Identity verification method, system and device and computer readable storage medium

By generating key pairs and using public key verification authentication methods, the problem of user data is solved, the security of data transmission and user experience is improved, and forged logins and man-in-the-middle attacks are prevented.

CN120337203APending Publication Date: 2025-07-18LINGSHU TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510506555.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing user authentication methods have security risks such as password leakage and man-in-the-middle attacks, and over-reliance on centralized server security has led to insecure user data.

Method used

By generating a key pair, using the private key to sign the requested content, and completing identity identification through the server-side public key verification and consistency comparison, avoiding the transmission and storage of plain text passwords, and determining the legality of the request with the timestamp.

Benefits of technology

It realizes the security of data transmission, prevents fake login and man-in-the-middle attacks, reduces the dependence on client security management, provides good user experience and repetition, and prevents replay attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337203A_ABST
    Figure CN120337203A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an identity verification method, system and device and a computer readable storage medium, and the method comprises the steps: generating a registration key pair according to a registration user name and a registration password, and storing the registration user name and a registration public key in the registration key pair to a server side; generating a verification key pair according to the login user name and the corresponding login password; when a user initiates a request, combining an interface address, a request type, a request body and a timestamp into a request character string, and signing the request character string according to the verification private key to obtain a request signature; sending the request signature, the verification public key and the timestamp to the server side through the request header along with the request character string; and verifying the request signature at the server side according to the verification public key, performing consistency verification according to the verification public key and the corresponding registered public key, judging whether the time is out according to the timestamp, and returning request data according to the request character string when the time is not out and the verification and the consistency verification are passed. And the data security is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer information security, and in particular, to an identity authentication method, system, device, and computer-readable storage medium. Background Art

[0002] Existing user identity authentication methods usually rely on a matching mechanism of username and password. That is, during the user login process, the client transmits the username and password to the server through the network. After receiving them, the server verifies them. If the verification is correct, an identity token (Token) is generated and returned for identifying the user identity and maintaining the session state in subsequent user requests.

[0003] Although this traditional authentication method is simple to implement, it has great security risks. On the one hand, the password needs to be stored in the server database in some form, and it may be leaked due to an attack on the database, thus making the password at risk of being cracked. On the other hand, during the information transmission process, if there are security vulnerabilities in the communication channel, the user's identity credentials may be eavesdropped or intercepted by malicious middlemen, resulting in identity fraud. In addition, this type of authentication method overly relies on the security of the centralized server. Once the server is breached, a large amount of sensitive information of users will be at risk of getting out of control.

[0004] For the above problems in the prior art, there is currently no effective solution. Summary of the Invention

[0005] To solve the above problems, the present invention provides an identity authentication method, system, device, and computer-readable storage medium. By generating a key pair according to the username and password, signing the request content with the private key, and verifying the signature and comparing for consistency through the public key on the server side to complete identity recognition, so that the plaintext password is not transmitted during the entire authentication process and does not rely on the storage of the password, to solve the problem of insecure user data in the prior art.

[0006] To achieve the above-mentioned purpose, the present invention provides an identity authentication method, including: generating a registration key pair according to a registered user name and a corresponding registration password, and saving the registered public key in the registered user name and the registration key pair to a server; generating a verification key pair according to the login user name and the corresponding login password input by the user when logging in; wherein the verification key pair includes a verification private key and a verification public key; when a user initiates a request, the interface address, request type, request body and timestamp are combined into a request string, and the request string is signed according to the verification private key to obtain a request signature; the request signature, the verification public key and the timestamp are sent to the server along with the request string through a request header; the request signature is verified on the server according to the verification public key, consistency verification is performed according to the verification public key and the corresponding registration public key, and whether it is timed out is determined according to the timestamp, and when it is not timed out, the signature verification passes and the consistency verification passes, the request data is returned according to the request string.

[0007] Further optionally, generating a registration key pair based on a registered user name and a corresponding registration password includes: concatenating the registered user name and the registration password according to a preset rule to obtain a registration string; performing a hash calculation on the registration string to obtain a first hash string; generating a registration private key based on the first hash string, generating a registration public key based on the registration private key, and using the registration private key and the registration public key as a registration key pair.

