CN101998387A - Client authentication method, password agent device and system - Google Patents

Client authentication method, password agent device and system Download PDF

Info

Publication number
CN101998387A
CN101998387A CN2009100909032A CN200910090903A CN101998387A CN 101998387 A CN101998387 A CN 101998387A CN 2009100909032 A CN2009100909032 A CN 2009100909032A CN 200910090903 A CN200910090903 A CN 200910090903A CN 101998387 A CN101998387 A CN 101998387A
Authority
CN
China
Prior art keywords
password
user
dynamic
authentication request
dynamic authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2009100909032A
Other languages
Chinese (zh)
Inventor
张乐
高翔
赵刚
张向祺
冯运波
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd filed Critical China Mobile Communications Group Co Ltd
Priority to CN2009100909032A priority Critical patent/CN101998387A/en
Publication of CN101998387A publication Critical patent/CN101998387A/en
Pending legal-status Critical Current

Links

Images

Abstract

The invention discloses a client authentication method, a password agent device and a system. The method comprises the following steps of: receiving a dynamic authentication request containing user identification; generating a dynamic password according to the dynamic authentication request, and sending the dynamic password to the user; receiving the dynamic password of the user, and searching a corresponding static password for the user passing the verification; and performing authentication on a subsequent core network element according to the static password. The method can improve the security of client login, and overcomes the defect of low reliability in the IMS login mode in the prior art.

