CN106230594A - Method for user authentication based on dynamic password - Google Patents

Method for user authentication based on dynamic password Download PDF

Info

Publication number
CN106230594A
CN106230594A CN201610579570.XA CN201610579570A CN106230594A CN 106230594 A CN106230594 A CN 106230594A CN 201610579570 A CN201610579570 A CN 201610579570A CN 106230594 A CN106230594 A CN 106230594A
Authority
CN
China
Prior art keywords
user
password
dynamic password
seconds
certification
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201610579570.XA
Other languages
Chinese (zh)
Other versions
CN106230594B (en
Inventor
曾超
姜艳
沈学师
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inspur General Software Co Ltd
Original Assignee
Inspur General Software Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inspur General Software Co Ltd filed Critical Inspur General Software Co Ltd
Priority to CN201610579570.XA priority Critical patent/CN106230594B/en
Publication of CN106230594A publication Critical patent/CN106230594A/en
Application granted granted Critical
Publication of CN106230594B publication Critical patent/CN106230594B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3228One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • H04L63/0838Network architectures or network communication protocols for network security for authentication of entities using passwords using one-time-passwords

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Storage Device Security (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The invention discloses a method for user authentication based on a dynamic password, which comprises the following steps: time configuration is completed between a server and a client, wherein the server is used for realizing authentication service, and the client is used for providing the authentication service, so that the time is kept synchronous, and the time error is within ten seconds; carrying out server user key configuration: initializing all the accounts of the service management system, randomly generating a unique key of each account, and recording unique identification and key information of each account by prefabricating fields in a database table; and setting a user dynamic password at the client, namely inputting a secret key into the client by scanning a two-dimensional code generated by the authentication end or adopting a manual input mode, and judging the user login information authentication by the server according to the dynamic password. Compared with the prior art, the method for user authentication based on the dynamic password has the advantages that the dynamic password set is larger in capacity, authentication can be performed only through the password, the practicability is high, the application range is wide, and the popularization is easy.

