An identity authentication method and related equipment
By storing the user's autonomous identity and business identity in two terminals respectively, and using the second information generated by the first terminal for identity authentication, the security problem of the user's autonomous identity information being lost and misused is solved, and the security isolation and reliability of identity authentication are achieved.
Patent Information
- Application Number
- CN202110988997.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-26
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2041-08-26
AI Technical Summary
Once the user's self-identity information stored in the terminal is lost, it can be easily misused, posing a security risk.
The user's autonomous identity and business identity are stored in different terminals respectively, and identity authentication is performed on the second server through the second information generated by the first terminal, ensuring that the autonomous identity is isolated from the business side and will not be used fraudulently only when the second terminal is lost.
Effectively protect the user's autonomous identity from direct contact with the business side, avoid potential security issues, and ensure the security and reliability of identity authentication.
Smart Images

Figure CN115733630B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to an identity authentication method and related equipment. Background Art
[0002] With the rapid development of technology, users and enterprises can conduct business on the Internet. In order to ensure information security, enterprises providing services usually need to authenticate the real identity of users.
[0003] For ease of introduction, the server of the agency will be referred to as the first server, the device used by the user will be referred to as the terminal, and the server of the enterprise will be referred to as the second server. Specifically, the first server can issue information describing the user's self-sovereign identity (SSI) to the terminal, such as the identity private key and the identity certificate containing the identity public key, etc. When the terminal needs to register on the second server, the terminal can complete identity authentication on the second server based on this information. Then, after identity authentication, the terminal can communicate with the second server based on this information, thereby conducting business online.
[0004] However, the information used to describe the user's autonomous identity often involves the user's privacy. Once the terminal storing this information is lost, the user's identity may be impersonated, posing certain security issues. Summary of the Invention
[0005] The embodiment of the present application provides an identity authentication method and related equipment, which can isolate the user's autonomous identity and business identity and store them in two terminals respectively, effectively protecting the target user's autonomous identity from direct contact with the business side. Even if the terminal storing the business identity is lost, the autonomous identity will not be misused, thus avoiding potential security issues.
[0006] A first aspect of an embodiment of the present application provides an identity authentication method, the method comprising:
[0007] When the target user needs to obtain the first information used to describe his / her first identity, he / she may send a request to the first server, so that the first server generates the first information based on the request and sends it to the first terminal. It should be noted that the first identity of the target user can also be understood as the autonomous identity of the target user.
[0008] After the first terminal obtains the first information from the first server, it can generate second information based on the first information, and the second information is used to describe the second identity of the target user. It should be noted that the second identity of the target user can also be understood as the business identity of the target user.
[0009] After receiving the second information, the first terminal sends the second information to the second terminal, so that the second terminal can perform identity authentication on the second server based on the second information. After completing the identity authentication, the second terminal can use the second information to perform subsequent communication with the second server to conduct business online.
[0010] It can be seen from the above method that: after the first server sends the first information used to describe the first identity of the target user to the first terminal, the first terminal can generate the second information used to describe the second identity of the target user based on the first information. Then, the first terminal sends the second information to the second terminal, so that the second terminal uses the second information to complete the identity authentication at the second server. In the above process, since the first information is stored in the first terminal and the second information is stored in the second terminal, and when the second terminal performs identity authentication with the second server, only the second information is involved, the first identity (autonomous identity) and the second identity (business identity) of the target user are successfully isolated and stored in the two terminals respectively. This can effectively protect the first identity of the target user from direct contact with the second server (business side). Even if the second terminal is lost, the first identity of the target user will not be misused, which can avoid potential security issues.
[0011] In one possible implementation, the first information includes the first private key of the target user, the first private key is one of the private keys of multiple users matched with the first public key, and the multiple users include the target user; the first terminal generates the second information based on the first information, including: the first terminal generates the second private key of the target user and the second public key matched with the second private key; the first terminal signs the second public key based on the first private key to obtain a first certificate containing the second public key; wherein the second information includes the first certificate and the second private key, the first certificate is used by the second server to perform a first signature verification based on the first public key, and the second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful. In the aforementioned implementation, the first private key of the target user is stored in the first terminal as the most sensitive information used to describe the autonomous identity of the target user, and the second private key of the target user is stored in the second terminal as the most sensitive information used to describe the business identity of the target user. The second terminal will only use the second private key of the target user to complete identity authentication at the second server, that is, the second server can only access the most sensitive information used to describe the business identity of the target user, but cannot access the most sensitive information used to describe the autonomous identity of the target user. Therefore, the autonomous identity of the target user and the business identity of the target user can be isolated (that is, stored in the first terminal and the second terminal respectively). Even if the second terminal is lost, the information used to describe the autonomous identity of the target user is still stored on the first terminal. Therefore, the target user can use the autonomous identity of the target user through the first terminal to revoke the old business identity in time at the second server and register a new business identity. Therefore, in this case, the autonomous identity of the target user can be effectively protected and will not be misused.
[0012] In one possible implementation, the first private key is generated based on identity attributes shared by multiple users. In the aforementioned implementation, since the first private key is generated based on identity attributes shared by multiple users, if the second server successfully verifies the signature of the first certificate using the first public key (i.e., the first certificate is successfully signed based on the first private key), it can confirm that the target user is indeed a user with the aforementioned identity attributes, and that the identity attributes of the target user are indeed derived from the first server.
[0013] In one possible implementation, the first information and the second information also include a second certificate, the second certificate includes a first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used for the second server to perform a second signature verification based on the third public key matched with the third private key, and the first certificate is used for the second server to perform a first signature verification based on the first public key after the second signature verification is successful. Furthermore, the second certificate also includes identity attributes possessed by multiple users. In the aforementioned implementation, since the first private key is not generated based on the identity attributes possessed by multiple users, the second certificate includes identity attributes possessed by multiple users. Therefore, if the second server successfully performs a double-layer signature verification (i.e., the second certificate is successfully verified using the third public key, and then the first certificate is successfully verified using the first public key in the second certificate, the second certificate is obtained by signing based on the third private key, and the first certificate is obtained by signing based on the first private key), it can be confirmed that the target user is indeed a user with the aforementioned identity attributes, and that the identity attributes possessed by the target user are indeed derived from the first server.
[0014] A second aspect of the embodiments of the present application provides an identity authentication method, the method comprising:
[0015] When the target user needs to obtain the first information used to describe his / her first identity, he / she may send a request to the first server, so that the first server generates the first information based on the request and sends it to the first terminal. It should be noted that the first identity of the target user can also be understood as the autonomous identity of the target user.
[0016] After the first terminal obtains the first information from the first server, it can generate second information based on the first information and send it to the second terminal. The second information is used to describe the second identity of the target user. It should be noted that the second identity of the target user can also be understood as the business identity of the target user.
[0017] After obtaining the second information from the first terminal, the second terminal sends part of the second information to the second server to implement identity authentication at the second server.
[0018] It can be seen from the above method that: after the first server sends the first information used to describe the first identity of the target user to the first terminal, the first terminal can generate the second information used to describe the second identity of the target user based on the first information. Then, the first terminal sends the second information to the second terminal, so that the second terminal uses the second information to complete the identity authentication at the second server. In the above process, since the first information is stored in the first terminal and the second information is stored in the second terminal, and when the second terminal performs identity authentication with the second server, only the second information is involved, the first identity (autonomous identity) and the second identity (business identity) of the target user are successfully isolated and stored in the two terminals respectively. This can effectively protect the first identity of the target user from direct contact with the second server (business side). Even if the second terminal is lost, the first identity of the target user will not be misused, which can avoid potential security issues.
[0019] In one possible implementation, the first information includes the first private key of the target user, the first private key is one of the private keys of multiple users matched with the first public key, the multiple users include the target user, the second information includes the first certificate and the second private key of the target user, part of the information includes the first certificate, the first certificate includes the second public key matched with the second private key, the first certificate is signed based on the first private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key; the second terminal implements identity authentication at the second server, including: after the first signature verification is successful, the second terminal proves to the second server that the second terminal owns the second private key.
[0020] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0021] In one possible implementation, the first information and partial information also include a second certificate, the second certificate includes a first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0022] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0023] A third aspect of the embodiments of the present application provides an identity authentication method, the method comprising:
[0024] When the target user needs to obtain first information for describing his / her first identity, he / she may send a request to the first server so that the first server generates the first information based on the request. It should be noted that the first identity of the target user may also be understood as the autonomous identity of the target user.
