Intelligent agent identity registration, authentication and credential issuance method and system

CN122578332BActive Publication Date: 2026-09-22JIANGSU IDEABANK MICROELECTRONICS TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202611054789.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-07-16
Publication Date
2026-09-22
Estimated Expiration
2046-07-16

AI Technical Summary

Technical Problem

[0007]本申请提供了一种智能体身份管理及认证方案,旨在解决将传统的身份认证方案在应用于智能体时暴露出的、由智能体特性所导致的注册环节无法适配自动化行为模式、身份体系缺乏原生数字可追溯性、以及验证环节固有的易受重放攻击的缺陷

Benefits of technology

[0018]综上所述,本申请各实施例提供的智能体身份管理及认证系统与方法,通过引入基于多维度(来源、频率、完整性)的实时量化风险评估与动态分级核验机制,系统能够自动识别注册请求的风险特征并执行差异化处理,适配智能体自动化、行为模式化的特性,从而精准解决了注册环节无法适配自动化行为的缺陷;通过为智能体生成全局唯一的“智能体身份码”,并将其作为核心标识与公钥证书进行强绑定签发,为智能体建立了贯穿其全生命周期的、不可篡改的数字身份凭证链。这实现了身份与行为的精准、可靠追溯,从根本上克服了身份体系缺乏原生数字可追溯性的缺陷;通过在挑战-响应验证中增加服务器端的会话信息缓存与基于该缓存的状态校验机制,确保每一次下发的挑战值仅具一次性效力,使系统能够主动识别并拒绝重放攻击,适配智能体可被恶意复制、指令可重放的特性,彻底弥补了传统方案验证环节固有的易受重放攻击的安全短板;上述技术特征相互关联、协同作用,共同构成了一个从“智能准入”到“可信标识”再到“安全验证”的完整技术闭环,实现了对智能体身份全生命周期的主动、闭环管理,取得了全面提升智能体身份管理体系在自动化、高并发复杂环境下的安全性、可信性与整体效能的显著技术效果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122578332B_ABST
    Figure CN122578332B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of network security and identity authentication, and particularly relates to an intelligent agent identity registration, authentication and credential issuing method and system. The system comprises an intelligent agent, an identity registration device, a credential issuing device, a relying party device and a verification device. In the registration and credential issuing process, the identity registration device dynamically decides the verification path based on multi-dimensional quantitative risk assessment and generates a unique intelligent agent identity code; the credential issuing device strongly binds and issues the identity code with a public key certificate to establish a traceable digital identity. In the authentication and service access process, the verification device generates a challenge and caches the session state, and after receiving the intelligent agent response, not only verifies the signature, but also actively checks the one-off of the challenge based on the cached information, and has the essential anti-replay capability. The application realizes the closed-loop trusted management of the whole life cycle of the intelligent agent identity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network security and identity authentication technology, specifically relating to a method and system for intelligent agent identity registration, authentication and credential issuance. Background Technology

[0002] With the widespread application of autonomous software agents (such as software robots and automated agents) in distributed systems, trusted authentication of their identities has become the cornerstone of ensuring secure system interactions. Agents are characterized by automation, high concurrency, and lack of binding to natural person entities, which leads to systemic incompatibility issues when traditional identity authentication schemes are applied to agents.

[0003] Current mainstream solutions still rely on Public Key Infrastructure (PKI) frameworks. However, because PKI frameworks fail to adapt to the aforementioned characteristics of intelligent agents, existing technical solutions suffer from the following fundamental flaws: First, given the "automatic initiation and patterned behavior" characteristics of intelligent agents, their registration requests exhibit features such as fixed sources and regular frequencies. Existing registration processes employ static, passive review strategies, lacking mechanisms for real-time quantitative risk assessment and dynamic hierarchical verification of dimensions such as request source, frequency, and material completeness. This results in an inability to strike a balance between blocking malicious automated registration and efficiently allowing legitimate intelligent agent registration, leading to insufficient flexibility and risk mitigation capabilities in the registration process, making it difficult to simultaneously ensure security and registration efficiency.

[0004] Secondly, given the "non-physical, purely digital" nature of intelligent agents, their identities rely entirely on digital identifiers and credentials. Current technologies have failed to create a globally unique, cryptographically-bound native digital identity that persists throughout the agent's lifecycle. This results in a fragile connection between the agent's identity account, digital credentials, and its "body," making accurate identity tracing and accountability difficult in the event of credential leakage or misuse, leading to poor traceability in identity lifecycle management.

[0005] Finally, given the characteristics of intelligent agents being "maliciously copyable and their instructions replayable," their authentication process faces a serious risk of replay attacks. Existing PKI frameworks primarily employ a challenge-response mechanism, where the "challenge value," a one-time random number generated by the verifier, serves as a key verification element. Its core function is to allow the requesting party (i.e., the intelligent agent) to verify its signature, thereby confirming that the requesting party indeed possesses the corresponding private key. Existing challenge-response mechanisms generally lack effective caching and lifecycle management mechanisms for the "challenge value" on the verification server. This makes it impossible for the system to reliably verify whether a challenge has been reused, failing to provide fundamental resistance to replay attacks for intelligent agent authentication, thus constituting a serious security weakness.

