ROOT SYSTEM AND MULTIFACTOR AUTHENTICATION METHOD BASED ON IPV6
Patent Information
- Authority / Receiving Office
- RU · RU
- Patent Type
- Applications
- Current Assignee / Owner
- ХУ ЦЯНЬЦЯНЬ
- Filing Date
- 2024-12-25
- Publication Date
- 2026-07-06
AI Technical Summary
Traditional root servers are insecurity and inconvenient to operate, and cannot meet the convenience needs of governments, enterprises, families, individuals, etc.
The multi-factor authentication root system based on IPv6 is adopted, and the user identity information and enterprise information are obtained through the first acquisition module, the second acquisition module obtains the IPv6 digital address, and the third acquisition module obtains the certificate and key of the digital authentication center. The information authentication module performs digital authentication, generates electronic name seals and official seals, and uses the root certificate issuance module to perform multi-key verification and issuance.
It realizes dual-stack interoperability between IPv6 and IPv4, multi-category authentication interoperability and mutual recognition, supports multi-certificate and multi-key application, is independent of the international CA certification system, is safe and reliable, supports the digitization of Chinese strokes, and forms a unified and intensive multi-element, multi-key, and multi-certificate authentication system.
Abstract
Description
Multi-factor authentication root system and method based on IPv6 Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a root system and method. Background Art
[0002] The root server is a digital trust service facility. However, traditional root servers usually require the certification process of an international digital certification center, and often only use single-key, single-certificate, and single-platform authentication. They are only suitable for centralized cloud deployment and have security concerns. They are not convenient for governments, businesses, families, and individuals.
[0003] Therefore, those skilled in the art urgently need to develop a root server (i.e., root system) and method that can effectively solve security concerns, operational inconveniences, and other problems, to create an integrated platform from certification, credit enhancement, credit investigation to trust, and realize the full life cycle management of digital assets of governments, enterprises, families, and individuals.
[0004] It should be noted that the above technical background is merely provided to provide a clear and complete description of the technical solutions of the present invention and to facilitate understanding by those skilled in the art. Simply because these solutions are described in the technical background section of the present invention, it should not be assumed that the above technical solutions are well known to those skilled in the art. Summary of the Invention
[0005] In order to overcome the defects in the prior art, the embodiments of the present invention provide a multi-factor authentication root system and method based on IPv6.
[0006] The embodiment of the present application discloses a multi-factor authentication root system based on IPv6, comprising: a first acquisition module for acquiring a user's multiple identity information, multiple enterprise information and enterprise code; a second acquisition module for acquiring the user's IPv6 digital address, wherein the IPv6 digital address includes multiple sets of sixteen-bit address segments; a third acquisition module for acquiring multiple digital certificates and corresponding multiple keys provided by multiple digital certification centers; an information authentication module for authenticating the user's multiple identity information and multiple keys based on the multiple sets of sixteen-bit address segments of the IPv6 digital address; A plurality of enterprise information is digitally authenticated, and a plurality of authenticated identity information and a plurality of authenticated enterprise information are generated; an electronic seal / official seal generation module is used to generate a user's electronic seal and electronic official seal based on a plurality of authenticated identity information and a plurality of authenticated enterprise information; a root certificate issuance module is used to link a plurality of digital certification centers through a third capture module when a user issues a root certificate issuance request, perform multi-key verification on a plurality of authenticated identity information and a plurality of authenticated enterprise information based on a plurality of digital certificates and a corresponding plurality of keys, and issue a plurality of root certificates.
[0007] Furthermore, the electronic name seal is a printed electronic name seal or a handwritten electronic name seal. Optionally, the electronic name seal also requires a handwritten signature.
[0008] Furthermore, the root system also includes: a binding module for binding the enterprise code with the IPv6 digital address and generating an IPv6-based domain name.
[0009] Furthermore, the enterprise code is bound to a landline phone number, and the landline phone number is a digital application that meets the global financial security level.
[0010] Furthermore, the IPv6-based multi-factor authentication root system is a global digital application authentication and encryption chain operating system.
[0011] Furthermore, the root system also includes: a stroke digitization module, which is used to convert each Chinese character in the plurality of identity information into a set of digital codes according to a stroke digital code table.
[0012] Furthermore, the root system also includes multiple modules. The multiple modules include: a central control module, and a communication module, an identity authentication module, a key module, and a storage module connected to the central control module; the communication module is used to realize communication between the multi-factor authentication root system based on IPv6 and an external server; the identity authentication module is used to authenticate the biometric data input by the user to generate authenticated biometric data, and authorize the user after the authentication is passed; the key module is used to store a plurality of keys and encrypt a plurality of authenticated identity information and a plurality of authenticated enterprise information according to corresponding keys in the plurality of keys to generate a plurality of encrypted authenticated identity information and a plurality of encrypted authenticated enterprise information; the storage module is used to store the authenticated biometric data, a plurality of encrypted authenticated identity information, a plurality of encrypted authenticated enterprise information, an electronic seal, an electronic official seal, and a plurality of root certificates; and the central control module is used to receive input and control the operation of other modules, and allow the user to call the electronic seal and the electronic official seal after the user is authorized.
