Identity endorsement generation method and management system

Through the identity sign generated on mobile terminals and computers, pattern recognition and information security algorithms are used to solve the problems of inconvenience and difficulty in identification of traditional certificates, and a convenient and secure universal identity certificate is achieved, preventing false certificates and impersonation, and protecting private information.

CN120281501APending Publication Date: 2025-07-08阳振庭
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411793639.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2017-12-26
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing traditional certificates are inconvenient in carrying and use, and have difficulty in identification and security defects. In particular, the problem of dispersed and unrelated identity information leading to counterfeiting and private information leakage. Although digital certificates provide user verification methods on the Internet, they are difficult to deploy and apply to general identity certificates for social members.

Method used

By using pattern recognition algorithms and information security key algorithms on mobile terminals and computers, an identity signature containing multiple information is generated, and a TLV compilation format is used, combining asymmetric key algorithms and notarization keys to realize the generation and management of identity signatures, supporting dynamic license application and private information protection.

Benefits of technology

It provides convenient and secure universal identity proof, prevents fake certificates and impersonation, protects private information, realizes close connection and easy identification of identity information, and is suitable for a wide range of equipment and scenarios, reducing the risk of document imitation and leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure HDA0005176084880000011
    Figure HDA0005176084880000011
  • Figure HDA0005176084880000012
    Figure HDA0005176084880000012
  • Figure HDA0005176084880000021
    Figure HDA0005176084880000021
Patent Text Reader

Abstract

The invention discloses an identity endorsement generation method and an identity endorsement management system. The identity endorsement generation method comprises the following steps: accepting an identity endorsement application, arranging identity endorsement members as an endorsement member combination according to the identity endorsement application, signing the endorsement member combination by using an asymmetric key algorithm and a notarization private key to obtain a digital signature, and configuring the digital signature to the endorsement member combination to obtain identity endorsement; the identity endorsement management system comprises a front-end application program and a background service program, the front-end application program comprises a user interface unit, an endorsement packaging unit, an endorsement affirmation unit and the like, and the background service program comprises an endorsement service center unit, a secret processing unit, a digital signature processing unit, a feature recognition unit, a data storage unit and the like. According to the method and the system, the problems of counterfeiting, private information leakage and the like caused by inconvenience in carrying and use, difficulty in identification, scattered information members and the like of the existing identity certificate are solved, and social harm caused by fake certificates or illegal certificates is prevented.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the Chinese patent with the invention title "A Method and System for Generating Identity Endorsements" filed on December 26, 2017, with the application number 201711443105.4.

[0002] Technical Field

[0003] The present invention relates to the field of digital identities, and particularly to a general digital identity endorsement. Background Art

[0004] The Internet Public Key Infrastructure (PKI) is a security system that provides network digital signature services and is responsible for asymmetric key and certificate management. The Certificate Authority (CA) is the core of PKI. A digital certificate is an electronic document issued by the CA and is used for user identification between both parties in end-to-end network communication. It provides a means for user verification between two predictable communication parties on the Internet, and the two predictable communication parties can use it to confirm each other. The core technology on which digital certificates rely is the asymmetric key algorithm technology. The asymmetric key algorithm uses a public key and a private key to encrypt and decrypt the information transmitted in the communication and verify digital signatures. The commonly used asymmetric key algorithm is the Ron Rivest, Adi Shamir, Len Adleman (RSA) algorithm. Currently, digital certificates have been widely used for user identification between both parties in Internet communication (for example, in the Hyper Text Transfer Protocol over Secure Socket Layer (HTTPS)). Both communication parties need to know and verify each other's digital certificates in advance, and each communication party needs to apply for and save its own certificate. Carrying, saving, and using separate digital certificates are all very cumbersome, and there is a high risk of leakage of the private key corresponding to the certificate. It cannot be used as a general identity certificate for the daily activities of social members. Moreover, a digital certificate is an electronic document, and what is encrypted is also an electronic document, which is extremely inconvenient in actual use, especially in on-site verification applications.

[0005] Existing traditional certificates such as ID cards, work permits, driver's licenses, graduation certificates, and qualification certificates are essential identity proofs for social members (such as organizations, natural persons, etc.) to conduct social activities. The information contained in traditional certificates is completely open and transparent and contains important private information. They inherently have usability problems such as inconvenience in carrying and use, and also have security flaws such as difficult identification (discrimination), easy imitation, easy to be misused, and leakage of private information due to the lack of simple and effective identification (discrimination) means. Moreover, traditional certificates generally have a fixed long-term validity and are used universally throughout. They lack effective dynamic controls such as on-demand permission applications, so it is very easy to be misused due to reasons such as the loss or borrowing of the certificate. At the same time, the various information in traditional certificates is discrete and isolated. In particular, the main identity representations of the certificate owner (such as face images, etc.) and identity identifiers (such as certificate numbers) are scattered and unassociated, which not only greatly reduces the reliability of the certificate but also makes the identification of the certificate more difficult and complex, and also makes it more difficult to prevent the misappropriation and imitation of ID certificates. Although with the development of electronic information technology and digital certificate technology, it provides new possible means for user verification between both parties in Internet communication, due to the professionalism and cumbersome use of digital certificates, it is difficult to deploy and apply them widely. Moreover, digital certificates applied to the Internet cannot be used as general identity proofs for social members. Traditional certificates are also developing towards chip cards, but since only special equipment can read the information on chip cards, it is not only inconvenient to carry and use, but also the cost of chip certificates and card readers is not low. It is difficult to fully deploy and use chip certificates for all people. Moreover, limited by existing chip technology, chip certificates also have the defect of no association between the main identity representations of the certificate owner (such as face images, etc.) and identity identifiers (such as certificate numbers). Chip certificates still have the problems of traditional paper certificates. Based on the above analysis, existing traditional certificates not only have the problem of inconvenience in carrying and use, but also the above-mentioned security flaws are easily exploited by lawbreakers. In particular, the leakage of private information and the difficulty in identifying certificates leading to misappropriation and imitation have seriously affected the normal social order and caused great harm to both social members and society.

[0006] Pattern recognition technology closely combines computers with means such as optics, acoustics, electronic sensors, and mathematical statistics principles, and uses the inherent internal and external perception attributes of things (such as fingerprints, face images, irises, eye patterns, handwriting, voices, etc.) to identify identities. Further, the pattern recognition system samples and analyzes the attributes of things, extracts their model features and converts them into digital code features or feature vectors, and uses these features for identification. For example: A fingerprint refers to the ridges and valleys on the front skin of the fingertips of a person. The ridges are regularly arranged to form different patterns. The starting points, ending points, joining points, and bifurcation points of the ridges are called the minutiae of the fingerprint. Fingerprint recognition means identifying by comparing the minutiae of different fingerprints. Face recognition extracts feature vectors from face images and identifies or discriminates by comparing or classifying the feature vectors.

[0007] A 2-dimensional code refers to a bar code that extends another dimension with readability on the basis of a 1-dimensional bar code. The information contained therein can be automatically read by an image input device or an optoelectronic scanning device. It is a black and white pattern distributed in a plane according to a certain rule by a specific geometric figure to record data symbol information; in code compilation, it cleverly uses the concept of "0" and "1" bit streams that form the internal logic basis of a computer, and uses several geometric shapes corresponding to binary to represent alphanumeric information. Common 2-dimensional code standards include PDF417, QR Code, Code49, Code 16K, Code One, etc. Since 2-dimensional codes have the characteristics of large capacity, strong error tolerance, and easy reading, it has become very simple and convenient to transfer and exchange data through 2-dimensional codes.

[0008] Chinese Patent 201710033091.2, "A Method and System for Unified Management of Identity Endorsements", provides (implements) a basic (fundamental) and general digital identity certificate and has achieved remarkable technical effects compared with existing traditional identity certificates. However, Patent 201710033091.2 still does not solve two core problems of general digital identity certificates: the inability to integrate identity information as a whole, especially the lack of association between identity representations (such as face images, etc.) and identity identifiers (such as certificate numbers), resulting in problems such as being misused and private information leakage. These two problems have always been the key difficulties that have long plagued general identity certificates. With the continuous development of information technology, it has become increasingly difficult to prevent identity theft, especially the harm caused by private information leakage is even more serious. The next-generation general identity certificate is required to be extremely reliable and have the characteristics of protecting privacy (private information). The present invention is a further invention based on Patent 201710033091.2, which solves the two core problems of identity certificates and meets the requirements of the next-generation general digital identity certificate.

[0009] To solve the problems of inconvenience in carrying and using (especially offline use) and security defects of existing traditional identity certificates such as physical certificates, and to protect the legitimate rights and interests of social members from being violated, the present invention provides a method and system for the general identity certificate of social members in their daily activities. The present invention not only provides the characteristics of being simple to use, tightly associated, extremely reliable, and easy to identify, but also further provides protection of private information (privacy) and / or protection applicable to dynamic permissions, which is more convenient and secure (reliable) than existing traditional identity certificates such as physical certificates, and prevents social harms caused by fake certificates or identity theft. Summary of the Invention

[0010] In view of the inconveniences in carrying and using existing traditional identity certificates and other identity proofs, as well as the difficulties in identification due to the lack of simple and effective identification means, and the inability to integrate and associate identity information members (scattered), especially the lack of association between identity representations and identity identifiers, etc., which lead to security defects such as being counterfeited and private information leakage. The purpose of the embodiments of the present invention is to utilize existing widely used ordinary mobile terminals, computers and other devices, as well as existing communication and interconnection networks, and use advanced information security key algorithms, pattern recognition algorithms, and technologies such as arrangement, association, and combination, in cooperation with parameters such as identity information and identity permission application rules, and notarization keys, to implement a method for generating identity endorsements and a management system for general identity proofs for the daily activities of social members. As a general identity proof, digital identity endorsements are not only more convenient, easy to use, secure and reliable than existing traditional identity certificates and other identity proofs, but also meet the extremely reliable and convenient requirements of the next-generation general identity proof, bringing great benefits to social members (the public) and society, and preventing social harms caused by the breeding of fake certificates or identity theft.

[0011] The above object is achieved through the following technical solutions:

[0012] The embodiments of the present invention provide a highly reliable (secure) and convenient digital identity endorsement. The identity endorsement is a byte stream (sequence) data that integrates multiple information members layout into one, used to prove identity or authorization permission matters. Identity endorsement members can be conveniently processed and implemented using compilation formats such as Type Length Value (TLV for short). The digital identity endorsement of the present invention is short and integrated, and can not only be directly encapsulated and used, but also be extended and converted into a visible character identity endorsement and grouped and converted into a two-dimensional code-based identity endorsement. The short and integrated identity endorsement is not only very convenient for use and carrying, but also not restricted by the carrier, and the identity endorsement of the present invention has wide applicability.

[0013] The above identity endorsement at least includes a legal identity identifier and a digital signature member. The legal identity identifier is an identity recognition identifier based on legal regulations for the identity endorsement subject (referred to as the signer). The legal identity identifier includes, but is not limited to, one or more of the legal name, legal license number, etc. The legal name includes the organization name, natural (individual) person name, etc. The legal license number includes the personal ID number, personal passport number, organization code, vehicle engine number, license plate number, etc.

