Network security authentication method, device and system
By combining asymmetric encryption and hash algorithms with multidimensional matching of biometric data and decryption action commands, and utilizing haptic feedback devices, the vulnerability of USB key authentication to attacks has been solved, achieving a higher level of security for authentication.
Patent Information
- Application Number
- CN202511063083.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-10-31
AI Technical Summary
Existing USB key authentication methods are vulnerable to biometric forgery and USB key theft, resulting in insufficient security.
Asymmetric encryption algorithms are used to generate public and private keys. Combined with hash algorithms and digital certificates, identity authentication is achieved through multi-dimensional matching of biometric data and decryption action command data. Haptic feedback devices are used to provide invisible decryption action commands, reducing the risk of data leakage.
It improves the security level of identity authentication, reduces the risk of biometric data and decryption instructions being intercepted or tampered with during transmission, and enhances the ability to verify user identity.
Smart Images

Figure CN120880671A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security authentication technology, and more specifically, to a network security authentication method, apparatus, and system. Background Technology
[0002] Identity authentication technology is an effective solution developed to verify the identity of operators in computer networks. In the world of computer networks, all information, including user identity information, is represented by a specific set of data. Computers can only recognize a user's digital identity, and all authorizations granted to users are based on that digital identity. How can we ensure that the operator performing an operation using a digital identity is indeed the legitimate owner of that digital identity? In other words, how can we ensure that the operator's physical identity corresponds to their digital identity? Identity authentication technology aims to solve this problem. As the first line of defense for protecting network assets, identity authentication plays a crucial role.
[0003] Today, identity authentication has become a core cornerstone of cybersecurity. From mobile payments to remote work, from government services to industrial control, every network interaction relies on verifying the authenticity of the user's identity. However, emerging threats such as password leaks, AI face-swapping attacks, and biometric forgery are constantly challenging the reliability of traditional authentication systems. Identity authentication technology is undergoing a paradigm shift from "single verification" to "multi-dimensional trust," building a comprehensive protection system encompassing cryptography, biometrics, and behavioral analysis.
[0004] Currently, authentication methods built using USB keys can employ a combination of hardware and software to authenticate users based on built-in keys or digital certificates combined with fingerprint features or digital passwords. The biggest vulnerability of this authentication method lies in its ability to be compromised by malicious actors who forge biometric data and steal USB keys.
[0005] This disclosure aims to build a higher level of security for a USB key-based identity authentication system. Summary of the Invention
[0006] This invention provides a network security authentication method, apparatus, and system that can overcome some or all of the defects of the prior art.
[0007] According to a network security authentication method of the present invention, when authenticating the identity of the requesting party on the server side, it includes: The requester obtains signature data, digest data, and digital certificate. The signature data is obtained by encrypting the biometric data and decryption command data with the requester's private key. The digest data is obtained by calculating the biometric data and decryption command data with a hash algorithm. The digital certificate is issued by a certificate authority and contains the requester's public key. The signature data and decryption action command data are obtained by decrypting the signature data using the public key in the digital certificate. A hash algorithm is used to calculate the biometric data and decryption action instruction data obtained from the self-signed data, and the calculation results are compared with the digest data. The biometric data and decryption command data are matched with the password database located on the server. Complete the server-side authentication of the requesting client.
[0008] Preferably, the password database includes a biometric template corresponding to the requesting end and a decryption action instruction template; The process of matching biometric data and decryption command data with a password database located on the server includes: Match biometric data with biometric templates; Match the decryption action command data with the decryption action command template.
[0009] Preferably, the biometric template includes multiple sub-biometric templates arranged in sequence, and the biometric data includes multiple sub-biometric data arranged in sequence, wherein the number of the multiple sub-biometric data is consistent with the number of the multiple sub-biometric templates. The process of matching biometric data with biometric templates includes, The multiple sub-biometric data are matched one-to-one with the multiple sub-biometric templates according to their sorting.
[0010] Preferably, the decryption action instruction template includes multiple sub-decryption action instruction templates arranged sequentially corresponding to each sub-biometric template, and the decryption action instruction data includes multiple sub-decryption action instruction data arranged sequentially corresponding to the sub-biometric data. The step of matching the decryption action command data with the decryption action command template includes, Match the multiple sub-decryption action instruction data with the multiple sub-decryption action instruction templates.
