Real person authentication method and system

By implementing a real-person password-free authentication system on the device side, using the private key signature and the signature verification mechanism of the digital identity verification server, combining identity information and facial information for verification, the problems of privacy leakage and network dependence in the existing technology are solved, and efficient and secure real-person authentication is achieved.

CN120180414APending Publication Date: 2025-06-20WUXI RONGKA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510279330.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing practical authentication technology has the risks of privacy leakage, network dependence, poor user experience, security issues, high costs and compatibility issues, and it is difficult to effectively solve these problems.

Method used

A real-person password-free system based on the device is adopted. By initiating an authentication request to the application server, generating data to be signed, signing with a private key and sending it to the digital identity authentication server for signature verification, combining identity information and facial information for identity verification, and generating an identity token certificate to ensure privacy and security.

Benefits of technology

While ensuring privacy and security, it simplifies user operations, improves authentication efficiency, reduces costs, and enhances system compatibility and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180414A_ABST
    Figure CN120180414A_ABST
Patent Text Reader

Abstract

The invention discloses a real person authentication method and system. The real person authentication method according to the embodiment of the invention comprises the following steps: initiating an authentication request to an application server; generating data to be signed; signing the to-be-signed data by using a private key to obtain signed data; the signature data is sent to a digital identity authentication server, a signature verification result of the digital identity authentication server on the signature data is received, and the signature verification result is provided for the application server; the signature verification result is used for judging whether real person authentication is passed or not. According to the real person authentication system and method provided by the embodiment of the invention, the privacy security is ensured, the user operation is simplified, and the authentication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of real-person authentication, and particularly to a real-person authentication method and system. Background Art

[0002] With the development of the Internet, more and more enterprises and institutions have migrated business handling to the online platform, such as bank account opening, loan applications, large-amount transfers, and social security services. These services require real-person authentication technology to ensure the authenticity of user identities and prevent identity theft and fraud.

[0003] Existing real-person authentication mainly involves document OCR recognition, face recognition, liveness detection, and face comparison. However, these technologies have disadvantages such as privacy leakage risks, network dependence, poor user experience, security issues, high costs, and compatibility problems. There is an urgent need to improve the existing technologies in terms of enhancing security and user experience, strengthening privacy protection, optimizing network dependence, simplifying the authentication process, reducing costs, and enhancing compatibility.

[0004] Therefore, there is a need for a new real-person authentication method and system that can overcome the above problems. Summary of the Invention

[0005] In view of the above problems, the purpose of the present invention is to provide a real-person authentication method and system, especially a real-person passwordless system based on the device side, which simplifies user operations and improves the efficiency of authentication while ensuring privacy and security.

[0006] According to one aspect of the present invention, there is provided a real-person authentication method, including:

[0007] Sending an authentication request to an application server;

[0008] Generating data to be signed;

[0009] Signing the data to be signed with a private key to obtain signed data;

[0010] Sending the signed data to a digital identity verification server and receiving the verification result of the signed data by the digital identity verification server,

[0011] wherein the verification result is provided to the application server;

[0012] The verification result is used to determine whether the real-person authentication is passed.

[0013] Optionally, the real-person authentication method further includes:

[0014] Collecting identity information and face information;

[0015] Obtaining identity verification information based on the identity information and the face information;

[0016] Send the authentication information to the digital identity authentication server for authentication.

[0017] Wherein, after the authentication is passed, the digital identity authentication server generates an identity token certificate; the identity token certificate includes a public key that matches the private key, and the public key is used by the digital identity authentication server to verify the signature data.

[0018] The digital identity authentication server generates a first public key and a first private key that matches the first public key.

[0019] The mobile terminal receives the first public key and stores the first public key in the secure storage environment of the mobile terminal; the mobile terminal uses the first public key to encrypt the identity information and the face information to obtain the authentication information.

[0020] Optionally, after the authentication request is sent to the application server, the real-person authentication method further includes:

[0021] Receiving a challenge value feedback by the application server.

[0022] Wherein, the challenge value is included in the signature data.

[0023] Optionally, before using the private key to sign the data to be signed to obtain the signature data, the real-person authentication method further includes:

[0024] Performing biometric authentication.

[0025] Optionally, the real-person authentication method further includes:

[0026] After the real-person authentication is passed, binding the real-person authentication and the biometric authentication.

[0027] After binding the real-person authentication and the biometric authentication, passing the biometric authentication is equivalent to passing the real-person authentication.

[0028] Optionally, the real-person authentication method further includes:

[0029] Sending a registration request to the application server.