[0006] In summary, existing technologies suffer from three fundamental problems stemming from the characteristics of intelligent agents: the registration process cannot adapt to automated behavior patterns, the identity system lacks native digital traceability, and the verification process is inherently vulnerable to replay attacks. These problems severely restrict the application of intelligent agent identity authentication technology in complex distributed environments that require high security and high reliability. Summary of the Invention

[0007] This application provides an intelligent agent identity management and authentication scheme, which aims to solve the defects exposed when applying traditional identity authentication schemes to intelligent agents, such as the inability of the registration process to adapt to automated behavior patterns caused by the characteristics of intelligent agents, the lack of native digital traceability of the identity system, and the inherent vulnerability of the verification process to replay attacks.

[0008] A first aspect of this application provides a system for intelligent agent identity registration, authentication, and credential issuance, including an intelligent agent, an identity registration device, a credential issuance device, a dependent device, and a verification device, wherein: The intelligent agent is configured to send an identity registration request to the identity registration device during the intelligent agent identity registration, verification and credential issuance process; generate a public-private key pair after identity verification is passed; provide its public key to the credential issuance device to apply for a public key certificate; and initiate a service access request to the dependent device when access to the service is required during the identity authentication and service access process, and generate a signature in response to the challenge issued by the verification device. The identity registration device is configured to receive an identity registration request sent by the intelligent agent during the intelligent agent identity registration, verification, and credential issuance process; conduct a risk assessment based on at least one dimension of the request's source, frequency, and material completeness; and, based on the risk assessment result, if a preset first condition is met, complete the identity verification of the intelligent agent based on the request; if a preset second condition is met, request the intelligent agent to supplement the identity verification materials and complete the identity verification after the review is approved; and, after the identity verification is passed, establish an identity account for the intelligent agent and generate a unique intelligent agent identity code bound to the identity account. The credential issuance device is configured to receive the public key provided by the intelligent agent during the intelligent agent identity registration, verification and credential issuance process, and issue a corresponding public key certificate based on the public key and the unique intelligent agent identity code generated by the identity registration device. The dependent device is configured to receive a service access request initiated by the agent in the identity authentication and service access process, initiate an identity authentication request for the agent to the verification device, and authorize or deny the agent's access based on the authentication result received from the verification device. The verification device is configured to, in the identity authentication and service access process, receive an identity authentication request from the dependent device, generate a random number for the current authentication session as a challenge, and send the challenge to the agent via the dependent device. Simultaneously, it caches information related to the challenge and the current session, receives a response from the agent forwarded via the dependent device, the response containing at least the public key certificate and a digital signature generated for the challenge based on the private key corresponding to the public key certificate. It verifies the validity of the digital signature using the public key certificate and checks whether the challenge is valid and unused based on the cached information. If both verification and validation pass, it generates an authentication success assertion indicating the agent's legitimate identity and sends it to the dependent device.

[0009] In some embodiments of this application, the verification device is further configured to: Immediately after generating the authentication success assertion, the challenge is invalidated or removed from the cache.

[0010] In some embodiments of this application, the credential issuing device issues corresponding public key certificates, including: The unique agent identity code is used as a verifiable identity identifier and written into a specific extended field of the public key certificate to achieve a cryptographic binding between the public key certificate and the unique agent identity code.

[0011] In some embodiments of this application, the dependent device is further configured to: Based on the service type requested in the service access request or the resource security level involved in the service access request, a corresponding identity authentication strategy is determined, wherein the identity authentication strategy includes at least the complexity requirements of the challenge-response algorithm or the acceptable credential types; the dependent device initiates the identity authentication request to the verification device according to the determined strategy.

[0012] A second aspect of this application provides a method for intelligent agent identity registration and credential issuance, applied to the identity registration device described in the first aspect of this application, including: Receive the identity registration request sent by the intelligent agent; A risk assessment is conducted based on at least one of the following dimensions: the source of the request, its frequency, and the integrity of the materials. Based on the risk assessment results, if the first preset condition is met, the identity verification of the intelligent agent is completed based on the request; if the second preset condition is met, the intelligent agent is requested to supplement the identity verification materials and the identity verification is completed after the review is approved. After identity verification is successful, an identity account is established for the intelligent agent, and a unique intelligent agent identity code is generated and bound to the identity account. The credential issuance device then uses the public key generated by the intelligent agent to issue a public key certificate bound to the unique intelligent agent identity code.

[0013] In some embodiments of this application, the risk assessment based on at least one dimension of the source, frequency, and material integrity of the request includes: A risk score is assigned to the source, frequency, and material integrity of the request; A comprehensive risk score is calculated based on the risk scores of each dimension. The comprehensive risk score is compared with a preset threshold to determine whether the first condition or the second condition is met.

[0014] In some embodiments of this application, generating a unique smart agent identity code bound to the identity account includes: Obtain the agent's attribute information, registration timestamp, random salt value, and public key digest; Input the attribute information, registration timestamp, random salt value, and public key digest into the SM3 hash function; The hash value output by the SM3 hash function is used as the unique identity code of the intelligent agent.