[0008] Further optionally, the generating of the verification key pair based on the login username and the corresponding login password input by the user when logging in includes: concatenating the login username and the corresponding login password according to the preset rule to obtain a login string; performing a hash calculation on the login string to obtain a second hash string; generating a verification private key based on the second hash string, generating a verification public key through the verification private key, and using the verification private key and the verification public key as a verification key pair.

[0009] Further optionally, the consistency verification based on the verification public key and the corresponding registration public key includes: querying the corresponding registration public key on the server side according to the login user name corresponding to the verification public key; performing byte-level comparison between the verification public key and the queried registration public key, and when they are consistent, it is determined that the consistency verification has passed; when they are inconsistent, the consistency verification fails and returns a failure message.

[0010] On the other hand, the present invention also provides an authentication system, including: a registration data storage module, configured to generate a registration key pair according to a registered user name and a corresponding registered password, and save the registered user name and the registered public key in the registration key pair to the server side; a data processing module, configured to generate an authentication key pair according to the login user name and the corresponding login password input by the user when logging in; wherein, the authentication key pair includes an authentication private key and an authentication public key; an authentication module, configured to, when the user initiates a request, combine the interface address, the request type, the request body, and the time stamp into a request string, sign the request string according to the authentication private key to obtain a request signature; send the request signature, the authentication public key, and the time stamp to the server side along with the request string through the request header; verify the request signature according to the authentication public key at the server side, perform consistency verification according to the authentication public key and the corresponding registered public key, and judge whether it times out according to the time stamp. When it does not time out, the signature verification passes, and the consistency verification passes, return the request data according to the request string.

[0011] Further optionally, the registration data storage module includes: a first splicing sub-module, configured to splice the registered user name and the registered password according to a preset rule to obtain a registration string; a first hash calculation sub-module, configured to perform hash calculation on the registration string to obtain a first hash string; a registration key pair generation sub-module, configured to generate a registration private key according to the first hash string, generate a registration public key according to the registration private key, and use the registration private key and the registration public key as a registration key pair.

[0012] Further optionally, the data processing module includes: a second splicing sub-module, configured to splice the login user name and the corresponding login password according to the preset rule to obtain a login string; a second hash calculation sub-module, configured to perform hash calculation on the login string to obtain a second hash string; an authentication key pair generation sub-module, configured to generate an authentication private key according to the second hash string, generate an authentication public key through the authentication private key, and use the authentication private key and the authentication public key as an authentication key pair.

[0013] Further optionally, the authentication module includes: a matching sub-module, configured to query the corresponding registered public key on the server side according to the login user name corresponding to the authentication public key; a comparison sub-module, configured to perform byte-level comparison between the authentication public key and the queried registered public key, and when they are consistent, determine that the consistency verification passes; a failure reminder sub-module, configured to, when they are inconsistent, the consistency verification fails and return a failure message.

[0014] On the other hand, the present invention also provides an authentication device, including the above-mentioned authentication system.

[0015] On the other hand, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the above authentication method is implemented.

[0016] The above technical solutions have the following beneficial effects: By generating and transmitting a key based on the password and username, it avoids the transmission or storage of the user password in plain text or reversible form at any stage, providing data transmission security; Through the signature and signature verification process implemented by the encryption mechanism, a unique signature can be generated for each user login request, and a request string is formed by combining content such as the interface address and the request body, effectively preventing common security threats such as forged logins and man-in-the-middle attacks; In addition, the key pair is completely derived from the username and password, the client does not need to store the private key for a long time, nor does it need to transmit the password to the server, having good repeatability and user experience, reducing the dependence on local security management of the client while maintaining high security; By verifying the timestamp to check whether the message has timed out, replay attacks are prevented. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and for those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0018] Figure 1 is a flowchart of the authentication method provided by the embodiment of the present invention;

[0019] Figure 2 is a flowchart of the registration key pair generation method provided by the embodiment of the present invention;

[0020] Figure 3 is a flowchart of the verification key pair generation method provided by the embodiment of the present invention;

[0021] Figure 4 is a flowchart of the consistency verification method provided by the embodiment of the present invention;

[0022] Figure 5 is a schematic structural diagram of the authentication system provided by the embodiment of the present invention;

[0023] Figure 6 is a schematic structural diagram of the registration data storage module provided by the embodiment of the present invention;

[0024] Figure 7 is a schematic structural diagram of the data processing module provided by the embodiment of the present invention;

[0025] Figure 8It is a schematic structural diagram of a verification module provided by an embodiment of the present invention.

