Method and device for signing and issuing role certificate and method and device for tracing real identity based on role certificate
By introducing extended information items into the role certificate, the association between the role certificate and the user's real-name identity is realized, solving the problems of high storage costs and data leakage risks in the existing technology, and improving the security and efficiency of identity traceability.
Patent Information
- Application Number
- CN202510535274.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the role certificate issuing agency needs to associate the real-name identities of all users with the role certificates, resulting in high storage costs and a risk of data leakage. In the prior art, the traceability process of role certificates and real-name identities is cumbersome, and the identity issuing party needs to participate.
By introducing extended information items into the role certificate, including the user's unique identity ciphertext, the information ciphertext of the identity certificate issuing agency and the public key identifier of the supervisory agency, it will only be decrypted by the authorized supervisory authority to realize the association and traceability of the user's real-name identity, avoiding the long-term storage of real-name identity information by the person issuing the role certificate issuing party.
It reduces data storage costs and leakage risks, improves the security and efficiency of identity traceability, reduces duplicate verification steps, and improves user data privacy protection.
Smart Images

Figure CN120342630A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data security. Specifically, it relates to a method and device for issuing role certificates and tracing real identities based on role certificates. Background Art
[0002] In many existing applications, in order to achieve the technical effect of front-end anonymity, role certificates are designed to contain only non-real-name information directly related to specific application scenarios. For example, in the service industry, business personnel need to communicate with the public by phone to promote and implement relevant services. However, the public often cannot confirm whether the other party is a legitimate employee of a certain company. At the same time, for privacy protection and security reasons, business personnel also do not want to expose their real-name identities. By using role certificates, business personnel can prove that they are legitimate employees of a certain company without disclosing specific real-name identity information. To achieve traceability of real identities, usually the role certificate issuing agency needs to store the real identities of all users in association with the role certificates, with a large amount of data and high database construction costs; moreover, there is a risk of data being attacked during long-term storage.
[0003] Therefore, how to provide a technical solution for a method of issuing role certificates with low storage cost and high security has become a technical problem that urgently needs to be solved. Summary of the Invention
[0004] Some embodiments of this application aim to provide a method and device for issuing role certificates and tracing real identities based on role certificates. In the technical solution of the embodiments of this application, the role certificate itself cannot be directly associated with the real identity, and there will be no identity association between multiple role certificates of the same user. It only supports the authorized supervision agency to trace the real identity through the role certificate, and the identity tracing process does not require the participation of the role certificate issuer. Therefore, the role issuer does not need to store the correspondence between the role and the real identity for a long time, reducing the difficulty and cost in the tracing process and enhancing the privacy security of user data.
[0005] In a first aspect, some embodiments of the present application provide a method for issuing a role certificate, including: receiving a role certificate issuance request sent by a client, where the certificate issuance request carries user identity certificate information, role information, a role signature value, and a third-party institution certificate. The role signature value is obtained by the third-party institution signing the user identity certificate information and the role information, and the role information characterizes the identity attributes of the user in the application scenario; generating a role certificate when it is confirmed that the role certificate issuance request passes the verification, where the role certificate includes: the role information and an extended information item; the extended information item includes: some or all of the information of the user's unique identity ciphertext, the identity certificate issuing institution information ciphertext, the encryption algorithm, and the public key identifier of the regulatory institution; sending the role certificate to the client.
[0006] Some embodiments of the present application generate a role certificate and send it to the client after receiving the certificate issuance request; among them, the role certificate may include role information and an extended information item for managing user identity information. Some embodiments of the present application authorize the regulatory institution to directly associate the user's real identity information in the role certificate, reducing the data storage cost and the risk of data leakage, and having relatively high security.
[0007] In some embodiments, the confirmation that the certificate issuance request passes the verification includes: confirming that the user identity certificate information passes the verification, confirming that the role signature value passes the verification, and confirming that the third-party institution certificate passes the verification.
[0008] Some embodiments of the present application can verify the user's real identity and role information by verifying the user identity certificate information, the role signature value, and the third-party institution certificate, ensuring data security.
[0009] In some embodiments, the extended information item is obtained by the following method: encrypting the user's identity identifier with the public key of the authorized regulatory institution to obtain the user's unique identity ciphertext; where the identity identifier includes at least one of the certificate serial number, ID number, and network number of the user identity certificate information; encrypting the identity certificate issuing institution information with the public key of the regulatory institution to obtain the identity certificate issuing institution information ciphertext.