[0013] The embodiment of the present application also discloses a multi-factor root authentication method based on IPv6, which includes the following steps: providing a multi-factor root authentication system based on IPv6, the multi-factor root authentication system based on IPv6 including a first capture module, a second capture module, a third capture module, an information authentication module, an electronic seal / official seal generation module and a root certificate issuance module; using the first capture module to obtain a plurality of identity information, a plurality of enterprise information and an enterprise code of the user; using the second capture module to obtain the user's IPv6 digital address, wherein the IPv6 digital address includes a plurality of sixteen-bit address fragments; using the third capture module to obtain a plurality of digital certificates and corresponding plurality of keys provided by a plurality of digital certification centers ; Use the information authentication module to digitally authenticate the user's multiple identity information and multiple enterprise information based on the multiple sixteen-bit address fragments of the IPv6 digital address, and generate multiple authenticated identity information and multiple authenticated enterprise information; use the electronic seal / official seal generation module to generate the user's electronic seal and electronic official seal based on the user's multiple authenticated identity information and multiple authenticated enterprise information; use the root certificate issuance module to link multiple digital certification centers through the third capture module when the user issues a root certificate issuance request, perform multi-key verification on the multiple authenticated identity information and multiple authenticated enterprise information based on multiple digital certificates and corresponding multiple keys, and issue multiple root certificates.
[0014] By means of the above technical solution, the beneficial effects of the present invention are as follows: Compared with the prior art, the multi-factor authentication root system and method based on IPv6 provided by the present invention have the following advantages: (1) Based on the IPv6 protocol, by integrating multiple trusted factors to the digital authentication center to obtain a certificate with equal security, the system of the present invention can not only realize the dual-stack intercommunication of IPv6 and IPv4, but also realize the multi-category intercommunication and mutual recognition of digital authentication of all digital authentication centers and national electronic seal authentication; (2) It can complete the application and issuance of multiple certificates and multiple keys in one authentication on a single platform; it can write to a variety of the most secure storage media devices; (3) Through the certificate and key chain management, it innovatively completes the authentication and storage of multiple factors and multiple certificates from the beginning of the entity's "birth", and establishes a one-master-multiple-duplicate and one-household-multiple-key distribution operation mode through one-number-multiple-use; (4) The digital authentication of the present invention is independent of the international CA authentication system and is safe and reliable. Furthermore, the IPv6-based multi-factor authentication root system and method of the present invention can also convert each Chinese character into a set of digital codes D_Code through a stroke-to-digital code table, making it computer-readable. This further localizes the written code language from the bottom up, making it no longer limited to Western English. In other words, the IPv6-based multi-factor authentication root system of the present invention is a digital trust service facility with proprietary Chinese intellectual property rights. It is based on the next-generation IPv6 digital address authentication, while integrating the global multi-factor authentication of enterprises and individuals as its core, integrating the mutual trust authentication services of domestic and international digital certification centers, and forming a solid foundation for a unified, integrated, multi-key, multi-factor, enterprise and individual credit system.
[0015] In order to make the above and other objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are listed below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0017] FIG1 is a framework diagram of an IPv6-based multi-factor authentication root system in a first embodiment of the present invention.
[0018] FIG2 is a framework diagram of an IPv6-based multi-factor authentication root system in a second embodiment of the present invention.
[0019] FIG3 is a framework diagram of an IPv6-based multi-factor authentication root system in a third embodiment of the present invention.
[0020] FIG. 4 is a schematic diagram of an embodiment of a stroke-to-digital code table of the present invention.
[0021] FIG5 is a framework diagram of the multiple modules in FIG1 , FIG2 , and FIG3 .
[0022] FIG6 is a flowchart of a multi-factor root authentication method based on IPv6 in the first embodiment of the present invention.
[0023] FIG7 is a flow chart of a multi-factor root authentication method based on IPv6 in a second embodiment of the present invention.
