An authentication method and device, electronic equipment and readable storage medium

CN122554249BActive Publication Date: 2026-09-29FEITIAN TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202611052322.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-07-15
Publication Date
2026-09-29
Estimated Expiration
2046-07-15

AI Technical Summary

Technical Problem

[0004]为了解决现有技术中Windows系统登录与Web登录认证体系割裂、本地动态令牌种子存储安全性低的问题,本发明提供了一种认证方法、装置、电子设备及可读存储介质

Benefits of technology

本发明实施例通过将生物特征验证与动态口令认证相结合,利用生物特征验证服务生成的密钥因子与设备标识动态派生种子密钥,有效保护了令牌种子和登录凭证在本地存储的安全性;种子密钥在认证时生成、使用后释放,不持久化存储,从根本上消除了密钥长期存储被泄露的风险。用户通过一次生物特征识别(如轻触指纹或扫脸)即可完成本地认证,无需记忆和输入复杂密码,操作便捷;认证组件可替换,认证服务器与目标系统分离,易适配单点登录等多场景。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554249B_ABST
    Figure CN122554249B_ABST
Patent Text Reader

Abstract

The application discloses an authentication method and device, and belongs to the technical field of identity authentication and information security. The method comprises the following steps: receiving a triggering operation of a user on an authentication option on a login interface, determining a token type registered by the current user on the current device; calling a system-level biometric verification service to perform first authentication according to the token type; after the first authentication is passed, generating a seed key; obtaining a dynamic password and sending the dynamic password to an authentication server to perform second authentication; after the second authentication is passed, obtaining a locally-stored login credential ciphertext, decrypting the login credential ciphertext by using the seed key to obtain a login credential plaintext, assembling an authentication protocol data packet according to the login credential plaintext and submitting the authentication protocol data packet to a target system to perform authentication, and receiving an authentication result. The application derives the seed key, effectively protects the security of local storage of the token seed and the login credential, and realizes the unity of security and convenience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of identity authentication and information security technology, specifically to an authentication method and apparatus, an electronic device, and a readable storage medium. Background Technology

[0002] With the development of information technology, users typically need to manage multiple accounts and frequently log in to Windows systems and various web services. To ensure security, password policies are becoming increasingly stringent (such as requiring complex characters and regular password changes), which places a heavy burden on users' memory and exposes them to the risk of password leaks or brute-force attacks. Traditional logins can be achieved through software token authentication. Existing software tokens (such as Google Authenticator) provide dynamic passwords based on timestamps or event counts, but their seed storage usually relies on the local file system or a simple keychain, posing a risk of being stolen by malware. Furthermore, scenarios such as Windows system logins and website logins often require maintaining multiple independent credential systems, resulting in a fragmented authentication experience for users in different scenarios and making it difficult to achieve unified and secure identity management.

[0003] Therefore, how to propose a unified and easy-to-use authentication scheme while maintaining high security has become a pressing technical problem to be solved in this field. Summary of the Invention

[0004] To address the issues of fragmented authentication systems for Windows system login and Web login, and low security of local dynamic token seed storage in existing technologies, this invention provides an authentication method, device, electronic device, and readable storage medium.

[0005] In a first aspect, this application provides an authentication method applied to a system including a terminal device, an external device, and an authentication server, the method comprising: Receive user's trigger operation on the authentication option on the login interface, and determine the token type registered by the user on the current device; The system-level biometric verification service is invoked according to the token type to perform the first authentication, and the first authentication result returned by the biometric verification service is obtained. If the first authentication result is successful, then obtain the key factor and device identifier generated by the user when registering for the biometric verification service, and generate a seed key based on the key factor and the device identifier; Obtain a dynamic password, send the dynamic password to the authentication server for a second authentication, and receive the second authentication result returned by the authentication server; If the second authentication result is successful, the locally stored ciphertext of the login credential is obtained, the ciphertext of the login credential is decrypted using the seed key to obtain the plaintext of the login credential, the authentication protocol data packet is assembled according to the plaintext of the login credential and submitted to the target system for authentication, and the authentication result returned by the target system is received.

[0006] In a second aspect, the present invention provides an authentication device, comprising: The first determining module is used to receive the user's trigger operation on the authentication option on the login interface and determine the token type registered by the user on the current device; The first authentication module is used to call the system-level biometric verification service to perform the first authentication according to the token type, and obtain the first authentication result returned by the biometric verification service; The key derivation module is used to obtain the key factor and device identifier generated by the user when registering the biometric verification service when the first authentication result is successful, and generate a seed key based on the key factor and device identifier; The dynamic password authentication module is used to obtain a dynamic password, send the dynamic password to the authentication server for a second authentication, and receive the second authentication result returned by the authentication server. The login authentication module is used to obtain the locally stored ciphertext of the login credential when the second authentication result is successful, decrypt the ciphertext of the login credential using the seed key to obtain the plaintext of the login credential, assemble the authentication protocol data packet according to the plaintext of the login credential and submit it to the target system for authentication, and receive the authentication result returned by the target system.

[0007] Thirdly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the above-described method.

[0008] Fourthly, the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described method.

[0009] Fifthly, the present invention provides a computer program product, including a computer program / instructions, which, when executed by a processor, implement the above-described method.