[0010] Some embodiments of the present application encrypt the user's identity identifier and the issuing institution information with the public key of the authorized regulatory institution to obtain the extended information item, which can realize the binding of the role certificate and the user's real identity, facilitate the subsequent traceability of the real identity, and can control that only the authorized regulatory institution can perform subsequent decryption and traceability to protect the user's privacy.
[0011] In some embodiments, when a user has multiple role certificates, the user's unique identity ciphertext is obtained by the following method: for each role certificate, use the public key of the regulatory agency to encrypt the user's identity identifier to obtain the user's unique identity ciphertext corresponding to each role certificate.
[0012] In some embodiments of the present application, by using the public key encryption algorithm to encrypt the identity identifier of each role certificate, the ciphertexts of the identity identifiers of the same user in each role certificate are different, which can resist the correlation attack between multiple role certificates generated based on the same user identity certificate information, and has relatively high security.
[0013] In a second aspect, some embodiments of the present application provide a method for tracing the true identity based on role certificates, which is applied to an authorized regulatory agency and includes: parsing the role certificate of a user to obtain the extended information items in the role certificate; the extended information items include: some or all of the information of the user's unique identity ciphertext, the identity certificate issuing agency information ciphertext, the encryption algorithm, and the public key identifier of the regulatory agency; the role certificate is obtained by any method embodiment in the first aspect; finding the private key corresponding to the public key identifier, and using the private key to decrypt the user's unique identity ciphertext to obtain the user's identity identifier; wherein, the identity identifier includes: at least one of the certificate serial number, the ID number, and the network number of the user's identity certificate information; tracing the user through the identity identifier to obtain a tracing result.
[0014] In some embodiments of the present application, by parsing the role certificate of a user, the user's unique identity ciphertext in the extended information items is obtained, and then the user's identity identifier is obtained by decrypting with the corresponding private key, and the user's identity tracing is realized through the identity identifier. In the role certificate data structure of this method embodiment, it can be directly associated with the true identity information, and the user's identity can be traced through the role certificate, reducing the tracing cost and difficulty.
[0015] In some embodiments, when the identity identifier is the certificate serial number, the tracing the user's identity information through the identity identifier to obtain a tracing result includes: using the private key to decrypt the identity certificate issuing agency information ciphertext to obtain the identity certificate issuing agency information; obtaining the user's identity certificate information queried from the issuing agency corresponding to the identity certificate issuing agency information, and parsing to obtain the true identity information in the user's identity certificate information; tracing the user through the true identity information to obtain the tracing result.
[0016] In some embodiments of the present application, when the identity identifier is the certificate serial number, the real-name information of the user can be queried from the corresponding certificate issuing authority by determining the certificate issuing authority information of the identity certificate, and then the user identity can be traced, ensuring the accuracy of identity authentication.
[0017] In a third aspect, some embodiments of the present application provide an apparatus for issuing role certificates, including: a receiving module, configured to receive a role certificate issuing request sent by a user terminal, where the certificate issuing request carries user identity certificate information, role information, a role signature value, and a third-party institution certificate, and the role signature value is obtained by the third-party institution signing the user identity certificate information and the role information, and the role information represents the identity attributes of the user in the application scenario; a certificate generation module, configured to generate a role certificate when it is confirmed that the role certificate issuing request passes the verification, where the role certificate includes: the role information and an extended information item; the extended information item includes: some or all of the ciphertext of the user's unique identity identifier, the ciphertext of the certificate issuing authority information of the identity certificate, the encryption algorithm, and the public key identifier of the regulatory authority; a sending module, configured to send the role certificate to the user terminal.
[0018] In a fourth aspect, some embodiments of the present application provide an apparatus for tracing the real identity based on role certificates, which is applied to an authorized regulatory authority, including: an analysis module, configured to analyze the role certificate of the user to obtain the extended information item in the role certificate; the extended information item includes: some or all of the ciphertext of the user's unique identity identifier, the ciphertext of the certificate issuing authority information of the identity certificate, the encryption algorithm, and the public key identifier of the regulatory authority; the role certificate is obtained by any method embodiment in the first aspect; a decryption module, configured to find the private key corresponding to the public key identifier and use the private key to decrypt the ciphertext of the user's unique identity identifier to obtain the user's identity identifier; where the identity identifier includes: at least one of the certificate serial number, the ID number, and the network number of the user identity certificate information; a tracing module, configured to trace the user through the identity identifier to obtain a tracing result.