Description

Client certificate method, password agent apparatus and system
Technical field
The present invention relates to IP Multimedia System in the communications field (IP MultimediaSubsystem is called for short IMS) technology, particularly, relate to a kind of client certificate method, password agent apparatus and system.
Background technology
IMS is as 3GPP next generation communication technical standard and evolution direction, for the fusion of IT technology and CT technology provides strong support and solution.The multiple different physics access communications mode of IMS technical support in the communication mode of numerous supports, is utilized computer to connect Internet and is realized that IMS communication has become main flow.
The active user is when using client login IMS network, mainly finish user's authentication and authentication by username and password, be IMS client user, can login the IMS network by the input username and password, and then finish charging projects such as voice call, visual telephone and note.With in the means of communication in the past, be denoted as the strong authentication pattern difference of authentication mode with the SIM cards of mobile phones sign or with telephone number, the IMS client of computer log mode is user bound or equipment not, but mainly login with username and password.
In realizing process of the present invention, the inventor finds that there are the following problems at least in the IMS communication of active computer login mode:
1. existing static login authentication mode is unreliable, can not ensure information security.
2. existing static login mode needs the user to remember password and user name, and convenience is poor, may cause and can't normally login if misremember.
3. the fail safe of existing login mode is subject to the complexity of password itself and user's computer level usually, and safe class is relatively poor, often easily by assault.
Summary of the invention
First purpose of the present invention is to propose a kind of client certificate method, to improve the fail safe of IMS client login.
Second purpose of the present invention is to propose a kind of password agent apparatus, to realize improving the fail safe reliability of client certificate.
The 3rd purpose of the present invention is a kind of client certificate of proposition system, to realize improving the fail safe of client certificate.
For realizing above-mentioned first purpose, according to an aspect of the present invention, provide a kind of client certificate method.
Client certificate method according to the embodiment of the invention comprises: receive the dynamic authentication request that comprises user ID; Generate dynamic password according to described dynamic authentication request, and be sent to described user; Receive described user's described dynamic password, the user who is proved to be successful is searched corresponding static password; Carry out the authentication of follow-up core network element according to described static password.
For realizing above-mentioned second purpose, according to another aspect of the present invention, provide a kind of password agent apparatus.
Password agent apparatus according to the embodiment of the invention, comprise: interface unit, be used to receive the dynamic authentication request that comprises user ID, and will verify that legal dynamic authentication request is sent to one and is used to generate the dynamic authentication module of dynamic password, and receive the dynamic password of described user's input; Processing unit is used for legal checking is carried out in described dynamic authentication request, and to the described user of dynamic password verification success, searches corresponding static password, and the static password of described user's correspondence is sent to the IMS core net; Memory cell is used to store each user and corresponding user ID, static password thereof
For realizing above-mentioned the 3rd purpose, according to another aspect of the present invention, provide a kind of client certificate system.
Client certificate system according to the embodiment of the invention, comprise: password agent apparatus and dynamic authentication module, wherein said password agent apparatus is used to receive and verify user's dynamic authentication request, and will verify that legal dynamic authentication request is sent to described dynamic authentication module; Receive described user's dynamic password, and search the static password of the user's correspondence that is proved to be successful, carry out the authentication of follow-up core network element according to described static password; The dynamic authentication module is used for generating dynamic password according to described dynamic authentication request, and is sent to described user.
The client certificate method of various embodiments of the present invention, password agent apparatus and system, because the mode that adopts dynamic authentication and static authentication to combine is carried out login authentication to client, adopt dynamic password to carry out access authentication, the user can only send the dynamic authentication request when login, and the dynamic password that the reception network side generates at random authenticates, therefore, login security height.Simultaneously, the user need not to remember static password, only needs to receive random dynamic puzzle, can finish login, when improving fail safe, has also improved user's experience.
Below by drawings and Examples, technical scheme of the present invention is described in further detail.
Description of drawings
Accompanying drawing is used to provide further understanding of the present invention, and constitutes the part of specification, is used from explanation the present invention with embodiments of the invention one, is not construed as limiting the invention.In the accompanying drawings:
Fig. 1 is client certificate method embodiment one flow chart according to the present invention;
Fig. 2 is client certificate method embodiment two flow charts according to the present invention;
Fig. 3 is client certificate system embodiment one structural representation according to the present invention;
Fig. 4 is client certificate method embodiment three and system embodiment two schematic diagrames according to the present invention;
Fig. 5 is client certificate method embodiment four and system embodiment three schematic diagrames according to the present invention;
Fig. 6 is password agent apparatus embodiment one structural representation according to the present invention;
Fig. 7 is password agent apparatus embodiment two structural representations according to the present invention.
Embodiment
Below in conjunction with accompanying drawing the preferred embodiments of the present invention are described, should be appreciated that preferred embodiment described herein only is used for description and interpretation the present invention, and be not used in qualification the present invention.
