Personal digital identity management system and method
View Patent ↗The present disclosure provides a personal identity management system and method. The method includes a client and a service end. The client uses a user-specified keyword to perform hierarchical management on keys, and the service end accepts the digital identity information from the client and performs digital signature and further displays the information in public. In the method of the present disclosure, available digital identities can be generated securely and quickly with an unlimited quantity, such that the user can perform switching between multiple digital identities so as to achieve the effect of combating the tracking for the digital identities and protecting the user privacy better. Furthermore, in a scenario where identity verification and access control are required, verification can be completed by providing public key and signature.
1 . A method for managing a digital identity, executed by a first client device, comprising:
generating a plurality of digital identities for a user based on a plurality of keys, wherein each digital identity of the plurality of digital identities is generated based on a corresponding key among the plurality of keys, wherein generating the plurality of digital identities comprises, for each digital identity of the plurality of digital identities:
determining the corresponding key from the plurality of keys; and
generating the digital identity based on the corresponding key, wherein the digital identity comprises identity information, the identity information comprising at least a public key, wherein the corresponding key serves as a private key paired with the public key, and wherein generating the digital identity based on the corresponding key comprises:
receiving an inputted first keyword, and
invoking a first script which generates the identity information based on the inputted first keyword; and
communicating with a server or a second client device by using a target digital identity to represent the user, wherein the target digital identity is capable of being switched among the plurality of digital identities.
2 . The method according to claim 1 , wherein the plurality of keys are grouped into at least two levels, wherein among the at least two levels, each key in a level other than a highest level is subordinate to a parent key in a directly previous level, and wherein the method further comprises:
for each key in the level other than the highest level among the at least two levels, generating said key based on the parent key and a salt; and
for each key in the highest level, generating said key based on a random number.
3 . The method according to claim 2 , wherein the salt comprises another random number, one or more second keywords, and time information.
4 . The method according to claim 3 , wherein for each key in a level other than the highest level and a second highest level among the at least two levels, the salt further comprises each second keyword in the salt for generating the parent key.
5 . The method according to claim 1 , wherein the identity information further comprises at least one of:
a name of the digital identity,
an additional signature,
an index of the digital identity,
a name of a platform, and
one or both of an account and a password of the account for the platform.
6 . The method according to claim 1 , wherein generating the digital identity based on the corresponding key further comprises:
receiving information of a platform; and
invoking the first script which generates the identity information based on the inputted first keyword, wherein invoking the first script comprises:
determining whether the first script comprises a second keyword representing the platform; and
invoking the first script in response to the first script comprising the second keyword representing the platform.
7 . The method according to claim 6 , wherein generating the digital identity based on the corresponding key further comprises:
in response to the first script not comprising the second keyword representing the platform, invoking a second script which generates the identity information based on the inputted first keyword, wherein the second script comprises the second keyword representing the platform or is specified by the user.
8 . The method according to claim 1 , wherein determining the corresponding key from the plurality of keys comprises:
displaying the plurality of keys;
receiving an operation of the user for selecting the corresponding key; and
determining the corresponding key according to the operation.
9 . The method according to claim 1 , wherein the method further comprises:
receiving a digital signature of the second client device; and
adding the digital signature into the identity information,
wherein the digital signature is generated by the second client device based on a private key of the second client device.
10 . The method according to claim 1 , wherein communicating with the server or the second client device by using the target digital identity to represent the user comprises:
transmitting the identity information of the target digital identity to the server, to enable the server to assign an index for the target digital identity; and
receiving the index from the server.
11 . The method according to claim 10 , wherein the index is configured to enable the first client device or another client device to request at least the public key of the identity information of the target digital identity from the server.
12 . The method according to claim 1 , wherein communicating with the server or the second client device by using the target digital identity to represent the user comprises:
transmitting the identity information of the target digital identity to the server to enable the server to generate a digital signature for the target digital identity based on a private key of the server, wherein the digital signature is configured to prove that the server has verified the target digital identity.
13 . The method according to claim 1 , wherein communicating with the server or the second client device by using the target digital identity to represent the user comprises:
generating a digital signature by using the corresponding key of the target digital identity;
transmitting the digital signature to the second client device; and
transmitting at least the identity information of the target digital identity to the server to enable the second client device to verify the digital signature by using the public key, which is requested by the second client device from the server.
14 . The method according to claim 1 , wherein communicating with the server or the second client device by using the target digital identity to represent the user comprises:
displaying the plurality of digital identities;
receiving an operation of the user for selecting a first digital identity from the plurality of digital identities; and
determining the first digital identity to serve as the target digital identity.
15 . The method according to claim 14 , wherein communicating with the server or the second client device by using the target digital identity to represent the user comprises:
receiving another operation of the user for selecting a second digital identity when the first digital identity serves as the target digital identity; and
determining the second digital identity to serve as the target digital identity.
16 . An apparatus for managing a digital identity, comprising:
a memory storing computer-readable instructions; and
a processor, wherein the computer-readable instructions, when executed by the processor, configure a first client device to:
generate a plurality of digital identities for a user based on a plurality of keys, wherein each digital identity of the plurality of digital identities is generated based on a corresponding key among the plurality of keys, wherein generating the plurality of digital identities comprises, for each digital identity of the plurality of digital identities:
determining the corresponding key from the plurality of keys; and
generating the digital identity based on the corresponding key, wherein the digital identity comprises identity information, the identity information comprising at least a public key, wherein the corresponding key serves as a private key paired with the public key, and wherein generating the digital identity based on the corresponding key comprises:
receiving an inputted first keyword, and
invoking a first script which generates the identity information based on the inputted first keyword; and
communicate with a server or a second client device by using a target digital identity to represent the user, wherein the target digital identity is capable of being switched among the plurality of digital identities.
17 . A non-transitory computer-readable storage medium comprising computer-readable instructions, wherein the computer-readable instructions, when executed by a processor, configure a first client device to:
generate a plurality of digital identities for a user based on a plurality of keys, wherein each digital identity of the plurality of digital identities is generated based on a corresponding key among the plurality of keys, wherein generating the plurality of digital identities comprises, for each digital identity of the plurality of digital identities:
determining the corresponding key from the plurality of keys; and
generating a digital identity based on the corresponding key, wherein the digital identity comprises identity information, the identity information comprising at least a public key, wherein the corresponding key serves as a private key paired with the public key, and wherein generating the digital identity based on the corresponding key comprises:
receiving an inputted first keyword, and
invoking a first script which generates the identity information based on the inputted first keyword; and
communicate with a server or a second client device by using a target digital identity to represent the user, wherein the target digital identity is capable of being switched among the plurality of digital identities.