A browser-extended quantum-resistant authentication release control method and system

By using browser extensions for authentication preprocessing and joint probing, the problem of device misuse and compatibility issues in browser authentication schemes under quantum migration-resistant environments is solved, thereby improving security and compatibility and providing unified audit logs and hybrid authentication support.

CN122419964APending Publication Date: 2026-07-17山东三未信安信息科技有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
山东三未信安信息科技有限公司
Filing Date
2026-06-04
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing browser authentication schemes are susceptible to risks such as accidental device calls, cross-site calls, and calls in low-trust environments under quantum migration resistance. They are difficult to balance compatibility and security, and lack joint judgment on device capabilities, page context, and site policies.

Method used

Authentication preprocessing is performed through browser extensions, various authentication-related messages are collected, the detection channels and device capabilities are jointly explored, site policies are matched, appropriate access channels are selected and algorithm negotiation is performed, controlled rollback is performed when negotiation fails, authentication messages are generated and audit logs are recorded.

Benefits of technology

It reduces the risk of cross-site calls and accidental calls, improves security and compatibility, supports hybrid authentication modes, achieves compatibility and security against quantum migration, and provides unified audit logs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419964A_ABST
    Figure CN122419964A_ABST
Patent Text Reader

Abstract

This invention relates to the field of information security technology, specifically disclosing a quantum-resistant authentication access control method and system based on browser extensions. The method includes: when a browser extension detects a highly sensitive business action, it collects various authentication-related messages, performs joint probing of the current channel, selects an access channel, requests a device capability statement and a device proof digest, and performs joint matching of the various authentication-related messages, device capability statement, and device proof digest with the site policy; if the joint matching is successful, authentication is allowed; after authentication is allowed, the browser extension and the local cryptographic device perform algorithm negotiation; if the negotiation is successful, the local cryptographic device generates a set of authentication messages; if the negotiation fails, a controlled fallback process is initiated. This invention integrates device capability probing, policy matching, and authentication into the browser extension control plane, solving the problem that the browser can access the device but does not know when to allow access.
Need to check novelty before this filing date? Find Prior Art