[0014] The above-mentioned identity endorsement may further include one or more of the following members: identity permission application rules, operation control words, identity association (subject link) representations, appendix of endorsement items, civil affairs and people's conditions, etc. The identity permission application rules include one or more of the following: identity permission application level, identity permission application time domain, identity permission application region, identity permission application object, etc. The operation control words include one or more of the following, including but not limited to version number, identity endorsement length, asymmetric key algorithm type, hash algorithm type, indication of hidden private members, etc. The identity association representation refers to the distinguishable identity representation (such as face image, voice, fingerprint, handwriting, etc.) that is closely associated (linked) with the endorser in the identity endorsement. The identity association representation is further subdivided into identity association (subject link) perception representation, identity association (subject link) gene representation, identity association (subject link) extension representation, etc. The identity permission application level includes level one (identity verification and filing), level two (business identity bundling), etc. The rule of the identity permission application level is that the permission application level of the permission identity endorsement must not be lower than the endorsement level used by the authentication party (the default is level one). The above-mentioned identity association perception representation includes (is divided into) fingerprint, face image, voice, eye pattern, iris, vein pattern, handwriting, appearance, etc. The above-mentioned identity association gene representation (marking features) includes deoxyribonucleic acid (DNA for short), blood type, element arrangement and composition structure, etc. The above-mentioned identity association extension representation includes (is divided into) residential address, registered address, email address, private (individual) digital certificate signature, preset identity password, legal person information, contact information, trademark, bank account, etc. The above-mentioned identity permission application time domain refers to the effective time range for which the identity endorsement is permitted to be applied. The above-mentioned identity permission application region refers to the effective geographical range for which the identity endorsement is permitted to be applied. The appendix of endorsement items includes the explanatory statement appendix of the matters needing attention in the identity endorsement or the digest of the explanatory statement appendix of the matters needing attention in the identity endorsement. The identity permission application object includes the legal identity identifier, extended representation features, or identity endorsement of the purpose party or authorized party to which the identity endorsement is permitted to be applied.

[0015] The embodiment of the present invention uses a user (member) address. The user corresponds to a legal social member, and the legal social members include natural (individual) persons, organizations, etc. The social member can apply for an identity endorsement for himself or his legal affiliated entity, and his legal affiliated entity includes vehicles, real estate, etc., that is, the identity endorsement subject (referred to as the endorser) corresponds to or is associated with the social member or the legal affiliated entity of the social member.

[0016] The embodiment of the present invention uses a key (referred to as a notarization key) for uniformly notarizing (certifying) the identity endorsement. The notarization key includes a public-private key pair of a unified (pre-set) asymmetric key algorithm, and may further include a key of a unified symmetric key algorithm.

[0017] An embodiment of the present invention provides a method for generating an identity endorsement, including: accepting an identity endorsement application, arranging identity endorsement members, and signing identity endorsement members to obtain an identity endorsement.

[0018] Before the above-mentioned acceptance of the identity endorsement application, further including inputting the identity endorsement application. The specific implementation of the above-mentioned input of the identity endorsement application includes, but is not limited to, the user inputting the identity endorsement application through a front-end application (APP).

[0019] The above-mentioned input of the identity endorsement application includes inputting identity endorsement application information and distributing and processing the identity endorsement application information. Among them, the above-mentioned identity endorsement application information includes one or more of identity permission application rules, operation control words, annotation item appendices, civil affairs and public sentiment status indicators, etc. The above-mentioned operation control word information includes one or more of identity association (subject link) representation types, legal identity identification types, asymmetric key algorithm types, hash algorithm types, secret private member indicators, etc.

[0020] The above-mentioned distribution and processing of the identity endorsement application information includes: checking the identity endorsement application information, constructing an identity endorsement application communication protocol message, filling the identity endorsement application information into the identity endorsement application communication protocol message, and sending the identity endorsement application communication protocol message. The specific implementation includes, but is not limited to, the front-end application constructing an identity endorsement hypertext transfer protocol (HTTP) message, filling the identity endorsement application information into the identity endorsement application HTTP message, and sending the identity endorsement application HTTP message to the background service program through the Internet.

[0021] The above-mentioned acceptance of the identity endorsement application includes: receiving a generated identity endorsement application communication protocol message, parsing the identity endorsement application communication protocol message, and extracting the identity endorsement application information therefrom. The specific implementation includes, but is not limited to, the background service program receiving and parsing the identity endorsement application communication protocol message.

[0022] The above-mentioned arrangement of the identity endorsement members further includes: preparing the identity endorsement members according to the identity endorsement application and laying out the identity endorsement members as an endorsement member combination. The specific implementation includes, but is not limited to, the background service program arranging the identity endorsement members.

[0023] The above-mentioned preparation of the identity endorsement members according to the identity endorsement application includes: selecting an option source of the identity endorsement members from the retained identity information in the data storage unit or from the identity endorsement application information according to the identity endorsement application, and preparing the option source as the identity endorsement members.

[0024] The above-mentioned preparation of the option source into the identity endorsement members includes:

[0025] Compressing the option source and configuring the compressed result of the option source in TLV format as the identity endorsement members;

[0026] The mapping option source is an Internet address, and the Internet address is configured as an identity endorsement member;

[0027] Convert the option source, and configure the conversion result of the option source as an identity endorsement member;

[0028] Calculate the digest of the option source using a hashing algorithm, and configure the digest of the option source as an identity endorsement member;

[0029] Extract the feature vector (value) of the option source using a pattern recognition algorithm, and configure the feature vector of the option source as an identity endorsement member;

[0030] Supplement and align the option source, and configure the supplementary alignment result of the option source as an identity endorsement member;

[0031] Set the default option source, and configure the default option source as one or more of the following, such as an identity endorsement member.

[0032] The above-mentioned extraction of the feature vector (value) of the option source using a pattern recognition algorithm includes extracting one or more of the following feature vectors using a pattern recognition algorithm: face image, fingerprint, eye pattern, voice, handwriting, appearance, etc.

[0033] The above-mentioned pattern recognition algorithms include, but are not limited to, one or more combinations of image analysis and processing algorithms, image recognition algorithms, speech recognition algorithms, voiceprint recognition algorithms, etc. Among them, the image recognition algorithms include, but are not limited to, one or more combinations of deep learning algorithms, machine learning algorithms, model feature extraction algorithms, model feature classification algorithms, etc. The deep learning algorithms include neural network algorithms, convolutional neural network algorithms, etc. The machine learning algorithms include support vector machine algorithms, naive Bayes classifiers, decision trees, K-nearest neighbors, K-means, etc.

[0034] The above-mentioned extraction of the feature vector of the option source using a pattern recognition algorithm can be a pre-extracted identity perception representation feature stored in the identity information, that is, configure the feature of the identity perception representation attribute pre-extracted according to the pattern recognition algorithm to the identity endorsement member.

[0035] The above-mentioned calculation of the digest of the option source using a hashing algorithm includes calculating the digest of random values and passwords using a hashing algorithm.

[0036] The above-mentioned identity endorsement members include one or more of the following: legal identity identifier, license application rules, operation control word, identity association representation, annotation item appendix, civil affairs and people's conditions, etc. Among them,

[0037] The above-mentioned operation control word includes one or more of the following: version number, identity association representation type, legal identity identifier type, asymmetric key algorithm type, hashing algorithm type, secret private member indication, etc.;

[0038] The described identity - associated representation members include, but are not limited to, one or more of identity - associated perception representation, identity - associated gene representation, identity - associated extended representation, etc.;

[0039] The described civil affairs and public sentiment conditions include, but are not limited to, one or more of credit information, marital status, financial status, educational status, health status, legal status, ratings from other parties, red - black records, etc.

[0040] The above - mentioned option source for selecting identity endorsement members from the retained identity information or from the identity endorsement application information according to the identity endorsement application, and compiling the option source as identity endorsement members specifically may include:

[0041] Set the default endorsement version number and configure the version number as a version number member;

[0042] Select the operation control word information (source) from the identity endorsement application information and convert and configure the operation control word information as an operation control word member;

[0043] Select the identity - permission applicable rules information from the identity endorsement application information and convert and configure the identity - permission applicable rules information as an identity - permission applicable rules member;

[0044] Select the legal identity identifier from the retained identity information according to the identity endorsement application and configure the legal identity identifier as a legal identity identifier member;

[0045] Select the identity - associated representation from the retained identity information according to the identity endorsement application and configure the identity - associated representation as an identity - associated representation member, etc., one or more of them.

[0046] The above - mentioned selection of the identity - associated representation from the retained identity information according to the identity endorsement application and configuration of the identity - associated representation as an identity - associated representation member specifically may include:

[0047] Select the identity - associated representation features extracted by using the usage pattern recognition algorithm from the retained identity information according to the identity endorsement application and configure the identity - associated representation features as an identity - associated representation member;

[0048] Select the identity - associated representation attributes from the retained identity information according to the identity endorsement application, extract the identity - associated representation features by using the pattern recognition algorithm for the identity - associated representation attributes, and configure the identity - associated representation features as an identity - associated representation member;

[0049] Select the identity - associated representation attributes from the retained identity information according to the identity endorsement application, map the identity - associated representation attributes to a network address to obtain the identity - associated representation network address, and configure the identity - associated representation network address as an identity - associated representation member;

[0050] Select an identity password (option source) from the identity endorsement application information, use a hash algorithm to calculate the identity password to obtain an identity password summary, and configure the identity password summary as one or more of the identity password members.

[0051] The above-mentioned steps of selecting the applicable details of identity license from the identity endorsement application information and converting and configuring the applicable details of identity license into applicable details members of identity license further include but are not limited to: selecting the applicable time domain information of identity license from the identity endorsement application information and converting and configuring the applicable time domain information of identity license into applicable time domain members of identity license; selecting the applicable level information of identity license from the identity endorsement application information and converting and configuring the applicable level information of identity license into applicable level members of identity license; selecting the applicable object information of identity license from the identity endorsement application information and converting and configuring the applicable object information of identity license into applicable object members of identity license, etc.

[0052] The above-mentioned selecting identity-related characterization features from the retained identity information according to the identity endorsement application, and configuring the identity-related characterization features as identity-related characterization members further includes but is not limited to: selecting facial features from the retained identity information according to the identity endorsement application, and configuring the facial image representation as the identity-related facial image member, wherein the facial features are feature vectors pre-extracted from the facial image using an image (shape) recognition algorithm, and the image (shape) recognition algorithm includes but is not limited to a deep learning neural network algorithm;

[0053] The above-mentioned selecting identity-related characterization attributes from the retained identity information according to the identity endorsement application, extracting the identity-related characterization attributes using a pattern recognition algorithm to obtain identity-related characterization features, and configuring the identity-related characterization features as identity-related characterization members further include but are not limited to: selecting a facial image from the retained identity information according to the identity endorsement application, extracting facial features from the facial image using an image (shape) recognition algorithm, and configuring the facial image representation as an identity-related facial image member, wherein the image (shape) recognition algorithm includes but is not limited to a deep learning neural network algorithm, and the facial image features include but are not limited to an X-dimensional integer or decimal vector;

[0054] The above-mentioned arrangement of identity endorsement members into an endorsement member combination includes arranging and associating the identity endorsement members into an endorsement member combination according to a specified format or a default format. The specific implementation of the endorsement member combination is generally a digital byte stream (sequence).

[0055] The above-mentioned layout identity endorsement member is an endorsement member combination and can further include: a hidden (encrypted) identity endorsement member.

[0056] The above-mentioned stealth identity endorsement members include: stealth identity endorsement members that encrypt private identity endorsement members or combinations of endorsement members using symmetric or asymmetric key algorithms, and stealth identity endorsement members that calculate the digest of private identity endorsement members or combinations of endorsement members using a hashing algorithm and replace and update them. The above-mentioned private identity endorsement members include, but are not limited to, one or more of a legal name, a legal license number, etc. The above-mentioned stealth identity endorsement members are optional steps depending on the specific implementation.

