Identity authentication method and system based on front end, and apparatus, device and medium

Obtain identity credentials through front-end devices and encrypt them and then transmit them to the authentication server for verification, solving the complex problem of private key certificate management in multiple user scenarios, realizing resource conservation and user experience improvement.

WO2025139862A1PCT designated stage expired Publication Date: 2025-07-03CHINA UNIONPAY
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/139374
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-13
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In multi-user scenarios, it is difficult for front-end devices to effectively manage and store private key certificates of multiple users, resulting in excessive resource usage. At the same time, the use of tokens increases user operation complexity and risk of leakage.

Method used

Obtain identity credentials from the authentication server through the front-end device, and encrypt the identity credentials and signatures using symmetric keys, request verification from the authentication server, reduce the private key certificate management of the front-end device and simplify user operations.

Benefits of technology

Without the need to store and manage private key certificates, resource savings for identity authentication are achieved, user operations are simplified, user experience is improved, and token leakage risks are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024139374_03072025_PF_FP_ABST
    Figure CN2024139374_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the field of data processing. Disclosed are an identity authentication method and system based on a front end, and an apparatus, a device and a medium. The method comprises: acquiring an identity credential from an authentication server by means of an application program, so as to obtain a first signature of the identity credential; pulling up a browser by means of the application program, so as to request a service page from the authentication server, and acquiring the identity credential and the first signature from the application program by means of the service page; and sending an authentication key request to the authentication server by means of the service page, such that the authentication server verifies the identity credential and the first signature, wherein the authentication key request comprises first ciphertext and symmetric key ciphertext, the first ciphertext is obtained by encrypting the identity credential and the first signature by means of a symmetric key, and the symmetric key ciphertext is obtained by encrypting the symmetric key by means of a first public key built in the service page.
Need to check novelty before this filing date? Find Prior Art

Description

Front-end-based identity authentication method, device, equipment, system and medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese patent application 202311870815.0, filed on December 29, 2023, entitled “Front-end-based identity authentication method, device, equipment, system and medium,” and the entire contents of that application are incorporated herein by reference. Technical Field

[0003] The present application relates to the field of data processing, and in particular to a front-end-based identity authentication method, device, equipment, system and medium. Background Art

[0004] When users perform business operations, identity authentication is required to determine whether they are authorized to perform the business operation. This authentication can be performed using a signature. The front-end device can sign a message digest using a private key certificate and send the signature to the receiving server via a request. The receiving server then decrypts the signature using the public key and verifies the consistency of the message digest, achieving identity authentication. However, in scenarios where the front-end device has multiple users, the storage, management, and replacement of the private key certificates of multiple users is too complex for the front-end device, and the front-end device's resources are insufficient to support the storage, management, and replacement of the private key certificates of multiple users. Summary of the Invention

[0005] The embodiments of the present application provide a front-end-based identity authentication method, apparatus, device, system, and medium, which enable the front-end device to support user identity authentication while reducing the resources occupied by identity authentication.

[0006] In the first aspect, an embodiment of the present application provides a front-end-based identity authentication method, which is applied to a front-end device. The method includes: obtaining an identity credential from an authentication server through an application to obtain a first signature of the identity credential; launching a browser through the application to request a business page from the authentication server, and obtaining the identity credential and the first signature from the application through the business page; sending an authentication key request to the authentication server through the business page so that the authentication server verifies the identity credential and the first signature. The authentication key request includes a first ciphertext and a symmetric key ciphertext. The first ciphertext is obtained by encrypting the identity credential and the first signature with a symmetric key, and the symmetric key ciphertext is obtained by encrypting the symmetric key with a first public key built into the business page.

[0007] In the second aspect, an embodiment of the present application provides a front-end-based identity authentication method, which is applied to an authentication server, and the method includes: issuing an identity credential to an application in a front-end device; in response to a request initiated by a browser in the front-end device being pulled up by an application, providing a business page to the front-end device, so that the business page obtains the identity credential and the first signature of the identity credential from the application; receiving an authentication key request sent by the front-end device through the business page, the authentication key request includes a first ciphertext and a symmetric key ciphertext, the first ciphertext is obtained by encrypting the identity credential and the first signature by a symmetric key, and the symmetric key ciphertext is obtained by encrypting the symmetric key by a first public key built into the business page; based on the authentication key request, verifying the identity credential and the first signature.

[0008] In the third aspect, an embodiment of the present application provides a front-end device, including: a receiving module, used to obtain identity credentials from an authentication server through an application; a processing module, used to obtain a first signature of the identity credential; a sending module, used to pull up a browser through an application to request a business page from the authentication server; an obtaining module, used to obtain the identity credential and the first signature from the application through the business page; the sending module is also used to send an authentication key request to the authentication server through the business page, so that the authentication server verifies the identity credential and the first signature, the authentication key request includes a first ciphertext and a symmetric key ciphertext, the first ciphertext is obtained by encrypting the identity credential and the first signature with the symmetric key, and the symmetric key ciphertext is obtained by encrypting the symmetric key with the first public key built into the business page.

[0009] In a fourth aspect, an embodiment of the present application provides an authentication server, comprising: a sending module for issuing identity credentials to an application in a front-end device; and, in response to a request initiated by a browser in the front-end device being pulled up by an application, providing a business page to the front-end device, so that the business page obtains the identity credentials and the first signature of the identity credentials from the application; a receiving module for receiving an authentication key request sent by the front-end device through the business page, the authentication key request comprising a first ciphertext and a symmetric key ciphertext, the first ciphertext being obtained by encrypting the identity credentials and the first signature by a symmetric key, and the symmetric key ciphertext being obtained by encrypting the symmetric key by a first public key built into the business page; a processing module for verifying the identity credentials and the first signature based on the authentication key request.

[0010] In a fifth aspect, an embodiment of the present application provides a front-end device, comprising: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the front-end-based identity authentication method of the first aspect is implemented.

[0011] In a sixth aspect, an embodiment of the present application provides an authentication server, comprising: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the front-end-based identity authentication method of the second aspect is implemented.

[0012] In the seventh aspect, an embodiment of the present application provides a front-end-based identity authentication system, comprising the front-end device of the fifth aspect and the authentication server of the sixth aspect.

[0013] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, the front-end-based identity authentication method of the first aspect or the front-end-based identity authentication method of the second aspect is implemented.