[0024] Reference numerals in the above drawings:
[0025] 10A, 10B, and 10C IPv6-based multi-factor authentication root system
[0026] 110 First Capture Module
[0027] 120 Second Capture Module
[0028] 130 Second Capture Module
[0029] 140 Information Authentication Module
[0030] 150 Electronic seal / official seal generation module
[0031] 160 root certificate issuance module
[0032] 170 Binding Module
[0033] 180 stroke digitization module
[0034] More than 200 modules
[0035] 30A-30N Digital Certification Center
[0036] 210 Central Control Module
[0037] 220 communication module
[0038] 230 identity authentication module
[0039] 240 key module
[0040] 250 storage modules
[0041] ID1-IDn identity information
[0042] aID1-aIDn authenticated identity information
[0043] eaID1-eaIDn encrypted authenticated identity information
[0044] CI1-CIm Company Information
[0045] aCI1-aCIm Certified Enterprise Information
[0046] eaCI1-eaCIm encrypted authenticated enterprise information
[0047] Code_E Enterprise Code
[0048] IPv6_ADDIPv6 numeric address
[0049] ADD_S1-ADD_Sq sixteen-bit address segments
[0050] CAC1-CACp digital certificate
[0051] KEY1-KEYp key
[0052] EPS electronic seal
[0053] ECS electronic official seal
[0054] REQRoot certificate issuance request
[0055] ROOT_C1-ROOT_Cq root certificate
[0056] ROOT_DN domain name
[0057] D_Code digital code
[0058] BID biometric data
[0059] aBID authenticated biometric data
[0060] S610-S670, S710-S760 steps DETAILED DESCRIPTION
[0061] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0062] It should be noted that, in the description of the present invention, the terms "first," "second," etc., are used solely for descriptive purposes and to distinguish similar objects. There is no order of precedence between the two, nor should they be construed as indicating or implying relative importance. Furthermore, in the description of the present invention, unless otherwise specified, "plurality" means two or more.
[0063] Please refer to Figure 1, which is a framework diagram of an IPv6-based multi-factor authentication root system 10A in a first embodiment of the present invention. As shown in Figure 1, the IPv6-based multi-factor authentication root system 10A includes a first capture module 110, a second capture module 120, a third capture module 130, an information authentication module 140, an electronic seal / official seal generation module 150, a root certificate issuance module 160, and multiple modules 200. The first capture module 110 is used to obtain a user's multiple identity information ID1-IDn, multiple enterprise information CI1-CIm, and an enterprise code Code_E. The second capture module 120 is used to obtain the user's IPv6 digital address IPv6_ADD, where the IPv6 digital address IPv6_ADD includes a plurality of sixteen-bit address segments ADD_S1-ADD_Sq. The third retrieval module 130 is configured to obtain a plurality of digital certificates CAC1-CACp and corresponding keys KEY1-KEYp provided by a plurality of digital certification authorities 30A-30N. The information authentication module 140 is coupled to the first retrieval module 110, the second retrieval module 120, and the third retrieval module 130, and is configured to perform physical or digital authentication of the user's plurality of identity information ID1-IDn and plurality of enterprise information CI1-CIm based on the plurality of 16-bit address segments ADD_S1-ADD_Sq of the IPv6 digital address IPv6_ADD, thereby generating a plurality of authenticated identity information aID1-aIDn and a plurality of authenticated enterprise information aCI1-aCIm. The electronic seal / official seal generation module 150 is coupled to the information authentication module 140 and is used to generate the user's electronic seal (EPS) and electronic official seal (ECS) based on the user's multiple authenticated identity information aID1-aIDn and authenticated corporate information aCI1-aCIm. The root certificate issuance module 160 is coupled to the information authentication module 140 and is used to, when a user issues a root certificate issuance request REQ, connect to multiple digital certification centers 30A-30N via the third retrieval module 130, perform multi-key authentication on the authenticated identity information aID1-aIDn and authenticated corporate information aCI1-aCIm based on the multiple digital certificates CAC1-CACp and the corresponding multiple keys KEY1-KEYp, and issue multiple root certificates ROOT_C1-ROOT_Cq.
[0064] Please note that the multiple identity information ID1-IDn may include the ID card, bank account, address, email address, bound mobile phone number, bound landline phone number, WeChat account, Alipay account, JD account, Pinduoduo account, Weibo account, QQ number, Douyin account, live broadcast room number and / or video number of the user's company founder, and the multiple corporate information CI1-CIm may include the bound landline phone number, bound bank account, electronic business license, tax control information, official seal number, legal person certificate number, unified social credit code, electronic certificate number, corporate WeChat account, live broadcast room number and / or video number of corporate users authorized by the banking system and / or government system, but this is only for example and the present invention is not limited to this.
[0065] The electronic name seal is a printed electronic name seal or a handwritten electronic name seal. Optionally, the electronic name seal also requires a handwritten signature.
[0066] Please note that the Enterprise Code, Code_E, is bound to a landline phone number, which is a digital application that meets global financial security standards. Therefore, the IPv6-based multi-factor authentication root system 10A / 10B / 10C of the present invention is a global, digital, and cryptographic chain operating system.
