Chain type anonymous identity authentication and dynamic encryption communication method based on byte mapping

Through the byte mapping structure and dynamic identity fingerprint chain construction mechanism, the problems of centralization risk and lack of identity chain structure in existing encrypted communications are solved, and efficient and secure decentralized communication and anonymous identity authentication are achieved, which is suitable for a variety of secure communication scenarios.

CN120602207APending Publication Date: 2025-09-05陈家浩
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510983454.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing encrypted communication mechanisms have risks of centralized key storage, rely heavily on real-name verification, have complex and inefficient communication negotiation processes, and lack a verifiable identity chain structure, making it difficult to achieve decentralized, lightweight, anonymous communication and identity traceability.

Method used

It adopts a chained anonymous identity authentication and dynamic encryption communication method based on a byte mapping structure, generates identity fingerprints through a random byte mapping table, supports reversible mask processing and disturbance control, realizes identity derivation and two-way encryption negotiation, builds a trusted chained identity structure, simplifies the communication process and supports decentralized communication.

Benefits of technology

It achieves efficient and secure decentralized communication, supports anonymous authentication and identity traceability, reduces centralization risks, improves communication efficiency, is suitable for resource-constrained devices, and has anti-counterfeiting and controllable encryption capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The invention discloses a chained identity authentication and dynamic encryption communication method based on byte mapping, which is suitable for real name removal communication and identity authentication scenes without centralized key management. The method comprises the following steps: executing byte mapping initialization processing on information input by a user, and generating an identity fingerprint structure with uniqueness and irreversibility in combination with disturbance and reversible operation; an inheritable and derived fingerprint chain is constructed through multi-round transformation, and a bidirectional traceable identity authentication mechanism is realized; two communication parties generate communication fingerprints through identity fingerprint exchange, and the communication fingerprints are used for constructing a byte mapping table and a dynamic mask so as to realize mapping encryption and mask processing of plaintext data; the method supports fingerprint level access control, anonymous communication initialization and identity binding in the communication process. According to the method, a traditional three-way handshake process is omitted, the communication efficiency and safety are improved, and the method is suitable for various safety communication scenes such as Internet of Things equipment authentication, digital identity management, real-name communication network removal and real-time data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical fields of data encryption, secure communication, and digital identity authentication, and more specifically, to a method for generating irreversible fingerprint chain identities and dynamic communication authentication based on a derivable byte mapping structure. This method integrates a byte-level mapping structure, an inheritable identity chain mechanism, and a dynamic masked encryption communication process. It is suitable for a variety of application scenarios, including network de-identified authentication, data desensitization storage, lightweight real-time communication encryption, two-way anonymous verification, IoT device authentication, decentralized interaction protocols, and digital asset chain identity management. Background Art

[0002] With the rapid development of digital communication technology, information security, privacy protection, and identity authentication have become key issues. While traditional encryption communication mechanisms (such as AES and RSA) offer high security in terms of encryption strength, they still have significant limitations in terms of flexibility, decentralization, and communication efficiency. These limitations are primarily manifested in the following aspects: Centralized key storage carries significant risks: Existing communication systems often rely on central servers to manage symmetric or asymmetric keys. Once a key is leaked, the entire communication data may be exposed, and tracing or revocation is difficult. Identity authentication relies on real-name authentication and static binding: Current architectures generally use account passwords, certificates, or centralized management, which cannot support dynamically generated anonymous communication identities and verifiable anonymous authorization. The communication negotiation process is complex and inefficient: For example, the TLS protocol requires multiple rounds of handshake negotiations, which prolongs the communication initialization time and creates the risk of man-in-the-middle attacks during the handshake phase. Lack of a verifiable identity chain structure: Traditional identity systems are typically one-time authentication systems that lack an identity derivation mechanism with inheritable, traceable, or chain-verifiable capabilities, making it difficult to achieve identity-level trust transfer and permission inheritance. Furthermore, while some research has proposed "magic cube encryption" or mapping encryption methods for image or data dimensions, which offer some degree of data obfuscation, most have yet to address the coordination issues of identity mapping, interactive communication, and chain verification. While technologies like blockchain and hash chains offer tamper-proof chain structures, their integration with lightweight identity systems and real-time communication protocols remains challenging.

[0003] Therefore, there is an urgent need for a lightweight, chainable, communication-efficient, anonymous, and identity-traceable encryption verification method to achieve a decentralized communication and authentication process from identity generation, data encryption to access control.

[0004] This invention, proposed against this technical backdrop, utilizes a byte-mapping structure and a dynamic identity fingerprint chain construction mechanism, combined with disturbance control and reversible masking, to implement a chained identity authentication method that is resistant to counterfeiting, inheritable, verifiable, and anonymous. This provides an efficient, decentralized, secure, and controllable solution for digital communication systems. Summary of the Invention

[0005] (1) Purpose of the invention This paper proposes a chained anonymous identity authentication and dynamic encrypted communication method based on a byte mapping structure. By initializing and generating a random byte mapping table and identity fingerprint, it achieves functions such as de-identified communication, hidden identity authentication, and chained authentication. This method is lightweight, efficient, and scalable, and can be widely applied to anonymous communication, decentralized interaction, edge device communication, and digital identity management. The main objectives include: Generate a unique and tamper-proof fingerprint chain to ensure the uniqueness and traceability of identity; Supports controllable forward and reverse encryption and decryption processes to meet diverse secure communication scenarios; Allows the formation of "sub-fingerprints" through derivation, building a trusted chain identity structure, and realizing identity inheritance and association verification; A two-way identity fingerprint negotiation mechanism is used to complete communication key exchange, reducing the handshake process and improving communication efficiency; Generate structured decryption credentials at each encryption stage to achieve controllable data restoration, desensitization tracking and security auditing; It supports low-memory and high-concurrency operation in resource-constrained device environments and is suitable for IoT communication systems.

[0006] (2) Technical solution The present invention discloses a chained anonymous identity authentication and dynamic encryption communication method based on byte mapping, covering multiple technical levels such as identity initialization, identity derivation, communication key negotiation, mapping encryption, authentication binding, authority control, data protection and identity loss reporting, mainly including the following aspects:

[0007] By collecting the original identity parameters entered by the user (including passwords, device characteristics, hardware identification, etc.), based on the default 256-byte mapping table, the number of perturbation rounds is determined according to the summary results, and multiple rounds of byte-level masking, byte position permutation, bit logic perturbation and other operations are performed to generate a highly nonlinear random byte mapping structure table, and based on this, a unique and irreversible identity fingerprint is derived as the user's digital identity.

[0008] 2. Identity Derivation Mechanism and Chain Identity Structure Construction Based on the generated identity fingerprint, by intercepting the maternal fingerprint feature segment and combining it with the maternal private key to perform reversible masking operations (such as XOR, shift, perturbation, etc.), the new fingerprint structure is embedded to achieve identity derivation with a verifiable lineage chain. This mechanism allows the construction of a one-way traceable identity chain without exposing the original identity, realizing hierarchical trust and authentication management of multi-level identity structures.

[0009] 3. Derived Key Agreement and Mapping Communication Encryption Mechanism Before establishing a session, both communicating parties exchange their identity fingerprint fragments and generate a temporary communication fingerprint based on the same mapping rules and perturbation logic. This fingerprint then generates a symmetric communication key and a mapping structure table unique to the current session. Communication data is mapped byte by byte and reversibly masked based on this structure table, creating a lightweight encryption channel without a key center. This eliminates the need for traditional symmetric or asymmetric encryption algorithms and improves communication efficiency.

[0010] 4. De-real-name identity registration and binding mechanism During initial identity registration, users only need to submit a locally generated fingerprint digest. Without knowing the user's original information, the server derives the fingerprint structure using the company's private key and returns it. No plaintext identity information is exposed during the entire process, and the returned fingerprint serves as the foundation for communication and permission binding between the two parties, achieving a completely anonymous identity initialization and binding process.

