PUF-NFC-based identity interaction authentication method, apparatus and device, and storage medium
Through the PUF-NFC-based identity interaction authentication method, the dynamic key and virtual environment are used to perform user interaction authentication, which solves the shortcomings of the existing technology in terms of security and user experience, and realizes an efficient, secure and interesting identity authentication process.
Patent Information
- Application Number
- CN202510208663.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing identity authentication technology has shortcomings in terms of security and user experience, especially in VR/AR scenarios, traditional NFC tags are susceptible to cloning and replay attacks, and PUF technology is used separately with limited efficiency and compatibility.
The identity interactive authentication method based on PUF-NFC is adopted. By obtaining the PUF-NFC tag of the user equipment, extracting the dynamic key, starting the virtual environment for user interaction authentication, encrypting the user operation data using encryption algorithms and dynamic keys, and sending it to the backend server through a secure communication protocol for verification.
It improves the security and fun of identity authentication, reduces the risk of man-in-the-middle attacks, and enhances the reliability and user experience of identity authentication.
Smart Images

Figure CN120165872A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of identity authentication, and particularly to an identity interaction authentication method, device, equipment, and storage medium based on PUF-NFC. Background Art
[0002] In the current digital age, with the wide application of the Internet and intelligent devices, identity authentication technology plays a crucial role in ensuring information security and user privacy. Traditional identity authentication methods have problems such as being easily cracked and privacy leakage, and the user experience is poor. With the rapid development of mobile devices and VR (Virtual Reality) / AR (Augmented Reality) technology, authentication technology needs to balance efficiency and security. Especially in the VR / AR scenario, immersive interaction has higher requirements for convenience and real-time performance. Although the existing NFC tag authentication effectively improves security, it is vulnerable to cloning and replay attack threats, and there are compatibility and user experience problems in the integration with VR / AR devices. Physically Unclonable Functions (PUF) technology generates unique identifiers using hardware characteristics and has the advantage of anti-cloning, but its efficiency and compatibility are limited when applied alone.
[0003] Therefore, there is an urgent need for an identity interaction authentication method that integrates PUF-NFC technology and VR / AR technology to achieve a more secure, efficient, and user-friendly identity authentication process. Summary of the Invention
[0004] According to the embodiments of the present application, an identity interaction authentication solution based on PUF-NFC is provided, which can improve the security and interest of identity authentication and greatly reduce security risks such as man-in-the-middle attacks.
[0005] In the first aspect of the present application, an identity interaction authentication method based on PUF-NFC is provided.
[0006] The method includes:
[0007] Obtain the PUF-NFC tag of the user device and extract the dynamic key from the PUF-NFC tag;
[0008] Start the virtual environment according to the dynamic key, and the user performs user interaction authentication in the virtual environment;
[0009] When the user device passes the user interaction authentication, encrypt the user operation data using an encryption algorithm and the dynamic key, and send the encrypted user operation data to the background server through a secure communication protocol;
[0010] The background server decrypts the encrypted user operation data according to the dynamic key and the encryption algorithm, then compares and verifies the user information in the user operation data with the user information stored in the database, and sends the verification result information to the user device.
[0011] In a possible implementation, the dynamic key is the PUF response value output by the physical unclonable function in the PUF-NFC tag on the user device.
[0012] In a possible implementation, a virtual environment is started according to the dynamic key, and the user performs user interaction authentication in the virtual environment, including:
[0013] Score the user's performance in the user interaction authentication and feedback it to the user in real time;
[0014] Adjust the difficulty of the questions in the user interaction authentication according to the score;
[0015] When the sum of the scores reaches the passing threshold, the user passes the user interaction authentication.
[0016] Optionally, the method further includes:
[0017] When the number of failures of the user in the user interaction authentication reaches the failure threshold, send a prompt message to the user according to the user's performance in the user interaction authentication.
[0018] In a possible implementation, the user interaction authentication includes knowledge quizzes, scenario puzzles, and dynamic challenges;
[0019] The knowledge quiz is dynamically selected in the knowledge base according to the user's identity information and the type of the virtual environment;
[0020] The scenario puzzles include maze puzzles, jigsaw puzzles, and logic puzzles;
[0021] The dynamic challenges include gesture recognition, body pose challenges, and action sequence challenges.
