Digital identity encryption authentication method

By generating a master key store and constructing a multi-level authentication chain, performing two-way verification and path reconstruction, the problem of key management and rigid authentication rules in traditional digital identity authentication methods in complex network environments is solved, achieving highly secure and flexible digital identity authentication.

CN120915561AActive Publication Date: 2025-11-07YIQIBANG (ANHUI) DIGITAL TECHNOLOGY CO LTD

Patent Information

Application Number
CN202511186128.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-23
Publication Date
2025-11-07
Estimated Expiration
2045-08-23

AI Technical Summary

Technical Problem

Traditional digital identity authentication methods suffer from problems such as rigid key management, lack of dynamic adjustment of authentication rules, and insufficient anomaly handling capabilities when facing the collaborative authentication needs of multiple devices and users in complex network environments, making it difficult to meet the requirements of high security and flexibility.

Method used

By collecting biometric data, dynamic token data, and identity credential data to generate a master key library, performing multi-dimensional encryption preprocessing, extracting fragmented verification features, constructing a multi-level authentication chain and performing two-way verification, identifying abnormal nodes and reconstructing paths, the system achieves dynamic authentication rule adjustment and intelligent anomaly handling.

Benefits of technology

It improves the security and standardization of key management, the scientific nature and flexibility of authentication strategies, enhances the stability and self-healing capabilities of the authentication system, and adapts to the collaborative authentication needs of multiple devices and multiple users in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915561A_ABST
    Figure CN120915561A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of digital identity authentication, and discloses a digital identity encryption authentication method, which comprises the following steps of: acquiring a user identity information feature data set, and generating a master key library through multi-dimensional encryption preprocessing; extracting fragment verification features of each master key library to determine an authentication rule; and constructing a multi-level authentication chain and a verification node, and obtaining a node authentication state through bidirectional verification. In an effective authentication state, the master key library is subjected to association authentication according to permission levels; and in the invalid authentication state, identifying the abnormal verification node, calculating the authentication offset of the master key library under the abnormal verification node, and reconstructing the path of the abnormal verification node based on the authentication offset until the authentication is completed. Wherein the generation of the master key library relates to encryption, confusion and format standardization of various types of data; fragment verification feature extraction comprises key fragment sorting and the like; the authentication rule is determined based on the dynamic feature priority; and exception processing is combined with historical tracing and offset calculation. According to the method, the authentication security and the dynamic adaptability are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of digital identity authentication, in particular to a digital identity encryption authentication method. BACKGROUND

[0002] In the digital era, digital identity authentication, as a core link to ensure information security, is facing increasingly complex security challenges. Traditional digital identity authentication methods mostly use single-dimensional encryption verification methods, such as relying only on static passwords or simple biometric identification. When facing security threats such as data leakage and identity forgery, the protection capability is insufficient. With the diversification and intelligentization of network attack means, single authentication mode is difficult to meet the strict requirements of user identity authenticity and data integrity in high security scenarios.

[0003] In the prior art, although some authentication schemes introduce the concept of multi-factor authentication, there are significant defects in key management, authentication path construction and abnormal processing mechanism. For example, the key storage method lacks dynamic adaptability and cannot adjust the encryption strategy according to real-time security threats; the authentication path is fixed and difficult to respond to dynamic attacks in complex network environments; the processing of abnormal authentication nodes lacks systematicness, which can easily lead to authentication link interruption or security vulnerabilities. In addition, traditional methods lack sufficient data confusion and standardization when processing multi-dimensional identity information, which may cause problems such as encryption field redundancy and low verification efficiency, and cannot achieve efficient integration and secure storage of biometric data, dynamic token data and identity credential data.

[0004] In terms of dynamic adjustment of authentication rules, the prior art lacks scientific division of verification feature priority, and cannot update the authentication strategy in real time according to the dynamic changes of the features, resulting in that the authentication priority of high-risk features is lower than that of static features, increasing the security risks of the authentication process. At the same time, the path reconstruction mechanism of abnormal nodes lacks the ability of historical tracing and dynamic correction, and it is difficult to quickly locate the root cause of authentication deviation and implement effective repair, affecting the stability and reliability of the authentication system.

[0005] With the widespread application of cloud computing, Internet of Things and other technologies, digital identity authentication scenarios are increasingly diversified, and higher requirements are put forward for the flexibility, scalability and security of the authentication system. Traditional authentication methods have been difficult to adapt to the collaborative authentication needs of multiple devices and multiple users in complex network environments due to their rigid architecture and insufficient dynamic response capability. Therefore, there is an urgent need for a digital identity encryption authentication method that can realize multi-dimensional encryption preprocessing, dynamic authentication rule adjustment, multi-level authentication chain construction and intelligent abnormal processing, in order to improve the security, reliability and adaptability of the authentication system and meet the high-standard requirements of new generation information technology for digital identity authentication. SUMMARY

[0006] The present application aims to provide a digital identity encryption authentication method to solve the problems raised in the background.

[0007] To achieve the above-mentioned purpose, the present application provides the following technical solutions: a digital identity encryption authentication method, the method comprising:

[0008] Obtaining a feature data set of user identity information and performing multi-dimensional encryption preprocessing to generate a master key library;

[0009] Extracting the slice verification features of each master key library and determining the authentication rules of different key libraries according to the slice verification features;

[0010] According to the authentication rules, the authentication path of each master key library is constructed to form a multi-level authentication chain and the verification nodes of each authentication chain;

[0011] Each verification node is subjected to bidirectional verification to obtain the authentication status of each node, wherein the authentication status includes valid authentication status and invalid authentication status;

[0012] In the valid authentication status, the master key libraries under each verification node are subjected to associated authentication according to the permission level;

[0013] In the invalid authentication status, the abnormal verification nodes are identified and the authentication offset of the master key libraries under the abnormal verification nodes is calculated;

[0014] Based on the authentication offset, the path of the abnormal verification nodes is reconstructed until all the master key libraries complete the authentication according to the permission level.