[0026] Reference numerals: 100 - registration data storage module; 1001 - first splicing sub - module; 1002 - first hash calculation sub - module; 1003 - registration key pair generation sub - module; 200 - data processing module; 2001 - second splicing sub - module; 2002 - second hash calculation sub - module; 2003 - verification key pair generation sub - module; 300 - verification module; 3001 - matching sub - module; 3002 - comparison sub - module; 3003 - failure reminder sub - module. Detailed implementation manners

[0027] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0028] To solve the problem of insecure user data in the prior art, an embodiment of the present invention provides an identity verification method. Figure 1 It is a flowchart of the identity verification method provided by an embodiment of the present invention. As Figure 1 shown, the method includes:

[0029] S1. Generate a registration key pair according to the registered user name and the corresponding registered password, and save the registered user name and the registration public key in the registration key pair to the server side;

[0030] In the user registration stage, the client receives the registered user name and the registered password input by the user. Based on the registered user name and the registered password, a registration key pair is generated. This key pair includes a registration public key and a registration private key, and this key pair is the unique identity credential of the user.

[0031] Bind the registration public key and the registered user name, and store the binding information in the database on the server side for subsequent identity verification during login.

[0032] S2. Generate a verification key pair according to the login user name and the corresponding login password entered by the user when logging in; wherein, the verification key pair includes a verification private key and a verification public key;

[0033] When the user logs in on the web page, the login user name and the login password are entered. A verification key pair is generated according to the login user name and the login password, and the verification key pair is stored in the memory to meet the subsequent verification requirements.

[0034] S3. When a user initiates a request, the interface address, request type, request body and timestamp are combined into a request string, and the request string is signed according to the verification private key to obtain the request signature; the request signature, verification public key and timestamp are sent to the server through the request header along with the request string; the request signature is verified on the server according to the verification public key, and the consistency is verified between the verification public key and the corresponding registered public key, and whether it has timed out is determined according to the timestamp. When it has not timed out, the signature verification has passed and the consistency verification has passed, the request data is returned according to the request string.

[0035] When a user initiates a request, the user name, login interface address, request type, request body, and timestamp are combined into a request string. The request string is signed with the verification private key stored in the memory to obtain a request signature, which is used to ensure that the source of the request is credible and has not been tampered with.

[0036] Among them, the interface address refers to the specific address or path of the server-side interface accessed by the user when requesting back-end data, which is used to obtain resources; the user request refers to the operation data or parameter information submitted by the user during the login process, usually in the form of a request body, and the specific content depends on the business scenario.

[0037] When the client sends an identity authentication request to the server, the client sends the constructed request string, request signature, verification public key and timestamp to the server along with the request header.

[0038] After receiving this information, the server first uses the received verification public key to verify the request signature to determine whether the signature is valid. Then, the server compares the received verification public key with the registered public key saved in the database to determine whether it is the same user. In addition, it is also necessary to use the timestamp to determine whether the timeout period has exceeded. When it has not timed out, the signature verification has passed, and the public key is consistent, the server confirms that the user's identity is legitimate and performs operations or returns corresponding data based on the request string.

[0039] As an optional implementation, Figure 2 is a flow chart of a registration key pair generation method provided by an embodiment of the present invention, such as Figure 2 As shown, a registration key pair is generated based on the registered user name and the corresponding registration password, including:

[0040] S101, concatenate the registered user name and the registered password according to a preset rule to obtain a registered character string;

[0041] First, receive the registered username and registered password input by the user, and merge the two according to a preset splicing rule to generate an original string, called the "registration string". The preset rule can be to directly concatenate the username and password in sequence, or insert a specific character or delimiter between the two, such as "username + ':' + password", to ensure the consistency and repeatability of the splicing process. The splicing result is used as the input for subsequent hashing processing, which affects the generation result of the entire key pair.