[0022] In a possible implementation, the encryption algorithm uses the national cipher SM4 algorithm.
[0023] In a possible implementation, the method further includes:
[0024] The secure communication protocol includes the national cipher SSL protocol and the QUIC protocol;
[0025] When sending the encrypted user operation data to the background server through the secure communication protocol, dynamically select the secure communication protocol according to the data type of the user operation data.
[0026] In a second aspect of the present application, there is provided an identity interaction authentication device based on PUF-NFC.
[0027] The device includes:
[0028] An acquisition module, configured to acquire a PUF-NFC tag of a user device and extract a dynamic key from the PUF-NFC tag;
[0029] A virtual authentication module, configured to start a virtual environment according to the dynamic key, and the user performs user interaction authentication in the virtual environment;
[0030] A transmission module, configured to, when the user device passes the user interaction authentication, encrypt user operation data by using an encryption algorithm and the dynamic key, and send the encrypted user operation data to a background server through a secure communication protocol;
[0031] A verification module, where the background server decrypts the encrypted user operation data according to the dynamic key and the encryption algorithm, then compares and verifies the user information in the user operation data with the user information stored in a database, and sends a verification result message to the user device.
[0032] In a third aspect of the present application, an electronic device is provided. The electronic device includes: a memory and a processor, where a computer program is stored on the memory, and when the processor executes the program, the method described above is implemented.
[0033] In a fourth aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method according to the first aspect of the present application is implemented.
[0034] The identity interaction authentication method based on PUF-NFC provided in the embodiments of the present application obtains a PUF-NFC tag of a user device, extracts a dynamic key from the PUF-NFC tag, then starts a virtual environment according to the dynamic key, and the user performs user interaction authentication in the virtual environment. When the user device passes the user interaction authentication, user operation data is encrypted by using an encryption algorithm and the dynamic key, and the encrypted user operation data is sent to a background server through a secure communication protocol. The background server decrypts the encrypted user operation data according to the dynamic key and the encryption algorithm, then compares and verifies the user information in the user operation data with the user information stored in a database, and sends a verification result message to the user device, realizing efficient and secure identity interaction authentication, enhancing the reliability of identity authentication while increasing the fun.
[0035] It should be understood that the content described in the summary of the invention is not intended to limit the key or important features of the embodiments of the present application, nor to limit the scope of the present application. Other features of the present application will become easily understood through the following description. Description of the Drawings
[0036] In conjunction with the accompanying drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present application will become more apparent. In the drawings, the same or similar reference numerals denote the same or similar elements, where:
[0037] Figure 1 is a flowchart of a PUF-NFC-based identity interaction authentication method according to an embodiment of the present application;
[0038] Figure 2 is a flowchart of a user interaction authentication method in a virtual environment according to an embodiment of the present application;
[0039] Figure 3 is a schematic diagram of multi-factor authentication according to an embodiment of the present application;
[0040] Figure 4 is a block diagram of a PUF-NFC-based identity interaction authentication device according to an embodiment of the present application;
[0041] Figure 5 is a schematic structural diagram of a terminal device or a server suitable for implementing the embodiments of the present application. Detailed implementation manners
[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by a person of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the scope of protection of the present disclosure.
[0043] In addition, the term "and / or" in this document is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally represents an "or" relationship between the preceding and following associated objects.
[0044] Figure 1 is a flowchart of a PUF-NFC-based identity interaction authentication method according to an embodiment of the present application. Refer to Figure 1 , the method includes:
[0045] S101, obtain the PUF-NFC tag of the user device, and extract the dynamic key from the PUF-NFC tag.
[0046] Among them, the PUF-NFC tag is a secure tag that combines the Physical Unclonable Function (PUF) and Near Field Communication (NFC) technology. PUF is a hardware-based security technology that utilizes the physical characteristics of semiconductor devices to generate unique and unpredictable outputs, which can be used as keys or other security parameters. Since they are very sensitive to even minor physical changes, they are difficult to copy or clone. NFC is a short-range wireless communication technology that allows non-contact data exchange between electronic devices. NFC tags usually contain an RFID chip and can communicate with NFC-enabled devices (such as smartphones). The PUF-NFC tag combines the uniqueness of PUF and the convenient communication ability of NFC. The PUF is responsible for generating a unique dynamic key or identity information, and then the NFC is responsible for transmitting the generated PUF response value to the verification end.
