Identity authentication method based on trusted label and authentication system thereof

By registering an identity tag in a trusted authentication gateway and disrupting and encrypting the QR code, and automatically generating problem codes and identity codes, the problems of high cost of integrated circuit cards and easy forgery of QR codes are solved, and safe and convenient identity authentication is achieved.

CN120263501AInactive Publication Date: 2025-07-04WUHAN TUOQIANHAI NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510476738.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, integrated circuit cards are costly, while ordinary QR codes are easy to forge and are difficult to meet the needs of identity authentication.

Method used

Identity authentication is performed using trusted tags. By registering the identity tag of the computer terminal in the trusted authentication gateway, including the user's own identity, private key and public key, using the QR code to import the public key, and disrupting the QR code content and Euler function encryption, automatically generating the problem code and identity code to perform identity authentication.

Benefits of technology

It improves the security and convenience of identity authentication, reduces costs, ensures the security of data transmission, simplifies the public key distribution process, and achieves efficient, secure and convenient user identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263501A_ABST
    Figure CN120263501A_ABST
Patent Text Reader

Abstract

The invention discloses an identity authentication method based on a trusted label and an authentication system thereof. The identity authentication method comprises the steps that a computer terminal sends an access request to a trusted authentication gateway; according to the invention, the identity tag of the computer terminal is registered in the trusted authentication gateway, so that the security of the system is enhanced, the use of the private key and the public key provides a basis for encryption and decryption of data, and the security of data transmission is ensured; the making content of the two-dimensional code is disrupted and encrypted based on the Euler function, so that the difficulty of illegally copying or tampering the two-dimensional code is increased, and the security of the system is further improved; accurate authentication of the user identity is ensured through registration of the identity tag and the subsequent identity code analysis and comparison process, and the system can verify whether the user identity is legal or not through an automatically generated problem code and scanning and analysis of the user on the problem code; the public key is imported to the user in the form of the two-dimensional code, the distribution process of the public key is simplified, and the efficient, safe and convenient user identity authentication process is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and specifically relates to an identity authentication method based on a trusted label and its authentication system. Background Art

[0002] Identity authentication refers to a process for effectively confirming the identity of a legitimate operator during computer network communication. It ensures that when an operator obtains access rights, services, or privileges in a certain identity, the actual operator is the legitimate operator corresponding to the identity held.

[0003] Currently, identity authentication is generally implemented using integrated circuit cards, but its disadvantage is high cost. To save costs, some merchants have tried to use two-dimensional codes to replace IC cards. However, due to the innate vulnerability to forgery of ordinary two-dimensional codes, it is difficult to meet the needs of staff. Summary of the Invention

[0004] To solve the above technical problems, an identity authentication method based on a trusted label and its authentication system are provided. The present technical solution solves the problem proposed in the above background art that identity authentication is generally implemented using integrated circuit cards, but its disadvantage is high cost. To save costs, some merchants have tried to use two-dimensional codes to replace IC cards. However, due to the innate vulnerability to forgery of ordinary two-dimensional codes, it is difficult to meet the needs of staff.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows: In the first aspect of the present invention, an identity authentication method based on a trusted label is provided, including: A computer terminal sends an access request to a trusted authentication gateway and registers the identity label of the computer terminal in the trusted authentication gateway. The identity label includes the user's own identifier, private key, and public key, and the public key is imported to the user in the form of a two-dimensional code; Perform a traceability process on the two-dimensional code in the trusted authentication system, obtain the production content of the two-dimensional code, scramble it, and encrypt the production content of the two-dimensional code based on the Euler function; Automatically generate a question code based on the identity label; The user scans and analyzes the question code to generate a corresponding identity code; The trusted authentication system analyzes and compares the identity code to determine whether the user's identity authentication is correct.

[0006] Preferably, the specific steps for registering the basic identity information of the computer terminal in the trusted authentication gateway are as follows: The administrator enters the user's personal basic information in the trusted authentication system to obtain the user's own identifier; The user binds identity information such as the answer to the security question, password, etc. in the trusted authentication system with their own identifier, and the different security questions, decryption answers, and question serial numbers correspond one by one; The administrator assigns keys according to the user identifier, including a public key and a private key; Generate a QR code with the public key; The user opens the mobile phone to scan the QR code to import and save the public key.