[0011] 5. Derived Authentication Mechanism and Identity Binding Upgrade The system supports an authentication and binding upgrade process for identity fingerprints: the parent fingerprint is combined with the child fingerprint fragment, private key, and mapping table to generate a derived authentication fingerprint, which is embedded in the parent identification segment and mask perturbation structure. This authentication fingerprint is unique, anti-counterfeiting, and traceable, and is stored long-term as a communication credential, enabling secure and highly reliable identity authentication and permission activation.

[0012] 6. Dual fingerprint combination communication mechanism This invention proposes a dual fingerprint collaboration mechanism of "authentication fingerprint + temporary communication fingerprint" to improve communication security and identity binding consistency: Temporary fingerprints are generated by negotiation between the two parties and are valid for a one-time session. Authentication fingerprint provides identity tracing and authority confirmation; The dual structure combination builds a unique encryption path to resist man-in-the-middle attacks; Simplify the traditional handshake process and improve communication initialization efficiency.

[0013] 7. File-level permission control and mapping encryption mechanism The system supports extending the identity fingerprint mechanism to file data mapping encryption applications. By calling the perturbation instruction set and mapping structure table, the file stream is perturbed in blocks or streams. Encryption is performed in conjunction with the identity fingerprint structure mask to generate a structured decryption credential (including perturbation parameters, block information, and mask pattern). After authorized access, the credential can be restored to its original state, supporting complete access control and tamper protection.

[0014] 8. Identity loss reporting and restoration mechanism If a user's fingerprint or private key information is leaked or lost, they can request a report of identity loss using a secondary password or local private key. The system verifies the legitimacy of their parent or root fingerprint, allowing the user to regenerate a new fingerprint and transfer the original permissions and data binding, ensuring the security and recoverability of the communication system.

[0015] (3) Beneficial effects Compared with the existing technology, the "chained anonymous identity authentication and dynamic encryption communication method based on byte mapping" proposed in this invention has the following technical advantages and practical application value:

[0016] This invention abandons the traditional communication mode that relies on centralized key servers and real-name verification, supports local independent generation of identity fingerprint structure, and completes identity authentication and permission binding through a derivation mechanism, effectively reducing the risks brought by failure or leakage of central nodes, and improving the system's anti-attack capabilities and user privacy protection capabilities.

[0017] By negotiating identity fingerprints to build temporary communication fingerprints, the traditional handshake process is omitted, and communication is established quickly. At the same time, the fingerprint structure itself is anonymous, eliminating the need to transmit plaintext identities, achieving hidden encrypted communication and reducing the risk of man-in-the-middle monitoring and replay attacks.

[0018] Users can complete multi-scenario authentication and access control with their local identity fingerprint, without the need for frequent logins or interactive password entry. The system supports static authentication and low-coupling permission verification processes, reducing enterprise deployment and operation and maintenance costs.

[0019] Using a chained fingerprint structure and verifiable derivation logic, communication permissions are only established between devices with a legitimate parent-child identity relationship. The fingerprint chain is constructed using an irreversible derivation algorithm, making it impossible to reverse-derive the parent fingerprint from the child fingerprint, effectively preventing identity forgery and unauthorized access.

[0020] Pseudo-random perturbation parameters and mask operations are introduced during the communication process to generate non-fixed communication paths and decryption mapping structures, making it difficult for automated crawlers or replay attacks to successfully reproduce data flows or identify key patterns.

[0021] The encryption process used is based on byte mapping and mask perturbation. It does not require complex large number calculations and key infrastructure. It has high encryption and decryption speed and low resource consumption. It is suitable for deployment in resource-constrained environments such as embedded devices, IoT terminals, and edge nodes.

[0022] A structured decryption credential is automatically generated for each ciphertext, recording only the minimum necessary mapping and disturbance information. This is suitable for low-bandwidth, cross-platform, distributed, or desensitized transmission scenarios, facilitating decoupled deployment of multiple systems.

[0023] Through multiple rounds of perturbations and reversible mapping, the communication data structure changes dynamically, eliminating repeated ciphertext paths and effectively enhancing anti-eavesdropping and anti-replay capabilities. The fingerprint chain structure supports communication path backtracking and identity chain auditing to meet security and compliance requirements.

[0024] Support identity loss reporting and controllable recovery mechanism Users can use the parent fingerprint verification mechanism to regenerate a legitimate new fingerprint and migrate the original permissions when the private key is lost or the identity is leaked, ensuring the long-term stability of the system and the integrity of user data.

[0025] Adapt to diverse application scenarios This method is applicable to multiple secure communication areas, including anonymous communication, IoT device authentication, edge computing node identity binding, live broadcast content encryption, digital asset tracking and identification, and zero-trust network architecture. Its identity chain structure can be expanded to a multi-level inter-organizational identity governance system, offering high configurability and business adaptability. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 :Initialization flow chart of identity mapping fingerprint structure Figure 2 :Fingerprint derivation structure diagram Figure 3 :Two-way communication negotiation flow chart Figure 4 : User and enterprise registration and login process logic diagram DETAILED DESCRIPTION

[0026] Premise: This specific implementation plan is a method for identity generation and communication negotiation based on real and credible user input information. The prevention mechanism for identity information forgery is not within the core concept scope of this method. Developers can design supplementary anti-counterfeiting strategies based on actual business scenarios.

[0027] (I) Specific implementation plan 1 of the initialization method of the identity mapping fingerprint structure: like Figure 1 Initialization flow chart of identity mapping fingerprint structure Step 1: The user enters their identity information (A) and specifies an identity nickname of at least 8 characters, which serves as the local identity private key (B). This private key is used for subsequent fingerprint generation and identity authentication. A custom random mapping structure table (F) of at least 256 characters can be created to further generate irreversible initial changes.

[0028] Step 2: Convert the user's input identity information (A) and identity private key (B) into corresponding byte states as the basic data for subsequent fingerprint calculation.

[0029] Step 3: Based on the length of the private key (B) and the total length of the identity information (A), dynamically calculate the perturbation factor (C), the perturbation operation type (D), and determine the number of rounds required for the perturbation process (E) in-- Perturbation factor (C): used to control the transformation intensity applied in each round of perturbation operation; Perturbation operation (D): can include but is not limited to any reversible processing method such as bit-based XOR perturbation, byte-level offset perturbation, bit segment block reversal perturbation, random number seed-based structural replacement perturbation, etc. Round parameter (E): used to set the number of perturbation iterations. This step effectively improves the security and anti-collision capability of the derived fingerprint structure through a dynamic perturbation control mechanism.

[0030] Step 4: Initialize the mapping structure table. If the user provides a starting mapping structure table (F), the user-provided mapping structure table (F) is used as the initial reference. If the user does not provide one, the system automatically generates a default mapping structure table (F) with a length of 256 bytes and arranged in sequence (0-255) for subsequent perturbation calculations.

[0031] Step 5: Based on the perturbation factor (C), perturbation operation (D), and round number parameter (E), a reproducible and unpredictable dynamic perturbation calculation process is performed. The system generates an independent intermediate structure table for each perturbation round. After completing all or a specified number of perturbation rounds, each byte value (range 0-255) of the user-entered identity information (A) in the byte state is used as an index to extract the byte value at the corresponding position from the perturbation structure table of the corresponding round. N rounds of mapping and replacement operations are performed, and each set of mapped and obfuscated byte sequences is spliced ​​in sequence using unspecified markers. (G, H, I, J, K) Note: G, H, I, J, and K represent the byte confusion sequence after each round of mapping.

[0032] This step effectively constructs a highly obfuscated and unique fingerprint chain input structure through multiple rounds of mapping perturbation and differential obfuscation between rounds. This not only enhances the security of the derived fingerprint but also provides a trusted data source for subsequent session key generation and identity verification. Furthermore, the resulting random byte mapping structure table (F) serves as the encryption mapping table for network communication and local file encryption.