[0011] Preferably, the number of the plurality of sub-decryption action instruction data is not less than the number of the plurality of sub-decryption action instruction templates; The step of matching the plurality of sub-decryption action instruction data with the plurality of sub-decryption action instruction templates includes, If the multiple sub-decryption action instruction data contains the multiple sub-decryption action instruction templates in a sorted manner, then the match is successful; otherwise, the match is unsuccessful.
[0012] Preferably, fingerprint data is used for biometric data, and press action command data is used for decryption action command data.
[0013] Preferably, biometric data and decryption command data are obtained based on an identity authentication device.
[0014] According to the present invention, a network security authentication device is used to perform server-side authentication of the requesting party's identity, including, The receiving unit is used to obtain signature data, digest data, and digital certificate from the requesting end. The signature data is obtained by encrypting the biometric data and decryption action instruction data with the private key of the requesting end. The digest data is obtained by calculating the biometric data and decryption action instruction data with a hash algorithm. The digital certificate is issued by a certificate authority and contains the public key of the requesting end. The first authentication unit is used to decrypt the signature data using the public key in the digital certificate, thereby obtaining biometric data and decryption action instruction data; The second authentication unit is used to calculate the biometric data and decryption command data obtained from the self-signed data using a hash algorithm, and to compare the calculation result with the digest data; and The third authentication unit is used to match biometric data and decryption command data with the password database located on the server.
[0015] According to a network security authentication system of the present invention, it is used to realize the identity authentication of the requesting party by the server, including any of the above-mentioned network security authentication devices.
[0016] The beneficial effects of this invention are as follows: It can collect and generate biometric data and decryption action command data. The biometric data and decryption action command data can be encrypted by the private key stored in the storage device and sent to the server along with the digital certificate. In this process, the encryption of the private key can reduce the risk of the biometric data and decryption action command data being intercepted or tampered with during transmission. The digital certificate issued by the certificate authority can reduce the risk of the public key or private key corresponding to the user being stolen or replaced. The digest data obtained by calculating the biometric data and decryption action instruction data using a hash algorithm can also be sent to the server. After receiving the signature data, the server can perform a hash operation on the biometric data and decryption action instruction data in the signature data and compare it with the digest data, thereby enabling the verification of the received data. Attached Figure Description
[0017] Figure 1 This is a block diagram of an identity authentication device disclosed herein; Figure 2 This is a schematic diagram of the structure of an identity authentication device disclosed herein; Figure 3 This is a schematic diagram of the structure of a secret command device disclosed herein; Figure 4 This is a half-section structural diagram of a secret command device disclosed herein; Figure 5 This is a schematic diagram of the structure of a haptic feedback device disclosed herein; Figure 6 This is a schematic diagram of the structure of a power rod disclosed herein; Figure 7 This is a schematic diagram of the structure of an adapter rod disclosed herein; Figure 8 This is a flowchart illustrating one of the network security authentication methods disclosed herein. Detailed Implementation
[0018] To further understand the content of this invention, the invention will be described in detail with reference to the embodiments. It should be understood that the embodiments are merely illustrative and not limiting of the invention.
[0019] Example 1 Seen in Figure 1-7 This embodiment provides an identity authentication device for a computer system, which integrates a fingerprint recognition device and a haptic feedback device that can work together to construct a password based on the user's biometrics and pressing actions, thereby achieving a higher level of security in identity authentication.
[0020] Combination Figure 2 As shown, this embodiment provides an identity authentication device for a computer system, which includes an authentication device body 100, and the authentication device body 100 has, Interface device 110 is used to realize data interaction; Storage device for storing digital certificates, private keys, and fingerprint templates; Fingerprint recognition device 210, used to collect fingerprint features; Pressure detection device 220 is used to detect the pressure borne by fingerprint recognition device 210; The haptic feedback device 230 is used to provide different tactile feedback to the fingerprint recognition device 210 when the pressure applied at the fingerprint recognition device 210 is different; and The control device is used to control the tactile feedback device 230 to provide tactile feedback to the fingerprint recognition device 210 based on the pressure detection device 220 when the fingerprint feature data and the fingerprint feature template are successfully matched; and is used to generate biometric data based on fingerprint features, generate decryption action command data based on tactile action, encrypt the biometric data and decryption action command data with a private key to obtain signature data, and calculate digest data with a hash algorithm on the biometric data and decryption action command data.
