Network equipment communication system and method based on distributed digital identity

By introducing distributed digital identity technology, IoT devices can automatically discover and communicate securely, solving the problems of identity information leakage and low data security caused by IoT devices relying on centralized services, and realizing decentralized, secure and reliable communication.

CN120475027APending Publication Date: 2025-08-12TRAVELSKY TECHNOLOGY LIMITED
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510675732.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

Communication connections between IoT devices rely on centralized services, which can easily lead to identity information leakage and low data security.

Method used

Using distributed digital identity (DID) technology, the device and its IP address are automatically discovered through the DID discovery component, and the DID routing component provides data routing and encryption services to realize decentralized communication between devices.

Benefits of technology

Reduce the leakage of device identity information, enhance the security of data transmission, and ensure the security and reliability of direct communication between devices and data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120475027A_ABST
    Figure CN120475027A_ABST
Patent Text Reader

Abstract

The invention discloses a network device communication system and method based on distributed digital identity, and relates to the field of Internet of Things, the system comprises a physical device layer and a DI D service layer, each DI D physical device in the physical device layer at least comprises a DI D discovery component, a DI D routing component and a DI D application set component, the DI D discovery component is used for discovering a new DI D device and a corresponding device I P address and providing DI D device state maintenance, the DI D routing component is used for providing a data routing service and a data automatic encryption service for a DI D application layer, and a plurality of DI D application programs are stored and run in the DI D application set component; and the DI D service layer is in network communication with the DI D discovery component in each DI D physical device. According to the invention, the technical problems of identity information leakage and low data security caused by dependence of communication connection between Internet of Things devices on centralized service in the prior art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet of Things technology or other related fields, and in particular to a network device communication system and method based on distributed digital identity. Background Art

[0002] In traditional identity systems, identity information is typically centrally managed and authenticated by a centralized organization. This model presents problems such as single points of failure, high risk of data leakage, and limited user control over their identity information. For example, if a centralized organization's database is hacked, the identity information of a large number of users could be leaked, posing a serious security and privacy threat to users.

[0003] In related technologies, with the rapid development of the digital economy and the widespread use of IoT devices, the demand for identity recognition is growing. For example, communication and interaction between IoT devices also require effective identity recognition and authentication to ensure data security and the normal operation of devices. In IoT systems, communication between devices is the foundation of system operation, and the security of data transmission between devices is an important component of IoT system security. Traditional communication between IoT devices mainly relies on IP addresses for data transmission, which has the following problems: inter-device communication relies on IP addresses. When the IP address of a device changes, the device's IP address needs to be reconfigured, resulting in communication interruption and affecting the normal operation of the device.

[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0005] The embodiments of the present invention provide a network device communication system and method based on distributed digital identity, which at least solves the technical problems in the related art that the communication connection between IoT devices relies on centralized services, which easily causes identity information leakage and low data security.

[0006] According to one aspect of an embodiment of the present invention, a network device communication system based on distributed digital identity is provided, comprising: a physical device layer, comprising a plurality of distributed digital identity (DID) physical devices, wherein the plurality of distributed digital identity (DID) physical devices constitute a DID device network, wherein each DID physical device comprises at least a DID discovery component, a DID routing component, and a DID application set component, wherein the DID discovery component is used to discover new DID devices and corresponding device IP addresses and provide DID device status maintenance, wherein the DID routing component is used to provide data routing services and data automatic encryption services for the DID application layer, wherein the DID application set component stores and runs a plurality of DID applications, wherein each DID application interacts with DID applications in other DID physical devices; and a DID service layer, which performs network communication with the DID discovery component in each of the DID physical devices, comprising a DID device manufacturer code management component and a DID basic service component, wherein the functions provided by the DID basic service component include: DID registration, DID resolution, and DID device update, and wherein the DID device manufacturer code management component is used to query the DID service interface address provided externally by the DID device manufacturer based on the DID device manufacturer code.

[0007] Optionally, the DID discovery component is further used to provide a DID document query function to the DID routing component, wherein the DID document records entity information corresponding to the entity represented by each DID, wherein the entity information includes at least one of the following: an entity public key, an entity service endpoint, and metadata, wherein the entity public key is used to verify the identity and signature of the entity, the entity service endpoint is used to indicate the interaction strategy between entities, and the metadata includes the creation time and update time of each DID.

[0008] Optionally, when the DID routing component provides automatic data encryption services for the DID application layer, the DID data format used includes: source device DID, destination DID, application code, data encryption protocol, data encryption key, encrypted data, signature algorithm, and data signature.

[0009] Optionally, when the DID discovery component in the DID physical device communicates with the DID service layer over the network, the DID specification protocol adopted is: DID mode identifier, manufacturer code, and device unique identifier; wherein, the DID mode identifier is fixed to dev, and the manufacturer code is used to query the service interface address of the corresponding DID device manufacturer.

[0010] According to another aspect of an embodiment of the present invention, a network device communication method based on distributed digital identity is also provided, which is applied to any of the above-mentioned network device communication systems based on distributed digital identity, and the network device communication method includes: receiving data to be sent, application code and destination DID of a source application, and obtaining the IP address and DID document of the peer DID device corresponding to the destination DID from the DID discovery component, and encrypting the data to be sent using a pre-randomly generated symmetric encryption key to generate an encrypted data packet; obtaining the entity public key corresponding to the entity represented by the destination DID in the DID document, and encrypting the symmetric encryption key to generate a data encryption key; using the private key corresponding to the DID document corresponding to the source device DID, signing the data spliced by the source device DID, the destination DID, the application code, the encryption protocol, the data encryption key, the encrypted data packet, and the signature algorithm; assembling the signed source device DID, the destination DID, the application code, the encryption protocol, the data encryption key, the encrypted data packet, the signature algorithm and the data signature using a preset DID data format to generate a target data packet; and sending the target data packet to the DID routing component of the peer DID device.

[0011] Optionally, after sending the target data packet to the DID routing component of the peer DID device, the network device communication method further includes: the peer DID device parses the target data packet according to a preset DID data format to obtain the source device DID, the destination DID, the application code, the encryption protocol, the data encryption key, the encrypted data packet, the signature algorithm and the data signature; the peer DID device uses the public key corresponding to the source device DID to sign and visa; when the signature and visa result indicates that the received data is complete, the peer DID device uses the destination DID to decrypt the data encryption key, and uses the decrypted data encryption key to decrypt the encrypted data packet to obtain the data to be sent; the DID routing component in the peer DID device transmits the data to be sent to the DID target application according to the registration information of the source application.

