Identity verification method and device, computer equipment, readable storage medium and program product
The dual encryption method using snapshot keys and public key encryption for login password verification strengthens account security by ensuring intercepted passwords cannot be used for unauthorized access, providing high-security authentication without additional factors.
Patent Information
- Application Number
- CN202510791940.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-13
AI Technical Summary
The existing account password authentication method is easily stolen by malicious personnel, resulting in unsafe user accounts.
The randomly generated snapshot key and reference snapshot key are used to double-encrypt the initial login password, and the encrypted snapshot key is generated through public key encryption. The server performs decryption and account verification, and uses the key relationship table to query the intermediate snapshot key for further decryption and verification.
Improve the security of the account, prevent password leakage and illegal login, and enhance the security of identity authentication.
Smart Images

Figure CN120321038A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular, to an authentication method, device, computer device, computer-readable storage medium, and computer program product. Background Art
[0002] With the rapid development of Internet identity authentication technology, the authentication method based on account password (account-password) always occupies the mainstream position due to its advantages such as low deployment cost and low user cognitive threshold.
[0003] Currently, the relatively common user authentication method is account-password authentication. In the scenario where the server needs to perform password strength verification, many solutions use a predefined key to encrypt the transmitted password once. If malicious personnel steal the transmitted password ciphertext, then they can log in to the user account using this method, resulting in the insecurity of the user account. Summary of the Invention
[0004] Based on this, it is necessary to provide an authentication method, device, computer device, computer-readable storage medium, and computer program product that can improve security for the above technical problems.
[0005] In a first aspect, the present application provides an authentication method applied to a server; the method includes:
[0006] Receiving an authentication instruction sent by a client; the authentication instruction carries a ciphertext, an encrypted snapshot key, and a user identifier; the ciphertext is obtained by the client encrypting an initial login password using the snapshot key and a reference snapshot key; the encrypted snapshot key is obtained by the client encrypting the snapshot key using a public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time;
[0007] Decrypting the encrypted snapshot key and the ciphertext to obtain a reference login password, and performing a first account-password verification on the reference login password to obtain an account-password verification result;
[0008] When the account-password verification result is not passed and the key relationship table is available for use, querying an intermediate snapshot key from the key relationship table according to the user identifier, decrypting the reference login password using the intermediate snapshot key to obtain a decryption result, and performing a second account-password verification on the decryption result to obtain an authentication result; the intermediate snapshot key is the decrypted snapshot key obtained by the server during the last authentication.
[0009] In one embodiment, decrypting the encrypted snapshot key and the ciphertext to obtain a reference login password, and performing a first account-password verification on the reference login password to obtain an account-password verification result, including:
[0010] Decrypting the encrypted snapshot key according to the private key to obtain the decrypted snapshot key;
[0011] Decrypting the ciphertext based on the decrypted snapshot key to obtain the reference login password;
[0012] Calculating a first hash value corresponding to the user identifier and the reference login password, and matching the hash value with a pre-stored first credential to obtain the account-password verification result.
[0013] In one embodiment, decrypting the reference login password using the intermediate snapshot key to obtain a decryption result, and performing a second account-password verification on the decryption result to obtain an identity verification result, including:
[0014] Decrypting the reference login password using the intermediate snapshot key to obtain the decryption result;
[0015] Calculating a second hash value corresponding to the user identifier and the decryption result, and matching the second hash value with a pre-stored second credential to obtain the identity verification result.
[0016] In a second aspect, the present application provides an identity verification method applied to a client, the method including:
[0017] Obtaining an initial login password and a user identifier;
[0018] Encrypting the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time;
[0019] Encrypting the snapshot key according to a pre-obtained public key to obtain an encrypted snapshot key;
[0020] Generating a verification instruction according to the user identifier, the ciphertext, and the encrypted snapshot key, and sending the verification instruction to the server; the server performs identity verification according to the user identifier, the ciphertext, and the encrypted snapshot key.
[0021] In one embodiment, encrypting the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext, including:
[0022] Encrypt the initial login password with the randomly generated snapshot key to obtain a reference ciphertext;
[0023] Encrypt the reference ciphertext with the reference snapshot key to obtain the ciphertext;
[0024] After obtaining the ciphertext, it further includes:
[0025] Save the ciphertext and replace the stored initial login password with the ciphertext.
[0026] In a third aspect, the present application provides an identity authentication device applied to a server side. The device includes:
[0027] A receiving module, configured to receive an authentication instruction sent by a client; the authentication instruction carries a ciphertext, an encrypted snapshot key, and a user identifier; the ciphertext is obtained by the client encrypting the acquired initial login password with the snapshot key and the reference snapshot key; the encrypted snapshot key is obtained by the client encrypting the snapshot key with a public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time.
[0028] A decryption module, configured to decrypt the encrypted snapshot key and the ciphertext to obtain a reference login password, and perform a first account-password verification on the reference login password to obtain an account-password verification result;
[0029] A verification module, configured to, when the account-password verification result is not passed and the key relationship table is available for use, query an intermediate snapshot key from the key relationship table according to the user identifier, decrypt the reference login password with the intermediate snapshot key to obtain a decryption result, and perform a second account-password verification on the decryption result to obtain an identity authentication result; the intermediate snapshot key is the decrypted snapshot key obtained by the server side during the last identity authentication.
