Identity authentication method, system and device based on national secret technology, medium and equipment

By combining the SM2 algorithm with hardware security devices, this authentication method addresses the security vulnerabilities in operating system authentication, achieving strong security protection and anti-attack capabilities, and safeguarding user identity information and system stability.

CN121530623APending Publication Date: 2026-02-13BEIJING GUODIAN ZHISHEN CONTROL TONGDY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511503745.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing operating system authentication methods have security vulnerabilities, making it difficult to meet the requirements of independent and controllable security compliance. Furthermore, internationally used cryptographic algorithms pose potential supply chain risks and cannot effectively prevent attacks or ensure data security.

Method used

An identity authentication method combining the SM2 algorithm and hardware security devices is adopted. The hardware security device uses SM2 private key signing and combines it with national cryptographic authentication service for verification to ensure the security and accuracy of the identity authentication process.

Benefits of technology

It achieves high-strength security protection, enhances the operating system's resistance to attacks in the network environment, ensures the security of user identity information and the stability of the operating system, and prevents unauthorized users from logging in.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530623A_ABST
    Figure CN121530623A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of identity authentication, and provides an identity authentication method, system and device based on a national secret technology, a medium and equipment, and the method comprises the steps: responding to a user login operation, and receiving user login information; initiating an authentication request to the national secret authentication service through the identity authentication plug-in, and receiving a random number generated by the authentication service as a challenge value; sending the challenge value to the hardware security device, and receiving a returned signature result after the device signs by using an SM2 private key stored in the device; sending the signature result and the user digital certificate information to a national secret authentication service to trigger the validity verification of the digital certificate and the SM2 signature verification operation of the signature result; and finally, controlling the user login according to the result, if the signature verification is successful, approving the login, and if the signature verification is failed, refusing the login. According to the embodiment of the invention, the security protection capability of user identity authentication of the operating system is enhanced, the anti-attack capability of the operating system in a network environment is ensured, and the security of system data is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of identity authentication, in particular to an identity authentication method, system and device based on a national cryptographic technology, a medium and equipment. BACKGROUND

[0002] With the promotion of the digital transformation wave, industrial control systems are widely used in various fields. As the core of computing devices, the importance of the identity authentication mechanism of the operating system is increasingly prominent. It is the first line of defense to protect data assets and privacy security. In the current situation of deepening digitalization and increasingly complex network attack methods, the traditional operating system identity authentication method has been difficult to meet the security needs. Once the industrial control system is attacked, it may lead to production stagnation, data leakage and other serious consequences, causing huge losses to enterprises and society.

[0003] In related technologies, the "username + password" single-factor authentication method has weak strength and is vulnerable to threats such as brute force cracking and phishing attacks. Although multi-factor authentication technologies such as integrated biometric recognition and hardware tokens have emerged, their cores are generally built on international general-purpose cryptographic algorithms such as RSA, ECC and SHA, which have potential supply chain security risks and are difficult to meet the mandatory compliance requirements of the security level protection system for the self-controllable commercial cryptographic technology. SUMMARY

[0004] The embodiments of the present disclosure at least provide an identity authentication method, system, device, medium and equipment based on a national cryptographic technology. By introducing the combination of the SM2 algorithm and the hardware security device, high-strength security protection in the authentication process is realized, the anti-attack ability and security of the operating system in the network environment are improved, and the security of the user's identity information and the stability of the operating system are thus ensured.

[0005] The embodiments of the present disclosure provide an identity authentication method based on a national cryptographic technology, comprising: In response to a user login operation, receiving user login information; and initiating an authentication request to a national cryptographic authentication service through an identity authentication plug-in, and receiving a random number generated by the national cryptographic authentication service as a challenge value; Sending the challenge value to a hardware security device associated with the user, and receiving a signature result returned by the hardware security device after signing the challenge value using an internally stored SM2 private key; Sending the signature result and user digital certificate information corresponding to the user to the national cryptographic authentication service to trigger the national cryptographic authentication service to verify the validity of the user digital certificate information and perform an SM2 signature verification operation on the signature result; receive a signature verification result from the national cryptographic authentication service, and control user login according to the signature verification result: if the signature verification succeeds, approve login, and if the signature verification fails, reject login.

[0006] The identity authentication system based on the national cryptographic technology comprises a client device, a hardware security device, and a national cryptographic authentication server. The client device is installed with an identity authentication plug-in configured to communicate with the national cryptographic authentication server and the hardware security device. The hardware security device is detachably connected to the client computing device, internally stores an SM2 private key and a digital certificate of a user, and is configured to sign a received challenge value using the SM2 private key after verifying that a user PIN code is correct. The national cryptographic authentication server communicates with the client device. The identity authentication plug-in is configured to initiate an authentication request to the national cryptographic authentication server in response to a user login operation, receive a challenge value returned by the national cryptographic authentication server, and forward the challenge value to the hardware security device, receive a signature result returned by the hardware security device, and send the signature result and a user digital certificate obtained from the hardware security device to the national cryptographic authentication server, and control completion of a user login process according to a signature verification result returned by the national cryptographic authentication server. The national cryptographic authentication server is configured to generate a random number as the challenge value and return the challenge value to the identity authentication plug-in in response to the authentication request, verify validity of the digital certificate and perform SM2 signature verification on the signature result after receiving the signature result and the user digital certificate, and return a signature verification result to the identity authentication plug-in.

