Digital identity label declaration generation method and device, medium and product
By proving identity ownership to an authoritative organization and using zero-knowledge proof technology to generate different types of identity statements, the problem of users requiring sensitive identity identification information when registering is solved, and privacy protection and application requirements are achieved.
Patent Information
- Application Number
- CN202510110150.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-23
AI Technical Summary
The prior art requires providing sensitive identity identification information when registering a user, which leads to a high risk of potential exposure of user privacy information and is difficult to meet the various needs of subsequent applications for user identity identification.
By proving identity ownership to an authoritative organization, obtaining proof of user identity identification, and using zero-knowledge proof technology to generate different types of identity statements, including unique identity identifiers, selective disclosure identity identification statements and full display identity identification statements, for users to choose to send to the verification party for identity verification.
Effectively protect user privacy, avoid users’ unintentional disclosure of personal sensitive identity information, reduce the potential exposure risk of privacy information, and meet the application’s various usage needs for user identity.
Smart Images

Figure CN120034363A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security, and in particular to a method, device, medium and product for generating a digital identity declaration. Background Art
[0002] With the continuous development of science and technology, human society has entered the information age, and networking, digitization, and intelligence have gradually penetrated into all areas of human life. As a result, the number of Internet applications has increased dramatically, and everyone must register various digital accounts in order to use various applications smoothly. However, when registering an account, existing applications often collect users' sensitive digital identity identifiers (such as mobile phone numbers, email addresses, ID numbers, etc.) to distinguish different users or verify the true identity of users, which undoubtedly leaks users' personal privacy.
[0003] As the public's awareness of privacy protection grows, how to generate privacy-protected digital identity statements has attracted more and more attention. In the implementation process, it is necessary to ensure the availability of the generated digital identity statement, that is, the statement can protect user privacy while meeting the various usage requirements of the current application for the digital identity.
[0004] In the field of single sign-on, for example, zkLogin supports users to use their online accounts as identity identifiers for verification. Based on the single sign-on protocol OpenID Connect (OIDC), it constructs a signature system through identity tokens issued by online account providers (such as Google, Facebook, etc.), allowing users to sign only by relying on their existing OpenID accounts without storing or managing signature public and private key pairs. In this way, users can avoid leaking the specific content of identity tokens when using them, and third-party applications can verify the authenticity of tokens through zero-knowledge proof technology, thereby proving the user's ownership of the OpenID account they claim. However, this solution does not convert identity identifiers such as email or single sign-on into declaration information that adapts to current application needs, and it is difficult to meet the various usage requirements of subsequent applications for user identity identifiers.
[0005] In addition, when registering an application account, users need to provide their sensitive identity information (such as email address, etc.) to the third-party application service provider. Then the user completes the account binding operation by checking the verification code or verification link so that the account can be restored later. This method undoubtedly leaks the user's sensitive information. And if the user binds the same sensitive identity information to multiple third-party application accounts, malicious attackers can use this identity information to link to all the user's application accounts on the Internet, increasing the potential risk of exposing the user's privacy information. Summary of the invention
[0006] The purpose of this application is to provide a method, device, medium and product for generating a digital identity declaration to solve the problem that users may inadvertently disclose personal sensitive identity information, resulting in a high risk of potential exposure of user privacy information.
[0007] To achieve the above objectives, this application provides the following solutions:
[0008] In a first aspect, the present application provides a method for generating a digital identity declaration, comprising:
[0009] The user is required to prove the ownership of the user identity to the authority, and the authority is required to issue a user identity certificate; the user identity is a digital identity that has passed the single sign-on protocol or TLS Oracle authentication process; the user identity certificate is a temporary identity token or TLS Oracle commitment containing a sensitive identity; the sensitive identity includes sensitive identity information that the user does not want to be disclosed;
[0010] Based on the user identity certificate, the user is asked to generate different types of identity statements; the identity statements include a unique identity identifier, a selective disclosure identity statement, and a full display identity statement;
[0011] According to the verification party's requirements, the user is allowed to independently select an identity statement and send it to the verification party for identity verification.
[0012] In a second aspect, the present application provides a computer device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the above-described methods for generating a digital identity declaration.
[0013] In a third aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described methods for generating a digital identity declaration.
[0014] In a fourth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, implements any of the above-mentioned methods for generating a digital identity declaration.