[0030] In a fourth aspect, the present application provides an identity authentication device applied to a client side. The device includes:
[0031] An acquisition module, configured to acquire an initial login password and a user identifier;
[0032] A first encryption module, configured to encrypt the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time;
[0033] A second encryption module, configured to encrypt the snapshot key according to a pre-acquired public key to obtain an encrypted snapshot key;
[0034] A sending module, configured to generate an authentication instruction according to the user identifier, the ciphertext, and the encrypted snapshot key, and send the authentication instruction to the server; the server performs identity authentication according to the user identifier, the ciphertext, and the encrypted snapshot key.
[0035] In a fifth aspect, the present application provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the method in any one of the above embodiments are implemented.
[0036] In a sixth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in any one of the above embodiments are implemented.
[0037] In a seventh aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method in any one of the above embodiments are implemented.
[0038] The above identity authentication method, device, computer device, computer-readable storage medium, and computer program product receive an authentication instruction sent by a client, decrypt the ciphertext according to the encrypted snapshot key carried in the authentication instruction to obtain a reference login password, and perform a first account-password verification on the reference login password to obtain an account-password verification result. When the account-password verification result fails, it indicates that the client has double-encrypted the initial login password using the snapshot key and the reference snapshot key. At this time, query the key relationship table, query the decrypted snapshot key obtained by the server during the previous identity authentication through the user identifier in the key relationship table, and decrypt the reference login password to obtain a decryption result. After obtaining the decryption result, perform a second account-password verification on the decryption result to obtain the final identity authentication. In this way, the server can make the account have highly secure authentication without introducing multi-factor authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for describing the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained without creative efforts based on these drawings.
[0040] Figure 1 It is an application environment diagram of the identity authentication method in an embodiment;
[0041] Figure 2Schematic flowchart of an authentication method in an embodiment;
[0042] Figure 3 Schematic flowchart of the authentication steps performed by a client in an embodiment;
[0043] Figure 4 Schematic flowchart of an authentication method in another embodiment;
[0044] Figure 5 Schematic flowchart of the authentication steps of a server in an embodiment;
[0045] Figure 6 Block diagram of an authentication device in an embodiment;
[0046] Figure 7 Block diagram of an authentication device in another embodiment;
[0047] Figure 8 Internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0048] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0049] The authentication method provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. Among them, the client 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed on the cloud or other network servers. The client 102 obtains the initial login password and the user identifier; encrypts the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; encrypts the snapshot key with a pre-obtained public key to obtain an encrypted snapshot key; generates an authentication instruction according to the user identifier, the ciphertext and the encrypted snapshot key, and sends the authentication instruction to the server; the server performs identity authentication according to the user identifier, the ciphertext and the encrypted snapshot key; the server performs identity authentication according to the user identifier, the ciphertext and the encrypted snapshot key. The server 104 receives the authentication instruction sent by the client; the authentication instruction carries the ciphertext, the encrypted snapshot key and the user identifier; the ciphertext is obtained after the client encrypts the obtained initial login password with the snapshot key and the reference snapshot key; the encrypted snapshot key is obtained after the client encrypts the snapshot key with the public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; decrypts the encrypted snapshot key and the ciphertext to obtain a reference login password, and performs a first account-password verification on the reference login password to obtain an account-password verification result; when the account-password verification result is not passed and the key relationship table is available for use, query the intermediate snapshot key from the key relationship table according to the user identifier, decrypt the reference login password with the intermediate snapshot key to obtain a decryption result, and perform a second account-password verification on the decryption result to obtain an identity authentication result; the intermediate snapshot key is the decrypted snapshot key obtained by the server during the last identity authentication. Among them, the client 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. The server 104 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0050] In an exemplary embodiment, as Figure 2 shown, an authentication method is provided, and this method is applied to Figure 1Taking the client 102 in [as an example, the following steps 202 to 208 are included. Among them:
[0051] Step 202, obtain the initial login password and the user identifier.
[0052] Among them, the initial login password refers to the password of the user obtained by the client, which is used for login verification. The user identifier refers to the information that uniquely identifies the user, that is, the user's ID.
[0053] Optionally, there are two ways to obtain the initial login password. Exemplarily, one is the password entered by the user using the virtual keyboard; Exemplarily, the other is the "memory" of the client.
[0054] Exemplarily, when the user logs in to a certain website, the user can enter the password and the user identifier through the virtual keyboard. At this time, the client will obtain the corresponding initial login password and the user identifier.
[0055] Exemplarily, if the user has logged in to the website on the same device before and has selected "Remember Password" or used the autofill function, the client can automatically fill in the user's initial login password and user identifier based on the encrypted credentials stored locally or the secure storage mechanism, so as to complete the login quickly.
[0056] Step 204, encrypt the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; The reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time.
