Identity verification method, device and system
The server-based identity verification method with random identifiers and encrypted authentication items addresses the vulnerability of direct device-server connections, enhancing security and reliability by ensuring secure communication and preventing information leakage.
Patent Information
- Application Number
- CN202510812189.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-18
AI Technical Summary
During the process of establishing a communication connection between the user equipment and the server, the transmitted identity information is easily intercepted, resulting in information leakage, and the security of the existing identity authentication method is low.
By generating a unique identifier on the server, randomly selecting authentication items for encryption processing, using visual display and decryption operations of the terminal device and the user side to realize identity authentication, and using encryption algorithms to protect authentication information to avoid direct transmission of plain text identity information.
Improve the security and reliability of identity authentication, prevent information leakage, and enhance the security and privacy protection of the authentication process.
Smart Images

Figure CN120321052A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of identity authentication, and particularly relates to an identity authentication method, device and system. Background Art
[0002] Identity authentication technology is an effective solution method generated in the process of confirming the identity of an operator in a computer network. Identity authentication technology mainly includes the following three methods: First, password, verification code and other password authentication; second, digital certificate and other token authentication; third, fingerprint, iris, face recognition and other biometric authentication.
[0003] For the authorized use of shared devices (such as shared printers, power banks, charging piles, etc.) and intelligent devices such as access control systems, it is necessary to authenticate the user before authorizing the user. When authorizing the user, it is necessary to establish a communication connection between the user's mobile phone and other devices and the server corresponding to the intelligent device that needs to be authorized for use. The user uploads the identity information to the server, and after passing the authentication on the server, the user is authorized to use.
[0004] However, during the process of establishing a communication connection between the user device and the server, the transmitted identity information is easily intercepted, resulting in information leakage, and the security of this authentication method is relatively low. Summary of the Invention
[0005] The purpose of the present invention is to provide an identity authentication method, device and system to solve the problem that in the prior art, during the process of establishing a communication connection between the user device and the server, the transmitted identity information is easily intercepted, resulting in information leakage, and the security of this authentication method is relatively low.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions: In the first aspect, the present invention provides an identity authentication method, which is applied to a server, and the server is communicatively connected to a terminal device. The method includes: Obtain an authentication request input by the user on the terminal device, where the authentication request is a unique identifier randomly generated on the server according to the user's basic information; Match the authentication information reserved by the user based on the authentication request, where the authentication information includes multiple authentication items and the authentication content corresponding to each authentication item; Construct an item to be authenticated based on the authentication item, and encrypt the item to be authenticated with the key of a preset encryption algorithm to obtain an authentication ciphertext; Send the key and the authentication ciphertext to the terminal device. The terminal device is used to visually display the key and the authentication ciphertext, input the key and the authentication ciphertext into the user side. The user side is used to decrypt the authentication ciphertext with the key to obtain the item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext; Obtain the verification ciphertext input by the user on the terminal device, decrypt the verification ciphertext to obtain the authentication content input by the user; Authenticate the authentication content input by the user to obtain a verification result, and send the verification result to the terminal device, where the terminal device is used to grant the user the usage permission for the terminal device according to the verification result.
[0007] Preferably, the item to be authenticated includes a first authentication item and multiple second authentication items. Constructing the item to be authenticated based on the authentication items includes: Randomly select one authentication item from multiple authentication items of the user as the first authentication item; Extract the keywords from all authentication items, cluster all the keywords to obtain multiple categories; Randomly select at least two categories from the multiple categories, and generate multiple second authentication items based on the at least two selected categories.
[0008] Preferably, the authentication content input by the user includes: the first content corresponding to the first authentication item and the second content corresponding to multiple second authentication items; authenticating the authentication content input by the user to obtain a verification result includes: Compare the first content with the authentication content corresponding to each authentication item of the user to obtain a first result; Calculate the similarity between each second content and the authentication content corresponding to each authentication item of the user to obtain a second result; Determine the verification result based on the first result and the second result.