[0033] Step 6: Use the additional predefined identity header and the user's complete private key (B) to generate an origin identifier (M), and embed the origin identifier (M) in the generated fingerprint chain. Then, use the internal authorization signature module (N) and the user's private key signature (B) in sequence to perform any reversible encryption or perturbation processing on the overall fingerprint to generate the final identity-derived fingerprint data packet (P) with a dual authentication mechanism. This step is a crucial step in the fingerprint derivation process. It aims to prevent the infinite recursion of the parent fingerprint chain to search for sub-class identities. It also provides a security mechanism for emergency reporting and identity recovery in the event of subsequent fingerprint theft. (For details on the specific reporting and emergency response mechanism, please refer to the subsequent implementation plan section.) Optional parameters for this solution: Initialization mapping structure table (F): supports users to define and input an initialization mapping structure table (F) of any length, but the byte length of the mapping table must be greater than or equal to the maximum byte value (i.e., byte value range) in the byte state of the user-entered identity information.

[0034] When the user does not enter the mapping table, the system automatically uses the default sequence mapping structure table with a length of 256 bytes.

[0035] This design ensures the validity of indexes and the integrity of mapping tables during the mapping process, avoids out-of-bounds access and mapping conflicts, and improves the flexibility and security of the system.

[0036] At the same time, the initialization mapping structure table (F) does not need to be the same entity variable as the random byte mapping structure table used in subsequent network communication and file encryption processes.

[0037] This solution allows the creation of a separate, independent, random byte mapping structure table and the identical initialization operation for both. By distinguishing the fingerprint characteristics of the initialization mapping structure table and the random byte mapping structure table, it is possible to manage normal fingerprints and encrypted fingerprints separately, enhancing system security and the diversity of fingerprint applications.

[0038] (II) Specific implementation plan for the identity derivation mechanism and chained identity verification structure: like Figure 2 Shown is a schematic diagram of the fingerprint derivation structure.

[0039] Step 1: Based on the identity fingerprint structure (M) generated in the above "Specific Implementation Plan 1 of the Identity Mapping Fingerprint Structure Initialization Method", use the other party's fingerprint as the new round of derived identity input information (A), and use the local identity private key (B) as the private key to execute the complete process (C) of the "Identity Mapping Fingerprint Structure Initialization Method", thereby deriving a new sub-fingerprint structure (D).

[0040] This sub-fingerprint serves as the basic data for derived identity identification. While maintaining the original identity chain traceability capability, it can generate a branch identity node with independent access permission control capabilities.

[0041] Optional parameter description:

[0042] The local private key can be a newly generated identity key or an existing private key from the parent identity. This parameter can be used to implement granular control of identity inheritance, permission control, or derived permissions.

[0043] Disturbance control parameters: When executing step 3 of the above initialization method, the controllable generation of derived fingerprints in specific application scenarios can be achieved by setting the fixed perturbation factor (C), perturbation operation type (D), and perturbation round number parameter (E).

[0044] For example: when deriving fingerprints on a limited platform, within a fixed permission range, or within the same trust domain, fixed perturbation logic can be used to generate predictable and traceable chain sub-fingerprints, thereby building a stable identity structure with authentication relationships.

[0045] Step 2: Extract the last several characteristic segments (E) from the maternal fingerprint structure (M) and embed them into the generated derived fingerprint structure (D). Subsequently, use the private key corresponding to the maternal identity (B) to perform any reversible encryption or perturbation processing (such as position permutation, byte XOR, structure perturbation, etc.) on the derived fingerprint structure with the embedded maternal characteristic segments to increase the uniqueness and unforgeability of the structure.

[0046] Optional parameter description: Maternal feature fragment (E): By default, it is the combination of feature fields at the end of the maternal fingerprint structure, and can also be upgraded to the fusion calculation result of any structure of the paternal and maternal fingerprint structures; Controllable embedding position: The embedding operation of the parent feature fragment (E) can be performed in the head, middle and other non-tail areas of the derived fingerprint structure (D). It can also be combined with a hash function to achieve a uniform distribution of feature fragments to enhance the security and unpredictability of the structure.

[0047] NoticeIt's not recommended to embed maternal fingerprint fragments at the tail of the derived structure. This is because, during the subsequent derivation process, the system defaults to extracting maternal fingerprint fragments at the "tail" of the structure. If the embedding location conflicts with the extraction logic, it may invalidate the bloodline verification relationship in the chained identity structure, causing structural confusion and verification confusion.

[0048] Fusion method: You can choose to use the joint embedding of maternal and paternal fingerprints, or extract the tail feature fragment from the paternal fingerprint structure alone and embed it into the derived fingerprint structure (D) to form a derived structure.

[0049] Through the above operations, the derived fingerprint generated has a chained identity inheritance relationship to its maternal origin, constructing a chained identity structure with bloodline traceability. This structure can be used as an identity identifier with authentication capabilities, hereinafter referred to as the "authentication fingerprint."

[0050] This "authentication fingerprint" can prove its origin as a maternal fingerprint in a legitimate trust chain without revealing the full maternal identity, providing reliable provenance and authorized traceability. The system can send this authentication fingerprint structure to the communicating party, and both parties can complete local storage and binding operations. Subsequent communications only require the authentication fingerprint to achieve login-free access and identity confirmation without the traditional login process, and support cross-session and cross-system permission verification and access control.

[0051] The key advantages of this mechanism are: The legitimacy of the source can be verified without transmitting the maternal identity information in plain text; Ensure the controllability and verifiability of each generation of identity derivation process, with one-way traceability and irreversible restoration; A structured authentication channel can be established between multiple generations of identity fingerprint structures, supporting multi-level authority transfer and identity migration. It effectively serves to build a decentralized, verifiable, and highly secure identity system, and is suitable for digital identity management scenarios across platforms, multiple nodes, and trustless infrastructure.

[0052] Step 3: This step verifies the legitimacy of the fingerprint identity and the authenticity of the source chain. The system performs a reverse verification operation on the received derived fingerprint structure to determine whether it is derived from a legitimate maternal or paternal identity fingerprint.

[0053] The specific operations are as follows: The recipient uses the locally stored private key to perform a reversible restoration calculation on the received authentication fingerprint structure in the same manner as the original derivation process, and extracts the maternal (paternal or a fusion of the two) fingerprint feature fragments embedded inside it.

[0054] Subsequently, the fragment is compared with the homonymous segment extracted from the locally stored maternal (paternal or a fusion of the two) fingerprint structure. If the contents are consistent, it can be confirmed that the authentication fingerprint is indeed derived from the current identity fingerprint and has chain source legitimacy.

[0055] The technical advantages of this mechanism include: One-time local reversible verification: Through only one local operation consistent with the original derivation process, it is possible to verify whether the fingerprint is derived from the locally known parent identity structure, ensuring that it cannot be forged; Dual chain verification capability: After completing paternal lineage verification, the system can further verify the maternal lineage in the same way, achieving multi-generational identity continuity and integrity authentication; No need for plaintext identity exchange: The entire process does not rely on plaintext identity transmission, nor does it require the intervention of a centralized server. It supports fully offline verification and peer-to-peer trust establishment. Strong anti-forgery and tampering capabilities: The parent fragments embedded in the derived structure are bound to the perturbation rules. Any tampering will destroy the restoration path and is extremely easy to identify.

[0056] (III) Specific implementation plan 1 of the derived key agreement and mapping communication encryption mechanism: like Figure 3 Two-way communication negotiation flow chart.

[0057] Step 1: Communication initialization phase Before establishing a connection, each communicating party extracts a fragment of its own identity fingerprint structure (denoted as A and B) and sends it to the other party. Each party then performs structural blending, mapping, or other agreed-upon reversible calculations on the fingerprint fragments sent by the other party with its own original identity fingerprint to generate new session user information (denoted as AB and BA). This calculation method is consistent with the operations described in "Specific Implementation Plan 1 for Initializing the Identity Mapping Fingerprint Structure" above, ensuring equivalent and reproducible calculation results.

[0058] Step 2: Negotiating fingerprint generation The communicating parties use the above user information (AB and BA) as identity input information, call the complete process of "Specific Implementation Plan 1 of the Initialization Method of Identity Mapping Fingerprint Structure" for derivation processing, and generate new derived fingerprints (respectively denoted as C and D) as the negotiated fingerprints for this communication session.

[0059] This negotiated fingerprint is further used as a symmetric key or its equivalent in session encryption communication and can be used for dynamic encryption and authentication of all subsequent data packets.

