CN117579245A - Security authentication method, device and storage medium - Google Patents

Security authentication method, device and storage medium Download PDF

Info

Publication number
CN117579245A
CN117579245A CN202311349207.5A CN202311349207A CN117579245A CN 117579245 A CN117579245 A CN 117579245A CN 202311349207 A CN202311349207 A CN 202311349207A CN 117579245 A CN117579245 A CN 117579245A
Authority
CN
China
Prior art keywords
authentication
authorization
blockchain
certificate
operator
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN202311349207.5A
Other languages
Chinese (zh)
Other versions
CN117579245B (en
Inventor
陈海强
邱浚漾
赖燕燕
刘希宙
余筱
林巧晶
原薇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
China Mobile Internet Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
China Mobile Internet Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd, China Mobile Internet Co Ltd filed Critical China Mobile Communications Group Co Ltd
Priority to CN202311349207.5A priority Critical patent/CN117579245B/en
Publication of CN117579245A publication Critical patent/CN117579245A/en
Application granted granted Critical
Publication of CN117579245B publication Critical patent/CN117579245B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/50Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/085Secret sharing or secret splitting, e.g. threshold schemes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)
  • Storage Device Security (AREA)

Abstract

本申请提供了一种安全认证方法、装置及存储介质。其中方法包括:通过网关取号,获取本机手机号码;进行本机号码校验;向运营商认证服务端发送授权请求,并接收所述运营商认证服务端返回的授权凭证;授权相关信息进行区块链存证;向第三方能力方发送所述授权凭证,第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验,运营商认证服务端返回所述鉴权结果,鉴权相关信息进行区块链存证;基于所述鉴权结果,获取所述终端应用的登录授权。确保登录的有迹可循,提升了用户的登录安全性和便捷性。

This application provides a security authentication method, device and storage medium. The method includes: obtaining the local mobile phone number through the gateway; performing local number verification; sending an authorization request to the operator authentication server, and receiving the authorization certificate returned by the operator authentication server; and authorizing related information. Blockchain storage certificate; send the authorization certificate to the third-party capable party, the third-party capable party sends the authorization voucher to the operator authentication server for authentication verification, and the operator authentication server returns the authentication certificate Based on the authentication result, the authentication-related information is stored in the blockchain; based on the authentication result, the login authorization of the terminal application is obtained. Ensure that login is traceable and improve user login security and convenience.

Description

安全认证方法、装置及存储介质Security authentication method, device and storage medium

技术领域Technical field

本申请涉及安全认证技术领域,尤其涉及一种安全认证方法、装置及存储介质。This application relates to the technical field of security authentication, and in particular to a security authentication method, device and storage medium.

背景技术Background technique

目前市场一些平台采用了人像比对登录的相关方式,利用用户头像配合姓名、身份证等相关用户信息进行用户人像三要素校验,来确保本人的实名登陆。但该方法的使用方式成本高,且用户在登录过程中的流程繁琐,耗时较长,用户登陆体验感较差。At present, some platforms in the market adopt the method of portrait comparison login, using the user's avatar together with the name, ID card and other relevant user information to perform three-factor verification of the user's portrait to ensure that the person logs in with his real name. However, the cost of using this method is high, and the user login process is cumbersome and time-consuming, and the user login experience is poor.

还有一些平台才赢无校验方式的密码账户登录,此种方式的用户密码存在泄露的可能,同时用户的登录存在盗登等相关现象,且登录历史无迹可循。There are also some platforms that only use password account login without verification. User passwords in this way may be leaked. At the same time, user logins may be stolen and other related phenomena, and the login history cannot be traced.

发明内容Contents of the invention

本申请提供了一种安全认证方法、装置及存储介质,以至少提高用户登录过程中的安全性和便捷性。本申请的技术方案如下:This application provides a security authentication method, device and storage medium to at least improve the security and convenience during user login. The technical solution of this application is as follows:

第一方面,本申请实施例提供了一种安全认证方法,所述安全认证方法应用于运营商认证服务端,包括:In the first aspect, embodiments of this application provide a security authentication method. The security authentication method is applied to the operator authentication server, including:

接收来自终端应用的取号请求,向所述终端应用返回对应终端的本机手机号码;Receive a number request from the terminal application, and return the local mobile phone number of the corresponding terminal to the terminal application;

接收所述终端应用基于所述本机手机号码发送的授权请求,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证;Receive the authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application and store the authorization-related information in the blockchain;

接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证;其中,所述鉴权结果用于指示所述终端应用是否允许对应的终端用户登录所述终端应用。Receive an authentication request carrying the authorization certificate sent by the terminal application, return the authentication result and store the authentication-related information in the blockchain; wherein the authentication result is used to indicate whether the terminal application allows the corresponding The terminal user logs in to the terminal application.

在一些实现方式中,所述接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证,包括:In some implementations, receiving an authentication request carrying an authorization certificate sent by the terminal application, returning the authentication result and storing the authentication-related information on the blockchain includes:

接收第三方能力方发送的携带所述终端应用发送的授权凭证的鉴权请求;Receive an authentication request sent by a third-party capable party carrying the authorization certificate sent by the terminal application;

对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证。The authorization certificate sent by the terminal application is verified and authenticated, the authentication result is returned to the third-party capable party, and the authentication-related information is stored in the blockchain.

在一些实现方式中,所述对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证,包括:In some implementations, the verification and authentication of the authorization certificate sent by the terminal application, returning the authentication result to the third-party capable party and storing the authentication-related information in the blockchain include:

通过多线程工作流队列的形式,对多个终端应用发送的授权凭证进行校验鉴权;Verify and authenticate authorization credentials sent by multiple terminal applications in the form of multi-threaded workflow queues;

通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Multiple authentication-related information is stored in the blockchain in the form of a multi-threaded workflow queue.

在一些实现方式中,所述通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链之前,还包括:In some implementations, storing multiple authentication-related information before the blockchain in the form of a multi-threaded workflow queue also includes:

基于所述运营商认证服务端的资源利用率和多个所述鉴权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authentication-related information;

基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Based on the multi-thread work efficiency factor and the preset threshold, it is determined whether to store multiple authentication-related information in the blockchain in the form of a multi-thread workflow queue.

在一些实现方式中,所述向所述终端应用发送授权凭证并将授权相关信息进行区块链存证,包括:In some implementations, sending an authorization voucher to the terminal application and storing the authorization-related information on the blockchain includes:

基于所述运营商认证服务端的资源利用率和多个所述授权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authorization-related information;

基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个授权相关信息存储于区块链;Based on the multi-thread work efficiency factor and the preset threshold, determine whether to store multiple authorization-related information in the blockchain in the form of a multi-thread workflow queue;

在确定之后,通过多线程工作流队列的形式,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证。After the determination, the authorization certificate is sent to the terminal application in the form of a multi-threaded workflow queue and the authorization-related information is stored in the blockchain.

在一些实现方式中,所述进行区块链存证之前,还包括:In some implementations, before performing blockchain certification, the process also includes:

通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息;Extract the secret key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs through the channel phase response key extraction algorithm;

基于提取的所述秘钥对信息,验证所述运营商认证服务端与所述区块链平台之间的密钥一致性。Based on the extracted key pair information, the key consistency between the operator authentication server and the blockchain platform is verified.

在一些实现方式中,所述通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息,包括:In some implementations, the channel phase response key extraction algorithm extracts key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs, including:

基于所述区块链,接收受信任的第三方发布的包含校正序列的不匹配位;Based on the blockchain, receive mismatched bits containing correction sequences published by a trusted third party;

基于所述第三方发布的包含校正序列的不匹配位,通过信道相位响应密钥提取算法,从所述区块链平台发送的秘钥数据包中提取秘钥对信息;其中,所述授权凭证作为所述运营商认证服务端与所述区块链平台之间的整个会话的临时可信度证明。Based on the mismatched bits containing the correction sequence issued by the third party, the secret key pair information is extracted from the secret key data packet sent by the blockchain platform through the channel phase response key extraction algorithm; wherein, the authorization certificate As a temporary credibility certificate for the entire session between the operator authentication server and the blockchain platform.

第二方面,本申请实施例提供了一种安全认证方法,所述安全认证方法应用于终端,包括:In the second aspect, embodiments of the present application provide a security authentication method, which is applied to a terminal and includes:

响应于终端应用启动操作,通过网关取号,获取本机手机号码;In response to the terminal application startup operation, obtain the local mobile phone number through the gateway;

基于所述本机手机号码与用户输入的手机号码,进行本机号码校验;Based on the local mobile phone number and the mobile phone number input by the user, perform local number verification;

校验通过后,向运营商认证服务端发送授权请求,并接收所述运营商认证服务端基于所述授权请求返回的授权凭证;其中,所述运营商认证服务端返回所述授权凭证的同时将授权相关信息进行区块链存证;After the verification is passed, an authorization request is sent to the operator authentication server, and the authorization voucher returned by the operator authentication server based on the authorization request is received; wherein, the operator authentication server returns the authorization voucher at the same time Store authorization-related information on the blockchain;

向第三方能力方发送所述授权凭证,指示所述第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验,并接收所述第三方能力方返回的鉴权结果;其中,所述运营商认证服务端返回所述鉴权结果的同时将鉴权相关信息进行区块链存证;Send the authorization certificate to the third-party capable party, instruct the third-party capable party to send the authorization voucher to the operator authentication server for authentication verification, and receive the authentication returned by the third-party capable party Result; wherein, the operator authentication server returns the authentication result and at the same time stores the authentication-related information in the blockchain;

基于所述鉴权结果,获取所述终端应用的登录授权。Based on the authentication result, the login authorization of the terminal application is obtained.

在一些实现方式中,所述通过网关取号,获取本机手机号码,包括:In some implementations, obtaining the local mobile phone number through a gateway includes:

通过运营商认证SDK,向所述运营商认证服务端发送手机号凭证申请;Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK;

获取所述运营商认证服务端基于所述手机号凭证申请返回的手机号凭证;Obtain the mobile phone number certificate returned by the operator authentication server based on the mobile phone number certificate application;

基于所述手机号凭证,通过所述运营商认证SDK向所述运营商认证服务端发送取号凭证申请;Based on the mobile phone number certificate, send a number certificate application to the operator authentication server through the operator authentication SDK;

获取所述运营商认证服务端基于所述取号凭证申请返回的取号凭证;Obtain the number-taking certificate returned by the operator authentication server based on the number-taking certificate application;

基于所述取号凭证,通过所述终端应用对应的应用后端服务,从所述运营商服务端获取本机手机号码。Based on the number retrieval certificate, the local mobile phone number is obtained from the operator server through the application backend service corresponding to the terminal application.

第三方面,本申请实施例提供了一种安全认证装置,所述装置配置于运营商认证服务端,所述装置包括:In a third aspect, embodiments of the present application provide a security authentication device, which is configured on an operator authentication server. The device includes:

取号处理模块,用于接收来自终端应用的取号请求,向所述终端应用返回对应终端的本机手机号码;A number retrieval processing module, configured to receive a number retrieval request from a terminal application and return the local mobile phone number of the corresponding terminal to the terminal application;

授权处理模块,用于接收所述终端应用基于所述本机手机号码发送的授权请求,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证;An authorization processing module, configured to receive an authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application, and store the authorization-related information in the blockchain;

鉴权处理模块,用于接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证;其中,所述鉴权结果用于指示所述终端应用是否允许对应的终端用户登录所述终端应用。An authentication processing module, configured to receive an authentication request carrying an authorization certificate sent by the terminal application, return the authentication result, and store the authentication-related information on the blockchain; wherein the authentication result is used to indicate the Whether the terminal application allows the corresponding terminal user to log in to the terminal application.