[0009] Preferably, a display screen and a camera are integrated on the terminal device, and the method further includes: The terminal device generates a first identification code containing the key and the authentication ciphertext based on the key and the authentication ciphertext, and the first identification code is a barcode and / or a two-dimensional code; The terminal device visually displays the first identification code through the display screen; the user terminal scans the first identification code displayed by the terminal device to obtain the key and the authentication ciphertext.
[0010] Preferably, the method further includes: The user terminal generates a second identification code containing the verification ciphertext based on the verification ciphertext, and the second identification code is a barcode and / or a two-dimensional code, and visually displays the second identification code; The camera of the terminal device scans the second identification code displayed by the user terminal to obtain the verification ciphertext; The terminal device uploads the verification ciphertext to the server.
[0011] Preferably, the private keys corresponding to each user are stored on the server, and the ciphertext to be verified is decrypted to obtain the authentication content input by the user, including: Obtain all private keys, decrypt the ciphertext to be verified based on all private keys, and determine whether the decryption is successful; If not, generate a verification failure prompt and send the verification failure prompt to the terminal device, which is used to visually display the verification failure prompt; If so, obtain the authentication content input by the user.
[0012] Preferably, encrypt the item to be authenticated based on the key of the preset encryption algorithm to obtain the authentication ciphertext, including: Based on the acquisition time of the authentication request; Perform hash encryption on the acquisition time to obtain the time hash value; Concatenate the acquisition time and the item to be authenticated to obtain the plaintext, and use the time hash value as the key of the preset encryption algorithm to encrypt the plaintext to obtain the authentication ciphertext.
[0013] In a second aspect, the present invention provides an identity authentication device for implementing the above identity authentication method, and the device includes: A request acquisition module, configured to acquire an authentication request input by a user on a terminal device, where the authentication request is a unique identifier randomly generated according to the user's basic information on a server; An authentication matching module, configured to match the authentication information reserved by the user based on the authentication request, where the authentication information includes a plurality of authentication items and the authentication content corresponding to each authentication item; An authentication encryption module, configured to construct an item to be authenticated based on the authentication item, and encrypt the item to be authenticated based on the key of the preset encryption algorithm to obtain the authentication ciphertext; An authentication sending module, configured to send the key and the authentication ciphertext to the terminal device, where the terminal device is used to visually display the key and the authentication ciphertext, input the key and the authentication ciphertext into the user side, and the user side is used to decrypt the authentication ciphertext with the key to obtain the item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain the ciphertext to be verified; A ciphertext acquisition module, configured to acquire the ciphertext to be verified input by the user on the terminal device, and decrypt the ciphertext to be verified to obtain the authentication content input by the user; An identity authentication module, configured to perform identity authentication on the authentication content input by the user to obtain a verification result, and send the verification result to the terminal device, where the terminal device is used to grant the user the usage right to the terminal device according to the verification result.
[0014] In a third aspect, the present invention provides an authentication system, which includes: a server, a terminal device, and a user terminal. The server is communicatively connected to the terminal device, and the server is used to implement the above-mentioned authentication method; The user terminal is used to input a secret key and an authentication ciphertext, decrypt the authentication ciphertext using the secret key to obtain an item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext.
[0015] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the above-mentioned authentication method.