[0060] Optional parameter description:

[0061] The local private key (B) used to perform the initial derivation can be generated in two ways: 1) Extract and calculate the summary from user information (AB or BA); 2) Both parties negotiate to set the same digest or rules (such as the number of rounds, perturbation factor, and perturbation operation) to generate equivalent local private key values.

[0062] This mechanism supports the flexible generation of non-plaintext private keys, and has multiple security features such as anti-replay, anti-leakage, and man-in-the-middle interception.

[0063] Technical advantages: Key negotiation does not require the prior sharing of symmetric keys, thus avoiding the risks of theft, replay, or man-in-the-middle attacks inherent in traditional symmetric key distribution mechanisms. The derived fingerprint is used as a dynamic key source. Each communication negotiation generates a different fingerprint structure, which is highly one-time and unpredictable. The session symmetric key is generated based on the fingerprint mapping chain and is bound to the identity structure of both communicating parties to ensure the source is trustworthy. This mechanism is suitable for decentralized, anonymized, and real-time encrypted communication scenarios, and can be widely used in IoT device communications, low-latency network protocols, and cross-regional encrypted channel construction.

[0064] Step 3: After the two communicating parties successfully negotiate to generate fingerprints (C and D), they must each perform a round of preset operation instructions (such as perturbation, permutation, rotation, hash mapping, etc.) on the initialized scrambled byte mapping table to generate a new scrambled byte mapping table (M).

[0065] Subsequently, both parties use the random byte mapping table (M) to perform byte-by-byte mapping encryption operations on the plaintext byte data to be sent to obtain the first layer of encrypted ciphertext (P).

[0066] Then, using the negotiated fingerprint (C or D) as the mask source, a reversible encryption mask operation (such as XOR, byte shuffling, difference perturbation, etc.) is performed on P to generate the final ciphertext, which is then sent to the other party.

[0067] After receiving the ciphertext (P), the receiver first performs a mask restoration operation using the same negotiated fingerprint as the sender, and then restores the plaintext (U) through a reverse mapping operation of the scrambled byte mapping table (M).

[0068] This step implements a double encryption structure for the data, namely dynamic mapping + mask encryption, ensuring that the original data cannot be restored even if the communication content is intercepted.

[0069] Step 4: All subsequent communication processes are carried out in the same manner as in Step 3. Before each round of sending (receiving) data, both communicating parties need to perform another round of perturbation operation on the current out-of-order mapping table (M) to generate a new round of out-of-order mapping table (M) to achieve continuous changes in dynamic synchronous mapping.

[0070] The evolution rules of this mapping structure can be determined by deriving a specific perturbation instruction sequence or index table from the negotiated fingerprints of both parties, ensuring that both parties are always synchronized and unique, and realizing a lightweight, high-strength decentralized encryption tunnel without the need for traditional symmetric / asymmetric algorithms.

[0071] Through the above mechanism, the communicating parties complete highly secure communication with the following features without having to disclose the symmetric key: The mapping structure changes dynamically and resists replay attacks; The masked fingerprint is generated independently to prevent key leakage; Double-layer protection of mapping and masking to increase the cracking threshold; It supports unlimited rounds of communication synchronization and is suitable for persistent communication scenarios.

[0072] Description of the optional options: To enhance the flexibility and anti-cracking capabilities of the system, the present invention also supports the following two variant implementations of communication encryption as a supplement and upgrade to the main solution:

[0073] In addition to performing mapping operations through the index of the scrambled byte mapping table after each round of perturbation, the system can also use an overall structure alignment method to align the complete mapping structure table generated in the current round with the plaintext data at the byte level (bit by bit, segment by segment, or block by block), and perform arbitrary reversible calculations (such as bit-wise XOR, position interleaving, logical operator assembly, etc.) to generate the first layer of ciphertext.

[0074] Subsequently, the negotiated fingerprint is used to perform a secondary mask encryption operation (such as XOR, difference perturbation, byte shuffling, etc.) on the ciphertext to obtain the final ciphertext and send it to the other party.

[0075] Optionally, use the secret key calculated based on the fingerprint to perform a secondary mask encryption operation on the ciphertext (such as XOR, difference perturbation, byte shuffling, etc.) Compared with Solution 1, this method is more "holistically synergistic" and suitable for medium and high-intensity encryption needs.

[0076] Option 3 (Dynamic perturbation command automatic drive mechanism, hell-level encryption version): In this variant, the system introduces an automated unpredictable perturbation mechanism, namely: during each communication process, the value of any two bytes in the current ciphertext or plaintext (such as the last two bytes, random position pairs, structural marker bits, etc.) is extracted, and the type of perturbation operation, parameter values, perturbation algorithm selection, etc. of the next round are dynamically determined based on this.

[0077] This perturbation strategy does not rely on fixed rules or preset patterns. Instead, it drives the evolution of perturbation logic through the communication content itself, forming a behavior pattern that is extremely difficult to predict and simulate, effectively defending against man-in-the-middle attacks, replay attacks, and rule-based password guessing.

[0078] This method is suitable for communication encryption tasks in highly sensitive and high-risk environments, and can be used in conjunction with the main solution or solution 2 to further enhance security strength.

[0079] The above solutions can be used independently or in combination to form a customized encryption communication mechanism for different security requirements, and realize the adjustable and automatic upgrade of encryption structure and behavior control strategy.

[0080] This implementation is suitable for typical client / server (C / S) architecture applications. The client and server communicate using the aforementioned encryption and authentication mechanisms, ensuring anonymity, integrity, and bidirectional identity security during transmission.

[0081] All three solutions are suitable for C / S architecture and have good scalability. They can be ported to P2P, edge computing or decentralized identity systems as needed.

[0082] For the exception handling solution of disturbance state synchronization mechanism and multi-threaded data transmission: To avoid decryption failures caused by asynchronous byte mapping state during communication due to factors such as multi-thread concurrency, asynchronous channels, or network delays, the present invention provides a complete set of disturbance state synchronization and conflict fallback mechanisms, including but not limited to the following strategies: 1. Disturbance state synchronization strategy: Perturbation number embedding mechanism When each round of perturbation is performed, a unique perturbation sequence number (perturbation counter) is assigned to the mapping structure, and the current perturbation number is embedded in the packet header or structure as additional metadata, so that the receiver can automatically load and perform the corresponding perturbation state reconstruction operation during the decryption phase to ensure decryption alignment.

[0083] Disturbance copy mechanism Before sending data, the system saves a read-only copy of the byte mapping structure of the current state as the mapping source for the data packet sent this time, ensuring that the perturbation state of this round remains stable and independent in multi-threaded or non-blocking communication, and avoiding state drift caused by contention between different threads.

[0084] Perturbation instruction embedding mechanism (optional) If the security requirement is high, the perturbation instruction summary or perturbation parameter plain text used in this round of perturbation can be embedded in the data. The receiver can execute the synchronous perturbation process based on the instruction without relying on the global state, forming a self-describing data structure.

[0085] 2. Abnormal conflict handling mechanism: Disturbance state fallback mechanism When the receiver detects that the perturbation number is inconsistent with the local state or decryption fails, the perturbation state rollback strategy can be automatically triggered, that is, rolling back to the previous perturbation state based on the current perturbation history record and retrying decryption to avoid data loss.

[0086] Fault-tolerant retry mechanism If the data cannot be correctly decrypted after several consecutive perturbation rollbacks, the system can automatically mark the data packet as "delayed processing" status, waiting for the complete perturbation certificate to be supplemented or requesting a resend operation to ensure data consistency and integrity.

[0087] Data reordering support (optional) If the application scenario is a high-concurrency asynchronous communication environment (such as IoT edge nodes or high-speed bus systems), the out-of-order packet processing module can be enabled to reorder and cache the packets according to the perturbation number, and then descramble them uniformly after reassembly.

[0088] 3. System security and design advantages: Ensure that each round of perturbation operation corresponds to a data packet one by one to avoid state drift; Supports disturbance isolation and state synchronization in concurrent environments; Decoupling the perturbation state from the data encryption process enables the receiver to independently complete descrambling without requiring global state. Reduce data packet dependency, improve decryption stability and fault resistance; Effectively improve robustness and recovery capabilities in extreme network environments or malicious attack scenarios.