[0025] After obtaining the first information, the first server may send the first information to the first terminal, causing the first terminal to generate second information based on the first information and send it to the second terminal. The second terminal then performs identity authentication on the second server based on the second information. The second information describes the second identity of the target user. It should be noted that the second identity of the target user can also be understood as the target user's business identity.
[0026] It can be seen from the above method that: after the first server sends the first information used to describe the first identity of the target user to the first terminal, the first terminal can generate the second information used to describe the second identity of the target user based on the first information. Then, the first terminal sends the second information to the second terminal, so that the second terminal uses the second information to complete the identity authentication at the second server. In the above process, since the first information is stored in the first terminal and the second information is stored in the second terminal, and when the second terminal performs identity authentication with the second server, only the second information is involved, the first identity (autonomous identity) and the second identity (business identity) of the target user are successfully isolated and stored in the two terminals respectively. This can effectively protect the first identity of the target user from direct contact with the second server (business side). Even if the second terminal is lost, the first identity of the target user will not be misused, which can avoid potential security issues.
[0027] In a possible implementation, the method also includes: the first server generates a first private key, the first private key is one of the private keys of multiple users matched with the first public key, and the multiple users include the target user; wherein the first information includes the first private key of the target user, the second information includes the first certificate and the second private key of the target user, the first certificate includes the second public key matching the second private key, the first certificate is signed based on the first private key, the first certificate is used by the second server to perform a first signature verification based on the first public key, and the second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
[0028] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0029] In one possible implementation, the method further includes: the first server signs the first public key based on the third private key of the first server to obtain a second certificate containing the first public key; wherein the first information and the second information also include a second certificate, the second certificate is used by the second server to perform a second signature verification based on the third public key matched with the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0030] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0031] A fourth aspect of the embodiments of the present application provides an identity authentication method, the method comprising:
[0032] When a target user needs to obtain first information describing their first identity, they can send a request to the first server. The first server then generates the first information based on the request and sends it to the first terminal. The first terminal then generates second information based on the first information and sends it to the second terminal. The second terminal then sends part of the second information to the second server. The second information is used to describe the target user's second identity. It should be noted that the target user's first identity can also be understood as the target user's autonomous identity, and the target user's second identity can also be understood as the target user's business identity.
[0033] After obtaining part of the second information from the second terminal, the second server may perform identity authentication on the second terminal according to the part of the second information.
[0034] It can be seen from the above method that: after the first server sends the first information used to describe the first identity of the target user to the first terminal, the first terminal can generate the second information used to describe the second identity of the target user based on the first information. Then, the first terminal sends the second information to the second terminal, so that the second terminal uses the second information to complete the identity authentication at the second server. In the above process, since the first information is stored in the first terminal and the second information is stored in the second terminal, and when the second terminal performs identity authentication with the second server, only the second information is involved, the first identity (autonomous identity) and the second identity (business identity) of the target user are successfully isolated and stored in the two terminals respectively. This can effectively protect the first identity of the target user from direct contact with the second server (business side). Even if the second terminal is lost, the first identity of the target user will not be misused, which can avoid potential security issues.
[0035] In one possible implementation, the first information includes a first private key of a target user, the first private key is one of private keys of multiple users matched with the first public key, the multiple users include the target user, the second information includes a first credential and a second private key of the target user, partial information includes the first credential, the first credential includes a second public key matched with the second private key, and the first credential is signed based on the first private key; and the second server authenticates the second terminal based on the partial information, including: performing a first signature verification on the first credential by the second server based on the first public key;
[0036] After the first signature verification succeeds, the second server controls the second terminal and proves to the second server that the second terminal possesses the second private key.
[0037] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0038] In one possible implementation, the first information and partial information also include a second certificate, the second certificate includes a first public key, and the second certificate is signed based on the third private key of the first server. Before the second server performs a first verification on the first certificate based on the first public key, the method also includes: the second server performs a second verification on the second certificate based on the third public key matching the third private key; the second server performs a first verification on the first certificate based on the first public key, including: after the second verification is successful, the second server performs a first verification on the first certificate based on the first public key.
[0039] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0040] The fifth aspect of an embodiment of the present application provides a terminal, which serves as a first terminal, and the first terminal includes: an acquisition module, used to obtain first information from a first server, the first information is used to describe the first identity of the target user; a processing module, used to generate second information based on the first information, the second information is used to describe the second identity of the target user; a sending module, used to send second information to a second terminal, the second information is used for the second terminal to implement identity authentication at the second server.
[0041] In one possible implementation, the first information includes a first private key of a target user, where the first private key is one of the private keys of multiple users matched by the first public key, and the multiple users include the target user; a processing module is used to: generate a second private key of the target user and a second public key matching the second private key; sign the second public key based on the first private key to obtain a first certificate including the second public key; wherein the second information includes the first certificate and the second private key, the first certificate is used by the second server to perform a first signature verification based on the first public key, and the second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
[0042] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0043] In one possible implementation, the first information and the second information also include a second certificate, the second certificate includes a first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0044] In a possible implementation, the second credential further includes identity attributes possessed by multiple users.
[0045] The sixth aspect of an embodiment of the present application provides a terminal, which serves as a second terminal, and the second terminal includes: an acquisition module, used to obtain second information from the first terminal, the second information is generated by the first terminal based on the first information from the first server, the first information is used to describe the first identity of the target user, and the second information is used to describe the second identity of the target user; a sending module, used to send part of the second information to the second server to realize identity authentication at the second server.
[0046] In one possible implementation, the first information includes the first private key of the target user, the first private key is one of the private keys of multiple users matched with the first public key, the multiple users include the target user, the second information includes the first certificate and the second private key of the target user, part of the information includes the first certificate, the first certificate includes the second public key matched with the second private key, the first certificate is signed based on the first private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key; the sending module is used to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
[0047] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0048] In one possible implementation, the first information and part of the second information also include a second certificate, the second certificate includes a first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0049] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0050] The seventh aspect of an embodiment of the present application provides a server, which serves as a first server, and the first server includes: a sending module, used to send first information to a first terminal, the first information is used to describe the first identity of the target user, and the first information is also used for the first terminal to generate second information, the second information is used to describe the second identity of the target user, and the second information is also used for the second terminal to implement identity authentication at the second server.
[0051] In one possible implementation, the first server also includes: a processing module, used to generate a first private key, the first private key is one of the private keys of multiple users matched with the first public key, and the multiple users include the target user; wherein the first information includes the first private key of the target user, the second information includes the first certificate and the second private key of the target user, the first certificate includes the second public key matching the second private key, the first certificate is signed based on the first private key, the first certificate is used by the second server to perform a first signature verification based on the first public key, and the second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
[0052] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0053] In one possible implementation, the processing module is further used to sign the first public key based on the third private key of the first server to obtain a second certificate containing the first public key; wherein the first information and the second information also include a second certificate, and the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0054] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0055] The eighth aspect of an embodiment of the present application provides a server, which serves as a second server, and the second server includes: an acquisition module, used to obtain part of the second information from the second terminal, the second information is generated by the first terminal based on the first information from the first server, the first information is used to describe the first identity of the target user, and the second information is used to describe the second identity of the target user; a processing module, used to perform identity authentication on the second terminal based on the partial information.
[0056] In one possible implementation, the first information includes a first private key of a target user, the first private key is one of the private keys of multiple users matched with the first public key, the multiple users include the target user, the second information includes a first certificate and a second private key of the target user, part of the information includes the first certificate, the first certificate includes the second public key matched with the second private key, and the first certificate is signed based on the first private key; the processing module is used to: perform a first signature verification on the first certificate based on the first public key; after the first signature verification is successful, control the second terminal to prove to the second server that the second terminal owns the second private key.
[0057] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0058] In one possible implementation, the first information and partial information also include a second certificate, the second certificate includes a first public key, and the second certificate is signed based on the third private key of the first server. Before the second server performs a first verification on the first certificate based on the first public key, the processing module is also used to perform a second verification on the second certificate based on the third public key matching the third private key; the processing module is used to perform a first verification on the first certificate based on the first public key after the second verification is successful.
[0059] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0060] A ninth aspect of an embodiment of the present application provides a terminal, which serves as a first terminal and includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the first terminal executes the method described in the first aspect or any possible implementation method of the first aspect.
[0061] A tenth aspect of an embodiment of the present application provides a terminal, which serves as a second terminal, and the first terminal includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the second terminal executes the method described in the second aspect or any possible implementation method of the second aspect.
[0062] In an eleventh aspect of an embodiment of the present application, a server is provided, which serves as a first server and includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the first server executes the method described in the third aspect or any possible implementation of the third aspect.
