Login verification method and system based on dynamic password
Through the method of generating dynamic passwords and verifying data through smart card applications, the security and offline authentication of username and password login in the prior art are solved, and secure authentication and high success rate login verification are realized under network-free conditions.
Patent Information
- Application Number
- CN202510835850.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-20
AI Technical Summary
In the prior art, the username and password login method has security problems, the SMS verification code is severely delayed and cannot be used offline, the QR code login depends on the network and has many environmental restrictions, and the existing offline authentication cannot verify the user's identity in real time and cannot update the security policy in time.
The login verification method based on dynamic password is adopted to generate offline authentication and online authentication passwords through smart card applications, and dynamic passwords are generated using hash value conversion and encryption calculations, and data verification is carried out through the operator's server, supporting offline authentication and improving verification success rate.
It realizes security authentication while no network conditions, improves the success rate and security level of login verification, optimizes the one-time password generation method, and enhances the transmission security and cracking difficulty of the system.
Smart Images

Figure CN120342793A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and provides a login verification method and system based on dynamic passwords, which can be used for offline authentication login and online authentication login. Background Art
[0002] In existing solutions, there are problems with the security of user passwords in the existing username and password login method. Some websites store passwords in plain text, making it easy to encounter risk situations. In addition, weak user passwords are easily cracked. Users need to record passwords and modify them regularly. In addition, the existing SMS verification code login method has the following problems: the delay is relatively serious, and there is even a situation where the verification code cannot be received. Especially after multiple failures, there is a SMS frequency limit and it is impossible to send or receive SMS again, and it does not support offline authentication. In addition, the existing QR code login method has the following risks: 1) the risk of attacking malicious QR codes; 2) the risk of device permissions. QR code login usually depends on the permissions of the mobile phone camera, resulting in risks caused by device permissions; 3) there is a requirement for network connection. QR code login requires both the mobile phone and the target device to be connected to the network. If the network is interrupted (such as unstable public WiFi), the login process will fail; 4) there are environmental limitations: environmental factors such as insufficient light, blurred QR codes, and screen reflections result in a low success rate of QR code scanning; 5) it cannot be used offline. In scenarios where there is no mobile carrier signal or no cellular network at the terminal (such as remote areas), QR code login completely fails and other backup solutions are required. In addition, the existing one-click login method only supports login on the mobile phone side and requires mobile data to be enabled. In addition, the existing offline authentication method cannot verify the user's identity in real time and cannot update security policies in a timely manner.
[0003] Therefore, it is necessary to provide an improved authentication login method and system based on dynamic passwords to solve the above problems. Summary of the Invention
[0004] The present invention provides a login verification method and system based on dynamic passwords to solve the verification problem during online authentication in the prior art, support offline authentication, improve the verification success rate, and solve the deficiency of lacking convenient hardware device support during offline authentication. The technical problems to be solved by the present invention are realized through the following technical solutions.
[0005] A first aspect of the present invention proposes a login verification method based on dynamic passwords. The login verification method includes: when the front end of the service system receives a dynamic password acquisition request, the front end of the service system applies for the following authentication passwords to the smart card application according to the network status and security requirements: online authentication password, offline authentication password; the smart card application uses the selected password algorithm and parameter items to perform hash value conversion, encryption calculation, and intercept according to the intercept algorithm, and generates dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and returns the generated dynamic passwords to the current terminal application and the current user; after the current terminal application receives the dynamic password, it transmits the smart card serial number, the generated dynamic password, and related data to the server of the current terminal application, and then to the operator server; when the operator server receives a data verification request, it automatically identifies the authentication type, performs dynamic password calculation for data verification, and returns a data verification result to the server of the service system, where the authentication type includes offline authentication and online authentication.
[0006] A second aspect of the present invention proposes a login verification system based on dynamic passwords, which executes the login verification method based on dynamic passwords described in the first aspect of the present invention. The login verification system includes: a request processing module, which is used for when the front end of the service system receives a dynamic password acquisition request, the front end of the service system applies for the following authentication passwords to the smart card application according to the network status and security requirements: online authentication password, offline authentication password; a calculation processing module, which is used for the smart card application to use the selected password algorithm and parameter items to perform hash value conversion, encryption calculation, and intercept according to the intercept algorithm, and generate dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and return the generated dynamic passwords to the current terminal application and the current user; a data transmission module, which is used for after the current terminal application receives the dynamic password, it transmits the smart card serial number, the generated dynamic password, and related data to the server of the current terminal application, and then to the operator server; a data verification module, which is used for when the operator server receives a data verification request, it automatically identifies the authentication type, performs dynamic password calculation for data verification, and returns a data verification result to the server of the service system, where the authentication type includes offline authentication and online authentication.
[0007] A third aspect of the present invention provides an electronic device, including: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the login verification method based on dynamic passwords described in the first aspect of the present invention.
[0008] A fourth aspect of the present invention provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processor, the login verification method based on dynamic passwords described in the first aspect of the present invention is implemented.
[0009] The embodiments of the present invention include the following advantages: Compared with the prior art, in the present invention, when the front end of the service system receives a dynamic password acquisition request, the front end of the service system applies for the following authentication passwords from the smart card application according to the network status and security requirements: online authentication password, offline authentication password; the smart card application uses the selected password algorithm and parameter items to perform hash value conversion and encryption calculation, and intercepts according to the interception algorithm to generate dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and returns the generated dynamic passwords to the current terminal application and the current user; after the current terminal application receives the dynamic password, it transmits the smart card serial number, the generated dynamic password, and related data to the server of the current terminal application, and then transmits it to the operator server; when the operator server receives a data verification request, it automatically identifies the authentication type, performs dynamic password calculation for data verification, and returns a data verification result to the server end of the service system. Among them, the smart card and the operator server generate dynamic passwords according to the same algorithm and related parameters. The user fills in the parameters in the smart card application, and the smart card application transmits the parameters to the server of the smart card application, and then transmits them to the operator server through the server of the smart card application for data verification. The operator server can independently generate dynamic passwords for comparison and verification, and then complete data verification, and can realize offline authentication, thus effectively solving the problem that "one-key login" cannot be authenticated especially when there is no network provided by the operator.
[0010] In addition, the use of quantum keys improves the transmission security of system data and increases the difficulty of cracking.
[0011] In addition, the present invention can realize flexible verification methods and OTP generation methods, support offline authentication, as a supplement to the operator's "one-key login" solution, improve the verification success rate, the login verification method of the present invention can improve the security level and optimize the method of generating one-time passwords. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 is a step flowchart of an example of the login verification method based on dynamic passwords of the present invention; Figure 2 is a schematic flowchart of the login verification method based on dynamic passwords of the present invention from another perspective; Figure 3 is a partial flowchart of online authentication in the login verification method based on dynamic passwords of the present invention; Figure 4It is a structural block diagram of the login verification system based on dynamic password of the present invention; Figure 5 It is a schematic structural diagram of an electronic device according to an embodiment of the present invention; Figure 6 It is a schematic structural diagram of a computer-readable medium according to an embodiment of the present invention. Detailed implementation manners
[0013] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the drawings and in combination with the embodiments.
[0014] In view of the above problems, the present invention proposes a login verification method based on dynamic password. In this method, when the front end of the service system receives a dynamic password acquisition request, the front end of the service system applies for the following authentication passwords from the smart card application according to the network status and security requirements: online authentication password, offline authentication password; the smart card application uses the selected password algorithm and parameter items to perform hash value conversion and encryption calculation, and intercepts according to the interception algorithm to generate dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and returns the generated dynamic passwords to the current terminal application and the current user; after the current terminal application receives the dynamic password, it transmits the smart card serial number, the generated dynamic password, and related data to the server of the current terminal application, and then transmits it to the operator server; when the operator server receives a data verification request, it automatically identifies the authentication type, performs dynamic password calculation for data verification, and returns a data verification result to the server of the service system. Among them, the smart card and the operator server generate dynamic passwords according to the same algorithm and related parameters. The user fills in the parameters in the smart card application, and the smart card application transmits the parameters to the server of the smart card application, and then transmits them to the operator server through the server of the smart card application for data verification. The operator server can independently generate dynamic passwords for comparison and verification, and then complete the data verification, which can realize offline authentication, and effectively solve the problem that "one-key login" cannot be authenticated especially when there is no network provided by the operator.
[0015] Embodiment 1 The following will refer to Figure 1 , Figure 2 , Figure 3 , and will describe the content of the present invention in detail.
[0016] Figure 1 It is a step flowchart of an example of the login verification method based on dynamic password of the present invention. Figure 2 It is a schematic flowchart of a specific application example of the login verification method based on dynamic password of the present invention.
[0017] Reference Figure 1 and Figure 2 In step S101, when the front end of the service system receives a current dynamic password acquisition request, the front end of the service system applies for the following authentication passwords to the smart card application according to the network status and security requirements: online authentication password, offline authentication password.
[0018] Specifically, the front end of the service system includes but is not limited to a smart card application and a terminal application (such as an application in a mobile phone or a tablet), a smart terminal operating system, and a smart card operating system. The online authentication and offline authentication respectively correspond to the online authentication password and the offline authentication password.
