Cross-data-space identity authentication method, device and medium
By building cross-chain connectors and identity chains, combining zero-knowledge proof and distributed ledger algorithms, security and privacy issues in cross-data space identity authentication are solved, efficient and secure identity authentication and data sharing are achieved, and identity data is not tampered with and privacy protection is ensured.
Patent Information
- Application Number
- CN202510469188.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-08-01
AI Technical Summary
In the prior art, traditional identity authentication methods cannot meet the requirements of security, privacy and interoperability in data communication scenarios across data spaces, resulting in insufficient protection of single points of failure, information security risks and data privacy.
Build a cross-chain connector and identity chain, realize data format conversion and node discovery between heterogeneous blockchain networks through cross-link routing protocols, integrate zero-knowledge proof module to generate anonymous credentials, combine distributed ledger algorithms and smart contracts to generate encryption tags, and use verified credentials and homomorphic encryption technology to perform dual-factor verification to ensure the immutability of identity data and privacy protection.
It realizes secure and efficient identity authentication and data sharing across data spaces, ensures immutability and high availability of identity data, supports anonymous credential verification, reduces the risk of data leakage, and realizes refined access permission control and risk warning mechanisms.
Smart Images

Figure CN120415780A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of identity authentication, and particularly to an identity authentication method, device, and medium across data spaces. Background Art
[0002] With the acceleration of digital transformation and the rapid development of Internet technology, all walks of life are gradually building their own data spaces to achieve data collection, storage, processing, and analysis.
[0003] However, in the prior art, traditional identity authentication methods usually rely on a centralized system structure, that is, a central entity manages and verifies identity information. Although this centralized mode provides certain conveniences in management and control to a certain extent, it also has disadvantages such as single point of failure, information security risks, insufficient data privacy protection, and lack of cross-system and cross-regional interoperability.
[0004] Especially in the data exchange scenario across data spaces, traditional identity authentication methods often cannot meet the requirements of security, privacy, and interoperability.
[0005] Therefore, how to achieve secure and efficient identity authentication across data spaces has become an urgent technical problem to be solved. Summary of the Invention
[0006] The embodiments of this application provide an identity authentication method, device, and medium across data spaces to solve the following technical problems: how to achieve secure and efficient identity authentication and data sharing across data spaces.
[0007] In a first aspect, the embodiments of this application provide an identity authentication method across data spaces, characterized in that the method includes: constructing a cross-chain connector and an identity master chain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; wherein, the identity master chain is constructed by a preset institution, and the data space includes a basic connector, an identity authentication connector, and an identity chain; sending a data access request from the basic connector of the data space to be accessed to the basic connector of the target data space through the basic connector of the data space to be accessed, so as to generate a reception signal through the basic connector of the target data space; wherein, both the data space to be accessed and the target data space are on-chain to the identity master chain, and the reception signal includes a credential submission requirement; submitting a verifiable credential to the target data space by the data space to be accessed according to the credential submission requirement; sending the verifiable credential to the cross-chain connector by the target data space, and verifying the verifiable credential based on the identity master chain and the identity chain of the data space to be accessed to generate a verification result; if the verification result is passed, the target data space and the data space to be accessed construct a connection relationship.
[0008] In an implementation manner of the present application, a cross-chain connector is constructed, and an identity total chain connected to the cross-chain connector is constructed, specifically including: constructing a communication channel of the cross-chain connector based on a preset cross-chain routing protocol; wherein, the cross-chain routing protocol is used to define data format conversion rules and node discovery mechanisms between different blockchain networks; integrating a preset zero-knowledge proof module in the communication channel to generate and verify anonymous credentials in cross-chain transactions; deploying blockchain nodes through a preset institution, and constructing an identity total chain based on a preset distributed ledger algorithm; wherein, the distributed ledger algorithm includes a Byzantine fault-tolerant consensus mechanism.
[0009] In an implementation manner of the present application, the basic connector of the data space to be accessed sends a data access request to the basic connector of the target data space, specifically including: generating an encrypted tag through the smart contract of the identity total chain based on the access requirements of the data space to be accessed; wherein, the encrypted tag has a timeliness feature; constructing a data access request based on the encrypted tag and the identity identifier of the data space to be accessed, and sending it to the basic connector of the target data space through the cross-chain connector.
[0010] In an implementation manner of the present application, the basic connector of the target data space generates a reception signal, specifically including: verifying the data access request through the target data space to generate a preliminary reception signal; processing the industry attribute of the data space to be accessed based on a preset mapping database to determine the access permission of the data space to be accessed; wherein, the mapping database includes industry attributes and corresponding access permissions; determining a credential submission requirement based on the preliminary reception signal and the access permission to generate a reception signal.
[0011] In an implementation manner of the present application, the data space to be accessed submits a verifiable credential to the target data space according to the credential submission requirement, specifically including: generating a verifiable credential that conforms to a preset format based on the credential submission requirement in the reception signal, and generating a verifiable proof associated with the verifiable credential through a zero-knowledge proof algorithm; encrypting the verifiable credential and the verifiable proof based on a preset homomorphic encryption technology, and adding the public key signature of the target data space to the verifiable credential and the verifiable proof; sending the encrypted verifiable credential and verifiable proof to the target data space through the cross-chain connector.