[0063] The twelfth aspect of the embodiments of the present application provides a server, which serves as a second server and includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the first server executes the method described in the fourth aspect or any possible implementation method of the fourth aspect.
[0064] The thirteenth aspect of the embodiment of the present application provides an identity authentication system, which includes the first terminal as described in the ninth aspect, the second terminal as described in the tenth aspect, the first server as described in the eleventh aspect, and the second server as described in the twelfth aspect.
[0065] A fourteenth aspect of an embodiment of the present application provides a computer storage medium storing one or more instructions, which, when executed by one or more computers, enables one or more computers to implement the method described in the first aspect, any possible implementation of the first aspect, the second aspect, any possible implementation of the second aspect, the third aspect, any possible implementation of the third aspect, the fourth aspect, or any possible implementation of the fourth aspect.
[0066] A fifteenth aspect of the embodiments of the present application provides a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the method described in the first aspect, any possible implementation of the first aspect, the second aspect, any possible implementation of the second aspect, the third aspect, any possible implementation of the third aspect, the fourth aspect, or any possible implementation of the fourth aspect.
[0067] In an embodiment of the present application, after the first server sends the first information for describing the first identity of the target user to the first terminal, the first terminal can generate the second information for describing the second identity of the target user based on the first information. Then, the first terminal sends the second information to the second terminal, so that the second terminal uses the second information to complete the identity authentication at the second server. In the aforementioned process, since the first information is stored in the first terminal, the second information is stored in the second terminal, and when the second terminal performs identity authentication with the second server, only the second information is involved, the first identity (autonomous identity) and the second identity (business identity) of the target user are successfully isolated and stored in the two terminals respectively, which can effectively protect the first identity of the target user from direct contact with the second server (business side). Even if the second terminal is lost, the first identity of the target user will not be impersonated, which can avoid potential security issues. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Figure 1 A schematic diagram of the structure of the identity authentication system provided in an embodiment of the present application;
[0069] Figure 2 A flowchart of the identity authentication method provided in an embodiment of the present application;
[0070] Figure 3 Another flowchart of the identity authentication method provided in an embodiment of the present application;
[0071] Figure 4 A schematic diagram of the structure of a terminal provided in an embodiment of the present application;
[0072] Figure 5 Another schematic diagram of the structure of the terminal provided in an embodiment of the present application;
[0073] Figure 6 A schematic diagram of the structure of a server provided in an embodiment of the present application;
[0074] Figure 7 Another structural diagram of the server provided in an embodiment of the present application;
[0075] Figure 8 Another schematic diagram of the structure of the terminal provided in an embodiment of the present application;
[0076] Figure 9 Another schematic diagram of the structure of the terminal provided in an embodiment of the present application;
[0077] Figure 10 Another structural diagram of the server provided in an embodiment of the present application;
[0078] Figure 11 Another structural diagram of the server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0079] The embodiment of the present application provides an identity authentication method and related equipment, which can isolate the user's autonomous identity and business identity and store them in two terminals respectively, effectively protecting the target user's autonomous identity from direct contact with the business side. Even if the terminal storing the business identity is lost, the autonomous identity will not be misused, thus avoiding potential security issues.
[0080] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0081] With the rapid development of technology, users and enterprises can conduct business on the Internet. In order to ensure information security, enterprises providing services usually need to authenticate the real identity of users.
[0082] For ease of introduction, the server of the government agency will be referred to as the first server, the device used by the user will be referred to as the terminal, and the server of the enterprise will be referred to as the second server. Specifically, the first server can issue information to the terminal that describes the user's autonomous identity, such as an identity private key and an identity certificate containing an identity public key, etc. When the terminal needs to register on the second server, the terminal can send the identity certificate to the second server. Since the identity certificate is usually signed based on the identity private key, the second server can verify the identity certificate based on the identity public key. After the verification is successful, the terminal can prove to the second server that it has the identity private key to prove its own identity. At this point, the terminal has completed identity authentication. Then, after identity authentication, the terminal can log in to the second server based on the identity public and private keys to conduct business online.
[0083] However, the information used to describe the user's autonomous identity often involves the user's privacy. Once the terminal storing this information is lost, the user's identity may be impersonated, posing certain security issues.
[0084] In order to solve the above problems, the embodiment of the present application provides an identity authentication method, which is applied to a new identity authentication system, such as Figure 1 As shown ( Figure 1 A structural diagram of an identity authentication system provided in an embodiment of the present application) includes: a first server, a first terminal, a second terminal and a second server, the first server is communicatively connected to the first terminal, the first terminal is communicatively connected to the second terminal, and the second terminal is communicatively connected to the second server, wherein the communication connection can be a wired communication connection or a wireless communication connection, which is not limited here.
[0085] The first server is the server of the agency that issues the user's autonomous identity, the second server is the server of the enterprise that provides business services, the first terminal and the second terminal are devices used by the user, the first terminal can be some terminal devices with a relatively high security level, such as wearable devices (such as smart watches, smart bracelets, smart glasses, etc.), personal computers, etc., and the second terminal can be some portable but lower security level terminal devices, such as mobile phones, tablets, etc.
[0086] The first server may provide the first terminal with information describing the user's autonomous identity. The first terminal may store this information and, based on it, generate and store information describing the user's service identity. The first terminal then sends this information describing the user's service identity to the second terminal. The second terminal may store this information and forward it to the second server for identity authentication on the second server.
[0087] In order to further understand the above process, the following will further introduce the process. For the sake of convenience, the information used to describe the user's autonomous identity is referred to as the first information, and the information used to describe the user's business identity is referred to as the second information. It should be noted that this process can include two situations. In different situations, the content of the first information and the second information is different. The following will first explain the first situation. Figure 2 A flow chart of the identity authentication method provided in the embodiment of the present application is as follows: Figure 2 As shown, the method includes:
[0088] 201. A first server generates a first private key of a target user, where the first private key is one of private keys of multiple users that match a first public key, where the multiple users include the target user.
[0089] 202. The first server signs the first public key based on the third private key of the first server to obtain a second certificate including the first public key.
[0090] In this embodiment, when a target user needs to obtain first information describing the target user's first identity, they can send a first request to the first server, causing the first server to generate the first information based on the first request. The first information includes the target user's first private key and a second credential including the first public key. The target user's first private key is one of the private keys of multiple users that match the first public key. These multiple users have the same identity attributes, and these multiple users include the target user. The second credential including the aforementioned identity attributes and the first public key is obtained by signing the first public key. Thus, the first private key and the second credential, when combined, can be used to describe the target user's first identity, indicating that the target user is a user with certain identity attributes.
[0091] Specifically, the first identity of the target user may include at least one identity attribute of the target user. For example, the autonomous identity of user A may include identity attributes such as user A's name, user A's date of birth, user A's address, and user A's household registration. It should be noted that all identity attributes of the target user are generated and issued by the first server. For each identity attribute of the target user, the operation performed by the first server on each identity attribute is the same. Therefore, for ease of explanation, the following will use the target user's jth identity attribute Attr as the example. j For schematic illustration, the first server can also perform the same operation on the jth identity attribute Attr for the remaining identity attributes of the target user. j The executed steps (ie, step 201 to step 210) will not be described in detail later.
[0092] For the target user's identity attribute Attr j , in order to convert the identity attribute Attrj To securely issue the certificate to the first terminal, the first server may perform the following steps:
[0093] (1) The first server can be the identity attribute Attr j Create a group, then, have the identity attribute Attr j The first server can also generate a master public key MPK for the group that is shared by all members. j (i.e. the first public key), and generate different private keys SK for different members in the group j Assume that the target user is the i-th member of the group, so the private key of the target user in the group can be expressed as (i.e. the first private key of the target user), where MSK j This is the master private key shared by all members of the group. It can be seen that the target user’s private key in the group It is based on the group's master private key MSK j The private keys of other members in the group are generated in the same way, which will not be described here. It should be noted that the master public key MPK of the group j And the group's master private key MSK j A public-private key pair randomly generated by the first server for the group, and the private keys SK of different members in the group j Both are the same as the group's master public key MPK j Match (because the private keys SK of different members in the group j All are based on the group's master private key MSK j generated).
[0094] (2) The first server can also obtain the public-private key pair representing the first server itself, that is, the private key SK of the first server I (i.e., the third private key of the first server) and the private key SK I The public key PK of the first matching server I (i.e. the third public key of the first server). Then, the first server uses the private key SK I For identity attribute Attr j And the master public key MPK j Perform a signature (e.g., a signature operation based on a conventional signature algorithm, etc.) to obtain a certificate (i.e. the second certificate).