[0019] In a fifth aspect, some embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described in any embodiment of the first aspect can be implemented.
[0020] In a sixth aspect, some embodiments of the present application provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, the method described in any embodiment of the first aspect can be implemented.
[0021] In a seventh aspect, some embodiments of the present application provide a computer program product, which includes a computer program. When the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the accompanying drawings required for some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0023] Figure 1 System diagram for issuing role certificates provided by some embodiments of the present application;
[0024] Figure 2 Method flowchart for issuing role certificates provided by some embodiments of the present application;
[0025] Figure 3 Method flowchart for real identity tracing based on role certificates provided by some embodiments of the present application;
[0026] Figure 4 Block diagram of the device for issuing role certificates provided by some embodiments of the present application;
[0027] Figure 5 Block diagram of the device for real identity tracing based on role certificates provided by some embodiments of the present application;
[0028] Figure 6 Schematic diagram of an electronic device provided by some embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] The technical solutions in some embodiments of the present application will be described below with reference to the accompanying drawings in some embodiments of the present application.
[0030] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.
[0031] In related technologies, a role certificate only contains necessary role information, such as "an employee of a certain company". This design can effectively prove the role identity while protecting personal privacy by showing a minimized set of information, ensuring a balance between privacy and credibility during the interaction. However, in current technologies, in order to achieve traceability, the role certificate issuing authority needs to store the real identities of all users in association with the role certificates, resulting in a large amount of data and high database construction costs. Moreover, the method of tracing real identities through database association requires long-term storage of role certificates and real identity information. During the long-term storage process, the risk of database attack and tampering is high, and there is also a risk of privacy data leakage. In addition, the supervision process requires the cooperation of the identity issuer to obtain real identities, and the supervisor cannot obtain the association between role identities and real identities on its own. However, in practical applications, the supervision behavior of the supervisor should have a higher degree of freedom and should not be restricted by any relevant parties. Moreover, in practical applications, a user may have multiple roles. During the process of applying for the issuance of role certificates, each role certificate issuance process needs to repeatedly verify the same real identity, resulting in redundant verification operations and being unfavorable to the real-time nature of role certificate issuance.
[0032] As can be seen from the above related technologies, the process of tracing trusted identity verification from role certificates in the existing technology is relatively cumbersome, and the security of storing role certificates and real identity information needs to be improved.
[0033] In view of this, some embodiments of the present application provide a method for issuing role certificates. The role certificates generated by this method not only contain the role information of the user, but also contain extended information items associated with the user. The extended information items can contain the encrypted real identity information of the user. By adding custom extensions to the role certificates, the binding between the role certificates and the identity certificates / real identity information is realized. The association between the real identity and the role certificate is naturally established during the issuance process, reducing the data storage cost and the risk of data leakage. In terms of privacy protection, while achieving the security effect of being anonymous in the foreground and real-name in the background, it can also ensure that only authorized supervisors can trace the real identity corresponding to the role certificate based on the extended information.
[0034] Moreover, a ciphertext processing method with time-varying parameters is introduced between the real-name identity and the role certificate, enabling the establishment of the association between the real-name identity and the role identity while ensuring that unauthorized parties cannot obtain the real-name identity information corresponding to the role certificate and can resist the correlation attack between multiple role certificates generated based on the same identity certificate. Additionally, considering that a user may have multiple role identities in reality, during the issuance process, this application also designs the application for role certificates based on personal identity certificates (i.e., user identity certificate information), verifying the real-name identity by validating the personal identity certificate, which only needs to be verified once when applying for the personal identity certificate, avoiding repeated and cumbersome real-name verification steps and improving the real-time performance of certificate issuance.
[0035] The following combines the attached Figure 1 Exemplarily expounds the overall composition structure of the system for issuing role certificates and identity authentication provided by some embodiments of this application.
[0036] As Figure 1 Shown in the figure, some embodiments of this application provide a system diagram for issuing role certificates and identity authentication. The system for issuing role certificates and identity authentication may include: a user terminal 100, a personal identity certificate issuing agency 200, a role certificate issuing agency 300, a third-party agency 400, and a regulatory agency 500. Among them, the user of the user terminal 100 can apply for a personal identity certificate from the personal identity certificate issuing agency 200. The user can apply for role information from the third-party agency 400 through the user terminal 100 to establish the association between the user and the role. Subsequently, the user can apply for the issuance of a role certificate from the role certificate issuing agency 300 through the user terminal 100. When real identity tracing is required, the regulatory agency 500 can complete the identity tracing through the identity information on the role certificate.
