Identity management method and system

By generating temporary public-private key pairs and identity identifiers for mobile intelligent agents, and combining them with digital certificates and symmetric keys, privacy-preserving identity management is achieved when mobile intelligent agents perform tasks. This solves the problem that mobile intelligent agents cannot demonstrate that they belong to the same owner in terms of privacy protection, and ensures the accuracy of identity recognition and privacy security.

CN120811800BActive Publication Date: 2025-12-23CHINA TELECOM ARTIFICIAL INTELLIGENCE TECHNOLOGY (BEIJING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511316810.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2025-12-23
Estimated Expiration
2045-09-15

AI Technical Summary

Technical Problem

When performing tasks, mobile intelligent agents cannot demonstrate to the other party that they belong to the same owner in a privacy-preserving manner. Existing technologies suffer from privacy leaks and uncertainty in identity recognition.

Method used

Multiple temporary public-private key pairs and temporary identity identifiers are generated for each mobile intelligent agent. By frequently changing the public-private key pairs and identity identifiers, combined with digital certificates and symmetric keys, identity management is achieved, ensuring privacy protection.

Benefits of technology

It effectively reveals its identity to other intelligent agents on the same side while protecting privacy and avoiding being associated with and tracked by adversaries, thus solving the problems of privacy leakage and uncertainty in identity recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811800B_ABST
    Figure CN120811800B_ABST
Patent Text Reader

Abstract

The application discloses an identity management method and system, which is suitable for mobile agents or other devices. The method comprises the following steps: generating a plurality of public-private key pairs for each mobile agent before the mobile agent performs a target task, wherein each mobile agent corresponds to an actual identity identifier, and each public-private key pair corresponds to a public-private key pair identifier; determining a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier; generating a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair; signing the digital certificate by using the private key of the mobile agent device owner, and storing the signed digital certificate, the temporary private key in the public-private key pair and the public key of the mobile agent device owner into the mobile agent. The application solves the technical problem that the mobile agent cannot indicate that it belongs to the same owner in a privacy protection manner in the related art.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, in particular to an identity management method and system. BACKGROUND

[0002] Currently, with the rapid development of artificial intelligence technology, mobile AI agents such as unmanned vehicles and unmanned aerial vehicles are increasingly widely used. When performing tasks, they often need to identify their identities through wireless communication to ensure cooperation with other agents belonging to the same party and prevent interference or intelligence gathering by opponents. However, under the technical framework of the related art, mobile agents cannot indicate that they belong to the same party in a privacy-protected manner to the communication peer.

[0003] To address the above problems, no effective solutions have been proposed so far. SUMMARY

[0004] Embodiments of the present application provide an identity management method and system to at least solve the technical problem that mobile agents cannot indicate that they belong to the same party in a privacy-protected manner to the communication peer in the related art.

[0005] According to an aspect of an embodiment of the present application, an identity management method is provided, comprising: generating a plurality of temporary public-private key pairs for each mobile agent before the mobile agent performs a target task, wherein each mobile agent corresponds to an actual identity identifier, and each public-private key pair of the mobile agent corresponds to a public-private key pair identifier; determining a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, wherein each public-private key pair identifier corresponds to a temporary identity identifier; generating a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, wherein each public-private key pair identifier corresponds to a digital certificate, and the digital certificate includes the temporary identity identifier corresponding to the public-private key pair identifier and the temporary public key in the public-private key pair; signing the digital certificate with the private key of the mobile agent device owner, and storing the signed digital certificate, the temporary private key in the public-private key pair, and the public key of the mobile agent device owner into the mobile agent, so that the mobile agent can identify other mobile agents belonging to the same owner according to the information stored by itself during the execution of the target task.

[0006] Optionally, the generating, for each mobile agent, a plurality of temporary public-private key pairs comprises: determining security specification requirement information corresponding to a target task that the mobile agent is scheduled to perform, and determining a task setting time period of the target task, wherein the security specification requirement information at least indicates an update period for the mobile agent to replace a public-private key pair applied when communicating; determining a first number of public-private key pairs scheduled to be generated for the mobile agent according to a length of the task setting time period and the update period, and generating the first number of public-private key pairs for each mobile agent.

[0007] Optionally, in the task setting time period of the target task, the mobile agent replaces the current corresponding public-private key pair and the temporary identity identifier according to the update period corresponding to the security specification requirement information.

[0008] Optionally, the determining, for each mobile agent, a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier comprises: determining a symmetric key corresponding to the target task; determining a plurality of specific mixing results according to the actual identity identifier and the public-private key pair identifier, wherein for each mobile agent, a series of specific mixing results are determined, and the number of the specific mixing results corresponding to each mobile agent is equal to the first number; and encrypting the first number of specific mixing results using the symmetric key to obtain the first number of temporary identity identifiers.

[0009] Optionally, the generating, for each mobile agent, a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier comprises: determining a symmetric key corresponding to the target task; determining a plurality of specific mixing results according to the actual identity identifier and the public-private key pair identifier, wherein for each mobile agent, a series of specific mixing results are determined, and the number of the specific mixing results corresponding to each mobile agent is equal to the first number; and encrypting the first number of specific mixing results using the symmetric key to obtain the first number of temporary identity identifiers.

[0010] Optionally, in the task setting time period of the target task, the method further comprises: in a case where it is detected that there is an anomaly in a signed message sent by mobile agents identified as belonging to the same owner, obtaining a temporary identity identifier currently corresponding to the mobile agent; decrypting the temporary identity identifier using the symmetric key to obtain a specific mixing result, and determining an actual identity identifier corresponding to the mobile agent according to the specific mixing result; obtaining all public-private key pair identifiers corresponding to the actual identity identifier, and determining all first number of temporary identity identifiers of the mobile agent according to the actual identity identifier and all public-private key pair identifiers; adding all temporary identity identifiers of the mobile agent to a certificate revocation list together with a current timestamp, and signing the certificate revocation list using a private key of the owner of the mobile agent device, and broadcasting the signed certificate revocation list to other mobile agents, wherein the certificate revocation list is used to indicate that the temporary identity identifiers contained in the certificate revocation list are all cancelled.

[0011] According to another aspect of the embodiments of the present application, another identity management method is also provided, which comprises: in a task setting period of a target task, digitally signing a service message according to a temporary private key stored by a mobile agent itself, wherein the mobile agent is configured to perform the target task in the task setting period, the temporary private key is a private key part of a plurality of public-private key pairs corresponding to the mobile agent, each public-private key pair corresponds to a public-private key pair identifier, each public-private key pair identifier corresponds to a temporary identity identifier, the temporary identity identifier is determined according to an actual identity identifier of the mobile agent and the public-private key pair identifier, and the temporary identity identifier is configured to temporarily identify the identity of the mobile agent in a communication process; and sending the service message after the digital signature and a digital certificate after the all-party signature of the mobile agent device corresponding to a temporary identity identifier corresponding to the temporary private key to other mobile agents, wherein the digital certificate comprises the temporary identity identifier and a temporary public key corresponding to the temporary private key in the public-private key pair, and other mobile agents receiving the service message and the digital certificate can identify whether the mobile agent sending the service message and the digital certificate is a mobile agent belonging to the same party according to information stored by the mobile agent itself and the service message and the digital certificate.