[0015] Preferably, the feature data set of user identity information is obtained and subjected to multi-dimensional encryption preprocessing to generate a master key library, comprising:

[0016] Collecting biological feature data, dynamic token data and identity certificate data, respectively encrypting them into independent key units, and assigning each key unit a unique encryption identifier;

[0017] The data in each independent key unit is subjected to obfuscation processing to remove repeated or redundant encryption fields;

[0018] The obfuscated independent key units are subjected to format standardization processing to unify the encryption structure of the key units, and the independent key units with unified structure are output as the master key library.

[0019] Preferably, the slice verification features of each master key library are extracted, comprising:

[0020] Obtaining the key slices under each master key library and sorting them according to the verification strength;

[0021] extracting logical correlation between adjacent key fragments, and marking as hierarchical decision parameters;

[0022] obtaining a preset hierarchical threshold, and dividing intervals according to the hierarchical threshold to generate a plurality of verification intervals;

[0023] counting the number of decision parameters in each verification interval and recording as a feature weight parameter, and determining the shard verification features of each master key library based on the feature weight parameter;

[0024] Among them, the shard verification features include static features and dynamic features, and the authentication priority of the dynamic features is higher than that of the static features.

[0025] Preferably, the determination of the shard verification features of each master key library based on the feature weight parameter comprises:

[0026] obtaining the feature weight parameter under each master key library;

[0027] Sort the feature weight parameters under the same master key library from low to high according to the numerical value, and calculate the deviation weight of the feature weight parameter with the lowest numerical value;

[0028] obtaining a deviation threshold and comparing the deviation threshold with the deviation weight of the feature weight parameter with the lowest numerical value;

[0029] If the deviation weight is greater than the deviation threshold, it is determined that the master key library corresponding to the feature weight parameter has dynamic features;

[0030] If the deviation weight is less than or equal to the deviation threshold, it is determined that the master key library corresponding to the feature weight parameter has static features.

[0031] Preferably, the determination of the authentication rules of different key libraries according to the shard verification features comprises:

[0032] obtaining the shard verification features of each master key library;

[0033] The minimum value of the verification interval corresponding to the dynamic feature is taken as the permission judgment threshold;

[0034] Summarize the permission judgment threshold of the master key library under all dynamic features, and arrange them from large to small to generate an authentication priority sequence;

[0035] According to the authentication priority sequence, the permission of each master key library is determined, and after the master key library under the dynamic feature is determined, the master key library under the static feature is additionally determined;

[0036] The generating of the authentication priority sequence comprises:

[0037] Obtaining the historical change record of the permission judgment threshold of the master key library under the dynamic feature;

[0038] Extracting the actual effective number of times of the permission judgment threshold in the historical authentication path, and calculating the error ratio thereof with the preset number of times;

[0039] Generating a dynamic correction factor based on the error ratio, and weighting and adjusting the current permission judgment threshold according to the correction factor;

[0040] Summarizing the weighted permission judgment threshold, rearranging the authentication priority sequence, and synchronizing the adjusted sequence to the path construction of the subsequent verification nodes.

[0041] Preferably, the bidirectional verification of each of the verification nodes comprises:

[0042] Obtaining the authentication result of the master key library under each of the verification nodes, and performing hash check conversion to generate a plurality of check parameters;

[0043] Calling a preset check algorithm, inputting the check parameters into the check algorithm, and recording the output value as an authentication parameter;

[0044] Obtaining an authentication threshold, and comparing the authentication parameter with the authentication threshold;

[0045] If the authentication parameter is less than the authentication threshold, it is determined that the verification node is in an effective authentication state;

[0046] If the authentication parameter is greater than or equal to the authentication threshold, it is determined that the verification node is in an invalid authentication state.

[0047] Preferably, the calculation of the authentication offset of the master key library under the abnormal verification node comprises:

[0048] Obtaining the actual verification node of the master key library that has not completed the associated authentication under the abnormal verification node;

[0049] Calculating the logical difference between the actual verification node and the abnormal verification node, and marking it as a real-time offset;

[0050] Historically tracing the abnormal verification node to extract the historical offset of the associated historical node thereof;

[0051] Obtaining a preset error threshold, and terminating the tracing operation when the historical offset is less than or equal to the error threshold;

[0052] Calling an offset calculation function, inputting the real-time offset and the historical offset into the calculation function, and recording the output result as the authentication offset.

[0053] Preferably, the path reconstruction of the abnormal verification node based on the authentication offset comprises:

[0054] Statistics of the historical trace number of the abnormal verification node are obtained and recorded as a reconstruction reference value;

[0055] A reconstruction threshold is obtained, and the reconstruction reference value is compared with the reconstruction threshold;

[0056] When the reconstruction reference value is greater than or equal to the reconstruction threshold, the abnormal verification node is logically reset according to the authentication offset, a reconstruction verification node is generated, and the associated authentication is performed under the reconstruction verification node;

[0057] When the reconstruction reference value is less than the reconstruction threshold, the authentication offset is continuously collected until the reconstruction reference value reaches or exceeds the reconstruction threshold to trigger the path reconstruction.

[0058] Preferably, the hash check conversion comprises:

[0059] The encryption field and the permission attribute in the authentication result are extracted to construct a composite check parameter;

[0060] The composite check parameter is fragmented and recombined to generate a standardized hash sequence;

[0061] According to a preset permission weight matrix, the standardized hash sequence is iteratively calculated to generate the check parameter and input the check algorithm.

[0062] Preferably, the dynamic correction factor is generated based on the error ratio, and the current permission determination threshold is weighted and adjusted according to the correction factor, comprising:

[0063] The effective frequency of the dynamic feature in the current authentication path is obtained;

[0064] A dynamic attenuation factor is generated based on the effective frequency, and the permission determination threshold is attenuated and compensated;

[0065] The compensated permission determination threshold is synchronized to the master key library verification in the next authentication cycle.

[0066] Compared with the prior art, the present application has the following advantages:

[0067] In terms of key management, by collecting biometric data, dynamic token data and identity certificate data and encrypting them into independent key units respectively, and assigning each key unit a unique encrypted identifier, the security isolation and independent storage of multi-source identity information are effectively realized. The data in the independent key unit is processed by confusion and redundant encrypted fields are removed, improving the compactness and security of data storage. Format standardization processing unifies the encryption structure of the key unit, facilitating efficient calling and verification of the key library in the subsequent authentication process, and enhancing the standardization and systematicness of key management.