[0016] Advantageous effects: 1. By inputting an authentication request and a verification ciphertext on the terminal device, the user terminal does not establish a communication connection with the terminal device, nor does it communicate with the server. The user terminal only provides input of the secret key and the authentication ciphertext, decrypts the authentication ciphertext using the secret key to obtain the item to be authenticated, and encrypts the authentication content input by the user with reference to the item to be authenticated to obtain the verification ciphertext. This improves the security and reliability of identity authentication; 2. The present invention only sends the authentication item in the authentication information to the terminal device, and the authentication content corresponding to the authentication item is stored on the server; assuming that the authentication item is stolen, it will not cause privacy leakage, and the authentication item is also encrypted using an encryption algorithm, which can further improve security. Description of the drawings
[0017] The drawings are used to provide a further understanding of the embodiments of the present invention, and constitute a part of the specification. They are used together with the following specific embodiments to explain the embodiments of the present invention, but do not constitute a limitation to the embodiments of the present invention. In the drawings: Figure 1 is a flowchart of an authentication method provided by an embodiment of the present invention; Figure 2 is a block diagram of an authentication device provided by an embodiment of the present invention; Figure 3 is a block diagram of an authentication system provided by an embodiment of the present invention. Specific embodiments
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the present invention in combination with the accompanying drawings and the description of the embodiments or the prior art. Obviously, the following description of the structures of the accompanying drawings is only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings. It should be noted here that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation to the present invention.
[0019] Embodiment 1 Figure 1 is a flowchart of an authentication method provided by an embodiment of the present invention. As Figure 1 shown, this embodiment provides an authentication method, which is applied to a server. The server is communicatively connected to a terminal device. In this embodiment, the terminal device can be a shared device (such as a shared printer, a power bank, and a charging pile, etc.) and an intelligent device such as an access control system. Users obtain the usage permission of the intelligent device through identity authentication. For example, after passing the identity authentication, they obtain the permission to use the printer. This method runs on the server and includes the following steps: Step S10: Obtain an authentication request input by the user on the terminal device. The authentication request is a unique identifier randomly generated according to the user's basic information on the server.
[0020] In this embodiment, when each user needs to use the terminal device, they need to access the server in advance for registration, upload the user's basic information (such as: name, gender, age, identity information, contact information, etc.) to the server. The server randomly generates a unique identifier according to the user's basic information. The unique identifier is a string, which is bound to the user, and this unique identifier is returned to the user, who can save it locally.
[0021] When needing to use the same type of intelligent device, the user only needs to input the unique identifier into the intelligent device, and the intelligent device uploads the unique identifier to the server, and the server can start the identity authentication process to start authenticating the user's identity.
[0022] In this embodiment, an input keyboard or a camera can be integrated on the terminal device. The input keyboard can be used to input the unique identifier. Moreover, to improve the input efficiency of the unique identifier, the user side can convert the unique identifier into a barcode or a two-dimensional code, and use the camera on the terminal device to obtain the unique identifier in the barcode or two-dimensional code, and upload the recognized unique identifier to the server.
[0023] Step S20: Match the authentication information reserved by the user based on the authentication request. The authentication information includes multiple authentication items and the authentication content corresponding to each authentication item.
[0024] In this embodiment, after the user registers, some authentication information needs to be reserved, such as: authentication password, authentication security question, etc. The authentication password and authentication security question are used as authentication items, and the specific password and the content of the security question are used as the authentication content corresponding to the authentication item.
[0025] Step S30: Construct an item to be authenticated based on the authentication item, and encrypt the item to be authenticated with the key of the preset encryption algorithm to obtain an authentication ciphertext. In this embodiment, one authentication item can be randomly selected from all the authentication items of the user as the item to be authenticated.
[0026] In this embodiment, usually the user will set multiple authentication items, and the more the number of authentication items, the easier it is for the user to forget the authentication content corresponding to the authentication item. Therefore, randomly selecting one authentication item will increase the probability of the user's authentication failure, resulting in the user repeating the authentication; and there are also differences in the reserved authentication content on different servers, further increasing the difficulty of authentication.
[0027] In response to this, the item to be authenticated in this embodiment includes a first authentication item and multiple second authentication items. Constructing the item to be authenticated based on the authentication item includes: Step a10: Randomly select one authentication item from the multiple authentication items of the user as the first authentication item.
[0028] Step a20: Extract the keywords from all the authentication items, cluster all the keywords, and obtain multiple categories; for example: the authentication security question set by the user is: My favorite food is xx, the food I least like is xx, my favorite cat is xx, my best friend is xx, etc., and the specific content set by each user is different; keywords such as food, friend, cat, etc. can be extracted, and then these keywords are clustered to obtain categories: for example: categories such as food, pet, relatives and friends, etc.
