Identity authentication method and device in distributed data flow environment, equipment and medium
By verifying the real-name identity information of the access subject and issuing trusted identity credentials at regional functional nodes, the problem of the inability of identity information to be shared under centralized systems is solved, cross-domain identity mutual recognition and hierarchical authorization are realized, and the security and reliability of data circulation are ensured.
Patent Information
- Application Number
- CN202511341450.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-19
- Publication Date
- 2025-12-09
AI Technical Summary
Existing identity authentication mechanisms are mostly based on their own independent centralized systems, lacking unified standards and mutual recognition mechanisms. This results in the inability to share identity information between different regions, industries, and organizations, forming "identity silos," increasing the complexity and cost of data circulation, and bringing security risks.
The system obtains the identity registration request of the access subject through the regional functional node, verifies the real-name identity information, issues a trusted identity certificate, and completes the identity authentication process through the target access connector, thereby building a cross-domain identity mutual recognition and hierarchical authorization mechanism to achieve cross-domain identity mutual recognition and hierarchical authorization.
It has achieved cross-domain identity mutual recognition and hierarchical authorization, providing basic identity protection for the secure, efficient and compliant circulation of data elements, and building a secure and reliable data circulation environment.
Smart Images

Figure CN121098516A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to an identity authentication method, apparatus, device, and medium in a distributed data circulation environment. Background Technology
[0002] Against the backdrop of the rapid development of the digital economy, data has become a core production factor at the national strategic level, and various regions are actively promoting the market-oriented allocation and circulation of data elements. The traditional model, primarily based on centralized data collection and exchange, is no longer sufficient to meet the needs of cross-domain, cross-organizational, and cross-network data circulation. There is an urgent need to build a more flexible, secure, and interoperable distributed data circulation infrastructure. In this system, identity authentication serves as the first security checkpoint for data circulation, and its credibility directly determines the security and reliability of the entire data circulation environment.
[0003] However, existing identity authentication mechanisms are mostly based on independent centralized systems, lacking unified standards and mutual recognition mechanisms. This results in the inability to share identity information between different regions, industries, and organizations, creating "identity silos." This not only increases the complexity and cost of data circulation but also brings security risks such as identity theft and permission confusion, severely restricting the efficient flow and compliant use of data elements.
[0004] As can be seen from the above, how to achieve cross-domain identity mutual recognition and hierarchical authorization to provide basic identity protection for the secure, efficient and compliant circulation of data elements is an urgent problem to be solved. Summary of the Invention
[0005] In view of this, the purpose of this invention is to provide an identity authentication method, apparatus, device, and medium in a distributed data circulation environment, capable of achieving cross-domain identity mutual recognition and hierarchical authorization, providing basic identity protection for the secure, efficient, and compliant circulation of data elements. The specific solution is as follows:
[0006] Firstly, this application provides an identity authentication method in a distributed data circulation environment, including:
[0007] The system obtains the identity registration request of the access subject through the regional functional node, verifies the real-name identity information of the access subject based on the identity registration request, and returns the corresponding identity registration result to the access subject based on the verification result of the real-name identity information, so that the access subject can obtain the target access connector based on the identity registration result.
[0008] The access entity's access connector registration request is obtained through the regional functional node. Based on the access connector registration request, the information of the target access connector is reviewed. Based on the review result of the target access connector's information, a trusted identity certificate is issued to the access entity and the target access connector. The trusted identity certificate includes a digital certificate, account password, and decentralized identification certificate.
[0009] If a login request from the access subject is received through the regional functional node, the access subject is connected to the preset business processing platform through the target access connector based on the trusted identity credentials to complete the identity authentication process.
[0010] Optionally, the identity authentication method in the distributed data circulation environment further includes:
[0011] The real-name identity information and the trusted identity credential are synchronized to the global functional node through the regional functional node, so that the real-name identity information and trusted identity credential of the access subjects in each regional functional node can be managed through the global functional node.
[0012] The global functional nodes manage trusted identity authorities for real-name identity verification and trusted identity credential providers for issuing trusted identity credentials.