[0012] Optionally, the network device communication method also includes: after the DID discovery component receives the DID network join request, parsing the DID network join request to obtain the source device DID and IP address; establishing a mapping relationship between the source device DID and the IP address, and storing the mapping relationship to the DID routing component; publishing the source device DID and IP address to each DID physical device in the DID device network.

[0013] Optionally, the network device communication method also includes: the DID discovery component sends an address query request to the DID device manufacturer code management component corresponding to the source device DID, and queries the DID service interface address provided to the outside by the DID device manufacturer according to the manufacturer code carried in the address query request; the DID discovery component sends a DID document request to the queried DID service interface address, and caches the DID document returned by the DID service interface to the local device.

[0014] Optionally, the network device communication method also includes: after receiving a DID device offline message, updating the local device status cache according to the DID device offline message, marking the status of the offline DID physical device as offline, and updating the routing table of the DID routing component, deleting the routing entry associated with the offline DID physical device; publishing the DID device offline message associated with the offline DID physical device to each DID physical device in the DID device network.

[0015] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned network device communication methods based on distributed digital identity.

[0016] According to another aspect of an embodiment of the present invention, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the above-mentioned network device communication methods based on distributed digital identity.

[0017] According to another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program, which, when executed by a processor, implements the steps of any one of the above-mentioned network device communication methods based on distributed digital identities.

[0018] In this disclosure, by introducing DID technology, each IoT device has a unique identity identifier, reducing large-scale device identity information leakage. Through the DID discovery component, IoT devices can automatically discover other devices and their IP addresses in the network without relying on centralized services to query and forward device information, ensuring direct communication between devices, reducing the chance of data exposure during transmission, and enhancing the security of data transmission. The DID routing component provides a secure data transmission channel for communication between devices, avoiding the leakage of keys during transmission. Combining DID technology with the communication mechanism of IoT devices realizes decentralized, secure and reliable communication between devices, thereby solving the technical problem in related technologies that the communication connection between IoT devices relies on centralized services, which is prone to identity information leakage and low data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0020] Figure 1 is a schematic diagram of an optional distributed digital identity-based network device communication system according to an embodiment of the present invention;

[0021] Figure 2 1 is an architectural diagram of an optional distributed digital identity (DID) device secure communication system according to an embodiment of the present invention;

[0022] Figure 3 is a flow chart of an optional method for network device communication based on distributed digital identity according to an embodiment of the present invention;

[0023] Figure 4 This is a hardware structure block diagram of an electronic device (or mobile device) for a network device communication method based on distributed digital identity according to an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0025] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] To facilitate those skilled in the art to understand the present invention, some of the terms or nouns involved in the embodiments of the present invention are explained below:

[0027] Decentralized Identifier (DID) is a new type of identifier used to uniquely identify entities such as individuals, organizations, and devices in a decentralized system. DID only requires the same uniqueness as traditional IDs within a specific scope. In this invention, DID is set to comply with W3C specifications and has the following format: scheme: method: method-specific-identifer.

[0028] The scheme refers to the DID schema identifier, while the method refers to the DID method. The DID method primarily defines how the DID issuer implements various DID features, such as DID registration, resolution to a DID Document, and DID updates and deactivations. The method-specific-identifer is a unique identifier within a method.

[0029] A DID Document is a set of structured information associated with a DID, used to describe the attributes, capabilities, and other related information of the entity associated with the DID.

[0030] DID Device: A DID physical device. In this invention, a DID device refers to a device with a fixed and globally unique ID. The DID has the following specifications: dev:manufacturer:device-identifier.

[0031] The DID scheme is always dev. Manufacturer: The DID manufacturer or provider code, consisting of only characters a-z, with a fixed length of 5 characters and is case-insensitive. Device-Identifier: A unique identifier within the same manufacturer, with a fixed length of 56 characters, generated by the manufacturer.

[0032] DID Router refers to the routing component within a DID physical device, which is responsible for providing data routing and automatic data encryption services for DID applications, ensuring that data is securely protected during communication between devices.

[0033] DID Discovery refers to the discovery component within a DID physical device, which is used to automatically discover other DID devices in the network and resolve DIDs to corresponding DID documents or IP addresses. It also provides cache management functions for DID documents to improve data access speed and reduce network load.

[0034] DID Service is a component that provides basic DID services, including DID registration, DID resolution, DID update, and DID abandonment operations. In this invention, it is a bridge for communication between DID devices and the DID Manufacturer Registry.

[0035] DID Manufacturer Registry: A component used to manage the registration of DID device manufacturer codes. In this invention, an open query service is provided, which mainly queries the DID service interface address disclosed by the DID device manufacturer based on the manufacturer code.

[0036] DID Application: An application or system running on a DID device, developed and maintained by the user to complete the user's business functions.

[0037] UDP, User Datagram Protocol, is a connectionless transport layer protocol used to transmit datagrams on the network.

[0038] TCP, the Transmission Control Protocol, is a connection-oriented, reliable transport layer protocol used to transmit data streams over the network. It establishes a connection through a three-way handshake and provides error detection and correction mechanisms to ensure that data is delivered intact and in order.

[0039] IGMP, Internet Group Management Protocol, is a protocol used in multicast networks that allows hosts to report their multicast group memberships to directly connected routers. For DID device networks, it can be used in cross-network environments to support multicast communication.

[0040] P2P (Peer-to-Peer) is a distributed network model in which each node (peer) acts as both a client and a server, communicating directly with each other and sharing resources. This model is useful for device discovery and communication in distributed networks.

[0041] It should be noted that the network device communication method and apparatus based on distributed digital identity in the present disclosure can be used in the field of Internet of Things technology. When secure communication of network devices is achieved based on distributed digital identity, it can also be used in any field other than the field of Internet of Things technology. When secure communication of network devices is achieved based on distributed digital identity, the present disclosure does not limit the application field of the network device communication method and apparatus based on distributed digital identity.

[0042] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) collected by this disclosure are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of the relevant regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation portals for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or institution through the interface, and obtain relevant information after receiving the consent information fed back by the aforementioned user or institution.

[0043] It should be noted that in this disclosure, when collecting and analyzing customer information, the corresponding operation entrance is provided for users to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered.