[0012] In one implementation of the present application, a verifiable credential is sent to a cross-chain connector through a target data space, and the verifiable credential is verified based on an identity total chain and an identity chain of a data space to be accessed to generate a verification result. Specifically, it includes: sending the verifiable credential to the cross-chain connector through a basic connector of the target data space; generating a query request based on the verifiable credential by the cross-chain connector and sending the query request to an identity authentication connector of the data space to be accessed; sending the query request to the identity chain of the data space to be accessed by the identity authentication connector of the data space to be accessed; verifying the query request based on the identity chain of the data space to be accessed and generating a verification result; wherein the verification result includes a security level label.
[0013] In one implementation of the present application, if the verification result is passed, a connection relationship is established between the target data space and the data space to be accessed. Specifically, it includes: forwarding the verification result to an identity authentication connector of the target data space through the cross-chain connector; uploading the data space to be accessed to the identity chain of the target data space based on the verification result through the identity chain of the target data space; uploading the target data space to the identity chain of the data space to be accessed based on the verification result through the identity chain of the data space to be accessed; determining the access range of the data space to be accessed based on the security level label in the verification result.
[0014] In one implementation of the present application, the method further includes: if the verification result is not passed, the target data space generates a security warning event and sends it to the identity total chain through the cross-chain connector; wherein the security warning event includes a failure reason; restricting subsequent access requests of the data space to be accessed based on a smart contract of the identity total chain.
[0015] Second aspect, an embodiment of the present application further provides an identity authentication device across data spaces, characterized in that the device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to: construct a cross-chain connector, and construct an identity master chain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; wherein, the identity master chain is constructed by a preset institution, and the data spaces include a basic connector, an identity authentication connector, and an identity chain; send a data access request to the basic connector of the target data space through the basic connector of the data space to be accessed, so as to generate a reception signal through the basic connector of the target data space; wherein, the data space to be accessed and the target data space are both chained to the identity master chain, and the reception signal includes a credential submission requirement; submit a verifiable credential to the target data space by the data space to be accessed according to the credential submission requirement; send the verifiable credential to the cross-chain connector by the target data space, and verify the verifiable credential based on the identity master chain and the identity chain of the data space to be accessed to generate a verification result; if the verification result is passed, a connection relationship is constructed between the target data space and the data space to be accessed.
[0016] Third aspect, an embodiment of the present application further provides a non-volatile computer storage medium for identity authentication across data spaces, storing computer-executable instructions, characterized in that the computer-executable instructions are set to: construct a cross-chain connector, and construct an identity master chain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; wherein, the identity master chain is constructed by a preset institution, and the data spaces include a basic connector, an identity authentication connector, and an identity chain; send a data access request to the basic connector of the target data space through the basic connector of the data space to be accessed, so as to generate a reception signal through the basic connector of the target data space; wherein, the data space to be accessed and the target data space are both chained to the identity master chain, and the reception signal includes a credential submission requirement; submit a verifiable credential to the target data space by the data space to be accessed according to the credential submission requirement; send the verifiable credential to the cross-chain connector by the target data space, and verify the verifiable credential based on the identity master chain and the identity chain of the data space to be accessed to generate a verification result; if the verification result is passed, a connection relationship is constructed between the target data space and the data space to be accessed.
[0017] An identity authentication method, device and medium across data spaces provided by an embodiment of the present application at least include the following technical effects:
[0018] Decentralized Identity Management: The Identity Total Chain centrally stores and dynamically manages identity documents in each data space, and combines distributed ledger algorithms and Byzantine Fault Tolerance consensus mechanisms to ensure the immutability and high availability of identity data to a certain extent, providing a trusted basis for cross-chain authentication.
[0019] Cross-chain Interoperability Enhancement: Based on the cross-chain routing protocol and zero-knowledge proof module, it realizes seamless communication and privacy protection between heterogeneous blockchain networks, supports anonymous credential verification in cross-chain transactions, and reduces the risk of data leakage.
[0020] Secure Access Control: Generate time-limited encryption tags through smart contracts, and dynamically determine access permissions in combination with the industry attribute mapping database to ensure the legality of the request source and the refined control of permissions.
[0021] Dual Verification and Dynamic Connection: Adopt verifiable credentials and homomorphic encryption technology to achieve dual security verification. The cross-chain connector and the identity chain cooperate to complete two-way identity anchoring, and dynamically configure the access scope based on security level tags to improve the flexibility and security of the system.
[0022] Risk Warning and Control: Automatically trigger security warning events when verification fails, and the identity total chain smart contract restricts illegal access in real time, forming a closed-loop risk prevention and control mechanism to effectively resist identity fraud and unauthorized access.. Description of the Drawings
[0023] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0024] Figure 1 It is a flowchart of an identity authentication method across data spaces provided by an embodiment of the present application;
[0025] Figure 2 It is a schematic internal structure diagram of an identity authentication device across data spaces provided by an embodiment of the present application. Detailed Embodiments
[0026] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0027] The embodiments of the present application provide a cross-data-space identity authentication method, device, and medium to solve the following technical problems: how to achieve secure and efficient identity authentication and data sharing across data spaces.