[0068] In terms of authentication rule construction, by extracting the verification features of the main key library and dividing the verification interval, combining the feature weight parameters to distinguish static features and dynamic features, and giving higher authentication priority to dynamic features, the priority verification of high-risk and high-dynamic features is ensured, and the scientificity and pertinence of the authentication strategy are improved. Based on the historical change record and error ratio, a dynamic correction factor is generated to weight and adjust the permission judgment threshold, so that the authentication priority sequence can be dynamically optimized according to the real-time authentication environment, and the adaptability and flexibility of the authentication rule are enhanced.

[0069] In terms of authentication link construction, by constructing multi-level authentication chain and setting verification nodes, hierarchical management of the authentication process is realized. The bidirectional verification mechanism ensures the accuracy and reliability of the authentication state of the verification node through hash check conversion and preset verification algorithm. The permission level association authentication in the effective authentication state realizes the ordered collaborative verification between different key libraries, improving the authentication efficiency. The abnormal node identification and authentication offset calculation in the invalid authentication state, combined with historical tracing and offset calculation function, can quickly locate the root cause of authentication anomaly, providing accurate basis for path reconstruction.

[0070] In terms of exception handling, according to the comparison result of the reconstruction reference value and the reconstruction threshold value, the path reconstruction is triggered by flexibly selecting the logical reset or continuously collecting the authentication offset, ensuring the efficient repair of the abnormal verification node. The logical reset generates a reconstruction verification node and performs associated authentication, which can quickly restore the normal operation of the authentication link. The record and analysis of the number of historical traces provide data support for long-term monitoring and systematic optimization of abnormal nodes, improving the stability and self-healing ability of the authentication system.

[0071] Through multi-dimensional technical innovation, the present application constructs a complete digital identity encryption authentication system covering key generation, authentication rule formulation, authentication link construction and exception handling, effectively solving the shortcomings of traditional authentication methods in security, dynamics and adaptability, providing an efficient and reliable technical solution for digital identity authentication in complex scenarios such as cloud computing and Internet of Things, and having significant engineering application value and market prospect. BRIEF DESCRIPTION OF DRAWINGS

[0072] Figure 1 The working principle diagram of the digital identity encryption authentication method of the present application;

[0073] Figure 2 The design diagram of the fragment verification feature determination method;

[0074] Figure 3 The design diagram of the authentication rule determination method;

[0075] Figure 4 The design diagram of the authentication offset calculation method. DETAILED DESCRIPTION

[0076] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0077] Please refer to Figures 1-4 The digital identity encryption authentication method of the present application involves the following specific implementation steps:

[0078] Obtain the feature data set of user identity information and perform multi-dimensional encryption preprocessing to generate a master key library. Through multi-dimensional encryption processing of user identity information, the security and reliability of the master key library are ensured.

[0079] Extract the fragment verification features of each master key library and determine the authentication rules of different key libraries according to the fragment verification features. By analyzing the fragment verification features of the master key library, appropriate authentication rules are formulated for different key libraries to ensure the accuracy and effectiveness of authentication.

[0080] According to the authentication rules, the authentication paths of each master key library are constructed to form a multi-level authentication chain and the verification nodes of each authentication chain. According to the authentication rules, the authentication paths are constructed to form a multi-level authentication chain and verification nodes, which provide structural support for the subsequent authentication process.

[0081] Each verification node is subjected to bidirectional verification to obtain the authentication status of each node, wherein the authentication status includes valid authentication status and invalid authentication status. The authentication status of the verification node is determined through bidirectional verification for subsequent processing.

[0082] In the valid authentication state, the master key libraries under each verification node are subjected to associated authentication according to the permission level. It is ensured that in the valid authentication state, the master key libraries can be correctly associated and authenticated according to the permission level.

[0083] In the invalid authentication state, an abnormal authentication node is identified, and an authentication offset of the master key library under the abnormal authentication node is calculated. Identifying the abnormal authentication node in time and calculating the authentication offset provide a basis for path reconstruction.

[0084] Based on the authentication offset, path reconstruction is performed on the abnormal authentication node, and the process is terminated after all the master key libraries complete authentication according to the permission hierarchy. Through path reconstruction, the abnormal authentication node is restored to normal, and it is ensured that all the master key libraries complete authentication.

[0085] The technical solutions of the present application will be further described in detail below in combination with specific embodiments.

[0086] Embodiment 1:

[0087] In the process of obtaining the feature data set of user identity information and generating the master key library, the specific implementation is as follows: first, multi-dimensional data acquisition of user identity information needs to be completed, and the acquisition process covers three types of core information, namely, biological feature data, dynamic token data and identity certificate data. Among them, the biological feature data includes but is not limited to fingerprint line features, iris pigment distribution features, voice frequency features and other inherent physiological or behavioral characteristics of human body. These data are collected through professional biological recognition equipment, for example, a fingerprint collector obtains fingerprint images through optical imaging or capacitive sensing, an iris recognition device captures iris texture details through a near-infrared camera, and a voiceprint collection module records voice samples through a microphone and extracts frequency spectrum features. Dynamic token data is a one-time dynamic password generated based on time synchronization or event triggering mechanism, commonly seen in dynamic codes generated by hardware token devices or mobile phone APPs, for example, a token based on time synchronization generates a new 6-digit password every 60 seconds, which is synchronized and checked with the timestamp on the authentication server. Identity certificate data includes legal identity identifier such as ID number, passport number, driver's license number, and user-defined account identifier, etc. These data are obtained through manual input or system interface connection, for example, through an ID card reader to read the identity information in the chip, or through manual input of account and password by the user in the registration interface.