[0095] At this point, the first server has obtained the private key of the target user and Credentials j , which is equivalent to the first server obtaining the first private key and second certificate of the target user, that is, the first information.
[0096] 203. The first server sends the first private key and the second certificate to the first terminal.
[0097] After obtaining the first information describing the first identity of the target user, the first server may send the first information to the first terminal for processing. Specifically, after obtaining the first private key of the target user and the second certificate including the first public key, the first private key and the second certificate may be sent to the first terminal.
[0098] As in the above example, the first server obtains the target user's private key and Credentials j After that, the first server can send the target user's private key and Credentials j Sent to the first terminal.
[0099] 204. The first terminal generates a second private key of the target user and a second public key matching the second private key.
[0100] 205. The first terminal signs the second public key based on the first private key to obtain a first certificate including the second public key.
[0101] After obtaining the target user's first private key and the second certificate containing the first public key, the first terminal can generate second information describing the target user's second identity based on this information. The second information includes the second certificate, the target user's second private key, and the first certificate containing the second public key. The second public key and the second private key match, and the first certificate containing the second public key is obtained by signing the second public key. Therefore, when the second private key, the first certificate, and the second certificate are combined, they can be used to describe the target user's second identity, indicating that the target user possesses certain identity attributes (i.e., the identity attributes contained in the second certificate).
[0102] Specifically, the second identity of the target user may also include at least one identity attribute of the target user, and the identity attributes included in the first identity and second identity of the target user may be the same. For example, both the autonomous identity and the business identity of user A may include identity attributes such as user A's name, user A's date of birth, user A's address, and user A's household registration.
[0103] Still as in the above example, for the target user's identity attribute Attr j , the first terminal obtains the private key of the target user and Credentials j Afterwards, the first terminal may perform the following steps:
[0104] (1) The first terminal can obtain (for example, randomly generate in advance or randomly generate in real time, etc.) a new public-private key pair representing the target user himself, namely, the target user's new private key SK2 (that is, the target user's second private key) and the target user's new public key PK2 (that is, the target user's second public key) that matches the new private key SK2.
[0105] (2) The first terminal can use the target user's private key Sign the target user's new public key PK2 (e.g., a signature operation based on a group signature (GS) algorithm, etc.) to obtain a new credential (i.e. the first certificate).
[0106] At this point, the first terminal has obtained the target user's new private key SK2 and certificate Cred j and the new certificate σ, which is equivalent to the first terminal obtaining the second private key, the second certificate and the first certificate of the target user, that is, the second information.
[0107] 206. The first terminal sends the first certificate, the second certificate, and the second private key to the second terminal.
[0108] After the first terminal obtains the second information describing the second identity of the target user, if the target user needs to register with the second server, the first terminal may send the second information to the second terminal, so that the second terminal can perform identity authentication on the second server based on the second information. Specifically, after the first terminal obtains the target user's second private key, the first certificate, and the second certificate containing the second public key, the first terminal may send the second private key, the first certificate, and the second certificate to the second terminal.
[0109] As in the above example, the first terminal obtains the target user's new private key SK2 and certificate Cred j After the first terminal can use the target user's new private key SK2 and the new certificate Cred j and the new credential σ is sent to the second terminal.
[0110] 207. The second terminal sends the first credential and the second credential to the second server.
[0111] After obtaining the second information, the second terminal may send part of the second information to the second server. Specifically, after obtaining the second private key, the first certificate, and the second certificate containing the second public key of the target user, the second terminal may send the first certificate and the second certificate to the second server.
[0112] As in the above example, the second terminal obtains the target user's new private key SK2 and certificate Cred j After the second terminal has the new certificate σ, the certificate Cred jand the new credential σ is sent to the second server.
[0113] 208. The second server performs a second signature verification on the second certificate based on the third public key that matches the third private key.
[0114] 209. After the second signature verification succeeds, the second server performs a first signature verification on the first certificate based on the first public key.
[0115] After the second server obtains the first and second certificates, since the second certificate is obtained by signing the first public key based on the third private key of the first server, the second server can obtain the third public key that matches the third private key (the third public key is public, so the second server can directly obtain it), and use the third public key to perform a second signature verification on the second certificate (for example, a signature verification operation based on a conventional signature algorithm). If the second signature verification is successful, it means that the information in the second certificate originated from the first server (that is, the information has not been tampered with during the transmission process), and the second server will perform the second signature verification. If the first signature verification fails, it means that the information in the second certificate did not originate from the first server (that is, the information was tampered with during the transmission process), and the second server will end the operation.
[0116] After the second verification is successful, since the first certificate is obtained by signing the second public key based on the first private key of the target user, the second server can use the first public key in the second certificate to perform a first verification on the first certificate (for example, a verification signature operation based on a group signature algorithm). If the first verification is successful, it means that the information in the first certificate comes from the first terminal (that is, during the transmission process, these information have not been tampered with). At this point, both the first signature verification and the second signature verification are successful, and the second server recognizes the second identity of the target user (that is, confirms that the target user is indeed a user with certain identity attributes), and confirms that the identity attributes contained in the second identity of the target user are issued by the first server (that is, confirms that the identity attributes possessed by the target user are indeed from the first server), so the second server can implement step 210. If the first verification fails, it means that the information in the first certificate does not come from the first terminal (that is, during the transmission process, these information have been tampered with), and the second server ends the operation.
[0117] As in the above example, the second server obtains the credential Cred j After the new certificate σ is obtained, the public key PK of the first server can be used I Verification Perform signature verification. If the verification is successful, the second server will continue to use the master public key MPK j For new credentials If the signature verification is successful, the second server will recognize that the target user does have the identity attribute Attr j The user, and the identity attribute Attr jIssued to the target user by the first server.
[0118] In the above process, since the master public key MPK j Based on the identity attribute Attr j The private keys SK of multiple members in the established group j Then, the second server uses the master public key MPK j After the new certificate σ is successfully signed, the second server cannot know which user in the group the target user is (that is, it cannot determine which user's private key SK the new certificate σ is based on). j The target user can only be determined to have the identity attribute Attr j users.
[0119] 210. After the first signature verification succeeds, the second terminal proves to the second server that the second terminal owns the second private key.
[0120] After the first signature verification succeeds, the second server sends a second request to the second terminal. Based on this second request, the second terminal can prove to the second server that it possesses the second private key, thus completing identity authentication. Subsequently, if the target user has business needs, they can use the second private key and second public key to log in to the second server through the second terminal and conduct business online.
[0121] Still as in the above example, after the double-layer signature verification is successful, the second server can send a request to the second terminal, so that the second terminal can perform zero-knowledge proof on the second server, thereby proving that the second terminal has the new private key SK2 that matches the target user's new public key PK2. At this point, the second terminal has achieved identity authentication at the second server, so the second terminal can subsequently use the target user's new public key PK2 and the target user's new private key SK2 to communicate with the second server, thereby conducting business online.
[0122] In the above process, the target user's private key (i.e., the first private key of the target user) is the most sensitive information used to describe the target user's autonomous identity and is stored in the first terminal. The target user's new private key SK2 (i.e., the second private key of the target user) is the most sensitive information used to describe the target user's business identity and is stored in the second terminal. The second terminal will only use the target user's new private key SK2 to complete identity authentication at the second server. That is, the second server can only access the most sensitive information used to describe the target user's business identity, but cannot access the most sensitive information used to describe the target user's autonomous identity. Therefore, the target user's autonomous identity and the target user's business identity can be isolated (i.e., stored in two terminals respectively). Even if the second terminal is lost, the information used to describe the target user's autonomous identity is still stored on the first terminal. Therefore, the target user can use the target user's autonomous identity through the first terminal to promptly revoke the old business identity at the second server and register a new business identity. Therefore, in this case, the target user's autonomous identity can be effectively protected and will not be misused.
[0123] In an embodiment of the present application, after the first server sends the first information for describing the first identity of the target user to the first terminal, the first terminal can generate the second information for describing the second identity of the target user based on the first information. Then, the first terminal sends the second information to the second terminal, so that the second terminal uses the second information to complete the identity authentication at the second server. In the aforementioned process, since the first information is stored in the first terminal, the second information is stored in the second terminal, and when the second terminal performs identity authentication with the second server, only the second information is involved, the first identity (autonomous identity) and the second identity (business identity) of the target user are successfully isolated and stored in the two terminals respectively, which can effectively protect the first identity of the target user from direct contact with the second server (business side). Even if the second terminal is lost, the first identity of the target user will not be impersonated, which can avoid potential security issues.