[0007] The identity authentication apparatus based on the national cryptographic technology comprises: An authentication request module is configured to receive user login information in response to a user login operation, initiate an authentication request to a national cryptographic authentication service through an identity authentication plug-in, and receive a random number generated by the national cryptographic authentication service as a challenge value. A data sending module is configured to send the challenge value to a hardware security device associated with a user, and receive a signature result returned by the hardware security device after the hardware security device signs the challenge value using an internally stored SM2 private key. An information authentication module is configured to send the signature result and user digital certificate information corresponding to the user to the national cryptographic authentication service to trigger the national cryptographic authentication service to perform validity verification on the user digital certificate information and SM2 signature verification on the signature result. The login control module is configured to receive a signature verification result from the national cryptography authentication service, and control user login according to the signature verification result: if the signature verification succeeds, the login is approved, and if the signature verification fails, the login is rejected.

[0008] The present disclosure provides a computer device, comprising a processor, a memory and a bus, the memory stores machine readable instructions executable by the processor, when the computer device is running, the processor and the memory communicate through the bus, the machine readable instructions are executed by the processor to perform the identity authentication method based on the national cryptography technology as described in any possible implementation manner.

[0009] The present disclosure provides a computer readable storage medium, the computer readable storage medium stores a computer program, the computer program is run by the processor to implement the identity authentication method based on the national cryptography technology as described in any possible implementation manner.

[0010] The identity authentication method, system, device, medium and equipment based on the national cryptography technology provided in the present disclosure can effectively ensure the security and accuracy of the identity authentication process by introducing the SM2 algorithm and the combination of the hardware security device, prevent attacks of forging identity information or cracking the authentication mechanism. The high-strength security protection in the authentication process is realized, the anti-attack ability and security of the operating system in the network environment are further improved, so as to protect the security of the identity information of the user and the stability of the operating system, effectively prevent the login of unauthorized users, and protect the data security of the system.

[0011] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, the following preferred embodiments are described in detail below, and the accompanying drawings are described as follows. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings required in the embodiments will be briefly introduced below. The drawings herein are incorporated into the specification and form a part of the specification, which illustrate the embodiments consistent with the present disclosure, and are used to illustrate the technical solutions of the present disclosure together with the specification. It should be understood that the following drawings only show some embodiments of the present disclosure, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor.

[0013] Figure 1 A flowchart of an identity authentication method based on the national cryptography technology provided by the embodiments of the present disclosure is shown; Figure 2 A flowchart of a user registration method provided by the embodiments of the present disclosure is shown; Figure 3 A structural schematic diagram of an identity authentication system based on a national cryptographic technology is shown. Figure 4 A structural schematic diagram of an identity authentication device based on a national cryptographic technology is shown. Figure 5 A structural schematic diagram of a computer device is shown. DETAILED DESCRIPTION

[0014] To make the objectives, technical solutions and advantages of the embodiments of the present disclosure clearer, the following will be combined with the accompanying drawings of the embodiments of the present disclosure to make a clear and complete description of the technical solutions in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments. The components of the embodiments of the present disclosure described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present disclosure provided in the accompanying drawings is not intended to limit the scope of the claimed present disclosure, but only represents selected embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.

[0015] It should be noted that: similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0016] The term "and / or" herein is only to describe an associated relationship, which means that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone. In addition, the term "at least one" herein means any one of a plurality or any combination of at least two of a plurality, for example, including at least one of A, B and C can mean including any one or more elements selected from the set consisting of A, B and C.

[0017] Under the impetus of digital transformation, the operating system identity authentication mechanism in the industrial control system has become a key defense line to protect data assets and privacy security. At present, most operating systems still mainly use the single-factor authentication mode of "username + password", but this mode has serious security vulnerabilities and is vulnerable to malicious attack means such as brute force cracking, dictionary attack, phishing attack and keylogging. At the same time, the phenomenon of users setting weak passwords is common, which seriously undermines the security strength and makes it difficult to effectively protect system security.

[0018] Further, although some operating systems have attempted to integrate second factors such as biometrics (e.g., fingerprints, facial recognition) for multi-factor authentication, there are still risks, and the authentication core is mostly based on international general-purpose cryptographic algorithms (e.g., RSA, ECC) or private protocols. There are mandatory compliance requirements for self-controllable cryptographic technologies in the field of key information infrastructure in China, and the existing authentication methods cannot meet this demand.

[0019] Research has found that the existing authentication scheme has defects in multi-factor combination, and each factor is mostly a simple logical combination, without building a secure closed loop with domestic cryptographic technology as the trust root. For example, if the generation, transmission, and verification process of dynamic password (OTP) or digital certificate do not use national cryptographic algorithms, the security of the entire authentication system depends on foreign cryptographic standards, which poses a risk to the safe and stable operation of the system. At the same time, there is a problem of disconnection in the authentication chain from the user identity to the operating system kernel, and the communication channel between the external authentication device and the operating system kernel lacks high-strength encryption protection, the authentication result is easy to be intercepted or tampered with by malicious software, and a complete domestic trust chain from hardware, firmware to operating system cannot be formed, resulting in obvious security vulnerabilities.