[0010] Compared with the prior art, this application has the following beneficial effects: This invention combines biometric verification with dynamic password authentication. It utilizes a key factor generated by the biometric verification service and a seed key dynamically derived from the device identifier, effectively protecting the security of locally stored token seeds and login credentials. The seed key is generated during authentication and released after use, without persistent storage, fundamentally eliminating the risk of key leakage due to long-term storage. Users can complete local authentication with a single biometric identification (such as a fingerprint or facial scan), eliminating the need to remember or enter complex passwords, making it convenient. The authentication components are replaceable, the authentication server is separated from the target system, and it is easily adaptable to various scenarios such as single sign-on. Attached Figure Description

[0011] To illustrate more clearly, the embodiments of the present invention or the prior art will be briefly described below with reference to the accompanying drawings. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 This is a schematic diagram of the overall architecture of the authentication system provided in an embodiment of the present invention.

[0013] Figure 2 This is a schematic diagram of an authentication method provided in Embodiment 1 of the present invention.

[0014] Figure 3 This is a schematic diagram of the registration process in an authentication method provided in Embodiment 1 of the present invention.

[0015] Figure 4 This is a schematic diagram of an authentication method provided in Embodiment 2 of the present invention.

[0016] Figure 5 This is a schematic diagram of an authentication method provided in Embodiment 3 of the present invention.

[0017] Figure 6 This is a schematic diagram of an authentication method provided in Embodiment 4 of the present invention. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.

[0019] In the following description, when referring to the accompanying drawings, the same numbers in different drawings denote the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of devices and methods consistent with some aspects of the invention as detailed in the appended claims.

[0020] In the description of this application, the terms “first,” “second,” etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or order; the term “multiple” refers to two or more unless otherwise expressly defined.

[0021] Reference Figure 1 The authentication method provided in this embodiment of the invention is applicable to systems including a terminal device 100 and an authentication server 200. The terminal device 100 is equipped with an operating system that provides system-level biometric verification services for local biometric verification of user identity. The terminal device 100 can be a computing device with an operating system and biometric verification capabilities, such as a personal computer, laptop, workstation, or tablet computer.

[0022] The terminal device 100 is equipped with a credential provisioning module 110, a login management application 120, and a backend service 130.

[0023] The credential provisioning module 110 is registered in the operating system's credential provisioning framework and is used to render authentication options and process login requests on the system login interface.

[0024] In one alternative implementation, the credential provider module 110 is installed as a dynamic link library (DLL) in the operating system directory. After installation, it is registered in the operating system's credential provider registry and credential provider filter registry. The credential provider registry is used by the operating system's login user interface (LogonUI) program to load the credential provider module 110, and the credential provider filter is used to filter existing system credentials, enabling users to log in using the authentication options provided by the credential provider module 110.

[0025] The login management application 120 is used to manage user token activation, registration, and security configuration.

[0026] In one alternative implementation, the login management application 120 is also responsible for managing the authentication protection configuration for users in web application login scenarios.

[0027] Backend service 130 is integrated into the target website or web application to provide authentication services in web login scenarios.

[0028] The authentication server 200 is used to remotely verify dynamic passwords and manage the distribution and lifecycle of token seeds. The terminal device 100 communicates with the authentication server 200 through a communication network.

[0029] In embodiments involving external tokens, the system also involves an external device 300 on which a token application 310 is installed. The external device 300 is a portable computing device independent of the terminal device 100, such as a user's smartphone. The token application 310 installed on the external device 300 is used to generate and display dynamic passwords.

[0030] In the description of this invention, the term "system-level biometric authentication service" refers to a system service supported by the operating system kernel or security subsystem that performs local authentication using user biometric information (such as fingerprints, facial features, iris scans, etc.) or a secure PIN code. This biometric authentication service generates an encrypted key pair associated with the user's account during initial setup.

[0031] "Dynamic password" refers to a one-time password generated based on a seed and a specific algorithm. It can be a one-time password based on a timestamp (TOTP) or a one-time password based on an event counter (HOTP). The embodiments of the present invention do not limit this.

[0032] "Login credentials" refer to the credentials used by a user to prove their identity to an operating system or target website, including but not limited to passwords, PIN codes, etc. Example 1

[0033] like Figure 2 As shown, Embodiment 1 of the present invention provides an authentication method applied to a terminal device equipped with authentication management software. The method includes: Step S101: Receive the user's trigger operation on the authentication option on the login interface and determine the token type registered by the user on the current device.

[0034] In this embodiment, before step S101, the credential providing module renders an authentication option, such as an authentication tile, on the system login interface. The user triggers the authentication option by clicking, touching, or other interactive methods to initiate login and execute step S101.

[0035] After receiving the trigger operation, the credential provisioning module obtains the user identifier of the current user and queries the user configuration information stored locally based on the user identifier to determine the token type registered by the current user on the current device.

[0036] Specifically, the token type is specified and recorded by the user during the registration phase, including soft tokens and external tokens.

[0037] Step S102: Invoke the system-level biometric verification service to perform the first authentication based on the token type, and obtain the first authentication result returned by the biometric verification service.

[0038] In one feasible approach, if the token type determined in step S101 is a soft token, then in step S102 the credential providing module directly calls the system-level biometric verification service for the first authentication.

[0039] The system-level biometric verification service performs the first authentication in the following ways: the operating system pops up a biometric verification interface to prompt the user to perform biometric verification, such as prompting the user to enter a fingerprint for verification or look at the camera for facial verification.

[0040] After the user completes biometric verification on the verification interface, the biometric verification service will match the collected biometric information with the template data stored locally in a secure manner, and return the first authentication result based on the matching result.

[0041] In one feasible approach, if the token type determined in step S101 is an external token, then in step S102 the credential providing module enters the OTP authentication login verification page, and displays the authentication method for the user to choose from. The authentication methods include manual input authentication and push authentication.

[0042] After a user selects an authentication method, the credential provisioning module calls the system-level biometric verification service to perform the first authentication based on the selected authentication method and returns the first authentication result.