[0007] Preferably, the process of tracing the QR code in the trusted authentication system, obtaining the production content of the QR code, and scrambling it specifically includes the following steps: Scan the production content data of the QR code; Evenly divide the production content data of the QR code into multiple data intervals; Assign values to the bits within the data interval according to the data interval sorting; Use a random algorithm to generate random operators with the same number as the bits within the data interval; Sort the bits within the data interval according to the size of the random algorithm to obtain the scrambled data of the production content of the QR code.

[0008] Preferably, the process of encrypting the production content of the QR code based on the Euler function specifically includes the following steps: Extract the scrambled data of the production content of multiple QR codes; Respectively convert the multiple scrambled data into decimal quantization data; Randomly construct two prime numbers; Respectively obtain the modulus of the corresponding quantization data according to the two prime numbers; According to the Euler function, combine the two prime numbers to obtain the Euler function value; Obtain the first exponent according to the Euler function value; Obtain the second exponent according to the first exponent and the Euler function value; Obtain the first encryption key and the second encryption key according to the first exponent, the second exponent, and the modulus; Among them, the calculation formula of the Euler function value is: ; Among them, the calculation formula of the modulus is: N = pq; Among them, the specific composition of the first encryption key and the second encryption key: First encryption key: ; Second encryption key: ; In the formula, are the two prime numbers selected respectively, is the Euler function value, is the first exponent, is the second exponent, is the modulus; Extract multiple quantization data respectively; Raise the quantization data to the power according to the first exponent to obtain the power exponent; According to the power exponent, combine the modulus to obtain the corresponding remainder; Replace the quantization data according to the remainder, so as to complete the encryption of the production content data of the two-dimensional code.

[0009] Preferably, the automatic generation of the question code based on the identity tag specifically includes the following steps: The server obtains the time value T accurate to milliseconds, and encrypts T with the MD5 algorithm to obtain the hash value H T =MD5(T, 32); Randomly extract a security question Q from the database, the question number is i, and obtain the current timestamp t a , and splice the bit strings of the current several key information to obtain the plaintext M = {t a + i + Q}; Take HT as the SM4 algorithm key K, use the SM4 key K to encrypt the plaintext M to obtain the ciphertext C = SM4(M, K), and generate the question code from the key K and the ciphertext C.

[0010] Preferably, the user scans and analyzes the question code specifically includes the following steps: Obtain the key K and the ciphertext C from the decoding result, and use the SM4 key K to decrypt the ciphertext C to obtain the plaintext M1 = SM4(C, K); Intercept the timestamp t from the plaintext M1 a , take the current timestamp t b , calculate the time interval ∆t = t b -t a , check whether ∆t exceeds the maximum time interval of 120s; If it exceeds, prompt the user that the question code has expired. If it does not exceed, continue to the next step. ∆t does not exceed the maximum time interval. The security question Q will be intercepted from the plaintext M1, the question number is i, and the question Q will be output; After completing the analysis of the question code, output the obtained security question Q on the interface to prompt the user to answer.

[0011] Preferably, the generation of the corresponding identity code specifically includes the following steps: The user inputs the security question answer Si according to the given security question Q; The current timestamp t c , the question number is i, and the security question answer Si input by the user. Splice the bit strings of these key information to obtain the plaintext M = {t c+i + Si}; Use the public key to encrypt the plaintext M to obtain the ciphertext C, generate an identity code from the ciphertext C, and the user places the generated identity code in front of the QR code scanner and waits for the authentication result.

[0012] Preferably, the trusted authentication system parses and compares the identity code to determine whether the user's identity authentication is correct, which specifically includes the following steps: The server processes the scan result returned by the QR code scanner to obtain a string of ciphertext, and performs collision decryption on the ciphertext C. The collision decryption is to obtain all users' private keys in the database and verify whether there is [dA]C1 = (x2, y2); If dA exists, the decryption is successful and the plaintext M' is obtained. If the decryption fails, it proves that the encryptor is an illegal user and the collision decryption fails; Intercept the timestamp t from the plaintext M' c , take the current timestamp t d , calculate the time interval Δt = t d -t c ; Check whether Δt exceeds the maximum time interval of 60s. If it exceeds, prompt the user that the identity code has expired. If it does not exceed, continue to the next step; If it does not exceed the maximum time interval, intercept the information of the security question number i and the user-entered answer Si of the security question from the plaintext M', and compare it one by one with the user information bound to the user's own identifier corresponding to the private key found in the database. If the comparison is successful, the authentication is successful. If the comparison fails, return the comparison result.

