A digital identity and account authentication method, device and storage medium
By generating a trusted digital identity root and binding it to the online certificate platform, the problem of plaintext identity information leakage in multi-tenant scenarios is solved, and more secure identity authentication is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU DABBY INTERNET TECH CO LTD
- Filing Date
- 2023-05-11
- Publication Date
- 2026-07-24
AI Technical Summary
In multi-tenant scenarios, there is a risk of plaintext information leakage when using plaintext identity information for authentication.
By generating a trusted digital identity root and binding it to the online certificate identifier of the online certificate platform, the trusted digital identity root can replace plaintext identity information to realize user identity authentication in different applications.
This reduces the risk of plaintext identity information being leaked during the identity authentication process and improves the stability and reliability of identity authentication.
Smart Images

Figure CN116846585B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computers, and more particularly to a method, apparatus, and storage medium for authenticating digital identities and their accounts. Background Technology
[0002] With the development of the internet, by using identity information as a marker of citizenship in the internet environment, it is possible to verify the true identity of each citizen online. In multi-tenant application scenarios, applications may belong to the same platform or different platforms. Sometimes, user authentication is required between applications. For example, when application A needs to obtain relevant data of user 1 in application B, application B authenticates the identity of user 1 relative to application 1, finds the account corresponding to user 1 in application B, retrieves the relevant data of that account, and then transmits it to application A. To achieve user authentication in this process, in the existing multi-tenant scenario, each platform stores the user's plaintext identity information, and then performs user authentication according to the following process: First, obtain the first account ID of user 1 in application A. Then, query the user's plaintext identity information corresponding to the first account ID. Then, query the second account ID corresponding to the user's plaintext identity information in application B based on the queried user's plaintext identity information, complete the user authentication, and then application B transmits the relevant data corresponding to the second account ID to application A.
[0003] In the above process, users' plaintext identity information is stored in each platform. The authentication process relies on the user's plaintext identity information to complete the user identity authentication. This method poses a risk of leakage of users' plaintext identity information. Summary of the Invention
[0004] This invention provides a method, apparatus, and storage medium for authenticating digital identities and their accounts, in order to solve the technical problem that using plaintext identity information for identity authentication can easily lead to the exposure of plaintext information.
[0005] To address the aforementioned technical problems, embodiments of the present invention provide a user identity authentication method, comprising:
[0006] Receive the authentication credential request from the first application and the first application-level digital identity account under the current first application;
[0007] Based on the first application-level digital identity account, a first authentication credential is generated and returned to the first application, so that after receiving the first authentication credential, the first application sends the first authentication credential and the business data acquisition request to the second application.
[0008] Receive the second authentication credential submitted by the second application and the second application-level digital identity account under the current second application, and verify the second authentication credential to determine whether the first authentication credential and the second authentication credential are consistent. If they are consistent, the verification passes; otherwise, the verification fails.
[0009] After verification, the first trusted digital identity root corresponding to the first application-level digital identity account is found based on the first application-level digital identity account; the second trusted digital identity root corresponding to the second application-level digital identity account is found based on the second application-level digital identity account; wherein, the first trusted digital identity root and the second trusted digital identity root are bound to the e-certificate identifier corresponding to the e-certificate platform.
[0010] Determine whether the first trusted digital identity root and the second trusted digital identity root are consistent. If they are, use the second application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and generate an authentication result.
[0011] If not, query the third application-level digital identity account of the first trusted digital identity root under the second application, use the third application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account under the second application, and generate an authentication result.
[0012] As a preferred embodiment, the second authentication credential is verified, including:
[0013] Determine whether the first authentication credential and the second authentication credential are consistent. If they are, the verification passes; otherwise, the verification fails.
[0014] As a preferred solution, the preset trusted digital identity root corresponding to the application-level digital identity account is found based on the application-level digital identity account, including:
[0015] Find the company-level digital identity account associated with the application-level digital identity account;
[0016] Find the organization-level digital identity account associated with the company-level digital identity account;
[0017] Find the platform-level digital identity account associated with the organization-level digital identity account;
[0018] Find the root digital identity account associated with the platform-level digital identity account based on the platform-level digital identity account;
[0019] Find the trusted digital identity root associated with the digital identity root.
[0020] As a preferred embodiment, after generating the authentication result by using the second application-level digital identity account as the user's application-level digital identity account corresponding to the first application-level digital identity account in the second application, the following steps are also included:
[0021] The authentication result is returned to the second application, so that the second application can extract the business data corresponding to the second application-level digital identity in the second application based on the second application-level digital identity account and the business data acquisition request, and transmit the business data and the authentication result to the first application;
[0022] After generating the authentication result by using the third application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, the method further includes:
[0023] The authentication result and the third application-level digital identity root are returned to the second application, so that the second application can extract the business data corresponding to the third application-level digital identity in the second application based on the third application-level digital identity account and the business data acquisition request, and transmit the business data and the authentication result to the first application.
[0024] As a preferred option, the method for generating a trusted digital identity root includes:
[0025] Collect user identity information;
[0026] The user's online ID is obtained by authenticating the user's identity information through the online ID platform.
[0027] Generate a first string based on the user's identity information and a random number;
[0028] The user's identity information in the first string is encrypted to generate a second string;
[0029] Use the second string as a trusted digital identity root;
[0030] Bind the trusted digital identity root to the network certificate identifier;
[0031] The user's identity information includes any one or more of the following: name, ID number, and document validity period.
[0032] As a preferred option, the method for generating a digital identity root includes:
[0033] Collect users' mobile phone numbers and biometric data;
[0034] The mobile phone number is processed by a feature extraction algorithm to generate a first feature;
[0035] The biometric features are extracted using a feature extraction algorithm to generate a second feature.
[0036] A digital identity root is generated based on the first feature and the second feature;
[0037] Associate the digital identity root with the trusted digital identity root;
[0038] The biometric features include any one or more of the following: facial image, iris, voiceprint, and fingerprint.
[0039] As a preferred solution, the generation of platform-level digital identity accounts includes:
[0040] Based on the platform name, platform key, and preset platform ID, a platform-level digital identity account is generated, and the platform-level digital identity account is associated with the digital identity root.
[0041] The generation of the organization-level digital identity account includes:
[0042] Based on the organization name and the preset organization ID, an organization-level digital identity account is generated, and the organization-level digital identity account is associated with the platform-level digital identity account;
[0043] The generation of the company-level digital identity account includes:
[0044] Based on the company name, the company's unified social credit code, and the preset company ID, a company-level digital identity account is generated, and the company-level digital identity account is associated with the organization-level digital identity account;
[0045] The generation of the application-level digital identity account includes:
[0046] Based on the application name, application type, and preset application ID, an application-level digital identity account is generated, and the application-level digital identity account is associated with the company-level digital identity account.
[0047] The present invention also provides a user identity authentication system, comprising:
[0048] The request receiving module is used to receive the authentication credential application request of the first application and the first digital identity account under the current first application;
[0049] The authentication credential processing module is used to generate a first authentication credential based on the first application-level digital identity account, and return the first authentication credential to the first application, so that after receiving the first authentication credential, the first application sends the first authentication credential and the business data acquisition request to the second application.
[0050] The verification module is used to receive the second authentication credential submitted by the second application and the second application-level digital identity account under the current second application, and to verify the second authentication credential.
[0051] The identity query module is used to, after verification, find the preset first trusted digital identity root corresponding to the first application-level digital identity account based on the first application-level digital identity account; and find the preset second trusted digital identity root corresponding to the second application-level digital identity account based on the second application-level digital identity account; wherein, the first trusted digital identity root and the second trusted digital identity root are bound to the e-certificate identifier corresponding to the e-certificate platform;
[0052] The authentication module is used to determine whether the first trusted digital identity root and the second trusted digital identity root are consistent. If they are, the second application-level digital identity account is used as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and an authentication result is generated. If not, the third application-level digital identity account of the first trusted digital identity root in the second application is queried, and the third application-level digital identity account is used as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and an authentication result is generated.
[0053] The present invention also provides a storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the storage medium is located to perform the aforementioned user authentication method.
[0054] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:
[0055] This invention provides a user identity authentication method, comprising: generating and returning authentication credentials for an application requesting authentication, so that the application sends the authentication credentials and a business data acquisition request to another application; verifying the received authentication credentials; after successful verification, confirming whether the application-level digital identity account that sent the authentication credentials corresponds to the same person through a trusted digital identity root; if so, authenticating the application-level identity information and generating an authentication result; if not, finding the application-level identity information corresponding to the same person, authenticating the application-level identity information, and generating an authentication result. This invention reduces the risk of plaintext identity information leakage during the authentication process by binding a trusted digital identity root to the corresponding network certificate identifier of the network certificate platform and using the trusted digital identity root to replace the role of plaintext identity information in the prior art to achieve identity authentication between the digital identity accounts of the same user in different applications. Attached Figure Description
[0056] Figure 1 A flowchart illustrating a user authentication method provided in an embodiment of the present invention;
[0057] Figure 2 This is a schematic diagram of the structure of a user identity authentication system provided in an embodiment of the present invention;
[0058] Figure 3 A diagram illustrating the structure of a user identity account provided in an embodiment of the present invention;
[0059] Figure 4 A flowchart for user authentication provided in an embodiment of the present invention;
[0060] Figure 5 This is an architecture diagram of a user identity account provided in an embodiment of the present invention. Detailed Implementation
[0061] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0062] Example 1
[0063] Please refer to Figure 1 The present invention provides a user authentication method, comprising the following steps:
[0064] Step S1: Receive the authentication credential application request from the first application and the first application-level digital identity account under the current first application;
[0065] The preferred authentication method described above is suitable for authenticating user identities when various applications in a multi-tenant architecture need to exchange business data.
[0066] Corresponding to the platform-level, organization-level, company-level, and application-level layers in the multi-tenant architecture, this system will generate platform-level digital identity accounts, organization-level digital identity accounts, company-level digital identity accounts, and application-level digital identity accounts for users.
[0067] When a user needs to exchange business data between a first application and a second application, for example, when the first application needs to send a business data retrieval request to the second application, the first application will send an authentication credential request and a first application-level digital identity account to the system. The first application-level digital identity account refers to the user's application-level digital identity account under the first application.
[0068] For example, such as Figure 4 , Figure 5 As shown, when user Zhang San needs to exchange business information between application E and application F, for example, if application E needs to send a business data acquisition request to application F, then application E will send an authentication credential application request and Zhang San's application-level digital identity account OpenID_A_1_1_1_1 under application E to the system.
[0069] Step S2: Generate a first authentication credential based on the first application-level digital identity account, and return the first authentication credential to the first application, so that after receiving the first authentication credential, the first application sends the first authentication credential and the business data acquisition request to the second application;
[0070] After receiving the authentication credential request and the application-level digital identity account from the first application, the system generates a random and unique string based on the application-level digital identity account, and uses this string as the first authentication credential. After generating the first authentication credential, the system returns it to the first application. Upon receiving the first authentication credential from the system, the first application sends the first authentication credential along with a request to obtain relevant business data to the second application.
[0071] After the system generates the authentication credential, it will also register the generation information of the authentication credential. The generation information of the authentication credential includes the authentication credential, the first application-level digital identity account, and the correspondence between the authentication credential and the first application-level digital identity account.
[0072] For example, as described in the previous example, after receiving the authentication credential request and application-level digital identity account OpenID_A_1_1_1_1 from application E, the system generates a random and unique string based on OpenID_A_1_1_1_1 and uses this string as the authentication credential_1. After generating the authentication credential_1, the system returns it to application E. Upon receiving the credential_1 from the system, application E sends the credential_1 along with a request to obtain relevant business data to application F.
[0073] Step S3: Receive the second authentication credential submitted by the second application and the second application-level digital identity account under the current second application, and verify the second authentication credential to determine whether the first authentication credential and the second authentication credential are consistent. If they are, the verification passes; otherwise, the verification fails.
[0074] After receiving the second authentication credential from a certain application, the second application sends the second authentication credential and the second application-level digital identity account to the system. The second application-level digital identity account refers to the application-level digital identity account of the current user of the second application under the second application.
[0075] After receiving the second authentication credential and the second application-level digital identity account from the second application, the system verifies the second authentication credential to determine if the first authentication credential and the second authentication credential are consistent. If they are consistent, the verification passes, and subsequent operations continue. If they are inconsistent, the verification fails, and subsequent operations stop. After successful verification, the system also extracts the first application-level digital identity account from the information generated by the first authentication credential.
[0076] Using verification methods to determine the first and second applications that require identity authentication makes the authentication process more stable and reliable.
[0077] For example, as described in the previous example, after receiving the authentication credential_2 from another application, application F sends Credential_2 and the application-level digital identity account OpenID_X_2_1_1_1 of the current user under application F to the system. After receiving the authentication credential_2 and the application-level digital identity account OpenID_X_2_1_1_1 from application F, the system verifies Credential_2 to determine whether Credential_1 and Credential_2 are consistent. If they are consistent, the verification passes and the subsequent operations continue. If they are inconsistent, the verification fails and the subsequent operations stop. After the verification passes, the system also extracts the application-level digital identity account OpenID_A_1_1_1_1 from the so-called generated information of the authentication credential_1.
[0078] Step S4: After verification, find the preset first trusted digital identity root corresponding to the first application-level digital identity account based on the first application-level digital identity account; find the preset second trusted digital identity root corresponding to the second application-level digital identity account based on the second application-level digital identity account; wherein, the first trusted digital identity root and the second trusted digital identity root are bound to the e-certificate identifier corresponding to the e-certificate platform;
[0079] In a preferred embodiment, finding the preset trusted digital identity root corresponding to the application-level digital identity account based on the application-level digital identity account includes:
[0080] Find the company-level digital identity account associated with the application-level digital identity account based on the application-level digital identity account;
[0081] Based on the company-level digital identity account, find the organization-level digital identity account associated with the company-level digital identity account;
[0082] Based on the organization-level digital identity account, find the platform-level digital identity account associated with the organization-level digital identity account;
[0083] Based on the platform-level digital identity account, find the root digital identity account associated with the platform-level digital identity account;
[0084] Based on the digital identity account root, a trusted digital identity account root associated with the digital identity account root is found.
[0085] After successful verification, the system will look up the first company-level digital identity account associated with the first application-level digital identity account, then look up the first organization-level digital identity account associated with the first company-level digital identity account, then look up the first platform-level digital identity account associated with the first organization-level digital identity account, then look up the first digital identity root managed by the first platform-level digital identity account, and finally look up the first trusted digital identity root associated with the first digital identity root. Simultaneously, the system will look up the second company-level digital identity account associated with the second application-level digital identity account, then look up the second organization-level digital identity account associated with the second company-level digital identity account, then look up the second platform-level digital identity account associated with the second organization-level digital identity account, then look up the second digital identity root associated with the platform-level digital identity account, and finally look up the second trusted digital identity root associated with the second digital identity root.
[0086] For example, as described in the previous example, after successful verification, the system will look up the company-level digital identity account UnionID_A_1_1_1_1 associated with OpenID_A_1_1_1_1, then look up the organization-level digital identity account UserID_A_1_1 associated with UnionID_A_1_1_1, then look up the platform-level digital identity account OneID_A_1_1 associated with UserID_A_1_1, then look up the digital identity root PhoneID_A associated with OneID_A_1, and finally look up the first trusted digital identity root Roo associated with PhoneID_A. tID_A; Simultaneously, the system will look up the company-level digital identity account UnionId_X_2_1_1_1 associated with OpenID_X_2_1_1_1 based on the application-level digital identity account OpenID_X_2_1_1_1. Then, it will look up the organization-level digital identity account UserID_X_2_1 associated with UnionId_X_2_1_1. Next, it will look up the platform-level digital identity account OneID_X_2 associated with UserID_X_2_1. Then, it will look up the digital identity root PhoneID_X associated with OneID_X_2. Finally, it will look up the trusted digital identity root RootID_X associated with PhoneID_X.
[0087] like Figure 3 As shown, in this invention, the trusted digital identity root is generated based on the online certificate platform information and the user's identity information; the digital identity root is generated based on the user's social attributes and biometrics; the platform-level digital identity account is generated based on the platform name, platform ID, and platform key; the organization-level digital identity is generated based on the organization name and organization ID; the company-level digital identity account is generated based on the company name, company ID, and company unified credit code; and the application-level digital identity account is generated based on the application name, application ID, and application type.
[0088] In a preferred embodiment, the method for generating a trusted digital identity root includes:
[0089] Collect user identity information;
[0090] The user's online ID is obtained by authenticating the user's identity information through the online ID platform.
[0091] Generate a first string based on the user's identity information and a random number;
[0092] The user's identity information in the first string is encrypted to generate a second string;
[0093] Use the second string as a trusted digital identity root;
[0094] Bind the trusted digital identity root to the network certificate identifier;
[0095] The user's identity information includes any one or more of the following: name, ID number, and document validity period.
[0096] The system collects user identity information, authenticates the user through the e-certificate platform based on this information, identifies the user on a specific e-certificate platform, and obtains a unique e-certificate identifier for that user. Simultaneously, the system generates a string based on the user's identity information and a random number. This string is then encrypted to remove the user's identity information, resulting in a new string that serves as the user's trusted digital identity root. After obtaining the user's e-certificate identifier and trusted digital identity root, the system binds the trusted digital identity root to the e-certificate identifier.
[0097] It should be noted that after the system obtains the user's network ID identifier, it performs irreversible feature extraction on the plaintext information to obtain plaintext feature information, and stores the plaintext feature information, the network ID identifier, and the correspondence between the plaintext feature information and the network ID identifier. After the trusted digital identity root is generated, the trusted digital identity root is saved and the user's plaintext identity information and the first string are completely deleted. Timely deletion of plaintext identity information, with the trusted digital identity serving as a substitute for plaintext identity information, reduces the risk of exposure of plaintext identity information.
[0098] User identity information is collected only when a user performs trusted digital identity authentication for the first time, i.e., when a trusted digital identity root is generated for the user for the first time. Subsequent times the user performs trusted digital identity authentication, irreversible feature extraction is performed on the user's submitted identity information to obtain plaintext feature information. The plaintext feature information is then used to check whether it and its corresponding online ID have already been stored. If so, trusted digital identity authentication will not be performed again; otherwise, it is considered a first-time trusted digital identity authentication and trusted digital identity authentication is performed for the user. This ensures that each user can only have one trusted digital identity root, improving the stability and reliability of the trusted digital identity root.
[0099] In a preferred embodiment, the method for generating a digital identity root includes:
[0100] Collect users' mobile phone numbers and biometric data;
[0101] The mobile phone number is processed by a feature extraction algorithm to generate a first feature;
[0102] The biometric features are extracted using a feature extraction algorithm to generate a second feature.
[0103] A digital identity root is generated based on the first feature and the second feature;
[0104] Associate the digital identity root with the trusted digital identity root;
[0105] The biometric features include any one or more of the following: facial image, iris, voiceprint, and fingerprint.
[0106] The system collects the user's mobile phone number and biometric features. It extracts features from the collected mobile phone number to obtain a first feature. At the same time, the system also extracts features from the collected biometric features to obtain a second feature. After obtaining the first feature and the second feature, the system generates a digital identity root based on the first feature and the second feature, and associates the digital identity root with the aforementioned trusted digital identity root.
[0107] In a preferred embodiment, the generation of the platform-level digital identity account includes:
[0108] Based on the platform name, platform key, and preset platform ID, a platform-level digital identity account is generated, and the platform-level digital identity account is associated with the digital identity root.
[0109] The generation of the organization-level digital identity account includes:
[0110] Based on the organization name and the preset organization ID, an organization-level digital identity account is generated, and the organization-level digital identity account is associated with the platform-level digital identity account;
[0111] The generation of the company-level digital identity account includes:
[0112] Based on the company name, the company's unified social credit code, and the preset company ID, a company-level digital identity account is generated, and the company-level digital identity account is associated with the organization-level digital identity account;
[0113] The generation of the application-level digital identity account includes:
[0114] Based on the application name, application type, and preset application ID, an application-level digital identity account is generated, and the application-level digital identity account is associated with the company-level digital identity account.
[0115] After generating a user's digital identity root, the system will sequentially generate platform-level digital identity accounts, organization-level digital identity accounts, company-level digital identity accounts, and application-level digital identity accounts for the user; and associate the digital identity accounts between adjacent levels with each other. Specifically, the system generates platform and digital identity accounts based on the platform name, platform key, preset platform ID, and a unique random number, and associates the generated platform-level digital identity account with the aforementioned digital identity root. After obtaining the platform-level digital identity account, the system generates an organization-level digital identity account based on the organization name, preset organization ID, and a unique random number, and associates the organization-level digital identity account with the aforementioned platform-level digital identity account. After obtaining the organization-level digital identity account, the system generates a company-level digital identity account based on the company name, company's unified social credit code, preset company ID, and a unique random number, and associates the company-level identity account with the aforementioned organization-level digital identity account. After obtaining the company-level digital identity account, the system generates an application-level digital identity account based on the application name, application type, preset application ID, and a unique random number, and associates the application-level digital identity account with the aforementioned company-level digital identity account.
[0116] Step S5: Determine whether the first trusted digital identity root and the second trusted digital identity root are consistent. If they are, use the second application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and generate an authentication result.
[0117] Step S6: If not, query the third application-level digital identity account of the first trusted digital identity root under the second application, use the third application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account under the second application, and generate an authentication result.
[0118] In a preferred embodiment, after generating the authentication result by using the second application-level digital identity account as the user's application-level digital identity account corresponding to the first application-level digital identity account in the second application, the method further includes:
[0119] The authentication result is returned to the second application, so that the second application can extract the business data corresponding to the second application-level digital identity in the second application based on the second application-level digital identity account and the business data acquisition request, and transmit the business data and the authentication result to the first application;
[0120] After generating the authentication result by using the third application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, the method further includes:
[0121] The authentication result and the third application-level digital identity are returned to the second application, so that the second application can extract the business data corresponding to the third application-level digital identity in the second application based on the third application-level digital identity account and the business data acquisition request, and transmit the business data and the authentication result to the first application.
[0122] After retrieving the first trusted digital identity root and the second trusted digital identity root using the first application-level digital identity account and the second application-level digital identity account, the system determines whether the first trusted digital identity root and the second trusted digital identity root are consistent. If they are consistent, it indicates that the first application-level digital identity account and the second application-level digital identity account belong to the same user, i.e., the user identity authentication is successful. The second application-level digital identity account is then used as the digital identity account of the user corresponding to the first application-level digital identity account in the second application, and an authentication result is generated. The system returns the authentication result to the second application. Upon receiving the authentication result, the second application, based on the second application-level digital identity account and the business data acquisition request from the first application, extracts the corresponding business data in the second application corresponding to the second application-level digital identity, and transmits the business data and the authentication result to the first application.
[0123] If the first trusted digital identity root is inconsistent with the second trusted digital identity root, it indicates that the first application-level digital identity account and the second application-level digital identity account do not belong to the same user, i.e., user authentication fails. In this case, the system will query the corresponding third application-level digital identity account under the second application based on the first trusted digital identity root, use the third application-level digital identity account as the user's application-level digital identity account under the second application, and generate an authentication result. The system returns the authentication result and the third application-level digital identity account to the second application. After receiving the authentication result and the third application-level digital identity account, the second application extracts the business data corresponding to the third application-level digital identity in the second application based on the third application-level digital identity account and the business data acquisition request from the first application, and transmits the business data and the authentication result to the first application.
[0124] For example, as described in the previous example, after the system queries RootID_A and RootID_X through OpenID_A_1_1_1_1 and OpenID_X_2_1_1_1, it determines whether RootID_A and RootID_X are consistent. If they are consistent, it means that RootID_X is RootID_A, and OpenID_X_2_1_1_1 is OpenID_A_2_1_1_1. Then, OpenID_A_1_1_1_1 and OpenID_X_2_1_1_1 (i.e., OpenID_A_2_1_1_1) belong to Zhang San, that is, the user identity authentication is successful. OpenID_X_2_1_1_1 (i.e., OpenID_A_2_1_1_1) is used as Zhang San's digital identity account under application F, and the authentication result is generated.
[0125] The system returns the authentication result to application F. After receiving the authentication result, application F extracts the corresponding business data in application F corresponding to OpenID_A_2_1_1_1 based on OpenID_A_2_1_1_1 and the business data acquisition request from application E, and transmits the business data and authentication result to application E.
[0126] If RootID_A is inconsistent with RootID_X, it indicates that OpenID_A_1_1_1_1 and OpenID_X_2_1_1_1 do not belong to the same user, meaning user authentication fails. In this case, the system will query the application-level digital identity account OpenID_A_2_1_1_1 under application F based on RootID_A, and use OpenID_A_2_1_1_1 as Zhang San's application-level digital identity account under application F, generating an authentication result. The system returns the authentication result and OpenID_A_2_1_1_1 to application F. After receiving the authentication result and OpenID_A_2_1_1_1, application F extracts the corresponding business data in application F based on OpenID_A_2_1_1_1 and the business data acquisition request from application E, and transmits the business data and the authentication result to application E.
[0127] This embodiment provides a user identity authentication method, which includes: generating and returning authentication credentials for an application requesting authentication, so that the application sends the authentication credentials and a business data acquisition request to another application; verifying the received authentication credentials; after successful verification, confirming through a trusted digital identity root whether the application-level digital identity account that sent the authentication credentials corresponds to the same person; if so, authenticating the application-level identity information and generating an authentication result; if not, finding the application-level identity information corresponding to the same person, authenticating the application-level identity information, and generating an authentication result. This embodiment reduces the risk of plaintext identity information leakage during the identity authentication process by binding the trusted digital identity root to the corresponding network certificate identifier of the network certificate platform and using the trusted digital identity root to replace the role of plaintext identity information in the prior art to realize identity authentication between the digital identity accounts of the same user in different applications.
[0128] Based on the above method embodiments, the present invention provides corresponding system embodiments:
[0129] Please refer to Figure 2 An authentication system for user identity provided in an embodiment of the present invention includes:
[0130] The request receiving module 100 is used to receive the authentication credential application request of the first application and the first digital identity account under the current first application;
[0131] The authentication credential processing module 200 is used to generate a first authentication credential based on the first application-level digital identity account, and return the first authentication credential to the first application, so that after receiving the first authentication credential, the first application sends the first authentication credential and the business data acquisition request to the second application.
[0132] The verification module 300 is used to receive the second authentication credential submitted by the second application and the second application-level digital identity account under the current second application, and to verify the second authentication credential.
[0133] The identity query module 400 is used to, after verification, find the preset first trusted digital identity root corresponding to the first application-level digital identity account based on the first application-level digital identity account; and find the preset second trusted digital identity root corresponding to the second application-level digital identity account based on the second application-level digital identity account; wherein, the first trusted digital identity root and the second trusted digital identity root are bound to the network certificate identifier corresponding to the network certificate platform;
[0134] The authentication module 500 is used to determine whether the first trusted digital identity root and the second trusted digital identity root are consistent. If they are, the second application-level digital identity account is used as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and an authentication result is generated. If not, the third application-level digital identity account of the first trusted digital identity root in the second application is queried, and the third application-level digital identity account is used as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and an authentication result is generated.
[0135] This embodiment provides a user identity authentication system, including: a request receiving module, an authentication credential processing module, a verification module, an identity query module, and an authentication module. This embodiment binds a trusted digital identity root to the corresponding online certificate identifier of the online certificate platform, and uses the trusted digital identity root to replace the role of plaintext identity information in existing technologies to achieve identity authentication between the same user's digital identity accounts in different applications, thereby reducing the risk of plaintext identity information being leaked during the identity authentication process.
[0136] It should be noted that the system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the system embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0137] Those skilled in the art will clearly understand that, for convenience and simplicity, the specific working process of the system described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0138] Based on the above method embodiments, the present invention provides corresponding storage medium embodiments:
[0139] Accordingly, embodiments of the present invention provide a storage medium, characterized in that the storage medium includes a stored computer program, wherein the computer program controls the device where the storage medium is located to execute the aforementioned user authentication method during runtime.
[0140] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0141] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A method for authenticating user identity, characterized in that, include: Receive the authentication credential request from the first application and the first application-level digital identity account under the current first application; Based on the first application-level digital identity account, a first authentication credential is generated and returned to the first application, so that after receiving the first authentication credential, the first application sends the first authentication credential and the business data acquisition request to the second application. Receive the second authentication credential submitted by the second application and the second application-level digital identity account under the current second application, and verify the second authentication credential to determine whether the first authentication credential and the second authentication credential are consistent; If yes, the verification passes; otherwise, the verification fails. After the verification is successful, the preset first trusted digital identity root corresponding to the first application-level digital identity account is found based on the first application-level digital identity account. The second application-level digital identity account is used to find the preset second trusted digital identity root corresponding to the second application-level digital identity account; wherein, the first trusted digital identity root and the second trusted digital identity root are bound to the network certificate identifier corresponding to the network certificate platform; Determine whether the first trusted digital identity root and the second trusted digital identity root are consistent. If they are, use the second application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and generate an authentication result. If not, query the third application-level digital identity account of the first trusted digital identity root under the second application, use the third application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account under the second application, and generate an authentication result; The process of finding the preset trusted digital identity root corresponding to the application-level digital identity account based on the application-level digital identity account includes: Find the company-level digital identity account associated with the application-level digital identity account based on the application-level digital identity account; Based on the company-level digital identity account, find the organization-level digital identity account associated with the company-level digital identity account; Based on the organization-level digital identity account, find the platform-level digital identity account associated with the organization-level digital identity account; Based on the platform-level digital identity account, find the root digital identity account associated with the platform-level digital identity account; Based on the digital identity account root, a trusted digital identity account root associated with the digital identity account root is found.
2. The user identity authentication method as described in claim 1, characterized in that, The verification of the second authentication credential includes: Determine whether the first authentication credential and the second authentication credential are consistent. If they are, the verification passes; otherwise, the verification fails.
3. The user identity authentication method as described in claim 1, characterized in that, After generating the authentication result by using the second application-level digital identity account as the user's application-level digital identity account corresponding to the first application-level digital identity account in the second application, the process further includes: The authentication result is returned to the second application, so that the second application can extract the business data corresponding to the second application-level digital identity in the second application based on the second application-level digital identity account and the business data acquisition request, and transmit the business data and the authentication result to the first application; After generating the authentication result by using the third application-level digital identity account as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, the method further includes: The authentication result and the third application-level digital identity account are returned to the second application, so that the second application can extract the business data corresponding to the third application-level digital identity in the second application based on the third application-level digital identity account and the business data acquisition request, and transmit the business data and the authentication result to the first application.
4. The user identity authentication method as described in claim 1, characterized in that, Methods for generating trusted digital identity roots include: Collect user identity information; The user's online ID is obtained by authenticating the user's identity information through the online ID platform. Generate a first string based on the user's identity information and a random number; The user's identity information in the first string is encrypted to generate a second string; Use the second string as a trusted digital identity root; Bind the trusted digital identity root to the network certificate identifier; The user's identity information includes any one or more of the following: name, ID number, and document validity period.
5. The user identity authentication method as described in claim 1, characterized in that, Methods for generating digital identity roots include: Collect users' mobile phone numbers and biometric data; The mobile phone number is processed by a feature extraction algorithm to generate a first feature; The biometric features are extracted using a feature extraction algorithm to generate a second feature. A digital identity root is generated based on the first feature and the second feature; Associate the digital identity root with the trusted digital identity root; The biometric features include any one or more of the following: facial image, iris, voiceprint, and fingerprint.
6. The user identity authentication method as described in claim 1, characterized in that, The generation of the platform-level digital identity account includes: Based on the platform name, platform key, and preset platform ID, a platform-level digital identity account is generated, and the platform-level digital identity account is associated with the digital identity root. The generation of the organization-level digital identity account includes: Based on the organization name and the preset organization ID, an organization-level digital identity account is generated, and the organization-level digital identity account is associated with the platform-level digital identity account; The generation of the company-level digital identity account includes: Based on the company name, the company's unified social credit code, and the preset company ID, a company-level digital identity account is generated, and the company-level digital identity account is associated with the organization-level digital identity account; The generation of the application-level digital identity account includes: Based on the application name, application type, and preset application ID, an application-level digital identity account is generated, and the application-level digital identity account is associated with the company-level digital identity account.
7. A user identity authentication system, characterized in that, include: The request receiving module is used to receive the authentication credential application request of the first application and the first digital identity account under the current first application; The authentication credential processing module is used to generate a first authentication credential based on the first application-level digital identity account, and return the first authentication credential to the first application, so that after receiving the first authentication credential, the first application sends the first authentication credential and the business data acquisition request to the second application. The verification module is used to receive the second authentication credential submitted by the second application and the second application-level digital identity account under the current second application, and to verify the second authentication credential. The identity query module is used to find the preset first trusted digital identity root corresponding to the first application-level digital identity account after the verification is passed. The second application-level digital identity account is used to find the preset second trusted digital identity root corresponding to the second application-level digital identity account; wherein, the first trusted digital identity root and the second trusted digital identity root are bound to the network certificate identifier corresponding to the network certificate platform; The authentication module is used to determine whether the first trusted digital identity root and the second trusted digital identity root are consistent. If they are, the second application-level digital identity account is used as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and an authentication result is generated. If not, the third application-level digital identity account of the first trusted digital identity root in the second application is queried, and the third application-level digital identity account is used as the application-level digital identity account of the user corresponding to the first application-level digital identity account in the second application, and an authentication result is generated. The process of finding the preset trusted digital identity root corresponding to the application-level digital identity account based on the application-level digital identity account includes: Find the company-level digital identity account associated with the application-level digital identity account based on the application-level digital identity account; Based on the company-level digital identity account, find the organization-level digital identity account associated with the company-level digital identity account; Based on the organization-level digital identity account, find the platform-level digital identity account associated with the organization-level digital identity account; Based on the platform-level digital identity account, find the root digital identity account associated with the platform-level digital identity account; Based on the digital identity account root, a trusted digital identity account root associated with the digital identity account root is found.
8. A storage medium, characterized in that, The storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device where the storage medium is located to perform the user authentication method as described in any one of claims 1 to 6.