Description

A kind of method carrying out user authentication based on dynamic password
Technical field
The present invention relates to field of computer technology, a kind of side carrying out user authentication based on dynamic password Method.
Background technology
In traditional business management system, common user authentication mode is to need user to input username and password to submit service to The password set before end, with this user of service end preservation is compared, if consistent, certification is passed through.Along with e-government Progressively development, government affairs operation system quantity get more and more, numerous operation systems relate to different network environments, custom composition Operation system is positioned at government affairs outer net, and part system is positioned at government intranet, and two sets improve the network environment of isolation, for government affairs system Uniting, operation system is integrated exists many technical difficulties, is especially running on the integrated side of operation system single-sign-on of heterogeneous networks Face, authentication center is the most infeasible with each operation system immediate data communication modes.
In the prior art, dynamic password is to use certain special algorithm to generate uncertain random spelling words intellectual, In current time period once effectively, after i.e. fixed cycle, dynamically update stochastic generation password again, be now widely used for leading to The fields such as letter operator, bank, network game, E-Government, enterprise, simultaneously because the random unpredictability of dynamic password, it is also It is the account anti-theft technology of a kind of safe and convenient, can effectively protect system authentication safety, whole after using dynamic password mode User is without configuration and remembers numerous numerous and diverse password, and based on this, the present invention provides a kind of and carries out user based on dynamic password and recognize The method of card, uses this dynamic-password technique, thus avoids the compromised risk of password caused due to user's miscarriage, User authentication link ensure that the safety of operation system system.
Summary of the invention
The technical assignment of the present invention is for above weak point, it is provided that a kind of carry out user authentication based on dynamic password Method.
A kind of method carrying out user authentication based on dynamic password, it realizes process and is:
Configuring with the client deadline in service end, wherein service end is used for realizing authentication service, and client is then used for Authentication service is proposed so that the time keeps synchronizing, and time error is within ten seconds;
Carry out service end user key configuration: to whole business management system account initialization, each account of stochastic generation Unique key, by field prefabricated in database table, records each account and uniquely identifies and key information;
In client, user's dynamic password, the Quick Response Code i.e. generated by scanning certification end or the employing side of manually entering are set Key is input to client by formula, and service end then differentiates user login information certification according to dynamic password.
Service end and client carry out time configuration and refer to by Network Time Protocol, make each computer, terminal unit in network Retention time synchronizes, and physical isolation between the arbitrary equipment of retention time synchronization, and mutual without immediate data each other, it is joined Process of putting is by having been manually done, it is achieved error time consistency in 10 seconds between equipment.
Described dynamic password refers to that user binds after initialized terminal unit in client, by TOTP dynamic password Algorithm obtains.
By dynamic password, service end differentiates that user login information certification refers to, user is asking certification or user in business When system submits to dynamic password to call service end interface, service end is audited by dynamic password, when dynamic password is that certain is used During the password in family current time period or front and back cycle, then certification is passed through, and the jump request that creation state is 302 exists simultaneously Http header adds and uniquely identifies based on user and the authentication state information of operation system mark reversible encryption.
When the password that dynamic password is certain user's current time period or front and back cycle then certification by referring to each use Family certification password within service end keeps current time 30 seconds or in 30 seconds front 30 second, after 30 seconds 30 seconds, i.e. except 30 In second, user correctly configures outside certification with password in 30 seconds, in 30 seconds user with password before 30 seconds or after 30 seconds password carry out Certification is passed through, to solve 30 seconds context errors of password of the error generation that the time exists between each equipment, this certification base Whole account password Hash table is kept in real time in server end.
Compared to the prior art a kind of of the present invention carry out the method for user authentication based on dynamic password, has following useful Effect:
The present invention a kind of carries out the method for user authentication based on dynamic password and remembers in each operation system without user The fixed password arranged, by 6 word incoming traffic management systems that the terminal unit initialized shows Realize user authentication, be particularly suitable for that operation system is numerous is not easy to remember all kinds of password and operation system safe class is high Sight, so that software product more conforms to the requirement of user, accomplishes on-demand to a certain extent;By operation system list Point login is integrated to combine with dynamic password, it is achieved the unifying user authentication under government affairs internal, external network many nets physical isolation sight; Password set can support Chinese character password set by user, dynamically configure by operation system, it is achieved magnanimity password set is random, in limit Violence in fixed cycle guesses that solution mode is hardly possible;Support Android, IOS, WindowsMobile and RestApi, WebServices much information interface, practical, applied widely, it is easy to promote.
Accompanying drawing explanation
Accompanying drawing 1 is that user's dynamic password login authentication of the present invention realizes procedure chart.
Detailed description of the invention
The invention will be further described with specific embodiment below in conjunction with the accompanying drawings.
As shown in Figure 1, a kind of method carrying out user authentication based on dynamic password of the present invention, it realizes process and is:
Configuring with the client deadline in service end, wherein service end is used for realizing authentication service, and client is then used for Authentication service is proposed so that the time keeps synchronizing, and time error is within ten seconds;
Carry out service end user key configuration: to whole business management system account initialization, each account of stochastic generation Unique key, by field prefabricated in database table, records each account and uniquely identifies and key information;