[0020] In related technologies, biometric authentication based on the FIDO (Fast Identity Online) standard uses a special FIDO security key or a device built-in trusted platform module (TPM) to bind the user's biometric features with a locally generated asymmetric key pair, and uses FIDO U2F or UAF protocols to rely on ECC algorithms for authentication. This method can improve user experience, but the technical standards and cryptographic algorithms are dominated by international organizations, and are usually only used as a Web application authentication method, with low integration with the operating system kernel, making it difficult to achieve end-to-end national cryptographic compliance. Software dynamic password authentication based on TOTP / HOTP algorithms generates a dynamic password that changes over time as a second factor through a user's mobile phone APP (e.g., Google Authenticator), uses OATH standards, and is based on SHA-1 and other hash algorithms. This scheme has low implementation cost, but the dynamic password is vulnerable to phishing attacks, and the seed key is stored in software form, which is less secure than hardware carriers and cannot resist malicious software attacks, and does not use national cryptographic algorithm systems.

[0021] Therefore, in-depth analysis shows that the related technical solutions have improved the operating system authentication security to some extent, but there are still core defects. In terms of cryptographic technology, the core cryptographic algorithms of existing solutions (such as PKI smart card, FIDO, TOTP) are based on international algorithm standards such as RSA, ECC, and SHA, and the technical system is dominated by foreign organizations and institutions. China's key information infrastructure and important field system security faces potential "backdoor" risks and technical dependence, which cannot meet the core requirements of the national network security protection system and the "Cryptography Law" for the use of commercial cryptographic protection. Once the underlying international algorithm is cracked or subject to technical sanctions, the entire authentication system will collapse, posing a serious threat to national information security.

[0022] Based on the above research, the identity authentication method, system, device, medium and equipment based on the national cryptographic technology are provided in the embodiments of the present disclosure. Specifically, in response to a user login operation, user login information is received; an authentication request is initiated to a national cryptographic authentication service through an identity authentication plug-in, and a random number generated by the authentication service is received as a challenge value; the challenge value is sent to a hardware security device, and a returned signature result signed by the SM2 private key stored in the device is received; the signature result and user digital certificate information are sent to the national cryptographic authentication service to trigger SM2 signature verification and signature result verification operations on the validity of the digital certificate; and finally, the user login is controlled according to the result, and if the signature verification is successful, the login is approved, and if the signature verification fails, the login is denied.

[0023] In the embodiments of the present disclosure, by introducing the SM2 algorithm and the combination of the hardware security device, the security and accuracy of the identity authentication process can be effectively ensured, the attack of forging identity information or cracking the authentication mechanism can be prevented, the high-strength security protection in the authentication process is realized, and the anti-attack ability and security of the operating system in the network environment are further improved, so as to protect the security of the identity information of the user and the stability of the operating system, effectively prevent the login of unauthorized users, and protect the data security of the system.

[0024] In order to facilitate the understanding of the present embodiment, first, the execution subject of the identity authentication method based on the national cryptographic technology provided by the present disclosure is introduced in detail. The execution subject of the identity authentication method based on the national cryptographic technology provided by the present disclosure is a computer device. The computer device can be a terminal device or a server. The terminal device can also be a mobile device, a user terminal, a terminal, a handheld device, a computing device, a vehicle-mounted device, a wearable device, etc. The server can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud storage, big data, and artificial intelligence platforms, etc. Basic cloud computing services. Optionally, the method can also be applied to an implementation environment composed of a computer device and a server.

[0025] It is understood that the identity authentication method based on national cryptographic technology described in this invention is typically used in operating system login. In this scenario, by employing national cryptographic algorithms to perform rigorous and secure authentication of user identities, it can effectively prevent unauthorized users from logging into the system and ensure the security and confidentiality of data and functions within the operating system. However, it is equally applicable to other systems or applications requiring high-strength identity authentication, such as industrial control systems. Industrial control systems often control critical links in industrial production processes, involving numerous core process parameters, equipment operating status, and other important information. Once illegally intruded, it may lead to production accidents, equipment damage, or even endanger personnel safety. The identity authentication method based on national cryptographic technology of this invention has a high-strength encryption and authentication mechanism, which can build a security defense for industrial control systems, ensuring that only strictly authenticated legitimate personnel can access and operate the relevant systems, thus ensuring the stable and safe operation of industrial production. However, for ease of explanation and understanding, the following description will use operating system login as an example.

[0026] The identity authentication method based on national cryptographic technology provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings. See also Figure 1 The diagram shows a flowchart of an identity authentication method based on national cryptographic technology provided in this disclosure. The method includes the following steps S101 to S104: S101, in response to a user login operation, receive user login information; and initiate an authentication request to the national cryptographic authentication service through the identity authentication plugin, and receive a random number generated by the national cryptographic authentication service as a challenge value.