[0043] Specifically, if the user selects push authentication as the authentication method, the system-level biometric verification service is invoked to perform the first authentication based on the user's selected authentication method, including: receiving the user's trigger operation for push authentication and invoking the system-level biometric verification service to perform the first authentication; Specifically, if the user selects manual input authentication as the authentication method, the system-level biometric verification service is invoked for the first authentication based on the user's selected authentication method. This includes: the credential provision module displaying an input box on the OTP authentication login verification page to prompt the user to enter a dynamic password, receiving the user's trigger operation upon completion of the input, and invoking the system-level biometric verification service for the first authentication.

[0044] Step S103: If the first authentication result is successful, obtain the key factor and device identifier generated by the current user when registering for the biometric verification service, and generate a seed key based on the key factor and device identifier.

[0045] In this embodiment, if the first authentication result is a verification failure, the login process is terminated, and the user is prompted that the first authentication has failed.

[0046] In this embodiment, after the first authentication is successful, the credential providing module obtains the key factor generated by the user during the initial registration of the system-level biometric verification service. This key factor is the public key in the encryption key pair generated by the biometric verification service during user registration. The credential providing module also obtains the device identifier, which is an identifier that uniquely identifies the current terminal device.

[0047] The credential provisioning module generates a seed key based on the key factor and device identifier.

[0048] Specifically, the credential providing module generates a seed key based on the key factor and the device identifier, including: performing a combination operation on the key factor and the device identifier to obtain the seed key, for example, concatenating the two and then performing a cryptographic hash operation to obtain the seed key. This seed key is generated in memory and is not written to permanent storage media.

[0049] Step S104: Obtain the dynamic password, send the dynamic password to the authentication server for second authentication, and receive the second authentication result returned by the authentication server.

[0050] In one feasible approach, if the token type determined in step S101 is a soft token, the credential providing module obtains the locally stored seed ciphertext in step S104, decrypts the seed ciphertext using the seed key generated in step S103 to obtain the seed plaintext, and calculates the dynamic password using a dynamic password algorithm based on the seed plaintext.

[0051] Specifically, the seed ciphertext is ciphertext data generated and stored locally by the user during the registration phase.

[0052] In one feasible manner, if the token type determined in step S101 is an external token and the user chooses to manually input authentication, then in step S104, the credential providing module obtains the dynamic password entered by the user on the OTP authentication login verification page, sends the dynamic password to the authentication server for second authentication, and receives the second authentication result.

[0053] Specifically, the dynamic password is generated by a token application installed on an external device based on a stored token seed.

[0054] In one feasible manner, if the token type determined in step S101 is an external token and the user selects push authentication, then in step S104, the credential providing module sends a push request to the authentication server. After receiving the push request, the authentication server sends login confirmation information to the external device. After receiving the login confirmation information, the token application on the external device calculates the dynamic password and returns it to the authentication server for verification. After the authentication server verifies the password, it returns a second authentication result of successful verification to the credential providing module.

[0055] Preferably, the authentication server sends login confirmation information to the external device after receiving the push request as follows: After receiving the push request, the authentication server obtains the device identifier of the external device stored corresponding to the identifier of the user to be logged in, and sends login confirmation information to the external device according to the device identifier.

[0056] Step S105: If the second authentication result is successful, obtain the locally stored ciphertext of the login credential, decrypt the ciphertext of the login credential using the seed key to obtain the plaintext of the login credential, assemble the authentication protocol data packet based on the plaintext of the login credential and submit it to the target system for authentication, and receive the authentication result returned by the target system.

[0057] In this embodiment, if the second authentication result is a verification failure, the login process is terminated, and the user is prompted that the second authentication has failed.

[0058] In this embodiment, the credential providing module obtains the locally stored ciphertext of the login credential, decrypts the ciphertext of the login credential using the seed key generated in step S103 to obtain the plaintext of the login credential, and assembles the authentication protocol data packet according to the username in the user identifier saved in the registration process and the plaintext of the login credential. Specifically, the login credential ciphertext is the encrypted data stored after the login credentials entered by the user during the registration process are encrypted.

[0059] In the system login scenario, the credential provisioning module calls the operating system's security authentication interface to submit the assembled authentication protocol data packet to the target system for authentication.

[0060] In this embodiment, the target system refers to the operating system or target website / website application that requires login; It should be noted that this application does not specifically limit the relationship between the seed key used for encrypting / decrypting login credentials and the seed key used for encrypting / decrypting seed data. That is, they can be different independent keys or the same key. This embodiment is only described as a preferred implementation, using the same key as an example. However, those skilled in the art should understand that using different keys also falls within the protection scope of this application and should not be considered a limitation on the technical solution.

[0061] In this embodiment, the target system authenticates the credential information in the authentication protocol data packet. If the authentication is successful, the system unlocks and enters the desktop or operation page, returning the authentication success result to the credential providing module. If the authentication fails, the system returns the authentication failure result to the credential providing module. Preferably, the credential providing module receives the authentication result returned by the target system. If the authentication result is successful, the method ends; if the authentication result is unsuccessful, the user is prompted that the login failed.

[0062] One possible implementation method, this embodiment provides a registration process in an authentication method, referring to... Figure 3 The method includes the following steps: Step S201: The login management application receives a token activation request.

[0063] Users initiate a token activation request by logging into the management application. This token activation request contains information about the token type selected by the user, such as a soft token or an external token.

[0064] Step S202: Check whether the system-level biometric verification service has been registered. If so, proceed to step S203; otherwise, guide the user to complete the initial registration of the biometric verification service and proceed to step S203.

[0065] In this embodiment, the login management application calls the system interface to check whether the system-level biometric verification service has completed registration for the current user. If not, the user is guided to complete the initial registration of the biometric verification service, including entering fingerprint information, scanning facial information, or setting a security PIN code.