[0057] Among them, the snapshot key refers to a one-time key, which is generated by the client, regenerated for each login session, stored in the client memory, encrypted and transmitted to the server through the public key, and the server authenticates the login according to different security policies; The reference snapshot key is the snapshot key generated when the user logs in with the same account on the same client. It should be noted that the snapshot key is stored in the memory and is not written into any persistent device of the client. Each time the login interface is entered, the snapshot key is refreshed, and this key is used to encrypt the initial login password.
[0058] Optionally, there may be a sequence in using the randomly generated snapshot key and the reference snapshot key to encrypt the initial login password. For example, the randomly generated snapshot key can be generated first to encrypt the initial login password, and then the reference snapshot key can be used for re-encryption to obtain the encrypted initial login key, that is, the ciphertext in this embodiment. At this time, it means that the initial login password may be encrypted twice.
[0059] Optionally, a randomly generated snapshot key and a reference snapshot key can also be used simultaneously to encrypt the initial login password. The two keys are used to encrypt the initial login password simultaneously to enhance the data's anti-cracking ability.
[0060] Whether using a randomly generated snapshot key to encrypt the initial login password, the encryption method can be a symmetric encryption algorithm (such as AES), an asymmetric encryption algorithm (such as RSA), or a hash algorithm combined with salt value encryption (such as PBKDF2, bcrypt), etc., multiple secure encryption methods.
[0061] Optionally, a secure random algorithm such as a pseudo-random number generator (PRNG), time-based random numbers (such as HMAC-DRBG), etc., is used to generate the key to ensure the unpredictability and security of the key.
[0062] Step 206: Encrypt the snapshot key according to the pre-obtained public key to obtain an encrypted snapshot key.
[0063] Before encryption, the client and the server first negotiate a public-private key pair. The public key is placed on the client, and the private key is stored in the authentication server. The public key can be obtained in the form of an https interface or written statically in the client in a pre-agreed manner, that is, the public key is statically stored in the client's code or configuration file to make it non-modifiable to ensure stability and availability.
[0064] Among them, one or more of multiple encryption methods such as SA (Security Association), ECC (Elliptic Curve Cryptography), DSA (Digital Signature Algorithm), etc., are not limited in this embodiment.
[0065] In this embodiment, the client encrypts the randomly generated snapshot key with the pre-obtained public key to obtain an encrypted snapshot key, which can prevent the leakage of the snapshot key.
[0066] Optionally, the client and the server will replace the public key and the private key at a preset time, which can reduce the security risks brought by the long-term use of the key.
[0067] Step 208: Generate an authentication instruction according to the user identifier, ciphertext, and encrypted snapshot key, and send the authentication instruction to the server; the server performs identity authentication according to the user identifier, ciphertext, and encrypted snapshot key.
[0068] Finally, the client generates a verification instruction based on the user identification, ciphertext, and encrypted snapshot key, and calls the login interface to send the verification instruction to the server. The server performs identity verification based on the user identification, ciphertext, and encrypted snapshot key carried in the verification instruction.
[0069] In the above identity verification method, the client encrypts the initial login key with a randomly generated snapshot key, so that the ciphertext submitted to the server is different for each login session. Moreover, the initial login password is encrypted with a randomly generated snapshot key and a reference snapshot key, which greatly improves the security of the key.
[0070] In one embodiment, encrypting the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext includes: encrypting the initial login password with the randomly generated snapshot key to obtain a reference ciphertext; encrypting the reference ciphertext with the reference snapshot key to obtain the ciphertext.
[0071] In this embodiment, first, the initial login password is encrypted with a randomly generated snapshot key to obtain a reference ciphertext. Then, the reference snapshot key is queried in the client according to the user identification, and the reference ciphertext is encrypted again with the reference snapshot key to obtain the final ciphertext.
[0072] Generally, only the randomly generated snapshot key is used to encrypt the initial login password to obtain a reference ciphertext. However, the reference ciphertext may become plaintext due to different sources, human tampering, etc. To improve security, in this embodiment, the reference ciphertext is encrypted again with the reference snapshot key.
[0073] In one embodiment, after obtaining the ciphertext, it further includes: saving the ciphertext and replacing the stored initial login password with the ciphertext.
[0074] In the prior art, many clients have the function of automatically remembering the login password. The purpose of storing the account password in the local system is to improve the login efficiency for the next time, especially on the user's frequently used login device. However, this also brings some security risks. If the device is lost, criminals can use the account password remembered by the user to log in to the user's system, or criminals temporarily use the user's device, take pictures or copy the account password information, and then log in to the user's system on their own device. Therefore, in this embodiment, the ciphertext will be saved and the ciphertext will replace the initial login password stored in the client, which can prevent the temporary password ciphertext from being stolen, and greatly improves the security of the password compared with the traditional plaintext storage or storage encrypted by the fingerprint algorithm.
[0075] Exemplarily, in combination with Figure 3 as shownFigure 3 Schematic diagram of the steps for a client to perform authentication in an embodiment.
[0076] The client first obtains the public key C from the server. When the user logs in to the session, the client randomly generates a snapshot key S1 for this session, and at the same time obtains the user identification corresponding to the user and the initial login password. Among them, the user login key is the plaintext password P1 entered by the user.
