An identity authentication system, method, device, medium and equipment

By using public key encryption and private key decryption between the client and the server, combined with the blockchain network's legality judgment on user attribute information, the problem of low identity authentication security and reliability when conducting data transactions based on blockchain technology is solved, and higher identity authentication security and reliability are achieved.

CN113850590BActive Publication Date: 2025-05-30AISINO CORPORATION
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010594874.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-28
Publication Date
2025-05-30
Estimated Expiration
2040-06-28

AI Technical Summary

Technical Problem

When conducting data transactions based on blockchain technology, identity authentication is less secure and reliable.

Method used

By using public key encryption and private key decryption between the client and the server, combined with the blockchain network's legality judgment of user attribute information, it is determined whether identity authentication is allowed to be allowed to be used for registered users.

Benefits of technology

Improve the security and reliability of identity authentication and ensure the reliability and security of data transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113850590B_ABST
    Figure CN113850590B_ABST
Patent Text Reader

Abstract

The present invention relates to an identity authentication system, method, device, medium and equipment. According to the solution provided by the embodiments of the present invention, the server can encrypt information using a public key and send it to the client. After the client decrypts it using the private key, it can submit the corresponding information to the server. The server can send the information submitted by the client to the blockchain network, and the blockchain network can determine whether to allow the user's identity authentication based on this information. When the blockchain network determines that the user's identity authentication is allowed, the server can pass the user's identity authentication, so that the user's identity authentication can be combined with the blockchain network, and the security and reliability of the identity authentication can be ensured by encrypting information with the public key and decrypting information with the private key between the client and the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain, and particularly to an identity authentication system, method, device, medium and equipment. Background Art

[0002] Blockchain technology is a new technology that has emerged in recent years. It can establish credit for both trading parties without the participation of a third-party institution, and has characteristics such as decentralization, openness, anonymity, and immutability. Based on the characteristics of blockchain technology, data transactions based on blockchain technology have been widely applied to better ensure data security and the rights and interests of both trading parties.

[0003] In the process of data transactions based on blockchain technology, it is necessary to authenticate the identities of both trading parties respectively to ensure the reliability and security of the transactions. However, the security and reliability of the current identity authentication methods need to be improved. Summary of the Invention

[0004] Embodiments of the present invention provide an identity authentication system, method, device, medium and equipment, which are used to solve the problem that the security and reliability of identity authentication are relatively low when conducting data transactions based on blockchain technology.

[0005] In a first aspect, the present invention provides an identity authentication system. The system includes a client installed in a terminal, a server of the client, and a blockchain network, where:

[0006] The client is configured to receive an identity authentication request and forward it to the server. The identity authentication request carries a user identifier of a user to be registered; receive the encrypted user attribute list to be filled sent by the server, and decrypt the encrypted user attribute list to be filled by using the private key corresponding to the saved user identifier; receive the user attribute information corresponding to the user attribute list to be filled, and send it to the server;

[0007] The server is configured to encrypt the user attribute list to be filled by using the public key corresponding to the generated user identifier according to the received identity authentication request, and send it to the client; send the received user attribute information to the blockchain network; and send an identity authentication success response message to the client when receiving the allow identity authentication passed message sent by the blockchain network;

[0008] The blockchain network is configured to judge the legality of the received user attribute information, and determine whether to allow the identity authentication of the user to be registered according to the judgment result. If it is determined to allow passing, send an allow identity authentication passed message to the server.

[0009] Second aspect, the present invention further provides an identity authentication method, the method comprising:

[0010] Receiving an identity authentication request and forwarding it to a server, the identity authentication request carrying a user identifier of a user to be registered;

[0011] Receiving the encrypted user attribute list to be filled sent by the server, and decrypting the encrypted user attribute list to be filled by using the private key corresponding to the saved user identifier;

[0012] Receiving the user attribute information corresponding to the user attribute list to be filled and sending it to the server;

[0013] Receiving the identity authentication success response message sent by the server.

[0014] Third aspect, the present invention further provides an identity authentication method, the method comprising:

[0015] Receiving an identity authentication request sent by a client, the identity authentication request carrying a user identifier of a user to be registered;

[0016] Encrypting the user attribute list to be filled by using the public key corresponding to the generated user identifier and sending it to the client;

[0017] Sending the user attribute information sent by the client and received to the blockchain network;

[0018] When receiving the message allowing the identity authentication to pass sent by the blockchain network, sending an identity authentication success response message to the client.

[0019] Fourth aspect, the present invention further provides an identity authentication method, the method comprising:

[0020] Receiving user attribute information sent by a server;

[0021] Judging the legality of the received user attribute information, and determining whether to allow the identity authentication of the user to be registered according to the judgment result;

[0022] If it is determined to allow passing, sending a message allowing the identity authentication to pass to the server.