[0021] The identity authentication device disclosed herein can be used by the user on the requesting end, thereby realizing the identity authentication of the user on the requesting end; Firstly, it can collect and generate biometric data and decryption action command data. This biometric data and decryption action command data can be encrypted with the private key stored in the storage device and sent to the server along with the digital certificate. In this process, the encryption of the private key can reduce the risk of the biometric data and decryption action command data being intercepted or tampered with during transmission. The digital certificate issued by the certificate authority can reduce the risk of the public key or private key corresponding to the user being stolen or replaced. Secondly, the digest data obtained by calculating the biometric data and decryption action instruction data using a hash algorithm can also be sent to the server. This allows the server to perform a hash operation on the biometric data and decryption action instruction data within the signature data after receiving the signature data, and then compare it with the digest data, thereby enabling the verification of the received data. Third, the control device can only control the haptic feedback device 230 to perform an action when the fingerprint feature at the fingerprint recognition device 210 successfully matches the fingerprint feature template; that is, when a non-actual user uses the authentication device 100 disclosed herein, the haptic feedback device 230 will not act, which makes it impossible to generate decryption action command data; thereby reducing the risk caused by the theft of the identity authentication device. Fourth, the haptic feedback device 230 can provide haptic feedback based on human perception rather than visual means. The intensity and duration of the haptic feedback can constitute decryption action command data, which reduces the risk of leakage of decryption action command data when users use the authentication device body 100 of this disclosure in daily life.
[0022] It is understandable that a user's public and private keys can be generated based on asymmetric encryption algorithms, and digital certificates can be obtained by processing the public key through a third-party certificate authority; this part is a relatively mature existing technology, and will not be elaborated in this disclosure.
[0023] Combination Figure 3As shown in this disclosure, the pressure detection device 220 may include an annular strain gauge 221, which may be disposed below the fingerprint recognition device 210 and provide support for the fingerprint recognition device 210.
[0024] This allows the pressure detection device 220 to detect the compressive stress at the fingerprint recognition device 210. When different pressing pressures are applied to the fingerprint recognition device 210, the fingerprint recognition device 210 will not undergo significant displacement, making it difficult to illegally monitor the pressure applied to the fingerprint recognition device 210.
[0025] In this disclosure, the haptic feedback device 230 is used to provide different intensities of impact to different areas of the fingerprint recognition device 210 from below.
[0026] This allows the haptic feedback device 230 to directly act on the fingerprint recognition device 210. In other words, during the generation of decryption action command data, the user needs to maintain a specific pressing pressure for a specific duration. This specific pressing pressure is determined by the intensity and area of the impact provided by the haptic feedback device 230, and the specific duration is determined by the number of impacts. This generation of decryption action command data based on perception can effectively reduce the risk of being compromised by means such as biometric forgery.
[0027] The fingerprint recognition device 210, pressure detection device 220 and tactile feedback device 230 disclosed herein are integrated into a password device 120. The password device 120 includes a housing 241 with an opening at the top and an annular cover plate 242 disposed at the opening at the top of the housing 241. A mounting cavity 243 is formed between the housing 241 and the annular cover plate 242. The fingerprint recognition device 210, pressure detection device 220 and tactile feedback device 230 are disposed sequentially from top to bottom in the mounting cavity 243.
[0028] This allows the command device 120 to be formed as a separate, independent component, which is beneficial for production assembly.
[0029] The tactile feedback device 230 disclosed herein has a carrier post 231, the upper part of the carrier post 231 extends outward to form an overlapping ring portion 232, and the inner wall of the mounting cavity 243 has a support ring portion 244 for cooperating with the overlapping ring portion 232. The carrier post 231 is fixedly mounted on the support ring portion 244 through the overlapping ring portion 232. A first mounting space 310 is formed between the upper end face of the carrier post 231 and the annular cover plate 242, and the fingerprint recognition device 210 and the pressure detection device 220 are disposed in the first mounting space 310.
[0030] The above structure is simple, reasonable, and easy to implement.
[0031] The carrier column 231 of this disclosure is provided with multiple installation channels 233 spaced circumferentially, and the installation channels 233 are provided axially through the carrier column 231. An impact assembly is provided in the installation channel 233, which includes an impact rod 244, a connecting rod 245 and a power rod 246 arranged sequentially from top to bottom in the installation channel 233. The power rod 246 is rotatably provided in the lower part of the installation channel 233 through a bearing (not shown in the figure). The connecting rod 245 is slidable in the axial direction and non-rotatable in the circumferential direction in the upper part of the installation channel 233. The impact rod 244 cooperates with the connecting rod 245 through a spring member 247. A connecting structure is formed between the connecting rod 245 and the power rod 246. The connecting structure is used to convert the rotation of the power rod 246 into the up and down movement of the connecting rod 245. The impact rod 244 is pressed against the fingerprint recognition device 210 through the spring member 247. The impact rod 244 is used to generate an impact at the fingerprint recognition device 210 following the up and down movement of the connecting rod 245.