[0057] The above-mentioned signature identity endorsement members obtaining an identity endorsement further includes: calculating a digital signature for the combination of endorsement members using an asymmetric key algorithm and a notarized private key signature, and configuring the digital signature into the combination of endorsement members (as the digital signature member of the identity endorsement) to obtain an identity endorsement. Obviously, the said identity endorsement is a digital byte stream (sequence) integrating multiple identity endorsement members. The above-mentioned asymmetric key algorithms include, but are not limited to, the Digital Signature Algorithm (DSA), the Elliptic Curve Cryptography Algorithm, etc.

[0058] After the above-mentioned signature identity endorsement members obtain an identity endorsement, it may further include: encapsulating the identity endorsement.

[0059] The above-mentioned encapsulating the identity endorsement may further include: one or more of converting the byte identity endorsement extension into a visible character identity endorsement, converting the identity endorsement grouping into a two-dimensional code-style identity endorsement, loading and processing the identity endorsement as a file, etc.

[0060] After the above-mentioned encapsulating the identity endorsement, it may further include: outputting the identity endorsement.

[0061] The above-mentioned outputting the identity endorsement includes one or more of displaying the identity endorsement, printing the identity endorsement, recording and storing the identity endorsement, etc. The specific implementation includes displaying a two-dimensional code-style identity endorsement or a visible character identity endorsement, printing a two-dimensional code-style identity endorsement or a visible character identity endorsement, recording and storing a two-dimensional code-style identity endorsement or a visible character identity endorsement or an identity endorsement file.

[0062] The embodiment of the present invention also provides a user registration method before the method for generating an identity endorsement, including: inputting a user registration application, accepting the user registration application, retaining the user identity information, responding to the user registration result, and outputting the user registration result.

[0063] The above input user registration application includes inputting user registration information and distributing and processing the user registration application. The above distribution and processing of the user registration application includes: checking the user registration information, constructing a communication protocol message for the user registration application, filling the user registration information into the communication protocol message for the user registration application, and sending the communication protocol message for the user registration application. The user registration information includes one or more of the user login password, user identification, identity information associated with the social member corresponding to the user, etc. The identity information associated with the social member includes one or more of a perceptual representation attribute or feature, a genetic representation feature, an extended representation feature, a legal identity identifier, a civil affairs and people's conditions, etc. The specific implementation includes, but is not limited to, the user inputting the user registration information and distributing and processing the user registration application through a front-end application (APP).

[0064] The above acceptance of the user registration application includes receiving the user registration application message sent by the user, parsing the user registration application message, extracting the user registration information, and sorting out the user registration information. Among them, the sorting out of the user registration information includes one or more of format conversion, encryption, cropping, compression, etc. of the user information.

[0065] The above retention of user identity information includes mapping the sorted user information into user identity information and storing it in a data unit.

[0066] The above retention of user identity information further includes using a pattern recognition algorithm to extract perceptual representation features from the perceptual representation attributes, and then mapping the perceptual representation features into user identity information and storing it in a data storage unit. Specifically, it includes, but is not limited to, using an image (shape) recognition algorithm to extract face features from a face image, and then storing the face features into the user identity information in the data storage unit.

[0067] The above response to the user registration result includes constructing a communication protocol message for the user registration result, filling the user registration result into the communication protocol message, and sending the user registration result message.

[0068] The above output of the registration result includes displaying the user registration result on the user interface.

[0069] After the above user registration, it further includes user review processing. The user review processing includes reviewing the user identity information provided and retained during user registration. Among them, the review includes manual confirmation review, service program assisted review, etc.

[0070] The embodiment of the present invention also provides an identity endorsement identification method after the identity endorsement generation method, including: inputting the identity endorsement, verifying the digital signature of the identity endorsement, identifying the endorser associated with the identity endorsement, defining the applicable rules of the identity permission, and outputting the identification result.

[0071] The above-mentioned input identity endorsement includes reading the identity endorsement using devices such as cameras, Bluetooth, and keyboards.

[0072] The above-mentioned verification of the digital signature of the identity endorsement includes using the asymmetric cryptographic algorithm specified or defaulted by the operation control word of the identity endorsement and the notarized public key to verify the digital signature of the identity endorsement.

[0073] The above-mentioned identification of the signatory associated with the identity endorsement includes identifying and confirming whether the identity-associated representation matches the signatory. The specific identification and confirmation implementation includes manual identification and confirmation and / or program-assisted identification and confirmation. The above-mentioned program-assisted identification and confirmation includes perceptual representation feature matching identification, password matching confirmation, etc. The above-mentioned perceptual representation feature matching identification includes, but is not limited to, capturing the facial image of the signatory, extracting facial features from the facial image using an image (shape) recognition algorithm, and matching the extracted facial features with the identity-associated representation of the identity endorsement. The above-mentioned image (shape) recognition algorithm includes, but is not limited to, the neural network algorithm of deep learning.

[0074] The above-mentioned definition of the applicable rules for identity permission includes verifying one or more of the applicable level of identity permission, the applicable time domain of identity permission, the applicable region of identity permission, the applicable object of identity permission, etc. This step is an optional step depending on the specific implementation.

[0075] The above-mentioned output of the authentication result includes displaying or recording the authentication result. The above-mentioned authentication result includes recording the authentication success and the authentication time or displaying the authentication failure and the reason for the failure.

[0076] The embodiment of the present invention also provides a method for decrypting an identity endorsement after the method for generating an identity endorsement, including: inputting a decryption application for the identity endorsement, accepting the decryption application for the identity endorsement, verifying the digital signature of the identity endorsement, decrypting the encrypted (ciphertext) identity endorsement member of the identity endorsement, responding to the decryption result of the identity endorsement, and outputting the decryption result of the identity endorsement.

[0077] The above-mentioned input of the decryption application for the identity endorsement includes inputting the identity endorsement and then submitting the decryption application for the identity endorsement. The above-mentioned input of the identity endorsement includes reading the identity endorsement using an optical device such as a camera. The above-mentioned submission of the decryption application for the identity endorsement includes constructing a decryption application message for the identity endorsement, filling the identity endorsement into the decryption application message for the identity endorsement, and sending the decryption application message for the identity endorsement.

[0078] The above-mentioned acceptance of the decryption application for the identity endorsement includes receiving the decryption application message for the identity endorsement and parsing the decryption application message for the identity endorsement to obtain the identity endorsement.

[0079] The above-mentioned acceptance of the decryption application for the identity endorsement further includes detecting whether the user of the decryption application for the identity endorsement has the authority to decrypt the identity endorsement.

[0080] The above-mentioned identity endorsement digital signature verification includes using the operation control word of the identity endorsement to specify or default asymmetric cryptographic algorithms and notarized public keys to verify the digital signature of the identity endorsement.

[0081] The above-mentioned decryption of the encrypted (ciphertext) identity endorsement members of the identity endorsement includes using the key algorithm and the notarized key pair to perform decryption calculations on the encrypted (ciphertext) identity endorsement members to obtain the plaintext of the encrypted (ciphertext) identity endorsement members.

[0082] The above-mentioned response to reveal the identity endorsement result specifically includes the background system constructing a response message, filling the revealed identity endorsement result into the message, and sending the message to the front-end APP.

[0083] The above-mentioned output of the revealed identity endorsement result specifically includes receiving the revealed identity endorsement result message, parsing the message, extracting the revealed identity endorsement result, and outputting the revealed identity endorsement result information.

[0084] The embodiment of the present invention also provides an identity endorsement generation system, including: a front-end application program and a background service program, which are connected using a communication network, where,

[0085] The above-mentioned front-end application program includes a user interface unit and an endorsement encapsulation unit, where,

[0086] The above-mentioned user interface unit is used for inputting user registration, user login, identity endorsement and other application information, distributing and processing the received application information, and outputting the application processing results of user registration, user login, identity endorsement, etc.

[0087] The above-mentioned endorsement encapsulation unit is used for encapsulating the identity endorsement, specifically including expanding and restoring the identity endorsement byte code or marshaling and translating the identity endorsement QR code. The above-mentioned expanding and restoring the identity endorsement byte code includes expanding and converting the byte identity endorsement into a visible character identity endorsement or restoring and converting the visible character identity endorsement into a byte identity endorsement. The above-mentioned marshaling and translating the identity endorsement QR code includes marshaling the byte or visible character identity endorsement into a QR code identity endorsement and translating the QR code identity endorsement into a byte or visible character identity endorsement.

[0088] The above-mentioned background service program includes an endorsement service center unit, a confidentiality (encryption / decryption) processing unit, a digital signature processing unit, and a data storage unit, where,

[0089] The above-mentioned endorsement service center unit is used for accepting user registration, user login, identity endorsement and other applications, distributing and processing the applications, and responding to the application processing results, where,

[0090] The above-mentioned application acceptance includes receiving application messages such as user registration, user login, and identity endorsement sent by users, parsing the application messages, and extracting application information such as user registration, user login, and identity endorsement.

[0091] The above-mentioned distribution and processing of registration applications includes sorting out user registration information and retaining user identity information. The retention of user identity information includes mapping the sorted user information into user identity information and storing it in a data unit.

[0092] The above-mentioned distribution and processing of login applications includes managing the session status information of user logins and enabling tracking and detection of user connection status.

[0093] The above-mentioned distribution and processing of identity endorsement applications includes arranging identity endorsement members, notifying (invoking) the stealth processing unit to stealth the identity endorsement members, and notifying (invoking) the digital signature processing unit to sign the identity endorsement members. The arrangement of identity endorsement members includes: compiling identity endorsement members according to the identity endorsement application and laying out the identity endorsement members as an endorsement member combination.

[0094] The above-mentioned endorsement service center unit further includes managing the notarization keys used by the system, including the key pair (private key and public key) of the asymmetric key algorithm, and may also include the symmetric key algorithm key.

[0095] The above-mentioned stealth processing unit is used to encrypt or decrypt identity endorsement members or calculate the digest of identity endorsement members.

[0096] The above-mentioned digital signature processing unit is used to sign identity endorsement members using the asymmetric key algorithm and the notarization private key.

[0097] The above-mentioned data storage unit is used to store user identity information, and the user identity information includes one or more of user identification, registration time, login password, applicable endorsement level, legal identity identification, perceptual representation characteristics and / or attributes, genetic representation (mark) characteristics, extended representation characteristics, civil affairs and public sentiment conditions, etc.

[0098] The above-mentioned background service program may further include a feature recognition unit. Among them, the feature recognition unit is mainly used to recognize the characteristics of perceptual representation attributes using pattern recognition algorithms.

[0099] The above-mentioned pattern recognition algorithm for recognizing the characteristics of perceptual representation attributes includes using the pattern recognition algorithm to extract feature vectors of one or more of the attributes such as face image, fingerprint, voice, eye pattern, iris, and handwriting.

[0100] The above-mentioned identity endorsement generation system further includes an identity endorsement authentication system, and the identity endorsement authentication system includes an endorsement recognition unit. The endorsement recognition unit is used to authenticate identity endorsements, and the authentication of identity endorsements includes verifying the digital signature of the identity endorsement, identifying the endorser associated with the identity endorsement, and defining the applicable rules of identity permission.

[0101] The user interface unit of the front-end application program of the above system is further used to input identity endorsement authentication information, distribute and process identity endorsement authentication information, and output the processing result of identity endorsement authentication.

[0102] The identity endorsement authentication system including the endorsement recognition unit specifically further includes that the front-end application program of the above system includes an endorsement recognition unit. The front-end application program may further include a feature (pattern) recognition unit, and the feature recognition unit is used to recognize the features of the perceptual representation attributes by using pattern recognition algorithms.

[0103] The endorsement recognition unit of the above front-end application program further includes a pre-set asymmetric key algorithm notarized public key.

[0104] The input of identity endorsement authentication information includes reading identity endorsements using devices such as cameras, Bluetooth, and keyboards.