在一些实现方式中,鉴权处理模块,具体用于:In some implementations, the authentication processing module is specifically used for:

接收第三方能力方发送的携带所述终端应用发送的授权凭证的鉴权请求;Receive an authentication request sent by a third-party capable party carrying the authorization certificate sent by the terminal application;

对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证。The authorization certificate sent by the terminal application is verified and authenticated, the authentication result is returned to the third-party capable party, and the authentication-related information is stored in the blockchain.

在一些实现方式中,鉴权处理模块对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证时,具体用于:In some implementations, when the authentication processing module verifies and authenticates the authorization certificate sent by the terminal application, returns the authentication result to the third-party capable party and stores the authentication-related information in the blockchain, Specifically used for:

通过多线程工作流队列的形式,对多个终端应用发送的授权凭证进行校验鉴权;Verify and authenticate authorization credentials sent by multiple terminal applications in the form of multi-threaded workflow queues;

通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Multiple authentication-related information is stored in the blockchain in the form of a multi-threaded workflow queue.

在一些实现方式中,鉴权处理模块,还用于:In some implementations, the authentication processing module is also used to:

基于所述运营商认证服务端的资源利用率和多个所述鉴权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authentication-related information;

基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Based on the multi-thread work efficiency factor and the preset threshold, it is determined whether to store multiple authentication-related information in the blockchain in the form of a multi-thread workflow queue.

在一些实现方式中,所述授权处理模块,具体用于:In some implementations, the authorization processing module is specifically used to:

基于所述运营商认证服务端的资源利用率和多个所述授权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authorization-related information;

基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个授权相关信息存储于区块链;Based on the multi-thread work efficiency factor and the preset threshold, determine whether to store multiple authorization-related information in the blockchain in the form of a multi-thread workflow queue;

在确定之后,通过多线程工作流队列的形式,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证。After the determination, the authorization certificate is sent to the terminal application in the form of a multi-threaded workflow queue and the authorization-related information is stored in the blockchain.

在一些实现方式中,该装置还包括秘钥管理模块,用于:In some implementations, the device also includes a key management module for:

通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息;Extract the secret key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs through the channel phase response key extraction algorithm;

基于提取的所述秘钥对信息,验证所述运营商认证服务端与所述区块链平台之间的密钥一致性。Based on the extracted key pair information, the key consistency between the operator authentication server and the blockchain platform is verified.

在一些实现方式中,秘钥管理模块通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息时,具体用于:In some implementations, the secret key management module uses the channel phase response key extraction algorithm to extract key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs, specifically for:

基于所述区块链,接收受信任的第三方发布的包含校正序列的不匹配位;Based on the blockchain, receive mismatched bits containing correction sequences published by a trusted third party;

基于所述第三方发布的包含校正序列的不匹配位,通过信道相位响应密钥提取算法,从所述区块链平台发送的秘钥数据包中提取秘钥对信息;其中,所述授权凭证作为所述运营商认证服务端与所述区块链平台之间的整个会话的临时可信度证明。Based on the mismatched bits containing the correction sequence issued by the third party, the secret key pair information is extracted from the secret key data packet sent by the blockchain platform through the channel phase response key extraction algorithm; wherein, the authorization certificate As a temporary credibility certificate for the entire session between the operator authentication server and the blockchain platform.

第四方面,本申请实施例提供了一种安全认证装置,所述装置配置于终端,所述装置包括:In the fourth aspect, embodiments of the present application provide a security authentication device, which is configured on a terminal and includes:

取号模块,用于响应于终端应用启动操作,通过网关取号,获取本机手机号码;The number retrieval module is used to obtain the local mobile phone number through the gateway in response to the terminal application startup operation;

校验模块,用于基于所述本机手机号码与用户输入的手机号码,进行本机号码校验;A verification module, configured to perform local number verification based on the local mobile phone number and the mobile phone number input by the user;

凭证申请模块,用于校验通过后,向运营商认证服务端发送授权请求,并接收所述运营商认证服务端基于所述授权请求返回的授权凭证;其中,所述运营商认证服务端返回所述授权凭证的同时将授权相关信息进行区块链存证;The certificate application module is used to send an authorization request to the operator authentication server after passing the verification, and receive the authorization certificate returned by the operator authentication server based on the authorization request; wherein, the operator authentication server returns Along with the authorization certificate, authorization-related information will be stored in the blockchain;

认证处理模块,用于向第三方能力方发送所述授权凭证,指示所述第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验,并接收所述第三方能力方返回的鉴权结果;其中,所述运营商认证服务端返回所述鉴权结果的同时将鉴权相关信息进行区块链存证;Authentication processing module, used to send the authorization voucher to the third party capable party, instruct the third party capable party to send the authorization voucher to the operator authentication server for authentication verification, and receive the third party capable party The authentication result returned by the capable party; wherein, the operator authentication server returns the authentication result and at the same time stores the authentication-related information in the blockchain;

认证处理模块,还用于基于所述鉴权结果,获取所述终端应用的登录授权。The authentication processing module is also configured to obtain the login authorization of the terminal application based on the authentication result.

在一些实现方式中,取号模块,具体用于:In some implementations, the number-taking module is specifically used for:

通过运营商认证SDK,向所述运营商认证服务端发送手机号凭证申请;Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK;

获取所述运营商认证服务端基于所述手机号凭证申请返回的手机号凭证;Obtain the mobile phone number certificate returned by the operator authentication server based on the mobile phone number certificate application;

基于所述手机号凭证,通过所述运营商认证SDK向所述运营商认证服务端发送取号凭证申请;Based on the mobile phone number certificate, send a number certificate application to the operator authentication server through the operator authentication SDK;

获取所述运营商认证服务端基于所述取号凭证申请返回的取号凭证;Obtain the number-taking certificate returned by the operator authentication server based on the number-taking certificate application;

基于所述取号凭证,通过所述终端应用对应的应用后端服务,从所述运营商服务端获取本机手机号码。Based on the number retrieval certificate, the local mobile phone number is obtained from the operator server through the application backend service corresponding to the terminal application.

第五方面,本申请实施例提供了一种电子设备,包括:至少一个处理器;以及与所述至少一个处理器通信连接的存储器;其中,所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器能够执行本申请第一方面实施例所述的安全认证方法。In a fifth aspect, embodiments of the present application provide an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores information that can be used by the at least one processor. Execution instructions, the instructions are executed by the at least one processor, so that the at least one processor can execute the security authentication method described in the embodiment of the first aspect of this application.

第六方面,本申请实施例提供了一种存储有计算机指令的非瞬时计算机可读存储介质,所述计算机指令用于使所述计算机执行本申请第一方面实施例所述的安全认证方法。In a sixth aspect, embodiments of the present application provide a non-transient computer-readable storage medium storing computer instructions, the computer instructions being used to cause the computer to execute the security authentication method described in the embodiment of the first aspect of the application.

第七方面,本申请实施例提供了一种计算机程序产品,包括计算机指令,该计算机指令被处理器执行时实现本申请第一方面实施例所述的安全认证方法的步骤。In a seventh aspect, embodiments of the present application provide a computer program product, which includes computer instructions that, when executed by a processor, implement the steps of the security authentication method described in the embodiment of the first aspect of the application.

本申请实施例提供的技术方案至少带来以下有益效果:The technical solutions provided by the embodiments of this application at least bring the following beneficial effects:

网关取号之后,通过授权和鉴权过程实现安全认证,并通过区块链对用户登录应用时进行安全认证的相关信息进行存证和出证,保证用户操作的不可抵赖性,确保登录的有迹可循,实现了基于用户本机手机号码取号校验,同时进行区块链存证出证不可抵赖格式的安全账户登录方式,提升了用户的登录安全性和便捷性。运营商认证服务端采用多线程工作流形式进行提供认证服务,在一定程度上提升了服务性能。运营商认证服务端和区块链平台通过引入基于信道相位响应的密钥提取算法,用于验证通信双方之间的密钥一致性,利用短期信道互易性和随机性来提取秘密加密共享密钥,进一步加强安全存证的可靠性。After the gateway obtains the number, security authentication is implemented through the authorization and authentication process, and relevant information for security authentication when the user logs in to the application is stored and certified through the blockchain to ensure the non-repudiation of user operations and the validity of the login. Traceable, a secure account login method is implemented based on the user's local mobile phone number for verification, and at the same time, the blockchain certificate is deposited and issued in a non-repudiation format, which improves the user's login security and convenience. The operator authentication server uses a multi-threaded workflow to provide authentication services, which improves service performance to a certain extent. The operator authentication server and blockchain platform introduce a key extraction algorithm based on channel phase response to verify the key consistency between the communicating parties and use short-term channel reciprocity and randomness to extract the secret encryption shared key. key to further enhance the reliability of secure certificate storage.

应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本申请。It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit the present application.

附图说明Description of the drawings

此处的附图被并入说明书中并构成本说明书的一部分,示出了符合本申请的实施例,并与说明书一起用于解释本申请的原理,并不构成对本申请的不当限定。The drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present application, and are used together with the description to explain the principles of the present application, and do not constitute undue limitations on the present application.

图1是根据一示例性实施例示出的一种安全认证方法的流程图。Figure 1 is a flow chart of a security authentication method according to an exemplary embodiment.

图2是根据一示例示出的业务方、能力方与运营商认证服务端之间的交互图。Figure 2 is an interaction diagram between the business party, the capability party and the operator authentication server according to an example.

图3是根据另一示例性实施例示出的一种安全认证方法的流程图。Figure 3 is a flow chart of a security authentication method according to another exemplary embodiment.

图4是根据一示例性实施例示出的一种安全认证装置的框图。Figure 4 is a block diagram of a security authentication device according to an exemplary embodiment.

图5是根据另一示例性实施例示出的一种安全认证装置的框图。Figure 5 is a block diagram of a security authentication device according to another exemplary embodiment.

图6是根据一示例性实施例示出的一种电子设备的框图。FIG. 6 is a block diagram of an electronic device according to an exemplary embodiment.

具体实施方式Detailed ways

为了使本领域普通人员更好地理解本申请的技术方案,下面将结合附图,对本申请实施例中的技术方案进行清楚、完整地描述。In order to enable ordinary people in the art to better understand the technical solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

需要说明的是,本申请中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本申请实施例能够以除了在这里图示或描述的那些以外的顺序实施。以下示例性实施例中所描述的实施方式并不代表与本申请相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本申请的一些方面相一致的装置和方法的例子。It should be noted that the terms "first", "second", etc. in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the application described herein can be practiced in sequences other than those illustrated or described herein. The implementations described in the following exemplary embodiments do not represent all implementations consistent with this application. Rather, they are merely examples of apparatus and methods consistent with aspects of the application as detailed in the appended claims.