The present invention adopts dynamic authentication and static authentication to carry out client certificate in the IMS network, and a kind of password agent apparatus and Verification System are provided accordingly, can improve fail safe, the reliability of client certificate and the convenience that improves the user, the present invention is illustrated below by Fig. 1-Fig. 7.
Embodiment one
Fig. 1 is client certificate method embodiment one flow chart according to the present invention.As shown in Figure 1, present embodiment comprises:
Step S102: receive the dynamic authentication request that comprises the IMS user ID;
Step S104: generate random dynamic puzzle to verifying legal dynamic authentication request, and be sent to IMS user; As whether legal to the IMS user ID checking that comprises in the dynamic authentication request;
Step S106: receive the dynamic password of IMS user's input, the user who is proved to be successful is searched corresponding static password;
Step S108: utilize this static password to carry out the authentication of follow-up each network element of IMS core net.
Present embodiment combines at this strong authentication mode of dynamic cipher verification and IMS user's, for user side provides reliable authentication mode to ensure information security, because adopt dynamic password to carry out the IMS access authentication, the login mode at the traditional static password is significantly improved in the fail safe.Simultaneously, the user need not to remember password, only needs to receive random cipher by client (as mobile phone terminal), can finish login, when improving fail safe, has also improved user's experience.
Embodiment two
Fig. 2 is client certificate method embodiment two flow charts according to the present invention.As shown in Figure 2, present embodiment comprises:
Step S201: receive the dynamic authentication request that comprises user ID, carry out the following step to verifying legal authentication request, otherwise can directly return the requesting party " disabled user " of dynamic authentication;
Step S202: judge the type of this user ID, as user's identify label (user ID), perhaps user's mobile number is as cell-phone number etc.If mobile number, execution in step S204 then is if ID users, then step S203;
Step S203: search this user ID corresponding mobile terminal sign (as: phone number), generally all can store the corresponding relation of user and sign thereof, as following table one
Table one user and sign mapping table thereof
The user User ID Mobile terminal identification Static password
Zhang San zhangsan 138...10 ***
Li Si Li Si 08 139...15 ...
... ... ... ...
Step S204: generate random dynamic puzzle to verifying legal dynamic authentication request, and be sent to corresponding mobile terminal (as mobile phone) by modes such as note/multimedia messages;
Step S206: receive the dynamic password of user by the client input;
During practical application, because the user has had user ID by client when applying for dynamic password (dynamic authentication request), dynamic password just can be dealt into specific user's corresponding mobile terminal like this, on mobile phone, therefore client also can be remembered this user's user ID (as user ID), and the user only needs this password of input to get final product after receiving dynamic password;
Step S207: judge whether this dynamic password is correct, judge promptly whether checking is successful, is the static password of then searching this user's correspondence, execution in step S208; Otherwise finish;
Step S208: utilize this static password to carry out the authentication of follow-up each network element of core net.
Present embodiment has carried out refinement to Fig. 1 embodiment, has carried out the different disposal of step S202 for two kinds of situations of user ID, and its beneficial effect and embodiment one are similar, no longer repeat.
Embodiment three
According to top description to method embodiment among Fig. 1 and Fig. 2, those skilled in the art as can be known, utilize the auxiliary IMS client certificate of finishing of strong authentication mode of dynamic cipher verification to login, the user need not to remember static password, and the dynamic password that input receives when only needing login gets final product.But during practical application, when adopting dynamic confirming method, following problems may be encountered:
When IMS user logins at present, though the user only need input password one time, but IMS nucleus equipment side need be finished as home subscriber server (Home Subscriber Server, abbreviation HSS), service application service device (Application Server, abbreviation AS), fixed network analog service (PSTN/ISDN Simulation Services, be called for short PSS) etc. the authentication and the authentication of a plurality of network elements because these network elements are all preserved user's static password information, are all needed independently finish separately authentification of user and login.When adopting dynamic cipher verification, because password is the sequence that generates at random, each network element of existing core net can't be discerned this random cipher, therefore is difficult to finish authentication.In order to solve the problem that runs in this practical operation, the present invention has also increased a password agent apparatus newly, finishes the password conversion work.
Fig. 3 is client certificate system embodiment one structural representation according to the present invention.Fig. 3 shows the IMS system architecture that adds behind the dynamic cipher authentication system, and this system architecture is compared with existing IMS system, also comprises dynamic cipher verification server and password agent apparatus.It will be understood by a person skilled in the art that when specific implementation, two equipment of Fig. 3 to be closed and establish, as with the dynamic cipher verification server as a dynamic authentication module and be arranged in the password agent apparatus.Owing to introduced dynamic cipher verification, pc client no longer directly sends to the CSCF network element to log-on message, but by the password agent apparatus, and then finish authentication again after finishing dynamic password comparison and conversion.Therefore, user's static password of need not to import in the past can be finished login.
Client certificate system to present embodiment is specifically described below:
The dynamic cipher verification server: this server receives calling of password agent apparatus, this parameter of calling is generally a user ID or phone number, when sending to phone number, server can directly send the note random cipher to this phone number, when sending to user ID, server retrieves its data storehouse, the phone number that finds user ID to mate, and to this phone number transmission note random cipher.After user mobile phone is received and is changed password, by client password is sent it back the password agent apparatus, the password agent apparatus can change password correctness (need dynamic cipher verification server cryptosync to the password agent apparatus) or password is returned to the dynamic cipher verification server again at internal verification, server is judged this password true and false, and the result is returned to the password agent apparatus.