[0037] It should be noted that the personal identity certificate issuing agency 200 and the role certificate issuing agency 300 can be the same agency or multiple independent agencies. In actual application scenarios, there may be multiple personal identity certificate issuing agencies 200 and multiple role certificate issuing agencies 300. Specifically, it can be selected according to the actual scenario, and the embodiments of this application are not limited thereto.
[0038] In some embodiments of this application, the user terminal 100 can be a mobile terminal or a non-portable computer terminal, and the embodiments of this application do not make specific limitations here. The third-party agency 400 can be a certain company agency, which can be specifically determined according to the actual application scenario.
[0039] The following exemplarily expounds Figure 1 the functions of relevant units in
[0040] The following combines the attached Figure 2Exemplarily illustrate the implementation process of issuing a role certificate executed by the role certificate issuing authority 300 provided by some embodiments of the present application.
[0041] Please refer to the attached Figure 2 , Figure 2 For some embodiments of the present application, a method flowchart for issuing a role certificate is provided. The method for issuing a role certificate may include:
[0042] S210, receiving a role certificate issuance request sent by the user terminal. Among them, the certificate issuance request carries user identity certificate information, role information, a role signature value, and a third-party institution certificate. The role signature value is obtained by the third-party institution signing the user identity certificate information and the role information. The role information characterizes the identity attributes of the user in the application scenario.
[0043] For example, in some embodiments of the present application, a user may send a request to the role certificate issuing authority 300 through the user terminal 100 to issue a role identity certificate (as a specific example of the role certificate issuance request). This request carries a personal identity certificate, role information, a role signature value, and a third-party institution certificate.
[0044] Among them, the personal identity certificate is obtained by the user from the personal identity certificate issuing authority 200. Specifically, the user submits real-name identity information to the personal identity certificate issuing authority 200 through the user terminal 100. The personal identity certificate issuing authority 200 verifies the real-name identity information. After the verification is passed, a personal identity certificate is issued to the user. The personal identity certificate can bind the user's entity identity to the personal identity certificate. It should be noted that each personal identity certificate will contain a certificate serial number (serialNumber), which is used as the unique identifier of the personal identity certificate to uniquely label the personal identity certificate.
[0045] After that, the user applies to the third-party institution 400 for role information endorsed by the third-party institution 400 through the user terminal 100. First, the user completes real-name registration at the third-party institution 400 using the personal identity certificate. The third-party institution 400 signs the user's role information and the hash of the user's personal identity certificate with the institution certificate to obtain a role signature value, and establishes the association between the user and the role information. The third-party institution 400 sends the role information and the role signature value to the user terminal 100 so that the user can obtain the relevant information.
[0046] In some embodiments of the present application, before executing S220, the method for issuing a role certificate further includes: confirming that the user identity certificate information passes the verification, confirming that the role signature value passes the verification, and confirming that the third-party institution certificate passes the verification.
[0047] For example, in some embodiments of the present application, the role certificate issuing authority 300 first goes to the personal identity certificate issuing authority 200 to verify the validity of the personal identity certificate provided by the user, verify the signature value of the role information, and verify the validity of the third-party institution certificate.
[0048] S220. When it is confirmed that the role certificate issuing request passes the verification, a role certificate is generated, where the role certificate includes: the role information and the extended information item; the extended information item includes some or all of the information such as the ciphertext of the user's unique identity identifier, the ciphertext of the identity certificate issuing authority information, the encryption algorithm, and the public key identifier of the regulatory authority.
[0049] For example, in some embodiments of the present application, when the user's request passes the verification, a role certificate is issued. In addition to including the minimized set of attribute information (i.e., role information) related to a specific application scenario, such as an employee of a certain insurance company or a food delivery person on a certain platform, etc., in addition, an extended information item of the role certificate needs to be generated. The extended information item may contain content such as the ciphertext of the user's unique identity identifier, the ciphertext of the identity certificate issuing authority information, the encryption algorithm, and the public key identifier of the regulatory authority, so as to realize the associated storage of the role certificate and the user's real-name identity.
