Disclosure of Invention
In view of the above, the main objective of the present invention is to provide an audio smart card authentication system and an authentication method, which avoid the tedious manual keystroke input in the authentication process.
The invention relates to an audio intelligent card identity verification system, which comprises: the system comprises an audio intelligent card unit, an audio signal receiving terminal, a demodulation unit and an authentication unit; the audio intelligent card unit sends an audio signal containing user authentication information to the audio signal receiving terminal; the audio signal receiving terminal receives an audio signal, converts the audio signal into an electric signal and transmits the electric signal to the demodulation unit; the demodulation unit restores the received electric signal into user authentication information and sends the user authentication information to the authentication unit; and the authentication unit verifies the validity of the user identity according to the user authentication information.
Wherein the audio smart card unit includes: the system comprises a trigger module and an audio smart card; the audio smart card is inserted into the trigger module to be activated, and the trigger module sends out an audio signal containing user authentication information.
And the audio signal receiving terminal sends the electrical signal obtained by converting the audio signal to the demodulation unit through a transmission network. The audio signal receiving terminal is a fixed telephone, and the transmission network is a PSTN network; or, the audio signal receiving terminal is a mobile terminal, and the transmission network is a wireless communication network.
The method for verifying the identity of the audio intelligent card, disclosed by the invention, is characterized in that an audio signal receiving terminal, a demodulation unit and an authentication unit are arranged in an application system in advance, and the method comprises the following steps:
A. the audio signal receiving terminal receives an audio signal which is sent by the audio intelligent card and is provided with user authentication information, converts the audio signal into an electric signal and sends the electric signal to the demodulation unit;
B. the demodulation unit restores the electric signal transmitted in the step A into carried user authentication information and transmits the user authentication information to the authentication unit;
C. and the authentication unit verifies the validity of the user identity according to the user authentication information.
The application system is a bank financial system, an access control system or an intelligent network system. When the application system is an intelligent network system, the demodulation unit is arranged on an intelligent peripheral AIP; the authentication unit is arranged on the SCP; the audio signal receiving terminal is a telephone and sends the electrical signal converted from the audio signal to the demodulation unit through the transmission network.
Wherein, the authentication information comprises a user ID; or a user ID and password.
Wherein, the user authentication information in step a is encrypted information, and the corresponding step B further includes: before the demodulation unit transmits the user authentication information to the authentication unit, the user authentication information is decrypted; or, the corresponding step C further comprises: before authenticating the transmitted user authentication information, the authentication unit decrypts the user authentication information.
The method combines the audio smart card technology with the existing service, and simplifies the process of inputting the user ID and the password by the user. Because the identity authentication is carried out through the audio signal, when the system is applied to various identity authentication systems, the input of the user ID and the password is realized only by receiving the audio signal of the audio intelligent card, for example, the signal is received by using the telephone of the existing PSTN network, thereby being more convenient for the user to use. In addition, since manual input is avoided and user ID and password information are transmitted in the form of a cipher text over a transmission network, security is also improved.
Detailed Description
In order to make the objects, technical solutions and advantages of the present invention more apparent, the present invention is described in further detail below with reference to specific embodiments and the accompanying drawings.
Fig. 1 schematic diagram of an audio smart card identity verification system. As shown in the figure, the identity verification system of the present invention at least includes an audio smart card unit, an audio signal receiving terminal, a demodulation unit and an authentication unit. The audio smart card unit comprises a trigger module and an audio smart card, and the audio smart card is activated by the trigger module and then sends an audio signal containing user authentication information. The audio signal receiving terminal is used for converting the audio signal of the audio smart card into an electric signal and transmitting the electric signal to the demodulation unit, wherein the signal can be transmitted through a transmission network. The demodulation unit is used for reducing the transmitted signal into user authentication information and transmitting the user authentication information to the authentication unit. The authentication unit carries out validity authentication on the received user authentication information.