[0013] Optionally, the step of obtaining the access subject's identity registration request through the regional functional node and verifying the access subject's real-name identity information based on the identity registration request includes:
[0014] The system obtains the identity registration request of the access subject through the regional functional node, and sends the identity verification materials of the access subject to the trusted identity authority based on the identity registration request, so that the trusted identity authority can verify the real-name identity information of the access subject through the identity verification materials and obtain the verification result of the real-name identity information.
[0015] Optionally, the step of verifying the information of the target access connector based on the access connector registration request, and issuing trusted identity credentials to the access subject and the target access connector according to the verification result of the target access connector information, includes:
[0016] The information of the target access connector is reviewed based on the access connector registration request, and an identity identifier corresponding to the target access connector is generated based on the review result of the target access connector information.
[0017] The identity identifier is sent to the access subject so that the access subject can configure the target access connector based on the identity identifier to generate trusted identity credential request information; the trusted identity credential request information includes the identity identifier, domain name information, and key information;
[0018] The trusted identity credential request information sent by the access subject is obtained and sent to the trusted identity credential provider so that the trusted identity credential provider can issue trusted identity credentials to the access subject and the target access connector based on the trusted identity credential request information.
[0019] Optionally, the step of connecting the access subject to the preset service processing platform through the target access connector based on the trusted identity credential to complete the identity authentication process includes:
[0020] Obtain the login request initiated by the access subject based on the trusted identity credential, and verify the validity of the trusted identity credential based on the login request to obtain the verification result;
[0021] If the verification result indicates that the validity verification is successful, the access subject will be connected to the preset business processing platform through the target access connector to complete the identity authentication process.
[0022] Optionally, obtaining the login request initiated by the access subject based on the trusted identity credential, and verifying the validity of the trusted identity credential based on the login request to obtain a verification result, includes:
[0023] Obtain the login request initiated by the access subject based on the account password, and verify the account password based on the login request to obtain a first verification result;
[0024] Alternatively, obtain the login request initiated by the access subject based on the digital certificate, perform digital signature parsing operation on the digital certificate based on the login request, and verify the parsed digital signature to obtain a second verification result;
[0025] Alternatively, the system may obtain a login request initiated by the access subject based on the decentralized identity credential, and obtain the decentralized identity credential public key corresponding to the decentralized identity credential from the preset decentralized identity credential system based on the login request, and verify the decentralized identity credential public key to obtain a third verification result.
[0026] Optionally, the identity authentication method in the distributed data circulation environment further includes:
[0027] Before obtaining the access subject's identity registration request through the first regional functional node, if the access subject has already completed identity registration at the second regional functional node, then when the first regional functional node obtains the access subject's identity registration request, it obtains the access subject's trusted identity credentials by accessing the second regional functional node in order to respond to the access subject's identity registration request.
[0028] Secondly, this application provides an identity authentication device in a distributed data circulation environment, comprising:
[0029] The identity registration module is used to obtain the identity registration request of the access subject through the regional functional node, verify the real-name identity information of the access subject based on the identity registration request, and return the corresponding identity registration result to the access subject based on the verification result of the real-name identity information, so that the access subject can obtain the target access connector based on the identity registration result.
[0030] The access connector registration module is used to obtain the access connector registration request of the access subject through the regional functional node, review the information of the target access connector based on the access connector registration request, and issue trusted identity credentials to the access subject and the target access connector according to the review result of the information of the target access connector; the trusted identity credentials include digital certificates, account passwords and decentralized identification credentials;
[0031] The identity authentication module is used to connect the access subject to the preset business processing platform through the target access connector based on the trusted identity credentials if a login request from the access subject is received through the regional functional node, so as to complete the identity authentication process.
[0032] Thirdly, this application provides an electronic device, comprising:
[0033] Memory, used to store computer programs;
[0034] A processor is used to execute the computer program to implement the aforementioned authentication method in a distributed data circulation environment.
[0035] Fourthly, this application provides a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned authentication method in a distributed data circulation environment.