[0047] In this embodiment, extracting the dynamic key from the PUF-NFC tag improves the security in verification and reduces the risk of key leakage.
[0048] Optionally, the dynamic key is the PUF response value output by the Physical Unclonable Function in the PUF-NFC tag on the user device.
[0049] In this embodiment, using the PUF response value output by the Physical Unclonable Function in the PUF-NFC tag as the dynamic key provides a secure, efficient, and reliable dynamic key generation method.
[0050] S102, Start the virtual environment according to the dynamic key, and the user performs user interaction authentication in the virtual environment.
[0051] The construction of the virtual environment can be divided into three parts: 3D modeling, real-time rendering, and spatial perception. First, in the 3D modeling part, the polygon modeling system is used as the basis, and the geometry details are iteratively refined through the subdivision surface algorithm. The weighted average formula of the subdivision surface algorithm is as follows:
[0052] P new =(1 - ω)P old +ω·avg(P neighbors ),
[0053] Among them, P new is the newly generated vertex coordinate, P old is the original vertex coordinate, P neighborsis the neighboring vertex coordinates of the original fixed-point coordinates, and ω is the weight hyperparameter. Subsequently, data structures such as the vertex coordinates, normal vectors, and texture coordinates of the basic geometric body are topologically optimized to generate a composite scene model that includes terrain, building clusters, and vegetation ecology. In the real-time rendering part, based on the physically-based rendering (PBR) technology, a complete rendering pipeline covering vertex shaders and fragment shaders is constructed. Then, the lighting model equation is used to accurately calculate the lighting parameters and material reflection characteristics. The formula of the lighting model equation is as follows:
[0054] L out = L diffuse ·(1 - F)+L specular ·F,
[0055] where L out is the reflected light value of vertex L, L diffuse is the diffuse reflection value, L specular is the specular reflection value, and F is the lighting weight hyperparameter. Finally, in the spatial perception dimension part, the simultaneous localization and mapping (SLAM) algorithm is used as the neural center of environmental interaction. Then, by fusing multi-modal data from camera images, depth sensors, and inertial measurement units (IMUs), the motion estimation equation is used to achieve centimeter-level positioning accuracy. The formula of the motion estimation equation is as follows:
[0056]
[0057] where T t is the positioning value at the t-th moment, T t-1 is the positioning value at the (t - 1)-th moment, and ΔT t is the difference in the positioning values at the t-th moment.
[0058] In this embodiment, a virtual environment provides an isolated space, which can protect the user interaction authentication process from malware and further protect the user's privacy and device security.
[0059] Optionally, the virtual environment is started according to a dynamic key, and the user performs user interaction authentication in the virtual environment, including:
[0060] Scoring the user's performance in the user interaction authentication and providing real-time feedback to the user;
[0061] Adjusting the difficulty of the questions in the user interaction authentication according to the score;
[0062] When the sum of the scores reaches the qualified threshold, the user passes the user interaction authentication.
[0063] Figure 2 Flowchart of a method for performing user interaction authentication in a virtual environment according to an embodiment of the present application, as shown in FIG. Figure 2 shown.
[0064] Among them, the difficulty of the questions in the user interaction authentication can be adjusted according to the score. For example, the difficulty of the questions in the user interaction authentication is divided into elementary, intermediate and advanced levels. The elementary questions are simple knowledge questions and answers, such as "Where does the sun rise from?", etc. The intermediate questions are scene puzzles, such as finding the key in the virtual room, etc., and the advanced questions are complex action challenges. The total score of each question is 10 points. If the user scores 3 points in the advanced question, which does not reach the qualified score threshold of 6 points for the question, then, in order to ensure that the user is always in a state of moderate challenge, the difficulty of the questions in the user interaction authentication is adjusted to intermediate. In addition, when the user completes multiple questions quickly and continuously and reaches the corresponding qualified score threshold, the difficulty of the questions in the user interaction authentication can be automatically increased. For example, when the user completes 3 elementary questions quickly and continuously and the scores are all higher than the corresponding qualified score threshold of 6 points, the difficulty of the questions in the user interaction authentication can be adjusted to intermediate. Finally, when the total score of the user in the user interaction certification reaches the qualified threshold, the user passes the user interaction certification. For example, the number of questions in the user interaction certification is 10, the qualified threshold is 60, and the total score of the user in the user interaction certification is 85, then the user passes the user interaction certification.
