsing, and provide the application service allowed by the permission information to the requesting end if the permission information is valid.

8. A requesting device, characterized in that: The requesting device is a requesting end, which specifically includes: A receiving unit, configured to receive an encrypted authentication file, wherein the encrypted authentication file includes authentication information, and the authentication information includes user information, authority information, and validity period; A storage unit, used to store the encrypted authentication file; The sending unit is used to send the encrypted authentication file to the authentication end when the service needs to be started, so that the authentication end can parse the validity period of the encrypted authentication file, verify whether the permission information is valid according to the validity period, and provide the application service allowed by the permission information if the permission information is valid.

9. A computing device, characterized in that The computing device includes a processor, a transceiver and a memory, wherein the processor, the transceiver and the memory are connected via a bus; the processor is used to execute multiple instructions; the transceiver is used to exchange data with other devices; the memory is used to store the multiple instructions, and the instructions are suitable for being loaded by the processor and executing the authentication method described in any one of claims 1 to 4, or for being loaded by the processor and executing the authentication method described in claim 5.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the authentication method described in any one of claims 1 to 4, or being loaded by a processor and executing the authentication method described in claim 5.