Authentication method and system
Triple authentication is carried out through UKEY equipment, combined with PIN code, signature value and certificate legality verification, the security risks of user name and password authentication methods are solved, and high security and convenient identity authentication is achieved.
Patent Information
- Application Number
- CN202510474526.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-07-08
AI Technical Summary
The existing username and password authentication methods have security risks, which are difficult to meet the requirements of modern information systems for high security and convenience of identity authentication.
The UKEY device is used for triple authentication, and the PIN code is locally verified, the signature value is generated and the certificate is obtained. Combined with the legality verification of the back-end server, a certificate of successful authentication is generated.
It achieves a high degree of security and convenience, ensures that only legitimate users can access the system, and improves the security and reliability of identity authentication.
Smart Images

Figure CN120281544A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly relates to an authentication method and system. Background Art
[0002] With the rapid development of the Internet, network applications have become increasingly popular, and security issues such as hacker attacks and data leaks have become more prominent. There are many security risks in the username and password authentication methods of the media, such as weak passwords, password reuse, etc., and password management is also very difficult. Single password authentication can no longer meet higher security requirements, and higher requirements for the security and convenience of identity authentication have been put forward in various application scenarios such as e-commerce, online banking, military systems, and government agencies. As a reliable identity authentication method, UKey authentication has high security and convenience, is applicable to multiple fields, and meets the multiple requirements of modern information systems for security and convenience. Summary of the Invention
[0003] This application provides an authentication method and system.
[0004] In a first aspect, this application provides an authentication method, which is applied to an authentication system. The authentication system includes a front-end device and a back-end server; the authentication method includes:
[0005] The front-end device verifies the PIN code input by the user based on the locally inserted UKEY; after the verification is passed, it sends a random number request to the password platform to obtain a random number; generates a signature value based on the random number, obtains the certificate of the UKEY, and sends the PIN code, signature value, and certificate to the back-end server;
[0006] The back-end server receives the PIN code, signature value, and certificate sent by the front-end device; after determining that the UKEY login authentication is authorized locally, it determines whether the PIN code is bound to the registered UKEY user; when the determination result is yes, it verifies the legality of the signature value and certificate based on the password platform; when it determines that the signature value and certificate are legal, it generates an authentication success certificate and sends the authentication success certificate to the front-end device.
[0007] Optionally, the step of verifying the PIN code input by the user based on the locally inserted UKEY includes:
[0008] After detecting that the UKEY is inserted locally, read the device serial number of the UKEY and the first PIN code bound to the device serial number;
[0009] Obtain the second PIN code input by the user based on the login page, and determine whether the first PIN code and the second PIN code are the same PIN code. Among them, if the first PIN code and the second PIN code are the same PIN code, it is determined that the second PIN code verification is passed.
[0010] Optionally, the backend server includes a portal system microservice and a UKEY login authentication and authorization microservice; the binding relationship between the PIN code of the legal UKEY and the registered UKEY user bound to it is maintained on the portal system microservice;
[0011] After determining that the authorization of UKEY login authentication is enabled locally, the steps of determining whether the PIN code is bound to the registered UKEY user include:
[0012] The portal system microservice determines whether the authorization of UKEY login authentication is enabled locally through the UKEY login authentication and authorization microservice;
[0013] When the portal system microservice determines that the authorization of UKEY login authentication is enabled locally, based on the binding relationship between the PIN code of the legal UKEY maintained locally and the registered UKEY user bound to it, it determines whether the PIN code is bound to the registered UKEY user.
[0014] Optionally, the password platform is a third-party password server, and a private key for verifying the signature value and certificate legality is maintained on the third-party password server.
[0015] Optionally, the steps of verifying the signature value and certificate legality based on the password platform include:
[0016] Call the interface of the third-party password server, and verify the legality of the signature value and certificate based on the private key maintained on the third-party password server.