User's dynamic password is set in client, is i.e. generated based on ISO international standard ISO/ by scanning certification end The Quick Response Code of IEC18004 or employing manually enter mode and under security context ensures, key are input to client, and service end is then User login information certification is differentiated according to dynamic password.
Service end and client carry out time configuration and refer to by Network Time Protocol, make each computer, terminal unit in network Retention time synchronizes, and physical isolation between the arbitrary equipment of retention time synchronization, and mutual without immediate data each other, it is joined Process of putting is by having been manually done, it is achieved error time consistency in 10 seconds between equipment, possesses little scope time error and holds Wrong feature.
Described dynamic password refers to that user binds after initialized terminal unit in client, by TOTP dynamic password Algorithm obtains.
By dynamic password, service end differentiates that user login information certification refers to, user is asking certification or user in business When system submits to dynamic password to call service end interface, service end is audited by dynamic password, when dynamic password is that certain is used During the password in family current time period or front and back cycle, then certification is passed through, and the jump request that creation state is 302 exists simultaneously Http header adds and uniquely identifies based on user and the authentication state information of operation system mark reversible encryption.
When the password that dynamic password is certain user's current time period or front and back cycle then certification by referring to each use Family certification password within service end keeps current time 30 seconds or in 30 seconds front 30 second, after 30 seconds 30 seconds, i.e. except 30 In second, user correctly configures outside certification with password in 30 seconds, in 30 seconds user with password before 30 seconds or after 30 seconds password carry out Certification is passed through, to solve 30 seconds context errors of password of the error generation that the time exists between each equipment, this certification base Whole account password Hash table is kept in real time in server end.
Additionally, operation system single sign-on authentication is also abstracted into interface by the present invention, will become by user authentication service abstraction One interface, wherein comprises operation system identification, user's identification, user's dynamic password authentication, time inquiring, user authentication record Deng service, in order to provide specific aim to implement for each operation system.
In the method for the present invention, each user's private cipher key can dynamically configure, after having configured first, follow-up alternately without There are private key information, safety guarantee;In operation system, the private cipher key of each user can dynamically configure, support change, change each User's private cipher key.After private cipher key has configured first, certification interaction just will not be carried key sensitive information, it is ensured that Key is in use without intercepting and capturing, stealing.
The present invention also supports that the safety certification of government private network environment requires:
Government private network is information resources share and the infrastructure network platform of network office between government's constituent parts, with the Internet Physical isolation completely, it is impossible to have immediate data mutual, in private network, business management system and terminal unit in non-private network are by manual Setup time near-synchronous, it is achieved second level error, safety certification can be realized on the network of spatial separation.
In government private network, business management system is isolated, strictly with the certification terminal unit physical isolation union space of each user Ensure two-way Key Exposure risk, make the rogue attacks in addition to solution approach is guessed in violence become impossible.
In the method for the present invention, key business operates after certification user login information, carries out dynamic examining authority and lets pass:
Except realizing certification in login process, by configuring the audit certification that key business can be supported to operate, by business operation User triggers application, and by operational control, personnel audit clearance.
When user has access to the business function the most surely needing re-authentication, operation system requires that user is shown by its terminal unit In the instant dynamic password incoming traffic system shown and submit application to;Application is turned by system to be audited by operational control personnel, passes through Rear user's successful access target industry function.
Realize the dynamic configuration management of key business operation, ensure the security requirement of key business operation.
Support Android mobile phone system, IOS cell phone system, Web Service much information interface, be specially and provide simultaneously Rest API and Web Service interface API, call for Android mobile phone system, IOS cell phone system and each terminal interface.
Enforcement example:
The present invention includes herein below and step:
One, the workflow of dynamic password single sign-on authentication, as shown in Figure 1.
Two, the implementation method of certification end user key configuration.
(1) design can be used for user key configuration field, with table TOTP_USERKEYS record.
(2) design can be used for user password code table field, with table TOTP_PWDTAB record.
(3) design can be used for current three the cycle dynamic password synopsis fields front and back of user, uses table TOTP_PWDLIST Record:
Three, user authentication process part design.
Design Table A UTH_LIST is used for recording user authentication process, and the structure of table is as follows:
Four, operation system request call design.
Design Table I NVOKE_LIST is used for record, and the structure of table is as follows:
Five, authentication data transmits design between operation system.
User when asking certification or user to submit to dynamic password to call certification end interface in operation system, certification end Being audited by dynamic password, if dynamic password is the password in certain user's current time period or front and back cycle, certification is led to Cross, and the jump request that creation state is 302 adds based on user's unique identification and operation system in http header simultaneously The authentication state information of mark reversible encryption.
By detailed description of the invention above, described those skilled in the art can readily realize the present invention.But should Working as understanding, the present invention is not limited to above-mentioned detailed description of the invention.On the basis of disclosed embodiment, described technical field Technical staff can the different technical characteristic of combination in any, thus realize different technical schemes.
In addition to the technical characteristic described in description, it is the known technology of those skilled in the art.