[0015] A third aspect of this application provides a method for intelligent agent identity authentication, applied to the verification device described in the first aspect of this application, comprising: Receive an identity authentication request for a target intelligent agent, wherein the target intelligent agent is an intelligent agent that has been registered and obtained a public key certificate uniquely bound to itself; Generate a random number as a challenge for this identity authentication session, and cache information related to the challenge and this session; Receive a response from the target agent, the response including at least the public key certificate and a digital signature generated by the target agent for the challenge based on the private key corresponding to the public key certificate; The validity of the digital signature is verified using the public key certificate, and the validity of the challenge is verified based on the cached information to ensure it is valid and has not been used. If both verification and validation pass, an authentication success assertion indicating the legitimacy of the target intelligent agent's identity is generated, which is then used by the dependent device to make authorization decisions.

[0016] In some embodiments of this application, generating a random number for this identity authentication session as a challenge includes: Random data is obtained based on a noise generation device; The random number is generated based on the random data; The noise generating device is a physical noise source.

[0017] In some embodiments of this application, verifying whether the challenge is valid and unused based on the cached information includes: Check if the challenge is within a predefined validity period; Check the cache for information related to this session to see if the challenge has been successfully used. If the challenge is within its validity period and has not been indicated as used, the verification is considered successful.

[0018] In summary, the intelligent agent identity management and authentication system and method provided in the embodiments of this application, by introducing a real-time quantitative risk assessment and dynamic hierarchical verification mechanism based on multiple dimensions (source, frequency, integrity), can automatically identify the risk characteristics of registration requests and perform differentiated processing, adapting to the characteristics of intelligent agents' automation and behavioral patterns, thereby accurately solving the defect that the registration process cannot adapt to automated behavior; by generating a globally unique "intelligent agent identity code" for the intelligent agent and strongly binding it with the public key certificate for issuance, an immutable digital identity credential chain that runs through the entire life cycle of the intelligent agent is established. This enables accurate and reliable traceability of identity and behavior, fundamentally overcoming the deficiency of the identity system's lack of native digital traceability. By adding server-side session information caching and a state verification mechanism based on this cache in the challenge-response verification process, it ensures that each issued challenge value has only one-time validity, enabling the system to proactively identify and reject replay attacks. This adapts to the characteristics of intelligent agents being maliciously copied and instructions being replayable, completely compensating for the inherent security shortcomings of traditional solutions in the verification process, which are vulnerable to replay attacks. The above technical features are interconnected and work synergistically to form a complete technical closed loop from "intelligent access" to "trusted identification" to "security verification," realizing proactive and closed-loop management of the entire lifecycle of intelligent agent identity. This has achieved significant technical effects in comprehensively improving the security, trustworthiness, and overall efficiency of the intelligent agent identity management system in automated, high-concurrency, and complex environments. Attached Figure Description

[0019] The features and advantages of this application will become clearer with reference to the accompanying drawings, which are illustrative and should not be construed as limiting the application in any way. In the drawings: Figure 1 These are example diagrams illustrating the intelligent agent identity registration, verification, and credential issuance process according to some embodiments of this application; Figure 2 This is an example diagram of the intelligent agent identity authentication and service access process according to some embodiments of this application; Figure 3 This is a schematic diagram of an intelligent agent identity registration, authentication, and credential issuance system architecture according to some embodiments of this application. Detailed Implementation

[0020] In the following detailed description, numerous specific details of this application are illustrated by example to provide a thorough understanding of the relevant disclosure. However, it will be apparent to those skilled in the art that this application can be practiced without these details. It should be understood that the terms “system,” “apparatus,” “unit,” and / or “module” used in this application are one way of distinguishing different parts, elements, sections, or components at different levels in a sequential arrangement. However, these terms may be replaced with other expressions if other expressions can achieve the same purpose.

[0021] It should be understood that when a device, unit, or module is referred to as being "on," "connected to," or "coupled to" another device, unit, or module, it may be directly connected to or coupled to or communicate with other devices, units, or modules, or there may be intermediate devices, units, or modules present, unless the context explicitly indicates otherwise. For example, the term "and / or" as used herein includes any one and all combinations of one or more of the relevant listed items.

[0022] The terminology used in this application is for the purpose of describing specific embodiments only and is not intended to limit the scope of this application. As shown in the specification and claims of this application, unless the context clearly indicates otherwise, words such as "a," "an," "an," and / or "the" do not specifically refer to the singular and may also include the plural. Generally speaking, the terms "comprising" and "including" only indicate that explicitly identified features, integrals, steps, operations, elements, and / or components are included, and such expressions do not constitute an exclusive list, and other features, integrals, steps, operations, elements, and / or components may also be included.

[0023] Referring to the following description and accompanying drawings, these and other features and characteristics, operating methods, functions of related structural elements, combinations of parts, and economics of manufacture of this application can be better understood, wherein the description and drawings form part of the specification. However, it is clearly understood that the drawings are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. It is understood that the drawings are not drawn to scale.

[0024] Various structural diagrams are used in this application to illustrate various variations of the embodiments according to this application. It should be understood that the preceding or following structures are not intended to limit this application. The scope of protection of this application is determined by the claims.

[0025] Under the trend of software-defined everything architecture, autonomous software agents (hereinafter referred to as "agents"), as automated software entities capable of perception, decision-making, and execution, are becoming core functional units in distributed systems and cloud-native applications. To ensure secure and reliable interaction between agents and between agents and various services, it is necessary to establish and verify unique digital identities for them.

[0026] Currently, solutions for establishing identities for such physical, programmable entities primarily rely on the Public Key Infrastructure (PKI) system and its challenge-response authentication paradigm, designed for "people" or "physical devices." A typical existing technical solution usually consists of the following roles: an identity registration authority (responsible for receiving applications), a certificate authority (responsible for issuing digital certificates), a dependent party (service provider), and a verifier. The core process can be summarized as follows: 1) The subject submits information to the identity registration authority to complete registration; 2) The subject generates a key pair, and the certificate authority (CA) issues a digital certificate containing identity information (i.e., an X.509 certificate) for its public key; 3) When the subject accesses the dependent party's service, the verifier generates a random number (i.e., a "challenge") and sends it to the subject. The subject signs the challenge using its private key and returns it. The verifier verifies the signature to confirm its identity.

[0027] However, when the above standard paradigm is directly applied to intelligent agents with core characteristics such as "automation, high concurrency, no entity binding, and precise reproducibility of behavior," the solution exhibits systemic incompatibility in both process architecture and security design, specifically manifested as follows: In the registration and access process, existing solutions adopt a static, indiscriminate review process for registration requests that lacks risk quantification. This makes it impossible to conduct real-time risk perception and quantitative assessment of the high-frequency and regular automated registration behavior of intelligent agents, and even more impossible to dynamically adjust the verification strategy based on the assessment results. As a result, it is difficult to balance between malicious registration defense and efficient access of legitimate intelligent agents, which has become a prominent contradiction between security and efficiency.

[0028] In the identity identification and binding process, existing solutions lack a technically enforced, globally unique, and cryptographically verifiable link between the identity account established for the intelligent agent and the subsequently issued digital certificate. The connections between key elements such as identity information, account ID, and public key certificates are loose. Once credential misuse or behavioral auditing occurs, it is difficult to achieve accurate and non-repudiable identity tracing and behavioral accountability at the technical level.

[0029] In the identity verification process, existing challenge-response mechanisms focus on verifying cryptographic signatures, but generally lack proactive, closed-loop state management of the challenge value itself throughout its lifecycle on the verification server. This means that an eavesdropped challenge-response pair may be replayed by a malicious agent within its validity period, and the verifier cannot identify and reject it through technical mechanisms, making replay attacks targeting agent identities a real and highly probable security threat.

[0030] To systematically address the aforementioned deficiencies, this application proposes an identity management and authentication scheme specifically designed for intelligent agents. By constructing a collaborative system covering registration access, credential binding, and anti-replay authentication, it achieves trusted management of the entire lifecycle of intelligent agent identities.

[0031] like Figure 1 (Example diagram of the intelligent agent identity registration, verification, and credential issuance process in this application) As shown, this application constructs an identity registration and credential issuance system in which an intelligent agent, an identity registration device, and a credential issuance device work collaboratively. The identity registration device and the credential issuance device... Figure 1 The process is implemented by an authentication service platform and a Certificate Authority (CA), respectively. Its core lies in the following: After receiving a registration request from an intelligent agent, the identity registration device performs a real-time risk assessment based on multi-dimensional quantitative standards and dynamically determines the verification path according to the risk level. Upon successful verification, the identity registration device generates a globally unique intelligent agent identity code for the intelligent agent. The intelligent agent then generates a key pair and applies for a certificate from a credential issuance device. The credential issuance device issues a strongly bound digital certificate based on the public key and the unique intelligent agent identity code. This process forms the foundation for the creation and initialization of a trusted intelligent agent identity.

[0032] like Figure 2 (Example diagram of the agent identity authentication and service access process in this application) As shown, based on the issued digital certificate, this application implements identity authentication for agents accessing services. This process involves three-party interaction between the agent, the dependent device, and the verification device, wherein the dependent device and the verification device... Figure 2 The process is implemented by service components and authentication services, respectively. Its core is as follows: When an agent initiates access, the dependent device requests an authentication policy from the verification device and obtains a one-time random challenge; subsequently, the dependent device sends the challenge to the agent, which signs the challenge using its private key and returns it; the dependent device forwards the agent's response to the verification device, which not only verifies the validity of the signature but also proactively checks whether the challenge has been used for the first time by querying its own cached session state, thus building a proactive anti-replay capability on top of the standard challenge-response mechanism.

[0033] In conclusion, this application is approved. Figure 1The process shown, which involves "dynamic risk assessment registration, unique identity code generation, and binding certificate issuance," is similar to... Figure 2 The "challenge state caching and active verification" anti-replay authentication process shown combines the establishment, use and verification of trusted identity, and systematically solves the above-mentioned defects of existing technologies.

[0034] The specific embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0035] Figure 3 This is a schematic diagram of a smart agent identity registration, authentication, and credential issuance system architecture according to some embodiments of this application. Figure 3 As shown, the system includes an intelligent agent, an identity registration device, a credential issuance device, a dependent device, and a verification device. These devices work together to realize the intelligent agent's identity registration, verification, and credential issuance processes, as well as the intelligent agent's identity authentication and service access processes.

[0036] The intelligent agent, such as a software robot or automated agent, is configured to send an identity registration request to an identity registration device during the intelligent agent identity registration, verification, and credential issuance process; and to initiate a service access request to a dependent device during the intelligent agent identity authentication and service access process.

[0037] The identity registration device is configured to perform identity verification and account establishment for intelligent agents during the intelligent agent identity registration, verification, and credential issuance process. Specifically, it is used to: receive registration requests from intelligent agents; conduct real-time risk assessments based on multiple dimensions such as the source of the request, request frequency, and the completeness of the attached materials; determine, based on the risk assessment results, whether to directly complete the verification of the intelligent agent or require it to supplement verification materials; and, upon successful verification, establish an identity account for the intelligent agent and generate a unique intelligent agent identity code bound to that account.

[0038] The credential issuance device is configured to issue digital credentials during the agent identity registration, verification, and credential issuance process. Specifically, it is used to: receive a public key provided by the agent; based on the public key and a unique agent identity code generated by the identity registration device, issue a public key certificate bound to the identity code, and return the certificate to the agent.

[0039] The dependent device is configured to act as a service provider and access control point in the agent identity authentication and service access process. Specifically, it is used to: receive a service access request from an agent and determine an identity authentication policy based on the request; initiate an identity authentication request for the agent to the authentication device; and authorize or deny the agent's access based on the authentication result received from the authentication device.

[0040] The verification device is configured to perform online verification of the agent's identity during the agent identity authentication and service access process. Specifically, it is used to: receive an identity authentication request from a dependent device; generate a random number as a challenge for this authentication session and cache session information related to the challenge; receive the agent's signed response to the challenge; verify the validity of the signature using the agent's public key certificate and check whether the challenge is valid and unused based on the cached session information; and finally generate an assertion indicating successful or failed authentication and return it to the dependent device.

[0041] In some preferred embodiments, the devices in the system can achieve enhanced security and manageability through the following configuration: Regarding the final state management of the challenge state of the verification device: The verification device is further configured to invalidate the challenge immediately after generating the successful authentication assertion. Specifically, the verification device can mark the challenge as "used" by updating the cached session state information, or directly remove the challenge and its associated information from the session cache, to ensure that the challenge cannot be used for verification again. This design completely eliminates the possibility of credential replay from the state management mechanism, thus perfecting the security closed loop of the identity authentication process.

[0042] Regarding the implementation of certificate binding in the certificate issuance device: When issuing a corresponding public key certificate, the credential issuing device implements the following method: It writes the unique agent identity code generated by the identity registration device, as the core identity identifier, into the issued public key certificate, thereby making this identity code an inherent component of the certificate data. Through this operation, the public key certificate forms a strong binding relationship with the unique agent identity code at the cryptographic level. This binding relationship ensures that the public key certificate not only proves the legitimacy of the public key but also becomes a verifiable digital carrier of the specific agent's identity.

[0043] Regarding the determination of the identification strategy for dependent devices: The dependent device is further configured to have policy decision-making capabilities. Upon receiving a service access request from an agent, it dynamically determines the specific requirements for authentication based on the type of service involved in the request (e.g., data access, control command execution, etc.) or the security level of the requested resource. The determined authentication policy may explicitly include requirements for the security strength of the challenge-response algorithm or specify the type of credentials the agent must provide. Subsequently, the dependent device initiates an authentication request with explicit security requirements to the verification device according to this policy, thereby achieving dynamic adaptation between access control and security risks.

[0044] The following is combined with Figure 1The interactive flow shown describes in detail the specific implementation details of the intelligent agent identity registration, verification, and credential issuance process in the embodiments of this application.

[0045] Step 1: Send an identity registration request.

[0046] Based on its type, the security level of its environment, and the system's preset policies, the intelligent agent selectively registers with the identity registration device (in...). Figure 1 The authentication service platform sends a registration request with or without identity verification materials.

[0047] Step 2, Identity Registration and Risk Assessment.

[0048] After receiving the request, the identity registration device performs a core quantitative risk assessment and decision-making process. This includes: Quantitative scoring: The identity registration device initiates a risk assessment, assigning risk scores to three dimensions—source, frequency, and completeness of materials—based on preset rules. For example, according to the quantification rules, in the source dimension: requests originating from trusted internal networks are rated as low risk (0-30 points); requests from known partner networks are rated as medium-low risk (31-60 points); and requests from unknown public IP addresses are rated as high risk (61-100 points).

[0049] Calculate the overall score: Input the scores from the three dimensions mentioned above into the calculation model to obtain a comprehensive risk score.

[0050] Tiered verification decision: The comprehensive risk score is compared with a preset threshold. If the score is lower than or equal to the threshold, the identity registration device completes the verification directly based on the existing materials; if the score is higher than the threshold, step 3 is triggered.

[0051] Step 3: Based on the risk assessment results, provide identity verification materials.

[0052] The identity registration device sends a notification to the intelligent agent, requesting it to provide more complete (or supplementary) identity verification materials.

[0053] Step 4, supplement materials.

[0054] The intelligent agent provides the identity registration device with the corresponding identity verification materials upon request.

[0055] Step 5: Complete identity verification, generate an identity account, and generate an agent identity code.

[0056] After receiving and verifying the submitted materials, the identity registration device establishes an identity account for the agent and generates a unique agent identity code. The specific generation process includes: Obtain the generating factor: This includes attribute information such as the agent's name, type, and ID; the timestamp of this registration; a random salt value generated by the identity registration device; and a digest of the agent's public key.

[0057] All the above factors are combined in a predetermined order and used as input to the national cryptographic SM3 hash function for calculation.

[0058] The hash value output by the SM3 hash function is used as a globally unique agent identity code and bound to the agent's identity account.

[0059] Step 6: Return registration result information.

[0060] The identity registration device will return information such as successful registration and the generated agent identity code to the agent.

[0061] Step 7: Generate a dedicated public-private key pair.

[0062] The agent uses domestically developed asymmetric encryption algorithms such as SM2 locally to generate a unique public-private key pair.

[0063] Step 8: Request the generation of identity-verifiable credentials (provide the public key).

[0064] Intelligent agents to credential issuing devices (in) Figure 1 The Certificate Authority (CA) initiates a credential request and submits its public key.

[0065] Step 9: Request the generation of certificate credentials associated with the intelligent agent.

[0066] After receiving the application, the certificate issuing device prepares to generate the certificate.

[0067] Step 10: Sign to generate relevant certificate credentials.

[0068] The credential issuing device writes the unique agent identity code generated in step 5 into the certificate data structure and signs the certificate using its own private key, thereby generating a public key certificate strongly bound to the agent's identity.

[0069] Step 11: Return the issued voucher.

[0070] The credential issuing device returns the issued public key certificate to the smart agent.

[0071] Step 12: Return the issued voucher to complete the process.

[0072] The intelligent agent receives and stores the public key certificate.

[0073] At this point, the process of registering, verifying, and issuing credentials for intelligent agents is complete.

[0074] The following is combined with Figure 2 The interactive flow shown describes in detail the specific implementation details of the agent identity authentication and service access process in the embodiments of this application.

[0075] Step 1, Identity Authentication Request.

[0076] intelligent agents to dependent devices (in) Figure 2 (The service access request is initiated by the service component).

[0077] Step 2, agent identity authentication strategy.

[0078] The dependent device determines the strategy required for this authentication based on the type of service requested or the security level of the resources involved.

[0079] Step 3: Based on the authentication strategy, submit an identity authentication request to the verification party.

[0080] Dependent device to verification device (in) Figure 2 (The authentication service in the middle) forwards the identity verification request.

[0081] Step 4: Generate the identification challenge based on the identification strategy.

[0082] The verification device generates the challenge required for this authentication. Specifically, the verification device acquires random data based on physical noise sources and generates a truly random number with unpredictability as the challenge value for this authentication. At the same time, the verification device stores the challenge value, session identifier, and generation timestamp, among other information, in a local cache.

[0083] Step 5: Return the relevant identification parameters.

[0084] The verification device returns the generated challenge and related parameters to the dependent device.

[0085] Step 6: Return the identification method and related parameters.

[0086] The dependent device returns the identification method and related parameters to the agent.

[0087] Step 7: Submit the agent's credentials certificate.

[0088] The intelligent agent uses its private key to digitally sign the received challenge and encapsulates its public key certificate and signature value into a process credential package, which is then submitted to the dependent device.

[0089] Step 8: Submit identity credentials (including certificate and signature value).

[0090] The dependent device forwards the identity credentials (process credential package) submitted by the agent to the verification device.

[0091] Step 9: Verify the credential packet during the forwarding process.

[0092] (After the dependent device forwards the request,) the verification device receives the process credential packet.

[0093] Step 10: Parse the credential packet and verify the identity.

[0094] The verification device performs core credential verification and anti-replay status checks. This step sequentially executes the following sub-operations: Analysis and extraction: The digital certificate and signature value are parsed from the process credential package.

[0095] Certificate verification: Verify the validity of the certificate (e.g., issuer, validity period).

[0096] Challenge Status Verification: Perform a replay protection check. First, check if the challenge used this time is within the predefined valid time window; second, query the local cache to confirm whether the challenge has already been used.

[0097] Signature verification: Extract the public key from the certificate and verify whether the signature value was correctly generated by the corresponding private key for this challenge.

[0098] Overall judgment: Identity verification is considered successful only when certificate verification, challenge status verification, and signature verification all pass.

[0099] Step 11: Return the identification results and other information.

[0100] The verification device generates an authentication assertion containing session state details based on the result of step 10. If authentication is successful, the verification device immediately destroys the challenge for this session (e.g., by removing it from the cache or marking it as permanently invalid), strictly prohibiting its reuse. Subsequently, the verification device returns the authentication assertion to the dependent device.

[0101] Step 12: Determine subsequent services or access requests based on the identification results.

[0102] The dependent device receives the authentication assertion returned by the verification device, performs final confirmation by verifying the matching of the session state carried in the assertion with the local record, and authorizes or denies the agent's access request accordingly.

[0103] Step 13: If identity verification is successful, allow subsequent connection establishment.

[0104] If the authentication is successful, the dependent device allows the agent to establish a service connection with it and conduct subsequent business interactions.

[0105] At this point, the agent's identity authentication and service access process is complete.

[0106] The foregoing embodiments are based on Figure 1 and Figure 2 This paper describes a typical process in which the identity registration device, credential issuance device, dependent device, and verification device work together as logically independent components. In actual deployment, the functions of the above devices can have different physical or logical integration forms, and this application also supports such implementations.

[0107] Integration and implementation of intelligent agent identity registration, verification, and credential issuance processes: In a preferred embodiment, the functions of the identity registration device and the credential issuance device can be carried out by the same entity platform. For example, the authentication service platform logically includes an "identity registration module" and a "credential issuance module." Under this implementation, Figure 1 Steps 8 to 12 will be completed within the platform through inter-module calls. The core logic functions and interactive data flow of identity registration and credential issuance are completely consistent with the separate deployment implementation.

[0108] 2. Integration of the verification device and dependent devices: In another embodiment, the functions of the dependent device and the verification device can be integrated within the same service gateway. In this implementation, Figure 2 The interaction process will be completed within the integrated gateway through inter-module calls. The core functional division of the dependent party being responsible for receiving requests, determining policies, and making authorization decisions, and the verifier being responsible for generating challenges and performing verification remains unchanged.

[0109] In summary, the intelligent agent identity management and authentication system and method provided in the embodiments of this application, by introducing a real-time quantitative risk assessment and dynamic hierarchical verification mechanism based on multiple dimensions (source, frequency, integrity), can automatically identify the risk characteristics of registration requests and perform differentiated processing, adapting to the characteristics of intelligent agents' automation and behavioral patterns, thereby accurately solving the defect that the registration process cannot adapt to automated behavior; by generating a globally unique "intelligent agent identity code" for the intelligent agent and strongly binding it with the public key certificate for issuance, an immutable digital identity credential chain that runs through the entire life cycle of the intelligent agent is established. This enables accurate and reliable traceability of identity and behavior, fundamentally overcoming the deficiency of the identity system's lack of native digital traceability. By adding server-side session information caching and a state verification mechanism based on this cache in the challenge-response verification process, it ensures that each issued challenge value has only one-time validity, enabling the system to proactively identify and reject replay attacks. This adapts to the characteristics of intelligent agents being maliciously copied and instructions being replayable, completely compensating for the inherent security shortcomings of traditional solutions in the verification process, which are vulnerable to replay attacks. The above technical features are interconnected and work synergistically to form a complete technical closed loop from "intelligent access" to "trusted identification" to "security verification," realizing proactive and closed-loop management of the entire lifecycle of intelligent agent identity. This has achieved significant technical effects in comprehensively improving the security, trustworthiness, and overall efficiency of the intelligent agent identity management system in automated, high-concurrency, and complex environments.

[0110] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the devices and modules described above can be referred to the corresponding descriptions in the foregoing device embodiments, and will not be repeated here.

[0111] Although the subject matter described herein is provided in the general context of execution on a computer system in conjunction with an operating system and applications, those skilled in the art will recognize that other implementations can also be executed in conjunction with other types of program modules. Generally, program modules include routines, programs, components, data structures, and other types of structures that perform specific tasks or implement specific abstract data types. Those skilled in the art will understand that the subject matter described herein can be practiced using other computer system configurations, including handheld devices, multiprocessor systems, microprocessor-based or programmable consumer electronics, minicomputers, mainframes, etc., and can also be used in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules may reside on both local and remote memory storage devices.

[0112] Those skilled in the art will recognize that the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0113] It should be understood that the specific embodiments described above are merely illustrative or explanatory of the principles of this application and do not constitute a limitation thereof. Therefore, any modifications, equivalent substitutions, improvements, etc., made without departing from the spirit and scope of this application should be included within the protection scope of this application. Furthermore, the appended claims are intended to cover all variations and modifications falling within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.

Claims

1. A system for intelligent agent identity registration, authentication, and credential issuance, characterized in that, It includes intelligent agents, identity registration devices, credential issuance devices, dependent devices, and verification devices, among which: The intelligent agent is configured to send an identity registration request to the identity registration device during the intelligent agent identity registration, verification, and credential issuance process; generate a public-private key pair after the identity verification is passed; provide its public key to the credential issuance device to apply for a public key certificate; and initiate a service access request to the dependent device during the intelligent agent identity authentication and service access process when it needs to access the service, and generate a signature in response to the challenge issued by the verification device. The identity registration device is configured to receive an identity registration request sent by the intelligent agent during the intelligent agent identity registration, verification, and credential issuance process; conduct a risk assessment based on at least one dimension of the request's source, frequency, and material completeness; and, based on the risk assessment result, if a preset first condition is met, complete the identity verification of the intelligent agent based on the request; if a preset second condition is met, request the intelligent agent to supplement the identity verification materials and complete the identity verification after the review is approved; and, after the identity verification is passed, establish an identity account for the intelligent agent and generate a unique intelligent agent identity code bound to the identity account. The credential issuance device is configured to receive the public key provided by the intelligent agent during the intelligent agent identity registration, verification and credential issuance process, and issue a corresponding public key certificate based on the public key and the unique intelligent agent identity code generated by the identity registration device. The dependent device is configured to receive a service access request initiated by the intelligent agent in the intelligent agent identity authentication and service access process, and to initiate an identity authentication request for the intelligent agent to the verification device, and to authorize or deny the intelligent agent's access based on the authentication result received from the verification device. The verification device is configured to, in the agent identity authentication and service access process, receive an identity authentication request from the dependent device, generate a random number for the current authentication session as a challenge, and send the challenge to the agent via the dependent device. Simultaneously, it caches information related to the challenge and the current session, receives a response from the agent forwarded via the dependent device, the response containing at least the public key certificate and a digital signature generated for the challenge based on the private key corresponding to the public key certificate. It verifies the validity of the digital signature using the public key certificate and checks whether the challenge is valid and unused based on the cached information. If both verification and validation pass, it generates an authentication success assertion indicating the agent's legitimate identity and sends it to the dependent device.

2. The system according to claim 1, characterized in that, The verification device is further configured to: Immediately after generating the authentication success assertion, the challenge is invalidated or removed from the cache.

3. The system according to claim 1, characterized in that, The credential issuance device issues corresponding public key certificates, including: The unique agent identity code is used as a verifiable identity identifier and written into a specific extended field of the public key certificate to achieve a cryptographic binding between the public key certificate and the unique agent identity code.

4. The system according to claim 1, characterized in that, The dependent device is also configured to: Based on the service type requested in the service access request or the resource security level involved in the service access request, a corresponding identity authentication strategy is determined, wherein the identity authentication strategy includes at least the complexity requirements of the challenge-response algorithm or the acceptable credential types; the dependent device initiates the identity authentication request to the verification device according to the determined strategy.

5. A method for intelligent agent identity registration and credential issuance, applied to the identity registration device as described in claim 1, characterized in that, include: Receive the identity registration request sent by the intelligent agent; A risk assessment is conducted based on at least one of the following dimensions: the source of the request, its frequency, and the integrity of the materials. Based on the risk assessment results, if the first preset condition is met, the identity verification of the intelligent agent is completed based on the request; if the second preset condition is met, the intelligent agent is requested to supplement the identity verification materials and the identity verification is completed after the review is approved. After identity verification is successful, an identity account is established for the intelligent agent, and a unique intelligent agent identity code is generated and bound to the identity account. The credential issuance device then uses the public key generated by the intelligent agent to issue a public key certificate bound to the unique intelligent agent identity code.

6. The method according to claim 5, characterized in that, The risk assessment based on at least one dimension of the request's source, frequency, and material integrity includes: A risk score is assigned to the source, frequency, and material integrity of the request; A comprehensive risk score is calculated based on the risk scores of each dimension. The comprehensive risk score is compared with a preset threshold to determine whether the first condition or the second condition is met.

7. The method according to claim 5, characterized in that, The generation of a unique smart agent identity code bound to the identity account includes: Obtain the agent's attribute information, registration timestamp, random salt value, and public key digest; Input the attribute information, registration timestamp, random salt value, and public key digest into the SM3 hash function; The hash value output by the SM3 hash function is used as the unique identity code of the intelligent agent.

8. A method for intelligent agent identity authentication, applied to the verification device as described in claim 1, characterized in that, include: Receive an identity authentication request for a target intelligent agent, wherein the target intelligent agent is an intelligent agent that has been registered and obtained a public key certificate uniquely bound to itself; Generate a random number as a challenge for this identity authentication session, and cache information related to the challenge and this session; Receive a response from the target agent, the response including at least the public key certificate and a digital signature generated by the target agent for the challenge based on the private key corresponding to the public key certificate; The validity of the digital signature is verified using the public key certificate, and the validity of the challenge is verified based on the cached information to ensure it is valid and has not been used. If both verification and validation pass, an authentication success assertion indicating the legitimacy of the target intelligent agent's identity is generated, which is then used by the dependent device to make authorization decisions.

9. The method according to claim 8, characterized in that, The challenge to generate a random number for this identity authentication session includes: Random data is obtained based on a noise generation device; The random number is generated based on the random data; The noise generating device is a physical noise source.

10. The method according to claim 8, characterized in that, The verification of whether the challenge is valid and unused based on the cached information includes: Check if the challenge is within a predefined validity period; Check the cache for information related to this session to see if the challenge has been successfully used. If the challenge is within its validity period and has not been indicated as used, the verification is considered successful.

Citation Information

Patent Citations

  • Distributed trusted virtual human identity authentication system and method based on block chain

    CN119989324A

  • System for realizing trusted authentication of financial agent based on distributed digital identity

    CN120811758A