[0028] The technical solutions proposed in the embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0029] Figure 1 It is a flowchart of cross-data-space identity authentication provided for the embodiments of the present application. As Figure 1 shown, a cross-data-space identity authentication method provided by the embodiments of the present application specifically includes the following steps:
[0030] Step 1: Construct a cross-chain connector and an identity masterchain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; among them, the identity masterchain is constructed by a preset institution, and the data spaces include a basic connector, an identity authentication connector, and an identity chain.
[0031] The cross-chain connector (Cross-Chain Connector) is a core component for realizing data intercommunication between different blockchain networks. It establishes a communication channel through a preset protocol to solve the interoperability problem between heterogeneous chains. The identity masterchain (Identity Masterchain) is a consortium chain constructed by a preset institution (such as an industry association, a regulatory agency) for centrally storing and managing decentralized identity (DID) documents of multiple data spaces to ensure the global verifiability of identity data.
[0032] Step 1.1: Construct a communication channel for the cross-chain connector based on a preset cross-chain routing protocol; among them, the cross-chain routing protocol is used to define data format conversion rules and node discovery mechanisms between different blockchain networks.
[0033] The cross-chain routing protocol (Cross-Chain Routing Protocol) is used to define data format conversion rules (such as JSON to Protobuf) and node discovery mechanisms (such as a DNS seed node list) between different blockchain networks to solve the data intercommunication obstacles caused by protocol differences between heterogeneous chains.
[0034] Data format conversion rules: For example, convert JSON format transactions on blockchain A to Protobuf format on blockchain B to ensure cross-chain readability of data;
[0035] Node discovery mechanism: By maintaining a dynamic seed node list, efficient addressing of cross-chain nodes is achieved.
[0036] A preset institution (such as a relevant department or industry association) selects nodes that support the cross-chain routing protocol as "border gateways" and configures protocol parameters (such as the maximum packet size, timeout threshold).
[0037] In a specific example, in the cross-chain scenario of medical data, the private chain of Institution A needs to communicate with the Ethereum network of Institution B. Through the cross-chain routing protocol, both parties agree to convert the patient's diagnosis and treatment records (JSON) into the Protobuf format and dynamically update the address of the other party's border gateway through the DNS seed node list to ensure communication stability.
[0038] Step 1.2: Integrate a preset zero-knowledge proof module into the communication channel to generate and verify anonymous credentials in cross-chain transactions.
[0039] The zero-knowledge proof module (Zero-Knowledge Proof Module) supports generating and verifying anonymous credentials (such as proving that the user's age is ≥18 years old without revealing the date of birth).
[0040] In the embodiment of the present application, the zk-SNARKs or Bulletproofs algorithm can be adopted to ensure the privacy of cross-chain transactions to a certain extent.
[0041] In a specific example, in the cross-chain authentication of educational qualifications, User C needs to prove to Institution B that he has a "bachelor's degree or above". The zero-knowledge proof module generates an encrypted credential containing the educational qualification information. Institution B confirms the validity of the credential through a preset verification circuit, but cannot know the specific institution or major of the user.
[0042] Step 1.3: Deploy blockchain nodes through a preset institution and construct an identity master chain based on a preset distributed ledger algorithm; wherein, the distributed ledger algorithm includes the Byzantine Fault Tolerance consensus mechanism.
[0043] Through the Byzantine Fault Tolerance (BFT) consensus mechanism (such as the Tendermint algorithm), the global consistency of identity data is ensured to a certain extent, and malicious node attacks are resisted.
[0044] A preset institution (such as a financial regulatory department) deploys at least 4 verification nodes and configures BFT consensus parameters (such as the block generation interval, voting timeout).
[0045] For example, a cross-border financial alliance constructs an identity master chain, and member banks A, B, and C each deploy 2 nodes. When enterprise user D submits a DID document (including the hash of enterprise registration information), the nodes reach consensus through three rounds of voting and write the document into the master chain. If node A goes offline due to a fault, the remaining nodes can still complete the consensus (meeting the BFT fault tolerance condition).
[0046] In a specific case, a medical industry association constructs a cross-chain connector and an identity master chain system: The association selects 5 hospitals as boundary gateways, configures a cross-chain routing protocol to convert the HL7 medical data format into a blockchain-compatible format; when patient data is transmitted across the chain, the zero-knowledge proof module generates an anonymous proof of "negative infectious disease test result"; the association deploys 7 nodes (including 2 regulatory agency nodes), and writes the patient DID document (including the encrypted medical record hash) into the identity master chain through BFT consensus. When Hospital A needs to query the cross-hospital diagnosis and treatment records of Patient B, it locates the blockchain of Hospital B through the cross-chain connector, verifies B's DID document, and returns the diagnosis and treatment summary encrypted by zero-knowledge proof.
[0047] Step 2: Send a data access request to the basic connector of the target data space through the basic connector of the data space to be accessed, so as to generate a reception signal through the basic connector of the target data space; wherein, both the data space to be accessed and the target data space are on-chain to the identity master chain, and the reception signal includes a voucher submission requirement.
[0048] A secure access mechanism implemented between the data space to be accessed (requesting party) and the target data space (requested party) through the identity master chain is generated by combining encrypted tags, permission verification, and voucher requirements.
[0049] Step 2.1: Based on the access requirements of the data space to be accessed, generate an encrypted tag through the smart contract of the identity master chain; wherein, the encrypted tag has a timeliness feature.
[0050] The encrypted tag (Encrypted Time-bound Token) is a dynamic voucher generated by the identity master chain smart contract for a single access request.
[0051] The tag contains the identity hash of the requesting party, a timestamp, and a random nonce value, which is encrypted through a preset algorithm (such as AES-256) and is only valid within a specified time window (such as 5 minutes) to prevent replay attacks.
[0052] The data space to be accessed calls the identity master chain smart contract to pass in the identity identifier and the request validity period parameter, and the contract returns an encrypted string.
[0053] For example, when Medical Institution A needs to temporarily access a patient's file, it calls the smart contract to generate a tag ETT-123, and sets the validity period to during the diagnosis and treatment session (30 minutes), which will automatically expire after timeout.
[0054] Step 2.2: Construct a data access request based on the encrypted tag and the identity identifier of the data space to be accessed, and send it to the basic connector of the target data space through the cross-chain connector.
[0055] A Data Access Request shall include an encrypted tag and the identity identifier of the requester, and be routed to the target data space through a cross-chain connector.
[0056] The target data space verifies the encrypted tag to confirm the legitimacy of the request and prevent unauthorized access.
[0057] The data space to be connected encapsulates the encrypted tag, identity identifier, and request type (such as "query patient records") into a standardized message and sends it through the cross-chain connector.
[0058] For example, Institution A sends ETT-123 (encrypted tag), its own DID, and query parameters to the cross-chain connector to request access to the medical records of Patient D in Institution B.
[0059] Step 2.3: Verify the data access request through the target data space to generate a preliminary reception signal.
[0060] The preliminary reception signal indicates that the target data space has received and preliminarily verified the request.
[0061] The target data space checks the validity of the encrypted tag (such as timestamp, signature) to confirm that the request has not been tampered with and comes from a legitimate identity.
[0062] The basic connector of the target data space calls the verification interface of the identity total chain and returns the result of the tag validity.
[0063] For example, the connector of Institution B verifies ETT-123 and confirms that ETT-123 is issued by the identity total chain, not expired, and bound to the DID of Institution A, and returns a preliminary reception signal.
[0064] Step 2.4: Process the industry attributes of the data space to be connected based on a preset mapping database to determine the access permissions of the data space to be connected; wherein, the mapping database includes industry attributes and corresponding access permissions.
[0065] The mapping database stores the association rules between industry attributes and access permissions.
[0066] For example, institutions in the medical industry can access basic patient information, but financial institutions have no right to access medical records.
[0067] A preset institution maintains a database, defining attribute fields (such as "industry type: medical") and permission levels (such as "allowed to access medical data").
[0068] The mapping database stipulates that if the industry attribute of the requester is "medical", access to patient medical records is allowed; if it is "finance", only access to anonymized statistical information is allowed.
[0069] Step 2.5: Determine the credential submission requirements based on the preliminary received signal to generate a received signal.
[0070] The received signal includes credential submission requirements, such as "a written authorization from the patient is required" or "multi-factor authentication is required".
[0071] Dynamically generate security requirements based on access rights to balance data openness and privacy protection.
[0072] The target data space combines the preliminary verification results with the mapping database rules to generate a response containing credential requirements.
[0073] For example, Institution B determines that Institution A belongs to the medical industry based on the mapping database, requires the submission of an electronically authorized document signed by the patient (credential requirement), and finally generates a received signal.
[0074] In a specific case, Medical Institution A needs to access the oncology treatment records of Patient D in Institution B: A calls the intelligent contract to generate an encrypted tag ETT-123 with a validity period of 30 minutes. A sends a request containing ETT-123 to the cross-chain connector; B verifies the validity of the tag and returns a preliminary received signal; B queries the mapping database to confirm that A's medical industry attribute has access rights; B generates a received signal requiring "submission of an electronically signed authorization from the patient", and A completes data access after supplementing the credentials.
[0075] Step 3: Submit verifiable credentials to the target data space through the data space to be connected according to the credential submission requirements.
[0076] The data space to be connected (requesting party) generates and securely transmits verifiable credentials to the target data space (requested party) according to the credential submission requirements, ensuring the privacy, integrity, and non-repudiation of the credentials.
[0077] Step 3.1: Generate verifiable credentials that conform to a preset format based on the credential submission requirements in the received signal, and generate a verifiable proof associated with the verifiable credentials through a zero-knowledge proof algorithm.
[0078] A verifiable credential is a digital document containing claims (such as identity, permissions), and zero-knowledge proofs are used to verify the authenticity of the credential without exposing sensitive information.
[0079] Zero-knowledge proofs ensure the validity of verifiable credentials in the target data space (such as whether the patient has authorized), but cannot obtain the plaintext content of the credentials (such as the patient's specific diagnosis information).
[0080] The requesting party calls the credential generation tool, inputs the fields in the credential submission requirements (such as "patient's electronic signature"), and the tool automatically fills in the structured data and generates a ZKP.
[0081] For example, medical institution A needs to submit an electronic authorization letter of patient D. The tool generates a credential VC-456, which contains a hash pointer pointing to the stored signature file, and generates a ZKP to prove that the signature is valid.
[0082] Step 3.2: Encrypt the verifiable credential and the verifiable proof based on a preset homomorphic encryption technology, and add the public key signature of the target data space to the verifiable credential and the verifiable proof.
[0083] Homomorphic Encryption allows direct computation on ciphertext, and PublicKey Signature ensures the credibility of the origin of the credential.
[0084] Homomorphic encryption protects the credential from being stolen during transmission, and the public key signature prevents the credential from being tampered with or forged.
[0085] Encrypt the credential and the ZKP using the public key of the target data space, and then sign with the private key of the requester to form a double security layer.
[0086] For example, institution A obtains the public key PUB-B of institution B, encrypts VC-456 and the ZKP with PUB-B, and then signs with its own private key PRI-A to generate an encrypted file ENC-VC-456.
[0087] Step 3.3: Send the encrypted verifiable credential and the verifiable proof to the target data space based on a cross-chain connector.
[0088] The cross-chain connector is responsible for routing encrypted data between heterogeneous data spaces to ensure end-to-end secure transmission.
[0089] The connector verifies the security of the transmission channel, prevents man-in-the-middle attacks, and ensures that the credential reaches the target data space intact.
[0090] The requester sends the encrypted file ENC-VC-456 to the cross-chain connector, and the connector routes it to the basic connector of institution B according to the target address.
[0091] For example, institution A sends ENC-VC-456 through the cross-chain connector. The connector verifies the file hash and the transmission protocol, and forwards the file to institution B after ensuring that it has not been tampered with.
[0092] In a specific case, medical institution A needs to submit an authorization credential of patient D to access their medical records: [[ID=$$]]
[0093] Generate a verifiable credential VC-456 (including the patient's signature hash), use the ZKP algorithm to generate a proof that "this signature is issued by the patient's private key", encrypt VC-456 and the ZKP with the public key PUB-B of institution B, and then sign with its own private key PRI-A to generate ENC-VC-456; A sends ENC-VC-456 to institution B through the cross-chain connector, and the connector verifies the transmission integrity and then completes the delivery. After institution B decrypts ENC-VC-456, it verifies the validity of the patient's signature through ZKP, and can complete the authorization confirmation without viewing the plaintext content, realizing secure access under privacy protection.
[0094] Step 4: Send the verifiable credential to the cross-chain connector through the target data space, and verify the verifiable credential based on the identity total chain and the identity chain of the data space to be accessed, so as to generate a verification result.
[0095] The target data space performs cross-chain verification on the received verifiable credential, interacts through the identity total chain and the identity chain of the data space to be accessed, and generates a verification result containing a security level label.
[0096] Step 4.1: Send the verifiable credential to the cross-chain connector through the basic connector of the target data space.
[0097] The basic connector is a local communication module deployed in the target data space, and the cross-chain connector is a routing node connecting heterogeneous data spaces.
[0098] The basic connector forwards the credential from the internal network of the target data space to the cross-chain connector to ensure the security of the data cross-chain transmission entry.
[0099] The target data space parses the received encrypted credential package, extracts the credential metadata (such as the issuer identifier), and sends it to the cross-chain connector through the basic connector.
[0100] For example, the basic connector of institution B receives the encrypted credential ENC-VC-456 from institution A, extracts the credential issuer IDISSUER-A, and sends the metadata and the encrypted file to the cross-chain connector.
[0101] Step 4.2: Generate a query request based on the verifiable credential through the cross-chain connector, and send the query request to the identity authentication connector of the data space to be accessed.
[0102] The query request is a standardized request constructed by the cross-chain connector to verify the authenticity of the credential.
[0103] The cross-chain connector generates query requests with different structures according to the credential type (such as identity credential, permission credential) to ensure that the identity authentication connector can parse them.
[0104] The cross-chain connector calls the preset template, fills the voucher hash, issuer ID, and target identity chain address into the request body, and sends it to the identity authentication connector of the data space to be accessed.
[0105] For example, the cross-chain connector generates a request REQ-789, which contains the hash value of VC-456, ISSUER-A, and the identity chain address CHAIN-A of institution A, and sends it to the identity authentication connector of institution A.
[0106] Step 4.3: Send a query request to the identity chain of the data space to be accessed through the identity authentication connector of the data space to be accessed.
[0107] The Identity Authentication Connector is a cross-chain communication module deployed in the data space to be accessed.
[0108] The identity authentication connector parses the query request and calls the verification interface of the local identity chain to ensure that the request data complies with the access protocol of the identity chain.
[0109] The identity authentication connector verifies the request signature (such as the public key verification of the cross-chain connector), and sends the request after converting it into a format recognizable by the identity chain.
[0110] For example, the identity authentication connector of institution A verifies the cross-chain connector signature of REQ-789, converts the request into API call parameters of the identity chain CHAIN-A, and sends it to CHAIN-A.
[0111] Step 4.4: Verify the query request based on the identity chain of the data space to be accessed and generate a verification result; among them, the verification result includes a security level tag.
[0112] The Security Level Tag is a risk assessment identifier attached by the identity chain according to the verification result.
[0113] The identity chain evaluates the authenticity of the voucher by comparing the voucher issuance records stored on the chain (such as user public key, voucher template hash), and returns a dynamically generated security label.
[0114] The identity chain executes a predefined smart contract to verify the voucher signature chain, validity period, and revocation status, and generates a verification result containing a label.
[0115] For example, the identity chain CHAIN-A verifies that the issuer signature of VC-456 matches the public key of user D, and the voucher has not been revoked, and returns the result VALID and attaches the label SL-GOLD (indicating a high security level).
[0116] In a specific example, financial institution B needs to verify the cross-chain identity credential of user D. B's basic connector sends VC-456 to the cross-chain connector. The cross-chain connector generates a request REQ-789, which includes the hash of VC-456 and ISSUER-A, and sends it to A's identity authentication connector. A's identity authentication connector routes the request to identity chain CHAIN-A. CHAIN-A verifies the validity of the credential, returns the result VALID and the label SL-GOLD to the cross-chain connector, and finally feeds it back to B. B automatically adjusts the trading permissions of user D according to the SL-GOLD label to achieve risk-controlled cross-chain service access.
[0117] Step 5: If the verification result is passed, the target data space and the data space to be accessed build a connection relationship.
[0118] The verification result-driven double-chain interoperability mechanism includes connection relationship construction, security label application, and verification failure handling.
[0119] Step 5.1: Forward the verification result to the identity authentication connector of the target data space based on the cross-chain connector.
[0120] The Identity Authentication Connector is a module in the target data space for receiving cross-chain verification results.
[0121] The cross-chain connector sends the verification result (including the security label) returned by the identity chain to the identity authentication connector of the target data space, triggering subsequent connection operations.
[0122] The cross-chain connector encapsulates the verification result into a standardized message (such as including a result field and a security-tag field) and sends it to the identity authentication connector of the target data space through an encrypted channel.
[0123] For example, the cross-chain connector sends the VALID result and the SL-GOLD label returned by institution A's identity chain to institution B's identity authentication connector.
[0124] Step 5.2: Based on the verification result, the identity chain of the target data space chains the data space to be accessed to the identity of the target data space.
[0125] The On-Chaining operation refers to writing the identity identifier of the other data space into the local identity chain to form a trusted connection record.
[0126] The identity chain of the target data space records the identity hash and security label of the data space to be accessed, providing identity endorsement for subsequent cross-chain data interaction.
[0127] The identity chain of the target data space executes a smart contract and writes the DID (Distributed Identity) and security label of the space to be connected into the on-chain database.
[0128] For example, the identity chain of institution B writes DID-DID-A of institution A and the SL-GOLD label onto the chain, generating a connection record CONN-B-A.
[0129] Step 5.3: Based on the verification result, the identity chain of the data space to be connected uploads the target data space to the identity chain of the data space to be connected.
[0130] The identity chain of the data space to be connected synchronously records the identity and label of the target space, realizing two-way identity anchoring.
[0131] The identity chain of the data space to be connected receives the DID of the target space through its identity authentication connector and performs a reverse recording operation.
[0132] For example, the identity chain of institution A writes DID-DID-B of institution B and the SL-GOLD label onto the chain, generating a record CONN-A-B.
[0133] Step 5.4: Determine the access range of the data space to be connected based on the security level label in the verification result.
[0134] The access range is determined by the permission policy mapped by the security label.
[0135] The security level label (such as SL-GOLD) corresponds to a predefined permission template, restricting the depth and type of cross-chain data interaction.
[0136] The target data space reads the security label, matches the access control list (ACL) in the local policy engine, and dynamically generates an access token.
[0137] For example, according to the SL-GOLD label, institution B authorizes institution A to access non-sensitive fields (such as diagnosis results) in its user's medical records, and secondary authorization is required for sensitive fields.
[0138] When the verification result is not passed:
[0139] A1. If the verification result is not passed, the target data space generates a security alert event and sends it to the identity master chain through the cross-chain connector; among them, the security alert event includes the reason for failure.
[0140] The security alert event is used to record and spread the verification failure risk.
[0141] When the verification result is INVALID, the target data space generates an alarm event containing the reason for failure (such as voucher tampering, revocation status), and broadcasts it to the identity main chain through the cross-chain connector.
[0142] The target data space constructs an alarm event (including alert-type, reason-code, timestamp), and sends it to the identity main chain through the cross-chain connector.
[0143] For example, institution B detects that the voucher VC-789 of institution A has been revoked, generates an alarm event ALERT-B-A, includes the reason code REASON-REVOKED, and sends it to the identity main chain.
[0144] A2. The smart contract based on the identity main chain restricts subsequent access requests to the data space to be accessed.
[0145] The compliance contract deployed on the identity main chain listens to the alarm event, automatically adds the relevant DID to the blacklist, and restricts it from initiating cross-chain requests.
[0146] The smart contract monitors the alarm event stream, updates the on-chain access control list after matching the blacklist rules.
[0147] For example, the compliance contract on the identity main chain detects ALERT-B-A, adds DID-A to the blacklist, and subsequent requests from institution A will be automatically rejected.
[0148] In a specific example, medical institution B needs to establish cross-chain data sharing with insurance company A: the cross-chain connector sends the verification result VALID of A and SL-GOLD to the identity authentication connector of B; the identity chain of B uploads the DID of A and SL-GOLD to the chain; the identity chain of A synchronously records the DID of B and SL-GOLD; B authorizes A to access the de-identified user medical records according to SL-GOLD; B generates an alarm event ALERT-B-A, the identity main chain automatically restricts A's access, the two chains establish a trusted connection, the permissions are dynamically adapted to the security label, and the risk event is blocked in real time, realizing safe and efficient cross-chain collaboration.
[0149] The above is the method embodiment proposed in this application. Based on the same inventive concept, the embodiment of this application also provides an identity authentication device across data spaces, and its structure is as Figure 2 shown.
[0150] Figure 2 This is a schematic internal structure diagram of an identity authentication device across data spaces provided by the embodiment of this application. As Figure 2 shown, the device includes:
[0151] At least one processor 201;
[0152] and a memory 202 communicatively connected to at least one processor;
[0153] wherein the memory 202 stores instructions executable by at least one processor, and the instructions are executed by at least one processor 201 to enable at least one processor 201 to:
[0154] Construct a cross-chain connector and construct an identity general chain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; wherein the identity general chain is constructed by a preset institution, and the data spaces include a basic connector, an identity authentication connector, and an identity chain; send a data access request from the basic connector of the data space to be accessed to the basic connector of the target data space, so as to generate a reception signal through the basic connector of the target data space; wherein both the data space to be accessed and the target data space are on-chain to the identity general chain, and the reception signal includes a credential submission requirement; submit a verifiable credential to the target data space by the data space to be accessed according to the credential submission requirement; send the verifiable credential to the cross-chain connector by the target data space, and verify the verifiable credential based on the identity general chain and the identity chain of the data space to be accessed to generate a verification result; if the verification result is passed, establish a connection relationship between the target data space and the data space to be accessed.
[0155] Some embodiments of the present application provide a non-volatile computer storage medium corresponding to Figure 1 for identity authentication across data spaces, storing computer-executable instructions, and the computer-executable instructions are set to:
[0156] Construct a cross-chain connector and construct an identity general chain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; wherein the identity general chain is constructed by a preset institution, and the data spaces include a basic connector, an identity authentication connector, and an identity chain; send a data access request from the basic connector of the data space to be accessed to the basic connector of the target data space, so as to generate a reception signal through the basic connector of the target data space; wherein both the data space to be accessed and the target data space are on-chain to the identity general chain, and the reception signal includes a credential submission requirement; submit a verifiable credential to the target data space by the data space to be accessed according to the credential submission requirement; send the verifiable credential to the cross-chain connector by the target data space, and verify the verifiable credential based on the identity general chain and the identity chain of the data space to be accessed to generate a verification result; if the verification result is passed, establish a connection relationship between the target data space and the data space to be accessed.
[0157] Each embodiment in this application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the Internet of Things devices and media, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the relevant parts of the method embodiments for the related content.
[0158] The systems and media provided in the embodiments of this application correspond one by one to the methods. Therefore, the systems and media also have beneficial technical effects similar to those of their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the systems and media will not be elaborated here.
[0159] Those skilled in the art should understand that the embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) that contain computer-usable program code.
[0160] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0161] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device that realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0162] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, causing a series of operational steps to be performed on the computer or other programmable apparatus to generate a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process Figure 1 one process or more processes and / or blocks Figure 1 steps for implementing the functions specified in one block or more blocks.
[0163] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0164] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
[0165] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0166] It should also be noted that the term "comprises", "comprising", or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0167] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. An identity authentication method across data spaces, characterized in that, The method includes: Constructing a cross-chain connector and constructing an identity master chain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; wherein, the identity master chain is constructed by a preset institution, and the data spaces include a basic connector, an identity authentication connector, and an identity chain; Sending a data access request from the basic connector of the data space to be accessed to the basic connector of the target data space through the cross-chain connector, so as to generate a reception signal through the basic connector of the target data space; wherein, both the data space to be accessed and the target data space are on-chain to the identity master chain, and the reception signal includes a credential submission requirement; Submitting a verifiable credential from the data space to be accessed to the target data space according to the credential submission requirement; Sending the verifiable credential to the cross-chain connector by the target data space, and verifying the verifiable credential based on the identity master chain and the identity chain of the data space to be accessed to generate a verification result; If the verification result is passed, a connection relationship is established between the target data space and the data space to be accessed.
2. The identity authentication method across data spaces according to claim 1, wherein Constructing a cross-chain connector and constructing an identity master chain connected to the cross-chain connector specifically includes: Constructing a communication channel of the cross-chain connector based on a preset cross-chain routing protocol; wherein, the cross-chain routing protocol is used to define data format conversion rules and node discovery mechanisms between different blockchain networks; Integrating a preset zero-knowledge proof module in the communication channel to generate and verify anonymous credentials in cross-chain transactions; Deploying blockchain nodes by the preset institution and constructing an identity master chain based on a preset distributed ledger algorithm; wherein, the distributed ledger algorithm includes a Byzantine fault tolerance consensus mechanism.
3. The identity authentication method across data spaces according to claim 1, wherein Sending a data access request from the basic connector of the data space to be accessed to the basic connector of the target data space specifically includes: Generating an encrypted tag through the smart contract of the identity master chain based on the access requirement of the data space to be accessed; wherein, the encrypted tag has a timeliness feature; Constructing a data access request based on the encrypted tag and the identity identifier of the data space to be accessed, and sending it to the basic connector of the target data space through the cross-chain connector.
4. The identity authentication method across data spaces according to claim 1, characterized in that The basic connector of the target data space generates a reception signal specifically includes: Verifying the data access request through the target data space to generate a preliminary reception signal; Processing the industry attribute of the data space to be accessed based on a preset mapping database to determine the access permission of the data space to be accessed; wherein, the mapping database includes industry attributes and corresponding access permissions; Determining the credential submission requirement based on the preliminary reception signal and the access permission to generate a reception signal.
5. The identity authentication method across data spaces according to claim 1, wherein Submitting a verifiable credential from the data space to be accessed to the target data space according to the credential submission requirement specifically includes: Generating a verifiable credential that conforms to a preset format based on the credential submission requirement in the reception signal, and generating a verifiable proof associated with the verifiable credential through a zero-knowledge proof algorithm; Encrypt the verifiable credential and verifiable proof based on a preset homomorphic encryption technology, and add the public key signature of the target data space to the verifiable credential and verifiable proof; Send the encrypted verifiable credential and verifiable proof to the target data space based on the cross-chain connector.
6. The identity authentication method across data spaces according to claim 1, characterized in that Send the verifiable credential to the cross-chain connector through the target data space, and verify the verifiable credential based on the identity total chain and the identity chain of the data space to be accessed to generate a verification result, specifically including: Send the verifiable credential to the cross-chain connector through the basic connector of the target data space; Generate a query request based on the verifiable credential through the cross-chain connector, and send the query request to the identity authentication connector of the data space to be accessed; Send the query request to the identity chain of the data space to be accessed through the identity authentication connector of the data space to be accessed; Verify the query request based on the identity chain of the data space to be accessed and generate a verification result; wherein, the verification result includes a security level label.
7. An identity authentication method across data spaces according to claim 6, characterized in that, If the verification result is passed, the target data space and the data space to be accessed establish a connection relationship, specifically including: Forward the verification result to the identity authentication connector of the target data space based on the cross-chain connector; Chain the data space to be accessed to the identity chain of the target data space based on the verification result through the identity chain of the target data space; Chain the target data space to the identity chain of the data space to be accessed based on the verification result through the identity chain of the data space to be accessed; Determine the access range of the data space to be accessed based on the security level label in the verification result.
8. The identity authentication method across data spaces according to claim 7, wherein The method further includes: If the verification result is not passed, the target data space generates a security warning event and sends it to the identity total chain through the cross-chain connector; wherein, the security warning event includes the reason for failure; Restrict subsequent access requests of the data space to be accessed based on the smart contract of the identity total chain.
9. An identity authentication device across data spaces, characterized in that, The device includes: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to: Construct a cross-chain connector and construct an identity total chain connected to the cross-chain connector to store and manage decentralized identity documents of multiple data spaces; wherein, the identity total chain is constructed by a preset institution, and the data space includes a basic connector, an identity authentication connector and an identity chain; Send a data access request to the basic connector of the target data space through the basic connector of the data space to be accessed, so as to generate a reception signal through the basic connector of the target data space; wherein, the data space to be accessed and the target data space are both chained to the identity total chain, and the reception signal includes a credential submission requirement; Submit a verifiable credential to the target data space by the data space to be accessed according to the credential submission requirement; Send the verifiable credential to the cross-chain connector through the target data space, and verify the verifiable credential based on the identity general chain and the identity chain of the data space to be accessed to generate a verification result; If the verification result is passed, the target data space and the data space to be accessed establish a connection relationship.
10. A non-volatile computer storage medium for cross-data-space identity authentication, storing computer-executable instructions, characterized in that, The computer-executable instructions are set as: Construct a cross-chain connector and construct an identity general chain connected to the cross-chain connector to store and manage the decentralized identity documents of multiple data spaces; wherein, the identity general chain is constructed by a preset institution, and the data space includes a basic connector, an identity authentication connector, and an identity chain; Send a data access request to the basic connector of the target data space through the basic connector of the data space to be accessed, so as to generate a reception signal through the basic connector of the target data space; wherein, the data space to be accessed and the target data space are both on-chain to the identity general chain, and the reception signal includes a credential submission requirement; Submit the verifiable credential to the target data space through the data space to be accessed according to the credential submission requirement; Send the verifiable credential to the cross-chain connector through the target data space, and verify the verifiable credential based on the identity general chain and the identity chain of the data space to be accessed to generate a verification result; If the verification result is passed, the target data space and the data space to be accessed establish a connection relationship.
Citation Information
Cited By
Distributed trusted data space construction method and system based on block chain
CN120850266A
Hyperlink cross-domain trusted data space implementation method, electronic equipment and storage medium
CN120915579A
Digital medical record management method and system
CN121145241A