[0044] The following embodiments of the present invention can be applied to various systems / applications / devices for network device communications based on distributed digital identities. The implementation scenario of the technical solution of the present invention can be in a decentralized distributed network environment, such as addressing the secure communication issues of digital identities (DIDs) in the fields of the Internet of Things (IoT), blockchain applications, digital transactions, and digital asset management. For example, it can be applied to Internet of Things (IoT) device communications: In the IoT environment, a large number of devices (such as smart home devices, industrial sensors, and Internet of Vehicles devices) need to frequently exchange data. These devices use DIDs for identification and authentication in a decentralized network. The solution of the present invention can automatically discover these devices and maintain their status, ensuring secure and reliable communication between devices. Alternatively, it can be applied to identity recognition scenarios in blockchain networks. Through the solution of the present invention, nodes in the blockchain network can use DIDs for identity authentication, while protecting the privacy and security of transaction and communication data through secure data routing and encryption mechanisms. In addition, the technical solution of the present invention can also be applied to digital asset management scenarios. Individuals or organizations may own a large number of digital assets, such as cryptocurrencies, digital certificates, copyrights, etc. DID technology can provide unique identification and security control for these assets. The solution of the present invention can conveniently manage access and control permissions of these assets through automatic discovery of DID Discovery and secure data transmission of DID Router.

[0045] Compared to existing technologies that typically rely on centralized services for device discovery and connection within a network, the present invention's solution, through the DID Discovery component and a customized DID Discovery Protocol, enables automatic discovery of DID devices within the network without relying on centralized services, thereby improving network flexibility and stability. Furthermore, the present invention's solution implements intelligent data routing through the DID Router component and uses the DID DATA format to encrypt and sign transmitted data, ensuring the security and integrity of data during transmission.

[0046] The present invention will be described in detail below with reference to various embodiments.

[0047] Example 1

[0048] According to one aspect of an embodiment of the present invention, a network device communication system based on distributed digital identity is provided. The network device communication system based on distributed digital identity includes multiple layers, mainly physical layer and service layer, to realize network data transmission based on distributed digital identity.

[0049] Figure 1 is a schematic diagram of an optional network device communication system based on distributed digital identity according to an embodiment of the present invention. Figure 1As shown, the network device communication system based on distributed digital identity includes: a physical device layer 101 and a DID service layer 102.

[0050] Among them, the physical device layer 101 includes multiple distributed digital identity DID physical devices ( Figure 1 (As shown in the figure, two DID physical devices are shown in the figure), multiple distributed digital identity DID physical devices form a DID device network, and each DID physical device includes at least: a DID discovery component, a DID routing component and a DID application set component. The DID discovery component is used to discover new DID devices and corresponding device IP addresses, and provide DID device status maintenance. The DID routing component is used to provide data routing services and data automatic encryption services for the DID application layer. The DID application set component stores and runs multiple DID applications, and each DID application interacts with the DID applications in other DID physical devices.

[0051] In this embodiment, the physical device layer 101 constitutes a core network, which is built by many distributed digital identity DID physical devices. Figure 1 While only two DID physical devices are shown schematically, this network can be expanded to any number of devices, covering a wide range of geographical areas and application scenarios. Each participating DID physical device embeds three key components: DID discovery, DID routing, and DID application set. These components work together to achieve a secure, autonomous, and decentralized communication ecosystem.

[0052] Among them, the DID discovery component is used to identify and locate each other between devices in the network. By implementing the DID Discovery Protocol, this component can scan and identify newly connected DID devices in the network and the IP addresses of these devices, thereby establishing a real-time updated device directory. In addition, the DID discovery component can also continuously monitor the online or offline status of the device to ensure that all members of the network can promptly know the status changes of their peers and adjust the communication strategy. Through active or passive methods, such as monitoring the Join and Ack messages and the offline message Leave, the DID discovery component can maintain a healthy and accurate view of the network topology and achieve efficient and secure communication on the network.

[0053] The DID routing component is used to improve the security and efficiency of data transmission. When providing services to the DID application layer, it is not only responsible for the precise routing of data but also undertakes the core task of data encryption. Optionally, when data is to be transmitted from one device to another, the DID routing component first obtains the DID and IP address information of the target device from the DID discovery component. It then selects an appropriate encryption method, generates an encryption key, and encrypts the transmitted data, ensuring that even if the data is intercepted during network transmission, it cannot be easily deciphered. Next, the encryption key is re-encrypted using the public key of the target DID device, forming a key package that is sent along with the data. Data integrity is ensured through digital signatures. Key data elements are signed using the private key of the source DID device, allowing the recipient to verify the source and integrity of the data, preventing data tampering or forgery, and ensuring the reliability and privacy of the communication link.

[0054] In the embodiments of the present invention, the DID application set component is the functional carrier unit of the DID physical device, and multiple DID applications can be deployed. These applications serve the needs of different business scenarios, such as smart home control, supply chain management, and digital copyright transactions. The DID application is designed to run independently while also having the ability to exchange data with similar applications in other DID devices. By calling DID routing components and services, DID applications can achieve cross-device data transmission without directly accessing the underlying network details, and the security of the data during the transmission process is guaranteed, thereby supporting flexibility and scalability in various business scenarios.

[0055] Optionally, the DID discovery component is also used to: provide a DID document query function to the DID routing component, wherein the DID document records entity information corresponding to the entity represented by each DID, wherein the entity information includes at least one of the following: an entity public key, an entity service endpoint, and metadata, the entity public key is used to verify the identity and signature of the entity, the entity service endpoint is used to indicate the interaction strategy between entities, and the metadata includes the creation time and update time of each DID.

[0056] It should be noted that the entity public key in this embodiment is used to verify the authenticity of the entity's identity and the reliability of the data signature, which is key to achieving trust in decentralized networks. The entity service endpoint information clarifies the interaction between entities, such as the port and protocol used for data transmission. This information enables different devices to establish connections and exchange data, enhancing system compatibility and interoperability.

[0057] In addition, the metadata provided in this embodiment, such as the record of creation time and update time, can track the status changes of DID to maintain the latest status information of DID devices in the network.

[0058] Optionally, when the DID routing component provides automatic data encryption services for the DID application layer, the DID data format used includes: source device DID, destination DID, application code, data encryption protocol, data encryption key, encrypted data, signature algorithm, and data signature.

[0059] At the data transmission security level, the DID routing component in this embodiment provides an automatic data encryption function, which is implemented based on a customized DID data format, which includes fields such as the source device DID, destination DID, application code, data encryption protocol, data encryption key, encrypted data, signature algorithm, and data signature. The source device DID and destination DID respectively indicate the starting and end points of data transmission; the application code, like the port number in the network protocol, identifies the specific application and facilitates the accurate distribution of data; the data encryption protocol and key ensure the confidentiality of data during transmission; the encrypted data, signature algorithm, and data signature further verify the integrity of the data and the authenticity of the source, together forming a complete data protection framework.

[0060] Optionally, when the DID discovery component in the DID physical device communicates with the DID service layer over the network, the DID specification protocol adopted is: DID mode identifier, manufacturer code, and device unique identifier; among which, the DID mode identifier is fixed to dev, and the manufacturer code is used to query the service interface address of the corresponding DID device manufacturer.

