Website authentication method based on picture identification digital signatures
Abstract
The invention discloses a website authentication method based on picture identification digital signatures. The authentication method for specific identification targets includes the steps: (1) websites submit data information registration to an identification management authority to apply identifications; (2) the identification management authority examines and verifies, then uses a private key to sign the data information and picture identifications to form specific identifications for the websites, and issues the specific identifications to the websites; (3) the websites arrange the identifications in web servers; (4) clients acquire the website identifications when accessing the websites through credible terminals, use a public key of the identification management authority to verify validity of the identification targets, and check whether access information is matched with information in the identifications or not; and (5) after the identifications pass the verification, the clients display contents in the identifications to users to prompt the users of the currently accessed website information. By the website authentication method based on picture identification digital signatures, the websites can be well identified, the identifications are visual and vivid and easy to deploy and have uniqueness, and the problems of counterfeit websites and phishing websites can be effectively solved.
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
12 claims: 9 independent, 3 dependent
- 1based on image identification digital signature of the network authentication method wherein said method is based on a mark authority management mechanism implementing said mechanism has representative of the digital certificate private key from the owned public key digital certificate according to the claims the authentication method comprises the following steps:Through the network station direction mark authority management mechanism the data information to application for registration mark;Identifying authority management mechanism check key-private key pairs then using the resource information and picture processing ideograph the picture of user data and signature with the network station wherein the marking object sending to the network station;Network station in a web server disposed in the middle part of the obtained marker object;Client terminal through the communication terminal access network station to obtain the network station mark object is used for identifying authority management mechanism of public key verification mark of the object the validity checking access information objects in the identification information if matching;The identification object after passing the verification the customer end of the marker object the content to the user displaying the user to the access network station information. 1. 一种基于图片标识数字签名的网站认证方法,其特征在于,所述方法基于一标识权威管理机构实施,所述机构具有代表自身的数字证书,其私钥自已拥有,公钥数字证书对外公开,所述认证方法包括如下步骤: (1)通过网站向标识权威管理机构提交资料信息进行注册,申请标识; (2)标识权威管理机构审核后,使用私钥对资料信息和图片进行签名,将图片、用户资料以及签名合成网站特有标识对象,发放给网站; (3)网站在web服务器中部署所获得的标识对象; (4)客户端通过可信终端访问网站时,获取网站标识对象,使用标识权威管理机构公钥验证标识对象有效性,核对访问信息与标识对象中信息是否匹配; (5)对标识对象验证通过后,客户端将标识对象中的内容向用户展示,提示用户正在访问的网站信息。
- 2According to claim i the invention claims a based on image identification digital signature of the network authentication method wherein said identifying authority management mechanism is an authority of the network recognizing the identification of the producing management centre is responsible for receiving identification request to finish the identification of the label to mark blacklist management function of audit. 2.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于,所述标识权威管理机构为一个权威的、网站认可的标识制作管理中心,负责接收标识申请、完成标识的签发、标识黑名单管理、审计功能。
- 3According to claim i the invention claims a based on image identification digital signature of the network authentication method wherein said step of network station it is submitted with the registered information comprises but does not limit to network station logo image network domain name card material network station owner identity card material network station ip address information. 3.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于,所述步骤(I)中网站提交的注册资料信息包括但不限于网站logo图片,网站域名证明材料、网站所有者身份证明材料、网站IP地址信息。
- 6according to claim i the invention claims a based on image identification digital signature of the network authentication method wherein said step of identifying authority management mechanism generated in the network station mark object is the picture object information comprises but not limited to itself the image data of the network station the domain name of network station ip address of network station owner name of sign object the period of validity of the marker object of the sequence number identifier identifying address mode identifier and authority information and identifying authority management mechanism to is set on said information of the signature data. 6.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于,所述步骤(2)中标识权威管理机构中生成的网站标识对象为图片对象,信息包含但不限于自身的图像数据,网站的域名,网站的IP地址,网站的所有者名称,标识对象的有效期,标识对象的序列号,标识验证地址及方式,标识权威机构信息,以及标识权威管理机构对以上所有信息的签名数据。
- 8according to claim i the invention claims a based on image identification digital signature of the network authentication method wherein said step of the deployment marker object when the marking object is put on the specific path as ordinary picture of the web page using 8.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于,所 述步骤(3)中在部署标识对象时将标识对象放在特定路径,作为普通图片在网页中引用
- 9according to claim i the invention claims a based on image identification digital signature of the network authentication method wherein the following steps in the communication terminal comprises but not limited to browser and capable of acquiring identification and verification tool. 9.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于, 述步骤(4)中的可信终端包括但不限于浏览器,以及能够获取标识并验证的工具。