[0017] In a second aspect, the present application provides an authentication system, which includes a front-end device and a backend server; wherein,
[0018] The front-end device is used to verify the PIN code input by the user based on the locally inserted UKEY; after the verification is passed, send a random number request to the password platform to obtain a random number; generate a signature value based on the random number, obtain the certificate of the UKEY, and send the PIN code, signature value and certificate to the backend server;
[0019] The backend server is used to receive the PIN code, signature value, and certificate sent by the front-end device; after determining that the authorization for UKEY login authentication is enabled locally, determine whether the PIN code is bound to a registered UKEY user; when the determination result is yes, verify the legality of the signature value and certificate based on the password platform; when it is determined that the signature value and certificate are legal, generate a certificate for successful authentication and send the certificate for successful authentication to the front-end device.
[0020] Optionally, when verifying the PIN code entered by the user based on the locally inserted UKEY, the front-end device is specifically used for:
[0021] After detecting that the UKEY is inserted locally, read the device serial number of the UKEY and the first PIN code bound to the device serial number;
[0022] Obtain the second PIN code entered by the user based on the login page, and determine whether the first PIN code and the second PIN code are the same PIN code. Among them, if the first PIN code and the second PIN code are the same PIN code, it is determined that the second PIN code is verified successfully.
[0023] Optionally, the backend server includes a portal system microservice and a UKEY login authentication authorization microservice; the binding relationship between the PIN code of the legal UKEY and the registered UKEY user bound to it is maintained on the portal system microservice;
[0024] After determining that the authorization for UKEY login authentication is enabled locally, when determining whether the PIN code is bound to a registered UKEY user,
[0025] The portal system microservice determines whether the authorization for UKEY login authentication is enabled locally through the UKEY login authentication authorization microservice;
[0026] When the portal system microservice determines that the authorization for UKEY login authentication is enabled locally, based on the binding relationship between the PIN code of the legal UKEY and the registered UKEY user bound to it maintained locally, determine whether the PIN code is bound to a registered UKEY user.
[0027] Optionally, the password platform is a third-party password server, and a private key for verifying the legality of the signature value and certificate is maintained on the third-party password server.
[0028] Optionally, when verifying the legality of the signature value and certificate based on the password platform, the backend server is specifically used for:
[0029] Call the interface of the third-party password server, and verify the legality of the signature value and the certificate based on the private key maintained on the third-party password server.
[0030] In summary, an authentication method provided by an embodiment of the present application is applied to an authentication system, and the authentication system includes a front-end device and a back-end server; the authentication method includes: the front-end device verifies the PIN code input by the user based on the locally inserted UKEY; after the verification is passed, a random number request is sent to the password platform to obtain a random number; a signature value is generated based on the random number, and the certificate of the UKEY is obtained, and the PIN code, the signature value, and the certificate are sent to the back-end server; the back-end server receives the PIN code, the signature value, and the certificate sent by the front-end device; after determining that the UKEY login authentication is authorized locally, it is determined whether the PIN code is bound to the registered UKEY user; when the determination result is yes, the legality of the signature value and the certificate is verified based on the password platform; when it is determined that the signature value and the certificate are legal, a certificate of successful authentication is generated and sent to the front-end device.
[0031] Using the authentication method provided by the embodiment of the present application, triple authentication is adopted, which has extremely high security. Combining the PIN code, License, certificate and signature value of the UKEY input by the user for authentication of three factors to ensure that only legitimate users can access the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments of the present application or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings in the embodiments of the present application.
[0033] Figure 1 It is a detailed flowchart of an authentication method provided by an embodiment of the present application;
[0034] Figure 2 It is a schematic diagram of a login interface provided by an embodiment of the present application;
[0035] Figure 3 It is a schematic diagram of a page for registering UKEY users provided by an embodiment of the present application;
[0036] Figure 4 It is a schematic diagram of a page for modifying an original ordinary user into a UKEY user provided by an embodiment of the present application;
[0037] Figure 5A schematic diagram of an authentication interaction process provided by an embodiment of the present application;
[0038] Figure 6 A schematic structural diagram of an authentication system provided by an embodiment of the present application. Detailed implementation manners
[0039] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments and do not limit the present application. The singular forms "a", "the" and "said" used in the present application and the claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to any or all possible combinations including one or more of the associated listed items.
