Method of verification and related device
The method and device for verifying user and AI digital agent identity using biometric-based encryption and decentralized identity documents address the challenge of managing AI digital agents, ensuring secure and privacy-preserving identity verification and ownership proof.
Patent Information
- Application Number
- PCT/CN2024/114462
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-26
- Publication Date
- 2026-03-05
AI Technical Summary
The management of artificial intelligence (AI) digital agents in various applications is inadequate, particularly in ensuring the verification of user identity and ownership, which is crucial for secure online transactions and interactions.
A method and device for verifying the identity of a user or AI digital agent using biometric information and asymmetric encryption keys, generating random numbers and digital signatures to ensure privacy and secure identity verification, with the use of decentralized identity documents for storage and management.
Enhances the management of AI digital agents by securely verifying user identity and ownership, ensuring privacy preservation and facilitating key revocation and audit tracing, thus strengthening the security of online interactions.
Smart Images

Figure CN2024114462_05032026_PF_FP_ABST
Abstract
Description
METHOD OF VERIFICATION AND RELATED DEVICETECHNICAL FIELD
[0001] Embodiments of the present application relate to the field of computers, and more particularly, to a method of verification, and related devices for verification.BACKGROUND
[0002] An artificial intelligence (AI) digital agent is an entity built using AI techniques, designed to perceive environment and take actions in order to achieve at least one specific goal. The AI digital agent simulates the real user behavior upon training. The AI digital agent is a software-based or physical entity. The AI digital agent perceives an environment through at least one sensor and at least one input stream, processes the information using algorithms or models, and then takes actions using at least one actuator or other means. Potential application of the AI digital agent includes at least one of: virtual assistants, online customer service, healthcare, finance, gaming, smart homes and internet of things (IoT) , robotics, autonomous vehicles, etc. As the application of the AI digital agents is increasing, it is necessary to strengthen the management of AI digital agents, such as verifying whether a real user or an AI digital agent is communicating with the service in certain high value / important online communication / transactions (ex. bank transactions) , or consenting to buy / sell valuable assets / goods / property.
[0003] Therefore, how to strengthen the management of an AI digital agent is a challenge.SUMMARY
[0004] Embodiments of the present application provide a method of verification and related devices for verification. The technical solution verifies the identity of a user or an AI digital agent, thereby strengthening the management of the AI digital agent.
[0005] According to a first aspect, an embodiment of this application provides a method of verification. This method includes: obtaining a first verification string and first helper data; obtaining a first random number based on biometric information of a second user and a first string, where the first string is obtained based on an identification of a first user and / or an identification of a first artificial intelligence (AI) digital agent, and the first AI digital agent belongs to the first user; obtaining a first private key based on the first random number and the first helper data; obtaining a second verification string by verifying a first digital signature based on a second public key, where the first digital signature is obtained by signing the first verification string based on the first private key, and the second public key is generated based on biometric information of the first user; and verifying the second verification string based on the first verification string.
[0006] According to the method above, a computing device generates the first private key for verification based on the second user's biometric information and the identification of the first user and / or the first AI digital agent, thereby obtaining the first digital signature by signing the first verification string based on the first private key. The computing devices obtains the second verification string by verifying a first digital signature based on a second public key, thereby verifying the identity of a user or the identity of the owner of an AI digital agent based on the first verification string and the second verification string, and strengthening the management of the AI digital agent. Further, generating the first random number based on the biometric information of the second user and the identification of the first user and / or AI digital agent eliminates the storage of private information (such as biometric information) of the user. At the same time, the first private key is generated based on the first random number to achieve identity verification, which proves the presence of the user and / or proof of ownership of the AI digital agent.
[0007] In a possible design, the first verification string is used to verify the first user or the first AI digital agent. The first helper data is stored in a decentralized identity (DID) document of the first user or the first AI digital agent.
[0008] In a possible design, the first private key belongs to a pair of asymmetric encryption keys. The second public key belongs to a pair of asymmetric encryption keys.
[0009] In a possible design, the obtaining a first random number based on biometric information of a second user and a first string includes: obtaining a second string based on the biometric information of the second user; and obtaining the first random number based on a first random number generator, the second string and the first string, where when inputs of the first random number generator are the same, outputs of the first random number generator are the same.
[0010] According to the method above, the second string does not reveal any biometric information and is hence safe to use online, which achieves the privacy preserving aspect.
[0011] In a possible design, the second string is obtained based on the biometric information of the second user and the first data extractor. The first data extractor is designed based on error tolerant cryptographic primitives, such as a fuzzy extractor. The fuzzy extractor is described in the paper titled "Fuzzy extractors: How to generate strong keys from biometrics and other noisy data" .
[0012] In a possible design, the first random number generator is a pseudo random number generator (PRNG) . The PRNG is the national institute of standards and technology (NIST) approved pseudo random number generator, such as NIST 800-90 deterministic random bit generator (DRBG) .
[0013] In a possible design, the second string is deleted after obtaining the first random number, or the second string is not stored in any device after obtaining the first random number.
[0014] According to the method above, the second string generated based on the biometric information of user does not need to be stored, or the second string can be deleted after using, thereby achieving privacy preserving.
[0015] In a possible design, the verifying the second verification string based on the first verification string includes: when the first verification string and the second verification string are the same, determining the first user and the second user are the same; or when the first verification string and the second verification string are different, determining the first user and the second user are different.
[0016] According to the method above, the computing device verifies the first digital signature based on the second public key obtained based on the biometric information of the first user, and compares the first verification string with the second verification string to confirm whether the second user and the first user are the same, thereby achieving identity verification.
[0017] In a possible design, the method further includes: obtaining a verification result based on the first verification string and the second verification string, where the verification result is used to indicate whether the first user and the second user are the same.
[0018] According to the method above, by comparing the first verification string and the second verification string, the verification result is obtained and provided to the first / second user or a device used to verify the first / second user's identity, thereby strengthening the management of AI digital agents.
[0019] In a possible design, the method further includes: obtaining a second random number based on the biometric information of the first user and the first string; and obtaining a second private key, the second public key and the first helper data based on the second random number.
[0020] In a possible design, the second public key and the second private key are a pair of asymmetric encryption keys.
[0021] According to the method above, the computing device generates the second public key, the second private key, and the first helper data corresponding to the first user or each AI digital agent of the first user based on the biometric information of the first user and the identification information of the first user or AI digital agent, thereby verifying the first user or AI digital agent and strengthening the management of the AI digital agent. And, this method is also useful for key revocation and easy trace back for audit purposes.
[0022] In a possible design, the obtaining a second random number based on the biometric information of the first user and the first string includes: obtaining a third string based on the biometric information of the first user; and obtaining the second random number based on a first random number generator, the third string and the first string, where when inputs of the first random number generator are the same, outputs of the first random number generator are the same.
[0023] In a possible design, the third string is obtained based on the biometric information of the first user and the first data extractor. The first data extractor is designed based on error tolerant cryptographic primitives, such as the fuzzy extractor.
[0024] In a possible design, the first random number generator is the PRNG.
[0025] In a possible design, the third string is deleted after obtaining the second random number, or the third string is not stored in any device after obtaining the second random number.
[0026] According to the method above, the third string does not reveal any biometric information and is hence safe to use online, which achieves the privacy preserving aspect. And, the third string does not need to be stored, or the third string can be deleted after using, thereby achieving privacy preserving.
[0027] In a possible design, a decentralized identity (DID) document of the first user or the first AI digital agent includes at least one of: the first helper data, the second public key, or a first identification, and the first identification is obtained based on the second random number.
[0028] In a possible design, the DID document is stored in a first storage space, and the first storage space belongs to a local device of the first user or a cloud storage space of the first user.
[0029] According to the method above, the computing device generates an identification for the user or each AI digital agent of the user, thereby achieving identity binding between the user and the AI digital agent, making it easy for verification on-demand.
[0030] In a possible design, the biometric information includes at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris.
[0031] According to the method above, the computing device uses different biometric information of the user for identity verification based on different application scenarios.
