[go: up one dir, main page]

CN103139773A - Method and system for movable client centralization electronic identity authentication - Google Patents

Method and system for movable client centralization electronic identity authentication Download PDF

Info

Publication number
CN103139773A
CN103139773A CN2011103841895A CN201110384189A CN103139773A CN 103139773 A CN103139773 A CN 103139773A CN 2011103841895 A CN2011103841895 A CN 2011103841895A CN 201110384189 A CN201110384189 A CN 201110384189A CN 103139773 A CN103139773 A CN 103139773A
Authority
CN
China
Prior art keywords
user
authentication
website
phone number
service end
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2011103841895A
Other languages
Chinese (zh)
Inventor
陈文博
吴勇
刘志诚
陈蕙茗
王刚
常玉明
王有为
傅平达
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Aspire Digital Technologies Shenzhen Co Ltd
Original Assignee
Aspire Digital Technologies Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Aspire Digital Technologies Shenzhen Co Ltd filed Critical Aspire Digital Technologies Shenzhen Co Ltd
Priority to CN2011103841895A priority Critical patent/CN103139773A/en
Publication of CN103139773A publication Critical patent/CN103139773A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The invention discloses a method and a system for movable client centralization electronic identity authentication, wherein the method mainly comprises the steps that an operator (OP) network of an open identification (ID) provider is used for receiving login certification request information sent by a user, the login certification request comprises a cell phone number of the input by the user. If the input cell phone number by the user in the login identification request is right and logon on the OP network, the OP network provides an authentication manner supported by a radio photography (RP) website of the open ID provider for users to choose, the OP network receives authentication information input by the user according to the selected authentication manner and sends the authentication information to a key management branch system, and the key management branch system conducts authentication according to the authentication information received, and returning the authentication result to the OP network. According to the method and the system for the movable client centralization electronic identity authentication, integral management and identity unified certification of movable user identities are achieved, and the aims that information safety, privacy safety and use safety of the user are fundamentally achieved.

