Information publishing method and system based on two-factor authentication mechanism and national secret algorithm, medium, terminal and program product
Through the combination of the two-factor authentication mechanism and the Guoxin algorithm SM2, the unauthorized access and information tampering of the internal information publishing platform of the enterprise is solved, and the secure release and integrity protection of information are achieved.
Patent Information
- Application Number
- CN202510485034.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, internal information publishing platforms of enterprises face security threats of unauthorized access and information tampering, and it is difficult to ensure the authenticity and integrity of the information.
The information release method based on the two-factor authentication mechanism and the Guomi algorithm SM2 is adopted to verify the user's identity through the two-factor authentication mechanism, and the Guomi algorithm SM2 is used to sign and verify the published information to ensure the security and integrity of the information.
Effectively prevent unauthorized access, ensure the authenticity and integrity of information, improve the security and reliability of the information release process, and prevent data from being maliciously tampered with or forged.
Smart Images

Figure CN120342691A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to an information publishing method, system, medium, terminal and program product based on a two-factor authentication mechanism and a national cryptographic algorithm. Background Art
[0002] On the enterprise internal information publishing platform, the administrator logs in to the system and publishes important enterprise internal information. However, during this process, various security threats are faced.
[0003] Due to the insufficient existing information security measures, in the login link, illegal users may obtain access rights through various means. This unauthorized access will lead to the leakage of important internal information and cause serious consequences. Moreover, there is a risk of malicious tampering of information during transmission and storage, affecting its authenticity and integrity.
[0004] Therefore, it is necessary to provide an information publishing method, system, medium, terminal and program product based on a two-factor authentication mechanism and a national cryptographic algorithm to solve the above problems existing in the prior art. Summary of the Invention
[0005] In view of the above-mentioned disadvantages of the prior art, the purpose of this application is to provide an information publishing method, system, medium, terminal and program product based on a two-factor authentication mechanism and a national cryptographic algorithm, which is used to solve the technical problems that it is difficult for the prior art to prevent unauthorized access and tampering and to ensure the authenticity and integrity of information.
[0006] To achieve the above purpose and other related purposes, the first aspect of this application provides an information publishing method based on a two-factor authentication mechanism and a national cryptographic algorithm, including:
[0007] In response to a user login request, authenticate the user identity based on a pre-configured two-factor authentication mechanism and return the identity authentication result information;
[0008] If it is determined that the identity authentication is successful according to the identity authentication result information, obtain the information to be published, sign the information to be published based on the national cryptographic algorithm SM2 to generate signature data, and verify the signature data. After the verification is successful, publish the information;
[0009] If it is determined that the identity authentication fails according to the identity authentication result information, return a prompt message for failed authentication.
[0010] In some embodiments of the first aspect of the present application, in response to a user login request, the user identity is authenticated based on a pre-configured two-factor authentication mechanism, and the identity authentication result information is returned. The execution process includes: performing a configuration operation of the two-factor authentication mechanism according to the received user login request, and returning the configuration completion result information; detecting whether the function module of the two-factor authentication mechanism is turned on; if the function module of the two-factor authentication mechanism is turned on, making the function module of the two-factor authentication mechanism generate an identification code; generating and providing a dynamic verification code in response to the user's recognition operation of the identification code; returning the corresponding identity authentication result information based on the input account password and the dynamic verification code; if the function module of the two-factor authentication mechanism is not turned on, the two-factor authentication mechanism is not enabled.
[0011] In some embodiments of the first aspect of the present application, signing the information to be published based on the national cryptography algorithm SM2 to generate signature data, the execution process includes: generating a private key and a public key based on a key generator, and storing the generated private key and public key; performing a hashing process on the information to be published using the national cryptography SM3 hashing algorithm to obtain a first hash value; signing the information to be published according to the stored private key and the first hash value to obtain a signature result; embedding the signature result into the information to be published and then packing it to form signature data and storing the signature data.
[0012] In some embodiments of the first aspect of the present application, verifying the signature of the signature data and waiting for the verification to succeed before publishing the information. The execution process includes: performing a hashing process on the information to be published in the signature data using the national cryptography SM3 hashing algorithm to obtain a second hash value; verifying the signature value in the signature result according to the stored public key and the second hash value; comparing and judging the second hash value and the first hash value, and judging whether the calculated result value obtained from the signature verification is equal to the signature value; if the second hash value and the first hash value are the same, and the calculated result value obtained from the signature verification is the same as the signature value, the signature verification is successful, and the information is published; if the second hash value and the first hash value are different or the calculated result value obtained from the signature verification is different from the signature value, the signature verification fails.
[0013] In some embodiments of the first aspect of the present application, the generated private key and public key based on the key generator are hashed using the SHA-256 hashing function to obtain a private key hash value and a public key hash value respectively and store them.