Password agent apparatus: can exist with form server, can finish the legal dynamic requests of checking sent the dynamic cipher verification server and the user verified by the dynamic password of client input outside, can also carry out subsequent treatment at the dynamic password verification result.When the dynamic password verification result is a fictitious time,, end subsequent authentication to the failure of client return authentication; The result is a true time when checking, and the password agent apparatus can help the user to finish the authentication of follow-up a plurality of IMS network elements.
Follow-up IMS core network element authentication can be passed through two kinds of methods:
Method 1 directly at the inboard stored user static password of password agent apparatus, after the user is by the dynamic password verification success, directly uses user's static password to finish subsequent authentication.
Method 2, revise follow-up all need the IMS network element of authentication, increase trust to the password agent apparatus, think that the user who examines through the password agency is validated user and grants login.
For do not increase as far as possible follow-up all need the IMS network element of authentication, the compatible existing equipment of the core network of energy, present embodiment adopts first method, i.e. its static password of user's active inquiry to being proved to be successful, assist to finish subsequent authentication by network side password agent apparatus, improve the convenience and the user experience of user's login.
In the such scheme, the actual authentication that comprises twice at first is the authentication of dynamic password, secondly is the authentication in a plurality of network elements of IMS core net.The authentication of dynamic password both can be finished in the dynamic cipher verification server, also can finish in the password agent apparatus; Wherein, when in the password agent apparatus, finishing, require the dynamic cipher verification server when the transmission dynamic password is to user mobile phone number, dynamic password is returned to the password agent apparatus finish the access checking relatively for the password agent apparatus.Following Fig. 4-Fig. 5 illustrates these two kinds of implementations.
Embodiment four
Fig. 4 is client certificate method embodiment three and system embodiment two schematic diagrames according to the present invention.At first use the IMS client to be example with the user below, specify the method for client certificate, present embodiment mainly is the checking of finishing dynamic password in the dynamic cipher verification server, flow process as shown in Figure 4:
Steps A 1, the user logins the IMS client, selects the login of note dynamic password, initiates the authentication request of visit IMS network;
Steps A 2, when the user selected the login of note dynamic password, client sent to password agent apparatus (being called for short the password agency) to this request;
Steps A 3, the password agency judges whether user ID is legal, as legal, the request of note dynamic password is sent to the dynamic cipher verification server;
Steps A 4, after the dynamic cipher verification server is received ID, retrieve the phone number (this operation also can be finished, and the password agency directly sends to note dynamic cipher verification server to phone number and gets final product) of user ID correspondence in the password agency, and send the random cipher note to this phone number;
Steps A 5, the user receives note;
Steps A 6 sends to the password agency after the user fills in the dynamic password in the note;
Steps A 7, the password agency returns to the dynamic cipher verification server to dynamic password and compares;
Steps A 8, the dynamic cipher verification server is compared password agency password that returns and the password that self sends, and finds not simultaneously, returns error message and acts on behalf of to password;
Steps A 9, the password agency returns login failure information and gives IMS client and user.
So far, finished a cover user dynamic cipher verification flow process, because the note password mistake of user's input, so login failed for user.
When the note password of user's input is correct, then will continue to finish following steps:
Step C1, the dynamic cipher verification server returns the password authentification successful information and acts on behalf of to password;
Step C2, the user's static password that stores in the password agents query its data storehouse, and finish the registration of user at follow-up IMS network element with this static password.
Present embodiment provides reliable authentication mode to ensure information security for user side, the user need not to remember that password can finish login, when improving fail safe, also improved user's experience, and can adopt static password to carry out subsequent authentication, do not increase the cost of authentication, compatible existing equipment of the core network.
Embodiment five
Fig. 4 also is client certificate system embodiment two schematic diagrames of the present invention simultaneously.As shown in Figure 4, comprising:
Pc client is used for when the user selects dynamic authentication, and the agency sends the dynamic authentication request that comprises this user ID to password, and after receiving the dynamic password of network side, the input dynamic password is verified.
Password agent apparatus: legal checking is carried out in the dynamic authentication request, and legal dynamic requests sent the dynamic cipher verification server and the dynamic password of user's input is sent the dynamic cipher verification server verify, the dynamic password verification result is carried out subsequent treatment.When the dynamic password verification result is a fictitious time,, end subsequent authentication to the failure of user's return authentication; The result is a true time when checking, and the password agent apparatus can help the user to finish the authentication of follow-up a plurality of IMS network elements.
The dynamic cipher verification server: receive calling of password agent apparatus, receive the dynamic authentication request, invoke user ID or phone number when comprising phone number in the request, directly send the dynamic password that generates at random to this phone number; When comprising user ID in the request, retrieve its data storehouse, find the phone number of user ID coupling, and send the dynamic password that generates at random to this phone number.Receive the password authentification that the password agency transmits, server is judged this password true and false, and the result is returned to the password agent apparatus.
The IMS core network element receives the static password that the password agent apparatus sends, and finishes this user's subsequent authentication registration.
Embodiment six
Fig. 5 is client certificate method embodiment four and system embodiment three schematic diagrames according to the present invention.Present embodiment mainly is the checking of finishing dynamic password password agency, flow process as shown in Figure 5:
Step B1 is with step A1
Step B2 is with step A2;
Step B3 is with step A3;
Step B4 is with step A4;
Step B5 is with step A5;
Step B6, the dynamic cipher verification server sends to the password agency to the dynamic password of issuing the user;
Step B7 is with step A6;
The password that password that step B8, password agency return the dynamic cipher verification server and user import is compared;
When step B9, password proxy authentication result are wrong, return error message and give client and user.
So far, finished a cover user dynamic cipher verification flow process, because the note password mistake of user's input, so login failed for user.
When the note password of user's input is correct, then will continue to finish following steps:
Step B10, the user's static password that stores in the password agents query its data storehouse, and finish the registration of user at follow-up IMS network element with this static password.
Present embodiment mainly is the checking of finishing dynamic password password agency, states the quantity and the Signalling exchange flow process that can also further reduce Signalling exchange on the effect basis of each embodiment in realization.
Embodiment seven
Fig. 5 also is client certificate system embodiment three schematic diagrames of the present invention simultaneously.The similar of Fig. 5 and Fig. 4, just the dynamic password of user's input is finished by the password agent apparatus, does not need to re-send to the dynamic cipher verification server and finishes password authentification, other identical contents is not carried out repeat specification at this.
It will be understood by those skilled in the art that password agency among Fig. 4 and Fig. 5 and dynamic cipher verification server can close establishes, and at this moment, the dynamic cipher verification server can be used as the dynamic authentication module in the password agency, and only a generation dynamic password at random gets final product.Password agency and dynamic cipher verification server among Fig. 4 and Fig. 5 can also be provided with respectively, exist with the two-server form.
Embodiment eight
Fig. 6 is password agent apparatus embodiment one structural representation according to the present invention.As shown in Figure 6, present embodiment comprises:
Interface unit 2 is used to receive the dynamic authentication request that comprises user ID, and to verifying that legal dynamic authentication request is sent to one and is used to generate the dynamic authentication module of dynamic password, and receive described user's dynamic password;
Processing unit 4 is used for legal checking is carried out in the dynamic authentication request, and to the described user of dynamic password verification success, searches corresponding static password, and the static password of user's correspondence is sent to the IMS core net;
Memory cell 6 is used to store each user and corresponding user ID (user ID, mobile terminal identification etc.) thereof, static password etc., can be as showing first-class form storage.
The dynamic authentication module can be arranged in this device, or is provided with this device is independent.
Concrete verification process and beneficial effect can be referring to the related description of method embodiment.
Embodiment nine
Fig. 7 is password agent apparatus embodiment two structural representations according to the present invention.As shown in Figure 7, other unit and Fig. 6 are similar, and difference is present embodiment to processing unit 4 inner further refinements, though syndeton is constant, built-in function has dual mode.
First kind of mode, processing unit 4 comprises: the first checking subelement 42 is used for legal checking is carried out in the dynamic authentication request; The second checking subelement 44 is used for receiving the dynamic password that dynamic authentication modules 8 generate by interface unit 2, and the user's that receives of docking port unit 2 dynamic password verifies, and the user who is proved to be successful is sent to inquiry subelement 46; Inquire about subelement 46, be used for searching the static password of user's correspondence from memory cell 6.
The second way, processing unit 4 comprises: the first checking subelement 42 is used for legal checking is carried out in the dynamic authentication request; The second checking subelement 44, the dynamic password that is used for user that interface unit 2 is received is sent to dynamic authentication module 8 and verifies, and by interface unit 2 Receipt Validation results, the user who is proved to be successful is sent to inquiry subelement 6; Inquire about subelement 6, be used for searching the static password of described user's correspondence from described memory cell.
Present embodiment is provided with a password agent apparatus in the existing IMS network, corresponding realization dynamic password verification, and the authentication mode that adopts dynamic password and static password to combine, can solve the problem that existing static login authentication mode is unreliable, can not ensure information security, and the user does not need to remember static password, improve authentication convenience and fail safe, be difficult for by assault.
The present invention can have multiple multi-form embodiment; be that example illustrates technical scheme of the present invention in conjunction with the accompanying drawings with Fig. 1-Fig. 7 above; this does not also mean that the applied instantiation of the present invention can only be confined in the specific flow process or example structure; those of ordinary skill in the art should understand; above the specific embodiments that is provided is some examples in the multiple its preferred usage, and any execution mode that adopts dynamic cipher verification and corresponding static password to carry out subsequent authentication in core net such as IMS all should be within technical solution of the present invention scope required for protection.
One of ordinary skill in the art will appreciate that: all or part of step that realizes said method embodiment can be finished by the relevant hardware of program command, aforesaid program can be stored in the computer read/write memory medium, this program is carried out the step that comprises said method embodiment when carrying out; And aforesaid storage medium comprises: various media that can be program code stored such as ROM, RAM, server, agent apparatus, certificate server, magnetic disc or CD.
It should be noted that at last: the above only is the preferred embodiments of the present invention, be not limited to the present invention, although the present invention is had been described in detail with reference to previous embodiment, for a person skilled in the art, it still can be made amendment to the technical scheme that aforementioned each embodiment put down in writing, and perhaps part technical characterictic wherein is equal to replacement.Within the spirit and principles in the present invention all, any modification of being done, be equal to replacement, improvement etc., all should be included within protection scope of the present invention.