[0032] Based on the above, impacts can be generated in different areas of the fingerprint recognition device 210, which helps users perceive impacts of different intensities.
[0033] The number of mounting channels 233 and impact components can be two, three, or four. That is, the haptic feedback device 230 can provide impacts of different intensities in two, three, or four different areas. It is understandable that although the more mounting channels 233 and impact components there are, the lower the possibility of the decryption action command being cracked, considering the human body's perception and differentiation of different zones, it is better to set the number of mounting channels 233 and impact components to two, three, or four.
[0034] The adapter structure includes a first protrusion structure 248 disposed on the upper end of the power rod 246 and a second protrusion structure 249 disposed on the lower end of the adapter rod 245. The first protrusion structure 248 forms a guide surface on one side and a vertical surface on the other side. The guide surface of the first protrusion structure 248 and the corresponding upper end surface of the power rod 246 form a travel path for cooperating with the second protrusion structure 249.
[0035] Based on the above, when the power rod 246 rotates, the second protrusion structure 249 travels along the guide surface to the highest point and then instantly falls to the corresponding upper end face of the power rod 246 at the vertical plane. This instantaneous displacement can be transmitted to the impact rod 244 through the spring member 247 to form an impact action.
[0036] It is understandable that the number of first protrusion structures 248 and second protrusion structures 249 affects the number of impact actions of the impact rod 244 during one rotation of the power rod 246; in order to allow the user to perceive the impact more clearly, the number of both the first protrusion structure 248 and the second protrusion structure 249 can be set to 1. Figure 5 and6 (All shown are 6).
[0037] The inner wall of the mounting channel 233 is provided with an axially oriented positioning groove (not shown in the figure), and the outer wall of the adapter rod 245 is provided with a positioning key (not shown in the figure) that mates with the positioning groove. This allows the adapter rod 245 to slide axially and be non-rotatable circumferentially in mate with the mounting channel 233.
[0038] The springs 247 at different impact components can also be configured to provide different levels of clamping force. This allows the impact components to provide different impact magnitudes in different areas, thereby better facilitating the user's perception of different tactile feedback intensities.
[0039] Specifically, the upper end of the adapter rod 245 can be provided with a slot structure, the lower end of the impact rod 244 can be provided with a plug structure for insertion into the slot structure, and the spring member 247 can be provided between the slot structure and the plug structure. By providing spring members 247 with different elastic coefficients at different impact components, or by providing different spacing between the slot structure and the plug structure at different impact components, different impact forces can be provided.
[0040] In this disclosure, a second mounting space 320 can be formed between the lower end face of the carrier column 231 and the bottom wall of the housing 241, and the power rod 246 can extend into the second mounting space 320; a motor mounting hole can be provided at the mounting channel 233 corresponding to the carrier column 231, and a motor 251 can be installed in the motor mounting hole. The output shaft of the motor 251 and the carrier column 231 can transmit power through a gear set 252.
[0041] Based on the above, the rotation control of the power rod 246 can be achieved more effectively.
[0042] Example 2 Based on the identity authentication device for a computer system proposed in Embodiment 1 of this disclosure, this disclosure also provides an identity authentication method for a computer system, which includes the following steps. Generate public and private keys corresponding to the user's identity based on an asymmetric encryption algorithm; A digital certificate is obtained by processing the public key through a certificate authority. Collect users' fingerprint data and construct fingerprint feature templates; Storing digital certificates, private keys, and fingerprint templates in a storage device; When a user presses their finger on the fingerprint recognition device 210, the fingerprint recognition device 210 collects the current fingerprint data, and the pressure detection device 220 collects the current pressing pressure. When the current fingerprint data is successfully matched with the fingerprint feature template, the tactile feedback device 230 controls the current pressing pressure to provide different tactile actions to the fingerprint recognition device 210. Biometric data is generated based on the current fingerprint data at each press action, and decryption action command data is generated based on the tactile intensity and duration provided by the tactile feedback device 230 at each press action. The signature data is obtained by encrypting the biometric data and decryption action command data with a private key, and the digest data is obtained by calculating the biometric data and decryption action command data with a hash algorithm. The signature data, digest data, and digital certificate are sent to the server via the interface device 110 to complete the authentication of the user on the requesting end.