[0014] In some embodiments of the first aspect of the present application, after the private key and the public key are generated based on the key generator and the generated private key and public key are stored, it further includes: validating the effectiveness of the stored private key and public key.
[0015] To achieve the above object and other related objects, the second aspect of the present application provides an information publishing system based on a two-factor authentication mechanism and a national cryptographic algorithm, including:
[0016] A two-factor authentication module, configured to authenticate the user identity based on a pre-configured two-factor authentication mechanism in response to a user login request, and return identity authentication result information;
[0017] An information signature verification module, configured to, if it is determined that the identity authentication is successful according to the identity authentication result information, obtain the information to be published, generate signature data by signing the information to be published based on the national cryptographic algorithm SM2, and verify the signature data for information publishing after the signature verification is successful;
[0018] A prompt information module, configured to return a prompt message for failed authentication if it is determined that the identity authentication fails according to the identity authentication result information.
[0019] To achieve the above object and other related objects, the third aspect of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method is implemented.
[0020] To achieve the above object and other related objects, the fourth aspect of the present application provides a computer program product, which includes computer program code, and when the computer program code runs on a computer, the computer implements the method.
[0021] To achieve the above object and other related objects, the fifth aspect of the present application provides an electronic terminal, including a memory, a processor, and a computer program stored on the memory; the processor executes the computer program to implement the method.
[0022] As described above, the information publishing method, system, medium, terminal, and program product based on the two-factor authentication mechanism and the national cryptographic algorithm of the present application have the following beneficial effects:
[0023] By verifying the identity information of the logged-in user based on a pre-established two-factor authentication mechanism, the identity information verification is strengthened. When logging in, the user not only needs to enter the account password but also needs to pass a dynamic verification code for secondary verification. This dual verification method significantly improves the access security of the platform system, ensuring that only users who have passed strict identity verification can enter the platform, effectively preventing unauthorized access, and protecting the security of sensitive information from the source. And after the identity authentication result information is verified successfully, the information to be published is signed based on the national cryptography algorithm SM2, and the signed data is verified. After the verification is successful, the information is published. This digital signature technology ensures the authenticity and integrity of the information. Any tampering with the data will be detected and rejected. At the same time, the high-strength encryption ability of the national cryptography algorithm SM2 guarantees the security of the information to be published during the transmission and storage processes, preventing the data from being maliciously tampered with or forged, and ensuring the authenticity and credibility of the information. This application combines the two-factor authentication mechanism and the national cryptography algorithm SM2 to form a dual protection mechanism, which not only enhances the security of identity authentication but also ensures the confidentiality of data transmission and storage. From identity authentication to data transmission, the entire link uses high-strength encryption protection, improving the overall security of the information publishing process and being applicable to various scenarios with high security requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It shows a schematic flow chart of the information publishing method based on the two-factor authentication mechanism and the national cryptography algorithm in an embodiment of the present application.
[0025] Figure 2 It shows a schematic flow chart of logging in based on the two-factor authentication mechanism in an embodiment of the present application.
[0026] Figure 3 It shows a schematic flow chart of signing and verifying the information to be published based on the national cryptography algorithm SM2 in an embodiment of the present application.
[0027] Figure 4 It shows a schematic framework diagram of the information publishing method based on the two-factor authentication mechanism and the national cryptography algorithm in an embodiment of the present application.
[0028] Figure 5 It shows a schematic framework diagram of the information publishing method based on the two-factor authentication mechanism and the national cryptography algorithm in another embodiment of the present application.
[0029] Figure 6 It shows a schematic structural diagram of the information publishing system based on the two-factor authentication mechanism and the national cryptography algorithm in an embodiment of the present application.
[0030] Figure 7 It shows a schematic structural diagram of an electronic terminal in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] The following specific examples illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0032] In the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. For example, the first XX and the second XX are only used to distinguish different XX, and do not limit their sequence. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and terms such as "first" and "second" do not necessarily mean different.
[0033] It should be noted that in the embodiments of the present application, words such as "exemplary" or "for example" indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific manner.
[0034] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item)" or its similar expression below refers to any combination of these items, including any combination of single item (s) or plural items (s). For example, at least one (item) of a, b or c can represent: a, b, c, a - b, a - c, b - c or a - b - c, where a, b, c can be single or multiple.
[0035] Before further elaborating on the present invention in detail, the nouns and terms involved in the embodiments of the present invention are described. The nouns and terms involved in the embodiments of the present invention are applicable to the following explanations:
[0036] <1>Two Factor Authentication (2FA): It is a security authentication process that requires users to provide two different types of authentication factors to prove their identities, including combinations of multiple factors such as passwords, fingerprints, SMS verification codes, smart cards, biometric recognition, etc., thereby enhancing the security and reliability of user accounts.