[0061] In the network communication between the DID physical device and the DID service layer, this embodiment adopts the DID structure under the W3C specification, that is, a three-segment DID consisting of a DID mode identifier, a manufacturer code, and a device unique identifier. Here, the DID mode identifier is fixed to "dev" to distinguish DID devices from non-device entities. The format of the manufacturer code is set by itself, generally a string consisting of five lowercase letters, which is used to uniquely identify the device manufacturer globally, making it easy to quickly locate the manufacturer service interface during the DID discovery phase, thereby obtaining device-related DID documents. The device unique identifier is generated by the manufacturer to ensure uniqueness among products of the same manufacturer.

[0062] The DID service layer 102 communicates with the DID discovery component in each DID physical device over the network, including: a DID device manufacturer code management component and a DID basic service component. The functions provided by the DID basic service component include: DID registration, DID resolution, and DID device update. The DID device manufacturer code management component is used to query the DID service interface address provided by the DID device manufacturer based on the DID device manufacturer code.

[0063] In this embodiment, the DID service layer 102 forms the core component of the distributed digital identity device network. It is responsible for network communication with the DID discovery components in each DID physical device, ensuring decentralized management and secure interaction of identity information. The DID service layer 102 is subdivided into two key subcomponents: the DID device manufacturer encoding management component and the DID basic service component. These two components work together to ensure the security, reliability, and efficiency of the DID device network.

[0064] Among them, the DID basic service component provides a series of basic services to support the identity management of DID devices. Specifically, this component includes the following key functions: DID registration, which allows new DID devices to register their identities in the DID network, ensuring that the DID of each device is unique globally and complies with W3C specifications. This not only enhances the credibility of the device identity, but also facilitates subsequent communication between devices and secure data transmission. DID resolution provides DID document resolution services for each entity in the network. By parsing the DID document, the entity attributes, public key information and service endpoint details associated with a specific DID can be obtained, laying the foundation for secure communication. DID device update and deactivation supports the update and deactivation of DID device information, ensuring that the identity information in the network is always up to date. At the same time, it can promptly handle inactive devices to reduce the risk of security vulnerabilities and outdated information.

[0065] The DID device manufacturer code management component, in this embodiment, is mainly used to maintain and manage the globally unified DID device manufacturer code. Through a public query service, it can quickly locate and provide the manufacturer's publicly disclosed DID service interface address based on a specific DID device manufacturer code. This not only simplifies the discovery and connection process between DID devices, but also strengthens the verification of the manufacturer's identity, further ensuring the stability and security of the network.

[0066] The above-mentioned network device communication system based on distributed digital identity, by introducing DID technology, enables each IoT device to have a unique identity identifier, reducing large-scale leakage of device identity information. Through the DID discovery component, IoT devices can automatically discover other devices and their IP addresses in the network, without relying on centralized services to query and forward device information, ensuring direct communication between devices, reducing the chance of data exposure during transmission, and enhancing the security of data transmission. It also provides a secure data transmission channel for communication between devices through the DID routing component, avoiding the leakage of keys during transmission. Combining DID technology with the communication mechanism of IoT devices, it realizes decentralized, secure and reliable communication between devices, thereby solving the technical problem in related technologies that the communication connection between IoT devices depends on centralized services, which is prone to identity information leakage and low data security.

[0067] The embodiments of the present invention are described below with reference to a specific secure communication system for a distributed digital identity device network.

[0068] The main components of this implementation include DID Router (i.e. the above-mentioned DID routing component), DID Discovery (i.e. the above-mentioned DID discovery component), and DID Service (corresponding to the above-mentioned DID service layer), which together complete the DID automatic discovery, data routing, data security communication and other functions in DID devices.

[0069] Figure 2 This is an optional architecture diagram of a distributed digital identity DID device secure communication system according to an embodiment of the present invention. Figure 2 As shown, from the service layer to the top, each component is explained as follows:

[0070] 1. DID Service: This layer provides the most basic DID services, including DID registration, DID resolution (DID Resolution), DID update and abandonment, and other operations.

[0071] Among them, DID Manufacturer Registry is used to manage manufacturer registration. This service provides an open query service to the outside world and the service address is fixed. It mainly queries the DID service interface address exposed by the DIDManufacturer based on the manufacturer code.

[0072] For the specific DID Resolution process, refer to the W3C DID specification.

[0073] 2. DID Discovery: Used for automatic DID discovery and resolution, and provides DID Document cache management function, providing DID Document query function to the upper-layer DID Router.

[0074] DID automatic discovery is mainly based on the DID Discovery protocol, which is used to discover DID devices and their corresponding IP addresses, and also provides DID device status maintenance, such as online and offline status detection.

[0075] 3. DID Router: Provides data routing and automatic data encryption functions for upper-layer DID Application.

[0076] 4. DID Application: A program or system developed and maintained by the user within a DID device that performs the user's business functions. It can exchange data with other DID applications in other devices. A DID device may have multiple DID applications.

[0077] The following combines the above Figure 1 and Figure 2 , a network device communication method based on distributed digital identity is explained.

[0078] According to another aspect of an embodiment of the present invention, an embodiment of a network device communication method based on distributed digital identity is also provided, which is applied to any of the above-mentioned network device communication systems based on distributed digital identity. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0079] Figure 3 is a flowchart of an optional method for network device communication based on distributed digital identity according to an embodiment of the present invention. Figure 3 As shown, the network device communication method includes:

[0080] Step S301: Receive the data to be sent, application code and destination DID of the source application, obtain the peer DID device IP address and DID document corresponding to the destination DID from the DID discovery component, and use the pre-randomly generated symmetric encryption key to encrypt the data to be sent to generate an encrypted data packet.

[0081] Within a DID device, when a source application needs to send data to another DID device on the network, it first submits the data to be sent, along with the application code and the destination DID, to the DID routing component. At this point, the DID routing component first queries the DID discovery component for the IP address and DID document of the peer DID device corresponding to the destination DID. This enables precise DID-based device positioning and ensures that subsequent data is accurately transmitted to the peer DID device.

[0082] The DID routing component then uses a pre-generated random symmetric encryption key to encrypt the data being sent, generating an encrypted data packet. This process not only increases the security of data during transmission, but also improves data transmission efficiency. Compared to public key encryption, symmetric encryption is faster and more suitable for encrypting large amounts of data.

[0083] Step S302: Obtain the entity public key corresponding to the entity represented by the target DID in the DID document, and encrypt the symmetric encryption key to generate a data encryption key.