Description

A kind of method and system of mobile client centralization electronic identity authentication
Technical field
The present invention relates to the mobile subscriber identifier field of authentication, relate in particular to a kind of method and system of mobile client centralization electronic identity authentication.
Background technology
OpenID is the digital identity identification framework of a customer-centric, and it is by the authentication of URL as the user.Have the OpenID account, the user can not need registration in the website log of supporting OpenID, realizes once registration, everywhere current purpose.
But traditional OpenID is based on the ID of URL, has increased user's memory and input burden, is especially a very difficult thing to Chinese's input URL; The use of tradition OpenID technology remains by the user name password comes authenticated user, can not fundamentally solve user's information security, personal secrets and use safety problem, thereby can not fundamentally solve user's centralized security management.
Summary of the invention
The technical problem to be solved in the present invention is increased user's memory and input burden and can not fundamentally solve user's information security, personal secrets and use the defective of safety problem for OpenID in prior art, provide a kind of and can realize the user of China Mobile centralized management, unified method and system of carrying out the mobile client centralization electronic identity authentication of identification.
The technical solution adopted for the present invention to solve the technical problems is:
A kind of method of mobile client centralization electronic identity authentication is provided, comprises the following steps:
The login authentication solicited message that the provider OP website reception user of S1, OpenID sends, described login authentication solicited message comprises the phone number that the user inputs;
If in the described login authentication solicited message of S2, the phone number of user input correctly and is registered on described OP website, described OP website provides the authentication mode that the RP website, support side of OpenID is supported to select for the user;
The authentication information that S3, described OP website reception user input according to selected authentication mode, and described authentication information is sent to the key management subsystem;
S4, described key management subsystem carry out authentication according to the described authentication information that receives, and return to authenticating result to described OP website.
In method of the present invention, also comprised step before step S1:
S0, user register by phone number in described OP website, and the registration of described key management subsystem User sends digital certificate and the private key that comprises based on the PKI technology to the user.
In method of the present invention, the authentication information of described user's input comprises phone number and described private key.
In method of the present invention, step S1 also comprises step:
S11, user are by the input handset number request described RP of login website;
S12, after the phone number of user input is by checking, described RP website sends the login authentication solicited message by the OpenID agreement to described OP website, described login authentication solicited message comprises the phone number that the user inputs.
In method of the present invention, after the success of described key management subsystem authentication, send the information of authentication success to described OP website, described OP website turns back to the predefined page that logins successfully in described RP website according to the information of described authentication success.
The present invention solves another technical scheme that its technical problem adopts:
A kind of system of mobile client centralization electronic identity authentication is provided, comprises OP website service end and difference connected user side, RP website service end and key management subsystem:
Described user side is used for sending the login authentication solicited message to described OP website service end, and described login authentication solicited message comprises the phone number that the user inputs;
Described OP website service end is used for when the phone number of user's input correctly and is registered on the OP website, provide the authentication mode that described RP website service end is supported to select for the user, and receive the authentication information that the user inputs according to selected authentication mode, and described authentication information is sent to described key management subsystem;
Described key management subsystem is used for receiving described authentication information and carrying out authentication according to this authentication information, and returns to authenticating result to described OP website service end.
In system of the present invention, described user side also is used for registering at described OP website service end by phone number; The registration that described key management subsystem also is used for User sends digital certificate and the private key that comprises based on the PKI technology to the user.
In system of the present invention, the authentication information of described user's input comprises phone number and described private key.
In system of the present invention, described user side also is used for by the described RP website service end of input handset number request login; Described RP website service end is used for receiving the phone number of user's input and verifying; After being verified, described RP website also is used for sending the login authentication solicited message by the OpenID agreement to described OP website, and described login authentication solicited message comprises the phone number that the user inputs.
In system of the present invention, described key management subsystem also is used for returning to the information of authentication success to described OP website service end after the authentication success; Described OP website service end also is used for turning back to the predefined page that logins successfully in described RP website according to the information of described authentication success.
The beneficial effect that the present invention produces is: all users that register at OP website service end by phone number can login and pass through the key management subsystem by OP website service end or RP website service end and carry out authentication, only have authentication success user could successfully login and access the RP website, thereby realized centralized management and unified certification to the mobile subscriber.The mobile subscriber need not to input different user names or complicated network address just can be easily by authenticating and access related web page.
Description of drawings
The invention will be further described below in conjunction with drawings and Examples, in accompanying drawing:
Fig. 1 is the flow chart of the method for embodiment of the present invention mobile client centralization electronic identity authentication;