[0067] Please refer to Figure 2, which is a framework diagram of an IPv6-based multi-factor authentication root system 10B according to a second embodiment of the present invention. The IPv6-based multi-factor authentication root system 10B of Figure 2 is similar in architecture to the IPv6-based multi-factor authentication root system 10A of Figure 1, except that the IPv6-based multi-factor authentication root system 10B of Figure 2 further includes a binding module 170, coupled to the first capture module 110 and the second capture module 120, for binding the enterprise code Code_E to the IPv6 digital address IPv6_ADD and generating the IPv6-based domain name ROOT_DN.
[0068] The IPv6-based domain name ROOT_DN can be a domain name defined based on the IPv6 protocol, for example, ending with the China-based root domain name ".ipv6" to distinguish it from existing overseas root domain names such as ".com" and ".net." By binding the enterprise code Code_E to the IPv6 numeric address IPv6_ADD, an IPv6-based domain name ROOT_DN can be generated, such as "059188881234.ipv6" or "059188881234.cn.ipv6."
[0069] Please refer to FIG. 3. FIG. 3 is a framework diagram of a multi-factor authentication root system 10C based on IPv6 in the third embodiment of the present invention. The multi-factor authentication root system 10C based on IPv6 in FIG. 3 has a similar architecture to the multi-factor authentication root system 10B based on IPv6 in FIG. 2. The difference between the two is that the multi-factor authentication root system 10C based on IPv6 in FIG. 3 further includes a stroke digitization module 180, which is coupled to the first capture module 110 and is used to convert each Chinese character in a plurality of identity information IDs 1-IDn into a set of digital codes D_Code according to the stroke digital code table.
[0070] Please refer to FIG. 4. FIG. 4 is a schematic diagram of an embodiment of the stroke digital code table of the present invention. Strokes usually refer to the various shapes of dots and lines that make up Chinese characters and are uninterrupted, such as horizontal (一), vertical (丨), left-falling stroke (丿), dot (丶), right-falling stroke etc. Strokes are the smallest continuous writing units that make up the glyphs of Chinese characters. FIG. 4 sorts out the common Chinese character strokes and the corresponding digital codes D_Code, which are divided into a total of 32 kinds of strokes. For example, the digital code D_Code corresponding to the horizontal stroke (一) is "01", the digital code D_Code corresponding to the vertical stroke (丨) is "02", the digital code D_Code corresponding to the left-falling stroke (丿) is "03",..., the digital code D_Code corresponding to the horizontal-folding-folding-hook stroke is "32", and so on. In this way, the stroke digitization module 180 can convert each Chinese character in a plurality of identity information IDs 1-IDn into a set of digital codes D_Code according to the stroke digital code table in FIG. 4. For example, the identity information includes name information, such as "Gu Jin". Among them, "Gu" can be sequentially disassembled into the horizontal stroke (一), the left-falling stroke (丿), the vertical stroke (丨), the horizontal-folding stroke and the horizontal stroke (一) according to the writing order, so the digital code D_Code generated after the conversion of "Gu" is (01, 03, 02, 09, 01); "Jin" can be sequentially disassembled into the left-falling stroke (丿) and the right-falling stroke There are four strokes: the dot (丶), the horizontal left-falling stroke (フ). Therefore, the digital code D_Code generated after the transformation of "今" is (03, 05, 04, 07). And optionally, D_Code can include a sequence code at the end to distinguish characters with the same strokes and writing order. For example, "土" can be disassembled into three strokes in sequence according to the writing order: the horizontal stroke (一), the vertical stroke (丨), and the horizontal stroke (一). The digital code D_Code generated after the transformation of "土" is (01, 02, 01, 1), and the "1" at the end of the digital code D_Code is the sequence code; "士" can be disassembled into three strokes in sequence according to the writing order: the horizontal stroke (一), the vertical stroke (丨), and the horizontal stroke (一). The digital code D_Code generated after the transformation of "士" is (01, 02, 01, 2), and the "2" at the end of the digital code D_Code is the sequence code.
[0071] Please note that in certain cases, the above-mentioned third extraction module 130 can also be omitted, and its function can be replaced by the second extraction module 120. In other words, the IPv6-based multi-factor authentication root system 10A / 10B / 10C of the present invention can use the IPv6 digital address IPv6_ADD to replace the digital certificate for authentication. Coupled with the stroke digitization module 180, each Chinese character can be converted into a set of digital codes D_Code through the stroke digital code table shown in Figure 4, which can be read by the computer, and further localize the writing code language from the bottom layer.