[0084] After completing the initial encryption of the data, the DID routing component parses the destination DID document to obtain the entity public key corresponding to the entity represented by the destination DID. Subsequently, this public key is used to perform a secondary encryption process on the previously generated symmetric encryption key to generate a data encryption key. This ensures that even if the encrypted data packet is intercepted during network transmission, the attacker cannot decrypt the data because the decryption key of the symmetric encryption key—the entity private key—is missing. At the same time, since the data encryption key itself is also encrypted, the confidentiality of the data is further strengthened.

[0085] Step S303: Use the private key corresponding to the DID document corresponding to the source device DID to sign the data spliced together by the source device DID, destination DID, application code, encryption protocol, data encryption key, encrypted data packet, and signature algorithm.

[0086] To ensure the non-repudiation and integrity of data during transmission, the DID routing component uses the entity private key corresponding to the source device DID to digitally sign the key information of the data to be sent. The key information may include: source device DID, destination DID, application code, encryption protocol, data encryption key, encrypted data packet and signature algorithm. The digital signature is generated based on the hash value of the above information, ensuring the authenticity and non-tampering of the data. It not only prevents malicious modification of data during transmission, but also provides a means for the receiving device to verify the source of the data, strengthening the trust between the two communicating parties.

[0087] Step S304: assemble the signed source device DID, destination DID, application code, encryption protocol, data encryption key, encrypted data packet, signature algorithm, and data signature using a preset DID data format to generate a target data packet.

[0088] After the data is encrypted and signed, the DID routing component begins to assemble the data packet using a pre-set DID data format. The pre-set DID data format can be selected voluntarily, for example, including multiple fields in the form of TLV (tag-length-value), namely: source device DID, destination DID, application code, encryption protocol, data encryption key, encrypted data packet, signature algorithm and data signature. This standardized format not only ensures the consistency and readability of data transmitted between different DID devices, but also facilitates the receiving end to unpack and verify the data packet, ensuring the safe arrival of the data.

[0089] Step S305: Send the target data packet to the DID routing component of the opposite DID device.

[0090] Finally, the DID routing component sends the generated target data packet to the DID routing component of the peer DID device. This transmission process can be based on underlying network protocols such as UDP or TCP, and the most appropriate transmission method can be selected according to network conditions and specific needs. Because the target data packet already contains security elements such as encrypted data, encryption keys, and digital signatures, even if there are potential risks during transmission, such as data monitoring or man-in-the-middle attacks, it is difficult to interpret or forge the contents of the data packet. After receiving the data packet, the DID routing component on the receiving end will decrypt the data, decapsulate the key, and verify the signature in reverse order, and finally securely deliver the original data to the corresponding application in the destination DID device.

[0091] In this embodiment, the data to be sent, the application code and the destination DID of the source application can be received, and the IP address and DID document of the peer DID device corresponding to the destination DID can be obtained from the DID discovery component. The data to be sent is encrypted using a pre-randomly generated symmetric encryption key to generate an encrypted data packet. The entity public key corresponding to the entity represented by the destination DID in the DID document is obtained, and the symmetric encryption key is encrypted to generate a data encryption key. The private key corresponding to the DID document corresponding to the source device DID is used to sign the data spliced by the source device DID, destination DID, application code, encryption protocol, data encryption key, encrypted data packet, and signature algorithm. The signed source device DID, destination DID, application code, encryption protocol, data encryption key, encrypted data packet, signature algorithm and data signature are assembled using a pre-set DID data format to generate a target data packet, and the target data packet is sent to the DID routing component of the peer DID device. In this embodiment, by introducing DID technology, each IoT device has a unique identity identifier, reducing large-scale device identity information leakage. Through the DID discovery component, the IoT device can automatically discover other devices and their IP addresses in the network without relying on centralized services to query and forward device information, ensuring direct communication between devices, reducing the chance of data exposure during transmission, and enhancing the security of data transmission. The DID routing component provides a secure data transmission channel for communication between devices, avoiding the leakage of keys during transmission. Combining DID technology with the communication mechanism of IoT devices realizes decentralized, secure and reliable communication between devices, thereby solving the technical problem in related technologies that the communication connection between IoT devices depends on centralized services, which is prone to identity information leakage and low data security.

[0092] In this embodiment, the network device communication method can also enable the peer DID device to receive and process data packets, ensuring the secure unpacking and distribution of data. Optionally, after sending the target data packet to the DID routing component of the peer DID device, the network device communication method further includes: the peer DID device parses the target data packet according to a pre-set DID data format to obtain the source device DID, the destination DID, the application code, the encryption protocol, the data encryption key, the encrypted data packet, the signature algorithm, and the data signature; the peer DID device uses the public key corresponding to the source device DID to perform a signature; when the signature result indicates that the received data is complete, the peer DID device uses the destination DID to decrypt the data encryption key, and uses the decrypted data encryption key to decrypt the encrypted data packet to obtain the data to be sent; the DID routing component in the peer DID device transmits the data to be sent to the DID target application based on the registration information of the source application.

[0093] First, the DID routing component of the peer DID device receives a target data packet that follows a pre-defined DID data format. This format includes key fields such as the source device DID, destination DID, application code, encryption protocol, data encryption key, encrypted data packet, signature algorithm, and data signature. The DID routing component is responsible for parsing this data packet and extracting the field information. After the data packet is parsed, the peer DID device uses the public key corresponding to the source device DID to sign and verify the integrity of the data packet and the credibility of its source. The DID discovery component in the DID device pre-caches the DID document of the source device, which includes the source device's public key information. Therefore, the peer DID device can quickly obtain and use this public key to verify the signature contained in the data packet. If the signature verification is successful, it means that the data packet has not been tampered with during transmission and indeed originated from the declared device, enhancing the security of communication.

[0094] After the signature result indicates that the received data is complete and correct, the peer DID device will use the private key recorded in the destination DID to decrypt the data encryption key. Based on the principle of symmetric encryption, the data encryption key is encrypted with the destination device's public key during transmission to ensure that even if the data packet is intercepted by a third party during transmission, the data cannot be directly decrypted. After decrypting the data encryption key, the peer DID device will use this key to decrypt the encrypted data packet, thereby restoring the original data to be sent, ensuring data confidentiality and integrity. Through the two encryption and decryption processes, double protection of data transmission is achieved.

[0095] The decrypted data, i.e., the data to be sent, is then processed by the DID routing component of the peer DID device based on the registration information of the source application. In this embodiment, the application code (APP CODE) field is used to identify the application to which the data packet belongs. This allows the DID device to quickly identify the source of the data and correctly distribute it to the target DID application. The registration of the DID application in the DID routing component ensures that the data is accurately transmitted to the correct application on the receiving end according to the preset routing policy, thereby enhancing the efficiency and accuracy of data processing.