[0089] Scope of application: This mechanism is applicable to all communication encryption, file encryption, fingerprint authentication and other modules involved in the present invention that are built based on disturbance instructions, disordered byte mapping structure and dynamic session state. It is particularly suitable for application scenarios in high concurrency, asynchronous communication, low latency sensitive or anti-crawler environments.

[0090] Exception handling solution 2 for byte mapping disturbance state: In the "perturbation-type encryption communication mechanism based on identity fingerprint" provided by the present invention, in order to prevent problems such as perturbation instruction dislocation, state conflict, and round confusion during high concurrency, asynchronous communication, and two-way synchronization, a synchronization mechanism based on "central lock" state control and perturbation token is further proposed to achieve sequential consistency protection and abnormal rollback capability during multi-round communication.

[0091] Step 1: Communication status marking and perturbation round number Before performing a disturbance operation (whether sending or receiving) in each round, both communicating parties must maintain a local round ID (RoundID) and disturbance state ID (DisturbID). Each round of operation is performed based on the state of the previous round, and the state record is updated after completion.

[0092] Step 2: Establish a central lock before perturbation execution To prevent the sender and receiver from being disturbed at the same time (causing state desynchronization), the present invention introduces a "central lock mechanism". This mechanism includes: TxLock: Locked before each round of encryption on the sender until the other party confirms successful decryption; Receive Lock (RxLock): Checks whether the perturbation state is synchronized with the sender before each round of decryption at the receiver; Central state lock (SessionLock): Uniformly mark the disturbance state in the current session to ensure that the currently executing state is not advanced to the next round before both parties agree.

[0093] Step 3: Perturbation Token Mechanism and Synchronous Confirmation Before each round of data transmission, the sender encapsulates the current disturbance state number (DisturbToken) in the data packet and sends it. After the receiver receives the data packet: Compare the tokens; If they are consistent, de-perturbation is performed; If inconsistent, suspend the current operation and request retransmission or reset the status.

[0094] Step 4: Round advancement and synchronization lock release When the receiver successfully decrypts and verifies, it sends an "acknowledgement synchronization instruction (ACK)" to the sender. After receiving the signal, the sender releases the current sending lock and advances the perturbation instruction to the next round.

[0095] Step 5: Rollback mechanism for abnormal situations If any of the following situations occurs: Timeout due to failure to receive confirmation packet from the other party; The received perturbation token is inconsistent with the local state; Status conflicts during synchronization; The system will automatically pause the disturbance propulsion and roll back to the previous round of disturbance state. It can automatically restore the state based on the previous round disturbance record or require re-negotiation of fingerprints to restore the communication link.

[0096] Advantages of the center lock mechanism: Synchronous control: strictly limit the order of disturbance advancement to prevent the status of both ends from being disordered.

[0097] State consistency: Ensures that the perturbation table is always synchronized, so that the decryption success rate of ciphertext reaches 100%.

[0098] Anti-concurrency attack: Prevent malicious nodes from forging rounds to send data and avoid disturbance dislocation attacks.

[0099] Rollback: Any round can be rolled back to the last stable state based on the state record.

[0100] This mechanism achieves secure synchronization with virtually no system hindrances in practice due to its extremely fast computational speed and highly concise logical structure for state synchronization and perturbation token verification. Even in high-concurrency, low-bandwidth, or unstable network environments, it ensures consistency in the perturbation states of both communicating parties and continuity of the command chain. This ensures extremely high execution efficiency and stability, making it suitable for secure communication scenarios and sensitive data exchange systems with stringent latency requirements.

[0101] Alternative 4: Static Mapping Communication Mode with Fingerprint Mask Priority To cope with situations such as concurrent communications, limited device performance, or unstable network status, this solution proposes a lightweight mode that bypasses the perturbation synchronization step and prioritizes the use of fingerprint masks for communication encryption.

[0102] The implementation steps are as follows: Initialize fingerprint structure: The communicating parties generate a negotiated fingerprint through the "initialization method of identity mapping fingerprint structure"; Direct encryption: Use the negotiated fingerprint or its hash-derived mask to perform a one-time reversible calculation (such as XOR, byte offset, structural scrambling, etc.) on the plaintext byte data; Send ciphertext: Output the encrypted ciphertext, which does not depend on the perturbation mapping table operation in each round; Decryption: The receiver uses the same mask structure to complete the decryption and restoration, and the process remains consistent; State Management: The mapping perturbation mechanism can be re-enabled in subsequent sessions or verification nodes to achieve policy-level progressive encryption upgrades.

[0103] advantage: Reduce system complexity; Avoid state confusion or deadlock; Reduce equipment synchronization pressure; Calculation speed slightly improved; Preserve core security (fingerprint mask still has strong identity binding); Still unpredictable and resistant to crawlers (mask changes are based on identity structure and cannot be forged);

[0104] Applicable to the communication initialization stage, weak device access environment, and anonymous session scenarios; It can be used as a backup path for the default solution and automatically switches intelligently according to the communication environment; Support dynamic combination with disturbance mechanism to improve resilience response capabilities.

[0105] The present invention supports switching to a fingerprint mask-priority encryption mode according to actual needs during the communication process, bypassing the disturbance state synchronization step, and realizing a more efficient ciphertext generation mechanism, thereby ensuring communication stability and compatibility in special scenarios.

[0106] (IV) Specific Implementation Plan 1 for the De-real-name Identity Registration and Binding Mechanism: like Figure 4 Shown is the logic diagram of user and enterprise registration and login process.

[0107] Step 1: Anonymous Registration Request During the initial registration phase, the user does not submit any plaintext identity information. Instead, the user generates an identity fingerprint (A) by locally executing the "Specific Implementation Plan 1 for Initializing the Identity Mapping Fingerprint Structure" and sends the identity fingerprint structure as a registration credential to the target application server (B).

[0108] Step 2: The server generates an authentication fingerprint After receiving the user's identity fingerprint information (A), the server (B) executes steps 1 and 2 described in "Specific Implementation Plan 1 for Identity Derivation Mechanism and Chained Identity Verification Structure Construction" and uses the enterprise-side parent identity private key and authentication process rules to derive an "authentication fingerprint" (C) bound to the user. This fingerprint has a clear bloodline source structure and a verifiable authorization chain to ensure that it cannot be forged or counterfeited.

[0109] Step 3: Local binding and authentication credential establishment The generated "authentication fingerprint" (C) is then sent by the server to the user's client, where both parties locally store and bind the fingerprint to their identities. During subsequent communications, users no longer need to log in again or submit their private identity information again; they only need to provide the authentication fingerprint to confirm their identity, verify their permissions, and establish a legitimate communication session.

[0110] Optional parameter description: Identity fingerprint summary / full structure (A): Users can choose to transmit partial fields or the entire structure, depending on the system sensitivity requirements, registration policy and privacy protection level settings; Authentication fingerprint (C): Optional support for multiple nested authentication fields, such as corporate signature identification, validity period field, fingerprint usage restrictions, authorization object ID, etc., for expanding future permission control logic; Authentication fingerprint embedding strategy: You can choose to embed the authentication fingerprint into the communication protocol message, use it as a database primary key field or encryption token to adapt to different network architectures and communication frameworks.

[0111] Technical advantages: De-identification design: The entire identity binding process does not involve plaintext identity information or fixed identification IDs, providing strong anonymity and resistance to user profiling. The binding process is unforgeable: the generated authentication fingerprint is derivative and traceable, and cannot be generated by simple copying and counterfeiting; Support cross-system migration and access control: The authentication fingerprint is a lightweight and structured authentication credential that is easy to transfer and parse between multiple systems or sub-modules; Easy to expand and automate deployment: The authentication process can be integrated into the server system in the form of plug-ins or APIs, supporting large-scale anonymous user registration requirements; Adaptable to various architectures: This mechanism is applicable to various communication architectures such as C / S, B / S, and P2P, and is particularly suitable for scenarios such as digital identity platforms, lightweight authentication systems, and IoT terminals.