Claims (5)

1. the method carrying out user authentication based on dynamic password, it is characterised in that it realizes process and is:
Configuring with the client deadline in service end, wherein service end is used for realizing authentication service, and client is then used for proposing Authentication service so that the time keeps synchronizing, and time error is within ten seconds;
Carrying out service end user key configuration: to whole business management system account initialization, each account is unique for stochastic generation Key, by field prefabricated in database table, record each account and uniquely identify and key information;
Arranging user's dynamic password in client, the Quick Response Code i.e. generated by scanning certification end or employing manually enter mode will Key is input to client, and service end then differentiates user login information certification according to dynamic password.
A kind of method carrying out user authentication based on dynamic password the most according to claim 1, it is characterised in that service end Carry out time configuration with client and refer to by Network Time Protocol, make each computer in network, terminal unit retention time synchronize, And physical isolation between the arbitrary equipment of retention time synchronization, mutual without immediate data each other, its configuration process passes through hands Work completes, it is achieved error time consistency in 10 seconds between equipment.
A kind of method carrying out user authentication based on dynamic password the most according to claim 1, it is characterised in that described dynamic State password refers to that user, after client binds initialized terminal unit, is obtained by TOTP dynamic password algorithm.
A kind of method carrying out user authentication based on dynamic password the most according to claim 3, it is characterised in that service end Differentiating that user login information certification refers to by dynamic password, user submits dynamic mouth in request certification or user in operation system When service end interface is called in order, service end is audited by dynamic password, when dynamic password is certain user's current time period Or during the password in front and back cycle, then certification is passed through, and the jump request that creation state is 302 adds in http header simultaneously Uniquely identify based on user and the authentication state information of operation system mark reversible encryption.
A kind of method carrying out user authentication based on dynamic password the most according to claim 4, it is characterised in that when dynamically When password is the password in certain user's current time period or front and back cycle then certification by referring to that each user keeps in service end Certification password in 30 seconds or 30 seconds front 30 second of current time, after 30 seconds 30 seconds, i.e. except in 30 seconds user with 30 seconds Interior password correctly configures outside certification, in 30 seconds user with password before 30 seconds or after 30 seconds password be authenticated passing through, to solve 30 seconds context errors of password that the error that certainly time exists between each equipment produces, this certification is real-time based on server end Keep whole account password Hash table.
CN201610579570.XA 2016-07-22 2016-07-22 Method for user authentication based on dynamic password Active CN106230594B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201610579570.XA CN106230594B (en) 2016-07-22 2016-07-22 Method for user authentication based on dynamic password

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201610579570.XA CN106230594B (en) 2016-07-22 2016-07-22 Method for user authentication based on dynamic password

Publications (2)

Publication Number Publication Date
CN106230594A true CN106230594A (en) 2016-12-14
CN106230594B CN106230594B (en) 2019-06-25

Family

ID=57531232

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201610579570.XA Active CN106230594B (en) 2016-07-22 2016-07-22 Method for user authentication based on dynamic password

Country Status (1)

Country Link
CN (1) CN106230594B (en)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106790166A (en) * 2016-12-29 2017-05-31 郑州云海信息技术有限公司 A kind of method of safety certification, apparatus and system
CN106953872A (en) * 2017-04-18 2017-07-14 北京韵盛发科技有限公司 A kind of method and apparatus of business authentication
CN107277059A (en) * 2017-08-08 2017-10-20 沈阳东青科技有限公司 A kind of one-time password identity identifying method and system based on Quick Response Code
CN108833608A (en) * 2018-06-12 2018-11-16 北斗天地股份有限公司 A method of server is dynamically determined and changed by password
CN108924104A (en) * 2018-06-21 2018-11-30 甘肃万维信息技术有限责任公司 A kind of method of E-Government encryption and decryption
CN111342964A (en) * 2020-05-15 2020-06-26 深圳竹云科技有限公司 Single sign-on method, device and system

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11843596B2 (en) 2021-06-30 2023-12-12 Micro Focus Llc Reregistration of client device with server device using user device

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101741567A (en) * 2009-12-31 2010-06-16 北京飞天诚信科技有限公司 Dynamic password-based authentication method and device
CN101800644A (en) * 2010-01-11 2010-08-11 上海众烁信息科技有限公司 Computer security protection system and method based on dynamic countersign
US20100250957A1 (en) * 2005-09-09 2010-09-30 University Of South Florida Method of Authenticating a User on a Network
CN103501228A (en) * 2013-08-01 2014-01-08 沈阳华矿新能源装备科技有限公司 Dynamic two-dimension code token and authentication method of dynamic two-dimension code instruction
CN105516104A (en) * 2015-12-01 2016-04-20 神州融安科技(北京)有限公司 Identity verification method and system of dynamic password based on TEE (Trusted execution environment)