[0032] According to a second aspect, an embodiment of this application provides a method of verification. This method includes: obtaining biometric information of a first user; obtaining a second random number based on the biometric information of the first user and a first string, where the first string is obtained based on an identification of the first user and / or an identification of a first artificial intelligence (AI) digital agent, and the first AI digital agent belongs to the first user; and obtaining a second private key, a second public key and first helper data based on the second random number, where the second private key, the second public key and the first helper data are used to verify the first user or the first AI digital agent.
[0033] According to the method above, the computing device generates the second public key, the second private key, and the first helper data corresponding to the first user or each AI digital agent of the first user based on the biometric information of the first user and the identification information of the first user or AI digital agent, thereby verifying the identity of the first user or the identity of the owner of the AI digital agent and strengthening the management of the AI digital agent. And, this method is also useful for key revocation and easy trace back for audit purposes.
[0034] In a possible design, the second public key and the second private key are a pair of asymmetric encryption keys.
[0035] In a possible design, the obtaining a second random number based on the biometric information of the first user and a first string includes: obtaining a third string based on the biometric information of the first user; and obtaining the second random number based on a first random number generator, the third string and the first string, where when inputs of the first random number generator are the same, outputs of the first random number generator are the same.
[0036] According to the method above, the third string does not reveal any biometric information and is hence safe to use online, which achieves privacy preserving aspect.
[0037] In a possible design, the third string is obtained based on the biometric information of the first user and the first data extractor. The first data extractor is designed based on error tolerant cryptographic primitives, such as the fuzzy extractor.
[0038] In a possible design, the first random number generator is the PRNG.
[0039] In a possible design, the third string is deleted after obtaining the second random number, or the third string is not stored in any device after obtaining the second random number.
[0040] According to the method above, the third string generated based on the biometric information of user does not need to be stored, or the third string can be deleted after using, thereby achieving privacy preserving.
[0041] In a possible design, the method further includes: obtaining a DID document of the first user or the first AI digital agent, where the DID document includes at least one of: the first helper data, the second public key, or a first identification, and the first identification is obtained based on the second random number.
[0042] According to the method above, the computing device generates the DID document for the user or AI digital agent, and stores information for identity verification in the DID document, making it easier to verify the identity of the user or AI digital agent and strengthen the management of the AI digital agent.
[0043] In a possible design, the DID document is stored in a first storage space, and the first storage space belongs to a local device of the first user or a cloud storage space of the first user.
[0044] In a possible design, the biometric information includes at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris.
[0045] According to the method above, the computing device uses different biometric information of user for identity verification based on different application scenarios.
[0046] According to a third aspect, an embodiment of this application provides a device for verification. This device includes: an obtaining unit configured to obtain a first verification string and first helper data; a processing unit configured to obtain a first random number based on biometric information of a second user and a first string, where the first string is obtained based on an identification of a first user and / or an identification of a first artificial intelligence (AI) digital agent, and the first AI digital agent belongs to the first user; obtain a first private key based on the first random number and the first helper data; obtain a second verification string by verifying a first digital signature based on a second public key, where the first digital signature is obtained by signing the first verification string based on the first private key, and the second public key is generated based on biometric information of the first user; and verify the second verification string based on the first verification string.
[0047] In a possible design, the first verification string is used to verify the first user or the first AI digital agent. The first helper data is stored in a DID document of the first user or the first AI digital agent.
[0048] In a possible design, the first private key belongs to a pair of asymmetric encryption keys. The second public key belongs to a pair of asymmetric encryption keys.
[0049] In a possible design, the processing unit is configured to: obtain a second string based on the biometric information of the second user; and obtain the first random number based on a first random number generator, the second string and the first string, where when inputs of the first random number generator are the same, outputs of the first random number generator are the same.
[0050] In a possible design, the second string is obtained based on the biometric information of the second user and the first data extractor. The first data extractor is designed based on error tolerant cryptographic primitives, such as the fuzzy extractor.
[0051] In a possible design, the first random number generator is the PRNG.
[0052] In a possible design, the second string is deleted after obtaining the first random number, or the second string is not stored in any device after obtaining the first random number.
[0053] In a possible design, when the first verification string and the second verification string are the same, the processing unit is configured to determine the first user and the second user are the same; or when the first verification string and the second verification string are different, the processing unit is configured to determine the first user and the second user are different.
[0054] In a possible design, the processing unit is configured to obtain a verification result based on the first verification string and the second verification string, where the verification result is used to indicate whether the first user and the second user are the same.
[0055] In a possible design, the processing unit is configured to: obtain a second random number based on the biometric information of the first user and the first string; and obtain a second private key, the second public key and the first helper data based on the second random number.
[0056] In a possible design, the second public key and the second private key are a pair of asymmetric encryption keys.
[0057] In a possible design, the processing unit is configured to: obtain a third string based on the biometric information of the first user; and obtain the second random number based on a first random number generator, the third string and the first string, where when inputs of the first random number generator are the same, outputs of the first random number generator are the same.
[0058] In a possible design, the third string is obtained based on the biometric information of the first user and the first data extractor. The first data extractor is designed based on error tolerant cryptographic primitives, such as the fuzzy extractor.
[0059] In a possible design, the first random number generator is the PRNG.
[0060] In a possible design, the third string is deleted after obtaining the second random number, or the third string is not stored in any device after obtaining the second random number.
[0061] In a possible design, the DID document of the first user or the first AI digital agent includes at least one of: the first helper data, the second public key, or a first identification, and the first identification is obtained based on the second random number.
[0062] In a possible design, the DID document is stored in a first storage space, and the first storage space belongs to a local device of the first user or a cloud storage space of the first user.
[0063] In a possible design, the biometric information includes at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris.
[0064] According to a fourth aspect, an embodiment of this application provides a device for verification. This device includes: an obtaining unit configured to obtain biometric information of a first user; and a processing unit configured to obtain a second random number based on the biometric information of the first user and a first string, where the first string is obtained based on an identification of the first user and / or an identification of a first artificial intelligence (AI) digital agent, and the first AI digital agent belongs to the first user; and the processing unit is further configured to obtain a second private key, a second public key and first helper data based on the second random number, where the second private key, and the second public key and the first helper data are used to verify the first user or the first AI digital agent.
[0065] In a possible design, the second public key and the second private key are a pair of asymmetric encryption keys.
[0066] In a possible design, the processing unit is configured to: obtain a third string based on the biometric information of the first user; and obtain the second random number based on a first random number generator, the third string and the first string, where when inputs of the first random number generator are the same, outputs of the first random number generator are the same.
[0067] In a possible design, the third string is obtained based on the biometric information of the first user and the first data extractor. The first data extractor is designed based on error tolerant cryptographic primitives, such as the fuzzy extractor.
[0068] In a possible design, the first random number generator is the PRNG.
[0069] In a possible design, the third string is deleted after obtaining the second random number, or the third string is not stored in any device after obtaining the second random number.
[0070] In a possible design, the processing unit is further configured to obtain a decentralized identity (DID) document of the first user or the first AI digital agent, where the DID document includes at least one of: the first helper data, the second public key, or a first identification, and the first identification is obtained based on the second random number.
[0071] In a possible design, the DID document is stored in a first storage space, and the first storage space belongs to a local device of the first user or a cloud storage space of the first user.
[0072] In a possible design, the biometric information includes at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris.
[0073] According to a fifth aspect, an embodiment of this application provides a computing device cluster, including at least one computing device, where the at least one computing device includes a processor and a memory coupled with the processor, where the memory is configured to store a computer program, and the processor is configured to invoke and run the computer program stored in the memory, so that the at least one computing device executes the method in any one of the first aspect, the second aspect or any possible design of the first aspect or the second aspect.
[0074] According to a sixth aspect, an embodiment of this application provides a computer program product including instructions, where when the computer program product is run on a server, the server is enabled to perform the method in any one of the first aspect, the second aspect or any possible design of the first aspect or the second aspect.
[0075] According to a seventh aspect, an embodiment of this application provides a computer readable storage medium including instructions, where when run on a server, the server is enabled to perform the method in any one of the first aspect, the second aspect or any possible design of the first aspect or the second aspect.