当今社会,电信手机诈骗现象普遍,用户账户信息存在着被盗登,账户信息存在被盗取等相关的情况。用户的密码管理等相关私密信息管理泄露等相关情况也时常发生,如何切实保护用户账户和账户密码信息成为急迫解决的问题;In today's society, telecommunications and mobile phone fraud are common. User account information has been stolen, account information has been stolen, and other related situations. Situations such as leakage of users' password management and other related private information management also often occur. How to effectively protect user accounts and account password information has become an urgent problem to solve;

目前市场一些平台采用了人像比对登录的相关方式,利用用户头像配合姓名、身份证等相关用户信息到进行用户人像三要素校验,来确保本人的实名登陆。但目前该方法的使用方式成本高,耗时大,在登陆过程中对用户登陆流程繁琐,登陆体验感差,且并没有进行认证信息存证等。At present, some platforms in the market adopt the method of portrait comparison login, using the user's avatar together with the name, ID card and other relevant user information to perform three-factor verification of the user's portrait to ensure that the person logs in with his real name. However, the current use of this method is costly and time-consuming. During the login process, the user login process is cumbersome, the login experience is poor, and the authentication information is not stored.

为了保障用户登录过程中的安全,便捷性考虑,本申请技术方案提供一种基于用户本机号码取号校验,同时进行区块链存证出证不可抵赖格式的安全账户登录方式,来代替用户人像三要素等登录方式。为安全,快捷式的解决用户账户安全登录方式,基于用户本人手机号码进行本机号码校验,确保用户本人注册手机号能在本机进行相关的登录操作,同时进行区块链的存证出证,确保该次操作有迹可循,用户不可抵赖等相关特征,在一定程度上大大提升用户登录的安全性和便捷性。In order to ensure the security and convenience of the user login process, the technical solution of this application provides a secure account login method based on the user's local number for verification, and at the same time performs blockchain certificate storage and non-repudiation format to replace User portrait three-factor and other login methods. In order to provide a safe and fast solution to the secure login method of user accounts, local number verification is performed based on the user's own mobile phone number to ensure that the user's registered mobile phone number can perform relevant login operations on the local machine, and at the same time, the blockchain certificate is deposited and issued. Certificate ensures that the operation is traceable and the user cannot deny it, which greatly improves the security and convenience of user login to a certain extent.

图1是根据本申请一个实施例的安全认证方法的流程图。需要说明的是,本申请实施例的安全认证方法可应用于本申请实施例的安全认证装置,该安全认证装置可被配置于终端等电子设备上。如图1所示,该安全认证方法可以包括如下步骤。Figure 1 is a flow chart of a security authentication method according to an embodiment of the present application. It should be noted that the security authentication method of the embodiment of the present application can be applied to the security authentication device of the embodiment of the present application, and the security authentication device can be configured on an electronic device such as a terminal. As shown in Figure 1, the security authentication method may include the following steps.

步骤S101,响应于终端应用启动操作,通过网关取号,获取本机手机号码。Step S101: In response to the terminal application startup operation, obtain the number through the gateway to obtain the local mobile phone number.

在用户触发终端应用(应用前端或者应用APP)启动操作时,终端应用通过网关取号方式,获取本机手机号码。When the user triggers the terminal application (application front-end or application APP) to start the operation, the terminal application obtains the local mobile phone number through the gateway number retrieval method.

示例性的,终端应用可以为安装于手机终端上应用APP或者需要登录认证的网站等,例如,外卖APP、购物APP等。For example, the terminal application may be an application APP installed on a mobile phone terminal or a website that requires login authentication, such as a takeout APP, a shopping APP, etc.

作为一种实现方式,终端应用通过网关取号获取本机手机号码的实现方式,包括:As an implementation method, the terminal application obtains the local mobile phone number through the gateway, including:

通过运营商认证SDK,向所述运营商认证服务端发送手机号凭证申请;获取所述运营商认证服务端基于所述手机号凭证申请返回的手机号凭证;基于所述手机号凭证,通过所述运营商认证SDK向所述运营商认证服务端发送取号凭证申请;获取所述运营商认证服务端基于所述取号凭证申请返回的取号凭证;基于所述取号凭证,通过所述终端应用对应的应用后端服务,从所述运营商服务端获取本机手机号码。Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK; obtain the mobile phone number voucher returned by the operator authentication server based on the mobile phone number voucher application; based on the mobile phone number voucher, through the mobile phone number voucher The operator authentication SDK sends a number-taking voucher application to the operator authentication server; obtains the number-taking voucher returned by the operator authentication server based on the number-taking voucher application; based on the number-taking voucher, through the The application backend service corresponding to the terminal application obtains the local mobile phone number from the operator server.

这里需要说明的是,运营商认证服务端可以理解为基站,即基站提供的运营商认证服务,也可以理解为整个基站的安全基座服务,运营商认证SDK相当于取号的一个组件,运营商认证SDK安装于终端。What needs to be explained here is that the operator authentication server can be understood as the base station, that is, the operator authentication service provided by the base station, or the security base service of the entire base station. The operator authentication SDK is equivalent to a component of number acquisition, operation Business certification SDK is installed on the terminal.

示例性的,手机终端装载有运营商认证SDK,手机用户启动应用时,应用前端通过装载的运营商认证SDK利用手机流量进行网关取号,初步获取手机卡的手机号掩码,运营商认证SDK将手机号等相关信息发送给运营商认证服务端,并给应用前端发放手机号凭证信息。应用前端拿到手机号凭证信息之后进行授权,应用前端通过手机号凭证信息请求运营商认证服务端,获取相关的取号凭证token参数,将取号凭证token参数返回至运营商认证SDK。应用前端将取号凭证传递给应用服务器,应用服务器通过该取号凭证请求运营商认证服务端获取相关的本机手机号码。For example, the mobile phone terminal is loaded with the operator authentication SDK. When the mobile phone user starts the application, the application front-end uses the mobile phone traffic to obtain the gateway number through the loaded operator authentication SDK, and initially obtains the mobile phone number mask of the mobile phone card, and the operator authentication SDK Send the mobile phone number and other relevant information to the operator authentication server, and issue the mobile phone number voucher information to the application front-end. After obtaining the mobile phone number voucher information, the application front-end performs authorization. The application front-end requests the operator authentication server through the mobile phone number voucher information, obtains the relevant number voucher token parameters, and returns the number voucher token parameters to the operator authentication SDK. The application front-end passes the number retrieval certificate to the application server, and the application server uses the number retrieval certificate to request the operator authentication server to obtain the relevant local mobile phone number.

步骤S102,基于所述本机手机号码与用户输入的手机号码,进行本机号码校验。Step S102: Perform local number verification based on the local mobile phone number and the mobile phone number input by the user.

应用前端通过网关取号获取到本机手机号码之后,再与本机用户输入的手机号或者注册的手机号进行本机号码校验,以确定是否为本机号码操作。After the application front-end obtains the local mobile phone number through the gateway, it then performs local number verification with the mobile phone number entered by the local user or the registered mobile phone number to determine whether the operation is a local number.

步骤S103,校验通过后,向运营商认证服务端发送授权请求,并接收所述运营商认证服务端基于所述授权请求返回的授权凭证;其中,所述运营商认证服务端返回所述授权凭证的同时将授权相关信息进行区块链存证。Step S103: After passing the verification, send an authorization request to the operator authentication server, and receive the authorization certificate returned by the operator authentication server based on the authorization request; wherein, the operator authentication server returns the authorization Along with the certificate, authorization-related information will be stored in the blockchain.

应用前端向运营商认证服务端请求授权,并获取运营商认证服务端反馈的授权凭证。The application front-end requests authorization from the operator authentication server and obtains the authorization credentials fed back by the operator authentication server.

步骤S104,向第三方能力方发送所述授权凭证,指示所述第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验,并接收所述第三方能力方返回的鉴权结果;其中,所述运营商认证服务端返回所述鉴权结果的同时将鉴权相关信息进行区块链存证。Step S104: Send the authorization voucher to the third-party capable party, instruct the third-party capable party to send the authorization voucher to the operator authentication server for authentication verification, and receive the return from the third-party capable party. The authentication result; wherein, the operator authentication server returns the authentication result and at the same time stores the authentication-related information in the blockchain.

在本实施例中,业务方向第三方能力方(简称能力方)发送所述授权凭证,指示所述第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验。In this embodiment, the business party sends the authorization voucher to a third-party capable party (capable party for short), and instructs the third-party capable party to send the authorization voucher to the operator authentication server for authentication verification.

也就是说,如图2所示,业务方获取授权凭证之后,将授权凭证传递至能力方,由能力方将授权凭证提供给运营商认证服务端(服务提供方)进行鉴权操作并返回鉴权结果。That is to say, as shown in Figure 2, after the business party obtains the authorization voucher, it passes the authorization voucher to the capable party, and the capable party provides the authorization voucher to the operator authentication server (service provider) for authentication operation and returns the authentication Right result.

这里需要说明的是,业务方可以理解为应用,应用前端和应用服务可以理解为业务方的前端和后端,业务方相当于运营商的用户,能立方可以理解为一个中间代理,这个中间代理可以将运营商的产品推荐给业务方。What needs to be explained here is that the business side can be understood as the application, and the application front-end and application service can be understood as the front-end and back-end of the business side. The business side is equivalent to the user of the operator, and Nenglifang can be understood as an intermediate agent. This intermediate agent Can recommend operators' products to business parties.

步骤S105,基于所述鉴权结果,获取所述终端应用的登录授权。Step S105: Obtain the login authorization of the terminal application based on the authentication result.

鉴权成功之后,用户便通过安全认证,可以登录应用。After successful authentication, the user passes the security authentication and can log in to the application.

在登录之后,还可以记录相关的话单信息,并通过消息中间件(kafka/rabbaitMQ)推送到话单系统,话单和授权鉴权等相关的信息推入数据库存储。After logging in, you can also record relevant bill information and push it to the bill system through message middleware (kafka/rabbaitMQ). Related information such as bill and authorization authentication is pushed into the database for storage.

本申请实施例的安全认证方法,网关取号之后,通过授权和鉴权过程实现安全认证,并通过区块链对用户登录应用时进行安全认证的相关信息进行存证和出证,保证用户操作的不可抵赖性,确保登录的有迹可循,实现了基于用户本机手机号码取号校验,同时进行区块链存证出证不可抵赖格式的安全账户登录方式,提升了用户的登录安全性和便捷性。In the security authentication method of the embodiment of this application, after the gateway obtains the number, security authentication is implemented through the authorization and authentication process, and relevant information for security authentication when the user logs in to the application is stored and issued through the blockchain to ensure user operations. The non-repudiation ensures that the login is traceable. It implements a secure account login method based on the user's local mobile phone number and a non-repudiation format for blockchain certificate storage and issuance, which improves the user's login security. sex and convenience.

图3是根据本申请一个实施例的安全认证方法的流程图。需要说明的是,本申请实施例的安全认证方法可应用于本申请实施例的安全认证装置,该安全认证装置可被配置于运营商认证服务端等电子设备上。如图3示,该安全认证方法可以包括如下步骤。Figure 3 is a flow chart of a security authentication method according to an embodiment of the present application. It should be noted that the security authentication method of the embodiment of the present application can be applied to the security authentication device of the embodiment of the present application, and the security authentication device can be configured on electronic equipment such as an operator authentication server. As shown in Figure 3, the security authentication method may include the following steps.

步骤S201,接收来自终端应用的取号请求,向所述终端应用返回对应终端的本机手机号码。Step S201: Receive a number request from the terminal application, and return the local mobile phone number of the corresponding terminal to the terminal application.

网关取号的过程参见上述实施例的步骤S101的具体实现过程,在此不在赘述。For the process of gateway number retrieval, please refer to the specific implementation process of step S101 in the above embodiment, which will not be described again here.

步骤S202,接收所述终端应用基于所述本机手机号码发送的授权请求,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证。Step S202: Receive the authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application and store the authorization-related information in the blockchain.

