CN101686126A - Method for certification of set of novel dynamic passwords and autonymous network accessing - Google Patents
Method for certification of set of novel dynamic passwords and autonymous network accessing Download PDFInfo
- Publication number
- CN101686126A CN101686126A CN200810211363A CN200810211363A CN101686126A CN 101686126 A CN101686126 A CN 101686126A CN 200810211363 A CN200810211363 A CN 200810211363A CN 200810211363 A CN200810211363 A CN 200810211363A CN 101686126 A CN101686126 A CN 101686126A
- Authority
- CN
- China
- Prior art keywords
- usbkey
- password
- real name
- digital certificate
- dynamic
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Images
Landscapes
- Storage Device Security (AREA)
Abstract
The invention relates to a method for the certification of a set of novel dynamic passwords and autonymous network accessing by an independent password management center based on a digital certificateand a USBKey technology. The method concretely comprises a password management center, client terminal software, a USBKey and a digital certificate. The password management center receives a dynamicpassword application, generates dynamic passwords and hands out the dynamic passwords to a client terminal safely by a digital certificate technology; the corresponding passwords of a certification system are synchronously updated, thereby realizing the certification of the dynamic passwords; and the method is applied to network-accessing certification, so that the autonymous safe network accessing of a user can be realized. The method solves the problems of high cost, password desynchronizing, no autonym, large system reconstruction quantity and the like existing in the current similar methodand provides an autonymous, safe, economical and reliable method for the novel dynamic password certification and the autonymous network accessing.
Description
[affiliated technical field]
A kind of dynamic password service and real name internet access method based on digital certificate and USBkey specifically comprise cryptogram management center, client software, USBkey, digital certificate.
[technical background]
The password code technology is the common technique that present internet, applications is carried out authentification of user, but traditional static password cryptographic technique security intensity is lower, can not adapt to current internet and use more outstanding security requirement; Current network connection mode is exactly generally to adopt the static password pin mode.
Existing a kind of dynamic password technology is carried out synchronous computing at the client and server end group in common algorithm, common parameter exactly, and the result that will work as time computing is as working as time authentication password, and client need be equipped with special hardware.There are three open defects in this technology: owing to need to be equipped with special client hardware, the individual event cost is too high; Still there are client and the nonsynchronous possibility of corresponding Verification System end password technically; For existing application system, require corresponding Verification System to transform, and increase the server authentication computing load.
Different with said method is, the present invention is by independent password management center, utilizes the security feature of digital certificate and USBkey and the cover novel dynamic passwords method that forms.USBkey has been meant all kinds of terminal equipments of safety chip integrated, comprises Uebkey and key dish, safety intelligent card etc., and various symmetries that the safety chip in the terminal is integrated to becoming cryptographic algorithm, can be preserved various passwords and data with non-safely.A kind of defective of dynamic cipher verification technology before this method has thoroughly solved: realize that dynamic cipher verification just utilizes the USBkey existing capability, do not need the adding hardware cost; The present invention has introduced independent cryptogram management center, and the dynamic password of the affairs logic control client and server end by this center upgrades synchronously, thoroughly solves client and server end password desynchronizing problem; For existing application authorization system, the present invention does not require and transforms, and do not increase Verification System authentication algorithm amount; Also have,, guaranteed that effectively dynamic password can secure distribution arrive each user USBkey, and safety is preserved because USBkey supports the safe storage of digital cryptographic certificate computing and private key thereof.This method is applied to the network connection authentication, can utilizes digital certificate to realize the online of user's system of real name, and the fail safe that improves existing account number/password mode.
The present invention has real name, safety, economy, reliable characteristics concurrently.
[goal of the invention]
Purpose of the present invention has two:
1. a cover real name, safety, economy, reliable dynamic cipher authentication method are provided.
2. a cover real name, safety, economy, reliable network access authentication method are provided.
[summary of the invention]
One cover is made up of cryptogram management center, client software, USBkey, digital certificate based on the method that digital certificate and USBkey realize dynamic cipher verification and real name online.Specifically comprise four methods:
1. based on the dynamic cipher method of digital certificate.