[0065] Furthermore, when the rating is fed back to the user, the feedback interface can be further optimized, so that the user can understand his or her performance in real time through the integration of visual, auditory and text feedback. Visual feedback includes but is not limited to progress bars, prompts and success animations. For example, when the user makes an error, the correct operation is prompted by animation, and after the user completes the puzzle, a celebration animation is played to enhance the user's sense of achievement; auditory feedback includes but is not limited to background music and sound effect prompts. For example, in tense advanced questions, tense music is played, and when the user operates correctly or incorrectly, corresponding sound effects are played, such as "ding" for correctness and "du" for error; text feedback includes but is not limited to real-time ratings and encouraging texts. For example, in scene puzzle problems, if the user successfully finds the key and opens the door, "Success! +10 points" is immediately displayed, and a celebration animation is played. In action challenge problems, after the user completes a difficult gymnastics move, he or she will get feedback of "perfect! +50 points" and unlock more advanced user interaction authentication problems.
[0066] In this embodiment, when a user performs user interaction authentication in a virtual environment, a real-time scoring and feedback mechanism can help the user improve the accuracy and efficiency of authentication. Moreover, by dynamically adjusting the difficulty of questions, not only is security improved, but the overall user experience is also enhanced.
[0067] Optionally, the method further includes:
[0068] When the number of failure times of the user in user interaction authentication reaches the failure threshold, a prompt message is sent to the user according to the user's performance in user interaction authentication.
[0069] For example, if the user fails to answer the knowledge quiz questions in user interaction authentication continuously for 5 times, and the failure threshold is 5 times, then a prompt message "Your security authentication attempt has failed five times. Please check your security question answers or contact customer support for help" will be sent to the user.
[0070] In this embodiment, sending a prompt message when the number of failure times of user interaction authentication reaches the failure threshold not only helps to enhance the user's security awareness and operation skills, but also effectively protects system resources and improves the overall security and user experience.
[0071] Optionally, user interaction authentication includes knowledge quizzes, scenario puzzles, and dynamic challenges;
[0072] Knowledge quizzes are dynamically selected in the knowledge base according to the user's identity information and the type of virtual environment;
[0073] Scenario puzzles include maze puzzles, jigsaw puzzles, and logic puzzles;
[0074] Dynamic challenges include gesture recognition, body posture challenges, and action sequence challenges.
[0075] Among them, the knowledge quiz questions generated according to the user's identity information include but are not limited to security questions, industry-related questions, and random questions. For example, according to the personal security questions preset by the user during registration, such as the name of a pet, the surname of a high school head teacher, etc. In addition, the types of virtual environments include but are not limited to finance, construction, and official business, etc. The knowledge quiz questions generated according to the type of virtual environment can be monetary policy tools for users in the financial industry, etc. And the knowledge quiz questions generated according to the knowledge base are conventional life or calculation questions, such as "1 + 1 =?" etc. These knowledge quiz questions are all to ensure that only the correct user can provide accurate answers.
[0076] In the scenario puzzle-solving problem, the user needs to complete a series of puzzle-solving tasks in a virtual environment. For example, in the maze puzzle-solving problem, the user enters the virtual environment and completes specific puzzle-solving tasks (such as finding hidden items, etc.). Specific puzzle-solving tasks include but are not limited to maze puzzle-solving, jigsaw puzzle-solving, and logic puzzle-solving, all of which are realized through the 3D modeling technology and VR (Virtual Reality) / AR (Augmented Reality) mentioned above. Among them, in maze puzzle-solving, the user enters a virtual maze with multiple levels, and each level has specific puzzle-solving tasks. The user needs to find clues hidden in the maze, such as opening a certain hidden door to find a specific item (such as a key), etc.; in jigsaw puzzle-solving, the user needs to complete a jigsaw puzzle in the virtual environment. The pieces of the jigsaw puzzle are distributed in different scenes. The user needs to find all the pieces and correctly assemble them. After the jigsaw puzzle is completed, the next step of identity authentication is triggered; in logic puzzle-solving, the user enters a virtual room with multiple mechanisms that need to be solved. The user needs to observe and reason to solve the mechanisms, such as finding a hidden password lock and entering the correct password, etc.
