Digital identity encryption authentication method
By generating a master key store and constructing a multi-level authentication chain, implementing two-way verification and anomaly handling, the flexibility and adaptability issues of traditional digital identity authentication methods in complex network environments are solved, achieving efficient and reliable multi-dimensional identity authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- YIQIBANG (ANHUI) DIGITAL TECHNOLOGY CO LTD
- Filing Date
- 2025-08-23
- Publication Date
- 2026-04-17
AI Technical Summary
Traditional digital identity authentication methods lack flexibility and adaptability when facing dynamic attacks in complex network environments. They cannot effectively integrate multi-dimensional identity information and have insufficient anomaly handling mechanisms, resulting in poor stability and reliability of the authentication system.
By collecting biometric data, dynamic token data, and identity credential data, a master key library is generated, and multi-dimensional encryption preprocessing is performed. Fragmented verification features are extracted, a multi-level authentication chain is constructed, two-way verification and anomaly handling are implemented, and authentication rules are dynamically adjusted to improve security and adaptability.
It achieves secure isolation and efficient storage of multi-source identity information, improves the scientific nature and flexibility of authentication strategies, ensures the accuracy of the authentication process and the stability of the system, can quickly locate and repair authentication anomalies, and adapts to the collaborative authentication needs of multiple devices and multiple users in complex network environments.
Smart Images

Figure CN120915561B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of digital identity authentication technology, specifically to a digital identity encryption authentication method. Background Technology
[0002] In the digital age, digital identity authentication, as a core component of information security, faces increasingly complex security challenges. Traditional digital identity authentication methods often employ single-dimensional encryption verification approaches, such as relying solely on static passwords or simple biometric identification. These methods are insufficient in protecting against security threats such as data breaches and identity forgery. With the diversification and increasing sophistication of cyberattacks, single authentication models are struggling to meet the stringent requirements for user identity authenticity and data integrity in high-security scenarios.
[0003] While some existing authentication schemes introduce the concept of multi-factor authentication, they suffer from significant shortcomings in key management, authentication path construction, and anomaly handling mechanisms. For example, key storage methods lack dynamic adaptability, failing to adjust encryption strategies based on real-time security threats; fixed authentication paths struggle to cope with dynamic attacks in complex network environments; and the handling of abnormal authentication nodes lacks systematicity, easily leading to authentication link interruptions or security vulnerabilities. Furthermore, traditional methods, when processing multi-dimensional identity information, suffer from insufficient data obfuscation and standardization, potentially causing redundant encrypted fields and low verification efficiency, failing to achieve efficient integration and secure storage of biometric data, dynamic token data, and identity credential data.
[0004] Regarding the dynamic adjustment of authentication rules, existing technologies lack a scientific prioritization of verification features and cannot update authentication strategies in real time based on dynamic changes in features. This results in high-risk features having lower authentication priority than static features, increasing security risks in the authentication process. Furthermore, the path reconstruction mechanism for abnormal nodes lacks historical tracing and dynamic correction capabilities, making it difficult to quickly locate the root cause of authentication deviations and implement effective repairs, thus affecting the stability and reliability of the authentication system.
[0005] With the widespread application of technologies such as cloud computing and the Internet of Things, digital identity authentication scenarios are becoming increasingly diversified, placing higher demands on the flexibility, scalability, and security of authentication systems. Traditional authentication methods, due to their rigid architecture and insufficient dynamic response capabilities, are no longer able to adapt to the collaborative authentication needs of multiple devices and users in complex network environments. Therefore, there is an urgent need for a digital identity encryption authentication method that can achieve multi-dimensional encrypted preprocessing, dynamic authentication rule adjustment, multi-level authentication chain construction, and intelligent anomaly handling, in order to improve the security, reliability, and adaptability of authentication systems and meet the high standards of digital identity authentication required by next-generation information technology. Summary of the Invention
[0006] The purpose of this invention is to provide a digital identity encryption and authentication method to solve the problems mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a digital identity encryption authentication method, the method comprising:
[0008] Obtain the feature dataset of user identity information, perform multi-dimensional encryption preprocessing, and generate a master key library;
[0009] Extract the fragment verification features of each master key store, and determine the authentication rules for different key stores based on the fragment verification features;
[0010] The authentication paths for each master key repository are constructed according to the authentication rules, forming a multi-level authentication chain, and a verification node for each authentication chain.
[0011] Each of the verification nodes is bidirectionally verified to obtain the authentication status of each node, wherein the authentication status includes a valid authentication status and an invalid authentication status;
[0012] In the valid authentication state, the master key library under each of the verification nodes performs association authentication according to the permission level;
[0013] In the invalid authentication state, abnormal verification nodes are identified, and the authentication offset of the master key library under the abnormal verification node is calculated.
[0014] Based on the authentication offset, the abnormal verification node is reconstructed until all master key libraries complete authentication according to the permission level, and then the process terminates.
[0015] Preferably, the step of obtaining the feature dataset of user identity information and performing multi-dimensional encryption preprocessing to generate a master key store includes:
[0016] Biometric data, dynamic token data, and identity credential data are collected, encrypted into independent key units, and a unique encryption identifier is assigned to each key unit.
[0017] The data within each of the independent key units is obfuscated to remove duplicate or redundant encryption fields;
[0018] The obfuscated independent key units are standardized in format to unify the encryption structure of the key units, and the unified independent key units are output as the master key library.
[0019] Preferably, the extraction of fragment verification features from each of the master key bases includes:
[0020] Obtain the key fragments under each of the master key stores and sort them according to the verification strength;
[0021] Extract the logical correlation between adjacent key fragments and label it as a hierarchical determination parameter;
[0022] Obtain a preset grading threshold, and divide each judgment parameter into intervals based on the grading threshold to generate multiple verification intervals;
[0023] The number of judgment parameters in each of the verification intervals is counted and recorded as feature weight parameters, and the sharding verification features of each master key library are determined based on the feature weight parameters.
[0024] The fragmented verification features include static features and dynamic features, and the authentication priority of the dynamic features is higher than that of the static features.
[0025] Preferably, determining the sharding verification features of each master keystore based on the feature weight parameters includes:
[0026] Obtain the feature weight parameters for each of the aforementioned master key libraries;
[0027] The feature weight parameters under the same master key library are sorted from low to high according to their values, and the deviation weight of the feature weight parameter with the lowest value is calculated.
[0028] Obtain the deviation threshold and compare the deviation threshold with the deviation weight of the feature weight parameter with the lowest value;
[0029] If the deviation weight is greater than the deviation threshold, then the master key library corresponding to the feature weight parameter is determined to have dynamic characteristics;
[0030] If the deviation weight is less than or equal to the deviation threshold, then the master key library corresponding to the feature weight parameter is determined to have static characteristics.
[0031] Preferably, determining the authentication rules for different key bases based on the fragmentation verification features includes:
[0032] Obtain the fragmentation verification features of each of the master key libraries;
[0033] The minimum value of the verification interval corresponding to the dynamic feature is used as the permission determination threshold;
[0034] Summarize the permission determination thresholds of the master keystore under all the dynamic features, and arrange them in descending order of the thresholds to generate an authentication priority sequence;
[0035] The permissions of each master key library are determined according to the authentication priority sequence, and after the master key library determination under the dynamic feature is completed, the master key library under the static feature is added for determination.
[0036] The generation of the authentication priority sequence includes:
[0037] Obtain historical change records of the master key store's permission determination threshold under the aforementioned dynamic characteristics;
[0038] Extract the actual number of times the permission judgment threshold takes effect in the historical authentication path, and calculate the error ratio between the threshold and the preset number;
[0039] A dynamic correction factor is generated based on the error ratio, and the current permission determination threshold is adjusted according to the correction factor.
[0040] The weighted permission determination thresholds are aggregated, the authentication priority sequence is rearranged, and the adjusted sequence is synchronized to the path construction of subsequent verification nodes.
[0041] Preferably, the bidirectional verification of each of the verification nodes includes:
[0042] Obtain the authentication results of the master key library under each verification node, perform hash verification and conversion, and generate multiple verification parameters;
[0043] Invoke the preset verification algorithm, input the verification parameters into the verification algorithm, and record the output value as the authentication parameter;
[0044] Obtain the authentication threshold and compare the authentication parameters with the authentication threshold;
[0045] If the authentication parameter is less than the authentication threshold, the verification node is determined to be in a valid authentication state.
[0046] If the authentication parameter is greater than or equal to the authentication threshold, the verification node is determined to be in an invalid authentication state.
[0047] Preferably, calculating the authentication offset of the master keystore under the abnormal verification node includes:
[0048] Obtain the actual verification node of the master keystore that has not completed associated authentication under the abnormal verification node;
[0049] Calculate the logical difference between the actual verification node and the abnormal verification node, and label it as the real-time offset;
[0050] The abnormal verification node is traced back historically, and its historical offset is extracted from its associated historical nodes;
[0051] Obtain a preset error threshold, and terminate the tracing operation when the historical offset is less than or equal to the error threshold;
[0052] Call the offset calculation function, input the real-time offset and the historical offset into the calculation function, and record the output result as the authentication offset.
[0053] Preferably, the step of reconstructing the path of the abnormal verification node based on the authentication offset includes:
[0054] The historical tracing count of the abnormal verification nodes is counted and recorded as a reconstruction reference value;
[0055] Obtain the reconstruction threshold and compare the reconstruction reference value with the reconstruction threshold;
[0056] When the reconstruction reference value is greater than or equal to the reconstruction threshold, the abnormal verification node is logically reset according to the authentication offset to generate a reconstruction verification node, and associated authentication is performed under the reconstruction verification node.
[0057] When the reconstruction reference value is less than the reconstruction threshold, the authentication offset is continuously collected until the reconstruction reference value reaches or exceeds the reconstruction threshold, at which point path reconstruction is triggered.
[0058] Preferably, the hash verification transformation includes:
[0059] Extract the encrypted fields and permission attributes from the authentication results to construct composite verification parameters;
[0060] The composite verification parameters are fragmented and reassembled to generate a standardized hash sequence;
[0061] Based on the preset permission weight matrix, the standardized hash sequence is iteratively calculated to generate the verification parameters and input into the verification algorithm.
[0062] Preferably, the step of generating a dynamic correction factor based on the error ratio and adjusting the current permission determination threshold according to the correction factor includes:
[0063] Get the frequency of activation of dynamic features in the current authentication path;
[0064] A dynamic attenuation factor is generated based on the effective frequency, and attenuation compensation is applied to the permission determination threshold.
[0065] The compensated permission determination threshold will be synchronized to the master keystore verification in the next authentication cycle.
[0066] Compared with the prior art, the beneficial effects of the present invention are:
[0067] In terms of key management, by collecting biometric data, dynamic token data, and identity credential data and encrypting them into independent key units, and assigning a unique encryption identifier to each key unit, the secure isolation and independent storage of multi-source identity information are effectively achieved. Obfuscation of data within each independent key unit and removal of duplicate or redundant encryption fields improve the compactness and security of data storage. Standardized format processing unifies the encryption structure of key units, facilitating efficient access and verification of the key store during subsequent authentication processes, and enhancing the standardization and systematic nature of key management.
[0068] In terms of authentication rule construction, by extracting fragmented verification features from the master key repository and dividing the verification intervals, and combining feature weight parameters to distinguish between static and dynamic features, dynamic features are given higher authentication priority. This ensures that high-risk and highly dynamic features are prioritized for verification, improving the scientific nature and targeting of the authentication strategy. A dynamic correction factor is generated based on historical change records and error ratios to adjust the permission judgment thresholds with weights, enabling the authentication priority sequence to be dynamically optimized according to the real-time authentication environment, thus enhancing the adaptability and flexibility of the authentication rules.
[0069] In terms of authentication chain construction, a multi-level authentication chain and verification nodes were established to achieve hierarchical management of the authentication process. The two-way verification mechanism, through hash verification conversion and preset verification algorithms, ensures the accuracy and reliability of the authentication status of verification nodes. Hierarchical authentication of permissions under valid authentication status enables ordered collaborative verification between different key libraries, improving authentication efficiency. Abnormal node identification and authentication offset calculation under invalid authentication status, combined with historical tracing and offset calculation functions, can quickly locate the root cause of authentication anomalies, providing precise evidence for path reconstruction.
[0070] In terms of anomaly handling, based on the comparison results between the reconstruction reference value and the reconstruction threshold, the path reconstruction is triggered flexibly by either logical reset or continuous collection of authentication offsets, ensuring efficient repair of abnormal verification nodes. Logical reset generates reconstructed verification nodes and performs associated authentication, which can quickly restore the normal operation of the authentication link; the recording and analysis of historical traceability times provide data support for long-term monitoring and systematic optimization of abnormal nodes, improving the stability and self-healing capability of the authentication system.
[0071] This invention, through multi-dimensional technological innovation, constructs a complete digital identity encryption authentication system covering key generation, authentication rule formulation, authentication link construction, and anomaly handling. It effectively solves the shortcomings of traditional authentication methods in terms of security, dynamism, and adaptability, and provides an efficient and reliable technical solution for digital identity authentication in complex scenarios such as cloud computing and the Internet of Things. It has significant engineering application value and market promotion prospects. Attached Figure Description
[0072] Figure 1 This is a schematic diagram illustrating the working principle of the digital identity encryption and authentication method described in this invention.
[0073] Figure 2 Design diagram of the segmented verification feature determination method;
[0074] Figure 3 A design diagram for determining the method of authentication rules;
[0075] Figure 4 Design diagram for the authentication offset calculation method. Detailed Implementation
[0076] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0077] Please see Figures 1-4 The digital identity encryption and authentication method involved in this invention has the following specific implementation steps:
[0078] A feature dataset of user identity information is obtained and subjected to multi-dimensional encryption preprocessing to generate a master key store. The security and reliability of the master key store are ensured through multi-dimensional encryption of user identity information.
[0079] The fragmentation verification features of each master key repository are extracted, and authentication rules for different key repositories are determined based on these features. By analyzing the fragmentation verification features of the master key repository, appropriate authentication rules are formulated for different key repositories to ensure the accuracy and effectiveness of authentication.
[0080] Authentication paths are constructed for each master key repository according to the authentication rules, forming a multi-level authentication chain, and verification nodes for each authentication chain. Constructing authentication paths according to the authentication rules, forming multi-level authentication chains and verification nodes, provides structural support for subsequent authentication processes.
[0081] Each verification node undergoes bidirectional verification to obtain its authentication status, which includes valid and invalid authentication status. The authentication status of the verification nodes is determined through bidirectional verification for subsequent processing.
[0082] In the valid authentication state, the master keystores under each verification node perform association authentication according to the permission level. This ensures that, in the valid authentication state, the master keystore can perform correct association authentication according to the permission level.
[0083] In the invalid authentication state, abnormal verification nodes are identified, and the authentication offset of the master keystore under the abnormal verification node is calculated. Timely identification of abnormal verification nodes and calculation of authentication offsets provide a basis for path reconstruction.
[0084] Based on the authentication offset, the abnormal verification node undergoes path reconstruction until all master key libraries complete authentication according to their permission levels, at which point the process terminates. Path reconstruction restores the abnormal verification node to normal operation, ensuring that all master key libraries complete authentication.
[0085] The technical solution of the present invention will be further described in detail below with reference to specific embodiments.
[0086] Example 1:
[0087] The specific implementation method for acquiring the feature dataset of user identity information and generating the master key store is as follows: First, multi-dimensional data collection of user identity information needs to be completed. This collection process covers three core types of information: biometric data, dynamic token data, and identity credential data. Biometric data includes, but is not limited to, inherent physiological or behavioral characteristics of the human body, such as fingerprint patterns, iris pigment distribution, and voiceprint frequency. This data is collected using specialized biometric devices. For example, fingerprint scanners acquire fingerprint images through optical imaging or capacitive sensing; iris recognition devices capture iris texture details using near-infrared cameras; and voiceprint acquisition modules record voice samples and extract spectral features using microphones. Dynamic token data is a one-time dynamic password generated based on time synchronization or event triggering mechanisms. It is commonly found in hardware token devices or dynamic codes generated by mobile apps. For example, a time-synchronized token generates a new 6-digit numeric password every 60 seconds, and this password is synchronized with the timestamp on the authentication server. Identity credential data includes legal identity information such as ID card number, passport number, and driver's license number, as well as user-defined account identifiers. This data is obtained through manual input or system interface integration, such as reading the identity information in the chip through an ID card reader, or manually entering the account and password by the user on the registration interface.
[0088] After data collection, the three types of data need to be independently encrypted to generate independent key units. The encryption process employs a layered encryption strategy, selecting appropriate encryption algorithms for different data types. For biometric data, due to its large volume and irreversibility, AES-256 encryption is used for block encryption. The original biometric data is divided into fixed-size blocks, each encrypted with a different session key. The session key is protected by a master key, which is stored and managed through a Hardware Security Module (HSM). Dynamic token data, due to its time-sensitive nature, is encrypted using the HMAC-SHA256 algorithm. The dynamic token value is hashed with the key to generate a fixed-length encrypted digest, which is transmitted along with a timestamp to verify the validity and freshness of the dynamic token. Identity credential data involves sensitive personal identification information and is encrypted using the RSA asymmetric encryption algorithm. The server's public key is used to encrypt the identity credential data, and the encrypted data can only be decrypted using the corresponding private key, ensuring confidentiality during transmission and storage. After the encryption operation is completed, a unique encrypted identifier is assigned to each independent key unit. This identifier is generated using the UUID (Universally Unique Identifier) generation rule and consists of 128 binary numbers. It is generated by combining a timestamp, node MAC address and random number to ensure global uniqueness and facilitate accurate identification and management of key units in the future.
[0089] To further enhance data security and resistance to attacks, data within each independent key unit is obfuscated. Obfuscation involves two stages: field scrambling and redundancy removal. Field scrambling involves randomly rearranging the order of encrypted data fields, disrupting the original data's logical structure. For example, in biometric data, fingerprint feature point coordinates, orientation, and curvature fields are rearranged in a random order, making it difficult for attackers to deduce the data's true meaning even if they obtain it. Redundancy removal uses deduplication algorithms to identify and remove duplicate or redundant encrypted fields from each key unit. For instance, duplicate timestamp fields or fixed-format redundant characters may exist in identity credential data and dynamic token data. These are detected and removed through hash value comparison or regular expression matching, reducing data storage and transmission overhead and mitigating security risks caused by data redundancy. During obfuscation, a strict data verification mechanism must be established to ensure data integrity is not compromised after scrambling and deduplication. This can be achieved by calculating the MD5 checksums of the data before and after obfuscation and comparing them. If they are inconsistent, a data recovery process is triggered, and obfuscation is repeated.
[0090] After obfuscation, the individual key units need to be standardized to unify their encryption structure. Standardization includes two parts: data format definition and metadata encapsulation. The data format definition specifies the basic structure of each key unit, including header information, data body, and footer checksum. The header information contains metadata such as an encryption identifier, data type identifier (biometric data, dynamic token data, or identity credential data), encryption algorithm identifier, and version number, used to identify the basic attributes and encryption parameters of the key unit. The data body is the obfuscated encrypted data. The footer checksum includes a CRC checksum generated based on the data body, used to verify the integrity of the data during transmission and storage. Metadata encapsulation combines the header information, data body, and footer checksum according to a specified format to generate a standard-compliant key unit file, such as using JSON or binary format, ensuring that different systems and modules can correctly parse and process the key units. During format standardization, relevant industry standards and specifications must be followed, such as the Biometric Data Exchange Format Standard (ANSI / INCITS 378) and Public Key Infrastructure (PKI) standards, to ensure the compatibility and interoperability of the master key repository.
[0091] Finally, the unified, independent key units are output as the master keystore. The master keystore employs a distributed storage architecture, storing different types of key units on different physical servers or cloud storage nodes. Load balancing and data redundancy mechanisms ensure data availability and reliability. For example, key units for biometric data are stored on dedicated biometric data servers, key units for dynamic token data are stored on dynamic authentication servers, and key units for identity credential data are stored in the user center database. Storage nodes communicate and synchronize through secure data channels. The master keystore's output interface requires strict access control; only authorized systems and modules can access and call data from the master keystore. The access process uses authentication and authorization protocols such as OAuth 2.0 to ensure data access security. Simultaneously, a version management mechanism for the master keystore is established. When encryption algorithms, data formats, or business requirements change, the master keystore can be upgraded and updated promptly, ensuring system sustainability and adaptability.
[0092] Throughout the process of generating the master keystore, each step is closely interconnected, forming a complete data processing chain. The data acquisition stage ensures comprehensive and accurate user identity information; the independent encryption stage guarantees data confidentiality through appropriate encryption algorithms; the allocation of encryption identifiers provides unique identifiers for key unit management; obfuscation further enhances data security; format standardization ensures the standardization and compatibility of key units; and distributed storage and access control guarantee the availability and secure access to the master keystore. Each step employs mature technologies and strict process control to ensure that the generation of the master keystore complies with information security standards and business requirements, providing a solid data foundation for subsequent operations such as fragmented verification feature extraction, authentication rule determination, and authentication path construction. Through this series of implementation steps, a secure, reliable, structurally unified, and easily manageable master keystore can be generated, laying a crucial foundation for the overall operation of the digital identity encryption authentication system. This ensures that the data in the master keystore can be used accurately and efficiently in subsequent authentication processes, achieving reliable authentication and encryption protection of user identities.
[0093] Example 2:
[0094] When extracting the fragment verification features of each master key repository, it is necessary to obtain the key fragments under the master key repository. These key fragments are independent data units formed by dividing the master key repository according to specific rules. The division method can be based on factors such as data type, timestamp, or business logic. For example, for a master key repository composed of biometric data, it can be fragmented according to different biometric types such as fingerprint, iris, and voiceprint; for a master key repository containing dynamic token data for multiple time periods, it can be fragmented according to timestamps. After obtaining the key fragments, their integrity needs to be verified. This is done by calculating the hash value of each fragment and comparing it with the hash value pre-stored in the master key repository to ensure that the obtained key fragments have not been tampered with or damaged.
[0095] Key fragments are ranked according to their verification strength. Verification strength is an indicator of the importance and reliability of key fragments in the identity authentication process, and its evaluation requires comprehensive consideration of multiple factors. For biometric key fragments, verification strength is related to the uniqueness, stability, and anti-counterfeiting properties of the feature. For example, iris features have high uniqueness and stability, resulting in high verification strength; while fingerprint features, although widely used, are at risk of being forged, resulting in relatively low verification strength. For dynamic token key fragments, verification strength is related to the complexity of the token generation algorithm, its timeliness, and its resistance to replay attacks. Time-synchronized dynamic tokens, which are updated every 60 seconds and whose generation algorithm includes a random factor, have high verification strength; while event-triggered dynamic tokens, if the triggering mechanism is simple, have relatively low verification strength. The verification strength of identity credential key fragments is related to the authority of the credential and its anti-counterfeiting technology. For example, ID cards using electronic chips and digital signature technology have higher verification strength than ordinary paper credentials. The sorting process uses a weighted scoring mechanism, assigning corresponding weights to each factor affecting verification strength, and obtaining the verification strength score of each key fragment through quantitative calculation, and then sorting them from high to low scores.
[0096] After sorting, the logical correlation between adjacent key fragments is extracted. Logical correlation reflects the inherent connection between key fragments in terms of data structure, business logic, or time series. For biometric key fragments, adjacent fragments may correspond to different parts of the same biometric feature, such as different regions of a fingerprint; their logical correlation is reflected in the continuity and matching degree of feature points. The logical correlation can be quantified by calculating indicators such as the Euclidean distance and directional consistency of feature points in adjacent fingerprint fragments. For dynamic token key fragments, adjacent fragments may correspond to tokens generated at different times; their logical correlation is reflected in the continuity of the time series and the correlation of the generation algorithms. The logical correlation can be evaluated by analyzing the time intervals, numerical variation patterns, and common parameters in the generation algorithms of adjacent tokens. The logical correlation of identity credential key fragments is reflected in the consistency and complementarity of credential information, such as the relationship between ID card numbers and information like names and dates of birth. After extracting the logical correlation, it is labeled as a hierarchical judgment parameter for subsequent interval division and feature weight calculation.
[0097] The system obtains preset grading thresholds and divides the judgment parameters into intervals. These preset grading thresholds are standard values pre-set based on extensive historical data and business experience, used to divide the logical correlation judgment parameters into different intervals. These intervals represent different levels of correlation strength, such as strong correlation, medium correlation, and weak correlation intervals. The division process employs a dynamic threshold adjustment mechanism, automatically adjusting the grading thresholds based on the characteristics of the current master key repository and changes in the authentication environment. For authentication scenarios with high security requirements, the threshold for strong correlation intervals can be appropriately increased, while the range of weak correlation intervals can be narrowed; for general authentication scenarios, the threshold restrictions can be relaxed. After interval division, multiple verification intervals are generated, each corresponding to a different correlation strength level.
[0098] The number of decision parameters within each verification interval is counted and recorded as feature weight parameters. These feature weight parameters reflect the importance of each verification interval in the overall logical correlation, and their calculation is based on the distribution density and correlation strength of the decision parameters. In strongly correlated intervals, a higher number of decision parameters indicates a closer logical connection between key fragments within that interval, contributing more to the reliability of the overall authentication; therefore, a higher feature weight parameter is assigned. In weakly correlated intervals, a smaller number of decision parameters results in a relatively smaller impact on the overall authentication, and the feature weight parameter is correspondingly lower. This method transforms the qualitative analysis of logical correlation into a quantitative representation of feature weight parameters, providing data support for subsequently determining the fragment verification features of the master key repository.
[0099] The sharding verification features for each master key repository are determined based on feature weight parameters, including static and dynamic features. The determination process first obtains the feature weight parameters for each master key repository and sorts them from lowest to highest value within the same master key repository. After sorting, the deviation weight of the feature weight parameter with the lowest value is calculated. The deviation weight is an indicator that measures the degree of deviation of this feature weight parameter from other parameters, and its calculation is based on statistical methods such as standard deviation and coefficient of variation. The deviation weight value is obtained by calculating the difference between this feature weight parameter and the average of all parameters, and then standardizing the difference.
[0100] The deviation threshold is obtained and compared with the deviation weight of the feature weight parameter with the lowest value. The deviation threshold is a pre-set standard value based on system stability and authentication accuracy requirements, used to determine whether the feature weight parameter has abnormal deviations. If the deviation weight is greater than the deviation threshold, it indicates that the verification interval corresponding to the feature weight parameter differs significantly from other intervals, possibly reflecting the dynamic changes of the master key repository; therefore, the master key repository is determined to have dynamic characteristics. If the deviation weight is less than or equal to the deviation threshold, it indicates that the distribution of the feature weight parameter is relatively consistent with other parameters, and the verification characteristics of the master key repository are relatively stable; therefore, the master key repository is determined to have static characteristics. The authentication priority of dynamic characteristics is higher than that of static characteristics because dynamic characteristics can more timely reflect the real-time status and change trends of the master key repository, improving the accuracy and security of authentication.
[0101] In the entire process of extracting fragment verification features, each step is closely linked and mutually influential. Integrity verification of key fragments ensures data reliability, providing an accurate foundation for subsequent analysis. Sorting by verification strength distinguishes key fragments of varying importance, facilitating focused attention on fragments with high verification strength. Extracting logical correlations and dividing intervals transforms the complex relationships between key fragments into quantifiable feature parameters. Statistical feature weighting parameters and determining fragment verification features further transform these parameters into meaningful authentication features, providing a basis for subsequent authentication rule development. The entire process employs various data analysis and statistical methods to ensure the accuracy and effectiveness of fragment verification features, providing reliable feature support for digital identity encryption authentication systems. This enables the system to develop personalized authentication strategies based on the characteristics of different master key repositories, improving authentication efficiency and security.
[0102] Example 3:
[0103] When determining authentication rules for different key repositories based on fragmented verification features, it is necessary to comprehensively acquire the fragmented verification features of each master key repository. These features encompass both static and dynamic features. Among them, dynamic features, due to their strong real-time nature and high authentication priority, become the core basis for determining authentication rules. After acquiring the features, the verification intervals corresponding to the dynamic features are analyzed, and their minimum values are extracted as the permission determination threshold. The setting of this threshold needs to be combined with the data characteristics of the key repository. For example, the minimum value of the verification interval corresponding to the dynamic features in a biometric master key repository may be related to the real-time acquisition error range of biometric features such as fingerprints and irises; the threshold for a dynamic token master key repository is related to the timestamp accuracy and random factor range of the token generation algorithm. This threshold is used to measure the permission level of the master key repository in the authentication process. The larger the value, the higher the authority and reliability of the key repository in authentication.
[0104] The permission determination thresholds for all master key libraries under all dynamic features are aggregated and arranged in descending order of threshold value to generate an initial authentication priority sequence. This sequence follows a "threshold priority" principle, meaning that master key libraries with higher thresholds are given priority in permission determination during the authentication process. For example, in a system that includes both dynamic tokens and biometric dynamic features, if the permission determination threshold for dynamic tokens is 85 and the threshold for biometric dynamic features is 70, then the master key library corresponding to the dynamic token will be ranked higher in the authentication priority sequence. After the initial sequence is formed, it needs to be further dynamically optimized using historical authentication data to adapt to changes in the actual authentication environment.
[0105] The dynamic optimization process begins by obtaining historical change records of the access control thresholds of the master key repository under dynamic characteristics. These records contain information such as the time, reason, and magnitude of threshold adjustments, and analysis can reveal patterns and trends in threshold changes. For example, some master key repositories may experience frequent changes in their access control thresholds due to adjustments in business requirements or upgrades to security policies. Next, the actual number of times the access control threshold took effect in the historical authentication path is extracted—that is, the number of times the threshold was successfully applied and verified during the authentication process—and the error ratio between this number and the preset number is calculated. The preset number can be set according to the system's authentication frequency and stability requirements; the error ratio reflects the degree of deviation between the actual effectiveness of the threshold and the expected value.
[0106] A dynamic correction factor is generated based on the error ratio, which is used to adjust the current permission determination threshold with weights. The correction factor is calculated using algorithms such as linear interpolation or exponential smoothing. For example, when the error ratio is positive (the actual number of effective attempts exceeds the preset number), it indicates that the threshold has high applicability, and a positive correction factor can be generated to enhance the threshold adjustment; when the error ratio is negative, a negative correction factor is generated to attenuate the threshold adjustment. The adjusted permission determination threshold is closer to actual authentication requirements. For example, the permission determination threshold of a dynamic token master keystore was adjusted from 85 to 88 to cope with the recent frequent high-security authentication requests.
[0107] The weighted permission determination thresholds are aggregated, the authentication priority sequence is rearranged, and the adjusted sequence is synchronized to the path construction of subsequent verification nodes. This synchronization process is implemented through a system message queue or data interface to ensure that each verification node obtains the latest authentication priority information in real time. For example, in a multi-level authentication chain, after the front-end verification node adjusts the authentication priority sequence, it synchronizes the sequence to the back-end nodes through a secure data channel, ensuring that the permission determination logic throughout the entire authentication path remains consistent.
[0108] After completing the permission assessment for the master keystore under dynamic features, it is necessary to further assess the master keystore under static features. Static features have a lower authentication priority than dynamic features, and their permission assessment process is relatively fixed, typically based on preset static rules. For example, for static features of identity credential-based master keystores, fixed permission levels can be set, such as the highest level corresponding to an ID card and a lower level for ordinary account identifiers. During the assessment, verification is performed sequentially according to the permission level of the static features until the permission assessment of all master keystores is completed.
[0109] In the entire authentication rule determination process, prioritizing dynamic features and dynamically adjusting based on historical data are crucial. By using the minimum value of the verification interval corresponding to the dynamic feature as the permission judgment threshold, the sensitivity of the authentication rules to real-time data is ensured. Error analysis based on historical change records and actual effective counts enables the authentication priority sequence to adapt to changes in business scenarios. The addition of static features supplements the comprehensiveness of the authentication rules, covering authentication requirements with higher stability. Through data interaction and logical linkage, each stage forms a set of authentication rules that combine dynamic and static elements with clear priorities. This provides a clear execution basis for subsequent authentication path construction and two-way verification of verification nodes, ensuring the standardization and efficiency of the digital identity encryption authentication process.
[0110] Example 4:
[0111] When performing two-way authentication on each authentication node, the authentication result of the master key store under that node must first be obtained. The authentication result includes the processing status of the master key store on the current authentication node, such as whether the initial verification has passed and the permission matching status. These results are extracted from the storage and processing module of the master key store through the authentication interface. The extraction process must follow security protocols to ensure the confidentiality and integrity of the data during transmission, such as using a TLS encrypted channel for data transmission to prevent the authentication result from being stolen or tampered with.
[0112] After obtaining the authentication result, it needs to be hashed and verified. This process involves three key steps. The first step is to construct composite verification parameters, which involves extracting the encrypted fields and permission attributes from the authentication result. The encrypted fields include metadata such as the encryption identifier and encryption algorithm identifier used by the master keystore during generation and processing, as well as obfuscated and encrypted user identity information data. The permission attributes involve the user permission level corresponding to the master keystore and access control rules in the authentication path. For example, for the authentication result of a biometric master keystore, the encrypted fields may contain encrypted data blocks of fingerprint features and an AES-256 encryption algorithm identifier, and the permission attributes may indicate that the user has permission to access confidential data. Combining this information forms composite verification parameters containing multi-dimensional data, providing comprehensive input data for subsequent hash verification.
[0113] The second step is to fragment and reassemble the composite check parameters to generate a standardized hash sequence. Fragmentation and reassembly require dividing the composite check parameters into fixed-length data fragments according to preset rules and rearranging their order. For example, the composite check parameters can be divided into 128-bit fragments, and then reassembled in the order of encryption identifier, permission attribute, and encryption field to form a sequence structure that meets the input requirements of the hash algorithm. The generation of the standardized hash sequence must ensure that the data fragmentation and reassembly process is deterministic; that is, the same composite check parameters will inevitably generate the same hash sequence after processing, thus guaranteeing the consistency and repeatability of the check results.
[0114] The third step involves iteratively calculating the standardized hash sequence based on a predefined permission weight matrix to generate verification parameters, which are then input into the verification algorithm. The permission weight matrix is a predefined set of weight values used to measure the importance of different fields in the composite verification parameters. For example, the weight of a permission attribute field may be higher than that of a metadata field in the encryption field, because permission attributes directly relate to user access permissions and system security. The iterative calculation process uses a circular hashing method, performing bit-by-bit operations on the standardized hash sequence and the permission weight matrix. Each operation result serves as the input for the next operation, and after several iterations, the final verification parameters are generated. These verification parameters are fixed-length numerical values that uniquely represent the content and structure of the authentication result.
[0115] After completing the hash verification transformation, a preset verification algorithm is invoked. The verification parameters are input into the algorithm, and the output value is recorded as the authentication parameter. The preset verification algorithm can use common hash algorithms such as SHA-256 and MD5, or a custom algorithm can be defined according to system security requirements. The core function of the verification algorithm is to perform complex mathematical operations on the verification parameters to generate an authentication parameter that reflects the authenticity of the authentication result. For example, using the SHA-256 algorithm to operate on the verification parameters generates a 256-bit binary number as the authentication parameter. There is a strict mapping relationship between this parameter and the verification parameter; any slight change in the authentication result will lead to a significant change in the authentication parameter.
[0116] The authentication threshold is obtained, and the authentication parameters are compared with the authentication threshold. The authentication threshold is a pre-set value based on the system's security policy and authentication accuracy requirements, used to determine the authentication status of the verification node. The setting of the authentication threshold needs to comprehensively consider the balance between false positive rate and false negative rate. For example, in high-security scenarios, the authentication threshold can be set to a higher value to strictly screen valid authentications; in general scenarios, the threshold can be appropriately reduced to improve authentication efficiency. The comparison process uses numerical comparison. If the authentication parameters are less than the authentication threshold, the verification node is determined to be in a valid authentication state, indicating that the master key library has passed authentication at the current node, and can proceed to the subsequent permission level association authentication stage; if the authentication parameters are greater than or equal to the authentication threshold, the verification node is determined to be in an invalid authentication state, and an exception handling process needs to be triggered to identify and repair the abnormal verification node.
[0117] Throughout the entire two-way verification process, each step of the hash verification and transformation must strictly adhere to the algorithm rules and data processing flow to ensure the accuracy of the verification and authentication parameters. When constructing composite verification parameters, encrypted fields and permission attributes must be fully extracted to avoid omitting critical information; the fragmentation and reassembly process must ensure the consistency of the data fragment segmentation and arrangement order; iterative calculations must correctly apply the permission weight matrix to ensure that the importance of different fields is reasonably reflected in the authentication parameters. The selection of the preset verification algorithm and the setting of the authentication threshold must be optimized according to the actual needs of the system. For example, in environments with limited computing resources, the computationally efficient MD5 algorithm can be selected; in scenarios with extremely high security requirements, high-strength algorithms such as SHA-512 should be prioritized.
[0118] The two-way authentication mechanism achieves dynamic verification and status determination of authentication nodes through hash verification and parameter comparison of authentication results. This enables timely detection of anomalies during the authentication process, preventing unauthorized access and data leakage. Determining a valid authentication status ensures normal access for legitimate users, while identifying invalid authentication status provides an early warning and response mechanism for system security. Subsequent anomaly handling and path reconstruction allow the authentication system to resume normal operation, ensuring the continuity and reliability of digital identity encryption authentication. The entire process revolves around the authenticity and validity of the authentication results, ensuring the scientific rigor and credibility of two-way authentication through standardized processing procedures and rigorous algorithm application.
[0119] Example 5:
[0120] When handling invalid authentication states, the first step is to identify abnormal authentication nodes. These nodes are those determined to be in an invalid authentication state through two-way verification. The identification process is implemented through the status marking of the authentication system. After each authentication node completes two-way verification, its authentication status (valid or invalid) is marked in real time and stored in the system status table. When the system detects a node marked as invalid through polling or event triggering mechanisms, it determines that the node is an abnormal authentication node.
[0121] After identifying the abnormal verification node, the authentication offset of the master key store under that node needs to be calculated. The specific steps are as follows: First, obtain the actual verification node of the master key store that has not completed association authentication under the abnormal verification node. The actual verification node refers to the next or previous node in the authentication path that should be directly associated with and authenticated by the abnormal verification node according to normal logic. Its information is stored in the logical structure table of the authentication path. For example, in a multi-level authentication chain, if the abnormal verification node is a level n node, its actual verification node may be a level n+1 node (next node) or a level n-1 node (previous node), depending on the direction of the authentication path.
[0122] Calculate the logical difference between the actual verification node and the abnormal verification node, and label it as the real-time offset. The logical difference is calculated based on the logical hierarchy of nodes in the authentication path. Each node is assigned a unique logical hierarchy number (e.g., 1, 2, 3, ..., n) in the authentication chain, and the logical difference is the absolute difference between their hierarchy numbers. Let the hierarchy number of the abnormal verification node be... The actual verification node's hierarchical number is Then the real-time offset This offset reflects the degree to which the abnormal node deviates from the hierarchy in the authentication path.
[0123] Historical tracing is performed on abnormal verification nodes to extract the historical offsets of their associated historical nodes. Historical tracing is achieved by querying authentication logs, which record the logical differences between the abnormal verification node and its associated nodes during the historical authentication process. The tracing process starts from the current abnormal event and traces back to the beginning, extracting the historical offset at the time of each abnormality. This continues until the extracted historical offset is less than or equal to a preset error threshold. The tracing operation will be terminated upon completion. A preset error threshold is required. This is a fixed value pre-set according to the stability requirements of the authentication system, used to determine whether the historical offset is within the normal fluctuation range.
[0124] After extracting the real-time and historical offsets, the offset calculation function is called, inputting the real-time and historical offsets into the function, and recording the output as the authentication offset. The offset calculation function uses a weighted summation method, with the following formula:
[0125]
[0126] in, For authentication offset, and These are the weighting coefficients for real-time offset and historical offset, respectively. ,and This is used to reflect the degree of influence of both on the authentication offset; The number of historical offsets traced. For the first Each historical offset. The weighting coefficient is set according to the real-time requirements of the authentication system; for example, when the system is more concerned with current anomalies, The higher the value, the better. The value is relatively high.
[0127] Based on the authentication offset, path reconstruction is performed on abnormal verification nodes. First, the historical tracing count of abnormal verification nodes is counted and recorded as a reconstruction reference value. Historical trace count refers to the total number of times the node has triggered historical trace operations within a certain period, reflecting the frequency of node anomalies. Obtain the reconstruction threshold. This threshold is an integer threshold pre-set based on the system's fault tolerance capability, used to determine whether path reconstruction should be triggered.
[0128] Reconstruct reference values With reconstruction threshold Compare: If This indicates that the abnormal verification node is frequently shifting, requiring deep repair. At this point, the repair should be based on the authentication offset. Perform a logical reset on the abnormal verification node. This logical reset is achieved by modifying the node's hierarchical number within the authentication path; for example, changing the original hierarchical number... Adjusted to This allows the node to be re-matched to the correct logical level, generating a reconstructed verification node, and re-executing the associated authentication process under the reconstructed verification node; if This indicates that the anomaly is still within an acceptable range. At this point, continue collecting authentication offset data until... Reaching or exceeding This triggers path reconstruction.
[0129] Throughout the invalid authentication process, the real-time offset calculation is based on the logical relationship at the node level. Historical tracing ensures the analysis of abnormal trends, the weighted authentication offset integrates current and historical data, and the comparison mechanism between the reconstruction reference value and the threshold balances the system's stability and fault tolerance. Through this series of operations, the authentication system can take corresponding remedial measures for abnormal verification nodes of varying severity, avoiding authentication interruptions caused by single anomalies. Simultaneously, through multiple tracings and final path reconstruction, the cumulative impact of node offsets is gradually eliminated, ensuring that all master key repositories complete authentication according to their permission levels and maintaining the normal operation of the digital identity encryption authentication system.
[0130] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0131] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A digital identity encryption authentication method, characterized in that: include: Obtain the feature dataset of user identity information, perform multi-dimensional encryption preprocessing, and generate a master key library; Extract the fragment verification features of each master key store, and determine the authentication rules for different master key stores based on the fragment verification features; The authentication paths for each master key repository are constructed according to the authentication rules, forming a multi-level authentication chain, and a verification node for each authentication chain. Each of the verification nodes is bidirectionally verified to obtain the authentication status of each node, wherein the authentication status includes a valid authentication status and an invalid authentication status; In the valid authentication state, the master key library under each verification node is associated for authentication according to the permission level. In the invalid authentication state, abnormal verification nodes are identified, and the authentication offset of the master key library under the abnormal verification node is calculated. Based on the authentication offset, the abnormal verification node is reconstructed until all master key libraries complete authentication according to the permission level, and then the process terminates.
2. The digital identity encryption authentication method according to claim 1, characterized in that: The process of acquiring the feature dataset of user identity information, performing multi-dimensional encryption preprocessing, and generating a master key store includes: Biometric data, dynamic token data, and identity credential data are collected, encrypted into independent key units, and a unique encryption identifier is assigned to each key unit. The data within each of the independent key units is obfuscated to remove duplicate or redundant encryption fields; The obfuscated independent key units are standardized in format to unify the encryption structure of the key units, and the unified independent key units are output as the master key library.
3. The digital identity encryption authentication method according to claim 1, characterized in that: The extraction of fragment verification features from each of the master key stores includes: Obtain the key fragments under each of the master key stores and sort them according to the verification strength; Extract the logical correlation between adjacent key fragments and label it as a hierarchical determination parameter; Obtain a preset grading threshold, and divide each judgment parameter into intervals based on the grading threshold to generate multiple verification intervals; The number of judgment parameters in each of the verification intervals is counted and recorded as feature weight parameters, and the sharding verification features of each master key library are determined based on the feature weight parameters. The fragmented verification features include static features and dynamic features, and the authentication priority of the dynamic features is higher than that of the static features.
4. The digital identity encryption authentication method according to claim 3, characterized in that: The step of determining the sharding verification features of each master key repository based on the feature weight parameters includes: Obtain the feature weight parameters for each of the aforementioned master key libraries; The feature weight parameters under the same master key library are sorted from low to high according to their values, and the deviation weight of the feature weight parameter with the lowest value is calculated. Obtain the deviation threshold and compare the deviation threshold with the deviation weight of the feature weight parameter with the lowest value; If the deviation weight is greater than the deviation threshold, then the master key library corresponding to the feature weight parameter is determined to have dynamic characteristics; If the deviation weight is less than or equal to the deviation threshold, then the master key library corresponding to the feature weight parameter is determined to have static characteristics.
5. The digital identity encryption authentication method according to claim 3, characterized in that: The step of determining authentication rules for different master key libraries based on the fragmented verification features includes: Obtain the fragmentation verification features of each of the master key libraries; The minimum value of the verification interval corresponding to the dynamic feature is used as the permission determination threshold; Summarize the permission determination thresholds of the master keystore under all the dynamic features, and arrange them in descending order of the thresholds to generate an authentication priority sequence; The permissions of each master key library are determined according to the authentication priority sequence, and after the master key library determination under the dynamic feature is completed, the master key library under the static feature is added for determination. The generation of the authentication priority sequence includes: Obtain historical change records of the master key store's permission determination threshold under the aforementioned dynamic characteristics; Extract the actual number of times the permission judgment threshold takes effect in the historical authentication path, and calculate the error ratio between the threshold and the preset number; A dynamic correction factor is generated based on the error ratio, and the current permission determination threshold is adjusted according to the correction factor. The weighted permission determination thresholds are aggregated, the authentication priority sequence is rearranged, and the adjusted sequence is synchronized to the path construction of subsequent verification nodes.
6. The digital identity encryption authentication method according to claim 1, characterized in that: The bidirectional verification of each verification node includes: Obtain the authentication results of the master key library under each verification node, perform hash verification and conversion, and generate multiple verification parameters; Invoke the preset verification algorithm, input the verification parameters into the verification algorithm, and record the output value as the authentication parameter; Obtain the authentication threshold and compare the authentication parameters with the authentication threshold; If the authentication parameter is less than the authentication threshold, the verification node is determined to be in a valid authentication state. If the authentication parameter is greater than or equal to the authentication threshold, the verification node is determined to be in an invalid authentication state.
7. The digital identity encryption authentication method according to claim 1, characterized in that: The calculation of the authentication offset of the master keystore under the abnormal verification node includes: Obtain the actual verification node of the master keystore that has not completed associated authentication under the abnormal verification node; Calculate the logical difference between the actual verification node and the abnormal verification node, and label it as the real-time offset; The abnormal verification node is traced back historically, and its historical offset is extracted from its associated historical nodes; Obtain a preset error threshold, and terminate the tracing operation when the historical offset is less than or equal to the error threshold; Call the offset calculation function, input the real-time offset and the historical offset into the calculation function, and record the output result as the authentication offset.
8. The digital identity encryption authentication method according to claim 7, characterized in that: The step of reconstructing the path for the abnormal verification node based on the authentication offset includes: The historical tracing count of the abnormal verification nodes is counted and recorded as a reconstruction reference value; Obtain the reconstruction threshold and compare the reconstruction reference value with the reconstruction threshold; When the reconstruction reference value is greater than or equal to the reconstruction threshold, the abnormal verification node is logically reset according to the authentication offset to generate a reconstruction verification node, and associated authentication is performed under the reconstruction verification node. When the reconstruction reference value is less than the reconstruction threshold, the authentication offset is continuously collected until the reconstruction reference value reaches or exceeds the reconstruction threshold, at which point path reconstruction is triggered.
9. A digital identity encryption authentication method according to claim 6, characterized in that: The hash verification conversion includes: Extract the encrypted fields and permission attributes from the authentication results to construct composite verification parameters; The composite verification parameters are fragmented and reassembled to generate a standardized hash sequence; Based on the preset permission weight matrix, the standardized hash sequence is iteratively calculated to generate the verification parameters and input into the verification algorithm.
10. A digital identity encryption authentication method according to claim 5, characterized in that: The step of generating a dynamic correction factor based on the error ratio and adjusting the current permission determination threshold according to the correction factor includes: Get the frequency of activation of dynamic features in the current authentication path; A dynamic attenuation factor is generated based on the effective frequency, and attenuation compensation is applied to the permission determination threshold. The compensated permission determination threshold will be synchronized to the master keystore verification in the next authentication cycle.
Citation Information
Patent Citations
Cross-domain identity authentication method and system in cloud environment
CN119071045A
Blockchain-based authentication system
DE202025100776U1