[0037] <2>GuoMi Algorithm SM2: It is a set of asymmetric encryption algorithms and an important part of the Chinese commercial cryptography system. It is designed based on Elliptic Curve Cryptography (ECC) and is used to replace the internationally common RSA algorithm, having advantages in terms of security, efficiency, and key length.
[0038] <3>GuoMi SM3 Hash Algorithm: It is a cryptographic hash function used to compress a message of any length into a fixed-length digest, with an output length of 256 bits.
[0039] <4>SHA-256 (Secure Hash Algorithm 256-bit) Hash Function: It is a one-way cryptographic hash function that can compress a message of any length (input data) into a fixed-length (256-bit) hash value (digest). Its output is a 256-bit binary number, usually represented by 64 hexadecimal characters.
[0040] <4>GmSSL Library: It is an open-source cryptographic toolbox that supports GuoMi (National Commercial Cryptography) algorithms such as SM2 / SM3 / SM4 / SM9 / ZUC, GuoMi digital certificates of SM2, and SSL / TLS security communication protocols based on SM2 certificates. It supports GuoMi hardware cryptographic devices, provides programming interfaces and command-line tools that conform to GuoMi specifications, and can be used to build security applications that conform to GuoMi standards such as PKI / CA, secure communication, and data encryption.
[0041] For ease of understanding the embodiments of the present application, first, in combination with Figure 1 detailed description will be given. Figure 1 The flowchart of an information publishing method based on the two-factor authentication mechanism and GuoMi algorithm in the embodiments of the present invention is shown. The information publishing method based on the two-factor authentication mechanism and GuoMi algorithm in this embodiment mainly includes the following steps:
[0042] Step S11: In response to a user login request, authenticate the user's identity based on the pre-configured two-factor authentication mechanism and return the identity authentication result information.
[0043] In some embodiments of the present application, in response to a user login request, the user identity is authenticated based on a pre-configured two-factor authentication mechanism, and the identity authentication result information is returned. The execution process includes: performing a configuration operation of the two-factor authentication mechanism according to the received user login request, and returning the configuration completion result information; detecting whether the function module of the two-factor authentication mechanism is turned on; if the function module of the two-factor authentication mechanism is turned on, making the function module of the two-factor authentication mechanism generate an identification code; in response to the user's recognition operation of the identification code, generating and providing a dynamic verification code; based on the input account password and the dynamic verification code, returning the corresponding identity authentication result information; if the function module of the two-factor authentication mechanism is not turned on, the two-factor authentication mechanism is not enabled.
[0044] Specifically, as Figure 2 shown, after the user successfully logs in to the system and enters the configuration interface, find and select the function operation that needs to enable the two-factor authentication mechanism. The configuration interface and process are simple and clear, and the user can complete the setting of the two-factor authentication mechanism with only a few operations. After the configuration is completed, when the user attempts to perform an operation that requires secondary security verification, it is intelligently detected whether the function module of the two-factor authentication mechanism is enabled. It should be noted that the function module of the two-factor authentication mechanism includes software form, plug-in form, cloud service form, etc. Among them, the two-factor authentication in software form, such as Google Authenticator, Authy, etc., is used to generate and manage two-factor authentication codes; the two-factor authentication of the browser plug-in is integrated into the browser and automatically processes the two-factor authentication process; the two-factor authentication in cloud service form enables users to quickly integrate the two-factor authentication function through the API. For the convenience of description, the two-factor authentication mechanism will be referred to as 2FA hereinafter.
[0045] If the two-factor authentication mechanism is detected to be enabled, continue to perform the 2FA operation until the verification is successful. If the two-factor authentication mechanism is detected to be disabled, do not enable the two-factor authentication mechanism and prompt the user whether to enable this function to ensure the security of subsequent operations. After the user confirms to enable the two-factor authentication mechanism, enter the interface for enabling two-factor authentication. At this time, the function module of the two-factor authentication mechanism generates a unique identification code; the user performs an identification operation on the identification code to generate and provide a dynamic verification code to the user; the user inputs the account password and the obtained dynamic verification code, and returns the corresponding identity authentication result information. After the verification is successful, the two-factor authentication mechanism is officially enabled, and the user can continue to perform operations that require secondary verification. Among them, the types of identification codes include, but are not limited to: two-dimensional codes, barcodes, biometric codes. Exemplarily, the function module of the two-factor authentication mechanism generates a two-dimensional code, and the user only needs to use the Authenticator software application on the mobile phone to scan the two-dimensional code to obtain the dynamic verification code. Subsequently, the user inputs the account password and the just-obtained dynamic verification code for identity verification, and the returned identity authentication result information is successful or failed.