[0088] After the collection is completed, the three types of data need to be independently encrypted, and independent key units are generated. The encryption process adopts a hierarchical encryption strategy, and different encryption algorithms are selected according to the characteristics of different types of data. For biometric data, due to its large data volume and irreversibility, AES-256 encryption algorithm is used for block encryption. The original biometric data is divided into fixed-size data blocks, each data block is encrypted using a different session key, and the session key is protected by the master key. The master key is stored and managed by the hardware security module (HSM). Dynamic token data is strongly time-sensitive, so HMAC-SHA256 algorithm is used for encryption. The dynamic token value and the key are hashed to generate a fixed-length encrypted digest. This digest is transmitted with the timestamp to verify the validity and freshness of the dynamic token. Identity credential data involves sensitive personal information, so RSA asymmetric encryption algorithm is used to encrypt the identity credential data using the server's public key. The encrypted data can only be decrypted by the corresponding private key to ensure the confidentiality of the data during transmission and storage. After completing the encryption operation, a unique encryption identifier is assigned to each independent key unit. The identifier is generated using the UUID (Universal Unique Identifier) generation rule, which consists of 128-bit binary numbers. It is generated by combining timestamp, node MAC address and random number to ensure uniqueness worldwide, facilitating accurate identification and management of key units in the future.

[0089] The data in each independent key unit is subjected to obfuscation processing to further enhance the security and attack resistance of the data. Obfuscation processing includes field scrambling and redundancy elimination. Field scrambling refers to randomly rearranging the order of encrypted data fields to break the logical structure of the original data. For example, the fingerprint feature point coordinate field, direction field, and curvature field in biometric data are rearranged in random order, making it difficult for attackers to infer the true meaning of the data even if they obtain the encrypted data. Redundancy elimination identifies and removes duplicate or redundant encrypted fields in each key unit, such as duplicate timestamp fields or fixed-format redundant characters in identity credential data and dynamic token data. These are detected and removed through hash value comparison or regular expression matching, reducing data storage and transmission overhead and reducing security risks caused by data redundancy. During the obfuscation process, a strict data verification mechanism must be established to ensure that the integrity of the data is not compromised after scrambling and deduplication. For example, by calculating the MD5 checksum of the data before and after obfuscation, the checksums are compared to ensure consistency. If they are not consistent, the data recovery process is triggered and the obfuscation process is restarted.

[0090] After the obfuscation process is completed, the independent key unit needs to be standardized in format, and the encryption structure of the key unit is unified. Standardization processing includes data format definition and metadata packaging. Data format definition specifies the basic structure of each key unit, including header information, data body and tail check. The header information includes encryption identifier, data type identifier (biometric data, dynamic token data or identity credential data), encryption algorithm identifier, version number and other metadata, which are used to identify the basic attributes and encryption parameters of the key unit; the data body is the obfuscated encrypted data; the tail check contains the CRC check code generated based on the data body, which is used to verify the integrity of the data during transmission and storage. Metadata packaging is to combine the header information, data body and tail check according to the specified format to generate a standard key unit file, such as using JSON format or binary format for packaging, to ensure that different systems and modules can correctly parse and process the key unit. During the format standardization process, relevant industry standards and specifications need to be followed, such as the biometric data exchange format standard (ANSI / INCITS 378), public key infrastructure (PKI) standard, etc., to ensure the compatibility and interoperability of the master key library.

[0091] Finally, the independent key unit with unified structure is output as the master key library. The storage of the master key library adopts a distributed storage architecture, and different types of key units are stored in different physical servers or cloud storage nodes, and through load balancing and data redundancy mechanisms to ensure data availability and reliability. For example, the key unit of biometric data is stored in a dedicated biometric data server, the key unit of dynamic token data is stored in a dynamic authentication server, and the key unit of identity credential data is stored in a user center database, and each storage node communicates and synchronizes through a secure data channel. The output interface of the master key library needs strict permission control, only authorized systems and modules can access and call the data in the master key library, and the access process uses OAuth 2.0 and other authentication authorization protocols to ensure the security of data access. At the same time, a version management mechanism of the master key library is established, when the encryption algorithm, data format or business requirement changes, the master key library can be upgraded and updated in time to ensure the sustainability and adaptability of the system.

[0092] During the entire process of generating the master key library, each link is closely connected to form a complete data processing chain. The data acquisition link ensures that comprehensive and accurate user identity information is obtained; the independent encryption link ensures the confidentiality of the data through the adapted encryption algorithm; the allocation of the encrypted identifier provides a unique identifier for the management of the key unit; the obfuscation process further enhances the security of the data; the format standardization process ensures the standardization and compatibility of the key unit; and the distributed storage and permission control ensure the availability and access security of the master key library. Each link uses mature technology and strict process control to ensure that the generation process of the master key library meets the information security standards and business requirements, and provides a solid data foundation for subsequent operations such as slice verification feature extraction, authentication rule determination, and authentication path construction. Through this series of implementation steps, a secure, reliable, and easy-to-manage master key library can be generated, laying a key foundation for the overall operation of the digital identity encryption and authentication system, and ensuring that the data in the master key library can be accurately and efficiently used in the subsequent authentication process to achieve reliable authentication and encryption protection of user identity.

[0093] Embodiment 2:

[0094] When extracting the slice verification features of each master key library, the key slices under the master key library need to be obtained. These key slices are independent data units formed by the master key library according to specific rules, and the splitting method can be based on data type, timestamp, or business logic, etc. For example, for a master key library composed of biometric data, it can be sliced according to different biometric types such as fingerprints, irises, and voiceprints; for a master key library containing dynamic token data of multiple time periods, it can be time-sliced according to the timestamp. After obtaining the key slices, their integrity needs to be checked by calculating the hash value of each slice and comparing it with the pre-stored hash value in the master key library to ensure that the obtained key slices have not been tampered with or damaged.

[0095] The key fragments are sorted according to the verification strength. The verification strength is an indicator that measures the importance and reliability of the key fragments in the identity authentication process, which needs to consider multiple factors. For biometric key fragments, the verification strength is related to the uniqueness, stability and anti-fake of the features. For example, the iris feature has high uniqueness and stability, and its verification strength is high; while the fingerprint feature, although widely used, has the risk of being forged, and its verification strength is relatively low. For dynamic token key fragments, the verification strength is related to the complexity of the token generation algorithm, timeliness and anti-replay attack capability. Based on time synchronization, the dynamic token is updated every 60 seconds and the generation algorithm contains a random factor, so the verification strength is high; while the event-triggered dynamic token, if the trigger mechanism is simple, the verification strength is relatively low. The verification strength of identity credential key fragments is related to the authority and anti-fake technology of the credential, such as the identity card using electronic chip and digital signature technology, whose verification strength is higher than that of ordinary paper credentials. The sorting process uses a weighted scoring mechanism to assign appropriate weights to each factor affecting the verification strength, and calculates the verification strength score of each key fragment, and then sorts them from high to low according to the score.