[0029] Step a30: Randomly select at least two categories from the multiple categories, and generate multiple second authentication items based on the selected at least two categories; in this embodiment, when selecting categories, at least one category is selected from the categories to which the user belongs, and at least one category from the categories to which other users belong is selected as an interference item; finally, the second authentication item is generated according to the selected categories. The second authentication item is an optional item for the user. If the user forgets the specific content of the first authentication item, the user can fill in the specific content in the optional item for auxiliary authentication.
[0030] Step S40: Send the key and the authentication ciphertext to the terminal device. The terminal device is used to visually display the key and the authentication ciphertext, input the key and the authentication ciphertext into the user terminal. The user terminal is used to decrypt the authentication ciphertext with the key to obtain the item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext.
[0031] In this embodiment, a display screen and a camera are integrated on the terminal device. The display screen can be used for keys and authentication ciphertexts. Secondly, to improve the convenience of inputting the key and the authentication ciphertext into the user terminal, the method further includes: Step b10: The terminal device generates a first identification code containing the key and the authentication ciphertext based on the key and the authentication ciphertext, and the first identification code is a bar code and / or a two-dimensional code; Step b20: The terminal device visually displays the first identification code through the display screen; the user terminal scans the first identification code displayed by the terminal device to obtain the key and the authentication ciphertext.
[0032] Step S50: Obtain the verification ciphertext input by the user on the terminal device, decrypt the verification ciphertext, and obtain the authentication content input by the user.
[0033] In this embodiment, the private keys corresponding to each user are stored on the server. Decrypting the verification ciphertext to obtain the authentication content input by the user includes: Step S501: Obtain all private keys, decrypt the verification ciphertext based on all private keys, and determine whether the decryption is successful; Step S502: If not, generate a verification failure prompt and send the verification failure prompt to the terminal device, and the terminal device is used to visually display the verification failure prompt; Step S503: If so, obtain the authentication content input by the user.
[0034] Similarly, to improve the convenience of inputting the verification ciphertext into the terminal device, the method further includes: Step c10: The user terminal generates a second identification code containing the verification ciphertext based on the verification ciphertext, and the second identification code is a bar code and / or a two-dimensional code, and visually displays the second identification code; Step c20: The camera of the terminal device scans the second identification code displayed by the user terminal to obtain the verification ciphertext; Step c30: The terminal device uploads the verification ciphertext to the server.
[0035] Step S60: Authenticate the authentication content input by the user to obtain a verification result, and send the verification result to the terminal device, and the terminal device is used to grant the user the usage permission of the terminal device according to the verification result.
[0036] In this embodiment, the authentication content input by the user includes: the first content corresponding to the first authentication item and the second content corresponding to multiple second authentication items; authenticating the authentication content input by the user to obtain a verification result includes: Step S601: Compare the first content with the authentication content corresponding to each authentication item of the user to obtain a first result; Step S602: Calculate the similarity between each second content and the authentication content corresponding to each authentication item of the user to obtain a second result; Step S603: Determine the verification result based on the first result and the second result.
[0037] In this embodiment, when the first result is that the first content exists in the authentication content corresponding to each authentication item, it indicates that the verification is passed, and the user is granted the usage permission for the terminal device.
[0038] When the first result is that the first content does not exist in the authentication content corresponding to each authentication item, it is necessary to combine the second content for auxiliary authentication.
[0039] For example: In step a30, two categories are selected, relatives and friends, and food; among them, only the category that exists in the authentication information reserved by the "relatives and friends" user is used as the real item, while "food" is an interference item. The categories of these authentication items are used to prompt the relevance of the secret security questions. The user can answer flexibly according to the usual setting habits, and the content of these answers is used as the second content; at this time, calculate the similarity between the second content and the authentication content corresponding to each authentication item of the user. When the similarity is higher than the threshold, it means that the user's answer is correct and the authentication is passed; at the same time, it is also determined whether the authentication is passed according to the number of times the user answers. For example, if the interference item is not answered and the similarity of the answered content is relatively high, it can be determined that the verification is passed; when the number of items answered for the interference item is more (even if the similarity of the answered real item is relatively high), it can be determined that the authentication fails.