运营商认证服务端接收所述终端应用基于所述本机手机号码发送的授权请求,向所述终端应用发送授权凭证,并将授权相关信息进行区块链存证。发送授权凭证和将授权相关信息进行区块链存证通过不同的线程实现。The operator authentication server receives the authorization request sent by the terminal application based on the local mobile phone number, sends an authorization certificate to the terminal application, and stores the authorization-related information in the blockchain. Sending authorization credentials and storing authorization-related information on the blockchain are implemented through different threads.

在授权过程中,针对授权凭证(授权token)进行两种约定:During the authorization process, two agreements are made for the authorization credentials (authorization token):

1、持久化:如规定授权token为持久化格式,则需要将授权token根据运管配置缓存时间存入系统缓存中之外,还需要将授权token进行数据库存储,在存储格式中,用户与应用服务方约定存储有效时间,当在有效时间内,则判断授权token有效,反之,则token失效。2、非持久化:如规定授权token为非持久化格式,则只需要根据缓存时间进行系统缓存即可。其中,授权token的生成格式还需要和用户appid,用户使用的能力属性进行关联。1. Persistence: If the authorization token is specified to be in a persistent format, the authorization token needs to be stored in the system cache according to the cache time configured by the operation and management, and the authorization token also needs to be stored in the database. In the storage format, users and applications The service party agrees on the storage validity time. When it is within the validity time, the authorization token is judged to be valid. Otherwise, the token is invalid. 2. Non-persistent: If the authorization token is in a non-persistent format, it only needs to be cached by the system according to the cache time. Among them, the generation format of the authorization token also needs to be associated with the user appid and the ability attributes used by the user.

在一些实现方式中,运营商认证服务端通过多线程工作流队列的形式,将来自多个终端的多个授权相关信息存储于区块链。In some implementations, the operator authentication server stores multiple authorization-related information from multiple terminals in the blockchain through a multi-threaded workflow queue.

步骤S203,接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证;其中,所述鉴权结果用于指示所述终端应用是否允许对应的终端用户登录所述终端应用。Step S203: Receive the authentication request carrying the authorization certificate sent by the terminal application, return the authentication result, and store the authentication-related information in the blockchain; where the authentication result is used to indicate whether the terminal application Allow the corresponding terminal user to log in to the terminal application.

运营商认证服务端接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果,并将鉴权相关信息进行区块链存证,鉴权相关信息可以包括但不限于鉴权过程相关流程信息、相关用户信息、鉴权凭证、用户操作信息等。The operator authentication server receives the authentication request carrying the authorization certificate sent by the terminal application, returns the authentication result, and stores the authentication-related information in the blockchain. The authentication-related information may include but is not limited to the authentication process. Related process information, related user information, authentication credentials, user operation information, etc.

在一些实施中,运营商认证服务端:接收第三方能力方发送的携带所述终端应用发送的授权凭证的鉴权请求;对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证。In some implementations, the operator authentication server: receives an authentication request carrying the authorization certificate sent by the terminal application sent by a third-party capable party; performs verification and authentication on the authorization certificate sent by the terminal application, and sends the authorization certificate to the terminal application. The third-party capable party returns the authentication result and stores the authentication-related information on the blockchain.

可以理解为,如图2所示,运营商认证服务端接收的是能力方发送的授权凭证。即,运营商认证服务端接收所述终端应用通过能力方转发的所述授权凭证;对所述终端应用发送的授权凭证进行校验鉴权,向能力方返回鉴权结果。而能力方可以选择多个授权凭证,同时发送运营商认证服务端进行授权凭证的校验鉴权。即作为中间代理的能力方可以选择发送多个授权凭证,向运营商认证服务端申请鉴权服务,即申请安全基座的token校验鉴权。It can be understood that, as shown in Figure 2, the operator authentication server receives the authorization certificate sent by the capable party. That is, the operator authentication server receives the authorization voucher forwarded by the terminal application through the capable party; verifies and authenticates the authorization voucher sent by the terminal application, and returns the authentication result to the capable party. The capable party can select multiple authorization credentials and simultaneously send the operator authentication server for verification and authentication of the authorization credentials. That is, the capable party acting as an intermediary agent can choose to send multiple authorization credentials and apply for authentication services from the operator's authentication server, that is, apply for token verification and authentication of the security base.

运营商认证服务端可以通过多线程工作流队列的形式,对多个终端应用发送的授权凭证进行校验鉴权;通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链;通过多线程工作流队列的形式,将多个授权相关信息存储于区块链。也就是说,运营商认证服务端可以通过多线程工作流队列的形式,同时处理来自多个业务方或者能力方的授权请求和鉴权请求。The operator authentication server can verify and authenticate authorization certificates sent by multiple terminal applications in the form of multi-threaded workflow queues; store multiple authentication-related information in blocks through multi-threaded workflow queues Chain; multiple authorization-related information is stored in the blockchain in the form of a multi-threaded workflow queue. In other words, the operator authentication server can process authorization requests and authentication requests from multiple business parties or capability parties at the same time through a multi-threaded workflow queue.

在一些实施例中,通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链之前,还包括:基于所述运营商认证服务端的资源利用率和多个所述鉴权相关信息对应的上链任务量,获取多线程工作效率因子;基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。In some embodiments, storing multiple authentication-related information in front of the blockchain in the form of a multi-threaded workflow queue also includes: based on the resource utilization of the operator authentication server and multiple authentication The amount of on-chain tasks corresponding to the relevant information is obtained to obtain the multi-thread work efficiency factor; based on the multi-thread work efficiency factor and the preset threshold, it is determined whether to store multiple authentication-related information in the area in the form of a multi-thread workflow queue. Blockchain.

示例性的,用户线程(即应用方)将来自多个终端的鉴权参数提交给运营商认证服务端的多线程工作流;多个任务进入多线程工作流队列;多线程任务出列,并在区块链进行上链操作;多线程工作流结束,进程生命周期结束;之后再将用户的信息上报区块链平台,区块链进行存证和出证,将用户操作信息进行上链。For example, the user thread (i.e. the application side) submits authentication parameters from multiple terminals to the multi-threaded workflow of the operator authentication server; multiple tasks enter the multi-threaded workflow queue; the multi-threaded tasks are dequeued and The blockchain performs on-chain operations; the multi-threaded workflow ends, and the process life cycle ends; then the user's information is reported to the blockchain platform, the blockchain performs certificate storage and issuance, and the user operation information is uploaded to the chain.

其中,多线程工作队列工作方式,参照以下公式:Among them, the multi-threaded work queue working method refers to the following formula:

其中,f(i)代表多线程工作队列的效率因子结果,i代表多线程任务个数,m代表多线程池的使用率,β代表服务器机器CPU性能利用率,δ代表每次上链的文本量,hcost代表每次上链存证的耗时。Among them, f (i) represents the efficiency factor result of the multi-threaded work queue, i represents the number of multi-threaded tasks, m represents the usage of the multi-thread pool, β represents the server machine CPU performance utilization, and δ represents the text uploaded each time. The amount, h cost represents the time it takes to upload the certificate each time.

其中, in,

这里涉及的是多线程池的工作原理,ω(i,m)表示多线程使用率,P表示CPU的可用核心数,当时创建线程i小于p时,线程队列并不进行创建;当创建线程i大于p,线程队列进行创建。这里表达的含义是当i小于p时,效率可以达到最大值,而当i大于p,则呈现分子函数形式进行效率递减。What is involved here is the working principle of the multi-thread pool. ω(i,m) represents the multi-thread usage rate, and P represents the number of available cores of the CPU. When the created thread i is less than p, the thread queue is not created; when the thread i is created Greater than p, a thread queue is created. The meaning expressed here is that when i is less than p, the efficiency can reach the maximum value, and when i is greater than p, the efficiency decreases in the form of a molecular function.

其中, in,

其中,表示内存使用情况和利用率,其中N代表一个大于0的常数,i为线程数,sigmoid(i)为激活函数(由于i大于0,其取值在0.5~1之间),V代表java服务虚拟机设置的内存大小。in, Indicates memory usage and utilization, where N represents a constant greater than 0, i is the number of threads, sigmoid(i) is the activation function (since i is greater than 0, its value is between 0.5 and 1), and V represents the java service The memory size set by the virtual machine.

其中, in,

其中,分子函数中Among them, in the numerator function

其中,τ(i,hcost)表示多个线程上链时对应的延时:,h(n)表示第n次区块链平台消耗的时间值,通过累积法后进行平均求和。Among them, τ(i,h cost ) represents the corresponding delay when multiple threads are uploaded to the chain: h (n) represents the time value consumed by the n-th blockchain platform, which is averaged and summed through the accumulation method.

其中,分子函数中 Among them, in the numerator function

其中,γ(i,δ)表示文本请求体大小,δ(n)表示第n次安全存证平台向区块链平台上传的文本数量,通过累积法后进行平均求和。Among them, γ (i, δ) represents the size of the text request body, and δ (n) represents the number of texts uploaded by the secure certificate platform to the blockchain platform for the nth time, and is averaged and summed through the accumulation method.

其中,多线程的编排方式,设施一个工作队列模式,其中服务A侧扮演消费者角色,当每次任务请求时,则将相关的参数进行封装,推送进工作队列,根据公平原则,工作流为“先进先出”,另一个服务群体B则扮演消费者的角色,当工作队列存在工作任务时,进行唤醒,服务群体进行分片消费;工作队列不存在工作任务时,服务群体B则进入沉睡,等到工作队列唤醒。Among them, the multi-threaded orchestration method implements a work queue mode, in which the service A side plays the role of consumer. When each task request is made, the relevant parameters are encapsulated and pushed into the work queue. According to the principle of fairness, the workflow is "First in, first out", another service group B plays the role of a consumer. When there are work tasks in the work queue, it wakes up and the service group consumes in slices; when there are no work tasks in the work queue, service group B goes to sleep. , wait until the work queue wakes up.

其中,效率因子代表多线程工作效率因子,它表示多线程状态下,批量授权token校验鉴权的执行的效率,其中呈现正相关和负相关的参数,与非多线程工作流的批量token校验相比,效率因子可以看出在何种情况使用多线程工作流,何种情况下使用非多线程工作流。在对正常稳健的服务进行多次试验之后,根据加权平均可以设置一个阈值阈值/>受服务机器内存,CPU核数等相关参数影响,倘若:Among them, the efficiency factor represents the multi-threaded work efficiency factor, which represents the efficiency of the execution of batch authorization token verification and authentication in the multi-threaded state. There are positive and negative correlation parameters, which are different from the batch token verification of non-multi-threaded workflows. Compared with the experiment, the efficiency factor can tell under what circumstances a multi-threaded workflow is used and under what circumstances a non-multi-threaded workflow is used. After many experiments with a normally robust service, a threshold can be set based on a weighted average Threshold/> Affected by related parameters such as service machine memory, CPU core number, etc., if:

则效率因子有效,可以使用多线程工作流的工作模式,倘若,Then the efficiency factor is valid and the multi-threaded workflow working mode can be used. If,

则多线程工作流方式不适用本个业务场景,应选取非多线程工作流模式。Then the multi-threaded workflow mode is not suitable for this business scenario, and the non-multi-threaded workflow mode should be selected.

其中,授权相关上链信息中主要强调业务方的流程信息,而鉴权相关上链信息中更加强调能力方的流程信息。Among them, the authorization-related uplink information mainly emphasizes the process information of the business side, while the authentication-related uplink information emphasizes the process information of the capable party.