[0042] S102. Perform a hashing calculation on the registration string to obtain a first hash string;

[0043] Perform a hashing operation on the registration string generated in the previous step. Hashing calculation refers to converting input data of any length into a fixed-length output digest through a hash function, and this digest is the "first hash string". This hash function is preferably a secure one-way function, such as SHA-256, which has characteristics such as irreversibility, collision resistance, and determinacy. This hash result will be used as the basis for subsequent key generation operations to improve the stability and security of key derivation.

[0044] S103. Generate a registration private key based on the first hash string, generate a registration public key based on the registration private key, and use the registration private key and registration public key as a registration key pair.

[0045] The generation method of the key pair can be based on an encryption algorithm that supports seed derivation, such as Ed25519, ECDSA, or RSA, etc. This first hash string can be used as a seed to generate a registration private key, and a corresponding public key is generated based on the registration private key, which is used to ensure that the same key pair can always be generated when the user uses the same username and password. Among the finally generated registration key pairs, the registration private key is retained within the client or under user control, while the registration public key is submitted to the server side and stored in the server side for subsequent identity verification.

[0046] As an alternative implementation manner, Figure 3 is a flowchart of the verification key pair generation method provided by an embodiment of the present invention. As Figure 3 shown, generating a verification key pair according to the login username and the corresponding login password includes:

[0047] S201. Splice the login username and the corresponding login password according to a preset rule to obtain a login string;

[0048] Receive the login username and corresponding login password input by the user, and merge the two according to the same preset rules as in the registration stage to generate a combined data called "login string". The preset rules need to be consistent to ensure that the same username and password always generate the same basic input value in the registration and login stages. The concatenation method can be direct connection, encrypted connection, or using delimiters, etc. The ultimate goal is to form an input string for subsequent hash processing.

[0049] S202. Perform a hash calculation based on the login string to obtain a second hash string;

[0050] After obtaining the login string, perform a hash operation on it to obtain a result called "second hash string". This hash process is the same as in the registration stage. It is preferably to use a consistent one-way hash function, such as SHA-256, to ensure that the hash result generated in the login stage is consistent with the same input conditions in the registration stage. This second hash string serves as the basis for subsequent key generation and is used to derive a verification key pair.

[0051] S203. Generate a verification private key based on the second hash string, generate a verification public key through the verification private key, and use the verification private key and verification public key as a verification key pair.

[0052] Based on the second hash string, use an asymmetric encryption algorithm that supports key derivation to generate a verification key pair, including a verification private key and a verification public key. The selected algorithm is preferably Ed25519, ECDSA, or other algorithms with repeatable key derivation characteristics to ensure that when the username and password are the same and the concatenation and hash logic are consistent, the key pairs generated in the registration stage and the login stage are exactly the same. The verification private key in this verification key pair is used to sign the request data, while the verification public key is used to submit to the server side for the server side to perform signature verification and identity verification.

[0053] As an alternative implementation Figure 4 is the flowchart of the consistency verification method provided by the embodiment of the present invention. As Figure 4 shown, perform consistency verification according to the verification public key and the corresponding registration public key, including:

[0054] S301. Query the corresponding registration public key on the server side according to the login username corresponding to the verification public key;

[0055] The server side authenticates the user's identity. After receiving the login request from the client side, the server side will retrieve the registration public key saved when the user registered from the database according to the username attached to the request. The purpose of this operation is to extract the original and recognized user identity information, which is used as the reference data for comparing the consistency with the current login public key.

[0056] S302. Perform a byte-level comparison between the verification public key and the retrieved registration public key. When they are consistent, it is determined that the consistency verification passes.

[0057] The server-side makes a byte-by-byte exact comparison between the verification public key submitted by the client for this login and the registration public key retrieved from the database. If the two public keys are exactly the same in terms of data structure and content, it indicates that the key pair generated by the client this time is the same as that in the registration stage, showing that the user is indeed the original registrant, thus confirming the legitimacy of their identity and passing the consistency verification.

[0058] S303. When they are inconsistent, the consistency verification fails and a failure message is returned.

[0059] If the above byte-level comparison result indicates that the verification public key is inconsistent with the registration public key, it means that the combination of the username and password submitted by the current user cannot generate the same key pair as in the registration stage, which may be due to a wrong password or identity forgery. In this case, the server-side will reject this request and return a prompt message of failed consistency verification to the client to prevent illegal access.

[0060] An embodiment of the present invention also provides an identity verification system. Figure 5 It is a schematic structural diagram of the identity verification system provided by the embodiment of the present invention, as Figure 5 shown. The system includes:

[0061] A registration data storage module 100, which is used to generate a registration key pair according to the registration username and the corresponding registration password, and save the registration username and the registration public key in the registration key pair to the server-side.

[0062] In the user registration stage, the client receives the registration username and registration password input by the user. Based on the registration username and registration password, a registration key pair is generated. This key pair includes a registration public key and a registration private key, and this key pair belongs to the user's unique identity credential.

[0063] Bind the registration public key and the registration username, and store the binding information in the database on the server-side for subsequent identity verification during login.

[0064] A data processing module 200, which is used to generate a verification key pair according to the login username and the corresponding login password input by the user during login; wherein, the verification key pair includes a verification private key and a verification public key.

[0065] When the user logs in on the web page, the login username and login password will be input, and a verification key pair is generated according to the login username and login password. The verification key pair is stored in the memory to meet the subsequent verification requirements.

[0066] The verification module 300 is used to combine the interface address, request type, request body, and timestamp into a request string when the user initiates a request, sign the request string according to the verification private key to obtain a request signature; send the request signature, verification public key, and timestamp to the server side along with the request string through the request header; verify the request signature on the server side according to the verification public key, perform consistency verification between the verification public key and the corresponding registered public key, and determine whether it times out according to the timestamp. When it does not time out, the signature verification passes, and the consistency verification passes, the request data is returned according to the request string.

[0067] In the stage where the client sends an identity verification request to the server side, the client sends the constructed request string, request signature, verification public key, and timestamp to the server side along with the request header.

[0068] After receiving this information, the server side first uses the received verification public key to verify the request signature to determine whether the signature is valid. Then, the server side will compare the received verification public key with the registered public key saved in the database to determine whether it is the same user. In addition, it is also necessary to judge whether the timeout time is exceeded through the timestamp. When it does not time out, the signature verification passes, and the public keys are consistent, the server side confirms that the user identity is legal and performs operations or returns corresponding data according to the request string.

[0069] As an optional implementation manner, Figure 6 is a schematic structural diagram of the registration data storage module provided by the embodiment of the present invention. As Figure 6 shown, the registration data storage module 100 includes:

[0070] The first splicing sub-module 1001 is used to splice the registered user name and the registered password according to a preset rule to obtain a registration string;

[0071] First, receive the registered user name and registered password input by the user, and combine the two according to a preset splicing rule to generate an original string, called the "registration string". The preset rule can be to directly connect the user name and password in sequence, or insert a specific character or separator between the two, such as "user name + ':' + password", to ensure the consistency and repeatability of the splicing process. The splicing result is used as the input for subsequent hash processing and affects the generation result of the entire key pair.

[0072] The first hash calculation sub-module 1002 is used to perform hash calculation on the registration string to obtain a first hash string;

[0073] Perform a hash operation on the registration string generated in the previous step. Hash calculation refers to converting input data of any length into a fixed-length output digest through a hash function, and this digest is the "first hash string". This hash function is preferably a secure one-way function, such as SHA-256, which has characteristics such as irreversibility, collision resistance, and determinism. This hash result will be used as the basis for subsequent key generation operations to improve the stability and security of key derivation.

[0074] The registration key pair generation sub-module 1003 is used to generate a registration private key based on the first hash string, generate a registration public key based on the registration private key, and use the registration private key and the registration public key as the registration key pair.

[0075] The generation method of the key pair can be based on encryption algorithms that support seed derivation, such as Ed25519, ECDSA, or RSA, etc. This first hash string can be used as a seed to generate a registration private key, and a corresponding public key is generated based on the registration private key, which is used to ensure that the same key pair can always be generated when the user uses the same username and password. Among the finally generated registration key pairs, the registration private key is retained within the client or under user control, while the registration public key is submitted to the server side and stored in the server side for subsequent identity authentication.