- 10according to claim i the invention claims a based on image identification digital signature of the network authentication method wherein said step of acquiring identification object in time according to the fixed location obtains the identifier or the web page identifier analyzing. 10.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于,所述步骤(4)获取标识对象时通过到固定位置获取标识或从网页中解析标识。
- 11according to claim i the invention claims a based on image identification digital signature of the network authentication method wherein said step of verification mark of the object including but not limited to the authenticating means:Judging if the object is authority issue object;Using authority public key authentication object in the signature is not effective judging whether the object data is tampered;If the object contains network station the digital certificate through object websites in existing digital certificate authentication address and method validating whether there is network station and the certificate private key of corresponding;Verification is corresponding to private key operation including but not limited to the ssl https access and network station can use the private key operation the response of authentication request;Verification mark object is not overdue;Verification mark if the object has been waste the authentication mode including but not limited to the mark address in the authentication real-time validation and the pre-set caching identifier blacklist mechanism;Verification mark of the information whether the access network station information matching verification information comprises but not limited to ip address domain name;11.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于,所述步骤(4)验证标识对象包括但不限于以下验证手段: (41)判断对象是否为权威机构签发的对象;(42)使用权威机构公钥验证对象中的签名是否有效,判断对象数据是否被篡改; (43)如果对象包含网站自身数字证书,通过对象中网站已有数字证书验证地址及方式验证网站是否具有与证书对应的私钥;验证对应私钥的操作包括但不限于采用https的SSL访问,以及网站能够使用私钥操作回应验证请求; (44)验证标识对象是否过期; (45)验证标识对象是否已经被废除,验证方式包括但不限于采用标识中的验证地址实时验证,以及采用预先缓存标识黑名单机制; (46)验证标识中的信息是否与访问的网站信息匹配,验证信息包括但不限于域名、IP地址;
- 12according to claim i the invention claims a based on image identification digital signature of the network authentication method wherein said step of forming display mode including but not limited to the communication terminal to display information and user selection the rear display information display content comprises but not limited mark in the logo image information mark in the network station identity information of authentication mechanism information. 12.根据权利要求I所述的一种基于图片标识数字签名的网站认证方法,其特征在于,所述步骤(5)中的展示方式包括但不限于可信终端主动显示信息,以及用户选择后显示信息,显示的内容包括但不限标识中logo图片信息,标识中的网站身份信息,认证机构信息。
Independent claims9
62 paragraphs, as filed
The technical field of
[0001] the invention claims a network security technology and specifically claims an internet network the network station method for authenticating.
Background technology
[0002] connected with the internet fast development information has been inserted into the social each other field and exert the to the important action at the same time network safety problem of the internet threatening economic and it becomes larger gradually the counterfeit network station and the fishing network station and the harm of especially serious the four commercial bank website the 2008 olympic games beijing guan method then to the website tenxun tao bao such as known internet ltd basically has been suffered from counterfeit network station harm. Data statistic 2010 new year and the fishing network station 175 wan of the net citizen to reach 4411 wan human time caused by directly the loss of over 200 hundred million. So it solves the problem of network chengxin website authentication has been is needed the invention is to solve the problem of network security.
[0003] when the existed in the utility model claims a picture to the network station id authentication method. The following steps the network station at the bottom of the first page and a picture l 0g0 static or dynamic user access network station first page and user click icon a system of new window is connected with the special web page content displayed just now the user access network whether it passes through validation and displays network station information domain name registering personal network the business license with the human operation range and so on information. This mode although it has simple and it is complex and has many shortcomings:
[0004] icon it is easy to be ignored. Normal network common people can not be paid attention to the page layout on the bottom of the identification.
[0005] is simple the picture and it is easy to be stolen and copies it can not be embezzled method for network station if the user does not drive the click fraud it is easy to be.
[0006] authentication information the security is bad the user click picture it is comprised of the jumping to the web site address to carry out verification and network jumping accuracy and it is difficult to confirm at the same time skip information it is easy to be copies and tampered.
[0007] from said several point can be seen the present network icon mark no matter in the main showing activity icon anti-counterfeiting performance and verification of safe property of all existing problem of not accurately to the network station to perform the certification.
The content of invention
[0008] this invention aims at existing network safety certification the problem which exists in order to provide a security and authentication the image identification object at the same time the invention claims a marker object method for using by the method can effectively solve the problem that false website and cold and the fishing network station the problem of.