在一些实施例中,进行区块链存证之前,还包括:In some embodiments, before performing blockchain certification, it also includes:

通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息;基于提取的所述秘钥对信息,验证所述运营商认证服务端与所述区块链平台之间的密钥一致性。利用短期信道互易性和随机性来提取秘密加密共享密钥,进一步加强安全存证的可靠性。Extract the secret key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs through the channel phase response key extraction algorithm; verify the operator authentication service based on the extracted secret key pair information Key consistency between the client and the blockchain platform. The short-term channel reciprocity and randomness are used to extract the secret encryption shared key to further enhance the reliability of secure certificates.

其中,密钥信道通道的信息响应,经历了三个主要阶段,即量化、信息协调和信息提取。其中量化阶段是将通道分量转换为位流的映射操作。而信息协调阶段是一个纠错阶段,涉及纠正由不完美的通道互易性导致的不匹配位。最后阶段的信息提取则是利用哈希操作来维护提取密钥的机密性。通过信息间信息的转化传后,进行数据信息滤波去噪,最终进行逆转化得到目标信息。Among them, the information response of the key channel channel has gone through three main stages, namely quantification, information coordination and information extraction. The quantization stage is a mapping operation that converts channel components into bit streams. The information coordination phase is an error correction phase that involves correcting mismatched bits caused by imperfect channel reciprocity. The final stage of information extraction uses hashing operations to maintain the confidentiality of the extraction key. After the information is converted and transmitted, the data information is filtered and denoised, and finally reverse transformation is performed to obtain the target information.

下面对信道相位响应密钥提取算法包括如下内容:The following channel phase response key extraction algorithm includes the following contents:

1、在运营商认证服务端与区块链平台交互过程中,密钥对在传输过程中可以二进制编码进行量化为:1. During the interaction between the operator authentication server and the blockchain platform, the key pair can be quantified in binary encoding during transmission as:

Fn(secret)F n (secret)

2、当运营商认证服务端向区块链平台发送密钥数据包PV1时,在时间T1中频域信息可以表示为:2. When the operator authentication server sends the key data packet PV 1 to the blockchain platform, the frequency domain information at time T 1 can be expressed as:

其中,是均匀分布的相位,由于在间隔区间[0,2π)中,可以得知区块链收到的信息RV12为:in, is a uniformly distributed phase. Since in the interval [0, 2π), it can be known that the information RV 12 received by the blockchain is:

其中,σ1(t)表示为高斯白噪声,α1和θ1是正向链路通道增益和相位响应。最后区块链平台收到的噪声相位可以近似为 Among them, σ 1 (t) represents Gaussian white noise, α 1 and θ 1 are the forward link channel gain and phase response. Finally, the noise phase received by the blockchain platform can be approximated as

3、相同的道理,区块链平台向运营商认证服务端发送的信息数据包PV2,在时间T2中频域信息可以表示:3. In the same way, the information packet PV 2 sent by the blockchain platform to the operator authentication server at time T 2 can be represented by the frequency domain information:

其中,是均匀分布的相位,由于在间隔区间[0,2π)中,可以得知运营商服务端收到的信息RV21in, is a uniformly distributed phase. Since in the interval [0, 2π), it can be known that the information RV 21 received by the operator's server is

其中,σ2(t)表示为高斯白噪声,α2和θ2是正向链路通道增益和相位响应。最后区块链平台收到的噪声相位可以近似为 Among them, σ 2 (t) represents Gaussian white noise, α 2 and θ 2 are the forward link channel gain and phase response. Finally, the noise phase received by the blockchain platform can be approximated as

4、由上述2和3内容中,可以得到运营商认证服务端和区块链平台的最后阶段分量为:4. From the above 2 and 3, the final stage components of the operator authentication server and blockchain platform can be obtained:

其中,时间间隔区间都为[0,2π)。Among them, the time intervals are all [0, 2π).

5、由于RV12(t)和RV21(t)都存在着相关的噪声信息量,此处需要通过滤波器对其进行数据去噪,数据去噪滤波器(曲线拟合)如下:5. Since both RV 12 (t) and RV 21 (t) have relevant noise information, it is necessary to use a filter to denoise the data. The data denoising filter (curve fitting) is as follows:

其中,Fk为加权系数,基函数为旋转因子,在函数Fk中进行阈值设置,即可进行数据去噪拟合。Among them, F k is the weighting coefficient, and the basis function is the rotation factor, and the threshold is set in the function F k to perform data denoising and fitting.

6、经过数据拟合去噪的流程之后,运营商认证服务端和区块链平台对密钥对信息进行反编码逆量化可以得到对应的信息值。6. After the data fitting and denoising process, the operator authentication server and the blockchain platform decode and inverse the key pair information to obtain the corresponding information value.

在一些实施例中,基于所述区块链,接收受信任的第三方发布的包含校正序列的不匹配位;基于所述第三方发布的包含校正序列的不匹配位,通过信道相位响应密钥提取算法,从所述区块链平台发送的秘钥数据包中提取秘钥对信息;其中,所述授权凭证作为所述运营商认证服务端与所述区块链平台之间的整个会话的临时可信度证明。In some embodiments, based on the blockchain, receiving mismatched bits containing a correction sequence published by a trusted third party; based on the mismatched bits containing a correction sequence published by the third party, responding to a key through a channel phase Extraction algorithm: extract key pair information from the secret key data packet sent by the blockchain platform; wherein the authorization certificate serves as the key to the entire session between the operator authentication server and the blockchain platform. Provisional Certificate of Credibility.

可以理解为,为了进一步解决信道相位方法仅能协调少数不匹配位,导致安全性上存在着一定的风险的问题。以及,编码中的低密度奇偶校验法和涡轮码,也存在着计算复杂度高的问题。本方案中,还可以进一步设计一种基于区块链的协调技术来解决这些限制,该技术允许受信任的第三方通过发布包含校正序列的不匹配位,使用基于智能合约的区块链技术。已发布的用户号码认证信息作为整个会话的临时可信度证明,而不是每次都传输证书,从而节省通信成本和存储容量。It can be understood that, in order to further solve the problem that the channel phase method can only coordinate a few mismatched bits, there is a certain risk in security. In addition, the low-density parity check method and turbo code in encoding also have the problem of high computational complexity. In this scenario, a blockchain-based coordination technology can be further designed to address these limitations, which allows a trusted third party to use smart contract-based blockchain technology by publishing mismatched bits containing correction sequences. The published user number authentication information serves as a temporary proof of trustworthiness for the entire session, rather than transmitting the certificate each time, thus saving communication costs and storage capacity.

本申请实施例的安全认证方法,在通过网关取号之后,通过授权和鉴权过程实现安全认证,并通过区块链对用户登录应用时进行安全认证的相关信息进行存证和出证,保证用户操作的不可抵赖性,确保登录的有迹可循,实现了基于用户本机手机号码取号校验,同时进行区块链存证出证不可抵赖格式的安全账户登录方式,提升了用户的登录安全性和便捷性。运营商认证服务端采用多线程工作流形式进行提供认证服务,在一定程度上提升了服务性能。运营商认证服务端和区块链平台通过引入基于信道相位响应的密钥提取算法,用于验证通信双方之间的密钥一致性,利用短期信道互易性和随机性来提取秘密加密共享密钥,进一步加强安全存证的可靠性。The security authentication method in the embodiment of this application implements security authentication through the authorization and authentication process after obtaining the number through the gateway, and uses the blockchain to store and issue relevant information for security authentication when the user logs in to the application, ensuring that The non-repudiation of user operations ensures that the login is traceable. It implements a secure account login method based on the user's local mobile phone number and a non-repudiation format for blockchain certificate storage and issuance, which improves the user's security. Login security and convenience. The operator authentication server uses a multi-threaded workflow to provide authentication services, which improves service performance to a certain extent. The operator authentication server and blockchain platform introduce a key extraction algorithm based on channel phase response to verify the key consistency between communicating parties, and use short-term channel reciprocity and randomness to extract secret encryption shared keys. key to further enhance the reliability of secure certificate storage.

图4是根据一示例性实施例示出的一种安全认证装置的框图,该装置配置于运营商认证服务端。参照图4,该安全认证装置可以包括:取号处理模块401、授权处理模块402和鉴权处理模块403。Figure 4 is a block diagram of a security authentication device according to an exemplary embodiment. The device is configured at an operator authentication server. Referring to FIG. 4 , the security authentication device may include: a number processing module 401 , an authorization processing module 402 and an authentication processing module 403 .

具体地,取号处理模块401,用于接收来自终端应用的取号请求,向所述终端应用返回对应终端的本机手机号码;Specifically, the number retrieval processing module 401 is used to receive a number retrieval request from a terminal application, and return the local mobile phone number of the corresponding terminal to the terminal application;

授权处理模块402,用于接收所述终端应用基于所述本机手机号码发送的授权请求,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证;The authorization processing module 402 is used to receive the authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application and store the authorization-related information in the blockchain;

鉴权处理模块403,用于接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证;其中,所述鉴权结果用于指示所述终端应用是否允许对应的终端用户登录所述终端应用。The authentication processing module 403 is configured to receive an authentication request carrying an authorization certificate sent by the terminal application, return the authentication result, and store the authentication-related information in the blockchain; wherein the authentication result is used to indicate Whether the terminal application allows the corresponding terminal user to log in to the terminal application.

在一些实现方式中,鉴权处理模块403,具体用于:In some implementations, the authentication processing module 403 is specifically used to:

接收第三方能力方发送的携带所述终端应用发送的授权凭证的鉴权请求;Receive an authentication request sent by a third-party capable party carrying the authorization certificate sent by the terminal application;

对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证。The authorization certificate sent by the terminal application is verified and authenticated, the authentication result is returned to the third-party capable party, and the authentication-related information is stored in the blockchain.

在一些实现方式中,鉴权处理模块403对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证时,具体用于:In some implementations, the authentication processing module 403 verifies and authenticates the authorization certificate sent by the terminal application, returns the authentication result to the third-party capable party, and stores the authentication-related information in the blockchain. , specifically used for:

通过多线程工作流队列的形式,对多个终端应用发送的授权凭证进行校验鉴权;Verify and authenticate authorization credentials sent by multiple terminal applications in the form of multi-threaded workflow queues;

通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Multiple authentication-related information is stored in the blockchain in the form of a multi-threaded workflow queue.

在一些实现方式中,鉴权处理模块403,还用于:In some implementations, the authentication processing module 403 is also used to:

基于所述运营商认证服务端的资源利用率和多个所述鉴权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authentication-related information;

基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Based on the multi-thread work efficiency factor and the preset threshold, it is determined whether to store multiple authentication-related information in the blockchain in the form of a multi-thread workflow queue.

在一些实现方式中,所述授权处理模块402,具体用于:In some implementations, the authorization processing module 402 is specifically used to:

基于所述运营商认证服务端的资源利用率和多个所述授权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authorization-related information;

基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个授权相关信息存储于区块链;Based on the multi-thread work efficiency factor and the preset threshold, determine whether to store multiple authorization-related information in the blockchain in the form of a multi-thread workflow queue;

在确定之后,通过多线程工作流队列的形式,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证。After the determination, the authorization certificate is sent to the terminal application in the form of a multi-threaded workflow queue and the authorization-related information is stored in the blockchain.