[0096] After sorting, the logical correlation between adjacent key fragments is extracted. The logical correlation reflects the internal connection between key fragments in data structure, business logic or time sequence. For biometric key fragments, adjacent fragments may correspond to different parts of the same biometric feature, such as different areas of a fingerprint, and their logical correlation is reflected in the continuity and matching degree of feature points. By calculating the Euclidean distance, direction consistency and other indicators of adjacent fingerprint fragment feature points, the logical correlation can be quantified. For dynamic token key fragments, adjacent fragments may correspond to tokens generated at different time points, and their logical correlation is reflected in the continuity of time sequence and the relevance of generation algorithm. By analyzing the time interval, numerical change rule and common parameters in the generation algorithm of adjacent tokens, the logical correlation can be evaluated. The logical correlation of identity credential key fragments is reflected in the consistency and complementarity of the credential information, such as the association between the identity card number and the name, birth date and other information. After extracting the logical correlation, it is labeled as a hierarchical decision parameter for subsequent interval division and feature weight calculation.

[0097] The preset classification threshold is a standard value pre-set according to a large amount of historical data and business experience, and is used to divide the logical correlation degree judgment parameters into different intervals. These intervals represent different correlation strength levels, such as a strong correlation interval, a medium correlation interval, and a weak correlation interval. The division process adopts a dynamic threshold adjustment mechanism, which automatically adjusts the classification threshold according to the characteristics of the current master key library and changes in the authentication environment. For authentication scenarios with high security level requirements, the threshold of the strong correlation interval can be appropriately increased, and the range of the weak correlation interval can be narrowed; for general authentication scenarios, the threshold limit can be relaxed. After the interval division is completed, multiple verification intervals are generated, each corresponding to a different correlation strength level.

[0098] The number of judgment parameters in each verification interval is counted and recorded as a feature weight parameter. The feature weight parameter reflects the importance of each verification interval in the overall logical correlation degree, and its calculation is based on the distribution density and correlation strength of the judgment parameters. In the strong correlation interval, the more the number of judgment parameters, the tighter the logical connection between the key fragments in this interval, and the greater the contribution to the reliability of the overall authentication, so a higher feature weight parameter is given. In the weak correlation interval, the number of judgment parameters is small, and its influence on the overall authentication is relatively small, so the feature weight parameter is also relatively low. In this way, the qualitative analysis of logical correlation is converted into a quantitative representation of the feature weight parameter, providing data support for subsequent determination of the fragment verification features of the master key library.

[0099] Based on the feature weight parameters, the fragment verification features of each master key library are determined, including static features and dynamic features. The determination process first obtains the feature weight parameters under each master key library, and sorts the feature weight parameters under the same master key library from low to high. After sorting, the deviation weight of the lowest numerical value feature weight parameter is calculated. The deviation weight is an index that measures the deviation of this feature weight parameter from other parameters, which is calculated based on methods such as standard deviation and coefficient of variation in statistics. By calculating the difference between this feature weight parameter and the average value of all parameters, and standardizing the difference, the deviation weight value is obtained.

[0100] The deviation threshold is compared with the deviation weight of the feature weight parameter with the lowest numerical value. The deviation threshold is a standard value preset according to the system stability and authentication accuracy requirement, which is used to judge whether the feature weight parameter deviates abnormally. If the deviation weight is greater than the deviation threshold, it means that the verification interval corresponding to the feature weight parameter has a significant difference with other intervals, which may reflect the dynamic change characteristics of the master key library, so it is determined that the master key library has dynamic characteristics. If the deviation weight is less than or equal to the deviation threshold, it means that the feature weight parameter is consistent with other parameters, and the verification features of the master key library are relatively stable, so it is determined that the master key library has static characteristics. The authentication priority of dynamic characteristics is higher than that of static characteristics, because dynamic characteristics can more timely reflect the real-time state and change trend of the master key library, and improve the accuracy and security of authentication.

[0101] In the whole process of extracting the verification features of the fragments, each step is closely connected and interacts with each other. The integrity check of the key fragments ensures the reliability of the data, providing an accurate basis for subsequent analysis. The verification strength sorting allows the key fragments of different importance to be distinguished, facilitating the focus on high verification strength fragments. The logical correlation is extracted and the interval is divided, which converts the complex relationship between key fragments into quantifiable feature parameters. The statistical feature weight parameters and the determination of the fragment verification features further convert these parameters into authentication features with practical significance, providing a basis for subsequent authentication rule making. The whole process uses a variety of data analysis and statistical methods to ensure the accuracy and effectiveness of the fragment verification features, which can provide reliable feature support for the digital identity encryption authentication system, so that the system can develop personalized authentication strategies according to the characteristics of different master key libraries, and improve the efficiency and security of authentication.

[0102] Embodiment 3:

[0103] When determining the authentication rules of different key libraries according to the fragment verification features, the fragment verification features of each master key library need to be comprehensively obtained, which include static features and dynamic features. Dynamic features have strong real-time performance and high authentication priority, and become the core basis for determining authentication rules. After obtaining the features, the minimum value of the verification interval corresponding to the dynamic features is extracted as the permission judgment threshold. The setting of this threshold needs to be combined with the data characteristics of the key library. For example, the minimum value of the verification interval corresponding to the dynamic features in the biological feature type master key library may be related to the real-time collection error range of fingerprints, iris and other biological features. The threshold of the dynamic token type master key library is related to the timestamp precision of the token generation algorithm and the range of random factors. This threshold is used to measure the permission level of the master key library in the authentication process. The larger the value, the higher the authority and reliability of the key library in authentication.