[0012] Optionally, the digital certificate after the all-party signature of the mobile agent device is obtained by signing with a private key of the all-party of the mobile agent device, the digital certificate further comprises a start and end time of a validity period of the digital certificate, and the information stored by the mobile agent itself comprises a public key of the all-party of the mobile agent device; the method further comprises: in a case where the service message and the digital certificate sent by the other mobile agent are received, verifying the digital certificate after the all-party signature of the mobile agent device by using the public key of the all-party of the mobile agent device; in a case where the digital certificate is verified and the current time is between the start and end time of the validity period of the digital certificate, verifying the service message after the digital signature by using the temporary public key contained in the digital certificate; and in a case where the service message is verified, determining that the other mobile agent sending the service message and the digital certificate and the current mobile agent belong to the same party.

[0013] Optionally, the method further comprises: in the case that the signed certificate revocation list is received, obtaining a timestamp carried by the certificate revocation list, wherein the signed certificate revocation list is obtained by signing the certificate revocation list with the private key of the mobile agent device owner, and the certificate revocation list is used to indicate that the temporary identity identifiers contained in the certificate revocation list are all cancelled; in the case that an error between the timestamp and a local timestamp of the mobile agent is within a preset time range, verifying the signed certificate revocation list by using the public key of the mobile agent device owner; and in the case that the certificate revocation list is verified, storing the temporary identity identifiers contained in the certificate revocation list in the mobile agent locally, and the mobile agent subsequently discards a signed message sent by a mobile agent corresponding to the temporary identity identifier contained in the certificate revocation list when the signed message is received.

[0014] According to another aspect of the embodiments of the present application, an identity management system is also provided, comprising: an owner's agent management device and a plurality of mobile agents, wherein the agent management device is configured to generate a plurality of public-private key pairs for each mobile agent before performing a target task, wherein each mobile agent corresponds to an actual identity identifier, and each public-private key pair corresponds to a public-private key pair identifier; determine a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, wherein each public-private key pair identifier corresponds to a temporary identity identifier; generate a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, wherein each public-private key pair identifier corresponds to a digital certificate, and the digital certificate comprises the temporary identity identifier corresponding to the public-private key pair identifier and a temporary public key in the public-private key pair; sign the digital certificate by using the private key of the mobile agent device owner, and store the signed digital certificate, a temporary private key in the public-private key pair, and a public key of the mobile agent device owner in the mobile agent; and the mobile agent is configured to perform the target task in a task setting period of the target task, and digitally sign a business message according to the temporary private key stored by the mobile agent itself in the task setting period of the target task; and send the signed business message and a digital certificate corresponding to a temporary identity identifier corresponding to the temporary private key signed by the mobile agent device owner to other mobile agents, wherein the other mobile agents receiving the business message and the digital certificate can identify whether the mobile agent sending the business message and the digital certificate is a mobile agent belonging to the same owner according to information stored by the mobile agents themselves and the business message and the digital certificate.

[0015] In the embodiment of the present application, by using the above manner, the mobile AI agent can effectively indicate the identity to other agents belonging to the same party while protecting privacy, avoiding being associated and tracked by the opponent, when performing the task by frequently changing the temporary public-private key pair and the temporary identity, thereby solving the technical problem in the related art that the mobile agent cannot indicate the same party to the communication peer in a privacy protection manner. BRIEF DESCRIPTION OF DRAWINGS

[0016] The accompanying drawings, which are included to provide a further understanding of the present application and are incorporated in and constitute a part of this application, illustrate embodiments of the present application and serve to explain the present application. In the drawings:

[0017] Figure 1 FIG. 1 is a schematic diagram of a method flow of identity management of an execution subject being an intelligent agent management device according to an embodiment of the present application;

[0018] Figure 2 FIG. 2 is a schematic diagram of a method flow of identity management of an execution subject being a mobile intelligent agent according to an embodiment of the present application;

[0019] Figure 3 FIG. 3 is a schematic diagram of an identity management system according to an embodiment of the present application. DETAILED DESCRIPTION

[0020] In order to enable persons skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by persons skilled in the art without creative labor should fall within the scope of protection of the present application.

[0021] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that such expressions can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.

[0022] For the convenience of those skilled in the art to better understand the embodiments of the present application, some technical terms or nouns related to the embodiments of the present application are explained as follows:

[0023] AI agent: referred to as agent, is a software or hardware system that can perceive the environment, make decisions and take actions, and has a certain autonomy. The agent interacts with the environment, learns and adapts constantly, and thus achieves a specific goal.

[0024] It should be noted that the mobile agent concerned in the embodiments of the present application is an intelligent hardware device capable of changing the physical position outdoors through automatic driving or sailing, including but not limited to: robots, robotic dogs, unmanned vehicles, unmanned aerial vehicles or other automated devices, etc. For example, it can be an unmanned aerial vehicle for delivering goods to customers, an unmanned vehicle for delivering fast food or other express delivery, an unmanned underwater vehicle for deep sea exploration, etc.

[0025] When performing tasks, how to effectively identify the identity of the self and protect the privacy of the agent, prevent competitors or the enemy from inferring the number, whereabouts and other key information of the agent through communication information is a problem to be solved.

[0026] For example, assume that two companies are using unmanned vehicles to deliver food in a certain town. In this scenario, unmanned vehicles of the same company will send messages through radio to report road conditions and other information, and will cooperate in groups to share information to improve delivery efficiency. On the other hand, the two companies in competition will not only avoid interference from the unmanned vehicles of the opponent, but may also collect and analyze relevant information about the opponent's unmanned vehicles to infer their operating status (such as vehicle fleet size, main customer group, average delivery distance and time per order, etc.). In this case, unmanned vehicles of the same company can ensure the confidentiality of communication through point-to-point encryption, but the basic premise of encryption is that both vehicles confirm that the other belongs to the same company.

[0027] As can be seen, the self-identity recognition and privacy protection of mobile agents are significantly different from common identity management problems. In view of the above-mentioned self-identity recognition problem, in the related art, one way is to use identity verification means of digital signature technology. In order to achieve the purpose of privacy protection, related technologies usually use cryptographic techniques such as group signature or ring signature, although the use of group signature or ring signature provides a higher level of privacy protection in theory, but they have specific requirements for the underlying algebraic structure, and have not become the focus of standardization organizations. This not only limits the practical application range of these schemes, but also may cause legal compliance challenges, especially in countries and regions that attach great importance to password compliance.

[0028] Another way in the related art is to identify the agent through physical features or behavior patterns, for example, using deep learning to analyze the appearance or motion parameters of the device to signal recognize the physical characteristics of the agent. However, in a competitive or hostile environment with homogeneous agent devices, the effectiveness of these methods is greatly reduced, it is difficult to distinguish the differences between the owners of the same devices, thereby causing uncertainty in identity recognition.

[0029] To solve the above problems, the related solutions provided in the embodiments of the present application can achieve the following effects:

[0030] 1) The agent can indicate that it belongs to the same side to the same companion, so as to be accurately identified as "ours";

[0031] 2) The agent does not reveal the actual effective identity when indicating the identity attribution, so as to avoid being associated and tracked by the opponent, thereby preventing the opponent from guessing how many entities the legitimate side has and where each entity has appeared, etc.

[0032] 3) The scheme does not depend on specific cryptographic algorithms (such as group signature or ring signature), but is implemented based on general standards, thereby paving the way for legal compliance.

[0033] The related solutions provided in the embodiments of the present application are described in detail below.