[0015] According to the specific embodiments provided in this application, this application discloses the following technical effects:
[0016] This application is based on the user identity certificate issued by an authoritative organization and adopts zero-knowledge proof technology to enable users to generate different types of identity statements, among which the unique identity identifier and the selective disclosure identity statement do not contain the user's complete user sensitive identity information, thereby ensuring that privacy data is not leaked; and in accordance with the requirements of the verification party, this application allows users to independently choose to send the identity statement to the verification party for identity authentication. The user actively chooses the identity statement for verification, which avoids the problem of users inadvertently revealing personal sensitive identity information and reduces the potential risk of exposure of user privacy information. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0018] Figure 1 A flow chart of the method for generating a digital identity statement provided in this application;
[0019] Figure 2 This is a JWT example diagram in the single sign-on authentication protocol provided for this application;
[0020] Figure 3 This is a diagram of the information interaction between the authority, verifier and user provided by this application. DETAILED DESCRIPTION
[0021] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0022] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0023] The present application embodiment provides a method for generating a digital identity statement, which is executed by a computer device, and can be executed by a computer device such as a terminal or a server alone, or can be executed by a terminal and a server together. In the present application embodiment, Figure 1 As shown, the method includes the following steps.
[0024] S1: The user is required to prove ownership of the user identity to an authority, and the authority is required to issue a user identity certificate; the user identity is a digital identity that has passed the single sign-on protocol or TLS Oracle authentication process; the user identity certificate is a temporary identity token or TLS Oracle commitment containing a sensitive identity; the sensitive identity includes sensitive identity information that the user does not want to be disclosed.
[0025] S2: Based on the user identity certificate, the user is asked to generate different types of identity statements; the identity statements include a unique identity identifier, a selective disclosure identity statement, and a full display identity statement.
[0026] S3: According to the verification party's requirements, the user is asked to independently select an identity statement and send it to the verification party for identity verification.
[0027] In an exemplary embodiment, Figure 2 As shown in FIG, the specific process of generating a corresponding statement through user identity certification can be divided into three stages: single sign-on interaction stage, statement generation stage and statement verification stage. S1 can be replaced by the following steps.
[0028] S11: When the user identity is a digital identity authenticated by a single sign-on protocol, the user is instructed to send a single sign-on request to the authority and provide account information required for this identity authentication; the account information includes a user name and a password.
[0029] S12: Based on the account information, the authority responds to the single sign-on request. If the account information is correct, the authority issues a temporary identity token to the user; the temporary identity token includes the user identifier, issuer identifier, issuance timestamp, expiration timestamp, digital signature and other information of the user under the authority; the other information includes sensitive identity identification information registered by the user in the authority.
[0030] Furthermore, the first stage: the single sign-on interaction stage. In this stage, the user needs to interact with the authority for the single sign-on process, and the authority completes the authentication of the user's identity. Specifically, the user sends a single sign-on request to the authority's server, the authority responds to the request and provides the specific information required for this identity authentication (such as user name, password, etc.), the user submits the information, and if the account information is correct, the authentication process is completed, and the authority issues a temporary identity token (Json Web Token, JWT) to the user.
[0031] JWT contains the user identifier (sub) of the user under the authority, the issuer identifier (iss), the issuance timestamp (iat), the expiration timestamp (exp), the digital signature (sig) and other information (others). Specifically, the above information can be expressed as:
[0032] JWT←{sub, iss, iat, exp, others, sig}
[0033] sig←Sign(H(sub,iss,iat,exp,others),sk TA )
[0034] In the above formula, Sign(·) represents the digital signature algorithm, Sk TA The signature private key owned by the authority (the corresponding public key is denoted as pk TA ). After the user obtains the JWT, he sends iss, iat, exp, and sig to the verifier for subsequent verification.
[0035] In an exemplary embodiment, the second stage: statement generation stage. The present application can generate three types of identity statements: unique identity identifier, selective disclosure and full identity statement. Users can make choices based on the corresponding requirements of the application.
[0036] Under normal circumstances, users should choose the first method to generate an identity identifier. In this case, no user's digital identity will be leaked, and the user can use the application normally through the generated unique identity identifier; if the application needs to verify some additional information, such as the organization to which the user belongs, the user needs to disclose some identity information (such as the email domain name), which is the second generation method; if the user needs to disclose complete user information during the use of the application (in order to display his or her contact information, communicate with others, etc.), then the third generation method is required.