[0009] in order to reach the purpose of this invention adopts the technology plan is as follows:
[0010] based on image identification digital signature of the network authentication method the method is based on a mark authority management mechanism implementing said mechanism has representative of the digital certificate private key of its own public key it has the digital certificate according to the claims the authentication method comprises the following steps:
[0011] through the network station direction mark authority management mechanism the data information to application for registration mark;
[0012] identifying authority management mechanism check key-private key pairs then using the resource information and picture processing ideograph the picture of user data and signature with the network station wherein the marking object sending to the network station;
[0013] network station in a web server disposed in the middle part of the obtained marker object;
[0014] client terminal through the communication terminal access network station to obtain the network station mark object is used for identifying authority management mechanism of public key verification mark of the object the validity checking access information objects in the identification information if matching;
[0015] the identification object after passing the verification the customer end of the marker object the content to the user displaying the user to the access network station information.
[0016] the invention one embodiment of said identifying authority management mechanism is an authority of the network recognizing the identification of the producing management centre is responsible for receiving identification request to finish the identification of the label to mark blacklist management function of audit.
[0017] the step of network station it is submitted with the registered information comprises but does not limit to network station logo image network domain name card material network station owner identity card material network station ip address information.
[0018] further said web site it is submitted with the registration information and it also comprises the network station the existing digital certificate.
0019 ] and [ further said web site of existing digital certificate comprises but not limited to the third party ca mechanism issuing digital certificate authority the centre identified issue to the network station of the digital certificate.
[0020] the step of identifying authority management mechanism generated in the network station mark object is the picture object information comprises but not limited to itself the image data of the network station the domain name of network station ip address of network station owner name of sign object the period of validity of the marker object of the sequence number identifier identifying address mode identifier and authority information and identifying authority management mechanism to is set on said information of the signature data.
[0021] further the information further comprises a network station the digital certificate or web site of existing digital certificate authentication address and method of.
[0022] the step of the deployment marker object when the marking object is put on the specific path as ordinary picture of the web page using.
[0023] said step *** in the communication terminal comprises but not limited to browser and capable of acquiring identification and verification tool.
[0024] the following steps obtains the identifier through the object to the fixed location obtains the identifier or the web page identifier analyzing.
[0025] said step verification mark of the object including but not limited to the authenticating means:
[0026] judging if the object is authority issue object;
[0027] using authority public key authentication object in the signature is not effective judging whether the object data is tampered;
[0028] if the object contains network station the digital certificate through object websites in existing digital certificate authentication address and method validating whether there is network station and the certificate private key of corresponding; Verification is corresponding to private key operation including but not limited to the ssl https access and network station can use the private key operation the response of authentication request;
[0029] verification mark object is not overdue;
[0030] verification mark if the object has been waste the authentication mode including but not limited to the mark address in the authentication real-time validation and the pre-set caching identifier blacklist mechanism;
[0031] verification mark of the information whether the access network station information matching verification information comprises but not limited to ip address domain name;
[0032] the step of the display mode including but not limited to the communication terminal to display information and user selection the rear display information display content comprises but not limited mark in the logo image information mark in the network station identity information of authentication mechanism information.
[0033] according to said obtained by the technology scheme of this invention can well network station authenticity to carry out verification and it can effectively prevent counterfeit and network station and the fishing network station the attack of.
Specification attached drawing
[0034] following combining the attached drawing and specific implementing manner to further explain the invention.
[0035] image i is the invention embodiment of the frame image.
[0036] picture 2 in the invention is composed of object mark diagrammatic sketch.
[0037] picture 3 is the invention implement the effect of the image.
Specific implementing manner
[0038] in order to make the invention can realize the technical means making feature to achieve the purpose and effect it is easy to understand the lower surface of the combination of the image display further this invention claims compounds of said.
[0039] i the picture displayed in the implementation method of this invention in the process firstly the trusted third party by using a trust pki system establishing a identifying authority management mechanism it is a authority of the network recognizing the identification of the producing management centre is responsible for receiving identification request to finish the identification of the label to mark blacklist management function of audit.
[0040] wherein the trusted third party can be national authority department also can be a have a common signal power of the intermediary institution.
[0041] the mechanism has representative of the digital certificate private key of its own has a public key according to the digital certificate claims
[0042] based on said mechanism implementing network authentication method includes the following steps:
[0043] network station direction mark authority management mechanism the data information to application for registration mark. Wherein it is submitted with the data information comprises network station logo image network domain name card material network station ip address network business license network station which has been application of digital certificate applying mark.