[0077] After that, the client uses S1 to encrypt P1 to obtain the reference ciphertext P2. P2 is a snapshot ciphertext string. For the same password, P2 obtained for each login operation is different. P2 = S1(P1). S1 changes for each login activity, P1 remains unchanged, and P2 naturally changes accordingly.
[0078] Normally, it is the temporary ciphertext P2 generated by encrypting with the snapshot key S1 last time. However, this P2 may become plaintext due to different sources, human tampering, etc. To improve security and for unified processing, in this embodiment, a secondary encryption method is used to encrypt P2 in this situation again. Therefore, the temporary ciphertext P2 transmitted to the background for this login may have two encryption situations:
[0079] ① P2 = S1(P1)
[0080] ② P2 = S1(S1_last(P1))
[0081] Where P1 is the plaintext password, P2 is the temporary ciphertext generated for this login session, S1 is the snapshot key generated for this login session, and S1_last is the snapshot key generated when logging in with the same device and the same account last time, that is, the reference snapshot key mentioned in the above embodiment. Therefore, it can be seen that P2 may be encrypted at most twice, and two different snapshot keys are used for the two times.
[0082] In the above embodiment, the client encrypts the initial login key with a randomly generated snapshot key, so that the ciphertext submitted to the server for each login session is different, and the initial login password is encrypted with a randomly generated snapshot key and a reference snapshot key, which greatly improves the security of the key.
[0083] In an exemplary embodiment, as Figure 4 shown, a method of authentication is provided. Taking the method applied to the Figure 1 server 104 as an example for illustration, it includes the following steps 402 to step 406. Among them:
[0084] Step 402: Receive the verification instruction sent by the client. The verification instruction carries the ciphertext, the encrypted snapshot key, and the user identification. The ciphertext is obtained by the client encrypting the obtained initial login password using the snapshot key and the reference snapshot key. The encrypted snapshot key is obtained by the client encrypting the snapshot key using the public key. The reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identification last time.
[0085] For the specific process of the client authenticating the initial login password, reference can be made to the description in the above embodiments, and it will not be repeated here.
[0086] Step 404: Decrypt the encrypted snapshot key and the ciphertext to obtain the reference login password, and perform the first account-password verification on the reference login password to obtain the account-password verification result.
[0087] Since the client encrypts both the randomly generated snapshot key and the initial login password, in this embodiment, the encrypted snapshot key and the ciphertext will be decrypted to obtain the decrypted initial login password, which is the reference login password described in this embodiment. After obtaining the reference login password, perform the first account-password verification on the reference login password to obtain the corresponding account-password verification result.
[0088] Among them, if the account-password verification result passes, the authentication on the server side passes. If the account-password verification result fails, it is necessary to further query the key relationship table and use the intermediate snapshot key in the key relationship table for decryption.
[0089] Optionally, the encrypted snapshot key can be decrypted first, and then the decrypted encrypted snapshot key is used to decrypt the ciphertext to obtain the reference login password.
[0090] It should be noted that this step is for the case where the client only encrypts the initial login password using the randomly generated snapshot key. For security reasons, the client encrypts the initial login password twice before sending it, but the server does not know the encryption method of the client, that is, whether it only uses the randomly generated snapshot key for encryption or performs two encryptions. Therefore, when decrypting, the server first decrypts the encrypted snapshot key and the ciphertext to obtain the reference login password, and performs the first account-password verification on the reference login password. If it fails, the intermediate snapshot key in the key relationship table is queried for authentication.
[0091] Step 406: When the account-password verification result is failed and the key relationship table is available for use, query the intermediate snapshot key from the key relationship table according to the user identifier, decrypt the reference login password using the intermediate snapshot key to obtain a decryption result, and perform a second account-password verification on the decryption result to obtain an authentication result; the intermediate snapshot key is the decryption snapshot key obtained by the server during the previous authentication.
[0092] Among them, the key relationship table refers to a table recorded by the server that shows the relationship between a user and the key used by the user for the most recent successful login. The relationship table can be enabled or disabled according to different security policies, and the data in the table will be continuously updated with different login session activities.
[0093] Exemplarily, in combination with Table 1, Table 1 is the key relationship table in an embodiment.
[0094] Table 1
[0095]
[0096] The relationship table is mainly used in the scenario where the device remembers the password for login. To improve the login efficiency and provide a good login experience for users, many devices offer the function of remembering passwords. In fact, the remembered password may have been modified due to various factors. To ensure security, in this embodiment, the remembered password will be encrypted again, so there may be a possibility of double encryption of the password. In this scenario, to enable the user to log in correctly, the snapshot key during the previous successful login must be saved. And since the session key is different for each login, in order to log in directly without entering the password next time, the user must log in on the device used for the previous login, which virtually enhances the security of authentication greatly. If the device is lost, the user does not need to modify the password. The user only needs to manually enter the password and log in again on another device. At this time, the server will update the relationship table using the snapshot key of this time, and malicious users will not be able to log in to the account using the lost device. This process will be carried out every time the account and password are manually entered, which greatly improves the security of the account. It is also possible to prohibit malicious users from logging in by disabling the entry of a certain user in the relationship table.