[0046] Step S12: If it is determined that the identity authentication is successful according to the identity authentication result information, obtain the information to be published, sign the information to be published based on the national cryptography algorithm SM2 to generate signature data, and verify the signature data until the signature verification is successful and then publish the information.
[0047] In some embodiments of the present application, the process of signing the information to be published based on the national cryptography algorithm SM2 to generate signature data includes: generating a private key and a public key based on a key generator, and storing the generated private key and public key; performing a hashing process on the information to be published using the national cryptography SM3 hashing algorithm to obtain a first hash value; signing the information to be published according to the stored private key and the first hash value to obtain a signature result; embedding the signature result into the information to be published and then packing it to form signature data and storing the signature data.
[0048] Specifically, the elliptic curve equation is:
[0049] y 2 = x 3 + ax + b mod p; Formula (1)
[0050] First, the coefficients a and b in the above elliptic curve equation and the prime number p of the finite field need to be defined to form an elliptic curve. Based on a key generator, a private key d and a public key P are generated. The generated private key d is securely stored, and the public key P is publicly stored. Among them, d is a randomly selected integer that satisfies 1 ≤ d ≤ n - 1; n is the order of the base point G (a point on the elliptic curve). The public key P is obtained according to the following formula (2):
[0051] P = dG; Formula (2)
[0052] Use the national cryptographic SM3 hash algorithm to perform a hash process on the information M to be published, and output the first hash value e = SM3(M). Then, use the securely stored private key d and the first hash value e to sign the information M to be published. The specific calculation process is as follows:
[0053] Select a random number k that satisfies 1 ≤ k ≤ n - 1 to generate the random number k.
[0054] Use the random number k and the base point G to calculate the elliptic curve point according to the following formula (3):
[0055] (x1, y1) = kG; Formula (3)
[0056] Calculate the signature values r and s. The specific calculation formulas are as follows:
[0057] r = (e + x1) mod n; Formula (4)
[0058] s = (1 + d) -1 ×(k - r × d) mod n; Formula (5)
[0059] If r = 0, re - select k and repeat the above steps; if s = 0, re - calculate k and repeat the above steps; combine the signature values r and s into a signature result (r, s) in a certain format. Embed the signature result after the information to be published to form a complete data structure for packaging to form signature data and store it. That is, the signature data includes the information to be published and the signature result.
[0060] In some embodiments of the present application, the generated private key and public key based on the key generator are hashed using the SHA - 256 hash function to obtain a private key hash value and a public key hash value respectively and store them.
[0061] Specifically, the private key and the public key are used as input data respectively, and a hash value of a fixed length is calculated through the SHA - 256 hash function, that is, the private key hash value and the public key hash value are output, and at the same time, the private key, the public key, the private key hash value, and the public key hash value are stored.
[0062] In some embodiments of the present application, after the private key and the public key are generated based on the key generator and the generated private key and public key are stored, the method further includes: validating the effectiveness of the stored private key and public key.
[0063] As Figure 3 shown, when the multimedia service is started, it is first necessary to detect whether there is a key pair, that is, a private key and a public key. If there is no key, a key is generated and saved; if there is a key, the effectiveness of the key is verified. The effectiveness verification method is, for example: reusing the SHA-256 hash function to calculate the hash values of the private key and the public key respectively. Compare the stored private key hash value with the hash value calculated for the private key this time. If the two are the same, it means that the private key or the public key has not been tampered with and is valid; if the two are different, it means that the private key or the public key may have been tampered with and is invalid. Compare the stored public key hash value with the hash value recalculated for the public key this time. If the two are the same, it means that the private key or the public key has not been tampered with and is valid; if the two are different, it means that the private key or the public key may have been tampered with and is invalid. In the case where the private key and the public key are invalid, the old key needs to be deleted at this time, and a new key is regenerated through the key generator, its hash value is calculated and stored. On the premise that the key pair is valid, the signature data is generated and stored through the above specific process of signing based on the national cryptography algorithm SM2. When verifying the signature, first detect whether the signature exists. If it exists, the signature data is returned; if the signature does not exist, the private key is used for signing and saved. The stored signature data is transmitted to the signature verification end, such as a server or a controller, and the signature verification end uses the public key to verify the signature value of the information to be published. The detailed description of the signature verification steps is as follows.
[0064] In some embodiments of the present application, when verifying the signature data and waiting for the signature verification to succeed before publishing the information, the execution process includes: using the national cryptography SM3 hash algorithm to perform hash processing on the information to be published in the signature data to obtain a second hash value; verifying the signature value in the signature result according to the stored public key and the second hash value; comparing the second hash value with the first hash value to judge, and judging whether the calculated result value obtained by the signature verification is equal to the signature value; if the second hash value is the same as the first hash value, and the calculated result value obtained by the signature verification is the same as the signature value, the signature verification is successful and the information is published; if the second hash value is different from the first hash value or the calculated result value obtained by the signature verification is different from the signature value, the signature verification fails.