[0040] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "when" or "while" or "in response to determining".
[0041] Exemplarily, refer to Figure 1 As shown, it is a detailed flowchart of an authentication method provided by an embodiment of the present application, which is applied to an authentication system. The authentication system includes a front-end device and a back-end server. The method includes the following steps:
[0042] Step 100: The front-end device verifies the PIN code input by the user based on the locally inserted UKEY; after the verification is passed, it sends a request for obtaining a random number to the password platform to obtain a random number; generates a signature value based on the random number, obtains the certificate of the UKEY, and sends the PIN code, the signature value and the certificate to the back-end server.
[0043] In the embodiments of the present application, when verifying the PIN code input by the user based on the locally inserted UKEY, a preferred implementation manner is:
[0044] After detecting that the UKEY (USB Key) is locally inserted, read the device serial number of the UKEY and the first PIN code (Personal Identification Number) bound to the device serial number;
[0045] Obtain the second PIN code entered by the user based on the login page, and determine whether the first PIN code and the second PIN code are the same PIN code. Among them, if the first PIN code and the second PIN code are the same PIN code, it is determined that the second PIN code verification is passed.
[0046] Specifically, the front-end device provides a login / verification page. When the UKEY is inserted into the front-end device, the front-end device can automatically recognize the device serial number of the UKEY and display it on the login / verification page (modification is not allowed). Further, while reading the device serial number of the UKEY, the front-end device reads the PIN code of the UKEY bound to the device serial number of the UKEY.
[0047] In the embodiment of the present application, on the window displaying the device serial number on the login / verification page, a PIN code input box is displayed for the user to enter the PIN code. Exemplarily, refer to Figure 2 As shown, it is a schematic diagram of a login interface provided by the embodiment of the present application; when the user logs in using the USB Key method, the device serial number of the UKEY read is displayed on the corresponding window, and at the same time, a PIN code input box for the user to enter the PIN code is shown.
[0048] After the user enters the PIN, the front-end authentication module (a functional module of the front-end device) will verify the validity of the PIN code. Specifically, it is determined whether the PIN code entered by the user is the same as the PIN code on the UKE locally. If they are the same, it is determined that the PIN code is valid and the subsequent authentication process is executed. If they are different, it is determined that the PIN code is invalid and the authentication process ends.
[0049] In practical applications, when it is determined that the PIN code entered by the user is valid and the PIN code verification is passed, the front-end authentication module will call a specified interface (such as SKFKEY.SKF.OpenContainer()) to obtain a container handle, and use the obtained handle to send a request for obtaining a random number to the password platform. After obtaining the random number from the password platform, the front-end authentication module encodes the random number (such as Base64 encoding), and then calls the UEKY interface (such as SKFKEY.SKF.SignData()) to sign the encoded data (random number). The front-end authentication module calls the interface of the UKEY (such as SKFKEY.SKF_ExportCertificate()) to obtain a certificate from the UKEY, and then encapsulates the certificate, the PIN code (transmitted after being encrypted by the RSA algorithm), and the signature value into an entity class and sends it to the back-end server (such as the portal system microservice of the back-end server).
[0050] Step 110: The back-end server receives the PIN code, signature value and certificate sent by the front-end device; after determining that the UKEY login authentication authorization is enabled locally, determines whether the PIN code is bound to a registered UKEY user; when the judgment result is yes, verifies the legitimacy of the signature value and certificate based on the password platform; when it is determined that the signature value and certificate are legal, generates a successful authentication credential, and sends the successful authentication credential to the front-end device.
[0051] In the embodiment of the present application, the backend server includes a portal system microservice and a UKEY login authentication authorization microservice; the portal system microservice maintains the binding relationship between the PIN code of a legitimate UKEY and the registered UKEY user bound to it.
[0052] Then, after determining that the UKEY login authentication authorization is enabled locally, when determining whether the PIN code is bound to a registered UKEY user, a better implementation method is:
[0053] The portal system microservice determines whether the UKEY login authentication authorization is enabled locally through the UKEY login authentication authorization microservice; when the portal system microservice determines that the UKEY login authentication authorization is enabled locally, it determines whether the PIN code is bound to the registered UKEY user based on the binding relationship between the locally maintained legal UKEY PIN code and the registered UKEY user bound to it.
