Subsidiary digital identity establishment method, legal digital identity establishment method and digital identity management system
By issuing and associated with an affiliated digital identity certificate through the legal digital identity terminal, the data source uncertainty and security risks of the 'middleman' framework system are solved, effective supervision and privacy protection of user-side operations are achieved, and the credibility of information transmission is improved.
Patent Information
- Application Number
- PCT/CN2025/071756
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-29
- Filing Date
- 2025-01-10
- Publication Date
- 2025-08-07
AI Technical Summary
In the prior art, the 'middleman' framework system cannot determine the authenticity of the data source, poses security risks, cannot effectively protect customer privacy, cannot meet the requirements of digital signature law, and there are regulatory problems in the decentralized blockchain identity system.
Establish a secure connection with the user through the legal digital identity terminal, receive and review the information on the affiliated digital identity, issue the affiliated digital identity certificate, and associate it with the legal digital identity identification identification, combine it with a complete and simple legal digital identity certificate to protect personal privacy, and use the regional certificate management server for supervision.
It realizes effective tracking and supervision of user-side operations, reduces the spread of information spam, enhances the credibility of information transmission, protects personal privacy, and meets the reliability and regulatory requirements of legal digital identity terminals.
Smart Images

Figure CN2025071756_07082025_PF_FP_ABST
Abstract
Description
A method for establishing a subsidiary digital identity, a method for establishing a legal digital identity, and a digital identity management system Technical Field
[0001] The present application belongs to the field of digital information technology and relates to a method for establishing an affiliated digital identity, a method for establishing a legal digital identity, and a digital identity management system. Background Art
[0002] Based on the current TCP / IP communication protocol, in order to clarify the data sending identity and data receiving identity of the target data, a "middleman server" (hereinafter referred to as "middleman") has to be used. That is, during the user login process, the "middleman" confirms the user's identity through the user's registered account and password. During the information interaction process, the data sender forwards the target data to the data receiver through the "middleman".
[0003] However, introducing a framework system that uses a "middleman" to determine identity will raise many new technical issues:
[0004] First, the current "middleman" framework system cannot determine the true source of the data received by the current "middleman": Take the increasingly popular artificial intelligence as an example: natural persons, as the owners of artificial intelligence, need to be responsible for the behavior of artificial intelligence devices. However, the current "middleman" framework system increases the difficulty for data receivers to distinguish whether the received information is generated by natural persons or artificial intelligence devices. To a certain extent, it will block human supervision and responsibility for the behavior of artificial intelligence devices, which poses a huge risk. For example: intellectual property is one of the most important assets of mankind. If the original source of intellectual property cannot be effectively authenticated, the interests of the true creators of intellectual property cannot be effectively protected.
[0005] Secondly, the current "middleman" framework presents significant security risks: Due to the interdependence between "middlemen" in the customer service chain, security and reliability issues with any one "middleman" will lead to problems for all associated service providers, multiplying security risks.
[0006] Thirdly, the current "middleman" framework cannot effectively protect customer privacy: when three or more service providers are required to participate at the same time, and each party uses its own server, one service provider will act as the user of another service provider, ultimately forming a customer service chain. Because each service provider has different information requirements for customers, excessive information collection is inevitable;
[0007] From this, once authoritative or credible information leaves the "middleman" server it can rely on, its authority or credibility will decline, thus fostering an environment where information islands are created and restricting the further development of the digital economy.
[0008] From a macroeconomic perspective, a digital economy reliant on "middlemen" can be compared to a feudal digital economy, where the "middlemen" are lords. Lords often set the rules of their territories based on their own interests, and these rules may be inconsistent with the needs of social development. When the digital economy becomes the mainstay of the economy, the "middleman" system cannot guarantee the rights and interests of social members in the digital space. The "middleman" system can only grant digital identities valid within the territory. Once you leave the territory, your digital identity is lost, and your digital rights and interests are no longer protected. For example, a salesperson builds a sales network in a social "middleman" territory. This sales network is the salesperson's digital asset. If the salesperson leaves the "middleman" territory for any reason, they lose their digital identity within that territory, and with it, their digital assets.
[0009] Finally, the current "middleman" framework system does not meet the requirements of the Digital Signature Act: the Digital Signature Act requires that the signer is the only holder of the signature secret text. Even if the "middleman" establishes a virtual machine on the cloud corresponding to each user with all files encrypted, if the signing program needs to be run on the virtual machine, it will not meet the requirements of the Digital Signature Act because the memory used by the virtual machine is difficult to meet the physical isolation requirements.
[0010] In addition to the technical issues mentioned above, the current internet presents numerous other challenges in information exchange. For example, messages received by data receivers may undergo multiple copies, summaries, and processing during transmission, rendering them unreliable. This is particularly true when large amounts of data are collected from diverse sources. Without an effective mechanism for verifying the source of messages, users will be unable to distinguish between reliable and fraudulent messages. To address this technical issue, in current communication systems, when a user wants to send target data to another, they must first physically bind it. For example, binding a line to a time slot, binding a frame relay to a frame address, binding an IP address to an IP address, or binding a "middleman" to a server account. While these binding operations help identify the sender and receiver of target data, they reduce the real-time nature and flexibility of communication. However, once disconnected from a trusted publishing server or unbound from the server, the target data becomes a "three-no product": no source, no warranty, and no date. It is foreseeable that the application of these "three-no products" in the fields of artificial intelligence and children's education will create unpredictable risks.
[0011] Humanity is currently experiencing an information explosion, evolving from an era of information scarcity to one of information abundance and extreme information pollution. Reducing information pollution is crucial to the further development of the information society, and technically tracing the sources of information waste and pollution is fundamental to its healthy development. Digital identity can be used to directly identify the source of information and is the foundation for information traceability. Web3, as it is currently known, enables individuals to own and control their own identity information. Through decentralized blockchain identity systems, users can securely manage and verify their identities without relying on centralized identity verification agencies. However, decentralized blockchain identity systems present challenges such as difficulty in privacy protection, immutability and revocability, delayed confirmation, and difficulty adapting to regulatory requirements. For the digital economy, the regulatory requirements for Web3 digital identity are an unavoidable requirement. Summary of the Invention
[0012] The purpose of this application is to overcome the deficiencies in the prior art and to provide a method for establishing a subsidiary digital identity, a method for establishing a legal digital identity, and a digital identity management system, which can achieve effective supervision and safe use of digital identities.
[0013] To achieve the above objectives, this application is implemented using the following technical solutions:
[0014] In a first aspect, the present application provides a method for establishing a subsidiary digital identity, comprising:
[0015] After establishing a secure connection with the user terminal, the legal digital identity terminal receives the user terminal's supplementary digital identity application information;
[0016] The legal digital identity terminal reviews and authenticates the supplementary digital identity application information;
[0017] The legal digital identity terminal signs a supplementary digital identity certificate for the user terminal that has passed the review and authentication, and issues the supplementary digital identity certificate to the user terminal;
[0018] Among them, the legal digital identity terminal is installed with a legal digital identity certificate and holds the private key of the legal digital identity certificate; the legal digital identity certificate installed by the legal digital identity terminal and the subsidiary digital identity certificate issued by it are associated through a legal digital identity identification identifier.
[0019] In combination with the first aspect, further, the legal digital identity certificate includes a full legal digital identity certificate and at least one simplified legal digital identity certificate;
[0020] The complete legal digital identity certificate contains at least the complete identity identification information required by law for the natural person or legal person;
[0021] The simplified legal digital identity certificate carries minimum personal information based on the user's personal privacy protection needs; the minimum personal information includes anonymous information.
[0022] In combination with the first aspect, further, the legal digital identity identification identifier is unique and at least includes the region information of the issuer of the legal digital identity certificate.
[0023] In combination with the first aspect, further, the legal digital identity identification identifier includes a description byte, a country code, a region code, and an identity number;
[0024] The description byte is used to describe the structure of the legal digital identity identification mark;
[0025] The country number is used to describe the country information that issued the root certificate;
[0026] The region code is used to describe the region information for issuing the regional certificate;
[0027] The identity number is used to describe unique digital identity information.
[0028] In combination with the first aspect, further, the legal digital identity certificate is issued by one or more regional certificate management servers that have regional certificates installed and hold the private keys of the corresponding regional certificates; when the legal digital identity certificate is jointly issued by multiple regional certificate management servers, the multiple regional certificate management servers are respectively installed with different regional certificates of the same region and hold the private keys of the corresponding regional certificates;
[0029] In which, the regional certificate is issued by one or more national certificate management servers that have installed a root certificate and hold the private key of the corresponding root certificate; when the regional certificate is jointly issued by multiple national certificate management servers, the multiple national certificate management servers are respectively installed with different root certificates of the same country and hold the private keys of the corresponding root certificates.
[0030] In combination with the first aspect, further, the legal digital identity certificate is installed in the legal digital identity terminal after being authenticated by a certificate chain consisting of the root certificate and the regional certificate;
[0031] The subsidiary digital identity certificate is installed on the user terminal after being authenticated by a certificate chain consisting of the root certificate, the regional certificate and the legal digital identity certificate.
[0032] In combination with the first aspect, further, the private key of the legal digital identity certificate, and / or the private key of the regional certificate, and / or the private key of the root certificate are encrypted and protected by a password, and / or biometrics, and / or physically protected by a dedicated chip.
[0033] In combination with the first aspect, further, the root certificate is issued through block code, website announcement, application pre-installation and / or blockchain, and provides multiple verifications.
[0034] In combination with the first aspect, further, the subsidiary digital identity certificate also includes a subsidiary digital identity identification identifier for describing the subsidiary digital identity, and / or an authority identifier for characterizing the use authority of the subsidiary digital identity certificate, and / or a subsidiary digital identity abbreviation.
[0035] In combination with the first aspect, further, the authority identifier can be extended through an authority extension certificate.
[0036] In combination with the first aspect, further, the supplementary digital identity application information at least includes identity identification information that can uniquely identify the user terminal.
[0037] In combination with the first aspect, further, after issuing the subsidiary digital identity certificate to the user terminal, the method further includes:
[0038] Receiving the certificate serial number and digital signature returned by the user terminal after installing the supplementary digital identity certificate;
[0039] Performing signature authentication on the digital signature, and after the signature authentication passes, adjusting the status of the subsidiary digital identity certificate corresponding to the certificate serial number to enabled;
[0040] The subsidiary digital identity certificate and certificate serial number are filed.
[0041] In combination with the first aspect, further, after issuing the subsidiary digital identity certificate to the user terminal, the method further includes:
[0042] Adjusting the status of the subsidiary digital identity certificate,
[0043] and / or,
[0044] The authority of the user end that obtains the attached digital identity certificate is adjusted through the authority extension certificate.
[0045] In combination with the first aspect, further, the holder of the legal digital identity terminal includes a natural person or legal person who can independently bear legal responsibility; the holder of the legal digital identity terminal bears full legal responsibility for the behavior of the user terminal holding the affiliated digital identity certificate issued by it; wherein, the behavior of the user terminal only includes behavior within the scope of authority explicitly authorized by the legal digital identity terminal.
[0046] In combination with the first aspect, further, after the subsidiary digital identity certificate is issued to the user terminal, the legal liability agreement is digitally signed and filed;
[0047] Among them, the legal liability agreement includes the agreement that the holder of the legal digital identity terminal bears all legal responsibilities for the actions of the user terminal of the attached digital identity certificate issued by it, and the actions of the user terminal only include actions within the scope of authority authorized by the legal digital identity terminal to the user terminal.
[0048] In a second aspect, the present application provides a legal digital identity terminal, comprising:
[0049] Application information receiving module: used to receive the user's supplementary digital identity application information after establishing a secure connection with the user;
[0050] Audit and authentication module: used to audit and authenticate the application information of the subsidiary digital identity;
[0051] Certificate signing and issuing module: used for signing the subsidiary digital identity certificate for the user terminal that has passed the audit and authentication, and issuing the subsidiary digital identity certificate to the user terminal;
[0052] Among them, the legal digital identity terminal is installed with a legal digital identity certificate and holds the private key of the legal digital identity certificate; the legal digital identity certificate installed by the legal digital identity terminal and the subsidiary digital identity certificate issued by it are associated through a legal digital identity identification identifier.
[0053] In conjunction with the second aspect, further comprising:
[0054] Return information receiving module: used to receive the certificate serial number and digital signature returned by the user end after installing the subsidiary digital identity certificate;
[0055] Signature authentication module: used to perform signature authentication on the digital signature, and after the signature authentication is passed, adjust the status of the subsidiary digital identity certificate corresponding to the certificate serial number to enabled;
[0056] Filing module: used to file the subsidiary digital identity certificate and certificate serial number.
[0057] In conjunction with the second aspect, further comprising:
[0058] Digital signature module: used to digitally sign and file the legal liability agreement after issuing the subsidiary digital identity certificate to the user terminal;
[0059] Among them, the legal liability agreement includes the agreement that the holder of the legal digital identity terminal bears all legal responsibilities for the actions of the user terminal of the attached digital identity certificate issued by it, and the actions of the user terminal only include actions within the scope of authority authorized by the legal digital identity terminal to the user terminal.
[0060] In a third aspect, this application provides a method for establishing a legal digital identity, including:
[0061] Sending the region information of the terminal applying for establishing a legal digital identity to the application access server, so that the application access server can determine the corresponding regional certificate management server according to the region information;
[0062] Establishing a secure connection with the regional certificate management server, and sending legal digital identity application information to the regional certificate management server after the secure connection is established, so that the regional certificate management server can complete authentication based on the legal digital identity application information and issue a legal digital identity certificate after the authentication is successful;
[0063] Receive the legal digital identity certificate issued by the regional certificate management server, and complete the establishment of the legal digital identity according to the legal digital identity certificate.
[0064] In conjunction with the third aspect, further, establishing a secure connection with the regional certificate management server includes:
[0065] receiving information returned by the access application server about establishing a secure connection with the regional certificate management server;
[0066] A secure connection is established with the regional certificate management server using a securely authenticated communication channel according to the information on establishing a secure connection.
[0067] In conjunction with the third aspect, further, completing the establishment of the legal digital identity based on the legal digital identity certificate includes:
[0068] receiving a temporary key sent by the regional certificate management server, and using the temporary key to decrypt the legal digital identity certificate;
[0069] Authenticating the decrypted legal digital identity certificate using a certificate chain, and installing the legal digital identity certificate after passing the authentication;
[0070] The activation instruction containing the serial number of the legal digital identity certificate is digitally signed and sent to the regional certificate management server, so that the regional certificate management server sets the corresponding legal digital identity certificate status to enabled after the digital signature of the activation instruction is authenticated.
[0071] In conjunction with the third aspect, further, the legal digital identity certificate is issued by one or more regional certificate management servers that have regional certificates installed and hold the private keys of the corresponding regional certificates; when the legal digital identity certificate is jointly issued by multiple regional certificate management servers, the multiple regional certificate management servers are respectively installed with different regional certificates of the same region and hold the private keys of the corresponding regional certificates;
[0072] In which, the regional certificate is issued by one or more national certificate management servers that have installed a root certificate and hold the private key of the corresponding root certificate; when the regional certificate is jointly issued by multiple national certificate management servers, the multiple national certificate management servers are respectively installed with different root certificates of the same country and hold the private keys of the corresponding root certificates.
[0073] In combination with the third aspect, further, the certificate chain is composed of regional certificates held by at least half of the regional certificate management servers and root certificates held by at least half of the national certificate management servers.
[0074] In a fourth aspect, the present application provides an electronic terminal comprising a processor and a memory connected to the processor, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the steps of the method described in any one of the first aspect or the third aspect are performed.
[0075] In a fifth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any one of the first aspect or the third aspect.
[0076] In a sixth aspect, the present application provides a digital identity management system, comprising:
[0077] Application access server: used to determine the corresponding certificate management server based on the region information provided by the digital identity application terminal;
[0078] The certificate management server is used to establish a secure connection with the digital identity application terminal through the application access server, and receive the digital identity application information submitted by the digital identity application terminal after the secure connection is established; review and authenticate the digital identity application information and issue a digital identity certificate to the digital identity application terminal after the review and authentication passes;
[0079] Certificate server: used to register and file the digital identity certificate sent by the certificate management server and supervise and manage the digital identity certificate.
[0080] In combination with the sixth aspect, further, the application access server is also used to provide the digital certificate of the certificate management server to the digital identity application terminal, and receive the digital identity application information encrypted by the digital certificate submitted by the digital identity application terminal, and forward the encrypted digital identity application information to the certificate management server.
[0081] In combination with the sixth aspect, further, the certificate server is further configured to send an abnormality reminder notification to all terminals that have downloaded the digital identity certificate when an abnormality occurs in the digital identity certificate under supervision and management.
[0082] In combination with the sixth aspect, further, the certificate server is also used to store the digital identity identification identifier, certificate serial number, abnormal status, abnormal status reporter and time of entering the abnormal status of the digital identity certificate with abnormality in the abnormal certificate list.
[0083] In combination with the sixth aspect, further, the certificate server is also used to record the usage record of the digital identity certificate containing privacy information.
[0084] In combination with the sixth aspect, further, the certificate server is also used to provide certificate services to the digital identity certificate holder according to the privacy authority settings of the digital identity certificate holder.
[0085] In combination with the sixth aspect, further, the certificate management server is also used to encrypt the digital identity certificate using the activated temporary key before issuing the digital identity certificate to the digital identity application terminal, and send the temporary key to the digital identity application terminal through a secure authenticated communication channel.
[0086] In combination with the sixth aspect, further, there are one or more certificate management servers. If the digital identity certificate is jointly issued by multiple certificate management servers, the digital identity certificate needs to be authenticated by the digital certificates of at least half of the certificate management servers before use.
[0087] In a seventh aspect, the present application provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, performs the steps of the method described in any one of the first aspect or the third aspect.
[0088] Compared with the prior art, the present invention has the following beneficial effects:
[0089] The method for establishing a subsidiary digital identity provided by this application uses a legal digital identity terminal installed with a legal digital identity certificate and holding the private key of the legal digital identity certificate to issue a subsidiary digital identity certificate to a user terminal. The legal digital identity terminal and the user terminal of the subsidiary digital identity are associated and bound through a legal digital identity identification identifier, which facilitates tracking and supervision of operations performed by the user terminal (including published information), helping to reduce the spread of spam.
[0090] The legal digital identity certificate includes a full legal digital identity certificate and at least one simplified legal digital identity certificate. The simplified legal digital identity certificate carries minimal personal information based on the user's privacy protection needs, and can maximize the protection of the personal privacy of the legal digital identity terminal holder;
[0091] The legal digital identity establishment method provided in this application obtains a legal digital identity by issuing a legal digital identity certificate through a regional certificate management server, which helps regional management departments to supervise legal digital identity terminals, enhance the reliability of legal digital identity terminals, and improve the credibility of information transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0092] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0093] FIG1 is a flow chart of a method for establishing a subsidiary digital identity according to an embodiment of the present application;
[0094] FIG2 is a schematic diagram of the structure of a unique identification identifier UID of an auxiliary digital identity certificate provided according to an embodiment of the present application;
[0095] FIG3 is a flow chart of a method for establishing a legal digital identity according to an embodiment of the present application;
[0096] FIG4 is a schematic diagram of a digital identity certificate issuance chain and an authentication chain according to an embodiment of the present application;
[0097] FIG5 is a schematic structural diagram of an electronic terminal provided according to an embodiment of the present application;
[0098] FIG6 is a schematic structural diagram of a digital identity management system provided according to an embodiment of the present application. DETAILED DESCRIPTION
[0099] The technical solution of the present application is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application.
[0100] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0101] Example 1:
[0102] Figure 1 is a flowchart of a method for establishing a subsidiary digital identity, as provided in Example 1 of the present application. This flowchart merely illustrates the logical sequence of the method described in this embodiment. In other possible embodiments of the present application, the steps shown or described may be performed in a different order than that shown in Figure 1, provided that no conflict exists.
[0103] The method for establishing a secondary digital identity provided in this embodiment can be applied to an electronic terminal, such as any smartphone, tablet, or computer device with communication capabilities. This method can be executed by an electronic terminal with a legal digital identity, which can be implemented using software and / or hardware. Referring to Figure 1 , the method provided in this embodiment can be executed by a legal digital identity terminal. Before a user terminal applies to establish a secondary digital identity, it must first establish a secure connection with the legal digital identity terminal. This method specifically includes the following steps:
[0104] Step 101: The legal digital identity terminal receives the user's supplementary digital identity application information;
[0105] Step 102: The legal digital identity terminal reviews and authenticates the supplementary digital identity application information;
[0106] Step 103: The legal digital identity terminal signs a supplementary digital identity certificate for the user terminal that has passed the review and authentication, and issues the supplementary digital identity certificate to the user terminal;
[0107] Among them, the legal digital identity terminal is installed with a legal digital identity certificate and holds the private key of the legal digital identity certificate; the legal digital identity certificate installed by the legal digital identity terminal and the subsidiary digital identity certificate issued by it are associated through a legal digital identity identification identifier.
[0108] It should be noted that in this embodiment, both "legal digital identity" and "supplementary digital identity" are concepts in cyberspace, and are online identities adopted by individuals, organizations or electronic devices on the Internet. The legal digital identity refers to a digital identity granted by the laws and decrees of the country or region to which it belongs. The holder of the legal digital identity should be an individual or legal person who can bear legal responsibility; and the supplementary digital identity is a digital identity granted by the holder of the legal digital identity. The holder of the supplementary digital identity can be an individual, an organization or an electronic device. The supplementary digital identity certificate is held by the user terminal. After the legal digital identity terminal issues the supplementary digital identity certificate to the user terminal and activates the supplementary digital identity certificate, the legal digital identity terminal bears the corresponding legal responsibility for all operations performed by the user terminal.
[0109] In summary, the method for establishing a subsidiary digital identity provided in the embodiment of the present application issues a subsidiary digital identity certificate to the user terminal through a legal digital identity terminal that is installed with a legal digital identity certificate and holds the private key of the legal digital identity certificate. The legal digital identity terminal and the user terminal of the subsidiary digital identity are associated and bound through a legal digital identity identification identifier. That is to say, the legal digital identity identification identifier held by the user terminal can be used to query and determine the legal digital identity terminal authorized to it, so that the user terminal's behavior (including information release behavior) is constrained within a traceable and controllable range, which helps to reduce the spread of spam.
[0110] To facilitate supervision of user terminal behavior, the legal digital identity terminal can initially set the user terminal's behavior permissions. If necessary, it can also switch the status of the subsidiary digital identity certificate from enabled to disabled, or adjust the user terminal's operation permissions accordingly. The subsidiary digital identity certificate may include a subsidiary digital identity identification identifier used to describe the subsidiary digital identity, and / or a permission identifier used to represent the permission to use the subsidiary digital identity certificate, and / or a subsidiary digital identity abbreviation. Table 1 shows an example of an attribute table of a subsidiary digital identity certificate:
[0111] Table 1
[0112] The authority identifier can be extended through an authority extension certificate. For example, a certain subsidiary digital identity certificate is a network communication certificate. The user terminal installed with the subsidiary digital identity certificate can order attachments through a designated website. When ordering, an authority extension certificate needs to be provided. The authority extension certificate can be granted by a legal digital identity terminal.
[0113] To prevent repudiation, the legal digital identity terminal may be required to digitally sign and file the legal liability agreement after issuing the subsidiary digital identity certificate to the user end. The legal liability agreement should clearly state that the holder of the legal digital identity terminal shall bear all legal responsibilities for the actions of the user end of the subsidiary digital identity certificate it has issued.
[0114] To protect the privacy of legal digital identity terminals as much as possible, the legal digital identity certificate provided in this embodiment includes a full legal digital identity certificate and at least one simplified legal digital identity certificate. The full legal digital identity certificate and the simplified legal digital identity certificate have the same functions and are interchangeable. The full legal digital identity certificate contains at least the complete identity identification information required by law for the natural person or legal person. Table 2, as an example, shows the attribute table of a full legal digital identity certificate:
[0115] Table 2
[0116] As shown in Table 2, a complete legal digital identity certificate can include the certificate version number, issuer digital identity information, digital identity identification identifier, digital identity abbreviation, certificate type, basic constraints, certificate validity start and end times, public key information (including public key type and public key parameters), signature algorithm, signature hash algorithm, digital fingerprint, and holder information. Holder information includes personal privacy information such as full name, abbreviation, birthday, address, and photo. Of course, other information can be expanded as needed. A complete legal digital identity certificate carries relatively comprehensive personal information, and users can pre-set access permissions to ensure that only authorized persons can obtain the complete legal digital identity certificate.
[0117] The simplified legal digital identity certificate carries minimal personal information based on the user's privacy protection requirements. Table 3, as an example, shows the attribute table of a simplified legal digital identity certificate:
[0118] Table 3
[0119] By comparing Table 2 and Table 3, it can be seen that compared with the complete legal digital identity certificate, the simplified legal digital identity certificate at least hides the holder's personal information. When facing the public, the holder of the legal digital identity certificate can prove his or her legal digital identity through the simplified legal digital identity certificate, which can protect the user's personal privacy to the greatest extent. It should be understood that Table 2 is only one of the attribute tables of the simplified legal digital identity certificate given in this application. Users can also hide other information according to personal needs. The simplified legal digital identity certificate can only contain anonymous information. At this time, the terminal that is granted the right to obtain private information can make a request to the certificate issuer through known information such as version number and digital identity identification. After the request is approved, the legal digital identity certificate containing the required private information can be obtained. The certificate issuer can protect the privacy of the legal digital identity terminal through permission settings. At the same time, the legal digital identity terminal can also send a legal digital identity certificate or certificate-type electronic business card containing private information to the terminal that issued the request according to its own needs.
[0120] The digital identity abbreviations in Tables 1 and 2 can typically be user-defined email addresses, phone numbers, device names, custom anonymities, and other identifiers that are easy to remember and identify and at least partially unique. Local uniqueness here means being unique among all contacts on the local terminal.
[0121] For the aforementioned legal digital identity identification identifier, a legal digital identity can be uniquely identified through a legal digital identity identification identifier. It can be a string of numbers or a combination of numbers and letters or a combination of numbers, letters and special symbols, but it should at least contain regional information that can reflect the issuer of the legal digital identity certificate. The setting of regional information can be used to meet the requirements of jurisdiction, data rights, data sovereignty, network security, and regional credibility.
[0122] As an embodiment of the present application, the legal digital identity identification mark may include:
[0123] Description byte: can be used to describe the structure of the legal digital identity identification mark;
[0124] Country number: can be used to describe the country that issued the root certificate;
[0125] Region code: can be used to describe the region information where the regional certificate is issued;
[0126] Identity number: can be used to describe unique digital identity information;
[0127] The first and second bytes of the description byte can be used to define the description method, for example: "10" is the version description method, "00" is the direct description method, and the remaining bytes can be used to represent the description data; the country code is 2 bytes (64K), the region code is 4 bytes (2G), and the identity number is 4 bytes (2G). The description byte, country code, region code, and identity number can all be represented by numbers and / or letters. A country can have multiple different forms of country codes, and a region can have multiple different forms of region codes. Similarly, a digital identity can have multiple different forms of identity numbers. However, a country code should uniquely correspond to a country. Accordingly, a region code can only uniquely correspond to a region, and an identity number can only uniquely correspond to a digital identity.
[0128] For ease of use, digital identity identifiers typically use a naming method similar to that of internet domain names. For example, the legal digital identity identifier is "caadmin.beijing.cnid," which can be understood as "Certificate Administration Server.Beijing.China Digital Identity." "caadmin" is the descriptor, "beijing" is the region code, and "cn" is the country code. "id" can be used to identify the identity number and can be represented using numbers and / or letters, for example, HEX: 00000001.00000010.0860. Another example: "phone1.tommy01.beijing.cnid" represents a subsidiary digital identity identifier named "phone1" with the legal digital identity identifier "tommy01.beijing.cnid." "tommy01" is the unique online name within the domain name "beijing.cnid," "beijing" can be used to identify the region code as Beijing, and "cnid" is the Chinese digital identity domain.
[0129] In step 101, the supplementary digital identity application information includes at least identification information that uniquely identifies the user. This identification information can be a shared key between a legal digital identity terminal and a supplementary digital identity terminal. In practice, the user can obtain the shared key by inputting the application information using a pre-installed app, or by scanning an image code provided by the legal digital identity terminal.
[0130] Whether it is a legal digital identity certificate or an auxiliary digital identity certificate, it should be verified before initial installation and use. In the embodiment of this application, the verification of the digital identity certificate can be completed through the authentication of the certificate chain, as follows:
[0131] First of all, it should be noted that the legal digital identity certificate held by the legal digital identity terminal can be issued by one or more regional certificate management servers that have installed a regional certificate and hold the private key of the regional certificate; the regional certificate can be issued by one or more national certificate management servers that have installed a root certificate and hold the private key of the root certificate.
[0132] A country has at least two or more root certificates and corresponding private keys. Accordingly, the national certificate management server can be configured as multiple sets. Each national certificate management server can install different root certificates and hold corresponding private keys. When less than half of the root certificates have abnormalities, the certificate chain will not collapse.
[0133] A regional certificate can be jointly issued by multiple national certificate management servers. In this case, when authenticating the regional certificate, the certificate chain consisting of the root certificates held by at least half of the national certificate management servers that participated in issuing the regional certificate must be authenticated before it can pass.
[0134] Accordingly, a country can set up several regional certificate issuing centers as needed. Each regional certificate issuing center can set up multiple independent regional certificate management servers that belong only to the region. Multiple regional certificate management servers can install different regional certificates to meet the power exercise requirements of different functional departments in the same region. At this time, the legal digital identity certificate can be jointly issued by multiple regional certificate management servers. For example, a region has five independent and normally operating regional certificate management servers A, B, C, D, and E. When a terminal under the jurisdiction of the region requests a legal digital identity certificate, it can send a request to the five regional certificate management servers at the same time. Each regional certificate management server will generate a legal digital identity certificate according to the request. The regional certificate management servers A, B, C, D, and E can digitally sign each legal digital identity certificate in sequence. After all regional certificate management servers have completed the signing, the legal digital identity certificate will be issued to the requesting terminal.
[0135] If a legal digital identity certificate is jointly issued by multiple regional certificate management servers, the certificate chain used to authenticate the legal digital identity certificate shall be composed of at least half of the regional certificates and more than half of the root certificates. For example, when regional certificate management servers C and D encounter abnormalities, the legal digital identity certificate can at least pass the authentication of the regional certificates held by regional certificate management servers A, B, and E. If the regional certificates used for authentication of the legal digital identity certificate are also jointly issued by multiple national certificate management servers, the regional certificates shall also be authenticated by at least more than half of the root certificates.
[0136] The required number of national certificate management servers and regional certificate management servers can be calculated based on security and reliability. Considering that the private keys of independent certificate management servers can be physically protected, there is no real-time networking requirement, and effective management measures are in place, under the premise of equal security and reliability, the required number of certificate management servers will be much lower than that of blockchain, and the energy consumption can be ignored.
[0137] When a certificate is issued by multiple issuers, the "Issuer Digital Identity" column in Table 3 will list all issuer digital identities, and the certificate will contain the digital signatures of all issuers.
[0138] The regional certificate issuing center can directly face the user's smart terminal and assume the responsibility of distributed storage of new user applications and information authentication to cope with the disasters that may be caused by the large-scale spread of bad information.
[0139] The root certificate can be announced on the website in the form of a square code or barcode. It can also be widely publicized through methods such as application pre-installation and blockchain, and provide multi-factor authentication. The purpose of multi-factor authentication is to increase security. After the root certificate is installed, any change will trigger the application's highest priority alarm and trigger the re-verification process of multi-factor authentication.
[0140] Before the legal digital identity terminal installs the legal digital identity certificate, it must first pass the certificate chain authentication composed of the root certificate and the regional certificate. Only after the authentication is passed, the installation program of the legal digital identity certificate is enabled. Correspondingly, before the user terminal installs the subsidiary digital identity certificate, it needs to pass the certificate chain authentication composed of the root certificate, the regional certificate and the legal digital identity certificate, that is, the subsidiary digital identity certificate is authenticated by the legal digital identity certificate, the legal digital identity certificate is authenticated by the regional certificate, and the regional certificate is authenticated by the root certificate. Referring to Figure 4, a schematic diagram of a digital identity certificate issuance chain and authentication chain is given. The certificate authentication process is an authentication process for the content and digital signature of the certificate. According to the issuer identity information in the certificate, the issuer's digital identity certificate is obtained, and the digital identity certificate is used to authenticate the digital signature of the current certificate. The authentication is carried out step by step until the digital signature authentication of the root certificate is passed, that is, the certificate chain authentication is completed. At the same time, it is also necessary to authenticate whether the validity period of the certificate and the certificate serial number exist in the abnormal certificate list. This abnormal certificate list can be understood as a comparison table, primarily including: the legal digital identity identification identifier, certificate serial number, abnormal status, the person reporting the abnormal status, and the time the abnormal status entered. When a legal digital identity certificate enters an abnormal status, the regional certificate management server will issue a real-time notification to all terminals that have previously downloaded the legal digital identity certificate, ensuring that these terminals are promptly informed of the certificate status change. To ensure certificate validity, legal digital identity terminals can also periodically synchronize the status of their legal digital identity certificates with the regional certificate management server.
[0141] Digital identity is typically demonstrated through a digital identity certificate and its corresponding private key. The private key should be owned exclusively by the certificate holder and not disclosed or shared with any other party. As a crucial element of digital identity, the private key must be adequately and effectively protected. Specifically, the private key can be encrypted using a password and / or biometrics, or physically protected using a dedicated chip.
[0142] As shown in Figure 2, this is a structural diagram of the unique identification identifier UID of a subsidiary digital identity certificate provided in an embodiment of the present application. In addition to the description byte, country code, region code and identity number, the subsidiary digital identity certificate may also include a subsidiary number. The subsidiary number can be used to distinguish different subsidiary digital identities authorized by the same legal digital identity. The subsidiary number is 4 bytes (2G number).
[0143] Upon receiving the subsidiary digital identity certificate issued by the legal digital identity terminal, the user terminal requesting the establishment of a subsidiary digital identity will first authenticate the subsidiary digital identity certificate through the certificate chain. Once authentication is successful, the subsidiary digital identity certificate installation process will continue. After certificate installation is complete, the user terminal can provide the subsidiary digital identity certificate's serial number and digital signature to the legal digital identity terminal. The legal digital identity terminal will perform signature authentication on the digital signature provided by the user terminal. Upon successful signature authentication, the legal digital identity terminal will adjust the status of the subsidiary digital identity certificate corresponding to the certificate serial number to normal and send the subsidiary digital identity certificate and serial number to the corresponding certificate server for recordation.
[0144] At this point, the process of establishing the subsidiary digital identity is completed.
[0145] In some embodiments of the present application, when a user submits a request for a supplementary digital identity, the legal digital identity terminal can be switched to a signing supplementary digital identity mode. The user can use the supplementary digital identity application app to establish a secure connection with the legal digital identity terminal. The supplementary digital identity application app can generate a certificate application and private key based on the supplementary digital identity application information. The certificate application can be encrypted with the public key of the legal digital identity terminal and then sent to the legal digital identity terminal.
[0146] It should be noted that, unless there is a conflict, the embodiments of this application and the technical features therein may be combined with other embodiments, and the technical content of other embodiments may be used to explain the technical solution of this embodiment. For example, the method provided in this embodiment may be implemented based on the digital identity infrastructure network described in Example 3, and may also be implemented based on the digital identity management system provided in Example 6.
[0147] Example 2:
[0148] This embodiment provides a legal digital identity terminal, which can be used to implement the method for establishing a subsidiary digital identity as described in Example 1. The terminal can be a smartphone, tablet, or computer device, and can be implemented through pre-installed software and / or integrated hardware. Specifically, the method includes:
[0149] Application information receiving module: used to receive the user's supplementary digital identity application information after establishing a secure connection with the user;
[0150] Audit and authentication module: used to audit and authenticate the application information of the subsidiary digital identity;
[0151] Certificate signing and issuing module: used for signing the subsidiary digital identity certificate for the user terminal that has passed the audit and authentication, and issuing the subsidiary digital identity certificate to the user terminal;
[0152] Among them, the legal digital identity terminal is installed with a legal digital identity certificate and holds the private key of the legal digital identity certificate; the legal digital identity certificate installed by the legal digital identity terminal and the subsidiary digital identity certificate issued by it are associated through a legal digital identity identification identifier.
[0153] The specific implementation details of the above modules for realizing their corresponding functions can be referred to in Example 1 and will not be described in detail here.
[0154] In some embodiments of the present application, the legal digital identity terminal further includes:
[0155] Return information receiving module: used to receive the certificate serial number and digital signature returned by the user end after installing the subsidiary digital identity certificate;
[0156] Signature authentication module: used to perform signature authentication on the digital signature, and after the signature authentication is passed, adjust the status of the subsidiary digital identity certificate corresponding to the certificate serial number to enabled;
[0157] Filing module: used to file the subsidiary digital identity certificate and certificate serial number.
[0158] In some embodiments of the present application, the legal digital identity terminal may further include:
[0159] Digital signature module: used to digitally sign and file the legal liability agreement after issuing the subsidiary digital identity certificate to the user terminal;
[0160] Among them, the legal liability agreement includes the agreement that the holder of the legal digital identity terminal bears all legal liability for the actions of the user terminal of the attached digital identity certificate issued by it. Here, the actions of the user terminal only include actions within the scope of authority authorized by the legal digital identity terminal to the user terminal.
[0161] Given that the legal digital identity terminal provided in the embodiment of this application can execute the method provided in Example 1 of this application, it has the functional modules and beneficial effects corresponding to the execution method. To save space, technical details not described in detail in this embodiment can be referred to in Example 1 and will not be repeated here. In the absence of conflict, the embodiments of this application and the technical features in the embodiments can be combined with other embodiments, and the technical content of other embodiments can be used to explain the technical solution of this embodiment.
[0162] Example 3:
[0163] An embodiment of the present application provides a method for establishing a legal digital identity, which can be implemented by a terminal that applies to establish a legal digital identity (hereinafter referred to as a legal digital identity terminal). The legal digital identity terminal can be a smartphone, a tablet, or a computer device. To implement this method, software is pre-installed in the legal digital identity terminal and / or corresponding hardware is integrated.
[0164] It should be noted that the process of establishing a legal digital identity for an electronic terminal can be understood as the process of obtaining a legal digital identity certificate and successfully running and installing the legal digital identity certificate. Referring to Example 1, the legal digital identity certificate can be issued by a regional certificate management server. A country can correspond to several regions, and correspondingly there are also several regional certificate management servers. For this reason, the legal digital identity can be issued by one regional certificate management server, or it can be jointly issued by multiple regional certificate management servers. The multiple regional certificate management servers are respectively installed with different regional certificates of the same region and hold the private keys of the corresponding regional certificates. Before obtaining the legal digital identity certificate, it is first necessary to determine the region where the legal digital identity terminal is located, so as to determine the corresponding regional certificate management server.
[0165] The regional certificates can be issued by one or more national certificate management servers that have installed root certificates and hold the private keys for those root certificates. A country should possess at least two root certificates and their corresponding private keys. Accordingly, multiple national certificate management servers can be configured, each with a different root certificate installed and its corresponding private key. This prevents the certificate chain from collapsing if fewer than half of the root certificates fail.
[0166] When a regional certificate is jointly issued by multiple national certificate management servers, when authenticating the regional certificate, it shall be deemed to have passed the authentication only if the certificate chain consisting of the root certificates held by at least half of the national certificate management servers that participated in issuing the regional certificate is authenticated.
[0167] Accordingly, a country can set up several regional certificate issuing centers as needed. Each regional certificate issuing center can set up multiple independent regional certificate management servers that belong only to the region. Multiple regional certificate management servers can install different regional certificates, so as to meet the power exercise needs of different functional departments in the same region. At this time, the legal digital identity certificate can be jointly issued by multiple regional certificate management servers. For example, a region has five independent and normally operating regional certificate management servers A, B, C, D, and E. When a terminal under the jurisdiction of the region requests a legal digital identity certificate, it can send a request to the five regional certificate management servers at the same time. Each regional certificate management server will generate a legal digital identity certificate according to the request. The regional certificate management servers A, B, C, D, and E can digitally sign each legal digital identity certificate in sequence. After all regional certificate management servers have completed the signing, the legal digital identity certificate will be issued to the requesting terminal.
[0168] If a legal digital identity certificate is jointly issued by multiple regional certificate management servers, the certificate chain used to authenticate the legal digital identity certificate shall be composed of at least half of the regional certificates and more than half of the root certificates. For example, when regional certificate management servers C and D encounter abnormalities, the legal digital identity certificate can at least pass the authentication of the regional certificates held by regional certificate management servers A, B, and E. If the regional certificates used for authentication of the legal digital identity certificate are also jointly issued by multiple national certificate management servers, the regional certificates shall also be authenticated by at least more than half of the root certificates.
[0169] FIG3 is a flowchart of a method for establishing a legal digital identity provided by an embodiment of the present application. The method specifically includes the following steps:
[0170] Step 201: Sending the region information of the legal digital identity terminal to the access application server, so that the access application server can determine the corresponding regional certificate management server according to the region information;
[0171] The application access server bridges the gap between the internet and the digital identity infrastructure network. Because the digital identity infrastructure network is more secure than the internet, certificate management servers typically reside only within it. Internet terminals without digital identities cannot access the network and must communicate with the certificate management server through the application access server. The layout of application access servers is primarily based on factors such as network efficiency, network security, data rights, and data sovereignty.
[0172] The digital identity infrastructure network can be understood as a network based on the transmission of units. The term "unit" here can be understood as the target data transmitted using a digital identity as the communication address. The digital identity here can be the aforementioned legal digital identity identification identifier or the aforementioned auxiliary digital identity identification identifier. The digital identity identifier used to identify the data sender in the unit can be regarded as the data sender identity identifier, and the digital identity identifier used to identify the data receiver can be regarded as the data receiver identity identifier. That is, the same digital identity identification identifier can be the data sender identity identifier or the data receiver identity identifier in different communication scenarios. The digital identity infrastructure network can include a forwarder, the aforementioned certificate management server, a certificate server, an application access server, and a terminal. Any device joining the network must have a unique digital identity. The digital identity infrastructure can also be any communication network with a digital identity as the communication address, plus a certificate server and a certificate management server.
[0173] The regional certificate management server is installed with a regional certificate and holds the private key of the regional certificate; the regional certificate is issued by a national certificate management server that is installed with a root certificate and holds the private key of the root certificate. For other relevant information about regional certificates and root certificates, please refer to Example 1.
[0174] In some embodiments, the legal digital identity terminal, the application access server, and the regional certificate management server can achieve communication connection through the MetaNet / digital identity infrastructure network. The so-called MetaNet is a network that supports MetaNet packet forwarding based on digital identity and is superimposed on the existing network. Just as the IP network forwards data packets based on IP addresses, the MetaNet can forward MetaNet packets based on digital identity identification as the communication address. Using the MetaNet for data transmission can trace the true source of the data and ensure the reliability and security of data transmission. The aforementioned "MeMeNet packet" can be understood as a data packet transmitted with a digital identity identifier as the communication address, and the digital identity identifier is unique. The specific explanation is as follows:
[0175] In an embodiment of the present invention, the legal digital identity terminal, the application access server and the regional certificate management server can be collectively referred to as infrastructure, and the data that needs to be communicated between the two infrastructures is used as target data. For the convenience of description, in an embodiment of the present invention, the target data is abbreviated as MC (MeCell in English, and can be abbreviated as "MeCell" in Chinese). , the method for generating and sending target data may include the following steps: obtaining the data body of the target data, and storing the data body in a pre-created payload field in the target data; digitally signing the payload field using the private key of the data sender of the target data to form a payload digital signature; binding the payload digital signature and the data sender identity identifier and storing them in the target data; encrypting the payload field to generate a payload ciphertext and storing it in the target data, and the payload ciphertext can only be decrypted by a designated data receiving end; wherein the data sender identity identifier is used to identify the identity of the data sender that sends the target data and is unique; the data sender identity identifier is bound to the digital certificate of the data sender, and the digital certificate of the data sender can pass the verification of the corresponding certificate chain; the payload digital signature is used to perform trust authentication on the payload field and identity authentication on the data sender. The target data also stores a data transmission type. After generating the target data, before sending the target data to the data receiving end, the data sending end will also read the data transmission type stored in the target data and send the target data to the data receiving end based on the data transmission type. Furthermore, the target data also stores a data receiving end identity identifier, which is used to identify the identity of the data sending end receiving the target data and is also unique. Furthermore, the target data may also store a data receiving end agent. Here, the term "agent" can refer to an independent application, including artificial intelligence application systems, such as live video streaming, chatGPT, P2P WEB, trusted transactions, banks, and other agent application data sending ends. Before sending the target data to the data receiving end, the data sending end also needs to read the data receiving end identity identifier and data receiving end agent in the target data; identify the data receiving end receiving the target data based on the data receiving end identity identifier; obtain the operating status of the data receiving end agent; and, in response to the data receiving end agent being in an active state, send the target data to the data receiving end.
[0176] Step 202: Establishing a secure connection with the regional certificate management server, and sending legal digital identity application information to the regional certificate management server after the secure connection is established, so that the regional certificate management server can complete authentication based on the legal digital identity application information and issue a legal digital identity certificate after the authentication is successful;
[0177] The legal digital identity application information usually includes: name, abbreviation, birthday, address, contact information, certificate type, certificate number, certificate issuance place, certificate issuer, certificate validity period, certificate photo, personal photo, and other documents specified by the local authentication center.
[0178] In some embodiments of the present application, for step 202, establishing a secure connection with the regional certificate management server includes:
[0179] Step 202-01: Receive information returned by the access application server on establishing a secure connection with the regional certificate management server;
[0180] Step 202-02: Establish a secure connection with the regional certificate management server using a securely authenticated communication channel according to the information for establishing a secure connection.
[0181] Step 203: Receive the legal digital identity certificate issued by the regional certificate management server, and complete the establishment of the legal digital identity based on the legal digital identity certificate.
[0182] In the embodiment of the present application, in step 203, the establishment of the legal digital identity according to the legal digital identity certificate includes:
[0183] Step 203-01: Receive a temporary key sent by the regional certificate management server, and use the temporary key to decrypt the legal digital identity certificate;
[0184] Step 203-02: Authenticate the decrypted legal digital identity certificate using the certificate chain, and install the legal digital identity certificate after the authentication is successful;
[0185] Step 203-03: digitally sign the activation instruction containing the serial number of the legal digital identity certificate and send it to the regional certificate management server, so that the regional certificate management server sets the corresponding legal digital identity certificate status to enabled after the digital signature of the activation instruction is authenticated.
[0186] Authenticating the decrypted legal digital identity certificate using a certificate chain as described in step 203-02 includes authenticating the legal digital identity certificate using a certificate chain consisting of the root certificate and the regional certificate, i.e., authenticating the legal digital identity certificate using the regional certificate and authenticating the regional certificate using the root certificate. For detailed steps of certificate authentication, see Example 1.
[0187] For the regional certificate management server, each issuance / download of a legal digital identity certificate will leave a relevant record in the regional certificate management server. The main record content of the record may include: certificate serial number and certificate user. When the legal digital identity certificate it manages expires, the record will be cleared.
[0188] In addition, the regional certificate management server maintains a list of abnormal certificates, which can be understood as a comparison table. Its main contents may include: legal digital identity identification identifier, certificate serial number, abnormal status, abnormal status reporter, and the time when the abnormal status entered. When a legal digital identity certificate enters an abnormal state, the regional certificate management server will issue a real-time notification to all terminals that have previously downloaded the legal digital identity certificate, ensuring that the terminals are promptly informed of the certificate status change. To ensure the validity of the certificate, the legal digital identity terminal can also regularly synchronize the status of its legal digital identity certificate with the regional certificate management server.
[0189] After the legal digital identity certificate is installed, the regional certificate management server can also adjust the status of the legal digital identity certificate based on the feedback from the legal digital identity terminal, including adjusting from disabled to enabled, from enabled to disabled, or maintaining disabled or enabled.
[0190] Regarding step 201, it should be noted that when a smart terminal requesting to establish a legal digital identity registers in a roaming location, the roaming location registers its roaming location information with the original location. When a meta-packet is sent to the roaming smart terminal, it is first sent to the forwarder in the original location, which then forwards it to the forwarder in the roaming location. Simultaneously, the forwarder in the original location sends a temporary "packet-in-packet" request to the forwarder in the originating location to improve network efficiency. After the forwarder in the originating location receives the "packet-in-packet" roaming notification, subsequent packets sent to the roamer are packaged into a new packet sent to the forwarder in the roaming location. The forwarder in the roaming location also receives a corresponding notification, but the roaming address information of the roamer is masked to protect privacy. Upon receiving this type of packet, the forwarder in the roaming location removes the inner packet and sends it to the roamer. When the sender fails to receive a receipt for the message, the sender will ask the repeater to cancel the “package within package” setting and the package will continue to be sent to the roamer’s original registered location.
[0191] It should be noted that, unless there is a conflict, the embodiments of this application and the technical features within them may be combined with other embodiments, and the technical content of other embodiments may be used to explain the technical solution of this embodiment. For example, the digital identity infrastructure network described in this embodiment may support the method described in Example 1; and the method provided in this embodiment may be implemented based on the digital identity management system described in Example 6.
[0192] Example 4:
[0193] As shown in FIG5 , an embodiment of the present application further provides an electronic terminal including a processor and a storage medium;
[0194] The storage medium is used to store instructions;
[0195] The processor is configured to operate according to the instructions to execute the steps of the method described in embodiment 1 or embodiment 3.
[0196] Since the electronic terminal provided in the embodiment of the present application is the aforementioned legal digital identity terminal, it can execute the method provided in embodiment one or embodiment three of the present application. When executing the method described in embodiment one, the electronic terminal establishes a secure connection with the user terminal so that the user terminal can establish an affiliated digital identity; when executing the method described in embodiment three, the electronic terminal establishes a secure connection with the regional certificate management server to complete the establishment of the legal digital identity at the electronic terminal.
[0197] The electronic terminal provided in the embodiment of the present application has a program module and beneficial effects corresponding to the execution method. For technical details related to the method not recorded in this embodiment, please refer to Example 1 or Example 3, which will not be described in detail here. In the absence of conflict, the technical features in the embodiment of the present application and the embodiments can be combined with other embodiments, and the technical content in other embodiments can be used to explain the technical solution of this embodiment.
[0198] Embodiment 5:
[0199] An embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps of the method described in embodiment one or embodiment three are implemented.
[0200] Similarly, the embodiments of the present application have program modules and beneficial effects corresponding to the execution method. For technical details related to the method not recorded in this embodiment, please refer to Example 1 or Example 3, which will not be repeated here. In the absence of conflict, the embodiments of the present application and the technical features in the embodiments can be combined with other embodiments, and the technical content in other embodiments can be used to explain the technical solution of this embodiment.
[0201] Example 6:
[0202] As shown in FIG6 , a digital identity management system provided in an embodiment of the present application includes:
[0203] Application access server: used to determine the corresponding certificate management server based on the region information provided by the digital identity application terminal;
[0204] The certificate management server is used to establish a secure connection with the digital identity application terminal through the application access server, and receive the digital identity application information submitted by the digital identity application terminal after the secure connection is established; review and authenticate the digital identity application information and issue a digital identity certificate to the digital identity application terminal after the review and authentication passes;
[0205] Certificate server: used to register and file the digital identity certificate sent by the certificate management server and supervise and manage the digital identity certificate.
[0206] It should be noted that the certificate management server in this embodiment can be a regional certificate management server or a root certificate management server. It should be understood that when the certificate management server is a regional certificate management server, the digital identity certificate described in this embodiment refers to a legal digital identity certificate; when the certificate management server is a root certificate management server, the digital identity certificate described in this embodiment refers to a regional certificate.
[0207] As an embodiment of the present application, the application access server is further configured to provide the digital certificate of the certificate management server to the digital identity application terminal, receive digital identity application information submitted by the digital identity application terminal and encrypted using the digital certificate, and forward the encrypted digital identity application information to the certificate management server. After receiving the digital identity application information, the certificate management server first decrypts the digital identity application information using the digital certificate. The digital certificate and the encrypted digital identity application information can be transmitted using different physical channels, such as SMS, email, or mail.
[0208] In some embodiments of the present application, the certificate server's supervision and management of the digital identity certificate includes: when an abnormality occurs in the managed digital identity certificate, sending an abnormality alert notification to all terminals that have downloaded the digital identity certificate, ensuring that the terminals are promptly informed of changes in the digital identity certificate's status. To facilitate querying abnormality information about the digital identity certificate, the certificate server is further configured to store the digital identity identification identifier, certificate serial number, abnormal status, abnormal status reporter, and time of entry into the abnormal status of the abnormal digital identity certificate in an abnormal certificate list.
[0209] The certificate server is further configured to record usage records of the digital identity certificate, and to clear usage records of the digital identity certificate when the digital identity certificate expires.
[0210] To ensure privacy and information security and enable users to use certificates reasonably within the scope of authorization, the certificate server provides certificate services to digital identity certificate holders based on the privacy authority settings of the digital identity certificate holders.
[0211] To ensure the security of the digital identity certificate during transmission, in some embodiments of the present application, the certificate management server is further configured to, before issuing the digital identity certificate to the digital identity application terminal, encrypt the digital identity certificate using an activated temporary key and send the temporary key to the digital identity application terminal via a securely authenticated communication channel. The digital identity application terminal then decrypts the encrypted digital identity certificate using the received temporary key.
[0212] It should be noted that, unless there is a conflict, the embodiments of this application and the technical features therein may be combined with other embodiments, and the technical content of other embodiments may be used to explain the technical solutions of this embodiment. For example, the explanations regarding the application access server in Example 3 may also be used to explain the application access server in the embodiments of this application; for another example, when the certificate management server in the embodiments of this application serves as a regional certificate management server, the technical content related to the regional certificate management server described in Example 3 may be used to explain the certificate management server in the embodiments of this application.
[0213] Embodiment seven:
[0214] The present application provides a computer program product, including a computer program / instruction. When the computer program / instruction is executed by a processor, the steps of the method described in Example 1 or Example 3 are performed.
[0215] Similarly, the embodiments of the present application have program modules and beneficial effects corresponding to the execution method. For technical details related to the method not recorded in this embodiment, please refer to Example 1 or Example 3, which will not be repeated here. In the absence of conflict, the embodiments of the present application and the technical features in the embodiments can be combined with other embodiments, and the technical content in other embodiments can be used to explain the technical solution of this embodiment.
[0216] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0217] The present application is described with reference to the flow chart and / or block diagram of the method, device (system), and computer program product according to the embodiment of the present application. It should be understood that each flow process and / or box in the flow chart and / or block diagram and the combination of the flow process and / or box in the flow chart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processing machine or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for realizing the function specified in one flow chart flow or multiple flows and / or one box or multiple boxes of the block diagram.
[0218] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0219] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0220] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for establishing a subsidiary digital identity, characterized in that: include: After establishing a secure connection with the user terminal, the legal digital identity terminal receives the user terminal's supplementary digital identity application information; The legal digital identity terminal reviews and authenticates the supplementary digital identity application information; The legal digital identity terminal signs a supplementary digital identity certificate for the user terminal that has passed the review and authentication, and issues the supplementary digital identity certificate to the user terminal; Among them, the legal digital identity terminal is installed with a legal digital identity certificate and holds the private key of the legal digital identity certificate; the legal digital identity certificate installed by the legal digital identity terminal and the subsidiary digital identity certificate issued by it are associated through a legal digital identity identification identifier.
2. The method according to claim 1, characterized in that The legal digital identity certificate includes a complete legal digital identity certificate and at least one simplified legal digital identity certificate; The complete legal digital identity certificate contains at least the complete identity identification information required by law for the natural person or legal person; The simplified legal digital identity certificate carries minimum personal information based on the user's personal privacy protection needs; the minimum personal information includes anonymous information.
3. The method according to claim 1, characterized in that The legal digital identity identification identifier is unique and at least includes the region information of the issuer of the legal digital identity certificate.
4. The method according to claim 1 or 3, characterized in that The legal digital identity identification includes a description byte, a country code, a region code, and an identity number; The description byte is used to describe the structure of the legal digital identity identification mark; The country number is used to describe the country information that issued the root certificate; The region code is used to describe the region information for issuing the regional certificate; The identity number is used to describe unique digital identity information.
5. The method according to claim 4, characterized in that The legal digital identity certificate is issued by one or more regional certificate management servers that have regional certificates installed and hold the private keys of the corresponding regional certificates; when the legal digital identity certificate is jointly issued by multiple regional certificate management servers, the multiple regional certificate management servers are respectively installed with different regional certificates of the same region and hold the private keys of the corresponding regional certificates; In which, the regional certificate is issued by one or more national certificate management servers that have installed a root certificate and hold the private key of the corresponding root certificate; when the regional certificate is jointly issued by multiple national certificate management servers, the multiple national certificate management servers are respectively installed with different root certificates of the same country and hold the private keys of the corresponding root certificates.
6. The method according to claim 5, characterized in that The legal digital identity certificate is installed on the legal digital identity terminal after being authenticated by the certificate chain consisting of the root certificate and the regional certificate; The subsidiary digital identity certificate is installed on the user terminal after being authenticated by a certificate chain consisting of the root certificate, the regional certificate and the legal digital identity certificate.
7. The method according to claim 5, characterized in that The private key of the legal digital identity certificate, and / or the private key of the regional certificate, and / or the private key of the root certificate are encrypted and protected by a password and / or biometrics, and / or physically protected by a dedicated chip.
8. The method according to claim 4, characterized in that The root certificate is issued through block code, website announcement, application pre-installation and / or blockchain, and provides multiple verifications.
9. The method according to claim 4, characterized in that The subsidiary digital identity certificate further includes a subsidiary digital identity identification identifier for describing the subsidiary digital identity, and / or an authority identifier for characterizing the authority to use the subsidiary digital identity certificate, and / or a subsidiary digital identity abbreviation.
10. The method according to claim 9, characterized in that The authority identifier can be extended by an authority extension certificate.
11. The method according to claim 1, wherein The supplementary digital identity application information at least includes identity identification information that can uniquely identify the user terminal.
12. The method according to claim 1, characterized in that After issuing the subsidiary digital identity certificate to the user terminal, the method further includes: Receiving the certificate serial number and digital signature returned by the user terminal after installing the supplementary digital identity certificate; Performing signature authentication on the digital signature, and after the signature authentication passes, adjusting the status of the subsidiary digital identity certificate corresponding to the certificate serial number to enabled; The subsidiary digital identity certificate and certificate serial number are filed.
13. The method according to claim 1, wherein After issuing the subsidiary digital identity certificate to the user terminal, the method further includes: Adjusting the status of the subsidiary digital identity certificate, and / or, The authority of the user end that obtains the attached digital identity certificate is adjusted through the authority extension certificate.
14. The method according to claim 1, wherein The holder of the legal digital identity terminal includes a natural person or legal person who can independently bear legal responsibility; the holder of the legal digital identity terminal bears full legal responsibility for the behavior of the user terminal holding the attached digital identity certificate issued by it; wherein, the behavior of the user terminal only includes the behavior within the scope of authority explicitly authorized by the legal digital identity terminal.
15. The method according to claim 14, characterized in that After issuing the subsidiary digital identity certificate to the user terminal, the legal liability agreement is digitally signed and filed; Among them, the legal liability agreement includes the agreement that the holder of the legal digital identity terminal bears all legal responsibilities for the actions of the user terminal of the attached digital identity certificate issued by it, and the actions of the user terminal only include actions within the scope of authority authorized by the legal digital identity terminal to the user terminal.
16. A legal digital identity terminal, characterized in that: include: Application information receiving module: used to receive the user's supplementary digital identity application information after establishing a secure connection with the user; Audit and authentication module: used to audit and authenticate the application information of the subsidiary digital identity; Certificate signing and issuing module: used for signing the subsidiary digital identity certificate for the user terminal that has passed the audit and authentication, and issuing the subsidiary digital identity certificate to the user terminal; Among them, the legal digital identity terminal is installed with a legal digital identity certificate and holds the private key of the legal digital identity certificate; the legal digital identity certificate installed by the legal digital identity terminal and the subsidiary digital identity certificate issued by it are associated through a legal digital identity identification identifier.
17. The legal digital identity terminal according to claim 16, characterized in that: Also includes: Return information receiving module: used to receive the certificate serial number and digital signature returned by the user end after installing the subsidiary digital identity certificate; Signature authentication module: used to perform signature authentication on the digital signature, and after the signature authentication is passed, adjust the status of the subsidiary digital identity certificate corresponding to the certificate serial number to enabled; Filing module: used to file the subsidiary digital identity certificate and certificate serial number.
18. The legal digital identity terminal according to claim 16, characterized in that: Also includes: Digital signature module: used to digitally sign and file the legal liability agreement after issuing the subsidiary digital identity certificate to the user terminal; Among them, the legal liability agreement includes the agreement that the holder of the legal digital identity terminal bears all legal responsibilities for the actions of the user terminal of the attached digital identity certificate issued by it; the actions of the user terminal only include actions within the scope of authority authorized by the legal digital identity terminal to the user terminal.
19. A method for establishing a legal digital identity, characterized in that: include: Sending the region information of the terminal applying for establishing a legal digital identity to the application access server, so that the application access server can determine the corresponding regional certificate management server according to the region information; Establishing a secure connection with the regional certificate management server, and sending legal digital identity application information to the regional certificate management server after the secure connection is established, so that the regional certificate management server can complete authentication based on the legal digital identity application information and issue a legal digital identity certificate after the authentication is successful; Receive the legal digital identity certificate issued by the regional certificate management server, and complete the establishment of the legal digital identity according to the legal digital identity certificate.
20. The method according to claim 19, characterized in that The establishing of a secure connection with the regional certificate management server comprises: receiving information returned by the access application server about establishing a secure connection with the regional certificate management server; A secure connection is established with the regional certificate management server using a securely authenticated communication channel according to the information on establishing a secure connection.
21. The method according to claim 19 or 20, characterized in that The establishment of a legal digital identity according to the legal digital identity certificate includes: receiving a temporary key sent by the regional certificate management server, and using the temporary key to decrypt the legal digital identity certificate; Authenticating the decrypted legal digital identity certificate using a certificate chain, and installing the legal digital identity certificate after passing the authentication; The activation instruction containing the serial number of the legal digital identity certificate is digitally signed and sent to the regional certificate management server, so that the regional certificate management server sets the corresponding legal digital identity certificate status to enabled after the digital signature of the activation instruction is authenticated.
22. The method according to claim 21, characterized in that The legal digital identity certificate is issued by one or more regional certificate management servers that have regional certificates installed and hold the private keys of the corresponding regional certificates; when the legal digital identity certificate is jointly issued by multiple regional certificate management servers, the multiple regional certificate management servers are respectively installed with different regional certificates of the same region and hold the private keys of the corresponding regional certificates; In which, the regional certificate is issued by one or more national certificate management servers that have installed a root certificate and hold the private key of the corresponding root certificate; when the regional certificate is jointly issued by multiple national certificate management servers, the multiple national certificate management servers are respectively installed with different root certificates of the same country and hold the private keys of the corresponding root certificates.
23. The method according to claim 22, characterized in that The certificate chain is composed of regional certificates held by at least half of the regional certificate management servers and root certificates held by at least half of the national certificate management servers.
24. An electronic terminal, characterized in that: The method comprises a processor and a memory connected to the processor, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 15 or claims 19 to 23 are performed.
25. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 15 or claims 19 to 23 are implemented.
26. A digital identity management system, characterized in that: include: Application access server: used to determine the corresponding certificate management server based on the region information provided by the digital identity application terminal; The certificate management server is used to establish a secure connection with the digital identity application terminal through the application access server, and receive the digital identity application information submitted by the digital identity application terminal after the secure connection is established; review and authenticate the digital identity application information and issue a digital identity certificate to the digital identity application terminal after the review and authentication passes; Certificate server: used to register and file the digital identity certificate sent by the certificate management server and supervise and manage the digital identity certificate.
27. The system according to claim 26, wherein: The application access server is also used to provide the digital certificate of the certificate management server to the digital identity application terminal, receive the digital identity application information encrypted by the digital certificate submitted by the digital identity application terminal, and forward the encrypted digital identity application information to the certificate management server.
28. The system according to claim 26, wherein: The certificate server is further configured to send an abnormality reminder notification to all terminals that have downloaded the digital identity certificate when an abnormality occurs in the digital identity certificate under supervision and management.
29. The system according to claim 28, wherein: The certificate server is further configured to store the digital identity identification identifier, certificate serial number, abnormal status, abnormal status reporter and abnormal status entry time of the digital identity certificate with abnormality in an abnormal certificate list.
30. The system according to claim 26, wherein: The certificate server is further configured to record usage records of digital identity certificates containing private information.
31. The system according to claim 26, wherein: The certificate server is further configured to provide certificate services to the digital identity certificate holder according to the privacy authority setting of the digital identity certificate holder.
32. The system according to claim 26, wherein: The certificate management server is further configured to encrypt the digital identity certificate using the activated temporary key before issuing the digital identity certificate to the digital identity application terminal, and send the temporary key to the digital identity application terminal through a secure authenticated communication channel.
33. The system according to claim 26, wherein: There are one or more certificate management servers. If the digital identity certificate is jointly issued by multiple certificate management servers, the digital identity certificate needs to be authenticated by the digital certificates of at least half of the certificate management servers before use.
34. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 15 or claims 19 to 23 are implemented.
Citation Information
Patent Citations
Digital certificate management method and device
CN108667781A
A method for applying for digital certificate
CN111917685A
Digital certificate issuing method, device, terminal entity and system
CN114598455A
Affiliated digital identity establishing method, legal digital identity establishing method and digital identity management system
CN118041537A
Apparatus and method for managing digital certificates
US20190074982A1