Fig. 2 is the flow chart of the method for another embodiment of the present invention mobile client centralization electronic identity authentication;
Fig. 3 is the structural representation of embodiment of the present invention mobile client centralization electronic identity authentication system.
Embodiment
In order to make purpose of the present invention, technical scheme and advantage clearer, below in conjunction with drawings and Examples, the present invention is further elaborated.Should be appreciated that specific embodiment described herein only in order to explain the present invention, is not intended to limit the present invention.
The present invention carries out centralized management and unified certification to the identity of Chinese mobile client.As shown in Figure 1, in an embodiment of the method for mobile client centralization electronic identity authentication of the present invention, the user can directly log in OP (OpenID Provider) website on client (as PC), carry out authentication by the key management subsystem again, the authentication of completing user.In this embodiment, the method for mobile client centralization electronic identity authentication mainly comprises the following steps:
In step 102, the user is that the OP website enters its website homepage by OpenID provider; In step 104, the user by at the login interface input handset number of OP website as logging in the checking solicited message; In step 106, what the OP website received user's input logs in the checking solicited message, and verifies whether this phone number is correct; In step 108, when the input the telephone number mistake time, OP returns to the information of input error in the website to user side; In step 110, when the telephone number of user input is correct, more whether authentication of users is registered on the OP website in advance;
In step 112, when the user does not register, return to enrollment page to user side on the OP website, the guiding user registers, and when the user registers, can directly forward step 120 to; In step 114, the user registers under the guidance of enrollment page; In step 116, after the user successfully registers, return to log-in interface; In step 118, the user logs on the log-in interface that returns again;
In step 120, when the user registers, inquire about the authentication mode that support side's (also can be described as the relying party) RP (Relying Part) website of OpenID is supported, comprise common static password authentication mode, and the digital certificate authentication mode or other authentication modes that generate based on the asymmetric code of PKI in the present invention, do not enumerate at this; In step 122, OP selects the interface to user's return authentication mode in the website; In step 124, the user selects interface selective authenticate mode by authentication mode, in embodiments of the present invention, user-selected number word certificate verification mode is carried out authentication, this digital certificate is that CMAC (authentication center of China Mobile) issues according to application, and issues the user by the key management subsystem; In step 126, the authentication mode of selecting according to the user provides corresponding log-in interface; In step 128, the user is in corresponding log-in interface input authentication information, as phone number and static password, perhaps phone number and private key password, the user is during by the registration of OP website, and the registration that the key management subsystem can User sends by the OP website digital certificate and the corresponding private key password that is used for authentication to the user;
In step 130, the OP website sends to the key management subsystem with the authentication information of user's input of receiving, and request key management subsystem carries out authentication; In step 132, the key management subsystem carries out authentication according to the authentication information that receives; In step 134, the key management subsystem returns to authenticating result to the OP website; In step 136, the OP website is returned to corresponding information according to authenticating result to the user, when authentication failed, returns to wrong information to the user; In step 138, when being proved to be successful, can directly turn back to personal information interface.
In the present invention, the user can also carry out authentication by the RP website, support side that directly logs in OpenID.As shown in Figure 2, in this embodiment, the method for mobile client centralization electronic identity authentication mainly comprises the following steps:
In step 202, the user enters the RP website of supporting Mobile OpenID; In step 204, at the login porch of RP website input handset number, and click login button; In step 206, whether RP website authentication of users phone number is correct; In step 208, if the subscriber phone number input error, the information of input error is returned in the BP website to the user;
In step 210, when the input of user's phone number was correct, the OpenID agreement of RP website Application standard was initiated the login authentication solicited message to the OP website, and this login authentication solicited message can comprise the phone number that the user inputs; In step 212, whether OP website authentication of users is registered; In step 214, if not registration of user, OP returns to enrollment page in the website, and guiding user registration can directly forward step 224 to if registered; In step 216, complete register flow path on the enrollment page that the user returns in the OP website; In step 218, after user registration was completed, OP website guiding user turned back to RP website log interface;
In step 220, the user returns to RP website log interface; In step 222, the user re-enters the phone number login at the login page of RP website; In step 224, if the user registers, the authentication mode that OP query site RP supports the website comprises common static password authentication mode, and the digital certificate authentication mode or other authentication modes that generate based on the asymmetric code of PKI in the present invention, do not enumerate at this; In step 226, OP returns to the website authentication mode of RP website support and selects the interface; In step 228, the user selects a certain authentication mode, comprises static password or digital certificate, user-selected number word certificate verification mode in the embodiment of the present invention;
In step 230, the authentication mode that the OP website is selected according to the user returns to the login prompt interface, requires the user to input relevant authentication information, wherein if the static password authentication mode returns to the Password Input frame; If the digital certificate authentication mode is returned to digital certificate Password Input frame, this digital certificate password is the private key password, the user is during by the registration of OP website, and the registration that the key management subsystem can User sends by the OP website digital certificate and the corresponding private key password that is used for authentication to the user; In step 232, the user is according to the required authentication information of prompting input; In step 234, OP calls the key management subsystem interface according to the authentication mode of user's selection and the authentication information of input in the website, and request key management subsystem carries out authentication; In step 236, the key management subsystem carries out authentication according to the authentication information of user's input; In step 238, the key management subsystem returns to authenticating result to the OP website;