[0037] S2 can be replaced by the following steps.
[0038] How to generate a unique identifier:
[0039] Based on the temporary identity token, use id=PRF salt (sub, iss) generates a user ID; id is the user ID; sub is the user identifier; iss is the issuer identifier; PRF k (·) represents a pseudo-random function with k as a parameter; salt is a determined salt value generated according to other account security options, and the other account security options include a security question.
[0040] Furthermore, to generate a unique identity identifier, the user can generate it in the following ways:
[0041] id=PRF salt (sub,iss)
[0042] In the above formula, PRF k (·) represents a pseudo-random function with k as a parameter, salt is a determined salt value generated based on other account security options (such as security questions, etc.), sub is the user's unique identifier on the authoritative system, which can be considered to remain unchanged during multiple single-point sign-on processes, and iss is the authoritative system identifier. The introduction of this item can facilitate applications to distinguish statements generated by different authoritative agencies. Then the user can generate the first zero-knowledge proof Π through zero-knowledge proof using the following formula 1 :
[0043] Π 1 ←NIZK{(sub, salt, others): Verify(sig, H(sub, iss, iat, exp, others), pk TA )∧id=PRF salt (sub, iss)}
[0044] Among them, NIZK(x 1 , x 2 , ...): statement(x 1 , x 2 , ...) represents a non-interactive zero-knowledge proof algorithm, (x 1 , x 2 , ...) is the secret value to be hidden, statement(x 1 , x 2 , ...) is a Boolean expression about secret value and public parameter. The zero-knowledge proof algorithm can be used without revealing the secret input (x 1 , x 2 , ...) to construct a statement about the specific value of 1 , x 2 , ...), the proof value Π is then verified by the verifier through the zero-knowledge proof verification algorithm. If the verification is successful, it means that statement(x 1 , x 2 , ...) is true. Verify(·) means using the public key pk of the authority TA The digital signature value sig is verified, and the verification is true if it passes, otherwise it is false. Here, the user proves to the verifier the validity of the temporary identity token he holds and the fact that the id is uniquely determined by (sub, iss) through zero-knowledge proof. Finally, the user sends the id, Π, generated in this step to the verifier.
[0045] Based on the temporary identity token, construct a first zero - knowledge proof using zero - knowledge proof; the unique identity identifier includes the user ID and the first zero - knowledge proof.
[0046] For the generation method of the selective disclosure identity identifier statement:
[0047] Based on the temporary identity token and the partial sensitive information items required by the verifier, let the user disclose part of the sensitive identity identifier to form a statement, and construct a second zero - knowledge proof for this statement; the selective disclosure identity identifier includes the statement and the second zero - knowledge proof.
[0048] Furthermore, for the selective disclosure identity identifier statement, the user discloses part of the sensitive identity identifier in others (such as age) according to the specific requirements of the application for sensitive information. These selectively disclosed sensitive identity identifiers are called statement θ. Subsequently, construct a second zero - knowledge proof Π 2 Give a proof of the authenticity of θ:
[0049] Π 2 ←NIZK{(sub, salt, others): Verify(sig, H(sub, iss, iat, exp, others), pk TA )
[0050] ∧θ ∈ others}
[0051] The above formula shows that the user proves the validity of the temporary identity token held by the user and the authenticity of statement θ to the verifier through zero - knowledge proof.
[0052] For the generation method of the fully disclosed identity identifier statement: Use the complete temporary identity token as the fully disclosed identity identifier statement.
[0053] Furthermore, for the fully disclosed identity identifier statement, the user can directly forward the complete JWT to the verifier.
[0054] In an exemplary embodiment, the third stage: statement verification stage. In this stage, the verifier first verifies the timeliness of the proof, that is, determines whether the current timestamp cur satisfies the inequality: isa < cur < exp. This verification can be used to avoid replay attacks. The following separately introduces the subsequent verification methods for the two types of statements:
[0055] S3 can be replaced by the following steps.
[0056] For the verification method of the unique identity identifier:
[0057] The verification algorithm of the zero-knowledge proof is executed according to the first public parameter to verify the first zero-knowledge proof; the first public parameter includes a user ID, a digital signature, an issuer identifier, an issuance timestamp, an expiration timestamp, and a public key corresponding to a signature private key owned by the authority.