[0066] In this embodiment, when the system-level biometric verification service Windows Hello is first set up, it generates an asymmetric key pair (public key and private key) for the combination of the current user account and the current device. The private key is securely stored in the trusted platform module (TPM) chip of the device and will never leave the device, while the public key is sent and registered to the system account. In this invention, the public key participates in the generation of the seed key.

[0067] Step S203: Prompt the user to log in and receive the verification result.

[0068] The login management application prompts the user to verify their login credentials, such as by prompting the user to enter their current system login password. It receives the verification result returned by the system. If the verification is successful, it obtains and saves the user's entered identifier and executes step S204. If the verification fails, it prompts the user that the registration failed.

[0069] Step S204: Obtain the key factor and device identifier generated by the user when registering for the biometric verification service, and generate a seed key based on the key factor and device identifier.

[0070] Step S205: Encrypt the login credentials entered by the user during login verification using the seed key to obtain the ciphertext of the login credentials and save it.

[0071] The login management application encrypts the login credentials in the user identifier entered by the user in step S203 using the seed key, obtains the ciphertext of the login credentials, and saves the ciphertext of the login credentials locally.

[0072] Step S206: Send a seed generation request containing the device identifier to the authentication server and receive the seed data returned by the authentication server.

[0073] The login management application sends the device identifier in the seed generation request to the authentication server. The authentication server generates seed data corresponding to the device identifier and returns it to the login management application.

[0074] Step S207: Determine the type of token selected by the current user for binding. If it is a soft token, proceed to step S208; if it is an external token, proceed to step S209.

[0075] Step S208: Generate a dynamic password based on the seed data and send it to the authentication server for verification. After successful verification, encrypt the seed data using the seed key to obtain the seed ciphertext and store it locally, indicating successful registration.

[0076] Step S209: Display a QR code containing seed data, receive the activation response returned by the authentication server after the user scans the QR code through an external device, and determine whether the registration was successful based on the activation response.

[0077] In this embodiment, the user scans a QR code using a token application on an external device. The token application parses the QR code to obtain a token seed and stores the token seed. The token application then generates a dynamic password based on the token seed and sends it to the authentication server for verification. After successful verification, the authentication server returns an activation success response to the login management application. The login management application receives this response and confirms successful registration.

[0078] Preferably, the process of the token application generating a dynamic password based on the token seed and sending it to the authentication server for verification further includes: the token application sending the device identifier of the external device to the authentication server; and the authentication server generating login confirmation information based on the stored device identifier of the external device during login.

[0079] This invention combines biometric verification with dynamic password authentication. It utilizes a key factor generated by the biometric verification service and a seed key dynamically derived from the device identifier, effectively protecting the security of the token seed and login credentials stored locally. The seed key is generated during authentication and released after use, without persistent storage, fundamentally eliminating the risk of key leakage due to long-term storage. Furthermore, in the soft token scheme, both the seed ciphertext and the login credential ciphertext are protected by the seed key; in the external token scheme, the token seed is physically isolated from the terminal device, and the login credential ciphertext is also protected by the seed key. All scenarios maintain a unified authentication order of biometric verification first, followed by dynamic password verification, and provide multiple interaction methods such as manual input and push notifications, adapting to both system login and web login scenarios, achieving a balance between security and convenience. Example 2

[0080] This second embodiment provides an authentication method for the system login process when the user registers a soft token on the current device.

[0081] Reference Figure 4 The method includes the following steps: Step S301: The credential provisioning module receives the user's trigger operation on the authentication option on the login interface.

[0082] In this embodiment, when the user is in the system lock screen state, the credential provisioning module has rendered an authentication option, such as an authentication tile, on the system login interface.

[0083] Users initiate login by clicking, touching, or engaging in other interactive methods to trigger the authentication option. The credential provisioning module receives this trigger.

[0084] In this embodiment, the credential provisioning module obtains the user identifier entered by the user and saved by the login management application during the registration process, and displays the user identifier on the authentication options or in the system login interface; In step S302, after receiving the trigger operation, the credential providing module obtains the user's user identifier and queries the locally stored user configuration information based on the user identifier to determine that the token type registered by the user on the current device is a soft token.

[0085] Step S303: Call the system-level biometric verification service to perform the first authentication, obtain the first authentication result, and determine whether the first authentication result is successful. If so, proceed to step S304; otherwise, prompt the user that the first authentication has failed.

[0086] Since the token type is a soft token, the credential providing module directly calls the system-level biometric verification service for the first authentication.

[0087] Specifically, the operating system pops up a biometric verification interface, such as prompting the user to enter their fingerprint or prompting the user to look at the camera to scan their facial information. The user completes the biometric verification on the verification interface, and the biometric verification service matches the collected biometric information with the template data stored locally in a secure manner, and returns the first authentication result based on the matching result.

[0088] If verification fails, the process is aborted, and the user is notified that the first authentication failed.

[0089] Step S304: Obtain the key factor and device identifier, and generate a seed key based on the key factor and device identifier.

[0090] The credential provisioning module obtains the key factor generated when the current user registers for the biometric verification service, and also obtains the device identifier. The key factor is the public key in the encryption key generated by the biometric verification service during the user's initial registration, and is protected by the operating system security mechanism and hardware. The device identifier is an identifier that can uniquely identify the current terminal device.

[0091] The credential providing module generates a seed key based on the key factor and the device identifier. Specifically, it performs a combination operation on the key factor and the device identifier to generate the seed key.

[0092] In one alternative implementation, the combination operation is a hash operation in cryptography, that is, the hash value obtained by concatenating the key factor and the device identifier is used as the seed key.