[0040] Therefore, the present invention improves the security and reliability of identity authentication through operations such as inputting an authentication request and a verification ciphertext on the terminal device. At this time, the user terminal does not establish a connection with the terminal device, nor does it communicate with the server. The user terminal only provides the input key and the authentication ciphertext, decrypts the authentication ciphertext using the key to obtain the item to be authenticated, encrypts the authentication content input by the user with reference to the item to be authenticated to obtain the verification ciphertext, etc.; and only sends the authentication items in the authentication information to the terminal device, and the authentication content corresponding to the authentication items is stored on the server; assuming that the authentication item is stolen, it will not cause privacy leakage, and the authentication item also adopts an encryption algorithm for encryption processing, which can further improve security.
[0041] As a further optimization of this embodiment, for step S30, where the item to be authenticated is encrypted based on the key of the preset encryption algorithm to obtain the authentication ciphertext, it includes: Step d10: Based on the acquisition time of the authentication request.
[0042] Step d20: Perform hash encryption on the acquisition time to obtain a time hash value. In this embodiment, the MD5 algorithm is used to perform hash encryption on the acquisition time. The MD5 algorithm is a widely used digest algorithm and a common hash function that is used to convert an input of any length of data into a fixed-length output of 128 bits, with characteristics such as irreversibility, data integrity, and non-repudiation.
[0043] Step d30: Concatenate the acquisition time and the item to be authenticated to obtain a plaintext, and use the time hash value as the key of a preset encryption algorithm to encrypt the plaintext to obtain an authentication ciphertext, where the preset encryption algorithm is an asymmetric encryption algorithm, such as the RSA algorithm, the ECC algorithm, etc.
[0044] In this embodiment, the acquisition time is dynamically changing, and each generated authentication ciphertext is encrypted using a different key. Even if an attacker intercepts the authentication ciphertext, it is impossible to perform a replay attack in a short time because the key has changed.
[0045] Since the plaintext contains the acquisition time, when the user fails to answer within the specified time and inputs the authentication ciphertext into the terminal device, it can be determined that the authentication fails, ensuring the timeliness of the authentication.
[0046] Embodiment 2 Figure 2 is a block diagram of an identity authentication device provided by an embodiment of the present invention. As Figure 2 shown, this embodiment provides an identity authentication device for implementing the identity authentication method in Embodiment 1. The device includes: A request acquisition module, configured to acquire an authentication request input by a user on a terminal device, where the authentication request is a unique identifier randomly generated on a server according to the basic information of the user; An authentication matching module, configured to match the authentication information reserved by the user based on the authentication request, where the authentication information includes multiple authentication items and the authentication content corresponding to each authentication item; An authentication encryption module, configured to construct an item to be authenticated based on the authentication item and encrypt the item to be authenticated based on the key of a preset encryption algorithm to obtain an authentication ciphertext; An authentication sending module, configured to send the key and the authentication ciphertext to the terminal device, where the terminal device is configured to visually display the key and the authentication ciphertext, input the key and the authentication ciphertext to the user side, and the user side is configured to decrypt the authentication ciphertext using the key to obtain the item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext; A ciphertext acquisition module, configured to acquire the verification ciphertext input by the user on the terminal device, and decrypt the verification ciphertext to obtain the authentication content input by the user; An authentication module is used to authenticate the authentication content input by a user, obtain an authentication result, and send the authentication result to a terminal device. The terminal device is used to grant the user the usage right to the terminal device according to the authentication result.