[0058] Furthermore, for generating a unique identity identifier, the verifier generates a unique identity identifier based on the public parameters (id, sig, iss, iat, exp, pk TA ) executes the verification algorithm of zero-knowledge proof, and verifies the first zero-knowledge proof Π 1 To verify:
[0059] {0, 1}←NIZK.Verify{Π 1 ,(id,sig,iss,iat,exp,pk TA )}
[0060] Where, NIZK.Verify{Π 1 , P} represents the verification algorithm of zero-knowledge proof, Π 1 is the first zero-knowledge proof value to be verified, P represents the public parameter, the output of the algorithm is 0 or 1, if the output is 1, it means the verification is passed, at this time the verifier accepts the user's statement, and uses id as the unique identifier.
[0061] Verification method for selective disclosure of identity claims:
[0062] The verification algorithm of the zero-knowledge proof is executed according to the second public parameter to verify the second zero-knowledge proof; the second public parameter includes the user's statement, digital signature, issuer identifier issuance timestamp, expiration timestamp and the public key corresponding to the signature private key owned by the authority.
[0063] Furthermore, for the selective disclosure of identity claims, the verifier uses the public parameters (θ, sig, iss, iat, exp, pk TA ) executes the verification algorithm of the zero-knowledge proof, and verifies the second zero-knowledge proof Π 2 To verify:
[0064] {0, 1}←NIZK.Verify{Π 2 ,(θ,sig,iss,iat,exp,pk TA )}
[0065] If the output of the zero-knowledge proof verification algorithm is 1, the statement θ is considered legal and valid, and the verifier accepts the user's statement θ.
[0066] Verification method for full presentation of identity claim:
[0067] The complete presentation identity statement is verified using a digital signature verification algorithm.
[0068] Furthermore, for a fully displayed identity statement, the verifier only needs to verify the correctness of sig through a digital signature verification algorithm:
[0069] {0,1}←Verify(sig,H(sub,iss,iat,exp,others),pk TA )
[0070] If the signature is valid, the user indicates that the submitted JWT is legal and valid, and the user's statement is accepted.
[0071] In another exemplary embodiment, taking the email address identity as an example, the specific process of generating a statement through user identity certification is introduced. The process can be divided into three stages: TLS Oracle commitment acquisition, statement generation and statement verification.
[0072] Phase 1: TLS Oracle commitment acquisition phase, S1 can be replaced by the following steps.
[0073] S11: When the user identity is a digital identity that has passed the TLS Oracle authentication process, the user is required to negotiate and cooperate with the verification party, and the user and the verification party are established as a whole with the authority to establish a TLS Oracle connection.
[0074] S12: Based on the TLS Oracle connection, the user is required to perform authentication interaction with the authority to obtain a TLS Oracle commitment.
[0075] Furthermore, the user must first conduct a series of negotiations and cooperation with the authenticator, and as a whole establish a TLS Oracle connection with the authority's server (such as the mail provider's SMTP server). From the authority's perspective, TLS Oracle is no different from an ordinary TLS connection, so there is no need to make any modifications to the identity authentication program deployed on the server, and the other party of the connection is also regarded as an ordinary interacting party. However, from the user's perspective, the TLS Oracle connection is shared with the authenticator, which means that neither the user nor the authenticator can independently exchange data with the server on this connection. At the same time, in the TLS Oracle connection establishment mechanism, the authenticator can ensure that the other end of the current connection is an authority, not a fake server forged by a malicious user. After the connection is established, the user must perform authentication interaction according to the identity authentication process specified by the authority. If the authentication is successful, the user will obtain the TLS Oracle commitment cm:
[0076] cm←Commit(Q,pp)
[0077] In the above formula, Q is the authentication request containing sensitive identity identifiers (such as email addresses and login passwords), and pp is the public parameter during the execution of this TLS Oracle.
[0078] In an exemplary embodiment, the second stage is the statement generation stage. After the user obtains the TLS Oracle commitment, it is immediately sent to the verifier for subsequent verification. In this stage, the user needs to independently select a suitable generation method according to different needs to generate the identity statement, and after completion, the identity statement is sent to the verifier for subsequent verification.
[0079] S2 can be replaced by the following steps.
[0080] How the unique identifier is generated:
[0081] Using id=PRF salt (sub) Generate user ID; where id is user ID; sub is user identifier; PRF k (·) represents a pseudo-random function with k as a parameter; salt is a determined salt value generated according to other account security options, and the other account security options include security questions.
