Digital identity generation method, digital identity authentication method, electronic apparatus and computer program product

WO2026189023A1PCT designated stage Publication Date: 2026-09-17ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/074024
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-10
Filing Date
2026-01-21
Publication Date
2026-09-17

Smart Images

  • Figure CN2026074024_17092026_PF_FP_ABST
    Figure CN2026074024_17092026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present disclosure are a digital identity generation method, a digital identity authentication method, an electronic apparatus and a computer program product. The method comprises: acquiring a private key of a first digital identity, and receiving, from a second node, an authenticity proof of the first digital identity, information of the first digital identity, and a signature of the first digital identity; and generating the first digital identity on the basis of the private key of the first digital identity, the authenticity proof of the first digital identity, the information of the first digital identity, and the signature of the first digital identity. Therefore, at least the problem in the related art of it being impossible to authenticate the authenticity and ownership of a digital identity can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Digital identity generation methods, digital identity authentication methods, electronic devices and computer program products

[0001] Cross-reference of related applications

[0002] This disclosure is based on and claims priority to Chinese Patent Application No. 202510278725.5, filed on March 10, 2025, entitled “Digital Identity Generation Method, Digital Identity Authentication Method, Electronic Device and Computer Program Product”, and incorporates the entire contents of that patent application by reference. Technical Field

[0003] This disclosure relates to the field of communication technology, and more specifically, to a digital identity generation method, a digital identity authentication method, an electronic device, and a computer program product. Background Technology

[0004] A digital identity structure primarily consists of three parts: identifiers, attributes, and credentials. Identifiers are used to uniquely identify a digital identity subject, such as usernames and email addresses. Attributes describe the characteristics and information of the digital identity subject, such as name, age, gender, and address. Credentials are credentials used to verify a digital identity, such as passwords, digital certificates, and biometrics. These components together constitute a complete digital identity, used to identify and verify an entity's identity in a digital environment, but they cannot authenticate the authenticity or ownership of the digital identity. Summary of the Invention

[0005] This disclosure provides a digital identity generation method, a digital identity authentication method, an electronic device, and a computer program product to at least solve the problem of the inability to authenticate the authenticity and ownership of digital identities in related technologies.

[0006] According to one embodiment of this disclosure, a digital identity generation method is provided, applied to a first node, including:

[0007] Obtain the private key of the first digital identity, and receive the authenticity certificate of the first digital identity, the information of the first digital identity, and the signature of the first digital identity from the second node;

[0008] The first digital identity is generated based on the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

[0009] According to another embodiment of this disclosure, a digital identity authentication method is also provided, applied to a first node, comprising:

[0010] Two-way authentication is performed between the first digital identity and the fourth node, wherein the first digital identity consists of the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

[0011] According to yet another embodiment of this disclosure, a computer-readable storage medium is also provided, wherein a computer program is stored therein, wherein the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0012] According to yet another embodiment of this disclosure, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0013] According to yet another embodiment of this disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps in any of the above method embodiments. Attached Figure Description

[0014] Figure 1 is a schematic diagram of the hardware structure of the mobile terminal operating in the embodiments of the method disclosed herein;

[0015] Figure 2 is a flowchart of a digital identity generation method according to an embodiment of the present disclosure;

[0016] Figure 3 is a schematic diagram of a digital identity structure according to an embodiment of the present disclosure;

[0017] Figure 4 is a schematic diagram of a private key authenticity verification structure according to an embodiment of the present disclosure;

[0018] Figure 5 is a flowchart of a digital identity authentication method according to an embodiment of the present disclosure;

[0019] Figure 6 is a flowchart of a digital identity authentication method according to an optional embodiment of the present disclosure. Detailed Implementation

[0020] The embodiments of this disclosure will be described in detail below with reference to the accompanying drawings and examples.

[0021] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0022] The method embodiments provided in this disclosure can be executed in a mobile terminal, computer terminal, or similar computing device. Taking running on a mobile terminal as an example, FIG1 is a schematic diagram of the hardware structure of a mobile terminal running in the method embodiments of this disclosure. As shown in FIG1, the mobile terminal may include one or more (only one is shown in FIG1) processors 102 (processor 102 may include, but is not limited to, processing devices such as microprocessors MCUs or programmable logic devices FPGAs) and a memory 104 for storing data. The mobile terminal may also include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that the structure shown in FIG1 is only illustrative and does not limit the structure of the mobile terminal. For example, the mobile terminal may also include more or fewer components than shown in FIG1, or have a different configuration than shown in FIG1.

[0023] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the digital identity generation method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the mobile terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0024] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the mobile terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0025] This embodiment provides a digital identity generation method operating on the aforementioned mobile terminal or network architecture. Figure 2 is a flowchart of the digital identity generation method according to an embodiment of this disclosure. As shown in Figure 2, applied to the first node, the process includes the following steps:

[0026] Step S202: Obtain the private key of the first digital identity, and receive the authenticity certificate of the first digital identity, the information of the first digital identity, and the signature of the first digital identity from the second node;

[0027] Step S204: Generate the first digital identity based on the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

[0028] Through the above embodiments of this disclosure, a digital identity is generated based on the private key of the digital identity, the proof of authenticity of the digital identity, the information of the digital identity, and the signature. Through the proof of authenticity of the digital identity, the authenticity and ownership of the digital identity can be verified, thus solving the problem in related technologies that the authenticity and ownership of digital identities cannot be authenticated.

[0029] The generation process of digital identity is the core of a digital identity system, ensuring that the identity information of each node is unique and verifiable. The private key is crucial for digital identity generation; paired with the public key, it is used to encrypt and decrypt information. Authenticity verification is the cornerstone of digital identity, verified through a series of public-private key signatures to confirm the source and validity of the digital identity. The information in a digital identity includes a detailed description of the identity, such as the identity holder's name and permissions, while the signature provides encrypted confirmation of this information, preventing tampering.

[0030] This disclosure achieves high security and immutability of digital identity through a combination of private key, proof of authenticity, information, and signature. The use of the private key ensures that only the identity holder can generate or modify their digital identity, while the proof of authenticity and information signature, through multi-layered public-private key pairing, ensure the traceability of the digital identity's origin and effectively prevent identity forgery and information tampering.

[0031] In one embodiment, obtaining the private key of the digital identity may include: sending a first request message to the second node to request the granting of the digital identity; and receiving the private key of the first digital identity sent by the second node, wherein the private key of the first digital identity is the private key in the public-private key pair generated by the second node for the first node based on the first request message.

[0032] In the initial stage of digital identity generation, a node needs to request a private key from an identity management authority (such as a second node). This process is the starting point for digital identity generation, ensuring that the generation and distribution of the private key are carried out in a trusted environment. The first request message contains the node's basic information and its need to apply for a digital identity. After receiving this request, the second node will generate the corresponding public-private key pair, send the private key to the first node, and retain the public key for subsequent verification processes.

[0033] By generating and distributing public-private key pairs, controllability and security in digital identity generation are achieved. The generation of public-private key pairs ensures that each node has a unique identity, while the confidentiality of the private key guarantees the uncopyability of the digital identity.

[0034] In another embodiment, obtaining the private key of the first digital identity may include: generating a public-private key pair; and retrieving the private key of the first digital identity from the public-private key pair. In some cases, nodes may need to generate the public-private key pair themselves to enhance the autonomy and flexibility of digital identity. This process typically occurs in the node's local environment, ensuring that the generation of the private key is unaffected by the external environment. The generated public-private key pair is not only used for digital identity generation but also forms the basis for subsequent digital authentication and encrypted communication. Generating the public-private key pair locally achieves autonomy and flexibility in digital identity generation. Nodes can independently generate public-private key pairs, which not only improves the scalability of the digital identity system but also enhances the node's control over its own digital identity.

[0035] In this embodiment, a first request message for granting a digital identity can be sent to the second node; a public-private key pair verification message can be received from the second node; the public-private key verification pair can be encrypted using the private key; the encrypted public-private key verification pair and the public key in the public-private key pair can be sent to the second node, so that the second node can decrypt the encrypted public-private key verification pair using the public key; the decrypted public-private key verification pair can be compared with the stored public-private key verification pair; if the comparison result is the same, the authenticity certificate of the first digital identity, the information of the first digital identity, and the signature of the first digital identity can be sent. This process is a key step in private key verification and digital identity granting, ensuring the validity and consistency of the public-private key pair. When applying for a digital identity, a node not only needs to send a request message, but also needs to verify the correctness of its public-private key pair through encryption and decryption. This verification process is a prerequisite for digital identity generation; only when the verification is successful will the second node grant the first node the authenticity certificate, information, and signature of the digital identity. Through the verification of the public-private key pair, the accuracy and consistency of digital identity generation are achieved. Before applying for a digital identity, a node needs to verify the validity of its public-private key pair. This not only ensures the correct generation of the key pair but also verifies the authenticity of the node's request. This method solves the problem of verifying the public-private key pair in a digital identity system. Through encryption and decryption, it ensures the consistency of the key pair, providing a solid foundation for the generation of digital identities and subsequent authentication processes. In practical applications, this method effectively prevents nodes from using invalid or tampered public-private key pairs to generate digital identities, further enhancing the security and reliability of the digital identity system.