[0036] This application provides an identity authentication method in a distributed data circulation environment. The method involves obtaining an access subject's identity registration request through a regional functional node, verifying the access subject's real-name identity information based on the registration request, and returning a corresponding identity registration result to the access subject based on the verification result. This allows the access subject to obtain a target access connector based on the identity registration result. The method also involves obtaining the access subject's access connector registration request through the regional functional node, reviewing the target access connector's information based on the registration request, and issuing trusted identity credentials to the access subject and the target access connector based on the review result. The trusted identity credentials include digital certificates, account passwords, and decentralized identification credentials. If a login request from the access subject is received through the regional functional node, the access subject is connected to a preset business processing platform through the target access connector based on the trusted identity credentials to complete the identity authentication process.
[0037] As can be seen from the above, this application ensures the trustworthiness of users accessing the data circulation system by authenticating and verifying the identities of access subjects and access connectors at regional functional nodes, thus constructing a secure and trustworthy circulation environment. This enables cross-domain identity mutual recognition and hierarchical authorization, providing fundamental identity guarantees for the secure, efficient, and compliant circulation of data elements. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0039] Figure 1 This application discloses a flowchart of an identity authentication method in a distributed data circulation environment.
[0040] Figure 2 This is a schematic diagram of a user identity registration process disclosed in this application;
[0041] Figure 3 This is a schematic diagram of an access connector registration process disclosed in this application;
[0042] Figure 4 This is a schematic diagram of a cross-regional user identity registration process disclosed in this application;
[0043] Figure 5 This is a schematic diagram of a login process based on an account password disclosed in this application;
[0044] Figure 6 This is a schematic diagram of a login process based on a digital certificate disclosed in this application;
[0045] Figure 7 This is a schematic diagram of a login process based on DID authentication disclosed in this application;
[0046] Figure 8 This is a schematic diagram of an identity authentication device in a distributed data circulation environment disclosed in this application;
[0047] Figure 9 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation
[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0049] In the context of the rapid development of the digital economy, data has become a core production factor at the national strategic level, and various regions are actively promoting the market-oriented allocation and circulation of data elements. The traditional model, primarily based on centralized data aggregation and exchange, is no longer sufficient to meet the needs of cross-domain, cross-organizational, and cross-network data circulation. There is an urgent need to build a more flexible, secure, and interoperable distributed data circulation infrastructure. In this system, identity authentication, as the first security gate for data circulation, directly determines the security and reliability of the entire data circulation environment. However, existing identity authentication mechanisms are mostly based on independent centralized systems, lacking unified standards and mutual recognition mechanisms. This results in the inability to exchange identity information between different regions, industries, and organizations, forming "identity silos." This not only increases the complexity and cost of data circulation but also brings security risks such as identity theft and permission confusion, severely restricting the efficient flow and compliant use of data elements. Therefore, this application provides an identity authentication scheme in a distributed data circulation environment that can achieve cross-domain identity mutual recognition and hierarchical authorization, providing basic identity protection for the secure, efficient, and compliant circulation of data elements.
[0050] See Figure 1 As shown in the figure, this application discloses an identity authentication method in a distributed data circulation environment, including:
[0051] Step S11: Obtain the identity registration request of the access subject through the regional functional node, verify the real-name identity information of the access subject based on the identity registration request, and return the corresponding identity registration result to the access subject based on the verification result of the real-name identity information, so that the access subject can obtain the target access connector based on the identity registration result.
[0052] In this embodiment, the access entity obtains its identity through registration at a regional functional node. The regional functional node connects to a trusted identity credential provider to issue identity credentials and verifies the authenticity of the identity through a trusted identity authority. The access connector obtains its identity through user registration at the regional functional node and performs trusted access. The platform needs to register and connect with the regional functional node to obtain a trusted identity. The access entity includes, but is not limited to, individuals, legal persons, and other organizations. Individuals refer to natural persons who participate in data circulation in their personal capacity, while legal persons or other organizations refer to entities with legal subject status participating in data circulation and utilization. The regional functional node is used for the registration and authentication of access entities and access connectors, as well as for connecting with trusted identity credential providers and issuing trusted identity credentials to access entities.