[0013] In the second aspect of the present invention, a trusted label-based identity authentication system is further provided, including: A registration module, which is used for the computer terminal to send an access request to the trusted authentication gateway and register the identity label of the computer terminal in the trusted authentication gateway. The identity label includes the user's own identifier, private key, and public key, and the public key is imported to the user in the form of a QR code; A public key encryption module, which is used to trace the QR code in the trusted authentication system, obtain the production content of the QR code, scramble it, and encrypt the production content of the QR code based on the Euler function; A question code generation module, which is used to automatically generate a question code based on the identity label; An identity code generation module, which is used for the user to scan and parse the question code and generate a corresponding identity code; A comparison module, which is used for the trusted authentication system to parse and compare the identity code to determine whether the user's identity authentication is correct.

[0014] In a third aspect of the present invention, an electronic device is further provided. The electronic device includes at least one processor; and a memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method of the first aspect of the present invention.

[0015] Compared with the prior art, the present invention provides an identity authentication method based on a trusted tag and its authentication system, having the following beneficial effects: By registering the identity tag of the computer terminal in the trusted authentication gateway in the present invention, the security of the system is enhanced. The use of private and public keys provides a basis for data encryption and decryption, ensuring the security of data transmission; the production content of the two-dimensional code is scrambled and encrypted based on the Euler function, increasing the difficulty of illegal copying or tampering of the two-dimensional code and further enhancing the security of the system; the registration of the identity tag and the subsequent identity code parsing and comparison process ensure the accurate authentication of the user's identity. Through the automatically generated question code and the user's scanning and parsing of the question code, the system can verify whether the user's identity is legal; the public key is imported to the user in the form of a two-dimensional code, simplifying the public key distribution process and improving the user experience. The user only needs to scan the two-dimensional code to obtain the public key without manually inputting complex public key information. The introduction of the question code and the identity code realizes an efficient, secure and convenient user identity authentication process. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a schematic diagram of the identity authentication method based on a trusted tag in the present invention; Figure 2 It is a schematic diagram of the method for registering the basic identity information of a computer terminal in the trusted authentication gateway in the present invention; Figure 3 It is a schematic diagram of the method for obtaining the production content of the two-dimensional code and scrambling it in the present invention; Figure 4 It is a schematic diagram of the method for automatically generating a question code based on the identity tag in the present invention; Figure 5 It is a schematic diagram of the method for the user to scan and process the question code and parse it in the present invention; Figure 6 It is a schematic diagram of the method for generating a corresponding identity code in the present invention; Figure 7 It is a schematic diagram of the method for the trusted authentication system to parse and compare the identity code to determine whether the user's identity authentication is correct in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and other obvious variations can be conceived by those skilled in the art.

[0018] Embodiment 1 Please refer to Figure 1 As shown, in the first aspect of the present invention, a method for identity authentication based on a trusted tag is provided, including: S101. The computer terminal sends an access request to the trusted authentication gateway and registers the identity tag of the computer terminal in the trusted authentication gateway. The identity tag includes the user's own identifier, private key, and public key, and the public key is imported to the user in the form of a QR code. S102. Trace the source of the QR code in the trusted authentication system, obtain the production content of the QR code, scramble it, and encrypt the production content of the QR code based on the Euler function. S103. Automatically generate a question code based on the identity tag. S104. The user scans and parses the question code to generate a corresponding identity code. S105. The trusted authentication system parses and compares the identity code to determine whether the user's identity authentication is correct.

[0019] Those skilled in the art can understand that the present invention enhances the security of the system by registering the identity tag of the computer terminal in the trusted authentication gateway. The use of the private key and public key provides a basis for data encryption and decryption, ensuring the security of data transmission. The production content of the QR code is scrambled and encrypted based on the Euler function, increasing the difficulty of illegal copying or tampering of the QR code and further enhancing the security of the system. The registration of the identity tag and the subsequent parsing and comparison process of the identity code ensure the accurate authentication of the user's identity. Through the automatically generated question code and the user's scanning and parsing of the question code, the system can verify whether the user's identity is legal. The public key is imported to the user in the form of a QR code, simplifying the public key distribution process and improving the user experience. The user only needs to scan the QR code to obtain the public key without manually inputting complex public key information. The introduction of the question code and the identity code realizes an efficient, secure, and convenient user identity authentication process.

[0020] Please refer to Figure 2 As shown, the specific steps for registering the basic identity information of the computer terminal in the trusted authentication gateway are as follows: S201. The administrator enters the user's personal basic information in the trusted authentication system to obtain the user's own identifier. S202. The user sets identity information such as the answers to security questions and passwords in the trusted authentication system and binds them to their own identifier, and different security questions, decryption answers, and question serial numbers correspond one by one; S203. The administrator assigns keys according to the user identifier, including a public key and a private key; S204. Generate a QR code from the public key; S205. The user opens the mobile phone to scan the QR code to import and save the public key.