[0030] Receiving a registration challenge value feedback by the application server.

[0031] Generating registration request data including the registration challenge value.

[0032] Signing the registration request data to obtain request signature data.

[0033] Send the request signature data to the digital identity authentication server and receive the signature verification result of the request signature data from the digital identity authentication server,

[0034] wherein, the signature verification result of the request signature data is used to determine whether the registration request passes.

[0035] Optionally, the real-person authentication method further includes:

[0036] After sending an authentication request to the application server, receive the challenge value feedback by the application server;

[0037] Assemble the data to be signed and call system authentication;

[0038] After performing biometric authentication, use the private key to sign the data to be signed to obtain the signature data;

[0039] Send a service request including the signature data to the application server.

[0040] Optionally, the service request includes a mobile terminal device identifier;

[0041] When the service request is a passwordless login service, the application server queries the mobile terminal device identifier and executes the login service for the account;

[0042] When the service request is a non-passwordless login service, the application server verifies the account binding relationship and assembles the data to be signed including the challenge value;

[0043] Send the data to be signed to the digital identity authentication server, and the digital identity authentication server verifies the data to be signed to obtain the signature verification result.

[0044] According to another aspect of the present invention, there is provided a real-person authentication method, including:

[0045] Receive an authentication request;

[0046] Generate a challenge value and return the challenge value to the mobile terminal;

[0047] Receive the service request of the mobile terminal;

[0048] Generate data to be signed according to at least a part of the service request;

[0049] Send the data to be signed to the digital identity authentication server, and the digital identity authentication server performs real-person authentication according to the data to be signed.

[0050] According to another aspect of the present invention, there is provided a real person authentication system, comprising a mobile terminal, wherein the mobile terminal initiates an authentication request to an application server;

[0051] The mobile terminal generates data to be signed;

[0052] The mobile terminal signs the data to be signed using a private key to obtain signature data;

[0053] The mobile terminal sends the signature data to the digital identity authentication server, and receives the verification result of the signature data by the digital identity authentication server.

[0054] Wherein, the signature verification result is provided to the application server;

[0055] The signature verification result is used to determine whether the real-person authentication is passed.

[0056] The real-person authentication method and system provided by the present invention determine whether the real-person authentication is passed by verifying the signature data through a digital identity authentication server, thereby simplifying user operations and improving the efficiency of authentication while ensuring privacy and security.

[0057] Furthermore, identity information and facial information are collected for identity authentication, and an identity token certificate is generated after the identity authentication is passed. The user is identified by the identity token certificate, anonymously in the application organization and with real name on the authoritative organization's server, thereby ensuring user privacy and data security and preventing the risk of application organizations leaking user identity information privacy. At the same time, the organization does not need to save user identity information data, which also solves legal and compliance issues.

[0058] Furthermore, biometric authentication is performed before obtaining signature data, thereby improving the security of real-person authentication.

[0059] Furthermore, after the real-person authentication is passed, the real-person authentication and biometric authentication are bound. Passing the biometric authentication is equivalent to passing the real-person authentication. While ensuring security, it provides a more convenient password-free login service.

[0060] The real-person authentication method and system provided by the embodiments of the present invention generate a key pair in a secure storage environment on the (device) side and work with a CA organization to issue an identity token certificate; the real-person authentication result is bound to the identity token certificate, and the identity authentication process is integrated in the secure storage environment on the (device) side. While ensuring the authenticity of the identity and the credibility of the certificate, a third-party application organization does not need to access the user's identity data to achieve the purpose of real-person verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Through the following description of the embodiments of the present invention with reference to the accompanying drawings, the above and other objects, features and advantages of the present invention will become clearer. In the drawings:

[0062] Figure 1 A method flow chart of a real person authentication method according to Embodiment 1 of the present invention is shown;

[0063] Figure 2 A schematic diagram of a registration interaction of real person authentication according to Embodiment 2 of the present invention is shown;

[0064] Figure 3 A schematic diagram of a usage interaction of real person authentication according to Embodiment 3 of the present invention is shown;

[0065] Figure 4 A schematic diagram of an identity token activation interaction of real person authentication according to Embodiment 4 of the present invention is shown;

[0066] Figure 5 A method flow chart of a real person authentication method according to Embodiment 5 of the present invention is shown;

[0067] Figure 6 A schematic diagram of the structure of a real person authentication system according to Embodiment 6 of the present invention is shown. Detailed Embodiments

[0068] The various embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. In each of the drawings, the same elements are denoted by the same or similar reference numerals. For clarity, the various parts in the drawings are not drawn to scale. In addition, some well-known parts may not be shown in the figures.