[0065] Specifically, first, it is necessary to verify whether the signature values r and s are within the valid value range, that is, whether they satisfy the range of r, s ∈ [1, n - 1]. If r and s are not within this range, the signature verification fails. If satisfied, the subsequent verification steps are continued. The national cryptography SM3 hashing algorithm is used to re-hash the message to be published, and the second hash value e' of the message to be published is calculated: e' = SM3(M). The second hash value e' is compared with the first hash value e. If the two are the same, the subsequent verification operations are continued; if not, the signature verification fails. The signature is verified using the stored public key P and the second hash value e', and the specific calculation process is as follows:
[0066] Calculate the intermediate value t according to the following formula (6):
[0067] t = (r + s) mod n; Formula (6)
[0068] If t = 0, the signature verification fails.
[0069] According to the signature value s and the intermediate value t, calculate the point on the elliptic curve:
[0070] (x1, y1) = sG + tP; Formula (7)
[0071] Verify the signature value r according to the second hash value, and calculate R according to formula (8):
[0072] R = (e' + x1) mod n; Formula (8)
[0073] Verify whether R is equal to the signature value r according to the R calculated by formula (8). If R = r, the signature verification passes; otherwise, the verification fails.
[0074] In some specific embodiments, as Figure 4 shown, the controller, as the signature verification end, based on the information publishing process of 2FA verification login and national cryptography algorithm SM2 is as follows: In the initialization stage, a key pair (private key and public key) is generated using a key generator, such as the SM2 key generation (sm2keygen) command of the GmSSL library, and the generated private key and public key are securely stored in the database. The user verifies and logs in based on 2FA. If the identity authentication information passes, the information to be published is obtained from the database, and the private key generated is used to sign the information to be published through the SM2 signature (sm2sign) command of the GmSSL library to obtain the information to be published embedded with the signature result. The controller calls the SM2 signature verification (sm2verify) command of the GmSSL library to verify the signature data. If the signature verification is successful, the information publishing end, such as the player, is controlled to play the information to be published, such as the program.
[0075] To adapt to the playback environments of different systems, signature verification logic is integrated into Linux players and Windows players. At the same time, the controller supports flexible modification of signature verification methods to meet different security requirements. The update and management of public keys are also more convenient to ensure the security of the system.
[0076] Specifically, in the Linux player, the controller can verify or not verify the program with the signature result, but the controller signature verification is enabled by default. If the verification passes through the controller, the controller will control the player to play the program. The specific method to modify the controller signature verification in the Linux system is as follows: First, enter the controller configuration (config) directory by entering the command: cdxstudiopro / config; then configure the net_xstudio_enable_sign_verify parameter in the net_plugin.xstudio.conf file: sudo vi m net_plugin_xstudio.conf [0: verification; 1: non-verification]; then restart the controller: sudo reboot, and the modification of the controller signature verification can be completed. The specific method to modify the public key in the offline state of the controller in the Linux system is as follows: Enter the other directory of the controller through the remote tool ssh: cdxstudio / config / other; place the correct public key into the sm2pub.pem file: sudo vim sm2pub.pem; restart the controller: sudo reboot.
[0077] In the Windows player, the controller can verify or not verify the program with the signature result, but the controller signature verification is enabled by default. If the verification passes through the controller, the controller will control the player to play the program. The specific method to modify the public key in the offline state of the controller in the Windows system is as follows: Place the public key file (pubkey.txt) downloaded from the platform side into the same directory as start.bat; then click to run the script file: checkpem.bat.
[0078] In some other specific embodiments, such as Figure 5As shown, the server acts as the signature verification end, and the GmSSL library is installed on the server. The information publishing process based on 2FA verification login and the national cryptographic algorithm SM2 is as follows: In the initialization stage, the server uses the SM2 key generation (sm2keygen) command of the GmSSL library to generate a key pair (private key and public key), and securely stores the generated private key and public key in the database. The user verifies and logs in based on 2FA. If the identity authentication information passes, the information to be published is retrieved from the database, and the retrieved information to be published is signed using the generated private key through the SM2 signature (sm2sign) command of the GmSSL library to obtain the information to be published embedded with the signature result. The server uses the SM2 signature verification (sm2verify) command of the GmSSL library to verify the signature data through the public key. If the signature verification is successful, the information to be published after successful signature verification, such as a program, is transmitted to the control information publishing end, such as a player, for playback, ensuring that the transmitted program has not been tampered with and ensuring the authenticity and integrity of the program played by the player.