[0112] Specific implementation plan 1 of the delayed authenticated anonymous communication and authentication dual-channel mechanism: The present invention further proposes a delayed identity authentication communication mechanism based on derived fingerprints, establishing a dual security channel that combines anonymous communication initialization with authentication fingerprint binding verification. This mechanism controls the sequence of fingerprint usage in stages, eliminating the need to expose any real identity information during the initial communication startup. Initial data exchange is completed by deriving a "negotiated fingerprint" to construct a session key through the process of "Specific Implementation Plan 1 of Derived Key Negotiation and Mapping Communication Encryption Mechanism." In subsequent scenarios requiring identity binding, permission verification, and sensitive operations, the authentication fingerprint structure is transmitted back through the secure channel established by the "negotiated fingerprint," completing two-way trust authentication and strengthening the communication channel.

[0113] This mechanism includes the following steps:

[0114] The communicating parties generate a temporary communication "negotiation fingerprint" locally through the process of "Specific Implementation Plan 1 of Derived Key Agreement and Mapping Communication Encryption Mechanism"; • The fingerprint is used to initialize the temporary byte mapping structure table, and both parties synchronously generate the same temporary session encryption structure before communication starts; • The entire process does not require any plaintext identity fingerprint or real private key information, achieving anonymous, secure, and decentralized initialization channel construction.

[0115] Delayed authentication process in encrypted channels • During the communication process, when permission verification, identity binding or sensitive data submission operations are required, the communicating parties can upload the local complete authentication fingerprint structure in the encrypted channel; • The other party completes the legitimacy verification through the identity chain, maternal mask fragment, signature information and other contents contained in the authentication fingerprint structure, and establishes a corresponding mapping relationship with the previous temporary communication fingerprint; • Once the verification is passed, the session is deemed to have a trusted identity binding and can be dynamically upgraded to an authenticated communication session channel with identity permissions.

[0116] Dual fingerprint complementary mechanism • Temporary communication fingerprints are one-time, secure, efficient, and anonymous, and are used to establish communication tunnels; • Authentication fingerprints have long-term, traceable, and identity-binding capabilities, and are used to establish a foundation of trust; • The present invention supports the use of a dynamic combination of the two in a session, ensuring communication data while achieving gradual verification and upgrade of session identity.

[0117] This mechanism effectively integrates the dual security demands of anonymity and trust, avoiding the problem of traditional communication architecture exposing identity information or static keys during the communication initialization phase, while avoiding the risks of man-in-the-middle attacks and forged identity logins. It has extremely high security value, privacy protection capabilities and flexible adaptability, and is suitable for all digital communication systems that need to support real-name authentication and dynamic trust negotiation.

[0118] (V) Specific implementation plan 1 of the permission control and file mapping encryption mechanism: This implementation scheme proposes a file encryption process based on the combination of derived identity fingerprint and byte mapping perturbation mechanism, which is suitable for implementing file-level permission control, encryption access management and dynamic decryption authorization.

[0119] Step 1: Initialize identity fingerprint and mapping structure The user generates the current user's permission fingerprint (A) locally by executing the "Specific Implementation Plan 1 of the Initialization Method of the Identity Mapping Fingerprint Structure" and generates a default or user-defined random byte mapping table (B) based on the initialization parameters as the initial structure for subsequent mapping encryption.

[0120] Step 2: Read file data and map encryption The system sequentially reads the original file data stream (C). Each time a byte block of a specified length (or a variable-length block) is read, a predefined perturbation instruction set is invoked to perturb and update the current scrambled mapping structure table (B). The updated byte mapping table is then used to perform byte-by-byte mapping encryption on the current block. The identity fingerprint (A) is then used to perform a round of reversible perturbation calculations (e.g., XOR scrambling, structural signatures, byte offsets, etc.) on the encrypted result of the block to further enhance tamper resistance. The processed encrypted data is then written to a new file, database, chained storage structure, or any external storage medium.

[0121] Step 3: Dynamically perturb the scrolling mechanism Before each round of data processing, a perturbation operation must be performed again based on the current state to generate a new round of byte mapping structure. This dynamic rolling mechanism makes each round of encryption unpredictable, enhancing the system's security and anti-collision capabilities.

[0122] Step 4: Generate decryption credentials and bind permissions After completing file encryption, the system generates a structured decryption credential that records the execution sequence of each perturbation instruction, perturbation type, data block size, mask mode, and other necessary parameters. This decryption credential is reversibly encrypted using the identity permission fingerprint (A), ensuring that only legitimate identity authentication can correctly decrypt and obtain file access rights.

[0123] This mechanism supports subsequent fingerprint-based permission verification and file access authorization, forming a complete closed-loop link of "identity-permission-data".

[0124] 1. Description of the predefined perturbation instruction set: The instruction set can be freely arranged according to the needs of the implementer; Support static preset or dynamic selection at runtime; Operation types include but are not limited to: permutation, flipping, displacement, byte swapping, perturbation hashing, out-of-order mapping and reorganization, etc. It can support instruction compression encoding or jump table logic to optimize storage and parsing efficiency.

[0125] 2. Suggestions for decryption credential structure record items (not limited to): Encrypted block length; The type, parameters, and perturbation factor of each round of perturbation operation; identification fingerprint number or summary; Decrypted signature or verification code (for anti-tampering and anti-counterfeiting).

[0126] 3. Summary of technical advantages: Prevent illegal users from bypassing verification and decryption; Supports fine-grained permission division; Supports traceability of decryption process, anti-replay and anti-copying; It can be used in conjunction with the fingerprint chain mechanism to achieve permission inheritance and cross-generation access control.

[0127] Optional expansion plan 2:

[0128] In order to enhance the adaptability and user controllability of the perturbation mechanism, the present invention proposes a mechanism for generating perturbation instructions based on graphical user interaction.

[0129] 1. Operation process: The system provides a graphical interface before disturbance operation; Users can define disturbance modes independently through gesture operation, module dragging, slider parameter setting, etc. The background analyzes the user input and automatically generates a perturbation instruction sequence (such as OP1-5|OP3-21|OP7-4); Each round of perturbation can dynamically change based on user input, forming a "perturbation script" with visual recording function; The final perturbation script can be embedded into the decryption certificate as structured content to achieve restoration verification.

[0130] 2. Advantages and Value: Empower users to control their encryption strategies and increase participation; Lower the operational threshold so that non-professionals can also customize the encryption structure; Prevent fixed instruction paths from being reversed by machine learning attacks; Enhance dynamism and encryption complexity; It can avoid behavioral analysis attacks such as keyboard monitoring and command leakage.

[0131] Supplementary Note: Flexible Scalability of Multi-Level Reversible Encryption Mechanism In the encryption process described in the above steps, the encryption method used in the present invention is not limited to using only identity fingerprints for masking operations. It can also introduce multi-level, modular, and combined reversible encryption calculation methods according to actual application requirements to further enhance the data's anti-counterfeiting, anti-reversal and access isolation capabilities.

[0132] Optional multi-layer encryption strategies include but are not limited to: Using the fingerprint as the master mask, nested multiple reversible perturbation calculations (such as cyclic XOR + offset scrambling + random permutation); After each round of mapping encryption, a temporary perturbation vector or a dynamically generated perturbation mask is introduced to perform superimposed perturbation; Add a dynamic scrambling layer based on timestamp or device fingerprint after perturbation mapping; The behavioral fingerprint sequence generated by combining the user's operation behavior is used to generate the disturbance factor of the perturbation function; Dynamically configure the encryption level and number of perturbation functions based on file type or data sensitivity level.

[0133] Technical advantages: Enhance encryption diversity to prevent homogeneous encryption patterns from being predicted or reused; The encryption complexity and decryption threshold can be flexibly set for different file types and access scenarios; Improve the tamper resistance and auditability of data in long-term storage and distributed environments; Realize dynamic desensitization, permission tracking and zero-trust access control during data usage.

[0134] This mechanism not only realizes identity binding, file-level encryption and closed-loop control of access rights, but can also be combined with a graphical perturbation input system to find a good balance between data security, usage threshold and flexibility. It is suitable for enterprise-level data protection, personal privacy leakage prevention, chain storage verification and file circulation security architecture under the zero-trust system.

[0135] (VI) Specific implementation plan for the emergency mechanism for identity loss and recovery: The present invention further provides an emergency loss reporting and identity recovery mechanism based on a fingerprint structure, which is suitable for when user identity credentials (such as derived fingerprints, authentication fingerprints, etc.) are stolen, lost or actively revoked. Through controlled verification and disconnection operations, the integrity, security and traceability of the digital identity system are guaranteed.

[0136] Step 1: Identity verification and report loss request submission If a user discovers a risk of theft or loss of control over their fingerprint, they can proactively submit a report to the system. The system will then request the user's local private key (i.e., the local encryption parameters corresponding to the original identity credential). The system will then verify the original identity fingerprint structure in the database and invoke Step 6 of "Specific Implementation Plan 1 for Initializing the Identity Mapping Fingerprint Structure" to parse the "origin identifier" and signature chain associated with the identity.

[0137] The system performs a two-way comparison between the origin identifier and the signature chain to determine whether the requester is the legal holder of the identity.

[0138] Step 2: Freeze the invalid fingerprint chain and permission chain Once verification is successful, the system immediately marks the current derived identity fingerprint and its associated permission structure as "invalid." This action prevents the original identity from participating in subsequent communications, data decryption, authentication, and system access operations, preventing the further misuse of leaked or illegally obtained fingerprints.

[0139] Step 3: Fingerprint reconstruction and permission recovery After completing the report of loss, the system allows the user to re-execute the initialization process of the identity mapping fingerprint structure based on the "origin identifier", generate a new fingerprint structure, and form a new fingerprint chain and permission chain.

[0140] To ensure the security of user assets and operational continuity, the system can enable an authorized data migration mechanism to bind data resources under the old fingerprint (such as communication keys, encrypted files, and permission tables) to the new identity structure, thereby achieving identity recovery and smooth transfer of permissions.

[0141] Optional backup plan 2: auxiliary password loss verification mechanism During the actual identity registration process, as described in step 2 of "Specific Implementation Plan 1 for De-real-name Identity Registration and Binding Mechanism," the system allows the enterprise to guide the user to submit a password credential for auxiliary identity identification when generating a user-derived identity structure.

[0142] The system converts the password credential into a byte stream, and performs a perturbation operation on the password byte state through the random byte mapping table of the enterprise's parent identity fingerprint (i.e., the system's own identity fingerprint), generating an encrypted segment as a loss report chain segment, which is embedded in the end structure of the user's derived authentication fingerprint.

[0143] The loss report verification process is as follows: When the user submits a report of loss, he / she shall provide the password certificate originally submitted; The server processes the password credential in the same way as during registration and generates a verification segment; If the generated verification segment is completely consistent with the loss report segment embedded at the end of the fingerprint, the identity is confirmed to be legitimate; The system executes steps 2 and 3 in the above solution 1 to complete the loss report, fingerprint reconstruction and permission recovery process.

[0144] Technical advantages and applicable scenarios Flexible adaptation to various identity authentication methods (such as private key signature or auxiliary password); Implement a dual-path loss reporting and recovery process (high-authority path + low-threshold auxiliary path); It meets multiple security requirements such as decentralization, anonymous authentication, fingerprint chain reconstruction, and permission recovery and migration; It is suitable for high-security scenarios such as enterprise-level communication systems, distributed identity networks, and digital asset custody systems.

[0145] 6. Comparison with existing technologies In the field of identity authentication and encrypted communication technology, this invention overcomes the many limitations of traditional encryption systems in terms of identity dependence, key reuse, centralized authentication, user experience, and performance adaptation. It proposes a new decentralized encryption and identity authentication system that combines a chain-derived fingerprint structure with a dynamic mapping perturbation mechanism. Compared with existing mainstream technical solutions, the specific differences and technical advantages are as follows:

[0146] Existing solutions generally rely on static keys, preset key agreement mechanisms (such as Diffie-Hellman), and centralized key infrastructure (PKI / CA) for key management and identity binding. Communication initialization requires multiple rounds of handshakes, resulting in high communication latency and security risks such as key reuse and replay attacks.

[0147] The innovation of this invention lies in: adopting a dynamic fingerprint mapping structure and a local perturbation instruction set, completely breaking away from the static key system and centralized dependence, and realizing negotiation-free, handshake-free instant communication; each communication key is independently derived through the identity structure, which is more secure and more real-time.

[0148] 2. Compared with centralized authentication systems (such as certificate login, OAuth, SSO) Traditional authentication solutions rely on account systems or centralized servers to verify user identities. Sensitive user information must be registered and stored in the cloud, posing risks such as privacy leaks, single points of failure, and authentication service interruptions. Furthermore, authentication mechanisms are rigid and lack personalization and dynamic authorization capabilities.

[0149] The present invention, through the construction of local identity fingerprints and a chained identity structure derivation mechanism, combines an anonymous mask with the authentication fingerprint to achieve user identity self-sustaining, anonymous verification, and account-free login. This eliminates the need to upload plaintext identity information or bind a real identity identifier, fundamentally avoiding the structural risks of traditional authentication architectures.

[0150] 3. Compared with decentralized identity authentication (such as DID, blockchain-based smart contract authentication) Although blockchain authentication solutions have the advantages of decentralization and on-chain verifiability, they rely on off-chain key management platforms to interact with on-chain transactions, and have limitations such as complex deployment, high latency, and high on-chain costs. They are not suitable for edge computing, low-power devices, or communication systems with high real-time requirements.

[0151] The identity derivation mechanism of the present invention runs completely locally without relying on a blockchain platform or smart contract system. It adopts a lightweight mapping structure and perturbation algorithm to achieve a low-latency, highly adaptable anonymous identity authentication and communication encryption system, which is particularly suitable for resource-constrained devices and high-concurrency application scenarios.

[0152] 4. Compared to quantum-safe cryptography (such as short vector perturbation algorithms based on lattice theory) Quantum encryption schemes often rely on complex key spaces constructed using high-intensity mathematical models, making them difficult to implement efficiently on standard devices. Their high computational and communication costs and high technical barriers make them unsuitable for widespread commercial use.

[0153] Relatively speaking, the present invention is based on an identity fingerprint structure derived from behavioral characteristics and a low-complexity byte perturbation algorithm. It does not rely on high-intensity mathematical hardware support, but can still build an anti-counterfeiting authentication and encryption mechanism of equivalent strength, support identity loss reporting and authority migration, with lower costs and easier operation.

[0154] 5. Compared with traditional visual mapping or Rubik's Cube encryption schemes Traditional Rubik's Cube encryption or mapping algorithms are mostly used for image data obfuscation or fixed replacement encryption. They lack identity binding, permission control and derivative verification capabilities, have weak security, and are difficult to prevent replay and forgery.

[0155] The present invention generates a unique identity fingerprint through a 256-byte dynamic mapping structure, and combines a chained identity derivation mechanism and a perturbation instruction set to achieve a deep integration of identity authentication and encrypted communication. It not only has authentication significance, but can also be used as a dynamic communication token or encrypted evidence, and has high practical value and anti-counterfeiting capabilities.

[0156] 6. Compared with other authentication methods such as one-time password (OTP), verification code, temporary token, etc. Traditional OTP authentication methods rely on network synchronization and manual user input, and are subject to problems such as man-in-the-middle monitoring, reuse, and poor user experience, making them difficult to apply to non-interactive scenarios.

[0157] The authentication fingerprint mechanism provided by the present invention has the advantages of local generation, fully encrypted transmission, and no need for repeated login and input; through dynamic perturbation logic and a unique fingerprint structure, a one-time verification, long-term validity, secure, anonymous, and non-replayable communication identity authentication mechanism is realized, greatly simplifying system deployment and improving user experience.

[0158] In summary, the present invention demonstrates significant technical advantages in communication encryption, identity authentication, user privacy protection, and cross-platform deployment, solving the following key problems in existing technical architectures: Communication security risks caused by static key reuse; Privacy leakage and system vulnerability caused by reliance on central authentication agencies; The encryption process is complex, the communication handshake is cumbersome, and the latency is high; Difficulty in achieving anonymous communication, dynamic identity chains, and permission inheritance; Unable to deal with the issues of reporting loss and recovery after identity leakage.

[0159] The fingerprint-derived chain encryption mechanism proposed in this invention lays a solid foundation for building the next generation of traceable, recoverable and controllable decentralized digital identity system.

[0160] This paper proposes a new digital identity authentication and encryption communication system that integrates dynamic mapping perturbation, chained identity fingerprint derivation mechanism, and anonymous communication structure. It has the following core technical advantages and application value: De-realization of identity authentication and decentralization of the process: anonymous identity fingerprints and parent-line derivation structures are used to achieve identity binding, without relying on PKI, certificates or account registration systems; Dynamic perturbation encryption mechanism, highly secure and computationally lightweight: Communication keys are generated in real time based on fingerprint perturbations, are highly unpredictable and non-reusable, and are suitable for embedded and edge computing scenarios. Chain fingerprint structure enables identity inheritance, verification, and loss reporting: It can build an identity structure pedigree to achieve cross-generational authority inheritance, anti-counterfeiting verification, and loss recovery; Supports dual-channel delayed authentication mechanism: anonymous encryption is implemented in the pre-communication stage, and authentication binding is completed in the mid- and post-communication stages to prevent security risks such as eavesdropping, hijacking, and replay; Supports graphical perturbation input and behavioral fingerprint fusion mechanism: The visual interaction method enhances controllability and user participation, and improves the personalization and dynamic complexity of encryption strategies.

[0161] 2. Technical Adaptability and Scalability This system is compatible with a variety of network and terminal environments, including but not limited to: C / S, B / S, P2P, and Internet of Things (IoT) communication architectures; Online identity authentication, device access control, live stream encryption, etc. Digital assets, chain certificates, and government and enterprise data security management platform; Off-chain identity mapping and on-chain permission identification binding system in blockchain; Behavioral auditing, data traceability and communication reinforcement mechanisms under the zero-trust architecture.

[0162] 3. Implementation Feasibility and Industrial Potential This system has a compact design, low computing cost, and flexible deployment, making it suitable for mobile devices, edge gateways, embedded systems, etc. It is highly modular and can be integrated into various communication systems and platforms through API, SDK, plug-ins, etc. It can effectively build a decentralized identity authentication infrastructure that supports anonymity, verifiability, and recoverability, and support the next generation of digital social identity governance system.

[0163] IV. Conclusion In summary, this invention demonstrates not only a high degree of innovation in its theoretical framework but also strong adaptability and scalability in engineering practice. Its decentralized authentication structure, based on identity fingerprints, integrates multiple core mechanisms, including perturbation encryption, fingerprint derivation, permission binding, dynamic authorization, emergency reporting, and graphical intervention, to form a complete, secure, and efficient closed-loop digital identity system. This system is expected to be widely applicable in key areas such as digital communications, anonymous networks, IoT access, smart device authentication, digital asset transmission, and privacy protection, providing strong support and technical assurance for building the next-generation digital identity and trust infrastructure.

Claims

1. A chained anonymous identity authentication and dynamic encryption communication method based on byte mapping, suitable for encrypted communication between a client and a server, characterized in that: The method comprises the following steps: By inputting any byte sequence, user private key and system initialization parameters, an original identity fingerprint structure for identity authentication is constructed. The identity fingerprint structure is constructed through byte mapping processing, perturbation factor embedding and derivation calculation, and has uniqueness, irreversibility, derivability and identity verification capabilities; The communicating parties exchange their identity fingerprints and generate a consistent communication fingerprint through fingerprint negotiation, which is used as the session key in the symmetric communication process and the data mapping table for encryption; During the communication process, based on the communication fingerprint and the predefined perturbation mechanism, mapping encryption and reversible masking operations are performed on the transmitted data, and corresponding mapping decryption and mask restoration operations are performed on the received data to achieve encryption and decryption synchronization; The communication process supports anonymous initialization based on the fingerprint chain structure and allows identity authentication and binding at the end of the communication. The identity fingerprint structure supports multi-level derivation, allowing the construction of a parent-child fingerprint chain structure. Each layer of derived fingerprints can be verified to be legitimate and traceable to the original identity.

2. The method according to claim 1, characterized in that The original identity fingerprint structure includes the user's private key and origin identifier for identity authentication, and a reversible masking operation is performed on the entire structure to generate a signature to support identity authentication and permission binding; The derived identity fingerprint structure is based on the original identity fingerprint structure and is embedded with a maternal mask fragment, a paternal mask fragment or a fusion mask fragment thereof, and a reversible mask operation is performed on the embedded structure again to generate a signature, so as to establish an identity derivation chain with traceability capability.

3. A method according to any preceding claim, characterized in that The perturbation instruction set is a callable predefined set structure, which can be provided by the system by default or customized by the user in a visual manner before communication initialization. The perturbation operation can be dynamically called and executed as needed during the communication process to enhance communication security and non-repetitiveness.

4. A method according to any preceding claim, characterized in that Also included is a mechanism for file-level permission control and mapping encryption, the mechanism comprising the following steps: (1) Based on the identity fingerprint structure and the perturbation instruction set, the data stream of the target file is mapped and encrypted; (2) Before each round of data processing begins, the current mapping structure table is disturbed and updated to improve encryption strength and dynamics; (3) Synchronously generate a structured decryption credential, which is used to describe the parameters required for decryption; (4) performing one or more layers of reversible masking operations on the decryption credential to generate a controlled encryption credential to achieve access control and legal decryption authorization; (5) The structured decryption credential at least includes a perturbation parameter, a block size, and a mask pattern, and other auxiliary information may be added as needed to support the decryption process in extended scenarios.

5. The method according to claim 5, characterized in that The perturbation parameters and operation sequence can be configured by the user through a visual interface. Configuration methods include dragging, combining modules or slider input. The system automatically generates a perturbation script based on the user operation and uses it in data encryption processing and the generation of structured decryption credentials.

6. A method according to any preceding claim, characterized in that The communication method includes a delayed identity authentication process, in which, during the communication initialization phase, anonymous communication is performed based only on a communication fingerprint generated through temporary negotiation; When the system detects that a sensitive operation needs to be performed, the user needs to submit an authenticated identity fingerprint or a complete identity fingerprint structure to complete the identity binding and permission activation operations.

7. A method according to any preceding claim, characterized in that The system supports a loss and recovery mechanism for identity fingerprints. Users can submit local private keys or auxiliary identity passwords, and the system will verify their legitimacy based on the parent fingerprint structure. After verification, the user is allowed to regenerate a new identity fingerprint structure and migrate the original permission data and authentication status.

8. A method according to any preceding claim, characterized in that In order to avoid the communication disturbance and asynchrony problem caused by multi-threading or concurrent state, the system introduces a central lock mechanism before each round of sending or receiving operations. It is used to synchronize and lock the encryption status of the current ciphertext and the execution status of the perturbation instruction set to ensure data consistency and decryption accuracy.

9. A method according to any preceding claim, characterised in that The dynamic mapping encryption mode in the communication system includes one or more of the following methods: (1) Before sending a message or after receiving a message in each round, perform a preset perturbation step on the current mapping structure table; (2) Selecting some bytes from each sent or received message as dynamic perturbation parameters to control the perturbation of the mapping structure table; (3) Perform reversible masking operations on plaintext or ciphertext based on the negotiated communication fingerprint; (4) Performing a reversible masking operation on the plaintext or ciphertext based on the private key used in the generation of the negotiated communication fingerprint; (5) Perform block-aligned reversible masking on the plaintext or ciphertext using the current byte mapping table.

10. A method according to any preceding claim, characterised in that The reversible masking operation is a type of reversible byte perturbation processing method, which specifically includes but is not limited to: performing reversible processing operations such as XOR operation, byte order flipping, structural displacement, difference perturbation or rolling shuffling on the target byte sequence, which is used to ensure the transformation and signing of the identity fingerprint without losing information.