[0077] In the dynamic challenge problem, through gesture recognition, body posture challenges, and action sequence challenges, every action of the user is accurately captured and analyzed, ensuring the accuracy and security of authentication. In the gesture recognition problem, the user needs to make specific gestures in the virtual environment. For example, draw a specific figure or make specific gesture actions. In the body posture challenge problem, the user needs to complete a series of body posture actions in the virtual environment. For example, imitate the dance movements or gymnastic movements of a virtual character. In the action sequence challenge problem, the user needs to complete a series of actions in a specific order. For example, pass through a series of obstacles in the virtual environment. The user device uses action capture technology (such as a camera or sensor) to capture the user's dynamic actions. Then, the user's action data is encrypted through an encryption algorithm and transmitted to the background service. After being decrypted by the background service, it is compared with a preset action template to score the user's dynamic actions, and then determine whether it is correct.
[0078] In this embodiment, the user interaction authentication provides a diversified, highly interactive, and secure authentication process, which can not only effectively protect the background server from illegal access, but also provide a richer and more friendly user experience.
[0079] S103, when the user device passes the user interaction authentication, it encrypts the user operation data using an encryption algorithm and a dynamic key, and sends the encrypted user operation data to the background server through a secure communication protocol.
[0080] In this embodiment, the use of dynamic keys and encryption algorithms ensures the security of user operation data during transmission, effectively preventing data from being stolen or tampered with. In addition, the secure communication protocol guarantees the integrity and confidentiality of data during transmission.
[0081] Optionally, the encryption algorithm adopts the national cryptographic SM4 algorithm.
[0082] Among them, the national cryptographic SM4 algorithm is a symmetric key encryption algorithm released by the State Cryptography Administration of China, and its official name is "GM / T 0002-2012 SM4 Block Cipher Algorithm". First, the national cryptographic SM4 algorithm divides the 128-bit dynamic key into 4 32-bit round keys. Then, through 32 rounds of iterative operations, non-linear transformation and linear transformation are performed on the keys in each round key to obtain new round keys. Finally, the newly generated round keys are combined into a 128-bit encryption key to achieve efficient and secure data encryption of the dynamic key.
[0083] In this embodiment, the national cryptographic SM4 algorithm has characteristics such as high security, high efficiency, easy implementation, and good compatibility, and plays an important role in the field of identity authentication.
[0084] Optionally, the method further includes:
[0085] The secure communication protocol includes the national cryptographic SSL protocol and the QUIC protocol;
[0086] When sending the encrypted user operation data to the background server through the secure communication protocol, the secure communication protocol is dynamically selected according to the data type of the user operation data.
[0087] Among them, the national secret SSL protocol and the QUIC protocol are two important protocols in modern network security communication. The national secret SSL protocol is a secure transport layer protocol formulated by the China National Cryptography Administration, which supports national secret algorithms such as national secret SM2, national secret SM3, and national secret SM4. It is designed specifically to protect the security of network data transmission. It has been widely used in fields such as finance, government affairs, and e-commerce, not only ensuring the confidentiality and integrity of data during transmission, but also providing end-to-end security through the digital certificate mechanism. The QUIC protocol (Quick UDP Internet Connections) is a new network protocol developed by Google, aiming to improve the speed and security of network connections. It achieves a reliability mechanism similar to TCP (Transmission Control Protocol) on UDP (User Datagram Protocol), and at the same time integrates the encryption function of TLS (Transport Layer Security), providing users with a fast and secure network experience and being able to effectively handle network fluctuations and latency issues.
[0088] In the present invention, the secure communication protocol can be dynamically selected according to the data type of the user operation data. For example, when authenticating the identity of the user during sensitive operations (such as login, transfer, and financial transactions, etc.), the national secret SSL protocol is automatically selected for data transmission to ensure the high security of sensitive data. When the user performs general data browsing, non-sensitive information query, or needs to establish a quick connection and has low latency (such as online games) and other identity authentications, the QUIC protocol is automatically selected, thereby improving the data transmission speed and user experience.
[0089] In this embodiment, the most suitable secure communication protocol is dynamically selected according to the data type of the user operation data, improving the communication efficiency and being able to more effectively utilize server and network resources.