在一些实现方式中,该装置还包括秘钥管理模块404,用于:In some implementations, the device also includes a key management module 404 for:

通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息;Extract the secret key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs through the channel phase response key extraction algorithm;

基于提取的所述秘钥对信息,验证所述运营商认证服务端与所述区块链平台之间的密钥一致性。Based on the extracted key pair information, the key consistency between the operator authentication server and the blockchain platform is verified.

在一些实现方式中,秘钥管理模块404通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息时,具体用于:In some implementations, the key management module 404 uses the channel phase response key extraction algorithm to extract key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs, specifically for:

基于所述区块链,接收受信任的第三方发布的包含校正序列的不匹配位;Based on the blockchain, receive mismatched bits containing correction sequences published by a trusted third party;

基于所述第三方发布的包含校正序列的不匹配位,通过信道相位响应密钥提取算法,从所述区块链平台发送的秘钥数据包中提取秘钥对信息;其中,所述授权凭证作为所述运营商认证服务端与所述区块链平台之间的整个会话的临时可信度证明。Based on the mismatched bits containing the correction sequence issued by the third party, the secret key pair information is extracted from the secret key data packet sent by the blockchain platform through the channel phase response key extraction algorithm; wherein, the authorization certificate As a temporary credibility certificate for the entire session between the operator authentication server and the blockchain platform.

关于上述实施例中的装置,其中各个模块执行操作的具体方式已经在有关该方法的实施例中进行了详细描述,此处将不做详细阐述说明。Regarding the devices in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be described in detail here.

本申请实施例的安全认证装置,在通过网关取号之后,通过授权和鉴权过程实现安全认证,并通过区块链对用户登录应用时进行安全认证的相关信息进行存证和出证,保证用户操作的不可抵赖性,确保登录的有迹可循,实现了基于用户本机手机号码取号校验,同时进行区块链存证出证不可抵赖格式的安全账户登录方式,提升了用户的登录安全性和便捷性。运营商认证服务端采用多线程工作流形式进行提供认证服务,在一定程度上提升了服务性能。运营商认证服务端和区块链平台通过引入基于信道相位响应的密钥提取算法,用于验证通信双方之间的密钥一致性,利用短期信道互易性和随机性来提取秘密加密共享密钥,进一步加强安全存证的可靠性。The security authentication device in the embodiment of this application implements security authentication through the authorization and authentication process after obtaining the number through the gateway, and stores and issues relevant information for security authentication when the user logs in to the application through the blockchain, ensuring that The non-repudiation of user operations ensures that the login is traceable. It implements a secure account login method based on the user's local mobile phone number and a non-repudiation format for blockchain certificate storage and issuance, which improves the user's security. Login security and convenience. The operator authentication server uses a multi-threaded workflow to provide authentication services, which improves service performance to a certain extent. The operator authentication server and blockchain platform introduce a key extraction algorithm based on channel phase response to verify the key consistency between the communicating parties and use short-term channel reciprocity and randomness to extract the secret encryption shared key. key to further enhance the reliability of secure certificate storage.

图5是根据一示例性实施例示出的一种安全认证装置的框图,该装置配置于终端。参照图5,该安全认证装置可以包括:取号模块501、校验模块502、凭证申请模块503和认证处理模块504。Figure 5 is a block diagram of a security authentication device according to an exemplary embodiment. The device is configured on a terminal. Referring to FIG. 5 , the security authentication device may include: a number taking module 501 , a verification module 502 , a certificate application module 503 and an authentication processing module 504 .

具体地,取号模块501,用于响应于终端应用启动操作,通过网关取号,获取本机手机号码;Specifically, the number retrieval module 501 is used to obtain the local mobile phone number through the gateway in response to the terminal application startup operation;

校验模块502,用于基于所述本机手机号码与用户输入的手机号码,进行本机号码校验;The verification module 502 is used to perform local number verification based on the local mobile phone number and the mobile phone number input by the user;

凭证申请模块503,用于校验通过后,向运营商认证服务端发送授权请求,并接收所述运营商认证服务端基于所述授权请求返回的授权凭证;其中,所述运营商认证服务端返回所述授权凭证的同时将授权相关信息进行区块链存证;The certificate application module 503 is used to send an authorization request to the operator authentication server after passing the verification, and receive the authorization certificate returned by the operator authentication server based on the authorization request; wherein, the operator authentication server While returning the authorization certificate, the authorization-related information will be stored in the blockchain;

认证处理模块504,用于向第三方能力方发送所述授权凭证,指示所述第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验,并接收所述第三方能力方返回的鉴权结果;其中,所述运营商认证服务端返回所述鉴权结果的同时将鉴权相关信息进行区块链存证;The authentication processing module 504 is configured to send the authorization voucher to the third-party capable party, instruct the third-party capable party to send the authorization voucher to the operator authentication server for authentication verification, and receive the third party. The authentication result returned by the third-party capable party; wherein, the operator authentication server returns the authentication result and at the same time stores the authentication-related information in the blockchain;

认证处理模块505,还用于基于所述鉴权结果,获取所述终端应用的登录授权。The authentication processing module 505 is also configured to obtain the login authorization of the terminal application based on the authentication result.

在一些实现方式中,取号模块501,具体用于:In some implementations, the number taking module 501 is specifically used for:

通过运营商认证SDK,向所述运营商认证服务端发送手机号凭证申请;Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK;

获取所述运营商认证服务端基于所述手机号凭证申请返回的手机号凭证;Obtain the mobile phone number certificate returned by the operator authentication server based on the mobile phone number certificate application;

基于所述手机号凭证,通过所述运营商认证SDK向所述运营商认证服务端发送取号凭证申请;Based on the mobile phone number certificate, send a number certificate application to the operator authentication server through the operator authentication SDK;

获取所述运营商认证服务端基于所述取号凭证申请返回的取号凭证;Obtain the number-taking certificate returned by the operator authentication server based on the number-taking certificate application;

基于所述取号凭证,通过所述终端应用对应的应用后端服务,从所述运营商服务端获取本机手机号码。Based on the number retrieval certificate, the local mobile phone number is obtained from the operator server through the application backend service corresponding to the terminal application.

关于上述实施例中的装置,其中各个模块执行操作的具体方式已经在有关该方法的实施例中进行了详细描述,此处将不做详细阐述说明。Regarding the devices in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be described in detail here.

本申请实施例的安全认证装置,网关取号之后,通过授权和鉴权过程实现安全认证,并通过区块链对用户登录应用时进行安全认证的相关信息进行存证和出证,保证用户操作的不可抵赖性,确保登录的有迹可循,实现了基于用户本机手机号码取号校验,同时进行区块链存证出证不可抵赖格式的安全账户登录方式,提升了用户的登录安全性和便捷性。In the security authentication device of the embodiment of this application, after the gateway obtains the number, security authentication is implemented through the authorization and authentication process, and the relevant information for security authentication when the user logs in to the application is stored and issued through the blockchain to ensure user operations. The non-repudiation ensures that the login is traceable. It implements a secure account login method based on the user's local mobile phone number and a non-repudiation format for blockchain certificate storage and issuance, which improves the user's login security. sex and convenience.

根据本申请的实施例,本申请还提供了一种电子设备和一种可读存储介质。According to embodiments of the present application, the present application also provides an electronic device and a readable storage medium.

如图6所示,是根据本申请实施例的用于实现安全认证的方法的电子设备的框图。电子设备旨在表示各种形式的数字计算机,诸如,膝上型计算机、台式计算机、工作台、个人数字助理、服务器、刀片式服务器、大型计算机、和其它适合的计算机。电子设备还可以表示各种形式的移动装置,诸如,个人数字处理、蜂窝电话、智能电话、可穿戴设备和其它类似的计算装置。本文所示的部件、它们的连接和关系、以及它们的功能仅仅作为示例,并且不意在限制本文中描述的和/或者要求的本申请的实现。As shown in Figure 6, it is a block diagram of an electronic device used to implement a security authentication method according to an embodiment of the present application. Electronic devices are intended to refer to various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are examples only and are not intended to limit the implementation of the present application as described and/or claimed herein.

如图6所示,该电子设备包括:一个或多个处理器601、存储器602,以及用于连接各部件的接口,包括高速接口和低速接口。各个部件利用不同的总线互相连接,并且可以被安装在公共主板上或者根据需要以其它方式安装。处理器可以对在电子设备内执行的指令进行处理,包括存储在存储器中或者存储器上以在外部输入/输出装置(诸如,耦合至接口的显示设备)上显示GUI的图形信息的指令。在其它实施方式中,若需要,可以将多个处理器和/或多条总线与多个存储器和多个存储器一起使用。同样,可以连接多个电子设备,各个设备提供部分必要的操作(例如,作为服务器阵列、一组刀片式服务器、或者多处理器系统)。图6中以一个处理器601为例。As shown in Figure 6, the electronic device includes: one or more processors 601, memory 602, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses and can be mounted on a common motherboard or otherwise mounted as desired. The processor may process instructions executed within the electronic device, including instructions stored in or on memory to display graphical information of the GUI on an external input/output device, such as a display device coupled to the interface. In other embodiments, multiple processors and/or multiple buses may be used with multiple memories and multiple memories, if desired. Likewise, multiple electronic devices can be connected, each device providing part of the necessary operation (eg, as a server array, a set of blade servers, or a multi-processor system). In Figure 6, a processor 601 is taken as an example.

存储器602即为本申请所提供的非瞬时计算机可读存储介质。其中,所述存储器存储有可由至少一个处理器执行的指令,以使所述至少一个处理器执行本申请所提供的安全认证的方法。本申请的非瞬时计算机可读存储介质存储计算机指令,该计算机指令用于使计算机执行本申请所提供的安全认证的方法。The memory 602 is the non-transitory computer-readable storage medium provided by this application. The memory stores instructions executable by at least one processor, so that the at least one processor executes the security authentication method provided by this application. The non-transitory computer-readable storage medium of this application stores computer instructions, which are used to cause the computer to execute the security authentication method provided by this application.

存储器602作为一种非瞬时计算机可读存储介质,可用于存储非瞬时软件程序、非瞬时计算机可执行程序以及模块,如本申请实施例中的安全认证的方法对应的程序指令/模块(例如,附图4所示的取号处理模块401、授权处理模块402和鉴权处理模块403)。处理器601通过运行存储在存储器602中的非瞬时软件程序、指令以及模块,从而执行服务器的各种功能应用以及数据处理,即实现上述方法实施例中的安全认证的方法。As a non-transitory computer-readable storage medium, the memory 602 can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions/modules corresponding to the security authentication method in the embodiment of the present application (for example, The number processing module 401, authorization processing module 402 and authentication processing module 403 shown in Figure 4). The processor 601 executes various functional applications and data processing of the server by running non-transient software programs, instructions and modules stored in the memory 602, that is, the method of implementing the security authentication in the above method embodiment.

存储器602可以包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需要的应用程序;存储数据区可存储根据安全认证的电子设备的使用所创建的数据等。此外,存储器602可以包括高速随机存取存储器,还可以包括非瞬时存储器,例如至少一个磁盘存储器件、闪存器件、或其他非瞬时固态存储器件。在一些实施例中,存储器602可选包括相对于处理器601远程设置的存储器,这些远程存储器可以通过网络连接至安全认证的电子设备。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。The memory 602 may include a stored program area and a stored data area, where the stored program area may store an operating system and an application program required for at least one function; the stored data area may store data created according to the use of a security-certified electronic device, etc. In addition, memory 602 may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory 602 optionally includes memory located remotely relative to processor 601, and these remote memories may be connected to securely authenticated electronic devices through a network. Examples of the above-mentioned networks include but are not limited to the Internet, intranets, local area networks, mobile communication networks and combinations thereof.

