Patent attributes
In a network authentication method, a client device stores a certificate reference mapped uniquely to a certificate, which is assigned to an end user, and a reference private key obtained by encrypting a private key with a PIN code determined by the end user. The client device generates a digital signature for transaction data associated with the certification reference using a current key that is obtained by decrypting the reference private key with a user input code obtained through an input operation. A verification server verifies, based on a public key of a stored certificate, whether a received digital signature is signed with the private key, and obtains from the digital signature the transaction data when verification result is affirmative.