[0014] The embodiment of the present application provides a front-end-based identity authentication method, apparatus, device, system and medium, wherein the front-end device obtains an identity credential from an authentication server through an application, signs the identity credential to obtain a first signature, launches a browser to request a business page from the authentication server, provides the identity credential and the first signature to the business page, and sends an authentication key request to the authentication server through the business page, wherein the authentication key request includes a first ciphertext obtained by encrypting the identity credential and the first signature with a symmetric key and a symmetric key ciphertext obtained by encrypting the symmetric key with a first public key built into the business page, so that the authentication server verifies the identity credential and the first signature based on the authentication key request. In this process, regardless of whether it is a multi-user scenario or a single-user scenario, the front-end device does not need to store, manage or replace the user's private key certificate, but instead converts the identity authentication of the front-end device to the authentication server by applying for an identity credential from the authentication server and then encrypting the identity credential and transmitting it to the authentication server, so that the front-end device can support the user's identity authentication while reducing the resources occupied by identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0016] FIG1 is a schematic diagram of an example of the architecture of a front-end-based identity authentication system provided in an embodiment of the present application;

[0017] FIG2 is a schematic diagram of the architecture of another example of a front-end-based identity authentication system provided in an embodiment of the present application;

[0018] FIG3 is a flow chart of a front-end-based identity authentication method provided by an embodiment of the first aspect of the present application;

[0019] FIG4 is a flow chart of a front-end-based identity authentication method provided by another embodiment of the first aspect of the present application;

[0020] FIG5 is a flowchart of a front-end-based identity authentication method provided by another embodiment of the first aspect of the present application;

[0021] FIG6 is a flowchart of a front-end-based identity authentication method provided by an embodiment of the second aspect of the present application;

[0022] FIG7 is a flowchart of a front-end-based identity authentication method provided by another embodiment of the second aspect of the present application;

[0023] FIG8 is a flowchart of a front-end-based identity authentication method provided by another embodiment of the second aspect of the present application;

[0024] FIG9 is a schematic diagram of an example of an identity authentication and service execution process provided in an embodiment of the present application;

[0025] FIG10 is a schematic structural diagram of a front-end device provided in an embodiment of the third aspect of the present application;

[0026] FIG11 is a schematic diagram of the structure of an authentication server provided in an embodiment of the fourth aspect of the present application;

[0027] Figure 12 is a structural diagram of the front-end device provided in an embodiment of the fifth aspect of this application. DETAILED DESCRIPTION

[0028] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating examples of the present application. It should be noted that the acquisition, storage, use, processing, etc. of information and data in the embodiments of the present application are authorized by the user or relevant agencies and comply with the relevant provisions of national laws and regulations.

[0029] When users perform business operations, identity authentication is required to determine if they are authorized to perform the operation. Signature authentication can be used for this purpose. The front-end device can sign a message digest using a private key certificate and send the signature via a request to the receiving server. The receiving server then decrypts the signature using the public key and verifies the digest's consistency, achieving identity authentication. However, when the front-end device has multiple users, storing, managing, and replacing multiple users' private key certificates is complex, and the front-end device's resources may not be sufficient to support this. Alternatively, the front-end device can authenticate users through login or authorization. Based on this, the back-end server issues a token to the front-end device, which it uses to access the back-end server. However, when users perform business operations through business pages, login and authorization are difficult to maintain, requiring multiple manual steps, increasing complexity and reducing the user experience. Furthermore, tokens pose a risk of being leaked. Once intercepted, they can be used to obtain the original user's data, potentially leading to data leakage.

[0030] The present application provides a front-end-based identity authentication method, apparatus, device, system and medium, which can obtain identity credentials from an authentication server through an application in a front-end device, and launch a browser to request a business page from the authentication server, provide the identity credentials and the signature of the identity credentials to the business page, and send a ciphertext including the identity credentials and signature encrypted with a symmetric key and the ciphertext encrypted with the symmetric key using the public key built into the business page to the authentication server through the business page, so that the authentication server can verify the identity credentials and signature. In this process, whether in a multi-user scenario or a single-user scenario, the front-end device does not need to store, manage or replace the user's private key certificate. Instead, it applies for an identity credential from the authentication server, and then encrypts the identity credential and transmits it to the authentication server, thereby converting the identity authentication of the front-end device to the authentication server for execution, so that the front-end device can support the user's identity authentication while reducing the resources occupied by identity authentication. Moreover, during this identity authentication process, the user does not need to perform login operations or authorization operations, which simplifies user operations and improves user experience.

[0031] The following is an introduction to the front-end-based identity authentication method, device, equipment, system and medium provided in this application.

[0032] For ease of explanation, the system architecture involved in the front-end-based identity authentication method provided in the embodiment of the present application is briefly described here. Figure 1 is a schematic diagram of the architecture of an example of a front-end-based identity authentication system provided in the embodiment of the present application. As shown in Figure 1, the front-end-based identity authentication system may include a front-end device 11 and an authentication server 12, and the front-end device 11 and the authentication server 12 can communicate and interact.

[0033] The front-end device 11 may include but is not limited to mobile phones, computers, tablet computers, smart wearable devices, etc. The front-end device 11 may have an application program that can be used to execute business. The front-end device 11 also has a browser, which can request a business page from the authentication server 12 through the browser and display the business page to the user. The application program in the front-end device 11 may correspond to a back-end server. The owner of the application program and the owner of the back-end server 13 are the same owner. The owner of the application program and the owner of the authentication server are different owners. In some examples, as shown in Figure 1, the communication interaction between the application program in the front-end device 11 and the authentication server 12 can be achieved through the back-end server 13 of the application program, that is, the application program in the front-end device 11 communicates and interacts with the back-end server 13, and the back-end server 13 communicates and interacts with the authentication server 12. The communication interaction between the business page triggered by the front-end device 11 and the authentication server 12 can be a direct communication interaction between the front-end device 11 and the authentication server 12.

[0034] The front-end device 11 and the authentication server 12 can realize the user's identity authentication. If the user's identity authentication is passed, the front-end device 11 can perform specific business operations. Figure 2 is an architectural diagram of another example of a front-end-based identity authentication system provided in an embodiment of the present application. The difference between Figure 2 and Figure 1 is that the front-end-based identity authentication system shown in Figure 2 can also include a business server 14. The front-end device 11 can communicate and interact with the business server 14. The owner of the business server 14 and the owner of the authentication server 12 can be the same owner. If the user's identity authentication is passed, the front-end device 11 can initiate a business request to the business server 14, and the business server 14 can feedback business response information to the front-end device 11, so that the business page in the front-end device 11 can display the business response information required by the user, thereby completing the business operation. The business response information displayed on the business page can be determined according to the business performed by the user. For example, if the business field includes the payment field, the business page of the front-end device 11 can display the user's payment code, display transaction result information, etc., but is not limited to this.

[0035] In a first aspect, the present application provides a front-end-based identity authentication method that can be applied to a front-end device, i.e., the front-end-based identity authentication method can be executed by the front-end device. FIG3 is a flow chart of the front-end-based identity authentication method provided by an embodiment of the first aspect of the present application. As shown in FIG3, the front-end-based identity authentication method may include steps S201 to S203.