[0096] The DID Router in this embodiment implements secure data transmission between DID devices. It encrypts data by generating a random symmetric encryption key, encrypting the key using the public key in the destination DID Document, and signing it with the private key corresponding to the source DID Document, ensuring the confidentiality, integrity, and authenticity of the data.

[0097] Optionally, the network device communication method also includes: after the DID discovery component receives the DID network joining request, parsing the DID network joining request to obtain the source device DID and IP address; establishing a mapping relationship between the source device DID and the IP address, and storing the mapping relationship to the DID routing component; publishing the source device DID and IP address to each DID physical device in the DID device network.

[0098] The DID network joining request received by the DID discovery component generally follows the DID Discovery Protocol defined in this embodiment. When parsing this request, the component extracts the source device DID and corresponding IP address information from the request data. The source device DID uses a globally unified format, namely dev:manufacturer:device-identifier, which ensures global uniqueness and standardization, allowing the DID discovery component to determine the source of the request and how to establish communication with the new device.

[0099] After the parsing is completed, the DID discovery component will establish a mapping relationship between the source device DID and the IP address. The establishment of this mapping relationship is to build a directory of DID devices in the network, so that the DID routing component can quickly identify the network location of a specific DID device, thereby achieving efficient data routing. The storage of the mapping relationship adopts an efficient and secure mechanism to ensure the reliability and access speed of the data, while also taking into account data security to prevent the leakage of sensitive information. Finally, in order to enable newly added devices to be identified and discovered by other DID physical devices in the network, the DID discovery component will publish the mapping relationship between the source device DID and the IP address to all devices in the DID device network through broadcasting or specific network transmission protocols, ensuring the dynamic and connectivity of the network, ensuring that information can be spread quickly, and avoiding interference from malicious devices and abuse of data.

[0100] Optionally, the network device communication method also includes: the DID discovery component sends an address query request to the DID device manufacturer code management component corresponding to the source device DID, and queries the DID service interface address provided by the DID device manufacturer to the outside according to the manufacturer code carried in the address query request; the DID discovery component sends a DID document request to the queried DID service interface address, and caches the DID document returned by the DID service interface locally on the device.

[0101] It should be noted that when a new DID device appears in the network, the DID discovery component will send an address query request to the DID device manufacturer code management component. Optionally, the request may include the manufacturer code of the new device. The manufacturer code management component will locate the corresponding DID device manufacturer globally based on this code and provide the manufacturer's service interface address. This address is usually fixed and is used for subsequent DID document requests. Once the DID discovery component obtains the service interface address of the DID device manufacturer, it will send a DID document request directly to this address. The DID document contains entity information related to the DID, including the entity public key, entity service endpoint, and metadata, which are all necessary to achieve secure communication between devices. Here, the request and response of the DID document follow the W3C DID specification, ensuring the consistency of the data format and the standardization of operations.

[0102] After receiving the DID document returned by the DID service interface, the DID discovery component caches the document locally on the device. This caching mechanism is designed to improve the efficiency of subsequent DID document requests, reduce network latency, and reduce the load on the DID service layer. The cached DID document provides the DID routing component with the necessary information to perform security operations such as authentication, encryption, and signing during data transmission. In addition, the local cache supports fast access to DID documents, especially during poor network conditions, ensuring the continuity and stability of communication.

[0103] In this embodiment, when the network detects the offline state of a DID physical device, a series of measures are taken to maintain the health of the network and the accuracy of data routing. Optionally, the network device communication method further includes: upon receiving a DID device offline message, updating a local device status cache based on the DID device offline message, marking the offline DID physical device as offline, updating the routing table of the DID routing component, and deleting the routing entry associated with the offline DID physical device; and publishing the DID device offline message associated with the offline DID physical device to each DID physical device in the DID device network.

[0104] First, when the DID discovery component detects a communication interruption with a DID physical device or actively receives a DID Leave message from the device, it will immediately initiate the offline processing process. This trigger mechanism ensures that the network can quickly respond to changes in device status and promptly update device information in the network. Once an offline message is received, the DID discovery component will check and update the local device status cache. For DID physical devices that have been confirmed to be offline, the system will mark their status as "offline", which helps other online devices to immediately understand changes in network topology and make reasonable communication decisions. Next, the local DID discovery component notifies the DID routing component, which then updates the internal routing table. Here, the update includes but is not limited to deleting all routing entries pointing to offline DID physical devices, ensuring that no data attempts to be transmitted through invalid links, avoiding invalid transmission and potential security risks. By dynamically adjusting the routing table, the network's self-healing capabilities and data transmission efficiency are significantly improved.

[0105] After local processing, the DID discovery component also broadcasts the DID device offline message to other physical devices in the entire DID device network, allowing all network members to synchronously obtain the latest device status information, especially offline notifications, which is extremely important for maintaining a globally consistent view of the network status. Broadcast messages utilize the DID Discovery Protocol to ensure effective message propagation, while using UDP broadcast or other suitable network protocols to achieve fast and widespread notification.

[0106] Other DID physical devices that receive the offline message will also perform update actions, including marking the offline device's status, updating the local device status cache, and adjusting the routing table. This chain reaction enables the entire network to quickly adapt to the device's offline changes, reducing communication anomalies and data transmission errors caused by unknown device status. Through this series of adaptive adjustments, the stability and security of the network are enhanced, ensuring that the core function of data transmission is not affected even if some devices are offline.

[0107] Through the above steps, this embodiment not only ensures the self-repair capability of the DID device network when the device is offline, but also optimizes the allocation of network resources, reduces the possibility of invalid data transmission, and further improves the overall performance of the network and user experience.

[0108] The following describes a method for secure communication between devices in a distributed digital identity (DID) network in conjunction with another specific implementation method.

[0109] First, it's important to note that the three most important components of a DID device—the DID Router, DID Discovery, and DID Application—interact with each other regardless of type. For example, in Linux operating systems, common inter-process communication methods such as Unix Sockets or shared memory can be used. Furthermore, communication between DID Routers across DID devices can utilize common network protocols such as UDP or TCP. Furthermore, interaction between the DID Discovery component and the DID Service component must comply with the W3C DID specification and utilize HTTP / HTTPS.

[0110] In this implementation, the DID Service, DID Discovery, DID Router, and DID Application components have clear divisions of labor, working together to accomplish DID device automatic DID discovery, data routing, and secure data communication. The interaction between these components is clear and logical. For example, the HTTP / HTTPS interaction protocol between DID Discovery and DID Service complies with the W3C DID specification, ensuring both standardization and security. There are no restrictions on the type of interaction between the DID Router, DID Discovery, and DID Application, allowing for flexibility in selecting the appropriate inter-process communication method based on the operating system.

[0111] Next, each component is described in detail.

[0112] The DID Discovery component mainly provides DID automatic discovery and DID Document acquisition functions based on the DID Discovery Protocol. The DID discovery process it provides includes the following steps:

[0113] Step 1: The Discovery component in the source DID device sends a Join message. For details, see DID Discovery Protocol.

[0114] Step 2: After receiving the DID Join message, the DID device records the information of the source DID device and the corresponding IP address, and responds with its own DID and IP address.

[0115] Step 3: After receiving the mapping data between the DID and the IP address, the DID device caches the mapping relationship in itself.

[0116] Step 4: At the appropriate time, DID Discovery needs to resolve the DID and cache the resolved DID Document locally (DID resolution process).

[0117] It should be noted that DID Discovery has two DID resolution modes: lazy and eager. In lazy mode, the DID Router queries DID Discovery for the DID Document. In eager mode, DID Discovery immediately performs the resolution process upon receiving the DID and IP mapping.

[0118] The DID Discovery component in this implementation implements automatic discovery of DID devices based on the DID Discovery Protocol. It can discover DID devices and their corresponding IP addresses and provide device status maintenance. Furthermore, by sending Join, Leave, and Ack messages, it effectively manages the joining and leaving of devices on the network, ensuring the dynamic and stable nature of the DID device network.

[0119] It should be noted that the interaction methods between components in this implementation offer a variety of options across different operating systems. For example, in Linux, inter-process communication methods such as Unix Sockets or shared memory can be used, demonstrating the solution's cross-platform capabilities and adaptability to diverse operating system environments. Furthermore, DID Routers across DID devices can interact using common network protocols (such as UDP or TCP), adapting to diverse network environments.

[0120] The DID resolution process includes the following steps:

[0121] Step 1: The DID Discovery component queries the DID Manufacturer Registry for the DIDManufacturer service address.

[0122] Step 2: The DID Discovery component requests the DID document from the DID Manufacturer service address and caches it locally on the device.

[0123] DID device network maintenance includes the following steps:

[0124] When a DID device is offline, it needs to actively send a DID Leave message to the DID device network. When the DID device receives the DID Leave message, it updates the local corresponding cache data of the device and invalidates the changed Leave device entry.

[0125] DID discovery protocol:

[0126] It is mainly used to send messages when a device joins or leaves the network. It contains three types of messages: Join, Leave, and Ack.

[0127] Join message: This message is sent when a DID device joins the network.

[0128] Leave message: This message is sent when a DID device leaves the network.

[0129] Ack message: When a DID device receives a Join message, it responds to the message.

[0130] DID Discovery protocol message format: |TYPE|SRC|DST|DATA|.

[0131] The Type in the message format indicates the current message format, which can be 0, 1, or 2. 0 indicates a Join message, 1 indicates an Ack message, and 2 indicates a Leave message.

[0132] SRC indicates the DID of the source device (see the glossary), which is a fixed 64-character field.

[0133] DST indicates the DID of the target device (see the glossary). It is fixed at 64 characters and is empty for Join and Leave messages.

[0134] DATA is the message data. It is valid only when the Join and Ack fields are present. It indicates an IP address in the xxx.xxx.xxx.xxx format. The Leave field is empty.

[0135] The DID Discovery protocol is an application layer protocol. The underlying network protocol only needs to be able to broadcast Join and Leave messages to the DID device network. Within a local area network, UDP broadcast protocol can be used, while cross-network protocols such as IGMP or P2P can be used.

[0136] The DID Discovery protocol in this implementation serves as an application layer protocol. The underlying network protocol only needs to broadcast Join and Leave messages to the DID device network. Common protocols such as UDP broadcast, IGMP, or P2P can be used, offering good versatility and scalability. The DID DATA data format used for interaction between DID Routers uses the TLV format, which has a clear structure, facilitates data assembly and unpacking, and also facilitates communication and interaction between different devices. The following is an illustrative example of a UDP broadcast network protocol code:

[0137]

[0138]

[0139]

[0140]

[0141] It is mainly used to transmit data securely between DID devices. The underlying network protocol can use UDP or TCP. The DID DATA format used for interaction between different DID Routers is:

[0142] |SRC DID|DST DID|APP CODE|ENCRYPT METHOD|ENCRYPT KEY|CIPHERTEXT|SIGNMETHOD|SIGNATURE.

[0143] It should be noted that this data format is variable length, and each part uses the TLV format. The specific explanation is as follows:

[0144] SRC DID: Source device DID, TAG: 1.

[0145] DST DID: Destination device DID, TAG: 2.

[0146] APP CODE: application code, similar to the port in the network protocol, TAG: 3.

[0147] ENCRYPT-METHOD: Data encryption protocol, symmetric encryption, such as AES, 3DES, etc., TAG: 4.

[0148] ENCRYPT KEY: data encryption key, TAG: 5.

[0149] CIPHERTEXT: Encrypted data, TAG: 6.

[0150] SIGN METHOD: signature algorithm, TAG: 7.

[0151] SIGNATURE: data signature, TAG: 8.

[0152] The following describes the data sending process, which includes the following steps:

[0153] Step 1: Receive the data to be sent, application code, and DID of the receiving device from the DID Application;

[0154] Step 2: Obtain the IP address and DID Document corresponding to the target DID from the DID Discovery component;

[0155] Step 3: Generate a random symmetric encryption key and encrypt the data;

[0156] Step 4: Obtain the public key from the target DID Document and encrypt the key from step b.

[0157] Step 5: Use the private key corresponding to the source DID Document to sign the data consisting of the source DID, destination DID, application code, encryption protocol, key, encrypted data, and signature algorithm.

[0158] Step 6: Assemble the source DID, destination DID, application code, encryption protocol, key, encrypted data, signature algorithm, and data signature according to the TLV format.

[0159] Step 7: Send data to the DID Router component of the peer DID device based on the underlying protocol.

[0160] The following describes the data receiving process, which includes the following steps:

[0161] Step 1: Unpack the source DID, destination DID, application code, encryption protocol, key, encrypted data, signature algorithm, and data signature in TLV format.

[0162] Step 2: Use the public key corresponding to the DID of the source device to sign and confirm the integrity of the received data;

[0163] Step 3: Decrypt the data encryption key using the device DID.

[0164] Step 4: Decrypt the data using the data encryption key.

[0165] Step 5: The information registered by the DID Application in the DID Router is delivered to the corresponding DID Application according to the APP CODE field.

[0166] The above implementation method can solve the traditional identity recognition problem. Compared with the existing identity recognition system, which has problems such as single point failure, high risk of data leakage and limited user control over identity information, this implementation method adopts decentralized DID technology, avoiding the drawbacks of centralized institutions in centrally managing identity information, reducing the risk of data leakage, enhancing the stability and security of the system, and users have more control over their own identity information.

[0167] Through the above implementation, diversified identity authentication needs can be met. With the development of the digital economy and the Internet of Things, the demand for identity recognition is becoming increasingly diversified and large-scale. This implementation can meet the needs of secure and reliable identity authentication in scenarios such as online transactions, digital asset transfers, and communication interactions between Internet of Things devices in the digital economy.

[0168] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the network device communication methods based on distributed digital identity in the above-mentioned embodiment one.

[0169] According to another aspect of an embodiment of the present invention, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement the network device communication method based on distributed digital identity of any one of the above-mentioned embodiments.

[0170] The present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the network device communication method based on distributed digital identity described in each embodiment of the present application.

[0171] The present application also provides a computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the network device communication method based on distributed digital identity described in each embodiment of the present application are implemented.

[0172] Figure 4 1 is a hardware structure block diagram of an electronic device (or mobile device) for a network device communication method based on distributed digital identity according to an embodiment of the present invention. Figure 4As shown, the electronic device may include one or more ( Figure 4 (As shown in the figure, 402a, 402b, ..., 402n are used) processor 402 (processor 402 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), memory 404 for storing data. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 4 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 4 More or fewer components than shown, or with Figure 4 Different configurations shown.

[0173] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0174] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0175] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0176] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0177] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0178] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.

[0179] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A network device communication system based on distributed digital identity, characterized in that: include: The physical device layer includes multiple distributed digital identity DID physical devices, which form a DID device network. Each DID physical device includes at least: a DID discovery component, a DID routing component, and a DID application set component. The DID discovery component is used to discover new DID devices and corresponding device IP addresses, provide DID device status maintenance, and the DID routing component is used to The DID application layer provides data routing services and automatic data encryption services. The DID application set component stores and runs multiple DID applications, and each DID application interacts with DID applications in other DID physical devices. The DID service layer communicates with the DID discovery components in each of the DID physical devices over the network, including: a DID device manufacturer code management component and a DID basic service component. The functions provided by the DID basic service component include: DID registration, DID resolution, and DID device update. The DID device manufacturer code management component is used to query the DID service interface address provided by the DID device manufacturer based on the DID device manufacturer code.

2. The network device communication system according to claim 1, wherein: The DID discovery component is further used to provide a DID document query function to the DID routing component, wherein the DID document records entity information corresponding to the entity represented by each DID, and the entity information includes at least one of the following: an entity public key, an entity service endpoint, and metadata. The entity public key is used to verify the identity and signature of the entity, the entity service endpoint is used to indicate the interaction strategy between entities, and the metadata includes the creation time and update time of each DID.

3. The network device communication system according to claim 1, wherein: When the DID routing component provides automatic data encryption services for the DID application layer, the DID data formats used include: Source device DID, destination DID, application code, data encryption protocol, data encryption key, encrypted data, signature algorithm, and data signature.

4. The network device communication system according to claim 1, wherein: The DID physical device When the DID discovery component communicates with the DID service layer over the network, the DID specification protocol used is: DID mode identifier, manufacturer code, and device unique identifier; wherein the DID mode identifier is fixed to dev, and the manufacturer code is used to query the service interface address of the corresponding DID device manufacturer.

5. A network device communication method based on distributed digital identity, characterized in that: The network device communication system based on distributed digital identity according to any one of claims 1 to 4, wherein the network device communication method comprises: Receive the data to be sent, the application code, and the destination DID from the source application, obtain the peer DID device IP address and DID document corresponding to the destination DID from the DID discovery component, encrypt the data to be sent using a pre-randomly generated symmetric encryption key, and generate an encrypted data packet; Obtain the entity public key corresponding to the entity represented by the target DID in the DID document, and encrypt the symmetric encryption key to generate a data encryption key; Use the private key corresponding to the DID document corresponding to the source device DID to sign the data spliced together by the source device DID, the destination DID, the application code, the encryption protocol, the data encryption key, the encrypted data packet, and the signature algorithm; Assembling the signed source device DID, the destination DID, the application code, the encryption protocol, the data encryption key, the encrypted data packet, the signature algorithm, and the data signature using a preset DID data format to generate a target data packet; The target data packet is sent to the DID routing component of the opposite DID device.

6. The network device communication method according to claim 5, wherein: After sending the target data packet to the DID routing component of the peer DID device, the network device communication method further includes: The peer DID device parses the target data packet according to a preset DID data format to obtain the source device DID, the destination DID, the application code, the encryption protocol, the data encryption key, the encrypted data packet, the signature algorithm, and the data signature; The peer DID device uses the public key corresponding to the source device DID to sign the visa; When the signature result indicates that the received data is complete, the peer DID device uses the destination DID to decrypt the data encryption key, and uses the decrypted data encryption key to decrypt the encrypted data packet to obtain the data to be sent; The DID routing component in the opposite-end DID device transmits the data to be sent to the DID target application according to the registration information of the source application.

7. The network device communication method according to claim 5, wherein: The network device communication method further includes: After the DID discovery component receives the DID network joining request, it parses the DID network joining request to obtain the source device DID and IP address; Establishing a mapping relationship between the source device DID and the IP address, and storing the mapping relationship in a DID routing component; The source device DID and IP address are published to each DID physical device in the DID device network.

8. The network device communication method according to claim 5, wherein: The network device communication method further includes: The DID discovery component sends an address query request to the DID device manufacturer code management component corresponding to the source device DID, and queries the DID service interface address provided by the DID device manufacturer based on the manufacturer code carried in the address query request; The DID discovery component sends a DID document request to the queried DID service interface address, and caches the DID document returned by the DID service interface locally on the device.

9. The network device communication method according to claim 5, wherein: The network device communication method further includes: After receiving the DID device offline message, update the local device status cache according to the DID device offline message, mark the status of the offline DID physical device as offline, and update the routing table of the DID routing component to delete the routing entry associated with the offline DID physical device; The DID device offline message associated with the offline DID physical device is published to each DID physical device in the DID device network.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the network device communication method based on distributed digital identity described in any one of claims 5 to 9 are implemented.

Citation Information

Patent Citations

  • Centerless multi-device joint operation system

    CN107995071A

  • Point-to-point distributed digital identity connection establishment method, device, equipment and medium

    CN116232737A

  • Functional application module based on distributed digital identity, trusted DID functional chip and distributed data exchange system

    CN118074920A

  • Data transmission method and device, storage medium and electronic equipment

    CN118611927A

  • Mobile terminal equipment credibility authentication method and system based on Internet of Things

    CN118631570A