Claims (11)

1. a client certificate method is characterized in that, comprising:
Reception comprises the dynamic authentication request of user ID;
Generate dynamic password according to described dynamic authentication request, and be sent to described user;
Receive described user's described dynamic password, the user who is proved to be successful is searched corresponding static password;
Carry out the authentication of follow-up core network element according to described static password.
2. method according to claim 1 is characterized in that, generates dynamic password according to described dynamic authentication request, and the operation that is sent to described user comprises:
When described dynamic authentication request comprises described user's user ID, search the mobile terminal identification of mating, and the described dynamic password that will generate is sent to described user's portable terminal with described user ID;
When described dynamic authentication request comprises described user's mobile terminal identification, directly described dynamic password is sent to described user's portable terminal.
3. method according to claim 1 is characterized in that, also comprises before the described operation according to described dynamic authentication request generation dynamic password:
Judge whether described user ID is legal, and carry out the operation of follow-up generation dynamic password when legal, described user ID comprises user ID or mobile terminal identification.
4. according to each described method among the claim 1-3, it is characterized in that, adopt note or multimedia message mode to send and receive aforesaid operations.
5. according to each described method among the claim 1-3, it is characterized in that be applied to IP Multimedia System, described user is IMS user.
6. a password agent apparatus is characterized in that, comprising:
Interface unit is used to receive the dynamic authentication request that comprises user ID, and will verify that legal dynamic authentication request is sent to one and is used to generate the dynamic authentication module of dynamic password, and receives the dynamic password of described user's input;
Processing unit is used for legal checking is carried out in described dynamic authentication request, and to the described user of dynamic password verification success, searches corresponding static password, and the static password of described user's correspondence is sent to the IMS core net;
Memory cell is used to store each user and corresponding user ID and static password thereof.
7. device according to claim 6 is characterized in that, described dynamic authentication module be provided with described password agent apparatus in, or independently be provided with described password agent apparatus.
8. according to claim 6 or 7 described devices, it is characterized in that described processing unit comprises:
The first checking subelement is used for legal checking is carried out in described dynamic authentication request;
The second checking subelement is used for receiving the dynamic password that described dynamic authentication module generates by described interface unit, and the described user's that described interface unit is received dynamic password verifies, and the described user that will be proved to be successful is sent to the inquiry subelement;
Inquire about subelement, be used for searching the static password of described user's correspondence from described memory cell.
9. according to claim 6 or 7 described devices, it is characterized in that described processing unit comprises:
The first checking subelement is used for legal checking is carried out in described dynamic authentication request;
The second checking subelement, the dynamic password that is used for described user that described interface unit is received is sent to described dynamic authentication module and verifies, and by described interface unit Receipt Validation result, the described user who is proved to be successful is sent to the inquiry subelement;
Inquire about subelement, be used for searching the static password of described user's correspondence from described memory cell.
10. a client certificate system is characterized in that, comprises password agent apparatus and dynamic authentication module:
Described password agent apparatus is used to receive and verify user's dynamic authentication request, and will verify that legal dynamic authentication request is sent to described dynamic authentication module; Receive described user's dynamic password, and search the static password of the user's correspondence that is proved to be successful, carry out the authentication of follow-up core network element according to described static password;
The dynamic authentication module is used for generating dynamic password according to described dynamic authentication request, and is sent to described user.
11. system according to claim 10 is characterized in that, described password agent apparatus or described dynamic authentication module are verified described user's dynamic password.
CN2009100909032A 2009-08-14 2009-08-14 Client authentication method, password agent device and system Pending CN101998387A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2009100909032A CN101998387A (en) 2009-08-14 2009-08-14 Client authentication method, password agent device and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2009100909032A CN101998387A (en) 2009-08-14 2009-08-14 Client authentication method, password agent device and system

