Identity authentication method, computer equipment, storage medium and program product
By setting identifiers and attribute identifiers for the keys of substation smart terminals, and using secure channels to address the target objects with pre-stored platform keys, the problem of key mismatch caused by the mobility of smart terminals is solved, and secure cross-platform authentication and key management are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN POWER SUPPLY BUREAU
- Filing Date
- 2026-01-15
- Publication Date
- 2026-04-10
AI Technical Summary
In substations, the flexibility of smart terminals leads to a mismatch between the pre-filled quantum keys and the key requirements of the actual deployment location, resulting in the inability to achieve access authentication.
By setting a key identifier and a unique attribute identifier for each key, and using a secure channel to address the target authentication operation object that has a pre-stored platform key, cross-platform identity authentication is achieved, solving the dilemma of static key binding caused by the mobility of secure terminals.
It achieves cross-platform identity authentication, ensures the security of key query and transmission processes, and reduces storage and management burden.
Smart Images

Figure CN121841646A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to an identity authentication method, computer equipment, computer-readable storage medium, and computer program product. Background Technology
[0002] Reference Figure 1 Traditional substations are equipped with corresponding quantum key service platforms and business system servers, which provide authentication, key distribution, and data management services for secure terminals within the substation. All kinds of intelligent terminals within the substation require access authentication. With the application of quantum technology, current access authentication operations mainly rely on quantum keys pre-loaded into the terminals, quantum key service platforms, and business system servers, such as using pre-loaded symmetric quantum keys to achieve access authentication.
[0003] In practice, quantum key service platforms (or business system servers) are often multiple due to limitations imposed by distance and the number of service targets. For example, they can be divided into regions, with one quantum key service platform set up in each region to provide authentication and key provision services to terminals in all substations within that region. However, due to the numerous uncertainties involved in the process from the smart terminal's manufacture to key filling and then its access to the substation, and because smart terminals are not bound to fixed sites—they can be used in fixed substations or mounted on mobile platforms (such as patrol vehicles or maintenance devices)—this flexibility means that the pre-filled quantum keys may not match the key requirements of the actual deployment location of the terminal. In the above scenario, the quantum key service platform (or business system server) providing access authentication services to the terminal does not have the corresponding authentication quantum key pre-stored, resulting in access authentication failing. Summary of the Invention
[0004] Therefore, it is necessary to provide an identity authentication method, computer device, computer-readable storage medium, and computer program product to address the above-mentioned technical problems, which can solve the dilemma of static key binding caused by the mobility of secure terminals and ensure the security of key query and transmission processes.
[0005] Firstly, this application provides an identity authentication method, including:
[0006] Receive platform identity information sent by the authentication operation object;
[0007] Find the key identifier corresponding to the platform identity information from the pre-filled key data;
[0008] If the key identifier is not found, the platform key information and terminal identity information are sent to the authentication operation object to instruct the authentication operation object to obtain the first platform key that matches the terminal identity information from the target authentication operation object pointed to by the platform key information through a secure channel.
[0009] The unique attribute identifier of the first platform key returned by the authentication operation object;
[0010] Find the first pre-stored platform key that corresponds to the unique attribute identifier of the first platform key from the pre-filled key data;
[0011] The first pre-stored platform key is sent to the authentication operation object to instruct the authentication operation object to compare the first platform key with the first pre-stored platform key, and determine the identity authentication result based on the comparison result.
[0012] In one embodiment, the authentication operation target includes a quantum key service platform or a business system server; the method further includes:
[0013] In the first authentication mode, the system receives the first identity authentication result returned by the quantum key service platform and the second identity authentication result returned by the business system server; if both the first and second identity authentication results are successful, the access authentication is confirmed to be successful.
[0014] In the second authentication mode, the system receives the first authentication result returned by the quantum key service platform or the second authentication result returned by the business system server; if the first authentication result is successful or the second authentication result is successful, the access authentication is confirmed to be successful.
[0015] In one embodiment, the method further includes:
[0016] If a key identifier is found, the terminal identity information is sent to the authentication operation object to instruct the authentication operation object to find a second platform key that matches the terminal identity information;
[0017] The unique attribute identifier of the second platform key returned by the authentication operation object;
[0018] Find the second pre-stored platform key that corresponds to the unique attribute identifier of the second platform key from the pre-filled key data;
[0019] The second pre-stored platform key is sent to the authentication operation object to instruct the authentication operation object to compare the second platform key with the second pre-stored platform key, and determine the identity authentication result based on the comparison result.
[0020] In one embodiment, before receiving the platform identity information sent by the authentication operation object, the method further includes:
[0021] Receive key data and associated platform identity information sent by the key filling system;
[0022] Assign a key identifier to the key data corresponding to the identity information of the associated platform to obtain pre-filled key data.
[0023] Secondly, this application also provides an identity authentication method, including:
[0024] Send platform identity information to the secure terminal to instruct the secure terminal to search for the key identifier corresponding to the platform identity information from the pre-filled key data. If the key identifier is not found, return the platform key information and the terminal identity information.
[0025] Receive platform key information and terminal identity information returned by the secure terminal, and determine the target platform identity information based on the platform key information;
[0026] Based on the target platform identity information, the target authentication operation object is located, and an auxiliary authentication request including the terminal identity information is sent to the target authentication operation object to instruct the target authentication operation object to select the first platform key from multiple pre-stored platform keys corresponding to the terminal identity information;
[0027] The system receives the first platform key returned by the target authentication operation object through a secure channel and sends the unique attribute identifier of the first platform key to the secure terminal, so as to instruct the secure terminal to find the first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data.
[0028] Receive the first pre-stored platform key returned by the secure terminal, compare the first platform key with the first pre-stored platform key, and determine the identity authentication result based on the comparison result.
[0029] In one embodiment, the method further includes:
[0030] When multiple target platform identity information is determined based on platform key information, the authentication operation object pointed to by any one of the target platform identity information is randomly selected as the target authentication operation object.
[0031] In one embodiment, before sending platform identity information to the secure terminal, the method further includes:
[0032] Receive key data and associated terminal identity information sent by the key filling system;
[0033] Assign a key identifier corresponding to the identity information of the associated terminal to the key data to obtain pre-filled key data.
[0034] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in the first or second aspect above.
[0035] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first or second aspect above.
[0036] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in the first or second aspect above.
[0037] The aforementioned authentication method, computer equipment, computer-readable storage medium, and computer program product receive platform identity information sent by the authentication operation object; search for a key identifier corresponding to the platform identity information from pre-loaded key data; if no key identifier is found, send platform key information and terminal identity information to the authentication operation object, instructing the authentication operation object to obtain a first platform key matching the terminal identity information from the target authentication operation object pointed to by the platform key information through a secure channel; receive the unique attribute identifier of the first platform key returned by the authentication operation object; search for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-loaded key data; send the first pre-stored platform key to the authentication operation object, instructing the authentication operation object to compare the first platform key with the first pre-stored platform key, and determine the authentication result based on the comparison result. Through this method, even when the secure terminal does not have a pre-stored key corresponding to the authentication operation object, the authentication operation object can locate the target authentication operation object with a pre-stored platform key through the platform key information, achieving cross-platform authentication and solving the problem of static key binding caused by the mobility of secure terminals. Setting a key identifier and a unique attribute identifier for each key, and setting up a secure channel, can ensure the security of the key query and transmission process. The authentication process eliminates the need to pre-store all keys for all potentially accessing terminals, reducing storage and management burden. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0039] Figure 1This is a schematic diagram of the architecture of a traditional substation security authentication system in one embodiment.
[0040] Figure 2 This is a flowchart illustrating an identity authentication method in one embodiment;
[0041] Figure 3 This is a schematic diagram of the architecture of a security authentication system in one embodiment;
[0042] Figure 4 This is a timing diagram of the authentication process in one embodiment;
[0043] Figure 5 This is a flowchart illustrating the identity authentication method in another embodiment;
[0044] Figure 6 This is a schematic diagram of the architecture of a security authentication system in another embodiment;
[0045] Figure 7 This is a flowchart illustrating the key filling process in one embodiment;
[0046] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0047] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0048] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.
[0049] In one exemplary embodiment, such as Figure 2 As shown, an authentication method is provided. Taking the application of this method to a secure terminal as an example, it includes:
[0050] Step 202: Receive the platform identity information sent by the authentication operation object.
[0051] The authentication operation target refers to the server or platform that the secure terminal needs to access. Figure 1In the substation environment shown, the authentication operation objects include a quantum key service platform or a business system server, which provide authentication, key distribution, and data management services to secure terminals within the substation. Secure terminals refer to various mobile or fixed business terminals within the substation that rely on the authentication operation objects for identity authentication and communication encryption. When a secure terminal accesses the substation, the authentication operation object sends platform identity information (ID) to the secure terminal.
[0052] Step 204: Find the key identifier corresponding to the platform identity information from the pre-filled key data.
[0053] The key data includes pre-filled quantum keys used for authentication of target objects, such as platform keys for authentication of a quantum key service platform or server keys for authentication of a business system server. During the pre-filling of key data within the secure terminal, at least one quantum key tag corresponding to each authentication object is assigned a key identifier that matches the object's ID (e.g., quantum service platform ID and business system server ID). This key identifier ensures that the quantum key can only be used for authentication operations with a specific object. The secure terminal retrieves the corresponding key identifier based on the received platform identity information.
[0054] Step 206: If the key identifier is not found, send platform key information and terminal identity information to the authentication operation object to instruct the authentication operation object to obtain the first platform key that matches the terminal identity information from the target authentication operation object pointed to by the platform key information through a secure channel.
[0055] If no key identifier is found, it indicates that the authentication operation object that the secure terminal is expected to bind to is different from the authentication operation object currently requesting access. This means the secure terminal does not have a pre-stored key for the authentication operation object to perform authentication operations, and the authentication operation object also does not have a pre-stored key for authenticating the secure terminal's identity, making it impossible to directly establish two-way authentication. To address the problems of traditional technologies, in this embodiment, when no key identifier is found, the secure terminal sends platform key information and terminal identity information (ID) to the authentication operation object. The platform key information is used to characterize the platform key attributes stored within the secure terminal, including the pre-stored key identifier. It is understood that the same secure terminal can bind to only one authentication operation object or multiple authentication operation objects simultaneously. Accordingly, the platform key information includes key identifiers corresponding to the IDs of one or more bound authentication operation objects.
[0056] Optionally, the target authentication operation object bound to the secure terminal is pre-loaded with a quantum key for authenticating the secure terminal. When pre-loading key data into the target authentication operation object, at least one quantum key corresponding to the secure terminal is marked with a key identifier corresponding to the secure terminal's ID. This key identifier ensures that the quantum key can only perform authentication operations with a specific secure terminal, thus linking the secure terminal to the quantum service platform (or business system server). The authentication operation object currently connected to the secure terminal determines the target platform's identity information based on the platform key information, addresses the target authentication operation object according to the target platform's identity information, and sends an auxiliary authentication request including the terminal's identity information to the target authentication operation object. This instructs the target authentication operation object to select a first platform key from a set of pre-stored platform keys corresponding to the terminal's identity information. The authentication operation object currently connected to the secure terminal receives the first platform key returned by the target authentication operation object through a secure channel.
[0057] Step 208: Receive the unique attribute identifier of the first platform key returned by the authentication operation object.
[0058] When the authentication operation object currently accessed by the secure terminal receives the first platform key, it sends the unique attribute identifier of the first platform key to the secure terminal. The unique attribute identifier is a reference credential that can uniquely correspond to a specific platform key but does not expose sensitive information about the key itself, such as a hash digest (e.g., MD5 value) generated based on the platform key.
[0059] Step 210: Search for the first pre-stored platform key that corresponds to the unique attribute identifier of the first platform key from the pre-filled key data.
[0060] The secure terminal compares the unique attribute identifier of each pre-stored platform key in the key data with the unique attribute identifier of the received first platform key to find the corresponding first pre-stored platform key.
[0061] Step 212: Send the first pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the first platform key with the first pre-stored platform key, and determine the identity authentication result based on the comparison result.
[0062] In this process, the authentication object compares the first platform key with the first pre-stored platform key. If they are the same or are symmetric keys, the authentication is successful; otherwise, the authentication fails. Compared to traditional technologies, this application provides more refined key management, enabling authentication to meet various scenarios.
[0063] In the aforementioned authentication method, the following steps are taken: The system receives platform identity information from the authentication target; searches for a key identifier corresponding to the platform identity information from pre-loaded key data; if no key identifier is found, it sends platform key information and terminal identity information to the authentication target, instructing the authentication target to obtain a first platform key matching the terminal identity information from the target authentication target indicated by the platform key information through a secure channel; it receives the unique attribute identifier of the first platform key returned by the authentication target; searches for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-loaded key data; and sends the first pre-stored platform key to the authentication target, instructing the authentication target to compare the first platform key with the first pre-stored platform key, and determines the authentication result based on the comparison result. Through this method, even when the secure terminal does not have a pre-stored key corresponding to the authentication target, the authentication target can locate the target authentication target with the pre-stored platform key through the platform key information, achieving cross-platform authentication and solving the problem of static key binding caused by the mobility of secure terminals. Setting a key identifier and a unique attribute identifier for each key, and establishing a secure channel, ensures the security of the key query and transmission process. The authentication process eliminates the need to pre-store all keys for all potentially accessing terminals, reducing storage and management burden.
[0064] In one exemplary embodiment, refer to Figure 3 Security terminal A was not deployed to the designated substation as planned. Security terminal A was pre-bound to both quantum key service platform A and business system server B. Assume that the authentication operation of security terminal A is performed on either quantum key service platform B or business system server B. (Refer to...) Figure 4 Taking the access authentication process between secure terminal A and quantum key service platform B as an example, the access authentication process includes:
[0065] Secure terminal A connects to the substation. Quantum key service platform B sends ID information to secure terminal A. The secure terminal uses this ID information to search for the corresponding key identifier. If it cannot find it, secure terminal A sends platform key information and its own ID information to quantum key service platform B. The platform key information represents the platform key attributes (especially the platform key identifier) stored within secure terminal A.
[0066] Quantum key service platform B receives the platform key information and, based on this, determines the ID information of quantum key service platform A. Quantum key service platform B then uses the ID information to locate quantum key service platform A and sends the ID information of secure terminal A and an auxiliary authentication request to quantum key service platform A.
[0067] Quantum key service platform A, based on the ID information of secure terminal A, finds multiple pre-stored platform keys corresponding to secure terminal A according to the key identifier, randomly extracts a platform key Keyp from the multiple platform keys, and sends the randomly extracted platform key Keyp to key service platform B through a secure channel.
[0068] Quantum key service platform B receives the platform key Keyp, which has a unique attribute identifier. Quantum key service platform B sends the unique attribute identifier of the platform key Keyp to secure terminal A and requests it to return the corresponding authentication key.
[0069] After receiving the unique attribute identifier, secure terminal A finds the corresponding platform key Keyp' from its own platform key and sends the platform key Keyp' to quantum key service platform B.
[0070] The quantum key service platform B compares the platform key Keyp and the platform key Keyp'. If they are the same or are symmetric keys, the authentication is successful.
[0071] It is understandable that the access authentication between secure terminal A and business system server B follows the same principle and steps as the access authentication between secure terminal A and quantum key service platform B.
[0072] In an exemplary embodiment, the authentication operation target includes a quantum key service platform or a business system server; the method further includes: in a first authentication mode, receiving a first identity authentication result returned by the quantum key service platform and a second identity authentication result returned by the business system server; if both the first identity authentication result and the second identity authentication result are successful, determining that access authentication is successful; in a second authentication mode, receiving the first identity authentication result returned by the quantum key service platform or the second identity authentication result returned by the business system server; if either the first identity authentication result or the second identity authentication result is successful, determining that access authentication is successful.
[0073] Among them, reference Figure 3 For strong authentication modes, such as security terminals used for long-term access to substations, successful authentication requires successful authentication from both the quantum key service platform B and the business system server B. For weak authentication modes, such as maintenance or detection security terminals used for temporary access to substations, successful authentication requires only successful authentication from either the quantum key service platform B or the business system server B.
[0074] In an exemplary embodiment, the method further includes: if a key identifier is found, sending terminal identity information to the authentication operation object to instruct the authentication operation object to find a second platform key that matches the terminal identity information; receiving a unique attribute identifier of the second platform key returned by the authentication operation object; searching for a second pre-stored platform key corresponding to the unique attribute identifier of the second platform key from the pre-filled key data; and sending the second pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the second platform key with the second pre-stored platform key, and determining the identity authentication result based on the comparison result.
[0075] If the security terminal finds a key identifier, it indicates that the security terminal has been deployed to the designated substation according to the predetermined plan. The security terminal pre-stores the key used for authentication operations, and the authentication target also pre-stores a key for authenticating the security terminal's identity, enabling direct two-way authentication. At this point, the authentication target randomly selects a second platform key from at least one platform key matching the terminal's identity information, sends the unique attribute identifier of the second platform key to the security terminal, and requests the return of the corresponding authentication key. The security terminal searches its pre-loaded key data for the second pre-stored platform key corresponding to the unique attribute identifier of the second platform key and sends the second pre-stored platform key to the authentication target. The authentication target compares the second platform key with the second pre-stored platform key. If they are the same or are symmetric keys, authentication is successful; otherwise, authentication fails.
[0076] Optionally, refer to Figure 3 For strong authentication modes, such as security terminals used for long-term access to substations, successful authentication requires successful authentication from both the quantum key service platform A and the business system server A. For weak authentication modes, such as maintenance or detection security terminals used for temporary access to substations, successful authentication requires only successful authentication from either the quantum key service platform A or the business system server A.
[0077] In an exemplary embodiment, before step 202, the method further includes: receiving key data and associated platform identity information sent by the key filling system; assigning a key identifier corresponding to the associated platform identity information to the key data to obtain pre-filled key data.
[0078] The key filling system generates and allocates matching key data to the associated secure terminal and the authentication operation object (quantum key service platform or business system server), and provides associated identity information. The secure terminal assigns a key identifier corresponding to the associated platform identity information to the key data and fills it into the secure terminal for subsequent access authentication.
[0079] In one exemplary embodiment, such as Figure 5 As shown, an identity authentication method is provided. Taking the application of this method to a quantum key service platform or business system server as an example, the method includes:
[0080] Step 502: Send platform identity information to the secure terminal to instruct the secure terminal to search for the key identifier corresponding to the platform identity information from the pre-filled key data. If the key identifier is not found, return the platform key information and the terminal identity information.
[0081] Step 504: Receive platform key information and terminal identity information returned by the secure terminal, and determine the target platform identity information based on the platform key information.
[0082] Step 506: Based on the target platform identity information, locate the target authentication operation object and send an auxiliary authentication request including the terminal identity information to the target authentication operation object to instruct the target authentication operation object to select the first platform key from multiple pre-stored platform keys corresponding to the terminal identity information.
[0083] Step 508: Receive the first platform key returned by the target authentication operation object through the secure channel, and send the unique attribute identifier of the first platform key to the secure terminal to instruct the secure terminal to search for the first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data.
[0084] Step 510: Receive the first pre-stored platform key returned by the secure terminal, compare the first platform key with the first pre-stored platform key, and determine the identity authentication result based on the comparison result.
[0085] It is understood that the explanations of steps 502 to 510 can be found in the explanations of steps 202 to 212 above, and will not be repeated here.
[0086] In this embodiment, when the secure terminal does not pre-store the key corresponding to the authentication operation object, the authentication operation object addresses the target authentication operation object that has pre-stored the platform key through the platform key information, realizing cross-platform identity authentication and solving the problem of static key binding caused by the mobility of secure terminals. Setting a key identifier and unique attribute identifier for each key, and establishing a secure channel, ensures the security of key query and transmission processes. The authentication operation object does not need to pre-store all keys for all potentially accessing terminals, reducing the storage and management burden.
[0087] In an exemplary embodiment, the method further includes: when multiple target platform identity information is determined based on platform key information, randomly selecting the authentication operation object pointed to by any one of the target platform identity information as the target authentication operation object.
[0088] Among them, reference Figure 3 The platform key loaded into secure terminal A corresponds only to quantum key service platform B. In practice, according to the plan, the secure terminal may be switched between multiple substations. (Refer to...) Figure 6 The secure terminal A can also be pre-loaded with platform keys corresponding to multiple quantum key service platforms (quantum key service platform A1 and quantum key service platform A2), and the service keys are similarly pre-loaded. For example, the secure terminal is a maintenance device for substations, specifically designed for substations 1 and 2. When either substation requires maintenance, the secure terminal (maintenance device) is connected to the corresponding substation, and encrypted transmission of maintenance data is performed during the maintenance process.
[0089] For example, refer to Figure 6 When secure terminal A is deployed to the substation corresponding to the quantum key service platform C and the business system server C, taking the access authentication process between secure terminal A and the quantum key service platform C as an example, the access authentication process includes:
[0090] Secure terminal A connects to the substation. Quantum key service platform C sends ID information to secure terminal A. The secure terminal uses this ID information to search for the corresponding key identifier. If it cannot find it, secure terminal A sends platform key information and its own ID information to quantum key service platform C. The platform key information represents the platform key attributes (especially the platform key identifier) stored within secure terminal A.
[0091] Quantum key service platform C receives the platform key information and, based on this information, determines the IDs of quantum key service platforms A1 and A2. Quantum key service platform C then addresses either quantum key service platform A1 or A2 using the ID information. Quantum key service platform C randomly selects one of A1 or A2 as an authentication auxiliary platform. Assuming that quantum key service platform A1 is selected, quantum key service platform C sends the ID information of secure terminal A and an auxiliary authentication request to quantum key service platform A1. Optionally, the authentication auxiliary platform can be selected based on distance; for example, the quantum key service platform closer to quantum key service platform C can be chosen as the authentication auxiliary platform. Optionally, the quantum key service platform with more remaining keys can be selected as the auxiliary authentication platform.
[0092] Based on the ID information of secure terminal A, quantum key service platform A1 finds multiple pre-stored platform keys corresponding to secure terminal A according to the key identifier, randomly extracts a platform key Keyp1 from the multiple platform keys, and sends the randomly extracted platform key Keyp1 to key service platform C through a secure channel.
[0093] Quantum key service platform C receives platform key Keyp1. For platform key Keyp1, quantum key service platform C sends the unique attribute identifier of platform key Keyp1 and the ID information of key service platform A1 to secure terminal A, and requests it to return the corresponding authentication key.
[0094] After receiving the unique attribute identifier and ID information, the secure terminal A finds the corresponding platform key Keyp1' from the multiple platform keys corresponding to the ID information and sends the platform key Keyp1' to the quantum key service platform C.
[0095] The quantum key service platform C compares the platform key Keyp1 and the platform key Keyp1'. If they are the same or are symmetric keys, the authentication is successful.
[0096] It is understandable that the principle and steps for access authentication between a secure terminal and a business system server are the same as those for access authentication between a secure terminal and a quantum key service platform.
[0097] In this embodiment, the secure terminal can simultaneously authenticate itself through multiple objects. Efficient management of authentication keys is achieved by setting corresponding key identifiers during key filling. During access authentication, if the secure terminal is connected to other non-preset substations, the access authentication scheme of this embodiment can still achieve secure authentication, avoiding authentication failures or easy leakage of authentication data.
[0098] In an exemplary embodiment, before step 502, the method further includes: receiving key data and associated terminal identity information sent by the key filling system; assigning a key identifier corresponding to the associated terminal identity information to the key data to obtain pre-filled key data.
[0099] The key filling system generates and allocates matching key data to the associated secure terminal and the authentication operation object (quantum key service platform or business system server), and provides associated identity information. The authentication operation object assigns a key identifier corresponding to the associated terminal's identity information to the key data and fills it into the authentication operation object for subsequent access authentication.
[0100] For example, refer to Figure 7 The key filling process includes:
[0101] 1. Pre-determine the quantum key service platform A corresponding to the secure terminal A. Pre-determining can be understood as, based on the current plan, the secure terminal A may be deployed to the substation corresponding to the quantum key service platform A. The key injection system obtains the ID information corresponding to both the secure terminal A and the quantum key service platform A, and then generates several pairs of quantum key-based symmetric keys (or several pairs of identical keys) based on quantum random numbers provided by a quantum random number generator; these are the platform keys.
[0102] 2. The key filling system sends a portion of the symmetric key and the ID information of the quantum key service platform A to the secure terminal A through a secure transmission path. This portion of the platform key is filled into the secure terminal A and is assigned the same key identifier, which corresponds to the ID information of the quantum key service platform A.
[0103] 3. The key injection system sends a portion of the symmetric key and the ID information of secure terminal A to the quantum key service platform A via a secure transmission path. This portion of the platform key is injected into the quantum key service platform A and assigned the same key identifier, which corresponds to the ID information of secure terminal A. The portion of the platform key stored on the quantum key service platform A corresponds to the portion of the platform key stored on secure terminal A, and a successful match is achieved.
[0104] 4. Pre-determine the business system server A corresponding to the secure terminal A. The key injection system obtains the ID information corresponding to the secure terminal A and the business system server A, and then generates several pairs of symmetric keys based on quantum key distribution (or several pairs of identical keys) based on quantum random numbers provided by the quantum random number generator, i.e., the server keys.
[0105] 5. The key filling system sends a portion of the symmetric key and the ID information of the business system server A to the secure terminal A through a secure transmission path. This portion of the server key is filled into the secure terminal A and is assigned the same key identifier, which corresponds to the ID information of the business system server A.
[0106] 6. The key injection system sends a portion of the symmetric key and the ID information of secure terminal A to the business system server A via a secure transmission path. This portion of the server key is injected into the business system server A and assigned the same key identifier, which corresponds to the ID information of secure terminal A. A corresponding relationship exists between the portion of the platform key stored on business system server A and the portion of the platform key stored on secure terminal A, ensuring a successful match.
[0107] At this point, the key impregnation step is complete. Secure terminal A is now impregnated with a platform key and a server key for authentication, both of which have specific key identifiers. These identifiers ensure that the authentication key can only be used for authentication operations with a fixed target. Simultaneously, the business system server and the quantum key service platform also possess corresponding authentication keys, each with a specific key identifier. This identifier ensures that the authentication key can only perform authentication operations with the designated secure terminal. This key impregnation method provides more granular key management, enabling authentication requirements to be met in various scenarios.
[0108] For example, for security terminals that require authentication across multiple substations, such as those used for equipment maintenance, the key filling process includes:
[0109] 1. Predetermine the quantum key service platforms A1 and A2 corresponding to the secure terminal A. The key filling system obtains the ID information corresponding to the secure terminal A, quantum key service platform A1, and quantum key service platform A2, and then generates several pairs of symmetric keys based on quantum keys (or several pairs of identical keys) based on quantum random numbers provided by the quantum random number generator, i.e., platform keys.
[0110] 2. The key filling system sends a portion of the symmetric key and the ID information of the quantum key service platform A1 to the secure terminal A through a secure transmission path. This portion of the platform key is filled into the secure terminal A and is assigned the same key identifier, which corresponds to the ID information of the quantum key service platform A1.
[0111] 3. The key filling system sends another part of the symmetric key and the ID information of the quantum key service platform A2 to the secure terminal A through a secure transmission path. This part of the platform key is filled into the secure terminal A and is given the same key identifier, which corresponds to the ID information of the quantum key service platform A2.
[0112] 4. The key injection system sends a portion of the symmetric key and the ID information of secure terminal A to the quantum key service platform A1 via a secure transmission path. This portion of the platform key is injected into the quantum key service platform A1 and assigned the same key identifier, which corresponds to the ID information of secure terminal A. The portion of the platform key stored in the quantum key service platform A1 corresponds to the portion of the platform key stored in secure terminal A, and a successful match is achieved.
[0113] 5. The key injection system sends a portion of the symmetric key and the ID information of secure terminal A to the quantum key service platform A2 via a secure transmission path. This portion of the platform key is injected into the quantum key service platform A2 and assigned the same key identifier, which corresponds to the ID information of secure terminal A. The portion of the platform key stored in the quantum key service platform A2 corresponds to the portion of the platform key stored in secure terminal A, and a successful match is achieved.
[0114] 6. The principle of server key filling is the same as above. The authentication keys corresponding to business system server A1 and business system server A2 are filled into security terminal A respectively, and the authentication keys corresponding to security terminal A are filled into business system server A1 and business system server A2 respectively.
[0115] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.
[0116] In one exemplary embodiment, a computer device is provided, the internal structure of which can be as shown in the figure. Figure 8 As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and databases. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media to run. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements an authentication method.
[0117] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0118] In an exemplary embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps: receiving platform identity information sent by an authentication operation object; searching for a key identifier corresponding to the platform identity information from pre-filled key data; if the key identifier is not found, sending platform key information and terminal identity information to the authentication operation object to instruct the authentication operation object to obtain a first platform key matching the terminal identity information from the target authentication operation object pointed to by the platform key information through a secure channel; receiving a unique attribute identifier of the first platform key returned by the authentication operation object; searching for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data; and sending the first pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the first platform key with the first pre-stored platform key and determine the identity authentication result based on the comparison result.
[0119] In one embodiment, when the processor executes the computer program, it further implements the following steps: in a first authentication mode, receiving a first identity authentication result returned by the quantum key service platform and a second identity authentication result returned by the business system server; if both the first identity authentication result and the second identity authentication result are successful, determining that the access authentication is successful; in a second authentication mode, receiving either the first identity authentication result returned by the quantum key service platform or the second identity authentication result returned by the business system server; if either the first identity authentication result or the second identity authentication result is successful, determining that the access authentication is successful.
[0120] In one embodiment, when the processor executes the computer program, it further performs the following steps: if a key identifier is found, it sends terminal identity information to the authentication operation object to instruct the authentication operation object to find a second platform key that matches the terminal identity information; it receives the unique attribute identifier of the second platform key returned by the authentication operation object; it searches for a second pre-stored platform key corresponding to the unique attribute identifier of the second platform key from the pre-filled key data; and it sends the second pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the second platform key with the second pre-stored platform key and determine the identity authentication result based on the comparison result.
[0121] In one embodiment, when the processor executes the computer program, it further performs the following steps: receiving key data and associated platform identity information sent by the key filling system; assigning a key identifier corresponding to the associated platform identity information to the key data to obtain pre-filled key data.
[0122] In one embodiment, when the processor executes the computer program, it further performs the following steps: sending platform identity information to a secure terminal to instruct the secure terminal to search for a key identifier corresponding to the platform identity information from pre-filled key data; if no key identifier is found, returning platform key information and terminal identity information; receiving the platform key information and terminal identity information returned by the secure terminal, and determining the target platform identity information based on the platform key information; addressing the target authentication operation object according to the target platform identity information, and sending an auxiliary authentication request including terminal identity information to the target authentication operation object to instruct the target authentication operation object to select a first platform key from a plurality of pre-stored platform keys corresponding to the terminal identity information; receiving the first platform key returned by the target authentication operation object through a secure channel, and sending the unique attribute identifier of the first platform key to the secure terminal to instruct the secure terminal to search for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data; receiving the first pre-stored platform key returned by the secure terminal, comparing the first platform key with the first pre-stored platform key, and determining the identity authentication result based on the comparison result.
[0123] In one embodiment, when the processor executes the computer program, it further performs the following steps: when multiple target platform identity information is determined based on platform key information, randomly selects the authentication operation object pointed to by any one of the target platform identity information as the target authentication operation object.
[0124] In one embodiment, when the processor executes the computer program, it further performs the following steps: receiving key data and associated terminal identity information sent by the key filling system; assigning a key identifier corresponding to the associated terminal identity information to the key data to obtain pre-filled key data.
[0125] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When executed by a processor, the computer program performs the following steps: receiving platform identity information sent by an authentication operation object; searching for a key identifier corresponding to the platform identity information from pre-filled key data; if the key identifier is not found, sending platform key information and terminal identity information to the authentication operation object to instruct the authentication operation object to obtain a first platform key matching the terminal identity information from the target authentication operation object pointed to by the platform key information through a secure channel; receiving a unique attribute identifier of the first platform key returned by the authentication operation object; searching for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data; and sending the first pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the first platform key with the first pre-stored platform key and determine the authentication result based on the comparison result.
[0126] In one embodiment, when the computer program is executed by the processor, it further implements the following steps: in a first authentication mode, receiving a first identity authentication result returned by the quantum key service platform and a second identity authentication result returned by the business system server; if both the first identity authentication result and the second identity authentication result are successful, determining that the access authentication is successful; in a second authentication mode, receiving either the first identity authentication result returned by the quantum key service platform or the second identity authentication result returned by the business system server; if either the first identity authentication result or the second identity authentication result is successful, determining that the access authentication is successful.
[0127] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: if a key identifier is found, sending terminal identity information to the authentication operation object to instruct the authentication operation object to find a second platform key that matches the terminal identity information; receiving the unique attribute identifier of the second platform key returned by the authentication operation object; searching for a second pre-stored platform key corresponding to the unique attribute identifier of the second platform key from the pre-filled key data; and sending the second pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the second platform key with the second pre-stored platform key and determine the identity authentication result based on the comparison result.
[0128] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: receiving key data and associated platform identity information sent by the key filling system; assigning a key identifier corresponding to the associated platform identity information to the key data to obtain pre-filled key data.
[0129] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: sending platform identity information to a secure terminal to instruct the secure terminal to search for a key identifier corresponding to the platform identity information from pre-filled key data; if no key identifier is found, returning platform key information and terminal identity information; receiving the platform key information and terminal identity information returned by the secure terminal, and determining the target platform identity information based on the platform key information; addressing the target authentication operation object according to the target platform identity information, and sending an auxiliary authentication request including terminal identity information to the target authentication operation object to instruct the target authentication operation object to select a first platform key from a plurality of pre-stored platform keys corresponding to the terminal identity information; receiving the first platform key returned by the target authentication operation object through a secure channel, and sending the unique attribute identifier of the first platform key to the secure terminal to instruct the secure terminal to search for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data; receiving the first pre-stored platform key returned by the secure terminal, comparing the first platform key with the first pre-stored platform key, and determining the identity authentication result based on the comparison result.
[0130] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: when multiple target platform identity information is determined based on platform key information, randomly selects the authentication operation object pointed to by any one of the target platform identity information as the target authentication operation object.
[0131] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: receiving key data and associated terminal identity information sent by the key filling system; assigning a key identifier corresponding to the associated terminal identity information to the key data to obtain pre-filled key data.
[0132] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps: receiving platform identity information sent by an authentication operation object; searching for a key identifier corresponding to the platform identity information from pre-filled key data; if the key identifier is not found, sending platform key information and terminal identity information to the authentication operation object to instruct the authentication operation object to obtain a first platform key matching the terminal identity information from the target authentication operation object pointed to by the platform key information through a secure channel; receiving a unique attribute identifier of the first platform key returned by the authentication operation object; searching for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data; and sending the first pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the first platform key with the first pre-stored platform key and determine the authentication result based on the comparison result.
[0133] In one embodiment, when the computer program is executed by the processor, it further implements the following steps: in a first authentication mode, receiving a first identity authentication result returned by the quantum key service platform and a second identity authentication result returned by the business system server; if both the first identity authentication result and the second identity authentication result are successful, determining that the access authentication is successful; in a second authentication mode, receiving either the first identity authentication result returned by the quantum key service platform or the second identity authentication result returned by the business system server; if either the first identity authentication result or the second identity authentication result is successful, determining that the access authentication is successful.
[0134] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: if a key identifier is found, sending terminal identity information to the authentication operation object to instruct the authentication operation object to find a second platform key that matches the terminal identity information; receiving the unique attribute identifier of the second platform key returned by the authentication operation object; searching for a second pre-stored platform key corresponding to the unique attribute identifier of the second platform key from the pre-filled key data; and sending the second pre-stored platform key to the authentication operation object to instruct the authentication operation object to compare the second platform key with the second pre-stored platform key and determine the identity authentication result based on the comparison result.
[0135] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: receiving key data and associated platform identity information sent by the key filling system; assigning a key identifier corresponding to the associated platform identity information to the key data to obtain pre-filled key data.
[0136] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: sending platform identity information to a secure terminal to instruct the secure terminal to search for a key identifier corresponding to the platform identity information from pre-filled key data; if no key identifier is found, returning platform key information and terminal identity information; receiving the platform key information and terminal identity information returned by the secure terminal, and determining the target platform identity information based on the platform key information; addressing the target authentication operation object according to the target platform identity information, and sending an auxiliary authentication request including terminal identity information to the target authentication operation object to instruct the target authentication operation object to select a first platform key from a plurality of pre-stored platform keys corresponding to the terminal identity information; receiving the first platform key returned by the target authentication operation object through a secure channel, and sending the unique attribute identifier of the first platform key to the secure terminal to instruct the secure terminal to search for a first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data; receiving the first pre-stored platform key returned by the secure terminal, comparing the first platform key with the first pre-stored platform key, and determining the identity authentication result based on the comparison result.
[0137] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: when multiple target platform identity information is determined based on platform key information, randomly selects the authentication operation object pointed to by any one of the target platform identity information as the target authentication operation object.
[0138] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: receiving key data and associated terminal identity information sent by the key filling system; assigning a key identifier corresponding to the associated terminal identity information to the key data to obtain pre-filled key data.
[0139] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0140] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0141] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0142] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. An identity authentication method, characterized in that, The method includes: Receive platform identity information sent by the authentication operation object; Find the key identifier corresponding to the platform identity information from the pre-filled key data; If the key identifier is not found, the platform key information and terminal identity information are sent to the authentication operation object to instruct the authentication operation object to obtain a first platform key that matches the terminal identity information from the target authentication operation object pointed to by the platform key information through a secure channel; The unique attribute identifier of the first platform key returned by the authentication operation object; Find the first pre-stored platform key that corresponds to the unique attribute identifier of the first platform key from the pre-filled key data; The first pre-stored platform key is sent to the authentication operation object to instruct the authentication operation object to compare the first platform key with the first pre-stored platform key, and determine the identity authentication result based on the comparison result.
2. The method according to claim 1, characterized in that, The authentication operation targets include a quantum key service platform or a business system server; the method further includes: In the first authentication mode, the system receives the first identity authentication result returned by the quantum key service platform and the second identity authentication result returned by the business system server; if both the first identity authentication result and the second identity authentication result are successful, the access authentication is determined to be successful. In the second authentication mode, the system receives the first authentication result returned by the quantum key service platform or the second authentication result returned by the business system server; if the first authentication result is successful or the second authentication result is successful, the system determines that the access authentication is successful.
3. The method according to claim 1, characterized in that, The method further includes: If the key identifier is found, the terminal identity information is sent to the authentication operation object to instruct the authentication operation object to find a second platform key that matches the terminal identity information; The unique attribute identifier of the second platform key returned by the authentication operation object; Find the second pre-stored platform key from the pre-filled key data that corresponds to the unique attribute identifier of the second platform key; The second pre-stored platform key is sent to the authentication operation object to instruct the authentication operation object to compare the second platform key with the second pre-stored platform key, and determine the identity authentication result based on the comparison result.
4. The method according to any one of claims 1 to 3, characterized in that, Before receiving the platform identity information sent by the authentication operation object, the method further includes: Receive key data and associated platform identity information sent by the key filling system; Assign a key identifier corresponding to the identity information of the associated platform to the key data to obtain pre-filled key data.
5. An identity authentication method, characterized in that, The method includes: Send platform identity information to the security terminal to instruct the security terminal to search for the key identifier corresponding to the platform identity information from the pre-filled key data. If the key identifier is not found, return the platform key information and the terminal identity information. Receive the platform key information and the terminal identity information returned by the security terminal, and determine the target platform identity information based on the platform key information; Based on the target platform identity information, the target authentication operation object is located, and an auxiliary authentication request including the terminal identity information is sent to the target authentication operation object to instruct the target authentication operation object to select the first platform key from a plurality of pre-stored platform keys corresponding to the terminal identity information; The system receives the first platform key returned by the target authentication operation object through a secure channel, and sends the unique attribute identifier of the first platform key to the secure terminal, so as to instruct the secure terminal to search for the first pre-stored platform key corresponding to the unique attribute identifier of the first platform key from the pre-filled key data; The system receives the first pre-stored platform key returned by the secure terminal, compares the first platform key with the first pre-stored platform key, and determines the authentication result based on the comparison result.
6. The method according to claim 5, characterized in that, The method further includes: When multiple target platform identity information is determined based on the platform key information, the authentication operation object pointed to by any one of the target platform identity information is randomly selected as the target authentication operation object.
7. The method according to claim 5, characterized in that, Before sending the platform identity information to the secure terminal, the method further includes: Receive key data and associated terminal identity information sent by the key filling system; The key data is assigned a key identifier corresponding to the identity information of the associated terminal to obtain pre-filled key data.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.