[0082] A third zero-knowledge proof of the user ID is constructed according to the sensitive identity identifier and the public parameters in the current TLS Oracle execution process; the unique identity identifier includes the user ID and the third zero-knowledge proof.
[0083] Furthermore, for a unique identifier, a user can generate one in the following ways:
[0084] id=PRF salt (sub)
[0085] In the above formula, PRF k (·) represents a pseudo-random function with k as a parameter, salt is a determined salt value generated based on other account security options (such as security questions, etc.), and sub is the user's unique identifier in the authority (such as a complete email address). The third zero-knowledge proof Π for id is constructed by the following formula 3 :
[0086]
[0087] ∧id=PRF salt (sub)}
[0088] In the above formula, Open(·) represents the opening process of the TLS Oracle commitment, which ensures that Q is the real identity content corresponding to the commitment cm and has not been tampered with; Match e (x, y) can be regarded as a matching function of the regular expression e, that is, judging whether the position of the string x in y satisfies the constraint relationship described by the regular expression e. Here, the regular expression e 1 It is to determine whether the position of the corresponding subject identifier in Q is sub.
[0089] How to generate a selective disclosure identity statement:
[0090] Based on some sensitive information items that the verifier needs to obtain, according to the sensitive identity identifier and the public parameters during the execution of this TLSOracle, a fourth zero-knowledge proof of the partial sensitive identity identifier is constructed; the selective disclosure identity identifier statement includes the partial sensitive identity identifier and the fourth zero-knowledge proof.
[0091] Furthermore, the user may disclose part of the sensitive identity identifier θ (such as the domain name part in the email address) according to specific application requirements, and create the fourth zero-knowledge proof Π for the part of the sensitive identity identifier θ through the following formula: 4 :
[0092]
[0093] In the formula, e 2 It is a regular expression determined by some sensitive information items that the verifier needs to obtain, and is used to match specific values in the identity identifier (for example, matching the content after "@" in an email address).
[0094] Regarding the generation method of the fully exposed identity statement: based on the regular expression matching the complete identity, according to the sensitive identity and the public parameters in the current TLS Oracle execution process, construct the fifth zero-knowledge proof of the digital identity statement; the fully exposed identity statement includes the complete sensitive identity and the fifth zero-knowledge proof.
[0095] Furthermore, if the user needs to fully reveal the identity, a similar generation method based on the selective disclosure of identity statement is used, where the regular expression is selected to match the complete identity. 1 , the matching object is the complete identity information θ, that is: Π 5 This is the fifth zero-knowledge proof.
[0096] In an exemplary embodiment, the third stage: claim verification stage S3 can be replaced by the following steps.
[0097] Based on the TLS Oracle commitment and the public parameters during the execution of this TLS Oracle, determine whether the authentication request sent by the user this time complies with the authentication protocol of the authority.
[0098] If yes, the received identity statement is verified according to the identity statement generation method selected by the user, based on the TLS Oracle commitment and the zero-knowledge proof verification method of the identity statement.
[0099] Furthermore, after receiving the identity statement (θ, Π) from the user, the verifier first determines whether the authentication request sent by the user complies with the authentication protocol of the authority based on the TLS Oracle commitment cm and the public parameter pp, and then executes the zero-knowledge proof verification algorithm based on cm, θ, Π and other public parameters to verify the correctness of the zero-knowledge proof Π:
[0100] {0,1}←NIZK.Verify{Π,(cm,pp,θ')},Π∈{Π 3 ,Π 4 ,Π 5}
[0101] If the verification algorithm of the zero-knowledge proof passes, the user's identity claim is accepted.
[0102] In response to various needs of existing applications, this application provides multiple declaration generation methods.
[0103] This application generates a privacy protection statement through the user identity certificate (digital signature or commitment) issued by an authoritative organization, which can meet the needs of third-party applications to verify user identity. This application mainly focuses on the needs of third-party applications for identity and the protection of user privacy. For example, when registering an application account, users are required to provide identity information as an account recovery factor, including email address, single sign-on identity, etc., while not disclosing the specific content of this information.