[0072] Please refer to Figures 1 to 3 and 5. The IPv6-based multi-factor authentication root system 10A / 10B / 10C in Figures 1 to 3 also includes multiple modules 200. As shown in Figure 5, the multiple modules 200 include a central control module 210, a communication module 220, an identity authentication module 230, a key module 240, and a storage module 250 connected to the central control module 210. The communication module 220 is used to enable communication between the IPv6-based multi-factor authentication root system 10A / 10B / 10C and an external server. The identity authentication module 230 is used to authenticate the biometric data BID input by the user to generate authenticated biometric data aBID, and authorize the user after successful authentication. The key module 240 is used to store a plurality of keys KEY1-KEYp and encrypt a plurality of authenticated identity information aID1-aIDn and a plurality of authenticated enterprise information aCI1-aCIm according to the corresponding keys in the plurality of keys KEY1-KEYp to generate a plurality of encrypted authenticated identity information eaID1-eaIDn and a plurality of encrypted authenticated enterprise information eaCI1-eaCIm. The storage module 250 is used to store authenticated biometric data aBID, a plurality of encrypted authenticated identity information eaID1-eaIDn, a plurality of encrypted authenticated enterprise information eaCI1-eaCIm, an electronic seal EPS, an electronic official seal ECS, and a plurality of root certificates ROOT_C1-ROOT_Cq. The central control module 210 is used to receive input and control the operation of the other modules 220-250, and after the user obtains authorization, allows the user to call the electronic seal EPS and electronic official seal ECS.
[0073] Generally speaking, the above-mentioned electronic seal refers to a digital image of a seal or impression that has been authorized and authenticated, while an electronic signature is a handwritten signature on a touch screen, handwriting board, computer, tablet or mobile phone.
[0074] In addition, whether in Chinese, English, or other languages, the surname and given name can be separated into each smallest unit (word) to create an authentication and authorization application. In other words, in the present invention, a single platform cannot sign a complete name. For example, "Gu Jin Lai" requires three different platforms to perform authentication and authorization applications for "Gu", "Jin", and "Lai" respectively. After authentication and authorization, the electronic seal / electronic signature also needs to be bound to a mobile phone number and / or email address for integrated use.
[0075] Furthermore, the communication module 220 may include: at least one of: a 3G communication module, a 4G communication module, a 5G communication module, a WIFI module, a NBIoT module, a Bluetooth module, an NFC module and an infrared module; the communication module 220 supports IPv4 and IPv6 protocols.
[0076] Please note that the electronic seal (EPS) here can be a cross-domain electronic seal, a cross-domain electronic signature, or both. The electronic seal can be a printed electronic name seal or a handwritten electronic name seal. The language of the electronic seal can be in various languages, and the corresponding number is the bound mobile phone number. Optionally, the electronic seal also requires a handwritten electronic signature. The electronic signature language can be in various languages, and the corresponding number is the bound mobile phone number.
[0077] Please note that the aforementioned biometric data BID may include fingerprint information, palm print information, iris information, facial feature recognition data, voiceprint information, and / or electrocardiogram data, or any other biometric data that can identify a user. In actual applications, a combination of one or more of these data may be used for security identification. In addition, when using biometric data BID for authentication, it is necessary to focus on physiological and behavioral characteristics. Physiological characteristics include fingerprints, palm prints, palm shape, iris, face, voiceprint, DNA, etc., while behavioral characteristics include posture, heartbeat, signature, etc.
[0078] It's worth noting that the IPv6-based multi-factor authentication root system of the present invention is not only a root server for multi-factor authentication based on IPv6, but also a server for Chinese stroke writing applications. Based on the IPv6 protocol, by integrating multiple trusted factors into a digital authentication certificate with equal security, the present invention's integrated authentication system not only enables dual-stack interoperability between IPv6 and IPv4, but also enables multi-category interoperability and mutual recognition of all digital authentications and national electronic seal authentication. Furthermore, the digital authentication of the present invention is independent of the international CA certification system, making it secure and reliable. Furthermore, by using the stroke-to-digital code table shown in Figure 4, each Chinese character is converted into a set of digital codes D_Code, making them computer-readable. This further localizes the writing code language from the ground up, freeing it from being limited to Western English. In other words, the IPv6-based multi-factor authentication root system of the present invention is a digital trust service facility with proprietary Chinese intellectual property rights. It is based on the next-generation IPv6 digital address authentication, and focuses on integrating global multi-factor authentication for enterprises and individuals. It integrates domestic and international digital authentication and mutual trust services, forming a solid foundation for a unified, integrated, multi-key, multi-factor, enterprise and individual credit system.
[0079] Please note that for any unit or organization other than individuals, the IPv6-based multi-factor authentication root system of the present invention uses a bound landline phone number as a unique digital mark, and each element of the data carries the landline phone number as an important authentication factor; while for individuals and families, the IPv6-based multi-factor authentication root system of the present invention needs to match and bind the real-name authentication mobile phone number.
[0080] The IPv6-based multi-factor authentication root system of the present invention can be a trusted authentication server system or a third-party authentication platform system. This terminal device includes the authentication, storage, management, and application of various certificate keys such as electronic seals. It corresponds to any department or platform system of social and economic transactions, including government, enterprises, individuals, and families.
[0081] The IPv6-based multi-factor authentication root system of the present invention can be implemented by a chip of an integrated physical and electrical intelligent electronic seal, which stores various certificates and keys, all of which can be remotely distributed, downloaded, stored, and applied.
[0082] Please refer to Figure 1 and Figure 6. Figure 6 is a flowchart of a multi-factor root authentication method based on IPv6 in the first embodiment of the present invention. The multi-factor root authentication method based on IPv6 in Figure 6 includes the following steps:
[0083] Step S610: Providing an IPv6-based multi-factor authentication root system, the IPv6-based multi-factor authentication root system comprising a first capture module, a second capture module, a third capture module, an information authentication module, an electronic seal / official seal generation module, and a root certificate issuance module;
[0084] Step S620: Utilize the first acquisition module to obtain the user's multiple identity information, multiple company information, and company code;
[0085] Step S630: Utilize the second acquisition module to obtain the user's IPv6 digital address, wherein the IPv6 digital address includes a plurality of sixteen-bit address segments;
[0086] Step S640: Utilizing a third retrieval module to obtain a plurality of digital certificates and corresponding keys provided by a plurality of digital certification authorities;
[0087] Step S650: Utilizing an information authentication module to perform physical or digital authentication on the user's multiple identity information and multiple enterprise information based on the multiple 16-bit address segments of the IPv6 digital address, and generating multiple authenticated identity information and multiple authenticated enterprise information;
[0088] Step S660: using the electronic seal / official seal generation module to generate the user's electronic seal and electronic official seal according to the user's multiple authenticated identity information and multiple authenticated enterprise information;
[0089] Step S670: When a user issues a root certificate issuance request, the root certificate issuance module is used to link to multiple digital certification centers through the third capture module, perform multi-key verification on multiple authenticated identity information and multiple authenticated enterprise information based on multiple digital certificates and corresponding multiple keys, and issue multiple root certificates.
[0090] Please note that step S620 is executed by the first capture module 110, step S630 is executed by the second capture module 120, step S640 is executed by the third capture module 130, step S650 is executed by the information authentication module 140, step S660 is executed by the electronic seal / official seal generation module 150, and step S670 is executed by the root certificate issuance module 160.
[0091] Please refer to Figures 5 and 7. Figure 7 is a flow chart of a multi-factor root authentication method based on IPv6 in the second embodiment of the present invention. The multi-factor root authentication method based on IPv6 in Figure 7 includes the following steps:
[0092] Step S710: providing a central control module, and a communication module, an identity authentication module, a key module, and a storage module connected to the central control module;
[0093] Step S720: Using the communication module to implement communication between the IPv6-based multi-factor authentication root system and the external server;
[0094] Step S730: Utilizing the identity authentication module to authenticate the biometric data input by the user to generate authenticated biometric data, and authorizing the user after the authentication is successful;
[0095] Step S740: Using a key module to store a plurality of keys, and encrypting the plurality of authenticated identity information and the plurality of authenticated enterprise information according to corresponding keys among the plurality of keys to generate a plurality of encrypted authenticated identity information and a plurality of encrypted authenticated enterprise information;
[0096] Step S750: Using a storage module to store authenticated biometric data, a plurality of encrypted authenticated identity information, a plurality of encrypted authenticated enterprise information, an electronic name seal, an electronic official seal, and a plurality of root certificates; and
[0097] Step S760: Utilize the central control module to receive input and control the operation of other modules, and allow the user to call the electronic personal seal and electronic official seal after the user obtains authorization.
[0098] Please note that step S720 is executed by the communication module 220 , step S730 is executed by the identity authentication module 230 , step S740 is executed by the key module 240 , step S750 is executed by the storage module 250 , and step S760 is executed by the central control module 210 .
[0099] The specific embodiment of the present invention provides a multi-factor authentication root system and method based on IPv6, which can issue root certificates with multiple certificates, multiple keys, multiple factors, and multiple platforms. Therefore, compared with the traditional root system that only supports a single certificate, a single key, a single factor, and a single platform, the present invention can effectively solve the problems of security concerns and inconvenience in operation. Furthermore, the multi-factor authentication root system based on IPv6 of the present invention is privately deployed with an integrated physical and electrical application, and each smart terminal is an edge cloud with integrated computing power and storage. The smart terminal includes a Jizhengtong credit server, a smart seal, a Jizhengtong set-top box, a Jizhengtong router, a Jizheng U shield, etc., so it can solve the problem of insecurity in the centralized deployment of private keys. In addition, the multi-factor authentication root system based on IPv6 of the present invention is bound to a fixed telephone number and / or a mobile phone number, which can realize the expansion of the digital space with multiple uses of one number, create an integrated platform from certification, credit enhancement, credit investigation to trust, and realize the full life cycle management of digital assets of governments, enterprises, families, and individuals.
[0100] The above-described embodiments of the present invention may be implemented in various hardware, software encodings, or a combination thereof. For example, embodiments of the present invention may also be program code that performs the above-described methods in a digital signal processor (DSP). The present invention may also relate to various functions performed by a computer processor, a digital signal processor, a microprocessor, or a field programmable gate array (FPGA). The above-described processors may be configured according to the present invention to perform specific tasks by executing machine-readable software code or firmware code that defines the specific methods disclosed herein. The software code or firmware code may be developed in different programming languages and in different formats or forms. The software code may also be compiled for different target platforms. However, the different code styles, types, and languages of the software code that performs tasks according to the present invention and other types of configuration code do not depart from the spirit and scope of the present invention.
[0101] By means of the above technical solution, the beneficial effects of the present invention are as follows: Compared with the prior art, the multi-factor authentication root system and method based on IPv6 provided by the present invention have the following advantages: (1) Based on the IPv6 protocol, by integrating multiple trusted factors into digital authentication certificates with equal security, the system of the present invention can not only realize the intercommunication between IPv6 and IPv4 dual stacks, but also realize the multi-category intercommunication and mutual recognition of all digital authentications and national electronic seal authentications; (2) It can complete the application and issuance of multiple certificates and multiple keys on a single platform at one time; it can write to a variety of the most secure storage media devices; (3) Through the certificate and key chain management, it innovatively completes the authentication and storage of multiple factors and multiple certificates from the beginning of the entity's "birth", and establishes a one-master-multiple-duplicate and one-household-multiple-key distribution operation mode through one-number-multiple-use; (4) The digital authentication of the present invention is independent of the international CA authentication system and is safe and reliable. Furthermore, the IPv6-based multi-factor authentication root system and method of the present invention can also convert each Chinese character into a set of digital codes D_Code through a stroke-to-digital code table, making it computer-readable. This further localizes the written code language from the bottom up, making it no longer limited to Western English. In other words, the IPv6-based multi-factor authentication root system of the present invention is a digital trust service facility with proprietary Chinese intellectual property rights. It is based on the next-generation IPv6 digital address authentication, while integrating the global multi-factor authentication of enterprises and individuals as its core, integrating the mutual trust authentication services of domestic and international digital certification centers, and forming a solid foundation for a unified, integrated, multi-key, multi-factor, enterprise and individual credit system.
[0102] Specific embodiments are used in the present invention to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for ordinary technicians in this field, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.
Claims
1. IPv6-based multi-factor authentication core system, containing: a first extraction module configured to obtain a number of pieces of user identification information, a number of pieces of enterprise information, and an enterprise code; a second extraction module for obtaining the IPv6 digital address of the user, wherein the IPv6 digital address comprises a number of sets of sixteen-bit address segments; a third extraction module designed to obtain a number of digital certificates and a number of corresponding keys provided by a number of digital certificate authorities; an information authentication module connected to the first extraction module, the second extraction module and the third extraction module and designed to perform physical or digital authentication with respect to a plurality of pieces of identification information and a plurality of pieces of information about the user's enterprise in accordance with a plurality of sets of sixteen-bit segments of the IPv6 digital address and generate a plurality of pieces of authenticated identification information and a plurality of pieces of authenticated information about the enterprise; an electronic name seal / official seal generation module connected to the information authentication module and designed to generate an electronic name seal and an electronic official seal of the user in accordance with a number of fragments of authenticated identification information and a number of fragments of authenticated information about the enterprise; and a root certificate issuing module connected to the information authentication module and configured to, when a user submits a root certificate issuance request, link a plurality of digital certificate certification authorities through a third retrieval module, perform multi-key verification on a plurality of pieces of authenticated identification information and a plurality of pieces of authenticated enterprise information in accordance with the plurality of digital certificates and the plurality of corresponding keys, and issue a plurality of root certificates.
2. The IPv6-based multifactor authentication root system according to claim 1, characterized in that it further comprises a linking module connected to the first extraction module and the second extraction module and designed to link the enterprise code with the IPv6 digital address and generate a domain name based on IPv6.
3. The IPv6-based multi-factor authentication root system of claim 1, further comprising a barcode digitization module coupled to the first extraction module and configured to convert each Chinese character in a number of identification information fragments into a set of digital codes in accordance with a barcode digital code table.
