User identity verification method and system based on block chain

Through the multi-level encryption mechanism of the Merkle Tree and SHA-3 hash function combined with the multi-level encryption mechanism of the Merkle Tree and SHA-3 hash function, the problem of data leakage and tampering in the blockchain identity verification system is solved, and efficient and secure user identity verification is achieved.

CN120296714AInactive Publication Date: 2025-07-11NANJING YINYUNSHENG TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510330031.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing blockchain identity verification system has shortcomings in preventing sensitive data leakage, ensuring data is not tampered with, and the security of encryption processes, especially when multi-party verification and data updates are inefficient, and there are security vulnerabilities in a single encryption mechanism.

Method used

The elliptic curve encryption algorithm is used to generate public-private key pairs, combined with decentralized identity authentication technology and AES128-bit encryption algorithm, and the root hash is generated using Merkle Tree and SHA-3 hash functions. Sensitive information is encrypted through the public key and stored on the blockchain. Combined with the Nonce value and private key decryption mechanism, a multi-level encryption and decryption process is realized.

Benefits of technology

It improves the security and efficiency of identity authentication, ensures data integrity and immutability, avoids security vulnerabilities in a single encryption method, enhances the protection of user identity information, and is suitable for large-scale user data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296714A_ABST
    Figure CN120296714A_ABST
Patent Text Reader

Abstract

The invention discloses a user identity verification method based on a block chain, and relates to the technical field of identity verification, and the method comprises the steps: encrypting sensitive identity information through an AES128-bit encryption algorithm, generating a root hash for the encrypted sensitive identity information through a Merkle Tree and an SHA3 hash function, and when a user carries out identity verification, carrying out authentication on the encrypted sensitive identity information through the Merkle Tree and the SHA3 hash function. And decrypting the second registration information encrypted by the public key through the identifier and the Non value in combination with the private key, recalculating the root hash of the encrypted sensitive identity information, and comparing the root hash with the root hash stored on the block chain. By combining an AES encryption algorithm, a Merkle Tree and an SHA3 hash function, integrity verification is performed on encrypted sensitive identity information, privacy and security of the information are ensured, data integrity is improved through a multi-layer hash and encryption verification mechanism, security vulnerabilities caused by a single encryption mode are avoided, and the security of the sensitive identity information is improved. The safety and the efficiency of identity verification are further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity verification, and in particular, to a user identity verification method and system based on blockchain. Background Art

[0002] With the rapid development of Internet technology and information systems, user identity authentication and information security have become the core issues of data protection and privacy maintenance. Traditional identity authentication technologies (such as usernames and passwords) can no longer meet the requirements of high-security identity authentication in the modern digital society due to their vulnerable characteristics. Therefore, new identity authentication methods and technologies have emerged, especially the decentralized identity authentication technology based on blockchain and encryption algorithms. Blockchain technology has gradually become an important tool in the fields of identity verification and information protection due to its decentralized, immutable, and transparent characteristics. Although the existing technologies have solved the problems of identity verification and information encryption to a certain extent, there are still some deficiencies. First, most traditional identity authentication methods rely on centralized identity management systems, which means that once the central server is attacked or fails, the entire system will be at risk. Second, existing encryption algorithms are often limited to a single encryption process and lack a multi-level encryption mechanism, resulting in limited security of the encryption process. Especially when dealing with sensitive identity information, it is impossible to ensure the encryption security, data integrity, and verification efficiency of the information at the same time. Multiple separate steps are often required for encryption, hashing, and integrity verification, which not only reduces the efficiency of the system but also increases the risk of vulnerabilities. Although the encrypted storage of user information can prevent the leakage of sensitive data, how to ensure its integrity and non-tampering during the transmission and verification processes of the encrypted data is still a difficult point. Especially in the process of data update and multi-party verification, how to efficiently and seamlessly perform identity verification and data consistency verification and avoid redundant verification steps is a bottleneck in the current technology. In view of these problems, the existing technologies still have significant deficiencies in preventing the leakage of sensitive data, ensuring data immutability, and ensuring the efficiency of the verification process. Summary of the Invention

[0003] In view of the above existing problems, the present invention is proposed.

[0004] Therefore, the present invention provides a user identity verification method and system based on blockchain, which solves the deficiencies of the existing technologies in aspects such as preventing the leakage of sensitive data, ensuring data immutability, and a single encryption mechanism in the blockchain identity verification system.