[0104] In a specific application scenario, the user's identity to be authenticated is certified by a relevant authority, which is derived from a digital signature issued by the authority that owns the attribute or a commitment generated through other privacy protection technologies. In the use environment of this application, the authority can be regarded as a trusted entity, that is, the user cannot tamper with the relevant data by colluding with internal personnel of the authority or breaking into the server of the authority. Therefore, the correctness and completeness of the statement generated by this application can be manifested as follows: (1) Malicious users cannot use tampered or forged identity certificates to generate statements that can be verified by the verification party; (2) Malicious users cannot generate false attribute values or statements that attributes do not exist in the identity certificate; (3) Malicious users cannot directly generate verifiable statements without the identity certificate issued by an authority.
[0105] The system corresponding to the digital identity statement generation method of the present application includes three parties: a trusted authority (TA), a verifier (Verifier) and a user (User), such as Figure 3 shown.
[0106] The authority shall issue an identity certificate upon the user's request. The certificate shall take the form of a digital signature of the identity or a commitment generated by converting network data through cryptographic methods.
[0107] The verifier is a third-party application or platform that needs to obtain user identity information to support its daily services. For example, some third-party applications need to obtain the user's email address to provide account recovery services, and need to collect the user's unique identity identifier to accurately deliver advertisements.
[0108] As the user of the application, the core demand of the user is to enjoy the services provided by the application without discrimination, under the premise of ensuring that personal privacy information is not leaked.
[0109] This application focuses on the privacy protection of sensitive information by users and the application's demand for key digital identity identification. It uses zero-knowledge proof technology to generate statements that can be used in third-party applications based on identity identification certificates issued by authoritative institutions. The main supported identities include authoritative platform single sign-on IDs and email addresses. Based on the specific needs that can be met, the generated digital identity identification statements can be roughly divided into the following three categories:
[0110] Unique identity identifier: A unique identity identifier is generated based on the identity certificate. The application can use this identity identifier as the user's legal ID within the application for unique identification, which can be used to verify user identity, recover accounts, etc.
[0111] Selective disclosure of identity: Displaying a portion of the identity can be used to prove the user's organizational affiliation (for example, disclosing the domain name of the email address can prove the user's organizational identity).
[0112] Full Identity Revealed: Under certain conditions, users can fully reveal their identity (such as their full email address) to the application in order to establish direct contact with other users.
[0113] In the statement generation system described in this application, the data input by the user is an identity certificate issued by an authoritative organization, and there are two ways to obtain the certificate, namely single sign-on and TLS Oracle.
[0114] The single sign-on method is applicable to scenarios where an authority has deployed a single sign-on protocol (such as OAuth), and the user needs to declare to a third-party application that he has a legal account under the authority. According to the single sign-on protocol specification, the user independently authenticates with the authority, and after passing, he can obtain a temporary network token (JSON Web Token, JWT) issued by the authority. JWT contains the account information owned by the user under the organization and the valid digital signature of the authority on the account information, and the digital signature can be regarded as a proof in the system described in this application.
[0115] The TLS Oracle method is applicable to scenarios where an authority provides an identity authentication service interface based on the TLS protocol. Specifically, the user and the verifier cooperate with each other to jointly maintain a TLS Oracle connection with the authority. The user sends the materials required for identity authentication in the TLS encrypted channel in accordance with the protocol requirements specified by the authority, and then the authority gives the corresponding authentication result. After that, the user generates a cryptographic commitment to the verifier for all encrypted data sent and received in this connection, which can also be regarded as a proof of the system described in this application.
[0116] After obtaining the identity certificate from the authority, the user sends the certificate to the verifier. The user then uses his or her identity as private input, and the verifier uses the certificate as input, along with other public parameters, to generate a digital identity statement that meets the application requirements through zero-knowledge proof technology.
[0117] With the rapid growth in the number of Internet applications, when users register for a new third-party application, they are frequently required to provide sensitive identity information for use by the application provider. In order to ensure that the user's sensitive privacy information is not leaked while meeting the application's demand for identity data as much as possible, the digital identity declaration generation method and system provided in this application can enable users to conveniently generate declarations that meet the reasonable requirements of the application based on the single sign-on authentication protocol or the TLS Oracle authentication protocol, thereby enhancing users' ability to independently control their own identity and promoting the healthy development of the Internet industry.