[0043] Based on the above, a higher level of security authentication can be achieved.
[0044] Specifically, if the current fingerprint data fails to match the fingerprint feature template, the haptic feedback device 230 will not activate; the fingerprint feature template can collect fingerprint data from multiple different fingers of the same user; the decryption action command data only collects relevant data during the period when the fingerprint recognition device 210 is held down.
[0045] Taking a practical application scenario as an example, the fingerprint feature template includes fingerprint data from three different fingers of the same user. The tactile feedback device 230 has four impact components driven by different corresponding motors 251. These four impact components are distributed clockwise in the upper, right, lower, and left directions, respectively. Each time the power rod 246 in the impact component rotates once, the impact rod 244 generates one impact action. At this time, the four impact components can be numbered as 00 (upper), 01 (right), 10 (lower), and 11 (left). The fingerprint data of the three different fingers can also be numbered as 001 (right thumb), 010 (left thumb), and 011 (right index finger). The decryption actions that the user needs to perform at the fingerprint recognition device 210 are set as follows: The fingerprint recognition device 210 is pressed by the finger corresponding to number 001 (right thumb), which triggers the impact component number 01 (right) to impact twice and the impact component number 10 (bottom) to impact three times. The fingerprint recognition device 210 is pressed by the finger corresponding to number 010 (left thumb), which triggers the impact component number 11 (left) to impact 4 times and the impact component number 00 (top) to impact 2 times. The fingerprint recognition device 210 is pressed by the finger corresponding to number 011 (right index finger), which triggers the impact component number 00 (above) to impact 4 times; The actual execution process can be as follows: Control the finger corresponding to number 001 (i.e., the right thumb) to press the fingerprint recognition device 210, keep the corresponding finger from leaving the fingerprint recognition device 210, change the pressing pressure, hold the impact twice after feeling the impact from the right, then change the pressing pressure, hold the impact three times after feeling the impact from the bottom, and then the first action can be completed. Control the finger corresponding to number 010 (i.e., the left thumb) to press the fingerprint recognition device 210, keep the corresponding finger from leaving the fingerprint recognition device 210, change the pressing pressure, hold the impact 4 times after feeling the impact from the left, then change the pressing pressure, hold the impact 2 times after feeling the impact from the top, and then the second action can be completed. Control the finger corresponding to number 011 (i.e., the right index finger) to press the fingerprint recognition device 210, keep the corresponding finger from leaving the fingerprint recognition device 210, change the pressing pressure, and after feeling the impact from the top, hold the impact 4 times, and then the third action can be completed.
[0046] During the above process, the control device will match the fingerprint data collected by the fingerprint recognition device 210 with the fingerprint feature template, and will only control the haptic feedback device 230 to control the corresponding impact component to act based on the different pressing pressures detected by the pressure detection device 220 when the matching is successful. The control device can be configured with four pressure threshold ranges, for example... When the compressive stress F detected by the pressure detection device 220 satisfies the relationship a≤F≤b, the control device controls the motor 251 corresponding to the impact component numbered 00 (above) to operate. When the compressive stress F detected by the pressure detection device 220 satisfies the relationship c≤F≤d, the control device controls the motor 251 corresponding to the impact component numbered 01 (right) to operate. When the compressive stress F detected by the pressure detection device 220 satisfies the relationship e≤F≤f, the control device controls the motor 251 corresponding to the impact component numbered 10 (below) to operate. When the compressive stress F detected by the pressure detection device 220 satisfies the relationship g≤F≤h, the control device controls the motor 251 corresponding to the impact component numbered 11 (left) to operate.
[0047] After the first to third actions mentioned above are completed, the corresponding fingerprint data numbers of the sequentially executed actions can be encoded to obtain biometric data, and the decryption action command data can be obtained by sequentially encoding the motor operation data corresponding to the impact component during each action.