[0069] The specific embodiments of the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. Many specific details of the present invention are described below, such as the structure, materials, dimensions, processing techniques and technologies of components, in order to understand the present invention more clearly. However, as those skilled in the art can understand, the present invention can be implemented without these specific details.

[0070] It should be understood that when describing the structure of a component, when a layer or a region is referred to as being "above" or "on top of" another layer or another region, it may mean directly above the other layer or another region, or there may be other layers or regions between it and the other layer or another region. And if the component is flipped, this layer or region will be "below" or "beneath" the other layer or region.

[0071] The prior art mainly conducts real-name authentication online, generally including the following steps: After the user downloads and installs the APP, registers and logs in to the account, enters the real-name authentication page, fills in personal information and uploads the photo of the identity document, conducts face recognition verification, and submits the authentication information to wait for review. After the review is passed, the user will receive a notice and can then enjoy the services that can only be carried out after real-name authentication.

[0072] The inventors found that although the existing online real-name authentication of APPs helps to improve the security of accounts and reduce fraud, it also brings some potential problems and challenges:

[0073] Complicated operation: For each APP that requires real-name authentication, the user needs to fill in a large amount of personal information, upload the photo of the identity document, and even conduct face recognition. These steps are relatively complex and may cause inconvenience and complication to the user.

[0074] Risk of privacy leakage: During the process of uploading the identity document and conducting face recognition, the user's sensitive information may be improperly processed or stored, increasing the risk of privacy leakage. The user data stored on the server may be attacked by hackers. Once the data is leaked, the user's personal information will face great risks.

[0075] Legal and policy risks: Different countries and regions have different laws and regulations on data protection, which may lead to legal disputes, especially for cross-border data transmission and storage.

[0076] Risk of abuse: The personal information collected during the authentication process may be abused, such as for advertising or other commercial purposes, which may infringe on the legitimate rights and interests of the user.

[0077] Decrease in user trust: If the user does not trust the way the APP processes personal information, it may have a negative impact on the overall trust of the APP and affect user stickiness.

[0078] Inconvenient login: After the user completes real-name authentication, they still need to remember the password or use other verification methods to log in, increasing the operation complexity.

[0079] To solve the deficiencies in the prior art, the inventors proposed a new real person authentication method and system. First, refer to Figure 6 Unify the descriptions of the terms that may be involved in the real person authentication method and system described in this application:

[0080] Identity Token refers to the identity proof data used to present to the authenticator in this product.

[0081] Identity Token System is the technical system that supports the operation of the Identity Token product.

[0082] Remote Trusted Service Platform (RTSP), namely the remote trusted service platform server 300.

[0083] Certificate Authority (CA) server, which forms part of the RTSP and is responsible for issuing, managing, storing, and revoking digital certificates.

[0084] User Device Cert (UDC), a digital certificate issued by the RTSP for user trusted devices.

[0085] User Device Identifier (UDI), an identification number generated by the RTSP for user trusted devices according to rules, which is associated with both the user and the trusted device. The UDIs of the same user on different devices are different, and the UDI is bound to the user device certificate.

[0086] Trusted Device Key (TDK), a trusted device authentication key deployed by the device manufacturer into the device. The TDK can be invoked through the TEE interface and used to sign data to ensure that the data comes from a legitimate device trusted by the device manufacturer.

[0087] Trusted device authentication server, which forms part of the RTSP and is responsible for verifying the data signed with the TDK in the device to ensure that the data comes from a legitimate device trusted by the device manufacturer.

[0088] A unified description of the keys that may be involved in this application:

[0089] The Trusted Device Key (abbreviation: TDK) is a trusted device authentication key deployed by the device manufacturer into the device. The TDK is invoked through the TEE interface and used to sign data to ensure that the data comes from a legitimate device trusted by the device manufacturer. The trusted device key is generated or pre - installed in the security carrier 110. The security carrier 110 holds the private key of the trusted device key, and the RTSP holds the public key or certificate of the trusted device key.

[0090] The RTSP platform key (abbreviation: RTSP - TK) is created or pre - installed by the RTSP. The RTSP holds the private key of the RTSP platform key, and the security carrier 110 pre - installs the public key of the RTSP platform key.

[0091] The CA root key (abbreviation: CA - ROOT) is the key used by the certificate issuing server in the RTSP to issue certificates. The CA root key is generated or pre - installed by the RTSP. The RTSP stores the private key and certificate of the CA root key; the CA - ROOT certificate is also distributed to the authentication device 500.