[0050] In some embodiments of the present application, the extended information item is obtained by the following method: encrypting the user's identity identifier with the public key of the authorized regulatory authority to obtain the ciphertext of the user's unique identity identifier; where the identity identifier includes at least one of the user's unique identifiers such as the certificate serial number, ID number, and network number of the user identity certificate information; encrypting the identity certificate issuing authority information with the public key of the regulatory authority to obtain the ciphertext of the identity certificate issuing authority information.
[0051] For example, in some embodiments of the present application, the role certificate issuing authority 300 obtains the user's long-term valid unique identity identifier (abbreviated as UID) in the personal identity certificate, such as: any one of the user's unique identifiers such as the certificate serial number serialNumber, ID number, and network number in the personal identity certificate. In addition, different regulatory authorities (such as financial regulatory departments, industrial and commercial regulatory departments, etc.) apply for and store their respective different public key certificates.
[0052] First, the role certificate issuing authority 300 can encrypt the UID and / or UID type combination information (as a specific example of the identity identifier) using the public key of the authorized regulatory agency; the UID types include certificate serial numbers, ID numbers, network numbers, etc., and the UID type combination information can contain at least one of the above. For example, encrypt 1b30...09e1a||certificate serial number using the public key of the regulatory agency to obtain the UID ciphertext (as a specific example of the user's unique identity identifier ciphertext). This can ensure that only the authorized regulatory agency can decrypt it.
[0053] Secondly, considering the situation where the serial numbers of the personal identity certificates issued by different personal identity certificate issuing authorities 200 for a user are different, in order to ensure traceability, if the UID or the UID type combination information contains the certificate serial number serialNumber in the personal identity certificate, then it is necessary to encrypt the personal identity certificate issuing authority information of the personal identity certificate using the public key of the authorized regulatory agency to obtain the encrypted personal identity certificate issuing authority information.
[0054] Finally, write the encrypted UID ciphertext, the encrypted personal identity certificate issuing authority information (which can be selected according to the actual situation), the encryption algorithm, and the encrypted public key identifier into the extension information item in the role certificate. Among them, the public key identifier can be the digest value of the public key, or the label of the corresponding key in the regulatory agency's key library, etc. Moreover, when the key of the regulatory agency is updated, the corresponding decryption private key can be mapped according to the public key identifier to achieve key update.
[0055] Based on the above steps, an example of the generated extension item information is as follows:
[0056] Processing method of UID based on public key encryption
[0057] PkEncryptUID::=SEQUENCE{
[0058] uidCipher BIT String,-- Encrypted UID and UID type combination information
[0059] uidAuthority BIT String OPTIONAL,-- Encrypted personal identity certificate issuing authority
[0060] algorithm AlgorithmIdentifer,-- Encryption algorithm
[0061] PublicKeyIdentifier OCTET STRING,-- Public key identifier
[0062] }
[0063] In some embodiments of the present application, when a user has multiple role certificates, the user unique identity ciphertext is obtained by the following method: for each role certificate, use the public key of the regulatory agency to encrypt the user's identity identifier to obtain the user unique identity ciphertext corresponding to each role certificate.
[0064] For example, in some embodiments of the present application, to ensure the security of each role certificate, when encrypting multiple role certificates of the same user, use the public key of the regulatory agency to encrypt the user's identity identifier to obtain the user unique identity ciphertext corresponding to each role certificate. The public key encryption algorithm makes each encryption result different by introducing a random number, which can ensure that the encrypted data processed in the role certificates of the same user entity is different in different application scenarios and can resist the correlation attack between multiple role certificates of the same entity. The public key encryption algorithm used in the embodiments of the present application should select a public key encryption algorithm that introduces time-varying parameters for each encryption. The RSA public key encryption algorithm without time-varying parameters needs to add a random number before it is applicable to the present application. Specifically, it can be confirmed according to the actual application scenario, and the embodiments of the present application do not make specific limitations here.
[0065] Through the above method, the association relationship between the role certificate and the real identity can be established, and only the corresponding authorized regulatory agency or issuing agency can restore the UID to achieve the security effect of anonymity in the front end and real name in the back end.
[0066] S230, send the role certificate to the user terminal.
[0067] For example, in some embodiments of the present application, the role certificate issuing agency 300 may send the issued role certificate to the user terminal 100.
[0068] From some embodiments of the present application described above, it can be seen that the present application embeds the information related to the UID encrypted into the extended information item of the role certificate to solve the problem of traceability of the real identity and privacy security in the role certificate. The type of the public key encryption algorithm used in the embodiments of the present application is not limited, and the type of the encryption algorithm can be flexibly selected according to the actual application scenario.