[0054] In actual applications, the authentication and authorization microservice can be a license service. The portal system microservice needs to register the license authorization information of UKEY login authentication with the license service in advance. In other words, the portal system calls the interface of the license service to determine whether it is the authorization information of UKEY login authentication.
[0055] Specifically, exemplarily, see Figure 3 As shown, a schematic diagram of a UKEY user registration page provided in an embodiment of the present application is provided. The user can choose to create a UKEY user, select the authentication method as UKEY authentication, and bind a PIN code (one UKEY user corresponds to one PIN code and one UKEY).
[0056] Further, illustratively, see Figure 4 As shown, it is a schematic diagram of a page for modifying an original ordinary user to a UKEY user provided in an embodiment of the present application. The user can choose to change the original user authentication method to UKEY authentication, change the original authenticated user to a UKEY user, and bind a PIN code (one UKEY user corresponds to one PIN code, corresponding to one UKEY).
[0057] In the embodiments of the present application, when creating a UKEY user / modifying an ordinary user to a UKEY user, a user password is set for the account. As a transitional usage method or when the UKEY device is lost, the password is used for login.
[0058] In the embodiments of the present application, the password platform is a third-party password server, and a private key for verifying the signature value and certificate legality is maintained on the third-party password server.
[0059] Then, the steps for verifying the legality of the signature value and certificate based on the password platform include:
[0060] Call the interface of the third-party password server to verify the legality of the signature value and certificate based on the private key maintained on the third-party password server.
[0061] Preferably, the portal system decrypts the PIN code, searches for the UKEY user corresponding to the PIN code. After finding the UKEY user corresponding to the PIN, it then calls the interface (such as the FM_DSVS_VerifySignedData() interface) of the signature verification server in the third-party password platform to verify the legality of the certificate and signature. In the embodiments of the present application, the private keys required for verification are all stored in the third-party password platform, rather than inside the portal system, further improving the security level of authentication.
[0062] After the legality verification of the certificate and signature value passes, the portal system generates an identity authentication credential Token based on field information such as the username and IP address of the current user using a preset tool, and returns it to the front-end device, and the page displays that the user has successfully logged in to the portal system.
[0063] The authentication interaction process provided by the embodiments of the present application will be described in detail in combination with specific application scenarios. Exemplarily, refer to Figure 5 As shown, it is a schematic diagram of an authentication interaction process provided by the embodiments of the present application;
[0064] It should be noted that the UKEY (USB KEY portable device) is plugged into the front-end device (client machine), and the UKEY has been issued a certificate by the third-party CA system. Users who authenticate with the UKEY are pre-registered on the portal system page of the back-end server.
[0065] Open the login page, the system automatically identifies the device serial number, and the front-end authentication module reads the device serial number from the UKEY and displays it on the login page, and does not allow modification, waiting for the user to input the PIN code. When the user inputs the PIN, the front-end authentication module verifies the validity of the PIN code. At this time, it is the first level of authentication.
[0066] After the first - level authentication is successful, the front - end authentication module will obtain the container handle. After obtaining the handle, it will send a request to the password platform to obtain a random number. The front - end authentication module encodes the obtained random number in Base64, and then signs the encoded data. The front - end authentication module obtains the certificate from the UKEY, and then encapsulates the certificate, PIN code (transmitted after being encrypted by the RSA algorithm), and signature value into an entity class and sends it to the portal system.
[0067] After receiving the request, the portal system calls the interface of the License service to determine whether the authorization function for UKEY login authentication is enabled. It should be noted that the portal system needs to register the License authorization information for UKEY login authentication with the License service in advance. At this time, it is the second - level authentication.
[0068] After the second - level authentication passes, the portal system decrypts the PIN code, finds the user corresponding to the PIN code, and then calls the signature verification server in the password platform to verify the legality of the certificate and signature value. At this time, it is the third - level authentication. In particular, the private keys for verification are all stored in the third - party service password platform, rather than inside the portal system, which further improves the security level of authentication.