[0079] Exemplarily, on the enterprise internal information publishing platform, the administrator logs in to the system to publish important internal information. To ensure the legality of the administrator's identity and the security and authenticity of the published information, the following security measures are adopted: When the administrator logs in to the system or triggers an operation in the system that requires two-factor verification, not only does the administrator need to enter the account password, but also needs to scan the QR code through the Authenticator application on the mobile phone to obtain the dynamic verification code for two-factor verification. This ensures that only legitimate administrators can access the system and prevents unauthorized access. And before publishing the information, the system signs the published materials and programs using the private key, and the signed data is transmitted to the server together with the published content. The public key is used in the server to verify the received data to ensure the authenticity and integrity of the information, and any tampering will be detected and rejected. The two-factor authentication mechanism ensures from the source that only legitimate users can access the system and prevents the intrusion of illegal users, while the national cryptographic algorithm ensures the confidentiality of information during transmission and storage. The combination of the two constructs a multi-level security defense line.
[0080] Step S13: If it is determined that the identity authentication fails according to the identity authentication result information, a prompt message for failed authentication is returned.
[0081] Specifically, if the account password or identification code entered by the user is recognized incorrectly, it will cause the user's identity authentication to fail, and information such as incorrect account password or incorrect identification code will be prompted.
[0082] The information publishing method based on the two-factor authentication mechanism and the national cryptography algorithm SM2 of the present application combines the dual protection of the two-factor authentication mechanism and the national cryptography algorithm SM2 to build a multi-level security defense line. The two-factor authentication mechanism prevents the intrusion of illegal users, while the national cryptography algorithm SM2 ensures the confidentiality of the information to be published during transmission and storage. Even if the information is intercepted, it cannot be cracked or tampered with, thus effectively preventing the risk of information leakage and providing higher security protection for users. Specifically: By adopting the two-factor authentication mechanism, the identity verification is strengthened. When logging in, the user not only needs to enter the account password but also needs to pass the dynamic verification code for secondary verification. This dual verification method greatly improves the access security of the platform system, ensuring that only users who have passed strict identity verification can enter the platform system and effectively preventing unauthorized access, protecting the security of sensitive information from the source. At the same time, the national cryptography algorithm SM2 is introduced to digitally sign and encrypt the published information. The digital signature technology ensures the authenticity and integrity of the information, and any tampering with the data will be detected and rejected by the system. At the same time, the high-strength encryption ability of the SM2 algorithm guarantees the security of the information to be published during transmission and storage, preventing the data from being maliciously tampered with or forged and ensuring the authenticity and reliability of the information.
[0083] Figure 6 It is a schematic block diagram of an information publishing system based on a two-factor authentication mechanism and a national cryptography algorithm provided by an embodiment of the present application. As Figure 6 shown, the information publishing system 600 based on the two-factor authentication mechanism and the national cryptography algorithm includes:
[0084] A two-factor authentication module 601, configured to authenticate the user identity based on a pre-configured two-factor authentication mechanism in response to a user login request, and return identity authentication result information;
[0085] An information signature verification module 602, configured to, if it is determined that the identity authentication is successful according to the identity authentication result information, obtain the information to be published, sign the information to be published based on the national cryptography algorithm SM2 to generate signature data, and verify the signature data, and perform information publishing after the signature verification is successful;
[0086] A prompt information module 603, configured to return prompt information for failed authentication if it is determined that the identity authentication fails according to the identity authentication result information.
[0087] To improve the security and reliability of information publishing, prevent unauthorized access and tampering, and ensure the authenticity and integrity of information, this application provides an information publishing system 600 based on a two-factor authentication mechanism and national cryptography algorithms. The aim is to enhance the security and reliability of the information publishing system through multiple security measures, that is, through a technical solution combining the two-factor authentication mechanism and the national cryptography algorithm SM2 to resist external attacks, build a secure and reliable information publishing environment, and meet the country's requirements for information security independence and controllability. Specifically: Through the two-factor authentication mechanism, it is ensured that only users who have passed strict identity verification can access the system, effectively preventing unauthorized access; at the same time, the system 600 uses the national cryptography algorithm SM2 to digitally sign and encrypt the published information to ensure the authenticity and integrity of the information and prevent the information from being tampered with or forged during transmission and storage.
[0088] It should be understood that the specific processes of each module executing the corresponding steps have been described in detail in the above method embodiments. For the sake of brevity, they will not be repeated here.
[0089] It should also be understood that the division of modules in the embodiments of this application is illustrative, merely a logical function division. In actual implementation, there may be other division methods. Additionally, in each embodiment of this application, each functional module may be integrated in a processor, or may exist separately physically, or two or more modules may be integrated in one module. The above integrated modules may be implemented in the form of hardware or in the form of software functional modules.
