User identity certificate processing method and device, identity authentication device and server

By generating symmetric identity credentials and transmitting them in anonymous channels, combining multi-link authentication and signatures, the problem of high complexity of the user identity credential system is solved, and efficient and secure user identity verification and simplified system deployment is achieved.

CN120263438APending Publication Date: 2025-07-04CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510069971.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, the user identity credential system is complex, and relying on multi-party coordination leads to increased computing load and communication overhead, difficulty in deployment and maintenance, and integration of advanced cryptography technology leads to high development and high resource consumption, which affects business development.

Method used

By generating symmetric identity credentials and transmitting them in anonymous channels, combining multi-link verification and signatures, we reduce the dependence on multi-party coordination, adopt simple cryptography technology, select appropriate encryption algorithms and transmission channels, and monitor the transmission process to ensure security and efficiency.

Benefits of technology

It improves the security and efficiency of user authentication, reduces computing load and communication overhead, simplifies system deployment and maintenance, meets different network environments and security needs, and provides personalized access to services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263438A_ABST
    Figure CN120263438A_ABST
Patent Text Reader

Abstract

The invention relates to the field of information security, in particular to a user identity certificate processing method and device, an identity authentication device and a server. According to the invention, a safe and reliable service acquisition mode is provided for the target user, and the accuracy and security of service provision are enhanced through multi-link verification and signature. Particularly, symmetric identity credentials are transmitted through anonymous channels, so that the dependence on coordination of multiple parties is reduced, and the calculation load and the communication overhead are reduced. The anonymous channel does not need complex multi-party interaction and is only transmitted under a specific framework, so that the transmission efficiency is improved. And secondly, multiple advanced cryptography technologies are not excessively integrated. In the generation, verification and signature processes of the symmetric identity credential, a relatively simple method is adopted, and the development realization difficulty is reduced. Therefore, resource consumption is reduced, the system is easier to deploy and maintain, and the problems that deployment and maintenance are difficult due to high complexity of the system and service development is affected by high resource consumption are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and particularly to a method for processing user identity credentials, a device, an identity authentication device, and a server. Background Art

[0002] In the information age, identity credentials, as an important infrastructure for digital life, are crucial for ensuring the authenticity and legality of network user identities. Although traditional identity credential schemes such as password authentication are convenient, they directly expose user identity information, posing serious security risks and easily leading to the leakage of users' personal information during the authentication process. Especially with the frequent occurrence of data leakage incidents nowadays, users' demand for privacy protection is becoming increasingly urgent.

[0003] Based on this, some existing solutions use an anonymous credential mechanism to achieve anonymous authentication of vehicle users, review and restore the identities of users with illegal behaviors, etc., and can also prevent Sybil attacks. However, the system complexity is high, relying on multi-party coordination work, increasing the computational load and communication overhead, and the deployment and maintenance are difficult; some solutions, although improving the security and privacy protection capabilities, lead to high system complexity, high development and implementation difficulty, and high resource consumption, affecting the business development due to the integration of multiple advanced cryptographic technologies. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method for processing user identity credentials, a device, an identity authentication device, and a server to solve problems such as increased computational load and communication overhead caused by relying on multi-party coordination due to high system complexity, difficulty in deployment and maintenance, and high development and implementation difficulty and affecting business development due to the integration of multiple advanced cryptographic technologies.

[0005] In a first aspect, an embodiment of the present invention provides a method for processing user identity credentials, the method including:

[0006] Obtain an initial identity credential currently received by a target client, where the target client is a client used by a target user who currently requests to provide a service, and the initial identity credential is generated by an issuer device according to user identity attributes of the target user;

[0007] Generate a symmetric identity credential based on the initial identity credential, and send the symmetric identity credential to the issuer device through an anonymous channel, where the issuer device is used to verify the symmetric identity credential and sign the symmetric identity credential after verification;

[0008] Receive the symmetric identity credential with a signature fed back by the issuer device;

[0009] Send the symmetric identity credential carrying the signature to the verifier device, so that the verifier device verifies the signature and the symmetric identity credential, and when the signature and the symmetric identity credential pass the verification, feedback a verification identifier to the target client, where the verification identifier is used to request the server to provide services for the target client.

[0010] Further, the obtaining the initial identity credential currently received by the target client includes:

[0011] Obtain the user identity attribute of the target client, and generate a certificate request based on the user identity attribute;

[0012] Send the certificate request to the issuer device, where the issuer device is used to verify the user identity attribute carried in the certificate request, and if the user identity attribute passes the verification, feedback the initial identity credential to the target client;

[0013] Receive the initial identity credential fed back by the issuer device, where the initial identity credential is generated by the issuer device based on a pre-generated private key and system parameters, and the private key is the private key in the public-private key pair pre-generated by the issuer device.

[0014] Further, the sending the certificate request to the issuer device includes:

[0015] Detect the current metric data of the key metrics of the secure transmission channel between the target client and the issuer device;

[0016] Analyze the network status of the secure transmission channel by using the current metric data of the key metrics;

[0017] If the network status of the secure transmission channel is an available state, send the certificate request through the secure transmission channel; or, if the network status of the secure transmission channel is an unavailable state, obtain the encryption method corresponding to the target user, and encrypt the certificate request by using the encryption method, and send the encrypted certificate request to the issuer device.

[0018] Further, the obtaining the encryption method corresponding to the target user includes:

[0019] Obtain the security configuration file corresponding to the target user, where the security configuration file includes the security requirements corresponding to the target user in different service scenarios;

[0020] Obtain the service information of the service currently requested by the target user, and obtain the target service scenario hit by the service information;

[0021] Obtain the target security requirements corresponding to the target business scenario from the security profile;

[0022] Obtain the target encryption algorithm corresponding to the target security requirements from the encryption algorithm library, and use the target encryption algorithm as the encryption method for the target user.

[0023] Further, sending the symmetric identity credential with signature to the verifier device includes:

[0024] Detect the network environment where the target client is currently located and the corresponding network security protection measures for the network environment;

[0025] Select a corresponding target transmission channel according to the network environment and the network security protection measures;

[0026] Send the symmetric identity credential with signature to the verifier device through the target transmission channel.

[0027] Further, sending the symmetric identity credential with signature to the verifier device through the target transmission channel includes:

[0028] Obtain the corresponding monitoring strategy according to the channel type corresponding to the target transmission channel;

[0029] Monitor whether there are any abnormal situations during the process of the target transmission channel transmitting the symmetric identity credential with signature according to the monitoring strategy;

[0030] If there are no abnormal situations, it is determined that the symmetric identity credential with signature has been successfully sent to the verifier device.

[0031] Further, monitoring whether there are any abnormal situations during the process of the target transmission channel transmitting the symmetric identity credential with signature according to the monitoring strategy includes:

[0032] If the target transmission channel is an encrypted security channel, detect the running state of the channel encryption algorithm in the encrypted security signal, and detect whether there is any abnormal use of the encryption key;

[0033] Obtain the check value synchronously generated during the process of sending the symmetric identity credential with signature, and compare the check value with the check information fed back by the receiving end;

[0034] If the running state of the channel encryption algorithm is in an error state, and / or there is any abnormal use of the encryption key, it is determined that there are abnormal situations; or, if the running state of the channel encryption algorithm is in a correct state, and / or the encryption key is used normally, it is determined that there are no abnormal situations.

[0035] Further, when monitoring whether there is an abnormal situation in the process of transmitting the symmetric identity credential carrying the signature through the target transmission channel according to the monitoring strategy, it includes:

[0036] If the target transmission channel is an anonymous transmission channel, detect the jump path of the symmetric identity credential carrying the signature in the anonymous transmission channel to obtain the activity status of each node in the jump path;

[0037] Analyze whether there is a target node with abnormal activity among the activity statuses of each node in the jump path;

[0038] If there is a target node with abnormal activity, it is determined that there is an abnormal situation; or, if there is no target node with abnormal activity, it is determined that there is no abnormal situation.

[0039] Further, the method further includes:

[0040] If there is an abnormal situation, obtain the abnormal cause that leads to the abnormal situation;

[0041] Obtain an alternative transmission scheme by using the channel type and the abnormal cause;

[0042] Transmit the symmetric identity credential carrying the signature to the verifier device according to the alternative transmission scheme.

[0043] In a second aspect, an embodiment of the present invention provides a processing device for user identity credentials, and the device includes:

[0044] An acquisition module, configured to acquire an initial identity credential currently received by a target client, where the target client is a client used by a target user who currently requests to provide services, and the initial identity credential is generated by an issuer device according to the user identity attribute of the target user;

[0045] A generation module, configured to generate a symmetric identity credential based on the initial identity credential, and send the symmetric identity credential to the issuer device through an anonymous channel, where the issuer device is configured to verify the symmetric identity credential and sign the symmetric identity credential after the verification passes;

[0046] A receiving module, configured to receive the symmetric identity credential carrying the signature fed back by the issuer device;

[0047] A sending module, configured to send the symmetric identity credential carrying the signature to a verifier device, so that the verifier device verifies the signature and the symmetric identity credential, and in the case where the signature and the symmetric identity credential are verified to pass, feedback a verification identifier to the target client, and the verification identifier is used to request the server to provide services for the target client.

[0048] In a third aspect, an embodiment of the present invention provides an identity authentication device, which includes an issuer device and a verifier device;

[0049] The issuer device is configured to receive a symmetric identity credential sent by a target client via an anonymous channel; verify the symmetric identity credential, and sign the symmetric identity credential when the symmetric identity credential passes the verification; send the symmetric identity credential with the signature to the target client, so that the target client sends the symmetric identity credential with the signature to the verifier device, where the target client is the client used by the target user who currently requests to provide a service, the symmetric identity credential is generated according to the initial identity credential of the target user, and the initial identity credential is generated according to the user identity attribute of the target user;

[0050] The verifier device is configured to receive the symmetric identity credential with the signature sent by the target client, and verify the signature and the symmetric identity credential; when the signature and the symmetric identity credential pass the verification, feedback a verification identifier to the target client, so that the target client requests the server to provide a service according to the verification identifier.