[0069] After the role certificate is issued, the real identity of the user can be traced through the extended information item in the role certificate. The following combines the attached Figure 3 Exemplarily elaborate the specific process of real identity tracing based on the role certificate executed by the authorized regulatory agency provided by some embodiments of the present application.
[0070] Please refer to the attached Figure 3 , Figure 3A flowchart of a method for real identity tracing based on role certificates provided for some embodiments of the present application. The method for real identity tracing based on role certificates may include:
[0071] S310. Parse the role certificate of the user to obtain the extended information items in the role certificate. The extended information items include some or all of the information of the user's unique identity identifier ciphertext, the identity certificate issuing agency information ciphertext, the encryption algorithm, and the public key identifier of the regulatory agency.
[0072] For example, in some embodiments of the present application, the role certificate is issued through the method embodiments provided above. When a dispute occurs between the two communicating parties, such as arbitration for economic losses caused to one party, the regulatory agency needs to trace back to the real identity of the user. The regulatory agency obtains the role certificate and, through parsing, obtains the UID ciphertext of the combined information of the user's unique identity identifier UID and UID type encrypted by the public key, the encrypted identity certificate issuing agency information ciphertext, the encryption algorithm, and the encrypted public key identifier.
[0073] S320. Search for the private key corresponding to the public key identifier and use the private key to decrypt the user's unique identity identifier ciphertext to obtain the user's identity identifier. The identity identifier includes at least one of the certificate serial number, the ID number, and the network number of the user's identity certificate information.
[0074] For example, in some embodiments of the present application, the regulatory agency uses the public key identifier to retrieve the corresponding private key and uses the private key to decrypt the UID ciphertext to obtain the user's long-term valid unique identity identifier UID or the combined information of UID types, such as at least one of the user's unique identifiers including the certificate serial number serialNumber, the ID number, the network certificate, and the network number in the personal identity certificate.
[0075] S330. Trace the user through the identity identifier to obtain a trace result.
[0076] For example, in some embodiments of the present application, the authentication of the user's identity can be achieved through the identity identifier UID or the combined information of UID types to obtain an authentication result (as a specific example of the authentication result). If the UID is the ID number information, the regulatory agency can directly obtain the real identity information to achieve the authentication of the user. If the UID is the network certificate / network number information, the regulatory agency can go to the relevant department to query the real identity information corresponding to the network certificate / network number to achieve the tracing of the user.
[0077] In some embodiments of the present application, when the identity identifier is the certificate serial number, S330 may include: decrypting the ciphertext of the identity certificate issuing authority information using the private key to obtain the identity certificate issuing authority information; obtaining the user identity certificate information queried from the issuing authority corresponding to the identity certificate issuing authority information, and parsing and obtaining the real identity information in the user identity certificate information; tracing the user through the real identity information to obtain the tracing result. The tracing result indicates whether the user's identity information is true.
[0078] For example, in some embodiments of the present application, if the UID is the certificate serial number serialNumber, the regulatory agency also needs to use the private key to decrypt the ciphertext of the identity certificate issuing authority information to obtain the issuing authority uidAuthority of the personal identity certificate (as a specific example of the personal identity certificate issuing authority 200). The regulatory agency goes to the issuing authority uidAuthority and queries the corresponding personal identity certificate using the certificate serial number to obtain the real identity information of the user, thereby realizing the tracing of the user's real identity.
[0079] As can be seen from some embodiments of the present application above, the role certificate contains role information related to a specific application scenario and the user's identity information, and authenticates the user's identity by presenting a minimized set of attribute information. The role certificate contains the encrypted user unique identity identifier uidCipher, establishing an association between the real-name identity and the role identity, and only an authorized agency can decrypt to obtain the UID, achieving the security effect of anonymity in the front end and real-name in the back end. The processing method of the encrypted UID in the role certificate introduces time-varying parameters and is encrypted using the public key of the authorized regulatory agency. The public key encryption process introduces a random number each time, so that the same UID is encrypted multiple times, and the ciphertext obtained each time is different. In reality, a user may have a large number of roles, while the real-name identity is relatively fixed and unique. By introducing the encrypted UID with time-varying parameters in the role certificate, not only can the association between the real-name identity and the role identity be established, but also the association attack of a real-name identity in different scenarios can be prevented.