[0118] The advantages of this application are described in detail below:
[0119] 1. Privacy protection: This application uses cryptographic technology to protect the security of users' sensitive information. Users only need to generate corresponding statements by generating zero-knowledge proofs after obtaining the identity certificate from the authoritative server. In this process, there is no need to provide a complete identity to the third-party application service provider to meet the application's verification requirements for user identity, thereby protecting the user's privacy information. In particular, if the user uses a unique identity as a statement, when using different application platforms, different unique identity statements can be generated using the same digital identity (such as an email address) according to the process of this application, and these statements have no correlation, so malicious attackers cannot associate account data of multiple applications. Therefore, this application can effectively avoid the linkability between multiple application accounts, prevent malicious attackers from connecting multiple user account data through public identity identification, and further reduce the risk of data leakage to users throughout the Internet.
[0120] 2. Diverse forms: This application supports the generation of three different forms of digital identity declarations, which can meet the diverse needs of users and different applications. Under normal circumstances, the unique identity identifier declaration can meet the needs of most applications. The application can use the identity identifier declaration as the user's legal ID in the application for unique identification, to verify the user's identity, and provide account recovery and other functions. If the application needs to further verify the user's special identity (for example, to determine whether the user belongs to a certain organization), it can require the user to generate a selective disclosure identity declaration, and the user usually only needs part of the complete identity content to complete the identity proof. In particular, under certain conditions, users can choose to completely disclose their identity (such as a complete email address) to the application in order to establish direct contact with other users. The diversity of declaration forms ensures the strong usability of the digital identity declaration generated by this application, which can meet the multi-level and all-round usage needs between users and applications.
[0121] 3. Authenticity: This application uses a series of secure and mature cryptographic technologies to ensure the authenticity and integrity of the generated statements. Malicious users cannot use tampered or forged identity certificates to generate statements that can be verified by the verifier, nor can they generate statements with false attribute values or non-existent attributes in the identity certificate. In particular, if the identity certificate cannot be issued by an authoritative organization, malicious users cannot generate verifiable statements.
[0122] In an exemplary embodiment, a computer device is provided, which may be a server or a terminal. The computer device includes a processor, a memory, an input / output interface (I / O for short) and a communication interface. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface is connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store digital identity declaration generation data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a digital identity declaration generation method is implemented.
[0123] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the above method is implemented when the processor executes the computer program.
[0124] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, and the computer program implements the above method when executed by a processor.
[0125] In an exemplary embodiment, a computer program product is provided, including a computer program, which implements the above method when executed by a processor.
[0126] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ReadOnlyMemory, ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (Magnetoresistive RandomAccess Memory, MRAM), ferroelectric random access memory (Ferroelectric RandomAccess Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (RandomAccess Memory, RAM) or external cache memory, etc. By way of illustration and not limitation, RAM may be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0127] In this application, all actions to obtain signals, information or data are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.
[0128] The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. The non-relational database may include a distributed database based on blockchain, etc., but is not limited thereto. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but is not limited thereto.
[0129] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0130] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, according to the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.
Claims
1. A method for generating a digital identity statement, characterized in that: The digital identity statement generation method comprises: The user is required to prove the ownership of the user identity to the authority, and the authority is required to issue a user identity certificate; the user identity is a digital identity that has passed the single sign-on protocol or TLS Oracle authentication process; the user identity certificate is a temporary identity token or TLS Oracle commitment containing a sensitive identity; the sensitive identity includes sensitive identity information that the user does not want to be disclosed; Based on the user identity certificate, the user is asked to generate different types of identity statements; the identity statements include a unique identity identifier, a selective disclosure identity statement, and a full display identity statement; According to the verification party's requirements, the user is allowed to independently select an identity statement and send it to the verification party for identity verification.
2. The method for generating a digital identity statement according to claim 1, characterized in that: Require the user to prove ownership of the user's identity to the authority, and require the authority to issue a user identity certificate, including: When the user identity is a digital identity authenticated by a single sign-on protocol, the user is instructed to send a single sign-on request to the authority and provide account information required for this identity authentication; the account information includes a user name and a password; Based on the account information, the authority responds to the single sign-on request. If the account information is correct, the authority issues a temporary identity token to the user; the temporary identity token includes the user identifier, issuer identifier, issuance timestamp, expiration timestamp, digital signature and other information of the user under the authority; the other information includes sensitive identity identification information registered by the user in the authority.