[0051] In a fourth aspect, an embodiment of the present invention provides a server, which is configured to receive a service request sent by a target client, where the service request includes a service requirement and a verification identifier, the target client is the client used by the target user who currently requests to provide a service, the verification identifier is sent after the symmetric identity credential with the signature passes the verification, the symmetric identity credential is generated according to the initial identity credential of the target user, and the initial identity credential is generated according to the user identity attribute of the target user; call service resources based on the verification identifier, obtain a target resource corresponding to the service requirement from the service resources, and feedback the target resource to the target client.

[0052] In a fifth aspect, an embodiment of the present invention provides a computer device, which includes a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the method according to the first aspect or any corresponding embodiment thereof.

[0053] In a sixth aspect, an embodiment of the present invention provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the method according to the first aspect or any corresponding embodiment thereof.

[0054] The method provided by the embodiment of the present application provides a secure and reliable service acquisition method for target users, ensures the authenticity and legality of user identities, and enhances the accuracy and security of service provision through multi-link verification and signature. Specifically, symmetric identity credentials are transmitted through an anonymous channel, reducing the dependence on multi-party coordination and lowering the computational load and communication overhead. The anonymous channel does not require complex multi-party interactions and is only transmitted under a specific architecture, improving the transmission efficiency. Secondly, the application of cryptographic technologies in this application is relatively appropriate, without over-integrating a variety of advanced cryptographic technologies. In the process of generating, verifying, and signing symmetric identity credentials, relatively simple methods are adopted, reducing the difficulty of development and implementation. Thereby reducing resource consumption, making the system easier to deploy and maintain, and solving the problems of difficult deployment and maintenance caused by high system complexity and high resource consumption affecting business operations.

[0055] The method provided by the embodiment of the present application first generates a certificate request by obtaining the user identity attributes of the target client and sends it to the issuer device, ensuring that only legitimate users can obtain the initial identity credentials, providing strong guarantee for the authenticity and legality of user identities. During the transmission of the certificate request, key indicators of the secure transmission channel can be detected to analyze the network status, and the transmission method can be flexibly selected. If the channel is available, it is directly sent; if not, the encryption method is determined according to the security profile of the target user and the certificate request is encrypted and sent. This fully considers different network conditions and user security requirements, improving the security and stability of transmission. At the same time, the security profile corresponding to the target user is obtained, and the target security requirements are determined according to its security requirements in different business scenarios and the information of the currently requested service. Then, a suitable target encryption algorithm is selected from the encryption algorithm library as the encryption method, realizing personalized security protection, meeting the specific security requirements of different users in different business scenarios, improving the security of the system, enhancing the user experience, and providing a more reliable, efficient, and personalized service acquisition approach for users.

[0056] The method provided by the embodiment of the present application first detects the network environment of the target client and the corresponding network security protection measures, and can select the most suitable target transmission channel according to the actual situation, improving the pertinence and efficiency of transmission. By obtaining the corresponding monitoring strategy according to the channel type, the transmission process of the symmetric identity credentials with signature is strictly monitored. In the scenario of an encrypted secure channel, the running status of the channel encryption algorithm and the usage of the encryption key are detected, and the verification value is compared to ensure the confidentiality, integrity, and stability of data transmission. If there is no abnormal situation, it is determined that the credentials are successfully sent to the verifier device. This method provides multiple guarantees for data transmission, reducing the risk of data being stolen, tampered with, or transmission failure, and at the same time adapting to different network environments and security requirements, improving the reliability and security of the system, and providing an efficient, stable, and secure solution for the transmission and verification of user identity credentials. Brief Description of the Drawings

[0057] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0058] Figure 1 is a schematic flowchart of a method for processing user identity credentials according to some embodiments of the present invention;

[0059] Figure 2 is a schematic diagram of the relationship among the user - issuer - verifier according to some embodiments of the present invention;

[0060] Figure 3 is a timing diagram of a method for processing user identity credentials according to some embodiments of the present invention;

[0061] Figure 4 is a schematic diagram of an identity authentication device according to some embodiments of the present invention;

[0062] Figure 5 is a structural block diagram of a processing device for user identity credentials according to an embodiment of the present invention;

[0063] Figure 6 is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Specific Embodiments

[0064] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0065] According to an embodiment of the present invention, there are provided a method, a device, an identity authentication device, and a server for processing user identity credentials. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer - executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0066] In this embodiment, a method for processing user identity credentials is provided, Figure 1It is a flowchart of a method for processing user identity credentials according to an embodiment of the present invention. As Figure 1 shown, the process includes the following steps:

[0067] Step S101, obtain the initial identity credential currently received by the target client, where the target client is the client used by the target user who currently requests to provide services, and the initial identity credential is generated by the issuer device according to the user identity attributes of the target user.

[0068] In an embodiment of the present application, as Figure 2 shown, the main bodies involved in the processing of user identity credentials in the present application include: the target client (the client used by the target user to request to provide services), the issuer device, and the verifier device. The target client sends its own identity attributes to the issuer through a secure channel and requests the corresponding certificate. The issuer device generates an initial identity credential according to the user's identity attributes. If the verification of the user identity attributes passes, the initial identity credential will be fed back to the target client. After receiving the initial identity credential, the target client will generate a symmetric identity credential based on this and send the symmetric identity credential back to the issuer through an anonymous channel. The issuer device verifies the symmetric identity credential. After the verification passes, it signs the symmetric identity credential and feeds back the symmetric identity credential with the signature to the target client. The target client then has to send the symmetric identity credential with the signature to the verifier device, and the verifier device verifies the signature and the symmetric identity credential. If the verification passes, the verifier device will provide services to the user.

[0069] The issuer device plays the roles of the generator and the verifier device of the identity credential throughout the process, ensuring the legality and authenticity of the user identity. The user obtains the required services through the interaction between the target client and the issuer device and the verifier device. The verifier device determines whether the user is entitled to obtain services based on the symmetric identity credential signed by the issuer device, playing a key role in service authorization. The entire process ensures the security of the user identity and the correct provision of services through different channels and interaction links.

[0070] In an embodiment of the present application, obtaining the initial identity credential currently received by the target client includes the following steps A1 - A3:

[0071] Step A1, obtain the user identity attributes of the target client and generate a certificate request based on the user identity attributes.

[0072] Specifically, in the target client, relevant data is collected from local storage (such as a secure storage area on the client device, which can be a specific encrypted folder or database) or information input by the user to obtain the identity attributes of the target user. The identity attributes cover a variety of information, such as the user's basic personal information (name, date of birth, contact information, etc.), registered account information in a specific system (username, password, etc. Although the password is generally not directly used as an identity attribute for transmission, it is used for local verification and other links), information about the organization or group to which the user belongs (if the relevant system involves an organizational structure, etc.), and some specific identification information related to the business (such as membership level, permission level, etc.). For some clients based on hardware devices, identity attributes related to the device are also collected, such as the unique identifier of the device (such as IMEI code, MAC address, etc.). These device information can be used as auxiliary identity attributes to further confirm whether the source of the device for user operations is legal and compliant.

[0073] After obtaining the complete user identity attributes, the target client will start the certificate request generation program. This program will first sort out and format the collected user identity attributes to ensure that all information meets the transmission format requirements specified by the system. For example, converting different types of data into specific data structures, such as JSON format or XML format, etc., for easy transmission and processing in the network.

[0074] Next, based on the sorted user identity attributes, some necessary request header information and metadata are added. The request header information includes the type of the request (clearly a certificate request here), the version number of the request (used to ensure that the issuing device can correctly identify and process the request), the identification information of the target client (such as the version number of the client software, device model, etc., so that the issuing device can understand the source of the request), etc. The metadata involves the timestamp of the request (recording the exact time when the request is generated, used for subsequent verification of the timeliness of the request, etc.), the serial number of the request (used to uniquely identify this certificate request, facilitating tracking and querying in the subsequent processing process), etc. Finally, the user identity attribute data after sorting, adding header information and metadata is encapsulated into a complete certificate request data packet, and this data packet is the final request content to be sent to the issuing device.

[0075] Step A2: Send the certificate request to the issuing device, where the issuing device is used to verify the user identity attributes carried in the certificate request. If the user identity attributes are verified successfully, an initial identity credential is fed back to the target client.

[0076] In the embodiment of the present application, sending the certificate request to the issuing device includes the following steps A201 - A203:

[0077] Step A201, detecting current indicator data of key indicators of a secure transmission channel between a target client and an issuer device.

[0078] Specifically, we must first identify the key indicators of the secure transmission channel that needs to be tested. These indicators usually include but are not limited to the following categories: Bandwidth: refers to the amount of data that the channel can transmit per unit time, and the unit is generally Mbps (megabits per second). It reflects the speed capability of the channel to transmit data. Delay: also known as latency, refers to the time delay experienced by data from the sender (target client) to the receiver (issuer device), including propagation delay, processing delay, queuing delay, etc., and the unit is usually milliseconds (ms). Packet loss rate: indicates the proportion of data packets (data packets) lost during the transmission process to the total data packets sent, usually expressed as a percentage. Packet loss is caused by network congestion, equipment failure, etc. Jitter: refers to the degree of change in data transmission delay, that is, the fluctuation of delay between different data packets, and the unit is also milliseconds (ms). Large jitter will affect applications with high real-time requirements. Channel encryption strength: evaluates the security level of the encryption algorithm used by the channel, such as encryption algorithms of different strengths such as AES-128 and AES-256, as well as factors such as the length of the key, which reflects the channel's ability to prevent data from being stolen or tampered with.

