Credible-based secure network authentication method
By using gene certificates to authenticate and trustworthy metrics in the network, the CA trustworthiness problem in existing network authentication is solved, the integration of identity authentication and access control is realized, and the security and robustness of the network system are improved.
Patent Information
- Application Number
- CN202410083313.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-07-22
AI Technical Summary
There are doubts about the trustworthiness of CAs in existing network authentication. The information of the certificate subject is unclear, making it difficult to distinguish entities with the same name, poor scalability and complex authentication process, resulting in network trust crisis and application restrictions.
The identity authentication method based on gene certificate is adopted to authenticate and trustworthy metrics for network members through the patriarch gene certificate and the application gene certificate, integrate identity authentication and access control in the same certificate, and use family genes to identify member legitimacy and determine access authorization to achieve static and dynamic trustworthy metrics.
It improves the security and robustness of the network system, prevents intruders from penetrating the identity authentication mechanism, realizes the endogenous security of the network system, and improves the security and credibility of the system.
Smart Images

Figure CN120358036A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer network security, and particularly relates to a trusted-based secure network authentication method. Background Art
[0002] Most network authentications in the prior art are based on conventional systems such as PKI for authentication. The trust relationship between the third party (CA) and the user in the model is artificially and forcibly established. The trustworthiness of the CA is in doubt, and there are defects such as unclear certificate subject information, difficulty in distinguishing homonymous entities in reality, poor scalability, and complex authentication processes. The network authentication of the conventional system has led to the emergence of a network trust crisis and has restricted the application of the network to a certain extent. Summary of the Invention
[0003] In view of the above analysis, the present invention aims to provide a trusted-based secure network authentication method. By performing identity authentication and trusted measurement on members based on the gene certificates carried by network members, integrating identity authentication and access control in the same certificate, forcibly performing identity discrimination and access control on all users and applications in the system, and enhancing the security of the system.
[0004] The present invention provides a trusted-based secure network authentication method, which specifically includes the following steps:
[0005] Before a network subject in the network loads an application, perform identity authentication and static trusted measurement on the application based on the gene certificate of the patriarch of the network domain family where the subject is located and the application gene certificate;
[0006] The network subject loads the application that passes the identity authentication and static trusted measurement, and performs dynamic trusted measurement on the application based on the application gene certificate during the running process of the application;
[0007] When applications access each other, perform identity authentication and access authorization on each other based on the application gene certificates and the gene certificates of the patriarchs of each other;
[0008] When an application is accessed by a network user, perform identity authentication and access authorization on the user based on the user gene certificate and the gene certificate of the patriarch of the network domain where the user is located.
[0009] Further, the performing identity authentication and static trusted measurement on the application based on the gene certificate of the patriarch of the network domain family where the subject is located and the application gene certificate includes:
[0010] Obtain the family gene and family public key of the patriarch based on the gene certificate of the patriarch;
[0011] Verify the digital signature of the application gene certificate based on the family public key, obtain the family gene of the application based on the application gene certificate. If the digital signature verification passes and the family gene of the patriarch matches the family gene of the application successfully, the identity authentication is successful;
[0012] Obtain the program gene of the application based on the application gene certificate with successful identity authentication, and perform static trusted measurement on the application based on the program gene and the family public key.
[0013] Further, the application gene certificate includes application gene main body information, application public key, and application gene signature. The application gene signature is obtained by signing the application public key and the application gene main body information based on the family private key, signature algorithm; Verifying the digital signature of the application gene certificate based on the family public key includes:
[0014] Decrypt the application signature information in the application gene signature based on the family public key and the signature algorithm carried by the application signature to obtain a decryption digest;
[0015] Calculate a message digest based on the application gene main body information and the application public key;
[0016] Compare whether the message digest and the decryption digest are consistent. If they are consistent, the digital signature verification is successful; otherwise, the digital signature verification fails.
[0017] Further, the application gene main body information includes the patriarch name, application name, family gene, application permission gene, and application program gene; The application program gene includes static information, dynamic information, and integrity signature value; The static trusted measurement of the application includes:
[0018] Obtain the application program gene based on the application gene certificate;
[0019] Perform integrity verification on the static information based on the family public key and the integrity signature value of the application program gene;
[0020] Obtain the current static information of the application, compare it with the static information that passes the integrity verification in the program gene. If they are consistent, the static trusted measurement is successful; otherwise, it fails.
[0021] Further, the dynamic trusted measurement of the application based on the application gene certificate during the running process of the application includes:
[0022] Obtain the application program gene based on the application gene certificate;
[0023] Obtain the dynamic information of the application based on the program gene. The dynamic information includes a resource file list, socket type, and socket port number;
[0024] Obtain the list of resource files, socket types, and socket port numbers during the current running process of the application, and compare them with the program gene. If they are consistent, the dynamic trusted measurement is successful; otherwise, identify.
[0025] Further, after the network entity fails in the dynamic trusted measurement of the application during the running process of the application, it further includes:
[0026] The network entity forcibly stops the application;
[0027] The network entity performs trusted recovery on the application.
[0028] Further, the network entity's trusted recovery of the application includes: the network entity performs static trusted measurement on the application and reloads the application with successful static trusted measurement.
[0029] Further, when the applications access each other, the mutual identity authentication and access authorization based on each other's application gene certificates and patriarch gene certificates include:
[0030] The applications mutually obtain each other's family genes and family public keys based on each other's patriarch gene certificates;
[0031] Perform identity authentication on each other based on each other's family genes and family public keys;
[0032] Obtain the permission genes in the application gene certificate of the other party that passes the identity authentication;
[0033] Perform access authorization on each other based on the patriarch gene certificate and the application permission genes of the other party. Further, the permission genes include resource access permission information encoding and integrity signature values; the access authorization of the other party's application based on the patriarch gene certificate and the permission genes of the other party's application includes:
[0034] Obtain the family public key based on the patriarch gene certificate;
[0035] Perform integrity verification on the resource access permission encoding information in the permission genes based on the family public key and the integrity signature value in the permission genes;
[0036] Perform access authorization on the other party's application based on the resource access permission encoding information that passes the integrity verification.
[0037] Further, the user gene certificate includes user gene main information and a user gene signature, where the user gene signature is obtained by signing the user gene main information and the user public key based on a family private key and a signature algorithm. The gene main information includes the patriarch name, user name, family gene, and user permission gene. The identity authentication and access authorization for the user based on the user gene certificate and the patriarch gene certificate of the network domain where the user is located include:
[0038] The application obtains the family gene and family public key of the other party based on the user's patriarch gene certificate;
[0039] Authenticate the user based on the user's family gene and family public key;
[0040] Obtain the permission gene in the user gene certificate of the user who passes the identity authentication;
[0041] Perform access authorization on the user based on the patriarch gene certificate and the user's user permission gene.
[0042] The present invention can at least achieve one of the following beneficial effects:
[0043] By performing identity authentication and trusted measurement on members based on the gene certificates carried by network members, integrating identity authentication and access control in the same certificate, identifying the legality of members' family genes according to the family genes of the network patriarchs, determining the access authorization of members based on legal member gene certificates, and performing static and dynamic trusted measurements on the applications in the members, identity discrimination and trusted-based access control for all users and applications in the system are achieved, improving the system security.
[0044] By the patriarch issuing and controlling the gene certificates of each member in the network, effectively preventing intruders from penetrating or bypassing the identity authentication mechanism to wantonly access network resources, the endogenous security of the network system is realized, and the robustness of the network system is improved.
[0045] Other features and advantages of the present invention will be described in the subsequent specification, and some advantages can be made obvious from the specification, or understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained from the content specifically pointed out in the specification, claims, and drawings. Description of the Drawings
[0046] The drawings are only for the purpose of showing specific embodiments, and are not considered as a limitation to the present invention. Throughout the drawings, the same reference signs represent the same components;
[0047] Figure 1 It is a flowchart of the security network authentication method of the present invention;
[0048] Figure 2Structural diagram of the gene certificate applied in the present invention;
[0049] Figure 3 Structural diagram of the user gene certificate of the present invention. Specific implementation manners
[0050] The following will specifically describe the preferred embodiments of the present invention with reference to the accompanying drawings. The accompanying drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, rather than to limit the scope of the present invention.
[0051] A specific embodiment of the present invention discloses a trusted security network authentication method, which specifically includes the following steps:
[0052] Step S1: Before the network entity in the network loads the application, perform identity authentication and static trusted measurement on the application based on the gene certificate of the clan leader of the network domain family where it is located and the application gene certificate;
[0053] Step S2: The network entity loads the application that passes the identity authentication and static trusted measurement, and performs dynamic trusted measurement on the application based on the application gene certificate during the running process of the application;
[0054] Step S3: When the applications access each other, perform identity authentication and access authorization on each other based on the application gene certificates and clan leader gene certificates of each other;
[0055] Step S4: When the application is accessed by the network user, perform identity authentication and access authorization on the user based on the user gene certificate and the gene certificate of the clan leader of the network domain where the user is located.
[0056] In this embodiment, identity authentication and trusted measurement are performed on the members based on the gene certificates carried by the network members, and identity authentication and access control are integrated in the same certificate, so as to realize identity authentication for all users and applications in the system and trusted-based access control, improving the security of the system.
[0057] Specifically, the network of the present invention includes multiple network domains at all levels in the network. Each network domain includes the clan leader of this network domain and multiple network entities. The types of the network entities include hosts, backbone routers in each network domain, and access routers in each network domain.
[0058] Furthermore, each network domain corresponds to the head of the family of each network domain, that is, one network domain in the network corresponds to one family, and there is an inheritance relationship between families. The head of the family of the network domain generates the gene certificate of the head of the family of the network domain based on the family information assigned by the head of the family of the upper network domain. In the entire network, the head of the family of the highest-level network domain is called the ancestor head. Starting from the ancestor head, the family information is distributed to the head of the family of the next-level network domain step by step, forming a top-down family inheritance relationship, ensuring that each network domain in the entire network architecture is securely managed by its own head of the family.
[0059] Furthermore, the family heads of network domains at all levels manage the members of their own network domains. The family heads of network domains at all levels serve as security management servers for their network domains, realizing the security management function of the security management center in the network.
[0060] Furthermore, the head of each network domain family issues a family public key and a family private key to himself, and issues respective gene certificates and user public and private key pairs to family members.
[0061] Specifically, the family members include users registered in this domain and applications published in this network domain. The head of the family issues user gene certificates to users registered in this network domain, and issues application gene certificates to applications when applications are published in this network domain. When a user or application is deregistered, the corresponding gene certificate is revoked. The head of the family issues user gene certificates and user public-private key pairs to users registered in this network domain, and issues application gene certificates and application public-private key pairs to applications when applications are published in this network domain.
[0062] Specifically, the family private key and family public key are used to sign and verify the corresponding gene certificates of the members, and the user private key / application and user / application public key are used to sign and verify the identity of family members during the network authentication process.
[0063] Furthermore, the family heads of network domains at all levels determine the family genes based on the family information and family private key assigned by the family head of the upper network; and generate the gene certificate of the family head of this network domain based on the family head name, family gene and family public key of the family head of this network domain. It should be noted that after the family heads of network domains at all levels generate the family head gene certificate, they submit it to the backup storage of the family head of the upper network domain. The family heads of network domains at all levels in the network provide family head gene query services to family members. Family members can trace back and query the family head gene certificates of the family heads of each network domain in the network step by step through the family heads of their network domains.
[0064] Furthermore, each network subject has a corresponding trust measurement service, and each network subject uses the trust measurement service to perform trust measurement on the application, and the trust measurement includes static trust measurement and dynamic trust measurement.
[0065] Specifically, in step S1, before the network body in the network loads the application, the identity authentication and static trusted measurement of the application based on the clan leader gene certificate and the application gene certificate of the clan leader in the network domain where it is located include S11 to S13:
[0066] S11. Obtain the clan gene and the clan public key of the clan leader based on the clan leader gene certificate;
[0067] S12. Verify the digital signature of the application gene certificate based on the clan public key, obtain the clan gene of the application based on the application gene certificate. If the digital signature verification passes and the clan gene of the clan leader matches the clan gene of the application successfully, the identity authentication is successful;
[0068] S13. Obtain the program gene of the application based on the application gene certificate with successful identity authentication, and perform static trusted measurement on the application based on the program gene and the clan public key.
[0069] Among them, the clan gene includes clan information and an integrity signature value. The clan information includes the name of the previous-level clan leader, the domain address of the previous-level clan leader, the name of the clan leader's network domain, and the prefix of the clan leader's network domain address; the clan leader performs integrity encryption on the clan information based on the clan private key to obtain the integrity signature value. It should be noted that in the clan group gene of the founder leader in the network, the name of the previous-level clan leader is the name of the founder leader, and the domain address of the previous-level clan leader is the domain address of the founder leader.
[0070] Among them, the application gene certificate is issued by the clan leader in the network domain where the application is located when the application is released, and includes application gene main body information, an application public key, and an application gene signature. Among them, the application gene main body information is generated by the clan leader in the network domain where the application is located based on the clan leader name, the application name, the clan gene, the application permission gene, and the application program gene; the clan leader performs digital signature on the application gene main body information and the application public key based on the clan private key to obtain the application gene signature information, and obtains the application gene signature based on the application gene signature information and the signature algorithm. The clan leader name is used to identify the certificate issuer, the application name is used to identify the certificate owner, and the structure of the clan gene is the same as the structure of the clan gene in the clan leader gene certificate. As Figure 2 is the structure diagram of the application gene certificate.
[0071] Furthermore, verifying the digital signature of the application gene certificate based on the clan public key in S12 includes:
[0072] Decrypt the application signature information in the application gene signature based on the clan public key and the signature algorithm carried by the application signature to obtain a decrypted digest;
[0073] Calculate the message digest based on the application gene main body information and the application public key;
[0074] Compare whether the message digest is consistent with the decrypted digest. If they are consistent, the digital signature verification is successful; otherwise, the digital signature verification fails.
[0075] Furthermore, the application gene includes static information, dynamic information, and an integrity signature value. The static information includes the software version and software size; the dynamic information includes the resource file list, socket type, and socket port number. When the family head issues an application gene certificate to an application, the integrity signature value is obtained based on the family private key of the application and the static information.
[0076] Furthermore, in S13, obtaining the program gene of the application based on the successfully authenticated application gene certificate, and performing static trusted measurement on the application based on the program gene and the family public key includes:
[0077] Obtain the application program gene based on the application gene certificate;
[0078] Perform integrity verification on the static information based on the family public key and the integrity signature value of the application program gene;
[0079] Obtain the current static information of the application, and compare it with the static information that has passed the integrity verification in the program gene. If they are consistent, the static trusted measurement is successful; otherwise, it fails.
[0080] Furthermore, in step S2, performing dynamic trusted measurement on the application based on the application gene certificate during the running process of the application includes:
[0081] S21. Obtain the application program gene based on the application gene certificate;
[0082] S22. Obtain the dynamic information of the application based on the program gene, and the dynamic information includes the resource file list, socket type, and socket port number;
[0083] S23. Obtain the resource file list, socket type, and socket port number during the current running process of the application, and compare them with the application program gene. If they are consistent, the dynamic trusted measurement is successful; otherwise, identify.
[0084] Furthermore, in step S2, after the network entity fails to perform dynamic trusted measurement on the application during the running process of the application, it further includes:
[0085] The network entity forcibly stops the application;
[0086] The network entity performs trusted recovery on the application, that is, the trusted measurement service performs static trusted measurement on the application. If the static trusted measurement is successful, the application that has passed the static trusted measurement is reloaded.
[0087] Specifically, in step S3, when the applications access each other, the mutual identity authentication and access authorization based on each other's application gene certificates and patriarch gene certificates include:
[0088] S31. The applications mutually obtain each other's family genes and family public keys based on each other's patriarch gene certificates;
[0089] S32. Authenticate each other based on each other's family genes and family public keys;
[0090] S33. Obtain the application permission genes in the application gene certificate of the other party that passes the identity authentication;
[0091] S34. Perform access authorization on the other party based on the patriarch gene certificate and the application permission genes of the other party.
[0092] Among them, the application permission genes include resource access permission information encoding and integrity signature values; the resource access permissions include, by way of example: application ID, cross-network access permission (yes / no), accessible file types (configuration file / executable file), file access permissions (read / write / execute), socket types (domain socket / stream / datagram), socket port numbers (one or more), and network service types (connection-oriented / connectionless); optionally, the resource access permissions are encoded using a preset encoding rule to obtain resource access permission encoding information; when the family patriarch issues an application gene certificate to an application, the integrity signature value is obtained by encrypting the resource access permission encoding information based on the family private key.
[0093] Further, the authentication of each other based on each other's family genes and family public keys in S32 includes:
[0094] Obtain the family gene and family public key based on the other party's patriarch gene certificate, and obtain the signature algorithm based on the application gene certificate;
[0095] Verify the signature of the application gene certificate based on the family public key and the signature algorithm. If the signature verification fails, the identity authentication fails. If the signature verification is successful, proceed to the next step;
[0096] Match the family gene in the other party's application gene certificate with the family gene in the other party's patriarch gene certificate. If the match is recognized, the identity authentication fails. If the match is successful, it means that the other party's application gene certificate has not been tampered with, and proceed to the next step;
[0097] Obtain the other party's user public key and signature algorithm based on the other party's application gene certificate, and verify the signature of the random number signature sent by the other party's application. If the signature verification passes, the identity authentication is successful; otherwise, the authentication fails.
[0098] It should be noted that during the mutual identity authentication process between the two parties, each party provides the other with an application gene certificate, a random number for this authentication, and a random number signature obtained based on its own user private key and signature algorithm; the other party verifies the signature of the random number. Since the random number signature and verification process are common technical means for mutual identity authentication negotiation in the prior art, the present invention will not elaborate further on this.
[0099] Further, the access authorization for the other party's application based on the patriarch gene certificate and the permission gene of the other party's application in S34 includes:
[0100] Obtain the family gene and family public key based on the other party's patriarch gene certificate;
[0101] Perform integrity verification on the resource access permission coding information in the permission gene based on the integrity signature value in the family public key and the permission gene;
[0102] Perform access authorization for the other party's application based on the resource access permission coding information that passes the integrity verification.
[0103] Exemplarily, when the access between applications is cross-domain access, when one application a accesses another cross-domain application b: application a needs to first access the access authentication service of the access router in its own network domain, that is, application a and the access authentication service of the access router in its own network domain mutually perform identity authentication and access authorization on each other's applications based on the application gene certificate and the patriarch gene certificate of the other party; further, the routing application of the access router and the routing applications of the backbone routers (exemplarily including OSPF, IS-IS, RIP, BGP), the routing applications of the backbone routers and the routing applications of the access routers in another network domain, the access authentication service of the access router in another network domain, and application b in another network domain mutually perform identity authentication and access authorization based on each other's gene certificates and patriarch gene certificates. Thus, a cross-domain access network trust chain is established, that is, the trust chain of application a - multiple routing services - application b, realizing the secure authentication of cross-domain access.
[0104] Specifically, in step S4, the identity authentication and access authorization for the user based on the user gene certificate and the patriarch gene certificate of the user's network domain include:
[0105] S41. The application obtains the family gene and family public key of the other party based on the user's patriarch gene certificate;
[0106] S42. Perform identity authentication on the user based on the user's family gene and family public key;
[0107] S43. Obtain the permission gene in the user gene certificate of the user who passes the identity authentication;
[0108] S44. Perform access authorization on the user based on the patriarch gene certificate and the user's user permission gene.
[0109] Among them, the user gene certificate includes user gene main body information and a user gene signature. The user gene signature is obtained by signing the user gene main body information and the user public key based on the family private key and the signature algorithm. The gene main body information includes the patriarch name, the user name, the family gene, and the user permission gene; among them, the structures of the family gene and the user permission gene are the same as the corresponding structures in the application gene certificate. As Figure 3 is the structure diagram of the user gene certificate.
[0110] Furthermore, the authentication of the user based on the user's family gene and family public key in S42 includes:
[0111] Obtain the family gene and family public key based on the user's patriarch gene certificate, and obtain the signature algorithm based on the user gene certificate;
[0112] Verify the signature of the user gene certificate based on the family public key and the signature algorithm. If the signature verification fails, the authentication fails. If the signature verification is successful, continue to the next step;
[0113] Match the family gene in the user gene certificate with the family gene in the other party's patriarch gene certificate. If the matching recognition fails, the authentication fails. If the matching is successful, it means that the user gene certificate has not been tampered with, and continue to the next step;
[0114] Obtain the other party's user public key and signature algorithm based on the user gene certificate, and verify the signature of the random number generated from the user's Ukey. If the signature verification passes, the authentication is successful, otherwise the authentication fails.
[0115] It should be noted that during the process of the application authenticating the user, the user provides the user gene certificate, the random number generated by the Ukey for this authentication, and the random number signature obtained based on the user's own user private key and signature algorithm to the application; the application verifies the signature of the random number. Since the random number signature and the signature verification process are common technical means for authentication negotiation in the prior art, the present invention will not elaborate further.
[0116] Furthermore, when the loaded application is accessed by the user, if the user and the application are not in the same network domain, that is, when cross-domain access occurs, when the user accesses the application, each access router and backbone router through which the user passes, as well as the application accessed by the user, all authenticate the user based on the user gene certificate in turn; and when the various routing applications and the application accessed by the user are connected to each other, they authenticate and authorize each other based on the application gene certificates of the other party to which they are connected; finally, the application accessed by the user authorizes the user based on the user gene certificate.
[0117] In this embodiment, an endogeneous security network trust method based on family genes is disclosed, which can achieve mutual authentication and access authorization between applications in the same network domain or across domains, and implement identity authentication and access authorization for applications to users in the same domain or across domains. It is realized by integrating identity authentication and access control in the same gene certificate. Based on the gene certificate, identity discrimination and access control are performed on all network users using system resources, so that intruders cannot penetrate or bypass the identity authentication mechanism to wantonly access network resources, and the system security is greatly improved.
[0118] It should be noted that the above embodiments are based on the same inventive concept, and for the parts not repeatedly described, reference can be made to each other.
[0119] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.
Claims
1. A trusted-based secure network authentication method, characterized in that It includes the following steps: Before the network entity in the network loads an application, perform identity authentication and static trusted measurement on the application based on the patriarch gene certificate of the patriarch of the network domain family where it is located and the application gene certificate; The network entity loads the application that passes the identity authentication and static trusted measurement, and performs dynamic trusted measurement on the application based on the application gene certificate during the running process of the application; When the applications access each other, perform identity authentication and access authorization on each other based on the application gene certificates and the patriarch gene certificates of each other; When the application is accessed by a network user, perform identity authentication and access authorization on the user based on the user gene certificate and the patriarch gene certificate of the network domain where the user is located.
2. The authentication method according to claim 1, wherein The performing identity authentication and static trusted measurement on the application based on the patriarch gene certificate of the patriarch of the network domain family where it is located and the application gene certificate includes: Obtain the family gene and family public key of the patriarch based on the patriarch gene certificate; Verify the digital signature of the application gene certificate based on the family public key, obtain the family gene of the application based on the application gene certificate. If the digital signature verification passes and the family gene of the patriarch matches the family gene of the application successfully, the identity authentication is successful; Obtain the program gene of the application based on the application gene certificate that passes the identity authentication, and perform static trusted measurement on the application based on the program gene and the family public key.
3. The authentication method according to claim 2, wherein The application gene certificate includes application gene main body information, application public key and application gene signature, and the application gene signature is obtained by signing the application public key and the application gene main body information based on the family private key and the signature algorithm; Verifying the digital signature of the application gene certificate based on the family public key includes: Decrypt the application signature information in the application gene signature based on the family public key and the signature algorithm carried by the application signature to obtain a decryption digest; Calculate a message digest based on the application gene main body information and the application public key; Compare whether the message digest and the decryption digest are consistent. If they are consistent, the digital signature verification is successful; otherwise, the digital signature verification fails.
4. The authentication method according to claim 3, wherein The application gene main body information includes the patriarch name, application name, family gene, application permission gene and application program gene; The application program gene includes static information, dynamic information and integrity signature value; The performing static trusted measurement on the application includes: Obtain the application program gene based on the application gene certificate; Perform integrity verification on the static information based on the family public key and the integrity signature value of the application program gene; Obtain the current static information of the application, and compare it with the static information that passes the integrity verification in the program gene. If they are consistent, the static trusted measurement is successful; otherwise, it fails.
5. The authentication method according to claim 4, wherein The performing dynamic trusted measurement on the application based on the application gene certificate during the running process of the application includes: Obtain the application program gene based on the application gene certificate; Obtain the dynamic information of the application based on the program gene, and the dynamic information includes a resource file list, socket type and socket port number; Obtain the list of resource files, socket types, and socket port numbers during the current running process of the application, and compare them with the program gene. If they are consistent, the dynamic trusted measurement is successful; otherwise, identify.
6. The authentication method according to claim 5, characterized in that After the network entity fails to perform dynamic trusted measurement on the application during the running process of the application, it further includes: The network entity forcibly stops the application; The network entity performs trusted recovery on the application.
7. The authentication method according to claim 6, wherein The network entity performing trusted recovery on the application includes: the network entity performing static trusted measurement on the application and reloading the application for which the static trusted measurement is successful.
8. The authentication method according to claim 7, wherein When the applications access each other, mutually performing identity authentication and access authorization based on the application gene certificates and patriarch gene certificates of each other includes: The applications mutually obtain the family gene and family public key of each other based on the patriarch gene certificate of each other; Perform identity authentication on each other based on the family gene and family public key of each other; Obtain the permission gene in the application gene certificate of the other party that passes the identity authentication; Perform access authorization on the other party based on the patriarch gene certificate and the application permission gene of the other party.
9. The authentication method according to claim 8, wherein The permission gene includes resource access permission information encoding and integrity signature value; The performing access authorization on the other application based on the patriarch gene certificate and the permission gene of the other application includes: Obtain the family public key based on the patriarch gene certificate; Perform integrity verification on the resource access permission encoding information in the permission gene based on the family public key and the integrity signature value in the permission gene; Perform access authorization on the other application based on the resource access permission encoding information that passes the integrity verification.
10. The authentication method according to claim 9, wherein The user gene certificate includes user gene subject information and user gene signature. The user gene signature is obtained by signing the user gene subject information and user public key based on the family private key and signature algorithm. The gene subject information includes patriarch name, user name, family gene, and user permission gene; The performing identity authentication and access authorization on the user based on the user gene certificate and the patriarch gene certificate of the network domain where the user is located includes: The application obtains the family gene and family public key of the other party based on the patriarch gene certificate of the user; Perform identity authentication on the user based on the family gene and family public key of the user; Obtain the permission gene in the user gene certificate of the user who passes the identity authentication; Perform access authorization on the user based on the patriarch gene certificate and the user permission gene of the user.