[0047] In the present invention, by inputting an authentication request and a verification ciphertext on the terminal device, at this time, the user terminal does not establish a connection with the terminal device, nor does it establish a communication connection with the server. The user terminal only provides the input of a secret key and an authentication ciphertext, decrypts the authentication ciphertext using the secret key to obtain an item to be authenticated, encrypts the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext, etc. These operations improve the security and reliability of identity authentication; and only the authentication item in the authentication information is sent to the terminal device, and the authentication content corresponding to the authentication item is stored on the server; assuming that the authentication item is stolen, it will not cause privacy leakage, and the authentication item is also encrypted using an encryption algorithm, which can further improve security.
[0048] Embodiment III Figure 3 It is a block diagram of an identity authentication system provided by an embodiment of the present invention. As Figure 3 shown, this embodiment provides an identity authentication system, and the system includes: a server, a terminal device, and a user terminal. The server is communicatively connected to the terminal device, and the server is used to implement the identity authentication method in Embodiment I; The user terminal is used to input a secret key and an authentication ciphertext, decrypt the authentication ciphertext using the secret key to obtain an item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext.
[0049] In the present invention, by inputting an authentication request and a verification ciphertext on the terminal device, at this time, the user terminal does not establish a connection with the terminal device, nor does it establish a communication connection with the server. The user terminal only provides the input of a secret key and an authentication ciphertext, decrypts the authentication ciphertext using the secret key to obtain an item to be authenticated, encrypts the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext, etc. These operations improve the security and reliability of identity authentication; and only the authentication item in the authentication information is sent to the terminal device, and the authentication content corresponding to the authentication item is stored on the server; assuming that the authentication item is stolen, it will not cause privacy leakage, and the authentication item is also encrypted using an encryption algorithm, which can further improve security.
[0050] Embodiment IV This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the identity authentication method in Embodiment I.
[0051] This embodiment also provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the identity authentication method in the first embodiment.
[0052] In the present invention, by inputting an authentication request and a verification ciphertext on a terminal device, at this time, the user side does not establish a communication connection with the terminal device, nor does it communicate with the server. The user side only provides an input key and an authentication ciphertext, decrypts the authentication ciphertext with the key to obtain an item to be authenticated, encrypts the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext, etc., which improves the security and reliability of identity authentication; and only sends the authentication item in the authentication information to the terminal device, and stores the authentication content corresponding to the authentication item on the server; assuming that the authentication item is stolen, it will not cause privacy leakage, and the authentication item is also encrypted by an encryption algorithm, which can further improve security.
[0053] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0054] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0055] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. An authentication method, characterized in that The method is applied to a server, which is communicatively connected to a terminal device. The method includes: Obtain an authentication request input by a user on the terminal device, where the authentication request is a unique identifier randomly generated on the server based on the user's basic information; Match the authentication information reserved by the user based on the authentication request, where the authentication information includes multiple authentication items and the authentication content corresponding to each authentication item; Construct an item to be authenticated based on the authentication item, and encrypt the item to be authenticated using the key of a preset encryption algorithm to obtain an authentication ciphertext; Send the key and the authentication ciphertext to the terminal device, where the terminal device is used to visually display the key and the authentication ciphertext, input the key and the authentication ciphertext into the user side, and the user side is used to decrypt the authentication ciphertext using the key to obtain the item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext; Obtain the verification ciphertext input by the user on the terminal device, decrypt the verification ciphertext to obtain the authentication content input by the user; Authenticate the authentication content input by the user to obtain a verification result, and send the verification result to the terminal device, where the terminal device is used to grant the user the usage permission for the terminal device according to the verification result.
2. The authentication method according to claim 1, wherein The item to be authenticated includes a first authentication item and multiple second authentication items. Constructing the item to be authenticated based on the authentication item includes: Randomly select one authentication item from the multiple authentication items of the user as the first authentication item; Extract the keywords from all the authentication items, cluster all the keywords to obtain multiple categories; Randomly select at least two categories from the multiple categories, and generate multiple second authentication items based on the at least two selected categories.