[0079] For bandwidth detection, network performance testing tools such as iperf can be used. Install the corresponding test end program on the target client and the issuer device respectively. By testing the data transmission between the two, the tool can accurately measure the available bandwidth of the current channel. Delay and jitter detection can also be done with the help of professional network testing tools, such as the extended functions of the ping command (in Windows system) or the traceroute command (in Linux system). These commands can send a series of test data packets and record the time from sending to returning of each data packet. By analyzing these data, the average delay and jitter can be calculated. Packet loss rate detection can also be based on similar testing tools mentioned above. By sending a certain number of data packets and counting the number of data packets that have not received a reply, the packet loss rate can be calculated. The channel encryption strength can be detected by checking the network setting information on the client and the issuer device, determining the encryption protocol (such as SSL / TLS version), and then combining the knowledge of the encryption algorithm library to evaluate its encryption strength. For example, AES-256 has higher encryption strength than AES-128.

[0080] Through the above-mentioned detection tools and methods, the current specific indicator data of each key indicator is obtained. For example, the current channel bandwidth is measured to be 50Mbps, the delay is 20ms, the packet loss rate is 1%, the jitter is 5ms, and the AES-256 encryption algorithm is used.

[0081] Step A202: Analyze the network status of the secure transmission channel using the current indicator data of key indicators.

[0082] Specifically, set the network status evaluation criteria corresponding to different key indicators in advance according to service requirements. For example: Bandwidth: If the service requires a high data transmission speed, such as video streaming services, set the bandwidth below 20 Mbps as the unavailable state, 20 - 50 Mbps as the available but restricted state, and above 50 Mbps as the good available state. Latency: For applications with high real-time requirements, such as online games or voice calls, a latency higher than 50 ms is considered the unavailable state, 20 - 50 ms is the available but experience-affecting state, and below 20 ms is the good available state. Packet loss rate: A packet loss rate higher than 5% causes obvious errors in data transmission, so a packet loss rate below 5% is the available state, and above 5% is the unavailable state. Jitter: Jitter exceeding 10 ms will have an obvious impact on some applications with high real-time requirements, so jitter below 10 ms is the available state, and above 10 ms is the unavailable state. Channel encryption strength: If the encryption algorithm strength reaches the industry standard (such as AES-256, etc.) and the authentication mechanism is effective, it is regarded as the encryption secure available state; otherwise, it is the unavailable state (such as using a weak encryption algorithm or having loopholes in the authentication mechanism).

[0083] Analyze the specific indicator data of each key indicator obtained one by one according to the set evaluation criteria. For example, assume the service is online video playback, the measured bandwidth is 30 Mbps, the latency is 30 ms, the packet loss rate is 3%, the jitter is 8 ms, and the AES-256 encryption algorithm is used and the authentication mechanism is effective. According to the evaluation criteria, the bandwidth of 30 Mbps is in the available but restricted state; the latency of 30 ms is in the available but experience-affecting state; the packet loss rate of 3% is in the available state; the jitter of 8 ms is in the available state; the channel encryption strength is in the secure state.

[0084] Comprehensively consider the evaluation results of these indicators and make an overall judgment on the network status of the secure transmission channel.

[0085] Step A203: If the network status of the secure transmission channel is the available state, send a certificate request through the secure transmission channel; or, if the network status of the secure transmission channel is the unavailable state, obtain the encryption method corresponding to the target user, encrypt the certificate request using the encryption method, and send the encrypted certificate request to the issuer device.

[0086] Specifically, when it is determined that the network state of the secure transmission channel is available, directly send a certificate request through the current secure transmission channel. Before sending, ensure that the secure transmission channel has established a connection. For example, if it is a secure channel based on the SSL / TLS protocol, confirm that both parties have completed preliminary preparations such as identity authentication and key exchange. Then, encapsulate the certificate request data packet in the format specified by the channel (such as adding necessary protocol headers, checksums, etc.) and send it to the issuer device through the channel. During the sending process, continuously monitor the state of the channel, such as whether there are data packet losses, connection interruptions, etc. If problems occur, handle them in a timely manner (such as retransmitting lost data packets, re-establishing connections, etc.).

[0087] When it is determined that the network state of the secure transmission channel is unavailable, obtain the security configuration file corresponding to the target user. Among them, the security configuration file includes the security requirements corresponding to the target user in different business scenarios; obtain the service information of the service currently requested by the target user, and obtain the target business scenario hit by the service information; obtain the target security requirements corresponding to the target business scenario from the security configuration file; obtain the target encryption algorithm corresponding to the target security requirements from the encryption algorithm library, and use the target encryption algorithm as the encryption method corresponding to the target user.

[0088] First, index and locate the corresponding security configuration file through the user's unique identifier (such as username, account ID, etc.). Before obtaining the security configuration file, identity authentication and authorization operations are usually required. Once the identity authentication and authorization are passed, the content of the security configuration file corresponding to the target user can be obtained through corresponding file reading operations (if stored locally) or database query operations (if stored in the server-side database). The content of this file is stored in a specific format, such as XML format, JSON format, etc., for easy parsing and processing, and contains the security requirement information corresponding to the target user in different business scenarios.

[0089] The target client will monitor the user's operation behavior. When the user initiates a service request, the client will collect a series of service information related to this request. These information include the type of service requested (such as file transfer service, online payment service, information query service, etc.), the specific content or object of the service (such as the specific file name requested for transfer, the amount and object of payment, the specific information keywords for query, etc.), the time of the request, the source device information of the request (such as device model, IP address, etc.), etc., in order to comprehensively understand the specific situation of the user's service request this time. After collecting the service information, the system will match this information with various predefined business scenarios. The predefined business scenarios are divided according to the types of services provided by the system and common business operation modes. For example, operations involving fund transactions are classified into the "financial transaction" business scenario, and simple information browsing and querying are classified into the "information query" business scenario, etc. By analyzing the key elements (such as service type, service content, etc.) in the service information, determine the target business scenario hit by this service request.

[0090] Parse the previously obtained security configuration file of the target user. According to its storage format (such as XML or JSON format), use the corresponding parsing tools or library functions to convert the file content into an operable data structure, so as to be able to conveniently extract the required information from it. In the parsed security configuration file, according to the classification identifier of the business scenario, search for the security requirement records corresponding to the previously determined target business scenario. These security requirement records detail the specific requirements of the target user for data security in this business scenario. For example, in the "financial transaction" business scenario, it is required to adopt high-strength encryption algorithms, strict authentication mechanisms, data integrity verification, etc.; in the "information query" business scenario, the requirement for encryption strength is relatively low, but more attention is paid to data availability and query efficiency, etc.

[0091] The target client deploys an encryption algorithm library, which includes common encryption algorithms, such as symmetric encryption algorithms (AES, 3DES, etc.), asymmetric encryption algorithms (RSA, ECC, etc.), and some hash functions (MD5, SHA, etc.), etc., and details and classifications of the characteristics, encryption strength, applicable scenarios, etc. of each encryption algorithm are provided. According to the target security requirements obtained from the security configuration file, search and match in the encryption algorithm library. If the target security requirement is for high-strength encryption and is used to protect important data (such as financial transaction data), a symmetric encryption algorithm such as AES-256 will be matched (because it has high encryption strength and good performance); if the target security requirement is for relatively low encryption strength and is mainly used for simple data integrity verification (such as user login information verification in the information query scenario), a hash function such as MD5 will be matched as the target encryption algorithm.

[0092] In subsequent operations, such as when encrypting data or conducting secure communication with other entities, the selected encryption method will be used. At the same time, according to the characteristics of the encryption algorithm, the corresponding key needs to be obtained (for example, a symmetric key is required for a symmetric encryption algorithm, and a public key or private key is required for an asymmetric encryption algorithm, etc.) to complete the specific encryption operation.

[0093] Send the encrypted certificate request to the issuer device through the network. Similarly, it is necessary to ensure the stability of the network connection during the sending process, and some network transmission tools or protocols can be used to guarantee it. When sending, attention should be paid to properly encapsulating the encrypted certificate request (such as adding necessary identification information so that the issuer device can identify it as an encrypted certificate request), and continuously monitor the situation during the sending process, such as whether there are problems like data packet loss or decryption failure. If problems occur, they should be handled promptly (such as retransmitting the lost data packets, checking the reasons for decryption failure and fixing them, etc.).

[0094] Step A3: Receive the initial identity credential feedback from the issuer device. Among them, the initial identity credential is generated by the issuer device based on the pre-generated private key and system parameters, and the private key is the private key in the public-private key pair pre-generated by the issuer device.

[0095] Specifically, after the issuer device completes generating the initial identity credential based on its pre-generated private key and system parameters, it will send the credential to the target client through a predefined feedback channel. The target client will prepare to receive data according to the communication protocol and data format previously agreed upon with the issuer device. Once receiving the feedback information from the issuer device, the client will first perform an integrity check on the received data, such as by using checksums, hash values, etc. to confirm whether the data has not been tampered with and is complete and error-free during the transmission process. If the data integrity check passes, the client will then parse the received data according to the communication protocol specifications used and extract the initial identity credential part.

[0096] Step S102: Generate a symmetric identity credential based on the initial identity credential and send the symmetric identity credential to the issuer device through an anonymous channel. Among them, the issuer device is used to verify the symmetric identity credential and sign the symmetric identity credential after the verification passes.