[0005] To solve the above technical problems, the present invention provides the following technical solutions:

[0006] In the first aspect, the present invention provides a user identity verification method based on blockchain, which includes

[0007] Users submit registration information, which is divided into sensitive and non-sensitive identity information, and a public-private key pair is generated for each user through the elliptic curve encryption algorithm;

[0008] Use decentralized identity authentication technology to create a unique identifier for the user, and assign a corresponding public-private key pair to each identifier;

[0009] Encrypt the sensitive identity information through the AES128-bit encryption algorithm, and generate a root hash for the encrypted sensitive identity information using the Merkle Tree and SHA-3 hash function;

[0010] Replace the unencrypted sensitive identity information with the encrypted sensitive identity information, and integrate it with the unencrypted non-sensitive identity information to generate the second registration information. Encrypt the user's second registration information with the public key, and store the encrypted information together with the root hash on the blockchain;

[0011] When the user conducts identity verification, decrypt the second registration information encrypted by the public key with the identifier and Nonce value combined with the private key, and recalculate the root hash of the encrypted sensitive identity information, and compare it with the root hash stored on the blockchain;

[0012] After the root hash comparison verification passes, use the AES decryption algorithm to decrypt and view the sensitive identity information.

[0013] As a preferred solution of the blockchain-based user identity verification method described in the present invention, wherein: the user submits registration information, which is divided into sensitive and non-sensitive identity information, and a public-private key pair is generated for each user through the elliptic curve encryption algorithm means that the user fills in a personal information form through the front-end interface, which includes the user's sensitive and non-sensitive identity information. The submitted information is subjected to format verification and data cleaning by the back-end, and the P-256 standard curve in the elliptic curve encryption algorithm is used to generate a known fixed point G on the elliptic curve, and a pair of public-private key pairs is generated for each user. PK is the public key of the user, and SK is the private key of the user.

[0014] As a preferred solution of the blockchain-based user identity verification method described in the present invention, wherein: the use of decentralized identity authentication technology to create a unique identifier for the user, and assign a corresponding public-private key pair to each identifier means that the decentralized identity authentication technology is used to generate a unique identifier for the user's identity information, and the corresponding public key is associated as a part of each identifier through the centralized identity management protocol to ensure that the public key of the user can be found through the identifier.

[0015] As a preferred solution of the blockchain-based user identity verification method described in the present invention, wherein: encrypting sensitive identity information through the AES128-bit encryption algorithm, generating a root hash for the encrypted sensitive identity information using the Merkle Tree and the SHA3 hash function means converting the user's sensitive identity information into byte form, filling it into a 4x4 state matrix, encrypting the state matrix using a 16-byte key through the AES128-bit encryption algorithm, and using it as the original key Key0, and filling the bytes of the original key Key0 using the key expansion algorithm as the first round key;

[0016] The first round key is XORed with the last word of itself, the result obtained is subjected to byte substitution through the S-Box, the round constant is XORed with the first word of the substituted round key to obtain a new word, and the new word is XORed with the first round key to obtain a second new word. Repeat the above steps to generate the keys for each round in turn. The generation of the keys for each round depends on the output of the previous round until the iteration is completed to generate a required set of round keys;

[0017] Perform an XOR operation on the state matrix using the first round key, and perform substitution on each byte of the state matrix after the XOR operation using the S-box to obtain the byte State’[i,j] of the substituted state matrix;

[0018] Use row shift to circularly shift each row in the state matrix State’[i,j] to the left to obtain the byte D[i,j] of the left-shifted state matrix;

[0019] Use column mixing to perform matrix multiplication on each column byte of the state matrix after row shift to obtain the byte F[i,j] of the state matrix after column mixing;

[0020] Organize all F[i,j] into a complete 4x4 state matrix, and each byte is in the state matrix to generate the updated state matrix F n ;

[0021] In the last step of each round, perform an XOR operation on the updated state matrix with the generated round key to obtain the state matrix E v ;

[0022] After encryption for a specified number of rounds, the final state matrix E v is the encrypted ciphertext E;

[0023] Calculate the SHA3 hash value for the ciphertext E. Take the SHA3 hash value of each user as the leaf node of the Merkle Tree. Combine the hash values of every pair of adjacent leaf nodes in position order, and use the BLAKE2b hash algorithm to calculate the hash value of the new node as the parent node hash value H ix Combine adjacent parent node hash values together, calculate the hash value of the new layer as the root hash H of the Merkle Tree ixcz .

[0024] As a preferred solution of the blockchain-based user identity verification method described in the present invention, wherein: replacing the unencrypted sensitive identity information with the encrypted sensitive identity information, integrating it with the unencrypted non-sensitive identity information to generate the second registration information, encrypting the user's second registration information with the public key, and storing the encrypted information together with the root hash on the blockchain means creating a second registration information, replacing the original unencrypted sensitive identity information with the encrypted ciphertext data, integrating it with the original non-sensitive identity information, encrypting the second registration information with the public key, and storing the encrypted second registration information and the root hash of the encrypted sensitive identity information on the blockchain

[0025] As a preferred solution of the blockchain-based user identity verification method described in the present invention, wherein: when the user performs identity verification, decrypt the second registration information encrypted with the public key by combining the identifier and the Nonce value with the private key, and recalculate the root hash of the encrypted sensitive identity information, and compare it with the root hash stored on the blockchain means querying the Nonce value stored during the previous verification in the blockchain according to the identifier, called Nonce old , by comparing the current Nonce U value and Nonce old 's timestamp, determine whether the Nonce value is increasing. If it is increasing, it means it is a new identity verification request, and the verification passes and continue to perform the identity verification;

[0026] If Nonce U is less than or equal to the timestamp of Nonce old , it means the request is an old request, then reject the request and return an error prompt;

[0027] Sign the message containing the identifier and the Nonce value with the private key, use the stored public key to verify the validity of the signature. If the verification passes, it proves that the user has a legal identity, and decrypt the second registration information encrypted with the public key by the user's private key;

[0028] To access the user's sensitive identity information, when the user applies for identity verification, use the user's encrypted sensitive identity information to generate a new hash value, reconstruct the Merkle Tree, generate a new root hash, and perform a byte-level comparison between the recalculated root hash of the user and the stored root hash. Only when the two are exactly the same can the verification pass.

[0029] As a preferred solution of the blockchain-based user identity verification method of the present invention, wherein: after the root hash comparison verification passes, use the AES decryption algorithm to decrypt and view the sensitive identity information. It means that after the root hash comparison verification passes, use the AES decryption algorithm to perform an exclusive OR operation on the encrypted ciphertext and the round key of the last round, initialize the state matrix, and perform multiple rounds of decryption operations in sequence. Use the inverse S-box to substitute the bytes in the state matrix to restore the original data, then perform a reverse shift operation, shift the bytes in each row to the right according to the row index to restore the data that was left-shifted during the encryption process, perform an inverse column mixing operation, restore the relationship between columns through matrix multiplication, and ensure that the diffusion effect of the data is correctly reversed. After each round ends, perform an exclusive OR operation on the current round's round key and the state matrix again. After all rounds of decryption operations, finally obtain the original plaintext identity information.

[0030] In a second aspect, the present invention provides a blockchain-based user identity verification method and system, including a user identity information collection and key generation module for collecting the user's identity information and generating a public-private key pair;

[0031] A sensitive data encryption and root hash generation module for encrypting the user's sensitive identity information and generating a root hash;

[0032] A second registration information encryption and storage module for integrating the encrypted sensitive identity information and non-sensitive identity information to generate second registration information, which is encrypted with the public key and stored on the blockchain;

[0033] A user identity verification module for verifying the user's identity;

[0034] A sensitive information viewing module for the user to decrypt the encrypted sensitive information using the AES decryption algorithm after the root hash verification passes.

[0035] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and wherein: when the computer program is executed by the processor, it implements any step of the blockchain-based user identity verification method and system described in the first aspect of the present invention.

[0036] Fourthly, the present invention provides a computer-readable storage medium, on which a computer program is stored, wherein: when the computer program is executed by a processor, any step of the blockchain-based user identity verification method described in the first aspect of the present invention is implemented.

[0037] The beneficial effects of the present invention are as follows: during the user identity verification process, the second registration information is first decrypted by the public key, and then the AES128-bit encryption algorithm is used to prevent theft and tampering by unauthorized visitors, which has a fast encryption speed and high security. The combination of the Merkle Tree and the SHA3 hash function further guarantees the integrity and immutability of the data. Even if a certain node is tampered with, the change of the root hash can be quickly detected, thereby ensuring the security of the entire system. The consistency and integrity of the data are verified layer by layer through the hash chain. Even for a large amount of data, it can be quickly verified through a single root hash, thus realizing efficient integrity verification of the data, further enhancing the security and efficiency of identity verification, and then using the AES decryption algorithm to decrypt the final sensitive identity information. In this way, through multiple levels of encryption and decryption steps, not only the security of the identity information is enhanced, but also the security and credibility of the entire identity verification process are ensured, avoiding security vulnerabilities brought by a single encryption method. Description of the Drawings

[0038] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0039] Figure 1 It is a flowchart of the blockchain-based user identity verification method in Embodiment 1.

[0040] Figure 2 It is a schematic structural diagram of the blockchain-based user identity verification system in Embodiment 1.

[0041] Figure 3 It is a flowchart of the encryption process of the blockchain-based user identity verification method in Embodiment 1.

[0042] Figure 4 It is a flowchart of the decryption process of the blockchain-based user identity verification method in Embodiment 1. Detailed Embodiments

[0043] To make the above objects, features, and advantages of the present invention more obvious and understandable, the detailed embodiments of the present invention will be described in detail below with reference to the drawings in the specification.

[0044] In the following description, numerous specific details are set forth to provide a thorough understanding of the present invention. However, the present invention may be practiced in other ways different from those described herein. Persons skilled in the art can make similar extensions without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0045] Secondly, as used herein, an "embodiment" or "embodiments" refers to specific features, structures, or characteristics that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an embodiment that is separate or mutually exclusive of other embodiments.

[0046] Example 1, referring to Figures 1 to 4 , is the first embodiment of the present invention. This embodiment provides a user identity verification method based on blockchain, including the following steps:

[0047] S1. The user submits registration information, which is divided into sensitive and non-sensitive identity information, and a public-private key pair is generated for each user through the elliptic curve encryption algorithm;

[0048] Use decentralized identity authentication technology to create a unique identifier for the user and assign a corresponding public-private key pair to each identifier;

[0049] Specifically, the user submits registration information, which is divided into sensitive and non-sensitive identity information, and generating a public-private key pair for each user through the elliptic curve encryption algorithm means that the user fills in a personal information form through the front-end interface, which includes the user's sensitive and non-sensitive identity information. The information submitted is format-verified and data-cleaned by the backend (referring to the backend server), and the P-256 standard curve in the elliptic curve encryption algorithm (ECC) is used to generate a known fixed point G on the elliptic curve, and a pair of public-private key pairs is generated for each user. The calculation formula is:

[0050] PK = s·G,

[0051] SK = s,

[0052] wherein, PK is the public key of the user, SK is the private key of the user, s is the random value of the private key, and a large integer is generated through a random number, which is located in the finite field of the elliptic curve;

[0053] The sensitive identity information includes mobile phone number, name, address, and ID number;

[0054] The non-sensitive identity information includes username, email address, and registered account.

[0055] By separately encrypting and storing sensitive identity information and non-sensitive identity information, it is ensured that sensitive information can only be accessed when needed. This separation processing method enhances privacy protection, so that even if the information encounters a man-in-the-middle attack during data transmission, the sensitive information will not be exposed; by using the elliptic curve encryption algorithm of the P-256 standard curve to generate a public-private key pair for each user, the public key is stored on the blockchain, and the private key is kept by the user himself. This method generates the private key by using random numbers, greatly improving the security of the key and avoiding the risk of key leakage existing in traditional methods. Compared with traditional encryption algorithms, ECC has higher encryption strength and computing efficiency, can effectively reduce the key length, improve security at the same time, and is more efficient when processing sensitive data.

[0056] Furthermore, the use of decentralized identity authentication technology to create identifiers on the blockchain and associate a public-private key pair with each identifier means using decentralized identity authentication technology to generate a unique identifier for the user's identity information (represented by a hash value for decentralized management and identification of the user's identity), and through the centralized identity management protocol, the corresponding public key is used as part of each identifier to be associated with each other to ensure that the public key of the user can be found through the identifier.

[0057] Through the combination of the elliptic curve encryption algorithm and the decentralized identity authentication technology, the problems of insufficient data privacy protection and low verification efficiency in the prior art are solved. By using the public-private key pair and the efficient encryption ability of ECC, the present invention not only improves the security of the identity verification process, but also ensures the efficiency and scalability of the system when processing large-scale user data.

[0058] S2. Encrypt the sensitive identity information through the AES128-bit encryption algorithm, and generate the root hash for the encrypted sensitive identity information by using the Merkle Tree and the SHA3 hash function;

[0059] Replace the unencrypted sensitive identity information with the encrypted sensitive identity information, and integrate it with the unencrypted non-sensitive identity information to generate the second registration information. Encrypt the user's second registration information with the public key, and store the encrypted information together with the root hash on the blockchain;

[0060] Specifically, the sensitive identity information is encrypted by the AES128-bit encryption algorithm. The integrity verification of the encrypted sensitive identity information using the Merkle Tree and the SHA-3 hash function means converting the user's sensitive identity information into byte form and filling it into a 4x4 state matrix. The state matrix is encrypted using a 16-byte (128-bit) key by the AES128-bit encryption algorithm and used as the original key Key0. The bytes of the original key Key0 are filled using the key expansion algorithm (Key Expansion) as the first round key;

[0061] The first round key is XORed with the last word of itself (each 4-byte group is called a word) to increase the randomness of encryption. The result obtained is subjected to byte substitution through the S-Box (the S-Box is a fixed substitution box for replacing bytes) to enhance the complexity of encryption. The round constant (referring to a set of fixed constants) is XORed with the first word of the round key after substitution to obtain a new word. The new word is XORed with the first round key to obtain a second new word. The above steps are repeated to generate the keys for each round in turn. The generation of the keys for each round depends on the output of the previous round until the iteration is completed to generate the required set of round keys;

[0062] The state matrix is XORed (XOR) using the first round key to ensure that the data in the initial state matrix is initialized by the key. The state matrix after the XOR operation is subjected to substitution for each byte using the S-box (substitution box). The horizontal row of the matrix is i, and the vertical column of the matrix is j. The calculation formula:

[0063] State’[i,j] = S-box(State[i,j]),

[0064] where State[i, j] is the byte in the i-th row and j-th column of the state matrix, and the S-box is a 16x16 substitution table;

[0065] Each row in the state matrix is circularly shifted left using row shift. The calculation formula:

[0066] D[i,j] = State’[i,(j+i)mod4],

[0067] where D[i, j] is the byte in the state matrix after the left shift, (j + i) is the sum of the current column index and the current row index, and mod4 is the modulo operation with 4. Since the AES state matrix has only 4 columns, the modulo operation can ensure that the value of the column index is always between 0 and 3;

[0068] Use column mixing to perform matrix multiplication on each column byte of the state matrix, enabling more interaction between the output of each column and the data of other columns, enhancing the diffusion effect of encryption. The calculation formula is:

[0069] F[i,j] = Mix(D[i,0], D[i,1], D[i,2], D[i,3]),

[0070] where F[i,j] is the byte in the column-mixed state matrix, Mix is a matrix multiplication operation that performs matrix multiplication on each column byte using a fixed matrix, and 0, 1, 2, 3 are the constant values of the fixed matrix in the matrix multiplication (constants defined by the AES encryption algorithm for the calculation of each byte);

[0071] Organize all F[i,j] into a complete 4x4 state matrix, with each byte in the state matrix, generating the updated state matrix F n ;

[0072] In the last step of each round, perform an exclusive OR operation on the updated state matrix and the generated round key to obtain the state matrix E v :

[0073]

[0074] where F n is the state matrix after column mixing in the nth round, and RoundKey K is the key of the current Kth round;

[0075] After encryption for a specified number of rounds (the number of rounds is set based on the AES standard), the final state matrix is the encrypted ciphertext E;

[0076] Calculate the SHA3 hash value of the ciphertext E:

[0077] H(E) = SHA3 - 256(E),

[0078] where H(E) is the hash value of the encrypted data, representing the unique identifier of the data, used to verify whether the data has been tampered with;

[0079] Use the SHA3 hash value of each user as the leaf node of the Merkle Tree (also known as a hash tree, which is a data structure), combine the hash values of each pair of adjacent leaf nodes in order (referring to adjacent nodes in the data structure), and calculate the hash value of the new node using the BLAKE2b hash algorithm:

[0080] H ix = BLAKE2b(H i ||H x)

[0081] Among them, H i is the hash value of the i-th leaf node, and H x is the hash value of the leaf node adjacent to H i , and H ix is the hash value of the parent node after connection;

[0082] Combine the adjacent parent node hash values together to calculate the hash value of the new layer:

[0083] H ixcz = BLAKE2b(H ix ||H cz ),

[0084] Among them, H cz is the adjacent parent node hash value of H ix , and H ixcz is the root hash of the Merkle Tree, representing the integrity of the entire data set;

[0085] In the prior art, a single encryption method cannot effectively guarantee both data integrity and the efficiency of identity authentication at the same time. The sensitive identity information is encrypted through the AES128-bit encryption algorithm, combined with the Merkle Tree and the SHA3 hash function, and multiple processes of hashing and integrity verification are performed on the sensitive information. The SHA3 hash function provides stronger collision resistance and security. Compared with the traditional SHA1 or SHA2, SHA3 can better resist collision attacks and various tampering behaviors. The structure of the Merkle Tree enables even large-scale data to be quickly verified through the root hash, avoiding the low efficiency problem of having to check data item by item in the verification process of the traditional scheme, and providing more efficient and secure data verification and encryption protection; then use the Merkle Tree and the SHA3 hash value to verify the data integrity, ensuring that the sensitive information is not only securely encrypted but also can effectively prevent tampering. This multi-level combination of encryption and verification not only strengthens the security of the data but also improves the verification efficiency; the combination of the AES encryption algorithm and the Merkle Tree makes the entire identity authentication process more efficient and secure, reduces the computational complexity in the verification process, and improves the response speed and overall performance of the system.

[0086] Further, replace the unencrypted sensitive identity information with the encrypted sensitive identity information, and integrate it with the unencrypted non-sensitive identity information to generate the second registration information. Encrypt the user's second registration information with the public key, and store the encrypted information together with the root hash on the blockchain, which means creating a second registration information, replacing the original unencrypted sensitive identity information with the encrypted ciphertext data, integrating it with the original non-sensitive identity information, and encrypting the second registration information with the public key. The calculation formula is as follows:

[0087] A = E(PK, R),

[0088] where A is the encrypted second registration information, E is the public key encryption operation, and R is the integrated registration information;

[0089] Store the encrypted second registration information A and the root hash of the encrypted sensitive identity information on the blockchain.

[0090] The public key encrypts the integrated second registration information, which will be stored on the blockchain to ensure data immutability and enhance the privacy protection of user data. On this basis, storing the encrypted sensitive information and the root hash through the blockchain avoids the security risks of traditional centralized storage, enabling users to perform efficient and secure identity verification while ensuring privacy. Finally, by encrypting, integrating, and storing the sensitive identity information through public key encryption, it makes up for the deficiencies of the existing technology in terms of privacy protection, data integrity, and verification efficiency, providing a more efficient and secure solution for large-scale identity verification and data protection.

[0091] S3. When the user conducts identity verification, decrypt the second registration information encrypted with the public key by combining the identifier and the Nonce value with the private key, and recalculate the root hash of the encrypted sensitive identity information, and compare it with the root hash stored on the blockchain;

[0092] After the root hash comparison verification passes, use the AES decryption algorithm to decrypt and view the sensitive identity information;

[0093] Specifically, when the user conducts identity verification, decrypt the second registration information encrypted with the public key by combining the identifier and the Nonce value with the private key, and recalculate the root hash of the encrypted sensitive identity information, and compare it with the root hash stored on the blockchain, which means querying the Nonce value stored during the previous verification in the blockchain according to the identifier (each time identity verification is performed, the identifier and the corresponding Nonce value are packed into a transaction record and stored in a block of the blockchain. Use the identifier as the query condition to retrieve the historical records related to this identifier from the blockchain, compare the timestamps, and determine the Nonce value that is the latest in history), called Nonce old , by comparing the current Nonce UValue and Nonce old Based on the timestamp, determine whether the Nonce value is incremented. If it is incremented, it indicates a new authentication request. If the verification passes, continue to perform the authentication;

[0094] If Nonce U is less than or equal to the timestamp of Nonce old , it indicates that the request is an old request. Then reject the request and return an error message;

[0095] Sign the message containing the identifier and Nonce value with the private key. The formula is as follows:

[0096] S = Sign(SK, M),

[0097] where M is the message composed of the identifier and Nonce value (referring to concatenating the identifier and Nonce value into a string), and S is the result after signing with the private key, representing the user's authentication of the message;

[0098] Use the stored public key to verify the validity of the signature to ensure that the signature is generated by the user's private key. The calculation formula is:

[0099] Verify(PK, S, M),

[0100] where Verify refers to the verification process, and PK is the public key stored on the blockchain;

[0101] If the verification passes, it proves that the user has a legal identity. Use the user's private key to decrypt the second registration information encrypted with the public key. The calculation formula is:

[0102] B = D(SK, A),

[0103] where B is the decrypted second registration information, and D is the decryption symbol;

[0104] When accessing the user's sensitive identity information, when the user applies for authentication, generate a new hash value using the user's encrypted sensitive identity information, reconstruct the Merkle Tree, generate a new root hash, and perform a byte-level comparison between the newly calculated root hash of the user and the stored root hash. Only when the two are exactly the same, indicating that the data has not been tampered with, can the verification pass.

[0105] Double protection through private key signature and public key verification ensures the legality and immutability of the signature. After the signature verification passes, only legitimate users can decrypt sensitive information. When applying for access to sensitive identity information, the integrity of the sensitive information is verified through the Merkle Tree and SHA3 hash function, ensuring that data cannot be tampered with even in a decentralized environment, and the verification process is efficient and reliable. Combining the Nonce value mechanism and the encryption and decryption process of public and private keys provides a secure, efficient, and scalable solution for large-scale user identity verification, effectively avoiding problems such as insufficient privacy protection, cumbersome identity verification processes, and low verification efficiency existing in the prior art.

[0106] Further, after the root hash comparison verification passes, the AES decryption algorithm is used for decryption to view sensitive identity information. That is, after the root hash comparison verification passes, if you want to view the sensitive identity information in the registration information, you need to use the AES decryption algorithm to perform an exclusive OR operation on the encrypted ciphertext and the round key of the last round, initialize the state matrix, and perform multiple rounds of decryption operations in sequence. Use the inverse S-box to substitute the bytes in the state matrix to restore the original data, and then perform a reverse shift operation to shift the bytes in each row to the right according to the row index to restore the data shifted to the left during the encryption process. Perform an inverse column mixing operation to restore the relationship between columns through matrix multiplication to ensure that the diffusion effect of the data is correctly reversed. After each round, perform an exclusive OR operation on the current round's round key and the state matrix again. After all rounds of decryption operations, the original plaintext identity information is finally obtained.

[0107] During the identity verification process, first ensure the integrity of the data through root hash comparison verification. Only when the root hashes are consistent can the decryption operation continue. Next, use the AES decryption algorithm to decrypt the encrypted sensitive information round by round. In each round of decryption operation, gradually restore the state matrix through the inverse S-box, reverse shift operation, and inverse column mixing operation, ensuring the secure decryption of the data and the effective restoration of the disrupted data structure during the encryption process; through multiple rounds of decryption processes and exclusive OR operations with round keys, ensure that each layer in the encryption process is associated with the output of the previous layer, effectively increasing the complexity of decryption and avoiding security vulnerabilities caused by simple decryption methods. This technical solution not only improves the security of the decryption process but also increases the unpredictability of the entire identity verification process, further strengthening the protection of sensitive data.

[0108] This embodiment also provides a blockchain-based user identity verification method and system, including:

[0109] A user identity information collection and key generation module, used to collect the user's identity information and generate a public-private key pair;

[0110] Sensitive data encryption and root hash generation module, which is used to encrypt the user's sensitive identity information and generate a root hash;

[0111] Second registration information encryption and storage module, which is used to integrate the encrypted sensitive identity information and non-sensitive identity information to generate second registration information, and this information is encrypted with a public key and stored on the blockchain;

[0112] User identity authentication module, which is used to authenticate the user;

[0113] Sensitive information viewing module, which is used to decrypt the encrypted sensitive information by the user using the AES decryption algorithm after the root hash verification passes.

[0114] This embodiment also provides a computer device, which is applicable to the situation of the user identity verification method based on the blockchain, and includes: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to implement the user identity verification method based on the blockchain as proposed in the above embodiment.

[0115] This computer device can be a terminal, and this computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of this computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication) or other technologies. The display screen of this computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of this computer device can be a touch layer covered on the display screen, or a button, a trackball or a touchpad set on the computer device shell, or an external keyboard, a touchpad or a mouse, etc.

[0116] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method and system for user identity verification based on blockchain as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM for short), electrically erasable programmable read-only memory (EEPROM for short), erasable programmable read-only memory (EPROM for short), programmable read-only memory (PROM for short), read-only memory (ROM for short), magnetic memory, flash memory, magnetic disk or optical disc.

[0117] In summary, in the user identity verification process of the present invention, the second registration information is first decrypted by the public key, and then the AES128-bit encryption algorithm is used to prevent theft and tampering by unauthorized visitors, with fast encryption speed and high security. The combination of the Merkle Tree and the SHA3 hash function further guarantees the integrity and immutability of the data. Even if a certain node is tampered with, the change of the root hash can be quickly detected, thus ensuring the security of the entire system. By verifying the consistency and integrity of the data layer by layer through the hash chain, even a large amount of data can be quickly verified through a single root hash, thereby realizing efficient integrity verification of the data, further improving the security and efficiency of identity verification. Then, the AES decryption algorithm is used to decrypt the final sensitive identity information. In this way, through multiple levels of encryption and decryption steps, not only the security of the identity information is enhanced, but also the security and credibility of the entire identity verification process are ensured, avoiding security vulnerabilities brought by a single encryption method.

[0118] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A user identity verification method based on blockchain, characterized in that: including, The user submits registration information, which is divided into sensitive and non-sensitive identity information, and a public-private key pair is generated for each user through the elliptic curve encryption algorithm; The decentralized identity authentication technology is used to create a unique identifier for the user, and a corresponding public-private key pair is assigned to each identifier; The sensitive identity information is encrypted through the AES128-bit encryption algorithm, and the Merkle Tree and SHA3 hash function are used to generate the root hash of the encrypted sensitive identity information; The encrypted sensitive identity information is used to replace the unencrypted sensitive identity information, and it is integrated with the unencrypted non-sensitive identity information to generate the second registration information. The second registration information of the user is encrypted through the public key, and the encrypted information is stored on the blockchain together with the root hash; When the user performs identity authentication, the second registration information encrypted by the public key is decrypted through the identifier and the Nonce value combined with the private key, and the root hash of the encrypted sensitive identity information is recalculated and compared with the root hash stored on the blockchain; After the root hash comparison verification passes, the AES decryption algorithm is used to decrypt and view the sensitive identity information.

2. The blockchain-based user identity verification method according to claim 1, wherein: The statement that the user submits registration information, which is divided into sensitive and non-sensitive identity information, and a public-private key pair is generated for each user through the elliptic curve encryption algorithm means that the user fills in the personal information form through the front-end interface, which includes the user's sensitive and non-sensitive identity information. The format of the submitted information is verified and the data is cleaned through the back-end. The P-256 standard curve in the elliptic curve encryption algorithm is used to generate the known fixed point G on the elliptic curve, and a pair of public-private key pairs is generated for each user. PK is the public key of the user, and SK is the private key of the user.

3. The method for verifying user identity based on blockchain according to claim 2, wherein: The statement that the decentralized identity authentication technology is used to create an identifier on the blockchain and a public-private key pair is corresponding to each identifier means that the decentralized identity authentication technology is used to generate a unique identifier for the user's identity information. The corresponding public key is associated as a part of each identifier through the centralized identity management protocol to ensure that the public key of the user can be found through the identifier.

4. The blockchain-based user identity verification method according to claim 3, characterized in that: The statement that the sensitive identity information is encrypted through the AES128-bit encryption algorithm, and the Merkle Tree and SHA3 hash function are used to generate the root hash of the encrypted sensitive identity information means that the user's sensitive identity information is converted into byte form and filled into a 4x4 state matrix. The state matrix is encrypted through the AES128-bit encryption algorithm using a 16-byte key, which is used as the original key Key0. The key expansion algorithm is used to fill the bytes of the original key Key0 as the first round key; The first round key performs an exclusive OR operation with the last word of itself. The result obtained is subjected to byte substitution through the S-Box. The round constant performs an exclusive OR operation with the first word of the substituted round key to obtain a new word. The new word performs an exclusive OR operation with the first round key to obtain a second new word. The above steps are repeated to generate the keys for each round in turn. The generation of the keys for each round depends on the output of the previous round until the iteration is completed to generate the required set of round keys; Perform an XOR operation on the state matrix using the first round key, and use the S-box to substitute each byte of the state matrix after the XOR operation to obtain the byte State’[i,j] of the substituted state matrix; Use row shift to cyclically left-shift each row in the state matrix State’[i,j] to obtain the byte D[i,j] of the left-shifted state matrix; Use column mixing to perform matrix multiplication on each column byte of the state matrix after row shift to obtain the byte F[i,j] of the state matrix after column mixing; Organize all F[i, j] into a complete 4x4 state matrix, with each byte in it, to generate the updated state matrix F n ; At the last step of each round, the updated state matrix is XORed with the generated round key to obtain the state matrix E v ; After encryption for a specified number of rounds, the final state matrix E v is the ciphertext E after encryption; Calculate the SHA3 hash value for the ciphertext E. Use the SHA3 hash value of each user as the leaf node of the Merkle Tree. Combine the hash values of every pair of adjacent leaf nodes in position order and calculate the hash value of the new node using the BLAKE2b hash algorithm as the parent node hash value H ix , combine the adjacent parent node hash values together, calculate the hash value of the new layer as the root hash H of the Merkle Tree ixcz .

5. The method for verifying user identity based on blockchain according to claim 4, wherein: The step of replacing the unencrypted sensitive identity information with the encrypted sensitive identity information and integrating it with the unencrypted non-sensitive identity information to generate the second registration information, encrypting the user's second registration information with the public key, and storing the encrypted information together with the root hash on the blockchain refers to creating a second registration information, replacing the original unencrypted sensitive identity information with the encrypted ciphertext data, integrating it with the original non-sensitive identity information, encrypting the second registration information with the public key, and storing the encrypted second registration information and the root hash of the encrypted sensitive identity information on the blockchain.

6. The method for verifying user identity based on blockchain according to claim 5, characterized in that: When the user performs identity authentication, the second registration information encrypted with the public key by combining the identifier and the Nonce value and the private key is decrypted, and the root hash of the encrypted sensitive identity information is recalculated and compared with the root hash stored on the blockchain. Query the Nonce value at the last verification stored in the blockchain according to the identifier, which is called Nonce old , by comparing the current Nonce U value and Nonce old timestamp, judge whether the Nonce value is incremented. If it is incremented, it means that it is a new identity authentication request, and the authentication is passed and the identity authentication continues to be executed; If the Nonce U is less than or equal to the Nonce old timestamp, it indicates that the request is an old request, then reject the request and return an error message; Sign the message containing the identifier and Nonce value with the private key, use the stored public key to verify the validity of the signature. If the verification passes, it proves that the user has a legal identity, and decrypt the second registration information encrypted with the public key using the user's private key; If you want to access the user's sensitive identity information, when the user applies for identity verification, generate a new hash value using the user's encrypted sensitive identity information, reconstruct the Merkle Tree to generate a new root hash, and perform a byte-level comparison between the root hash recalculated by the user and the stored root hash. Only when the two are exactly the same can the verification pass.

7. The blockchain-based user identity verification method according to claim 6, wherein: After the root hash comparison verification passes, use the AES decryption algorithm to decrypt and view the sensitive identity information. It means that after the root hash comparison verification passes, use the AES decryption algorithm to perform an XOR operation on the encrypted ciphertext and the round key of the last round, initialize the state matrix, perform multiple rounds of decryption operations in sequence, use the inverse S-box to substitute the bytes in the state matrix to restore the original data, then perform a reverse row shift operation to right-shift each row of bytes according to the row index to restore the data left-shifted during the encryption process, perform an inverse column mixing operation, and restore the relationship between columns through matrix multiplication to ensure that the diffusion effect of the data is correctly reversed. After each round, perform an XOR operation on the current round's round key and the state matrix again. After all rounds of decryption operations, finally obtain the original plaintext identity information.

8. A blockchain-based user identity verification system, based on the blockchain-based user identity verification method according to any one of claims 1 to 7, characterized in that: Including, A user identity information collection and key generation module, which is used to collect the user's identity information and generate a public-private key pair; A sensitive data encryption and root hash generation module, which is used to encrypt the user's sensitive identity information and generate a root hash; A second registration information encryption and storage module, which is used to integrate the encrypted sensitive identity information and non-sensitive identity information to generate the second registration information, and encrypt and store this information on the blockchain using the public key; A user identity verification module, which is used to verify the user's identity; The sensitive information viewing module is used to decrypt the encrypted sensitive information by the user using the AES decryption algorithm after the root hash verification passes.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the blockchain-based user identity verification method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the blockchain-based user identity verification method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Edge computing task unloading method and related equipment

    CN120561971A

  • Log processing method and device, computer equipment and storage medium

    CN121037021A