Cryptogram management center is accepted the dynamic password application from user or corresponding Verification System, produces dynamic password, by digital certificate technique with the dynamic password secure distribution to client; Transmission channel by safety sends to corresponding Verification System with identical dynamic password; And guarantee that by affair mechanism the dynamic password of user side and corresponding Verification System end upgrades synchronously, realize the dynamic cipher verification of customer certification system, thereby the dynamic password service is provided client.
In order to reduce the influence of this method to the conventional authentication pattern, improve the robustness of this method, can replenish abnormality eliminating method: after dynamic password upgrades, continue to preserve safely once the password that authentication success is crossed simultaneously in client and corresponding Verification System end, in case the user fails with the dynamic cipher verification after upgrading, the password that the client and server end can automatic adaptive last success identity be crossed authenticates, can shield like this because of cryptogram management center or other fault effects authentification of users, a key of this abnormality eliminating method is to preserve the password that last authentication success is crossed safely.
This method goes for all kinds of internet, applications, and prerequisite is the fail safe that the user must guarantee its certificate private key.
2. based on the dynamic cipher method of digital certificate and USBkey.
On the basis of method 1, increase USBkey safety and preserve digital certificate and private key, and the password crossed of last authentication success, and the safe interface visit by strengthening, the fail safe that can further improve method 1 is adapted to the application of higher security needs.
3. based on the real name secure internet connection method of digital certificate.
On the basis of method 1, the particularity in conjunction with the network connection authentication can provide real name secure internet connection method.The particularity of network connection authentication is: before user's network connection authentication is passed through, the user does not also possess the online ability, can't access code administrative center request dynamic password, must obtain an account number consistent and password when therefore the user opens an account with corresponding Verification System, when dialling up on the telephone first, the user dials with account and password, authentication by after promptly finish user side and corresponding Verification System end by method 1 dynamic password upgrade synchronously, and safety is saved in assigned address, next time is when dialling, dialup client software obtains account number and password after the renewal automatically by the secure access interface, finishes dialing authentication according to the dialing protocol of standard.
4. based on the real name secure internet connection method of digital certificate and USBkey.
On the basis of method 3, increase USBkey safety and preserve digital certificate and private key, and dialing account number and password, and the safe interface visit by strengthening, the fail safe that can further improve method 1.
If the system of real name certificate is used in the said method, can provide corresponding real name dynamic cipher verification and real name internet access method.
The method that relates to USBkey in the method also is applicable to other cryptosecurity chipsets except that USBkey; Other cryptosecurity chipsets also can form corresponding novel cipher safety chip device by increasing right 4 described functions, be not only at USBkey, also comprise the safety chip module of all kinds of IC-cards, mobile phone card, Payment Card etc. or other smart machines; Related digital certificate is meant various PKI digital certificates, no matter by which kind of mechanism is signed and issued.
[beneficial effect]
A kind of real name, safety, economy, reliable dynamic cipher method are provided; A kind of real name network connection method is provided, and the healthy and orderly development in the Internet is significant for keeping.
[description of drawings]
Accompanying drawing 1 is based on the dynamic cipher verification process of digital certificate.
Accompanying drawing 2 is based on the dynamic cipher verification process of digital certificate and USBKey.
Accompanying drawing 3 is based on the real name network access authentication process of digital certificate.
Accompanying drawing 4 is based on the real name network access authentication process of digital certificate and USBKey.
[implementation procedure]
Each process description of this part is not represented unique implementation of the present invention just for principle of the present invention is described, actual implementing procedure needs only spirit according to the invention, all covers within the claim scope of the present invention.
One, based on the process of the dynamic cipher verification of digital certificate:
1. client software is to cryptogram management center request dynamic password; Also can initiate the dynamic password request by the Verification System of correspondence, still be initiated by client by Verification System, can select according to concrete application scenarios, this flow process is initiated as example with client;
2. cryptogram management center produces dynamic password, and returns to client after utilizing customer digital certificate that dynamic password is encrypted; Simultaneously the dynamic password safety of correspondence is pushed to corresponding Verification System, in this process, it is synchronous that cryptogram management center is responsible for the dynamic password controlled between client and the Verification System;
3. client utilizes the customer digital certificate deciphering to obtain dynamic password, and submits corresponding Verification System checking automatically to.
According to concrete service needed, can be chosen in client and Verification System end and keep the dynamic password that last time, authentication success was crossed, in order to avoid this method influence user's use when unusual.
Two, based on the process of the dynamic cipher verification of digital certificate and USBkey:
1. client software is to cryptogram management center request dynamic password; Also can initiate the dynamic password request by the Verification System of correspondence, still be initiated by client by Verification System, can select according to concrete application scenarios, this flow process is initiated as example with client;
2. cryptogram management center produces dynamic password, and returns to client after utilizing customer digital certificate that dynamic password is encrypted; Simultaneously the dynamic password safety of correspondence is pushed to corresponding Verification System, in this process, it is synchronous that cryptogram management center is responsible for the dynamic password controlled between client and the Verification System;
3. client is utilized the customer digital certificate deciphering to obtain dynamic password and is kept at USBkey, and submits corresponding Verification System checking automatically to by the secure access interface that strengthens.
According to concrete service needed, can be chosen in the USBkey of client and Verification System end and keep the dynamic password that last time, authentication success was crossed, in order to avoid this method guarantees that the user normally authenticates when unusual.
Three, based on the process of the real name network access authentication of digital certificate:
1. local account number of preserving of client software utilization and password carry out the dialing authentication request according to the dialing protocol of standard; If dialing first, what then use is dialing account number and the password that distributes when opening an account, otherwise use be after dial-up success last time to the dynamic password of cryptogram management center acquisition request, if the dialing failure, the password attempt dialing that can use the last authentication success to cross;
2. Dui Ying Verification System returns to client with authentication result;
3. after the dial-up success, client software is to cryptogram management center request dynamic password; Also can initiate the dynamic password request, still initiate, can select according to concrete application scenarios, and flow process be initiated as example with client by client by Verification System by the Verification System of correspondence;
4. cryptogram management center produces dynamic password, and returns to dialup client after utilizing customer digital certificate that dynamic password is encrypted; Simultaneously the dynamic password safety of correspondence is pushed to corresponding Verification System, in this process, it is synchronous that cryptogram management center is responsible for the dynamic password controlled between dialup client and the Verification System;
5. dialup client utilizes the customer digital certificate deciphering to obtain dynamic password and safety preservation, and corresponding Verification System is also preserved corresponding dynamic password.Dialing next time uses this dynamic password to authenticate.
According to concrete service needed, can be chosen in client and Verification System end and keep the dynamic password that last time, authentication success was crossed, in order to avoid this method influence user's use when unusual.
Four, based on the process of the dynamic cipher verification of digital certificate:
1. the account number of the local USBkey preservation of client software utilization and password carry out the dialing authentication request according to the dialing protocol of standard; If dialing first, what then use is dialing account number and the password that distributes when opening an account, otherwise use be after dial-up success last time to the dynamic password of cryptogram management center acquisition request, if the dialing failure, the password attempt dialing that can use the last authentication success to cross;
2. Dui Ying Verification System returns to client with authentication result;
3. after the dial-up success, client software is to cryptogram management center request dynamic password; Also can initiate the dynamic password request, still initiate, can select according to concrete application scenarios, and flow process be initiated as example with client by client by Verification System by the Verification System of correspondence;
4. cryptogram management center produces dynamic password, and returns to dialup client after utilizing customer digital certificate that dynamic password is encrypted; Simultaneously the dynamic password safety of correspondence is pushed to corresponding Verification System, in this process, it is synchronous that cryptogram management center is responsible for the dynamic password controlled between dialup client and the Verification System;
5. dialup client utilizes the customer digital certificate deciphering to obtain dynamic password and is kept at USBkey safely, and corresponding Verification System is also preserved corresponding dynamic password.Dialing next time uses this dynamic password to authenticate.
According to concrete service needed, can be chosen in the USBkey of client and Verification System end and keep the dynamic password that last time, authentication success was crossed, in order to avoid this method influence user's use when unusual.
Claims (16)
1. method that realizes dynamic password based on the real name digital certificate, it is characterized in that: based on digital certificate technique, realize safety, economic, reliable novel dynamic passwords authentication method, cryptogram management center is accepted the dynamic password application from user or corresponding Verification System, produce dynamic password, by digital certificate technique with the dynamic password secure distribution to client; Transmission channel by safety sends to corresponding Verification System with identical dynamic password; And guarantee that by affair mechanism the dynamic password of user side and corresponding Verification System end upgrades synchronously, realize the dynamic cipher verification of customer certification system to client, thereby provide dynamic cipher verification, in order to reduce the influence of this method to the conventional authentication pattern, improve the robustness of this method, can replenish abnormality eliminating method.
2. real name dynamic cipher method based on the real name digital certificate.It is characterized in that: in the right 1 described method, when user certificate is the real name certificate, just can realize user's real name dynamic cipher verification.
3. dynamic cipher method based on digital certificate and USBkey.It is characterized in that: on the basis that comprises right 1 described method, increase USBkey safety and preserve digital certificate and private key, and the password crossed of last authentication success, and terminal security interface accessing by strengthening, can further improve the fail safe of right 1 described method, be adapted to the application of higher security needs.
4. real name dynamic cipher method based on real name digital certificate and USBkey.It is characterized in that: in the right 3 described methods, when user certificate is the real name certificate, just can realize real name dynamic cipher authentication method based on digital certificate and USBkey.
5. secure internet connection method based on digital certificate.It is characterized in that: on the basis that comprises right 1 described method, particularity in conjunction with the network connection authentication, real name is provided, safety, economical, reliable internet access method, the particularity of network connection authentication is: before user's network connection authentication is passed through, the user does not also possess the online ability, can't access code administrative center request dynamic password, therefore, this method is carried out following improvement on the basis of right 1 described method: at first, must obtain an account number consistent and password when the user opens an account, dial with account and password when the user dials up on the telephone first with corresponding Verification System; Secondly, the dynamic password that authentication is finished user side and corresponding Verification System end by the back by right 1 described method upgrades synchronously, and safety is saved in assigned address, next time is when dialling, dialup client software obtains account number and password after the renewal automatically by the secure access interface, finishes dialing authentication according to the dialing protocol of standard.
6. real name secure internet connection method based on the real name digital certificate.It is characterized in that: in the right 5 described methods, when user certificate is the real name certificate, just can realize user's real name secure internet connection.
7. secure internet connection method based on digital certificate and USBkey.It is characterized in that: comprise on the basis of right 5 described methods, increase USBkey safety and preserve digital certificate and private key, and dialing account number and password, and the safe interface visit by strengthening, the fail safe that can further improve right 5 described methods.
8. real name secure internet connection method based on real name digital certificate and USBkey.It is characterized in that: it is characterized in that: in the right 7 described methods, when user certificate is the real name certificate, just realized user's real name secure internet connection.
9. as method as described in the claim 1,3,5 and 7, it is characterized in that: digital certificate is meant various PKI digital certificates, no matter by which kind of mechanism is signed and issued.
10. as method as described in the claim 3,4,7 and 8, it is characterized in that: USBkey has been meant safety chip integrated and has supported the computer peripheral equipment of USB interface, various symmetries that safety chip in the terminal is integrated with non-to becoming cryptographic algorithm, can preserve various passwords and data safely, and the secure access interface is provided.
11. as claim 1,2,3,4,5,6,7 and 8 described methods, in order to reduce the influence of this method to the conventional authentication pattern, improve the robustness of this method, can replenish abnormality eliminating method, it is characterized in that: after dynamic password upgrades, continue the password that while safety keeps once authentication success to cross in client and corresponding Verification System end, in case the user fails with the dynamic cipher verification after upgrading, the password that the client and server end can automatic adaptive last success identity be crossed authenticates, can shield like this because of cryptogram management center or other fault effects authentification of users, a key of this abnormality eliminating method is to preserve the password that last authentication success is crossed safely.