[0092] The Application Business Authentication Key Public Key or Public Key Certificate (referred to as ABA-PK) is used to verify the submitted real-person information service authorization package when the general application program 120 calls the security carrier 100. This authorization package is signed by RTSP using the corresponding private key. The Application Business Authentication Key Public Key or Public Key Certificate is pre-set by RTSP or dynamically generates an application authorization verification key pair, and the public key is pre-set or synchronized (stored) to the security carrier 110.

[0093] The Application Authorization Verification Key Private Key (referred to as ABA-SK) is stored in RTSP. RTSP uses this key to authorize and sign the submitted real-person information service of the application.

[0094] The Token Encryption Master Key (referred to as TEK-MK) is used to disperse the master key of each identity token encryption key. The Token Encryption Master Key is created or pre-set by RTSP and synchronized to the authentication device 500. The Token Encryption Master Key is stored in RTSP / the authentication device 500.

[0095] The Token Encryption Sub-Key (referred to as TEK-DK) is the key used to encrypt the identity token data at the user device side. The Token Encryption Sub-Key is dispersed by RTSP and transmitted (stored) to the security carrier 110.

[0096] The Secure Channel Key Group (referred to as SCKs, specifically including the encryption key SCK-ENC and the verification key SCK-HMAC) is used to establish a secure channel between the security carrier 110 and RTSP, and is created during the process of opening the user device certificate. The Secure Channel Key Group is randomly generated by RTSP and synchronized to the security carrier 110. The Secure Channel Key Group is stored in RTSP / the security carrier 110.

[0097] The User Device Certificate Key Pair (including the User Device Certificate Private Key UDC-SK and the User Device Certificate Public Key UDC-PK) is created and generated (randomly generated) by the security carrier 110, and the public key is exported to RTSP for signing the user device certificate (UDC-PK is exported and sent to RTSP), the private key is used for service confirmation signature, and the public key is used for signature verification. The security carrier 110 saves UDC-SK and the UDC signed by RTSP; RTSP saves the UDC.

[0098] The Identity Information Submission Temporary Asymmetric Encryption Key (referred to as IEK) is used to encrypt and protect the identity information when submitting the identity information to the application. It is generated by the application server 200 and synchronized to the security carrier 110 after being authenticated by RTSP. The application server 200 caches or saves the private key of the identity information submission temporary asymmetric encryption key.

[0099] Figure 1The figure shows a flowchart of a real-person authentication method according to Embodiment 1 of the present invention. The entity executing the real-person authentication method described in Embodiment 1 is, for example, a mobile terminal. As Figure 1 shown, the real-person authentication method according to Embodiment 1 of the present invention includes the following steps:

[0100] In step S101, an authentication request is sent to the application server;

[0101] The mobile terminal sends an (identity) authentication request to the application server. Optionally, an application program for which identity authentication is to be performed is running on the mobile terminal; the mobile terminal sends an authentication request to the application server corresponding to the application program for which identity authentication is to be performed.

[0102] In step S102, data to be signed is generated;

[0103] The mobile terminal generates data to be signed.

[0104] In step S103, the data to be signed is signed with a private key to obtain signed data;

[0105] The mobile terminal signs the data to be signed with a private key to obtain signed data.

[0106] In step S104, the signed data is sent to the digital identity authentication server, and the verification result of the signature result by the digital identity authentication server is received.

[0107] The mobile terminal sends the signed data to the digital identity authentication server, and receives the verification result of the signature result by the digital identity authentication server. The verification result is provided to the application server; the verification result is used to determine whether the real-person authentication is passed. Optionally, the digital identity authentication server verifies the signed data using the public key corresponding to the private key during signature. When the verification passes, a verification result indicating that the identity authentication is passed is obtained; when the verification fails, a verification result indicating that the identity authentication fails is obtained.

[0108] In an optional embodiment of the present invention, the real-person authentication method further includes the following steps (registration steps):

[0109] Identity information and face information are collected. For example, the mobile terminal collects identity information (such as ID number) by receiving manually input information, OCR recognition, etc.; for example, the mobile terminal collects face information by calling the camera to take a photo.

[0110] Identity verification information is obtained based on the collected identity information and face information.

[0111] Send the authentication information to the digital identity authentication server for authentication. For example, the mobile terminal sends the authentication information to the digital identity authentication server; the digital identity authentication server verifies whether the identity information and the face information belong to the same person to achieve identity authentication.

[0112] Wherein, after the identity authentication is passed, the digital identity authentication server generates an identity token certificate. The identity token certificate includes the private key at the time of signature and the public key that matches the private key. The public key is used by the digital identity authentication server to verify the signature of the signature data.