[0069] After the third - level authentication is verified to pass, the portal system will generate an identity authentication credential Token based on the user name, IP address and other field information of the current user by using the JWT tool, and return it to the front - end device, and the page shows a successful login.
[0070] Exemplarily, refer to Figure 6 As shown, it is a schematic structural diagram of an authentication system provided by an embodiment of the present application. The authentication system includes a front - end device 60 and a back - end server 61; among them,
[0071] The front - end device 60 is used to verify the PIN code input by the user based on the UKEY inserted locally; after the verification passes, it sends a request to obtain a random number to the password platform to obtain a random number; generates a signature value based on the random number, obtains the certificate of the UKEY, and sends the PIN code, signature value and certificate to the back - end server 61;
[0072] The back - end server 61 is used to receive the PIN code, signature value and certificate sent by the front - end device 60; after determining that the authorization for UKEY login authentication is enabled locally, it determines whether the PIN code is bound to the registered UKEY user; when the determination result is yes, it verifies the legality of the signature value and certificate based on the password platform; when it determines that the signature value and certificate are legal, it generates a credential for successful authentication and sends the credential for successful authentication to the front - end device 60.
[0073] Optionally, when verifying the PIN code input by the user based on the locally inserted UKEY, the front-end device 60 is specifically configured to:
[0074] After detecting the locally inserted UKEY, read the device serial number of the UKEY and the first PIN code bound to the device serial number;
[0075] Obtain the second PIN code input by the user based on the login page, and determine whether the first PIN code and the second PIN code are the same PIN code. If the first PIN code and the second PIN code are the same PIN code, it is determined that the second PIN code is verified successfully.
[0076] Optionally, the back-end server 61 includes a portal system microservice and a UKEY login authentication and authorization microservice; the binding relationship between the PIN code of the legal UKEY and the registered UKEY user bound to it is maintained on the portal system microservice;
[0077] When determining whether the PIN code is bound to the registered UKEY user after determining that the UKEY login authentication authorization is enabled locally,
[0078] The portal system microservice determines whether the UKEY login authentication authorization is enabled locally through the UKEY login authentication and authorization microservice;
[0079] When the portal system microservice determines that the UKEY login authentication authorization is enabled locally, based on the binding relationship between the PIN code of the legal UKEY and the registered UKEY user maintained locally, it determines whether the PIN code is bound to the registered UKEY user.
[0080] Optionally, the password platform is a third-party password server, and a private key for verifying the signature value and certificate legality is maintained on the third-party password server.
[0081] Optionally, when verifying the signature value and certificate legality based on the password platform, the back-end server 61 is specifically configured to:
[0082] Call the interface of the third-party password server, and verify the legality of the signature value and certificate based on the private key maintained on the third-party password server.
[0083] The systems, devices, modules, or units described in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, laptop computer, cellular phone, camera phone, smart phone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or a combination of any several of these devices.
[0084] For convenience of description, when describing the above devices, various units are described separately according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in one or more software and / or hardware.
[0085] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, system, or computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0086] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate a device for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or multiple flows and / or blocks
[0087] Moreover, these computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one or more of the flows Figure 1 or multiple flows and / or blocks
[0088] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to generate a computer-implemented process, thereby providing instructions for implementing the steps specified in one process or multiple processes and / or blocks Figure 1 one process or multiple processes and / or blocks Figure 1 in one block or multiple blocks.
[0089] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the scope of protection of the present application.
Claims
1. A certification method, characterized in that, Applied to an authentication system, the authentication system includes a front-end device and a back-end server; the authentication method includes: The front-end device verifies the PIN code entered by the user based on the locally inserted UKEY; after the verification is passed, it sends a random number request to the password platform to obtain a random number; generates a signature value based on the random number, obtains the certificate of the UKEY, and sends the PIN code, signature value, and certificate to the back-end server; The back-end server receives the PIN code, signature value, and certificate sent by the front-end device; after determining that the UKEY login authentication is authorized locally, it determines whether the PIN code is bound to a registered UKEY user; when the determination result is yes, it verifies the legality of the signature value and certificate based on the password platform; when it determines that the signature value and certificate are legal, it generates an authentication success certificate and sends the authentication success certificate to the front-end device.