[0097] In the embodiment of the present application, first, obtain the received initial identity credential from the local secure storage area to ensure its integrity and accuracy. Then, start a program module dedicated to generating symmetric identity credentials, which operates according to a preset symmetric encryption algorithm (such as the AES algorithm, etc.). Use the key information (such as user identification, related attributes, etc.) in the initial identity credential as input data, and according to the rules of the symmetric encryption algorithm, through a series of complex mathematical operations and data processing, generate a new symmetric identity credential. This new credential has a specific data structure associated with the initial identity credential and meeting the requirements of subsequent verification and processing, and at the same time contains encrypted information generated based on symmetric encryption to ensure its security and uniqueness.

[0098] After generating the symmetric identity credential, it is then sent through an anonymous channel. First, ensure that the local client has installed and configured software or tools supporting anonymous communication (such as related applications based on the onion routing principle). Preprocess the generated symmetric identity credential to make it meet the transmission requirements of the anonymous channel, which includes operations such as encrypting the credential at multiple layers and adding anonymization identifiers to hide the true source and content of the credential. Then, use the anonymous channel software to establish a connection with the issuer device, and this connection will transmit data through multiple anonymous nodes. Each node only knows the connection situation with its adjacent nodes, thus effectively protecting the anonymity of the transmission path. Finally, send the processed symmetric identity credential to the issuer device through the established anonymous channel, and continuously monitor the channel status during the sending process to ensure that the data is transmitted to the issuer device completely and accurately.

[0099] Step S103: Receive the symmetric identity credential with a signature feedback from the issuer device.

[0100] In the embodiment of the present application, the client is in a state of listening for feedback information from the issuer device to ensure that it can detect and receive the upcoming symmetric identity credential with a signature in a timely manner. When the issuer device completes the verification and signature of the previously sent symmetric identity credential, it will send it back through a secure feedback channel.

[0101] After the client receives the feedback information, it will immediately perform an integrity check on the received data. This can be verified by means such as checksum and hash value to determine whether the data has been tampered with and is intact during the transmission process. If the integrity check passes, then parse the received data according to the pre-agreed communication protocol and data format, and extract the part of the symmetric identity credential with a signature. Finally, properly store the extracted symmetric identity credential with a signature in the local secure storage area for subsequent related verification and processing operations, such as sending it to the verifier for further identity verification, etc.

[0102] Step S104: Send the symmetric identity credential with a signature to the verifier device, so that the verifier device verifies the signature and the symmetric identity credential, and feeds back a verification identifier to the target client when the signature and the symmetric identity credential pass the verification. The verification identifier is used to request the server to provide services for the target client.

[0103] In the embodiment of the present application, sending the symmetric identity credential with a signature to the verifier device includes the following steps B1 - B3:

[0104] Step B1: Detect the network environment where the target client is currently located and the corresponding network security protection measures for the network environment.

[0105] Specifically, first, start a network environment detection program or module on the target client. This program collects various information to determine the network environment where the client is currently located. For example, by obtaining the network connection information of the client device, it is determined whether it is connected to a wired network (such as Ethernet) or a wireless network (such as Wi-Fi, mobile data network, etc.). At the same time, obtain the access point information of the network (such as the identifier of the router, base station information, etc.) to clarify the network type. Then, detect the basic attributes of the network, including indicators such as network bandwidth, latency, and packet loss rate, which can reflect the transmission performance status of the network.

[0106] For the detection of network security protection measures, check the security software installed on the client device and its running status. For example, whether the firewall is enabled, whether the anti-virus software is in real-time monitoring, and whether the intrusion detection system is in an active state. At the same time, check whether the network connection uses an encryption protocol (such as the SSL / TLS protocol to ensure the security of network transmission), and whether there are other network security configurations (such as the setting of network access control lists, etc.). Combining this information, comprehensively understand the network environment where the target client is currently located and the corresponding network security protection measures.

[0107] Step B2: Select a corresponding target transmission channel according to the network environment and the network security protection measures.

[0108] Specifically, after completing the detection of the network environment and the network security protection measures, select the target transmission channel based on the obtained information. If the client is in a trusted internal network environment, such as an enterprise internal office network, and the network security protection measures are complete (such as the firewall, intrusion detection system, etc. are all running normally, and there is a strict identity authentication mechanism for network access), and there are high requirements for transmission speed and efficiency, then a secure encrypted channel based on the SSL / TLS protocol will be preferentially selected. This channel can meet the requirements of fast and efficient transmission while ensuring the security of data transmission.

[0109] If the client is in a public network environment, such as using a wireless network in a public place, or although it is in an internal network but has extremely high requirements for privacy protection (such as involving sensitive business operations), an anonymous channel will be considered. Anonymous channels are usually implemented by means of technologies such as Onion Routing (Tor). It can effectively hide the source and transmission path of data, provide a high degree of anonymity, and ensure the protection of user privacy during the transmission of symmetric identity credentials carrying signatures.

[0110] In addition, if the network security protection measures in the network environment are average and sensitive to transmission costs (such as traffic fees, etc.), some conventional and relatively simple transmission channels will be selected, and additional security measures (such as simple encryption processing of data, etc.) will be taken during the transmission. However, this situation is relatively rare, and the final selected target transmission channel is mainly determined according to the security and privacy protection requirements of the network environment.

[0111] Step B3, send the symmetric identity credential carrying the signature to the verifier device through the target transmission channel.

[0112] In the embodiment of the present application, sending the symmetric identity credential carrying the signature to the verifier device through the target transmission channel includes the following steps B301 - B303:

[0113] Step B301, obtain the corresponding monitoring strategy according to the channel type corresponding to the target transmission channel.

[0114] Specifically, if the target transmission channel is an encrypted secure channel, the monitoring strategy includes real - time monitoring of the encryption algorithm status to ensure that the encryption key is normal and not tampered with, ensuring that the encryption strength meets the expectations, and preventing data theft; generating and comparing check values during data transmission, paying attention to packet loss situations, and judging data integrity based on the confirmation and re - transmission mechanism, and dealing with problems in a timely manner; continuously monitoring the connection status, ensuring connection stability through heartbeat signals, interruption prompts, and frequency statistics, and troubleshooting and reconnecting in case of anomalies. If it is an anonymous transmission channel, the monitoring strategy focuses on maintaining anonymity and preventing attacks, using tools to monitor the jump path, ensuring that nodes follow the anonymous protocol, and re - planning the path or strengthening protection if nodes are abnormal; at the same time, using special tools to monitor attack signs, such as abnormal probing requests, cracking attempts, etc., and enhancing anonymous protection after discovery, such as increasing the encryption layer or replacing nodes.

[0115] Step B302, monitor whether there are any abnormal situations during the process of the target transmission channel transmitting the symmetric identity credential carrying the signature according to the monitoring strategy.

[0116] Specifically, during the process of monitoring the target transmission channel for the transmission of symmetric identity credentials carrying signatures according to the monitoring strategy, it is necessary to check for abnormal situations, including: if the target transmission channel is an encrypted secure channel, detect the operating status of the channel encryption algorithm in the encrypted security signal, and detect whether there is any abnormal use of the encryption key; obtain the check value generated synchronously during the process of sending the symmetric identity credentials carrying signatures, and compare the check value with the check information fed back by the receiving end; if the operating status of the channel encryption algorithm is in an error state, and / or there is any abnormal use of the encryption key, it is determined that there is an abnormal situation; or, if the operating status of the channel encryption algorithm is in a correct state, and / or the encryption key is used normally, it is determined that there is no abnormal situation.

[0117] First of all, it is necessary to clarify the specific channel encryption algorithm adopted. Common ones are the encryption algorithms used in the SSL / TLS protocol (such as combinations of related algorithms like AES, RSA, etc.). Then, use the built-in monitoring tools of the system or specially developed detection programs to monitor the operating status of this encryption algorithm in real time.

[0118] The monitoring content includes but is not limited to the following aspects:

[0119] ① Initialization of the encryption algorithm: Check whether the encryption algorithm is correctly initialized before the transmission starts. For example, whether the required parameters are correctly loaded and whether the key length meets the configuration requirements. If there are errors in the initialization process, subsequent encryption operations cannot proceed normally.

[0120] ② Real-time operation of encryption and decryption: During the data transmission process, continuously observe whether the encryption algorithm encrypts the symmetric identity credentials carrying signatures smoothly and whether the receiving end decrypts the data smoothly. This can be judged by checking whether there are error messages indicating encryption or decryption failures. For example, if there are prompts like "Encryption algorithm execution error" during the encryption process, it indicates that there is a problem with the operating status of the encryption algorithm.

[0121] ③ Performance indicators of the encryption algorithm: Pay attention to the performance of the encryption algorithm during the transmission process, such as encryption speed, decryption speed, etc. Although slight fluctuations in these indicators are normal, if there is a significant performance decline, such as the encryption or decryption speed suddenly becoming extremely slow, it implies that there may be potential problems with the encryption algorithm, such as being affected by some interference or resource shortage.

[0122] Secondly, during the detection process, ensure that the source of the encryption key is legal and compliant, that is, it is obtained through a formal key generation and distribution mechanism and is stored securely on the local device (for example, stored in an encrypted key storage area). Detect whether there is any abnormal use of the encryption key from the following aspects:

[0123] ① Key access rights: Check whether there are unauthorized entities attempting to access the encryption key. This can be determined by reviewing the access logs of the key storage area. If there are abnormal login attempts or service requests from unauthorized IP addresses, user accounts, etc., it means there is a risk of the encryption key being stolen or misused.

[0124] ② Frequency and timing of key usage: Analyze whether the usage frequency of the encryption key conforms to normal business logic. For example, if the encryption key is used frequently within a short period of time, while the corresponding business operations do not have a corresponding large volume of data transfer requirements, this is an abnormal situation, indicating that there may be malicious programs misusing the encryption key for encryption operations. At the same time, attention should also be paid to the timing of key usage, whether it is used in the correct business process. If there are key usage records when keys should not be used, it also belongs to an abnormal situation.