3. The authentication method according to claim 2, wherein The authentication content input by the user includes: the first content corresponding to the first authentication item and the second content corresponding to the multiple second authentication items. Authenticating the authentication content input by the user to obtain a verification result includes: Compare the first content with the authentication content corresponding to each authentication item of the user to obtain a first result; Calculate the similarity between each second content and the authentication content corresponding to each authentication item of the user to obtain a second result; Determine the verification result based on the first result and the second result.
4. The authentication method according to claim 1, characterized in that, A display screen and a camera are integrated on the terminal device. The method further includes: The terminal device generates a first identification code containing the key and the authentication ciphertext based on the key and the authentication ciphertext, where the first identification code is a barcode and / or a QR code; The terminal device visually displays the first identification code through the display screen; the user side scans the first identification code displayed by the terminal device to obtain the key and the authentication ciphertext.
5. The authentication method according to claim 4, wherein The method further includes: The user side generates a second identification code containing the verification ciphertext based on the verification ciphertext, where the second identification code is a barcode and / or a QR code, and visually displays the second identification code; The camera of the terminal device scans the second identification code displayed by the user side to obtain the verification ciphertext; The terminal device uploads the verification ciphertext to the server.
6. The authentication method according to claim 1, wherein The private key corresponding to each user is stored on the server. Decrypting the verification ciphertext to obtain the authentication content input by the user includes: Obtain all private keys, decrypt the verification ciphertext based on all the private keys, and determine whether the decryption is successful; If not, generate a verification failure prompt and send the verification failure prompt to the terminal device, where the terminal device is used to visually display the verification failure prompt; If so, obtain the authentication content input by the user.
7. The authentication method according to any one of claims 1-6, characterized in that Encrypt the item to be authenticated based on the key of the preset encryption algorithm to obtain an authentication ciphertext, including: Based on the acquisition time of the authentication request; Perform hash encryption on the acquisition time to obtain a time hash value; Concatenate the acquisition time and the item to be authenticated to obtain a plaintext, and use the time hash value as the key of the preset encryption algorithm to encrypt the plaintext to obtain an authentication ciphertext.
8. An authentication device for implementing the authentication method according to any one of claims 1-7, characterized in that, The device includes: A request acquisition module, configured to acquire an authentication request input by a user on a terminal device, where the authentication request is a unique identifier randomly generated on a server according to the user's basic information; An authentication matching module, configured to match the reserved authentication information of the user based on the authentication request, where the authentication information includes multiple authentication items and the authentication content corresponding to each authentication item; An authentication encryption module, configured to construct an item to be authenticated based on the authentication item and encrypt the item to be authenticated based on the key of the preset encryption algorithm to obtain an authentication ciphertext; An authentication sending module, configured to send the key and the authentication ciphertext to the terminal device, where the terminal device is used to visually display the key and the authentication ciphertext, input the key and the authentication ciphertext into the user side, and the user side is used to decrypt the authentication ciphertext with the key to obtain the item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext; A ciphertext acquisition module, configured to acquire the verification ciphertext input by the user on the terminal device, decrypt the verification ciphertext to obtain the authentication content input by the user; An identity verification module, configured to perform identity verification on the authentication content input by the user to obtain a verification result, and send the verification result to the terminal device, where the terminal device is used to grant the user the usage right to the terminal device according to the verification result.
9. An authentication system, characterized in that, The system includes: a server, a terminal device, and a user side. The server is communicatively connected to the terminal device, and the server is used to implement the identity verification method described in any one of claims 1-7; The user side is used to input a key and an authentication ciphertext, decrypt the authentication ciphertext with the key to obtain the item to be authenticated, and encrypt the authentication content input by the user with reference to the item to be authenticated to obtain a verification ciphertext.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the identity verification method described in any one of claims 1-7.
Citation Information
Patent Citations
Method and system for single-point security certification
CN105025035A
Identity authentication method and device thereof, electronic equipment and storage medium
CN113645257A
Method for authenticating a user to a machine
US20150371214A1