[0021] Please refer to Figure 3 As shown, perform source tracing on the QR code in the trusted authentication system, obtain the production content of the QR code, and scramble it. The specific steps are as follows: S301. Scan the production content data of the QR code; S302. Divide the production content data of the QR code into multiple data intervals on average; S303. Assign values to the bits within the data interval according to the data interval sorting; S304. Use a random algorithm to generate random operators with the same number as the bits within the data interval; S305. Sort the bits within the data interval according to the size of the random algorithm to obtain the scrambled data of the production content of the QR code.

[0022] Encrypt the production content of the QR code based on the Euler function. The specific steps are as follows: Extract the scrambled data of the production content of multiple QR codes; Convert the multiple scrambled data into decimal quantization data respectively; Randomly construct two prime numbers; Obtain the modulus corresponding to the quantization data according to the two prime numbers respectively; Obtain the Euler function value according to the Euler function, combining the two prime numbers; Obtain the first exponent according to the Euler function value; Obtain the second exponent according to the first exponent and the Euler function value; Obtain the first encryption key and the second encryption key according to the first exponent, the second exponent and the modulus; Among them, the calculation formula of the Euler function value is: ; Among them, the calculation formula of the modulus is: N = pq; Among them, the specific composition of the first encryption key and the second encryption key: First encryption key: ; Second encryption key: ; In the formula, are two selected prime numbers respectively, is the Euler's totient function value, is the first exponent, is the second exponent, is the modulus; Extract multiple quantization data respectively; Raise the quantization data to the power according to the first exponent to obtain the power exponent; According to the power exponent, combine with the modulus to obtain the corresponding remainder; Replace the quantization data according to the remainder, so as to complete the encryption of the content data of the QR code.

[0023] Please refer to Figure 4 As shown, automatically generating a question code based on the identity tag specifically includes the following steps: S401. The server obtains the time value T accurate to milliseconds, and encrypts T with the MD5 algorithm to obtain the hash value H T =MD5(T, 32); S402. Randomly extract a security question Q from the database, the question number is i, and obtain the current timestamp t a , and splice the bit strings of the current several key information to obtain the plaintext M = {t + i + Q}; S403. Take HT as the SM4 algorithm key K, use the SM4 key K to encrypt the plaintext M to obtain the ciphertext C = SM4(M, K), and generate a question code from the key K and the ciphertext C.

[0024] Please refer to Figure 5 As shown, the user scans and parses the question code specifically includes the following steps: S501. Obtain the key K and the ciphertext C from the decoding result, and use the SM4 key K to decrypt the ciphertext C to obtain the plaintext M1 = SM4(C, K); S502. Intercept the timestamp t from the plaintext M1 a , take the current timestamp t b , calculate the time interval ∆t = t b - t a , and check whether ∆t exceeds the maximum time interval of 120s; S503. If it exceeds, prompt the user that the question code has expired. If it does not exceed, continue to the next step. ∆t does not exceed the maximum time interval. Intercept the security question Q from the plaintext M1, the question number is i, and output the question Q; S504. After completing the parsing of the question code, output the obtained security question Q on the interface and prompt the user to answer.

[0025] Please refer to Figure 6 As shown, generating the corresponding identity code specifically includes the following steps: S601. The user inputs the answer Si to the security question according to the given security question Q. S602. Concatenate the current timestamp t c , the question number i, and the answer Si to the security question input by the user, and splice the bit strings of these key information to obtain the plaintext M = {t c + i + Si}; S603. Encrypt the plaintext M using the public key to obtain the ciphertext C, generate an identity code from the ciphertext C, and the user places the generated identity code in front of the QR code scanner to wait for the authentication result.

[0026] Please refer to Figure 7 As shown, the trusted authentication system parses and compares the identity code to determine whether the user's identity authentication is correct, which specifically includes the following steps: S701. The server processes the scanning result returned by the QR code scanner to obtain a string of ciphertext, and performs collision decryption on the ciphertext C. Collision decryption is to obtain all users' private keys in the database and verify whether there is [dA]C1 = (x2, y2); S702. If dA exists, the decryption is successful and the plaintext M' is obtained. If the decryption fails, it proves that the encryptor is an illegal user and the collision decryption fails; S703. Intercept the timestamp t from the plaintext M' c , take the current timestamp t d , and calculate the time interval Δt = t d - t c ; S704. Check whether Δt exceeds the maximum time interval of 60s. If it exceeds, prompt the user that the identity code has expired. If it does not exceed, continue to the next step; S705. If the maximum time interval is not exceeded, intercept the information of the question number i and the answer Si to the security question input by the user from the plaintext M', and compare it one by one with the user information bound to the user's own identifier corresponding to the private key found in the database. If the comparison is successful, the authentication is successful. If the comparison fails, return the comparison result.