[0105] The input of identity endorsement authentication information further includes reading the perceptual representation attributes of the endorser of the identity endorsement, and the perceptual representation attributes include but are not limited to face images.

[0106] The distribution and processing of identity endorsement authentication information includes the user interface unit notifying (invoking) the endorsement recognition unit to authenticate identity endorsements.

[0107] The distribution and processing of identity endorsement authentication information may further include the user interface unit notifying (invoking) the feature (pattern) recognition unit to use pattern recognition algorithms to recognize the features of the perceptual representation attributes.

[0108] The identity endorsement authentication system including the endorsement recognition unit specifically may further include that the background service program of the above system includes an endorsement recognition unit.

[0109] The above-mentioned identity endorsement generation system further includes an identity endorsement decryption system, where

[0110] The user interface unit of the above front-end application program is further used to input identity endorsement decryption application information, distribute and process identity endorsement decryption application information, and output the processing result of identity endorsement decryption application.

[0111] The above endorsement service center unit is further used to accept identity endorsement decryption applications, distribute and process identity endorsement decryption applications, and respond to the processing results of identity endorsement decryption applications.

[0112] The above-mentioned acceptance of identity endorsement decryption application includes receiving the identity endorsement decryption application message sent by the user, parsing the application message, and extracting application information such as identity endorsement.

[0113] The above-mentioned acceptance of identity endorsement decryption application further includes detecting whether the user who decrypts the identity endorsement application has the authority to decrypt the identity endorsement.

[0114] The above-mentioned stealth processing unit is further used to perform decryption calculation on the encrypted (ciphertext) identity endorsement member using the key algorithm to obtain the plaintext of the encrypted (ciphertext) identity endorsement member.

[0115] It can be seen from the technical solutions provided by the embodiments of the present invention above that the embodiments of the present invention provide a method for generating an identity endorsement and a management system. By developing and deploying new applications on existing mobile terminals, computers, and communication interconnected networks, and making full use of the existing widely used devices, the present invention reasonably and effectively solves the problems existing in existing traditional identity certificates such as inconvenient carrying and use, and security defects such as being counterfeited and private information leakage caused by difficult identification and scattered information members. It overcomes the contradiction between private information and identity authentication (proof) and traceability, and achieves extremely beneficial technical and social effects. The identity endorsement of the embodiments of the present invention is short and integrated, and can be used as an additional anti-counterfeiting function or anti-counterfeiting code for traditional identity certificates; it can also replace traditional identity certificates and be used alone as a general identity certificate. The present invention not only achieves the technical effect of an integrated identity certificate that is simple to use, tightly associated, extremely reliable, and easy to identify (distinguish), but also further achieves the technical effects of private information protection and / or dynamic (i.e., sign-on-use) permission application protection, as well as an integrated identity certificate that is simple to use, tightly associated, extremely reliable, and easy to identify. The present invention not only obtains an inseparable integrated identity certificate, but also achieves the technical effect of an inseparable integrated identity certificate. The present invention not only facilitates the daily identity authentication of social members, greatly reduces the harm to society caused by identity privacy leakage and identity fraud, but also greatly reduces the cost of social production management of physical identity certificates. BRIEF DESCRIPTION OF THE DRAWINGS

[0116] Figure 1 It is an embodiment diagram of the system application environment and functions of the present invention;

[0117] Figure 2 It is an embodiment diagram of the method steps for user registration of the present invention;

[0118] Figure 3 It is an embodiment diagram of the method steps for generating an identity endorsement of the present invention;

[0119] Figure 4 It is an embodiment diagram of the steps for authenticating an identity endorsement of the present invention;

[0120] Figure 5This is an example diagram of the steps for revealing the identity endorsement of the present invention; Detailed implementation manners

[0121] The following describes and explains the implementation manners of the present invention in detail with reference to the accompanying drawings.

[0122] First, introduce the system for generating identity endorsements, that is, the application environment and functional modules of the present invention. Please refer to the attached Figure 1 .

[0123] The system for generating or managing the identity endorsement of the present invention includes a front-end application (Application, abbreviated as APP) and a back-end service program (abbreviated as the back-end system). The front-end APP host includes terminals such as mobile phones or personal computers, and the back-end system host includes computer servers or personal computers, etc. The front-end APP includes at least a 1001 user interface unit, and further may include a 1002 endorsement encapsulation unit or a 1003 endorsement recognition unit. The back-end system includes a 1014 endorsement service center unit, a 1015 encryption (or encryption / decryption) processing unit, a 1016 digital signature processing unit, a 1017 data storage unit, a 1018 feature recognition unit (or pattern recognition unit). The 1002 unit can be located in the front-end APP or the back-end system depending on the specific implementation. Therefore, the back-end system may further include the 1002 unit depending on the specific implementation. The front-end APP is generally integrated and implemented or deployed as a whole. The specific implementation program includes a mobile terminal APP, a computer program, or a web program running on browser software, etc. The back-end system is the management service center of the system, and each functional unit can be implemented and deployed separately or integrally. The specific implementation program includes an Internet website back-end system, an application server program, or a database program, etc. The 1017 unit is generally deployed separately, and the specific implementation program includes a database or a disk data file, etc. The front-end APP and the back-end system are connected through a communication network such as the Internet and communicate using a communication protocol. For example: Hypertext Transfer Protocol (abbreviated as HTTP) or HTTPS protocol. The functional units of the back-end system communicate with each other according to the actual deployment using local operating system call interfaces or protocols such as Transmission Control Protocol / Internet Protocol (abbreviated as TCP / IP). The front-end APP, the back-end system, and each functional unit support and cooperate with each other to generate and manage the identity endorsement, constituting the basic operating system and environment of the system of the present invention.

[0124] Unit 1001 is responsible for receiving input information, distributing and processing the received input information, and outputting the processing results. Receiving input information includes receiving user input information and network interface input information. Network interface input information includes response or detection messages sent by the background. User (or member) input information includes user registration applications, user login applications, generation of identity endorsements applications, disclosure of identity endorsements applications, verification of identity endorsements applications, querying local identity endorsements, deleting local identity endorsements, etc. The distribution and processing of the received generation of identity endorsements applications input includes: checking the input information of the identity endorsements application, constructing a communication protocol message for the generation of identity endorsements application, filling the input information of the identity endorsements application into this message, and sending this message, etc. Outputting the processing results includes storing the result information, printing the result information, displaying the result information, forwarding the result information, playing the result information, etc. The specific implementation of user input information includes inputting a QR code through an optical device, reading information through Bluetooth or Wi-Fi connection, reading information through the Global Positioning System (GPS), information input by the user keyboard, information read through a mobile network, information read through a microphone, etc. Forwarding information includes sending information to the destination through a communication protocol using Bluetooth or Wi-Fi or a mobile network, and playing information includes playing audio using a speaker.

[0125] Unit 1002 is used for one or more of expanding and restoring bytecodes, grouping and translating QR codes, loading and processing, etc. Expanding and restoring bytecodes includes expanding and converting byte identity endorsements into visible character identity endorsements or restoring visible character identity endorsements into byte identity endorsements. Grouping and translating includes grouping identity endorsements into QR codes or translating QR codes into identity endorsements. For example: expanding and converting byte identity endorsements into visible character identity endorsements, and the expansion and restoration rules include Base64, etc.; grouping identity endorsements into QR codes or translating QR code identity endorsements into identity endorsements, and the grouping and translation standards include PDF417, QR Code, etc. Loading and processing includes processing identity endorsements into pictures or files in a specified format, encapsulating them into QR codes or visible character identity endorsements, which can break through the limitations of electronic documents and be printed on physical objects, and can be read through devices including cameras, etc., greatly facilitating daily communication and use.

[0126] Unit 1003 is responsible for authenticating identity endorsements. Unit 1001 activates the corresponding device to receive the input of identity endorsements. For example, it activates the camera to read the QR code identity endorsement and then hands the identity endorsement to Unit 1003 for processing. Authenticating identity endorsements includes verifying the digital signature of the identity endorsement, identifying the associated signatory (identity endorsement subject) of the identity endorsement, and defining the applicable rules for identity permissions of the identity endorsement. The specific implementation of verifying the digital signature of the identity endorsement is to decrypt and calculate the digital signature members according to the asymmetric key algorithm and the pre-set notarized public key to obtain the signature digest. Calculate the verification digest according to the hash algorithm for all member combinations except the digital signature. If the signature digest and the verification digest are consistent, the digital signature verification is successful or passes. The above-mentioned asymmetric key algorithms include, but are not limited to, the Digital Signature Algorithm (DSA for short), the Elliptic Curves Cryptography (ECC for short) algorithm (for example: ECC(Ed)25519 algorithm or the national cryptographic SM2), etc. The RSA algorithm is theoretically feasible, but it is not actually recommended; the hash algorithms include, but are not limited to, the Message Digest (MD for short), the Secure Hash Algorithm (SHA for short) algorithm, etc. Unit 1003 can preset the digital certificate of the system or the notarized public key of the unified asymmetric key algorithm of the system during deployment according to the specific implementation. This notarized public key is publicly and uniformly used to prove the identity endorsement.

[0127] Unit 1014 is used to accept applications such as user registration, login, identity endorsement, and decrypting identity endorsements, distribute and process the above applications, and respond to the application processing results. Accepting applications includes receiving the application messages sent by users, parsing the application messages, and extracting application information. Distributing and processing the above applications includes calling the relevant units for processing according to the application type. For example: The registration application includes sorting out the user registration information and retaining the user identity information according to the user registration information; distributing and processing the login application includes recording the session status information after the user logs in, activating tracking and detecting the user session status such as using the Cookie technology, the keep-alive mechanism, the background session aging mechanism, etc., and performing user logout processing when detecting that the user connection status is interrupted (for example, closing the keep-alive detection and clearing the user session status information cache). Unit 1014 is also responsible for managing (presetting) the unified notarized keys of the system, including the symmetric key algorithm key and the key pair (private key and public key) of the asymmetric key algorithm.

[0128] The 1015 unit is used to encrypt or decrypt (hide) the identity endorsement members. The specific implementation of encryption or decryption (hiding) can be achieved using symmetric key algorithms or asymmetric key algorithms. It can also use a hash algorithm to calculate the digest of the private members of the identity endorsement or the private members of the endorsement member combination and replace the value of the private members with the digest. Symmetric key algorithms include, but are not limited to, the Advanced Encryption Standard (AES), Rivest Code (RC) algorithm, ChaCha algorithm, etc. The private members (information) generally include personal ID numbers, passport numbers, organization codes, vehicle engine numbers, names, etc. The same key is used for encryption and decryption with symmetric key algorithms, and public key encryption and private key decryption are used for encryption and decryption with asymmetric key algorithms.

[0129] The 1016 unit is responsible for digital signature or verification of identity endorsement. The signature or verification uses an asymmetric key algorithm. For example: First, calculate the signature digest for the members (endorsement member combination) of the laid-out identity endorsement, and then use the private key to calculate the digital signature value according to the asymmetric key signature algorithm for the signature digest, and configure the digital signature value as the digital signature member and layout it at the end of the members of the laid-out identity endorsement. Verifying the identity endorsement includes using an asymmetric key algorithm to verify the digital signature of the identity endorsement.

[0130] The 1017 unit is mainly used to store user identity information. User identity information includes user identification, registration time, login password, applicable endorsement level, identity identification, perceptual representation features or attributes, genetic representation (marker) features, extended representation features, civil affairs and people's conditions, etc. Identity identification refers to the identity identification mark based on legal regulations for the identity endorsement subject. Perceptual representation features or attributes, genetic representation features, and extended representation features refer to the distinguishable representations of the signatory. The specific implementation of the data storage unit can be a database program or a custom data file. The user identity information is stored in the database or file in the form of a table (table). For example, the data storage unit is implemented as an Oracle or MySQL database, and the user identity information is queried or updated through Structured Query Language (SQL). The user identity information stored in the data storage unit cannot be viewed without authorization and is strictly confidential. The 1017 unit can further cache the login session status information of the user, such as: login time, login location, session identification, user identification, etc.