Publications (1)

Publication Number Publication Date
CN101998387A true CN101998387A (en) 2011-03-30

Family

ID=43787770

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2009100909032A Pending CN101998387A (en) 2009-08-14 2009-08-14 Client authentication method, password agent device and system

Country Status (1)

Country Link
CN (1) CN101998387A (en)

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102510378A (en) * 2011-10-31 2012-06-20 福建天晴数码有限公司 Method for logging in online game through mobile equipment
CN102521540A (en) * 2011-12-09 2012-06-27 上海华勤通讯技术有限公司 Authentication system of electronic device and authentication method thereof
CN102740141A (en) * 2012-05-31 2012-10-17 董爱平 Mobile Internet instant video privacy protecting method and system
CN103106362A (en) * 2013-02-05 2013-05-15 广东全通教育股份有限公司 Method and system based on usage limit of established website platform for user
CN103856638A (en) * 2012-11-29 2014-06-11 中国移动通信集团公司 Method for avoiding multiple times of ringing of one-number main number mobile phone, client and server
CN104660404A (en) * 2013-11-21 2015-05-27 中国移动通信集团重庆有限公司 Authentication device and authentication method
CN105610767A (en) * 2014-11-24 2016-05-25 中国移动通信集团公司 Method, device and platform for safely issuing password
CN106919827A (en) * 2015-12-24 2017-07-04 北京奇虎科技有限公司 The wireless method for unlocking, computer equipment and the webserver
CN113268780A (en) * 2021-06-08 2021-08-17 天津赢达信科技有限公司 Identity authentication method and device, computer equipment and storage medium