[0076] According to an eighth aspect, an embodiment of this application provides a chip system, where the chip system includes a logic circuit, the logic circuit is coupled with an input / output interface which is used to transmit data, so that the chip system executes the method in any one of the first aspect, the second aspect or any possible design of the first aspect or the second aspect.DESCRIPTION OF DRAWINGS
[0077] FIG. 1 is a schematic block diagram of a system for verification according to an embodiment of this application.
[0078] FIG. 2 is a schematic diagram of a method of verification according to an embodiment of this application.
[0079] FIG. 3 is a schematic diagram of a method of verification according to an embodiment of this application.
[0080] FIG. 4 is a schematic diagram of a method of verification according to an embodiment of this application.
[0081] FIG. 5 is a schematic diagram of a method of verification according to an embodiment of this application.
[0082] FIG. 6 shows an example of a DID document.
[0083] FIG. 7 is a schematic diagram of a device for verification according to an embodiment of this application.
[0084] FIG. 8 is a schematic block diagram of a computing device according to an embodiment of this application.
[0085] FIG. 9 is a schematic block diagram of a computing device cluster according to an embodiment of this application.
[0086] FIG. 10 is a schematic block diagram of a computing device 800A and a computing device 800B connected by a network according to an embodiment of this application.DESCRIPTION OF EMBODIMENTS
[0087] The following describes the technical solutions in the present application with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, but not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without making creative labor shall fall within the scope of protection of the present application.
[0088] The present application will present aspects, embodiments, or features around systems that include multiple devices, components, modules, etc. It should be understood and appreciated that the individual systems may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in connection with the accompanying drawings. In addition, combinations of these options may be used.
[0089] In addition, in the embodiments of the present application, the word "exemplarily" and the phrase "as an example" are used to indicate for example, illustration or description. Any embodiment or design solution described as "exemplarily" in this application should not be construed as being superior to or more advantageous than other embodiments or design solutions. Rather, the use of the word "example" is intended to present the concept in a specific manner.
[0090] The phrases "in some possible embodiments" , "in some possible application scenarios" , etc., appearing in various places in this description, do not necessarily refer to the same embodiments, but rather mean "one or more, but not all, embodiments" unless otherwise specifically emphasized. Unless otherwise specifically emphasized, the terms "including" , "comprising" , "having" , and variations thereof all mean "including but not limited to" .
[0091] In the present application, "at least one" refers to one or more, and "multiple" refers to two or more. "and / or" , describing the association of the associated objects, indicates that three relationships can exist. For example, A and / or B can mean A alone, both A and B, and B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following associated objects are in an "or" relationship.
[0092] The application scenarios described in the present application embodiments are intended to illustrate the technical solutions of the present application embodiments more clearly and do not constitute a limitation to the technical solutions provided by the present application embodiments. It is known to those of ordinary skill in the art that the technical solutions provided by the present application embodiments are equally applicable to similar technical problems as the system architecture evolves and new application scenarios emerge.
[0093] The technical solution in the embodiments of the present application is applied to computing devices, such as servers, hosts, personal computers, laptops, desktop computers, etc. The server is a local server or a cloud server.
[0094] An AI digital agent in the embodiments of the present application is a digital agent with an AI capability, which is generated and used for specific applications. The AI digital agent can be authorized to perform certain routine tasks on behalf of a real user, such as online purchasing of items, booking tickets, holding items, etc. Each real user deploys multiple AI digital agents on different personal devices. That is, at least one AI digital agent of the user is deployed on each device of the user, and the AI digital agents deployed on different devices of the user are the same or different.
[0095] A string in the embodiments of the present application includes at least one character, which includes at least one of: letters, numbers, symbols, etc.
[0096] FIG. 1 is a schematic block diagram of a system for verification according to an embodiment of this application. The system 100 for verification in FIG. 1 includes a computing device 110, and the computing device 110 includes a processing module 111 and a storage module 112.
[0097] The processing module 111 is used to obtain a first verification string and first helper data. The first verification string is used to verify a first user or a first AI digital agent. The processing module 111 is further used to obtain a first random number based on biometric information of a second user and a first string, where the first string is obtained based on an identification of a first user and / or an identification of a first AI digital agent, and the first AI digital agent belongs to the first user. The processing module 111 is further used to obtain a first private key based on the first random number and the first helper data. The first private key belongs to a pair of asymmetric encryption keys. The processing module 111 is further used to obtain a second verification string by verifying a first digital signature based on a second public key, where the first digital signature is obtained by signing the first verification string based on the first private key, and the second public key is generated based on biometric information of the first user. The second public key belongs to a pair of asymmetric encryption keys. The processing module 111 is further used to verify the second verification string based on the first verification string. The specific implementation is described in FIG. 2.
[0098] For example, the computing device 110 belongs to the first user. Alternatively, the computing device 110 does not belong to the first user.
[0099] For example, the computing device 110 is used to verify the identity of the first user or the first AI digital agent (such as an AI digital agent 113, an AI digital agent 114, or an AI digital agent 123, etc. ) , and / or the computing device 110 is used to generates a pair of symmetric encryption keys corresponding to the user or the first AI digital agent.
[0100] In some embodiments, the processing module 111 is used to obtain a second random number based on the biometric information of the first user and a first string. The first string is obtained based on an identification of the first user and / or an identification of a first AI digital agent. The processing module 111 is also used to obtain a second private key, a second public key and first helper data based on the second random number. The second public key and the second private key are a pair of asymmetric encryption keys. The specific implementation is described in FIG. 3.
[0101] In some embodiments, the processing module 111 is used to obtain a DID document of the first user or the first AI digital agent. The DID document includes at least one of: the first helper data, the second public key, or the first identification, and the first identification is obtained based on the second random number.
[0102] In some embodiments, the processing module 111 is used to create at least one AI digital agent for the user for each personal device / smart device / hardware / cloud system service of the user. The processing module 111 is used to create an AI digital agent in the computing device 110 (such as an AI digital agent 113 and / or an AI digital agent 114) for the first user, and / or the processing module 111 is used to create an AI digital agent in the computing device 120 (such as an AI digital agent 123) for the first user. The computing device 120 belongs to the first user.
[0103] The storage module 112 is used to store various data required or generated by the processing module 111. For example, the storage module 112 is used to store at least one of: the first verification string, the first private key, the first digital signature, the DID document, etc.
[0104] In some embodiments, when the AI digital agent 113 and / or the AI digital agent 114 are included in the computing device 110, the storage module 112 is further used to store secret keys used by the AI digital agent for various purposes, such as data encryption, digital signature, authentication, etc. Alternatively, the storage module 112 is further used to store a key table for recording at least one key and the status of each key used by the user and / or the user's AI digital agent. Among them, the status of the key includes: active, expired, revoked, etc.
[0105] The AI digital agent 113 is used to run an AI digital agent (such as a first AI digital agent) of the user in the computing device 110 to implement the function of the first AI digital agent, such as purchasing goods, booking tickets, holding items, etc. The AI digital agent 114 is used to run another AI digital agent (such as a second AI digital agent) of the user. The first AI digital agent is different from the second AI digital agent.
[0106] In some embodiments, the computing device 110 is connected to the computing device 120. The computing device 120 includes a processing module 121, a storage module 122, and an AI digital agent 123. The processing module 111 in the computing device 110 independently executes the method in the embodiments of the present application. Alternatively, the processing module 121 in the computing device 120 independently executes the method in the in the embodiments of the present application. Alternatively, the processing module 111 and the processing module 121 jointly execute the method in the in the embodiments of the present application. The function of the storage module 122 and the storage module 112 are similar. The AI digital agent 123 is similar to the AI digital agent 113.
[0107] In the system for verification in FIG. 1, the computing device generates the first private key for verification based on the second user's biometric information and the identification of the first user and / or the first AI digital agent, thereby obtaining the first digital signature by signing the first verification string based on the first private key. The computing devices obtains the second verification string by verifying a first digital signature based on a second public key, thereby verifying the identity of a user or the identity of the owner of an AI digital agent based on the first verification string and the second verification string, and strengthening the management of the AI digital agent. Further, generating the first random number based on the biometric information of the second user and the identification of the first user and / or AI digital agent eliminates the storage of private information (such as biometric information) of the user. At the same time, the first private key is generated based on the first random number to achieve identity verification, which proves the presence of the user and / or proof of ownership of the AI digital agent.
[0108] FIG. 2 is a schematic diagram of a method of verification according to an embodiment of this application. The method in FIG. 2 is applied to the system for verification in FIG. 1. The method in FIG. 2 is executed by either the computing device 110 or the computing device 120 in FIG. 1. The method in FIG. 2 includes the following steps.
[0109] Step 210: obtaining a first verification string and first helper data.
[0110] The computing device receives the first verification string. The first verification string is used for authentication. The first verification string includes at least one character, which includes at least one of: letters, numbers, symbols, etc.
[0111] In some embodiments, the first verification string is sent by an external service that is interested to verify the AI digital agent or the owner of the AI digital agent. This external service is deployed on another device connected to the computing device. Alternatively, the external service is deployed on a cloud server.
[0112] In some embodiments, the first verification string is a randomly generated string. Alternatively, the first verification string is determined based on the identification of the external service. Alternatively, the first verification string is determined based on time of verification, for example, the time of verification is the time when the external service initiates the verification.
[0113] The computing device obtains the first helper data. The first helper data is stored in the DID document of the first user or the first AI digital agent. The first AI digital agent belongs to the first user. The first user has at least one AI digital agent, and the first AI digital agent belongs to the at least one AI digital agent. The first helper data includes at least one character, which includes at least one of: letters, numbers, symbols, etc.
[0114] In some embodiments, the DID document is stored in a first storage space, and the first storage space belongs to a local device of the first user or a cloud storage space of the first user.
[0115] In some embodiments, the DID document of the first user is securely stored in the wallet of the first user's device. The DID document of the first AI digital agent is securely stored in the wallet of the AI digital agent.
[0116] For example, when the first verification string is used to verify the identity of the first user, the first helper data belongs to the DID document of the first user. When the first verification string is used to verify the identity of the first AI digital agent, the first helper data belongs to the DID document of the first AI digital agent.
[0117] In some embodiments, the computing device obtains the DID document of the first user or the first AI digital agent before the step 210. Alternatively, the computing device obtains the first helper data before the step 210.
[0118] In some embodiments, a method of generating the first helper data is described in FIG. 3.
[0119] In some embodiments, the external service sends the first verification string to a device of the first user or a device including the first AI digital agent. The device of the first user obtains the first helper data from the DID document of the first user, or the device including the first AI digital agent obtains the first helper data from the DID document of the first AI digital agent. The device of the first user or the device including the first AI digital agent sends the first verification string and first helper data to the computing device which is used to verify the identity of the first user or the first AI digital agent.
[0120] In some embodiments, the device of the first user and the device including the first AI digital agent are the same or different. The device of the first user and the computing device which is used to verify the identity of the first user or the first AI digital agent are the same or different.
[0121] Step 220, obtaining a first random number based on biometric information of a second user and a first string.
[0122] Optionally, after obtaining the first verification string, the computing device requests the second user to input biometric information for liveliness detection and proof of presence of a real owner. In other words, the biometric information of the second user can be input in real-time by the second user.
[0123] Optionally, the computing device provides a first graphical interface to the second user, allowing the second user to input the biometric information in the first graphical interface. The embodiments of the present application do not limit the specific form of the first graphical interface.
[0124] Optionally, the biometric information of user includes at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris, etc.
[0125] The computing device obtains a first random number based on the biometric information of the second user and the first string. The first string is obtained based on an identification of the first user and / or an identification of the first AI digital agent. The first string includes at least one character, which includes at least one of: letters, numbers, symbols, etc.
[0126] In some embodiments, the first string includes some or all characters in the identification of the first user and / or the identification of the first AI digital agent. Alternatively, the first string includes some or all characters in a string obtained by converting the identification of the first user and / or the identification of the first AI digital agent into m-base. The value of m is a positive integer, and the specific value of m in the embodiments of the present application is not limited.
[0127] For example, the first string is obtained by converting the identification of the first user and / or the identification of the first AI digital agent into hexadecimal.
[0128] In some embodiments, the computing device inputs the biometric information of the second user and the first string into the second random number generator to obtain the output of the second random number generator: the first random number. When the difference of the inputs of the second random number generator is small, the random numbers output by the second random number generator are the same. For example, when the difference in biometric information between two inputs is less than the first preset threshold and the first string is the same, the second random number generator outputs the same random number twice. The specific value of the first preset threshold is not limited in the embodiments of the present application.
[0129] For example, the second random number generator includes a data extractor designed based on error tolerant cryptographic primitives and a pseudo random number generator (PRNG) . For example, the second random number generator includes a fuzzy extractor and a PRNG. The fuzzy extractor is described in the paper titled "Fuzzy extractors: How to generate strong keys from biology and other noise data" . The PRNG is the national institute of standards and technology (NIST) approved pseudo random number generator, such as NIST 800-90 deterministic random bit generator (DRBG) .
[0130] For example, the fuzzy extractor includes a Gen function and a Rep function. The computing device inputs a first input string into the Gen function, thereby obtaining the outputs of the Gen function: a second helper data and a first output string. The computing device inputs a second input string and the second helper data into the Rep function, thereby obtaining the outputs of the Rep function: the first output string. The second input string is similar to the first input string. Alternatively, the difference between the second input string and the first input string is less than a second preset threshold. The specific value of the second preset threshold is not limited in the embodiments of the present application.
[0131] Optionally, the computing device obtains a second string based on the biometric information of the second user. The second string does not reveal any biometric information and is hence safe to use online, thereby achieving the privacy preserving. The second string includes at least one character, which includes at least one of: letters, numbers, symbols, etc. The computing device obtains the first random number based on a first random number generator, the second string and the first string. When inputs of the first random number generator are the same, outputs of the first random number generator are the same. In other words, the computing device inputs the second string and the first string into the first random number generator, thereby obtaining the output of the first random number generator: the first random number.
[0132] For example, the first random number generator is the PRNG.
[0133] In some embodiments, the computing device obtains the second string based on the biometric information of the second user and the first data extractor. That is, the computing device inputs the biometric information of the second user into the first data extractor, thereby obtaining the output of the first data extractor: the second string. Even if there are slight differences in the biometric information inputted multiple times by the same user, the first data extractor still outputs the same string.
[0134] For example, the first data extractor is designed based on error tolerant cryptographic primitives. The first data extractor is the fuzzy extractor.
[0135] In some embodiments, the second string does not need to be stored. Alternatively, the second string is deleted after obtaining the first random number. Alternatively, the second string is not stored in any device after obtaining the first random number.
[0136] Step 230, obtaining a first private key based on the first random number and the first helper data.
[0137] Optionally, the computing device inputs the first random number and the first helper data into a first key generator, thereby obtaining the outputs of the first key generator: a first public key and a first private key. The first public key and the first private key belong to a pair of asymmetric encryption keys. The first key generator is used to generate a pair of asymmetric encryption keys based on a random number and helper data.
[0138] In some embodiments, the first key generator includes a first Rep function in a first fuzzy extractor and a first asymmetric encryption key generation function. For example, the computing device inputs the first random number and the first helper data into the first Rep function, thereby obtaining the outputs of the first Rep function: a second output string. The computing device inputs the second output string into the first asymmetric encryption key generation function, thereby obtaining the outputs of the first asymmetric encryption key generation function: the first public key and the first private key. The first fuzzy extractor includes: the first Rep function and a first Gen function described in FIG. 3. The specific type of the first asymmetric encryption key generation function in the embodiments of the present application is not limited, and any function in the prior art that obtains a pair of asymmetric encryption keys based on an input string can be applied.
[0139] Optionally, steps 220 and 230 can be merged into one step. In some embodiments, the computing device inputs the biometric information of the second user, the first string and the first helper data into a second key generator, thereby obtaining the outputs of the second key generator: the first public key and the first private key. The second key generator is used to generate a pair of asymmetric encryption keys based on a user's biometric information, a string and helper data.
[0140] In some embodiments, the second key generator includes: the second random number generator and the first key generator.
[0141] Step 240, obtaining a second verification string by verifying a first digital signature based on a second public key.
[0142] The computing device obtains a second verification string by verifying the first digital signature based on the second public key. The first digital signature is obtained by signing the first verification string based on the first private key. The embodiments of the present application do not limit the specific algorithm of the digital signature. The second public key is generated based on biometric information of the first user.
[0143] Optionally, the computing device obtains the first digital signature before step 240. In some embodiments, the computing device signs the first verification string based on the first private key to generate the first digital signature. Alternatively, the device of the first user or the device including the first AI digital agent signs the first verification string based on the first private key to generate the first digital signature, and sends to the computing device.
[0144] Optionally, the computing device obtains the second public key before step 240. In some embodiments, the second public key is stored in the DID document of the first user or the first AI digital agent.
[0145] In some embodiments, the DID document includes at least one of: the first helper data, the second public key, or a first identification. The first identification is obtained based on a second random number, and the second random number is used to obtain the second public key. The method of obtaining the first identification is described in FIG. 3.
[0146] In some embodiments, the method of obtaining the second public key includes: inputting the biometric information of the first user and the first string into the third key generator, and obtaining the output of the third key generator: the first helper data, the second public key, and a second private key. The third key generator is used to generate a pair of asymmetric encryption keys and helper data based on the user's biometric information and the first string.
[0147] In some embodiments, the relationship between the second key generator in step 230 and the third key generator includes: the third key generator generates a public key PK-A, a private key SK-A and helper data Data-A based on the user's biometric information and the first string, and the second key generator generates the public key PK-A, the private key SK-Abased on the same user's biometric information, the first string and the helper data Data-A. The key generator that achieves the above functions in the prior art are all applicable to the embodiments of the present application.
[0148] In some embodiments, the third key generator includes: the second random number generator and a fourth key generator. The third key generator and the fourth key generator are described in FIG. 3.
[0149] Step 250, verifying the second verification string based on the first verification string.
[0150] The computing device performs identity verification based on the first verification string and the second verification string. In some embodiments, when the first verification string and the second verification string are the same, the computing device determines the first user and the second user are the same, or the second user is the true owner of the first AI digital agent. That is, the verification is successful. When the first verification string and the second verification string are different, the computing device determines the first user and the second user are different, or the second user is not the true owner of the first AI digital agent. That is, the verification is failed.
[0151] Optionally, steps 240 and 250 can be merged into one step. In some embodiments, the computing device obtains a verification result by verifying the first digital signature based on the second public key and the first verification string. For example, the computing device inputs the first digital signature, the second public key and the first verification string into a validator, thereby obtaining the output of the validator: the verification result. The validator is used to verify the digital signature. The verification result is used to indicate whether the first user and the second user are the same. For example, the verification result includes: the second user and the first user are the same or different, or the second user and the owner of the first AI digital agent are the same or different.
[0152] In the method in FIG. 2, the computing device generates the first private key for verification based on the second user's biometric information and the identification of the first user and / or the first AI digital agent, thereby obtaining the first digital signature by signing the first verification string based on the first private key. The computing devices obtains the second verification string by verifying a first digital signature based on a second public key, thereby verifying the identity of a user or the identity of the owner of an AI digital agent based on the first verification string and the second verification string, and strengthening the management of the AI digital agent. Further, generating the first random number based on the biometric information of the second user and the identification of the first user and / or AI digital agent eliminates the storage of private information (such as biometric information) of the user. At the same time, the first private key is generated based on the first random number to achieve identity verification, which proves the presence of the user and / or proof of ownership of the AI digital agent.
[0153] FIG. 3 is a schematic diagram of a method of verification according to an embodiment of this application. The method in FIG. 3 is applied to the system for verification in FIG. 1. The method in FIG. 3 is executed by either the computing device 110 or the computing device 120 in FIG. 1. The method in FIG. 3 includes the following steps.
[0154] Step 310, obtaining biometric information of a first user.
[0155] Optionally, the computing device provides a second graphical interface to the first user, allowing the first user to input the biometric information in the second graphical interface. The embodiments of the present application do not limit the specific form of the second graphical interface.
[0156] Optionally, the biometric information of user includes at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris, etc.
[0157] Step 320, obtaining a second random number based on the biometric information of the first user and a first string.
[0158] The first string is obtained based on the identification of the first user and / or the identification of a first AI digital agent, and the first AI digital agent belongs to the first user. The first string is similar to the first string in step 220.
[0159] Optionally, the computing device inputs the biometric information of the first user and the first string into the second random number generator to obtain the output of the second random number generator: the second random number. When the difference of the inputs of the second random number generator is small, the random numbers output by the second random number generator are the same. For example, when the difference in biometric information between two inputs is less than the first preset threshold and the first string is the same, the second random number generator outputs the same random number twice.
[0160] For example, the second random number generator includes a data extractor designed based on error tolerant cryptographic primitives and a pseudo random number generator. For example, the second random number generator includes the fuzzy extractor and the PRNG as described in step 220.
[0161] Optionally, the computing device obtains a third string based on the biometric information of the first user. The third string does not reveal any biometric information and is hence safe to use online, thereby achieving the privacy preserving. The third string includes at least one character, which includes at least one of: letters, numbers, symbols, etc. The computing device obtains the second random number based on the first random number generator, the third string and the first string. When inputs of the first random number generator are the same, outputs of the first random number generator are the same. In other words, the computing device inputs the third string and the first string into the first random number generator, thereby obtaining the output of the first random number generator: the second random number. The first random number generator is described in step 220.
[0162] In some embodiments, the computing device obtains the third string based on the biometric information of the first user and the first data extractor. That is, the computing device inputs the biometric information of the first user into the first data extractor, thereby obtaining the output of the first data extractor: the third string. The first data extractor is described in step 220.
[0163] In some embodiments, the third string does not need to be stored. Alternatively, the third string is deleted after obtaining the first random number. Alternatively, the third string is not stored in any device after obtaining the first random number.
[0164] Step 330, obtaining a second private key, a second public key and a first helper data based on the second random number.
[0165] In some embodiments, the computing device inputs the second random number into the fourth key generator, and obtains the output of the fourth key generator: the first helper data, the second public key, and the second private key. The second private key, the second public key and the first helper data are used for identity verification. The second public key and the second private key are a pair of asymmetric encryption keys.
[0166] In some embodiments, the fourth key generator includes the first Gen function in the first fuzzy extractor and the first asymmetric encryption key generation function. For example, the computing device inputs the second random number into the first Gen function, thereby obtaining the outputs of the first Gen function: the first helper data and a third output string. The computing device inputs the third output string into the first asymmetric encryption key generation function, thereby obtaining the outputs of the first asymmetric encryption key generation function: the second public key and the second private key. The first fuzzy extractor and the first asymmetric encryption key generation function are described in step 230.
[0167] When the first user and the second user are the same, the first random number in step 220 is the same as the second random number in step 320. When the first random number and the second random number are the same, the third output string and the second output string are the same. The third output string and the first helper data is obtained by inputting the second random number into the first Gen function, and the second output string is obtained by inputting the first helper data and the first random number into the first Rep function. When the second output string and the third output string are the same, the first public key is the same as the second public key, and the first private key is the same as the second private key. When the first user and the second user are different, the first random number in step 220 is different from the second random number in step 320. When the first random number and the second random number are different, the third output string and the second output string are different. When the second output string and the third output string are different, the first public key is different from the second public key, and the first private key is different from the second private key. Therefore, identity verification is achieved through the method described in the embodiments of the present application.
[0168] In some embodiments, the relationship between the first key generator in step 230 and the fourth key generator includes: the fourth key generator generates a public key PK-B, a private key SK-B and helper data Data-B based on the second random number, and the first key generator generates the public key PK-B, the private key SK-B based on the second random number and the helper data Data-B. The key generator that achieves the above functions in the prior art are all applicable to the embodiments of the present application.
[0169] In some embodiments, the computing device generates the DID document of the first user or the first AI digital agent. The DID document includes at least one of: the first helper data, the second public key, or a first identification. The first identification is obtained based on the second random number.
[0170] In some embodiments, the first identification is obtained based on the hash value of the second random number. For example, the first identification is the hash value of the second random number. Alternatively, the first identification includes n bits of the hash value of the second random number, and n is a positive integer. The embodiments of present application do not limit the value of n.
[0171] For example, the first identification includes the first 20 bits of the hash value of the second random number.
[0172] In some embodiments, at least one of following is public: the second random number, the second public key, or the first helper data.
[0173] In some embodiments, the DID document and / or the second private key are securely stored in the wallet of the first user or the first AI digital agent.
[0174] In some embodiments, the computing device repeats the method in FIG. 3 for each AI digital agent of the user, thereby generating at least one of the following for each AI digital agent: the DID document, the second random number, the first helper data, the second public key, and the second private key.
[0175] In the method shown in FIG. 3, the computing device generates the second public key, the second private key, and the first helper data for each AI digital agent of the user based on the user's biometric information and the identification of the user or AI digital agent, thereby verifying the identity of the user or the identity of the owner of the AI digital agent. The computing devices also assign the first identification to the first AI digital agent, making it easier to track / assign / link to corresponding users. In the process of generating the public key and the private key corresponding to the AI digital agent, the user's biometric information is not stored, and the third string generated based on the user's biometric information is also not stored. Therefore, it is convenient to protect the user's privacy, achieve self-sovereign identity (SSI) and privacy protection. Meanwhile, the binding of the digital identity of the AI digital agent and user / owner is done automatically, without the need for explicit binding, and it is easy for verification on-demand. The method in FIG. 3 is also useful for key revocation and easy trace back for audit purposes.
[0176] FIG. 4 is a schematic diagram of a method of verification according to an embodiment of this application. The method in FIG. 4 is applied to the system for verification in FIG. 1. The method in FIG. 4 is executed by either the computing device 110 or the computing device 120 in FIG. 1. The method in FIG. 4 includes the following steps.
[0177] (1) The biometric information of the first user is input into a first data extractor 410 to generate a third string. The third string does not reveal any biometric information and is hence safe to use online, achieving privacy protection. The function of the first data extractor 410 is similar to that of the first data extractor in step 320.
[0178] (2) The third string and the first string are input into a first random number generator 420 to generate the second random number. The first string is described in step 320. The first random number generator 420 is similar to the first random number generator in step 320. The second random number is stored in the DID document of the first user or the first AI digital agent. Alternatively, the first identification obtained based on the second random number is stored in the DID document.
[0179] (3) The second random number is input into a fourth key generator 430 to generate the first helper data, the second public key, and the second private key. The fourth key generator 430, the first helper data, the second public key, and the second private key are described in step 330.
[0180] FIG. 5 is a schematic diagram of a method of verification according to an embodiment of this application. The method in FIG. 5 is applied to the system for verification in FIG. 1. The method in FIG. 5 is executed by either the computing device 110 or the computing device 120 in FIG. 1. The method in FIG. 5 includes the following steps.
[0181] (1) The biometric information of the second user is input into a first data extractor 510 to generate the second string. The second string does not reveal any biometric information and is hence safe to use online, achieving privacy protection. The first data extractor 510 is similar to the first data extractor 410.
[0182] (2) The second string and the first string are input into a first random number generator 520 to generate the first random number. The first string is the same as the first string in FIG. 4. The first random number generator 520 is similar to the first random number generator 420.
[0183] (3) The first random number and the first helper data are input into a first key generator 530 to generate the first public key and the first private key. The first key generator 530, the first helper data, the first public key, and the first private key are described in FIG. 2. The first helper data is the same as the first helper data in FIG. 4.
[0184] (4) The first private key and the first verification string are input into a digital signature generator 540 to obtain the first digital signature. The first verification string is described in step 210, and the first digital signature is described in step 240. The digital signature generator 540 is used to sign the first verification string based on the first private key.
[0185] (5) The first digital signature and the second public key are input into a digital signature resolver 550 to obtain the second verification string. The second verification string and the second public key are described in step 240. The digital signature resolver 550 is used to verify the first digital signature based on the second public key. The second public key is the same as the second public key in FIG. 4.
[0186] (6) The first verification string and the second verification string are input into a validator 560 to obtain the verification result. The validator 560 is used to verify whether the first verification string and the second verification string are the same. When the first verification string and the second verification string are the same, the validator 560 determines the verification result includes: the second user and the first user are the same, or the second user and the owner of the first AI digital agent are the same. That is, the verification is successful. When the first verification string and the second verification string are different, the validator 560 determines the verification result includes: the second user and the first user are different, or the second user and the owner of the first AI digital agent are different. That is, the verification is failed.
[0187] FIG. 6 shows an example of a DID document. The DID document 600 in FIG. 6 is the DID document of the first user or the DID document of the first AI digital agent. The DID document 600 includes the first identification and the second public key. The first identification includes the first 20 bits of the hash value of the second random number, as described in FIG. 3 or FIG. 4. The second public key is described in FIG. 2 to FIG. 4.
[0188] FIG. 7 is a schematic diagram of a device 700 for verification according to an embodiment of this application. As shown in FIG. 7, the device 700 for verification includes: an obtaining unit 710 and a processing unit 720. The device 700 for verification implements the method as shown in FIG. 2-FIG. 5. The device 700 for verification is applied to a computing device, such as the computing device 110 or the computing device 120 in FIG. 1.
[0189] When the device 700 for verification is used to execute the method in FIG. 2, the obtaining unit 710 is configured to obtain the first verification string and the first helper data. The obtaining unit 710 performs the step 210 in FIG. 2. The processing unit 720 is configured to: obtain a first random number based on biometric information of a second user and a first string; obtain a first private key based on the first random number and the first helper data; obtain a second verification string by verifying a first digital signature based on a second public key; and verify the second verification string based on the first verification string. The processing unit 720 performs the steps 220-250 in FIG. 2.
[0190] When the device 700 for verification is used to execute the method in FIG. 3, the obtaining unit 710 is configured to obtain the biometric information of the first user. The obtaining unit 710 performs the step 310 in FIG. 3. The processing unit 720 is configured to: obtain the second random number based on the biometric information of the first user and the first string; and obtain the second private key, the second public key and the first helper data based on the second random number. The processing unit 720 performs the step 320 and the step 330 in FIG. 3.
[0191] When the device 700 for verification is used to execute the method in FIG. 4, the obtaining unit 710 is configured to obtain the biometric information of the first user and the first string. The processing unit 720 is configured to: obtain the third string based on the biometric information of the first user; obtain the second random number based on the third string and the first string; and obtain the second private key, the second public key and the first helper data based on the second random number.
[0192] When the device 700 for verification is used to execute the method in FIG. 5, the obtaining unit 710 is configured to obtain the biometric information of the second user, the first string, the first helper data, the first verification string and the second public key. The processing unit 720 is configured to: obtain the second string based on the biometric information of the second user; obtain the first random number based on the second string and the first string; obtain the first private key, the first public key based on the first random number and the first helper data; obtain the first digital signature based on the first verification string and the first private key; obtain the second verification string based on the first digital signature and the second public key; and obtain the verification result based on the first verification string and the second verification string.
[0193] In some embodiments, When the device 700 for verification is used to execute the method in FIG. 5, the obtaining unit 710 is configured to obtain the first digital signature, and the processing unit 720 is not configured to obtain the first digital signature based on the first verification string and the first private key.
[0194] Among them, both the obtaining unit 710 and the processing unit 720 are implemented through software or hardware. The processing unit 720 is taken as an example to introduce the implementation of the processing unit 720. Similarly, the implementation of the obtaining unit 710 refers to the implementation of the processing unit 720.
[0195] When the unit is an example of a software functional unit, the processing unit 720 includes code running on a computational instance. Among them, the computational instance includes at least one of physical hosts (computing devices) , virtual machines, and containers. Furthermore, the above computational instance can be one or more. For example, the processing unit 720 includes code running on multiple hosts / virtual machines / containers. It should be noted that multiple hosts / virtual machines / containers used to run the code are distributed in the same region or in different regions. Furthermore, multiple hosts / virtual machines / containers used to run the code are distributed within the same availability zone (AZ) or across different AZs, each of which includes a data center or multiple geographically close data centers. Typically, a region includes multiple AZs.
[0196] Similarly, multiple hosts / virtual machines / containers used to run the code are distributed within the same virtual private cloud (VPC) or across multiple VPCs. Among them, usually one VPC is set within a region, and cross regional communication between two VPCs within the same region, as well as VPCs from different regions, requires a communication gateway to be set up within each VPC to achieve interconnection between VPCs.
[0197] When the unit is an example of a hardware functional unit, the processing unit 720 includes at least one computing device, such as a server. Alternatively, the processing unit 720 also is a device implemented using application specific integrated circuits (ASIC) or programmable logic devices (PLD) . Among them, the above-mentioned PLD is a complex programmable logic device (CPLD) , field programmable gate array (FPGA) , general array logic (GAL) , or any combination thereof.
[0198] The multiple computing devices included in the processing unit 720 are distributed in the same region or in different regions. The multiple computing devices included in the processing unit 720 are distributed within the same AZ or across different AZs. Similarly, the multiple computing devices included in the processing unit 720 are distributed within the same VPC or across multiple VPCs. Among them, the multiple computing devices are any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0199] Therefore, the units of each example described in the embodiments of the present application are implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians may use different methods to achieve the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0200] It should be noted that the device provided in the above embodiments only provides examples of the division of various functional units when executing the above methods. In practical applications, the above functions can be assigned to different functional units according to needs, that is, the internal structure of the device can be divided into different functional units to complete all or part of the functions described above. For example, the obtaining unit 710 can be used to perform any step in the above method, and the processing unit 720 can be used to perform any step in the above method. The steps responsible for implementing the obtaining unit 710 and the processing unit 720 can be specified as needed. The obtaining unit 710 and the processing unit 720 respectively implement different steps in the above methods to achieve all the functions of the above device.
[0201] In addition, the device and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments mentioned above, which will not be repeated here.
[0202] The method provided in the embodiments of the present application may be executed by a computing device, which may also be referred to as a computer system. This includes a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on top of the operating system layer. This hardware layer includes hardware such as processing units, memory, and memory control units, followed by a detailed explanation of the hardware’s functions and structure. This operating system is any one or more computer operating systems that implement business processing through processes, such as Linux operating system, Unix operating system, Android operating system, iOS operating system, or Windows operating system. This application layer includes applications such as browsers, contacts, word processing software, instant messaging software, etc. And, alternatively, the computer system can be a handheld device such as a smartphone, or a terminal device such as a personal computer, which is not specifically limited by the present application, as long as it can be implemented through the methods provided in the embodiments of the present application. The execution subject of the method provided in the embodiments of the present application can be a computing device, or a functional module in the computing device that can call and execute the program.
[0203] FIG. 8 is a schematic block diagram of a computing device according to an embodiment of this application. The computing device 800 can be a server, a computer, or other device with computing power. The computing device 800 shown in FIG. 8 includes at least one processor 810 and a memory 820.
[0204] It should be understood that embodiments of the present application do not limit the number of processors and memory in the computing device 800.
[0205] The processor 810 executes instructions in the memory 820 to enable the computing device 800 to implement the method provided in the embodiments of the present application. Alternatively, the processor 810 executes instructions in the memory 820 to enable the computing device 800 to implement the various functional modules provided in the embodiments of the present application, thereby implementing the methods provided in the embodiments of the present application.
[0206] Optionally, the computing device 800 also includes a communication interface 830. The communication interface 830 uses transceiver modules such as but not limited to network interface cards and transceivers to achieve communication between the computing device 800 and other devices or communication networks.
[0207] Optionally, the computing device 800 also includes a system bus 840, where the processor 810, the memory 820, and the communication interface 830 are respectively connected to the system bus 840. The processor 810 can access the memory 820 through the system bus 840, for example, the processor 810 can read and write data or execute code in the memory 820 through the system bus 840. The system bus 840 is either a peripheral component interconnect express (PCI) bus or an extended industry standard architecture (EISA) bus. The system bus 840 is divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in FIG. 8, but it does not mean that there is only one bus or one type of bus.
[0208] One possible implementation is that the function of the processor 810 is mainly to interpret instructions (or code) of computer programs and process data in computer software. Among them, the instructions of the computer program and the data in the computer software can be stored in the cache of the memory 820 or the processor 810.
[0209] Optionally, the processor 810 may be an integrated circuit chip with signal processing capabilities. As an example rather than a limitation, the processor 810 is a general-purpose processor, digital signal processor (DSP) , ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component. Among them, general-purpose processors are microprocessors, etc. For example, the processor 810 is a central processing unit (CPU) .
[0210] The memory 820 can provide running space for processes in the computing device 800, for example, storing computer programs (specifically, program code) used to generate processes in the memory 820. After the computer program is run by the processor and generates a process, the processor allocates corresponding storage space for the process in the memory 820. Furthermore, the above storage space further includes text segments, initialization data segments, bit initialization data segments, stack segments, heap segments, and so on. The memory 820 stores data generated during the operation of the process, such as intermediate data or process data, in the storage space corresponding to the above process.
[0211] Optionally, the memory is used to temporarily store operational data in the processor 810 and data exchanged with external memory such as hard drives. As long as the computer is running, the processor 810 will transfer the data that needs to be processed to memory for processing, and then transmit the result after the operation is completed.
[0212] As an example rather than a limitation, the memory 820 may be either volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Among them, non-volatile memory is read-only memory (ROM) , programmable ROM (PROM) , erasable PROM (EPROM) , flash, or electrically EPROM (EEPROM) . Volatile memory is a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM) , dynamic RAM (DRAM) , synchronous DRAM (SDRAM) , double data rate SDRAM (DDR SDRAM) , enhanced synchronous DRAM (ESDRAM) , synchronous link DRAM (SLDRAM) , and direct rambus DRAM (DRDRAM) . It should be noted that the memory 820 of the system and method described in this application is intended to include but not limited to these and any other suitable types of memory.
[0213] The structure of the computing device 800 listed above is only for illustrative purposes, and this application is not limited to it. The computing device 800 in the embodiments of this application includes various hardware in computer systems in prior art. For example, the computing device 800 also includes other storage devices besides memory 820, such as disk storage, etc. Technicians in this field should understand that the computing device 800 may also include other devices necessary for normal operation. Meanwhile, according to specific needs, technical personnel in this field should understand that the above-mentioned computing device 800 may also include hardware devices for implementing other additional functions. In addition, those skilled in the art should understand that the above-mentioned computing device 800 may only include the devices necessary to implement the embodiments of the present application, without necessarily including all the devices shown in FIG. 8.
[0214] The embodiment of this application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server. In some embodiments, the computing device may also be a terminal device such as a desktop computer, laptop, or smartphone.
[0215] As shown in FIG. 9, the computing device cluster includes at least one computing device 800. The memory 820 in one or more computing devices 800 in a computing device cluster may contain the same instructions for executing the above method.
[0216] In some possible implementations, the memory 820 in one or more computing devices 800 within the computing device cluster may also hold partial instructions for executing the above method. In other words, a combination of one or more computing devices 800 can jointly execute the instructions of the above method.
[0217] It should be noted that the memory 820 in different computing devices 800 in the computing device cluster can store different instructions, which are used to perform some of the functions of the above-mentioned devices. That is to say, the instructions stored in the memory 820 of different computing devices 800 can realize the function of one or more modules in the above-mentioned device.
[0218] In some possible implementations, one or more computing devices in a computing device cluster can be connected through a network. Among them, the network can be a wide area network, a local area network, or the like. FIG. 10 illustrates a possible implementation approach. As shown in FIG. 10, two computing devices 800A and 800B are connected through a network. Specifically, the computing devices 800A and 800B are connected to the network through their communication interfaces.
[0219] It should be understood that the functionality of the computing device 800A shown in FIG. 10 can also be accomplished by multiple computing devices 800. Similarly, the functionality of computing device 800B can also be accomplished by multiple computing devices 800.
[0220] An embodiment of this application provides a computer program product including instructions, which can run on a computing devices cluster or be stored in any available medium. When it is run by a computing device cluster, the computing device cluster is made to execute the methods provided above, or the computing device cluster is made to implement the functions of the devices provided above.
[0221] An embodiment of this application provides a computer readable storage medium including instructions. The computer readable storage medium is any available medium that computing devices can store, or a data storage device such as a data center containing one or more available media. The available media can be magnetic media (such as floppy disks, hard drives, magnetic tapes) , optical media (such as digital video disc (DVD) ) , or semiconductor media (such as solid-state drives) , etc. The computer readable storage medium includes instructions. When the instructions are run on a computer device cluster, the computer device cluster executes the methods provided above.
[0222] An embodiment of this application provides a chip system, where the chip system includes a memory and a processor, the memory is configured to store a computer program, and the processor is configured to invoke the computer program from the memory and run the computer program, so that a server on which a chip is disposed performs the methods provided above.
[0223] An embodiment of this application provides a chip system, where the chip system includes a logic circuit, the logic circuit is coupled with an input / output interface which is used to transmit data, so that the chip system executes the methods provided above.
[0224] A person of ordinary skill in the art may be aware that, in combination with the examples described in the embodiments disclosed in this specification, units and algorithm steps can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed by hardware or software depends on particular applications and design constraints of the technical solutions. A person skilled in the art may use different methods to implement the described functions for each particular application, but it should not be considered that the implementation goes beyond the scope of this application.
[0225] It may be clearly understood by a person skilled in the art that, for the purpose of convenient and brief description, for a detailed working process of the foregoing system, apparatus, and unit, refer to a corresponding process in the foregoing method embodiment. Details are not described herein again.
[0226] In the several embodiments provided in this application, it should be understood that the disclosed system, apparatus, and method may be implemented in other manners. For example, the described apparatus embodiment is merely an example. For example, the unit division is merely logical function division and may be other division in actual implementation. For example, a plurality of units or components may be combined or integrated into another system, or some features may be ignored or not performed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections may be implemented through some interfaces. The indirect couplings or communication connections between the apparatuses or units may be implemented in electronic, mechanical, or other forms.
[0227] The units described as separate parts may be or may not be physically separate, and parts displayed as units may be or may not be physical units, may be located in one position, or may be distributed on a plurality of network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments.
[0228] In addition, functional units in the embodiments of this application may be integrated into one processing unit, or each of the units may exist alone physically, or two or more units are integrated into one unit.
[0229] When the functions are implemented in a form of a software functional unit and sold or used as an independent product, the functions may be stored in a computer readable storage medium. Based on such an understanding, the technical solutions in this application essentially, or the part contributing to the prior art, or some of the technical solutions may be implemented in a form of a software product. The computer software product is stored in a storage medium, and includes several instructions for instructing a computer device (which may be a personal computer, a server, a network device, or the like) to perform all or some of the steps of the methods described in the embodiments of this application. The foregoing storage medium includes: any medium that can store program code, such as a USB flash drive, a removable hard disk, a read-only memory (ROM) , a random access memory (RAM) , a magnetic disk, or an optical disc.
[0230] The foregoing descriptions are merely specific implementations of this application, but are not intended to limit the protection scope of this application. Any variation or replacement readily figured out by a person skilled in the art within the technical scope disclosed in this application shall fall within the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims.
Claims
1.A method of verification, comprising:obtaining a first verification string and first helper data;obtaining a first random number based on biometric information of a second user and a first string, wherein the first string is obtained based on an identification of a first user and / or an identification of a first artificial intelligence (AI) digital agent, and the first AI digital agent belongs to the first user;obtaining a first private key based on the first random number and the first helper data;obtaining a second verification string by verifying a first digital signature based on a second public key, wherein the first digital signature is obtained by signing the first verification string based on the first private key, and the second public key is generated based on biometric information of the first user; andverifying the second verification string based on the first verification string.2.The method according to claim 1, wherein the obtaining a first random number based on biometric information of a second user and a first string comprises:obtaining a second string based on the biometric information of the second user; andobtaining the first random number based on a first random number generator, the second string and the first string, wherein when inputs of the first random number generator are the same, outputs of the first random number generator are the same.3.The method according to claim 2, wherein the second string is deleted after obtaining the first random number, or the second string is not stored in any device after obtaining the first random number.4.The method according to any one of claims 1-3, wherein the verifying the second verification string based on the first verification string comprises:when the first verification string and the second verification string are the same, determining the first user and the second user are the same; orwhen the first verification string and the second verification string are different, determining the first user and the second user are different.5.The method according to any one of claims 1-4, wherein the method further comprises:obtaining a verification result based on the first verification string and the second verification string, wherein the verification result is used to indicate whether the first user and the second user are the same.6.The method according to any one of claims 1-5, wherein the method further comprises:obtaining a second random number based on the biometric information of the first user and the first string; andobtaining a second private key, the second public key and the first helper data based on the second random number.7.The method according to claim 6, wherein the obtaining a second random number based on the biometric information of the first user and the first string comprises:obtaining a third string based on the biometric information of the first user; andobtaining the second random number based on a first random number generator, the third string and the first string, wherein when inputs of the first random number generator are the same, outputs of the first random number generator are the same.8.The method according to claim 7, wherein the third string is deleted after obtaining the second random number, or the third string is not stored in any device after obtaining the second random number.9.The method according to any one of claims 6-8, wherein a decentralized identity (DID) document of the first user or the first AI digital agent comprises at least one of: the first helper data, the second public key, or a first identification, and the first identification is obtained based on the second random number.10.The method according to any one of claims 1-9, wherein the biometric information comprises at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris.11.A method of verification, comprising:obtaining biometric information of a first user;obtaining a second random number based on the biometric information of the first user and a first string, wherein the first string is obtained based on an identification of the first user and / or an identification of a first artificial intelligence (AI) digital agent, and the first AI digital agent belongs to the first user; andobtaining a second private key, a second public key and a first helper data based on the second random number, wherein the second private key, the second public key and the first helper data are used to verify the first user or the first AI digital agent.12.The method according to claim 11, wherein the obtaining a second random number based on the biometric information of the first user and a first string comprises:obtaining a third string based on the biometric information of the first user; andobtaining the second random number based on a first random number generator, the third string and the first string, wherein when inputs of the first random number generator are the same, outputs of the first random number generator are the same.13.The method according to claim 12, wherein the third string is deleted after obtaining the second random number, or the third string is not stored in any device after obtaining the second random number.14.The method according to any one of claims 11-13, wherein the method further comprises:obtaining a decentralized identity (DID) document of the first user or the first AI digital agent, wherein the DID document comprises at least one of: the first helper data, the second public key, or a first identification, and the first identification is obtained based on the second random number.15.The method according to any one of claims 11-14, wherein the biometric information comprises at least one of: a fingerprint, a palmprint, a face, voice, a gait, a brain wave, or an iris.16.A device for verification, wherein the device comprises units to perform the method according to any one of claims 1-10 or 11-15.17.A computing device cluster, comprising at least one computing device, wherein the at least one computing device comprises a processor and a memory coupled with the processor, wherein the memory is configured to store a computer program, and the processor is configured to invoke and run the computer program stored in the memory, so that the at least one computing device executes the method according to any one of claims 1-10 or 11-15.18.A computer program product comprising instructions, wherein when the computer program product is run on a server, the server is enabled to perform the method according to any one of claims 1-10 or 11-15.19.A computer readable storage medium storing instructions, wherein when run on a server, the computer readable storage medium enables the server to perform the method according to any one of claims 1-10 or 11-15.20.A chip system, comprising a logic circuit, wherein the logic circuit is coupled with an input / output interface which is used to transmit data, and the chip system performs the method according to any one of claims 1-10 or 11-15.
Citation Information
Patent Citations
Group data completeness verification method based on proxy
CN108664814A
Identity-based cloud server calculation correctness verification method
CN112564911A
Data link establishment method and device, equipment and storage medium
CN115412280A
Method and apparatus for user authentication
US20210105139A1
System and method of blockchain enabled social platform ecosystem to collect, create, store, process, and distribute data, digital contents, digital assets and digital identities, using artificial intelligence, smart contracts, instructions, conditions and triggers
US20240265473A1