[0131] Unit 1018 is mainly used to extract, identify or classify the feature vectors of the perceptual representation attributes using pattern recognition algorithms. The pattern recognition algorithms include, but are not limited to, image analysis and processing algorithms, image (shape) recognition algorithms, speech recognition algorithms, voiceprint recognition algorithms, etc. The image analysis and processing algorithms include denoising processing, grayscale processing, etc. The image (shape) recognition algorithms include, but are not limited to, deep learning algorithms, machine learning algorithms, model feature extraction algorithms, model feature classification algorithms, etc. The speech and voiceprint recognition algorithms include neural network deep learning algorithms, mathematical equation model algorithms, etc. The mathematical equation model algorithms specifically include: Hidden Markov Model (HMM), Gaussian Mixture Model (GMM) algorithms, etc. The deep learning algorithms for graphic recognition include Convolutional Neural Network (CNN), etc. The machine learning algorithms for graphic recognition include Support Vector Machine (SVM), AdaBoost algorithm, etc. The model feature extraction algorithms for graphic recognition include Histogram of Oriented Gradient (HOG) feature algorithm, Local Binary Pattern (LBP), Haar algorithm for template features, geometric feature method, Local Face Analysis (LFA), Eigen-face method, etc. The model feature classification algorithms for graphic recognition include Bayesian network, decision tree, K-Nearest Neighbor (K-NN), K-Means (k-means), etc. For example: The face recognition method based on deep learning means inputting a face image into a neural network, and obtaining an X-dimensional feature vector through the calculation of the neural network. The X-dimensional feature vector can represent a specific face. Face image identification can simplify the comparison of the Euclidean distance of the X-dimensional vector. The neural network is a pre-trained mathematical model. Inputting a face image into the neural network can output an X-dimensional feature vector. The fingerprint recognition method includes performing image analysis and processing on the noise points of the fingerprint image to obtain the contour lines (ridge lines, valley lines) of the fingerprint image, and extracting the feature information such as the starting point, ending point, joint point, and bifurcation point of the contour lines.

[0132] Through the above-mentioned identity endorsement generation system, user identity information and identity license application details are organized into identity endorsement members, and the endorsement members are combined, associated and integrated to generate an identity endorsement for general identity proof. Social members registered as users use and manage identity endorsements through the identity endorsement system. This identity endorsement not only realizes dynamic (ready-to-use and sign-on) license application protection and simple, easy-to-use, tightly associated, highly reliable and easy-to-identify integrated identity proof, but also, by secretly associating the private members of the identity endorsement, the identity endorsement does not contain public private identity information, and further achieves private information protection and dynamic license application protection as well as simple, easy-to-use, tightly associated, highly reliable and easy-to-identify integrated identity proof, which effectively prevents imitation and counterfeiting by criminals and effectively solves the defects in the use of existing identity proofs such as traditional certificates.

[0133] The following describes the operating steps and related operations of the present invention in detail through embodiments and in combination with the above system.

[0134] Attached Figure 2 Describes the steps for social members to register as users in the system, including:

[0135] Step S2001, input registration application. Receive user registration information application input, distribute and process the above-mentioned received user registration application input. The 1001 unit of the front-end APP receives the user registration information input by the user, the user registration information includes the user login password, user identification, the identity information associated with the social member corresponding to the user, etc. The identity information associated with the social member includes the perceptual representation attribute or feature, the gene representation (marker) feature, the extended representation feature, the legal identity identification, the civil affairs and public sentiment, etc., the received registration information is format checked, the assignment range is checked, etc., the user registration application communication protocol message is constructed according to the communication protocol, the registration information is filled into the user registration application communication protocol message, and then the message is sent to the background system through the HTTPS and other protocols. For example, a social member opens the registration webpage provided by the system of the present invention or opens the mobile terminal application through a browser, and inputs the user login password, user identification, extended representation feature, legal identity identification, body shape, blood type, civil affairs and public sentiment, etc. through the keyboard, and reads the face image or picture of the social member corresponding to the user through the camera or reads the fingerprint image or graphic through the fingerprint identifier, and submits the registration application after completing the input of the registration information. Perceptual representations include facial image, body shape, voice, fingerprints, handwriting, etc.; genetic representation features include blood type, DNA, etc.; extended representation features include address, telephone number, ID password, bank account, etc.; legal identity identification includes the user's corresponding social member's name or name, ID card number, etc.; civil affairs and public sentiment status includes marital status (married or unmarried), legal status (whether there is a criminal record), degree status (highest academic degree), physical health status, etc.

[0136] Step S2002, accept the registration application. Receive the registration application message sent by the user, parse the registration application message, extract the user registration information, and organize the user registration information. The 1014 unit of the background system receives, analyzes, and extracts the user registration information, and organizes the user registration information. The organization includes format conversion, encryption, cropping, compression, initialization of default values, etc. For example: perform format conversion on the date in the user registration information, encrypt the private information of the user's identity (such as ID number, bank account number, etc.), compress the address in the user registration information, and crop, perform format conversion, and compress the image in the user registration information. Initializing default values includes initializing information such as the user registration time.

[0137] Step S2003, retain the user identity information. Map the organized user registration information above to user identity information and store it in the data storage unit. The 1014 unit of the background system sends the user registration information to the 1017 unit, and the 1017 unit stores the user registration information as user identity information. Storing the user identity information also includes initializing the user's creditworthiness, etc. For example, the 1014 unit maps the user registration information to an update command statement in SQL language and executes the command statement to store it in the database of the 1017 unit. Retaining the user identity information can further include using a pattern recognition algorithm to extract the feature vector of the perceptual representation attribute from the perceptual representation attribute, and then storing the feature vector of the perceptual representation attribute in the data storage unit. For example: the 1014 unit notifies the 1018 unit to use an image (shape) recognition algorithm (such as: neural network algorithm in deep learning) to extract the face features from the face image, and then store the face features.

[0138] Step S2004, respond to the registration result. After the 1014 unit of the background system stores the user registration information, it returns the registration result to the front-end APP. At the same time, it can start the audit start time, and then perform user login processing: record or cache the user login session status information (such as: login time, user identification, session identification), and then start the survival detection to track and monitor the user connection session status. If it is detected that the user is offline or the user logs out, or the user session timed aging mechanism times out, then perform user logout or cancellation processing: close the user session and clear the user login session status cache. The 1014 unit constructs a registration result communication protocol message, fills the registration result into the communication protocol message, and sends the registration result message to the front-end APP.

[0139] Step S2005, output the registration result. After the front-end APP receives the registration application result returned by the back-end system, it outputs the result and displays it to the user for user login processing: records the user login session status information used to construct the communication protocol message, and then starts the survival detection to track and monitor the user connection session status. The 1001 unit receives the registration result message, parses the registration result message, extracts the registration result, and displays the registration result on the end-user interface.

[0140] The above embodiments describe the process of social members registering as system users, which is a prerequisite for subsequent user audits and applications for identity endorsements. The registered user identity information provides information support for subsequent user audits and applications for identity endorsements.

[0141] After the above user registration is completed, the back-end system starts the user audit process according to the specific implementation. The user audit process includes auditing various (user identity) information provided and retained by the user, especially the identity information associated with the social member corresponding to the user. The user audit process is generally executed in the background. The user audit process includes manual confirmation audits, service program-assisted audits, etc. The specific methods of manual confirmation audits include remote video audits, information investigations, auditing individual digital certificate signatures, on-site door-to-door face-to-face confirmations, etc. Manual confirmation audits also include recording and storing audit materials such as videos, images, and audio. Service program-assisted audits include connecting to third parties (such as government agency identity information databases, degree and academic certificate databases, banks, etc.) for assisted audits and remote reading of perceptual characterization attribute verification audits. For example, the service program-assisted audit program transfers a secret value amount to the bank account registered by the user or sends a secret verification code to the mobile phone registered by the user, and then checks the user's reply confirmation, etc. Remote reading of perceptual characterization attribute verification includes remotely reading face images, voice audio, etc., and transmitting the read perceptual characterization attribute to the back-end. The back-end compares or matches and identifies the attribute with the corresponding attribute stored on file. After the user audit, the user's applicable endorsement level can be further set according to the user identity information (default is identity verification on file). The applicable endorsement level is used to classify and manage the identification permission applicable levels of identity endorsements. After the user audit is completed, an identity endorsement can be applied for. The user audit is the prerequisite and foundation for ensuring the generation of valid and reliable identity endorsements in the future.

[0142] After the user review process is completed, the back-end system can further perform preprocessing of the user's identity information. For example, the 1018 unit uses a pattern recognition algorithm to extract feature vectors from the perceptual representation attributes provided by the user, and then stores the feature vectors of the perceptual representation in the data storage unit. The specific implementation includes using an image (shape) recognition algorithm (e.g., the convolutional neural network algorithm of deep learning) to extract sample point features or feature vectors containing the contours of the mouth, nose, eyes, and eyelids from the face image of the user's corresponding social member, using a voice and voiceprint recognition algorithm to extract voice sample point features from the sound audio, and using an image (shape) recognition algorithm to extract handwriting features from the handwriting graph.

[0143] Appendix Figure 3 Describes the main steps of creating or generating an identity endorsement, that is, the method of generating an identity endorsement, specifically including:

[0144] Step S3001, input the identity endorsement application. Receive the input of the identity endorsement application, check the input information of the identity endorsement application, construct a communication protocol message for generating the identity endorsement application, fill the input information of the identity endorsement application into this message, and send this message to the back-end system. The user opens the front-end APP, logs in to the system, enters the identity endorsement application information, and submits the identity endorsement application. For example, the 1001 unit fills the received identity endorsement application information input into the POST message of the HTTPS protocol constructed according to the session status information, and then sends the POST message to the back-end system. The identity endorsement application information may include one or more of the identity permission application rules, operation control words, appendix of annotation items, civil affairs and public sentiment status indicators, etc. The operation control words include one or more of the identity association (subject link) representation type, legal identity identification type, etc. For example, the identity association representation type is the face perception representation feature type, the time domain applicable to the identity permission is from January 1, 2017 to December 31, 2018, the applicable level of the identity permission is level one or the default applicable level of the permission, and the applicable area of the identity permission is within the scope of the administrative region of the geographical coordinates read by GPS. The civil affairs and public sentiment status indicators include credit status and highest education level.