[0048] Taking the first action as an example, the theoretical original decryption action command data should be "0101101010". This data can be obtained by relying on the running time of the corresponding motor 251. For example, when the motor 251 corresponding to the number 01 rotates once, "01" is recorded once. In actual implementation, the motor 251 can be, for example, a stepper motor, and the number of rotations of the motor can be known based on the number of pulses driven by the motor. In reality, when a user performs a pressing action, it is difficult to ensure that only the required impact component is triggered. For example, in the first action, the user first triggers the impact component numbered 00 once, then triggers the impact component numbered 01 three times, then triggers the impact component numbered 11 twice, and then triggers the motor component numbered 10 five times. The corresponding original decryption action command data should be "0001010111111010101010". Although this original decryption action command data introduces noise, it still contains the correct action sequence and can be matched and judged based on the method described below, thereby improving the fault tolerance rate.
[0049] It is understandable that the decryption action command data can be obtained by concatenating and encoding the original decryption action command data of the three actions.
[0050] Example 3 Seen in Figure 8 Based on the identity authentication device provided in Embodiment 1 and the identity authentication method provided in Embodiment 2, this embodiment provides a network security authentication method, which includes, when authenticating the identity of the requesting party on the server side, the following steps: The requester obtains signature data, digest data, and digital certificate. The signature data is obtained by encrypting the biometric data and decryption command data with the requester's private key. The digest data is obtained by calculating the biometric data and decryption command data with a hash algorithm. The digital certificate is issued by a certificate authority and contains the requester's public key. The signature data is decrypted using the public key in the digital certificate to obtain biometric data and decryption action command data; A hash algorithm is used to calculate the biometric data and decryption action instruction data obtained from the self-signed data, and the calculation results are compared with the digest data. The biometric data and decryption command data are matched with the password database located on the server. Complete the server-side authentication of the requesting client.
[0051] Based on the above, the authentication of the requesting party by the server side can be achieved more effectively.
[0052] The secret code database includes biometric templates corresponding to the requesting end and decryption action instruction templates; The process of matching biometric data and decryption command data with a password database located on the server includes: Match biometric data with biometric templates; Match the decryption action command data with the decryption action command template.
[0053] This enables dual and multi-dimensional identity authentication, improving security.
[0054] The biometric template includes multiple sub-biometric templates arranged in sequence, and the biometric data includes multiple sub-biometric data arranged in sequence. The number of the multiple sub-biometric data is consistent with the number of the multiple sub-biometric templates. The process of matching biometric data with biometric templates includes, The multiple sub-biometric data are matched one-to-one with the multiple sub-biometric templates according to their sorting.
[0055] Based on the above, more complex password combinations can be achieved, which can effectively improve the security of identity authentication.
[0056] The decryption action instruction template includes multiple sub-decryption action instruction templates that are sequentially ordered and correspond to each sub-biometric feature template, and the decryption action instruction data includes multiple sub-decryption action instruction data that are sequentially ordered and correspond to the sub-biometric feature data. The step of matching the decryption action command data with the decryption action command template includes, Match the multiple sub-decryption action instruction data with the multiple sub-decryption action instruction templates.
[0057] Based on the above, more complex password combinations can be achieved, which can effectively improve the security of identity authentication.
[0058] The number of the plurality of sub-decryption action instruction data is not less than the number of the plurality of sub-decryption action instruction templates; The step of matching the plurality of sub-decryption action instruction data with the plurality of sub-decryption action instruction templates includes, If the multiple sub-decryption action instruction data contains the multiple sub-decryption action instruction templates in a sorted manner, then the match is successful; otherwise, the match is unsuccessful.
[0059] This can improve the fault tolerance rate.
[0060] The biometric data uses fingerprint data, and the decryption action command data uses press action command data. This means it can be implemented based on the methods and apparatus described in Embodiments 1 and 2.
[0061] The biometric data and decryption action command data are obtained based on the identity authentication device in Example 1.
[0062] Based on the method provided in this embodiment, another objective of this disclosure is to provide a network security authentication device for implementing server-side authentication of the requesting party's identity, including: The receiving unit is used to obtain signature data, digest data, and digital certificate from the requesting end. The signature data is obtained by encrypting the biometric data and decryption action instruction data with the private key of the requesting end. The digest data is obtained by calculating the biometric data and decryption action instruction data with a hash algorithm. The digital certificate is issued by a certificate authority and contains the public key of the requesting end. The first authentication unit is used to decrypt the signature data using the public key in the digital certificate, thereby obtaining biometric data and decryption action instruction data; The second authentication unit is used to calculate the biometric data and decryption command data obtained from the self-signed data using a hash algorithm, and to compare the calculation result with the digest data; and The third authentication unit is used to match biometric data and decryption command data with the password database located on the server.