[0125] ③ Key update situation: For some encryption keys that need to be updated regularly, check whether they are updated according to the specified cycle. If the key is not updated for a long time, it will increase the risk of the key being cracked, thus affecting data confidentiality. Moreover, during the key update process, it is necessary to ensure that the update operation is carried out in accordance with security specifications, without situations such as update failures or abnormal switching between old and new keys.

[0126] Then, when sending the signed symmetric identity credential through an encrypted secure channel, in order to ensure the integrity of the data during transmission, a check value of the data will be generated synchronously at the sending end. The way to generate the check value is usually based on a specific check algorithm, such as a hash algorithm (common ones include MD5, SHA-1, SHA-256, etc.). Before sending the signed symmetric identity credential, take the credential data as input and calculate a fixed-length check value through the hash algorithm. This check value can be regarded as a "fingerprint" of the sent data, which uniquely identifies the specific state of the data at a certain moment.

[0127] After the data is transmitted to the receiving end, the receiving end will also calculate the received data (i.e., the signed symmetric identity credential) according to the same check algorithm to obtain a check information at the receiving end. Then, compare the check value generated at the sending end with the check information feedback from the receiving end.

[0128] Finally, if the running state of the channel encryption algorithm is found to be in an error state during the detection process, such as error messages indicating encryption or decryption failure, encryption algorithm initialization error, etc., and / or if abnormal usage of the encryption key is detected, such as unauthorized access, abnormal usage frequency, failure to update as per regulations, etc., then it can be determined that an abnormal situation exists. This abnormal situation means that the confidentiality and integrity of the data during transmission have been threatened, and immediate measures need to be taken for investigation and repair, such as suspending data transmission, re-initializing the encryption algorithm, replacing the encryption key, etc.

[0129] Conversely, if after detection, the running state of the channel encryption algorithm is in a correct state, that is, the encryption and decryption operations proceed smoothly and the performance indicators are normal, and / or the encryption key is used normally, that is, there is no unauthorized access, the usage frequency conforms to the business logic, and it is updated as per regulations, then it can be determined that there is no abnormal situation. This indicates that the confidentiality and integrity of the data during transmission are effectively guaranteed at the current stage, and subsequent data transmission operations or other related business processes can continue.

[0130] Alternatively, during the process of monitoring the target transmission channel for the transmission of symmetric identity credentials with signatures according to the monitoring strategy, it is checked whether there are abnormal situations, including: if the target transmission channel is an anonymous transmission channel, then the jump path of the symmetric identity credentials with signatures in the anonymous transmission channel is detected to obtain the activity status of each node in the jump path; analyze whether there are target nodes with abnormal activities in the activity status of each node in the jump path; if there are target nodes with abnormal activities, then it is determined that an abnormal situation exists; or, if there are no target nodes with abnormal activities, then it is determined that there is no abnormal situation.

[0131] First of all, during the transmission process, when the symmetric identity credentials with signatures start to be transmitted in the anonymous transmission channel, the monitoring tool will record in real time each node it passes through and the jump order between each node, thus completely depicting the jump path of the data. This jump path is like a "journey record" of data transmission, which details the anonymous nodes that the data has passed through in sequence from the sending end, as well as information such as the entry and exit times at each node.

[0132] For each node in the jump path, the monitoring tool will further collect and analyze various activity status information related to it. This information mainly includes the following aspects:

[0133] ① Connection establishment and disconnection: Monitor whether the process of establishing connections between the monitoring node and its adjacent nodes before and after is smooth, whether there is a situation of repeated attempts after connection establishment fails, and whether the disconnection is due to normal transmission end or abnormal interruption (such as sudden disconnection, timeout disconnection, etc.). If a node frequently has problems in connection establishment or abnormal disconnection, this implies potential stability or security problems with this node.

[0134] ② Data processing speed: Observe the speed at which each node processes symmetric identity credential data with signatures (such as receiving, forwarding, etc.). Under normal circumstances, each node has a roughly stable range of processing speeds, which depends on factors such as the node's own hardware performance and network bandwidth. If the processing speed of a certain node suddenly becomes extremely slow or extremely fast (beyond the normal fluctuation range), this means that either the node itself has a performance failure or there are some abnormal operations during data processing (such as performing additional analysis or tampering with the data, etc.).

[0135] ③ Data traffic characteristics: Analyze the traffic situation of each node when processing symmetric identity credential data with signatures, including the incoming traffic to the node, the outgoing traffic from the node, and the cache traffic inside the node, etc. By comparing with the normal traffic pattern, it can be judged whether there is an abnormal increase or decrease in traffic. For example, if a node suddenly has an incoming traffic much larger than the normal level while the outgoing traffic is very small, this indicates that the node is hoarding data or there are abnormal situations such as data congestion; conversely, if the outgoing traffic is much larger than the incoming traffic and does not conform to the normal transmission logic, this also implies that there are problems with the node in data processing.

[0136] ④ Node identification and source tracking: Check whether each node has performed additional identification operations on the symmetric identity credential data with signatures passing through (which should not occur in anonymous transmission), or whether there are signs of attempting to track the data source. Since the key to anonymous transmission is to maintain the anonymity of the data, any behavior of performing additional identification on the data or attempting to track the source will destroy this anonymity. Therefore, once such a situation is discovered, it indicates that the activities of this node are seriously abnormal.

[0137] Secondly, after obtaining the above-mentioned activity conditions of each node in the jump path, it is necessary to conduct a comprehensive and detailed analysis of this information to determine whether there is a target node with abnormal activities in the entire jump path. During the analysis process, the actual activity conditions of each node will be compared with the activity characteristics that the node should have under normal circumstances. For example, comparing the current connection establishment situation of a certain node with the statistical data of normal connection establishment in the past, comparing its processing speed with the average processing speed range of similar nodes, comparing its traffic characteristics with the normal traffic pattern, and checking whether there are signs of violating the anonymous transmission rules or source tracking behaviors. If it is found during the comparison process that the activity conditions of a certain node deviate significantly from the normal range and this deviation cannot be explained by reasonable normal factors (such as temporary network fluctuations, minor faults in node hardware, etc.), then this node can be determined as the target node with abnormal activities.

[0138] Then, through analysis, it is determined that there is a target node with abnormal activities in the jump path, which means that during the anonymous transmission of the symmetric identity credential with a signature, the anonymity, integrity, or transmission stability of the data has been threatened. For example, an abnormal activity node will destroy the anonymity of the data, making the source or transmission path of the data likely to be leaked; or the node tampers with the data during the data processing process, affecting the integrity of the data; or its unstable activities lead to problems such as data transmission interruption or delay. Therefore, once a target node with abnormal activities is found, it can be determined that there is an abnormal situation, and at this time, measures need to be taken immediately for processing, such as re-planning the transmission path, avoiding the abnormal node for data transmission, strengthening the monitoring of the anonymous transmission channel, etc.

[0139] On the contrary, if after a comprehensive analysis of the activity conditions of each node in the jump path, no target node with abnormal activities is found, this indicates that at the current stage, the transmission of the symmetric identity credential with a signature in the anonymous transmission channel is normal, and the anonymity, integrity, and transmission stability of the data are effectively guaranteed. That is to say, the data can flow smoothly in the anonymous network as expected, without problems such as anonymity leakage, data tampering, or transmission interruption caused by abnormal node activities. Therefore, it can be determined that there is no abnormal situation, and at this time, the subsequent data transmission operations or other related business processes can be continued.

[0140] Step B303, if there is no abnormal situation, it is determined that the symmetric identity credential with a signature is successfully sent to the verifier device.

[0141] Specifically, after comprehensively monitoring the process of transmitting the symmetric identity credential with a signature through the target transmission channel (whether it is an encrypted secure channel or an anonymous transmission channel), if no abnormal situation is found after detecting and analyzing various aspects such as the running state of the channel encryption algorithm, the usage of the encryption key, the comparison of data check values (for encrypted secure channels), and the activities of each node in the credential jump path in the anonymous transmission channel. That is, the channel encryption algorithm runs normally and the encryption key is used normally, and the check value matches the check information feedback by the receiving end (applicable to the encrypted secure channel scenario); or in the anonymous transmission channel, the activities of each node in the credential jump path meet the normal requirements, and there is no target node with any abnormal activities. When these conditions are met, according to the established determination logic, it can be determined that the symmetric identity credential with a signature has been successfully sent to the verifier device through the target transmission channel completely, accurately and securely.

[0142] The method provided by the embodiment of the present application provides a secure and reliable service acquisition method for the target user, ensures the authenticity and legality of the user identity, and enhances the accuracy and security of service provision through multi-link verification and signature. Specifically, by transmitting the symmetric identity credential through the anonymous channel, the dependence on multi-party coordination is reduced, and the computational load and communication overhead are lowered. The anonymous channel does not require complex multi-party interaction and is only transmitted under a specific architecture, improving the transmission efficiency. Secondly, the present application uses cryptography technology moderately and does not over-integrate a variety of advanced cryptography technologies. In the process of generating, verifying and signing the symmetric identity credential, a relatively simple method is adopted, reducing the development and implementation difficulty. Thereby reducing resource consumption, making the system easier to deploy and maintain, and solving the problems of difficult deployment and maintenance caused by high system complexity and high resource consumption affecting business development.

[0143] In the embodiment of the present application, the method further includes the following steps C1 - C3:

[0144] Step C1, if there is an abnormal situation, obtain the abnormal reason that causes the abnormal situation.

[0145] Specifically, in terms of the channel encryption algorithm: when the target transmission channel is an encrypted secure channel, if an abnormal situation is found, first check the running state of the channel encryption algorithm. Check whether there is an error message indicating encryption or decryption failure. If such an error message appears, it is because there is a vulnerability in the encryption algorithm itself that is exploited, or the parameter settings are incorrect during algorithm initialization. For example, the key length required by the encryption algorithm is set incorrectly, resulting in insufficient encryption strength and unable to effectively protect data, which is one of the reasons for the abnormality.