[0113] The digital identity authentication server also generates a first public key and a first private key that matches the first public key. The mobile terminal receives the first public key and stores the first public key in the secure storage environment (such as TEE, SE, etc.) of the mobile terminal. The mobile terminal uses the first public key to encrypt the identity information and the face information to obtain the authentication information. The digital identity authentication server uses the first private key to decrypt the authentication information to obtain the identity information and the face information.

[0114] In an alternative embodiment of the present invention, the real person authentication method further includes:

[0115] After sending an authentication request to the application server, receive the challenge value feedback by the application server. Wherein, the challenge value is included in the signature data.

[0116] In an alternative embodiment of the present invention, the real person authentication method further includes: performing biometric authentication before using the private key to sign the data to be signed to obtain the signature data.

[0117] In an alternative embodiment of the present invention, the real person authentication method further includes:

[0118] After the real person authentication is passed, bind the real person authentication and the biometric authentication;

[0119] After binding the real person authentication and the biometric authentication, passing the biometric authentication is equivalent to passing the real person authentication.

[0120] In an alternative embodiment of the present invention, the real person authentication method further includes:

[0121] Send a registration request to the application server;

[0122] Receive the registration challenge value feedback by the application server;

[0123] Generate registration request data including the registration challenge value;

[0124] Sign the registration request data to obtain the request signature data;

[0125] Send the request signature data to the digital identity authentication server and receive the signature verification result of the request signature data from the digital identity authentication server. The signature verification result of the request signature data is used to determine whether the registration request passes.

[0126] In an alternative embodiment of the present invention, the real-person authentication method further includes:

[0127] After sending an authentication request to the application server, receive the challenge value feedback from the application server;

[0128] Assemble the data to be signed and invoke system authentication;

[0129] After performing biometric authentication, use the private key to sign the data to be signed to obtain the signature data;

[0130] Send a service request including the signature data to the application server.

[0131] Optionally, the service request includes the mobile terminal device identifier. When the service request is a passwordless login service, the application server queries the mobile terminal device identifier and executes the login service for the account. When the service request is a non-passwordless login service, the application server verifies the account binding relationship and assembles the data to be signed including the challenge value. The data to be signed is sent to the digital identity authentication server, and the digital identity authentication server performs signature verification on the data to be signed to obtain the signature verification result.

[0132] According to the real-person authentication method of the embodiments of the present invention, a powerful identity authentication system is created through a trusted identity token certificate issued by an authoritative institution and a (device) side security storage environment; for example, integrating the FIDO (Fast Identity Online) protocol can provide a general, secure, and convenient passwordless and multi-factor online user identity authentication solution, which supports being applied to various scenarios that require user identity verification such as user login, transfer and payment.

[0133] According to the real-person authentication method of the embodiments of the present invention, as a key technology for verifying the authenticity of user identity, it can be widely applied to a variety of business scenarios, including but not limited to financial industry scenarios (such as bank remote account opening, securities trading, loan application, etc.), e-commerce and payment scenarios (such as user registration, transaction payment, account security verification, etc.), digital government scenarios (such as online handling of social security, provident fund, tax declaration, etc.), sharing economy and travel (such as online car-hailing driver registration, shared bicycle user real-name, shared accommodation landlord authentication, etc.), social media and content platforms (such as user account real-name registration, live streamer authentication, anti-false comment, etc.), online education and medical (such as remote exam identity confirmation, online consultation real-name authentication, electronic prescription issuance, etc.), operator services (such as mobile phone card activation, package change, off-site card replacement, etc.), Internet of Things and industrial security (such as device access authorization, sensitive data access control, etc.).

[0134] Figure 2 shows a schematic diagram of the registration interaction for real-person authentication according to the second embodiment of the present invention. As Figure 2 shown, the registration interaction for real-person authentication according to the second embodiment of the present invention occurs among the general application 120, the security carrier 110, the application server 200, and the remote trusted service platform server 300. Among them, the general application 120 and the security carrier 110 run on a mobile terminal, for example.

[0135] Specifically, the process of the registration interaction is as follows:

[0136] The general application 120 sends a start registration request to the application server 200; the application server 200 generates a challenge value and returns the challenge value to the general application 120.

[0137] The general application 120 assembles the data to be signed and invokes system authentication.

[0138] The general application 120 sends a registration request to the security carrier 110, where the registration request includes the data to be signed and the challenge value. The security carrier 110 performs biometric authentication and signs the data to be signed using the UDC-SK (private key of the user device certificate). The security carrier 110 returns the signature and the UDI to the general application 120. UDC (User Device Cert) -SK is the private key of the user device certificate, for example. UDI (User Device Identifier) is an identification number associated with both the user and the trusted device generated according to rules, for example.