[0027] It can be understood that when the system responds to the user-initiated login operation, the user-input login information will be accepted to determine the legitimacy of the user's identity. Here, the user login information is used to identify the user's identity or verify the legitimacy of the user's identity to the system and the authentication service, which can include a PIN code, a system account and a password, etc. Among them, the PIN code is usually a specific sequence composed of numbers, as a personal identification number, which plays a role in relatively simple identity verification scenarios, such as in the preliminary identity verification link of some self-service equipment, the user needs to input the preset PIN code to prove the operation authority; the system account is a unique identifier registered by the user in the operating system, which is used to distinguish the identity of different users at the system level, for example, in the Linux operating system, each user will be assigned a unique system account when registering, and the system manages the user's file permissions, system settings and other personalized information through the account; the password is a character combination set by the user, which can contain numbers, letters and special symbols, which is used for identity verification when logging in, and its complexity directly affects the security of the account, such as the complex password set by the user containing uppercase and lowercase letters, numbers and special symbols, which can effectively improve the ability of the account to resist brute force attacks and other attacks.

[0028] It can be understood that after receiving the user login information, an authentication request can be initiated to the national secret authentication service through the identity authentication plug-in. Here, the identity authentication plug-in is a specially designed software module for identity authentication in the present disclosure, which has the ability to interact with external authentication services and can initiate an authentication request to the national secret authentication service through it.

[0029] In the present disclosure, the identity authentication plug-in is pre-integrated on the operating system, and when the operating system starts and is in a state that can receive user interaction, the plug-in is also automatically activated and in standby state, which can respond to the user login-related operation instructions forwarded by the operating system in real time, without the need for additional manual start or configuration operation by the user or administrator, and can realize the "plug and play" non-invasive security experience, greatly improving the convenience and timeliness of the identity authentication process startup.

[0030] Specifically, the national cryptographic authentication service is an authentication system based on relevant cryptographic algorithms and standards formulated by the National Cryptographic Administration of China, aiming to ensure the security and compliance in the process of information transmission and processing. At the same time, after initiating an authentication request to the national cryptographic authentication service, the national cryptographic authentication service will perform preliminary format checking and security evaluation on the received authentication request according to the pre-set security policy and verification process, to determine whether the request source is legal, the request data is complete and has not been tampered with. If the request passes the preliminary audit, the national cryptographic authentication service will call the signature verification server or hardware cryptographic device, combined with the current system time, device identifier and other dynamic factors, to generate a random number with high randomness and uniqueness. The national cryptographic authentication service can be an independent server, a cloud service or a software module integrated in a specific system, which is not limited here.

[0031] Further, after sending the challenge value to the user side, the user side needs to use its own legitimate private key and other security elements to process the challenge value and return the result, and the national cryptographic authentication service compares and analyzes the returned result with the expected result to determine the authenticity of the user's identity. The random number (i.e. challenge value) is a kind of unpredictable random data generated by the signature verification server called by the national cryptographic authentication service; the signature verification server will generate a new random number every time the user initiates a new login authentication request, to ensure the uniqueness of the login challenge value each time, to prevent security threats such as replay attacks. Here, the replay attack refers to the interception of legitimate authentication information by the attacker and the subsequent re-sending of these information for illegal authentication, while the generation of a new random challenge value each time ensures the independence and security of each authentication, so that the intercepted past authentication information cannot take effect in the new authentication process.

[0032] S102, send the challenge value to the hardware security device associated with the user, and receive the signature result returned by the hardware security device after signing the challenge value using the internally stored SM2 private key.

[0033] It can be understood that the hardware security device is a physical device with security storage and operation functions, such as a common U disk, which internally stores the private key and other key security information of the user. The hardware security device uses the internally stored SM2 private key to perform a signature operation on the challenge value. SM2 is an elliptic curve-based asymmetric encryption algorithm, which is a public key encryption algorithm standard issued by the National Cryptography Administration. The private key is a secret key used for signature and other operations, and only the legitimate user holds it. During signature, the hardware security device will perform mathematical operations on the challenge value and the private key according to the built-in SM2 algorithm rules to generate a unique signature value. After signing, the hardware security device returns the signature result to the system. Here, the signature result can include system account (used to identify the user system identity), password (additional element to enhance authentication security), signature value (used to verify user identity), and other information.

[0034] In some possible embodiments, to implement a more perfect and secure identity authentication process when the user logs in, and to ensure the close association of the user account and the hardware security device, before responding to the user login operation, the system database is referred to Figure 2 As shown in FIG. 2, the method can further include the following steps S201-S202: S201, in response to a user registration operation, receiving a system registration account and a registration password input by the user, and identifying hardware security device information currently connected by the user.

[0035] It can be understood that the user registration stage is the basis for building a secure authentication system. The system registration account is the unique identity of the user in the system, and the registration password is the password for protecting the account security. The hardware security device information currently connected by the user also needs to be identified during user registration. The hardware security device (such as a U disk) has high security and independence, and can provide additional security for the account. When the user connects the hardware security device for registration, the device information such as the model and serial number can be identified so as to be bound with the user account later.

[0036] S202, binding the system registration account input by the user with the hardware security device information, and storing the system registration account, the registration password, and the bound hardware security device information in the system database.