[0080] The role certificate issuing authority obtains the public key of the authorized regulatory agency and encrypts the UID using the public key of the authorized regulatory agency. During the tracing process, only the corresponding authorized regulatory agency can decrypt, which has high security. To achieve traceability, an encrypted UID is introduced during the process of issuing the role certificate, enabling the natural association of the role identity and the real-name identity without establishing a database to store the association between the real-name identity and the role certificate. The association relationship between the role certificate and the real-name identity is directly established during the issuing process, binding from the source. Compared with the traditional database established between the real-name identity and the role certificate, it increases the difficulty of attack and reduces the opportunity of attack (such as tampering with the database).
[0081] Moreover, this application also increases the efficiency of role certificate issuance. In reality, a user may have multiple roles. This application is designed as a mechanism for issuing role certificates based on personal identity certificates. When issuing a personal identity certificate, only face scanning is required once. The issuing agency verifies the personal identity certificate instead of verifying the real-name identity. There is no need to repeat face scanning verification. This can effectively improve the efficiency of role certificate issuance and improve the real-time nature of certificate issuance.
[0082] Please refer to Figure 4 , Figure 4 The block diagram of the device for issuing a role certificate provided by some embodiments of the present application is shown. It should be understood that the device for issuing a role certificate corresponds to the above method embodiment and can execute each step involved in the above method embodiment. The specific functions of the device for issuing a role certificate can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.
[0083] Figure 4 The device for issuing a role certificate includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the device for issuing a role certificate. The device for issuing a role certificate includes: a receiving module 410, which is used to receive a role certificate issuance request sent by a user terminal, wherein the certificate issuance request carries user identity certificate information, role information and a role signature value, and the role signature value is obtained by signing the user identity certificate information and the role information by a third-party organization, and the role information represents the identity attributes of the user in the application scenario; a certificate generation module 420, which is used to generate a role certificate when confirming that the role certificate issuance request has been verified, wherein the role certificate includes: the role information and extended information items; the extended information items include: part or all of the information in the user's unique identity identifier ciphertext, the identity certificate issuing agency information ciphertext, the encryption algorithm and the public key identifier of the regulatory agency; a sending module 430, which is used to send the role certificate to the user terminal.
[0084] Please refer to Figure 5 , Figure 5 The block diagram of the composition of the device for tracing the real identity based on the role certificate provided by some embodiments of the present application is shown. It should be understood that the device for tracing the real identity based on the role certificate corresponds to the above method embodiment and can execute each step involved in the above method embodiment. The specific functions of the device for tracing the real identity based on the role certificate can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.
[0085] Figure 5The device for tracing the real identity based on the role certificate includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the device for tracing the real identity based on the role certificate. The device for tracing the real identity based on the role certificate is applied to an authorized regulatory agency and includes: a parsing module 510, which is used to parse the user's role certificate to obtain extended information items in the role certificate; the extended information items include: part or all of the information in the user's unique identity ciphertext, the identity certificate issuing agency information ciphertext, the encryption algorithm and the public key identifier of the regulatory agency; the role certificate is obtained by the method described in any one of claims 1-4; a decryption module 520, which is used to find the private key corresponding to the public key identifier, and use the private key to decrypt the user's unique identity ciphertext to obtain the user's identity; wherein the identity includes: at least one of the certificate serial number, identity card number and network number of the user's identity certificate information; a tracing module 530, which is used to trace the user through the identity identifier to obtain a tracing result.
[0086] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.
[0087] Some embodiments of the present application further provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the operations of the method corresponding to any of the above methods provided in the above embodiments.
[0088] Some embodiments of the present application further provide a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the operations corresponding to any of the above methods provided in the above embodiments.
[0089] like Figure 6 As shown, some embodiments of the present application provide an electronic device 600, which includes: a memory 610, a processor 620, and a computer program stored in the memory 610 and executable on the processor 620, wherein the processor 620 can implement a method as described in any of the above embodiments when reading the program from the memory 610 through a bus 630 and executing the program.
[0090] Processor 620 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 620 can be a microprocessor.
[0091] The memory 610 can be used to store instructions executed by the processor 620 or data related to the instruction execution process. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 620 of the embodiments of the present disclosure can be used to execute the instructions in the memory 610 to implement the methods shown above. The memory 610 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.