[0104] All the permission determination thresholds of the master key vaults under the dynamic features are summarized and arranged in descending order of the thresholds to generate an initial authentication priority sequence. The generation of the sequence follows the "threshold priority" principle, that is, the master key vaults with higher thresholds are given priority in the permission determination in the authentication process. For example, in a system that contains both dynamic tokens and biometric dynamic features, if the permission determination threshold of the dynamic token is 85 and the threshold of the biometric dynamic feature is 70, the master key vault corresponding to the dynamic token is arranged in the front row in the authentication priority sequence. After the initial sequence is formed, it needs to be dynamically optimized in combination with historical authentication data to adapt to changes in the actual authentication environment.

[0105] The dynamic optimization process starts with obtaining the historical change records of the permission determination thresholds of the master key vaults under the dynamic features. These records contain information such as the time, reason, and adjustment range of the threshold adjustment, and by analyzing them, the rules and trends of threshold changes can be found. For example, some master key vaults may have their permission determination thresholds frequently changed due to business demand adjustment or security policy upgrade. Then, the actual effective times of the permission determination thresholds in the historical authentication paths are extracted, that is, the number of times that the threshold is successfully applied in the authentication process and passes the verification, and the error proportion of the preset number of times is calculated. The preset number of times can be set according to the authentication frequency and stability requirements of the system, and the error proportion reflects the deviation of the actual threshold effectiveness from the expected value.

[0106] Based on the error proportion, a dynamic correction factor is generated, which is used to adjust the current permission determination threshold. The calculation of the correction factor uses algorithms such as linear interpolation or exponential smoothing, for example, when the error proportion is positive (the actual effective times exceed the preset number of times), it means that the applicability of the threshold is higher, and a positive correction factor can be generated to enhance the adjustment of the threshold; when the error proportion is negative, a negative correction factor is generated to attenuate the adjustment of the threshold. The adjusted permission determination threshold is closer to the actual authentication requirements, for example, the permission determination threshold of a certain dynamic token master key vault is adjusted from 85 to 88 after correction to cope with the recent frequent high-security level authentication requests.

[0107] The weighted permission determination thresholds are summarized, the authentication priority sequence is rearranged, and the adjusted sequence is synchronized to the path construction of the subsequent verification nodes. This synchronization process is realized through system message queues or data interfaces to ensure that each verification node obtains the latest authentication priority information in real time. For example, in a multi-level authentication chain, after the front-end verification node adjusts the authentication priority sequence, it synchronizes the sequence to the back-end node through a secure data channel, so that the permission determination logic of the entire authentication path remains consistent.

[0108] After the permission determination of the master key library under dynamic characteristics is completed, the master key library under static characteristics needs to be determined. The authentication priority of static characteristics is lower than that of dynamic characteristics, and the permission determination process is relatively fixed, which is usually based on pre-set static rules. For example, for the static characteristics of identity credential type master key library, a fixed permission level can be set, such as the highest level corresponding to the identity card, and the lower level for the ordinary account identifier. During the determination, the verification is performed in order according to the permission level of the static characteristics, and the permission determination of all master key libraries is completed.

[0109] During the entire authentication rule determination process, the priority processing of dynamic characteristics and the dynamic adjustment driven by historical data are the keys. By taking the minimum value of the verification interval corresponding to the dynamic characteristics as the permission determination threshold, the sensitivity of the authentication rule to real-time data is ensured; based on the error analysis of the historical change record and the actual effective number of times, the authentication priority sequence can adapt to the changes of the business scene; and the additional determination of static characteristics supplements the comprehensiveness of the authentication rule, covering the authentication requirements with higher stability. Through data interaction and logical linkage, each link forms a set of authentication rule system combining dynamic and static, with clear priority, which provides clear execution basis for subsequent authentication path construction and bidirectional verification of verification nodes, and guarantees the standardization and efficiency of the digital identity encryption authentication process.

[0110] Embodiment 4:

[0111] When performing bidirectional verification on each verification node, the authentication result of the master key library under the verification node needs to be obtained first. The authentication result includes the processing state of the master key library at the current verification node, such as whether it passes the preliminary check, the permission matching situation, etc. These results are extracted from the storage and processing module of the master key library through the authentication interface, and the extraction process needs to follow the security protocol to ensure the confidentiality and integrity of the data during transmission, such as using the TLS encrypted channel for data transmission to prevent the authentication result from being stolen or tampered.

[0112] After obtaining the authentication result, it needs to be converted by hash check, which includes three key steps. The first step is to construct a composite check parameter, that is, to extract the encryption field and permission attribute in the authentication result. The encryption field includes the encryption identifier, encryption algorithm identifier and other metadata used by the master key library during generation and processing, as well as the user identity information data after obfuscation and encryption; the permission attribute involves the user permission level corresponding to the master key library, the access control rule in the authentication path, etc. For example, for the authentication result of the biological feature type master key library, the encryption field may include the encrypted data block of the fingerprint feature and the AES-256 encryption algorithm identifier, and the permission attribute may indicate that the user has the permission to access the confidential level data. Combining these information, a composite check parameter containing multi-dimensional data is formed, which provides comprehensive input data for subsequent hash check.

[0113] The second step is to fragment and reorganize the composite verification parameter to generate a standardized hash sequence. Fragmentation and reorganization requires splitting the composite verification parameter into fixed-length data fragments according to pre-set rules and rearranging their order. For example, the composite verification parameter is split into fragments of 128 bits each, and then reorganized according to the order of encryption identifier, permission attribute, and encryption field to form a sequence structure that meets the input requirements of the hash algorithm. The generation of the standardized hash sequence requires that the fragmentation and reorganization process of the data fragments be deterministic, i.e., the same composite verification parameter will always generate the same hash sequence after processing, to ensure consistency and repeatability of the verification result.

[0114] The third step is to perform iterative calculations on the standardized hash sequence according to a pre-set permission weight matrix to generate a verification parameter and input it into the verification algorithm. The permission weight matrix is a pre-defined set of weight values used to measure the importance of different fields in the composite verification parameter. For example, the weight of the permission attribute field may be higher than that of the metadata field in the encryption field, because the permission attribute is directly related to the user's access rights and system security. The iterative calculation process uses a loop hash method to perform bitwise operations on the standardized hash sequence and the permission weight matrix, with the result of each operation serving as the input for the next operation. After several rounds of iteration, the final verification parameter is generated. This verification parameter is a fixed-length numerical value that uniquely represents the content and structure of the authentication result.