[0093] Specifically, the seed key is generated in memory and is not written to persistent storage.

[0094] Step S305: Obtain the locally stored seed ciphertext, decrypt the seed ciphertext using the seed key to obtain the seed plaintext, and calculate the dynamic password based on the seed plaintext.

[0095] The credential provisioning module obtains the locally stored seed ciphertext, which is the ciphertext data stored locally on the device after the user encrypts the token seed with the seed key at that time during the registration phase. The credential provisioning module decrypts the seed ciphertext using the current seed key to obtain the seed plaintext, and then calculates the dynamic password based on the seed plaintext using a dynamic password algorithm.

[0096] In one alternative implementation, a time-based one-time password (TOTP) algorithm is used, which takes the current timestamp and seed plaintext as input, and generates a dynamic password through HMAC operation and truncation processing.

[0097] Step S306: Send the dynamic password to the authentication server for second authentication, receive the second authentication result, and determine whether the second authentication result is successful. If so, proceed to step S307; otherwise, prompt the user that the second authentication has failed.

[0098] The credential provisioning module sends the calculated dynamic password to the authentication server via the communication network. The authentication server stores a verification copy corresponding to the user's token seed, calculates the expected dynamic password using the same algorithm, and compares it with the received dynamic password. If they match, it returns a second authentication result that has passed the verification; otherwise, it returns a second authentication result that has failed the verification.

[0099] If the second authentication result is successful, proceed to step S307. If the authentication fails, the process is aborted, and the user is notified that the second authentication has failed.

[0100] Step S307: Obtain the locally stored ciphertext of the login credentials, and decrypt the ciphertext of the login credentials using the seed key to obtain the plaintext of the login credentials.

[0101] After the second authentication is successful, the credential provisioning module obtains the locally stored login credential ciphertext. The login credential ciphertext is the encrypted data stored after the login credentials in the user identifier are encrypted by the seed key generated during the registration phase when the user registers on the current device.

[0102] Step S308: Assemble the authentication protocol data packet according to the plaintext login credentials and submit it to the target system for authentication, and receive the authentication result returned by the target system.

[0103] The credential provisioning module assembles the authentication protocol data packet based on the username and login credentials in plaintext. In the system login scenario, the credential provisioning module calls the operating system's security authentication interface, such as LsaConnectUntrusted and LsaLookupAuthenticationPackage, to submit the authentication protocol data packet to the target system for authentication. The credential provisioning module receives the authentication result returned by the target system through the result callback interface.

[0104] Step S309: Determine whether the login was successful based on the authentication result.

[0105] In this embodiment, if the authentication result returned by the target system is successful, the login is successful, the operating system is unlocked and switched to the user's desktop; if the authentication result is unsuccessful, the user is prompted that the login failed. Example 3

[0106] This third embodiment provides an authentication method for the system login process when the user registers an external token on the current device.

[0107] Reference Figure 5 The method includes the following steps: Step S401: The credential provisioning module receives the user's trigger operation on the authentication option on the login interface.

[0108] In this embodiment, the credential providing module renders the authentication option on the system login interface. When the user triggers the authentication option, the credential providing module receives the trigger operation information.

[0109] Step S402: Obtain the user identifier of the current user, query the user configuration information stored locally based on the user identifier, and determine the token type registered by the current user on the current device as an external token based on the user configuration information.

[0110] Step S403: Enter the OTP authentication login verification page and display the authentication method for the user to choose. When the user chooses manual authentication, proceed to step S404. When the user chooses push authentication, proceed to step S409.

[0111] Since the token type is an external token, the credential provisioning module enters the OTP authentication login verification page, which displays the authentication methods for the user to choose from. The authentication methods include manual input authentication and push authentication.

[0112] Step S404: Display an input box for the user to enter a dynamic password.

[0113] The credential provisioning module displays a dynamic password input box on the page based on the user's selection. The user can view the current dynamic password from the token application on the external device and manually enter the dynamic password into the input box.

[0114] In one alternative implementation, the external device is the user's mobile phone, and the token application is a mobile token application installed on the mobile phone. The mobile token application calculates and generates a dynamic password based on the token seed stored locally and displays it on the mobile phone screen.

[0115] Step S405: Receive the dynamic password input by the user and the trigger operation for the input completion, call the system-level biometric verification service to perform the first authentication, obtain the first authentication result, and determine whether the first authentication result is successful. If so, proceed to step S406; otherwise, authentication fails.

[0116] In this embodiment, after the user completes the input of the dynamic password in the input box, they click the confirmation button or a similar interactive control to indicate that the input is complete. The credential provision module receives the user's trigger operation for the input completion, calls the system-level biometric verification service to perform the first authentication according to the manual input authentication method, the operating system pops up the biometric verification interface, the user completes the biometric verification, and the biometric verification service returns the first authentication result.

[0117] If the first authentication result is successful, proceed to step S406. If the authentication fails, the process is terminated.

[0118] Step S406: Obtain the key factor and device identifier, and generate a seed key based on the key factor and device identifier.

[0119] After the first authentication is successful, the credential providing module obtains the key factor generated by the current user when registering for the biometric verification service, as well as the device identifier, and generates a seed key based on the key factor and the device identifier. The generation method is the same as step S304 in Embodiment 2.

[0120] Step S407: Obtain the cached dynamic password and send it to the authentication server for secondary authentication.

[0121] The credential provisioning module obtains the dynamic password entered and temporarily stored by the user in step S405, and sends the dynamic password to the authentication server for second authentication.

[0122] Step S408: Receive the second authentication result returned by the authentication server, and determine whether the second authentication result is successful. If so, proceed to step S414; otherwise, authentication fails.