[0034] It should be noted that the service message sent by the agent can be unencrypted or encrypted; the embodiments of the present application focus on the identity management of mobile AI agents, and can also provide confidentiality protection when the agents communicate with each other (point-to-point encryption is used between the agents).

[0035] According to the embodiments of the present application, a method for identity management is provided. It should be noted that the steps shown in the flowchart can be executed by a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0036] The embodiments of the present application provide an identity management method, Figure 1 is a schematic diagram of a method flow for identity management according to the embodiments of the present application, as Figure 1 shown, the method can be applied to the agent management device of the agent of all parties, including the following steps:

[0037] Step S102, before the mobile agent executes the target task, generating a plurality of temporary public and private key pairs for each mobile agent, wherein each mobile agent corresponds to an actual identity identifier, and each public and private key pair of the mobile agent corresponds to a public and private key pair identifier;

[0038] Step S104, determining a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, wherein each public-private key pair identifier corresponds to a temporary identity identifier;

[0039] Step S106, generating a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, wherein each public-private key pair identifier corresponds to a digital certificate, and the digital certificate includes: the temporary identity identifier corresponding to the public-private key pair identifier, and the temporary public key in the public-private key pair;

[0040] Step S108, signing the digital certificate with the private key of the mobile agent device owner, and storing the signed digital certificate, the temporary private key in the public-private key pair, and the public key of the mobile agent device owner into the mobile agent, so that the mobile agent can identify other mobile agents belonging to the same owner according to the information stored by itself during the execution of the target task.

[0041] Through the above steps, the mobile AI agent can effectively identify the identity of other agents belonging to the same party by frequently changing the temporary public-private key pair and the temporary identity identifier when performing the task, while protecting privacy and avoiding being associated and tracked by the opponent, thereby solving the technical problem that the mobile agent cannot indicate that it belongs to the same owner in a privacy protection manner in the related art.

[0042] The identity management method in steps S102 to S108 of the embodiment of the present application is further described below.

[0043] The embodiment of the present application mainly includes an offline phase and an online phase, wherein the offline phase includes the initialization work performed by the mobile agent device owner in the base (such as an unmanned vehicle distribution warehouse or an unmanned aerial vehicle airport) before departure for this task, and the online phase refers to the process of each mobile agent traveling and performing a task (involving radio communication between agents, such as inquiry and response).

[0044] In this embodiment, it is assumed that the mobile agent device owner (for example, a company, denoted as M) has n mobile agents A i , 1≤i≤n, each mobile agent corresponds to an actual identity identifier i, and the real identity identifier (actual identity identifier) of A i can be marked on the surface of the device by physical methods such as spraying and engraving, and can be viewed by the owner M at zero distance, but cannot be disclosed in any communication. In the mobile agent A iIn the process of performing the target task, it is required that the mobile agent not only avoid revealing the real identity, but also avoid using any other identity for a long time. To this end, the embodiments of the present application provide corresponding solutions, and the method flows of the embodiments of the present application in the offline phase and the online phase will be introduced respectively. The main process steps of the offline phase can be carried out at the base of the mobile agent device owner, and are as follows.

[0045] First, before a batch of mobile agents A i (1≤i≤n) depart to perform the target task, the mobile agent device owner needs to confirm the security status of the hardware and software, including but not limited to: checking whether the physical appearance of the mobile agent is intact (such as not being disassembled, pierced, cut, pried, etc.), calculating the check value of the code and static data (which can be stored in the read-only memory area ROM of the mobile agent) using a standard algorithm (such as the domestic SM3), and comparing it with the reference value, etc. If it is found that a mobile agent has been damaged or illegally modified in hardware or software, it will be removed and new mobile agent devices will be added as needed.

[0046] The mobile agent device owner also needs to randomly select a symmetric key k and a symmetric encryption algorithm E(k,*) for the target task this time. For example, k can be a 128-bit secure random number, and E can be the domestic algorithm SM4.

[0047] At the same time, the mobile agent management device of the mobile agent device owner also needs to generate multiple temporary public and private key pairs for each mobile agent, and the specific steps are as follows.

[0048] In some embodiments of the present application, generating multiple temporary public and private key pairs for each mobile agent includes the following steps: determining the security specification requirement information corresponding to the target task planned to be performed by the mobile agent, and determining the task setting period of the target task, wherein the security specification requirement information at least indicates the update period of the public and private key pairs applied by the mobile agent when communicating; determining the first number of public and private key pairs planned to be generated for the mobile agent according to the length of the task setting period and the update period, and generating the first number of public and private key pairs for each mobile agent.

[0049] Specifically, the mobile agent device owner can generate temporary public and private key pairs (pk i ,sk ij ) for each mobile agent A ij 1≤j≤m according to a specific digital signature technology standard, where m is the upper limit of the number of public and private key pairs (i.e. the first number) required by the mobile agent to perform the target task this time (each public and private key pair corresponds to a public and private key pair identifier j, and each temporary public key will be associated with a temporary identity identifier).

[0050] In the task setting period of the target task, the mobile agent will replace the current corresponding public-private key pair and the temporary identity according to the update period required by the security specification. For example, if the upper limit of the completion time of the task is 1 day (i.e. the length of the task setting period is 1 day), and the security specification corresponding to the target task requires the agent to replace its public-private key pair every 1 minute (i.e. the update period is 1 minute), then m can be selected as 60x24 = 1440; if the security specification requires replacement every 30 seconds (i.e. the update period is 30 seconds), then m can be selected as 2880. In this step, A i may also generate the temporary public-private key pair by itself, but the preferred way is to uniformly manage the temporary public-private key pair by all parties, so as to effectively guarantee the randomness and uniqueness of the relevant parameters, and to avoid certain risks.

[0051] It should be noted that in the present embodiment, it is assumed that the security specification applied by the mobile agent is that the agent replaces its public-private key pair every certain period of time; in actual application, other security specifications can also be encountered, for example, the public-private key pair must be reselected after being used once, and in this security specification, different public-private key pair selection strategies can still be adapted according to the situation, for example, the public-private key pair can be selected from j = 1, and each time the value is increased by 1, and the specific selection strategy will not be described here.

[0052] After obtaining the first number m of public-private key pairs corresponding to each mobile agent, the multiple temporary identity identifiers B ij corresponding to the mobile agent can be determined according to the actual identity identifier i and the public-private key pair identifier j, and the specific steps are as follows.

[0053] In some embodiments of the present application, determining the multiple temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier comprises the following steps: determining the symmetric key corresponding to the target task; determining a plurality of specific mixing results according to the actual identity identifier and the public-private key pair identifier, wherein for each mobile agent, a series of specific mixing results are determined, and the number of the specific mixing results corresponding to each mobile agent is equal to the first number; and encrypting the first number of specific mixing results using the symmetric key to obtain the first number of temporary identity identifiers.

[0054] Specifically, a B ij corresponding to each pair (i, j) can be associated as the jth temporary identity identifier available for A i to perform the task. To this end, a plurality of specific mixing results can be determined according to the actual identity identifier and the public-private key pair identifier, for example, the specific mixing result i||j can be determined by splicing, and in the present embodiment, the specific mixing result i||j of i and j can be encrypted using the symmetric key k to obtain the temporary identity identifier B ij= E(k,i||j), where || represents bit string concatenation (aligned according to agreed byte boundaries), for example, concatenating 0xfa and 0xce can result in 0xface. Thus, all parties determine A for all 1≤i≤n and 1≤j≤m. i Temporary identity B ij .