[0115] After completing the hash verification conversion, the pre-set verification algorithm is called, the verification parameter is input into the verification algorithm, and the output value is recorded as the authentication parameter. The pre-set verification algorithm can use common hash algorithms such as SHA-256, MD5, etc., or can be customized according to system security requirements. The core function of the verification algorithm is to perform complex mathematical operations on the verification parameter to generate an authentication parameter that reflects the authenticity of the authentication result. For example, using the SHA-256 algorithm to operate on the verification parameter generates a 256-bit binary number as the authentication parameter, which has a strict mapping relationship with the verification parameter. Any small change in the authentication result will cause a significant change in the authentication parameter.

[0116] The authentication threshold is obtained and compared with the authentication parameter. The authentication threshold is a value set in advance according to the security policy and authentication accuracy requirement of the system, which is used to judge the authentication state of the verification node. The setting of the authentication threshold needs to consider the balance of false positive rate and false negative rate, for example, in a high security level scene, the authentication threshold can be set to a higher value to strictly screen the effective authentication; in a general scene, the threshold can be appropriately reduced to improve the authentication efficiency. The comparison process uses numerical comparison, if the authentication parameter is less than the authentication threshold, it is determined that the verification node is in an effective authentication state, which means that the master key library is authenticated at the current node, and can enter the subsequent permission level association authentication link; if the authentication parameter is greater than or equal to the authentication threshold, it is determined that the verification node is in an invalid authentication state, and an exception handling process needs to be triggered to identify and repair the abnormal verification node.

[0117] In the whole two-way verification process, each link of the hash check conversion needs to strictly follow the algorithm rules and data processing flow to ensure the accuracy of the check parameter and the authentication parameter. When constructing the composite check parameter, the encrypted field and the permission attribute need to be extracted completely to avoid missing key information; the consistency of the segmentation and arrangement order of the data pieces needs to be ensured in the fragmentation and recombination process; the correct application of the permission weight matrix is required in the iterative calculation to ensure that the importance of different fields is reasonably reflected in the authentication parameter. The selection of the preset check algorithm and the setting of the authentication threshold need to be optimized according to the actual needs of the system, for example, in an environment with limited computing resources, the MD5 algorithm with higher operation efficiency can be selected; in a scene with extremely high security requirements, high-strength algorithms such as SHA-512 are preferred.

[0118] The two-way verification mechanism realizes the dynamic verification and state judgment of the verification node through the hash check and parameter comparison of the authentication result, can timely find the abnormal situation in the authentication process, and prevent unauthorized access and data leakage. The judgment of the effective authentication state ensures the normal access process of the legal user, and the identification of the invalid authentication state provides a warning and response mechanism for the security protection of the system, through the subsequent exception handling and path reconstruction, the authentication system can recover to normal operation, and the continuity and reliability of the digital identity encryption authentication are ensured. The whole process closely revolves around the authenticity and validity of the authentication result, through the standardized processing flow and rigorous algorithm application, the scientificity and credibility of the two-way verification are ensured.

[0119] Example 5:

[0120] In handling the invalid authentication state, first, the abnormal verification node needs to be identified, which refers to the verification node determined to be in the invalid authentication state by the two-way verification. The identification process is achieved through the state marker of the authentication system. After completing the two-way verification, the authentication state (valid or invalid) of each verification node is marked and stored in the system state table in real time. When the system detects a node marked as invalid through polling or event triggering mechanism, it determines that it is an abnormal verification node.

[0121] After determining the abnormal verification node, the authentication offset of the master key library under the node needs to be calculated. The specific steps are as follows: first, the actual verification node of the master key library that has not completed the associated authentication under the abnormal verification node is obtained. The actual verification node refers to the next node or the previous node in the authentication path that should be directly associated and authenticated according to the normal logic, and its information is stored in the logical structure table of the authentication path. For example, in a multi-level authentication chain, the abnormal verification node is the nth node, and its actual verification node may be the n+1 node (next node) or the n-1 node (previous node), depending on the direction of the authentication path.

[0122] The logical difference between the actual verification node and the abnormal verification node is calculated and marked as the real-time offset. The calculation of the logical difference is based on the logical hierarchical relationship of the nodes in the authentication path. Each node is assigned a unique logical hierarchical number (such as 1, 2, 3, …, n) in the authentication chain, and the logical difference is the absolute difference between the hierarchical numbers of the two nodes. Let the hierarchical number of the abnormal verification node be , and the hierarchical number of the actual verification node be , then the real-time offset . This offset reflects the hierarchical deviation of the abnormal node in the authentication path.

[0123] The historical offset of the associated historical nodes of the abnormal verification node is extracted through historical tracing. Historical tracing is achieved by querying the authentication log, which records the logical difference between the abnormal verification node and the associated nodes in the historical authentication process. The tracing process traces back from the current abnormal event, and extracts the historical offset at each abnormal occurrence , until the extracted historical offset is less than or equal to the preset error threshold , and the tracing operation is terminated. The preset error threshold is a fixed value set in advance according to the stability requirements of the authentication system, which is used to determine whether the historical offset is within the normal fluctuation range.

[0124] After extracting the real-time offset and the historical offset, the offset calculation function is called, and the real-time offset and the historical offset are input into the calculation function, and the output result is recorded as the authentication offset. The offset calculation function uses the weighted summation method, and the formula is:

[0125]

[0126] wherein, is an authentication offset, and are weighting coefficients of real-time offset and historical offset respectively (0 , and ) for reflecting the degree of influence of both on the authentication offset; is the number of historical offsets traced back, is the historical offset. The value of the weighting coefficient is set according to the real-time requirement of the authentication system, for example, when the system pays more attention to the current exception, the value is higher, and vice versa.

[0127] Based on the authentication offset, the path of the abnormal verification node is reconstructed. First, the historical tracing number of the abnormal verification node is counted and recorded as the reconstruction reference value . The historical tracing number refers to the total number of times that the node triggers the historical tracing operation in the past period of time, reflecting the frequency of node exceptions. The reconstruction threshold is obtained, which is a preset integer threshold according to the fault tolerance capability of the system, for judging whether to trigger path reconstruction.

[0128] The reconstruction reference value is compared with the reconstruction threshold : if , it means that the abnormal verification node frequently appears offset and needs to be deeply repaired, at this time, the abnormal verification node is logically reset according to the authentication offset . The logical reset is realized by modifying the hierarchical number of the node in the authentication path, for example, adjusting the original hierarchical number to , so that the node is matched to the correct logical level again, a reconstructed verification node is generated, and the associated authentication process is re-executed under the reconstructed verification node; if , it means that the exception is still within the acceptable range, at this time, the authentication offset is continuously collected until reaches or exceeds , and then the path reconstruction is triggered.

[0129] ​During the whole invalid authentication state processing, the calculation of real-time offset is based on the logical relationship of node hierarchy, historical tracing ensures the analysis of abnormal trends, weighted calculation of authentication offset integrates current and historical data, and comparison mechanism of reconstructed reference value and threshold balances the stability and fault tolerance of the system. Through a series of operations, the authentication system can take corresponding repair measures for abnormal verification nodes of different severity, avoid authentication interruption caused by single abnormality, and gradually eliminate the cumulative effect of node offset through multiple retraces and final path reconstruction, ensuring that all master key libraries complete authentication according to the permission hierarchy and maintaining the normal operation of the digital identity encryption authentication system.

[0130] It should be noted that, in this text, relational terms such as first and second are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device.

[0131] Although embodiments of the present application have been shown and described, it will be understood by those having ordinary skill in the art that various changes, modifications, alternatives and variations can be made thereto without departing from the principles and spirit of the present application, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A digital identity encryption authentication method, characterized in that: The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device.

2. The digital identity encryption authentication method of claim 1, wherein: The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device.

3. The digital identity encryption authentication method of claim 1, wherein: The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device.

4. The digital identity encryption authentication method of claim 3, wherein: The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device.

5. The digital identity encryption authentication method of claim 3, wherein: The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The application relates to a multi-dimensional multi-level multi-key authentication method and device. The minimum value of the verification interval corresponding to the dynamic feature is taken as a permission judgment threshold value; The permission judgment threshold values of the master key libraries under all the dynamic features are summarized, arranged in descending order of threshold value, and an authentication priority sequence is generated; The permission of each master key library is judged according to the authentication priority sequence, and after the master key library under the dynamic feature is judged, the master key library under the static feature is additionally judged; The generation of the authentication priority sequence comprises: A history change record of the permission judgment threshold value of the master key library under the dynamic feature is obtained; The actual effective number of times of the permission judgment threshold value in the historical authentication path is extracted, and an error ratio with a preset number of times is calculated; A dynamic correction factor is generated based on the error ratio, and the current permission judgment threshold value is weighted and adjusted according to the correction factor; The weighted permission judgment threshold values are summarized, the authentication priority sequence is rearranged, and the adjusted sequence is synchronized to the path construction of the subsequent verification nodes.

6. The digital identity encryption authentication method of claim 1, wherein: The bidirectional verification of each verification node comprises: The authentication results of the master key libraries under each verification node are obtained, and a hash check conversion is performed to generate a plurality of check parameters; A preset check algorithm is called, the check parameters are input into the check algorithm, and the output value is recorded as an authentication parameter; An authentication threshold value is obtained, and the authentication parameter is compared with the authentication threshold value; If the authentication parameter is less than the authentication threshold value, it is determined that the verification node is in a valid authentication state; If the authentication parameter is greater than or equal to the authentication threshold value, it is determined that the verification node is in an invalid authentication state.

7. The digital identity encryption authentication method of claim 1, wherein: The calculation of the authentication offset of the master key library under the abnormal verification node comprises: An actual verification node of the master key library under the abnormal verification node which has not completed the associated authentication is obtained; The logical difference between the actual verification node and the abnormal verification node is calculated and marked as a real-time offset; The abnormal verification node is traced back in history, and the historical offset of the associated historical node is extracted; A preset error threshold value is obtained, and the tracing operation is terminated when the historical offset is less than or equal to the error threshold value; An offset calculation function is called, the real-time offset and the historical offset are input into the calculation function, and the output result is recorded as an authentication offset.

8. The digital identity encryption authentication method of claim 7, wherein: The path reconstruction of the abnormal verification node based on the authentication offset comprises: The number of times of historical tracing of the abnormal verification node is counted and recorded as a reconstruction reference value; A reconstruction threshold value is obtained, and the reconstruction reference value is compared with the reconstruction threshold value; When the reconstruction reference value is greater than or equal to the reconstruction threshold value, the abnormal verification node is logically reset according to the authentication offset, a reconstructed verification node is generated, and the associated authentication is performed under the reconstructed verification node; When the reconstruction reference value is less than the reconstruction threshold value, the authentication offset is continuously collected until the reconstruction reference value reaches or exceeds the reconstruction threshold value, and the path reconstruction is triggered.

9. The digital identity encryption authentication method of claim 6, wherein: The hash check conversion comprises: The encryption field and the permission attribute in the authentication result are extracted to construct a composite check parameter; The composite check parameter is fragmented and recombined to generate a standardized hash sequence; According to the preset permission weight matrix, the normalized hash sequence is iteratively calculated to generate the check parameter and input the check algorithm.

10. The digital identity encryption authentication method of claim 5, wherein: The dynamic correction factor is generated based on the error ratio, and the current permission determination threshold is adjusted by weighting according to the correction factor, including: Obtain the effective frequency of the dynamic feature in the current authentication path; Generate a dynamic attenuation factor based on the effective frequency and compensate the permission determination threshold; Synchronize the compensated permission determination threshold to the master key library verification of the next authentication cycle.

Citation Information

Patent Citations

  • Multistage controllable data sharing authorization method and device and block chain system

    CN117056983A

  • Cross-domain identity authentication method and system in cloud environment

    CN119071045A

  • AI and password technology fused identity authentication method

    CN120301605A

  • Blockchain-based authentication system

    DE202025100776U1

  • Systems and methods for distributed key storage

    US20200153627A1

Cited By

  • Distributed storage data protection method for cryptographic algorithm dynamic reconstruction

    CN121478196A