[0090] Figure 7 is a schematic block diagram of an electronic terminal provided by an embodiment of this application. As Figure 7 shown, the electronic terminal 700 includes: at least one processor 701, a memory 702, at least one network interface 703, and a user interface 705. Each component in the electronic terminal 700 is coupled together through a bus system 704. It can be understood that the bus system 704 is used to realize the connection and communication between these components. The bus system 704 includes, in addition to the data bus, a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 7 all kinds of buses are labeled as the bus system.
[0091] Among them, the user interface 705 may include a display, a keyboard, a mouse, a trackball, a click gun, a key, a button, a touchpad, or a touch screen, etc.
[0092] It can be understood that the memory 702 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM, Static Random Access Memory), synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory). The memory described in the embodiments of the present invention is intended to include but not be limited to these and any other suitable categories of memories.
[0093] The memory 702 in the embodiments of the present invention is used to store various categories of data to support the operation of the electronic terminal 700. Examples of these data include: any executable programs for operating on the electronic terminal 700, such as the operating system 7021 and application programs 7022; the operating system 7021 contains various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application programs 7022 can include various application programs, such as a media player (Media Player), a browser (Browser), etc., for implementing various application services. The information publishing method provided by the embodiments of the present invention based on the two-factor authentication mechanism and the national cryptography algorithm can be included in the application program 7022.
[0094] The method disclosed in the above embodiments of the present invention can be applied to the processor 701 or implemented by the processor 701. The processor 701 may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above method can be completed by the integrated logic circuit in the hardware of the processor 701 or by instructions in software form. The above-mentioned processor 701 can be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 401 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor 701 can be a microprocessor or any conventional processor, etc. Combining the steps of the accessory optimization method provided by the embodiments of the present invention can be directly embodied as being completed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, and this storage medium is located in the memory. The processor reads the information in the memory and combines its hardware to complete the steps of the foregoing method.
[0095] In an exemplary embodiment, the electronic terminal 700 may be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), or complex programmable logic devices (CPLDs) for performing the foregoing method.
[0096] According to the method provided by the embodiments of the present application, the present application further provides a computer program product, which includes computer program code that, when running on a computer, causes the computer to execute Figures 1 to 5 the method of any one of the illustrated embodiments.
[0097] According to the method provided by the embodiments of the present application, the present application further provides a computer-readable storage medium storing program code that, when running on a computer, causes the computer to execute Figures 1 to 5 the method of any one of the illustrated embodiments.
[0098] The terms "component", "module", "system", etc. used in this specification are used to denote computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component may be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and the computing device can be components. One or more components may reside in a process and / or execution thread, and a component may be located on one computer and / or distributed between two or more computers. In addition, these components may execute from various computer-readable media storing various data structures. A component may communicate, for example, through local and / or remote processes according to signals having one or more data packets (e.g., data from two components interacting with another component in a local system, a distributed system, and / or a network, such as data interacting with other systems through signals via the Internet).
[0099] Those of ordinary skill in the art will appreciate that the various illustrative logical blocks and steps described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans may use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0100] Those skilled in the art can clearly understand that for the sake of convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0101] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in an electrical, mechanical, or other form.
[0102] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0103] In addition, the functional units in the various embodiments of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0104] In the above embodiments, the functions of the respective functional units can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., high-density digital video disc (DVD)), or a semiconductor medium (e.g., solid state disk (SSD), etc.).
[0105] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present application. The foregoing storage medium includes: USB flash drive, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disc, etc., which can store program codes of various kinds.
[0106] As described above, the above are only the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0107] In summary, in view of the various security threats such as unauthorized access, data tampering, and information leakage faced in the current information publishing process, the present invention provides an information publishing method, system, medium, terminal, and program product based on a two-factor authentication mechanism and a national cryptographic algorithm. By verifying the identity information of logged-in users based on a pre-set two-factor authentication mechanism, the identity information verification is strengthened. When logging in, users not only need to enter their account passwords but also need to pass a dynamic verification code for secondary verification. This dual-verification method significantly improves the access security of the platform system, ensuring that only users who have passed strict identity verification can enter the platform, effectively preventing unauthorized access, and protecting the security of sensitive information from the source. And after the identity authentication result information is verified successfully, the information to be published is signed based on the national cryptographic algorithm SM2, and the signature data is verified. After the verification is successful, the information is published. This digital signature technology ensures the authenticity and integrity of the information. Any tampering with the data will be detected and rejected. At the same time, the high-strength encryption ability of the national cryptographic algorithm SM2 guarantees the security of the information to be published during transmission and storage, preventing the data from being maliciously tampered with or forged, and ensuring the authenticity and credibility of the information. The present application combines the two-factor authentication mechanism and the national cryptographic algorithm SM2 to form a dual protection mechanism, which not only enhances the security of identity authentication but also ensures the confidentiality of data transmission and storage. From identity authentication to data transmission, the entire link uses high-strength encryption protection, improving the overall security of the information publishing process. The two-factor authentication mechanism and the national cryptographic algorithm significantly improve the security and compliance of the system through multiple authentication and self-controlled encryption technology, while optimizing the user experience and being applicable to various scenarios with high security requirements. Therefore, the present application effectively overcomes various drawbacks in the prior art and has high industrial utilization value.