[0097] If it is necessary to invalidate the passwords recorded by the devices of all users or some users, it can be achieved by disabling the relationship table or invalidating some records in the relationship table. If a relatively high login efficiency and a good login experience are required, the relationship table can be enabled. If higher security is needed, the relationship table can be disabled, so that the user must enter the account and password for login every time.
[0098] In this embodiment, when the account-password verification result fails and the key relationship table is available, the intermediate snapshot key is queried from the key relationship table according to the user identifier. The intermediate snapshot key is the decrypted snapshot key obtained by the server during the previous authentication. Wherein, when the key relationship table is available, it means that the key relationship table is enabled.
[0099] The reference login password is decrypted using the intermediate snapshot key to obtain a decryption result, and a second account-password verification is performed on the decryption result to obtain an authentication result. If the authentication result is passed, it indicates successful authentication; otherwise, it indicates failed authentication.
[0100] The above authentication method, device, computer device, computer-readable storage medium, and computer program product receive a verification instruction sent by the client, decrypt the ciphertext according to the encrypted snapshot key carried in the verification instruction to obtain the reference login password, and perform a first account-password verification on the reference login password to obtain an account-password verification result. When the account-password verification result fails, it indicates that the client has double-encrypted the initial login password using the snapshot key and the reference snapshot key. At this time, the key relationship table is queried, and the decrypted snapshot key obtained by the server during the previous authentication is queried from the key relationship table according to the user identifier, and the reference login password is decrypted to obtain a decryption result. After obtaining the decryption result, a second account-password verification is performed on the decryption result to obtain the final authentication. In this way, the server can make the account have highly secure authentication without introducing multi-factor authentication.
[0101] Further, decrypting the encrypted snapshot key and the ciphertext to obtain the reference login password, and performing a first account-password verification on the reference login password to obtain an account-password verification result includes: decrypting the encrypted snapshot key according to the private key to obtain the decrypted snapshot key; decrypting the ciphertext based on the decrypted snapshot key to obtain the reference login password; calculating the first hash value corresponding to the user identifier and the reference login password, and matching the hash value with the pre-stored first credential to obtain the account-password verification result.
[0102] Since the client encrypts the randomly generated snapshot key using the public key, the server decrypts the encrypted snapshot key using the private key to obtain the decrypted snapshot key. The decrypted snapshot key obtained by the server is the snapshot key randomly generated by the client.
[0103] After that, the ciphertext is decrypted using the decrypted snapshot key to obtain the reference login password. The decrypted reference login password is the initial login password of the client. Then, the first hash value corresponding to the user identifier and the reference login password is calculated, and the first hash value is matched with the first credential to obtain the account-password verification result.
[0104] Optionally, a fingerprint algorithm can be used to calculate the first hash value, such as one or more of MD5 (Message Digest Algorithm 5), SHA256 (Secure Hash Algorithm 256-bit), and SHA-3 (Secure Hash Algorithm 3). Exemplarily, SHA256 can be used to calculate the first hash value. Different input contents can generate fixed-length values that do not collide using this algorithm. In this embodiment, the user's password is stored in the database using this algorithm, which is the first proof of identity. During identity authentication, the password is determined to be correct by comparing the SHA256 value in the database, that is, the first proof of identity, with the first hash value.
[0105] Furthermore, if the first proof of identity is consistent with the first hash value, the account and password verification result is passed; otherwise, it is not passed.
[0106] Furthermore, when the account and password verification result is not passed and the key relationship table is available for use, the intermediate snapshot key is queried from the key relationship table according to the user identifier. The reference login password is decrypted using the intermediate snapshot key to obtain a decryption result, and a second account and password verification is performed on the decryption result to obtain an identity verification result.
[0107] Among them, decrypting the reference login password using the intermediate snapshot key to obtain a decryption result, and performing a second account and password verification on the decryption result to obtain an identity verification result includes: decrypting the reference login password using the intermediate snapshot key to obtain a decryption result; calculating the second hash value corresponding to the user identifier and the decryption result, and matching the second hash value with the pre-stored second proof of identity to obtain an identity verification result.
[0108] When the account and password verification result is not passed, it indicates that the client has performed secondary encryption. Therefore, the server needs to decrypt the reference login password again. At this time, the server uses the decryption snapshot key obtained when authenticating the user last time, that is, the intermediate snapshot key, to decrypt the reference login password.
[0109] After the server decrypts the reference login password using the intermediate snapshot key, the corresponding decryption result is obtained, and a second account and password verification is performed on the decryption result.
[0110] Similar to the first account and password verification, during the second account and password verification process, the second hash value corresponding to the user identifier and the decryption result is calculated, and the second hash value is matched with the second proof of identity. Among them, the generation method of the second proof of identity is similar to that of the first proof of identity, and will not be repeated here.
[0111] Further, if the second certificate is consistent with the second hash value, the authentication result is passed; otherwise, it is not passed.
[0112] Exemplarily, in combination with Figure 5 as shown Figure 5 is a schematic flowchart of the server performing authentication in an embodiment.