[0019] Furthermore, the front end of the service system also includes a smart card system, etc. In addition, it also includes a backend corresponding to the front end of the service system. The backend of the service system includes a server of the terminal application and an operator server (i.e., the server corresponding to the operator service end), etc.
[0020] In Figure 2 example, it includes a user, a smart card application, a terminal application (or the terminal application of the service system, such as a user interface), a server of the terminal application (i.e., the server corresponding to the service end of the terminal application), an operator server (i.e., the server corresponding to the operator service end, i.e., the operator server), where the smart card installs, for example, a one-time password applet (i.e., OTP Applet) or other service applications. The one-time password applet is used to store quantum keys, store algorithm configurations, and perform data operations.
[0021] It should be noted that in the present invention, the smart card refers to a SIM card, a Subscriber Identity Module, specifically including but not limited to forms such as SIM cards, eSIMs, NanoSIMs, etc. It has the ability to access the network for calls and the ability to process over-the-air data messages through OTA.
[0022] Specifically, the smart card includes four layers of modules: a hardware layer, a COS layer, a capability support layer, and an application layer. In the hardware layer, there are SIM card physical layer access interfaces, IO, CPU, memory, algorithm units, etc. In the COS layer, there are SIM card memory management, application management, various security mechanisms, over-the-air SMS transmission protocol control, etc. The capability support layer is used to define various API interfaces supported for the application layer to call, etc. The application layer is used to carry various applications, including various industry applications (such as public transportation, finance, etc.). The smart card application is an application program developed to complete specific functions and run on the smart card, such as a one-time password applet.
[0023] Smart card applications and network operator servers distribute keys through the quantum key distribution system, such as injecting D group of symmetric keys, for example, D is 20000, and a key occupies 20 bytes of space, specifically including a 3-byte index, 1-byte status, and 16-byte key data.
[0024] In a specific implementation, the smart card presets a set of asymmetric keys, specifically a first public key (e.g., SimSM2pub) and a first private key (e.g., SimSM2pri). The operator server presets a set of asymmetric keys, specifically a second public key (e.g., MNOSM2pub) and a second private key (e.g., MNOSM2pri). The operator server and the smart card each know the other's public key (e.g., SimSM2pub, MNOSM2pub).
[0025] Preferably, the smart card and the OTP Applet are configured with parameters in the same manner, specifically including configuring a cryptographic algorithm identifier, a hash algorithm identifier, a signature algorithm identifier, an interception algorithm identifier, and optional items and default items of each algorithm.
[0026] In a specific implementation, a user browses a web page on a PC or mobile phone, and requests to log in to a website or system (corresponding to Figure 2 "1. User requests a dynamic password", after the user's security verification (corresponding to Figure 2 After security verification, obtain the user input parameters, current timestamp, and determine the security level parameters"), enter the dynamic password acquisition process (i.e., one-time password acquisition process), that is, the user initiates a current dynamic password acquisition request to the terminal application (corresponding to Figure 2 In "3. Initiate a dynamic password acquisition request"), when the terminal application receives the current dynamic password acquisition request, it applies to the smart card application (specifically the one-time password applet) for the following authentication passwords based on the network status and security requirements: online authentication password, offline authentication password.
[0027] The user security verification refers to, for example, biometric security verification of smart terminals, password security verification of smart applications, user password security verification of smart card applications, etc., specifically including fingerprint verification or first-level PIN password verification.
[0028] Specifically, when the front end of the service system receives a request to obtain a dynamic password, the terminal application can determine whether it is an online authentication or an offline authentication based on the network status and security requirements. Therefore, it can determine whether it is an online authentication password or an offline authentication password corresponding to the online authentication or offline authentication. The terminal application can interact with the smart card application for data and commands through the machine-card protocol. The smart card application can be regarded as the front end of the operator server. The operator server can send data to the smart card (including the smart card serial number corresponding to the mobile phone number, operation data, etc.). Each smart card corresponds to a mobile phone number, that is, each mobile phone number corresponds to a unique smart card serial number. The smart card application can interact with the smart card and obtain the smart card serial number corresponding to the smart card. Alternatively, existing data can also be obtained, such as the number of logins, login time, data verification time, etc.
[0029] It should be noted that in some embodiments of the present invention, the user applies to the operator for a one-time password service, that is, to activate the service. After the operator verifies the user's identity, the one-time password service is activated. The operator updates the smart card application to the smart card of the user's smart terminal through the air OTA server. At both ends of the operator and the smart card application, the default initial value of the counter is 0. The smart card application supports the following hash algorithm, cryptographic algorithm, asymmetric algorithm, interception algorithm, and one-time password generation method. The operator updates the one-time password service through the air OTA server to synchronize the updated offline parameters and online parameters to the smart card application, and the operator's service end (i.e., the operator server) also saves the above-mentioned data that is updated synchronously. In addition, the online authentication password and the offline authentication password correspond to the online authentication process and the offline authentication process, wherein the offline authentication process specifically refers to authentication not within the network range provided by the operator, such as authentication through wireless local area networks, hotspots, and other network methods. In the offline authentication process, there is no need for direct interaction between the smart card application and the terminal application (corresponding to the service system) and the operator. The above is explained as an optional example and cannot be understood as a limitation of the present invention.
[0030] Next, in step S102, the smart card application uses the selected cryptographic algorithm and parameter items to perform hash value conversion and encryption calculation, intercepts according to the interception algorithm, and generates dynamic passwords corresponding to online authentication and offline authentication in different ways.
[0031] When the authentication password applied is an offline authentication password, the terminal application initiates an offline authentication password request to the smart card application. The smart card application uses the cryptographic algorithm and parameter items selected based on the counter (see Table 1 below for details) to perform hash value conversion and encryption calculation, and then intercepts it according to the interception algorithm to generate a dynamic password, and returns the generated dynamic password to the current terminal application and the current user.
[0032] Table 1
[0033] It should be noted that in this example, the terminal application refers to an application in a terminal device such as a mobile phone or a tablet. The parameter items in Table 1 can be extensions for different terminal applications and use default values. At the same time, it also supports being divided into multiple configuration parameters according to the application direction, such as financial category and general verification code category.
[0034] For the case where the operator does not provide a network, the smart card application can determine that the applied authentication password is an offline authentication password and obtain a dynamic password through a non-direct interaction method with the operator. The smart card application is, for example, a short video application, a certain bank application, etc.
[0035] It should be noted that in this example, a set of asymmetric keys generated by the smart card application is the same as a set of asymmetric keys of the smart card, specifically the first public key (such as SimSM2pub) and the first private key (such as SimSM2pri). The first public key is uploaded to the operator server. The operator and the terminal smart application (such as a short video application, a certain bank application) have signed a verification service agreement. The above is only described as an optional example and should not be construed as a limitation to the present invention.
[0036] In a specific embodiment, for event-based OTP offline authentication (i.e., HOTP), offline parameters are generated according to the counter value (specifically the current value of the counter) and the polling key, and after further multi-step progressive calculations, a dynamic password, that is, a one-time password or an OTP password, is obtained.
[0037] In this example, the event specifically includes an event of the counter increment process related to the authentication process.
[0038] For example, "event" generally refers to the "increment of the counter value" or "operation times of the counter" triggered when the user performs identity authentication. The generation of the dynamic password depends on the event of the increment of the counter value and is synchronized with the counter value, that is, the user and the authentication server share a counter value. After each successful authentication, the counter value increments (i.e., the current value increases by one), ensuring that each dynamic password is only used for verification once.
[0039] For multiple dynamically polled password algorithms, determine the password algorithm to be used. For example, the parameter corresponding to the password algorithm is 0x05. Since hexadecimal 0x05 is equal to binary 00000101, which has 2 bits that are 1, the number of password algorithms is 2, that is, F in the following expression (1) is 2.
[0040] Specifically, the following expression is adopted. The remainder obtained by dividing the current value of the counter by the number of enabled cryptographic algorithms is used to determine the cryptographic algorithm to be used. The parameter corresponding to the cryptographic algorithm is 0x05.
[0041] Y = counter / F (1) Where Y represents the remainder obtained by dividing the current value of the counter by the number of enabled cryptographic algorithms, specifically 0 or 1; counter represents the current value of the counter; F represents the number of enabled cryptographic algorithms, which is two in this example, but is not limited to this. In other examples, it can also be three or more.
[0042] Specifically, the obtained remainder Y includes 0 and 1. For example, when the obtained remainder is 0, the polling position is determined to determine that the cryptographic algorithm to be used is SM4. For example, when the obtained remainder is 1, the cryptographic algorithm to be used is 3DES.
[0043] In a specific embodiment, for the cryptographic algorithm, the specific algorithm name, default configuration, and optional configuration can be referred to Table 2 below. For example, configure the encryption / decryption algorithm identifier (i.e., algorithm name), the default configuration is 0x07, and the optional configuration is 0x01, etc.
[0044] Table 2
[0045] Table 2 is a table showing an example of the cryptographic algorithm.