[0053] In this embodiment, see Figure 2 As shown, the access subject's identity registration request is obtained through a regional functional node, and the real-name identity information of the access subject is verified by a trusted identity authority based on the identity registration request. Specifically, obtaining the access subject's identity registration request through a regional functional node and verifying the real-name identity information of the access subject based on the identity registration request may include: obtaining the access subject's identity registration request through a regional functional node, and sending the access subject's identity verification materials to the trusted identity authority based on the identity registration request, so that the trusted identity authority can verify the access subject's real-name identity information using the identity verification materials to obtain the verification result of the real-name identity information.
[0054] It is important to note that the real-name identity information includes basic identity information used to determine user identity and mutual recognition, as well as additional attributes used to identify user identity and supplementary identity information that provides detailed user information. For example, in some specific implementations, personal identity information defines and identifies an individual's set of information, including name, document type, document number, mobile phone number, etc.; legal person or other organization identity information includes the legal person or other organization's name, unified social credit code, legal representative or person in charge, etc.; supplementary information for legal person or other organization identity includes registered address, registration date, industry type, business scope, electronic business license, etc.
[0055] Furthermore, the trusted identity information of each regional functional node is aggregated by connecting the global functional node with the regional functional nodes. Specifically, the identity authentication method in the distributed data circulation environment may also include: synchronizing the real-name identity information and the trusted identity credential to the global functional node through the regional functional nodes, so that the global functional node can manage the real-name identity information and trusted identity credential of the access subjects in each regional functional node; and managing the trusted identity authority for real-name identity verification and the trusted identity credential provider for issuing trusted identity credentials through the global functional node. That is, by providing cross-regional information query services and providing a list of trusted identity credential providers and trusted identity authorities in the data infrastructure system, unified management and cross-domain interoperability of the distributed identity authentication system are achieved.
[0056] Step S12: Obtain the access connector registration request of the access subject through the regional functional node, review the information of the target access connector based on the access connector registration request, and issue a trusted identity certificate to the access subject and the target access connector according to the review result of the information of the target access connector.
[0057] In this embodiment, see Figure 3 As shown, by collecting information on trusted identity credential providers in the region through the regional functional nodes and issuing trusted identity credentials, trusted mutual recognition between access subjects and other data infrastructure is achieved. Trusted identity credentials include, but are not limited to, digital certificates, account passwords, and decentralized identification credentials. Specifically, the step of reviewing the information of the target access connector based on the access connector registration request and issuing trusted identity credentials to the access subject and the target access connector according to the review result can include: reviewing the information of the target access connector based on the access connector registration request and generating an identity identifier corresponding to the target access connector according to the review result; sending the identity identifier to the access subject so that the access subject can configure the target access connector based on the identity identifier to generate trusted identity credential request information; the trusted identity credential request information includes the identity identifier, domain name information, and key information; obtaining the trusted identity credential request information sent by the access subject and sending the trusted identity credential request information to the trusted identity credential provider so that the trusted identity credential provider can issue trusted identity credentials to the access subject and the target access connector based on the trusted identity credential request information.
[0058] Further, see Figure 4As shown, when a registered user logs in at a new regional functional node, a cross-regional identity query is performed through the regional functional node to obtain the trusted identity credentials and real-name identity information of the access subject. Specifically, the identity authentication method in the distributed data circulation environment may further include:
[0059] A registered user requests login from an unregistered regional functional node in region A, simultaneously selecting a regional functional node in region B as the user's identity information authorization node to obtain an authorization token issued by node B. The regional functional node in region A then initiates user identity authentication with the regional functional node in region B using this authorization token. Upon successful authentication, the user obtains an access token issued by the regional functional node in region B to retrieve the current user's identity information. The regional functional node in region A then stores the returned user registration information, completing the identity registration process. In other words, by interacting with different regional nodes, access requests from different regions can be responded to quickly, improving the efficiency of the identity authentication process.
[0060] Step S13: If a login request from the access subject is received through the regional functional node, the access subject is connected to the preset business processing platform through the target access connector based on the trusted identity credential to complete the identity authentication process.
[0061] In this embodiment, the access subject accesses the preset service processing platform through the trusted identity credential to complete trusted access. Specifically, the step of connecting the access subject to the preset service processing platform through the target access connector based on the trusted identity credential to complete the identity authentication process may include: obtaining a login request initiated by the access subject based on the trusted identity credential, and verifying the validity of the trusted identity credential based on the login request to obtain a verification result; if the verification result indicates that the validity verification is successful, then the access subject is connected to the preset service processing platform through the target access connector to complete the identity authentication process. That is, by authenticating and verifying the identity of the access subject and the access connector at the regional functional node, the trustworthiness of users accessing the data circulation system is ensured, a secure and trustworthy circulation environment is constructed, and more efficient data cross-space, cross-domain, and cross-network circulation capabilities are provided.
[0062] Further, see Figure 5As shown, the access subject can reliably access the service platform using an account and password. Specifically, obtaining the login request initiated by the access subject based on the trusted identity credential, and verifying the validity of the trusted identity credential based on the login request to obtain a verification result, may include: obtaining the login request initiated by the access subject based on the account and password, verifying the account and password based on the login request, establishing a login session, and completing the user login.
[0063] Further, see Figure 6 As shown, the access subject can use a digital certificate to reliably access the service platform. Specifically, obtaining the login request initiated by the access subject based on the trusted identity credential, and verifying the validity of the trusted identity credential based on the login request to obtain a verification result, may include: obtaining the login request initiated by the access subject based on the digital certificate, performing a digital signature parsing operation on the digital certificate based on the login request, verifying the parsed digital signature, establishing a login session, and completing the user login.
[0064] Further, see Figure 7 As shown, users can use DID (Decentralized Identifier) authentication to reliably access the service platform. Specifically, obtaining the login request initiated by the user based on the trusted identity credential, and verifying the validity of the trusted identity credential based on the login request to obtain a verification result, may include: obtaining the login request initiated by the user based on the decentralized identifier credential, obtaining the public key of the decentralized identifier credential corresponding to the decentralized identifier credential from a preset decentralized identifier credential system based on the login request, verifying the public key of the decentralized identifier credential, returning the login result, and completing the user login authentication.
[0065] As can be seen from the above, this application embodiment ensures the trustworthiness of users accessing the data circulation system by authenticating and verifying the identities of access subjects and access connectors at regional functional nodes, thus constructing a secure and trustworthy circulation environment. By connecting global functional nodes with regional functional nodes, it aggregates the trusted identity information of each regional functional node, provides cross-regional information query services, and provides a list of trusted identity credential providers and trusted identity authorities for the data infrastructure system, ensuring unified management and cross-domain interoperability of the distributed identity authentication system. This enables cross-domain identity mutual recognition and hierarchical authorization, providing basic identity guarantees for the secure, efficient, and compliant circulation of data elements.
[0066] See Figure 8 As shown in the figure, this application discloses an identity authentication device in a distributed data circulation environment, including:
[0067] The identity registration module 11 is used to obtain the identity registration request of the access subject through the regional functional node, verify the real-name identity information of the access subject based on the identity registration request, and return the corresponding identity registration result to the access subject based on the verification result of the real-name identity information, so that the access subject can obtain the target access connector based on the identity registration result.
[0068] The access connector registration module 12 is used to obtain the access connector registration request of the access subject through the regional functional node, review the information of the target access connector based on the access connector registration request, and issue trusted identity credentials to the access subject and the target access connector according to the review result of the information of the target access connector; the trusted identity credentials include digital certificates, account passwords and decentralized identification credentials;
[0069] The identity authentication module 13 is used to connect the access subject to the preset business processing platform through the target access connector based on the trusted identity credential if a login request of the access subject is received through the regional functional node, so as to complete the identity authentication process.
[0070] In some specific embodiments, the identity registration module 11 may specifically include:
[0071] The identity registration unit is used to obtain the identity registration request of the access subject through the regional functional node, and send the identity verification materials of the access subject to the trusted identity authority based on the identity registration request, so that the trusted identity authority can verify the real-name identity information of the access subject through the identity verification materials and obtain the verification result of the real-name identity information.
[0072] In some specific embodiments, the access connector registration module 12 may specifically include:
[0073] The identity identification unit is used to review the information of the target access connector based on the access connector registration request, and generate an identity identification corresponding to the target access connector based on the review result of the target access connector information.
[0074] A trusted identity credential request information generation unit is used to send the identity identifier to the access subject, so that the access subject can configure the target access connector based on the identity identifier to generate trusted identity credential request information; the trusted identity credential request information includes the identity identifier, domain name information, and key information;
[0075] A trusted identity credential acquisition unit is used to acquire trusted identity credential request information sent by the access subject and send the trusted identity credential request information to the trusted identity credential provider, so that the trusted identity credential provider can issue trusted identity credentials to the access subject and the target access connector based on the trusted identity credential request information.
[0076] In some specific embodiments, the identity authentication module 13 may specifically include:
[0077] The login verification submodule is used to obtain the login request initiated by the access subject based on the trusted identity credential, and to verify the validity of the trusted identity credential based on the login request, so as to obtain the verification result;
[0078] The main access unit is used to connect the access subject to the preset business processing platform through the target access connector if the verification result characterizes the validity verification as passed, so as to complete the identity authentication process.
[0079] Furthermore, the login verification submodule may specifically include:
[0080] The first verification unit is used to obtain the login request initiated by the access subject based on the account password, and to verify the account password based on the login request to obtain a first verification result.
[0081] The second verification unit is used to obtain the login request initiated by the access subject based on the digital certificate, perform digital signature parsing operation on the digital certificate based on the login request, and verify the parsed digital signature to obtain a second verification result.
[0082] The third verification unit is used to obtain the login request initiated by the access subject based on the decentralized identity credential, and obtain the decentralized identity credential public key corresponding to the decentralized identity credential from the preset decentralized identity credential system based on the login request, and verify the decentralized identity credential public key to obtain the third verification result.
[0083] In some specific embodiments, the identity authentication device in the distributed data circulation environment may further include:
[0084] The first management unit is used to synchronize the real-name identity information and the trusted identity credential to the global functional node through the regional functional node, so as to manage the real-name identity information and trusted identity credential of the access subjects in each regional functional node through the global functional node.
[0085] The second management unit is used to manage, through the global functional nodes, trusted identity authorities for real-name identity verification and trusted identity credential providers for issuing trusted identity credentials.
[0086] The cross-domain registration unit is used to, before obtaining the access subject's identity registration request through the first regional functional node, if the access subject has already completed identity registration at the second regional functional node, then when the first regional functional node obtains the access subject's identity registration request, it obtains the access subject's trusted identity credentials by accessing the second regional functional node in order to respond to the access subject's identity registration request.
[0087] Furthermore, embodiments of this application also disclose an electronic device, Figure 9 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the identity authentication method in the distributed data circulation environment disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0088] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0089] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0090] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the authentication method in a distributed data circulation environment executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.
[0091] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned authentication method in a distributed data circulation environment. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.
[0092] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0093] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0094] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0095] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0096] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. An identity authentication method in a distributed data circulation environment, characterized in that, include: The system obtains the identity registration request of the access subject through the regional functional node, verifies the real-name identity information of the access subject based on the identity registration request, and returns the corresponding identity registration result to the access subject based on the verification result of the real-name identity information, so that the access subject can obtain the target access connector based on the identity registration result. The access entity's access connector registration request is obtained through the regional functional node. Based on the access connector registration request, the information of the target access connector is reviewed. Based on the review result of the target access connector's information, a trusted identity certificate is issued to the access entity and the target access connector. Trusted identity credentials include digital certificates, account passwords, and decentralized identity credentials; If a login request from the access subject is received through the regional functional node, the access subject is connected to the preset business processing platform through the target access connector based on the trusted identity credentials to complete the identity authentication process.
2. The identity authentication method in a distributed data circulation environment according to claim 1, characterized in that, Also includes: The real-name identity information and the trusted identity credential are synchronized to the global functional node through the regional functional node, so that the real-name identity information and trusted identity credential of the access subjects in each regional functional node can be managed through the global functional node. The global functional nodes manage trusted identity authorities for real-name identity verification and trusted identity credential providers for issuing trusted identity credentials.
3. The identity authentication method in a distributed data circulation environment according to claim 2, characterized in that, The step of obtaining the access subject's identity registration request through the regional functional node and verifying the access subject's real-name identity information based on the identity registration request includes: The system obtains the identity registration request of the access subject through the regional functional node, and sends the identity verification materials of the access subject to the trusted identity authority based on the identity registration request, so that the trusted identity authority can verify the real-name identity information of the access subject through the identity verification materials and obtain the verification result of the real-name identity information.
4. The identity authentication method in a distributed data circulation environment according to claim 2, characterized in that, The step of verifying the information of the target access connector based on the access connector registration request, and issuing trusted identity credentials to the access subject and the target access connector according to the verification result of the target access connector information, includes: The information of the target access connector is reviewed based on the access connector registration request, and an identity identifier corresponding to the target access connector is generated based on the review result of the target access connector information. The identity identifier is sent to the access subject so that the access subject can configure the target access connector based on the identity identifier to generate trusted identity credential request information; the trusted identity credential request information includes the identity identifier, domain name information, and key information; The trusted identity credential request information sent by the access subject is obtained and sent to the trusted identity credential provider so that the trusted identity credential provider can issue trusted identity credentials to the access subject and the target access connector based on the trusted identity credential request information.
5. The identity authentication method in a distributed data circulation environment according to claim 1, characterized in that, The process of connecting the access subject to the preset service processing platform through the target access connector based on the trusted identity credential to complete the identity authentication process includes: Obtain the login request initiated by the access subject based on the trusted identity credential, and verify the validity of the trusted identity credential based on the login request to obtain the verification result; If the verification result indicates that the validity verification is successful, the access subject will be connected to the preset business processing platform through the target access connector to complete the identity authentication process.
6. The identity authentication method in a distributed data circulation environment according to claim 5, characterized in that, The process of obtaining the login request initiated by the access subject based on the trusted identity credential, and verifying the validity of the trusted identity credential based on the login request to obtain a verification result, includes: Obtain the login request initiated by the access subject based on the account password, and verify the account password based on the login request to obtain a first verification result; Alternatively, obtain the login request initiated by the access subject based on the digital certificate, perform digital signature parsing operation on the digital certificate based on the login request, and verify the parsed digital signature to obtain a second verification result; Alternatively, the system may obtain a login request initiated by the access subject based on the decentralized identity credential, and obtain the decentralized identity credential public key corresponding to the decentralized identity credential from the preset decentralized identity credential system based on the login request, and verify the decentralized identity credential public key to obtain a third verification result.
7. The identity authentication method in a distributed data circulation environment according to any one of claims 1 to 6, characterized in that, Also includes: Before obtaining the access subject's identity registration request through the first regional functional node, if the access subject has already completed identity registration at the second regional functional node, then when the first regional functional node obtains the access subject's identity registration request, it obtains the access subject's trusted identity credentials by accessing the second regional functional node in order to respond to the access subject's identity registration request.
8. An identity authentication device in a distributed data circulation environment, characterized in that, include: The identity registration module is used to obtain the identity registration request of the access subject through the regional functional node, verify the real-name identity information of the access subject based on the identity registration request, and return the corresponding identity registration result to the access subject based on the verification result of the real-name identity information, so that the access subject can obtain the target access connector based on the identity registration result. The access connector registration module is used to obtain the access connector registration request of the access subject through the regional functional node, review the information of the target access connector based on the access connector registration request, and issue a trusted identity certificate to the access subject and the target access connector according to the review result of the information of the target access connector. Trusted identity credentials include digital certificates, account passwords, and decentralized identity credentials; The identity authentication module is used to connect the access subject to the preset business processing platform through the target access connector based on the trusted identity credentials if a login request from the access subject is received through the regional functional node, so as to complete the identity authentication process.
9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the authentication method in a distributed data circulation environment as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Used to store computer programs, wherein the computer programs, when executed by a processor, implement the authentication method in a distributed data circulation environment as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Intelligent household gateway register, remove method and system
CN105357224A
Cross-domain identity authentication method and system based on identity credibility and electronic equipment
CN115883102A
Identity authentication method, secret key storage method and device of Internet of Things equipment
CN118233193A
Block chain-based bidirectional authentication method and device, equipment, medium and product
CN118826997A
Decentralized biometric identity authentication
US20200145219A1