[0055] It should be noted that the embodiments of this application do not specifically limit the method for determining a particular mixing result. ij = E(k,i||j) is just one of the simplest implementations, where 64 bits of storage space can be allocated to i and j respectively. Obviously, other implementations can also be used, such as B... ij = E(k,i||0x0000000000000000||j), where j and i each occupy 32 bits, and they are filled with 64 bits of 0.

[0056] Furthermore, all parties will generate a series of digital certificates for each mobile intelligent agent, as detailed in the following steps.

[0057] In some embodiments of this application, generating multiple digital certificates corresponding to a mobile intelligent agent based on a temporary identity identifier and a public-private key pair includes the following steps: determining the start and end times of the validity period of the digital certificate according to the task setting time period of the target task; generating digital certificates based on the temporary identity identifier, the temporary public key in the public-private key pair, and the start and end times of the validity period, wherein each mobile intelligent agent corresponds to a first number of digital certificates.

[0058] Specifically, it can be done for each A i Create a series of digital certificates C ij =(B ij ,pk ij ,b ij ,e ij ) M The subscript M represents the private key sk of the owner of the mobile intelligent agent device. M Sign the digital certificate. In this embodiment, the digital signature algorithm used by party M can be compatible with A. i public-private key pair (pk ij ,sk ij Whether the digital signature algorithms used are the same or different, this application does not limit this.

[0059] Each digital certificate C ij In addition to temporary identity identifier B ij PK with temporary public key ij It should also include at least the start and end dates of the digital certificate's validity period (start validity period b). ijTermination of validity period e ij These two times can coincide with the start and end times of the target task's defined time period. For example, if the agent will execute the task within one day on April 1, 2026, then the offline phase can be executed on the evening of March 31, 2026, and each b ij All are set to 00:00:00 on April 1, 2026, each e ij Set all times to 23:59:59 on April 1, 2026; or, depending on the actual task requirements, set each b... ij All are set to 6:30:00 AM on April 1, 2026. ij Set them all to 18:29:59 on April 1, 2026.

[0060] For simplicity, in this implementation, the start and end validity periods of all certificates can be set to be the same. In practical applications, the start and end validity periods of each certificate can also be set to different times.

[0061] Additionally, it should be noted that the digital certificate fields used in the embodiments of this application (such as public key pk) ij , Start and effective time b ij Termination of validity period e ij (etc.) are all common fields that conform to domestic and international digital signature certificate standards, while temporary identity B ij Depending on the specific circumstances, either the subject or related fields can be used, or the serial number field can be used. Therefore, the certificate standard adopted in this application embodiment is compatible with domestic and international digital signature certificate standards.

[0062] After obtaining a series of digital certificates signed with the private key of the mobile intelligent agent device owner, the owner can clear A. i The space previously used to store digital certificates and private keys (e.g., in Flash memory) will now be used to store a series of pre-made digital certificates (C). ij Together with each temporary private key sk ij and the public key pk of all parties M M Load each A i , for A i In subsequent use, the signed digital certificate, the temporary private key in the public-private key pair, and the public key of the mobile intelligent agent device owner can be stored in the mobile intelligent agent, so that the mobile intelligent agent can identify other mobile intelligent agents belonging to the same owner based on the information stored in it when performing the target task.

[0063] In this embodiment of the application, intelligent agent A iThe public and private keys are bound together by the algorithm, and the digital certificate binds the temporary public key to a temporary identity. Therefore, changing the public and private key pair periodically (e.g., every minute or 30 seconds) is equivalent to changing the temporary identity. It's important to note that changing the public and private key pair only requires changing the public and private key pair identifier j; it doesn't necessarily mean that the public and private keys themselves must be used. (Mobile agent A...) i While on a mission, it doesn't send messages continuously; it only sends them when A... i It only needs to use a temporary private key sk when sending a message, whether actively or passively. ij Sign business messages with proof of freshness and upload the corresponding digital certificate. ij =(B ij, pk ij ,b ij ,e ij ) M This is sent along with the signed business message. Therefore, agent A... i A selection needs to be made from at most m j to determine which temporary private key sk to use. ij Therefore, A i There are multiple strategies available for execution, for example, agent A i Each time, an element can be randomly selected from 1 ≤ j ≤ m. Therefore, each j may be used multiple times, or it may not be selected until the task ends; or, agent A... i Alternatively, you can start with j=1 and increment by 1 each time, so j will never repeat (it may only repeat in a very short time, such as 30 seconds).

[0064] The following describes the method flow of the online phase in the embodiments of this application. The online phase refers to the phase in which each mobile intelligent agent A... i During the phase where they leave all bases to carry out their target missions, mobile intelligent agent A may only be able to conduct radio communication within a limited transmission and reception radius. i The main process steps performed during the online phase are as follows.

[0065] During the execution of the target task, mobile intelligent agent A i It can send messages containing its temporary identity identifier, either actively or passively. Actively sending messages involves using a temporary private key (sk) stored within itself. ij Digitally sign business messages (such as traffic announcements) and use your corresponding digital certificate C. ijThe signed business message is sent to other mobile agents. It should be noted that, in order to prevent replay attacks, all business messages contain freshness evidence (such as a timestamp). For example, when an unmanned vehicle finds that the road is congested, it can actively send a business message about the current road conditions to inform nearby other agents to avoid as much as possible; when an unmanned aerial vehicle finds that another unmanned aerial vehicle is approaching, it can actively send a business message to inquire about the identity.

[0066] On the other hand, if A i needs to respond to the relevant identity inquiry message, it needs to passively send a response message about its identity information, which can use a certain temporary private key sk ij Sign the current timestamp and / or challenge information in the inquiry message, and send this sk ij corresponding digital certificate C ij along with the signed business message.

[0067] Upon receiving the business message and digital certificate sent by other mobile agents, the public key of all parties of the mobile agent device can be used to verify the digital certificate signed by all parties of the mobile agent device; if the digital certificate is verified and the current time is between the start and end times of the validity period of the digital certificate (i.e. the current time is later than b ij but earlier than e ij , the temporary public key contained in the digital certificate is used to verify the digitally signed business message; if the business message is verified, it is determined that the other mobile agent that sent the business message and the digital certificate belongs to the same party as the current mobile agent.

[0068] It should be noted that in real life, agent devices belonging to two organizations in competition with each other may have consistent physical characteristics, so the embodiments of the present application do not identify the party based on the physical characteristics of the device (such as appearance images, motion parameters, etc.), but based on a digital signature algorithm. In particular, the embodiments of the present application do not specify or limit the digital signature algorithm used by A i Any standard digital signature algorithm at home and abroad can be used to instantiate the present solution.

[0069] During the execution of the target task by the mobile agent, if the owner M finds that a certain B ij correctly signed business message is seriously misleading (this message may be relayed back to the base by multiple agents), it is no longer considered that a certain agent A i is a party member, and the mobile agent A i owned by the party identity attribute can be excluded by sending a certificate revocation list, and the specific steps are as follows.

[0070] In some embodiments of this application, during the task setting period of the target task, the method further includes the following steps: when an anomaly is detected in the signed message sent by a mobile intelligent agent identified as belonging to the same owner, obtain the temporary identity identifier currently corresponding to the mobile intelligent agent; decrypt the temporary identity identifier according to the symmetric key to obtain a specific mixing result, and determine the actual identity identifier corresponding to the mobile intelligent agent according to the specific mixing result; obtain all public-private key pair identifiers corresponding to the actual identity identifier, and determine all the first number of temporary identity identifiers of the mobile intelligent agent according to the actual identity identifier and all public-private key pair identifiers; add all the temporary identity identifiers of the mobile intelligent agent together with the current timestamp to the certificate revocation list, and sign the certificate revocation list using the private key of the mobile intelligent agent device owner, and broadcast the signed certificate revocation list to other mobile intelligent agents, wherein the certificate revocation list is used to indicate that all temporary identity identifiers included in the certificate revocation list have been cancelled.

[0071] Specifically, when a certain B is discovered ij The correctly signed business message is seriously misleading and is no longer considered as a specific agent A. i When the user is a member of the user's own team, the target of the mobile intelligent agent A is... i The revocation, except for this specific B ij In addition, it should also include the mobile intelligent agent A. i For all j, because A i It is no longer trusted. Therefore, all parties need to perform the decryption operation of the symmetric encryption algorithm E, that is, to decrypt the temporary identity using the symmetric key k to recover i||j = E. -1 (k,Bij), from the temporary identity B ij Obtain the specific actual identity identifier i.

[0072] If the actual identity identifier i has not yet been revoked, then all parties calculate the agent A. i All the first quantity m temporary identity tokens B ij = E(k,i||j), 1≤j≤m, add all temporary identity identifiers of the mobile agent to the certificate revocation list, along with necessary timestamps and other information, using the private key sk of the mobile agent device owner. M After signing, it is broadcast as a business message. In this embodiment, the owner M issues a certificate revocation list containing m temporary identity identifiers for each agent removed. This certificate revocation list is relayed by each agent and can be transmitted to other agents.

[0073] The mobile agent verifies the certificate revocation list after receiving the certificate revocation list, and the specific steps are as follows.

[0074] In some embodiments of the present application, the method further comprises the following steps: obtaining a timestamp carried by the signed certificate revocation list in the case of receiving the signed certificate revocation list, wherein the signed certificate revocation list is obtained by signing the certificate revocation list with the private key of the mobile agent device owner, and the certificate revocation list is used to indicate that all the temporary identity labels contained in the certificate revocation list are cancelled; in the case that the error between the timestamp and the local timestamp of the mobile agent is within the preset time range, verifying the signed certificate revocation list by using the public key of the mobile agent device owner; in the case that the certificate revocation list is verified, storing the temporary identity labels contained in the certificate revocation list to the local mobile agent, and the mobile agent subsequently discards the signed message when receiving the signed message sent by the mobile agent corresponding to the temporary identity label contained in the certificate revocation list.

[0075] Specifically, when receiving the signed certificate revocation list, the mobile agent verifies the timestamp carried by the certificate revocation list, and if the error between the timestamp and the local timestamp of the mobile agent is within the preset time range, the public key pk M of the mobile agent device owner is used to verify the signed certificate revocation list. ij After the certificate revocation list is verified, all the temporary identity labels B ij contained in the certificate revocation list are saved to the local, for example, can be saved to the random access memory RAM of the mobile agent.

[0076] When a mobile agent A receives a message sent by another mobile agent B, at least the following checks need to be performed: the digital certificate of B attached in the message is within the valid period (the current time is later than b ij and earlier than e ij ), the temporary identity label B ij in the digital certificate is not revoked, and the digital certificate can be verified by the public key pk M of the owner.

[0077] After all the above checks are passed, A can use the pk ij in the digital certificate of B that has passed the check to verify the business message itself, and check the freshness evidence in the business message. If it is passed, it indicates that the message comes from a certain own agent (although the real identity cannot be determined), that is, the mobile agent B indeed belongs to the own party. And since the public key pk ij of B has been verified, A can also use the public key to temporarily establish a secure channel with B using a standard data encryption mechanism (such as a hybrid encryption mechanism such as ECIES).

[0078] Similarly, as long as all parties' public keys are PK'd M Deploying other facilities managed by all parties (e.g., temporary supply points, emergency rescue vehicles, etc.) enables these facilities to support various mobile intelligent agents A. i To protect A i This involves conducting self-identification in a privacy-preserving manner. For example, the owner of a self-driving car could deploy several automated charging stations in a city and implement public-key authentication on the access control system. M When the driverless car needs to stop at a charging station, it only needs to use a temporary private key sk. ij Digitally sign the "request to open" business message with proof of freshness, and include it in the digital certificate C. ij Send to the access control system for verification. Access control verification A i The method is similar to the other intelligent agent verification methods mentioned above. i The method is the same, so I will not repeat it here.

[0079] This application can be applied to mobile intelligent agent scenarios such as unmanned vehicle delivery and drone reconnaissance, primarily for identifying friendly members among mobile intelligent agents, especially when at least one competing organization exists. In this case, the intelligent agent must demonstrate its affiliation to the other party in a privacy-preserving manner. This application does not limit the mobile intelligent agents owned by competing organizations; for example, two competing organizations may possess intelligent agents of the same product model, which may have the same physical characteristics. Furthermore, this application can also be used by mobile intelligent agents to prove their identity to relevant facilities (such as temporary supply points, emergency rescue vehicles, etc.) in a privacy-preserving manner. This means that even if competitors conduct fixed-point surveillance at such facilities, they will not obtain valuable information.

[0080] To enable those skilled in the art to better understand the embodiments of this application, the identity management method in the embodiments of this application is illustrated below with examples.

[0081] Logistics companies A and B use autonomous vehicles for goods delivery in the same city. To improve the safety of autonomous driving and avoid startling pedestrians, all autonomous vehicles only operate during the day and return to their respective warehouses before evening. Taking company A as an example, company A confirms each night that the hardware and software of n autonomous vehicles are in good working order, and assigns a fee of A to each vehicle. i Generate m temporary public-private key pairs (pk ij ,sk ij ), 1≤i≤n, 1≤j≤m. Let A be the association between each pair (i,j) and B. ij = E(k,i||j) as A i The j-th temporary identity to be used on the next day, where E can be the SM2 encryption algorithm, k is a 128-bit secure random number updated every evening, and i and j each occupy 64 bits. This yields B. ij Afterwards, Party A paid each vehicle Ai m digital certificates C are made and loaded ij The validity period of each certificate is set to 6am to 8pm of the next day. The security specification requires each vehicle to change its temporary public key (temporary identity) every minute, so m can be chosen as 60x14=840.

[0082] During the daytime of the next day, when each unmanned vehicle is performing its delivery task, all the business messages sent contain a time stamp accurate to the second, are accompanied by the sender's digital signature and a digital certificate that can verify the signature. Each vehicle uses a "random" identity strategy. If A finds that a vehicle sends a business message abnormally with identity B ij , A can first obtain i from E -1 (k, B ij ), and then issue a certificate revocation list for all B ij = E(k, i||j) 1≤j≤m.

[0083] In the scheme of the present application, after the agent device owner confirms the safety of the agent software and hardware at zero distance, a large number of digital certificates (and corresponding private keys) complying with technical standards can be loaded for each mobile agent in a physical contact manner. The degree of privacy protection corresponds to the number of certificates loaded for each agent. The higher the privacy protection requirement, the greater the number of certificates. And this series of digital certificates are not bound to the real identity of the agent, but are associated with irregular temporary identities. These temporary identities can be used by the agent to prove that it is a member of the same party, and can be used by the manager to construct a certificate revocation list when necessary. In the scheme of the present application, the agent owner uses encryption technology to generate a series of temporary identities for each agent, which enables the owner to efficiently generate a certificate revocation list for a given temporary identity (in the form of decryption first and then encryption), and revoke all temporary identities of the agent at one time. Compared with related technologies, the scheme of the present application has at least the following beneficial technical effects:

[0084] 1) The mobile agent can show that it "belongs to the same party" to its own companions, so as to be accurately identified as a member of the same party, and this identification does not depend on any physical characteristics of the device (such as appearance image, motion parameters, etc.).