The information stored in the integrated circuit chip of the audio smart card is the authentication information of the user, including ID and password, when the audio smart card is inserted into the trigger module, the trigger module identifies the user authentication information and repeatedly transmits the user authentication information through the sound interface by an authentication sequence signal similar to MODEM. Wherein, the authentication information may be further encrypted information.
Fig. 2 is an embodiment of the identity authentication system of the present invention applied to a telecommunications intelligent network platform, the identity authentication system comprising: the system comprises a PSTN with a fixed telephone, an SSP with An Intelligent Peripheral (AIP), a Service Control Point (SCP) and an authentication server. The PSTN terminal, namely the fixed telephone serves as an audio signal terminal and is used for receiving an audio signal sent by the audio intelligent card and transmitting the signal to the AIP at the SSP side through the PSTN transmission network. Besides the functions of playing intelligent service voice and receiving user dialing, the AIP at SSP side also has a demodulation unit including Frequency Shift Keying (FSK) data analysis function for analyzing and restoring the signal transmitted from PSTN to user authentication information. Besides the SCP performs the original service control function, a software module for authentication may be provided in the SCP as an authentication module unit, and of course, the authentication module unit may also exist independently to minimize the influence on the original network change.
Taking fig. 2 as an example and referring to fig. 3, the authentication process of the present invention is described in detail as follows:
step 301: when the current business process prompts the user to input authentication information, for example, after prompting the user to input an ID or a user password, the user puts the audio smart card into the trigger module, then presses the trigger module to activate the audio smart card, and sends out a corresponding audio signal, wherein the audio signal carries the encrypted user authentication information. The user authentication information may be 16 bytes, which includes an 8-bit Identifier (ID) and an 8-bit authentication code (Ci), and may be used to represent the ID and the password of the user, respectively.
Step 302: the audio signal is converted into an electrical signal through a PSTN terminal, i.e., a fixed telephone, and then transmitted to a demodulation unit, i.e., an AIP apparatus in fig. 2, through the PSTN.
Step 303: the demodulation unit arranged in the AIP converts the electric signal into encrypted user authentication information, namely ciphertext data, through an FSK protocol.
Step 304: the demodulation unit of the AIP decrypts the ciphertext data to recover the original user authentication information, and transmits the original user authentication information to the authentication unit, i.e., the authentication server in fig. 2.
Step 305: and the authentication unit carries out authentication, if the authentication is successful, the subsequent service process is continued, otherwise, the current service process is quitted, and corresponding information is returned to prompt the user.
The decryption step in step 304 may also be completed by the authentication unit, that is, the demodulation unit sends the ciphertext data in step 303 to the authentication unit, and the authentication unit decrypts the ciphertext data and then performs step 305 to perform authentication.
The above method can be used in existing authentication procedures. For example, in the existing intelligent service provided based on the fixed-line telephone, when the user is required to input a personal account and a password, the user can input the password conveniently by adopting the mode, and after authentication, the subsequent process of the current service is continued according to the authentication result.
The above description takes the PSTN network given in fig. 2 as an example. The invention can also be used in other networks, such as wireless network, the audio receiving terminal is a mobile terminal, the transmission network is a wireless communication network, and the principle of realizing identity authentication is the same as that in PSTN network.
Alternatively, the communication may be an internet network. For example, when the method is used for identity authentication on the internet, when the network terminal requires the user to perform identity authentication by using the above authentication method, the network terminal collects audio information sent by the audio smart card through the provided microphone, then transmits the audio information to the demodulation unit through the internet, performs authentication through the above step 303 and 305, and then continues the subsequent process of the current service according to the authentication result.
By using the method, the user can be more conveniently used for the authentication process, such as the identity verification of an access control system, and can also be used for a bank financial system, so that the user can more conveniently pay by using the own account number, such as the payment of the expense by using an audio card, and the like, and the complicated password input process can be avoided.
The above description is only for the purpose of illustrating the preferred embodiments of the present invention and is not to be construed as limiting the invention, and any modifications, equivalents, improvements and the like that fall within the spirit and principle of the present invention are intended to be included therein.