2. The method according to claim 1, characterized in that, The step of verifying the PIN code entered by the user based on the locally inserted UKEY includes: After detecting the locally inserted UKEY, read the device serial number of the UKEY and the first PIN code bound to the device serial number; Obtain the second PIN code entered by the user based on the login page, and determine whether the first PIN code and the second PIN code are the same PIN code. Among them, if the first PIN code and the second PIN code are the same PIN code, it is determined that the second PIN code verification is passed.
3. The method according to claim 1 or 2, characterized in that, The back-end server includes a portal system microservice and a UKEY login authentication authorization microservice; the binding relationship between the PIN code of the legal UKEY and the registered UKEY user bound to it is maintained on the portal system microservice; After determining that the UKEY login authentication is authorized locally, the step of determining whether the PIN code is bound to a registered UKEY user includes: The portal system microservice determines whether the UKEY login authentication is authorized locally through the UKEY login authentication authorization microservice; When the portal system microservice determines that the UKEY login authentication is authorized locally, it determines whether the PIN code is bound to a registered UKEY user based on the binding relationship between the PIN code of the legal UKEY and the registered UKEY user bound to it maintained locally.
4. The method according to claim 3, characterized in that, The password platform is a third-party password server, and a private key for verifying the legality of the signature value and certificate is maintained on the third-party password server.
5. The method according to claim 4, characterized in that, The step of verifying the legality of the signature value and certificate based on the password platform includes: Call the interface of the third-party password server to verify the legality of the signature value and certificate based on the private key maintained on the third-party password server.
6. An authentication system, characterized in that, The authentication system includes a front-end device and a back-end server; among them, The front-end device is used to verify the PIN code entered by the user based on the locally inserted UKEY; after the verification is passed, it sends a random number request to the password platform to obtain a random number; generates a signature value based on the random number, obtains the certificate of the UKEY, and sends the PIN code, signature value, and certificate to the back-end server; The back-end server is used to receive the PIN code, signature value, and certificate sent by the front-end device; after determining that the UKEY login authentication authorization is enabled locally, it determines whether the PIN code is bound to the registered UKEY user; when the determination result is yes, it verifies the legality of the signature value and certificate based on the password platform; when it determines that the signature value and certificate are legal, it generates an authentication success certificate and sends the authentication success certificate to the front-end device.
7. The system according to claim 6, characterized in that, When verifying the PIN code entered by the user based on the locally inserted UKEY, the front-end device specifically is used for: After detecting the locally inserted UKEY, it reads the device serial number of the UKEY and the first PIN code bound to the device serial number; Obtains the second PIN code entered by the user based on the login page, and determines whether the first PIN code and the second PIN code are the same PIN code. Among them, if the first PIN code and the second PIN code are the same PIN code, it is determined that the second PIN code verification is passed.
8. The system according to claim 6 or 7, characterized in that, The back-end server includes a portal system microservice and a UKEY login authentication authorization microservice; the binding relationship between the PIN code of the legal UKEY and the registered UKEY user bound to it is maintained on the portal system microservice; After determining that the UKEY login authentication authorization is enabled locally, when determining whether the PIN code is bound to the registered UKEY user, The portal system microservice determines whether the UKEY login authentication authorization is enabled locally through the UKEY login authentication authorization microservice; When the portal system microservice determines that the UKEY login authentication authorization is enabled locally, it determines whether the PIN code is bound to the registered UKEY user based on the binding relationship between the PIN code of the legal UKEY and the registered UKEY user maintained locally.
9. The system according to claim 8, wherein The password platform is a third-party password server, and a private key for verifying the legality of the signature value and certificate is maintained on the third-party password server.
10. The system according to claim 9, wherein, When verifying the legality of the signature value and certificate based on the password platform, the back-end server specifically is used for: Invokes the interface of the third-party password server, and verifies the legality of the signature value and certificate based on the private key maintained on the third-party password server.