[0085] 2) The agent always uses a temporary identity when showing the identity attribution, without revealing any actual valid identity, thereby avoiding being associated and tracked by the opponent.

[0086] 3) The scheme does not depend on specific cryptographic algorithms (such as group signature or ring signature), but is implemented based on general digital signature algorithms and general digital signature certificate standards, avoiding possible legal and regulatory obstacles in practicality.

[0087] 4) The agent manager can efficiently generate a certificate revocation list by decryption and encryption calculation, and revoke the identity attributes of agents found to have problems in a timely manner to avoid the group being misled; even if the discovery or revocation is not timely, the short-term certificate of the agent will expire quickly, and its negative impact is controllable.

[0088] This application also provides another identity management method. Figure 2 This is a schematic diagram of another identity management method flow provided according to an embodiment of this application, such as... Figure 2 As shown, this method is applied to mobile intelligent agents and includes the following steps:

[0089] Step S202: During the task-defined time period of the target task, the business message is digitally signed based on the temporary private key stored by the mobile intelligent agent itself. The mobile intelligent agent is used to execute the target task during the task-defined time period. The temporary private key is the private key part of multiple public-private key pairs corresponding to the mobile intelligent agent. Each public-private key pair corresponds to a public-private key pair identifier. Each public-private key pair identifier corresponds to a temporary identity identifier. The temporary identity identifier is determined based on the actual identity identifier of the mobile intelligent agent and the public-private key pair identifier. The temporary identity identifier is used to temporarily identify the identity of the mobile intelligent agent during the communication process.

[0090] Step S204: The digitally signed business message and the digital certificate signed by the owner of the mobile intelligent agent device corresponding to the temporary identity identifier corresponding to the temporary private key are sent to other mobile intelligent agents. The digital certificate includes: temporary identity identifier, temporary public key corresponding to the temporary private key in the public-private key pair. Other mobile intelligent agents that receive the business message and digital certificate can identify whether the mobile intelligent agent that sent the business message and digital certificate belongs to the same owner based on their own stored information, as well as the business message and digital certificate.

[0091] Optionally, the digital certificate signed by the owner of the mobile intelligent agent device is obtained by signing with the private key of the owner of the mobile intelligent agent device. The digital certificate also contains the start and end times of the validity period of the digital certificate, and the information stored in the mobile intelligent agent itself contains the public key of the owner of the mobile intelligent agent device. The method further includes: when receiving a business message and a digital certificate sent by another mobile intelligent agent, using the public key of the owner of the mobile intelligent agent device to verify the digital certificate signed by the owner of the mobile intelligent agent device; if the digital certificate verification is successful and the current time is between the start and end times of the validity period of the digital certificate, using the temporary public key contained in the digital certificate to verify the digitally signed business message; if the business message verification is successful, determining that the other mobile intelligent agent that sent the business message and the digital certificate belongs to the same owner as the current mobile intelligent agent.

[0092] Optionally, the method further comprises: obtaining a timestamp carried by the signed certificate revocation list, wherein the signed certificate revocation list is obtained by signing the certificate revocation list with the private key of the mobile agent device owner, and the certificate revocation list is used to indicate that the temporary identity identifiers contained in the certificate revocation list are all cancelled; verifying the signed certificate revocation list by using the public key of the mobile agent device owner, when an error between the timestamp and a local timestamp of the mobile agent is within a preset time range; and storing the temporary identity identifiers contained in the certificate revocation list to the mobile agent locally, and the mobile agent subsequently discards a signed message sent by a mobile agent corresponding to the temporary identity identifiers contained in the certificate revocation list when receiving the signed message.

[0093] It should be noted that the identity management method provided in this embodiment is a method embodiment of the mobile agent side corresponding to the identity management method shown in Figure 1 Therefore, the related explanations and descriptions of the above identity management method are also applicable to this embodiment, and will not be repeated here.

[0094] This embodiment of the present application further provides an identity management system, Figure 3 is a schematic diagram of an identity system according to an embodiment of the present application, as shown in Figure 3 The system comprises:

[0095] The agent management device 30 of the owner is used to generate a plurality of public-private key pairs for each mobile agent before performing a target task, wherein each mobile agent corresponds to an actual identity identifier, and each public-private key pair corresponds to a public-private key pair identifier; determine a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, wherein each public-private key pair identifier corresponds to a temporary identity identifier; generate a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, wherein each public-private key pair identifier corresponds to a digital certificate, and the digital certificate comprises: the temporary identity identifier corresponding to the public-private key pair identifier, and the temporary public key in the public-private key pair; sign the digital certificate by using the private key of the mobile agent device owner, and store the signed digital certificate, the temporary private key in the public-private key pair, and the public key of the mobile agent device owner in the mobile agent;

[0096] a plurality of mobile agents 32, configured to perform a target task in a task setting period of the target task, and in the task setting period of the target task, to digitally sign a service message according to a temporary private key stored by the mobile agent itself; and to send the signed service message and a digital certificate corresponding to a temporary identity identifier corresponding to the temporary private key to other mobile agents, wherein the other mobile agents receiving the service message and the digital certificate can identify whether the mobile agent sending the service message and the digital certificate is a mobile agent belonging to the same owner according to information stored by the mobile agent itself and the service message and the digital certificate.

[0097] In some embodiments of the present application, the agent management device 30 is configured to generate a plurality of temporary public-private key pairs for each mobile agent, including: determining security specification requirement information corresponding to a target task planned to be performed by the mobile agent, and determining a task setting period of the target task, wherein the security specification requirement information at least indicates an update period for changing a public-private key pair applied by the mobile agent when communicating; determining a first number of public-private key pairs planned to be generated for the mobile agent according to a length of the task setting period and the update period, and generating the first number of public-private key pairs for each mobile agent.

[0098] In some embodiments of the present application, in the task setting period of the target task, the mobile agent will change the current corresponding public-private key pair and the temporary identity identifier according to the update period corresponding to the security specification requirement information.

[0099] In some embodiments of the present application, the agent management device 30 is configured to determine a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, including: determining a symmetric key corresponding to the target task; determining a plurality of specific mixing results according to the actual identity identifier and the public-private key pair identifier, wherein for each mobile agent, a series of specific mixing results are determined, and the number of specific mixing results corresponding to each mobile agent is equal to the first number; and encrypting the first number of specific mixing results using the symmetric key to obtain the first number of temporary identity identifiers.

[0100] In some embodiments of the present application, the agent management device 30 is configured to generate a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, including: determining a valid period start and end time corresponding to the digital certificate according to the task setting period of the target task; and generating the digital certificate according to the temporary identity identifier, the temporary public key in the public-private key pair, and the valid period start and end time, wherein each mobile agent corresponds to the first number of digital certificates.

[0101] In some embodiments of the present application, during the task setting period of the target task, the intelligent agent management device 30 is further configured to: in the case where it is detected that there is an anomaly in the signature messages sent by the mobile agents identified as belonging to the same owner, obtain the temporary identity currently corresponding to the mobile agent; decrypt the temporary identity according to the symmetric key to obtain a specific mixing result, and determine the actual identity identifier corresponding to the mobile agent according to the specific mixing result; obtain all public-private key pair identifiers corresponding to the actual identity identifier, and determine all first number of temporary identities of the mobile agent according to the actual identity identifier and all public-private key pair identifiers; add all temporary identities of the mobile agent to the certificate revocation list together with the current timestamp, and sign the certificate revocation list using the private key of the mobile agent device owner, and broadcast the signed certificate revocation list to other mobile agents, wherein the certificate revocation list is used to indicate that the temporary identities contained in the certificate revocation list are all cancelled.

[0102] In some embodiments of the present application, the digital certificate signed by the mobile agent device owner is obtained by signing the digital certificate using the private key of the mobile agent device owner, and the digital certificate further contains the start and end time of the validity period of the digital certificate, and the information stored by the mobile agent itself contains the public key of the mobile agent device owner; the mobile agent 32 is further configured to: in the case where it receives the service message and the digital certificate sent by other mobile agents, verify the digital certificate signed by the mobile agent device owner using the public key of the mobile agent device owner; in the case where the digital certificate is verified and the current time is between the start and end time of the validity period of the digital certificate, verify the service message signed by the digital signature using the temporary public key contained in the digital certificate; in the case where the service message is verified, determine that the other mobile agent sending the service message and the digital certificate belongs to the same owner as the current mobile agent.

[0103] In some embodiments of the present application, the mobile agent 32 is further configured to: in the case where it receives the signed certificate revocation list, obtain the timestamp carried by the certificate revocation list, wherein the signed certificate revocation list is obtained by signing the certificate revocation list using the private key of the mobile agent device owner, and the certificate revocation list is used to indicate that the temporary identities contained in the certificate revocation list are all cancelled; in the case where the error between the timestamp and the local timestamp of the mobile agent is within the preset time range, verify the signed certificate revocation list using the public key of the mobile agent device owner; in the case where the certificate revocation list is verified, store the temporary identities contained in the certificate revocation list to the mobile agent locally, and the mobile agent subsequently discards the signature message sent by the mobile agent corresponding to the temporary identity contained in the certificate revocation list when receiving the signature message.

[0104] It should be noted that the identity management system provided in this embodiment is a system embodiment corresponding to the identity management method shown in Figure 1 and Figure 2 Therefore, the related explanations of the above identity management method are also applicable to this embodiment, and will not be repeated here.

[0105] The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the following identity management method by running the computer program: generating a plurality of temporary public-private key pairs for each mobile agent before the mobile agent executes a target task, wherein each mobile agent corresponds to an actual identity identifier, and each public-private key pair of the mobile agent corresponds to a public-private key pair identifier; determining a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, wherein each public-private key pair identifier corresponds to a temporary identity identifier; generating a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, wherein each public-private key pair identifier corresponds to a digital certificate, and the digital certificate includes the temporary identity identifier corresponding to the public-private key pair identifier and the temporary public key in the public-private key pair; signing the digital certificate with the private key of the mobile agent device owner, and storing the signed digital certificate, the temporary private key in the public-private key pair, and the public key of the mobile agent device owner into the mobile agent, so that the mobile agent can identify other mobile agents belonging to the same owner according to the information stored by itself during the execution of the target task.

[0106] Alternatively, during the task setting period of the target task, digitally signing the business message according to the temporary private key stored by the mobile agent, wherein the mobile agent is used to execute the target task during the task setting period, the temporary private key is the private key part in the plurality of public-private key pairs corresponding to the mobile agent, each public-private key pair corresponds to a public-private key pair identifier, each public-private key pair identifier corresponds to a temporary identity identifier, the temporary identity identifier is determined according to the actual identity identifier of the mobile agent and the public-private key pair identifier, and the temporary identity identifier is used to temporarily identify the identity of the mobile agent during communication; sending the digitally signed business message and the digital certificate corresponding to the temporary identity identifier corresponding to the temporary private key, which is signed by the mobile agent device owner, to other mobile agents, wherein the digital certificate includes the temporary identity identifier and the temporary public key in the public-private key pair corresponding to the temporary private key, and other mobile agents receiving the business message and the digital certificate can identify whether the mobile agent sending the business message and the digital certificate is a mobile agent belonging to the same owner according to the information stored by itself and the business message and the digital certificate.

[0107] The embodiment of the present application further provides a computer program product comprising a computer program, which, when executed by a processor, implements the steps of the identity management method described in various embodiments of the present application: generating a plurality of temporary public-private key pairs for each mobile agent before the mobile agent performs a target task, wherein each mobile agent corresponds to an actual identity identifier, and each public-private key pair of the mobile agent corresponds to a public-private key pair identifier; determining a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, wherein each public-private key pair identifier corresponds to a temporary identity identifier; generating a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, wherein each public-private key pair identifier corresponds to a digital certificate, and the digital certificate comprises the temporary identity identifier corresponding to the public-private key pair identifier and a temporary public key in the public-private key pair; signing the digital certificate by using a private key of the mobile agent device owner, and storing the signed digital certificate, a temporary private key in the public-private key pair, and a public key of the mobile agent device owner into the mobile agent, so that the mobile agent can identify other mobile agents belonging to the same owner according to the information stored by itself during the execution of the target task.

[0108] Alternatively, during a task setting period of the target task, digitally signing a service message according to the temporary private key stored by the mobile agent, wherein the mobile agent is used to perform the target task during the task setting period, the temporary private key is a private key part in a plurality of public-private key pairs corresponding to the mobile agent, each public-private key pair corresponds to a public-private key pair identifier, each public-private key pair identifier corresponds to a temporary identity identifier, the temporary identity identifier is determined according to the actual identity identifier of the mobile agent and the public-private key pair identifier, and the temporary identity identifier is used to temporarily identify the identity of the mobile agent during communication; and sending the digitally signed service message and the digital certificate corresponding to the temporary identity identifier corresponding to the temporary private key and signed by the mobile agent device owner to other mobile agents, wherein the digital certificate comprises the temporary identity identifier and a temporary public key in the public-private key pair corresponding to the temporary private key, and other mobile agents receiving the service message and the digital certificate can identify whether the mobile agent sending the service message and the digital certificate is a mobile agent belonging to the same owner according to the information stored by itself and the service message and the digital certificate.

[0109] The above serial numbers of the embodiments of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments.

[0110] In the above embodiments of the present application, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0111] In several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented by other ways. Among them, the above-described device embodiments are only schematic, for example, the division of the units can be a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, units or modules, and can be electrical or other forms.

[0112] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e. can be located in one place or can be distributed to multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0113] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0114] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and various program codes that can be stored in the medium.

[0115] The above is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, and these improvements and refinements should be considered as the protection scope of the present application.

Claims

1. An identity management method characterized by, The method comprises: generating a plurality of temporary public-private key pairs for each of the mobile agents before the mobile agents perform a target task, wherein each of the mobile agents corresponds to an actual identity identifier, and each of the public-private key pairs of the mobile agents corresponds to a public-private key pair identifier; determining a plurality of temporary identity identifiers corresponding to the mobile agents according to the actual identity identifiers and the public-private key pair identifiers, wherein each of the public-private key pair identifiers corresponds to one of the temporary identity identifiers; generating a plurality of digital certificates corresponding to the mobile agents according to the temporary identity identifiers and the public-private key pairs, wherein each of the public-private key pair identifiers corresponds to one of the digital certificates, and each of the digital certificates comprises the temporary identity identifier corresponding to the public-private key pair identifier and a temporary public key in the public-private key pair; signing the digital certificates by using a private key of a mobile agent device owner, and storing the signed digital certificates, the temporary private key in the public-private key pair, and a public key of the mobile agent device owner into the mobile agents, so that the mobile agents can identify other mobile agents belonging to the same owner according to the information stored in the mobile agents during the performance of the target task.

2. The identity management method of claim 1, wherein, The method of generating a plurality of temporary public-private key pairs for each of the mobile agents comprises: determining security specification requirement information corresponding to the target task planned to be performed by the mobile agents, and determining a task setting period of the target task, wherein the security specification requirement information at least indicates an update period for the mobile agents to replace the applied public-private key pairs when communicating; determining a first number of public-private key pairs planned to be generated for the mobile agents according to the length of the task setting period and the update period, and generating the first number of public-private key pairs for each of the mobile agents.

3. The identity management method of claim 2, wherein, During the task setting period of the target task, the mobile agents will replace the current corresponding public-private key pairs and temporary identity identifiers according to the update period corresponding to the security specification requirement information.

4. The identity management method of claim 1, wherein, The method of determining a plurality of temporary identity identifiers corresponding to the mobile agents according to the actual identity identifiers and the public-private key pair identifiers comprises: determining a symmetric key corresponding to the target task; determining a plurality of specific mixing results according to the actual identity identifiers and the public-private key pair identifiers, wherein for each mobile agent, a series of the specific mixing results are determined, and the number of the specific mixing results corresponding to each of the mobile agents is equal to a first number; encrypting the first number of the specific mixing results by using the symmetric key to obtain the first number of the temporary identity identifiers.

5. The identity management method of claim 1, wherein, The method of generating a plurality of digital certificates corresponding to the mobile agents according to the temporary identity identifiers and the public-private key pairs comprises: determining start and end time instants of a validity period corresponding to the digital certificates according to a task setting period of the target task; According to the temporary identity, the temporary public key in the public-private key pair, and the validity period start and end time, the digital certificate is generated, wherein each mobile agent corresponds to a first number of the digital certificate.

6. The identity management method of claim 4, wherein, In the task setting period of the target task, the method further comprises: In the case where it is detected that the signed messages sent by the mobile agents identified as belonging to the same owner are abnormal, the temporary identity currently corresponding to the mobile agent is obtained; According to the symmetric key, the temporary identity is decrypted to obtain the specific mixing result, and according to the specific mixing result, the actual identity identifier corresponding to the mobile agent is determined; All public-private key pair identifiers corresponding to the actual identity identifier are obtained, and the actual identity identifier and all public-private key pair identifiers are used to determine the first number of temporary identities of the mobile agent; The temporary identities of the mobile agent are added to the certificate revocation list together with the current timestamp, and the private key of the mobile agent device owner is used to sign the certificate revocation list, and the signed certificate revocation list is broadcast to other mobile agents, wherein the certificate revocation list is used to indicate that the temporary identities contained in the certificate revocation list are cancelled.

7. An identity management method characterized by, Comprise: In the task setting period of the target task, the business message is digitally signed according to the temporary private key stored by the mobile agent itself, wherein the mobile agent is used to execute the target task in the task setting period, the temporary private key is the private key part of the multiple public-private key pairs corresponding to the mobile agent, each public-private key pair corresponds to a public-private key pair identifier, each public-private key pair identifier corresponds to a temporary identity, and the temporary identity is determined according to the actual identity identifier of the mobile agent and the public-private key pair identifier. The temporary identity is used to temporarily identify the identity of the mobile agent in the communication process; The digitally signed business message and the digital certificate signed by the mobile agent device owner corresponding to the temporary identity of the temporary private key are sent to other mobile agents, wherein the digital certificate includes the temporary identity, the temporary public key in the public-private key pair corresponding to the temporary private key, and other mobile agents receiving the business message and the digital certificate can identify whether the mobile agent sending the business message and the digital certificate is a mobile agent belonging to the same owner according to the information stored by itself and the business message and the digital certificate.

8. The identity management method of claim 7, wherein, The digital certificate signed by the mobile agent device owner is obtained by signing the private key of the mobile agent device owner, and the digital certificate further contains the validity period start and end time of the digital certificate, and the information stored by the mobile agent itself contains the public key of the mobile agent device owner; The method further comprises: In the case of receiving the service message and the digital certificate sent by the other mobile agent, the public key of the mobile agent device owner is used to verify the digital certificate signed by all parties of the mobile agent device; In the case that the digital certificate is verified and the current time is between the start and end time of the validity period of the digital certificate, the temporary public key contained in the digital certificate is used to verify the service message signed by the digital signature; In the case that the service message is verified, it is determined that the other mobile agent sending the service message and the digital certificate belongs to the same owner as the current mobile agent.

9. The identity management method of claim 8, wherein, The method further comprises: In the case of receiving a signed certificate revocation list, the timestamp carried by the certificate revocation list is obtained, wherein the signed certificate revocation list is signed by the private key of the mobile agent device owner, and the certificate revocation list is used to indicate that the temporary identity contained in the certificate revocation list is cancelled; In the case that the error between the timestamp and the local timestamp of the mobile agent is within the preset time range, the public key of the mobile agent device owner is used to verify the signed certificate revocation list; In the case that the certificate revocation list is verified, the temporary identity contained in the certificate revocation list is stored in the mobile agent, and the mobile agent subsequently discards the signed message sent by the mobile agent corresponding to the temporary identity contained in the certificate revocation list when receiving the signed message.

10. An identity management system, characterized by Comprise: The owner's agent management device and a plurality of mobile agents, wherein The agent management device is configured to generate a plurality of public-private key pairs for each mobile agent before executing a target task, wherein each mobile agent corresponds to an actual identity identifier, and each public-private key pair corresponds to a public-private key pair identifier; determine a plurality of temporary identity identifiers corresponding to the mobile agent according to the actual identity identifier and the public-private key pair identifier, wherein each public-private key pair identifier corresponds to a temporary identity identifier; generate a plurality of digital certificates corresponding to the mobile agent according to the temporary identity identifier and the public-private key pair, wherein each public-private key pair identifier corresponds to a digital certificate, and the digital certificate includes the temporary identity identifier corresponding to the public-private key pair identifier and the temporary public key in the public-private key pair; sign the digital certificate with the private key of the mobile agent device owner, and store the signed digital certificate, the temporary private key in the public-private key pair, and the public key of the mobile agent device owner in the mobile agent. The mobile agent is configured to perform the target task in a task setting period of the target task, and in the task setting period of the target task, digitally sign a service message according to the temporary private key stored by the mobile agent itself; and send the signed service message, and a digital certificate corresponding to the temporary identity identifier corresponding to the temporary private key to other mobile agents, wherein the other mobile agents receiving the service message and the digital certificate can identify whether the mobile agent sending the service message and the digital certificate is a mobile agent belonging to the same owner according to information stored by the mobile agents themselves and the service message and the digital certificate.

Citation Information

Patent Citations

  • Digital certificate distribution method, attribute certificate management terminal and certificate application terminal

    CN118842634A

  • Virtual resource processing method and device, computer equipment and storage medium

    CN120258794A