12. as method as described in the claim 3,4,7,8, by the terminal security interface accessing that strengthens, it is characterized in that: the terminal access interface possesses checking caller identity and access rights, and the encrypted transmission sensitive data, security mechanism such as prevent sensitive information leakage or distorted.
13. extended method that comprises right 3 described methods, it is characterized in that: right 3 described methods can expand to other cryptosecurity chipsets except that USBKey, just right 3 described methods are not only at USBkey, also comprise the safety chip module of all kinds of IC-cards, mobile phone card, Payment Card etc. or other smart machines.
14. extended method that comprises right 4 described methods, it is characterized in that: right 3 described methods can expand to other cryptosecurity chipsets except that USBKey, just right 3 described methods are not only at USBkey, also comprise the safety chip module of all kinds of IC-cards, mobile phone card, Payment Card etc. or other smart machines.
15. extended method that comprises right 7 described methods, it is characterized in that: right 3 described methods can expand to other cryptosecurity chipsets except that USBKey, just right 3 described methods are not only at USBkey, also comprise the safety chip module of all kinds of IC-cards, mobile phone card, Payment Card etc. or other smart machines.
16. extended method that comprises right 8 described methods, it is characterized in that: right 6 described methods can expand to other cryptosecurity chipsets except that USBKey, just right 6 described methods are not only at USBkey, also comprise the safety chip module of all kinds of IC-cards, mobile phone card, Payment Card etc. or other smart machines.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200810211363A CN101686126A (en) | 2008-09-24 | 2008-09-24 | Method for certification of set of novel dynamic passwords and autonymous network accessing |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200810211363A CN101686126A (en) | 2008-09-24 | 2008-09-24 | Method for certification of set of novel dynamic passwords and autonymous network accessing |
Publications (1)
Publication Number | Publication Date |
---|---|
CN101686126A true CN101686126A (en) | 2010-03-31 |
Family
ID=42049115
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN200810211363A Pending CN101686126A (en) | 2008-09-24 | 2008-09-24 | Method for certification of set of novel dynamic passwords and autonymous network accessing |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN101686126A (en) |
Cited By (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102769629A (en) * | 2012-07-27 | 2012-11-07 | 汉柏科技有限公司 | Client-side password storage method and service system |
CN102866998A (en) * | 2011-07-05 | 2013-01-09 | 中兴通讯股份有限公司 | Centralized password management method and centralized password management system in synchronous system |
CN103684798A (en) * | 2013-12-31 | 2014-03-26 | 南京理工大学连云港研究院 | Authentication system used in distributed user service |
CN106712948A (en) * | 2017-03-09 | 2017-05-24 | 铁道第三勘察设计院集团有限公司 | Software security distributed control framework and control method thereof |
WO2017101704A1 (en) * | 2015-12-16 | 2017-06-22 | 阿里巴巴集团控股有限公司 | Verification method and device |
CN107682153A (en) * | 2017-11-07 | 2018-02-09 | 歌尔股份有限公司 | Method for network access, password method for remote updating, internet of things equipment and system |
CN108429726A (en) * | 2017-07-12 | 2018-08-21 | 深圳市创想网络系统有限公司 | A kind of safe WIFI certificates encrypted authentication cut-in method and its system |
CN109194696A (en) * | 2018-11-01 | 2019-01-11 | 福建工程学院 | A kind of data-interface non-proliferation method |
CN115622687A (en) * | 2022-12-19 | 2023-01-17 | 深圳昂楷科技有限公司 | Dynamic password generation method, device, computer equipment and medium |
-
2008
- 2008-09-24 CN CN200810211363A patent/CN101686126A/en active Pending
Cited By (15)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102866998A (en) * | 2011-07-05 | 2013-01-09 | 中兴通讯股份有限公司 | Centralized password management method and centralized password management system in synchronous system |
CN102769629A (en) * | 2012-07-27 | 2012-11-07 | 汉柏科技有限公司 | Client-side password storage method and service system |
CN102769629B (en) * | 2012-07-27 | 2016-03-02 | 汉柏科技有限公司 | Client-side password storage method and service system |
CN103684798A (en) * | 2013-12-31 | 2014-03-26 | 南京理工大学连云港研究院 | Authentication system used in distributed user service |