[0139] The general application 120 sends a complete registration request to the application server 200, where the complete registration request includes the request data, the signature, and the UDI. The application server 200 assembles the data to be signed, where the data to be signed includes the request data and the challenge value.

[0140] The application server 200 verifies the signature with the remote trusted service platform server (digital identity authentication server) 300, where the content verified by the signature verification includes the data to be signed, the signature, and the UDI. The remote trusted service platform server 300 looks up the identity token certificate (UDI) and verifies the signature based on the identity token certificate (the verification object is the data to be signed and the signature). The remote trusted service platform server 300 returns the verification result to the application server 200.

[0141] The application server 200 binds the account to the real name, that is, binds it to the UDI. The application server 200 returns the registration result to the general application 120.

[0142] Figure 3Shows the usage interaction schematic diagram of real-person authentication according to Embodiment 3 of the present invention. As Figure 3 shown, the usage interaction of real-person authentication according to Embodiment 3 of the present invention occurs among the general application program 120, the security carrier 110, the application server 200, and the remote trusted service platform server 300. Among them, the general application program 120 and the security carrier 110 run on a mobile terminal, for example.

[0143] Specifically, the usage interaction process is as follows:

[0144] The general application program 120 sends a start authentication request to the application server 200. The application server 200 generates a challenge value and returns the generated challenge value to the general application program 120.

[0145] The general application program 120 assembles the data to be signed and calls the system authentication.

[0146] The general application program 120 sends the authentication request to the security carrier 110. Among them, the authentication request includes the request data and the challenge value. The security carrier 110 performs biometric authentication and signs the request data and the challenge value using UDC-SK after the security authentication passes. The security carrier 110 sends the signature and UDI to the general application program 120.

[0147] The general application program 120 sends a service request to the application server 200. Among them, the service request includes the request data, the signature, and the UDI.

[0148] When the service type is a non-secret-free login service, the application server 200 checks the account binding relationship and assembles the data to be signed (the assembled data to be signed includes the request data and the challenge value). The application server 200 verifies the signature with the remote trusted service platform server 300 (the content to be verified includes the data to be signed, the signature, and the UDI). The remote trusted service platform server 300 looks up the identity token certificate (UDI) and verifies the signature according to the identity token certificate (the verification object includes the data to be signed and the signature), and returns the verification result to the application server 200. When the service type is a secret-free login service, the application server 200 queries the account (UDI) and executes the login service of the account.

[0149] The application server 200 returns the result to the general application program 120.

[0150] Figure 4 Shows the identity token activation interaction schematic diagram of real-person authentication according to Embodiment 4 of the present invention. As Figure 4 shown, the identity token activation interaction of real-person authentication according to Embodiment 4 of the present invention occurs among the user, the management application program 130, the security carrier 110, and the remote trusted service platform server 300.

[0151] Specifically, the user sends a function activation request to the management application 130 (the user operates the management application 130 for activation); the management application 130 collects the identity information and on-site face of the user (takes a face photo), and the user provides the identity information and the on-site face photo to the management application 130.

[0152] The security carrier 110 obtains the ciphertext of the face information from the management application 130, calculates and saves the face feature template (calculates and saves the face feature data obtained by calculating using the face photo), encrypts the identity information and the face photo using the RTSP-TK public key, where RTSP-TK is, for example, the key of the remote trusted service platform server. The security carrier 110 sends the ciphertext of the identity information to the management application 130.

[0153] The management application 130 submits a real-person verification to the remote trusted service platform server 300, and the submitted real-person verification includes the ciphertext of the identity information (the user identity information and the face ciphertext). The remote trusted service platform server 300 decrypts the identity information and the photo (the user identity and the face data) using the RTSP-TK private key, and conducts a comparison with the database of the authoritative agency service (the face). The remote trusted service platform server 300 returns the comparison result to the management application 130.

[0154] The management application 130 invokes the security carrier 110 to create an activation request. The security carrier 110 conducts a security check on the device status, creates a UDC-SK key pair (the generation of the UDC-SK key has the attribute of one key per device), assembles the activation request data (at least including the public key of the security key pair, the device identifier, and the self-signature), and signs the activation request data using TDK (Trusted Device Key, the trusted device key) (secondarily). Among them, the security carrier 110 requests the user to set the key PIN code (pops up the TUI for the user to set the PIN code). The security carrier 110 returns the activation request data to the management application 130.