[0123] The credential provisioning module receives the second authentication result returned by the authentication server. If the verification is successful, step S414 is executed; if the verification fails, the process is terminated.

[0124] Step S409: Receive the user's trigger operation for push authentication method, call the system-level biometric verification service to perform the first authentication, obtain the first authentication result, and determine whether the first authentication is successful. If so, proceed to step S410; otherwise, authentication fails.

[0125] The credential provisioning module displays a push authentication button on the page. When the user clicks the push authentication button, the credential provisioning module receives the trigger operation information, calls the system-level biometric verification service to perform the first authentication, the operating system pops up the biometric verification interface, and after the user completes the biometric verification, the biometric verification service returns the first authentication result to the credential provisioning module.

[0126] If the first authentication result is successful, proceed to step S410; if the authentication fails, the process is terminated.

[0127] Step S410: Obtain the key factor and device identifier, and generate a seed key based on the key factor and device identifier.

[0128] After the first authentication is successful, the credential provisioning module obtains the key factor generated by the current user when registering for the biometric verification service, as well as the device identifier, and generates a seed key based on the key factor and the device identifier.

[0129] Step S411: Send a push request to the authentication server, triggering the authentication server to send login confirmation information to the external device.

[0130] The credential provisioning module sends a push request to the authentication server, which contains information such as user identifier and device identifier. After receiving the push request, the authentication server sends login confirmation information to the token application on the pre-bound external device.

[0131] In step S412, the token application on the external device calculates a dynamic password and sends it to the authentication server for verification.

[0132] After receiving the login confirmation information, the token application on the external device displays a login confirmation interface to the user. After the user confirms the login, the token application automatically calculates a dynamic password based on the token seed stored locally and sends the dynamic password to the authentication server. The authentication server verifies the dynamic password and returns a second authentication result to the credential providing module after successful verification.

[0133] Step S413: Receive the push result returned by the authentication server as the second authentication result, and determine whether the second authentication result is successful. If so, proceed to step S414; otherwise, the authentication fails.

[0134] The credential provisioning module receives the second authentication result returned by the authentication server. If the verification is successful, step S414 is executed; if the verification fails, the process is terminated.

[0135] Step S414: Obtain the locally stored ciphertext of the login credentials, and decrypt the ciphertext of the login credentials using the seed key to obtain the plaintext of the login credentials.

[0136] Step S415: Assemble the authentication protocol data packet based on the plaintext login credentials and submit it to the target system for authentication, and receive the authentication result returned by the target system.

[0137] Step S416: Determine whether the login was successful based on the authentication result.

[0138] Steps S414 to S416 are the same as steps S307 to S309 in Embodiment 2, and will not be repeated here. Example 4

[0139] This fourth embodiment provides an authentication method for the authentication process when the login interface is a web login interface.

[0140] Reference Figure 6 The method includes the following steps: Step S501: The backend service receives the user's trigger operation on the authentication option on the web login interface.

[0141] Users access the target website that integrates the backend service through a browser and enter the login page. The backend service generates authentication options on the web login interface, such as a login interface element that says "Log in with Windows Hello and dynamic password". When the user clicks the authentication option, the backend service receives the trigger operation.

[0142] Step S502: Determine the token type registered by the current user on the current device.

[0143] The backend service obtains the user's identifier and determines the token type registered by the current user on the current device.

[0144] Step S503: Based on the token type, call the system-level biometric verification service to perform the first authentication and obtain the first authentication result.

[0145] If the token type determined in step S502 is a soft token, in step S503 the backend service directly calls the system-level biometric verification service through the web authentication interface to perform the first authentication; if the token type determined in step S502 is an external token, in step S503 the backend service enters the OTP authentication login verification page, displays two authentication methods: manual input and push, and calls the system-level biometric verification service to perform the first authentication according to the authentication method selected by the user. The specific calling method corresponds to the first authentication calling method described in embodiments two and three.

[0146] Step S504: Determine whether the first authentication result is successful. If so, obtain the key factor and device identifier, generate a seed key based on the key factor and device identifier, and execute step S505. Otherwise, authentication fails.

[0147] Step S505: Obtain the dynamic password, send it to the authentication server for secondary authentication, and receive the secondary authentication result.

[0148] The method of obtaining the dynamic password is determined by the token type. If it is a soft token, the local seed ciphertext is obtained, and the dynamic password is calculated after decrypting the local seed ciphertext. If it is an external token that is manually entered, the dynamic password entered by the user is obtained. If it is an external token that is pushed, the dynamic password is calculated by the external device through the push process.

[0149] Step S506: Determine whether the second authentication result is successful. If so, obtain the ciphertext of the login credential, decrypt the ciphertext of the login credential to obtain the plaintext of the login credential, and execute step S507. Otherwise, authentication fails.

[0150] Step S507: Assemble the authentication protocol data packet based on the plaintext login credentials and submit it to the target website for authentication, and receive the authentication result returned by the target website.

[0151] The backend service assembles an authentication protocol data packet based on the plaintext login credentials and the username in the user identifier, and submits it to the target website for authentication. The target website verifies the authentication protocol data packet and returns the authentication result. The backend service receives the authentication result returned by the target website.

[0152] Step S508: Determine whether the login was successful based on the authentication result of the target website.