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102510378A (en) * 2011-10-31 2012-06-20 福建天晴数码有限公司 Method for logging in online game through mobile equipment
CN102521540A (en) * 2011-12-09 2012-06-27 上海华勤通讯技术有限公司 Authentication system of electronic device and authentication method thereof
CN102740141A (en) * 2012-05-31 2012-10-17 董爱平 Mobile Internet instant video privacy protecting method and system
CN103856638A (en) * 2012-11-29 2014-06-11 中国移动通信集团公司 Method for avoiding multiple times of ringing of one-number main number mobile phone, client and server
CN103106362A (en) * 2013-02-05 2013-05-15 广东全通教育股份有限公司 Method and system based on usage limit of established website platform for user
CN104660404A (en) * 2013-11-21 2015-05-27 中国移动通信集团重庆有限公司 Authentication device and authentication method
CN105610767A (en) * 2014-11-24 2016-05-25 中国移动通信集团公司 Method, device and platform for safely issuing password
CN105610767B (en) * 2014-11-24 2019-04-23 中国移动通信集团公司 A kind of method, apparatus that cryptosecurity issues and platform
CN106919827A (en) * 2015-12-24 2017-07-04 北京奇虎科技有限公司 The wireless method for unlocking, computer equipment and the webserver
CN106919827B (en) * 2015-12-24 2020-04-17 北京奇虎科技有限公司 Wireless unlocking method, computer equipment and network server
CN113268780A (en) * 2021-06-08 2021-08-17 天津赢达信科技有限公司 Identity authentication method and device, computer equipment and storage medium
CN113268780B (en) * 2021-06-08 2022-02-11 天津赢达信科技有限公司 Identity authentication method and device, computer equipment and storage medium

Similar Documents

Publication Publication Date Title
CN101998387A (en) Client authentication method, password agent device and system
CN109600306B (en) Method, device and storage medium for creating session
EP1741268B1 (en) A method for verifying a first identity and a second identity of an entity
CN101183932B (en) Security identification system of wireless application service and login and entry method thereof
CN103249045B (en) A kind of methods, devices and systems of identification
CN101163010B (en) Method of authenticating request message and related equipment
CN102201915B (en) Terminal authentication method and device based on single sign-on
CN101582762B (en) Method and system for identity authentication based on dynamic password
CN101729514B (en) Method, device and system for implementing service call
CN102217280B (en) Method, system, and server for user service authentication
CN102469091B (en) Method for processing verification codes of pages, device and terminal
EP3700164A1 (en) Method and apparatus for facilitating the login of an account
CN107113613B (en) Server, mobile terminal, network real-name authentication system and method
EP1861983A1 (en) Method and apparatuses for authenticating a user by comparing a non-network originated identities
TW201014315A (en) User identity authentication method, system thereof and identifying code generating maintenance subsystem
CN101582763B (en) Method and system for identity authentication based on dynamic password
CN102811228A (en) Network business login method, equipment and system
CN104468487A (en) Communication authentication method and device and terminal device
CN101582886A (en) Method and system for identity authentication based on dynamic password
CN103607416A (en) Method and application system for authenticating identity of network terminal machine
CN105262588A (en) Log-in method based on dynamic password, account number management server and mobile terminal
CN102882835A (en) Method and system for implementing single sign on
CN101656609A (en) Single sign-on method, system and device thereof
CN102984261A (en) Network service login method, equipment and system based on mobile telephone terminal
CN102420808A (en) Method for realizing single signon on telecom on-line business hall

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C12 Rejection of a patent application after its publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20110330