[0155] The management application 130 sends an activation request to the remote trusted service platform server 300, and the activation request includes the activation request data. The remote trusted service platform server 300 verifies the activation request data using the TDK public key, generates the UDI, issues the UDC (generates the user device identifier UDI according to the user information and issues the user device certificate UDC), generates the SCKs, disperses the sub-key TEK-DK using the TEK-MK (for the user device identifier), and encrypts the UDC, TEK-DK, UDI, and the user identity information using the SCKs, and encrypts the SCKs using the UDC-PK. The remote trusted service platform server 300 sends the activation response data (including the above data) to the management application 130.

[0156] The management application 130 imports the activation response (activation response data) into the security carrier 110. The security carrier 110 decrypts the SCKs using the UDC-SK, and then decrypts and saves the UDC, UDI, TEK-DK, and user identity information using the SCKs. The security carrier 110 binds the local biometric feature. If the binding is successful, the trusted token can be unlocked using the local biometric feature verification.

[0157] Figure 5 The method flow chart of the real person authentication method according to the fifth embodiment of the present invention is shown. The main body that executes the real person authentication method described in the fifth embodiment is, for example, the application server 200. As Figure 5 shown, the real person authentication method according to the fifth embodiment of the present invention includes the following steps:

[0158] In step S201, an authentication request is received;

[0159] The application server 200 receives the authentication request (sent by the mobile terminal).

[0160] In step S202, a challenge value is generated and returned to the mobile terminal;

[0161] The application server 200 generates a challenge value and returns the generated challenge value to the mobile terminal.

[0162] In step S203, the service request of the mobile terminal is received;

[0163] The application server 200 receives the service request sent by the mobile terminal.

[0164] In step S204, data to be signed is generated according to at least a part of the service request;

[0165] The application server 200 generates data to be signed according to at least a part of the service request.

[0166] In step S205, the data to be signed is sent to the digital identity authentication server, and the digital identity authentication server performs real person authentication according to the data to be signed.

[0167] The application server 200 sends the data to be signed to the digital identity authentication server. The digital identity authentication server performs real person authentication according to the data to be signed.

[0168] According to the real-person authentication method of the embodiment of the present invention, a digital identity verified by an authoritative CA organization is provided, the private key of the certificate is stored in the secure storage environment of the device, and it is bound to the system biometrics, which not only achieves security, but also provides a convenient password-free login service. The identity token certificate issued by the authoritative (CA) organization has legal effect and can be used in legal and administrative affairs that require identity authentication, which improves the enforceability of electronic affairs.

[0169] According to another aspect of the present invention, a real person authentication system is provided. The real person authentication system includes a mobile terminal. The mobile terminal initiates an authentication request to an application server. The mobile terminal generates data to be signed, and signs the data to be signed using a private key to obtain signature data. The mobile terminal sends the signature data to a digital identity authentication server, and receives a signature verification result of the signature data by the digital identity authentication server. The signature verification result is provided to the application server, and the signature verification result is used to determine whether the real person authentication is passed.

[0170] Figure 6 FIG. 2 shows a schematic diagram of the structure of a real person authentication system according to Embodiment 6 of the present invention. The real person authentication system according to Embodiment 6 of the present invention is used, for example, to implement the real person authentication method described above. Figure 6 As shown, the real person authentication system according to the sixth embodiment of the present invention includes at least one of the following components:

[0171] The terminal device (mobile terminal) 100 is a terminal device held by a user, such as a smart phone, a smart watch, etc. A security element (such as TEE or SE or both) is integrated on the terminal device 100 .

[0172] The security carrier 110 is a software and hardware module on the terminal device 100. It implements the security function interface by accessing TEE\SE internally, and provides the interface to external applications. Among them, the security carrier access service program 111 provides an entity program for the external interface of the security carrier 110, accesses TEE\SE to implement the functional interface encapsulation of the identity token, and provides external calls. TEE (Trusted Execution Environment) 112 is a security carrier, which is a logical security isolation area of ​​the system SOC and can execute security applications. SE (Secure Element) 112 is generally an independent encryption chip. Due to its independent isolation characteristics, it has a higher security level than TEE. Calling the SE interface in TEE can further ensure business security.

[0173] The general application 120 calls the secure element 110 to call the application of various functions of the identity token. The management application 130 calls the secure element 110 to perform identity token provisioning management.

[0174] The remote trusted service platform server 300 is the general term for services participating in the operation of the identity token service, including but not limited to: authoritative identity authentication service, certificate issuance service, identity token verification service, activation management service, application access service, etc., and also includes the relevant background services of terminal device manufacturers, etc.