[0063] Based on the method provided in this embodiment, the purpose of this disclosure is also to provide a network security authentication system for implementing server-side authentication of the requesting party's identity, including the aforementioned network security authentication device.
[0064] It is readily understood that those skilled in the art can combine, split, or reorganize the embodiments provided in this application to obtain other embodiments, all of which do not exceed the protection scope of this application.
[0065] The present invention and its embodiments have been described above illustratively. This description is not restrictive, and the embodiments shown are only part of the embodiments of the present invention. The actual structure is not limited thereto. Therefore, if those skilled in the art are inspired by this description and design similar structures and embodiments without departing from the spirit of the present invention, they should all fall within the protection scope of the present invention.
Claims
1. A network security authentication method, which, when authenticating the identity of a requesting client on the server side, includes: Obtain signature data, digest data, and digital certificate from the requesting end; among them... The signature data is obtained by encrypting the biometric data and decryption command data with the private key of the requesting party. The digest data is obtained by calculating the biometric data and decryption command data with a hash algorithm. The digital certificate is issued by a certificate authority and contains the public key of the requesting party. The signature data and decryption action command data are obtained by decrypting the signature data using the public key in the digital certificate. A hash algorithm is used to calculate the biometric data and decryption action instruction data obtained from the self-signed data, and the calculation results are compared with the digest data. The biometric data and decryption command data are matched with the password database located on the server. Complete the server-side authentication of the requesting client.
2. The network security authentication method according to claim 1, characterized in that: The password database includes biometric templates corresponding to the requesting end and decryption command templates; The process of matching biometric data and decryption command data with a password database located on the server includes: Match biometric data with biometric templates; Match the decryption action command data with the decryption action command template.
3. The network security authentication method according to claim 2, characterized in that: The biometric template includes multiple sub-biometric templates arranged in sequence, and the biometric data includes multiple sub-biometric data arranged in sequence, wherein the number of the multiple sub-biometric data is consistent with the number of the multiple sub-biometric templates; The process of matching biometric data with biometric templates includes, The multiple sub-biometric data are matched one-to-one with the multiple sub-biometric templates according to their sorting.
4. The network security authentication method according to claim 3, characterized in that: The decryption action instruction template includes multiple sub-decryption action instruction templates that are sequentially ordered and correspond to each sub-biometric feature template; the decryption action instruction data includes multiple sub-decryption action instruction data that are sequentially ordered and correspond to the sub-biometric feature data. The step of matching the decryption action command data with the decryption action command template includes, Match the multiple sub-decryption action instruction data with the multiple sub-decryption action instruction templates.
5. A network security authentication method according to claim 4, characterized in that: The number of the plurality of sub-decryption action instruction data is not less than the number of the plurality of sub-decryption action instruction templates; The step of matching the plurality of sub-decryption action instruction data with the plurality of sub-decryption action instruction templates includes, If the multiple sub-decryption action instruction data contains the multiple sub-decryption action instruction templates in a sorted manner, then the match is successful; otherwise, the match is unsuccessful.
6. The network security authentication method according to claim 1, characterized in that: The biometric data uses fingerprint data, and the decryption action command data uses press action command data.
7. The network security authentication method according to claim 1, characterized in that: Biometric data and decryption command data are obtained based on an identity authentication device.
8. A network security authentication device for authenticating the identity of a requester on the server side, comprising, The receiving unit is used to obtain signature data, digest data, and digital certificate from the requesting end; wherein, The signature data is obtained by encrypting the biometric data and decryption command data with the private key of the requesting party. The digest data is obtained by calculating the biometric data and decryption command data with a hash algorithm. The digital certificate is issued by a certificate authority and contains the public key of the requesting party. The first authentication unit is used to decrypt the signature data using the public key in the digital certificate, thereby obtaining biometric data and decryption action instruction data; The second authentication unit is used to calculate the biometric data and decryption action instruction data obtained from the self-signed data using a hash algorithm, and to compare the calculation results with the digest data. as well as The third authentication unit is used to match biometric data and decryption command data with the password database located on the server.
9. A network security authentication system for implementing server-side authentication of the requesting party's identity, including the network security authentication device as described in claim 8.
Citation Information
Cited By
Network security server starting protection method and system based on fusion of quantum encryption and trusted computing
CN121547188A