[0113] Among them, the private key corresponding to the public key is used to decrypt S2 to obtain the decrypted snapshot key, that is, S1. S2 is the encrypted snapshot key, that is, the client encrypts the snapshot key according to the pre-obtained public key.
[0114] After that, use S1 to decrypt P2 to obtain the decrypted P1, that is, the reference login password in this embodiment. Then, perform the first account and password judgment according to the user identifier and SHA256(P1). If it passes, the authentication passes. And when the key relationship table is in the open state, record the relationship between S1 and the user identifier; otherwise, do not record.
[0115] If the first account and password judgment fails, judge whether the key relationship table is open. If it is not open, the authentication fails. If it is open, query the previous snapshot key S1_Last, that is, the intermediate snapshot key, from the key relationship table according to the user identifier. If the previous snapshot key S1_Last is not queried in the key relationship table, the authentication fails.
[0116] In the case where the intermediate snapshot key is queried, use the intermediate snapshot key to decrypt P1 to obtain the decrypted password P1_RAW, that is, the decryption result. Then, perform the second account and password judgment on the decryption result according to the user identifier and SHA256(P1) to obtain the authentication result.
[0117] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.
[0118] Based on the same inventive concept, an embodiment of the present application further provides an authentication device for implementing the authentication method involved above. The implementation solutions provided by this device to solve problems are similar to the implementation solutions recorded in the above method. Therefore, the specific limitations in one or more embodiments of the authentication device provided below can refer to the limitations on the authentication method in the above text and will not be repeated here.
[0119] In an exemplary embodiment, as Figure 6 shown, an authentication device applied to a server is provided, which includes: a receiving module 100, a decryption module 200, and a verification module 300, where:
[0120] The receiving module 100 is configured to receive a verification instruction sent by a client; the verification instruction carries a ciphertext, an encrypted snapshot key, and a user identifier; the ciphertext is obtained by the client encrypting the obtained initial login password using the snapshot key and a reference snapshot key; the encrypted snapshot key is obtained by the client encrypting the snapshot key using a public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time.
[0121] The decryption module 200 is configured to decrypt the encrypted snapshot key and the ciphertext to obtain a reference login password, and perform a first account-password verification on the reference login password to obtain an account-password verification result.
[0122] The verification module 300 is configured to, when the account-password verification result is not passed and the key relationship table is available for use, query an intermediate snapshot key from the key relationship table according to the user identifier, decrypt the reference login password using the intermediate snapshot key to obtain a decryption result, and perform a second account-password verification on the decryption result to obtain an authentication result; the intermediate snapshot key is the decrypted snapshot key obtained by the server during the last authentication.
[0123] In one embodiment, the above decryption module includes:
[0124] The private key decryption unit is configured to decrypt the encrypted snapshot key according to the private key to obtain a decrypted snapshot key.
[0125] The first password decryption unit is configured to decrypt the ciphertext based on the decrypted snapshot key to obtain a reference login password.
[0126] The first hash verification module is configured to calculate a first hash value corresponding to the user identifier and the reference login password, and match the hash value with a pre-stored first credential to obtain an account-password verification result.
[0127] In one embodiment, the above verification module includes:
[0128] A second password decryption unit, configured to decrypt a reference login password by using an intermediate snapshot key to obtain a decryption result.
[0129] A second hash verification module, configured to calculate a second hash value corresponding to a user identifier and the decryption result, and match the second hash value with a pre-stored second credential to obtain an authentication result.
[0130] In an exemplary embodiment, as Figure 7 shown, there is provided an authentication device applied to a client, including: an acquisition module 400, a first encryption module 500, a second encryption module 600, and a sending module 700, where:
[0131] The acquisition module 400 is configured to acquire an initial login password and a user identifier.
[0132] The first encryption module 500 is configured to encrypt the initial login password by using a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time.
[0133] The second encryption module 600 is configured to encrypt the snapshot key according to a pre-acquired public key to obtain an encrypted snapshot key.
[0134] The sending module 700 is configured to generate an authentication instruction according to the user identifier, the ciphertext, and the encrypted snapshot key, and send the authentication instruction to the server; the server performs authentication according to the user identifier, the ciphertext, and the encrypted snapshot key.
[0135] In one embodiment, the above-mentioned first encryption module 500 includes:
[0136] A password encryption unit, configured to encrypt the initial login password by using a randomly generated snapshot key to obtain a reference ciphertext.
[0137] A key encryption unit, configured to encrypt the reference ciphertext by using the reference snapshot key to obtain a ciphertext.
[0138] In one embodiment, the above-mentioned device further includes a storage unit,
[0139] The storage unit is configured to save the ciphertext and replace the stored initial login password with the ciphertext.
[0140] Each module in the above-mentioned authentication device can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or stored in a memory in the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above-mentioned respective modules.
[0141] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in Figure 8 . The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store a key relationship table. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, an authentication method is implemented.
[0142] Those skilled in the art can understand that Figure 8 the structure shown in
[0143] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0144] In one embodiment, when the processor executes the computer program, the following steps are further implemented: decrypt the encrypted snapshot key according to the private key to obtain the decrypted snapshot key; decrypt the ciphertext based on the decrypted snapshot key to obtain the reference login password; calculate the first hash value corresponding to the user identifier and the reference login password, and match the hash value with the pre-stored first credential to obtain the account password verification result.