[0036] In step S201, an identity certificate is obtained from an authentication server through an application program to obtain a first signature of the identity certificate.

[0037] An application on a front-end device can initiate an identity credential request from an authentication server. In response to the identity credential request, the authentication server can issue the corresponding identity credential to the application on the front-end device. In some examples, the application can request the identity credential from the authentication server via the application's back-end server. Similarly, the identity credential issued by the authentication server can be transmitted to the application on the front-end device via the back-end server.

[0038] The identity credential can represent the identity of the user using the application. The application can sign the identity credential to obtain a first signature, which can represent that the identity credential is applied for by the application.

[0039] In step S202, the application launches a browser to request a service page from the authentication server, and obtains the identity certificate and the first signature from the application through the service page.

[0040] Once the application obtains the first signature, it can trigger the browser to automatically launch and request a service page from the authentication server. The service page can be a Hypertext Markup Language (HTML) page. The service page can obtain the identity credentials and the first signature from the application through an interface that interacts with the application.

[0041] In step S203, an authentication key request is sent to the authentication server through the business page, so that the authentication server verifies the identity certificate and the first signature.

[0042] The authentication key request includes a first ciphertext and a symmetric key ciphertext. The first ciphertext is obtained by encrypting the identity certificate and the first signature with the symmetric key. The symmetric key ciphertext is obtained by encrypting the symmetric key with the first public key built into the business page. The authentication key request is used to enable the authentication server to verify the identity certificate and the first signature, and can also enable the authentication server to obtain the symmetric key. The symmetric key corresponds to the business page. During the business processing period when the same business page exists, the key required for information transmission encryption can use the symmetric key corresponding to the business page. The symmetric key can be generated by the business page. In order to reduce the possibility of the symmetric key being predicted, the symmetric key can be randomly generated by the business page. The first public key can be built into the business page as a page variable of the business page. The first public key can be a public key paired with the private key of the authentication server.

[0043] After receiving the authentication key request, the authentication server can obtain the identity credentials and the first signature from the authentication key request and verify the identity credentials and the first signature. The verification of the identity credentials is the authentication of the user's identity, and the verification of the first signature is the authentication of the application that initiated the request, to prevent the identity credentials from being used by parties other than the identity credential requester and causing information leakage. If both the identity credentials and the first signature are verified, it means that the user corresponding to the identity credentials has the authority to conduct business and the identity credentials are used by the identity credential requester, which has information security. If at least one of the identity credentials and the first signature fails to be verified, it means that the user corresponding to the identity credentials does not have the authority to conduct business and / or the identity credentials are used by parties other than the identity credential requester, which has information security risks.

[0044] In an embodiment of the present application, the front-end device obtains an identity credential from the authentication server through an application, signs the identity credential to obtain a first signature, launches a browser to request a business page from the authentication server, provides the identity credential and the first signature to the business page, and sends an authentication key request to the authentication server through the business page. The authentication key request includes a first ciphertext obtained by encrypting the identity credential and the first signature with a symmetric key and a symmetric key ciphertext obtained by encrypting the symmetric key with the first public key built into the business page, so that the authentication server verifies the identity credential and the first signature based on the authentication key request. In this process, whether in a multi-user scenario or a single-user scenario, the front-end device does not need to store, manage, or replace the user's private key certificate. Instead, it applies for an identity credential from the authentication server, encrypts the identity credential, and transmits it to the authentication server. This converts the identity authentication of the front-end device to the authentication server, allowing the front-end device to support the user's identity authentication while reducing the resources occupied by identity authentication. In this identity authentication process, the user does not need to perform login or authorization operations, which can also simplify user operations and improve user experience.

[0045] In some embodiments, applications and business pages can be signed and the signatures can be verified with the authentication server using a pair of public and private keys. Figure 4 is a flow chart of a front-end-based identity authentication method provided by another embodiment of the first aspect of this application. The difference between Figure 4 and Figure 3 is that the front-end-based identity authentication method shown in Figure 4 can also include steps S204 and S205, and can also include steps S206 to S208. Step S201 in Figure 3 can be specifically refined into steps S2011 and S2012 in Figure 4.

[0046] In step S204, an identity credential request is generated by the application, and the identity credential request is signed using the second private key of the application to obtain a second signature.

[0047] The identity credential request includes user information, which may indicate the user's identity. For example, the user information may include user ID, user mobile number, user email address, and other user identifiers, which are not limited here. The second signature is a signature of the identity credential request using the second private key.

[0048] In some examples, the identity credential request may be generated by the application when the application receives user input regarding content related to a service provided by the service server in the application.

[0049] In step S205, the identity credential request and the second signature are sent to the authentication server through the application.

[0050] After the application generates the identity credential request and the second signature, it can send the identity credential request and the second signature to the authentication server. In some examples, the front-end device can send the identity credential and the second signature to the application's back-end server through the application, and the back-end server then sends the identity credential and the second signature to the authentication server. Corresponding to the application's second private key, the authentication server stores a second public key paired with the second private key. The second public key can be used to verify the second signature. The authentication server can use the second public key to verify the second signature, determining whether the received information has been tampered with and whether the identity credential requester is legitimate.

[0051] In step S2011, when the second signature passes the verification of the authentication server, the identity certificate issued by the authentication server is received through the application.

[0052] Verification of the second signature by the authentication server indicates that the identity credential request has not been tampered with and that the identity credential requester is legitimate. If the second signature is verified, the authentication server issues the identity credential corresponding to the identity credential request to the application. In some examples, the authentication server may first send the identity credential to the application's backend server, which then sends the identity credential to the application on the frontend device.

[0053] In step S2012, the application uses the second private key of the application to sign the identity certificate to obtain a first signature.

[0054] The second private key is the application's private key. Corresponding to the second private key, the authentication server stores a second public key paired with the second private key. The authentication server can use the second public key to verify the first signature. If the verification succeeds, it indicates that the identity credential has not been tampered with and the identity credential requester is legitimate. The identity credential is used by the identity credential requester, i.e., the application, and thus has information security. Generating the first signature using the second private key and verifying the first signature using the second public key prevents the identity credential from being used by other applications that have not applied for the identity credential, thereby preventing user information from being leaked.

[0055] In step S206, a symmetric key is randomly generated through the business page, and the identity certificate and the first signature are encrypted using the symmetric key to obtain a first ciphertext.

[0056] In step S207, the symmetric key is encrypted by the business page using the first public key built into the business page to obtain a symmetric key ciphertext.

[0057] In step S208, an authentication key request is generated through the business page according to the first ciphertext and the symmetric key ciphertext.

[0058] Correspondingly, the authentication server stores a first private key paired with the first public key. The first private key is used by the authentication server to decrypt the symmetric key ciphertext to obtain the symmetric key, and then use the symmetric key to decrypt the first ciphertext to obtain the identity certificate and the first signature. Upon receiving the authentication key request, the authentication server can use the first private key to decrypt the symmetric key ciphertext to obtain the symmetric key, and then use the symmetric key to decrypt the first ciphertext to obtain the identity certificate and the first signature, thereby verifying the identity certificate and the first signature.