[0175] The application server 200 is the background service of the ordinary application program 120, and processes the authentication requests of the ordinary application program 120.

[0176] The authentication device 500 is a device used to verify and authenticate the identity tokens generated by the terminal device.

[0177] According to the real-person authentication method and system of the embodiments of the present invention (which can be regarded as a real-person passwordless system based on the device side), relying on the PKI (Public Key Infrastructure) certificate system, using the identity token certificate issued by an authoritative CA (Certificate Authority), secure identity verification is achieved; combined with the secure storage environment of the mobile phone side (device side), this system provides a highly isolated execution space, effectively resisting security threats at the operating system level, ensuring the security of code and data, and thus bringing users a convenient and secure passwordless identity verification experience.

[0178] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0179] As described above according to the embodiments of the present invention, these embodiments do not describe all the details in detail, nor limit the invention to the specific embodiments described. Obviously, according to the above description, many modifications and variations can be made. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can make good use of the present invention and its modifications based on the present invention. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A real person authentication method, comprising: Initiate an authentication request to the application server; Generate data to be signed; Sign the data to be signed using a private key to obtain signed data; Send the signature data to a digital identity verification server, and receive a verification result of the signature data from the digital identity verification server. Wherein, the signature verification result is provided to the application server; The signature verification result is used to determine whether the real-person authentication is passed.

2. The real person authentication method according to claim 1, wherein: The real person authentication method further includes: Collect identity information and facial information; Obtaining identity verification information according to the identity information and the face information; Sending the identity verification information to the digital identity verification server for identity verification, Wherein, after the identity authentication is passed, the digital identity authentication server generates an identity token certificate; the identity token certificate includes a public key matching the private key, and the public key is used by the digital identity authentication server to verify the signature data; The digital identity authentication server generates a first public key and a first private key that matches the first public key; The mobile terminal receives the first public key and stores the first public key in a secure storage environment of the mobile terminal; the mobile terminal uses the first public key to encrypt the identity information and the face information to obtain the identity authentication information.

3. The real person authentication method according to claim 1, wherein: After initiating the authentication request to the application server, the real-person authentication method further includes: receiving a challenge value fed back by the application server, Wherein, the signature data includes the challenge value.

4. The real person authentication method according to claim 1, wherein: Before using the private key to sign the data to be signed to obtain the signed data, the real person authentication method further includes: Perform biometric authentication.

5. The real person authentication method according to claim 1, wherein: The real person authentication method further includes: After the real person authentication is passed, binding the real person authentication and biometric authentication; After binding the real person authentication and the biometric authentication, passing the biometric authentication is equivalent to passing the real person authentication.

6. The real person authentication method according to claim 1, wherein: The real person authentication method further includes: Initiate a registration request to the application server; Receiving a registration challenge value fed back by the application server; generating registration request data including the registration challenge value; Signing the registration request data to obtain request signature data; Send the requested signature data to the digital identity verification server, and receive the verification result of the requested signature data by the digital identity verification server, The verification result of the request signature data is used to determine whether the registration request is approved.

7. The real person authentication method according to claim 1, wherein: The real person authentication method further includes: After initiating an authentication request to the application server, receiving a challenge value fed back by the application server; Assembling the data to be signed and invoking system authentication; After performing biometric authentication, using the private key to sign the data to be signed to obtain the signature data; Sending a service request including the signature data to the application server.

8. The real person authentication method according to claim 7, wherein: The service request includes a mobile terminal device identifier; When the service request is a password-free login service, the application server queries the mobile terminal device identifier and performs the account login service; When the service request is a non-password-free login service, the application server checks the account binding relationship and assembles the data to be signed including the challenge value; The data to be signed is sent to the digital identity verification server, and the digital identity verification server verifies the data to be signed to obtain the verification result.

9. A real person authentication method, comprising: receiving a certification request; Generate a challenge value and return the challenge value to the mobile terminal; receiving a service request from the mobile terminal; Generate data to be signed according to at least a part of the service request; The data to be signed is sent to a digital identity verification server, and the digital identity verification server performs real-person authentication based on the data to be signed.

10. A real person authentication system, comprising a mobile terminal, wherein: The mobile terminal initiates an authentication request to the application server; The mobile terminal generates data to be signed; The mobile terminal signs the data to be signed using a private key to obtain signature data; The mobile terminal sends the signature data to the digital identity authentication server, and receives the verification result of the signature data by the digital identity authentication server. Wherein, the signature verification result is provided to the application server; The signature verification result is used to determine whether the real-person authentication is passed.