[0145] Step S3002, arranging identity endorsement members. First, accept identity endorsement applications, including: receiving communication protocol messages for generating identity endorsement applications, parsing these messages, and extracting identity endorsement application information. Then, compile identity endorsement members based on the identity endorsement application information, including: selecting the option sources for identity endorsement members from the retained identity information or identity endorsement application information in the data storage unit. The option sources include one or more pieces of information such as perceived representation attributes or features, gene representation (marker) features, extended representation features, legal identity identifiers, civil affairs and public sentiment conditions, etc. Compile the option sources as identity endorsement members. For example: compress the option sources and configure the compressed result of the option sources in TLV format as identity endorsement members; convert the option sources and configure the conversion result of the option sources as identity endorsement members; calculate the digest of the option sources and configure the digest of the option sources as identity endorsement members; extract the feature vectors of the perceived representation attribute option sources and configure the feature vectors of the perceived representation attribute option sources as identity endorsement members; configure the perceived representation feature option sources (pre-extracted eigenvalue vectors of perceived representation attributes) as identity endorsement members; supplement and align (padding) the option sources and configure the supplementary alignment result of the option sources as identity endorsement members; set default option sources and configure the default option sources as identity endorsement members, etc., one or more of them. Finally, layout the identity endorsement members as an endorsement member combination, including: arranging and integrating the compiled identity endorsement members in a specified format or default format into an endorsement member combination. The endorsement member group is a combined sequence of multiple identity endorsement members in a specified format, and correspondingly, it is also a byte stream (sequence) in a specified format. Obviously, through the compilation, compression, and integration technology, the endorsement member combination is made short and lightweight, which is a prerequisite for wide applicability (generality). Hand over the laid-out endorsement member combination to the next step for concealment or signature processing. Selecting the option sources from the data storage unit includes selecting the option sources through SQL query statements according to user identifiers, identity association (subject link) representation types, and legal identity identifier types. Setting default option sources includes setting the member values of operation control items. For example: setting the signature algorithm member, hash algorithm member, version number member, etc. of the operation control word. Layoutting the identity endorsement members includes arranging and integrating each member according to the format into an endorsement member combination. The specific format of the endorsement member combination is, for example: {version number}{identity permission application rules}{identity association representation}{legal identity identifier}. The specific implementation is as follows: Unit 1014 parses the generated identity endorsement application message of the HTTPS protocol, extracts the identity endorsement application information, then selects the option sources for identity endorsement members from Unit 1017, arranges the identity endorsement members according to the selected option sources, and then sends the identity endorsement to Unit 1015 for concealment processing or Unit 1016 for signature processing. Identity endorsement members generally include type, length, and value. For the sake of the shortness and lightness of the identity endorsement, the type and length of the identity endorsement members can be implicitly defaulted according to the identity endorsement format without explicit placeholder existence.Identity - associated representation refers to the distinguishable representation of the signer (main - certificate binding or correspondence) closely associated with the signer in the identity endorsement. For example, the identity - associated representation is the face - image perception representation feature. The face - image perception representation feature is several features including the contours of the mouth, nose, eyes, and eyelids or the X - dimensional feature vector of the human face. The X - dimensional feature vector can be an array of decimal numbers (floating - point numbers) between 64 (dimensions) - 1 and 1 or an array of integer values between 64 (dimensions) - 127 and 127. The 80 - dimensional feature vector can be an array of integer values between - 127 and 127. The several features of the contours of the mouth, nose, eyes, and eyelids can be an array of vectors composed of 68 coordinate points of the human - face contour. This feature or feature vector is extracted from the face - image of the user's identity information, which can be extracted in advance or extracted immediately during compilation. If it is extracted immediately during compilation, the face - image option source is selected from the retained identity information in the data - storage unit, and then the 1018 unit is called to use the deep - learning image - recognition algorithm of the pattern - recognition algorithm (for example: convolutional neural - network algorithm) to extract the face - image feature from the face - image. Configuring the face - image perception representation as an endorsement member is as follows: create a TLV - format member, set the type of the TLV member to the face - image perception representation, set the length of the TLV member to the length of the feature - vector array, and set the value of the TLV member to the X - dimensional feature vector. Legal identity identifiers include the name and ID number of individual social members, the name and organization code of organizational social members, etc.

[0146] Step S3003, conceal the identity - endorsement member. This step is an optional step. If there are no private members that need to be concealed or the operation control word contains an indication of non - concealed private members, then no processing is performed in this step. Depending on the specific implementation, the concealment - processing step of the identity - endorsement member can be merged into the step of compiling the identity - endorsement member in the arrangement of the identity - endorsement member, that is, the compilation of the identity - endorsement member in the arrangement of the identity - endorsement member can simultaneously include the concealment - processing of the identity - endorsement member. The concealment of the identity - endorsement member as an independent step is for clearer logic. Concealing the identity - endorsement specifically includes encrypting the private identity - endorsement member using a symmetric - key algorithm or an asymmetric - key algorithm, and can also use a hashing algorithm to calculate the digest of the private identity - endorsement member and replace and update it. For example: the 1015 unit uses the AES algorithm to encrypt the ID - number value in the ID - number member of the legal identity identifier, and the plain - text ID - number value of the ID - number member of the encrypted legal identity identifier has been replaced and updated with the ID - number ciphertext, or the 1015 unit uses the SHA algorithm to calculate the digest of the name value in the name member of the legal identity identifier to obtain the digest - result value, and then replaces and updates the name value of the name member of the legal identity identifier with the digest - result value. After the 1015 unit finishes processing, it returns the endorsement - member combination to the 1014 unit, and the 1014 unit sends the endorsement - member combination to the 1016 unit for signature.

[0147] Step S3004, sign the identity endorsement members. Use the asymmetric key algorithm and the notarized private key to sign and calculate the endorsement member combination to obtain a digital signature, configure the digital signature and layout it into the endorsement member combination to obtain an identity endorsement. For example: calculate the digest to be signed for the endorsement member combination according to the hashing algorithm, calculate the digital signature value for the digest to be signed according to the asymmetric key signature algorithm and the notarized private key, configure the digital signature value as a digital signature member and layout it at the end of the identity endorsement or replace it in the identity endorsement digital signature member. For example: first calculate the digest to be signed using SHA3, then perform signature calculation using ecc25519, and finally obtain a byte (native) identity endorsement in the format of {version number: 1}{license application rules: 1, 2017010120181231, longitude and latitude}{face feature vector}{name and ID number}{digital signature}. Obviously, this identity endorsement is a digital byte (byte) stream (sequence) that integrates multiple identity endorsement members in a specified format, and the identity endorsement format and member combination are combined with the publicly unified notarized public key to identify or trace the certifier of the identity certificate. The 1016 unit is responsible for signing the identity endorsement and then returning the signed identity endorsement to the 1014 unit.

[0148] Step S3005, encapsulate the identity endorsement. Encapsulating the identity endorsement includes one or more of expanding the byte (native) identity endorsement into a visible character (i.e., string) identity endorsement, grouping the identity endorsement into a QR code-style identity endorsement, loading and processing the identity endorsement as a file, etc. The identity endorsement after loading is convenient for storage, transmission, and management. The encapsulation of the identity endorsement depends on the specific implementation. For example: use the base64 rule to expand and convert the byte identity endorsement into a visible character identity endorsement, use the QR Code standard to group the byte or visible character identity endorsement into a QR code-style identity endorsement, and load the QR code-style identity endorsement into a Joint Photographic Experts Group (JPEG) or Portable Network Graphic Format (PNG) file; load the visible character identity endorsement into a text (txt) file or Portable Document Format (PDF); load the byte identity endorsement into a native byte (or binary) file. The 1002 unit is responsible for encapsulating the identity endorsement, and the processing format is carried out according to the control word instruction. The control word indicates the format of the identity endorsement. If there is no explicit instruction, it is loaded and processed according to the default format. After the 1002 unit finishes encapsulating the identity endorsement, it returns the identity endorsement to the 1014 or 1001 unit.

[0149] Step S3006: Output the identity endorsement. The 1001 unit receives the identity endorsement returned by the 1002 unit or the 1014 unit and outputs the identity endorsement. Outputting the identity endorsement includes recording (or storing) the identity endorsement in the local device, displaying the identity endorsement on the user interface, printing the identity endorsement to a specified physical location, and sending the identity endorsement to a specified destination via the network, such as sending the identity endorsement via the Common Internet File System (CIFS) or File Transfer Protocol (FTP). Storing the identity endorsement in the local device includes using local file storage or using a local database for storage. For example, the 1001 unit displays a QR code-based identity endorsement or a visible character identity endorsement on the user interface, prints the QR code-based identity endorsement or the visible character identity endorsement to a specified physical entity (such as paper), and saves the QR code-based identity endorsement or the visible character identity endorsement or the identity endorsement file to a file storage system or database. Obviously, this identity endorsement is short and integrated, and the encapsulated identity endorsement is not restricted by the carrier. The byte (or binary) identity endorsement can also be directly implanted into an Integrated Circuit (IC) chip.

[0150] The above embodiments describe the process of generating an identity endorsement. Based on a unified notarized key architecture, through technologies such as pattern recognition algorithms, orchestration techniques, steganography algorithms, and asymmetric key signature algorithms, and organically combining information such as identity information and license application rules, they support and cooperate with each other to generate an integrated digital identity endorsement for general identity verification. All members of the identity endorsement are closely associated and integrated, greatly improving its convenience, reliability, and discriminability. Moreover, the identity endorsement format and members, combined with the publicly unified notarized public key, can identify or trace the endorser of the identity verification. This identity endorsement not only perfectly meets the basic nature requirements of general identity verification but also solves the problem of incompatibility (conflict) between privacy protection and identity verification, effectively and reasonably protecting private information while providing an extremely reliable, secure, and convenient identity authentication or verification mechanism, eliminating potential risks such as forgery, identity theft, and private information leakage. Moreover, the identity endorsement is short and integrated, not restricted by the carrier, and has wide applicability. In today's era of widespread deployment of smartphones, identity verification has become very simple and convenient. The above identity endorsement also introduces license application rules, implementing a dynamic license application protection mechanism with on-demand signing and time and geographical range restrictions, further preventing the easy misuse caused by the universal use of a single certificate. The above identity endorsement introduces civil affairs and public sentiment conditions to provide additional transparent information, further enhancing the identity verification ability. This identity endorsement not only realizes dynamic (on-demand signing) license application protection and an integrated identity verification that is simple to use, tightly associated, extremely reliable, and easy to distinguish, but also, after secretly associating the private members of the identity endorsement, the identity endorsement does not contain publicly disclosed private identity information, and further achieves an integrated identity verification that combines private information protection, dynamic license application protection, and simple use, tight association, extreme reliability, and easy distinguishability.

[0151] The detailed steps for generating an identity endorsement with an identity password are described below, specifically including:

[0152] Step S3011, input an identity endorsement application. The user logs in to the system and then submits the identity endorsement application information after inputting it. The input permission application level is level 2, the identity association representation type is face image and identity password type, the permission application time domain is from January 1, 2017 to January 2, 2017, and the legal identity identification type is ID card.

[0153] Step S3012, arrange identity endorsement members. Select option sources such as user name, ID number, preset identity password, face online mark, etc. from the data storage unit according to the user identifier (specific implementation can extract the session identifier from the identity endorsement application message and select the user identifier from the session state cache). Compile the face identity association representation including: mapping the face to an Internet address of an externally accessible face (e.g., www.xxx.com / yyy?zzz=wwww&aaaa=hhhh), configuring the Internet address (or: hyperlink address) to the identity association representation member; compile the identity password identity association representation including: generating a random value (NONCE) using a random algorithm, concatenating the NONCE and the identity password to obtain a random password string, calculating the random password string using a hashing algorithm to obtain the identity password digest, and then configuring the NONCE and the identity password digest to the identity password member of the identity association representation. Compile the legal identity identification including: configuring the name and ID number to the legal identity identification member. Compile the identity permission application details including: setting the permission application level to 2, and the permission application time domain to 2017010120170102. Compile the operation control word including: setting the version number to 1, the hashing algorithm to 3 (representing SHA3), the asymmetric key algorithm to 2 (representing ECC25519), etc. Layout the identity endorsement members as {version number: 1}{hashing algorithm: 3}{asymmetric key algorithm: 2}{permission application level: 2, permission application time domain: 2017010120170102}{Internet address of the face, NONCE + identity password digest}{name, ID number}{N-byte blank digital signature}.