[0076] As an alternative implementation Figure 7 is a schematic structural diagram of the data processing module provided by an embodiment of the present invention, as Figure 7 shown, the login data processing module 200 includes:

[0077] The second splicing sub-module 2001 is used to splice the login username and the corresponding login password according to a preset rule to obtain a login string;

[0078] Receive the user-entered login username and the corresponding login password, and merge the two according to the same preset rule as in the registration stage to generate a combined data called the "login string". The preset rule needs to be consistent to ensure that the same username and password always generate the same basic input value in the registration and login stages. The splicing method can be in forms such as direct connection, encrypted connection, or using delimiters, and the ultimate goal is to form an input string for subsequent hash processing.

[0079] The second hash calculation sub-module 2002 is used to perform a hash calculation on the login string to obtain a second hash string;

[0080] After obtaining the login string, perform a hash operation on it to obtain a result called the "second hash string". This hash process is the same as in the registration phase, and it is preferable to use a consistent one-way hash function, such as SHA-256, to ensure that the hash result generated in the login phase is consistent under the same input conditions as in the registration phase. This second hash string serves as the basis for subsequent key generation and is used to derive the verification key pair.

[0081] The verification key pair generation sub-module 2003 is used to generate a verification private key based on the second hash string, generate a verification public key through the verification private key, and use the verification private key and the verification public key as the verification key pair.

[0082] Based on the second hash string, use an asymmetric encryption algorithm that supports key derivation to generate a verification key pair, including a verification private key and a verification public key. The selected algorithm is preferably Ed25519, ECDSA, or other algorithms with repeatable key derivation characteristics to ensure that when the username and password are the same and the splicing and hashing logic are consistent, the key pairs generated in the registration phase and the login phase are exactly the same. The verification private key in this verification key pair is used to sign the request data, while the verification public key is used to submit to the server side for the server side to perform signature verification and identity verification.

[0083] As an alternative implementation Figure 8 is the structural schematic diagram of the verification module provided by the embodiments of the present invention, as Figure 8 shown, the verification module 300 includes:

[0084] The matching sub-module 3001 is used to query the corresponding registered public key on the server side according to the login username corresponding to the verification public key;

[0085] The server side performs user identity verification. After receiving the login request from the client, the server side will retrieve the registered public key saved during registration for this username from the database according to the username attached in the request. The purpose of this operation is to extract the original and recognized user identity identification information, which is used as the reference data for consistency comparison with the current login public key.

[0086] The comparison sub-module 3002 is used to perform a byte-level comparison between the verification public key and the queried registered public key, and when they are consistent, it is determined that the consistency verification passes;

[0087] The server side makes a byte-by-byte precise comparison between the verification public key submitted by the client for this login and the registered public key obtained from the database query. If the two public keys are exactly the same in terms of data structure and content, it indicates that the key pair generated by the client this time is the same as in the registration phase, indicating that the user is indeed the original registrant, thus confirming that their identity is legal and the consistency verification passes.

[0088] The failure reminder sub-module 3003 is used to return a failure message when the consistency verification fails in case of inconsistency.

[0089] If the above byte-level comparison result indicates that the verification public key is inconsistent with the registered public key, it means that the combination of the user name and password submitted by the current user cannot generate the same key pair as in the registration stage, which may be due to an incorrect password or identity forgery. In this case, the server side will reject this request and return a prompt message indicating the failure of the consistency verification to the client to prevent illegal access.

[0090] An embodiment of the present invention also provides an identity authentication device, including the above identity authentication system.

[0091] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the above identity authentication method is implemented.

[0092] The above storage medium includes but is not limited to: optical discs, floppy disks, hard disks, erasable memories, etc.

[0093] The above technical solutions have the following beneficial effects: By generating key transmission according to the password and user name, it avoids the transmission or storage of the user password in plain text or reversible form at any stage, providing data transmission security; Through the signature and signature verification process implemented by the encryption mechanism, a unique signature can be generated for each user login request, and a request string is formed by combining the interface address and the request body, etc., effectively preventing common security threats such as forged logins and man-in-the-middle attacks; In addition, the key pair is completely derived from the user name and password. The client does not need to store the private key for a long time, nor does it need to transmit the password to the server side, which has good repeatability and user experience, and reduces the dependence on local security management of the client while maintaining high security; By verifying the timestamp to check whether the message times out, replay attacks are prevented.