In step 240, OP returns to corresponding information according to authenticating result to the user in the website, if failed authentication returns to miscue information to the user, shows authentication failed; In step 242, when the authentication success, i.e. user rs authentication success is if login first shows user's essential information; If not, can directly jump to the predefined page that logins successfully in RP website.
In the present invention, as long as in OP website registration once, just do not need to re-register, directly login on the RP website of OpenID can supported, and use telephone number as unified User Identity, it is associated with the attribute of mobile client, has solved the inconvenient problem of user's multi-site different identification login.Do not need to input complicated network address, be very easy to the mobile subscriber.Authentication mode adopts digital certificate can solve better user's safety problem in addition.
as shown in Figure 3, the system of embodiment of the present invention mobile client centralization electronic identity authentication mainly comprises OP website service end 20 and the connected user side 10 of difference, RP website service end 30 and key management subsystem 40, user side 10 and OP website service end 20, and be all that radio communication is connected between RP website service end 30 and website service end 20, RP website service end 30 (authentication relying party) is the support side of OpenID, support the user to login the website of oneself with OpenID, as broad as long with traditional RP, just do not need to input complicated network address, only need input telephone number login authentication just passable.OP website service end 20 is connected by interface with key management subsystem 40.
User side 10 is used for sending the login authentication solicited message to OP website service end, and the login authentication solicited message comprises the phone number that the user inputs.
OP website service end 20 is used for when the phone number of the login authentication solicited message user input that receives correctly and is registered on the OP website, provide the authentication mode that RP website service end 30 is supported to select for the user, and receive the authentication information that the user inputs according to selected authentication mode, and authentication information is sent to key management subsystem 40; OP website service end 20 is the authenticating user identification provider; it comprises the identity information storehouse that the mobile subscriber is unified, and each functional module that digital identity establishment, identity attribute management, login authentication, login sessions management, the supply of OpenID identity and user's secret protection is provided for the user.
Key management subsystem 40 is used for the authentication information of user's input of reception OP website service end 20 transmissions, and carries out authentication according to this authentication information, and returns to authenticating result to OP website service end.Key management subsystem 40 is mainly used in the user when registering and when logging on OP website service end 20, realize the functions such as customer digital certificate application, storage, authentication and management.Key management subsystem 40 mainly obtains digital certificate by the CMCA50 (authentication center of China Mobile) on backstage, then carries out data interaction with OP website service end 20.
In embodiments of the present invention, the user needs to register at OP website service end 20 by phone number at user side 10 in advance, just can obtain corresponding digital certificate or static password, and the rear user that succeeds in registration could login and authenticate.The registration of key management subsystem 40 Users sends digital certificate and the private key that comprises based on the PKI technology to the user.If the authentication mode of user-selected number word certificate, the authentication information of user's input comprises phone number and the private key that key management subsystem 40 returns when registration.
Further, in the embodiment of the present invention, user side 10 also is used for by input handset number request login RP website service end 30; RP website service end 30 is the support side of OpenID, by the user of RP website log, and the related web page that can directly access the RP website by authentication by the phone number of registering on the OP website.RP website service end 30 is used for receiving the phone number of user's input and verifying; After being verified, the RP website also is used for by the OpenID agreement to OP website transmission login authentication solicited message, the login authentication solicited message comprises the phone number that the user inputs, the authentication process of OP website service end 20 and key management subsystem 40 with above directly login identically by OP website service end 20, do not repeat them here.
Further, in the embodiment of the present invention, key management subsystem 40 also is used for returning to the information of authentication success to OP website service end 20 after the authentication success; OP website service end 20 also is used for turning back to the predefined page that logins successfully in RP website according to the information of authentication success.
In the present invention, all can get the user of OP website service end 20 registrations the digital certificate based on the PKI technology that key management subsystem 40 is provided by phone number, this digital certificate is generated by CMCA, and unification is managed by key management subsystem 40.When the user logins by OP website service end 20 or RP website service end 30, all can adopt chartered phone number as login name, carry out authentication through key management subsystem 40 again, only have the user of authentication success could successfully login and access the RP website, thereby realized centralized management and unified certification to the mobile subscriber, the user need not to input different user names or complicated network address just can be easily by authenticating and access OpenID service side OP website service end 20 and OpenID support side RP website service end 30.By the digital certificate authentication based on the PKI technology, can fundamentally solve user's information security, personal secrets and use safety.In addition because digital certificate has certain life cycle, can realize dynamic management to user identity according to this life cycle.
Should be understood that, for those of ordinary skills, can be improved according to the above description or conversion, and all these improve and conversion all should belong to the protection range of claims of the present invention.