[0146] Regarding the use of encryption keys: Pay attention to the usage of encryption keys at the same time. Check for unauthorized access attempts. You can discover whether there are abnormal login IP addresses or user accounts trying to obtain the keys by viewing the access logs of the key storage area. If such a situation is found, it indicates that the key is at risk of leakage, which is a potential cause of the abnormality. Additionally, analyze whether the usage frequency of the key conforms to normal business logic. If the key is frequently used within a short period of time, while the corresponding business operations do not have a corresponding large amount of data transmission requirements, it implies that there is a malicious program abusing the key, which is also a manifestation of the abnormal cause.

[0147] Regarding the activities of nodes: When the target transmission channel is an anonymous transmission channel, if there are abnormal situations, focus on analyzing the activities of each node in the jump path of the symmetric identity credential carrying a signature. For example, if the connection establishment of a certain node frequently fails, it is caused by reasons such as the node's own hardware failure, unstable network connection, or external attack interference. Another example is that if it is found that a certain node performs additional identification operations on the data, which clearly violates the rules of anonymous transmission, the reason is that the node is maliciously controlled and attempts to destroy the anonymity of the data.

[0148] Regarding the characteristics of data traffic: Observe the data traffic characteristics of the nodes. If a certain node has an inflow traffic much larger than the normal level while the outflow traffic is very small, it means that the node is hoarding data. The reason may be that it is controlled by a malicious program and attempts to tamper with or steal the data, etc.; conversely, if the outflow traffic is much larger than the inflow traffic and does not conform to the normal transmission logic, it also implies that there are problems with the data processing of the node, and the reasons involve node software failures or being attacked, etc.

[0149] Through the above detailed detection and analysis for different channel types, accurately find out the specific abnormal causes leading to the abnormal situation.

[0150] Step C2, obtain alternative transmission schemes using the channel type and the abnormal cause.

[0151] Specifically, if the abnormal cause is a vulnerability in the channel encryption algorithm, the alternative transmission scheme is to switch to another more secure and reliable encryption algorithm. For example, switch from the risky AES - 128 algorithm to the AES - 256 algorithm with higher encryption strength and more rigorous security verification. At the same time, it is necessary to regenerate the key and ensure that the processes of generating, distributing, and storing the new key all strictly follow security specifications.

[0152] When the risk of encryption key leakage is found, the alternative transmission plan is to immediately deactivate the currently compromised key and then regenerate a new set of key pairs. For the transmission method, it is possible to consider adding additional identity authentication mechanisms based on the original encrypted security channel, such as using two-factor authentication (in addition to the password, SMS verification code, etc.) to further ensure the security of transmission. In addition, in the subsequent transmission process, strengthen the real-time monitoring of key usage to ensure the safe use of new keys.

[0153] Abnormalities caused by malicious control of nodes: If it is determined that the abnormality is caused by malicious control of a node in the anonymous transmission channel, the alternative transmission plan can be to re-plan the data jump path to avoid the maliciously controlled node. This requires the use of the path adjustment function of the anonymous communication tool to re-select other reliable nodes to complete the data transmission. At the same time, in order to enhance anonymity and security, you can also consider increasing the number of encryption layers during data transmission, such as increasing from one layer of encryption to two layers of encryption, making it more difficult for data to be stolen or tampered with.

[0154] When data flow is abnormal, such as a node hoarding data, the alternative transmission solution can be to change the direction of data transmission and bypass the node with the problem. The settings of anonymous communication tools can be adjusted to guide data transmission through other normal nodes. In addition, in the subsequent transmission process, the real-time monitoring of node data flow is strengthened to promptly detect and handle similar abnormal situations in the future.

[0155] Step C3: Transmit the symmetric identity certificate carrying the signature to the verification party device according to the alternative transmission scheme.

[0156] Specifically, implement an alternative transmission scheme (based on the situation after the encrypted secure channel is adjusted):

[0157] If the alternative transmission scheme is to switch the encryption algorithm and regenerate the key, first ensure that the new encryption algorithm is installed and configured on both the client and the authenticator device, and that the new key is correctly generated, distributed, and stored. Then, re-encrypt the symmetric identity certificate with the signature according to the new encryption algorithm to make it meet the requirements of the new algorithm. During the transmission process, continue to pay attention to the operating status of the new encryption algorithm to ensure that the encryption and decryption operations proceed smoothly. At the same time, follow the normal transmission process of the encrypted secure channel, such as identity authentication, adding necessary protocol headers and checksums, and send the re-encrypted credentials to the authenticator device through the secure channel.

[0158] When the alternative transmission scheme is to add an identity authentication mechanism, the settings of the new identity authentication mechanism need to be synchronized at both the client and the verifier device ends. For example, relevant parameters required for two-factor authentication (such as the receiving mobile phone number for SMS verification codes, etc.) need to be configured properly. When transmitting the symmetric identity credential with a signature, first encrypt it in the same way as the original encrypted secure channel, and then, before sending, complete the newly added identity authentication steps to ensure the authenticity of both parties' identities. After that, send the credential to the verifier device through the secure channel. During the transmission process, also pay attention to the channel status and promptly handle problems such as connection interruptions and data packet losses that occur.

[0159] Implement the alternative transmission scheme (in the case of adjusted anonymous transmission channels):

[0160] If the alternative transmission scheme is to re-plan the path and increase the encryption layers, first use an anonymous communication tool to re-plan the path to ensure that the data can be transmitted through the newly selected reliable nodes. Then, perform re-encryption processing on the symmetric identity credential with a signature. According to the requirements after increasing the encryption layers, encrypt the original credential data in multiple layers to make it more confidential. During the transmission process, continuously monitor the running status of the anonymous communication tool to ensure that the data flows smoothly in the new jump path, and at the same time pay attention to maintaining the anonymity of the data to avoid situations where nodes add additional identifiers to the data and damage the anonymity. Finally, send the re-processed credential to the verifier device through the anonymous channel.

[0161] When the alternative transmission scheme is to change the data transmission flow direction and strengthen traffic monitoring, first adjust the settings of the anonymous communication tool to guide the data to be transmitted through other normal nodes to achieve the change of the data transmission flow direction. When transmitting the symmetric identity credential with a signature, perform encryption and other processing in the conventional processing manner of the anonymous channel to make it meet the requirements of anonymous transmission. During the transmission process, continuously monitor the data traffic situation of the nodes, promptly discover and handle abnormal traffic situations that occur, and at the same time ensure that the data can reach the verifier device smoothly through the changed transmission flow direction.

[0162] This embodiment provides an identity authentication device, as Figure 3 shown, the identity authentication device includes: an issuer device 301 and a verifier device 302;

[0163] The issuing device 301 is used to receive the symmetric identity credential issued by the target client based on the anonymous channel; verify the symmetric identity credential, and sign the symmetric identity credential if the symmetric identity credential verification passes; send the symmetric identity credential carrying the signature to the target client, so that the target client sends the symmetric identity credential carrying the signature to the verifying device, wherein the target client is the client used by the target user who currently requests to provide the service, the symmetric identity credential is generated based on the initial identity credential of the target user, and the initial identity credential is generated based on the user identity attribute of the target user.

[0164] The verification device 302 is used to receive the symmetric identity certificate with signature sent by the target client, and verify the signature and the symmetric identity certificate; if the signature and the symmetric identity certificate are verified, a verification identifier is fed back to the target client, so that the target client can request the server to provide services based on the verification identifier.

[0165] Specifically, when a target user wants to obtain a certain service, after initiating a request through the target client that the target user is using, an initial identity credential will be generated based on the user identity attribute of the target user, and then a symmetric identity credential will be further generated based on the initial identity credential. The target client will then send the symmetric identity credential to the issuer device 301 through an anonymous channel. After receiving the symmetric identity credential, the issuer device 301 will start to verify it. Once the verification result shows that the symmetric identity credential meets the requirements and can pass the verification, the issuer device 301 will add a signature to the symmetric identity credential, and then send the symmetric identity credential with the signature back to the target client. The target client will then forward the symmetric identity credential with the signature to the verification device, so that the verification device can subsequently verify the signature and the symmetric identity credential according to the corresponding rules and procedures. The entire process works together to complete the authentication operation of the target user's identity, ensuring the accuracy and security of the identity information in the service provision link.

[0166] The verification device 302 will first receive the symmetric identity certificate with a signature sent by the target client, and then perform rigorous verification on the signature on the certificate and the symmetric identity certificate itself according to established rules and standards. After careful verification, if it is determined that both the signature and the symmetric identity certificate can pass the verification successfully, the verification device 302 will feedback a verification mark to the target client to indicate that the identity verification is successful. Then it will formally provide the corresponding service to the target client through the server associated with it, thereby completing the entire service provision process based on identity verification, ensuring that the service is provided to the client used by the target user who has passed the legal identity authentication.

[0167] In this embodiment, a server is further provided, which is used to receive a service request sent by a target client. The service request includes a service requirement and a verification identifier. The target client is the client used by the target user who currently requests services. The verification identifier is sent after the symmetric identity credential with a signature passes the verification. The symmetric identity credential is generated based on the initial identity credential of the target user, and the initial identity credential is generated based on the user identity attribute of the target user; the service resource is called based on the verification identifier, the target resource corresponding to the service requirement is obtained from the service resource, and the target resource is fed back to the target client.