[0027] In the second aspect of the present invention, a trusted label-based identity authentication system is further provided, including: A registration module. The registration module is used for the computer terminal to send an access request to the trusted authentication gateway and register the identity label of the computer terminal in the trusted authentication gateway. The identity label includes the user's own identifier, private key, and public key, and the public key is imported to the user in the form of a QR code; A public key encryption module. The public key encryption module is used for tracing the QR code in the trusted authentication system, obtaining the production content of the QR code, scrambling it, and encrypting the production content of the QR code based on the Euler function; A problem code generation module, which is used to automatically generate problem codes based on identity tags; An identity code generation module, which is used for a user to scan and parse the problem code to generate a corresponding identity code; A comparison module, which is used for a trusted authentication system to parse and compare the identity code to determine whether the user's identity authentication is correct.

[0028] In a third aspect of the present invention, an electronic device is also provided.

[0029] The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described herein and / or claimed.

[0030] The electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0031] A plurality of components in the electronic device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0032] The computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 executes the various methods and processes described above, such as methods S101 - S105. For example, in some embodiments, methods S101 - S105 can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of methods S101 - S105 described above can be executed. Alternatively, in other embodiments, the computing unit 801 can be configured to execute methods S101 - S105 in any other suitable manner (e.g., by means of firmware).

[0033] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0034] The program code for implementing the methods of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0035] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0036] To provide for interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic, speech, or tactile input).

[0037] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0038] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, a server of a distributed system, or a server incorporating a blockchain.

[0039] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.

Claims

1. An identity authentication method based on a trusted label, characterized in that, Including: The computer terminal sends an access request to the trusted authentication gateway and registers the identity tag of the computer terminal in the trusted authentication gateway. The identity tag includes the user's own identifier, private key, and public key, and the public key is imported to the user in the form of a QR code. Trace the source of the QR code in the trusted authentication system, obtain the production content of the QR code, scramble it, and encrypt the production content of the QR code based on the Euler function. Automatically generate a question code based on the identity tag. The user scans and parses the question code to generate a corresponding identity code. The trusted authentication system parses and compares the identity code to determine whether the user's identity authentication is correct.

2. The identity authentication method based on a trusted label according to claim 1, wherein The specific steps for registering the basic identity information of the computer terminal in the trusted authentication gateway are as follows: The administrator enters the user's personal basic information in the trusted authentication system to obtain the user's own identifier. The user sets identity information such as the answer to the security question and password in the trusted authentication system and binds them to the user's own identifier, and different security questions, decryption answers, and question numbers correspond one by one. The administrator assigns keys according to the user identifier, including public key and private key. Generate a QR code from the public key. The user opens the mobile phone to scan the QR code to import and save the public key.

3. The identity authentication method based on a trusted tag according to claim 2, characterized in that, The specific steps for tracing the source of the QR code in the trusted authentication system, obtaining the production content of the QR code, and scrambling it are as follows: Scan the production content data of the QR code. Evenly divide the production content data of the QR code into multiple data intervals. Assign values to the bits in the data interval according to the data interval sorting. Use a random algorithm to generate random operators with the same number as the bits in the data interval. Sort the bits in the data interval according to the size of the random algorithm to obtain the scrambled data of the production content of the QR code.

4. The identity authentication method based on a trusted tag according to claim 3, wherein The specific steps for encrypting the production content of the QR code based on the Euler function are as follows: Extract the scrambled data of the production content of multiple QR codes. Respectively convert multiple scrambled data into decimal quantization data. Randomly construct two prime numbers. Obtain the modulus corresponding to the quantization data according to the two prime numbers respectively. Obtain the Euler function value according to the Euler function, combining the two prime numbers. Obtain the first exponent according to the Euler function value. Obtain the second exponent according to the first exponent and the Euler function value. Obtain the first encryption key and the second encryption key according to the first exponent, the second exponent, and the modulus. Among them, the calculation formula of the Euler function value is: ; Among them, the calculation formula of the modulus is: N = pq; Among them, the specific composition of the first encryption key and the second encryption key: First encryption key: ; Second encryption key: ; In the formula, are two selected prime numbers respectively, is the value of the Euler's totient function, is the first exponent, is the second exponent, is the modulus; Respectively extract multiple quantization data. Raise the quantization data to the power according to the first exponent to obtain the power exponent. Obtain the corresponding remainder according to the power exponent, combining the modulus. Replace the quantization data according to the remainder, thereby completing the encryption of the production content data of the QR code.