[0145] In one embodiment, when the processor executes the computer program, the following steps are further implemented: decrypt the reference login password using the intermediate snapshot key to obtain the decryption result; calculate the second hash value corresponding to the user identifier and the decryption result, and match the second hash value with the pre-stored second credential to obtain the authentication result.
[0146] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented: obtain the initial login password and the user identifier; encrypt the initial login password through a randomly generated snapshot key and a reference snapshot key to obtain the ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; encrypt the snapshot key according to the pre-obtained public key to obtain the encrypted snapshot key; generate a verification instruction according to the user identifier, the ciphertext, and the encrypted snapshot key, and send the verification instruction to the server; the server performs authentication according to the user identifier, the ciphertext, and the encrypted snapshot key.
[0147] In one embodiment, when the processor executes the computer program, the following steps are further implemented: encrypt the initial login password through a randomly generated snapshot key to obtain the reference ciphertext; encrypt the reference ciphertext using the reference snapshot key to obtain the ciphertext.
[0148] In one embodiment, when the processor executes the computer program, the following steps are further implemented: save the ciphertext and replace the stored initial login password with the ciphertext.
[0149] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: receiving a verification instruction sent by a client; the verification instruction carries a ciphertext, an encrypted snapshot key, and a user identifier; the ciphertext is obtained by the client encrypting an initial login password using a snapshot key and a reference snapshot key; the encrypted snapshot key is obtained by the client encrypting the snapshot key using a public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; decrypting the encrypted snapshot key and the ciphertext to obtain a reference login password, and performing a first account-password verification on the reference login password to obtain an account-password verification result; when the account-password verification result is not passed and the key relationship table is available for use, querying an intermediate snapshot key from the key relationship table according to the user identifier, decrypting the reference login password using the intermediate snapshot key to obtain a decryption result, and performing a second account-password verification on the decryption result to obtain an identity verification result; the intermediate snapshot key is the decrypted snapshot key obtained by the server during the last identity verification.
[0150] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: decrypting the encrypted snapshot key according to a private key to obtain a decrypted snapshot key; decrypting the ciphertext based on the decrypted snapshot key to obtain a reference login password; calculating a first hash value corresponding to the user identifier and the reference login password, and matching the hash value with a pre-stored first credential to obtain an account-password verification result.
[0151] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: decrypting the reference login password using the intermediate snapshot key to obtain a decryption result; calculating a second hash value corresponding to the user identifier and the decryption result, and matching the second hash value with a pre-stored second credential to obtain an identity verification result.
[0152] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: obtaining an initial login password and a user identifier; encrypting the initial login password using a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; encrypting the snapshot key according to a pre-obtained public key to obtain an encrypted snapshot key; generating a verification instruction according to the user identifier, the ciphertext, and the encrypted snapshot key, and sending the verification instruction to a server; the server performs identity verification according to the user identifier, the ciphertext, and the encrypted snapshot key.
[0153] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: encrypt the initial login password with a randomly generated snapshot key to obtain a reference ciphertext; encrypt the reference ciphertext with the reference snapshot key to obtain a ciphertext.
[0154] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: save the ciphertext and replace the stored initial login password with the ciphertext.
[0155] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the following steps: receive a verification instruction sent by a client; the verification instruction carries a ciphertext, an encrypted snapshot key, and a user identifier; the ciphertext is obtained by the client encrypting the acquired initial login password with the snapshot key and the reference snapshot key; the encrypted snapshot key is obtained by the client encrypting the snapshot key with a public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; decrypt the encrypted snapshot key and the ciphertext to obtain a reference login password, and perform a first account-password verification on the reference login password to obtain an account-password verification result; when the account-password verification result is not passed and the key relationship table is available for use, query an intermediate snapshot key from the key relationship table according to the user identifier, decrypt the reference login password with the intermediate snapshot key to obtain a decryption result, and perform a second account-password verification on the decryption result to obtain an identity verification result; the intermediate snapshot key is the decrypted snapshot key obtained by the server during the last identity verification.
[0156] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: decrypt the encrypted snapshot key according to a private key to obtain a decrypted snapshot key; decrypt the ciphertext based on the decrypted snapshot key to obtain a reference login password; calculate a first hash value corresponding to the user identifier and the reference login password, and match the hash value with a pre-stored first credential to obtain an account-password verification result.
[0157] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: decrypt the reference login password with the intermediate snapshot key to obtain a decryption result; calculate a second hash value corresponding to the user identifier and the decryption result, and match the second hash value with a pre-stored second credential to obtain an identity verification result.
[0158] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the following steps: obtaining an initial login password and a user identifier; encrypting the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; encrypting the snapshot key with a pre-obtained public key to obtain an encrypted snapshot key; generating an authentication instruction according to the user identifier, the ciphertext and the encrypted snapshot key, and sending the authentication instruction to a server; the server performs identity authentication according to the user identifier, the ciphertext and the encrypted snapshot key.