[0037] Specifically, by binding the system registration account with the hardware security device information, it can be ensured that each user account is uniquely corresponding to a specific hardware device, thereby effectively enhancing the security of the account. Storing the above related information in the system database allows the system to quickly and accurately retrieve this information for identity verification when the user logs in subsequently. When the user logs in again, the legality of the user's identity can be comprehensively and meticulously verified based on the information stored in the database combined with the feedback data of the hardware security device, effectively preventing illegal users from logging into the system and ensuring the safe and stable operation of the system.

[0038] Illustratively, since the user private key and other key information stored by the hardware security device are highly sensitive and will pose serious security risks to the user if illegally obtained or misused, in order to ensure that only legitimate users can use the hardware security device for signing and prevent illegal users from bypassing the authentication process, the following steps (1)-(3) can be included after sending the challenge value to the hardware security device: (1) sending the PIN code input by the user to the hardware security device for verification; (2) if the hardware security device returns a PIN code error message, terminating the login process and prompting an error; (3) if the hardware security device returns a PIN code correct message, triggering the hardware security device to perform a signing operation.

[0039] Specifically, the PIN code is a combination of numbers or characters set by the user in advance and can be used as the first line of defense for using the hardware security device. The user must input the correct PIN code to operate the device during identity authentication. Here, the PIN code input by the user can also be encrypted and sent to the hardware security device.

[0040] Further, if the hardware security device returns a PIN code error message, it indicates that the user has made a mistake, which may be a mistake or an attempt by an illegal user to crack it. At this time, to prevent illegal users from repeatedly attempting to guess the PIN code, the system terminates the login process and prompts an error, and can also limit the number of re-entries (such as locking after 6 failed PIN code verifications, requiring contact with the administrator to unlock) to enhance security. If the hardware security device returns a PIN code correct message, it indicates that the current operating user is a legitimate user, and the hardware security device can be triggered to perform a signing operation.

[0041] Here, the private key in the present disclosure never leaves the secure chip of the hardware security device, ensuring the uniqueness and non-replicability of the user's digital identity and greatly reducing the risk of identity fraud and data leakage.

[0042] S103, send the signature result and the user digital certificate information corresponding to the user to the national cryptographic authentication service to trigger the national cryptographic authentication service to verify the validity of the user digital certificate information and perform SM2 signature verification on the signature result.

[0043] It can be understood that the user digital certificate is an electronic document for proving the identity of the user and the legality of the public key. The user digital certificate information contains the identity information of the user, such as the name of the user, the unique identification number and other contents that can determine the identity of the user; and also contains the public key of the user, which is one-to-one corresponding to the private key stored in the hardware security device, that is, the public key is the public part of the private key, which is used for the receiver to verify the data signed by the private key; at the same time, the certificate also records the information of the certificate issuing authority, including the name of the issuing authority, digital signature and the like, which are used to confirm whether the source of the certificate is legal and reliable.

[0044] Exemplarily, in order to guarantee the security of data transmission and the integrity of the authentication process, the user digital certificate information in the present application is obtained from the hardware security device. After the hardware security device completes the signature operation on the challenge value, it encapsulates the user digital certificate information and the signature result, and then returns them to the system together. The system then sends these key information to the national cryptographic authentication service.

[0045] Specifically, after receiving these information, the national cryptographic authentication service will trigger two key operations: one is to verify the validity of the user digital certificate information. The national cryptographic authentication service will check whether the certificate is within the valid period according to strict standards and procedures, because each user digital certificate has a clear validity period, and the certificate will lose legal effect beyond this period. At the same time, it will also verify whether the certificate is issued by a legal certificate authority in the preset national cryptographic CA list. By checking the issuing agency information and the corresponding digital signature in the certificate, the authenticity and authority of the issuing agency can be confirmed. Only when the certificate is within the valid period and issued by a legal agency, the certificate will be considered valid. The second is to perform SM2 signature verification operation on the signature result. SM2 signature verification is a verification process based on SM2 asymmetric cryptography algorithm, which uses the public key contained in the user digital certificate (which corresponds to the private key used for signature in the hardware security device) to verify the signature result. In the verification process, the national cryptographic authentication service will perform mathematical operations and comparisons on the signature result and the original challenge value and other information according to the rules of the SM2 algorithm. If the verification is passed, it means that the signature is generated by the legal private key stored in the hardware security device, so the integrity of the data and the authenticity of the source can be confirmed, that is, the data has not been tampered with in the transmission process, and it indeed comes from a legal user; if the verification fails, it means that the signature may have a problem, the data may be tampered with or the signature does not come from a legal user, at which time the national cryptographic authentication service will reject the authentication request to ensure the security of the system and the reliability of the data.

[0046] S104, receiving the signature verification result from the national cryptographic authentication service, and controlling user login according to the signature verification result: if the signature verification is successful, approving the login, if the signature verification fails, refusing the login.

[0047] Here, the signature verification result explicitly indicates whether the signature is verified. According to this signature verification result, the user's login behavior can be controlled: if the signature verification is successful, it means that the user's identity is legal, and the user can be approved to log in; if the signature verification fails, it means that there may be security problems such as identity impersonation, and the user needs to be refused to log in, so as to ensure the security and reliability of the operating system login process.