Claims (10)

1. the method for a mobile client centralization electronic identity authentication, is characterized in that, comprises the following steps:
The login authentication solicited message that the provider OP website reception user of S1, OpenID sends, described login authentication solicited message comprises the phone number that the user inputs;
If in the described login authentication solicited message of S2, the phone number of user input correctly and is registered on described OP website, described OP website provides the authentication mode that the RP website, support side of OpenID is supported to select for the user;
The authentication information that S3, described OP website reception user input according to selected authentication mode, and described authentication information is sent to the key management subsystem;
S4, described key management subsystem carry out authentication according to the described authentication information that receives, and return to authenticating result to described OP website.
2. method according to claim 1, is characterized in that, also comprised step before step S1:
S0, user register by phone number in described OP website, and the registration of described key management subsystem User sends digital certificate and the private key that comprises based on the PKI technology to the user.
3. method according to claim 2, is characterized in that, the authentication information of described user's input comprises phone number and described private key.
4. method according to claim 3, is characterized in that, step S1 also comprises step:
S11, user are by the input handset number request described RP of login website;
S12, after the phone number of user input is by checking, described RP website sends the login authentication solicited message by the OpenID agreement to described OP website, described login authentication solicited message comprises the phone number that the user inputs.
5. method according to claim 4, it is characterized in that, after the success of described key management subsystem authentication, send the information of authentication success to described OP website, described OP website turns back to the predefined page that logins successfully in described RP website according to the information of described authentication success.
6. the system of a mobile client centralization electronic identity authentication, is characterized in that, comprises OP website service end and difference connected user side, RP website service end and key management subsystem:
Described user side is used for sending the login authentication solicited message to described OP website service end, and described login authentication solicited message comprises the phone number that the user inputs;
Described OP website service end is used for when the phone number of user's input correctly and is registered on the OP website, provide the authentication mode that described RP website service end is supported to select for the user, and receive the authentication information that the user inputs according to selected authentication mode, and described authentication information is sent to described key management subsystem;
Described key management subsystem is used for receiving described authentication information and carrying out authentication according to this authentication information, and returns to authenticating result to described OP website service end.
7. system according to claim 6, is characterized in that, described user side also is used for registering at described OP website service end by phone number; The registration that described key management subsystem also is used for User sends digital certificate and the private key that comprises based on the PKI technology to the user.
8. system according to claim 7, is characterized in that, the authentication information of described user's input comprises phone number and described private key.
9. system according to claim 8, is characterized in that, described user side also is used for by the described RP website service end of input handset number request login; Described RP website service end is used for receiving the phone number of user's input and verifying; After being verified, described RP website also is used for sending the login authentication solicited message by the OpenID agreement to described OP website, and described login authentication solicited message comprises the phone number that the user inputs.
10. system according to claim 9, is characterized in that, described key management subsystem also is used for returning to the information of authentication success to described OP website service end after the authentication success; Described OP website service end also is used for turning back to the predefined page that logins successfully in described RP website according to the information of described authentication success.
CN2011103841895A 2011-11-28 2011-11-28 Method and system for movable client centralization electronic identity authentication Pending CN103139773A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2011103841895A CN103139773A (en) 2011-11-28 2011-11-28 Method and system for movable client centralization electronic identity authentication

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2011103841895A CN103139773A (en) 2011-11-28 2011-11-28 Method and system for movable client centralization electronic identity authentication