[0059] In some examples, in order to prevent the identity credential from being misused by others, the identity credential is a one-time verification credential with a validity period, that is, the identity credential is a short-term, one-time credential. The identity credential will become invalid after the validity period expires. The validity period can be set according to the business scenario, business needs, and experience. For example, the validity period can be set to 30 minutes. The identity credential will become invalid after one verification. Correspondingly, the authentication server's verification of the identity credential includes verification of whether the identity credential is a credential issued by the authentication server and verification of whether the identity credential is valid. The verification of whether the identity credential is valid can be achieved by whether the identity credential is within the validity period and whether the identity credential is verified for the first time. When the authentication server determines that the identity credential is a credential issued by itself, the identity credential is within the validity period, and the identity credential is verified for the first time, the identity credential passes the verification. If at least one of the three conditions, namely, the identity credential is a credential issued by the authentication server, the identity credential is within the validity period, and the identity credential is verified for the first time, is not met, the identity credential is considered to have failed the verification.

[0060] In some embodiments, the authentication server may provide a key index of a symmetric key to the business page of the front-end device, so that the business page of the front-end device and the business server can use the symmetric key to exchange business information to implement the user's business operations. Figure 5 is a flowchart of a front-end-based identity authentication method provided by another embodiment of the first aspect of this application. The difference between Figure 5 and Figure 3 is that the flowchart of the front-end-based identity authentication method shown in Figure 5 can also include steps S209 and S210.

[0061] In step S209 , when the authentication server successfully verifies the identity credential and the first signature, the key index fed back by the authentication server is received through the service page.

[0062] Successful verification of the identity credentials and the first signature indicates successful authentication of the user's identity. If the identity credentials and the first signature are successfully verified, the authentication server may cache the symmetric key in a cache location and generate a key index based on the cache location. The key index may be used to indicate the cache location of the symmetric key. The authentication server sends the key index to the service page of the front-end device, so that the service page receives the key index. The symmetric key may be cached in the authentication server, in the service server, or in a third-party device, without limitation here.

[0063] In some examples, the authentication server may encrypt the key index using a symmetric key and send the encrypted key index, i.e., the ciphertext of the key index, to the business page. The business page receives the ciphertext of the key index and may decrypt the ciphertext of the key index using the symmetric key to obtain the key index.

[0064] When the user identity authentication is passed, the user indicated by the identity credential can access the service, and the service page of the front-end device can exchange information with the service server that provides the service.

[0065] In step S210 , when the authentication server successfully verifies the identity certificate and the first signature, a service request is sent to the service server through the service page, and service response information fed back by the service server is displayed through the service page.

[0066] The service request sent by the front-end device to the service server via the service page may include the user's request content. In response to the service request, the service server will provide service response information to the front-end device's service page. The front-end device's service page receives the service response information and displays it on the service page, allowing the user to obtain the service. For example, the front-end device may interact with the service server through the service page to obtain a payment code, or it may interact with the service server through the service page to obtain transaction result information.

[0067] While the business page is not closed, the information transmitted between the business page and the business server may be a ciphertext encrypted using a symmetric key. In some examples, the business request may include a second ciphertext and a key index. The second ciphertext is obtained by encrypting the business request information with a symmetric key. The key index is used to enable the business server to obtain the symmetric key from the corresponding cache location and use the symmetric key to decrypt the second ciphertext to obtain the business request information. When the business server receives the business request, it may obtain the symmetric key from the corresponding cache location according to the key index, decrypt the second ciphertext using the symmetric key, and obtain the business request information; the business server provides business response information corresponding to the business request information based on the business request information; the business server may encrypt the business response information using the symmetric key to obtain a third ciphertext, and feed the third ciphertext back to the business page of the front-end device; the business page of the front-end device may decrypt the third ciphertext using the symmetric key to obtain the business response information, thereby displaying the business response information.

[0068] It should be noted that if the service page is closed and the user needs to perform the next service operation, steps S201 to S203 above must be re-executed. The front-end device launches the browser through the application to re-request the service page and re-apply for identity credentials. The service page will randomly generate a new symmetric key and generate a new authentication key request to authenticate the user. While the re-requested service page is still open, the information transmitted between the service page and the service server can be encrypted using the new symmetric key.

[0069] In the above embodiment, the front-end device's service page transmits the symmetric key to the authentication server via an authentication key request. The authentication server then caches the symmetric key. This symmetric key can then be used for symmetrically encrypted information exchange during the service process corresponding to the service page. This eliminates the need to generate a new key for each exchange, reducing encryption resource consumption.

[0070] A second aspect of the present application provides a front-end-based identity authentication method that can be applied to an authentication server. That is, the front-end-based identity authentication method can be executed by the authentication server. Figure 6 is a flowchart of the front-end-based identity authentication method provided by an embodiment of the second aspect of the present application. As shown in Figure 6, the front-end-based identity authentication method may include steps S301 to S304.

[0071] In step S301, identity credentials are issued to the application in the front-end device.

[0072] In step S302, in response to a request initiated by the browser in the front-end device being launched by the application, a business page is provided to the front-end device, so that the business page obtains the identity credential and the first signature of the identity credential from the application.

[0073] In step S303, an authentication key request sent by the front-end device through the service page is received.

[0074] The authentication key request includes a first ciphertext and a symmetric key ciphertext. The first ciphertext is obtained by encrypting the identity credential and the first signature using the symmetric key. The symmetric key ciphertext is obtained by encrypting the symmetric key using the first public key built into the business page. In some examples, the symmetric key is randomly generated by the business page.

[0075] In step S304, based on the authentication key request, the identity certificate and the first signature are verified.

[0076] In some examples, the identity credential is a one-time verification credential with a validity period. The authentication server may determine whether the identity credential is an identity credential issued by the authentication server, whether the identity credential is within the validity period, and whether this is the first authentication of the identity credential. If the identity credential is an identity credential issued by the authentication server, is within the validity period, and this is the first authentication, the identity credential is determined to have passed authentication.

[0077] In some examples, the first signature is obtained by the application using the application's second private key to sign the identity credential. Correspondingly, the authentication server stores a second public key paired with the second private key. The second public key can be used to verify the first signature. That is, the authentication server can verify the first signature using the second public key.

[0078] The specific contents of the above steps S301 to S304 can be found in the relevant descriptions in the above embodiments, which will not be repeated here.

[0079] In an embodiment of the present application, an authentication server can issue an identity credential to an application on a front-end device. The front-end device launches a browser through the application and requests a service page from the authentication server. The authentication server provides the service page to the front-end device, allowing the front-end device to obtain the identity credential and the first signature of the identity credential from the application through the service page. The authentication server receives an authentication key request sent by the front-end device via the service page. The authentication key request includes a first ciphertext encrypted from the identity credential and the first signature using a symmetric key, and a symmetric key ciphertext encrypted from the symmetric key using a first public key built into the service page. The authentication server can verify the identity credential and the first signature based on the authentication key request. In this process, whether in a multi-user or single-user scenario, the front-end device does not need to store, manage, or replace the user's private key certificate. Instead, the front-end device transfers the identity authentication of the front-end device to the authentication server by requesting the identity credential from the authentication server and then encrypting and transmitting the identity credential to the authentication server. This allows the front-end device to support user identity authentication while reducing the resources occupied by identity authentication. During this authentication process, the user does not need to log in or authorize, which simplifies user operations and improves the user experience.

[0080] In some embodiments, the authentication server can sign and verify the signatures with the application and business page using a pair of public and private keys. Figure 7 is a flowchart of a front-end-based identity authentication method provided by another embodiment of the second aspect of this application. The difference between Figure 7 and Figure 6 is that the flowchart of the front-end-based identity authentication method shown in Figure 7 can also include steps S305 and S306, as well as steps S307 and S308. Step S301 in Figure 6 can be specifically refined into step S3011 in Figure 7.

[0081] In step S305, an identity credential request and a second signature sent by the front-end device through the application are received.

[0082] The second signature is obtained by the application using the second private key to sign the identity certificate request.

[0083] In step S306, the second signature is verified.

[0084] Corresponding to the second private key, the authentication server stores a second public key paired with the second private key. The second public key can be used to verify the second signature, that is, the authentication server can use the second public key to verify the second signature.

[0085] In step S3011, when the second signature is verified successfully, the identity certificate is sent to the application in the front-end device.

[0086] In step S307, the symmetric key ciphertext is decrypted using the first private key to obtain the symmetric key.

[0087] The authentication server stores a first private key paired with the first public key.

[0088] In step S308, the first ciphertext is decrypted using the symmetric key to obtain the identity certificate and the first signature.

[0089] The specific contents of the above steps S305 to S308 and step S3011 can be found in the relevant descriptions in the above embodiments and will not be repeated here.

[0090] In some embodiments, the authentication server may provide a key index of a symmetric key to the business page of the front-end device, so that the business server and the business page of the front-end device can use the symmetric key to exchange business information to implement the user's business operations. Figure 8 is a flowchart of a front-end-based identity authentication method provided by another embodiment of the second aspect of this application. The difference between Figure 8 and Figure 6 is that the front-end-based identity authentication method shown in Figure 8 can also include steps S309 and S310.

[0091] In step S309, when the identity credential and the first signature are verified, the symmetric key obtained based on the symmetric key ciphertext is cached to a cache location, and a key index is generated.

[0092] The key index is used to indicate the cache location of the symmetric key.

[0093] In step S310, the key index is sent to the business page.

[0094] The symmetric key corresponds to the business page.

[0095] In some examples, if the identity credentials and the first signature are verified successfully, the front-end device sends a service request to the service server via the service page, causing the service server to return service response information to the service page. The service request includes a second ciphertext and a key index. The second ciphertext is obtained by encrypting the service request information using a symmetric key on the service page. The key index is used by the service server to retrieve the symmetric key from the corresponding cache location and decrypt the second ciphertext using the symmetric key to obtain the service request information.

[0096] The specific contents of the above steps S309 and S310 can be found in the relevant descriptions in the above embodiments, which will not be repeated here.

[0097] For ease of understanding, the following example illustrates the identity authentication and service execution process involved in the front-end device, the service page requested by the front-end device, the authentication server, and the service server in the embodiment of the present application. Figure 9 is a schematic diagram of an example of the identity authentication and service execution process provided by the embodiment of the present application. The application in Figure 9 includes the application and the back-end server of the application. As shown in Figure 9, the identity authentication and service execution process may include steps a1 to a9.

[0098] In step a1, the application initiates an identity credential request to the authentication server, and signs the identity credential request to obtain a second signature.

[0099] In step a2, the authentication server verifies the second signature. If the verification is successful, the authentication server generates an identity credential and feeds the identity credential back to the application. The identity credential is a short-term, one-time credential.

[0100] In step a3, after the application obtains the identity certificate, it signs the identity certificate using the second private key to obtain a first signature, and then launches a browser to request a service page from the authentication server. The service page is an HTML page.

[0101] In step a4, the business page obtains the identity certificate and the first signature from the application through the application program interface.

[0102] In step a5, the business page randomly generates a symmetric key, uses the symmetric key to symmetrically encrypt the identity certificate and the first signature to obtain a first ciphertext; the business page uses the first public key built into the business page to asymmetrically encrypt the symmetric key to obtain a symmetric key ciphertext; the business page sends an authentication key request including the first ciphertext and the symmetric key ciphertext to the authentication server.

[0103] In step a6, after receiving the authentication key request, the authentication server uses the first private key paired with the first public key to decrypt the symmetric key ciphertext to obtain the symmetric key, and then uses the symmetric key to decrypt the first ciphertext to obtain the identity certificate and the first signature; the authentication server verifies whether the identity certificate is an identity certificate issued by the authentication server, whether the identity certificate is within the validity period and whether it is the first verification. If the identity certificate is an identity certificate issued by the authentication server, the identity certificate is within the validity period and it is the first verification, it is determined that the identity certificate has passed the verification; the authentication server uses the second public key paired with the second private key to verify the first signature; if both the identity certificate and the first signature are verified, it is determined that the identity authentication is successful; the authentication server generates a key index corresponding to the authentication key request, caches the symmetric key to the cache location indicated by the key index, and responds to the key index to the business page.

[0104] In step a7, the service page encrypts the service request information using the symmetric key to obtain a second ciphertext; the service page sends a service request including the second ciphertext and the key index to the service server.

[0105] In step a8, the business server obtains the symmetric key according to the key index, decrypts the second ciphertext using the second key, and obtains the business request information; the business server generates business response information according to the business request information; the business server encrypts the business response information using the symmetric key, and feeds back the ciphertext of the business response information to the business page.

[0106] In step a9, the business page decrypts the ciphertext of the business response information using the symmetric key to obtain the business response information and displays the business response information. The business page can be opened in the application, thereby displaying the business response information to the user through the application.

[0107] The specific contents of the above steps a1 to a9 can be found in the relevant descriptions in the above embodiments, which will not be repeated here.

[0108] FIG10 is a schematic diagram of the structure of a front-end device provided in an embodiment of the third aspect of the present application. As shown in FIG10 , the front-end device 400 may include a receiving module 401 , a processing module 402 , a sending module 403 , and an acquiring module 404 .