3. The method for generating a digital identity statement according to claim 2, characterized in that: Based on the user identity certificate, the user is asked to generate different types of identity statements, including: a method for generating a unique identity identifier, a method for generating a selective disclosure identity statement, and a method for generating a selective disclosure identity statement; How to generate a unique identifier: Based on the temporary identity token, use id=PRF salt (sub, iss) generates a user ID; id is the user ID; sub is the user identifier; iss is the issuer identifier; PRF k (·) represents a pseudo-random function with k as a parameter; salt is a determined salt value generated according to other account security options, wherein the other account security options include a security question; Based on the temporary identity token, construct a first zero-knowledge proof using a zero-knowledge proof algorithm; the unique identity identifier includes the user ID and the first zero-knowledge proof; How to generate a selective disclosure identity statement: Based on the temporary identity token and some sensitive information items that the verifier needs to obtain, the user is asked to disclose some sensitive identity identifiers to form a statement, and a second zero-knowledge proof is constructed for the statement; the selective disclosure of identity identifiers includes the statement and the second zero-knowledge proof; For the generation method of the full presentation identity claim: the full temporary identity token is used as the full presentation identity claim.
4. The method for generating a digital identity statement according to claim 3, characterized in that: According to the verification party's requirements, the user is asked to select an identity statement and send it to the verification party for identity verification, including: Unique Identifier Verification Method: Execute a verification algorithm of the zero-knowledge proof according to the first public parameter to verify the first zero-knowledge proof; the first public parameter includes a user ID, a digital signature, an issuer identifier, an issuance timestamp, an expiration timestamp, and a public key corresponding to a signature private key owned by the authority; Verification method for selective disclosure of identity claims: Execute a verification algorithm of the zero-knowledge proof according to the second public parameter to verify the second zero-knowledge proof; the second public parameter includes a statement, a digital signature, an issuer identifier issuance timestamp, an expiration timestamp, and a public key corresponding to a signature private key owned by the authority in other information; Verification method for full presentation of identity claim: The complete presentation identity statement is verified using a digital signature verification algorithm.
5. The method for generating a digital identity statement according to claim 1, characterized in that: Require the user to prove ownership of the user's identity to the authority, and require the authority to issue a user identity certificate, including: When the user identity is a digital identity that has passed the TLS Oracle authentication process, the user is required to negotiate and cooperate with the verification party, and the user and the verification party are established as a whole with the authority. TLS Oracle connection; Based on the TLS Oracle connection, the user is required to perform authentication interaction with the authority, and after the authentication is passed, the user is required to obtain the TLS Oracle commitment.
6. The method for generating a digital identity statement according to claim 5, characterized in that: Based on the user identity certificate, the user is asked to generate different types of identity statements, including: a method for generating a unique identity identifier, a method for generating a selective disclosure identity statement, and a method for generating a selective disclosure identity statement; How the unique identifier is generated: Using id=PRF salt (sub) Generate user ID; where id is user ID; sub is user identifier; PRF k (·) represents a pseudo-random function with k as a parameter; salt is a determined salt value generated according to other account security options, wherein the other account security options include a security question; Constructing a third zero-knowledge proof of the user ID according to the sensitive identity identifier and the public parameters in the current TLS Oracle execution process; the unique identity identifier includes the user ID and the third zero-knowledge proof; How to generate a selective disclosure identity statement: Based on some sensitive information items that the verifier needs to obtain, according to the sensitive identity identifier and the public parameters in the current TLS Oracle execution process, construct a fourth zero-knowledge proof of the part of the sensitive identity identifier; the selective disclosure identity identifier statement includes the part of the sensitive identity identifier and the fourth zero-knowledge proof; How to generate a full display identity claim: Based on the complete sensitive information items that the verifier needs to obtain, according to the sensitive identity identifier and the public parameters during the execution of this TLS Oracle, a fifth zero-knowledge proof of the complete sensitive identity identifier is constructed; the full disclosure identity identifier statement includes the complete sensitive identity identifier and the fifth zero-knowledge proof.
7. The method for generating a digital identity statement according to claim 6, characterized in that: According to the verification party's requirements, the user is asked to select an identity statement and send it to the verification party for identity verification, including: Based on the TLS Oracle commitment and the public parameters during the execution of this TLS Oracle, determine whether the authentication request sent by the user this time complies with the authentication protocol of the authority; If yes, the received identity statement is verified according to the identity statement generation method selected by the user, based on the TLS Oracle commitment and the zero-knowledge proof verification method of the identity statement.
8. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method for generating a digital identity declaration according to any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for generating a digital identity declaration according to any one of claims 1 to 7 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for generating a digital identity declaration according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Service voucher issuing method, service voucher using method, server side, service point and vehicle
CN121037845A