[0153] If authentication is successful, the backend service notifies the frontend to redirect to the logged-in page; if authentication fails, the user is prompted that login has failed. Example 5

[0154] Embodiment 5 of the present invention provides an authentication device, comprising: The first determining module is used to receive the user's trigger operation on the authentication option on the login interface and determine the token type registered by the current user on the current device; The first authentication module is used to call the system-level biometric verification service to perform the first authentication based on the token type and obtain the first authentication result returned by the biometric verification service. The key derivation module is used to obtain the key factor and device identifier generated by the current user when registering for the biometric verification service when the first authentication result is successful, and to generate a seed key based on the key factor and device identifier. The dynamic password authentication module is used to obtain a dynamic password, send the dynamic password to the authentication server for secondary authentication, and receive the secondary authentication result returned by the authentication server. The login authentication module is used to obtain the locally stored ciphertext of the login credentials when the second authentication result is successful, decrypt the ciphertext of the login credentials using the seed key to obtain the plaintext of the login credentials, assemble the authentication protocol data packet according to the plaintext of the login credentials and submit it to the target system for authentication, and receive the authentication result returned by the target system.

[0155] In one feasible manner, the first determining module is specifically used to trigger the first authentication module when it determines that the token type registered by the user on the current device is a soft token; The dynamic password authentication module is specifically used to obtain the locally stored seed ciphertext, decrypt the seed ciphertext using the seed key to obtain the seed plaintext, and calculate the dynamic password based on the seed plaintext.

[0156] In one feasible manner, the first determining module is specifically used to trigger the first authentication module when it determines that the token type registered by the user on the current device is an external token; The first authentication module is specifically used to redirect to the OTP authentication login verification page and display authentication methods for the user to choose from, receive the authentication method selected by the user, and call the system-level biometric verification service to perform the first authentication according to the authentication method.

[0157] Specifically, if the user selects push authentication as the authentication method, the first authentication module is specifically used to call the system-level biometric verification service to perform the first authentication according to the authentication method, and is also used to receive the user's trigger operation for push authentication and call the system-level biometric verification service to perform the first authentication. The dynamic password authentication module is specifically used to send a push request to the authentication server. After receiving the push request, the authentication server sends login confirmation information to the external device. After receiving the login confirmation information, the token application installed on the external device calculates the dynamic password and returns it to the authentication server for verification.

[0158] Specifically, if the authentication method selected by the user is manual input authentication, the first authentication module is specifically used to call the system-level biometric verification service to perform the first authentication according to the authentication method, and is also used to display an input box to prompt the user to enter a dynamic password, receive the user's trigger operation after the input is completed, and call the system-level biometric verification service to perform the first authentication. The dynamic password authentication module is specifically used to obtain the dynamic password input by the user. The dynamic password is generated by a token application installed on an external device based on a stored token seed.

[0159] In one implementable manner, the apparatus further includes a rendering generation module for rendering the authentication options on the login interface based on a credential providing module registered with the target system.

[0160] In one feasible manner, the login interface is a web login interface, and the device further includes a rendering generation module for generating login interface elements based on backend services integrated into the target website to obtain the authentication options. The login authentication module is specifically used to assemble an authentication protocol data packet based on the plaintext login credentials and submit it to the target website for authentication, and to receive the authentication result returned by the target website.

[0161] In one implementable manner, the device further includes a registration module, which comprises: a receiving and processing unit, a sending unit, and a verification unit; The receiving and processing unit is used to receive a token activation request, check whether the system-level biometric verification service has been registered, if so, prompt the user to perform login verification and receive the verification result. If the verification result is successful, the user identifier is saved, the key factor generated by the user when registering the biometric verification service and the device identifier are obtained, the seed key is generated according to the key factor and the device identifier, and the login credentials in the user identifier are encrypted with the seed key to obtain the login credentials ciphertext and saved. The sending unit is used to send a seed generation request containing the device identifier to the authentication server; The receiving and processing unit is also used to receive seed data returned by the authentication server; The verification unit is used to initiate verification to the authentication server based on the seed data, receive the verification result returned by the authentication server, and determine whether the registration is successful based on the verification result.

[0162] Specifically, the verification unit is used to detect the token type specified in the token activation request. If it is a soft token, a dynamic password is generated based on the seed data, and the dynamic password is sent to the authentication server for verification. If the verification is successful, the seed data is encrypted using the seed key to obtain seed ciphertext and stored locally. If it is an external token, a QR code containing the seed data is displayed, and the authentication server receives the activation response returned by the user after scanning the QR code through an external device. The registration is then determined to be successful based on the activation response.

[0163] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0164] This invention also provides an electronic device, including a memory and a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method of any of the foregoing embodiments.

[0165] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the method steps of any of the foregoing embodiments. The computer-readable storage medium may include, but is not limited to, any type of disk, including floppy disks, optical disks, DVDs, CD-ROMs, microdrives, as well as magneto-optical disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices, magnetic cards or optical cards, nanosystems (including molecular memory ICs), or any type of medium or device suitable for storing instructions and / or data.

[0166] This invention provides a computer program product, including a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the method of any of the foregoing embodiments.

[0167] In this invention, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or order; the term "multiple" refers to two or more unless otherwise explicitly defined. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. The terms "install," "connect," "link," "fix," etc., should be interpreted broadly. For example, "connect" can be a fixed connection, a detachable connection, or an integral connection; "link" can be a direct connection or an indirect connection through an intermediate medium. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0168] In the description of this invention, it should be understood that the terms "upper" and "lower" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or unit referred to must have a specific orientation or be constructed and operated in a specific orientation. Therefore, they should not be construed as limiting this invention.

[0169] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, equivalent variations made according to the claims of the present invention are still within the scope of the present invention.