[0109] The receiving module 401 may be configured to obtain identity credentials from an authentication server through an application.

[0110] The processing module 402 may be configured to obtain a first signature of the identity credential.

[0111] The sending module 403 may be configured to launch a browser through an application program to request a service page from the authentication server.

[0112] The acquisition module 404 may be configured to acquire the identity credential and the first signature from the application through the business page.

[0113] The sending module 403 may also be configured to send an authentication key request to the authentication server through the service page, so that the authentication server verifies the identity certificate and the first signature.

[0114] The authentication key request includes a first ciphertext and a symmetric key ciphertext. The first ciphertext is obtained by encrypting the identity certificate and the first signature using the symmetric key. The symmetric key ciphertext is obtained by encrypting the symmetric key using the first public key built into the business page.

[0115] In some examples, the identity credential is a one-time verification credential with a validity period. If the authentication server determines that the identity credential is a credential issued by itself, the identity credential is within the validity period, and it is the first time to verify the identity credential, the identity credential passes verification.

[0116] In an embodiment of the present application, the front-end device obtains an identity credential from the authentication server through an application, signs the identity credential to obtain a first signature, launches a browser to request a business page from the authentication server, provides the identity credential and the first signature to the business page, and sends an authentication key request to the authentication server through the business page. The authentication key request includes a first ciphertext obtained by encrypting the identity credential and the first signature with a symmetric key and a symmetric key ciphertext obtained by encrypting the symmetric key with the first public key built into the business page, so that the authentication server verifies the identity credential and the first signature based on the authentication key request. In this process, whether in a multi-user scenario or a single-user scenario, the front-end device does not need to store, manage, or replace the user's private key certificate. Instead, it applies for an identity credential from the authentication server, encrypts the identity credential, and transmits it to the authentication server. This converts the identity authentication of the front-end device to the authentication server, allowing the front-end device to support the user's identity authentication while reducing the resources occupied by identity authentication. In this identity authentication process, the user does not need to perform login or authorization operations, which can also simplify user operations and improve user experience.

[0117] In some embodiments, the processing module 402 can also be used to: randomly generate a symmetric key through the business page, use the symmetric key to encrypt the identity certificate and the first signature to obtain a first ciphertext; encrypt the symmetric key through the business page using the first public key built into the business page to obtain a symmetric key ciphertext; generate an authentication key request through the business page based on the first ciphertext and the symmetric key ciphertext.

[0118] In some examples, the processing module 402 may be specifically configured to: use the application program to sign the identity credential using the second private key of the application program to obtain a first signature.

[0119] In some embodiments, the processing module 402 may also be used to: generate an identity credential request through an application, sign the identity credential request using a second private key of the application to obtain a second signature, wherein the identity credential request includes user information.

[0120] The sending module 403 may also be configured to send an identity credential request and a second signature to the authentication server via the application.

[0121] The receiving module 401 may be specifically configured to: when the second signature passes verification by the authentication server, receive the identity certificate issued by the authentication server through the application program.

[0122] In some embodiments, the front-end device 400 may further include a display module.

[0123] The sending module 403 may also be configured to: send a service request to the service server via the service page when the authentication server successfully verifies the identity certificate and the first signature.

[0124] The display module can be used to display the business response information fed back by the business server through the business page.

[0125] In some examples, the receiving module 401 may also be configured to: receive a key index fed back by the authentication server through a service page when the authentication server successfully verifies the identity credential and the first signature. The key index is used to indicate a cache location of the symmetric key.

[0126] The service request includes a second ciphertext and a key index. The second ciphertext is encrypted using a symmetric key. The key index is used by the service server to retrieve the symmetric key from the corresponding cache location and decrypt the second ciphertext using the symmetric key to obtain the service request.

[0127] In some embodiments, the authentication server stores a first private key paired with the first public key. The first private key is used by the authentication server to decrypt the symmetric key ciphertext to obtain the symmetric key, and then use the symmetric key to decrypt the first ciphertext to obtain the identity certificate and the first signature.

[0128] In some embodiments, the authentication server stores a second public key paired with the second private key. The second public key is used to verify the first signature or the second signature.

[0129] FIG11 is a schematic diagram of the structure of an authentication server provided by an embodiment of the fourth aspect of the present application. As shown in FIG11 , the authentication server 500 may include a sending module 501 , a receiving module 502 , and a processing module 503 .

[0130] The sending module 501 can be used to issue identity credentials to the application in the front-end device; and, in response to a request initiated by the browser in the front-end device being pulled up by the application, provide a business page to the front-end device so that the business page obtains the identity credential and the first signature of the identity credential from the application.

[0131] The receiving module 502 may be configured to receive an authentication key request sent by the front-end device via a business page. The authentication key request includes a first ciphertext and a symmetric key ciphertext. The first ciphertext is obtained by encrypting the identity credential and the first signature using the symmetric key, and the symmetric key ciphertext is obtained by encrypting the symmetric key using the first public key built into the business page.

[0132] The processing module 503 may be configured to verify the identity credential and the first signature based on the authentication key request.

[0133] In an embodiment of the present application, an authentication server can issue an identity credential to an application on a front-end device. The front-end device launches a browser through the application and requests a service page from the authentication server. The authentication server provides the service page to the front-end device, allowing the front-end device to obtain the identity credential and the first signature of the identity credential from the application through the service page. The authentication server receives an authentication key request sent by the front-end device via the service page. The authentication key request includes a first ciphertext encrypted from the identity credential and the first signature using a symmetric key, and a symmetric key ciphertext encrypted from the symmetric key using a first public key built into the service page. The authentication server can verify the identity credential and the first signature based on the authentication key request. In this process, whether in a multi-user or single-user scenario, the front-end device does not need to store, manage, or replace the user's private key certificate. Instead, the front-end device transfers the identity authentication of the front-end device to the authentication server by requesting the identity credential from the authentication server and then encrypting and transmitting the identity credential to the authentication server. This allows the front-end device to support user identity authentication while reducing the resources occupied by identity authentication. During this authentication process, the user does not need to log in or authorize, which simplifies user operations and improves the user experience.

[0134] In some examples, the identity credential is a one-time verification credential with a validity period. The processing module 503 can be specifically configured to determine whether the identity credential is an identity credential issued by the authentication server, whether the identity credential is within the validity period, and whether this is the first verification of the identity credential; if the identity credential is an identity credential issued by the authentication server, is within the validity period, and this is the first verification, determine that the identity credential has passed verification.

[0135] In some examples, the symmetric key is randomly generated by the business page.

[0136] In some examples, the first signature is obtained by the application signing the identity credential using the application's second private key.

[0137] In some embodiments, the receiving module 502 may further be configured to receive an identity credential request and a second signature sent by the front-end device via an application program. The second signature is obtained by the application program signing the identity credential request using the second private key.

[0138] The processing module 503 may also be used to verify the second signature.

[0139] The sending module 501 may be specifically configured to send the identity certificate to the application in the front-end device when the verification of the second signature is successful.

[0140] In some embodiments, when the identity credential and the first signature are verified successfully, the service request sent by the front-end device to the service server through the service page is used to enable the service server to feed back service response information to the service page.

[0141] In some embodiments, the processing module 503 may also be configured to: if the identity credential and the first signature are verified successfully, cache the symmetric key obtained based on the symmetric key ciphertext to a cache location and generate a key index indicating the cache location of the symmetric key.

[0142] The sending module 501 may also be used to send a key index to the business page, where the symmetric key corresponds to the business page.

[0143] The service request includes a second ciphertext and a key index. The second ciphertext is encrypted by the service page using a symmetric key. The key index is used by the service server to retrieve the symmetric key from the corresponding cache location and decrypt the second ciphertext using the symmetric key to obtain the service request information.

[0144] In some embodiments, the authentication server stores a first private key paired with the first public key.

[0145] The processing module 503 may also be configured to: decrypt the symmetric key ciphertext using the first private key to obtain the symmetric key; and decrypt the first ciphertext using the symmetric key to obtain the identity certificate and the first signature.

[0146] In some examples, the authentication server stores a second public key paired with the second private key, and the second public key is used to verify the first signature or the second signature.

[0147] A fifth aspect of the present application further provides a front-end device. Figure 12 is a schematic diagram of the structure of a front-end device provided in an embodiment of the fifth aspect of the present application. As shown in Figure 12, the front-end device 600 includes a memory 601, a processor 602, and a computer program stored in the memory 601 and executable on the processor 602.

[0148] In some examples, the processor 602 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0149] The memory 601 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Therefore, typically, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the front-end-based identity authentication method in the embodiment of the first aspect of the present application.

[0150] The processor 602 runs the computer program corresponding to the executable program code by reading the executable program code stored in the memory 601, so as to implement the front-end-based identity authentication method in the embodiment of the first aspect mentioned above.

[0151] In some examples, the front-end device 600 may further include a communication interface 603 and a bus 604. As shown in FIG12, the memory 601, the processor 602, and the communication interface 603 are connected via the bus 604 and communicate with each other.

[0152] The communication interface 603 is mainly used to implement communication between the modules, devices, units and / or equipment in the embodiment of the present application. Input devices and / or output devices can also be connected through the communication interface 603.

[0153] The bus 604 includes hardware, software, or both, and couples the components of the front-end device 600 to each other. By way of example and not limitation, the bus 604 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-E) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 604 may include one or more buses. Although embodiments herein describe and illustrate a particular bus, this application contemplates any suitable bus or interconnect.

[0154] A sixth aspect of the present application provides an authentication server, which may include a memory, a processor, and a computer program stored in the memory and executable on the processor.

[0155] The memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the front-end-based identity authentication method in the embodiment of the second aspect of the present application.

[0156] The processor runs the computer program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the front-end-based identity authentication method in the above-mentioned second aspect embodiment.

[0157] In some examples, the authentication server may further include a communication interface and a bus. The memory, processor, and communication interface are connected via the bus and communicate with each other.

[0158] The connection relationship and specific implementation method of the above-mentioned memory, processor, communication interface and bus can be found in the connection relationship and specific implementation method of the memory, processor, communication interface and bus in the front-end device in the above-mentioned embodiment, and will not be repeated here.

[0159] The seventh aspect of the present application provides a front-end-based identity authentication system, which may include a front-end device and an authentication server. The specific contents of the front-end device and the authentication server can be found in the relevant descriptions in the above embodiments and will not be repeated here.

[0160] In some embodiments, the front-end-based identity authentication system may further include a business server. For specific contents of the business server, please refer to the relevant descriptions in the above embodiments and will not be repeated here.

[0161] In some embodiments, the front-end-based identity authentication system may further include a background server of the application. For the specific content of the background server, please refer to the relevant description in the above embodiments and will not be repeated here.

[0162] In an eighth aspect of the present application, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the front-end-based identity authentication method in the above embodiment can be implemented, and the same technical effect can be achieved. To avoid repetition, the above-mentioned computer-readable storage medium may include a non-transitory computer-readable storage medium, such as a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc., which is not limited here.

[0163] An embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by the processor of an electronic device, the electronic device can execute the front-end-based identity authentication method in the above-mentioned first embodiment or the front-end-based identity authentication method in the above-mentioned second embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0164] It should be clear that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. For the front-end device embodiment, authentication server embodiment, system embodiment, computer-readable storage medium embodiment, and computer program product embodiment, the relevant parts can be referred to the description part of the method embodiment. This application is not limited to the specific steps and structures described above and shown in the figures. Those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of this application. In addition, for the sake of brevity, a detailed description of known method technologies is omitted here.

[0165] Aspects of the present application have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed via the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. This processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or the flowchart and the combination of the boxes in the block diagram and / or the flowchart can also be implemented by the dedicated hardware that performs the specified function or action, or can be implemented by the combination of dedicated hardware and computer instructions.

[0166] Those skilled in the art should understand that the above embodiments are illustrative rather than restrictive. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Based on a study of the drawings, the specification and the claims, those skilled in the art should be able to understand and implement other variations of the disclosed embodiments. In the claims, the term "comprising" does not exclude other devices or steps; the quantifier "one" does not exclude a plurality; the terms "first" and "second" are used to identify names rather than to indicate any specific order. Any figure marks in the claims should not be understood as limiting the scope of protection. The functions of multiple parts appearing in the claims can be implemented by a separate hardware or software module. The fact that certain technical features appear in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.

Claims

1. A front-end based identity authentication method, applied to a front-end device, the method comprising: Obtaining an identity credential from an authentication server through an application, and obtaining a first signature of the identity credential; Pulling up a browser through the application to request a service page from the authentication server, and obtaining the identity credential and the first signature from the application through the service page; Sending an authentication key request to the authentication server through the service page, so that the authentication server verifies the identity credential and the first signature, the authentication key request includes a first ciphertext and a symmetric key ciphertext, the first ciphertext is obtained by encrypting the identity credential and the first signature with a symmetric key, and the symmetric key ciphertext is obtained by encrypting the symmetric key with a first public key built in the service page.

2. The method according to claim 1, wherein, Before sending the authentication key request to the authentication server through the service page, it further includes: Randomly generating the symmetric key through the service page, and encrypting the identity credential and the first signature with the symmetric key to obtain the first ciphertext; Encrypting the symmetric key with the first public key built in the service page through the service page to obtain a symmetric key ciphertext; Generating the authentication key request according to the first ciphertext and the symmetric key ciphertext through the service page.