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100250957A1 (en) * 2005-09-09 2010-09-30 University Of South Florida Method of Authenticating a User on a Network
CN101741567A (en) * 2009-12-31 2010-06-16 北京飞天诚信科技有限公司 Dynamic password-based authentication method and device
CN101800644A (en) * 2010-01-11 2010-08-11 上海众烁信息科技有限公司 Computer security protection system and method based on dynamic countersign
CN103501228A (en) * 2013-08-01 2014-01-08 沈阳华矿新能源装备科技有限公司 Dynamic two-dimension code token and authentication method of dynamic two-dimension code instruction
CN105516104A (en) * 2015-12-01 2016-04-20 神州融安科技(北京)有限公司 Identity verification method and system of dynamic password based on TEE (Trusted execution environment)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106790166A (en) * 2016-12-29 2017-05-31 郑州云海信息技术有限公司 A kind of method of safety certification, apparatus and system
CN106953872A (en) * 2017-04-18 2017-07-14 北京韵盛发科技有限公司 A kind of method and apparatus of business authentication
CN106953872B (en) * 2017-04-18 2019-08-16 韵盛发科技(北京)股份有限公司 A kind of method and apparatus of business authentication
CN107277059A (en) * 2017-08-08 2017-10-20 沈阳东青科技有限公司 A kind of one-time password identity identifying method and system based on Quick Response Code
CN108833608A (en) * 2018-06-12 2018-11-16 北斗天地股份有限公司 A method of server is dynamically determined and changed by password
CN108833608B (en) * 2018-06-12 2021-04-27 北斗天地股份有限公司 Method for dynamically determining and changing server through password
CN108924104A (en) * 2018-06-21 2018-11-30 甘肃万维信息技术有限责任公司 A kind of method of E-Government encryption and decryption
CN108924104B (en) * 2018-06-21 2021-06-15 甘肃万维信息技术有限责任公司 E-government affair encryption and decryption method
CN111342964A (en) * 2020-05-15 2020-06-26 深圳竹云科技有限公司 Single sign-on method, device and system
CN111342964B (en) * 2020-05-15 2020-08-11 深圳竹云科技有限公司 Single sign-on method, device and system

Also Published As

Publication number Publication date
CN106230594B (en) 2019-06-25

Similar Documents

Publication Publication Date Title
US9992176B2 (en) Systems and methods for encrypted communication in a secure network
US10972478B2 (en) Data processing method and apparatus, terminal, and access point computer
CN106230594B (en) Method for user authentication based on dynamic password
US20180295137A1 (en) Techniques for dynamic authentication in connection within applications and sessions
CN110582768B (en) Apparatus and method for providing secure database access
US9350548B2 (en) Two factor authentication using a protected pin-like passcode
US10904218B2 (en) Secure proxy to protect private data
CN105554098B (en) A kind of equipment configuration method, server and system
US8434137B2 (en) Method of securely logging into remote servers
CN109417553A (en) The attack using leakage certificate is detected via internal network monitoring
CN114679293A (en) Access control method, device and storage medium based on zero trust security
EP2932428B1 (en) Method of allowing establishment of a secure session between a device and a server
CN103906052B (en) A kind of mobile terminal authentication method, Operational Visit method and apparatus
US11716312B1 (en) Platform for optimizing secure communications
CN108347428A (en) Accreditation System, the method and apparatus of application program based on block chain
CN104869121A (en) 802.1x-based authentication method and device
KR101510290B1 (en) Apparatus for implementing two-factor authentication into vpn and method for operating the same
Fareed et al. Privacy-preserving multi-factor authentication and role-based access control scheme for the E-healthcare system
CN108123957B (en) Multi-mode authentication method and device for logging in virtual private network server
CN106850633A (en) A kind of method for authenticating and device
CN106888455A (en) A kind of access authentication of WLAN method, apparatus and system
Eldow et al. Literature review of authentication layer for public cloud computing: a meta-analysis
Xu et al. Qrtoken: Unifying authentication framework to protect user online identity
US20220138310A1 (en) Keystroke Cipher Password Management System and Method
CN109076066A (en) Use the system of the method and implementation this method of encryption and authentication method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant