Digital human identity recognition and verification method and system, electronic equipment and storage medium
By acquiring digital human feature values and using SM3 and SM2 algorithms for digital signature and watermark embedding, the traditional problem of digital human identity authentication is solved, enabling reliable verification of digital human identity and ensuring the security of the metaverse and virtual digital human applications.
Patent Information
- Application Number
- CN202511287738.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-10
- Publication Date
- 2026-01-20
AI Technical Summary
Traditional digital humans lack authoritative identity authentication mechanisms, making it difficult to securely bind real people's legal ID information with digital humans, resulting in the inability to verify the authenticity of digital human identities.
By obtaining the unique serial number of the target user's identity chip and the encrypted ciphertext of the identity information, a digital human feature value is generated. The key pair generated by the SM3 operation and the SM2 algorithm is used for digital signature and embedded digital watermark to realize digital human identity recognition and verification.
It effectively ensures the authenticity of digital human identities, prevents tampering and forgery, achieves reliable identity verification, and safeguards the security of the metaverse and virtual digital human application scenarios.
Smart Images

Figure CN121367593A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of artificial intelligence security, and in particular to a digital person identity recognition and verification method and system, an electronic device and a storage medium. BACKGROUND
[0002] In the metaverse and virtual digital person application scenarios, traditional digital persons lack an authoritative identity authentication mechanism and are easy to be tampered with and forged. The prior art is difficult to securely bind the legal identity card information of a real person to a digital person, resulting in the inability to verify the authenticity of the digital person's identity.
[0003] Therefore, there is an urgent need to provide a technical solution to solve the above problems. SUMMARY
[0004] To solve the above technical problems, the present application provides a digital person identity recognition and verification method and system, an electronic device and a storage medium.
[0005] In a first aspect, the present application provides a digital person identity recognition and verification method applied to a first terminal. The technical solution of the method is as follows: obtaining a unique serial number of an identity chip and an identity information encrypted ciphertext of a target user, and generating a digital person feature value corresponding to the target user; performing SM3 operation on the digital person feature value, the unique serial number and the identity information encrypted ciphertext to generate a digital person identity recognition identifier; using an SM2 private key in a target key pair generated based on an SM2 algorithm to digitally sign the digital person identity recognition identifier to obtain a target digital person file containing a signature data ciphertext, and publishing a target digital person having an identity verification function, so that a second terminal performs identity authentication on the target digital person according to an identity verification strategy; The identity verification strategy is that the second terminal performs signature verification on the signature data ciphertext extracted from the target digital person file using an SM2 public key in the target key pair. If the signature verification is passed, the target digital person is determined to be a legal digital person. If the signature verification is not passed, the target digital person is determined to be an illegal digital person.
[0006] The digital person identity recognition and verification method of the present application has the following beneficial effects: The method of the present application can effectively ensure the authenticity of the digital person's identity, prevent tampering and forgery, solve the problem of traditional digital person identity authentication, realize reliable identity verification, and ensure the security of the metaverse and virtual digital person application scenarios.
[0007] On the basis of the above-mentioned solution, the digital person identity recognition and verification method of the present application can also be improved as follows.
[0008] In an optional manner, the step of generating the digital human feature value corresponding to the target user comprises: generating a digital human image data file corresponding to the target user; converting the digital human image data file into a binary file; performing SM3 operation on the binary file to obtain the digital human feature value.
[0009] The beneficial effects of the above optional manner are that the generation manner of the digital human feature value is further refined, and the subsequent accurate generation of the identity recognition mark is provided with strong support by generating an image data file and then converting and operating, thereby improving the accuracy and reliability of digital human identity recognition.
[0010] In an optional manner, the step of digitally signing the digital human identity recognition mark by using the SM2 private key in the target key pair generated based on the SM2 algorithm to obtain a target digital human file containing signature data ciphertext comprises: generating the target key pair by using the SM2 asymmetric password algorithm; digitally signing the digital human identity recognition mark by using the SM2 private key in the target key pair to obtain the signature data ciphertext; embedding the signature data ciphertext in the digital human image data file in a digital watermark manner to obtain the target digital human file.
[0011] The beneficial effects of the above optional manner are that the key pair is generated by using the SM2 algorithm for digital signature, and the signature data ciphertext is embedded in the image file in a digital watermark manner, thereby enhancing the security and tamper resistance of the target digital human file and making the identity verification more credible.
[0012] In an optional manner, the step of obtaining the unique serial number of the identity chip of the target user and the identity information encryption ciphertext comprises: obtaining the unique serial number and the identity information encryption ciphertext in the identity chip of the target user by using an identity chip reader.
[0013] The beneficial effects of the above optional manner are that the key information is further obtained by using the identity chip reader, thereby ensuring the accuracy and authority of information acquisition and guaranteeing the authenticity of digital human identity information from the source, and laying a solid foundation for the entire identity recognition and verification process.
[0014] In a second aspect, the present application provides a digital human identity recognition and verification system, and the technical scheme of the system is as follows: comprises a processing module, a generation module and a verification module; The processing module is configured to obtain a unique serial number of an identity chip of a target user and identity information encrypted ciphertext, and generate a digital human feature value corresponding to the target user; The generating module is configured to perform SM3 operation on the digital human feature value, the unique serial number and the identity information encrypted ciphertext to generate a digital human identity identification; The verification module is configured to use an SM2 private key in a target key pair generated based on an SM2 algorithm to digitally sign the digital human identity identification to obtain a target digital human file containing signature data ciphertext, and publish a target digital human with an identity verification function, so that a second terminal performs identity verification on the target digital human according to an identity verification strategy. The identity verification strategy is that the second terminal uses an SM2 public key in the target key pair to perform signature verification on the signature data ciphertext extracted from the target digital human file; if the signature verification passes, the target digital human is determined to be a legal digital human; if the signature verification fails, the target digital human is determined to be an illegal digital human.
[0015] The digital human identity identification and verification system has the following advantages: The system can effectively ensure the identity authenticity of the digital human, prevent tampering and forgery, solve the traditional digital human identity authentication problem, realize reliable identity verification, and ensure the security of the metaverse and virtual digital human application scenarios.
[0016] On the basis of the above-mentioned scheme, the digital human identity identification and verification system can be further improved as follows.
[0017] In an optional manner, the processing module is specifically configured to: generate a digital human image data file corresponding to the target user; convert the digital human image data file into a binary file; perform SM3 operation on the binary file to obtain the digital human feature value.
[0018] The above-mentioned optional manner has the following advantages: the generation manner of the digital human feature value is further refined, the image data file is generated and converted into a binary file for operation, which provides strong support for subsequent accurate generation of identity identification, and improves the accuracy and reliability of digital human identity identification.
[0019] In an optional manner, the verification module is specifically configured to: generate the target key pair by using an SM2 asymmetric encryption algorithm; The SM2 private key in the target key pair is used to digitally sign the digital human identity identifier, to obtain the signature data ciphertext; The signature data ciphertext is embedded in the digital human image data file in a digital watermark manner, to obtain the target digital human file.
[0020] The beneficial effects of the above optional mode are that the SM2 algorithm is used to generate a key pair for digital signature, and the signature data ciphertext is embedded in the image file in a digital watermark manner, which enhances the security and tamper resistance of the target digital human file, and makes the identity verification more reliable.
[0021] In an optional mode, the processing module is specifically configured to: The unique serial number and the identity information encrypted ciphertext in the identity chip of the target user are obtained through an identity chip reader.
[0022] The beneficial effects of the above optional mode are that the key information is further obtained through the identity chip reader, which ensures the accuracy and authority of information acquisition, and guarantees the authenticity of digital human identity information from the source, laying a solid foundation for the entire identity recognition and verification process.
[0023] In a third aspect, a technical solution of an electronic device of the present application is as follows: The processor executes the program to realize the steps of the digital human identity recognition and verification method of the present application.
[0024] In a fourth aspect, a technical solution of a computer readable storage medium provided by the present application is as follows: The computer readable storage medium stores instructions, and when the computer readable storage medium reads the instructions, the computer readable storage medium executes the steps of the digital human identity recognition and verification method of the present application.
[0025] The above description is only a summary of the technical solutions of the present application, in order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented according to the content of the specification, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0026] The drawings are only used to show the embodiments and are not considered as limitations of the present application. Moreover, the same reference signs are used to represent the same parts throughout the drawings. In the drawings: Figure 1 Flowchart of an embodiment of a digital human identity recognition and verification method of the present application; Figure 2 FIG. 1 is a structural schematic diagram of an embodiment of a digital human identity recognition and verification system according to the present application; Figure 3 FIG. 2 is a structural schematic diagram of an embodiment of an electronic device according to the present application. DETAILED DESCRIPTION
[0027] Exemplary embodiments of the present application will be described in greater detail below with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the drawings, it is understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein.
[0028] Figure 1 FIG. 3 is a flowchart of an embodiment of a digital human identity recognition and verification method provided by the present application, which is executed by a first terminal. The first terminal can be an electronic device such as a terminal device or a server. The terminal device can be any fixed or mobile terminal such as a user equipment (UE), a mobile device, a user terminal, a terminal, a cellular phone, a cordless phone, a personal digital assistant (PDA), a handheld device, a computing device, a vehicle-mounted device, a wearable device, etc. The server can be a single server or a server cluster composed of multiple servers. Any electronic device can implement the digital human identity recognition and verification method by calling computer-readable instructions stored in a memory through a processor. As shown in FIG. 3, the method includes the following steps: Figure 1 S1, obtaining a unique serial number of an identity chip and an identity information encrypted ciphertext of a target user, and generating a digital human feature value corresponding to the target user.
[0029] The target user refers to a natural person holding an identity chip, and the identity information of the target user is used to generate a corresponding digital human identity. The identity chip refers to an integrated circuit chip built in a second-generation resident identity card, which stores legal identity data. The unique serial number refers to a physical non-replicable identifier of a second-generation identity card chip, which is used to distinguish different identity card chips. The identity information encrypted ciphertext refers to real human identity data stored in a second-generation identity card chip by a national encryption algorithm, which contains sensitive information such as name, gender, identity card number, photo, and fingerprint. The digital human feature value refers to a hash value obtained by performing a national encryption SM3 digest operation on a digital human image data file converted into binary format.
[0030] S2, performing an SM3 operation on the digital human feature value, the unique serial number, and the identity information encrypted ciphertext to generate a digital human identity recognition identifier.
[0031] The SM3 operation refers to a national SM3 cryptographic hash algorithm for generating a fixed-length digest of data. The digital human identity identification refers to a unique identity identification generated by combining the digital human feature value, unique serial number, and identity information encrypted ciphertext through SM3 operation.
[0032] S3, using the SM2 private key in the target key pair generated based on the SM2 algorithm, digitally signing the digital human identity identification, obtaining a target digital human file containing signature data ciphertext, and publishing a target digital human with identity verification function, so that the second terminal performs identity verification on the target digital human according to the identity verification strategy.
[0033] The SM2 asymmetric cryptographic algorithm is used for digital signature and verification. The target key pair refers to a public-private key pair generated by the SM2 asymmetric cryptographic algorithm, including an SM2 private key and an SM2 public key. The SM2 private key refers to a secret key used for performing digital signature operation on the digital human identity identification in the target key pair.
[0034] The identity verification strategy is that the second terminal uses the SM2 public key in the target key pair to perform signature verification on the signature data ciphertext extracted from the target digital human file. If the signature verification passes, the target digital human is determined to be a legal digital human. If the signature verification does not pass, the target digital human is determined to be an illegal digital human.
[0035] The signature data ciphertext refers to an encrypted signature result generated by performing digital signature operation on the digital human identity identification using the SM2 private key. The target digital human file refers to a verifiable file generated by embedding the signature data ciphertext in the digital human image data file in the form of digital watermark. The target digital human refers to a virtual digital human entity carrying the target digital human file and having identity verification function. The second terminal refers to an electronic device performing identity verification operation on the target digital human file, which extracts the signature data ciphertext and verifies the legality. The SM2 public key refers to a public key used to verify the legality of the signature data ciphertext in the target key pair. The legal digital human refers to the target digital human whose signature verification passes, and its identity is bound to the second-generation ID card chip held by the real person. The illegal digital human refers to the target digital human whose signature verification does not pass, indicating that the identity information is tampered or forged.
[0036] It should be noted that the specific steps of the second terminal obtaining the SM2 public key in the target key pair are: ① the second terminal extracts the associated stored SM2 public key certificate from the preset metadata field of the target digital human file; ② verifying the digital signature chain of the SM2 public key certificate to confirm the credibility of the certificate issuing authority; ③ parsing the SubjectPublicKeyInfo field of the SM2 public key certificate to obtain the original public key data when the certificate verification is passed; ④ performing the national standard SM2 format decoding operation on the original public key data to restore the elliptic curve point coordinate parameters; ⑤ reconstructing the complete SM2 public key object based on the elliptic curve point coordinate parameters for subsequent signature verification operation.
[0037] The technical scheme of the embodiment can effectively ensure the authenticity of the digital human identity, prevent tampering and forgery, solve the traditional digital human identity authentication problem, realize reliable identity verification, and protect the security of the meta universe and virtual digital human application scenarios.
[0038] In an optional manner, the step of generating the digital human feature value corresponding to the target user comprises: Generating a digital human image data file corresponding to the target user.
[0039] The digital human image data file refers to a digital human three-dimensional model or image data file generated based on the target user's biological characteristics.
[0040] Specifically: ① collecting multi-modal biological characteristic data of the target user, the multi-modal biological characteristic data including facial images, body action videos and voice samples of the target user; ② inputting the multi-modal biological characteristic data into a pre-trained digital human modeling engine, and performing three-dimensional feature extraction and fusion processing on the multi-modal biological characteristic data by the digital human modeling engine to generate a dynamic three-dimensional digital model of the target user; ③ rendering and optimizing the dynamic three-dimensional digital model according to the application scenario requirements, and outputting a digital human image data file meeting the preset format standard.
[0041] Converting the digital human image data file into a binary file.
[0042] The binary file refers to a data file in binary format that can be processed by a computer.
[0043] Specifically: ① analyzing the format coding rule of the digital human image data file to determine its data structure; ② separating the pixel data stream and metadata information in the digital human image data file according to the data structure; ③ performing decoding operation on the pixel data stream to restore the original pixel value sequence; ④ recombining the original pixel value sequence and the metadata information into a continuous data block according to the preset binary coding rule; ⑤ adding a file header identifier and a length check code to the continuous data block to generate a binary file meeting the computer processable standard.
[0044] Performing SM3 operation on the binary file to obtain the digital human feature value.
[0045] In the optional manner described above, the generation method of the digital human feature value is further refined, and by generating image data files and converting them into binary files for operation, strong support is provided for subsequent accurate generation of identity identification, thereby improving the accuracy and reliability of digital human identity identification.
[0046] In an optional manner, the step of using the SM2 private key in the target key pair generated based on the SM2 algorithm to digitally sign the digital human identity identification to obtain a target digital human file containing signature data ciphertext comprises: Generating the target key pair using the SM2 asymmetric password algorithm.
[0047] Using the SM2 private key in the target key pair to digitally sign the digital human identity identification to obtain the signature data ciphertext.
[0048] Specifically: ① using the hash function specified by the SM2 algorithm to perform digest operation on the digital human identity identification to generate the message digest to be signed; ② selecting a random number generator that meets the SM2 standard based on the principle of elliptic curve cryptography to generate an encrypted random number; ③ using the encrypted random number and the SM2 private key to construct a temporary public key on the elliptic curve and calculate the first signature component; ④ combining the message digest, the first signature component and the SM2 private key to generate the second signature component through modular inverse operation; ⑤ serializing the first signature component and the second signature component into a byte stream structure according to the ASN.1 encoding rule; ⑥ adding the SM2 signature protocol header identifier to the byte stream structure and performing Base64 transcoding operation to output the signature data ciphertext that meets the national standard.
[0049] Embedding the signature data ciphertext into the digital human image data file in a digital watermarking manner to obtain the target digital human file.
[0050] Wherein, the digital watermarking manner refers to an information hiding technology that invisibly embeds the signature data ciphertext into the digital human image data file.
[0051] Specifically: ① parse the pixel matrix structure of the digital human image data file and divide it into non-overlapping image blocks; ② perform discrete wavelet transform on each image block to decompose it into low-frequency sub-band and high-frequency sub-band coefficients; ③ select an embedding position in the low-frequency sub-band coefficients that meets the invisibility threshold of the human visual system; ④ modulate the binary bit stream of the signature data ciphertext to the low-frequency coefficients at the embedding position according to the preset embedding intensity coefficient; ⑤ perform inverse discrete wavelet transform on the modulated low-frequency sub-band coefficients and the original high-frequency sub-band coefficients to reconstruct the image block; ⑥ aggregate all reconstructed image blocks to generate a watermarked image data; ⑦ encapsulate the watermarked image data into the same format standard as the original file and update the file header information, and output the target digital human file.
[0052] In the above optional manner, the SM2 algorithm is further used to generate a key pair for digital signature, and the signature data ciphertext is embedded in the image file in the form of digital watermark, thereby enhancing the security and tamper resistance of the target digital human file and making the identity verification more reliable.
[0053] In an optional manner, the step of obtaining the unique serial number of the identity chip of the target user and the identity information encryption ciphertext comprises: obtaining the unique serial number in the identity chip of the target user and the identity information encryption ciphertext through an identity chip reader.
[0054] The identity chip reader refers to a special device that meets the technical standards of the Ministry of Public Security and is used to safely read the unique serial number and the identity information encryption ciphertext in the second-generation identity card chip.
[0055] In the above optional manner, the key information is further obtained through the identity chip reader, ensuring the accuracy and authority of the information acquisition and guaranteeing the authenticity of the digital human identity information from the source, thereby laying a solid foundation for the entire identity recognition and verification process.
[0056] To better illustrate the technical solutions of the present embodiment, the following examples are used for illustration: 1) Application background: Live streaming platform A deploys digital human anchors to provide online services, and the traditional digital human has the risk of identity forgery. The existing technology cannot securely bind the real person's identity information with the digital human, resulting in the inability of the audience to verify the authenticity of the digital human identity. The present example applies the solution of the above embodiment to solve this problem. The first terminal is the operation server of live streaming platform A, and the second terminal is the user terminal APP.
[0057] 2) Specific process: ① Digital human identity generation phase: S101, the first terminal (live broadcast platform operation server) obtains the unique serial number "ID_AAA" and the identity information encrypted ciphertext "xxx" in the identity chip of the target user B through the identity chip reader.
[0058] S102, the first terminal generates a digital human image data file corresponding to the target user B, converts the digital human image data file into a binary file, and performs SM3 operation on the binary file to obtain a digital human feature value SM3_Hash1.
[0059] S103, the first terminal combines the digital human feature value SM3_Hash1, the unique serial number "ID_AAA" and the identity information encrypted ciphertext "xxx", and generates a digital human identity identification SM3_Hash2 by using SM3 operation.
[0060] S104, the first terminal generates a target key pair including an SM2 private key PrivateKey_Star and an SM2 public key PublicKey_Star by using an SM2 asymmetric password algorithm.
[0061] S105, the first terminal performs digital signature on the digital human identity identification SM3_Hash2 by using the SM2 private key PrivateKey_Star in the target key pair to obtain signature data ciphertext Sig_Data.
[0062] S106, the first terminal embeds the signature data ciphertext Sig_Data in the digital human image data file in a digital watermark manner to obtain a target digital human file B_AI.glb.
[0063] S107, the first terminal stores the SM2 public key certificate Cert_PublicKey_Star in the metadata field of the target digital human file B_AI.glb.
[0064] S108, the first terminal publishes the target digital human B_AI.glb with identity verification function to the live broadcast platform A.
[0065] ②Digital human identity verification stage: S201, the second terminal (audience C's mobile phone APP) responds to the identity verification request of the target digital human B_AI.glb by the audience C.
[0066] S202, the second terminal performs operation operation on the target digital human file B_AI.glb to extract the signature data ciphertext Sig_Data.
[0067] S203. The second terminal extracts the SM2 public key certificate Cert_PublicKey_Star from the metadata field of the target digital human file.
[0068] S204. The second terminal verifies the digital signature chain of the SM2 public key certificate Cert_PublicKey_Star to confirm the certificate's trustworthiness.
[0069] S205. The second terminal parses the SubjectPublicKeyInfo field of the SM2 public key certificate Cert_PublicKey_Star to obtain the original public key data, performs national cryptographic SM2 standard format decoding on the original public key data to restore the elliptic curve point coordinate parameters, and reconstructs the SM2 public key PublicKey_Star based on the elliptic curve point coordinate parameters.
[0070] S206. The second terminal uses the SM2 public key PublicKey_Star in the target key pair to perform signature verification on the ciphertext Sig_Data of the signature data.
[0071] S207. Signature verification passed. The second terminal determines that the target digital human B_AI.glb is a legitimate digital human and displays the message "Digital human identity authentication passed" on the mobile app interface.
[0072] Figure 2 This diagram illustrates the structure of an embodiment of a digital human identity recognition and verification system 200 provided by the present invention. Figure 2 As shown, the system 200 includes: a processing module 210, a generation module 220, and a verification module 230; The processing module 210 is used to: obtain the unique serial number of the target user's identity chip and the encrypted ciphertext of the identity information, and generate the digital human feature value corresponding to the target user; The generation module 220 is used to: perform SM3 operation on the digital human feature value, the unique serial number and the encrypted ciphertext of the identity information to generate a digital human identity identification identifier; The verification module 230 is used to: digitally sign the digital human identity identifier using the SM2 private key in the target key pair generated based on the SM2 algorithm, to obtain a target digital human file containing ciphertext of the signature data, and publish the target digital human with identity verification function so that the second terminal can verify the identity of the target digital human according to the identity verification policy; The identity verification strategy is that the second terminal performs signature verification on the signature data ciphertext extracted from the target digital human file by using the SM2 public key in the target key pair; if the signature verification passes, the target digital human is determined to be a legal digital human; and if the signature verification does not pass, the target digital human is determined to be an illegal digital human.
[0073] In an optional mode, the processing module 210 is specifically configured to: generate a digital human image data file corresponding to the target user; convert the digital human image data file into a binary file; perform SM3 operation on the binary file to obtain the digital human feature value.
[0074] In an optional mode, the verification module 230 is specifically configured to: generate the target key pair by using an SM2 asymmetric encryption algorithm; perform digital signature on the digital human identity identifier by using the SM2 private key in the target key pair to obtain the signature data ciphertext; embed the signature data ciphertext in the digital human image data file in a digital watermark manner to obtain the target digital human file.
[0075] In an optional mode, the processing module 210 is specifically configured to: obtain the unique serial number and the identity information encrypted ciphertext in the identity chip of the target user by using an identity chip reader.
[0076] It should be noted that the digital human identity recognition and verification system 200 provided in the above embodiments has the same beneficial effects as the digital human identity recognition and verification method, which will not be repeated here. In addition, the system provided in the above embodiments is only exemplified by the division of the above functional modules when realizing its functions, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the system is divided into different functional modules according to actual conditions to complete all or part of the above described functions. In addition, the system and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process is described in the method embodiments, which will not be repeated here.
[0077] The digital human identity recognition and verification system 200 of the present application can be a computer program (including program code) running in a computer device, for example, the digital human identity recognition and verification system of the present application is an application software, which can be used to execute corresponding steps in the digital human identity recognition and verification method of the present application.
[0078] In some embodiments, the digital human identity recognition and verification system 200 of the present invention can be implemented in a combination of hardware and software. As an example, the digital human identity recognition and verification system 200 of the present invention can be a processor in the form of a hardware decoding processor, which is programmed to execute the digital human identity recognition and verification method of the present invention. For example, the processor in the form of a hardware decoding processor can be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0079] The modules described in the embodiments of this invention can be implemented in software or hardware. The names of the modules are not, in some cases, limiting the scope of the module itself.
[0080] An electronic device according to an embodiment of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the above-mentioned digital human identity recognition and verification methods. That is, an electronic device according to an embodiment of the present invention may include, but is not limited to: a processor and a memory; the memory is used to store the computer program; the processor is used to execute the digital human identity recognition and verification method shown in any embodiment of the present invention by calling the computer program.
[0081] In one alternative embodiment, an electronic device is provided, such as Figure 3 As shown, Figure 3 The illustrated electronic device 4000 includes a processor 4001 and a memory 4003. The processor 4001 and the memory 4003 are connected, for example, via a bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, which can be used for data interaction between the electronic device and other electronic devices, such as sending and / or receiving data. It should be noted that in practical applications, the transceiver 4004 is not limited to one type, and the structure of the electronic device 4000 does not constitute a limitation on the embodiments of the present invention.
[0082] The processor 4001 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic device, transistor logic device, hardware component, or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in connection with the present disclosure. The processor 4001 can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.
[0083] The bus 4002 can include a path for transmitting information between the above-mentioned components. The bus 4002 can be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, or the like. The bus 4002 can be divided into an address bus, a data bus, a control bus, and the like. For convenience of representation, Figure 3 The bus 4002 is represented by only one thick line, but it does not mean that there is only one bus or only one type of bus.
[0084] The memory 4003 can be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.
[0085] The memory 4003 is configured to store application code (computer program) for implementing the scheme of the present application, and the processor 4001 is configured to control the execution. The processor 4001 is configured to execute the application code stored in the memory 4003 to implement the content shown in the foregoing method embodiments.
[0086] The electronic device can also be a terminal device, and the terminal device can be any terminal device that can install an application and access a webpage through the application, including at least one of a smartphone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a smart television, and a smart vehicle device.
[0087] It should be noted that, Figure 3 The electronic device shown is only an example and should not limit the functions and use range of the embodiments of the present application.
[0088] The computer readable storage medium of the embodiment of the present application, the computer readable storage medium has a computer program stored thereon, and the computer program is executed by a processor to implement any of the above-mentioned digital person identity identification and verification methods.
[0089] Optionally, the computer readable storage medium can be a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a compact disc read-only memory (Compact Disc Read-Only Memory, CD-ROM), a magnetic tape, a floppy disk, and an optical data storage device, etc.
[0090] In the exemplary embodiments, a computer program product or computer program is also provided, which includes computer instructions stored in a computer readable storage medium. The processor of the electronic device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to make the electronic device execute the above-mentioned digital person identity identification and verification method.
[0091] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0092] It should be understood that the flowchart and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of various embodiments of the present application. In this regard, each block in the flowchart and block diagrams can represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations thereof, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or combinations of hardware and software.
[0093] The computer readable storage medium of embodiments of the present application can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium can include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present application, the computer readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.
[0094] The computer readable storage medium described above bears one or more programs, when the one or more programs are executed by the electronic device, the electronic device executes the method shown in the above embodiment.
[0095] The above description is merely exemplary of the application and the application principles of the technology used. Those skilled in the art should understand that the disclosed range of the application is not limited to the technical solutions formed by the specific combinations of the above technical features, and should also cover other technical solutions formed by any combinations of the above technical features or their equivalent features without departing from the disclosed concept. For example, the above features are replaced with the technical features disclosed in the application (but not limited to) having similar functions to form technical solutions.
[0096] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application are used to distinguish similar objects, and represent a specific order or sequence. The order of use of similar objects can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than that illustrated or described.
[0097] Those skilled in the art know that the application can be implemented as a system, a method or a computer program product, so the application can be specifically implemented as follows: it can be a complete hardware, a complete software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, which is generally referred to as "circuit", "module" or "system" in this paper. In addition, in some embodiments, the application can also be implemented as a computer program product in one or more computer readable media, which contains computer readable program code.
[0098] Although the embodiments of the application have been shown and described above, it should be understood that the above embodiments are exemplary and cannot be understood as limiting the application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the application.
Claims
1. A method for digital human identity recognition and verification, applied to a first terminal, and characterized in that, The method comprises the following steps: obtaining the unique serial number of the identity chip of a target user and the encrypted ciphertext of identity information, and generating a digital human characteristic value corresponding to the target user; performing SM3 operation on the digital human characteristic value, the unique serial number and the encrypted ciphertext of identity information to generate a digital human identity identification; using the SM2 private key in a target key pair generated based on the SM2 algorithm to digitally sign the digital human identity identification, obtaining a target digital human file containing signature data ciphertext, and publishing the target digital human with identity verification function, so that a second terminal performs identity verification on the target digital human according to an identity verification strategy; wherein the identity verification strategy is that the second terminal uses the SM2 public key in the target key pair to perform signature verification on the signature data ciphertext extracted from the target digital human file; if the signature verification is passed, it is determined that the target digital human is a legal digital human; if the signature verification is not passed, it is determined that the target digital human is an illegal digital human.
2. The method of claim 1, wherein, The step of generating the digital human characteristic value corresponding to the target user comprises the following steps: generating a digital human image data file corresponding to the target user; converting the digital human image data file into a binary file; performing SM3 operation on the binary file to obtain the digital human characteristic value.
3. The digital human identity recognition and verification method of claim 2, wherein, The step of using the SM2 private key in a target key pair generated based on the SM2 algorithm to digitally sign the digital human identity identification to obtain a target digital human file containing signature data ciphertext comprises the following steps: generating the target key pair using the SM2 asymmetric encryption algorithm; using the SM2 private key in the target key pair to digitally sign the digital human identity identification to obtain the signature data ciphertext; embedding the signature data ciphertext in the digital human image data file in the form of digital watermark to obtain the target digital human file.
4. The method of claim 1 to 3, wherein, The step of obtaining the unique serial number of the identity chip of a target user and the encrypted ciphertext of identity information comprises the following steps: obtaining the unique serial number and the encrypted ciphertext of identity information in the identity chip of the target user through an identity chip reader.
5. A digital human identity recognition and verification system, characterized in that, The method comprises the following steps: a processing module, a generating module and a verification module; the processing module is used for obtaining the unique serial number of the identity chip of a target user and the encrypted ciphertext of identity information, and generating a digital human characteristic value corresponding to the target user; the generating module is used for performing SM3 operation on the digital human characteristic value, the unique serial number and the encrypted ciphertext of identity information to generate a digital human identity identification; the verification module is used for using the SM2 private key in a target key pair generated based on the SM2 algorithm to digitally sign the digital human identity identification, obtaining a target digital human file containing signature data ciphertext, and publishing the target digital human with identity verification function, so that a second terminal performs identity verification on the target digital human according to an identity verification strategy; The identity verification strategy is that the second terminal performs signature verification on the signature data ciphertext extracted from the target digital human file by using the SM2 public key in the target key pair; if the signature verification passes, the target digital human is determined to be a legal digital human; and if the signature verification does not pass, the target digital human is determined to be an illegal digital human.
6. The digital human identity recognition and verification system of claim 5, wherein, The processing module is specifically configured to: generate a digital human image data file corresponding to the target user; convert the digital human image data file into a binary file; perform SM3 operation on the binary file to obtain the digital human feature value.
7. The digital human identity recognition and verification system of claim 6, wherein, The verification module is specifically configured to: generate the target key pair by using an SM2 asymmetric cryptography algorithm; perform digital signature on the digital human identity identification by using the SM2 private key in the target key pair to obtain the signature data ciphertext; embed the signature data ciphertext into the digital human image data file in a digital watermark manner to obtain the target digital human file.
8. The digital human identity recognition and verification system according to any one of claims 5 to 7, characterized in that, The processing module is specifically configured to: obtain the unique serial number and the identity information encryption ciphertext in the identity chip of the target user by using an identity chip reader.
9. An electronic device, comprising: The electronic device includes a processor, the processor is coupled with a memory, and the memory stores at least one computer program. The at least one computer program is loaded and executed by the processor, so that the electronic device implements the digital human identity identification and verification method according to any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores at least one computer program, and the at least one computer program is loaded and executed by the processor, so that the computer readable storage medium implements the digital human identity identification and verification method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Credible digital identity personnel verification method and system
CN114095211A
Identity certificate generation method and device
CN116108410A
Virtual human identity authentication method and virtual human identity verification method
CN117874737A
Electronic-data authentication method, Elctronic-data authentication program, and electronic-data, authentication system
US20100005311A1