[0036] For example, a first node generates a public-private key pair, and a second node grants the first node a digital identity based on this pair. The first node requests the digital identity from the second node. The second node sends the public-private key pair verification to the first node. The first node uses its private key to encrypt the verification and sends it back to the second node along with its public key. The second node uses its public key to decrypt the encrypted verification and compares the decryption result with its own verified public-private key pair. If they match, the second node generates the identity information and authenticity certificate of the first node's digital identity according to the format described above, writes the public key and validity period of the identity information sent by the first node into the first node's digital identity, and signs the identity information, public key, and validity period using its own private key. The second node sends the information, signature, and authenticity certificate back to the first node. The first node combines the received information, signature, and authenticity certificate with its private key to form a complete digital identity.

[0037] In an optional embodiment, the method further includes: sending a second request message to a third node requesting the grant of a digital identity; receiving a third digital identity sent by the third node, wherein the third digital identity consists of the private key in the public-private key pair generated by the third node for the first node, the authenticity certificate of the third digital identity, the information of the third digital identity, and the signature of the third digital identity. The cross-node granting process of digital identity allows the first node to obtain a digital identity from a third node. This typically occurs in scenarios involving the expansion or updating of digital identities, ensuring the diversity and adaptability of digital identities. The authenticity certificate, information, and signature of the third digital identity have a similar structure to the first digital identity, but may contain different permissions or information to adapt to different application scenarios. Through cross-node digital identity granting, the diversity and adaptability of digital identities are achieved. Nodes can apply for additional digital identities from other nodes to adapt to different application scenarios or obtain new permissions. This method solves the problem that a single identity in a digital identity system cannot meet the needs of multiple scenarios. Through cross-node digital identity granting, not only are the types of digital identities enriched, but the flexibility and adaptability of the digital identity system are also enhanced. In practical applications, this method can effectively support nodes in different network environments or application fields to acquire and use different digital identities as needed, thereby improving the practical value and user experience of the digital identity system.

[0038] For example, a third node generates a public-private key pair and grants a digital identity to the first node based on this pair. The first node requests a digital identity from the third node. The third node generates the public-private key pair. Following the digital identity structure, the third node generates the identity information and proof of authenticity for the first node's digital identity, writes the public key and validity period sent by the first node into the first node's digital identity, and signs the identity information, public key, and validity period using its own private key. The third node combines the private key from the public-private key pair with the first node's information, signature, and proof of authenticity to form a complete third digital identity. The third node then sends this third digital identity to the first node.

[0039] In this embodiment of the disclosure, step S204 may include: encrypting the hash value of the information of the first digital identity using the private key of the second digital identity node to obtain the signature of the first digital identity, wherein the second digital identity is the digital identity of the second node, and the second digital identity includes the private key of the second digital identity, the information and signature of the second digital identity, and the authenticity proof of the second digital identity; generating the first digital identity based on the private key in the public-private key pair of the first digital identity, the authenticity proof of the first digital identity, the information of the first digital identity, and the signature of the first digital identity, wherein the authenticity proof of the first digital identity includes: the trusted storage address of the public key corresponding to the private key of the second digital identity and the second target digital identity of the second node, and the second target digital identity includes the information and signature of the second digital identity and the authenticity proof of the second digital identity.

[0040] Furthermore, the information of the first digital identity, the private key in the public-private key pair of the first digital identity, and the proof of authenticity of the first digital identity are written into the first digital identity. The information of the first digital identity includes at least the identity information granted to the first node, identity permissions, validity period of the identity information, and the public key corresponding to the private key.

[0041] Preferably, the trusted storage address for the public key corresponding to the private key of the second digital identity is a storage address in a database or a query address of an identity management authority that manages digital identities. This storage address or the query address of the identity management authority is used to obtain the public key corresponding to the private key of the second digital identity. This trusted public key storage mechanism ensures the source and credibility of the public key. The trusted storage address for the public key can be a storage address in a database or a query address of an identity management authority, providing multiple avenues for obtaining the public key and enhancing the system's flexibility and reliability. Trusted public key storage is the foundation of digital identity verification, ensuring the correctness and validity of the public key. Through trusted public key storage, the accuracy and security of digital identity verification are achieved. The trusted public key storage address provides a means to obtain the public key, which not only ensures the correct acquisition of the public key but also verifies its credibility. This method solves the problem of unreliable public key sources in digital identity systems. Through trusted storage in a database or by an identity management authority, it not only improves the accuracy and efficiency of public key acquisition but also enhances the security and reliability of digital identity verification. In practical applications, this method can effectively prevent nodes from using invalid or tampered public keys for digital authentication, further improving the security and user experience of the digital identity system.

[0042] The second target digital identity of the granting node in this embodiment includes information about the digital identity granted to the second node, a signature, and a certificate of authenticity. The certificate of authenticity is nested in multiple layers according to the order in which the digital identity was granted, up to the root identity management authority. This multi-layered nesting ensures the source and credibility of the digital identity. The multi-layered nested structure of the certificate of authenticity, following the order of digital identity granting, starts from the direct grantor of the node and traces upwards layer by layer until the root identity management authority. This provides a clear path for verifying the digital identity, enhancing its reliability and security.

[0043] By employing multi-layered nested authentication methods, traceability and security of digital identities are achieved. The authentication of digital identities is nested in multiple layers according to the order of grant, ensuring not only the traceability of the digital identity's origin but also verifying its credibility. This method solves the problem of untraceable identity origin in digital identity systems. Through multi-layered nested authentication, it improves the accuracy and efficiency of digital identity verification, while also enhancing the reliability and security of the digital identity system. In practical applications, this method effectively prevents nodes from using forged or unverified digital identities, further improving the security of the digital identity system.

[0044] In this embodiment of the disclosure, the granting node refers to a node with a legitimate digital identity, which can grant sub-digital identities to other nodes based on its own digital identity. The nodes in this embodiment of the disclosure (including the first to fifth nodes) can be a network, a user device, a network device, or a digitized virtual human. The aforementioned first node can be either the granting node or the granting node. The legitimate digital identity of the granting node can be a root digital identity granted by an identity granting authority or a sub-digital identity granted by other nodes.

[0045] Figure 3 is a schematic diagram of a digital identity structure according to an embodiment of this disclosure. As shown in Figure 3, the digital identity (including the first digital identity, second digital identity, third digital identity, and fourth digital identity mentioned above) comprises the following three parts: a private key; information and signature; and proof of authenticity. Depending on different granting scenarios and requirements, the public-private key pair of the granted node can be generated by the granted node or by the granting node. The private key is generally stored separately by the granted node and is not used together with the other two parts. The information includes the identity information of the granted node, the public key of the granted node, the validity period of the identity information, etc. The identity information includes various types of information, such as name and number, corresponding to the flexible generation and granting requirements of the digital identity. The identity information also includes the permissions of the identity, such as the identity's usability scenarios and credit rating. The granted node can independently choose to provide at least a portion of its digital identity externally. The content of the information is stored in the form of a hash tree. The granting node's private key signs the root node of the hash tree composed of all the information to prevent tampering.

[0046] The aforementioned proof of authenticity is provided by the granting node. Figure 4 is a schematic diagram of the private key proof of authenticity structure according to an embodiment of this disclosure. As shown in Figure 4, it includes two parts: a trusted storage address for the granting node's public key, such as a distributed ledger address or an identity management authority storage address; and the granting node's digital identity. The granting node's digital identity includes the granting node's information and signature, and the proof of authenticity, but does not include the granting node's private key. When displaying the proof of authenticity externally, the node can display all of it or only a portion of it.

[0047] The authenticity proof in the recipient's digital identity includes the grantor's digital identity, and the authenticity proof in the grantor's digital identity in turn includes the grantor's digital identity. In this structure, authenticity proofs can be nested in multiple layers according to the identity granting relationship, ultimately tracing back to the root identity management authority. The root identity management authority, as the original granting node, autonomously issues and publishes its digital identity, which is pre-installed in the device.

[0048] This disclosure also provides a digital identity authentication method. Figure 5 is a flowchart of the digital identity authentication method according to an embodiment of this disclosure. As shown in Figure 5, the method is applied to the first node and includes:

[0049] Step S502: Perform two-way authentication with the fourth node based on the first digital identity, wherein the first digital identity consists of the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

[0050] Digital identity authentication is a crucial step in a digital identity system, ensuring that communication between nodes is based on authentic and trusted identities. The two-way authentication process involves a first and a fourth node, verifying the digital identity's private key, proof of authenticity, information, and its signature to ensure the accuracy and consistency of the identity information of both parties. Two-way authentication achieves both security and reliability in inter-node communication. Before communicating, nodes need to verify the digital identity's private key, proof of authenticity, information, and its signature to ensure the accuracy and consistency of the identity information of both parties. This method solves the problem of secure inter-node communication in digital identity systems. Through two-way authentication, it not only improves the security of inter-node communication but also ensures the trustworthiness of the communicating parties. In practical applications, this method can effectively prevent unauthorized third-party interference or impersonation in inter-node communication, further enhancing the security of the digital identity system and the user experience.

[0051] Figure 6 is a flowchart of a digital identity authentication method according to an optional embodiment of the present disclosure. As shown in Figure 6, the two-way authentication based on the first digital identity and the fourth node includes:

[0052] Step S602: Send the second encrypted material and the first target digital identity to the fourth node so that the fourth node can authenticate the second encrypted material and the first target digital identity. The second encrypted material is obtained by the first node encrypting the second authentication material of the fourth node using the private key in the first digital identity. The first target digital identity includes the authenticity proof of the first digital identity, the information of the first digital identity, and the signature of the first digital identity is the digital identity after removing the private key of the digital identity.

[0053] Step S604: Receive the first encrypted material and the fourth digital identity and the fourth target digital identity sent by the fourth node, and authenticate the first encrypted material and the fourth digital identity and the fourth target digital identity. The first encrypted material is obtained by the fourth node encrypting the first authentication material of the first node using the private key in the third and fourth digital identities. The fourth digital identity and the fourth target digital identity include: the authenticity proof of the fourth digital identity, the information of the fourth digital identity, and the signature of the fourth digital identity. The fourth digital identity includes the private key of the fourth target digital identity, the authenticity proof of the fourth target digital identity, the information of the fourth target digital identity, and the signature of the fourth target digital identity.

[0054] The execution order of steps S602 and S604 can be interchanged; that is, S602 can be executed first and then S604, or S604 can be executed first and then S602.

[0055] When the first node and the fourth node perform two-way authentication using the first digital identity, the following steps can be taken:

[0056] Step 11: The first node sends an authentication request to the fourth node, which includes an identifier indicating whether or not it is connected to the data network.

[0057] Step 12: If the fourth node agrees to the authentication, it replies with "agree to authentication," which includes the second authentication materials and an identifier indicating whether the data network is connected.

[0058] Step 13: The first node uses the private key corresponding to the first target digital identity to encrypt the second authentication material to form the second encrypted material. Then, the second encrypted material and the required first target digital identity are sent to the fourth node.

[0059] The information in the first target digital identity can expose only the parts that need verification. The first node determines the content of the authenticity proof in the first target digital identity based on whether the fourth node is connected to the data network. If it can connect to the data network, it can provide the trusted address part of the granting node's public key. If it cannot connect to the data network, it must provide the digital identity part.

[0060] Step 14: The fourth node verifies the authenticity of the first target digital identity and the correctness of the second encrypted material.

[0061] Specifically, if the fourth node can connect to the data network, it accesses the trusted address of the granting node's public key in the first target digital identity to obtain the granting node's public key for the first target digital identity, and uses the public key to decrypt the signature of the first target digital identity. If it can be decrypted, then the first target digital identity is authentic.

[0062] If the fourth node cannot connect to the data network, it accesses the granting node's digital identity portion of the first target digital identity, retrieves the root identity management authority's identity contained therein, and compares it with its own pre-set root identity management authority's identity. If the comparison is inconsistent, authentication fails, an authentication failure message is sent to the first node, and authentication ends. If the comparison is consistent, it decrypts each digital identity signature according to the granting order of digital identities, starting with the built-in root identity management authority's public key, to verify the authenticity of the digital identity. If any step in this process fails, authentication fails, an authentication failure message is sent to the first node, and authentication ends. If all steps are successful, the authenticity of the first target digital identity is successfully verified.

[0063] Step 15: The fourth node uses the public key of the decrypted first target digital identity to decrypt the second encrypted material and compares it with the second authentication material. If they do not match, authentication fails, and the node sends an authentication failure message to the first node, ending the authentication process. If they match, authentication succeeds.

[0064] Step 16: The fourth node uses the private key corresponding to the fourth target digital identity to encrypt the first authentication material to form the first encrypted material. The first encrypted material and the required fourth target digital identity are then sent to the first node.

[0065] The fourth target digital identity information can expose only the parts that need verification. The fourth node determines the authenticity proof content in digital identity information 2 based on whether the first node is connected to the data network. If it can connect to the data network, it can provide the trusted address of the granting node's public key. If it cannot connect to the data network, it must provide the granting node's digital identity information.

[0066] Step 17: The first node verifies the authenticity of the fourth target digital identity and the correctness of the first encrypted material according to the process described in Step 14. If authentication fails, it sends an authentication failure message to the fourth node, ending the authentication process.

[0067] If authentication is successful, the first node generates a subsequent communication key, encrypts the communication key using the public key of the fourth target's digital identity, and then sends it to the fourth node.

[0068] Step 18: The fourth node uses the private key of the fourth target digital identity to decrypt the communication key encrypted in step 17, and obtains the communication key for subsequent communication encryption with the first node.

[0069] When the first node and the fourth node perform two-way authentication using the first digital identity, the following steps can also be taken to reduce the number of interaction steps:

[0070] Step 21: The first node sends an authentication request to the fourth node. The authentication request includes the first authentication materials, the first target digital identity that needs to be provided, and an identifier indicating whether the data network is connected.

[0071] The information portion of the first target digital identity can only expose the parts that need to be verified. The authenticity verification portion needs to contain all information.

[0072] Step 22: If the fourth node agrees to authentication, it encrypts the first authentication material using its own private key to form the first encrypted material. It then sends the first encrypted material, the required fourth target digital identity, the second authentication material, and an identifier indicating whether the data network is connected to the first node.

[0073] The fourth target digital identity can expose only the parts that need verification. The fourth node determines the content of the authenticity proof in the fourth target digital identity based on whether the first node is connected to the data network. If it can connect to the data network, it can provide the trusted address of the granting node's public key. If it cannot connect to the data network, it must provide the granting node's digital identity portion.

[0074] Step 23: The first node verifies the authenticity of the fourth target digital identity and the correctness of the first encrypted material according to the process described in Step 14 above. If authentication fails, an authentication failure message is sent to the fourth node, ending the authentication process.

[0075] If authentication is successful, proceed to step 13 above.

[0076] Step 24 is the same as step 14 above.

[0077] Step 25: If authentication is successful, the fourth node generates a subsequent communication key, encrypts the communication key using the public key of the first target's digital identity, and sends it to the first node.

[0078] Step 26: The first node uses the private key of the first target digital identity to decrypt the communication key encrypted in step 25, and obtains the communication key for subsequent communication encryption with the fourth node.

[0079] The specific process of two-way authentication includes the sending and receiving of encrypted materials and the verification of digital identities. This process ensures that communication between nodes is based on authentic and trusted identities, while enhancing communication security and privacy through the use of encrypted materials. By sending and receiving encrypted materials and verifying digital identities, security and privacy are achieved in inter-node communication. When performing two-way authentication, nodes not only verify the authenticity of digital identities but also ensure data security and privacy during communication through the use of encrypted materials. This method solves the problem of security and privacy in inter-node communication within a digital identity system. Through encrypted materials and digital identity verification, it not only improves the security of inter-node communication but also ensures data privacy during communication. In practical applications, this method can effectively prevent unauthorized third parties from eavesdropping or tampering with inter-node communication, further enhancing the security and user experience of the digital identity system.

[0080] Furthermore, authenticating the first encrypted material and the fourth digital identity (the fourth target digital identity) may include: if the first node is connected to the data network, it accesses the trusted storage address of the public key in the authenticity certificate of the fourth target digital identity to obtain the corresponding public key, uses the obtained public key to decrypt the signature of the fourth digital identity, and if decryption is successful, the fourth target digital identity is authenticated; if decryption fails, it obtains the public key through the digital identity in the authenticity certificate of the fourth target digital identity and decrypts the signature of the fourth target digital identity, and if decryption fails, it sends an authentication failure message to the fourth node and ends the authentication process, wherein obtaining the public key through the digital identity is done after the digital identity has been successfully authenticated; if the first node is not connected to the data network, it accesses the digital identity in the authenticity certificate of the fourth target digital identity and verifies the... If the first node has stored the public key of the root identity management authority of the digital identity, it decrypts the signatures of other digital identities in the authenticity certificate of the fourth digital identity according to the granting relationship using the public key of the root identity management authority. If it has not stored the signature or decryption of any other digital identity's signature fails, authentication fails, an authentication failure message is sent to the fourth node, and authentication ends. If the signature of the fourth digital identity is successfully decrypted, the fourth target digital identity is successfully authenticated. The first encrypted material is decrypted using the public key of the fourth target digital identity, and the decrypted first authentication material is compared with the stored first authentication material. If the comparison is inconsistent, the authentication of the first encrypted material fails, an authentication failure message is sent to the fourth node, and authentication ends. If the comparison is consistent, the authentication of the first encrypted material passes.

[0081] The specific steps of digital identity authentication include both online and offline authentication modes. In online authentication mode, nodes can access the trusted storage address of the public key through the data network, obtain the public key, and perform authentication. In offline authentication mode, nodes need to authenticate through pre-defined root identity management authority information. This process ensures the flexibility and versatility of digital identity authentication, adapting to different network environments and application needs.

[0082] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0083] This embodiment also provides a digital identity generation device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated. Applied to a first node, the device includes:

[0084] The acquisition module is configured to acquire the private key of the first digital identity and receive the authenticity certificate of the first digital identity, the information of the first digital identity, and the signature of the first digital identity from the second node.

[0085] The generation module is configured to generate the first digital identity based on the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

[0086] This disclosure also provides a digital identity authentication device, applied to a first node, comprising:

[0087] The authentication module is configured to perform two-way authentication between the first digital identity and the fourth node, wherein the first digital identity consists of the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

[0088] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0089] Embodiments of this disclosure also provide a computer-readable storage medium storing a computer program configured to perform the steps in any of the above method embodiments when executed.

[0090] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0091] Embodiments of this disclosure also provide an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.

[0092] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0093] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.

[0094] It is obvious to those skilled in the art that the modules or steps of this disclosure described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this disclosure is not limited to any particular combination of hardware and software.

[0095] The above description is merely a preferred embodiment of this disclosure and is not intended to limit this disclosure. Various modifications and variations can be made to this disclosure by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A digital identity generation method, applied to a first node, comprising: Obtain the private key of the first digital identity, and receive the authenticity certificate of the first digital identity, the information of the first digital identity, and the signature of the first digital identity from the second node; The first digital identity is generated based on the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

2. The method according to claim 1, wherein, The private key used to obtain a digital identity includes: Send a first request message to the second node requesting the granting of a digital identity; The system receives the private key of the first digital identity sent by the second node, wherein the private key of the first digital identity is the private key in the public-private key pair generated by the second node for the first node based on the first request message.

3. The method according to claim 1, wherein, The private key for obtaining the first digital identity includes: Generate a public / private key pair; Obtain the private key of the first digital identity from the public-private key pair.

4. The method according to claim 3, wherein, The method further includes: Send a first request message to the second node requesting the granting of a digital identity; Receive the public / private key pair sent by the second node for verification; The public-private key pair is used to encrypt the public-private key verification pair; The encrypted public-private key pair verification is sent to the second node along with the public key in the public-private key pair verification, so that the second node can use the public key to decrypt the encrypted public-private key pair verification. The decrypted public-private key pair verification is compared with the stored public-private key pair verification. If the comparison result is the same, the authenticity certificate of the first digital identity, the information of the first digital identity, and the signature of the first digital identity are sent.

5. The method according to claim 1, wherein, The method further includes: Send a second request message to the third node requesting the granting of a digital identity; The third digital identity is received from the third node, wherein the third digital identity consists of the private key in the public-private key pair generated by the third node for the first node, the authenticity certificate of the third digital identity, the information of the third digital identity, and the signature of the third digital identity.

6. The method according to claim 1, wherein, Generating the first digital identity based on the private key of the first digital identity, proof of the authenticity of the first digital identity, information of the first digital identity, and signature of the first digital identity includes: The signature of the first digital identity is obtained by encrypting the hash value of the information of the first digital identity using the private key of the second digital identity. The second digital identity is the digital identity of the second node, and the second digital identity includes the private key of the second digital identity, the information and signature of the second digital identity, and the proof of authenticity of the second digital identity. The first digital identity is generated based on the private key in the first digital identity public-private key pair, the authenticity proof of the first digital identity, the information of the first digital identity, and the signature of the first digital identity. The authenticity proof of the first digital identity includes: the trusted storage address of the public key corresponding to the private key of the second digital identity and the second target digital identity of the second node. The second target digital identity includes the information and signature of the second digital identity and the authenticity proof of the second digital identity.

7. The method according to claim 6, wherein, Generating the first digital identity based on the private key of the first digital identity, proof of the authenticity of the first digital identity, information of the first digital identity, and signature of the first digital identity includes: The information of the first digital identity, the private key of the first digital identity, and the proof of authenticity of the first digital identity are written into the first digital identity. The information of the first digital identity includes at least the identity information of the first node, identity permissions, validity period of the identity information, and the public key corresponding to the private key.

8. The method according to claim 6, wherein, The trusted storage address of the public key corresponding to the private key of the second digital identity is either a storage address in a database or a query address of an identity management agency that manages digital identities. The storage address or the query address of the identity management agency is used to obtain the public key corresponding to the private key of the second digital identity.

9. The method according to claim 8, wherein, The authenticity verification of the second digital identity is nested in multiple layers according to the order in which digital identities are granted, up to the root identity management authority identity.

10. A digital identity authentication method, applied to a first node, comprising: Two-way authentication is performed between the first digital identity and the fourth node, wherein the first digital identity consists of the private key of the first digital identity, the proof of authenticity of the first digital identity, the information of the first digital identity, and the signature of the first digital identity.

11. The method according to claim 10, wherein, Two-way authentication based on the first digital identity and the fourth node includes: Send the second encrypted material and the first target digital identity to the fourth node so that the fourth node can authenticate the second encrypted material and the first target digital identity. The second encrypted material is obtained by the first node encrypting the second authentication material of the fourth node using the private key of the first digital identity. The first target digital identity includes the authenticity certificate of the first digital identity, the information of the first digital identity, and the signature of the first digital identity. The system receives a first encrypted material and a fourth target digital identity sent by the fourth node, and authenticates the first encrypted material and the fourth target digital identity. The first encrypted material is obtained by the fourth node encrypting the first authentication material of the first node using the private key of the fourth digital identity. The fourth digital identity includes the private key of the fourth digital identity, the authenticity certificate of the fourth digital identity, the information of the fourth digital identity, and the signature of the fourth digital identity. The fourth target digital identity includes the authenticity certificate of the fourth digital identity, the information of the fourth digital identity, and the signature of the fourth digital identity.

12. The method according to claim 11, wherein, Authenticating the first encrypted material and the fourth target digital identity includes: If the first node is connected to the data network, it accesses the trusted storage address of the public key in the authenticity proof of the fourth target digital identity to obtain the corresponding public key, and uses the obtained public key to decrypt the signature of the fourth digital identity. If decryption is successful, the authentication of the fourth target digital identity is passed; if decryption fails, it obtains the public key through the digital identity in the authenticity proof of the fourth target digital identity and decrypts the signature of the fourth target digital identity. If decryption fails, it sends an authentication failure message to the fourth node and ends the authentication process. Here, obtaining the public key through the digital identity is done after the digital identity has been successfully authenticated. If the first node is not connected to the data network, it accesses the digital identity in the authenticity certificate of the fourth target digital identity and checks whether the first node has stored the public key of the root identity management authority of the digital identity. If it has stored it, it decrypts the signatures of other digital identities in the authenticity certificate of the fourth digital identity according to the granting relationship using the public key of the root identity management authority. If it has not stored it or the decryption of the signature of any other digital identity fails, the authentication fails, an authentication failure message is sent to the fourth node, and the authentication ends. If the signature decryption of the fourth digital identity is successful, the fourth target digital identity is successfully authenticated. The first encrypted material is decrypted using the public key of the decrypted fourth target digital identity. The decrypted first authentication material is then compared with the stored first authentication material. If the comparison is inconsistent, the authentication of the first encrypted material fails, and an authentication failure message is sent to the fourth node to end the authentication process. If the comparison is consistent, the authentication of the first encrypted material is successful.

13. The method according to claim 11, wherein, After authenticating the first encrypted material and the fourth target digital identity, the method further includes: If all authentications are successful, a communication key is generated, the communication key is encrypted using the public key in the fourth target digital identity, and the encrypted communication key is sent to the fourth node. The communication with the fourth node is encrypted using the communication key.

14. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, performs the steps of the method according to any one of claims 1 to 9, 10 to 13.

15. A computer program product comprising a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1 to 9, 10 to 13.