[0124] The above is a detailed description of the first case. The second case will be introduced below. Figure 3 Another flow chart of the identity authentication method provided in the embodiment of the present application is as follows: Figure 3 As shown, the method includes:
[0125] 301. A first server generates a first private key of a target user, where the first private key is one of private keys of multiple users that match a first public key, where the multiple users include the target user.
[0126] In this embodiment, when a target user needs to obtain first information describing the target user's first identity, they can send a first request to the first server, causing the first server to generate first information based on the first request. The first information includes the target user's first private key. The target user's first private key is one of the private keys of multiple users that match the first public key. The first private key is generated based on the fact that these multiple users share the same identity attributes, and these multiple users include the target user. Therefore, the first private key can be used to describe the target user's first identity, indicating that the target user possesses certain identity attributes.
[0127] Specifically, the first identity of the target user may include at least one identity attribute of the target user. For example, the autonomous identity of user A may include identity attributes such as user A's name, user A's date of birth, user A's address, and user A's household registration. It should be noted that all identity attributes of the target user are generated and issued by the first server. Assume that the first identity of the target user includes N identity attributes, namely, Attr1, Attr2, ..., Attr N In order to convert the identity attributes Attr1, Attr2, ..., Attr N Securely issued to the first terminal, the first server can be identity attributes Attr1, Attr2, ..., Attr N Create a group, then, with identity attributes Attr1, Attr2, ..., Attr N The first server can also generate a master public key MPK (i.e., the first public key) for all members of the group, and generate different private keys SK for different members of the group. Let the target user be the i-th member of the group, so the private key of the target user in the group can be expressed as SK i =AttrIssue(Attr1,Attr2,...,Attr N , MSK) (i.e., the first private key of the target user), where MSK is the master private key shared by all members of the group. It can be seen that the private key SK of the target user in the group i is based on the identity attributes Attr1, Attr2, ..., Attr N The private keys of the remaining members in the group are generated based on the group's master private key MSK. This is not detailed here. It should be noted that the group's master public key MPK and the group's master private key MSK are a public-private key pair randomly generated by the first server for the group. The private keys SK of the different members in the group all match the group's master public key MPK (because the private keys SK of the different members in the group are all generated based on the group's master private key MSK).
[0128] At this point, the first server has obtained the target user's private key SK i, which is equivalent to the first server obtaining the first private key of the target user, that is, the first information.
[0129] 302. The first server sends a first private key to the first terminal.
[0130] After obtaining the first information describing the first identity of the target user, the first server may send the first information to the first terminal for processing. Specifically, the first server obtains the first private key of the target user and may send the first private key to the first terminal.
[0131] As in the above example, the first server obtains the target user's private key SK i After that, the first server can send the target user's private key SK i Sent to the first terminal.
[0132] 303. The first terminal generates a second private key of the target user and a second public key matching the second private key.
[0133] 304. The first terminal signs the second public key based on the first private key to obtain a first certificate including the second public key.
[0134] After obtaining the target user's first private key, the first terminal can generate second information describing the target user's second identity based on this information. The second information includes the target user's second private key and the first certificate including the second public key. The second public key matches the second private key, and the first certificate including the second public key is obtained by signing the second public key. Therefore, when the second private key and the first certificate are combined, they can be used to describe the target user's second identity, indicating that the target user possesses certain identity attributes (i.e., the identity attributes included in the second certificate).
[0135] Specifically, the second identity of the target user may also include at least one identity attribute of the target user, and the identity attributes included in the first identity and second identity of the target user may be the same. For example, both the autonomous identity and the business identity of user A may include identity attributes such as user A's name, user A's date of birth, user A's address, and user A's household registration.
[0136] Still as in the above example, for the target user's identity attributes Attr1, Attr2, ..., Attr N , the first terminal obtains the target user's private key SK i Afterwards, the first terminal may perform the following steps:
[0137] (1) The first terminal can obtain (for example, randomly generate in advance or randomly generate in real time, etc.) a new public-private key pair representing the target user himself, namely, the target user's new private key SK2 (that is, the target user's second private key) and the target user's new public key PK2 (that is, the target user's second public key) that matches the new private key SK2.
[0138] (2) The first terminal can use the target user's private key SK i Sign the target user's new public key PK2 (e.g., a signature operation based on a group signature (GS) algorithm, etc.) to obtain the certificate (i.e. the first certificate).
[0139] At this point, the first terminal obtains the new private key SK2 and certificate Cred of the target user, which is equivalent to the first terminal obtaining the second private key and first certificate of the target user, that is, the second information.
[0140] 305. The first terminal sends the first certificate and the second private key to the second terminal.
[0141] After obtaining the second information describing the second identity of the target user, the first terminal may send the second information to the second terminal for processing. Specifically, after obtaining the second private key and first credential of the target user, the first terminal may send the second private key and first credential to the second terminal.
[0142] Still like the above example, after the first terminal obtains the new private key SK2 and the certificate Cred of the target user, the first terminal may send the new private key SK2 and the certificate Cred of the target user to the second terminal.
[0143] 306. The second terminal sends the first credential to the second server.
[0144] After obtaining the second information, the second terminal may send part of the second information to the second server. Specifically, after obtaining the second private key and the first certificate of the target user, the second terminal may send the first certificate to the second server.
[0145] Still like the above example, after the second terminal obtains the new private key SK2 and the certificate Cred of the target user, the second terminal may send the certificate Cred to the second server.
[0146] 307. The second server performs a first signature verification on the first certificate based on the first public key.
[0147] After the second server obtains the first certificate, since the first certificate is obtained by signing the second public key based on the first private key of the target user, the second server can use the first public key (the first public key is public, so the second server can directly obtain it) to perform a first verification on the first certificate (for example, a verification signature operation based on a group signature algorithm). If the first verification is successful, it means that the information in the first certificate comes from the first terminal (that is, during the transmission process, this information has not been tampered with), the second server recognizes the second identity of the target user (that is, confirms that the target user is indeed a user with certain identity attributes), and confirms that the identity attributes contained in the second identity of the target user are issued by the first server (that is, confirms that the identity attributes possessed by the target user are indeed from the first server), so the second server can implement step 210. If the first verification fails, it means that the information in the first certificate does not come from the first terminal (that is, during the transmission process, this information has been tampered with), and the second server ends the operation.
[0148] As in the above example, after the second server obtains the certificate Cred, it can use the master public key MPK to verify the certificate. If the signature verification is successful, the second server recognizes that the target user does have the identity attributes Attr1, Attr2, ..., Attr N The user, and the identity attributes Attr1, Attr2, ..., Attr N Issued to the target user by the first server.
[0149] In the above process, since the master public key MPK is based on the identity attributes Attr1, Attr2, ..., Attr N The private keys SK of multiple members in the established group match. Then, the second server uses the master public key MPK j After the signature of the credential Cred is successfully verified, the second server cannot know which user in the group the target user is (that is, it cannot determine which user's private key SK the credential Cred is signed with), and can only determine that the target user has the identity attributes Attr1, Attr2, ..., Attr N users.
[0150] 308. After the first signature verification succeeds, the second terminal proves to the second server that the second terminal owns the second private key.
[0151] After the first signature verification succeeds, the second server sends a second request to the second terminal. Based on this second request, the second terminal can prove to the second server that it possesses the second private key, thus completing identity authentication. Subsequently, if the target user has business needs, they can use the second private key and second public key to log in to the second server through the second terminal and conduct business online.
[0152] Still as in the above example, after the signature verification is successful, the second server can send a request to the second terminal, so that the second terminal can perform zero-knowledge proof on the second server, thereby proving that the second terminal has the new private key SK2 that matches the target user's new public key PK2. At this point, the second terminal has achieved identity authentication at the second server, so the second terminal can subsequently use the target user's new public key PK2 and the target user's new private key SK2 to communicate with the second server, thereby conducting business online.
[0153] In the above process, the target user’s private key SK i (i.e., the first private key of the target user) is the most sensitive information used to describe the target user's autonomous identity and is stored in the first terminal. The target user's new private key SK2 (i.e., the second private key of the target user) is the most sensitive information used to describe the target user's business identity and is stored in the second terminal. The second terminal will only use the target user's new private key SK2 to complete identity authentication at the second server. That is, the second server can only access the most sensitive information used to describe the target user's business identity, but cannot access the most sensitive information used to describe the target user's autonomous identity. Therefore, the target user's autonomous identity and the target user's business identity can be isolated (i.e., stored in two terminals respectively). Even if the second terminal is lost, the information used to describe the target user's autonomous identity is still stored on the first terminal. Therefore, the target user can use the target user's autonomous identity through the first terminal to promptly revoke the old business identity at the second server and register a new business identity. Therefore, in this case, the target user's autonomous identity can be effectively protected and will not be misused.