安全认证的方法的电子设备还可以包括:输入装置603和输出装置604。处理器601、存储器602、输入装置603和输出装置604可以通过总线或者其他方式连接,图6中以通过总线连接为例。The electronic device of the security authentication method may also include: an input device 603 and an output device 604. The processor 601, the memory 602, the input device 603 and the output device 604 can be connected through a bus or other means. In Figure 6, connection through a bus is taken as an example.

输入装置603可接收输入的数字或字符信息,以及产生与安全认证的电子设备的用户设置以及功能控制有关的键信号输入,例如触摸屏、小键盘、鼠标、轨迹板、触摸板、指示杆、一个或者多个鼠标按钮、轨迹球、操纵杆等输入装置。输出装置604可以包括显示设备、辅助照明装置(例如,LED)和触觉反馈装置(例如,振动电机)等。该显示设备可以包括但不限于,液晶显示器(LCD)、发光二极管(LED)显示器和等离子体显示器。在一些实施方式中,显示设备可以是触摸屏。The input device 603 can receive input numeric or character information, and generate key signal input related to user settings and function control of a security-certified electronic device, such as a touch screen, a keypad, a mouse, a trackpad, a touch pad, a pointing stick, a Or multiple mouse buttons, trackballs, joysticks and other input devices. Output devices 604 may include display devices, auxiliary lighting devices (eg, LEDs), tactile feedback devices (eg, vibration motors), and the like. The display device may include, but is not limited to, a liquid crystal display (LCD), a light emitting diode (LED) display, and a plasma display. In some implementations, the display device may be a touch screen.

此处描述的系统和技术的各种实施方式可以在数字电子电路系统、集成电路系统、专用ASIC(专用集成电路)、计算机硬件、固件、软件、和/或它们的组合中实现。这些各种实施方式可以包括:实施在一个或者多个计算机程序中,该一个或者多个计算机程序可在包括至少一个可编程处理器的可编程系统上执行和/或解释,该可编程处理器可以是专用或者通用可编程处理器,可以从存储系统、至少一个输入装置、和至少一个输出装置接收数据和指令,并且将数据和指令传输至该存储系统、该至少一个输入装置、和该至少一个输出装置。Various implementations of the systems and techniques described herein may be implemented in digital electronic circuitry, integrated circuit systems, application specific ASICs (application specific integrated circuits), computer hardware, firmware, software, and/or combinations thereof. These various embodiments may include implementation in one or more computer programs executable and/or interpreted on a programmable system including at least one programmable processor, the programmable processor The processor, which may be a special purpose or general purpose programmable processor, may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device. An output device.

这些计算程序(也称作程序、软件、软件应用、或者代码)包括可编程处理器的机器指令,并且可以利用高级过程和/或面向对象的编程语言、和/或汇编/机器语言来实施这些计算程序。如本文使用的,术语“机器可读介质”和“计算机可读介质”指的是用于将机器指令和/或数据提供给可编程处理器的任何计算机程序产品、设备、和/或装置(例如,磁盘、光盘、存储器、可编程逻辑装置(PLD)),包括,接收作为机器可读信号的机器指令的机器可读介质。术语“机器可读信号”指的是用于将机器指令和/或数据提供给可编程处理器的任何信号。These computing programs (also referred to as programs, software, software applications, or code) include machine instructions for programmable processors, and may be implemented using high-level procedural and/or object-oriented programming languages, and/or assembly/machine language Calculation program. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and/or means for providing machine instructions and/or data to a programmable processor ( For example, magnetic disks, optical disks, memories, programmable logic devices (PLD)), including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal used to provide machine instructions and/or data to a programmable processor.

为了提供与用户的交互,可以在计算机上实施此处描述的系统和技术,该计算机具有:用于向用户显示信息的显示装置(例如,CRT(阴极射线管)或者LCD(液晶显示器)监视器);以及键盘和指向装置(例如,鼠标或者轨迹球),用户可以通过该键盘和该指向装置来将输入提供给计算机。其它种类的装置还可以用于提供与用户的交互;例如,提供给用户的反馈可以是任何形式的传感反馈(例如,视觉反馈、听觉反馈、或者触觉反馈);并且可以用任何形式(包括声输入、语音输入或者、触觉输入)来接收来自用户的输入。To provide interaction with a user, the systems and techniques described herein may be implemented on a computer having a display device (eg, a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user ); and a keyboard and pointing device (eg, a mouse or a trackball) through which a user can provide input to the computer. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and may be provided in any form, including Acoustic input, voice input or tactile input) to receive input from the user.

可以将此处描述的系统和技术实施在包括后台部件的计算系统(例如,作为数据服务器)、或者包括中间件部件的计算系统(例如,应用服务器)、或者包括前端部件的计算系统(例如,具有图形用户界面或者网络浏览器的用户计算机,用户可以通过该图形用户界面或者该网络浏览器来与此处描述的系统和技术的实施方式交互)、或者包括这种后台部件、中间件部件、或者前端部件的任何组合的计算系统中。可以通过任何形式或者介质的数字数据通信(例如,通信网络)来将系统的部件相互连接。通信网络的示例包括:局域网(LAN)、广域网(WAN)和互联网。The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., A user's computer having a graphical user interface or web browser through which the user can interact with implementations of the systems and technologies described herein), or including such backend components, middleware components, or any combination of front-end components in a computing system. The components of the system may be interconnected by any form or medium of digital data communication (eg, a communications network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

计算机系统可以包括客户端和服务器。客户端和服务器一般远离彼此并且通常通过通信网络进行交互。通过在相应的计算机上运行并且彼此具有客户端-服务器关系的计算机程序来产生客户端和服务器的关系。Computer systems may include clients and servers. Clients and servers are generally remote from each other and typically interact over a communications network. A client and server relationship is created by computer programs running on corresponding computers and having a client-server relationship with each other.

在示例性实施例中,还提供了一种计算机程序产品,当计算机程序产品中的指令由电子设备的处理器执行时,使得电子设备能够执行上述方法。In an exemplary embodiment, a computer program product is also provided. When instructions in the computer program product are executed by a processor of the electronic device, the electronic device can perform the above method.

还需要说明的是,本发明中提及的示例性实施例,基于一系列的步骤或者装置描述一些方法或系统。但是,本发明不局限于上述步骤的顺序,也就是说,可以按照实施例中提及的顺序执行步骤,也可以不同于实施例中的顺序,或者若干步骤同时执行。It should also be noted that the exemplary embodiments mentioned in the present invention describe some methods or systems based on a series of steps or devices. However, the present invention is not limited to the order of the above steps. That is to say, the steps may be performed in the order mentioned in the embodiments, or may be different from the order in the embodiments, or several steps may be performed simultaneously.

本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本申请的其它实施方案。本申请旨在涵盖本申请的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本申请的一般性原理并包括本申请未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的。Other embodiments of the present application will be readily apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary technical means in the technical field that are not disclosed in this application. . The specification and examples are to be considered as illustrative only.

应当理解的是,本申请并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本申请的范围仅由所附的权利要求来限制。It is to be understood that the present application is not limited to the precise structures described above and illustrated in the accompanying drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the application is limited only by the appended claims.

Claims (13)