[0168] Specifically, when the target user has a service requirement, the target user will send a service request to the server through the target client. The service request includes the specific service requirement and the verification identifier. The verification identifier here is sent after the symmetric identity credential with a signature passes the verification by the verification device in a series of previous verification processes. The symmetric identity credential is initially generated based on the initial identity credential of the target user, and the initial identity credential is obtained according to the user identity attribute of the target user. After receiving the service request, the server will call the corresponding service resource by virtue of the verification identifier therein, then accurately search and obtain the target resource corresponding to the service requirement from among the numerous service resources, and finally feed back these target resources to the target client, thereby completing the entire service provision process and ensuring that the service can be accurately and compliantly provided to the target user who has passed the identity verification.

[0169] As an example, the in-vehicle terminal (i.e., the target client) detects that the multimedia entertainment system resources of the vehicle are insufficient, some area data of the map navigation needs to be updated urgently, and at the same time, the vehicle safety monitoring module needs to obtain the latest fault warning rules and other resources. The in-vehicle terminal quickly sorts out the service requirements, combines them with the verification identifier to generate a service request, and then sends the service request to the server. The verification identifier is generated based on the user identity attributes such as the owner's identity information and the vehicle unique identification code registered by the owner in the vehicle enterprise system to generate the initial identity credential, and then the symmetric identity credential is derived therefrom. After being transmitted through the anonymous channel and the signature is verified by the issuer device, it is finally sent to the in-vehicle terminal after passing the verification by the verification device. After receiving the request sent by the in-vehicle terminal, the server quickly locates accurately in the service resource library according to the verification identifier, finds out the target resources such as the high-definition music library, the latest version of the map data packet, and the accurate vehicle safety monitoring rules that are adapted, and feeds them back to the in-vehicle terminal, so that the owner can enjoy rich multimedia entertainment in the car, reach the destination smoothly with accurate navigation, and can also rely on the advanced safety monitoring rules to ensure driving safety.

[0170] Specifically, as Figure 4 shown, the processing process of the user identity credential includes three stages, namely the certificate acquisition stage, the credential generation stage, and the credential authentication stage. The process of each stage is as follows:

[0171] I. Certificate acquisition stage:

[0172] Step 1: The user logs in to the target client, uploads their identity attribute information, and sends a request to the issuer device through a secure channel, clearly indicating in the request the expectation to obtain the corresponding certificate.

[0173] The issuer generates a pair of public and private keys: (pk issuer , sk issuer ).

[0174] The user encrypts the request content using the issuer's public key:

[0175] EncryptedRequested user = (pk issuer , (m1,..., m n ))

[0176] Step 2: After receiving the request, the issuer device comprehensively verifies the identity attributes submitted by the user based on the user information database stored in itself and the preset verification rules. This includes checking whether basic information such as name, date of birth, and contact information is consistent with the registered information, and checking whether the account password is correct, etc.

[0177] Step 3: If the user's identity attribute verification passes, proceed to the next step; if the verification fails, return a message of failed identity verification to the user.

[0178] Step 4: When the user's identity verification passes, the issuer device generates a corresponding initial identity credential according to the verification result and sends the initial identity credential back to the user. The initial identity credential contains the user's specific identifier, permission information, etc.

[0179] The issuer returns the certificate z = (z, z'), (z, z') ← MAC GGM (sk, (m1,..., m n ))

[0180] The process for the issuer device to generate the credential is as follows:

[0181]

[0182] In the above formula, π represents a zero - knowledge proof, used to ensure the legality of the MAC: The user proves to the issuer through the proof π that the (u, u') they hold is indeed a legal MAC value, and it is generated based on a set of legal attributes and keys. Among them, is the private key of the credential generation algorithm; z in is the base value in the credential, and z' is the associated calculated value of sk and the attribute value m. is an encrypted commitment about α0, is a random value used to generate this commitment so that α0 cannot be directly inferred, ensuring that α0 is consistent with the values in z'; In A i are the system public parameters. This equation is used to confirm that all attributes mi use the corresponding keys as defined by the protocol.

[0183] II. Credential Generation Phase:

[0184] Step 5, after the target client receives the initial identity credential returned by the issuer device, based on the initial identity credential and specific algorithms and rules, it generates an identity credential display (i.e., symmetric identity credential). The specific process is as follows:

[0185] Randomly select r in the finite field, (ω1,..., ω n ), r, (ω1,..., ω n ) are random values used to commit to the credential Z and the attribute m. The credential is z = (z, z').

[0186] Calculate and

[0187] The correct form of the zero-knowledge proof π:

[0188]

[0189] In the formula, z is the base value in the credential, h is the public parameter, m is the attribute value, σ is the signature, and V is a value used for verification, combining the credential and the commitment value. π ensures the correctness of the attribute m, the random numbers w, r.

[0190] The identity credential display can be a visual or data-based presentation form containing the user's key information and certificate-related information.

[0191] Step 6, the target client further verifies the initial identity credential sent by the issuer device to ensure that the certificate has not been tampered with during transmission and is authentic and valid.

[0192] Step 7, the issuer device digitally signs the generated identity credential display to generate the signature σ. This signature is encrypted using the private key, and the identity credential display carrying the signature is sent to the target client. σ = DS.Sign(sk, cre).

[0193] III. Credential Authentication Phase:

[0194] Step 8. After receiving the signed identity credential presentation sent by the issuer device, the target client sends the signed identity credential presentation to the verifier device, requesting the verifier device to further verify it to obtain a specific service.

[0195] Step 9. After receiving the signed identity credential presentation, the verifier device uses the public key of the issuer device to verify the signature and checks the content of the credential simultaneously to ensure the authenticity and legality of the credential.

[0196] The verification process of the verifier device is as follows:

[0197]

[0198] The verifier verifies the signature through DS.Verify(pk, σ, cre) to confirm that the credential has not been tampered with. Verifies the zero-knowledge proof π to ensure that the user's credential meets the expected conditions. The proof π verifies the consistency between some values in the credential and the publicly committed values, ensuring that the holder has a valid signature.

[0199] Step 10. The verifier device returns a verification success or failure message to the target client according to the verification result. If the verification is successful, the verifier device provides the corresponding service to the user; if the verification fails, the service is refused and the reason for the failure may be explained to the user.

[0200] In this embodiment, a processing device for user identity credentials is further provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be elaborated again. As used hereinafter, the term "module" may be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0201] This embodiment provides a processing device for user identity credentials, as Figure 5 shown, including:

[0202] An acquisition module 501, configured to acquire the initial identity credential currently received by the target client, where the target client is the client used by the target user who currently requests to provide a service, and the initial identity credential is generated by the issuer device according to the user identity attributes of the target user;

[0203] A generation module 502, configured to generate a symmetric identity credential based on the initial identity credential and send the symmetric identity credential to the issuer device through an anonymous channel, where the issuer device is used to verify the symmetric identity credential and sign the symmetric identity credential after the verification passes;

[0204] A receiving module 503, configured to receive a signed symmetric identity credential fed back by an issuer device;

[0205] A sending module 504, configured to send the signed symmetric identity credential to a verifier device, so that the verifier device verifies the signature and the symmetric identity credential, and feeds back a verification identifier to the target client when the signature and the symmetric identity credential pass the verification, where the verification identifier is used to request the server to provide services for the target client.

[0206] In an embodiment of the present application, an obtaining module 501 is specifically configured to obtain user identity attributes of a target client, and generate a certificate request based on the user identity attributes; send the certificate request to an issuer device, where the issuer device is configured to verify the user identity attributes carried in the certificate request, and if the user identity attributes pass the verification, feed back an initial identity credential to the target client; receive the initial identity credential fed back by the issuer device, where the initial identity credential is generated by the issuer device based on a pre-generated private key and system parameters, and the private key is the private key in the public-private key pair pre-generated by the issuer device.

[0207] In an embodiment of the present application, an obtaining module 501 is specifically configured to detect current metric data of key metrics of a secure transmission channel between the target client and the issuer device; analyze the network state of the secure transmission channel by using the current metric data of the key metrics; if the network state of the secure transmission channel is an available state, send the certificate request through the secure transmission channel; or, if the network state of the secure transmission channel is an unavailable state, obtain an encryption method corresponding to the target user, encrypt the certificate request by using the encryption method, and send the encrypted certificate request to the issuer device.

[0208] In an embodiment of the present application, an obtaining module 501 is specifically configured to obtain a security configuration file corresponding to the target user, where the security configuration file includes security requirements corresponding to the target user in different service scenarios; obtain service information of the service currently requested by the target user, and obtain a target service scenario in which the service information hits; obtain a target security requirement corresponding to the target service scenario from the security configuration file; obtain a target encryption algorithm corresponding to the target security requirement from an encryption algorithm library, and use the target encryption algorithm as the encryption method corresponding to the target user.

[0209] In an embodiment of the present application, a sending module 504 is specifically configured to detect the network environment where the target client is currently located and network security protection measures corresponding to the network environment; select a corresponding target transmission channel according to the network environment and the network security protection measures; send the signed symmetric identity credential to the verifier device through the target transmission channel.

[0210] In the embodiment of the present application, the sending module 504 is specifically configured to obtain a corresponding monitoring policy according to the channel type of the target transmission channel; monitor whether there is an abnormal situation during the process of the target transmission channel transmitting the symmetric identity credential carrying a signature according to the monitoring policy; if there is no abnormal situation, determine that the symmetric identity credential carrying a signature is successfully sent to the verifier device.

[0211] In the embodiment of the present application, the sending module 504 is specifically configured to, if the target transmission channel is an encrypted secure channel, detect the operating state of the channel encryption algorithm in the encrypted secure signal, and detect whether there is any abnormal use of the encryption key; obtain the check value synchronously generated during the process of sending the symmetric identity credential carrying a signature, and compare the check value with the check information fed back by the receiving end; if the operating state of the channel encryption algorithm is an error state, and / or there is any abnormal use of the encryption key, determine that there is an abnormal situation; or, if the operating state of the channel encryption algorithm is a correct state, and / or the encryption key is used normally, determine that there is no abnormal situation.

