A business account application method based on legal identity

By constructing a digital identity file based on account identity identification and device feature information, the problem of insufficient security of the existing identity authentication methods is solved, and unique authentication of user equipment and high security level authentication are realized.

CN115801333BActive Publication Date: 2025-08-29NEW CONTINENT (FUJIAN) PUBLIC SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211323069.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-27
Publication Date
2025-08-29
Estimated Expiration
2042-10-27

AI Technical Summary

Technical Problem

The existing identity authentication methods have insufficient security, especially the username/password and physical media methods are prone to leakage. The portability and security of the biological feature methods need to be improved, and the security of the existing online verification methods also need to be improved.

Method used

A digital identity file based on account identity identification and device feature information is constructed. The user equipment has a strong binding relationship with the digital identity file. The binding relationship is stored in the digital identity file instead of the system background. It adopts the data format of A+B+S and sets special controls on the client, combining two authentication modes for identity authentication.

Benefits of technology

Improve the security of identity authentication, prevent the leakage and tampering of binding relationships, improve the unique authentication of user equipment, reduce sensitive data leakage, and enhance the security level of the application system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801333B_ABST
    Figure CN115801333B_ABST
Patent Text Reader

Abstract

The present invention relates to a business account application method of a root legal identity, comprising: an application party obtains a digital identity file; the digital identity file contains device feature information and an account identity identifier; the application party generates the device feature information; the application party sends the digital identity file, device feature information and requests the account identity to a digital identity service party; the digital identity service party parses the digital identity file to obtain the account identity identifier and device feature information; the digital identity service party compares the parsed device feature information with the received device feature information, and if the comparison result is consistent, returns the account identity identifier to the application party. The present invention constructs a digital identity file as a user's login and matter handling credential in an application system, and the binding relationship between the account identity identifier and the device feature information is stored in the digital identity file rather than uniformly stored in the system background, thereby preventing the binding relationship from being leaked and tampered with on a large scale in the system background.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a business account application method of a root legal identity, belonging to the field of identity authentication. Background Art

[0002] Identity authentication refers to the process of verifying the user's identity information before accessing an application system to determine whether the user can complete the access. Currently, the following are the commonly used identity authentication methods:

[0003] 1. Username / password-based method: As long as the application system receives the correct password, it assumes the operator is a legitimate user. This method is simple and easy to use, but the risk of password leakage is extremely high. Once the password is leaked, anyone can impersonate the user.

[0004] 2. Physical media-based method: User identity data is stored in physical media such as IC cards and U-keys. Identity authentication is completed by reading the data in the physical media. However, physical media is not easy to carry and can be easily lost or forged.

[0005] 3. Based on biometrics: using the uniqueness of the user's physiological characteristics to identify the user, such as face recognition, fingerprint recognition, palm print recognition, retinal recognition, etc.

[0006] In summary, a more secure application system identity authentication method is needed.

[0007] Patent publication number CN109413086B, "Method and Apparatus for Online Identity Verification," discloses the use of trusted applications to verify user identity information online when online services require identity verification. Specifically, online business applications can invoke the trusted application's verification service. Based on the verification requirements of the online business corresponding to the business application, the trusted application backend collects the user's identity information and sends it to a third-party trusted verification source for verification, thereby ensuring the authority and security of the verification results. However, this security needs to be further improved. Summary of the Invention

[0008] In order to overcome the problems existing in the prior art, the present invention designs a business account application method based on legal identity, constructs a digital identity file based on account identity identification and device feature information as the user's login and matter handling credentials in the application system, so that the user device and the digital identity file have a strong binding relationship, and the user can only use the digital identity file on a specific device; at the same time, the binding relationship between the account identity identification and device feature information is stored in the digital identity file instead of being uniformly stored in the system background, avoiding the risk of large-scale leakage and tampering of the binding relationship in the system background.

[0009] In order to achieve the above object, the present invention adopts the following technical solutions:

[0010] A business account application method for a root legal identity includes the following steps:

[0011] The application party obtains a digital identity file; the digital identity file includes device feature information and account identity identification;

[0012] The application party generates device feature information;

[0013] The application sends the digital identity document and device feature information to the digital identity service provider and requests the account identity;

[0014] The digital identity service provider parses the digital identity file to obtain the account identity identifier and device feature information; the digital identity service provider compares the parsed device feature information with the received device feature information. If the comparison results are consistent, the account identity identifier is returned to the application party.

[0015] Furthermore, the application side is provided with a dedicated control, wherein the dedicated control stores a first algorithm; the application side generates device feature information according to the first algorithm.

[0016] Furthermore, the digital identity service provider is provided with a first authentication mode, which includes the following steps:

[0017] Verify the signature value in the digital identity file; if the verification succeeds, return the account identity identifier to the application; otherwise, return authentication failure to the application.

[0018] Furthermore, the digital identity service provider is provided with a second authentication mode, which includes the following steps:

[0019] Find the real-name identity associated with the account identity; use the real-name identity to query the real-name identity information; perform identity authentication based on the real-name identity information. If the authentication succeeds, return the account identity to the application; otherwise, return an authentication failure to the application.

[0020] Furthermore, the digital identity file includes segment A data, segment B data, and segment S data:

[0021] The A segment data includes the account identity; the B segment data includes the device feature information; the S segment data includes the A segment data and the B segment data; the A segment data and the B segment data are then spliced ​​together and the SM2 algorithm is used to generate the signature value of the splicing result of the A segment data and the B segment data as the S segment data.

[0022] Furthermore, the application party obtains the digital identity document, and the specific steps are as follows:

[0023] The application party generates device feature information;

[0024] The application sends real-name identity information and device feature information to the digital identity service provider and requests a digital identity document;

[0025] The digital identity service provider issues an account identity identifier; queries or generates the user's real-name identity identifier based on the real-name identity information; establishes and stores the association between the account identity identifier and the real-name identity identifier;

[0026] The digital identity service provider generates and returns a digital identity file to the application party based on device feature information and account identity identifier.

[0027] Technical Solution 2

[0028] A business account application method for a root legal identity, applied to a client, includes the following steps:

[0029] Obtaining a digital identity file, the digital identity file including device feature information and account identity identifier;

[0030] Generate device characteristic information;

[0031] Send digital identity documents, device characteristics information and request account identity;

[0032] Receive the returned account identity.

[0033] Furthermore, the client is provided with a dedicated control, which stores a first algorithm; the client generates device feature information according to the first algorithm

[0034] Technical Solution 3

[0035] A business account application method for a root legal identity, applied to a server, includes the following steps:

[0036] Receiving a digital identity file, wherein the digital identity file includes device feature information and an account identity identifier;

[0037] Receive device characteristic information;

[0038] Receive account identity request;

[0039] Parse the digital identity file to obtain the account identity and device feature information; compare the parsed device feature information with the received device feature information. If the comparison results are consistent, return the account identity.

[0040] Furthermore, the server is provided with a second authentication mode, which includes the following steps:

[0041] Find the real-name identity associated with the account identity; use the real-name identity to query the real-name identity information; perform identity authentication based on the real-name identity information. If the identity authentication succeeds, the account identity is returned to the application; otherwise, an authentication failure is returned.

[0042] Compared with the prior art, the present invention has the following characteristics and beneficial effects:

[0043] 1. The present invention constructs a digital identity file based on the account identity identifier and device feature information as a user's login and transaction credentials in the application system, so that the user device and the digital identity file have a strong binding relationship, and the user can only use the digital identity file on a specific device; at the same time, the binding relationship between the account identity identifier and the device feature information is stored in the digital identity file rather than uniformly stored in the system background, avoiding the risk of large-scale leakage and tampering of the binding relationship in the system background.

[0044] 2. The digital identity file of the present invention adopts the data format of A+B+S, wherein the S segment data is the signature value of the A segment data and the B segment data, thereby ensuring the integrity and tamper-proofing of the content of the digital identity file.

[0045] 3. The present invention sets a dedicated control in the application system client to save the first algorithm for reading device feature information and the second algorithm for encrypting message data, so as to prevent a third party from deciphering the first algorithm and the second algorithm used by the application system client, thereby forging device feature information and message data sent by the application system client, preventing a third party from forging message data to initiate credential authentication across mobile phone terminals, and improving the security level.

[0046] 4. In the present invention, the application system client sends a digital identity file to the digital identity service provider. The digital identity service provider verifies and parses the digital identity file, obtains and returns the account identity identifier therein, and the application system client handles business based on the account identity identifier. During the application process, the user does not need to enter the account identity identifier or real-name identity identifier to avoid the leakage of sensitive data.

[0047] 5. The present invention sets two authentication modes. The first authentication mode only verifies the digital identity document, which facilitates users to quickly complete login authentication; the second authentication mode uses the real-name identity identifier in the digital identity document and uses an external authoritative digital identity service platform to perform real-name identity authentication to further verify the authenticity of the user. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 It is a flow chart of the present invention;

[0049] Figure 2 It is a flowchart of digital identity document generation;

[0050] Figure 3It is a flowchart of digital identity document application. DETAILED DESCRIPTION

[0051] The present invention will be described in more detail below with reference to the embodiments.

[0052] Example 1

[0053] like Figure 1 and 2 As shown, the method for generating a digital identity document includes the following steps:

[0054] In this embodiment, the digital identity service provider includes a first digital identity service platform and an authoritative second digital identity service platform; the application provider includes an application system client and an application system server.

[0055] The application system client collects real-name identity information, such as name, ID number, etc.

[0056] The application system client collects authentication factors, such as facial images and passwords.

[0057] The application system client reads the device's characteristic factors and generates device characteristic information according to a first algorithm. The characteristic factors may be an advertising identifier, a vendor identifier, a mobile device identification code, an Ethernet physical address, a device fingerprint, etc.

[0058] The application system client sends real-name identity information, authentication factors, and device feature information to the first digital identity service platform and requests a digital identity file.

[0059] The first digital identity service platform sends the real-name identity information and authentication factors to the second digital identity service platform and requests identity authentication. The second digital identity service platform performs identity authentication based on the real-name identity information and authentication factors and returns the identity authentication result to the first digital identity service platform.

[0060] If the identity authentication result is passed, the first digital identity service platform will issue an account identity identifier for the user. Specifically, an encryption algorithm such as "snowflake" will generate a non-repeating random number as the account identity identifier.

[0061] The first digital identity service platform queries or generates the user's real-name identity identifier / network identity credential based on the real-name identity information. The first digital identity service platform establishes an association between the account identity identifier and the real-name identity identifier / network identity credential and stores the association in a database.

[0062] The first digital identity service platform splices account identity identification ciphertext, random number, timestamp and other data, and then encrypts the splicing result through the SM4 algorithm to generate segment A data; uses the device feature information as segment B data; then splices segment A data and segment B data and uses the signature value of the splicing result of segment A data and segment B data generated by the SM2 algorithm as segment S data; splices segment A data, segment B data and segment S data to obtain a digital identity file.

[0063] The digital identity service provider returns the digital identity file to the application system client.

[0064] Example 2

[0065] The difference between this embodiment and the first embodiment is that the application system client requests the digital identity file from the application system server, and the application system server forwards the digital identity file request to the digital identity service provider.

[0066] Example 3

[0067] The difference between this embodiment and the first embodiment is that the application system client is provided with a dedicated control, which stores a first algorithm for reading device characteristic information and a second algorithm for encrypting message data, thereby preventing a third party from deciphering the data content and data format of the device characteristic information and message data, thereby forging the device characteristic information and the message data sent by the application system client.

[0068] Example 4

[0069] like Figure 3 As shown, the digital identity service provider has a first digital identity service platform and a second digital identity service platform.

[0070] The digital identity document application method includes the following steps:

[0071] The application system client uses a dedicated control to encrypt the digital identity file.

[0072] The application system client uses a dedicated control to read device feature information.

[0073] The application system client collects authentication factors.

[0074] The application system client sends the digital identity file ciphertext, device feature information, and authentication factors to the first digital identity service platform to request account identity;

[0075] The first digital identity service platform determines the authentication mode (the first digital identity service platform determines the authentication mode according to the interface called by the application system client);

[0076] In the first authentication mode, the first digital identity service platform verifies the signature value in the digital identity file. Once the verification is successful, the digital identity file ciphertext is parsed to obtain the account identity identifier and device feature information. The first digital identity service platform determines the validity of the account identity identifier. If valid, it further compares the parsed device feature information with the received device feature information. If the comparison results are consistent, the first digital identity service platform returns the account identity identifier to the application client; otherwise, it returns an authentication failure to the application client.

[0077] In the second authentication mode, the first digital identity service platform verifies and parses the digital identity file, obtaining the account identifier and device feature information. The first digital identity service platform determines the validity of the account identifier (e.g., whether the data format is correct, whether there is a match in the account identifier database, etc.). If valid, the first digital identity service platform further compares the parsed device feature information with the received device feature information. If the comparison results are consistent, the first digital identity service platform searches the database for the real-name identifier associated with the account identifier, uses the real-name identifier to query the real-name identity information (e.g., user name, ID number), and sends the authentication factor and real-name identity information to the second digital identity service platform. Alternatively, the first digital identity service platform searches the database for the network identity credential associated with the account identifier, and sends the authentication factor and network identity credential to the second digital identity service platform. The second digital identity service platform performs identity authentication based on the authentication factor and real-name identity information / network identity credential, and returns the authentication result. If the authentication result is passed, the first digital identity service platform returns the account identifier to the application system client.

[0078] Example 5

[0079] The difference between this embodiment and the third embodiment is that the application system client requests the account identity from the application system server, and the application system server forwards the account identity request to the first digital identity service platform.

[0080] Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

Claims

1. A business account application method based on legal identity, characterized in that: The following steps are involved: The application party obtains a digital identity file; the digital identity file includes segment A data, segment B data, and segment S data: the segment A data includes the account identity identifier; the segment B data includes device feature information; the segment A data and segment B data are spliced ​​together and the SM2 algorithm is used to generate a signature value of the splicing result of the segment A data and segment B data as the segment S data; the segment A data, segment B data, and segment S data are spliced ​​together to obtain the digital identity file; The application party obtains the digital identity file in the following specific steps: The application party generates device feature information; The application sends real-name identity information and device feature information to the digital identity service provider and requests a digital identity document; The digital identity service provider issues the account identity identifier; queries or generates the user's real-name identity identifier based on the real-name identity information; establishes and stores the association between the account identity identifier and the real-name identity identifier; The digital identity service provider generates and returns a digital identity file to the application party based on the device feature information and account identity identifier; The application party generates device feature information; The application sends the digital identity document and device feature information to the digital identity service provider and requests the account identity identifier; The digital identity service provider parses the digital identity file to obtain the account identity identifier and device feature information; the digital identity service provider compares the parsed device feature information with the received device feature information. If the comparison results are consistent, the account identity identifier is returned to the application party.

2. A business account application method for root legal identity according to claim 1, characterized in that: The application side is provided with a dedicated control, wherein the dedicated control stores a first algorithm; the application side generates device feature information according to the first algorithm.

3. A business account application method for root legal identity according to claim 1, characterized in that: The digital identity service provider has a first authentication mode, which includes the following steps: The digital identity service provider verifies the signature value in the digital identity file; if the verification is successful, the digital identity file is parsed to obtain the account identity identifier and device feature information; the digital identity service provider determines the validity of the account identity identifier. If valid, the parsed device feature information is further compared with the received device feature information. If the comparison results are consistent, the digital identity service provider returns the account identity identifier to the application party; otherwise, the authentication failure is returned to the application party.

4. A business account application method for root legal identity according to claim 1, characterized in that: The digital identity service provider has a second authentication mode, which includes the following steps: The digital identity service provider verifies and parses the digital identity file to obtain the account identity identifier and device feature information; the digital identity service provider determines the validity of the account identity identifier. If valid, the service provider further compares the parsed device feature information with the received device feature information. If the comparison results are consistent, the service provider searches the database for the real-name identity identifier associated with the account identity identifier; uses the real-name identity identifier to query the real-name identity information; performs identity authentication based on the real-name identity information, and if the identity authentication is successful, returns the account identity identifier to the application party; Otherwise, an authentication failure is returned to the application.

Citation Information

Patent Citations

  • Methods and devices for online identity verification

    CN109413086B

  • Terminal equipment dependable authentication method and system in digital copyright protection system

    CN106656499A