4. The IPv6-based multi-factor authentication root system according to claim 1, characterized in that it further comprises a multi-module connected to a root certificate issuing module, wherein the multi-module comprises: a central control module, as well as a communication module, a personal authentication module, a key module, and a storage module connected to the central control module; The communication module is designed to provide communication between the IPv6-based multifactor authentication root system and the external server; the identity authentication module is designed to perform authentication with respect to the biometric data entered by the user to generate authenticated biometric data and authorize the user after successful authentication; the key module is designed to store a number of keys and perform encryption with respect to a number of fragments of authenticated identification information and a number of fragments of authenticated information about the enterprise in accordance with the corresponding keys from the number of keys to generate a number of encrypted fragments of authenticated identification information and a number of encrypted fragments of authenticated information about the enterprise; the storage module is designed to store authenticated biometric data, a number of encrypted fragments of authenticated identification information, a number of encrypted fragments of authenticated information about the enterprise, an electronic name seal, an electronic official seal and a number of root certificates; and The central control module is designed to receive input data and control the operation of other modules, as well as to provide the user with the ability to call up an electronic name seal and an electronic official seal after authorization.
5. The IPv6-based multi-factor authentication root system of claim 1, wherein the enterprise code is linked to a landline telephone number, and the landline telephone number is a digital application that meets the global financial security standards.
6. The IPv6-based multi-factor authentication root system of claim 1, wherein the IPv6-based multi-factor authentication root system is a certificate-secret chain operating system for global and universal digital applications.
7. The IPv6-based root multifactor authentication system according to paragraph 1, characterized in that the electronic name seal also requires a handwritten signature when affixed.
8. An IPv6-based root multi-factor authentication method used in the IPv6-based root multi-factor authentication system, comprising the following steps: creating an IPv6-based multi-factor authentication root system, wherein the IPv6-based multi-factor authentication root system comprises a first extraction module, a second extraction module, a third extraction module, an information authentication module, an electronic name seal / official seal generation module, and a root certificate issuance module; using the first extraction module to obtain a number of pieces of user identification information, a number of pieces of enterprise information, and an enterprise code; using a second extraction module to obtain the user's IPv6 digital address, wherein the IPv6 digital address comprises a number of sets of sixteen-bit address segments; using a third extraction module to obtain a set of digital certificates and a set of corresponding keys provided by a set of digital certificate authorities; using the information authentication module to perform physical or digital authentication with respect to a number of pieces of identification information and a number of pieces of information about the user's enterprise in accordance with a number of sets of sixteen-bit segments of the IPv6 digital address and generate a number of pieces of authenticated identification information and a number of pieces of authenticated information about the enterprise; using the electronic name seal / official seal generation module to generate an electronic name seal and an electronic official seal of the user in accordance with a number of pieces of authenticated identification information and a number of pieces of authenticated information about the user's enterprise; and using the root certificate issuance module to, when a user submits a root certificate issuance request, link a number of digital certificate authorities through the third extraction module, perform multi-key verification on a number of pieces of authenticated identification information and a number of pieces of authenticated enterprise information according to the number of digital certificates and the number of corresponding keys, and issue a number of root certificates.
9. The IPv6-based root multifactor authentication method according to paragraph 8, characterized in that it additionally includes the following steps: the IPv6-based multifactor authentication root system additionally contains a binding module; and Using the linker module to link the enterprise code to the IPv6 digital address and generate an IPv6-based domain name.
10. The IPv6-based root multifactor authentication method according to paragraph 8, characterized in that it additionally includes the following steps: The IPv6-based multi-factor authentication root system additionally contains a barcode digitization module; and using a barcode digitizer module to convert each Chinese character in a series of identification information fragments into a set of digital codes in accordance with a barcode digital code table.
11. The IPv6-based root multifactor authentication method according to paragraph 8, characterized in that it additionally includes the following steps: creation of a central control module, as well as a communication module, a personal authentication module, a key module and a storage module connected to the central control module; using the identity authentication module to perform authentication with respect to the biometric data entered by the user to generate authenticated biometric data and authorize the user upon successful authentication; using a key module to store a set of keys and perform encryption with respect to a set of pieces of authenticated identification information and a set of pieces of authenticated enterprise information in accordance with corresponding keys from the set of keys to generate a set of encrypted pieces of authenticated identification information and a set of encrypted pieces of authenticated enterprise information; using a storage module to store authenticated biometric data, a number of encrypted fragments of authenticated identification information, a number of encrypted fragments of authenticated information about the enterprise, an electronic name seal, an electronic official seal and a number of root certificates; and use of the central control module to receive input data and control the operation of other modules, as well as to provide the user with the ability to call up an electronic name seal and an electronic official seal after authorization.