[0154] In an embodiment of the present application, after the first server sends the first information for describing the first identity of the target user to the first terminal, the first terminal can generate the second information for describing the second identity of the target user based on the first information. Then, the first terminal sends the second information to the second terminal, so that the second terminal uses the second information to complete the identity authentication at the second server. In the aforementioned process, since the first information is stored in the first terminal, the second information is stored in the second terminal, and when the second terminal performs identity authentication with the second server, only the second information is involved, the first identity (autonomous identity) and the second identity (business identity) of the target user are successfully isolated and stored in the two terminals respectively, which can effectively protect the first identity of the target user from direct contact with the second server (business side). Even if the second terminal is lost, the first identity of the target user will not be impersonated, which can avoid potential security issues.
[0155] The above is a detailed description of the identity authentication method provided in the embodiment of the present application. The following will introduce the first server, first terminal, second terminal and second server provided in the embodiment of the present application. Figure 4A schematic diagram of the structure of the terminal provided in the embodiment of the present application is shown as follows: Figure 4 As shown, the terminal serves as a first terminal, and the first terminal includes:
[0156] An acquisition module 401 is configured to acquire first information from a first server, where the first information is used to describe a first identity of a target user;
[0157] A processing module 402 is configured to generate second information based on the first information, where the second information is used to describe a second identity of the target user;
[0158] The sending module 403 is configured to send second information to the second terminal, where the second information is used for the second terminal to perform identity authentication at the second server.
[0159] In one possible implementation, the first information includes a first private key of a target user, where the first private key is one of the private keys of multiple users matched by the first public key, and the multiple users include the target user; the processing module 402 is used to: generate a second private key of the target user and a second public key matching the second private key; sign the second public key based on the first private key to obtain a first certificate including the second public key; wherein the second information includes the first certificate and the second private key, the first certificate is used by the second server to perform a first signature verification based on the first public key, and the second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
[0160] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0161] In one possible implementation, the first information and the second information also include a second certificate, the second certificate includes a first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0162] In a possible implementation, the second credential further includes identity attributes possessed by multiple users.
[0163] Figure 5 Another structural diagram of the terminal provided in the embodiment of the present application is as follows Figure 5 As shown, the terminal serves as the second terminal, and the second terminal includes:
[0164] An acquisition module 501 is configured to acquire second information from a first terminal, where the second information is generated by the first terminal based on the first information from the first server, the first information being used to describe a first identity of a target user, and the second information being used to describe a second identity of the target user;
[0165] The sending module 502 is configured to send part of the second information to the second server, so as to implement identity authentication at the second server.
[0166] In one possible implementation, the first information includes the first private key of the target user, the first private key is one of the private keys of multiple users matched with the first public key, the multiple users include the target user, the second information includes the first certificate and the second private key of the target user, part of the information includes the first certificate, the first certificate includes the second public key matched with the second private key, the first certificate is signed based on the first private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key; the sending module 502 is used to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
[0167] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0168] In one possible implementation, the first information and part of the second information also include a second certificate, the second certificate includes a first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0169] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0170] Figure 6 A structural diagram of a server provided in an embodiment of the present application, such as Figure 6 As shown, the server serves as the first server, and the first server includes:
[0171] The sending module 601 is used to send first information to the first terminal. The first information is used to describe the first identity of the target user. The first information is also used by the first terminal to generate second information. The second information is used to describe the second identity of the target user. The second information is also used by the second terminal to implement identity authentication at the second server.
[0172] In one possible implementation, the first server also includes: a processing module, used to generate a first private key, the first private key is one of the private keys of multiple users matched with the first public key, and the multiple users include the target user; wherein the first information includes the first private key of the target user, the second information includes the first certificate and the second private key of the target user, the first certificate includes the second public key matching the second private key, the first certificate is signed based on the first private key, the first certificate is used by the second server to perform a first signature verification based on the first public key, and the second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
[0173] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0174] In one possible implementation, the processing module is further used to sign the first public key based on the third private key of the first server to obtain a second certificate containing the first public key; wherein the first information and the second information also include a second certificate, and the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
[0175] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0176] Figure 7 Another structural diagram of the server provided in the embodiment of the present application is as follows Figure 7 As shown, the server serves as the second server, and the second server includes:
[0177] An acquisition module 701 is configured to acquire part of second information from a second terminal, where the second information is generated by a first terminal based on first information from a first server, the first information being used to describe a first identity of a target user, and the second information being used to describe a second identity of the target user;
[0178] The processing module 702 is configured to perform identity authentication on the second terminal according to the partial information.
[0179] In one possible implementation, the first information includes a first private key of a target user, the first private key is one of the private keys of multiple users matched with the first public key, the multiple users include the target user, the second information includes a first certificate and a second private key of the target user, part of the information includes the first certificate, the first certificate includes the second public key matched with the second private key, and the first certificate is signed based on the first private key; the processing module 702 is used to: perform a first signature verification on the first certificate based on the first public key; after the first signature verification is successful, control the second terminal to prove to the second server that the second terminal owns the second private key.
[0180] In a possible implementation, the first private key is generated based on identity attributes possessed by multiple users.
[0181] In one possible implementation, the first information and partial information also include a second certificate, the second certificate includes a first public key, and the second certificate is signed based on the third private key of the first server. Before the second server performs a first verification on the first certificate based on the first public key, the processing module 702 is also used to perform a second verification on the second certificate based on the third public key matching the third private key; the processing module 702 is used to perform a first verification on the first certificate based on the first public key after the second verification is successful.
[0182] In a possible implementation, the second credential further includes a target attribute possessed by multiple users.
[0183] It should be noted that the information interaction, execution process, etc. between the modules / units of the above-mentioned device are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present application. For specific contents, please refer to the description in the method embodiment shown above in the embodiment of the present application, and no further details will be given here.
[0184] Figure 8 This is another schematic diagram of the structure of the terminal provided in the embodiment of the present application. Figure 8 , the terminal is used as the first terminal, and the first terminal can be a security device such as a smart watch, a smart bracelet, or smart glasses. For the sake of convenience, the following is a schematic introduction using a smart watch. The smart watch includes: a radio frequency (RF) circuit 810, a memory 820, an input unit 830, a display unit 840, a sensor 850, an audio circuit 860, a wireless fidelity (WiFi) module 870, a processor 880, and a power supply 890. Those skilled in the art will understand that Figure 8 The smart watch structure shown in the figure does not constitute a limitation to the smart watch, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0185] The following combination Figure 8 A detailed introduction to the various components of a smart watch:
[0186] The RF circuit 810 can be used to receive and send signals during information transmission or calls. In particular, after receiving the downlink information from the base station, it is sent to the processor 880 for processing; in addition, the designed uplink data is sent to the base station. Generally, the RF circuit 810 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF circuit 810 can also communicate with the network and other devices through wireless communication. The above-mentioned wireless communication can use any communication standard or protocol, including but not limited to the global system of mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), email, short messaging service (SMS), etc.
[0187] The memory 820 can be used to store software programs and modules. The processor 880 executes the various functional applications and data processing of the smart watch by running the software programs and modules stored in the memory 820. The memory 820 may mainly include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area may store data generated based on the use of the smart watch (such as audio data, a phone book, etc.). In addition, the memory 820 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0188] The input unit 830 can be used to receive input digital or character information, and to generate key signal inputs related to the user settings and function control of the smart watch. Specifically, the input unit 830 may include a touch panel 831 and other input devices 832. The touch panel 831, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using any suitable object or accessory such as a finger, stylus, etc. on or near the touch panel 831) and drive the corresponding connection device according to a pre-set program. Optionally, the touch panel 831 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch direction and detects the signal caused by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device and converts it into touch point coordinates, which are then sent to the processor 880. It can also receive commands sent by the processor 880 and execute them. In addition, the touch panel 831 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 831, the input unit 830 may further include other input devices 832. Specifically, the other input devices 832 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick.
[0189] The display unit 840 can be used to display information input by the user or information provided to the user and various menus of the smart watch. The display unit 840 may include a display panel 841. Optionally, the display panel 841 may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel 831 may cover the display panel 841. When the touch panel 831 detects a touch operation on or near it, it is transmitted to the processor 880 to determine the type of touch event. Subsequently, the processor 880 provides a corresponding visual output on the display panel 841 according to the type of touch event. Although in Figure 8 In the embodiment, the touch panel 831 and the display panel 841 are used as two independent components to realize the input and output functions of the smart watch, but in some embodiments, the touch panel 831 and the display panel 841 can be integrated to realize the input and output functions of the smart watch.