[0159] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: encrypting the initial login password with a randomly generated snapshot key to obtain a reference ciphertext; encrypting the reference ciphertext with the reference snapshot key to obtain a ciphertext.
[0160] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: saving the ciphertext and replacing the stored initial login password with the ciphertext.
[0161] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, a database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, data processing logics of programmable logics, artificial intelligence (AI) processors, etc., without limitation.
[0162] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0163] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. An authentication method, characterized in that, Applied to the server; the method includes: Receiving a verification instruction sent by the client; the verification instruction carries a ciphertext, an encrypted snapshot key, and a user identifier; the ciphertext is obtained by the client encrypting the initial login password using the snapshot key and a reference snapshot key; the encrypted snapshot key is obtained by the client encrypting the snapshot key using a public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time. Decrypting the encrypted snapshot key and the ciphertext to obtain a reference login password, and performing a first account-password verification on the reference login password to obtain an account-password verification result. When the account-password verification result is failed and the key relationship table is available for use, querying an intermediate snapshot key from the key relationship table according to the user identifier, decrypting the reference login password using the intermediate snapshot key to obtain a decryption result, and performing a second account-password verification on the decryption result to obtain an identity verification result; the intermediate snapshot key is the decrypted snapshot key obtained by the server during the last identity verification.
2. The method according to claim 1, wherein The step of decrypting the encrypted snapshot key and the ciphertext to obtain a reference login password, and performing a first account-password verification on the reference login password to obtain an account-password verification result includes: Decrypting the encrypted snapshot key according to the private key to obtain the decrypted snapshot key. Decrypting the ciphertext based on the decrypted snapshot key to obtain the reference login password. Calculating a first hash value corresponding to the user identifier and the reference login password, and matching the hash value with a pre-stored first credential to obtain the account-password verification result.
3. The method according to claim 1, characterized in that, The step of decrypting the reference login password using the intermediate snapshot key to obtain a decryption result, and performing a second account-password verification on the decryption result to obtain an identity verification result includes: Decrypting the reference login password using the intermediate snapshot key to obtain the decryption result. Calculating a second hash value corresponding to the user identifier and the decryption result, and matching the second hash value with a pre-stored second credential to obtain the identity verification result.
4. An authentication method, characterized in that, Applied to the client, the method includes: Obtaining an initial login password and a user identifier. Encrypting the initial login password using a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time. Encrypting the snapshot key according to a pre-obtained public key to obtain an encrypted snapshot key. Generating a verification instruction according to the user identifier, the ciphertext, and the encrypted snapshot key, and sending the verification instruction to the server; the server performs identity verification according to the user identifier, the ciphertext, and the encrypted snapshot key.
5. The method according to claim 4, wherein The step of encrypting the initial login password using a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext includes: Encrypt the initial login password with the randomly generated snapshot key to obtain a reference ciphertext; Encrypt the reference ciphertext with the reference snapshot key to obtain the ciphertext; After obtaining the ciphertext, it further includes: Save the ciphertext and replace the stored initial login password with the ciphertext.
6. An authentication device, characterized in that, Applied to the server, the device includes: A receiving module, configured to receive a verification instruction sent by a client; the verification instruction carries a ciphertext, an encrypted snapshot key, and a user identifier; the ciphertext is obtained by the client encrypting the acquired initial login password using the snapshot key and the reference snapshot key; the encrypted snapshot key is obtained by the client encrypting the snapshot key using a public key; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; A decryption module, configured to decrypt the encrypted snapshot key and the ciphertext to obtain a reference login password, and perform a first account-password verification on the reference login password to obtain an account-password verification result; A verification module, configured to, when the account-password verification result is not passed and the key relationship table is available for use, query an intermediate snapshot key from the key relationship table according to the user identifier, decrypt the reference login password using the intermediate snapshot key to obtain a decryption result, and perform a second account-password verification on the decryption result to obtain an identity verification result; the intermediate snapshot key is the decrypted snapshot key obtained by the server during the last identity verification.
7. An authentication device, characterized in that, Applied to the client, the device includes: An acquisition module, configured to acquire an initial login password and a user identifier; A first encryption module, configured to encrypt the initial login password with a randomly generated snapshot key and a reference snapshot key to obtain a ciphertext; the reference snapshot key is the snapshot key used by the client when encrypting the initial login password corresponding to the user identifier last time; A second encryption module, configured to encrypt the snapshot key according to a pre-acquired public key to obtain an encrypted snapshot key; A sending module, configured to generate a verification instruction according to the user identifier, the ciphertext, and the encrypted snapshot key, and send the verification instruction to the server; the server performs identity verification according to the user identifier, the ciphertext, and the encrypted snapshot key.
8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 3 or 4 to 5.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 3 or 4 to 5.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 3 or 4 to 5.
Citation Information
Patent Citations
Identity authentication method based on dynamic token, and decryption and encryption terminal
CN110224834A
Encryption authentication method and system, storage medium and equipment
CN112738024A
Ciphertext-based login method and equipment
CN113922973A
Account authentication method and device, equipment and storage medium
CN116707817A
A dynamic validation system
EP1050991A1