Claims

1. An authentication method applied to a system including terminal devices and an authentication server, characterized in that, The method includes: Receive user's trigger operation on the authentication option on the login interface, and determine the token type registered by the user on the current device; The system-level biometric verification service is invoked according to the token type to perform the first authentication, and the first authentication result returned by the biometric verification service is obtained. If the first authentication result is successful, then obtain the key factor and device identifier generated by the user when registering for the biometric verification service, and generate a seed key based on the key factor and the device identifier; Obtain a dynamic password, send the dynamic password to the authentication server for a second authentication, and receive the second authentication result returned by the authentication server; If the second authentication result is successful, the locally stored ciphertext of the login credential is obtained, the ciphertext of the login credential is decrypted using the seed key to obtain the plaintext of the login credential, the authentication protocol data packet is assembled according to the plaintext of the login credential and submitted to the target system for authentication, and the authentication result returned by the target system is received.

2. The method according to claim 1, characterized in that, If it is determined that the token type registered by the user on the current device is a soft token, the step of calling the system-level biometric verification service for the first authentication based on the token type includes: directly calling the system-level biometric verification service for the first authentication; The process of obtaining the dynamic password includes: obtaining the locally stored seed ciphertext, decrypting the seed ciphertext using the seed key to obtain the seed plaintext, and calculating the dynamic password based on the seed plaintext.

3. The method according to claim 1, characterized in that, If it is determined that the token type registered by the user on the current device is an external token, the step of calling the system-level biometric verification service for the first authentication based on the token type includes: redirecting to the OTP authentication login verification page and displaying authentication methods for the user to choose from, receiving the authentication method selected by the user, and calling the system-level biometric verification service for the first authentication based on the authentication method.

4. The method according to claim 3, characterized in that, If the user selects push authentication as the authentication method, the system-level biometric verification service is invoked to perform the first authentication according to the authentication method, including: receiving the user's trigger operation for push authentication and invoking the system-level biometric verification service to perform the first authentication; The step of obtaining the dynamic password and sending the dynamic password to the authentication server for second authentication includes: A push request is sent to the authentication server. After receiving the push request, the authentication server sends login confirmation information to the external device. After receiving the login confirmation information, the token application installed on the external device calculates a dynamic password and returns it to the authentication server for verification.

5. The method according to claim 3, characterized in that, If the user selects manual input authentication as the authentication method, the system-level biometric verification service is invoked to perform the first authentication according to the authentication method, including: displaying an input box to prompt the user to enter a dynamic password, receiving the user's trigger operation after the input is completed, and invoking the system-level biometric verification service to perform the first authentication; The process of obtaining the dynamic password includes: The system obtains the dynamic password input by the user, which is generated by a token application installed on an external device based on a stored token seed.

6. The method according to claim 1, characterized in that, Before receiving the user's trigger operation on the authentication option on the login interface, the method further includes: generating the authentication option on the login interface based on the credential providing module registered in the target system.

7. The method according to claim 1, characterized in that, The login interface is a web login interface. Before receiving the user's trigger operation on the authentication options on the login interface, the method further includes: generating login interface elements based on the backend service integrated into the target website to obtain the authentication options. Assemble an authentication protocol data packet based on the plaintext login credentials and submit it to the target system for authentication, and receive the authentication result returned by the target system, including: assembling an authentication protocol data packet based on the plaintext login credentials and submitting it to the target website for authentication, and receiving the authentication result returned by the target website.

8. The method according to claim 1, characterized in that, The method also includes a registration process, which includes: Upon receiving a token activation request, the system checks whether the system-level biometric verification service has been registered. If so, the user is prompted to log in and the verification result is received. If the verification result is successful, the user identifier is saved. The key factor generated by the user when registering the biometric verification service and the device identifier are obtained. The seed key is generated based on the key factor and the device identifier. The login credentials in the user identifier are encrypted using the seed key to obtain the ciphertext of the login credentials and saved. Send a seed generation request containing the device identifier to the authentication server, receive seed data returned by the authentication server, initiate verification with the authentication server based on the seed data, receive the verification result returned by the authentication server, and determine whether the registration is successful based on the verification result.

9. The method according to claim 8, characterized in that, The step of initiating verification with the authentication server based on the seed data, receiving the verification result returned by the authentication server, and determining whether the registration was successful based on the verification result includes: The token type specified in the token activation request is detected. If it is a soft token, a dynamic password is generated based on the seed data, and the generated dynamic password is sent to the authentication server for verification. If the verification is successful, the seed data is encrypted using the seed key to obtain the seed ciphertext and stored locally. If it is an external token, a QR code containing the seed data is displayed, and the authentication server receives the activation response returned by the user after scanning the QR code through an external device. The registration is then determined to be successful based on the activation response.

10. An authentication device, characterized in that, The device includes: The first determining module is used to receive the user's trigger operation on the authentication option on the login interface and determine the token type registered by the user on the current device; The first authentication module is used to call the system-level biometric verification service to perform the first authentication according to the token type, and obtain the first authentication result returned by the biometric verification service; The key derivation module is used to obtain the key factor and device identifier generated by the user when registering the biometric verification service when the first authentication result is successful, and generate a seed key based on the key factor and device identifier; The dynamic password authentication module is used to obtain a dynamic password, send the dynamic password to the authentication server for a second authentication, and receive the second authentication result returned by the authentication server. The login authentication module is used to obtain the locally stored ciphertext of the login credential when the second authentication result is successful, decrypt the ciphertext of the login credential using the seed key to obtain the plaintext of the login credential, assemble the authentication protocol data packet according to the plaintext of the login credential and submit it to the target system for authentication, and receive the authentication result returned by the target system.

11. An electronic device comprising a memory and a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 9.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.

13. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the method of any one of claims 1 to 9.

Citation Information

Patent Citations

  • Dynamic password authentication method

    CN101197667A

  • Identity authentication method and device

    CN107612940A