[0190] The smartwatch may also include at least one sensor 850, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 841 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 841 and / or the backlight when the smartwatch is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that identify the posture of the smartwatch (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that can be configured in the smartwatch, such as gyroscopes, barometers, hygrometers, thermometers, infrared, IMU, SLAM sensors, etc., they will not be described here.
[0191] Audio circuit 860, speaker 861, and microphone 862 provide an audio interface between the user and the smartwatch. Audio circuit 860 converts received audio data into electrical signals and transmits them to speaker 861, which then converts them into sound signals for output. Microphone 862, on the other hand, converts collected sound signals into electrical signals, which are then received by audio circuit 860 and converted into audio data. The audio data is then processed by processor 880 and then transmitted to, for example, another smartwatch via RF circuit 810, or stored in memory 820 for further processing.
[0192] WiFi is a short-range wireless transmission technology. Smart watches can help users send and receive emails, browse the web, and access streaming media through the WiFi module 870. It provides users with wireless broadband Internet access. Figure 8 A WiFi module 870 is shown, but it is understandable that it is not an essential component of the smart watch.
[0193] The processor 880 is the control center of the smartwatch, connecting all components of the smartwatch using various interfaces and circuits. By running or executing software programs and / or modules stored in the memory 820 and accessing data stored in the memory 820, it executes various smartwatch functions and processes data, thereby providing overall monitoring of the smartwatch. Optionally, the processor 880 may include one or more processing units; preferably, the processor 880 may integrate an application processor and a modem processor, with the application processor primarily handling the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into the processor 880.
[0194] The smart watch also includes a power supply 890 (such as a battery) for supplying power to various components. Preferably, the power supply can be logically connected to the processor 880 through a power management system, thereby realizing functions such as charging, discharging, and power consumption management through the power management system.
[0195] Although not shown, the smart watch may also include a camera, a Bluetooth module, etc., which will not be described in detail here.
[0196] In the embodiment of the present application, the processor 880 included in the smart watch can execute the aforementioned Figure 2 or Figure 3 The functions of the first terminal in the illustrated embodiment will not be described in detail here.
[0197] Figure 9 Another structural diagram of the terminal provided in the embodiment of the present application. Figure 9 , the terminal can be used as a second terminal, which can be a mobile phone, tablet computer, etc. For the sake of convenience, the following is a schematic description of a mobile phone. The mobile phone includes: radio frequency (RF) circuit 910, memory 920, input unit 930, display unit 940, sensor 950, audio circuit 960, wireless fidelity (WiFi) module 970, processor 980, and power supply 990. Those skilled in the art will understand that Figure 9 The mobile phone structure shown in the figure does not constitute a limitation to the mobile phone, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0198] The following combination Figure 9 A detailed introduction to the various components of a mobile phone:
[0199] The RF circuit 910 can be used to receive and send signals during information transmission or calls. In particular, after receiving the downlink information from the base station, it is sent to the processor 980 for processing; in addition, the designed uplink data is sent to the base station. Generally, the RF circuit 910 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF circuit 910 can also communicate with the network and other devices through wireless communication. The above-mentioned wireless communication can use any communication standard or protocol, including but not limited to the global system of mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), email, short messaging service (SMS), etc.
[0200] The memory 920 can be used to store software programs and modules. The processor 980 executes the various functional applications and data processing of the mobile phone by running the software programs and modules stored in the memory 920. The memory 920 may mainly include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area may store data created based on the use of the mobile phone (such as audio data, a phone book, etc.). In addition, the memory 920 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0201] The input unit 930 can be used to receive input digital or character information, and to generate key signal input related to the user settings and function control of the mobile phone. Specifically, the input unit 930 may include a touch panel 931 and other input devices 932. The touch panel 931, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using any suitable object or accessory such as a finger, stylus, etc. on or near the touch panel 931) and drive the corresponding connection device according to a pre-set program. Optionally, the touch panel 931 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch direction, detects the signal caused by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device and converts it into touch point coordinates, which are then sent to the processor 980, and can receive commands sent by the processor 980 and execute them. In addition, the touch panel 931 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 931, the input unit 930 may further include other input devices 932. Specifically, the other input devices 932 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick.
[0202] The display unit 940 can be used to display information input by the user or information provided to the user and various menus of the mobile phone. The display unit 940 may include a display panel 941. Optionally, the display panel 941 may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel 931 may cover the display panel 941. When the touch panel 931 detects a touch operation on or near it, it is transmitted to the processor 980 to determine the type of touch event. Subsequently, the processor 980 provides corresponding visual output on the display panel 941 according to the type of touch event. Although in Figure 9 In the embodiment, the touch panel 931 and the display panel 941 are used as two independent components to realize the input and output functions of the mobile phone, but in some embodiments, the touch panel 931 and the display panel 941 can be integrated to realize the input and output functions of the mobile phone.
[0203] The mobile phone may also include at least one sensor 950, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 941 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 941 and / or the backlight when the mobile phone is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that identify the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that the mobile phone can also be configured with, such as gyroscopes, barometers, hygrometers, thermometers, infrared, IMU, SLAM sensors, etc., they will not be repeated here.
[0204] Audio circuit 960, speaker 961, and microphone 962 provide an audio interface between the user and the phone. Audio circuit 960 converts received audio data into electrical signals and transmits them to speaker 961, which then converts them into sound signals for output. Microphone 962, on the other hand, converts collected sound signals into electrical signals, which are then received by audio circuit 960 and converted into audio data. The audio data is then processed by processor 980 and transmitted to, for example, another phone via RF circuit 910, or stored in memory 920 for further processing.
[0205] WiFi is a short-range wireless transmission technology. The mobile phone can help users send and receive emails, browse the web and access streaming media through the WiFi module 970. It provides users with wireless broadband Internet access. Figure 9 A WiFi module 970 is shown, but it is understandable that it is not an essential component of the mobile phone.
[0206] The processor 980 is the control center of the mobile phone, connecting all parts of the mobile phone using various interfaces and circuits. By running or executing software programs and / or modules stored in the memory 920 and accessing data stored in the memory 920, it performs various functions of the mobile phone and processes data, thereby providing overall monitoring of the mobile phone. Optionally, the processor 980 may include one or more processing units; preferably, the processor 980 may integrate an application processor and a modem processor, wherein the application processor primarily handles the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into the processor 980.
[0207] The mobile phone also includes a power supply 990 (such as a battery) for supplying power to various components. Preferably, the power supply can be logically connected to the processor 980 through a power management system, thereby managing charging, discharging, and power consumption management functions through the power management system.
[0208] Although not shown, the mobile phone may also include a camera, a Bluetooth module, etc., which will not be described in detail here.
[0209] In the embodiment of the present application, the processor 980 included in the mobile phone can execute the aforementioned Figure 2 or Figure 3 The functions of the second terminal in the illustrated embodiment will not be described in detail here.
[0210] Figure 10 Another structural diagram of the server provided in the embodiment of the present application. Figure 10 As shown, the server in the embodiment of the present application can serve as a first server. An embodiment of the first server can include one or more central processing units 1001, a memory 1002, an input and output interface 1003, a wired or wireless network interface 1004, and a power supply 1005.
[0211] The memory 1002 may be a temporary storage or a permanent storage. Furthermore, the central processing unit 1001 may be configured to communicate with the memory 1002 and execute a series of instruction operations in the memory 1002 on the first server.
[0212] In this embodiment, the CPU 1001 can execute the aforementioned Figure 2 or Figure 3 The operations performed by the first server in the illustrated embodiment will not be described in detail here.
[0213] In this embodiment, the specific functional module division in the central processing unit 1001 can be the same as the above Figure 6 The division of the processing module and the sending module described in is similar and will not be repeated here.
[0214] Figure 11 Another structural diagram of the server provided in the embodiment of the present application. Figure 11 As shown, the server in the embodiment of the present application can be used as a second server. An embodiment of the second server may include one or more central processing units 1101, a memory 1102, an input and output interface 1103, a wired or wireless network interface 1104, and a power supply 1105.
[0215] The memory 1102 may be a temporary storage or a permanent storage. Furthermore, the central processing unit 1101 may be configured to communicate with the memory 1102 and execute a series of instruction operations in the memory 1102 on the second server.
[0216] In this embodiment, the CPU 1101 can execute the aforementioned Figure 2 or Figure 3 The operations performed by the second server in the illustrated embodiment will not be described in detail here.
[0217] In this embodiment, the specific functional module division in the central processing unit 1101 can be the same as the above Figure 7 The division of modules such as the acquisition module and the processing module described in is similar and will not be repeated here.