[0092] The above are only the embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0093] As described above, these are only the specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
[0094] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
Claims
1. A method for issuing a role certificate, characterized in that Including: Receiving a role certificate issuance request sent by a user terminal, where the certificate issuance request carries user identity certificate information, role information, a role signature value, and a third-party institution certificate. The role signature value is obtained by the third-party institution signing the user identity certificate information and the role information. The role information characterizes the identity attributes of the user in the application scenario; Generating a role certificate when it is confirmed that the role certificate issuance request passes verification, where the role certificate includes: the role information and an extended information item; the extended information item includes: some or all of the information of the user's unique identity ciphertext, the identity certificate issuing institution information ciphertext, the encryption algorithm, and the public key identifier of the regulatory institution; Sending the role certificate to the user terminal.
2. The method according to claim 1, characterized in that, The confirmation that the certificate issuance request passes verification includes: Confirming that the user identity certificate information passes verification, confirming that the role signature value passes verification, and confirming that the third-party institution certificate passes verification.
3. The method according to claim 1 or 2, characterized in that, The extended information item is obtained by the following method: Encrypting the user's identity identifier with the public key of the authorized regulatory institution to obtain the identity identifier ciphertext; where the identity identifier includes at least one of the certificate serial number, ID number, and network number of the user identity certificate information; Encrypting the identity certificate issuing institution information with the public key of the regulatory institution to obtain the identity certificate issuing institution information ciphertext.
4. The method according to claim 1 or 2, characterized in that, When a user has multiple role certificates, the user's unique identity ciphertext is obtained by the following method: Encrypting the user's identity identifier with the public key of the regulatory institution for each role certificate to obtain the user's unique identity ciphertext corresponding to each role certificate.
5. A method for tracing real identities based on role certificates, characterized in that, Applied to an authorized regulatory institution, the method includes: Parsing the user's role certificate to obtain the extended information item in the role certificate; the extended information item includes: some or all of the information of the user's unique identity ciphertext, the identity certificate issuing institution information ciphertext, the encryption algorithm, and the public key identifier of the regulatory institution; the role certificate is obtained by the method described in any one of claims 1-4; Searching for the private key corresponding to the public key identifier and decrypting the identity identifier ciphertext with the private key to obtain the user's identity identifier; where the identity identifier includes at least one of the certificate serial number, ID number, and network number of the user identity certificate information; Tracing the user through the identity identifier to obtain a tracing result.
6. The method according to claim 5, characterized in that, When the identity identifier is the certificate serial number, the tracing the user's identity information through the identity identifier to obtain a tracing result includes: Decrypting the identity certificate issuing institution information ciphertext with the private key to obtain the identity certificate issuing institution information; Obtaining the user identity certificate information queried from the issuing institution corresponding to the identity certificate issuing institution information and parsing to obtain the real identity information in the user identity certificate information; Tracing the user through the real identity information to obtain the tracing result.
7. A device for issuing role certificates, characterized in that, Including: A receiving module, configured to receive a role certificate issuance request sent by a user terminal. The certificate issuance request carries user identity certificate information, role information, a role signature value, and a third-party institution certificate. The role signature value is obtained by the third-party institution signing the user identity certificate information and the role information. The role information characterizes the identity attributes of the user in the application scenario. A certificate generation module, configured to generate a role certificate when it is confirmed that the role certificate issuance request passes the verification. The role certificate includes the role information and an extended information item. The extended information item includes some or all of the information of the user unique identity identifier ciphertext, the identity certificate issuing authority information ciphertext, the encryption algorithm, and the public key identifier of the regulatory agency. A sending module, configured to send the role certificate to the user terminal.
8. A device for tracing real identities based on role certificates, characterized in that, Applied to a regulatory agency, the device includes: An analysis module, configured to analyze the role certificate of the user to obtain the extended information item in the role certificate. The extended information item includes some or all of the information of the user unique identity identifier ciphertext, the identity certificate issuing authority information ciphertext, the encryption algorithm, and the public key identifier of the regulatory agency. The role certificate is obtained by the method according to any one of claims 1-4. A decryption module, configured to find the private key corresponding to the public key identifier and use the private key to decrypt the user unique identity identifier ciphertext to obtain the user's identity identifier. The identity identifier includes at least one of the certificate serial number, the ID number, and the network number of the user identity certificate information. A tracing module, configured to trace the user through the identity identifier to obtain a tracing result.
9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is run by a processor, it executes the method according to any one of claims 1-6.
10. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and running on the processor. When the computer program is run by the processor, it executes the method according to any one of claims 1-6.