[0108] The above embodiments are only illustrative of the principles and effects of the present application and are not used to limit the present application. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by those with ordinary knowledge in the technical field without departing from the spirit and technical idea disclosed by the present application should still be covered by the claims of the present application.
Claims
1. An information publishing method based on a two-factor authentication mechanism and a national cryptography algorithm, characterized in that, Including: In response to a user login request, authenticate the user's identity based on a pre-configured two-factor authentication mechanism and return identity authentication result information; If it is determined to be successful in identity authentication according to the identity authentication result information, obtain the information to be published, sign the information to be published based on the national cryptography algorithm SM2 to generate signature data, and verify the signature data until the signature verification is successful before publishing the information; If it is determined to be a failed authentication according to the identity authentication result information, return a prompt message for failed authentication.
2. The information publishing method based on the two-factor authentication mechanism and the national cryptographic algorithm according to claim 1, characterized in that The step of, in response to a user login request, authenticating the user's identity based on a pre-configured two-factor authentication mechanism and returning identity authentication result information, its execution process includes: Perform a configuration operation on the two-factor authentication mechanism according to the received user login request and return a configuration completion result information; Detect whether the function module of the two-factor authentication mechanism is turned on; If the function module of the two-factor authentication mechanism is turned on, make the function module of the two-factor authentication mechanism generate an identification code; in response to the user's recognition operation of the identification code, generate and provide a dynamic verification code; based on the input account password and the dynamic verification code, return the corresponding identity authentication result information; If the function module of the two-factor authentication mechanism is not turned on, do not enable the two-factor authentication mechanism.
3. The information publishing method based on the two-factor authentication mechanism and the national cryptographic algorithm according to claim 1, wherein The step of signing the information to be published based on the national cryptography algorithm SM2 to generate signature data, its execution process includes: Generate a private key and a public key based on a key generator and store the generated private key and public key; Use the national cryptography SM3 hashing algorithm to perform hashing on the information to be published to obtain a first hash value; Sign the information to be published according to the stored private key and the first hash value to obtain a signature result; Embed the signature result into the information to be published and then package it to form signature data and store the signature data.
4. The information publishing method based on the two-factor authentication mechanism and the national cryptographic algorithm according to claim 3, wherein The step of verifying the signature data until the signature verification is successful before publishing the information, its execution process includes: Use the national cryptography SM3 hashing algorithm to perform hashing on the information to be published in the signature data to obtain a second hash value; Verify the signature value in the signature result according to the stored public key and the second hash value; Compare and judge the second hash value and the first hash value, and judge whether the calculated result value obtained from the signature verification is equal to the signature value; If the second hash value and the first hash value are the same, and the calculated result value obtained from the signature verification is the same as the signature value, then the signature verification is successful and the information is published; if the second hash value and the first hash value are different or the calculated result value obtained from the signature verification is different from the signature value, then the signature verification fails.
5. The information publishing method based on the two-factor authentication mechanism and the national cryptographic algorithm according to claim 3, wherein Perform hashing on the generated private key and public key based on the key generator using the SHA-256 hashing function to obtain a private key hash value and a public key hash value respectively and store them.
6. The information publishing method based on a two-factor authentication mechanism and a national cryptographic algorithm according to claim 3, wherein After generating the private key and public key based on the key generator and storing the generated private key and public key, it further includes: verifying the validity of the stored private key and public key.
7. An information publishing system based on a two-factor authentication mechanism and a national cryptographic algorithm, characterized in that, Including: A two-factor authentication module, configured to authenticate a user's identity based on a pre-configured two-factor authentication mechanism in response to a user login request, and return identity authentication result information; An information signature verification module, configured to, if it is determined that the identity authentication is successful according to the identity authentication result information, obtain information to be published, generate signature data by signing the information to be published based on the national cryptography algorithm SM2, and verify the signature data, and perform information publishing after the signature verification is successful; A prompt information module, configured to return prompt information for failed authentication if it is determined that the identity authentication is failed according to the identity authentication result information.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 6.
9. A computer program product, characterized in that, The computer program product includes computer program code, and when the computer program code runs on a computer, the computer is caused to implement the method according to any one of claims 1 to 6.
10. An electronic terminal, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, The processor executes the computer program to implement the method according to any one of claims 1 to 6.
Citation Information
Cited By
Identity remote authentication and security protection method of aircraft, identity remote authentication device and storage medium
CN121173481A