[0090] S104, the background server decrypts the encrypted user operation data according to the dynamic key and the encryption algorithm, then compares and verifies the user information in the user operation data with the user information stored in the database, and sends the verification result information to the user device.
[0091] Among them, when decrypting the encrypted user operation data according to the dynamic key and the encryption algorithm, the decryption is still performed according to the national secret SM4 algorithm. First, the received 128-bit dynamic key is divided into 4 32-bit round keys, and the order of the round keys is opposite to that during encryption. Then, nonlinear transformation and linear transformation are performed on the keys in each round key through 32 rounds of iterative operations to obtain the original round keys. Finally, the original round keys are spliced into the original 128-bit key.
[0092] In this embodiment, the background server compares and verifies the received user information with the user information stored in the database, improving the accuracy of verification. Moreover, it promptly feedbacks the verification result information to the user, enhancing the user experience.
[0093] Figure 3 Schematic diagram of multi-factor authentication according to an embodiment of the present application, as Figure 3 shown.
[0094] In a possible implementation manner, during the overall identity interaction authentication process, multi-factor authentication can be further used to ensure the security and reliability of the authentication process. Multi-factor authentication can include biometric identification and system security authentication. In the biometric identification part, by introducing dedicated biometric sensors, such as fingerprint modules, iris recognition devices, etc., latent biometric signals such as users' micro-expressions and iris tremors are periodically collected during the identity interaction authentication process to achieve dynamic identity maintenance. In the system security authentication part, passive defense is achieved through abnormal behavior detection. For example, when an abnormal login attempt is detected (such as accessing the core system from an overseas IP at 3 am), a multi-level response mechanism is automatically triggered, including but not limited to secondary biometric authentication, freezing of sensitive operation permissions, starting full-session video recording, and generating a forensic package. The abnormal behavior detection uses the normal behavior data of users collected historically as a training set to train the abnormal detection model, and then monitors the users' behavior in real time, inputs the users' behavior into the abnormal detection model for prediction, realizes real-time monitoring of abnormal behavior, and promptly discovers and blocks potential security threats.
[0095] According to the embodiments of the present disclosure, the following technical effects are achieved:
[0096] 1) A "one-time one-key" dynamic key is generated through NFC-PUF. Utilizing the physical unclonable feature, it ensures the uniqueness of key generation and the anti-physical replication ability, blocking the risk of tag forgery at the source.
[0097] 2) User interaction authentication is carried out in a virtual environment, providing an isolated secure environment for users, blocking the snooping or injection attacks of malware on sensitive operations (such as password input), and forming a three-dimensional protection for hardware - environment - data.
[0098] 3) After the background server synchronizes and decrypts the dynamic key, it conducts user comparison in combination with the database, double-verifying the legitimacy of the user identity and further improving the reliability of identity authentication.
[0099] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0100] The above is the introduction of the method embodiments. The following further illustrates the solution of this application through device embodiments.
[0101] Figure 4 The block diagram of the identity interaction authentication device based on PUF-NFC according to an embodiment of the present application is shown. As Figure 4 shown, it includes:
[0102] An acquisition module 401, configured to acquire a PUF-NFC tag of a user device and extract a dynamic key from the PUF-NFC tag;
[0103] A virtual authentication module 402, configured to start a virtual environment according to the dynamic key, and the user performs user interaction authentication in the virtual environment;
[0104] A transmission module 403, configured to, when the user device passes the user interaction authentication, encrypt user operation data by using an encryption algorithm and the dynamic key, and send the encrypted user operation data to a background server through a secure communication protocol;
[0105] A verification module 404, the background server decrypts the encrypted user operation data according to the dynamic key and the encryption algorithm, then compares and verifies the user information in the user operation data with the user information stored in a database, and sends a verification result message to the user device.
[0106] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the described modules can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0107] Figure 5 The structural schematic diagram of a terminal device or a server suitable for implementing the embodiments of the present application is shown.
[0108] As Figure 5As shown, the terminal device or server includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 502 or the program loaded from the storage section 508 into the random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the terminal device or server are also stored. The CPU 501, ROM 502, and RAM 503 are connected to each other via a bus 504. The input / output (I / O) interface 505 is also connected to the bus 504.