5. The identity authentication method based on a trusted tag according to claim 4, wherein The specific steps for automatically generating a question code based on the identity tag are as follows: The server obtains the time value T accurate to milliseconds and encrypts T using the MD5 algorithm to obtain the hash value H T = MD5(T, 32); Randomly extract a security question Q from the database, with the question number being i, and obtain the current timestamp t a , concatenate the bit strings of the current several key information to obtain the plaintext M = {t, a, i, Q}; Take HT as the SM4 algorithm key K, encrypt the plaintext M with the SM4 key K to obtain the ciphertext C = SM4(M, K), and generate a question code from the key K and the ciphertext C.

6. The identity authentication method based on a trusted label according to claim 5, wherein The specific steps for the user to scan and parse the question code are as follows: Obtain the key K and the ciphertext C from the decoding result, and decrypt the ciphertext C using the SM4 key K to obtain the plaintext M1 = SM4(C, K); Intercept the timestamp t from the plaintext M1 a , and obtain the current timestamp t b , calculate the time interval ∆t = t b - t a , and check whether ∆t exceeds the maximum time interval of 120s; If it exceeds, prompt the user that the question code has expired. If it does not exceed, continue to the next step. ∆t does not exceed the maximum time interval. Intercept the security question Q from the plaintext M1, where the question number is i, and output the question Q; After completing the parsing of the question code, output the obtained security question Q on the interface to prompt the user to answer.

7. The identity authentication method based on a trusted tag according to claim 6, wherein The generation of the corresponding identity code specifically includes the following steps: The user inputs the security question answer Si according to the given security question Q; Take the current timestamp t c , the question number is i, and the answer Si to the security question entered by the user. Concatenate the bit strings of these key information to obtain the plaintext M = {t c + i + Si}; Use the public key to encrypt the plaintext M to obtain the ciphertext C, generate an identity code from the ciphertext C, and the user places the generated identity code in front of the QR code scanner to wait for the authentication result.

8. The identity authentication method based on a trusted label according to claim 7, wherein, The trusted authentication system parses and compares the identity code to determine whether the user's identity authentication is correct, specifically including the following steps: The server processes the scanning result returned by the QR code scanner to obtain a string of ciphertext, and performs collision decryption on the ciphertext C. The collision decryption is to obtain all users' private keys in the database to verify whether [dA]C1 = (x2, y2) exists; If dA exists, the decryption is successful to obtain the plaintext M´. If the decryption fails, it proves that the encryptor is an illegal user and the collision decryption fails; Intercept the timestamp t from the plaintext M´ c , and take the current timestamp t d . Calculate the time interval ∆t = t d - t c ; Check whether ∆t exceeds the maximum time interval of 60s. If it exceeds, prompt the user that the identity code has expired. If it does not exceed, continue to the next step; If it does not exceed the maximum time interval, intercept the information of the security question answer Si with the question number i input by the user from the plaintext M´, and compare it one by one with the user information bound to the user's own identifier corresponding to the private key found in the database. If the comparison is successful, the authentication is successful. If the comparison fails, return the comparison result.

9. A trusted label-based identity authentication system for implementing a trusted label-based identity authentication method as described in any one of claims 1-8, characterized in that, Include: A registration module, which is used for the computer terminal to send an access request to the trusted authentication gateway and register the identity label of the computer terminal in the trusted authentication gateway. The identity label includes the user's own identifier, private key, and public key, and the public key is imported to the user in the form of a QR code; A public key encryption module, which is used for tracing the QR code in the trusted authentication system, obtaining the production content of the QR code, scrambling it, and encrypting the production content of the QR code based on the Euler function; A question code generation module, which is used for automatically generating a question code based on the identity label; An identity code generation module, which is used for the user to scan and parse the question code to generate a corresponding identity code; A comparison module, which is used for the trusted authentication system to parse and compare the identity code to determine whether the user's identity authentication is correct.

10. An electronic device, comprising at least one processor; and a memory communicatively connected to the at least one processor; characterized in that, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method according to any one of claims 1-8.