3. The method according to claim 1, wherein, The obtaining the first signature of the identity credential includes: Signing the identity credential with a second private key of the application through the application to obtain the first signature.

4. The method according to claim 1, wherein Before obtaining the identity credential from the authentication server through the application and obtaining the first signature of the identity credential, it further includes: Generating an identity credential request through the application, and signing the identity credential request with a second private key of the application to obtain a second signature, the identity credential request includes user information; Sending the identity credential request and the second signature to the authentication server through the application; The obtaining the identity credential from the authentication server through the application includes: Receiving the identity credential sent by the authentication server through the application in the case where the second signature passes the verification of the authentication server.

5. The method according to claim 1, further comprising: In the case where the authentication server passes the verification of the identity credential and the first signature, sending a service request to a service server through the service page, and displaying service response information fed back by the service server through the service page.

6. The method according to claim 5, further comprising: In the case where the authentication server passes the verification of the identity credential and the first signature, receiving a key index fed back by the authentication server through the service page, the key index is used to indicate the caching location of the symmetric key; The service request includes a second ciphertext and the key index. The second ciphertext is obtained by encrypting service request information with the symmetric key. The key index is used to enable the service server to obtain the symmetric key from a corresponding cache location and decrypt the second ciphertext with the symmetric key to obtain the service request information.

7. The method according to claim 1, wherein the authentication server stores a first private key paired with the first public key, the first private key is used for the authentication server to decrypt the symmetric key ciphertext to obtain the symmetric key, so as to decrypt the first ciphertext with the symmetric key to obtain the identity credential and the first signature.

8. The method according to claim 3 or 4, wherein the authentication server stores a second public key paired with the second private key, and the second public key is used to verify the first signature or verify the second signature.

9. The method according to any one of claims 1 to 7, wherein the identity credential is a one-time verification credential with a validity period, when the authentication server determines that the identity credential is a credential issued by itself, the identity credential is within the validity period, and the identity credential is verified for the first time, the identity credential passes the verification.

10. A front-end based identity authentication method applied to an authentication server, the method comprising: sending an identity credential to an application in a front-end device; in response to a request initiated when a browser in the front-end device is launched by the application, providing a service page to the front-end device, so that the service page obtains the identity credential and the first signature of the identity credential from the application; receiving an authentication key request sent by the front-end device through the service page, the authentication key request including a first ciphertext and a symmetric key ciphertext, the first ciphertext being obtained by encrypting the identity credential and the first signature with the symmetric key, and the symmetric key ciphertext being obtained by encrypting the symmetric key with a first public key built in the service page; verifying the identity credential and the first signature based on the authentication key request.

11. The method according to claim 10, wherein, The symmetric key is randomly generated by the service page.

12. The method according to claim 10, wherein, The first signature is obtained by the application signing the identity credential with a second private key of the application.

13. The method according to claim 10, wherein, Before sending the identity credential to the application in the front-end device, it further includes: receiving an identity credential request and a second signature sent by the front-end device through the application, the second signature being obtained by the application signing the identity credential request with a second private key; verifying the second signature; sending the identity credential to the application in the front-end device includes: when the verification of the second signature passes, sending the identity credential to the application in the front-end device.

14. The method according to claim 10, wherein when the identity credential and the first signature pass the verification, the service request sent by the front-end device to the service server through the service page is used to enable the service server to feedback service response information to the service page.

15. The method according to claim 14 further includes: When the identity credential and the first signature pass the verification, caching the symmetric key obtained from the symmetric key ciphertext to a cache location, and generating a key index for indicating the cache location of the symmetric key; Sending the key index to the service page, where the symmetric key corresponds to the service page; The service request includes a second ciphertext and the key index. The second ciphertext is obtained by the service page encrypting service request information using the symmetric key. The key index is used to enable the service server to obtain the symmetric key from the corresponding cache location and decrypt the second ciphertext using the symmetric key to obtain the service request information.

16. The method according to claim 10, wherein The authentication server stores a first private key paired with the first public key. Before verifying the identity credential and the first signature, it further includes: Decrypting the symmetric key ciphertext using the first private key to obtain the symmetric key; Decrypting the first ciphertext using the symmetric key to obtain the identity credential and the first signature.

17. The method according to claim 12 or 13, wherein The authentication server stores a second public key paired with the second private key, and the second public key is used to verify the first signature or the second signature.

18. The method according to any one of claims 10 to 16, wherein The identity credential is a one-time verification credential with a validity period. Verifying the identity credential includes: Determining whether the identity credential is the identity credential issued by the authentication server, whether the identity credential is within the validity period, and whether the identity credential is verified for the first time; When the identity credential is the credential issued by the authentication server, within the validity period and verified for the first time, determining that the identity credential passes the verification.

19. A front-end device includes: A receiving module for obtaining an identity credential from an authentication server through an application; A processing module for obtaining a first signature of the identity credential; A sending module for pulling up a browser through the application to request a service page from the authentication server; An obtaining module for obtaining the identity credential and the first signature from the application through the service page; The sending module is further configured to send an authentication key request to the authentication server through the service page, so that the authentication server verifies the identity credential and the first signature. The authentication key request includes a first ciphertext and a symmetric key ciphertext. The first ciphertext is obtained by encrypting the identity credential and the first signature using the symmetric key. The symmetric key ciphertext is obtained by encrypting the symmetric key using a first public key built in the service page.

20. An authentication server includes: A sending module for issuing an identity credential to an application in a front-end device; And, in response to a request initiated by pulling up a browser in the front-end device by the application, providing a service page to the front-end device, so that the service page obtains the identity credential and a first signature of the identity credential from the application. A receiving module, configured to receive an authentication key request sent by the front-end device through the service page, where the authentication key request includes a first ciphertext and a symmetric key ciphertext, the first ciphertext is obtained by encrypting the identity credential and the first signature with a symmetric key, and the symmetric key ciphertext is obtained by encrypting the symmetric key with a first public key built in the service page; A processing module, configured to verify the identity credential and the first signature based on the authentication key request.

21. A front-end device, comprising: A processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the method for front-end based identity authentication as described in any one of claims 1 to 9 is implemented.

22. An authentication server, comprising: A processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the method for front-end based identity authentication as described in any one of claims 10 to 18 is implemented.

23. A front-end based identity authentication system, including the front-end device as described in claim 21 and the authentication server as described in claim 22.

24. A computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method for front-end based identity authentication as described in any one of claims 1 to 18 is implemented.

Citation Information

Patent Citations

  • Cookie-based secure single sign-on method and unified authentication service system thereof

    CN108600203A

  • Safety protection system and method based on browser

    CN111159684A

  • Identity authentication method and device, equipment, storage medium and computer program product

    CN114070614A

  • Application login control method and device, electronic equipment and storage medium

    CN115809455A

  • Identity authentication method, device, equipment and system based on front end, and medium

    CN118013481A