[0109] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed so that a computer program read from it can be installed into the storage section 508 as needed.
[0110] Specifically, according to the embodiments of the present application, the above method flow steps can be implemented as a computer software program. For example, the embodiments of the present application include a computer program product, which includes a computer program carried on a machine-readable medium, and the computer program contains program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 509, and / or installed from the removable medium 511. When the computer program is executed by the central processing unit (CPU) 501, the above functions defined in the system of the present application are executed.
[0111] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0112] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code, and the foregoing module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0113] The units or modules involved in the embodiments described in this application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. Among them, the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.
[0114] As another aspect, this application also provides a computer-readable storage medium. The computer-readable storage medium can be included in the electronic device described in the foregoing embodiments; or it can exist alone without being assembled into the electronic device. The foregoing computer-readable storage medium stores one or more programs, and when the foregoing programs are executed by one or more processors, they implement the methods described in this application.
[0115] The above description is only a preferred embodiment of this application and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the application involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions described in this application.
Claims
1. A PUF-NFC-based identity interaction authentication method, characterized in that: include: Obtain a PUF-NFC tag of a user device, and extract a dynamic key from the PUF-NFC tag; Starting a virtual environment according to the dynamic key, and the user performing user interaction authentication in the virtual environment; When the user device passes the user interaction authentication, the user operation data is encrypted using an encryption algorithm and the dynamic key, and the encrypted user operation data is sent to the backend server through a secure communication protocol; The backend server decrypts the encrypted user operation data according to the dynamic key and the encryption algorithm, compares and verifies the user information in the user operation data with the user information stored in the database, and sends verification result information to the user device.
2. The identity interactive authentication method based on PUF-NFC according to claim 1, characterized in that: The dynamic key is a PUF response value output by a physical unclonable function in the PUF-NFC tag on the user device.
3. The identity interactive authentication method based on PUF-NFC according to claim 1, characterized in that: The step of starting a virtual environment according to the dynamic key and the user performing user interaction authentication in the virtual environment includes: Score the user's performance in the user interaction authentication and provide real-time feedback to the user; adjusting the difficulty of questions in the user interaction authentication according to the score; When the sum of the scores reaches a qualified threshold, the user passes the user interaction authentication.
4. The identity interactive authentication method based on PUF-NFC according to claim 3 is characterized in that: The method further comprises: When the number of failures of the user in the user interaction authentication reaches a failure threshold, a prompt message is sent to the user according to the performance of the user in the user interaction authentication.
5. The identity interactive authentication method based on PUF-NFC according to claim 1, characterized in that: The user interaction authentication includes knowledge quizzes, scene puzzle solving and dynamic challenges; The knowledge question and answer is dynamically selected from the knowledge base according to the identity information of the user and the type of the virtual environment; The scene puzzles include maze puzzles, jigsaw puzzles and logic puzzles; The dynamic challenges include gesture recognition, body posture challenges and action sequence challenges.
6. The identity interactive authentication method based on PUF-NFC according to claim 1, characterized in that: The encryption algorithm adopts the national encryption SM4 algorithm.
7. The identity interactive authentication method based on PUF-NFC according to claim 1, characterized in that: The method further comprises: The secure communication protocols include the national secret SSL protocol and the QUIC protocol; When the encrypted user operation data is sent to the background server via the secure communication protocol, the secure communication protocol is dynamically selected according to the data type of the user operation data.
8. An identity interactive authentication device based on PUF-NFC, characterized in that: include: An acquisition module, used to acquire a PUF-NFC tag of a user device and extract a dynamic key from the PUF-NFC tag; A virtual authentication module, used to start a virtual environment according to the dynamic key, and the user performs user interaction authentication in the virtual environment; A transmission module, used for encrypting user operation data using an encryption algorithm and the dynamic key when the user device passes the user interaction authentication, and sending the encrypted user operation data to a backend server through a secure communication protocol; The verification module is composed of the backend server decrypting the encrypted user operation data according to the dynamic key and the encryption algorithm, then comparing and verifying the user information in the user operation data with the user information stored in the database, and sending the verification result information to the user device.
9. An electronic device comprising a memory and a processor, wherein a computer program is stored in the memory, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Server NFC security management system and method based on dynamic key
CN121968103A
A dynamic key-based server NFC security management system and method
CN121968103B