Trust-based cross-domain authentication method

The invention relates to a trust-based cross-domain authentication method. The conventional method has the disadvantages of poor compatibility and low efficiency. The method comprises that: a first authentication server in a first trust domain performs identity authentication on a first entity, and sends an authentication result to a second authentication server in a second trust domain; the second authentication server verifies whether the first authentication server is lawful by utilizing the pre-established PKI authentication-based trust relationship, if the first authentication server is lawful, the process is continued, and if the first authentication server is not lawful, the process is finished; and finally, the second authentication server judges whether the received authentication result indicates the first authentication server passes the authentication, if the authentication result indicates the first authentication server passes the authentication, the cross-domain authentication is successful, and if the authentication result indicates the first authentication server does not pass the authentication, the cross-domain authentication is failed. The method simplifies the cross-domain authentication flow and improves the cross-domain authentication efficiency.