[0154] Step S3013, encrypt the identity endorsement members. Use the AES algorithm and the notarized key to encrypt the legal identity identification members (e.g., name and ID number). For example, the encrypted identity endorsement members are as follows: {version number: 1}{hashing algorithm: 3}{asymmetric key algorithm: 2}{permission application level: 2, permission application time domain: 2017010120170102}{Internet address of the face, NONCE + identity password digest}{ciphertext of name and ID number}{N-byte blank digital signature}.

[0155] Step S3014, Sign the identity endorsement members. Use SHA3, ECC25519, and the notarized private key to perform signature calculation on the member combination of {version number: 1}{hash algorithm: 3}{asymmetric key algorithm: 2}{permission application level: 2, permission application time domain: 2017010120170102}{Internet address of the face image, NONCE + identity password digest}{ciphertext of name and ID number} to obtain the digital signature value. Replace {N-byte blank digital signature} with the digital signature value to obtain the identity endorsement.

[0156] Step S3015, Respond to the identity endorsement application. Construct a communication protocol message for the identity endorsement application result, fill the identity endorsement into the communication protocol message, and send the identity endorsement application result message to the front-end APP. Unit 1014 is responsible for constructing the message or sending the message. Depending on the specific implementation, before filling the identity endorsement into the communication protocol message, the identity password digest can be set to a blank value.

[0157] Step S3016, Package the identity endorsement. Receive the identity endorsement application result message input from the network, parse the message, extract the identity endorsement, expand the identity endorsement into a visible character identity endorsement, group the visible character identity endorsements into a QR code identity endorsement, and load the identity endorsement QR code as a JPEG file. Unit 1001 is responsible for receiving the identity endorsement application result message and extracting the identity endorsement, and Unit 1001 hands the identity endorsement to Unit 1002 for packaging.

[0158] Step S3017, Output the identity endorsement. Store the identity endorsement JPEG file.

[0159] For the above identity endorsement containing the identity password, the face image can be used as a reference for manual confirmation and authentication. At the same time, when authenticating, it is required to input the identity password to prevent misappropriation caused by lax authentication, especially when handling bundled services to prevent losses to users caused by misappropriation due to lax authentication.

[0160] The following describes the detailed steps for generating an identity endorsement containing an appendix of annotation items. The specific implementation includes:

[0161] Step S3021, Input the identity endorsement application. The user logs in to the system, then enters the application information and submits it. The input permission application level is first level, the identity association characterization type is fingerprint type, the permission application time domain is from January 1, 2017 to January 2, 2017, and the legal identity identification type is ID card. The source of the annotation item appendix is the content summary of the protocol contract. For example: Sign a rental contract for xxx Garden xxx from January 2017 to December 2018 with XXX. The source of the annotation item appendix contains the content summary of the permission items. The operation control word also has a mark containing extended features such as address and phone number.

[0162] Step S3022, arrange identity endorsement members. Select option sources such as user name, ID number, fingerprint feature, address, and phone number from the data storage unit according to the user identifier, and compile a fingerprint identity association representation including: configuring the fingerprint feature as an identity-associated fingerprint member; compiling an appendix of endorsed matters including: calculating the source of the appendix of endorsed matters (i.e., the summary of the protocol contract content) using a hashing algorithm (such as SHA3) to obtain an endorsement matter digest, and then configuring the endorsement matter digest as an appendix member of the endorsed matters. Compile an extended address feature including: performing a compression process of replacing the administrative region name prefix of the address with an administrative region code, and configuring the compressed address as an extended feature member.

[0163] Step S3023, conceal identity endorsement members. Encrypt legal identity identification members (such as name, ID number) using the ECC25519 algorithm. For example: If the ID name member of the legal identity identification is in TLV format, use the ECC25519 algorithm to encrypt the value (corresponding to the name) of the TLV-format ID name member to obtain an encrypted result ciphertext, and replace and update the value (VALUE) of the ID name member with the encrypted result ciphertext.

[0164] Step S3024, sign identity endorsement members. Perform a signature calculation on the identity endorsement member combination using the ECC25519 and SHA3 algorithms to obtain a digital signature, and configure the digital signature to the endorsement member combination to obtain a byte (native) identity endorsement.

[0165] Step S3025, encapsulate identity endorsement. Expand the identity endorsement into a visible character identity endorsement, group the visible character identity endorsement into a QR code-style identity endorsement, and load the identity endorsement QR code as a PNG file. Group the source of the appendix of endorsed matters into an appendix QR code of endorsed matters, and load the appendix QR code of endorsed matters as a PNG file.

[0166] Step S3026, output identity endorsement. Print the identity endorsement QR code PNG file and the appendix QR code PNG file of the endorsed matters.

[0167] The above appendix of endorsed matters identity endorsement contains descriptions and declarations of matters, which are easy to identify and impossible to be misused, solving the problem that it was difficult to identify fingerprint impressions and handwriting signatures in the past. At the same time, the appendix of endorsed matters realizes the special certificate for immediate use and signature (one certificate for one use) instead of one certificate being used universally, completely solving the problem of certificate misuse.

[0168] The following describes the detailed steps for generating vehicle and driver identity endorsements. The specific implementation includes:

[0169] Step S3031, input the identity endorsement application. The user logs in to the system, then submits the application information after input. The input license applicable level is level one, the identity associated characterization type is the appearance (shape) feature type, the license applicable time domain is from January 1, 2017 to December 31, 2019, and the legal identity identification type is the driving license. The license applicable object is the identity endorsement of the driver. The civil affairs and people's conditions include the vehicle health condition, the vehicle credit condition, and the vehicle violation condition.

[0170] Step S3032, arrange the identity endorsement members. Select option sources such as the vehicle engine number, the vehicle health condition, the vehicle credit condition, and the vehicle violation condition from the data storage unit according to the user identification and the license plate number. Compile the identity associated characterization including: create the path to access the vehicle appearance (shape) image corresponding to the license plate number in the database, then format the path into an externally accessible Internet address, and configure the Internet address as a member of the identity associated characterization; Compile the legal identity identification including: configure the license plate number and the vehicle engine number as members of the legal identity identification; Compile the license applicable object including restoring the identity endorsement byte code of the driver, and then configure the byte identity endorsement as a member of the license applicable object. Compile the civil affairs and people's conditions including configuring the vehicle health condition being good, the vehicle credit condition being good, and no vehicle violation records, etc. into members of the civil affairs and people's conditions using the TLV mode.

[0171] Step S3033, encrypt the identity endorsement members secretly. Use the ECC25519 algorithm to encrypt the legal identity identification members (for example: the vehicle engine number). For example: if the identity identification member is in TLV format, use the ECC25519 algorithm and the notarized public key to encrypt the value of the legal identity identification member in TLV format (corresponding to the vehicle engine number) to obtain the encrypted result ciphertext, and update (replace) the value (VALUE) of the legal identity identification member with the encrypted result ciphertext.

[0172] Step S3034, sign the identity endorsement members. Use the ECC25519 and SHA3 algorithms to perform signature calculation on the endorsement member combination to obtain a digital signature, and configure the digital signature to the endorsement member combination to obtain the identity endorsement. For example: Unit 1016 uses the SHA3 algorithm to calculate the digest of the endorsement member combination to obtain a signature digest, uses the ECC25519 algorithm and the notarized private key to sign and calculate the signature digest to obtain a digital signature, configures the digital signature as a digital signature member, and arranges the digital signature member to the endorsement member combination to obtain the identity endorsement.

[0173] Step S3035, encapsulate the identity endorsement. Expand the identity endorsement into an identity endorsement identity endorsement, group the identity endorsement identity endorsement into a two-dimensional code type identity endorsement, and load the identity endorsement two-dimensional code as a PNG file.

[0174] Step S3036, output the identity endorsement. Print the identity endorsement two-dimensional code PNG file.

[0175] The above-mentioned identity signature includes the members of the license applicable objects, limits the scope of use of the identity signature, and is bound to the appearance (shape) of the physical object, which is easy to identify and cannot be misused.

[0176] Attached Figure 4 An embodiment of the authentication identity endorsement step is described, and the specific implementation includes:

[0177] Step S4001, input the identity signature. Methods for inputting the identity signature include but are not limited to camera reading, Bluetooth reading, WIFI reading, keyboard input, etc. For example: the user turns on the camera device through the front-end APP, scans the identity signature QR code image and translates the QR code to obtain the identity signature, and restores the identity signature to a byte identity signature. After unit 1001 scans the identity signature QR code image, it gives the QR code image to unit 1002 to translate the QR code and / or restore the identity signature to a byte (native) identity signature.

[0178] Step S4002, verify the digital signature of the identity annotation. The digital signature of the identity annotation is decrypted according to the asymmetric key algorithm and the notarized public key is calculated to obtain the signature summary. The other members in the identity annotation except the digital signature are calculated according to the hash algorithm to obtain the verification summary. If the verification summary and the signature summary are consistent, the verification signature is successful, otherwise the authentication fails (reason: the digital signature is invalid) and go to step S4005 for processing. The specific types of asymmetric key algorithms and hash algorithms are determined according to the operation control word of the identity annotation. If the operation control word of the identity annotation is not specified, the system default algorithm type is used. The digital signature of the identity annotation is verified using a public and unified asymmetric key algorithm notarized public key, for example: the notarized public key preset by the front-end APP1003 unit.

[0179] Step S4003, determine the signature owner associated with the identity endorsement. Determining the signature owner associated with the identity endorsement includes verifying whether the identity association (subject link) representation matches the signature owner (whether the main certificate corresponds), and the specific implementation includes manual verification (determination) and / or program-assisted verification (determination). Manual verification includes verifying whether the face image perception representation matches the signature owner, whether the communication method matches the signature owner, whether the location address matches the address where the signature owner is located, etc. Program-assisted verification includes perception representation feature matching verification, password matching confirmation, etc. For example: when the perception representation feature is a fingerprint, the appraiser inputs (or reads) the fingerprint perception representation of the signature owner through a fingerprint device, and matches the fingerprint perception representation of the signature owner with the fingerprint features of the identity association representation members of the identity endorsement. If the fingerprint features are similar, the verification is successful; otherwise, the verification fails (reason: identity mismatch), and the process proceeds to step S4005 for processing. When the perception representation feature is a face image perception representation, the appraiser captures the face image of the signature owner through an optical device such as a camera. The face image of the signature owner (physical natural person) can be captured on-site, or a digital or paper photo of the signature owner's face can be captured. The feature recognition unit extracts the face feature points or feature vectors of the signature owner from the face image using an image recognition algorithm, and matches the extracted face feature points or feature vectors with the face features of the identity association representation members. If the match is successful, the verification is successful; otherwise, the verification fails (reason: identity mismatch), and the process proceeds to step S4005 for processing. As a specific implementation, the front-end APP further includes a feature recognition unit 1004. The unit 1004 pre-trains a convolutional neural network, inputs the face image into the convolutional neural network to extract the X-dimensional feature vector of the face, and calculates the Euclidean distance between the face feature of the identity association representation and the X-dimensional feature vector of the source face of the representation determination. When the Euclidean distance is less than the specified threshold, the match is successful; otherwise, the match fails.

[0180] Step S4004, defining the identity license applicable rules, including one or more of checking the identity license applicable level, checking the identity license applicable time domain, checking the identity license applicable region, checking the identity license applicable object, etc. This step is an optional step depending on the specific implementation. Checking the identity license applicable time domain includes detecting whether the license applicable time domain in the identity endorsement contains the identification time. The specific implementation of the license validity is generally a period of time, such as 2016-12-01 to 2016-12-31. Checking the license applicable level means detecting whether the license applicable level of the license endorsement is lower than the endorsement level used by the identification party. If the detection result is lower, the verification fails (reason: the license applicable level is invalid). Checking the license applicable region includes detecting whether the current identification geographical location is included in the scope of the license applicable region. If the current identification geographical location is not included in the scope of the license applicable region, the identification fails (reason: the license applicable region is invalid). For example, the license applicable region is Beijing. If the identification location is not in Beijing, the identification fails. Checking the license applicable object specifically includes detecting whether the identification party is the authorized object of the identity endorsement or the identification license destination object.