[0048] In some possible embodiments, in order to build a multi-level security system, after the hardware authentication based on national cryptographic algorithm (such as SM2 signature verification) is successfully passed, traditional system account and password verification can also be selectively performed as a supplementary security layer. Specifically, the following steps (a)~(c) can be included: (a) verifying whether the system account and password input by the user match the pre-stored system user information; (b) if the system account and password do not match the pre-stored system user information, returning an error message, and locking the system account for a preset time after the number of consecutive errors reaches a preset threshold; (c) if the system account and password match the pre-stored system user information, completing user login.

[0049] Specifically, when verifying whether the user account password matches, the pre-stored information corresponding to the system account can be called from the pre-constructed and securely stored system user information database, and then the user-input password and the pre-stored password are compared and analyzed character by character and with high precision, while the format and validity of the system account are comprehensively checked, so as to determine whether the user-input system account and password completely match the pre-stored system user information.

[0050] In some possible embodiments, in order to further improve the security and accuracy of password verification, the SM3 algorithm can be used to verify the correctness of the password. The SM3 algorithm is a national standard hash algorithm with high security and collision resistance. When using the SM3 algorithm to verify the password, the user-input password is subjected to hash operation to generate a fixed-length hash value, and then the hash value is compared with the pre-stored password hash value in the database. If they are consistent, it means that the user-input password is correct; otherwise, it is determined that the password is incorrect. In this way, the risk of password leakage in the transmission and storage process can be effectively avoided, and the efficiency and security of password verification are improved.

[0051] Here, if the user-input system account and password are found not to match the pre-stored system user information after comparison, error information can be returned to the user to inform the user of login failure and prompt possible input problems, guiding the user to re-input the correct account and password. At the same time, an error counting mechanism can be started to count the number of consecutive error logins, and when the number of consecutive errors reaches a pre-set threshold, the system account can be automatically locked for a pre-set time according to the established security policy. In this way, malicious attackers can be effectively prevented from performing brute-force cracking by constantly trying different account and password combinations, the system is protected from illegal intrusion, and the stability and security of the system are maintained. For example, the pre-set threshold can be set to 5 times, and the pre-set locking time can be set to 30 minutes. When the user inputs the wrong account and password for 5 consecutive times, the system account will be locked for 30 minutes, and the user cannot attempt to log in again during this period.

[0052] Here, if the system account and password input by the user are verified to be completely matched with the pre-stored system user information, and the SM2 signature verification is passed, it is determined that the user is a legal user, and the user login process is successfully completed. At this time, the user can be provided with corresponding system functions and resource access permissions according to the user's permissions, so that the user can normally carry out business operations. The completion of the user login indicates that a secure and legal connection is established between the user and the system, and subsequent data interaction and business processing can be realized. For example, for an ordinary employee user, after successful login, the user can access the business system and data related to the user's work; for an administrator user, the user can have higher system management permissions to perform system configuration, user management and other operations.

[0053] The identity authentication method, system, device, medium and equipment based on the national secret technology provided in the embodiments of the present disclosure can effectively ensure the security and accuracy of the identity authentication process by introducing the SM2 algorithm and the combination of the hardware security device, prevent attacks of forging identity information or cracking the authentication mechanism. High-strength security protection is realized in the authentication process, and the anti-attack ability and security of the operating system in the network environment are further improved, so as to protect the security of the identity information of the user and the stability of the operating system, effectively prevent unauthorized user login, and protect the data security of the system.

[0054] Those skilled in the art can understand that in the above method of the specific implementation, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined by its function and possible internal logic.

[0055] Based on the same inventive concept, the embodiments of the present disclosure also provide an identity authentication system based on the national secret technology corresponding to the identity authentication method based on the national secret technology. Since the system in the embodiments of the present disclosure solves the problem by a similar principle to the above-mentioned identity authentication method based on the national secret technology, the implementation of the system can be referred to the implementation of the method, and the repeated parts will not be described herein.

[0056] Referring to Figure 3 FIG. 1 shows a schematic diagram of an identity authentication system based on the national secret technology provided by the embodiments of the present disclosure. The system includes a client device, a hardware security device and a national secret authentication server; The client device is installed with an identity authentication plug-in, which is configured to communicate with the national secret authentication server and the hardware security device; The hardware security device is detachably connected with the client computing device, internally stores the SM2 private key and digital certificate of the user, and is configured to sign the received challenge value using the SM2 private key after verifying that the user PIN code is passed; The national cryptographic authentication server communicates with the client device. The identity authentication plug-in is configured to: in response to a user login operation, initiate an authentication request to the national cryptographic authentication server; receive a challenge value returned by the national cryptographic authentication server, and forward the challenge value to the hardware security device; receive a signature result returned by the hardware security device, and send the signature result and a user digital certificate obtained from the hardware security device to the national cryptographic authentication server; and control an operating system to complete a user login process according to a signature verification result returned by the national cryptographic authentication server. The national cryptographic authentication server is configured to: in response to the authentication request, generate a random number as the challenge value and return the challenge value to the identity authentication plug-in; after receiving the signature result and the user digital certificate, verify validity of the digital certificate, and perform SM2 signature verification on the signature result; and return a signature verification result to the identity authentication plug-in.