1.一种安全认证方法,其特征在于,所述安全认证方法应用于运营商认证服务端,包括:1. A security authentication method, characterized in that the security authentication method is applied to the operator authentication server, including: 接收来自终端应用的取号请求,向所述终端应用返回对应终端的本机手机号码;Receive a number request from the terminal application, and return the local mobile phone number of the corresponding terminal to the terminal application; 接收所述终端应用基于所述本机手机号码发送的授权请求,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证;Receive the authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application and store the authorization-related information in the blockchain; 接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证;其中,所述鉴权结果用于指示所述终端应用是否允许对应的终端用户登录所述终端应用。Receive an authentication request carrying the authorization certificate sent by the terminal application, return the authentication result and store the authentication-related information in the blockchain; wherein the authentication result is used to indicate whether the terminal application allows the corresponding The terminal user logs in to the terminal application. 2.根据权利要求1所述的方法,其特征在于,所述接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证,包括:2. The method according to claim 1, characterized in that receiving an authentication request carrying an authorization certificate sent by the terminal application, returning the authentication result and storing the authentication-related information in the blockchain includes: : 接收第三方能力方发送的携带所述终端应用发送的授权凭证的鉴权请求;Receive an authentication request sent by a third-party capable party carrying the authorization certificate sent by the terminal application; 对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证。The authorization certificate sent by the terminal application is verified and authenticated, the authentication result is returned to the third-party capable party, and the authentication-related information is stored in the blockchain. 3.根据权利要求2所述的方法,其特征在于,所述对所述终端应用发送的授权凭证进行校验鉴权,向所述第三方能力方返回鉴权结果并将鉴权相关信息进行区块链存证,包括:3. The method according to claim 2, characterized in that the authorization certificate sent by the terminal application is verified and authenticated, the authentication result is returned to the third party capable party and the authentication-related information is Blockchain certificates include: 通过多线程工作流队列的形式,对多个终端应用发送的授权凭证进行校验鉴权;Verify and authenticate authorization credentials sent by multiple terminal applications in the form of multi-threaded workflow queues; 通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Multiple authentication-related information is stored in the blockchain in the form of a multi-threaded workflow queue. 4.根据权利要求3所述的方法,其特征在于,所述通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链之前,还包括:4. The method according to claim 3, characterized in that storing multiple authentication-related information before the blockchain in the form of a multi-threaded workflow queue also includes: 基于所述运营商认证服务端的资源利用率和多个所述鉴权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authentication-related information; 基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个鉴权相关信息存储于区块链。Based on the multi-thread work efficiency factor and the preset threshold, it is determined whether to store multiple authentication-related information in the blockchain in the form of a multi-thread workflow queue. 5.根据权利要求1所述的方法,其特征在于,所述向所述终端应用发送授权凭证并将授权相关信息进行区块链存证,包括:5. The method according to claim 1, characterized in that said sending an authorization certificate to the terminal application and storing the authorization-related information on a blockchain includes: 基于所述运营商认证服务端的资源利用率和多个所述授权相关信息对应的上链任务量,获取多线程工作效率因子;Obtain a multi-thread work efficiency factor based on the resource utilization of the operator authentication server and the amount of uplink tasks corresponding to multiple authorization-related information; 基于所述多线程工作效率因子和预设阈值,确定是否通过多线程工作流队列的形式,将多个授权相关信息存储于区块链;Based on the multi-thread work efficiency factor and the preset threshold, determine whether to store multiple authorization-related information in the blockchain in the form of a multi-thread workflow queue; 在确定之后,通过多线程工作流队列的形式,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证。After the determination, the authorization certificate is sent to the terminal application in the form of a multi-threaded workflow queue and the authorization-related information is stored in the blockchain. 6.根据权利要求1所述的方法,其特征在于,所述进行区块链存证之前,还包括:6. The method according to claim 1, characterized in that before performing blockchain certification, it further includes: 通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息;Extract the secret key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs through the channel phase response key extraction algorithm; 基于提取的所述秘钥对信息,验证所述运营商认证服务端与所述区块链平台之间的密钥一致性。Based on the extracted key pair information, the key consistency between the operator authentication server and the blockchain platform is verified. 7.根据权利要求6所述的方法,其特征在于,所述通过信道相位响应密钥提取算法,从所述区块链所属区块链平台发送的秘钥数据包中提取秘钥对信息,包括:7. The method according to claim 6, characterized in that the channel phase response key extraction algorithm extracts key pair information from the secret key data packet sent by the blockchain platform to which the blockchain belongs, include: 基于所述区块链,接收受信任的第三方发布的包含校正序列的不匹配位;Based on the blockchain, receive mismatched bits containing correction sequences published by a trusted third party; 基于所述第三方发布的包含校正序列的不匹配位,通过信道相位响应密钥提取算法,从所述区块链平台发送的秘钥数据包中提取秘钥对信息;其中,所述授权凭证作为所述运营商认证服务端与所述区块链平台之间的整个会话的临时可信度证明。Based on the mismatched bits containing the correction sequence issued by the third party, the secret key pair information is extracted from the secret key data packet sent by the blockchain platform through the channel phase response key extraction algorithm; wherein, the authorization certificate As a temporary credibility certificate for the entire session between the operator authentication server and the blockchain platform. 8.一种安全认证方法,其特征在于,所述安全认证方法应用于终端,包括:8. A security authentication method, characterized in that the security authentication method is applied to a terminal, including: 响应于终端应用启动操作,通过网关取号,获取本机手机号码;In response to the terminal application startup operation, obtain the local mobile phone number through the gateway; 基于所述本机手机号码与用户输入的手机号码,进行本机号码校验;Based on the local mobile phone number and the mobile phone number input by the user, perform local number verification; 校验通过后,向运营商认证服务端发送授权请求,并接收所述运营商认证服务端基于所述授权请求返回的授权凭证;其中,所述运营商认证服务端返回所述授权凭证的同时将授权相关信息进行区块链存证;After the verification is passed, an authorization request is sent to the operator authentication server, and the authorization voucher returned by the operator authentication server based on the authorization request is received; wherein, the operator authentication server returns the authorization voucher at the same time Store authorization-related information on the blockchain; 向第三方能力方发送所述授权凭证,指示所述第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验,并接收所述第三方能力方返回的鉴权结果;其中,所述运营商认证服务端返回所述鉴权结果的同时将鉴权相关信息进行区块链存证;Send the authorization certificate to the third-party capable party, instruct the third-party capable party to send the authorization voucher to the operator authentication server for authentication verification, and receive the authentication returned by the third-party capable party Result; wherein, the operator authentication server returns the authentication result and at the same time stores the authentication-related information in the blockchain; 基于所述鉴权结果,获取所述终端应用的登录授权。Based on the authentication result, the login authorization of the terminal application is obtained. 9.根据权利要求8所述的方法,其特征在于,所述通过网关取号,获取本机手机号码,包括:9. The method according to claim 8, characterized in that obtaining the local mobile phone number through a gateway includes: 通过运营商认证SDK,向所述运营商认证服务端发送手机号凭证申请;Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK; 获取所述运营商认证服务端基于所述手机号凭证申请返回的手机号凭证;Obtain the mobile phone number certificate returned by the operator authentication server based on the mobile phone number certificate application; 基于所述手机号凭证,通过所述运营商认证SDK向所述运营商认证服务端发送取号凭证申请;Based on the mobile phone number certificate, send a number certificate application to the operator authentication server through the operator authentication SDK; 获取所述运营商认证服务端基于所述取号凭证申请返回的取号凭证;Obtain the number-taking certificate returned by the operator authentication server based on the number-taking certificate application; 基于所述取号凭证,通过所述终端应用对应的应用后端服务,从所述运营商服务端获取本机手机号码。Based on the number retrieval certificate, the local mobile phone number is obtained from the operator server through the application backend service corresponding to the terminal application. 10.一种安全认证装置,其特征在于,所述装置配置于运营商认证服务端,所述装置包括:10. A security authentication device, characterized in that the device is configured at an operator authentication server, and the device includes: 取号处理模块,用于接收来自终端应用的取号请求,向所述终端应用返回对应终端的本机手机号码;A number retrieval processing module, configured to receive a number retrieval request from a terminal application and return the local mobile phone number of the corresponding terminal to the terminal application; 授权处理模块,用于接收所述终端应用基于所述本机手机号码发送的授权请求,向所述终端应用发送授权凭证并将授权相关信息进行区块链存证;An authorization processing module, configured to receive an authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application, and store the authorization-related information in the blockchain; 鉴权处理模块,用于接收携带所述终端应用发送的授权凭证的鉴权请求,返回鉴权结果并将鉴权相关信息进行区块链存证;其中,所述鉴权结果用于指示所述终端应用是否允许对应的终端用户登录所述终端应用。An authentication processing module, configured to receive an authentication request carrying an authorization certificate sent by the terminal application, return the authentication result, and store the authentication-related information on the blockchain; wherein the authentication result is used to indicate the Whether the terminal application allows the corresponding terminal user to log in to the terminal application. 11.一种安全认证装置,其特征在于,所述装置配置于终端,所述装置包括:11. A security authentication device, characterized in that the device is configured on a terminal, and the device includes: 取号模块,用于响应于终端应用启动操作,通过网关取号,获取本机手机号码;The number retrieval module is used to obtain the local mobile phone number through the gateway in response to the terminal application startup operation; 校验模块,用于基于所述本机手机号码与用户输入的手机号码,进行本机号码校验;A verification module, configured to perform local number verification based on the local mobile phone number and the mobile phone number input by the user; 凭证申请模块,用于校验通过后,向运营商认证服务端发送授权请求,并接收所述运营商认证服务端基于所述授权请求返回的授权凭证;其中,所述运营商认证服务端返回所述授权凭证的同时将授权相关信息进行区块链存证;The certificate application module is used to send an authorization request to the operator authentication server after passing the verification, and receive the authorization certificate returned by the operator authentication server based on the authorization request; wherein, the operator authentication server returns Along with the authorization certificate, authorization-related information will be stored in the blockchain; 认证处理模块,用于向第三方能力方发送所述授权凭证,指示所述第三方能力方将所述授权凭证发送至所述运营商认证服务端进行鉴权校验,并接收所述第三方能力方返回的鉴权结果;其中,所述运营商认证服务端返回所述鉴权结果的同时将鉴权相关信息进行区块链存证;Authentication processing module, used to send the authorization voucher to the third party capable party, instruct the third party capable party to send the authorization voucher to the operator authentication server for authentication verification, and receive the third party capable party The authentication result returned by the capable party; wherein, the operator authentication server returns the authentication result and at the same time stores the authentication-related information in the blockchain; 认证处理模块,还用于基于所述鉴权结果,获取所述终端应用的登录授权。The authentication processing module is also configured to obtain the login authorization of the terminal application based on the authentication result. 12.一种电子设备,其特征在于,包括:12. An electronic device, characterized in that it includes: 至少一个处理器;以及at least one processor; and 与所述至少一个处理器通信连接的存储器;其中,a memory communicatively connected to the at least one processor; wherein, 所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器能够执行权利要求1至7中任一项所述的安全认证方法,或者,权利要求8或9所述的安全认证方法。The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can perform any one of claims 1 to 7 The security authentication method, or the security authentication method described in claim 8 or 9. 13.一种存储有计算机指令的非瞬时计算机可读存储介质,其特征在于,所述计算机指令用于使所述计算机执行权利要求1至7中任一项所述的安全认证方法,或者,权利要求8或9所述的安全认证方法。13. A non-transient computer-readable storage medium storing computer instructions, characterized in that the computer instructions are used to cause the computer to execute the security authentication method according to any one of claims 1 to 7, or, The security authentication method according to claim 8 or 9.
CN202311349207.5A 2023-10-17 2023-10-17 Security authentication method, device and storage medium Active CN117579245B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202311349207.5A CN117579245B (en) 2023-10-17 2023-10-17 Security authentication method, device and storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202311349207.5A CN117579245B (en) 2023-10-17 2023-10-17 Security authentication method, device and storage medium

Publications (2)

Publication Number Publication Date
CN117579245A true CN117579245A (en) 2024-02-20
CN117579245B CN117579245B (en) 2025-06-13

Family

ID=89887027

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202311349207.5A Active CN117579245B (en) 2023-10-17 2023-10-17 Security authentication method, device and storage medium

Country Status (1)

Country Link
CN (1) CN117579245B (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111988313A (en) * 2020-08-19 2020-11-24 工银科技有限公司 Data processing method, device, system and medium for block chain
CN112637167A (en) * 2020-12-15 2021-04-09 平安资产管理有限责任公司 System login method and device, computer equipment and storage medium
CN114466353A (en) * 2022-02-09 2022-05-10 号百信息服务有限公司 App user ID information protection device and method, electronic equipment and storage medium
CN115189891A (en) * 2022-07-07 2022-10-14 Oppo广东移动通信有限公司 Application logging method, device, terminal, and computer-readable storage medium
WO2023087704A1 (en) * 2021-11-16 2023-05-25 深圳前海微众银行股份有限公司 Traceable picture authorization method and apparatus

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111988313A (en) * 2020-08-19 2020-11-24 工银科技有限公司 Data processing method, device, system and medium for block chain
CN112637167A (en) * 2020-12-15 2021-04-09 平安资产管理有限责任公司 System login method and device, computer equipment and storage medium
WO2023087704A1 (en) * 2021-11-16 2023-05-25 深圳前海微众银行股份有限公司 Traceable picture authorization method and apparatus
CN114466353A (en) * 2022-02-09 2022-05-10 号百信息服务有限公司 App user ID information protection device and method, electronic equipment and storage medium
CN115189891A (en) * 2022-07-07 2022-10-14 Oppo广东移动通信有限公司 Application logging method, device, terminal, and computer-readable storage medium

Also Published As

Publication number Publication date
CN117579245B (en) 2025-06-13

Similar Documents

Publication Publication Date Title
US12137091B2 (en) Single sign-on enabled with OAuth token
US11956371B2 (en) Recursive token binding for cascaded service calls
US12034713B2 (en) Secure authentication for accessing remote resources
US11121873B2 (en) System and method for hardening security between web services using protected forwarded access tokens
US10880292B2 (en) Seamless transition between WEB and API resource access
US9053306B2 (en) Authentication system, authentication server, service providing server, authentication method, and computer-readable recording medium
US10616196B1 (en) User authentication with multiple authentication sources and non-binary authentication decisions
US10298561B2 (en) Providing a single session experience across multiple applications
CN111062023B (en) Method and device for realizing single sign-on of multi-application system
CN114513350B (en) Identity verification method, system and storage medium
CN104754009A (en) Service acquisition and invocation method, device, client-side and server
US9444800B1 (en) Virtual communication endpoint services
US20220394039A1 (en) Seamlessly securing access to application programming interface gateways
CN114615084A (en) Single sign-on and logout method and system applied to front-end and back-end separation scene, electronic equipment and storage medium
CN113821784A (en) Multi-system single sign-on method, device and computer-readable storage medium
CN109818915A (en) Information processing method and device, server and readable storage medium
CN117336092A (en) Client login method and device, electronic equipment and storage medium
CN117579245A (en) Security authentication method, device and storage medium
CN117097472A (en) Identity authentication method of collaborative signature
CN117544378A (en) Authorization management method, device, equipment and storage medium
CN103095650B (en) Cloud service identity authentication method suitable for thin client terminal
CN104301285A (en) Login method for web system
CN114417318A (en) Method, device and electronic device for jumping to third-party pages
CN115834252B (en) Service access method and system
CN114448715B (en) Authentication method, device, equipment and storage medium based on token

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant