Digital identity management method and device, computer equipment and storage medium
By using cryptographic algorithms and synergistic encryption algorithms in the digital identity management system to generate and verify public key addresses, the shortcomings of traditional systems in terms of scalability, interoperability and security are solved, and efficient, secure and flexible identity management is achieved.
Patent Information
- Application Number
- CN202510072528.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-13
Smart Images

Figure CN119989328A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of artificial intelligence technology, and in particular to a digital identity management method, apparatus, computer equipment and storage medium. Background Art
[0002] With the rapid development of information technology and the sharp increase in global data volume, digital identity management systems are facing unprecedented challenges. Traditional digital identity authentication and management frameworks have gradually exposed their shortcomings in scalability, interoperability, and security, making it difficult to meet the needs of modern society for efficient, secure, and flexible identity management. In order to meet these challenges, the Digital Omnipotent Identity and Open System Interconnect (DOIDOSI / DOSI) model came into being, hoping to become the representative of a new generation of digital identity management and authentication frameworks. The DOIDOSI model can solve the problems of fragmentation, poor interoperability, and insufficient security in traditional digital identity systems. By building a unified, open, and scalable identity management platform, DOIDOSI promotes seamless connection and collaboration between different systems, greatly improving the utilization efficiency and security of digital identity data. In addition, the elastic chain concept in the model provides an innovative solution for coping with large-scale dynamically changing environments, enabling digital identity systems to achieve flexible expansion and adaptability while ensuring high security.
[0003] The DOIDOSI model builds a multi-layered, modular architecture by integrating various existing identity management and authentication technologies. From the social subject layer to the block data layer, each layer carries specific functions and responsibilities, and together constitutes a complete digital identity ecosystem. Among them, the cryptographic support layer serves as a bridge between the upper-layer business applications and the lower-layer blockchain technology, and its security is directly related to the stable operation of the entire system. However, a single cryptographic algorithm can no longer meet the increasingly complex business scenarios and diverse security requirements, and it is urgent to explore new cryptographic integration methods to improve the security and flexibility of the system.
[0004] With the development of new technologies such as quantum computing, traditional cryptographic algorithms are at risk of being cracked. At the same time, different application scenarios have significantly different requirements for security, efficiency, compatibility, etc., which puts higher requirements on the cryptographic support layer. How to effectively integrate multiple advanced cryptographic technologies in the same system to achieve the unity of security and flexibility has become a key issue that needs to be solved urgently. Summary of the invention
[0005] The purpose of the embodiments of the present application is to propose a digital identity management method, apparatus, computer device and storage medium to solve the problem of how to effectively integrate multiple advanced cryptographic technologies within the same system to achieve the unity of security and flexibility.
[0006] In order to solve the above technical problems, the present application embodiment provides a digital identity management method, which adopts the following technical solutions:
[0007] Receiving a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registration user information and registration public key information;
[0008] Performing a registration public key generation operation on the registration public key information according to a cryptographic algorithm to obtain a registration public key;
[0009] Perform a first public key address generation operation on the registered public key according to the combined encryption algorithm to obtain a registered public key address;
[0010] Storing the registered public key address in a database corresponding to the registered user information;
[0011] Receiving a digital identity authentication request sent by a verification terminal, wherein the digital identity authentication request includes verification user information and verification public key information;
[0012] Perform a second public key address generation operation on the verification public key information according to the combined encryption algorithm to obtain a verification public key address;
[0013] Reading a database, and obtaining a registered public key address corresponding to the verified user information in the database;
[0014] Determine whether the verification public key address and the registration public key address are consistent;
[0015] If the verification public key address and the registration public key address are consistent, then confirming that the digital identity authentication request has been verified;
[0016] If the verification public key address and the registration public key address are inconsistent, it is confirmed that the digital identity authentication request verification fails.
[0017] Furthermore, the step of performing a first public key address generation operation on the registered public key according to the combined encryption algorithm to obtain the registered public key address specifically includes the following steps:
[0018] The registered public key is synthesized and calculated according to the synthesis function F to obtain the registered public key address Zy1, wherein the registered public key address Zy1 is expressed as:
[0019] Zy1=F(Yg1)
[0020] Wherein, F represents the synthesis function, and Yg1 represents the registered public key;
[0021]
[0022] Among them, F1=Ms, F2=Yg1.
[0023] Furthermore, the step of storing the registered public key address in a database corresponding to the registered user information specifically includes the following steps:
[0024] Perform comprehensive calculation operations on the obtained registered public key addresses to obtain a public key address table;
[0025] The public key address table is stored in a database corresponding to the registered user information.
[0026] Furthermore, the step of performing a comprehensive calculation operation on the obtained plurality of registered public key addresses to obtain a public key address table specifically includes the following steps:
[0027] A hash algorithm calculation operation is performed on the plurality of registered public key addresses according to the hash algorithm function H to obtain the public key address table Zy, wherein the public key address table Zy is expressed as:
[0028] Zy=H(Zy1,Zy2,...,Zy n )
[0029] Among them, H represents the hash algorithm function, Zy n Indicates the registered public key address of the nth input data.
[0030] Furthermore, after the step of storing the registered public key address in a database corresponding to the registered user information, the following steps are also included:
[0031] The disposal public key address in the database is updated regularly.
[0032] Furthermore, after the step of confirming that the digital identity authentication request is verified if the verification public key address and the registration public key address are consistent, the following steps are also included:
[0033] Obtaining the data to be encrypted sent by the verification terminal;
[0034] Performing an encryption operation on the data to be encrypted according to the corresponding cryptographic algorithm decomposed from the combined encryption algorithm to obtain encrypted data;
[0035] A data transmission operation is performed on the encrypted data.
[0036] In order to solve the above technical problems, the embodiment of the present application also provides a digital identity management device, which adopts the following technical solution:
[0037] A registration request receiving module, used to receive a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registration user information and registration public key information;
[0038] A registration public key generation module, used to perform a registration public key generation operation on the registration public key information according to a cryptographic algorithm to obtain a registration public key;
[0039] A first public key address generation module, used to perform a first public key address generation operation on the registered public key according to the Heli encryption algorithm to obtain a registered public key address;
[0040] A registered public key address storage module, used to store the registered public key address in a database corresponding to the registered user information;
[0041] A verification request acquisition module, used to receive a digital identity verification request sent by a verification terminal, wherein the digital identity verification request includes verification user information and verification public key information;
[0042] A second public key address generation module, used to perform a second public key address generation operation on the verification public key information according to the combined encryption algorithm to obtain a verification public key address;
[0043] A registration public key address acquisition module is used to read a database and obtain a registration public key address corresponding to the verification user information in the database;
[0044] A public key address verification module, used to determine whether the verification public key address and the registration public key address are consistent;
[0045] A first verification result module, configured to confirm that the digital identity authentication request has been verified if the verification public key address and the registration public key address are consistent;
[0046] The second verification result module is used to confirm that the digital identity verification request fails if the verification public key address and the registration public key address are inconsistent.
[0047] Furthermore, the first public key address generation module includes:
[0048] The synthesis calculation submodule is used to perform a synthesis calculation operation on the registered public key according to the synthesis function F to obtain the registered public key address Zy1, wherein the registered public key address Zy1 is expressed as:
[0049] Zy1=F(Yg1)
[0050] Wherein, F represents the synthesis function, and Yg1 represents the registered public key;
[0051]
[0052] Among them, F1=Ms, F2=Yg1.
[0053] In order to solve the above technical problems, the embodiment of the present application further provides a computer device, which adopts the following technical solution:
[0054] The method comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of the digital identity management method as described above when executing the computer-readable instructions.
[0055] In order to solve the above technical problems, the embodiment of the present application further provides a computer-readable storage medium, which adopts the following technical solution:
[0056] The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the digital identity management method described above are implemented.
[0057] The present application provides a digital identity management method, including: receiving a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registration user information and registration public key information; performing a registration public key generation operation on the registration public key information according to a cryptographic algorithm to obtain a registration public key; performing a first public key address generation operation on the registration public key according to a combined encryption algorithm to obtain a registration public key address; storing the registration public key address in a database corresponding to the registration user information; receiving a digital identity authentication request sent by a verification terminal, wherein the digital identity authentication request includes verification user information and verification public key information; performing a second public key address generation operation on the verification public key information according to a combined encryption algorithm to obtain a verification public key address; reading a database, and obtaining a registration public key address corresponding to the verification user information in the database; judging whether the verification public key address and the registration public key address are consistent; if the verification public key address and the registration public key address are consistent, confirming that the digital identity authentication request is verified; if the verification public key address and the registration public key address are inconsistent, confirming that the digital identity authentication request is verified. Compared with the prior art, the present application can effectively improve the security and reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] In order to more clearly illustrate the scheme in the present application, a brief introduction is given below to the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0059] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;
[0060] Figure 2 is a flowchart of the implementation of the digital identity management method provided in the embodiment of the present application;
[0061] Figure 3 It is a structural diagram of a digital identity management device provided in an embodiment of the present application;
[0062] Figure 4 It is a structural diagram of an embodiment of a computer device according to the present application. DETAILED DESCRIPTION
[0063] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by technicians in the technical field of the present application; the terms used in the specification of the application herein are only for the purpose of describing specific embodiments and are not intended to limit the present application; the terms "including" and "having" and any variations thereof in the specification and claims of the present application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of the present application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.
[0064] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0065] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.
[0066] like Figure 1As shown, the system architecture 100 may include a terminal device 101, a network 102 and a server 103. The terminal device 101 may be a laptop 1011, a tablet computer 1012 or a mobile phone 1013. The network 102 is used to provide a medium for a communication link between the terminal device 101 and the server 103. The network 102 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0067] The user can use the terminal device 101 to interact with the server 103 through the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0068] The terminal device 101 can be any electronic device with a display screen and supporting web browsing. In addition to the laptop computer 1011, tablet computer 1012 or mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV), a laptop computer, a desktop computer, etc.
[0069] The server 103 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal device 101 .
[0070] It should be noted that the digital identity management method provided in the embodiment of the present application is generally executed by a server / terminal device, and accordingly, the digital identity management device is generally set in the server / terminal device.
[0071] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.
[0072] Continue to refer Figure 2 , shows a flow chart of an embodiment of a digital identity management method according to the present application. The digital identity management method comprises: step S201, step S202, step S203, step S204, step S205, step S206, step S207, step S208, step S209 and step S210.
[0073] In step S201, a digital identity registration request sent by a registration terminal is received, wherein the digital identity registration request includes registration user information and registration public key information.
[0074] In the embodiment of the present application, the present application is applicable to the Digital Omnipotent Identity and Open System Interconnect (DOIDOSI / DOSI) reference model, wherein the DOIDOSI / DOSI model is a comprehensive digital identity management framework, and its hierarchical structure is divided into ten layers from bottom to top, and each layer serves a specific functional area, specifically including:
[0075] Social subject layer: Service (assistant, helper, avatar, clone) Social subject is the full function and role of the DOIDOSI model. The social subject layer is the model entrance based on the social subject, focusing on the registration, registration and management of various entities in the society (such as individuals, organizations, equipment, etc.), ensuring that each entity has a unique identifier, unified regularity and the relevance of rights and obligations in the digital world. Specifically, the DOIDOSI model hierarchy includes:
[0076] (1) Subject ownership layer: manages the resources and permissions owned by each subject, involving the ownership and control of identity data, and safeguarding data sovereignty;
[0077] (2) Humanized identification layer: Confirm humanized identification and identification for each subject to facilitate identification, memory, and use, thereby enhancing the user experience;
[0078] (3) Name format layer: defines the naming rules and format standards of identity tags to ensure the consistency and readability of identity tags;
[0079] (4) Business set stratification: modularize different business logic and services to facilitate flexible combination and reuse, and support diverse application scenarios;
[0080] (5) Cryptographic support layer: responsible for generating, storing and managing cryptographic algorithms and keys, generating, storing and managing public key address tables and cryptographic algorithm data interfaces, and is the core link to ensure data confirmation, transmission and storage security;
[0081] (6) Relationship set hierarchy: describes the relationship network between different subjects and supports the implementation of trust transfer and access control policies;
[0082] (7) Blockchain consensus layer: blockchain technology is used to achieve decentralized consensus on data, ensuring the immutability and transparency of identity data;
[0083] (8) Blockchain network layer: building blockchain network infrastructure to promote efficient data transmission and sharing;
[0084] (9) Block data layer: As the final data storage layer, it uses distributed ledger technology to record all identity-related transactions.
[0085] In step S202, a registration public key generation operation is performed on the registration public key information according to a cryptographic algorithm to obtain a registration public key.
[0086] In the embodiment of the present application, the registration public key generation operation is mainly implemented in conjunction with the public key infrastructure (PKI), which is a security framework implemented through public key cryptography and is used to manage and distribute encryption keys and digital certificates. Its core components include:
[0087] (1) Certification Authority (CA): responsible for issuing and managing digital certificates and acting as a trusted third party to ensure the authenticity of public keys;
[0088] (2) Registration Authority (RA): handles the initial authentication and information review of certificate applicants;
[0089] (3) Certificate repository: stores issued digital certificates and certificate revocation lists (CRLs) for public query and verification;
[0090] (4) Key backup and recovery system: used to back up the user's private key to prevent data from being decrypted after the key is lost;
[0091] (5) Certificate revocation processing system: manage expired, invalid or revoked certificates and notify relevant parties by publishing CRLs;
[0092] (6) Client application: user-side software that uses digital certificates for identity authentication and data encryption;
[0093] (7) Formulate relevant policies: stipulate the use specifications, security management and operation procedures of PKI;
[0094] (8) Application Programming Interface (API): A programming interface provided to programmers to integrate PKI functions into their applications.
[0095] In the embodiments of the present application, public key encryption is an asymmetric encryption technology that uses a pair of mathematically related public keys and private keys to perform encryption and decryption operations. Its basic principles are as follows:
[0096] (1) Public key encryption: The sender uses the receiver's public key to encrypt data, and the ciphertext can only be decrypted using the corresponding private key. Since the public key is public, anyone can use it to encrypt data, but only those with the corresponding private key can decrypt it.
[0097] (2) Private key decryption: The recipient uses their own private key to decrypt the received ciphertext and restore the plaintext content. The private key must be kept strictly confidential to prevent others from obtaining it.
[0098] In the embodiments of this application, the above mechanism ensures that even if the data is intercepted during transmission, it cannot be decrypted by unauthorized persons, thus ensuring the confidentiality and integrity of the data. Typical public key encryption algorithms include RSA, ECC, etc. These algorithms are based on complex mathematical problems (such as large number factorization, elliptic curve discrete logarithm problem) to ensure that it is almost impossible to crack under the existing computing power.
[0099] In the embodiments of this application, the public key encryption algorithm can be the RSA algorithm, the ECC (Elliptic Curve Cryptography) algorithm, etc. Specifically:
[0100] (1) RSA algorithm: The RSA (Rivest–Shamir–Adleman) algorithm is one of the widely used public key encryption algorithms at present, named after its inventors Ron Rivest, Adi Shamir, and Leonard Adleman. Its security is based on the difficulty of factoring large integers. The main features include:
[0101] Key generation: Select two large prime numbers p and q, and calculate their product n = p * q as the modulus; select an integer e that is relatively prime to (p - 1) * (q - 1) and 1 < e < (p - 1) * (q - 1), and calculate the modular inverse d of e modulo (p - 1) * (q - 1) as d = e^-1 mod (p - 1) * (q - 1); the public key is (e, n), and the private key is (d, n);
[0102] Encryption process: For a given plaintext message m, the ciphertext c is calculated as c ≡ m^e mod n;
[0103] Decryption process: For the ciphertext c, the plaintext m is restored as m ≡ c^d mod n.
[0104] (2) ECC (Elliptic Curve Cryptography) algorithm: ECC (Elliptic Curve Cryptography) is a public key encryption algorithm based on the mathematical theory of elliptic curves. Compared with the traditional RSA algorithm, ECC requires a shorter key length and higher computing efficiency under the same security level. The main features include:
[0105] Elliptic curve based on finite field: Define an elliptic curve equation y 2 mod p = (x 3 + ax + b) mod p on the finite field GF(p), and select appropriate parameters a and b to make the curve have specific properties;
[0106] Generate a key pair: select a base point G(x,G,y;G) and a private key k, and calculate the public key K=kG. The private key k is an integer, and the public key K is a point on the elliptic curve;
[0107] Encryption and decryption process: Encryption and decryption operations are implemented using point addition operations and scalar multiplication of elliptic curves.
[0108] In the embodiment of the present application, the security of ECC is derived from the difficulty of the elliptic curve discrete logarithm problem, that is, it is difficult to calculate the integer k given a base point G and its multiple K. This makes ECC have a wide range of application prospects in modern cryptography.
[0109] In step S203, a first public key address generation operation is performed on the registered public key according to the combined encryption algorithm to obtain a registered public key address.
[0110] In the embodiment of the present application, the core idea of the combined encryption algorithm is to realize data encryption and decryption through the combined action of multiple vectors. The algorithm draws on the synthetic function of forces in classical mechanics, combines multiple encryption factors (similar to the action force) according to certain rules to form a composite encryption effect. The combined encryption algorithm not only improves the encryption strength, but also enhances the system's anti-attack ability. Its main features include the combined action of multi-dimensional vectors and flexible parameter configuration, which makes it perform well in different application scenarios.
[0111] In the embodiment of the present application, the uniqueness of the Heli encryption algorithm is that it uses vector operations in high-dimensional space to implement encryption operations. Unlike traditional single-dimensional encryption methods, the Heli encryption algorithm constructs a difficult-to-crack encryption matrix through the combination of multiple independent vectors. These vectors are synthesized through specific mathematical formulas to ultimately form a complex encryption effect. During the decryption process, the corresponding private key needs to be used for reverse operations to extract the original data. This method not only improves the encryption strength, but also increases the difficulty of cracking, and is a very effective encryption method.
[0112] In the embodiment of the present application, in the Digital Universal Identity Name Reference Model (DOIDOSI / DOSI model), the Heli encryption algorithm can be effectively applied to the cryptographic support layer to enhance data security and system reliability. The specific implementation steps are as follows:
[0113] (1) Generate business public key: In the cryptographic support layer, first generate a unique business public key (Yg) for each business. The generation of business public key can be customized according to specific business requirements and security policies (using existing cryptographic algorithms);
[0114] (2) Calculate the business public key address: Use the calculation formula Zy1=F(Yg1) and Zy2=F(Yg2) in the combined encryption algorithm to convert the business public key into the business public key address. This process ensures that each business public key has a unique address identifier, which is easy to manage and find;
[0115] (3) Generate a public key address: Finally, the public key address (Zy) generated by the Heli encryption algorithm can not only be used for data encryption, but also serve as an important basis for identity verification. In actual operation, the authenticity of the user's identity can be verified by comparing the public key address with the pre-stored address value.
[0116] In step S204, the registered public key address is stored in a database corresponding to the registered user information.
[0117] In step S205, a digital identity authentication request sent by the authentication terminal is received, wherein the digital identity authentication request includes authentication user information and authentication public key information.
[0118] In step S206, a second public key address generation operation is performed on the verification public key information according to the combined encryption algorithm to obtain a verification public key address.
[0119] In step S207, the database is read, and the registered public key address corresponding to the verified user information is obtained in the database.
[0120] In step S208, it is determined whether the verification public key address and the registration public key address are consistent.
[0121] In step S209, if the verification public key address and the registration public key address are consistent, it is confirmed that the digital identity authentication request verification is successful.
[0122] In step S210, if the verification public key address and the registration public key address are inconsistent, it is confirmed that the digital identity authentication request verification fails.
[0123] In actual applications, user registration: users first need to register through a secure channel and provide basic personal information and public key information. The system generates the user's initial public key address (Zy) through the Heli encryption algorithm and stores it in the database; identity authentication: during identity authentication, the user submits his or her public key address (Zy), and the system verifies it through the Heli encryption algorithm. If the calculation result is consistent with the pre-stored address, the verification is passed; otherwise, access is denied.
[0124] In an embodiment of the present application, a digital identity management method is provided, including: receiving a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registered user information and registered public key information; performing a registered public key generation operation on the registered public key information according to a cryptographic algorithm to obtain a registered public key; performing a first public key address generation operation on the registered public key according to a combined encryption algorithm to obtain a registered public key address; storing the registered public key address in a database corresponding to the registered user information; receiving a digital identity authentication request sent by a verification terminal, wherein the digital identity authentication request includes verified user information and verified public key information; performing a second public key address generation operation on the verified public key information according to a combined encryption algorithm to obtain a verified public key address; reading a database, and obtaining a registered public key address corresponding to the verified user information in the database; judging whether the verified public key address and the registered public key address are consistent; if the verified public key address and the registered public key address are consistent, then confirming that the digital identity authentication request is verified; if the verified public key address and the registered public key address are inconsistent, then confirming that the digital identity authentication request is verified. Compared with the prior art, the present application can effectively improve the security and reliability of the system.
[0125] In some optional implementations of the embodiments of the present application, the above-mentioned step of performing a first public key address generation operation on the registered public key according to the combined encryption algorithm to obtain the registered public key address specifically includes the following steps:
[0126] The registered public key is synthesized and calculated according to the synthesis function F to obtain the registered public key address Zy1, where the registered public key address Zy1 is expressed as:
[0127] Zy1=F(Yg1)
[0128] Where, F represents the synthesis function, and Yg1 represents the registered public key;
[0129]
[0130] Among them, F1=Ms, F2=Yg1.
[0131] In the embodiment of the present application, in the combined encryption algorithm, Ms and Yg1, Yg2... are key variables, and the calculation formula is as follows.
[0132]
[0133] Among them, Zy1 = F (Yg1): represents the intermediate result after the business public key Yg1 is transformed by the function F. The F function is a composite function of force The purpose of this formula is to initially confuse and transform the initial public key to increase the difficulty of cracking.
[0134]
[0135] Among them, Zy2=F(Yg2): represents the intermediate result after the business public key Yg2 is transformed by function F.
[0136] In the embodiment of the present application, by transforming the properties of Yg1 and Yg2, the security and complexity of the final generated public key address can be greatly enhanced. This transformation mechanism means that even if an attacker can crack one of the links, he still needs to solve the complexity problems caused by other transformations.
[0137] In some optional implementations of the embodiments of the present application, the above step of storing the registered public key address in a database corresponding to the registered user information specifically includes the following steps:
[0138] Perform comprehensive calculation operations on the obtained registered public key addresses to obtain a public key address table;
[0139] The public key address table is stored in a database corresponding to the registered user information.
[0140] In some optional implementations of the embodiments of the present application, the step of performing a comprehensive calculation operation on the obtained multiple registered public key addresses to obtain a public key address table specifically includes the following steps:
[0141] According to the hash algorithm function H, a hash algorithm calculation operation is performed on a number of registered public key addresses to obtain a public key address table Zy, where the public key address table Zy is expressed as:
[0142] Zy=H(Zy1,Zy2,...,Zy n )
[0143] Where H represents the hash algorithm function, Zy n Indicates the registered public key address of the nth input data.
[0144] In the embodiment of the present application, the generation of the public key address is one of the core steps of the Heli encryption algorithm, and the specific process is as follows:
[0145] (1) Initial input: The system accepts two (or more) business public keys Yg1 and Yg2 as input. These two public keys are usually generated by a specific encryption algorithm and used in subsequent calculation and verification processes;
[0146] (2) Calculate Zy1: According to the formula Zy1 = F(Yg1), process the first business public key Yg1 to obtain the first public key address Zy1. The function F here is the force synthesis function;
[0147] (3) Calculate Zy2: Similarly, according to the formula Zy2 = F (Yg2), the second business public key Yg2 is processed to obtain the second public key address Zy2. This step also uses the same conversion function F to ensure that the two public key addresses are generated under the same standard;
[0148] (4) Generate the final public key address table: perform comprehensive calculations on the public key addresses Zy1 and Zy2 obtained in the above two steps to obtain the final public key address table Zy. Specifically, use the hash function H to process Zy1 and Zy2, that is, Zy = H (Zy1, Zy2);
[0149] (5) Output result: The system returns the generated public key address table Zy as the final result. This public key address table can be used for various subsequent operations, such as signature verification, encrypted communication, etc.
[0150] In the embodiment of the present application, through the above five steps, the combined encryption algorithm can effectively generate a secure and unique public key address table. This process ensures that each business public key (such as Yg1) can generate a unique and highly secure public key address (such as Zy1), providing a solid foundation for subsequent identity authentication and data encryption.
[0151] In some optional implementations of the embodiments of the present application, after the step of storing the registered public key address in a database corresponding to the registered user information, the following steps are also included:
[0152] Regularly update the disposal public key address in the database.
[0153] In the embodiment of the present application, in order to ensure the security and reliability of the public key address, a complete management and maintenance mechanism must be established, specifically:
[0154] (1) Centralized management: All generated public key addresses should be centrally stored in a secure key management system to ensure that only authorized personnel can access and use them. (A public key address table is established on the resolution node to store the public keys of all associated business types and relationship types. This table can be stored on the full resolution server or distributed on multiple associated nodes; when a new public key needs to be added, the public key is converted into a public key address by itself and added to the address table of the cryptographic support layer in the Digital Universal Identity Name Reference Model (DOIDOSI / DOSI model). The specific operation is to associate the new public key with the corresponding business type and relationship type, and add the associated public key to the public key address table; when a public key needs to be queried, it is searched in the public key address table according to the business type and relationship type. If the corresponding public key is found, it is returned; if not found, a null value is returned; when a public key needs to be updated or deleted, the corresponding operation is performed in the public key address table according to the business type and relationship type. The specific operation is to remove the original public key from the public key address table or replace it with a new public key. Through the above steps, the public key management of the cryptographic support layer in the Digital Universal Identity Name Reference Model (DOIDOSI / DOSI model) can be implemented.)
[0155] (2) Regular update: In order to deal with possible security risks and improve security, it is recommended to update the public key address regularly. The update process includes regenerating Zy1 and Zy2 and calculating the new public key address table Zy.
[0156] (3) Backup and recovery: Establish a complete backup mechanism to regularly back up all public key addresses and related information (such as backup nodes). At the same time, formulate a detailed disaster recovery plan to ensure that the system can be quickly restored to operation (such as safe nodes, mirrored full-resolution servers) in the event of an unexpected situation.
[0157] (4) Monitoring and Auditing: Implement real-time monitoring and regular auditing mechanisms to continuously monitor and record the use of all public key addresses. When abnormal situations are found, timely alarms will be issued and corresponding measures will be taken.
[0158] (5) Lifecycle management: Perform full lifecycle management on each public key address, including generation, use, update, and cancellation. Ensure that the management and operation of each stage are well documented and traceable.
[0159] In some optional implementations of the embodiments of the present application, after the step of confirming that the digital identity authentication request has been verified if the verification public key address and the registration public key address are consistent, the following steps are also included:
[0160] Obtaining the data to be encrypted sent by the verification terminal;
[0161] Perform encryption operation on the encrypted data according to the corresponding cryptographic algorithm decomposed from the combined encryption algorithm to obtain encrypted data;
[0162] Perform data transfer operations on encrypted data.
[0163] In the embodiment of the present application, when the user uses the system, all sensitive data is decomposed into the corresponding cryptographic algorithm through the combined encryption algorithm and encrypted and transmitted. After receiving the ciphertext, the receiver uses the corresponding private key to decrypt it to ensure the confidentiality and integrity of the data.
[0164] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, artificial intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.
[0165] AI basic technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, mechatronics, etc. AI software technologies mainly include computer vision technology, robotics technology, biometrics technology, speech processing technology, natural language processing technology, and machine learning / deep learning.
[0166] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through computer-readable instructions, and the computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0167] It should be understood that, although the steps in the flowchart of the accompanying drawings are displayed in sequence as indicated by the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a part of the sub-steps or stages of other steps.
[0168] Further references Figure 3 , as a response to the above Figure 2 The present application provides an embodiment of a digital identity management device, and the device embodiment is similar to Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.
[0169] like Figure 3 As shown, the digital identity management device 2000 of the embodiment of the present application includes:
[0170] The registration request receiving module 210 is used to receive a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registration user information and registration public key information;
[0171] A registration public key generation module 220, configured to perform a registration public key generation operation on the registration public key information according to a cryptographic algorithm to obtain a registration public key;
[0172] The first public key address generation module 2030 is used to perform a first public key address generation operation on the registered public key according to the Heli encryption algorithm to obtain the registered public key address;
[0173] A registered public key address storage module 2040, used to store the registered public key address in a database corresponding to the registered user information;
[0174] The verification request acquisition module 2050 is used to receive a digital identity verification request sent by a verification terminal, wherein the digital identity verification request includes verification user information and verification public key information;
[0175] The second public key address generation module 2060 is used to perform a second public key address generation operation on the verification public key information according to the Heli encryption algorithm to obtain a verification public key address;
[0176] The registration public key address acquisition module 2070 is used to read the database and obtain the registration public key address corresponding to the verification user information in the database;
[0177] The public key address verification module 2080 is used to determine whether the verification public key address is consistent with the registration public key address;
[0178] The first verification result module 2090 is used to confirm that the digital identity authentication request verification is successful if the verification public key address and the registration public key address are consistent;
[0179] The second verification result module 2010 is used to confirm that the digital identity verification request fails if the verification public key address and the registration public key address are inconsistent.
[0180] In an embodiment of the present application, a digital identity management device 2000 is provided, including: a registration request receiving module 2010, used to receive a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registration user information and registration public key information; a registration public key generation module 2020, used to perform a registration public key generation operation on the registration public key information according to a cryptographic algorithm to obtain a registration public key; a first public key address generation module 2030, used to perform a first public key address generation operation on the registration public key according to a combined encryption algorithm to obtain a registration public key address; a registration public key address storage module 2040, used to store the registration public key address in a database corresponding to the registration user information; a verification request acquisition module 2050, used to receive a digital identity authentication request sent by a verification terminal, wherein In the digital identity authentication request, the digital identity authentication request includes the authentication user information and the authentication public key information; the second public key address generation module 2060 is used to perform the second public key address generation operation on the authentication public key information according to the combined encryption algorithm to obtain the authentication public key address; the registration public key address acquisition module 2070 is used to read the database and obtain the registration public key address corresponding to the authentication user information in the database; the public key address verification module 2080 is used to determine whether the authentication public key address and the registration public key address are consistent; the first verification result module 2090 is used to confirm that the digital identity authentication request is authenticated if the authentication public key address and the registration public key address are consistent; the second verification result module 2010 is used to confirm that the digital identity authentication request is not authenticated if the authentication public key address and the registration public key address are inconsistent. Compared with the prior art, the present application can effectively improve the security and reliability of the system.
[0181] In some optional implementations of the embodiments of the present application, the first public key address generation module includes:
[0182] The synthesis calculation submodule is used to perform a synthesis calculation operation on the registered public key according to the synthesis function F to obtain the registered public key address Zy1, where the registered public key address Zy1 is expressed as:
[0183] Zy1=F(Yg1)
[0184] Where, F represents the synthesis function, and Yg1 represents the registered public key;
[0185]
[0186] Among them, F1=Ms, F2=Yg1.
[0187] To solve the above technical problems, the present application also provides a computer device. Figure 4 , Figure 4 This is a basic structural block diagram of a computer device according to an embodiment of the present application.
[0188] The computer device 300 includes a memory 310, a processor 320, and a network interface 330 that are interconnected and communicated through a system bus. It should be noted that the figure only shows a computer device 300 having components 310-330, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (Application Specific Integrated Circuit, ASIC), programmable gate arrays (Field-Programmable Gate Array, FPGA), digital processors (Digital Signal Processor, DSP), embedded devices, etc.
[0189] The computer device may be a computing device such as a desktop computer, a notebook, a PDA, a cloud server, etc. The computer device may interact with a user through a keyboard, a mouse, a remote controller, a touch pad, or a voice control device.
[0190] The memory 310 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (for example, SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 310 can be an internal storage unit of the computer device 300, such as a hard disk or memory of the computer device 300. In other embodiments, the memory 310 can also be an external storage device of the computer device 300, such as a plug-in hard disk equipped on the computer device 300, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card, etc. Of course, the memory 310 can also include both the internal storage unit of the computer device 300 and its external storage device. In the embodiment of the present application, the memory 310 is generally used to store the operating system and various application software installed on the computer device 300, such as computer-readable instructions of the digital identity management method, etc. In addition, the memory 310 can also be used to temporarily store various data that have been output or are to be output.
[0191] The processor 320 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip in some embodiments. The processor 320 is generally used to control the overall operation of the computer device 300. In the embodiment of the present application, the processor 320 is used to run the computer-readable instructions stored in the memory 310 or process data, such as computer-readable instructions for running the digital identity management method.
[0192] The network interface 330 may include a wireless network interface or a wired network interface. The network interface 330 is generally used to establish a communication connection between the computer device 300 and other electronic devices.
[0193] The computer device provided by this application can effectively improve the security and reliability of the system.
[0194] The present application also provides another implementation, namely, providing a computer-readable storage medium, wherein the computer-readable storage medium stores computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to perform the steps of the digital identity management method as described above.
[0195] The computer-readable storage medium provided in this application can effectively improve the security and reliability of the system.
[0196] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0197] Obviously, the embodiments described above are only some embodiments of the present application, rather than all embodiments. The preferred embodiments of the present application are given in the accompanying drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present application more thorough and comprehensive. Although the present application is described in detail with reference to the aforementioned embodiments, for those skilled in the art, it is still possible to modify the technical solutions recorded in the aforementioned specific implementation methods, or to perform equivalent replacement of some of the technical features therein. Any equivalent structure made using the contents of the specification and drawings of this application, directly or indirectly used in other related technical fields, is similarly within the scope of patent protection of this application.
Claims
1. A digital identity management method, characterized in that: The steps include: Receiving a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registration user information and registration public key information; Performing a registration public key generation operation on the registration public key information according to a cryptographic algorithm to obtain a registration public key; Perform a first public key address generation operation on the registered public key according to the combined encryption algorithm to obtain a registered public key address; Storing the registered public key address in a database corresponding to the registered user information; Receiving a digital identity authentication request sent by a verification terminal, wherein the digital identity authentication request includes verification user information and verification public key information; Perform a second public key address generation operation on the verification public key information according to the combined encryption algorithm to obtain a verification public key address; Reading a database, and obtaining a registered public key address corresponding to the verified user information in the database; Determine whether the verification public key address and the registration public key address are consistent; If the verification public key address and the registration public key address are consistent, then confirming that the digital identity authentication request has been verified; If the verification public key address and the registration public key address are inconsistent, it is confirmed that the digital identity authentication request verification fails.
2. The digital identity management method according to claim 1, characterized in that: The step of performing a first public key address generation operation on the registered public key according to the combined encryption algorithm to obtain the registered public key address specifically includes the following steps: The registered public key is synthesized and calculated according to the synthesis function F to obtain the registered public key address Zy1, wherein the registered public key address Zy1 is expressed as: Zy1=F(Yg1) Wherein, F represents the synthesis function, and Yg1 represents the registered public key; Among them, F1=Ms, F2=Yg1.
3. The digital identity management method according to claim 1, characterized in that: The step of storing the registered public key address in a database corresponding to the registered user information specifically comprises the following steps: Perform comprehensive calculation operations on the obtained registered public key addresses to obtain a public key address table; The public key address table is stored in a database corresponding to the registered user information.
4. The digital identity management method according to claim 3, characterized in that: The step of performing a comprehensive calculation operation on the obtained plurality of registered public key addresses to obtain a public key address table specifically includes the following steps: A hash algorithm calculation operation is performed on the plurality of registered public key addresses according to the hash algorithm function H to obtain the public key address table Zy, wherein the public key address table Zy is expressed as: Zy=H(Zy1,Zy2,...,Zy n ) Among them, H represents the hash algorithm function, Zy n Indicates the registered public key address of the nth input data.
5. The digital identity management method according to claim 1, characterized in that: After the step of storing the registered public key address in a database corresponding to the registered user information, the following steps are also included: The disposal public key address in the database is updated regularly.
6. The digital identity management method according to claim 1, characterized in that: After the step of confirming that the digital identity authentication request is verified if the verification public key address and the registration public key address are consistent, the following steps are also included: Obtaining the data to be encrypted sent by the verification terminal; Performing an encryption operation on the data to be encrypted according to the corresponding cryptographic algorithm decomposed from the combined encryption algorithm to obtain encrypted data; A data transmission operation is performed on the encrypted data.
7. A digital identity management device, characterized in that: include: A registration request receiving module, used to receive a digital identity registration request sent by a registration terminal, wherein the digital identity registration request includes registration user information and registration public key information; A registration public key generation module, used to perform a registration public key generation operation on the registration public key information according to a cryptographic algorithm to obtain a registration public key; A first public key address generation module, used to perform a first public key address generation operation on the registered public key according to the Heli encryption algorithm to obtain a registered public key address; A registered public key address storage module, used to store the registered public key address in a database corresponding to the registered user information; A verification request acquisition module, used to receive a digital identity verification request sent by a verification terminal, wherein the digital identity verification request includes verification user information and verification public key information; A second public key address generation module, used to perform a second public key address generation operation on the verification public key information according to the combined encryption algorithm to obtain a verification public key address; A registration public key address acquisition module is used to read a database and obtain a registration public key address corresponding to the verification user information in the database; A public key address verification module, used to determine whether the verification public key address and the registration public key address are consistent; A first verification result module, configured to confirm that the digital identity authentication request has been verified if the verification public key address and the registration public key address are consistent; The second verification result module is used to confirm that the digital identity verification request fails if the verification public key address and the registration public key address are inconsistent.
8. The digital identity management device according to claim 7, characterized in that: The first public key address generation module includes: The synthesis calculation submodule is used to perform a synthesis calculation operation on the registered public key according to the synthesis function F to obtain the registered public key address Zy1, wherein the registered public key address Zy1 is expressed as: Zy1=F(Yg1) Wherein, F represents the synthesis function, and Yg1 represents the registered public key; Among them, F1=Ms, F2=Yg1.
9. A computer device comprising a memory and a processor, characterized in that: The memory stores computer-readable instructions, and when the processor executes the computer-readable instructions, the steps of the digital identity management method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by a processor, the steps of the digital identity management method according to any one of claims 1 to 6 are implemented.