[0181] Step S4005, output the identification result. The front-end APP displays or records the identification result. The front-end APP 1003 unit returns the identification result to the 1001 unit, and the 1001 unit displays or records the identification result, for example: recording the identification success and identification time or displaying the identification failure and the reason for failure.

[0182] The above-mentioned identification method of identity endorsement, through the mutual support and cooperation of public unified signature verification and identity identification associated signer and definition of applicable license rules, makes the identity proof and identification (identification) of the two parties in communication simple, reliable and dynamically protected on demand. In particular, the identity association representation member used for identity identification associated signer is closely associated with other identity endorsement members and is integrated. This integrated identity endorsement greatly improves the reliability and identifiability of identity proof, effectively prevents the problem of fraud, and the above-mentioned method of identifying identity endorsement does not require identity identification for reliable and accurate identification, solves the incompatibility (conflict) between privacy (private information) protection and identity proof and effectively protects identity private information. The use of QR code identity endorsement is simpler and more convenient, does not require additional costs, and is easy to promote and deploy. In particular, the above-mentioned identity endorsement can be performed locally offline (front-end APP), overcoming the defect that commonly used digital identity proof can only be authenticated online, and the public unified notarization public key combined with the identity endorsement format and members can clearly identify or trace the certifier of the identity proof, truly meeting the basic essential characteristics of universal identity proof.

[0183] Attached Figure 5 An embodiment of the steps of revealing identity endorsement is described, and the specific implementation includes:

[0184] Step S5001, input the application for revealing identity endorsement. The user logs in to this identity endorsement system through the front-end APP, inputs the identity endorsement, and then submits the application for revealing identity endorsement. For example: The user logs in to this identity endorsement system by inputting the user identifier and login password in Unit 1001 of the front-end APP, activates the camera to scan the identity endorsement QR code image and translates the QR code to obtain the byte (native) identity endorsement, and then constructs an application message for revealing identity endorsement according to the login session status (for example: create an HTTPS POST message and fill the session identifier into the POST message header), fill the scanned identity endorsement into the message body (Body) of the application message for revealing identity endorsement, and finally send the application message for revealing identity endorsement filled with the identity endorsement to the back-end system.

[0185] Step S5002, accept the application for revealing identity endorsement. The back-end system receives the application message for revealing identity endorsement containing the identity endorsement content, parses the application message for revealing identity endorsement to obtain the session identifier and the identity endorsement, selects the user identifier from the session status cache after the user logs in according to the session identifier, and then detects whether the applying user has the permission to reveal identity endorsement according to the user identifier. If the user does not have the permission to reveal identity endorsement, it goes to Step 5005 to respond to the failure of revelation (reason: no permission to reveal identity endorsement) for processing. Parse the application message for revealing identity endorsement and extract the identity endorsement. Unit 1014 is responsible for receiving the application message for revealing identity endorsement and parsing the application message for revealing identity endorsement to obtain the session identifier and the identity endorsement, and then selects the user's permission to reveal identity endorsement from the data storage unit according to the user identifier. If the user does not have the permission to reveal identity endorsement, it responds with the result of failure to reveal identity endorsement. If the user has the permission to reveal identity endorsement, it calls Unit 1016 to verify the digital signature of the identity endorsement.

[0186] Step S5003, verify the digital signature of the identity endorsement. The back-end system uses the asymmetric cryptographic algorithm specified by the operation control word of the identity endorsement or the default asymmetric cryptographic algorithm and the notarized public key to verify the digital signature of the identity endorsement. Unit 1014 transfers the identity endorsement and calls or notifies Unit 1016 to verify the digital signature of the identity endorsement. Unit 1016 is responsible for verifying the digital signature of the identity endorsement and returning the verification result to Unit 1014. If the verification of the digital signature of the identity endorsement fails, it directly goes to Step 5005 to respond to the failure of revealing identity endorsement (reason: invalid digital signature of the identity endorsement) for processing. Otherwise, it calls Unit 1015 to decrypt the identity endorsement.

[0187] Step S5004, decrypt the encrypted (ciphertext) identity endorsement members. The background system performs decryption calculations on the encrypted (ciphertext) identity endorsement members using the key algorithm and the unified key to obtain the plaintext of the encrypted identity endorsement members. The type of key algorithm is determined by the encryption algorithm type of the operation control word of the identity endorsement or the default algorithm. For example: if the identity endorsement is encrypted using a symmetric encryption algorithm, then the symmetric key is used for decryption; if the identity endorsement is encrypted using an asymmetric encryption algorithm, then the private key of the asymmetric key is used for decryption. The 1014 unit transfers the identity endorsement and the unified key (symmetric key or private key of the asymmetric key) and calls or notifies the 1015 unit to decrypt the encrypted (ciphertext) identity endorsement members, and returns the plaintext of the encrypted (ciphertext) identity endorsement members (value) obtained by decryption (such as name and ID number) to the 1014 unit.

[0188] Step S5005, respond to the result of decrypting the identity endorsement. The background system constructs a response message, fills the result of decrypting the identity endorsement into the message, and sends the message to the front-end APP. The 1015 unit is responsible for constructing a response message according to the received message type and communication protocol requirements, filling the decryption result (decryption failure and reasons, decryption success and the plaintext of the private information of the encrypted (ciphertext) identity endorsement members) and sending a message to the front-end APP.

[0189] Step S5006, output the result of decrypting the identity endorsement. The front-end APP receives the message of the result of decrypting the identity endorsement input through the network, parses the message, extracts the result of decrypting the identity endorsement, and outputs the result of decrypting the identity endorsement. For example: print, record, display the plaintext of the private information. The 1001 unit of the front-end APP is responsible for receiving the decryption result message, parsing the message and outputting the decryption result. For example: the 1001 unit displays and / or records the plaintext of the encrypted members after decrypting the identity endorsement or the 1001 unit displays the decryption failure result of the identity endorsement.

[0190] The above identity endorsement decryption method ensures the legal authority of the identity endorsement as a general identity certificate and the due archival persistence characteristics of the identity certificate (certificate body). By decrypting the identity endorsement, it can ensure the use of the identity endorsement for retrospective prosecution afterwards, and also reasonably and effectively eliminates the incompatibility (conflict) problem between the protection of private information (privacy) and the traceability of the identity certificate. The identity endorsement of the present invention not only well protects the identity privacy (private) information, but also completely retains the essential characteristics that a daily general identity certificate (voucher) should have. The authority of the user to decrypt the identity endorsement is strictly restricted. It must be an organization trusted by the public and with the prescribed qualifications. Generally, users corresponding to trusted institutions such as government departments and courts have the authority to decrypt the identity endorsement. In this way, it effectively protects private information while retaining the traceability characteristics of the identity certificate.

[0191] As described above, it is only the preferred specific implementation mode of the embodiments of the present invention, but the protection scope of the embodiments of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the embodiments of the present invention should be covered within the protection scope of the embodiments of the present invention. Therefore, the protection scope of the embodiments of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for generating an identity endorsement, characterized in that, Including the following steps: Accepting an identity endorsement application; Compiling identity endorsement members according to the identity endorsement application; Laying out the identity endorsement members into an endorsement member combination; Using an asymmetric key algorithm and a notarized private key to sign the endorsement member combination to obtain a digital signature, and configuring the digital signature to the endorsement member combination to obtain an identity endorsement.

2. The method according to claim 1, characterized in that, Before the above-mentioned accepting of the identity endorsement application, it further includes: Inputting the identity endorsement application. The inputting of the identity endorsement application includes inputting identity endorsement application information and distributing and processing the identity endorsement application information.

3. The method according to claim 1, wherein The above-mentioned accepting of the identity endorsement application includes: Receiving and generating an identity endorsement application message, parsing the identity endorsement application message and extracting identity endorsement application information therefrom.

4. The method according to claim 1, wherein The above-mentioned compiling of the identity endorsement members according to the identity endorsement application includes: Selecting an option source of the identity endorsement members from the retained identity information or from the identity endorsement application information according to the identity endorsement application, and compiling the option source into the identity endorsement members.

5. The method according to claim 4, characterized in that The above-mentioned compiling of the option source into the identity endorsement members includes: Using a hashing algorithm to calculate the digest of a random value and / or a password, and configuring the digest as an identity endorsement member; Using a pattern recognition algorithm to extract the features of the perceptual representation attributes, and configuring the features of the perceptual representation attributes as an identity endorsement member; Mapping the option source to an Internet address, and configuring the Internet address as an identity endorsement member, etc., one or more of them.

6. The method according to claim 1, 4 and 5, characterized in that, The above-mentioned identity endorsement members include: One or more of a legal identity identifier, identity permission application rules, identity association representations, annotation item appendices, etc. Among them, the legal identity identifier includes, but is not limited to, one or more of a legal name, a legal license number, etc. The above-mentioned identity association representations include, but are not limited to, one or more of an identity association perceptual representation, an identity association gene representation, an identity association extended representation, etc. The above-mentioned identity permission application rules include one or more of an identity permission application level, an identity permission application time domain, an identity permission application region, an identity permission application object, etc.

7. The method according to claims 1, 4, 5, and 6, characterized in that, The above-mentioned compiling of the identity endorsement members according to the identity endorsement application includes, but is not limited to: Selecting identity permission application rule information from the identity endorsement application, and configuring the identity permission application rule information as an identity permission application rule member; Selecting a legal identity identifier from the retained identity information according to the identity endorsement application, and configuring the legal identity identifier as a legal identity identifier member; Selecting an identity association representation from the retained identity information according to the identity endorsement application, and configuring the identity association representation as an identity association representation member, etc., one or more of them. Among them, the above-mentioned selecting of the identity association representation from the retained identity information according to the identity endorsement application and configuring the identity association representation as an identity association representation member further includes: Selecting the identity association representation features pre-extracted using a pattern recognition algorithm from the retained identity information according to the identity endorsement application, and configuring the identity association representation features as an identity association representation member; Selecting an identity association representation attribute from the retained identity information according to the identity endorsement application, using a pattern recognition algorithm to extract the identity association representation attribute to obtain identity association representation features, and configuring the identity association representation features as an identity association representation member; Select identity - related characterization attributes from the retained identity information according to the identity endorsement application, map the identity - related characterization attributes to network addresses, and configure the network addresses as one or more of identity - related members, etc.

8. The method according to claim 1, characterized in that, The layout identity endorsement members as an endorsement member combination may further include: concealed identity endorsement members. The concealed identity endorsement members include encrypting private identity endorsement members using a key algorithm or calculating the digest of private identity endorsement members using a hashing algorithm and replacing and updating them. The private identity endorsement members include, but are not limited to, one or more of the legal name, legal license number, etc.

9. The method according to claim 1, characterized in that After configuring the digital signature into the endorsement member combination to obtain the identity endorsement, it may further include: encapsulating the identity endorsement. The encapsulating of the identity endorsement includes: one or more of converting the byte - based identity endorsement extension to a visible - character identity endorsement, converting the identity endorsement grouping to a two - dimensional code - type identity endorsement, and loading and processing the identity endorsement as a file.

10. The method according to claim 1 or 9, characterized in that After the encapsulation of the identity endorsement, it may further include: Outputting the identity endorsement. The outputting of the identity endorsement includes one or more of displaying the identity endorsement, printing the identity endorsement, and recording and storing the identity endorsement.

Citation Information

Patent Citations

  • Method and system for uniformly managing identity endorsement

    CN106656511A