CN103684798B (en) * | 2013-12-31 | 2017-03-22 | 南京理工大学连云港研究院 | Authentication method used in distributed user service |
WO2017101704A1 (en) * | 2015-12-16 | 2017-06-22 | 阿里巴巴集团控股有限公司 | Verification method and device |
US10686801B2 (en) | 2015-12-16 | 2020-06-16 | Alibaba Group Holding Limited | Selecting user identity verification methods based on verification results |
US11196753B2 (en) | 2015-12-16 | 2021-12-07 | Advanced New Technologies Co., Ltd. | Selecting user identity verification methods based on verification results |
CN106712948A (en) * | 2017-03-09 | 2017-05-24 | 铁道第三勘察设计院集团有限公司 | Software security distributed control framework and control method thereof |
CN108429726A (en) * | 2017-07-12 | 2018-08-21 | 深圳市创想网络系统有限公司 | A kind of safe WIFI certificates encrypted authentication cut-in method and its system |
CN107682153A (en) * | 2017-11-07 | 2018-02-09 | 歌尔股份有限公司 | Method for network access, password method for remote updating, internet of things equipment and system |
CN109194696A (en) * | 2018-11-01 | 2019-01-11 | 福建工程学院 | A kind of data-interface non-proliferation method |
CN109194696B (en) * | 2018-11-01 | 2021-09-21 | 福建工程学院 | Data interface anti-diffusion method |
CN115622687A (en) * | 2022-12-19 | 2023-01-17 | 深圳昂楷科技有限公司 | Dynamic password generation method, device, computer equipment and medium |
CN115622687B (en) * | 2022-12-19 | 2023-10-20 | 深圳昂楷科技有限公司 | Dynamic password generation method, device, computer equipment and medium |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101686126A (en) | Method for certification of set of novel dynamic passwords and autonymous network accessing | |
JP5595636B2 (en) | Communication between secure information storage device and at least one third party, corresponding entity, information storage device, and method and system for third party | |
CN101222488B (en) | Method and network authentication server for controlling client terminal access to network appliance | |
CN101183932B (en) | Security identification system of wireless application service and login and entry method thereof | |
US6988210B1 (en) | Data processing system for application to access by accreditation | |
CN102202306B (en) | Mobile security authentication terminal and method | |
KR20110126124A (en) | Transforming static password systems to become 2-factor authentication | |
CN103679062A (en) | Intelligent electric meter main control chip and security encryption method | |
CN101841525A (en) | Secure access method, system and client | |
WO2018133674A1 (en) | Method of verifying and feeding back bank payment permission authentication information | |
CN101686127A (en) | Novel USBKey secure calling method and USBKey device | |
CN101686128A (en) | Novel usbkey external authentication method and Usbkey device | |
CN108055129B (en) | A kind of method, equipment and system for realizing the unified management of cellphone shield key | |
CN101986598B (en) | Authentication method, server and system | |
CN101321064A (en) | Information system access control method and apparatus based on digital certificate technique | |
CN102201137A (en) | Network security terminal, and interaction system and method based on terminal | |
CN106936588A (en) | A kind of trustship method, the apparatus and system of hardware controls lock | |
US5481612A (en) | Process for the authentication of a data processing system by another data processing system | |
CN101291221B (en) | Privacy protecting method for identity of customer, and communication system, device | |
KR20090019576A (en) | Certification method and system for a mobile phone | |
CN106357700A (en) | Cipher equipment virtualization method in cloud environment | |
CN101291220B (en) | System, device and method for identity security authentication | |
CN202206419U (en) | Network security terminal and interactive system based on terminal | |
US20070204167A1 (en) | Method for serving a plurality of applications by a security token | |
CN102983969A (en) | Security login system and security login method for operating system |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C57 | Notification of unclear or unknown address | ||
DD01 | Delivery of document by public notice |
Addressee: Li Hua Document name: Notification that Application Deemed to be Withdrawn |
|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C12 | Rejection of a patent application after its publication | ||
RJ01 | Rejection of invention patent application after publication |
Open date: 20100331 |