[0044] the network station which has been application of digital certificate comprising the third party ca mechanism issuing digital certificate authority identification centre issue to the network station of digital writing.
[0045] identifying authority management mechanism to the network station it is submitted with the verification data to confirm the authenticity of the additional mark the character data to the data to signature the original data and signature data synthesizing and the network station identification object. Marker object format such as picture 2 the identification object is the picture object information with self the image data of the network station the domain name of network station ip address of network station owner name web station of existing digital certificate can be selected website the existing digital certificate authentication address and method for marking object able to the period of validity of the marking object the sequence number of the mark address and verification method of label of authority information and identifying authority management mechanism to is set on said information of the signature data.
[0046] network station receives the marks and putting to the network station the special position of disposition as ordinary picture of the web page using such as http: / or www cs or sh rov j cn id jpr0
[0047] user browser to access network station such as http: And / or sh www csj rov ie browser from the specific position of http: / or sh www csj rov cn id or i' pr obtaining the identified object and from the web page identifier analyzing.
[0048] browser the identification object to carry out verification and it mainly comprises the following steps
[0049] checking identification to the identification of a central information whether the browser credit identification of the centre.
[0050] using the mark in the centre of the public key verification mark of the signature identification judging whether or not counterfeit or the data been tampered.
[0051] if the object contains network station the digital certificate through object websites in existing digital certificate authentication address and method validating whether there is network station and the certificate private key of corresponding; Verification is corresponding to private key operation including but not limited to the ssl https access and network station can use the private key operation the response of authentication request. Such as the use of https: / or www csj cn or sh rov establish security connection check the secure connection it can be used in network certificate whether the identification contained in the certificate.
[0052] inspection mark in the period of validity of the correctness.
[0053] is used for https: / or www utn com safety is connected with the querying the identification id has not been waste and.
[0054] angle jun analysis obtains the identifier entity in the characteristic data such as www csj sh rov cn and corresponding to the ip and then it is ih the access of ip domain name and is compared to see whether it is correct.
[0055] browser the identification after passing the validation displaying the logo identification information of all user information and certification organization information and so on such as picture 3.
[0056] according to the above scheme this invention can be known through the third party by using a trust pki system establishing a identifying authority management mechanism to the network station the image of the marker object to be authenticated so that it can be good for network station authenticity to carry out verification and it can effectively prevent counterfeit and network station and the fishing network station the attack of.
[0057] the displaying and describing the invention the basic principle of the main characteristic and the invention has the advantages of. Industry the technical personnel to the order to the invention is not affected by the embodiment of the limit of said embodiment and specification it is described in specification the principle of this invention is not separated from the invention the range of psychiatric and under the premise of the invention also has various changing and improved and these changes and improvement can fall into the requirement of the protection the invention in the range of. The present invention request the protection range of the surface of claim book and its equivalent material defining.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN104486079A | Cited by | China | Search report |
| WO2016172986A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11004163B2 | Cited by | United States of America | Applicant |
| CN107508682A | Cited by | China | Search report |
| CN108229970A | Cited by | China | Search report |
| CN108023863A | Cited by | China | Search report |
| CN103770503A | Cited by | China | Search report |
| CN103414688A | Cited by | China | Search report |
| CN104796502A | Cited by | China | Search report |
| CN105760783A | Cited by | China | Search report |
| CN103929406A | Cited by | China | Search report |
| CN105791253A | Cited by | China | Search report |
| CN104811421A | Cited by | China | Search report |
| CN105024813A | Cited by | China | Search report |
| CN105471877A | Cited by | China | Search report |
| CN103200179A | Cited by | China | Search report |
| CN101155028A | Cites | China | Search report |
| CN101860540A | Cites | China | Search report |
| EP1451967A1 | Cites | European Patent Office (EPO) | Search report |
| CN1737820A | Cites | China | Search report |
| CN1833398A | Cites | China | Search report |
| CN1960249A | Cites | China | Search report |
| US2005071636A1 | Cites | United States of America | Search report |
| US6134431A | Cites | United States of America | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201110110184 | China | A | |
| CN20111110184 | – | – | – |
Numbers
- Publication
- 102761529
- Publication, DOCDB
- 102761529
- Publication, EPODOC
- CN102761529
- Application
- 101101843
- Application, DOCDB
- 201110110184
- Application, EPODOC
- CN20111110184
Titles3
- English
- Based on image identification digital signature of the network authentication method
- Chinese
- 一种基于图片标识数字签名的网站认证方法
- English
- Website authentication method based on picture identification digital signatures
Classification
- IPC, 3
- H04L29 06
- H04L29 08
- H04L9 32