The invention provides a
certificate generation and access
authentication method based on host fingerprints, and aims to improve
authentication security by combining hardware fingerprints and
certificate management. In the traditional EAP-TLS
authentication, the user identity completely depends on a
client certificate and a private key, is easy to copy or leak and has potential safety hazards, and when the private key is captured, an attacker can disguise as a user to access an
intranet. According to the method, hardware fingerprints are dynamically calculated at a
client side (an SHA256 Hash value is generated based on information of a network card, a hard disk, an SMBIOS, a mainboard and the like) to verify a certificate, and the certificate is sent to an
authentication server. Meanwhile, on the basis of EAP-TLS bidirectional authentication, the matching condition of the certificate
fingerprint and the
client host is additionally checked,
strong binding of the certificate and the host is achieved, and the related certificate can only be used on the corresponding host. In order to further enhance the protection of the certificate, the client stores the certificate and the private key as EFI variables. The method is widely applicable to various
wireless network authentication scenes, and has wide applicability and remarkable
economic benefits.