[0218] The present application also relates to a computer storage medium storing one or more instructions, wherein the instructions, when executed by one or more computers, enable the one or more computers to implement the following Figure 2 or Figure 3 The method described.
[0219] The embodiment of the present application also relates to a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the following Figure 2 or Figure 3 The method described.
[0220] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0221] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0222] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0223] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0224] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
Claims
1. An identity authentication method, characterized in that: The method comprises: The first terminal obtains first information from the first server, where the first information is used to describe information about the autonomous identity of a target user, and the information about the autonomous identity of the target user includes at least one identity attribute of the target user; The first terminal generates second information based on the first information, where the second information is used to describe information about the service identity of the target user; The first terminal sends the second information to the second terminal, where the second information is used for the second terminal to implement identity authentication at a second server, and the first server and the second server are different servers.
2. The method according to claim 1, characterized in that The first information includes a first private key of the target user, where the first private key is one of private keys of multiple users that match the first public key, and the multiple users include the target user; The first terminal generating second information based on the first information includes: The first terminal generates a second private key of the target user and a second public key matching the second private key; The first terminal signs the second public key based on the first private key to obtain a first certificate including the second public key; The second information includes the first certificate and the second private key. The first certificate is used by the second server to perform a first signature verification based on the first public key. The second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
3. The method according to claim 2, characterized in that The first private key is generated based on identity attributes possessed by all of the multiple users.
4. The method according to claim 2, characterized in that The first information and the second information also include a second certificate, the second certificate includes the first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
5. The method according to claim 4, characterized in that The second credential further includes identity attributes possessed by the multiple users.
6. An identity authentication method, characterized in that: The method comprises: The second terminal obtains second information from the first terminal, where the second information is generated by the first terminal based on the first information from the first server, the first information is used to describe information about the autonomous identity of the target user, and the second information is used to describe information about the service identity of the target user; The second terminal sends part of the second information to a second server to implement identity authentication at the second server, and the first server and the second server are different servers.
7. The method according to claim 6, characterized in that The first information includes a first private key of the target user, the first private key is one of private keys of multiple users matched with the first public key, the multiple users including the target user, the second information includes a first credential and a second private key of the target user, the partial information includes the first credential, the first credential includes a second public key matched with the second private key, the first credential is signed based on the first private key, and the first credential is used by the second server to perform a first signature verification based on the first public key; The second terminal implementing identity authentication at the second server includes: After the first signature verification succeeds, the second terminal proves to the second server that the second terminal owns the second private key.
8. The method according to claim 7, characterized in that The first private key is generated based on identity attributes possessed by all of the multiple users.
9. The method according to claim 6, characterized in that The first information and the partial information also include a second certificate, the second certificate includes a first public key, the second certificate is signed based on the third private key of the first server, the second certificate is used by the second server to perform a second signature verification based on the third public key matching the third private key, and the first certificate is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
10. The method according to claim 9, characterized in that The second credential further includes a target attribute possessed by multiple users.
11. An identity authentication method, characterized in that: The method comprises: A first server sends first information to a first terminal. The first information is used to describe information about the autonomous identity of a target user. The first information is also used by the first terminal to generate second information. The second information is used to describe information about the service identity of the target user. The second information is also used by the second terminal to implement identity authentication at a second server. The first server and the second server are different servers.
12. The method according to claim 11, characterized in that The method further comprises: The first server generates a first private key, where the first private key is one of the private keys of multiple users that match the first public key, where the multiple users include the target user; The first information includes the first private key of the target user, the second information includes a first certificate and the second private key of the target user, the first certificate includes a second public key matching the second private key, the first certificate is signed based on the first private key, the first certificate is used by the second server to perform a first signature verification based on the first public key, and the second private key is used by the second terminal to prove to the second server that the second terminal owns the second private key after the first signature verification is successful.
13. The method according to claim 12, characterized in that The first private key is generated based on identity attributes possessed by all of the multiple users.
14. The method according to claim 12, characterized in that The method further comprises: The first server signs the first public key based on the third private key of the first server to obtain a second certificate including the first public key; The first information and the second information also include a second credential, the second credential is used by the second server to perform a second signature verification based on the third public key matched with the third private key, and the first credential is used by the second server to perform a first signature verification based on the first public key after the second signature verification is successful.
15. The method according to claim 14, characterized in that The second credential further includes a target attribute possessed by the plurality of users.
16. An identity authentication method, characterized in that: The method comprises: The second server obtains part of the second information from the second terminal, where the second information is generated by the first terminal based on the first information from the first server, the first information is used to describe the autonomous identity of the target user, and the second information is used to describe the service identity of the target user; The second server performs identity authentication on the second terminal according to the partial information, and the first server and the second server are different servers.
17. The method according to claim 16, characterized in that The first information includes a first private key of the target user, the first private key is one of private keys of multiple users matched with a first public key, the multiple users include the target user, the second information includes a first credential and a second private key of the target user, the partial information includes the first credential, the first credential includes a second public key matched with the second private key, and the first credential is signed based on the first private key; The second server implementing identity authentication on the second terminal according to the partial information includes: The second server performs a first signature verification on the first certificate based on the first public key; After the first signature verification succeeds, the second server controls the second terminal and proves to the second server that the second terminal owns the second private key.
18. The method according to claim 17, characterized in that The first private key is generated based on identity attributes possessed by all of the multiple users.
19. The method according to claim 17, wherein The first information and the partial information further include a second credential, the second credential including the first public key, the second credential being signed based on the third private key of the first server, and before the second server performs a first signature verification on the first credential based on the first public key, the method further includes: The second server performs a second signature verification on the second certificate based on a third public key matching the third private key; The second server performing a first signature verification on the first certificate based on the first public key includes: After the second signature verification succeeds, the second server performs a first signature verification on the first certificate based on the first public key.
20. The method according to claim 19, characterized in that The second credential further includes a target attribute possessed by the plurality of users.
21. A terminal, characterized in that: The terminal serves as a first terminal, and the first terminal includes: An acquisition module, configured to acquire first information from a first server, wherein the first information is used to describe information of a target user's autonomous identity; a processing module, configured to generate second information based on the first information, wherein the second information is used to describe information about the service identity of the target user; The sending module is configured to send the second information to the second terminal, where the second information is used for the second terminal to implement identity authentication at a second server, and the first server and the second server are different servers.
22. A terminal, characterized in that: The terminal serves as a second terminal, and the second terminal includes: an acquisition module, configured to acquire second information from a first terminal, where the second information is generated by the first terminal based on the first information from the first server, the first information being used to describe information about the autonomous identity of a target user, and the second information being used to describe information about the service identity of the target user; The sending module is used to send part of the second information to a second server to implement identity authentication at the second server, and the first server and the second server are different servers.
23. A server, characterized in that: The server serves as a first server, and the first server includes: A sending module is used to send first information to a first terminal, where the first information is used to describe information about the autonomous identity of a target user. The first information is also used by the first terminal to generate second information, where the second information is used to describe information about the service identity of the target user. The second information is also used by the second terminal to implement identity authentication at a second server, where the first server and the second server are different servers.
24. A server, characterized in that: The server serves as a second server, and the second server includes: an acquisition module, configured to acquire part of second information from a second terminal, where the second information is generated by the first terminal based on the first information from the first server, the first information being used to describe information about the autonomous identity of a target user, and the second information being used to describe information about the service identity of the target user; The processing module is configured to perform identity authentication on the second terminal according to the partial information, wherein the first server and the second server are different servers.
25. A terminal, characterized in that: The terminal serves as a first terminal, and the first terminal includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the first terminal executes the method according to any one of claims 1 to 5.
26. A terminal, characterized in that: The terminal serves as the second terminal, the first terminal includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the second terminal executes the method according to any one of claims 6 to 10.
27. A server, characterized in that: The server serves as a first server, and the first server includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the first server executes the method according to any one of claims 11 to 15.
28. A server, characterized in that: The server serves as a second server, and the second server includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the second server executes the method according to any one of claims 16 to 20.
29. An identity authentication system, characterized in that: The system comprises the first terminal according to claim 25 , the second terminal according to claim 26 , the first server according to claim 27 , and the second server according to claim 28 .
30. A computer storage medium, characterized in that The computer storage medium stores one or more instructions, which, when executed by one or more computers, cause the one or more computers to implement the method of any one of claims 1 to 20.
31. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, cause the computer to implement the method according to any one of claims 1 to 20.
Citation Information
Patent Citations
Identity authentication method and device
CN103905401A
Identity authentication method, server and authentication terminal
CN105515783A