[0057] Based on the same inventive concept, the embodiments of the present disclosure also provide a national cryptographic technology-based identity authentication device corresponding to the national cryptographic technology-based identity authentication method. Since the principle of the device in the embodiments of the present disclosure for solving the problem is similar to the above-mentioned national cryptographic technology-based identity authentication method of the embodiments of the present disclosure, the implementation of the device can be referred to the implementation of the method, and the repeated parts will not be described here.

[0058] Referring to Figure 4 Fig. 4 shows a schematic diagram of a national cryptographic technology-based identity authentication device 400 provided by the embodiments of the present disclosure. The device includes: An authentication request module 401 is configured to: in response to a user login operation, receive user login information; initiate an authentication request to a national cryptographic authentication service through an identity authentication plug-in, and receive a random number generated by the national cryptographic authentication service as a challenge value. A data sending module 402 is configured to: send the challenge value to a hardware security device associated with the user, and receive a signature result returned by the hardware security device after the hardware security device signs the challenge value using an internally stored SM2 private key. An information authentication module 403 is configured to: send the signature result and user digital certificate information corresponding to the user to the national cryptographic authentication service, so as to trigger the national cryptographic authentication service to perform validity verification on the user digital certificate information and perform SM2 signature verification on the signature result. A login control module 404 is configured to: receive a signature verification result from the national cryptographic authentication service, and control user login according to the signature verification result: if the signature verification is successful, approve login, and if the signature verification fails, refuse login.

[0059] In some possible embodiments, the user login information includes a PIN code; and the data sending module 402 is further configured to: send the PIN code input by the user to the hardware security device for verification; if the hardware security device returns PIN code error information, terminate the login process and prompt an error; if the hardware security device returns PIN code correct information, trigger the hardware security device to perform a signature operation.

[0060] In some possible embodiments, the user login information further includes a system account and a password; and the login control module 404 is further configured to: verify whether the system account and the password input by the user match pre-stored system user information; if the system account and the password do not match the pre-stored system user information, return error information, and lock the system account for a preset time after a preset threshold of consecutive error times is reached; if the system account and the password match the pre-stored system user information, complete user login.

[0061] In some possible embodiments, the user digital certificate information is obtained from the hardware security device; and the information authentication module 403 is specifically configured to: check whether an issuer of the user certificate exists in a preset national secret CA list, and whether the user certificate is within a valid period and has not been revoked.

[0062] In some possible embodiments, the random number is generated by a signature verification server called by the national secret authentication service; and the signature verification server generates the random number to ensure uniqueness of the login challenge value each time.

[0063] In some possible embodiments, the authentication request module 401 is further configured to: in response to a user registration operation, receive a system registration account and a registration password input by the user, and identify hardware security device information currently connected by the user; bind the system registration account input by the user and the hardware security device information, and store the system registration account, the registration password, and the bound hardware security device information in a system database.

[0064] Based on the same technical concept, the embodiments of the present disclosure further provide a computer device. Refer to Figure 5As shown, a structural schematic diagram of the computer device 500 provided by the embodiments of the present disclosure is shown, including a processor 501, a memory 502, and a bus 503. The memory 502 is used to store execution instructions, including an internal memory 5021 and an external memory 5022; the internal memory 5021 is also called an internal memory, used to temporarily store operation data in the processor 501, and exchange data with the external memory 5022 such as a hard disk, and the processor 501 exchanges data with the external memory 5022 through the internal memory 5021.

[0065] In the embodiments of the present application, the memory 502 is specifically used to store application program codes for executing the schemes of the present application, and is controlled to execute by the processor 501. That is, when the computer device 500 is running, the processor 501 and the memory 502 communicate through the bus 503, so that the processor 501 executes the application program codes stored in the memory 502, and further executes the methods described in any of the preceding embodiments.

[0066] The memory 502 can be, but is not limited to, a random access memory (RAM), a read only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc.

[0067] The processor 501 can be an integrated circuit chip with a processing capability of signals. The processor described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general processor can be a microprocessor or the processor can also be any conventional processor or the like.

[0068] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the computer device 500. In other embodiments of the present application, the computer device 500 can include more or fewer components than those illustrated, or combine certain components, or split certain components, or different arrangement of components. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.

[0069] The embodiments of the present disclosure also provide a computer readable storage medium, which stores a computer program. When the computer program is run by a processor, the steps of the identity authentication method based on the national cryptographic technology described in the above method embodiments are executed. The storage medium can be a volatile or non-volatile computer readable storage medium.

[0070] The embodiments of the present disclosure also provide a computer program product, which carries a program code. The instructions included in the program code can be used to execute the steps of the identity authentication method based on the national cryptographic technology described in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.

[0071] The computer program product can be specifically implemented by hardware, software or a combination thereof. In one optional embodiment, the computer program product is specifically embodied as a computer storage medium. In another optional embodiment, the computer program product is specifically embodied as a software product, such as a software development kit (SDK) and the like.

[0072] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described system and device can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here. In several embodiments provided by the present disclosure, it should be understood that the disclosed system and method can be implemented by other ways. The device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can be another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some communication interface, device or unit, which can be electrical, mechanical or other forms.

[0073] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0074] In addition, each functional unit in various embodiments of the present disclosure can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0075] If the functions are realized in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer readable storage medium executable by a processor. Based on this understanding, the technical solutions of the present disclosure or the part of the present disclosure that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present disclosure. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.

[0076] Finally, it should be noted that: the above-described embodiments are only specific embodiments of the present disclosure, used to illustrate the technical solutions of the present disclosure, and not to limit it, the protection scope of the present disclosure is not limited to this, although the present disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand: any person skilled in the art within the technical range disclosed by the present disclosure, still can modify or easily think of changes to the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part of the technical features; and these modifications, changes or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and all should be covered in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. An identity authentication method based on national cryptographic technology, characterized in that, include: In response to a user login action, receive the user login information; It initiates an authentication request to the national cryptographic authentication service through the identity authentication plugin, and receives a random number generated by the national cryptographic authentication service as a challenge value; The challenge value is sent to the hardware security device associated with the user, and the user receives the signature result returned by the hardware security device after signing the challenge value using the internally stored SM2 private key; The signature result and the user's digital certificate information corresponding to the user are sent to the national cryptographic authentication service to trigger the national cryptographic authentication service to verify the validity of the user's digital certificate information and to perform SM2 signature verification on the signature result. Receive the signature verification result from the national cryptographic authentication service, and control user login based on the signature verification result: if the signature verification is successful, approve login; if the signature verification fails, refuse login.

2. The method according to claim 1, characterized in that, The user login information includes a PIN code; after sending the challenge value to the hardware security device associated with the user, the process includes: The PIN code entered by the user is sent to the hardware security device for verification; If the hardware security device returns a PIN code error, the login process will be terminated and an error message will be displayed. If the hardware security device returns a correct PIN code, it will trigger the hardware security device to perform a signature operation.

3. The method according to claim 1 or 2, characterized in that, The user login information also includes a system account and password; the step of approving login upon successful signature verification also includes: Verify whether the system account and password entered by the user match the pre-stored system user information; If the system account and password do not match the pre-stored system user information, an error message will be returned, and the system account will be locked for a preset time after the number of consecutive errors reaches a preset threshold. If the system account and password match the pre-stored system user information, the user login is completed.

4. The method according to claim 1, characterized in that, The user's digital certificate information is obtained from the hardware security device; The national cryptographic authentication service verifies the validity of the user's digital certificate information, including: Check whether the issuer of the user certificate exists in the preset national cryptographic CA list, and whether the user certificate is within its validity period and has not been revoked.

5. The method according to claim 1, characterized in that, The random number is generated by the national cryptographic authentication service calling the signature verification server; wherein, the signature verification server generates the random number to ensure the uniqueness of the login challenge value each time.

6. The method according to claim 1, characterized in that, The response prior to the user login operation also includes: In response to a user registration operation, the system receives the user's system registration account and password, and identifies the information of the hardware security device currently connected to the user. The system registration account entered by the user is bound to the hardware security device information, and the system registration account, the registration password, and the bound hardware security device information are stored together in the system database.

7. An identity authentication system based on national cryptographic technology, characterized in that, This includes client devices, hardware security devices, and national cryptographic authentication servers; The client device is equipped with an identity authentication plugin, which is configured to communicate with the national cryptographic authentication server and the hardware security device. The hardware security device is detachably connected to the client computing device, internally stores the user's SM2 private key and digital certificate, and is configured to use the SM2 private key to sign the received challenge value after the user's PIN code is verified. The national cryptographic authentication server communicates with the client device. The identity authentication plugin is configured to, in response to a user login operation, initiate an authentication request to the national cryptographic authentication server; receive a challenge value returned by the national cryptographic authentication server and forward the challenge value to the hardware security device; receive a signature result returned by the hardware security device and send the signature result and the user's digital certificate obtained from the hardware security device to the national cryptographic authentication server; and, based on the signature verification result returned by the national cryptographic authentication server, control the completion of the user's login process. The national cryptographic authentication server is used to respond to the authentication request, generate a random number as the challenge value and return it to the identity authentication plugin; after receiving the signature result and the user's digital certificate, it verifies the validity of the digital certificate and performs SM2 verification on the signature result; and returns the verification result to the identity authentication plugin.

8. An identity authentication device based on national cryptographic technology, characterized in that, include: The authentication request module is used to respond to user login operations and receive user login information; It initiates an authentication request to the national cryptographic authentication service through the identity authentication plugin, and receives a random number generated by the national cryptographic authentication service as a challenge value; The data sending module is used to send the challenge value to the hardware security device associated with the user, and to receive the signature result returned by the hardware security device after signing the challenge value using the internally stored SM2 private key; The information authentication module is used to send the signature result and the user digital certificate information corresponding to the user to the national cryptographic authentication service, so as to trigger the national cryptographic authentication service to verify the validity of the user digital certificate information and perform SM2 signature verification operation on the signature result. The login control module is used to receive the signature verification result from the national cryptographic authentication service and control the user login according to the signature verification result: if the signature verification is successful, the login is approved; if the signature verification fails, the login is rejected.

9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.

10. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 6.