[0094] The specific implementation manners of the above invention further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above content is only the specific implementation manners of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. An authentication method, characterized in that, include: Generate a registration key pair based on the registered user name and the corresponding registration password, and save the registered public key in the registered user name and the registration key pair to the server; Generate a verification key pair according to the login username and corresponding login password entered by the user when logging in; wherein the verification key pair includes a verification private key and a verification public key; When a user initiates a request, the interface address, request type, request body and timestamp are combined into a request string, and the request string is signed according to the verification private key to obtain a request signature; the request signature, verification public key and timestamp are sent to the server along with the request string through the request header; the request signature is verified on the server according to the verification public key, and consistency verification is performed based on the verification public key and the corresponding registered public key, and whether it has timed out is determined based on the timestamp. When it has not timed out, the signature verification has passed and the consistency verification has passed, the request data is returned according to the request string.

2. The authentication method according to claim 1, wherein The generating of the registration key pair according to the registration user name and the corresponding registration password includes: Concatenate the registered user name and the registered password according to a preset rule to obtain a registered character string; Performing hash calculation on the registration string to obtain a first hash string; A registration private key is generated according to the first Hash character string, a registration public key is generated according to the registration private key, and the registration private key and the registration public key are used as a registration key pair.

3. The authentication method according to claim 2, wherein The generating of the verification key pair according to the login username and the corresponding login password input by the user when logging in includes: Concatenate the login user name and the corresponding login password according to the preset rule to obtain a login character string; Performing hash calculation on the login string to obtain a second hash string; A verification private key is generated according to the second Hash character string, a verification public key is generated by the verification private key, and the verification private key and the verification public key are used as a verification key pair.

4. The authentication method according to claim 1, wherein The consistency verification based on the verification public key and the corresponding registration public key includes: Querying the corresponding registration public key on the server side according to the login user name corresponding to the verification public key; Perform byte-level comparison between the verification public key and the queried registration public key, and when they are consistent, determine that the consistency verification has passed; When there is inconsistency, the consistency verification fails and returns a failure message.

5. An authentication system, characterized in that, include: A registration data storage module, used to generate a registration key pair according to the registration user name and the corresponding registration password, and save the registration public key in the registration user name and the registration key pair to the server; A data processing module, used to generate a verification key pair according to a login username and a corresponding login password input by a user when logging in; wherein the verification key pair includes a verification private key and a verification public key; The verification module is used to combine the interface address, request type, request body and timestamp into a request string when the user initiates a request, sign the request string according to the verification private key to obtain the request signature; send the request signature, verification public key and timestamp to the server side along with the request string through the request header; verify the request signature according to the verification public key on the server side, perform consistency verification based on the verification public key and the corresponding registered public key, and determine whether it has timed out based on the timestamp. When it has not timed out, the signature verification has passed and the consistency verification has passed, return the request data according to the request string.

6. The authentication system according to claim 5, characterized in that, The registration data storage module includes: A first splicing sub-module, configured to splice the registered username and the registered password according to a preset rule to obtain a registration string; A first hash calculation sub-module, configured to perform hash calculation on the registration string to obtain a first hash string; A registration key pair generation sub-module, configured to generate a registration private key according to the first hash string, generate a registration public key according to the registration private key, and use the registration private key and the registration public key as a registration key pair.

7. The authentication system according to claim 6, characterized in that, The data processing module includes: A second splicing sub-module, configured to splice the login username and the corresponding login password according to the preset rule to obtain a login string; A second hash calculation sub-module, configured to perform hash calculation on the login string to obtain a second hash string; A verification key pair generation sub-module, configured to generate a verification private key according to the second hash string, generate a verification public key through the verification private key, and use the verification private key and the verification public key as a verification key pair.

8. The authentication system according to claim 5, wherein The verification module includes: A matching sub-module, configured to query a corresponding registration public key on the server side according to the login username corresponding to the verification public key; A comparison sub-module, configured to perform byte-level comparison between the verification public key and the queried registration public key, and when they are consistent, determine that the consistency verification passes; A failure reminder sub-module, configured to, when they are inconsistent, indicate that the consistency verification fails and return a failure message.

9. An authentication device, characterized in that, Including the authentication system according to any one of claims 5-8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the authentication method according to any one of claims 1-4.