[0046] For example, Encrypt and Decrypt are used to represent the encryption algorithm and decryption algorithm in the cryptographic algorithm.
[0047] Specifically, if the parameter is 0x05, the algorithms to be enabled are 3DES algorithm and SM4 algorithm. Specifically, the current count value of the counter is divided by the remainder (the number of enabled is 2) to obtain 0 or 1 to further determine the algorithm to be enabled. When the remainder is 0, it corresponds to SM4 on the far right in Table 2, and when the remainder is 1, it corresponds to 3DES in Table 2.
[0048] For example, configure the hash algorithm identifier (specifically refer to Table 3 below), that is, the algorithm name, the default configuration bit is 0x07, and the optional configuration is 0x01, etc.
[0049] Table 3
[0050] Table 3 is a table showing an example of the hash algorithm.
[0051] For example, HASH is used to represent the hash algorithm.
[0052] Specifically, if the parameter is 0x07, the algorithms to be enabled are three algorithms. Specifically, the current count value of the counter is divided by the remainder of (the number of enabled algorithms is 3) to obtain 0, 1, or 2, so as to further determine the algorithm to be enabled. When the remainder is 0, it corresponds to SM3 on the far right in Table 3. When the remainder is 1, it corresponds to SHA256 in Table 3. When the remainder is 2, it corresponds to SHA384 in Table 3.
[0053] For the asymmetric signature algorithm, for example, configure the asymmetric signature algorithm identifier, that is, the algorithm name. The default configuration bit is 0x01, and the optional configuration is 0x07, etc.
[0054] Table 4
[0055] Table 4 is a table showing an example of the asymmetric signature algorithm.
[0056] For example, use SIGN to represent the asymmetric signature algorithm.
[0057] Specifically, if the parameter is 0x03, the algorithms to be enabled are RSASSA-PSS and SM2. Specifically, the current calculated value of the counter is divided by the remainder of (the number of algorithms to be enabled is 2) to obtain 0 or 1, so as to further determine the algorithm to be enabled. When the remainder is 0, it corresponds to SM2 on the far right in Table 4. When the remainder is 1, it corresponds to RSASSA-PSS in Table 4.
[0058] For the parameter identifier, specifically configure the parameter identifier (that is, the parameter name, specifically refer to Table 5 below), the default configuration bit is 0x03, and the optional configuration is 0x1F, etc.
[0059] Table 5
[0060] Table 5 is a table showing an example of the parameters participating in the operation.
[0061] It should be noted that on the smart card application side, the initial value of the counter is, for example, counter = 0x0000, and the maximum value is 0x7FFF. When the maximum value is reached, it needs to be reset, and after reset, it is 0x0000. Each time an operation is performed, the count value of the counter increases by one.
[0062] Select the key Id = (the remainder of counter divided by D) from the preset D-group keys. The D-group key IDs are 0, 1,..., D - 1. Specifically, select the authentication method according to the network status and the application-side request. Online authentication is preferred. When the network status is offline or the network signal is poor (specifically referring to situations where the network service provided by the operator is not available or the network signal provided by the operator is poor, such as through wireless local area network, hotspot, etc. network methods), offline authentication is selected.
[0063] Next, perform hash value conversion.
[0064] Specifically, if the parameter corresponding to the hash algorithm is 0x07, three hash algorithms can be enabled. Which algorithm to use specifically follows the same principle as expression (1), using the remainder obtained by dividing the current value of the counter (i.e., counter) by the number of enabled hash algorithms (for example, three). The obtained remainder is 0, 1, or 2. If the remainder is 0, it corresponds to SM3. If the obtained remainder is 1, it corresponds to SHA256. If the obtained remainder is 2, it corresponds to SHA384.
[0065] Adopt the hash algorithm determined according to the current value of the counter to calculate the hash value corresponding to the offline parameter PARA: dat1 = HASH(PARA 离线 )
[0066] Among them, dat1 represents the hash value calculated by using the hash algorithm HASH determined according to the current value of the counter, corresponding to PARA 离线 ; PARA 离线 represents the offline parameter generated by the current dynamic password acquisition request. Among them, PARA 离线 = ICCID + Counter, ICCID represents the serial number of the smart card corresponding to the current dynamic password acquisition request, and Counter represents the current value of the counter.
[0067] For example, PARA 离线 = ICCID + Counter = 8986012281100043644F + 0000 dat1 = HASH(PARA 离线 ) = SM3(8986012281100043644F0000) = FBCB4703D068FE9853F45AE824AC458396259E83DA114D967AD31EAB50CD375F.
[0068] For the determination of the signature algorithm, if the parameter corresponding to the signature algorithm is 0x03, RSASSA-PSS and SM2 can be enabled. Specifically, use the remainder obtained by dividing counter by the number of enabled signature algorithms. The obtained remainder is 0 or 1. Determine the specific algorithm according to the obtained remainder. For example, if the obtained remainder is 0, the corresponding signature algorithm is SM2. If the obtained remainder is 1, the corresponding signature algorithm is RSASSA-PSS.
[0069] In the first embodiment, when the applied authentication password is an offline authentication password, offline parameters are generated. The offline parameters include the smart card serial number and the current value of the counter. For example, PARA 离线 = ICCID + counter, where PARA 离线 represents the offline parameters corresponding to the current dynamic password acquisition request, ICCID represents the smart card serial number of the smart card corresponding to the current dynamic password acquisition request; counter represents the current value of the counter corresponding to the current dynamic password acquisition request.
[0070] For example, combining all parameter items gives the following offline parameter table: 070701040000010103000000, a total of 12 bytes. For information on parameter items, default values, and current values of relevant algorithms for generating offline parameters, see Table 1 above.
[0071] The smart card application selects a password algorithm Encrypt based on the counter and relevant parameters (such as the polling position parameter), and then selects a quantum secret key based on the current value of the counter for calculation to obtain an encryption result: dat2 = Encrypt(key 离线 , dat1) where dat2 represents the encryption result obtained by encrypting the calculated hash value using the selected password algorithm Encrypt and the quantum secret key selected according to the current value of the counter. The encryption calculation refers to encrypting using the quantum secret key selected according to the current value of the counter in offline authentication; key 离线 represents the quantum secret key selected according to the current value of the counter in offline authentication; dat1 represents the hash value calculated using the hash algorithm HASH determined according to the current value of the counter and corresponding to PARA 离线 ; PARA 离线 represents the offline parameters generated for the current dynamic password acquisition request.
[0072] According to the determined truncation algorithm (such as CUT), a decimal OTP password is intercepted. OTP = CUT(dat2).
[0073] The following expression is used to calculate the dynamic password, i.e., the one-time password (or OTP password): OTP 离线 = CUT(Encrypt(key 离线 , HASH(PARA 离线 ))) where OTP 离线Represents the one-time password corresponding to the currently applied authentication password; CUT() represents a truncation algorithm for truncating the data after encryption calculation to obtain the one-time password corresponding to the currently applied authentication password, specifically truncating a specified number of byte data at a specified position, where the specified position includes the byte position range from the first bit to the nth bit, and the specified number includes 4 bytes to 8 bytes, etc.; Encrypt() represents encrypting the hash value obtained by calculating the hash value of the generated PARA 离线 The encryption calculation is performed on the hash value obtained by calculating the hash value of 离线 , and the encryption calculation refers to encrypting using the quantum key selected according to the current value of the counter in the offline authentication; key 离线 Represents the quantum key selected according to the current value of the counter in the offline authentication; HASH(PARA 离线 ) represents calculating the hash value corresponding to PARA 离线 using the hash algorithm HASH determined according to the current value of the counter, and PARA 离线 Represents the offline parameter generated by the current dynamic password acquisition request.
[0074] Through the above calculations, a one-time password of four to eight digits is obtained.
[0075] Specifically, a four-digit dynamic password, that is, a one-time password (i.e., OTP password or OTP 离线 ), for example, is the decimal number 3456.
[0076] Further, the generated dynamic password is returned to the current user.
[0077] For example, using the truncation algorithm on the data "FBCB4703D068FE9853F45AE824AC4583962 59E83DA114D967AD31EAB50CD375F", with the truncation algorithm position parameter being 0x00000101, the ninth and first data from the left are obtained, that is: 96 and 5F, and further 0x965F = 38495, and four digits are truncated starting from the end position, obtaining 8495.
[0078] For example, parameters for generating OTP data by truncating a specified number of bytes (such as 32 bytes) of data.
[0079] If the 32-byte data before calculation is "0xE9180E184894DAA58BD91E7CF3D76C "F399941C39C2E3679BCAB624CE233454F1". Respectively intercept the bytes at the corresponding positions of these 32 bits of 0x00000101. That is, convert 0x9BF1 to the decimal "39921". When there are empty positions in front of or behind the byte data, fill them with 0 or 1. For example, in the above data, after padding, a six-digit number is obtained, that is, "039921". Then intercept the last four digits to get the final result "9921".
[0080] For example, 0x00000101 can be adjusted to 0x00000103 to get 0x9B54F1, and intercept six digits from the end position forward, and convert it to the decimal number "179825".
[0081] In the second embodiment, when the applied authentication password is an online authentication password, the smart card application uses the selected password algorithm and parameter items to perform hash value conversion and encryption calculation, and then intercepts according to the interception algorithm to generate a dynamic password, and returns the generated dynamic password to the current terminal application and the current user.
[0082] When the applied authentication password is an online authentication password, the terminal application sends an online authentication password request to the smart card application, carrying timestamp information and user input parameters. The smart card application uses the selected password algorithm and other parameter items to perform hash value conversion and encryption calculation, and intercepts according to the interception algorithm to generate a dynamic password (corresponding to Figure 2 "4. Calculate the dynamic password" in it), and returns the calculated dynamic password to the terminal application (corresponding to Figure 2 "5. Return the calculated dynamic password" in it), and sign the data participating in the operation, and then encrypt the relevant data with the quantum key to generate packaged data. Transmit the smart card serial number, the generated dynamic password, and the encrypted packaged data to the server of the current terminal application (corresponding to Figure 2 "6. Upload relevant data and upload a data verification request" in it), and then transmit it to the operator server (corresponding to Figure 2 "7. Request data verification" in it). Then, the operator server of the operator server performs data verification (corresponding to Figure 2 "8. Perform data verification" in it), returns the data verification result to the server of the terminal application (corresponding to Figure 2 "9. Return the data verification result" in it), and then returns the data verification result to the terminal application (corresponding to Figure 2 "10. Return the data verification result" in it), and according to the data verification result, jump to the corresponding interface (corresponding to Figure 2 "11. According to the data verification result, jump to the corresponding interface" in it), and finally return the data verification result of the dynamic password to the user (corresponding to Figure 2in "12. Return the data verification result of the dynamic password").
[0083] Specifically, the online parameters (specifically, the data plaintext) and the data signature are packaged and transmitted to the server of the current terminal application after being encrypted with the quantum key.
[0084] Such as Figure 3 As shown, for online authentication (when the applied authentication password is an online authentication password), the following steps are specifically executed: Step S201: According to the terminal application, judge the current usage scenario, select the current user input as the user input parameter, and when the user input parameter is not received, use a random number as the user input parameter.
[0085] Step S202: The terminal application transmits the timestamp information and the user input parameter to the smart card application.
[0086] Step S203: The smart card application splices the smart card serial number ICCID, the counter, the randomly generated number by itself, the timestamp information, and the user input parameter to generate the online parameter corresponding to the current dynamic password acquisition request.
[0087] Step S204: Calculate the dynamic password, that is, the one-time password (or OTP password).
[0088] Step S205: Use the first private key of the smart card application to sign the online parameter to obtain the signature value (such as SignDat).
[0089] Step S206: Use the following expression to encrypt and calculate the online parameter and its signature value with the quantum key to obtain the OTP packaged data.
[0090] Step S207: Return the calculated dynamic password and the OTP packaged data to the user, where the generated OTP 在线 and the OTP packaged data are generated simultaneously in the smart card application.
[0091] In a specific embodiment, the following expression is used to generate the online parameter corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request in step S101 and the current value of its corresponding counter: PARA 在线 = ICCID + Counter + Random + Input + Timestamp where PARA 在线Denotes the online parameters corresponding to the current dynamic password acquisition request generated based on the current dynamic password acquisition request and the current value of its corresponding counter; ICCID denotes the smart card serial number of the smart card corresponding to the current dynamic password acquisition request; Counter denotes the current value of the counter corresponding to the current dynamic password acquisition request; Random denotes a random number randomly generated by the smart card itself, for example, a random number of 4 to 10 digits, including numbers, letters, symbols, etc.; Input denotes the input data of the current user; Timestamp denotes the current timestamp returned by the terminal application or service system of the smart card application to the smart card when the applied authentication password is the authentication password, that is, when the smart card application receives an online authentication password acquisition request (i.e., corresponding to an online authentication request), the current timestamp transmitted or returned by the terminal application or service system of the smart card application to the smart card (for example, represented by Unix seconds).
[0092] For example, combining all parameter items gives the following online parameter table: 07070104000001011F000000, a total of twelve bytes.
[0093] Specifically, for example, the smart card application can pop up a dialog box to request the current user to input parameters (i.e., input, for example, 4 to 8 digits and letters). When no user input data is entered, input is replaced with a specified number of 0s or 1s (for example, 0000).
[0094] For the generation of online parameters, the smart card application selects an asymmetric algorithm (such as SIGN) according to the current value of the counter (i.e., counter), and calculates the signature value of PARA using the first private key of the smart card application (such as SimSM2pri). 在线 For example, use SignDat to denote the signature value of PARA 在线 of the signature value.
[0095] The smart card application packs and encrypts the data. Specifically, it selects a password algorithm (such as Encrypt) according to the current value of the counter and relevant parameters (such as the polling position parameter), then selects a quantum secret key according to the current value of the counter, and uses the following expression to perform an encryption calculation on the online parameters and their signature values to obtain the OTP packed data.
[0096] OTP packed data = Encrypt(key 在线 , PARA 在线 + SignDat) Among them, the OTP packaged data represents the OTP packaged data obtained by selecting the password algorithm Encrypt according to the current value of the counter and relevant parameters (such as the polling position parameter), then selecting the quantum secret key according to the current value of the counter, and performing encryption calculation on the online parameters and their signature values; PARA 在线 represents generating the online parameters corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request and the current value of its corresponding counter; SignDat represents the signature value of PARA 在线 calculated using the first private key (such as SimSM2pri) of the smart card application; key 在线 represents the quantum secret key selected according to the current value of the counter in online authentication.
[0097] For the applied authentication password being the online authentication password, it also includes generating a dynamic password, that is, a one-time password (or OTP password).
[0098] The smart card application selects the hash algorithm HASH according to the current value of the counter and relevant parameters (such as the polling position parameter), and calculates the hash value of PARA 在线 generated in step S201, specifically expressed as: dat1’ = HASH(PARA 在线 ) Among them, dat1’ represents the hash value calculated by selecting the hash algorithm HASH according to the current value of the counter and relevant parameters (such as the polling position parameter); PARA 在线 represents generating the online parameters corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request and the current value of its corresponding counter. 在线
[0099] Next, the smart card application selects the password algorithm Encrypt according to the current value of the counter and relevant parameters (such as the polling position parameter), and then selects the quantum secret key according to the current value of the counter (i.e., the current count value) to perform encryption calculation on the hash value of PARA 在线 : dat2’ = Encrypt(key 在线 , dat1’) Among them, dat2’ represents the encrypted data obtained by selecting the password algorithm according to the current value of the counter and relevant parameters (such as the polling position parameter), and then selecting the quantum secret key according to the current value of the counter to perform encryption calculation on the hash value of PARA 在线 ; Encrypt() represents selecting the password algorithm according to the current value of the counter and relevant parameters (such as the polling position parameter); key 在线 It represents selecting a quantum secret key according to the current value of the counter during online authentication; dat1’ represents selecting a hash algorithm HASH according to the current value of the counter and related parameters (such as polling position parameters), and calculating the hash value of PARA 在线 ; PARA 在线 represents generating online parameters corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request and the current value of its corresponding counter.
[0100] Next, the smart card application selects a truncation algorithm CUT according to the current value of the counter and related parameters (such as polling position parameters), and truncates to obtain a dynamic password, that is, a one-time password.
[0101] It is represented by the following expression: OTP 在线 = CUT(Encrypt(key 在线 ,HASH(PARA 在线 ))) where, OTP 在线 represents the one-time password corresponding to the authentication password currently applied for; CUT() represents a truncation algorithm for truncating the data after encryption calculation to obtain the one-time password corresponding to the authentication password currently applied for, specifically truncating a specified number of byte data at a specified position, the specified position includes the byte position range from the first bit to the nth bit, and the specified number includes 4 to 8 bytes, etc.; Encrypt() represents encrypting the hash value obtained by calculating the hash value of the generated PARA 在线 , key 在线 represents selecting a quantum secret key according to the current value of the counter during online authentication; HASH(PARA 离线 )represents calculating the hash value corresponding to PARA 在线 using the hash algorithm HASH determined according to the current value of the counter, PARA 在线 represents the online parameters generated by the current dynamic password acquisition request. In addition, this quantum secret key is also used when calculating the OTP packet data.
[0102] Specifically, the smart card application returns the generated OTP 在线 and the OTP packet data to the user, where the generated OTP 在线 and the OTP packet data are generated simultaneously in the smart card application.
[0103] It should be noted that the above is described as an optional example and should not be construed as a limitation to the present invention.
[0104] In the third embodiment, the smart card application selects each cryptographic algorithm using the current value of the counter, and determines the position parameters corresponding to each cryptographic algorithm through dynamic polling. Among them, the dynamic polling introduces a security level, and the security level includes offline verification codes, food delivery verification codes, office verification codes, financial verification codes, government affairs verification codes, items to be expanded, and their respective corresponding security levels.
[0105] Specifically, the offline verification code preferably uses the SM1 algorithm to improve security. For example, the SM1 algorithm exists in the chip of the smart card in the form of IP.
[0106] For the selection of algorithms corresponding to the security level, please refer to Table 6 below for details.
[0107] Table 6
[0108] Table 6 is a table showing examples of algorithms corresponding to the security level.
[0109] Table 7
[0110] Table 7 is a table showing an example of a summary of related algorithms.
[0111] For increasing the security level, the following expression is used to calculate the online parameter: PARA’ 在线 = ICCID + Counter + Random + Input + Timestamp + SecureLevel.
[0112] For the determination of the security level (i.e., SecureLevel), specifically judge whether to upgrade.
[0113] When the user input parameter (i.e., Input) is detected and the identifier corresponding to the security level is the first identifier (e.g., 00) or the second identifier (e.g., 01), the current security level remains unchanged.
[0114] When the user input parameter (i.e., Input) is detected and the identifier corresponding to the security level is greater than the second identifier (e.g., 01), a security check is performed on the user input. When it is determined to be a risky input, it is automatically upgraded, that is, the current security level is increased by one. Specifically, when the current security level increases to the maximum value (corresponding identifier 05), the corresponding security level is automatically determined. The security check includes whether the input length of the user input is greater than the specified number of digits, and whether the user input contains numbers, letters, and symbols. The specified number of digits is from five to eight, preferably six.
[0115] For the security level, the data transmitted increases the security level. Specifically, the terminal application transmits user input, timestamp information, and an optional security level (i.e., Input + Timestamp + SecureLevel) to the smart card application. For different security levels, specifically including offline verification codes, food delivery verification codes, office verification codes, financial verification codes, government verification codes, and items to be extended, they respectively correspond to the identifiers 00, 01, 02, 03, 04, 05.
[0116] The algorithm to be enabled or the algorithm to be used is determined through dynamic polling. The multiple algorithms dynamically determined in this way are used in combination, which can greatly increase the cracking difficulty and thus improve the security of data transmission.
[0117] It should be noted that in this embodiment, since the calculation method of the dynamic password is roughly the same as that in the second embodiment, only PARA 在线 is replaced by PARA' 在线 , so the description of the same part is omitted.
[0118] In another embodiment, with the authorization of the user and the terminal application, the operator server can perform big data model training. There are two training directions: on the one hand, under certain conditions, predict the optimal algorithm combination; on the other hand, under the condition of expanding the existing conditions (for example, expanding the algorithms in Table 7), find a better algorithm combination. When the prediction model reaches a certain accuracy value, the algorithm model and the smart card application can be updated to the user's smart card regularly. This makes the entire dynamic password system efficient and secure, and convenient and reassuring for users to use.
[0119] For the situation where the data model needs to be updated in a timely manner, a dynamic key SDK can be embedded in the terminal application. This dynamic key SDK is a closed-source code library provided by the operator for the terminal application to provide dynamic password services. The dynamic key SDK plays a role in communicating between the smart card application and the terminal application, and at the same time receives the updated model from the operator. It can also accurately predict the algorithm combination and security level required by the user in the current time period. The SDK acts as an agent for the terminal application to provide dynamic password services for the user and provides a security verification display page. The SDK acts as an agent for the terminal application to interact with the smart card application and uses smart card commands for interaction.
[0120] The training of the big data model can be based on the verification type, the terminal application type (such as the package name of the terminal application and the specific scenario application direction of the terminal application), the smart card serial number corresponding to the mobile phone number, the count value of the counter, the user input parameters, the timestamp information, the security level, and the polling location parameters, to perform the annotation of the algorithm combination (a set of algorithms with multiple combinations), establish a training data set, and let the neural network model learn the association relationship between the above data and the algorithm combination. At the same time, it supports adding new algorithms during model training and filling them into the RFU (reserved part) in the table, and finding a better algorithm combination through continuous deduction.
[0121] When the model accuracy reaches more than 95%, the prediction model in the trained algorithm combination is added to the smart card application in real time and remotely updated to the user's smart card.
[0122] Furthermore, the examples are as follows: For example, when the user does not input user input parameters in the terminal application at 11 am and initiates a request to obtain a dynamic password, the dynamic key SDK outputs the best algorithm combination.
[0123] For example, when the user is in a financial application at 9 am and enters the verification code and then initiates a request to obtain a dynamic password, the dynamic key SDK outputs the best algorithm combination and the security level.
[0124] For example, at the lunch and dinner times of the timestamp between noon and evening, the weight of the takeaway algorithm is increased in the algorithm model.
[0125] It should be noted that the above are only illustrative as optional examples and should not be construed as a limitation of the present invention.
[0126] Next, in step S103, after the terminal application receives the dynamic password input by the current user, the terminal application transmits the smart card serial number, the generated dynamic password, and the relevant data to the server of the current terminal application and then to the operator server.
[0127] For the offline authentication process, when the terminal application receives the dynamic password, the terminal application transmits the smart card serial number (such as represented by ICCID) and the generated dynamic password to the server of the terminal application.
[0128] For the online authentication process, when the terminal application receives the dynamic password, the terminal application transmits the smart card serial number (such as represented by ICCID), the generated dynamic password, and the packed data encrypted with the quantum key to the server of the terminal application. Among them, the smart card application packs the data encrypted with the quantum key to obtain the packed data.
[0129] Specifically, the user inputs the mobile phone number and the received dynamic password. After the smart card application receives the dynamic password input by the current user, the smart card application transmits the smart card serial number corresponding to the mobile phone number, the generated dynamic password, and the packaged data encrypted with the quantum key (i.e., the OTP packaged data. For offline authentication, the OTP packaged data is the OTP password; for online authentication, the OTP packaged data includes the OTP password and the smart card packaged data, and the smart card packaged data contains the parameters related to OTP generation and the signature data of the smart card) to the terminal application (or service system), and uploads it to the server of the terminal application (or service system) through the terminal application (or service system).
[0130] For example, the user opens the mobile phone terminal and views the OTP password through the APP or STK (for example, supporting PIN verification and other biometric verifications, and offline authentication can be selected in the case of no network or extremely poor signal). The user fills in the OTP password (or fills in the mobile phone number and the OTP password) on the PC side or the mobile phone side, etc., and clicks to log in and verify. Among them, the mobile phone number can be obtained through the interface on the PC side or the mobile phone side, etc.
[0131] It should be noted that the above is described as an optional example and should not be construed as a limitation to the present invention.
[0132] Next, in step S104, when a data verification request is received from the operator service end, the authentication type is automatically identified, and dynamic password calculation is performed for data verification, and the data verification result is returned to the service end of the service system. The authentication type includes offline authentication and online authentication.
[0133] Specifically, the server of the terminal application transmits the data verification request to the operator service end. The operator service end automatically identifies the authentication type, performs dynamic password calculation for data verification, and returns the data verification result. The authentication type includes online authentication (i.e., the online authentication process) and offline authentication (i.e., the offline authentication process).
[0134] In a specific embodiment, the server of the terminal application (or service system) sends a data verification request (including the OTP packaged data obtained in step S103 and the smart card serial number corresponding to the mobile phone number, and the OTP packaged data is the OTP password) to the operator service end (i.e., the operator server). When the data verification request is received from the operator service end, the authentication type is automatically identified, such as offline authentication. The operator server independently calculates the OTP password and compares the calculated OTP password with the received OTP password.
[0135] When the calculated OTP password is the same as the received OTP password, it indicates that the verification has passed, and the data verification result is returned to the server of the terminal application (or service system), and then transmitted to the terminal application (or service system) through the server of the terminal application (or service system). Further, according to the data verification result, it jumps to the corresponding interface.
[0136] For example, when the data verification is successful, it enters the relevant main interface to cache user data. When the data verification fails, it enters the retry interface or the login failure interface.
[0137] In another specific embodiment, the server of the terminal application (or service system) sends a data verification request to the operator server (i.e., the operator's server) (including the OTP package data obtained in step S103 and the smart card serial number corresponding to the mobile phone number. The OTP package data includes the OTP password and the smart card package data, and the smart card package data contains the parameters related to OTP generation and the signature data of the smart card). When receiving the data verification request from the operator server, it automatically identifies the authentication type, such as online authentication. The operator server independently calculates the OTP password and compares the calculated OTP password with the OTP password in the received OTP package data.
[0138] When the calculated OTP password is the same as the OTP password in the received OTP package data, it indicates that the verification has passed, and the data verification result is returned to the server of the terminal application (or service system), and then transmitted to the terminal application (or service system) through the server of the terminal application (or service system). Further, according to the data verification result, it jumps to the corresponding interface.
[0139] For example, when the data verification is successful, it enters the relevant main interface to cache user data, that is, the login verification is successful. When the data verification fails, it enters the retry interface or the login failure interface, that is, the login verification fails.
[0140] It should be noted that in the present invention, the smart card and the operator server respectively generate independent OTP passwords to complete data verification.
[0141] Optionally, the operator server can query the ICCID (smart card serial number) according to the user's mobile phone number and can query the configuration parameters.
[0142] Preferably, when the operator server receives the data verification request, it first verifies whether the mobile phone number is in a shutdown state or in a violation state. If it is in a shutdown state or in a violation state, the data verification is terminated, and the verification failure and the reason for failure are returned to the server of the terminal application (or service system).
[0143] When the data verification fails, the operator server immediately issues a command to reset the counter (i.e., counter). Other parameters can be reset optionally. The reset interval needs to be greater than 10 minutes to prevent repeated attacks.
[0144] In an optional implementation, the operator server determines the authentication type based on the intercepted retention length (e.g., four digits) in the interception algorithm and the OTP packet data length. Specifically, the operator server checks whether the intercepted retention length (e.g., four digits) and the OTP packet data length calculated by itself match the intercepted retention length and the OTP packet data length corresponding to the received OTP password. When it is determined that the intercepted retention length (e.g., four digits) and the OTP packet data length calculated by itself match the intercepted retention length and the OTP packet data length corresponding to the received OTP password, it is determined as online authentication.
[0145] When it is determined that the intercepted retention length (e.g., four digits) and the OTP packet data length calculated by itself do not match the intercepted retention length and the OTP packet data length corresponding to the received OTP password, it is determined as offline authentication.
[0146] If it is online authentication, the operator server selects the encryption algorithm Encrypt based on the current value of the counter and relevant parameters (such as the polling position parameter), and then selects the quantum secret key based on the current value of the counter.
[0147] The following expression is used to calculate the decrypted data to obtain the decrypted data: dat3=decrypt(key 在线 , OTP packet data) where dat3 represents the decrypted PARA 在线 , PARA 在线 =ICCID+Counter+Input+Timestamp+Random + SignDat, where PARA 在线Denotes the online parameters corresponding to the current dynamic password acquisition request generated based on the current dynamic password acquisition request and the current value of its corresponding counter; ICCID denotes the smart card serial number of the smart card corresponding to the current dynamic password acquisition request; Input denotes the input data of the current user; Timestamp denotes the timestamp returned by the terminal application or service system of the smart card application to the smart card when the applied authentication password is the online authentication password, that is, when the smart card application receives an online authentication password acquisition request (i.e., corresponding to an online authentication request), the timestamp represented by the current Unix seconds transmitted by the terminal application or service system of the smart card application to the smart card; Random denotes a random number randomly generated by the smart card itself, for example, a random number of 4 to 10 digits, including numbers, letters, symbols, etc.; Counter denotes the current value of the counter corresponding to the current dynamic password acquisition request.
[0148] For example, use the Decrypt algorithm to decrypt the data to obtain the plaintext of the following data: ICCID + Counter + Random + Input + Timestamp + SignDat.
[0149] The data verification includes verifying ICCID, verifying Counter, and checking whether the timestamp Timestamp is within a 10-minute time window. The SignDat signature is also verified using the first public key (such as SimSM2pub) prefabricated on the smart card.
[0150] Optionally, if the smart card is in a shutdown or other violation state, the one-time password service is suspended according to relevant rules. The operator server returns the verification result of the abnormal smart card state to the server of the terminal application.
[0151] It should be noted that in this example, the operator server generates a set of asymmetric keys for the one-time password service for the user, specifically the second public key (such as MNOSM2pub) and the second private key (such as MNOSM2pri). The operator server saves the second public key and the second private key and distributes the generated second public key to the smart card application. The above is only described as an optional example and should not be construed as a limitation to the present invention.
[0152] Compared with the prior art, when the front end of the service system receives a dynamic password acquisition request in the present invention, the front end of the service system applies for the following authentication passwords to the smart card application according to the network status and security requirements: online authentication password, offline authentication password; the smart card application uses the selected password algorithm and parameter items to perform hash value conversion and encryption calculation, intercepts according to the interception algorithm, and generates dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and returns the generated dynamic passwords to the current terminal application and the current user; after the current terminal application receives the dynamic password, it transmits the smart card serial number, the generated dynamic password, and the packaged data encrypted by the quantum key to the server of the current terminal application, and then transmits it to the operator server; when the operator server receives a data verification request, it automatically identifies the authentication type, performs dynamic password calculation for data verification, and returns a data verification result to the server end of the service system. Among them, the smart card and the operator server generate dynamic passwords according to the same algorithm and related parameters. The user fills in the parameters in the smart card application, and the smart card application transmits the parameters to the server of the smart card application, and then transmits them to the operator server through the server of the smart card application for data verification. The operator server can independently generate dynamic passwords for comparison and verification, and then complete data verification, which can realize offline authentication, and effectively solve the problem that "one-key login" cannot be authenticated especially when there is no network provided by the operator.
[0153] In addition, the use of quantum keys improves the transmission security of system data and increases the difficulty of cracking.
[0154] In addition, the present invention can realize flexible verification methods and OTP generation methods, support offline authentication, as a supplement to the operator's "one-key login" solution, improve the verification success rate, the login verification method of the present invention can improve the security level and optimize the method of generating one-time passwords.
[0155] Embodiment 2 The following is an embodiment of the system of the present invention, which can be used to execute the method embodiment of the present invention. For the details not disclosed in the system embodiment of the present invention, please refer to the method embodiment of the present invention.
[0156] Figure 4 is a schematic structural diagram of an example of a login verification system based on the present invention. The following will refer to Figure 4 , to describe the login verification system 400. The login verification system 400 executes the login verification system method described in Embodiment 1 of the present invention.
[0157] The login verification system 400 includes a request processing module 410, a calculation processing module 420, a data transmission module 430, and a data verification module 440.
[0158] In a specific embodiment, the request processing module 410 is configured to, when the front end of the service system receives a dynamic password acquisition request, the front end of the service system applies for the following authentication passwords to the smart card application according to the network status and security requirements: an online authentication password and an offline authentication password. The calculation processing module 420 is configured to the smart card application uses the selected password algorithm and parameter items to perform hash value conversion and encryption calculation, and intercepts according to the interception algorithm to generate dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and returns the generated dynamic passwords to the current terminal application and the current user. The data transmission module 430 is configured to, after the current terminal application receives the dynamic password, transmit the smart card serial number, the generated dynamic password, and related data to the server of the current terminal application, and then transmit them to the operator server side in the smart card application. The data verification module 440 is configured to, when the operator server side receives a data verification request, automatically identify the authentication type, perform dynamic password calculation for data verification, and return a data verification result to the server side of the service system, and the authentication type includes offline authentication and online authentication.
[0159] According to an alternative embodiment, when the applied authentication password is an offline authentication password, the smart card application uses the password algorithm and parameter items selected based on the counter to perform hash value conversion and encryption calculation, and then intercepts according to the interception algorithm to generate a dynamic password, and returns the generated dynamic password to the current user.
[0160] The following expression is used to calculate the dynamic password, i.e., the one-time password or OTP password: OTP 离线 = CUT(Encrypt(key 离线 ,HASH(PARA 离线 ))) where OTP 离线 represents the offline authentication one-time password corresponding to the currently applied authentication password; CUT() represents the interception algorithm for intercepting the data after encryption calculation to obtain the one-time password corresponding to the currently applied authentication password, specifically intercepting a specified number of byte data at a specified position, and the specified position includes the byte position or byte position range of a specified byte, and the specified number includes 4 to 8 bytes; Encrypt() represents encrypting the hash value obtained by performing a hash value calculation on the generated PARA 离线 , and the encrypting calculation refers to performing an encrypting calculation using the quantum secret key selected according to the current value of the counter in the offline authentication; key 离线 represents the quantum secret key selected according to the current value of the counter in the offline authentication; HASH(PARA 离线)indicates calculating the hash value corresponding to PARA using the hash algorithm HASH determined according to the current value of the counter 离线 where PARA 离线 represents the offline parameter generated for the current dynamic password acquisition request.
[0161] Using the following expression, according to the current dynamic password acquisition request and the current value of its corresponding counter, generate the offline parameter corresponding to the current dynamic password acquisition request: PARA 离线 =ICCID + Counter where PARA 离线 represents the offline parameter corresponding to the current dynamic password acquisition request generated according to the current dynamic password acquisition request and the current value of its corresponding counter; ICCID represents the smart card serial number of the smart card corresponding to the current dynamic password acquisition request; Counter represents the current value of the counter corresponding to the current dynamic password acquisition request, and the value increases by one after each calculation.
[0162] According to an alternative implementation, when the applied authentication password is an online authentication password, the following steps are specifically executed: Step S201: Determine the current usage scenario according to the terminal application, select the current user input as the user input parameter, and when no user input parameter is received, use a random number as the user input parameter.
[0163] Step S202: The terminal application transmits the timestamp information and the user input parameter to the smart card application.
[0164] Step S203: The smart card application splices the smart card serial number, the counter, the randomly generated number by itself, the timestamp information, and the user input parameter to generate the online parameter corresponding to the current dynamic password acquisition request.
[0165] Step S204: Calculate the dynamic password, that is, the one-time password or the OTP password.
[0166] Step S205: Sign the online parameter using the first private key of the smart card application to obtain the signature value.
[0167] Step S206: Using the following expression, use the quantum key to perform an encryption calculation on the online parameter and its signature value to obtain the OTP packaged data: OTP packaged data = Encrypt(key 在线 , PARA 在线 + SignDat) Among them, the OTP packaged data represents the OTP packaged data obtained by selecting a password algorithm according to the current value of the counter and related parameters, then selecting a quantum secret key according to the current value of the counter, and performing an encryption calculation on the online parameters and their signature values; PARA 在线 represents generating the online parameters corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request and the current value of its corresponding counter; SignDat represents the signature value of PARA 在线 calculated using the first private key of the smart card application; key 在线 represents the quantum secret key selected according to the current value of the counter in online authentication.
[0168] Step S207: Return the calculated dynamic password and OTP packaged data to the user; among them, the generated OTP 在线 and the OTP packaged data are generated simultaneously in the smart card application.
[0169] According to an alternative implementation, the smart card application selects an interception algorithm according to the current value of the counter and related parameters, and intercepts the dynamic password, that is, the one-time password, which is represented by the following expression: OTP 在线 = CUT(Encrypt(key 在线 ,HASH(PARA 在线 ))) Among them, OTP 在线 represents the one-time password corresponding to the authentication password currently applied for; CUT() represents an interception algorithm for intercepting the data after encryption calculation to obtain the one-time password corresponding to the authentication password currently applied for, specifically intercepting a specified number of byte data at a specified position, the specified position includes the byte position range from the first bit to the nth bit, and the specified number includes 4 to 8 bytes; Encrypt() represents encrypting the hash value obtained by calculating the hash value of the generated PARA 在线 , specifically encrypting using the quantum secret key selected according to the current value of the counter; key 在线 represents the quantum secret key selected according to the current value of the counter in online authentication; HASH(PARA 在线 ) represents calculating the hash value corresponding to PARA 在线 using the hash algorithm HASH determined according to the current value of the counter, and PARA 在线 represents the online parameters generated by the current dynamic password acquisition request.
[0170] According to an alternative implementation, the following expression is used to generate the online parameters corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request and the current value of its corresponding counter: PARA 在线 = ICCID + Counter + Random + Input + Timestamp Among them, PARA 在线 represents the online parameter corresponding to the current dynamic password acquisition request generated according to the current dynamic password acquisition request and the current value of its corresponding counter; ICCID represents the smart card serial number of the smart card corresponding to the current dynamic password acquisition request; Counter represents the current value of the counter corresponding to the current dynamic password acquisition request, and the value increases by one after each calculation; Random represents a random number randomly generated by the smart card itself, including numbers, letters, and symbols; Input represents the user input parameter of the current user. When no user input parameter is received, a random number is used as the user input parameter. Specifically, the terminal application uses a randomly generated random number by itself to fill in as the user input parameter, and the random number includes numbers, letters, and symbols; Timestamp represents the current timestamp returned by the terminal application or the service system to the smart card application when the applied authentication password is the authentication password.
[0171] According to an alternative embodiment, the smart card application selects each password algorithm using the current value of the counter, and determines the position parameter corresponding to each password algorithm through dynamic polling. Among them, the dynamic polling introduces a security level, and the security level includes offline type verification codes, food delivery type verification codes, office type verification codes, financial type verification codes, government affairs type verification codes, items to be extended, and their respective corresponding security levels; when a user input parameter is detected and the identifier corresponding to the security level is the first identifier or the second identifier, the current security level remains unchanged; when a user input parameter is detected and the identifier corresponding to the security level is greater than the second identifier, a security check is performed on the user input. When it is determined to be a risky input, it is automatically upgraded, that is, the current security level is increased by one. The security check includes whether the input length of the user input is greater than a specified number of digits, and whether the user input contains numbers, letters, and symbols.
[0172] According to an alternative embodiment, when the operator server receives a data verification request, the operator server automatically identifies the authentication type; when the operator server receives OTP packaged data, it automatically calculates the OTP using the online authentication algorithm according to the automatically identified authentication type, that is, the operator server independently calculates the OTP password, and compares the calculated OTP password with the received OTP password.
[0173] According to an optional embodiment, when the OTP password calculated by the operator server is the same as the received OTP password, it indicates that the data verification has passed, and the data verification result is returned to the server of the terminal application or service system, and then transmitted to the terminal application or service system through the server of the terminal application or service system, and further jumps to the corresponding interface according to the data verification result.
[0174] It should be noted that, because Figure 4 the dynamic password-based login verification method performed by the dynamic password-based login verification system of Figure 1 is substantially the same as the dynamic password-based login verification method in the example of
[0175] Therefore, the description of the same part is omitted.
[0176] In addition, the use of quantum keys improves the transmission security of system data and increases the difficulty of cracking.
[0177] In addition, the present invention can achieve flexible verification methods and OTP generation methods, support offline authentication, and as a supplement to the operator's "one-key login" solution, improve the verification success rate. The login verification method of the present invention can improve the security level and optimize the method of generating one-time passwords.
[0178] Figure 5 It is a schematic structural diagram of an embodiment of an electronic device according to the present invention.
[0179] As Figure 5 shown, the electronic device is presented in the form of a general computing device. The processor can be one or multiple and work collaboratively. The present invention does not exclude distributed processing, that is, the processors can be dispersed in different physical devices. The electronic device of the present invention is not limited to a single entity, and can also be the sum of multiple physical devices.
[0180] The memory stores computer-executable programs, usually machine-readable codes. The computer-readable programs can be executed by the processor so that the electronic device can execute the method of the present invention or at least some of the steps in the method.
[0181] The memory includes volatile memory, such as random access storage units (RAM) and / or cache storage units, and can also be non-volatile memory, such as read-only storage units (ROM).
[0182] Optionally, in this embodiment, the electronic device further includes an I / O interface, which is used for the electronic device to exchange data with external devices. The I / O interface can represent one or more of several bus structures, including a memory unit bus or a memory unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the multiple bus structures.
[0183] It should be understood that Figure 5 the displayed electronic device is only an example of the present invention, and the electronic device of the present invention may also include elements or components not shown in the above example. For example, some electronic devices also include a display unit such as a display screen, and some electronic devices also include human-computer interaction elements, such as buttons, keyboards, etc. As long as the electronic device can execute the computer-readable program in the memory to implement the method of the present invention or at least some of the steps of the method, it can be considered as the electronic device covered by the present invention.
[0184] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described here can be implemented by software or by a combination of software and necessary hardware. Therefore, as Figure 6 shown, the technical solution according to the embodiment of the present invention can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several commands to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiment of the present invention.
[0185] The software product may employ any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0186] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with a command execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0187] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).
[0188] The above-mentioned computer-readable medium bears one or more programs, and when the above-mentioned one or more programs are executed by a device, the computer-readable medium realizes the data interaction method of the present disclosure.
[0189] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and distributed in one or more devices that are only different from this embodiment. The modules of the above embodiments can be combined into one module, or can be further split into multiple sub-modules.
[0190] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present invention.
[0191] It should be noted that the above detailed description is exemplary and is intended to provide further illustration of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present application belongs.
[0192] In the above detailed description, reference has been made to the accompanying drawings, which form a part hereof. In the drawings, like symbols typically identify like components, unless the context indicates otherwise. The illustrated embodiments described in the detailed description, the drawings, and the claims are not meant to be limiting. Other embodiments may be used and other changes may be made without departing from the spirit or scope of the subject matter presented herein.
[0193] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A login verification method based on dynamic passwords, characterized in that, Including: When the front end of the service system receives a dynamic password acquisition request, the front end of the service system applies for the following authentication passwords to the smart card application according to the network status and security requirements: online authentication password, offline authentication password; The smart card application uses the selected password algorithm and parameter items to perform hash value conversion and encryption calculation, and intercepts according to the interception algorithm to generate dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and returns the generated dynamic passwords to the current terminal application and the current user; After the current terminal application receives the dynamic password, it transmits the smart card serial number, the generated dynamic password, and related data to the server of the current terminal application, and then to the operator service end; When the operator service end receives a data verification request, it automatically identifies the authentication type, performs dynamic password calculation for data verification, and returns a data verification result to the service end of the service system, and the authentication type includes offline authentication and online authentication.
2. The login verification method based on dynamic passwords according to claim 1, wherein Further including: When the applied authentication password is an offline authentication password, the smart card application uses the password algorithm and parameter items selected based on the counter to perform hash value conversion and encryption calculation, and then intercepts according to the interception algorithm to generate a dynamic password, and returns the generated dynamic password to the current user, where, The following expression is used to calculate the dynamic password, that is, the one-time password or OTP password: OTP 离线 = CUT(Encrypt(key 离线 ,HASH(PARA 离线 ))); Among them, OTP 离线 represents the offline authentication one-time password corresponding to the authentication password applied currently; CUT() represents a truncation algorithm for truncating the encrypted calculated data to obtain the one-time password corresponding to the authentication password applied currently, specifically truncating a specified number of byte data at a specified position, where the specified position includes the byte position or byte position range of a specified byte, and the specified number includes 4 to 8 bytes; Encrypt() represents encrypting the hash value obtained by calculating the hash value of the generated PARA 离线 , and the said encrypting calculation means performing an encrypting calculation using the quantum secret key selected according to the current value of the counter in the offline authentication; key 离线 represents the quantum secret key selected according to the current value of the counter in the offline authentication; HASH(PARA 离线 ) represents calculating the hash value corresponding to PARA 离线 using the hash algorithm HASH determined according to the current value of the counter, and PARA 离线 represents the offline parameter generated by the current dynamic password acquisition request.
3. The login verification method based on dynamic passwords according to claim 1, wherein, Further including: When the applied authentication password is an online authentication password, the following steps are specifically executed: Step S201: Judge the current usage scenario according to the terminal application, select the current user input as the user input parameter, and when the user input parameter is not received, use a random number as the user input parameter; Step S202: The terminal application transmits the timestamp information and the user input parameter to the smart card application; Step S203: The smart card application splices the smart card serial number, the counter, the randomly generated number by itself, the timestamp information and the user input parameter to generate the online parameter corresponding to the current dynamic password acquisition request; Step S204: Calculate the dynamic password, that is, the one-time password or OTP password; Step S205: Sign the online parameter using the first private key of the smart card application to obtain a signature value; Step S206: Using the following expression, use the quantum key to perform encryption calculation on the online parameter and its signature value to obtain the OTP package data: OTP Packed Data = Encrypt(key 在线 , PARA 在线 + SignDat); Among them, the OTP packaged data represents the OTP packaged data obtained by selecting a password algorithm according to the current value of the counter and relevant parameters, then selecting a quantum secret key according to the current value of the counter, and performing an encryption calculation on the online parameters and their signature values; PARA 在线 represents generating the online parameters corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request and the current value of its corresponding counter; SignDat represents the signature value of PARA 在线 calculated using the first private key of the smart card application; key 在线 represents the quantum secret key selected according to the current value of the counter in online authentication; Step S207: Return the calculated dynamic password and OTP package data to the user; among them, the calculated dynamic password and OTP package data are generated simultaneously in the smart card application.
4. The login verification method based on dynamic passwords according to claim 3, wherein Further including: The smart card application selects an interception algorithm according to the current value of the counter and related parameters, and intercepts to obtain the dynamic password, that is, the one-time password, which is expressed by the following expression: OTP 在线 = CUT(Encrypt(key 在线 ,HASH(PARA 在线 ))); Among them, OTP 在线 represents the one-time password corresponding to the authentication password currently applied for; CUT() represents a truncation algorithm for truncating the data after encryption calculation to obtain the one-time password corresponding to the authentication password currently applied for, specifically truncating a specified number of byte data at a specified position, the specified position including the byte position range from the first bit to the nth bit, and the specified number including 4 to 8 bytes; Encrypt() represents encrypting the hash value obtained by calculating the hash value of the generated PARA 在线 specifically using the quantum secret key selected according to the current value of the counter for encryption calculation; key 在线 represents the quantum secret key selected according to the current value of the counter in online authentication; HASH(PARA 在线 ) means that the hash algorithm HASH determined according to the current value of the counter is specifically adopted to calculate the hash value corresponding to PARA 在线 , and PARA 在线 represents the online parameter generated by the current dynamic password acquisition request.
5. The login verification method based on dynamic passwords according to claim 3, characterized in that, Further including: Using the following expression, according to the current dynamic password acquisition request and the current value of the corresponding counter, generate the online parameter corresponding to the current dynamic password acquisition request: PARA 在线 = ICCID + Counter + Random + Input + Timestamp wherein, PARA 在线 represents the online parameter corresponding to the current dynamic password acquisition request generated according to the current dynamic password acquisition request and the current value of its corresponding counter; ICCID represents the smart card serial number of the smart card corresponding to the current dynamic password acquisition request; Counter represents the current value of the counter corresponding to the current dynamic password acquisition request, and the value increases by one after each calculation; Random represents a random number randomly generated by the smart card itself, including numbers, letters, and symbols; Input represents the user input parameter of the current user. When no user input parameter is received, a random number is used as the user input parameter. Specifically, the terminal application uses a randomly generated random number by itself to fill in as the user input parameter, and the random number includes numbers, letters, and symbols; Timestamp represents the current timestamp returned by the terminal application or service system to the smart card application when the applied authentication password is the authentication password.
6. The login verification method based on dynamic passwords according to claim 1, characterized in that Further including: The smart card application selects each cryptographic algorithm using the current value of the counter, and determines the position parameters corresponding to each cryptographic algorithm through dynamic polling. Among them, the dynamic polling introduces a security level, and the security level includes offline verification codes, takeaway verification codes, office verification codes, financial verification codes, government verification codes, items to be extended, and their respective corresponding security levels; When the user input parameter is detected and the identifier corresponding to the security level is the first identifier or the second identifier, the current security level remains unchanged; When the user input parameter is detected and the identifier corresponding to the security level is greater than the second identifier, a security check is performed on the user input. When it is determined to be a risky input, it is automatically upgraded, that is, the current security level is increased by one. The security check includes whether the input length of the user input is greater than the specified number of digits, and whether the user input contains numbers, letters, and symbols.
7. The login verification method based on dynamic passwords according to claim 1, wherein Further includes: When the operator server receives a data verification request, the operator server automatically identifies the authentication type; When the operator server receives OTP packaged data, it automatically calculates the OTP using the online authentication algorithm according to the automatically identified authentication type, that is, the operator server independently calculates the OTP password, and compares the calculated OTP password with the received OTP password.
8. The login verification method based on dynamic passwords according to claim 7, wherein Further includes: When the OTP password calculated by the operator server is the same as the received OTP password, it indicates that the data verification is passed, and the data verification result is returned to the server of the terminal application or service system, and then transmitted to the terminal application or service system through the server of the terminal application or service system, and further jumps to the corresponding interface according to the data verification result.
9. A login verification system based on dynamic passwords, characterized in that, It executes the dynamic password-based login verification method described in any one of claims 1 to 8. The login verification system includes: A request processing module, which is used to, when the front end of the service system receives a dynamic password acquisition request, the front end of the service system applies for the following authentication passwords from the smart card application according to the network status and security requirements: online authentication password, offline authentication password; A calculation processing module, which is used for the smart card application to perform hash value conversion and encryption calculation using the selected cryptographic algorithm and parameter items, and intercept according to the interception algorithm to generate dynamic passwords corresponding to the offline authentication password request or the online authentication password request in different ways, and return the generated dynamic passwords to the current terminal application and the current user; A data transmission module, which is used to, after the current terminal application receives the dynamic password, transmit the smart card serial number, the generated dynamic password, and related data to the server of the current terminal application, and then transmit it to the operator server; A data verification module, which is used to, when the operator server receives a data verification request, automatically identify the authentication type, perform dynamic password calculation for data verification, and return the data verification result to the server of the service system. The authentication type includes offline authentication and online authentication.
10. The login verification system based on dynamic passwords according to claim 9, wherein Further includes: When the applied authentication password is an offline authentication password, the smart card application uses the password algorithm and parameter items selected based on the counter to perform hash value conversion and encryption calculation, and then intercepts according to the interception algorithm to generate a dynamic password, and returns the generated dynamic password to the current user, where The following expression is used to calculate the dynamic password, that is, the one-time password or OTP password: OTP 离线 = CUT(Encrypt(key 离线 ,HASH(PARA 离线 ))); Among them, OTP 离线 represents the offline authentication one-time password corresponding to the authentication password currently applied for; CUT() represents a truncation algorithm for truncating the encrypted calculated data to obtain the one-time password corresponding to the authentication password currently applied for, specifically truncating a specified number of byte data at a specified position, where the specified position includes the byte position or byte position range of a specified byte, and the specified number includes 4 to 8 bytes; Encrypt() represents encrypting the hash value obtained by calculating the hash value of the generated PARA 离线 , and the said encrypting calculation means performing an encrypting calculation using the quantum secret key selected according to the current value of the counter in the offline authentication; key 离线 represents the quantum secret key selected according to the current value of the counter in the offline authentication; HASH(PARA 离线 ) represents calculating the hash value corresponding to PARA 离线 using the hash algorithm HASH determined according to the current value of the counter, and PARA 离线 represents the offline parameter generated by the current dynamic password acquisition request; The following expression is used to generate the offline parameters corresponding to the current dynamic password acquisition request according to the current dynamic password acquisition request and the current value of its corresponding counter: PARA 离线 =ICCID + Counter; Among them, PARA 离线 represents the offline parameter corresponding to the current dynamic password acquisition request generated according to the current dynamic password acquisition request and the current value of its corresponding counter; ICCID represents the smart card serial number of the smart card corresponding to the current dynamic password acquisition request; Counter represents the current value of the counter corresponding to the current dynamic password acquisition request, and the value increases by one after each calculation.
Citation Information
Patent Citations
Method for realizing dynamic password generation and judge on smart card
CN101252435A
Smart card dynamic password creating and judging system
CN101252436A
Password management method, related device and system
CN104320422A
Online authentication method based on intelligent card, the intelligent card and authentication server
CN106411522A
Authentication method and device based on intelligent card and terminal application
CN109547398A
Cited By
Login authentication method and system based on smart card, and server
CN120897191A