Publications (1)

Publication Number Publication Date
CN103139773A true CN103139773A (en) 2013-06-05

Family

ID=48498962

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2011103841895A Pending CN103139773A (en) 2011-11-28 2011-11-28 Method and system for movable client centralization electronic identity authentication

Country Status (1)

Country Link
CN (1) CN103139773A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104113556A (en) * 2014-07-31 2014-10-22 国家超级计算深圳中心(深圳云计算中心) Network logon authentication method and system, mobile terminal and application server
CN108667785A (en) * 2017-04-01 2018-10-16 金联汇通信息技术有限公司 The system and method for network identity service based on Open ID
CN112351131A (en) * 2020-09-30 2021-02-09 北京达佳互联信息技术有限公司 Control method and device of electronic equipment, electronic equipment and storage medium

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101552673A (en) * 2009-04-30 2009-10-07 用友软件股份有限公司 An approach to log in single sign-on system by using OpenID account
US20100011421A1 (en) * 2008-07-13 2010-01-14 International Business Machines Corporation Enabling authentication of openid user when requested identity provider is unavailable

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100011421A1 (en) * 2008-07-13 2010-01-14 International Business Machines Corporation Enabling authentication of openid user when requested identity provider is unavailable
CN101552673A (en) * 2009-04-30 2009-10-07 用友软件股份有限公司 An approach to log in single sign-on system by using OpenID account

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
李川: ""统一身份认证在移动通信系统中的应用研究"", 《中国优秀硕士学位论文全文数据库》 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104113556A (en) * 2014-07-31 2014-10-22 国家超级计算深圳中心(深圳云计算中心) Network logon authentication method and system, mobile terminal and application server
CN108667785A (en) * 2017-04-01 2018-10-16 金联汇通信息技术有限公司 The system and method for network identity service based on Open ID
CN108667785B (en) * 2017-04-01 2020-11-27 金联汇通信息技术有限公司 System and method for network identity service based on Open ID
CN112351131A (en) * 2020-09-30 2021-02-09 北京达佳互联信息技术有限公司 Control method and device of electronic equipment, electronic equipment and storage medium

Similar Documents

Publication Publication Date Title
US10057251B2 (en) Provisioning account credentials via a trusted channel
CN103152331B (en) The method, system and the cloud server that log in/register is carried out by mobile terminal
CN102143482B (en) Method and system for authenticating mobile banking client information, and mobile terminal
EP3120591B1 (en) User identifier based device, identity and activity management system
CN101316282B (en) Terminal remote control method and related equipment
CN105357242B (en) Access the method and system of WLAN, short message pushes platform, gate system
CN101039311B (en) An identity identification webpage service network system and its authentication method
US9065903B2 (en) User-based authentication for realtime communications
WO2013127292A1 (en) Login method and device, terminal and network server
CN102811228B (en) Network login method, equipment and system
CN103139777B (en) The method, system and the cloud server that log in/register is carried out by mobile terminal
WO2013075661A1 (en) Login and open platform identifying method, open platform and system
CN102546914A (en) Automatic login system based on smart phone and control method
TWI632798B (en) Server, mobile terminal, and network real-name authentication system and method
WO2013067877A1 (en) User register and login method and mobile terminal
CN103532982A (en) Wearable device based authorization method, device and system
CN103916855A (en) Method for enabling mobile phone to be connected to WiFi network
CN103370955A (en) Seamless WI-FI subscription remediation
CN101366037A (en) Computer program product, device and method for secure HTTP digest response verification and integrity protection in mobile terminal
CN105828329A (en) Authentication management method for mobile terminals
CN104468108A (en) User identity authentication system and user identity authentication method based on barcode
JP2023531797A (en) 5G authentication method, 5G account opening method and system, electronic device, and computer readable storage medium
CN104660405A (en) Business equipment authentication method and equipment
CN102685090B (en) System login method
CN104378368A (en) Code scanning log-in method and system

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20130605