[0212] In the embodiment of the present application, the sending module 504 is specifically configured to, if the target transmission channel is an anonymous transmission channel, detect the jump path of the symmetric identity credential carrying a signature in the anonymous transmission channel, and obtain the activity conditions of each node in the jump path; analyze whether there is a target node with abnormal activity in the activity conditions of each node in the jump path; if there is a target node with abnormal activity, determine that there is an abnormal situation; or, if there is no target node with abnormal activity, determine that there is no abnormal situation.

[0213] In the embodiment of the present application, the device further includes: a processing module, configured to, if there is an abnormal situation, obtain the abnormal reason that causes the abnormal situation; obtain an alternative transmission scheme by using the channel type and the abnormal reason; and transmit the symmetric identity credential carrying a signature to the verifier device according to the alternative transmission scheme.

[0214] Please refer to Figure 6 , Figure 6 which is a schematic structural diagram of a computer device provided by an alternative embodiment of the present invention, as Figure 6As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting the components, including a high-speed interface and a low-speed interface. Each component communicates with each other using different buses and can be installed on a common motherboard or in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some alternative embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories. Similarly, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a set of blade servers, or a multi-processor system).

[0215] The processor 10 can be a central processing unit, a network processor, or a combination thereof. Among them, the processor 10 can further include a hardware chip. The above hardware chip can be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The above programmable logic device can be a complex programmable logic device, a field-programmable gate array, a generic array logic, or any combination thereof.

[0216] Among them, the memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiments.

[0217] The memory 20 can include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the computer device presented by a kind of mini-program landing page, etc. In addition, the memory 20 can include a high-speed random access memory and can also include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some alternative embodiments, the memory 20 can optionally include a memory remotely set relative to the processor 10, and these remote memories can be connected to the computer device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0218] The memory 20 can include a volatile memory, such as a random access memory; the memory can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid-state drive; the memory 20 can also include a combination of the above types of memories.

[0219] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or communication networks.

[0220] Embodiments of the present invention also provide a computer-readable storage medium. The method according to the embodiments of the present invention can be implemented in hardware, firmware, or be implemented as computer code that can be recorded on a storage medium, or be implemented as computer code that is originally stored in a remote storage medium or a non-transitory machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processes on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.

[0221] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A method for processing user identity credentials, characterized in that, The method includes: Obtaining an initial identity credential currently received by a target client, where the target client is a client used by a target user who currently requests to provide a service, and the initial identity credential is generated by an issuer device according to user identity attributes of the target user; Generating a symmetric identity credential based on the initial identity credential, and sending the symmetric identity credential to the issuer device through an anonymous channel, where the issuer device is used to verify the symmetric identity credential and sign the symmetric identity credential after the verification passes; Receiving the symmetric identity credential with a signature feedback by the issuer device; Sending the symmetric identity credential with a signature to a verifier device, so that the verifier device verifies the signature and the symmetric identity credential, and in the case where the signature and the symmetric identity credential pass the verification, feedbacks a verification identifier to the target client, and the verification identifier is used to request the server to provide a service for the target client.

2. The method according to claim 1, characterized in that, The obtaining the initial identity credential currently received by the target client includes: Obtaining user identity attributes of the target client, and generating a certificate request based on the user identity attributes; Sending the certificate request to the issuer device, where the issuer device is used to verify user identity attributes carried in the certificate request, and if the user identity attributes pass the verification, feedbacks an initial identity credential to the target client; Receiving the initial identity credential feedback by the issuer device, where the initial identity credential is generated by the issuer device based on a pre-generated private key and system parameters, and the private key is a private key in a public-private key pair pre-generated by the issuer device.

3. The method according to claim 2, characterized in that, The sending the certificate request to the issuer device includes: Detecting current metric data of key metrics of a secure transmission channel between the target client and the issuer device; Analyzing a network state of the secure transmission channel by using the current metric data of the key metrics; If the network state of the secure transmission channel is an available state, sending the certificate request through the secure transmission channel; or, if the network state of the secure transmission channel is an unavailable state, obtaining an encryption method corresponding to the target user, encrypting the certificate request by using the encryption method, and sending the encrypted certificate request to the issuer device.

4. The method according to claim 3, wherein The obtaining the encryption method corresponding to the target user includes: Obtaining a security configuration file corresponding to the target user, where the security configuration file includes security requirements corresponding to the target user in different service scenarios; Obtaining service information of a service currently requested by the target user, and obtaining a target service scenario hit by the service information; Obtaining a target security requirement corresponding to the target service scenario from the security configuration file; Obtaining a target encryption algorithm corresponding to the target security requirement from an encryption algorithm library, and using the target encryption algorithm as the encryption method corresponding to the target user.

5. The method according to claim 1, characterized in that, The sending the symmetric identity credential with a signature to the verifier device includes: Detect the network environment where the target client is currently located and the corresponding network security protection measures for the network environment; Select a corresponding target transmission channel according to the network environment and the network security protection measures; Send the symmetric identity credential with signature to the verifier device through the target transmission channel.

6. The method according to claim 5, characterized in that The step of sending the symmetric identity credential with signature to the verifier device through the target transmission channel includes: Obtain a corresponding monitoring policy according to the channel type of the target transmission channel; Monitor whether there is any abnormal situation during the process of the target transmission channel transmitting the symmetric identity credential with signature according to the monitoring policy; If there is no abnormal situation, it is determined that the symmetric identity credential with signature has been successfully sent to the verifier device.

7. The method according to claim 6, characterized in that, The step of monitoring whether there is any abnormal situation during the process of the target transmission channel transmitting the symmetric identity credential with signature according to the monitoring policy includes: If the target transmission channel is an encrypted secure channel, detect the running state of the channel encryption algorithm in the encrypted secure signal and detect whether there is any abnormal use of the encryption key; Obtain the check value synchronously generated during the process of sending the symmetric identity credential with signature, and compare the check value with the check information fed back by the receiving end; If the running state of the channel encryption algorithm is in an error state, and / or there is any abnormal use of the encryption key, it is determined that there is an abnormal situation; or, if the running state of the channel encryption algorithm is in a correct state, and / or the encryption key is used normally, it is determined that there is no abnormal situation.

8. The method according to claim 6, characterized in that, The step of monitoring whether there is any abnormal situation during the process of the target transmission channel transmitting the symmetric identity credential with signature according to the monitoring policy includes: If the target transmission channel is an anonymous transmission channel, detect the jump path of the symmetric identity credential with signature in the anonymous transmission channel to obtain the activity status of each node in the jump path; Analyze whether there is a target node with abnormal activity in the activity status of each node in the jump path; If there is a target node with abnormal activity, it is determined that there is an abnormal situation; or, if there is no target node with abnormal activity, it is determined that there is no abnormal situation.

9. The method according to claim 6, characterized in that, The method further includes: If there is an abnormal situation, obtain the abnormal reason that causes the abnormal situation; Obtain an alternative transmission scheme by using the channel type and the abnormal reason; Transmit the symmetric identity credential with signature to the verifier device according to the alternative transmission scheme.

10. A processing device for user identity credentials, characterized in that, The device includes: An acquisition module, configured to acquire the initial identity credential currently received by the target client, where the target client is the client used by the target user who currently requests to provide services, and the initial identity credential is generated by the issuer device according to the user identity attribute of the target user; A generation module, configured to generate a symmetric identity credential based on the initial identity credential and send the symmetric identity credential to the issuer device through an anonymous channel, where the issuer device is configured to verify the symmetric identity credential and sign the symmetric identity credential after the verification is passed; A receiving module, configured to receive the symmetric identity credential carrying a signature fed back by the issuer device; A sending module, configured to send the symmetric identity credential carrying the signature to the verifier device, so that the verifier device verifies the signature and the symmetric identity credential, and in the case that the signature and the symmetric identity credential are verified successfully, feeds back a verification identifier to the target client, and the verification identifier is used to request the server to provide services for the target client.

11. An identity authentication device, characterized in that, The identity authentication device includes: an issuer device and a verifier device; The issuer device is configured to receive the symmetric identity credential sent by the target client via an anonymous channel; verify the symmetric identity credential, and in the case that the symmetric identity credential is verified successfully, sign the symmetric identity credential; send the symmetric identity credential carrying the signature to the target client, so that the target client sends the symmetric identity credential carrying the signature to the verifier device, where the target client is the client used by the target user currently requesting services, the symmetric identity credential is generated according to the initial identity credential of the target user, and the initial identity credential is generated according to the user identity attribute of the target user; The verifier device is configured to receive the symmetric identity credential carrying the signature sent by the target client, and verify the signature and the symmetric identity credential; in the case that the signature and the symmetric identity credential are verified successfully, feed back a verification identifier to the target client, so that the target client requests the server to provide services according to the verification identifier.

12. A server, characterized in that, The server is configured to receive a service request sent by the target client, where the service request includes a service requirement and a verification identifier, the target client is the client used by the target user currently requesting services, the verification identifier is sent after the symmetric identity credential carrying the signature is verified successfully, the symmetric identity credential is generated according to the initial identity credential of the target user, and the initial identity credential is generated according to the user identity attribute of the target user; call service resources based on the verification identifier, obtain target resources corresponding to the service requirement from the service resources, and feed back the target resources to the target client.

13. An electronic device, characterized in that, Comprising: A memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the method according to any one of claims 1 to 9.

Citation Information

Cited By

  • Charging facility safety control method and device based on dynamic identity code and electronic equipment

    CN121418216A

  • A charging facility security control method and device based on a dynamic identity code and an electronic device

    CN121418216B