[0023] Fifth aspect, the present invention further provides an identity authentication device, the device comprising:

[0024] A transceiver module, configured to receive an identity authentication request and forward it to a server, where the user identifier of the user to be registered is carried in the identity authentication request; receive the encrypted user attribute list to be filled sent by the server; receive the user attribute information corresponding to the user attribute list to be filled obtained after decryption by the decryption module, and send it to the server; receive the identity authentication success response message sent by the server.

[0025] A decryption module, configured to use the private key corresponding to the user identifier saved to decrypt the encrypted user attribute list to be filled sent by the server received by the transceiver module.

[0026] In a sixth aspect, the present invention further provides an identity authentication device, where the device includes:

[0027] A receiving module, configured to receive an identity authentication request sent by a client, where the user identifier of the user to be registered is carried in the identity authentication request;

[0028] An encryption module, configured to encrypt the user attribute list to be filled using the public key corresponding to the generated user identifier, and send it to the client;

[0029] A sending module, configured to send the user attribute information received from the client to the blockchain network, and when the receiving module receives the message allowing the identity authentication to pass sent by the blockchain network, send an identity authentication success response message to the client.

[0030] In a seventh aspect, the present invention further provides an identity authentication device, where the device includes:

[0031] A receiving module, configured to receive user attribute information sent by a server;

[0032] A verification module, configured to judge the legality of the received user attribute information, and determine whether to allow the identity authentication of the user to be registered according to the judgment result;

[0033] A sending module, configured to send a message allowing the identity authentication to pass to the server if it is determined to allow it.

[0034] In an eighth aspect, the present invention further provides a non-volatile computer storage medium, where the computer storage medium stores an executable program, and the executable program is executed by a processor to implement the method as described above.

[0035] In a ninth aspect, the present invention further provides a blockchain data processing device, including a processor, a communication interface, a memory, and a communication bus, where the processor, the communication interface, and the memory complete communication with each other through the communication bus;

[0036] The memory is used to store computer programs;

[0037] The processor is used to implement the method steps as described above when executing the program stored in the memory.

[0038] According to the solution provided by the embodiment of the present invention, the server can encrypt information using the public key and send it to the client. After the client decrypts it using the private key, the corresponding information can be submitted to the server. The server can send the information submitted by the client to the blockchain network, and the blockchain network can determine whether to allow the user's identity authentication based on this information. When the blockchain network determines that the user's identity authentication is allowed, the server can pass the user's identity authentication, so that the user identity authentication can be combined with the blockchain network, and the public key encryption information and private key decryption information between the client and the server can be used to ensure the security and reliability of the identity authentication.

[0039] Other features and advantages of the present invention will be described in the subsequent description, and part of them will be obvious from the description or learned by implementing the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0041] Figure 1 It is a schematic structural diagram of the identity authentication system provided by the embodiment of the present invention;

[0042] Figure 2 It is a schematic flowchart of the identity authentication method provided by the embodiment of the present invention;

[0043] Figure 3 It is a schematic flowchart of the identity authentication method provided by the embodiment of the present invention;

[0044] Figure 4 It is a schematic flowchart of the identity authentication method provided by the embodiment of the present invention;

[0045] Figure 5 It is a schematic structural diagram of the identity authentication device provided by the embodiment of the present invention;

[0046] Figure 6 It is a schematic structural diagram of the identity authentication device provided by the embodiment of the present invention;

[0047] Figure 7 Schematic structural diagram of the identity authentication device provided by an embodiment of the present invention;

[0048] Figure 8 Schematic structural diagram of the identity authentication device provided by an embodiment of the present invention. Specific embodiments

[0049] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.

[0050] It should be noted that the term "a plurality or several" mentioned in this article refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0051] The terms "first", "second", etc. in the description of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein.

[0052] In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0053] An embodiment of the present invention provides an identity authentication system, and the structure of the system can be as Figure 1 shown, including a client 01 installed in a terminal, a server 02 of the client, and a blockchain network 03, where:

[0054] The client 01 is configured to receive an identity authentication request and forward it to the server, where the identity authentication request carries a user identifier of a user to be registered; receive the encrypted user attribute list to be filled sent by the server, and use the private key corresponding to the saved user identifier to decrypt the encrypted user attribute list to be filled; receive the user attribute information corresponding to the user attribute list to be filled and send it to the server;

[0055] The server 02 is configured to encrypt the to-be-filled user attribute list using the public key corresponding to the generated user identifier according to the received identity authentication request and send it to the client; send the received user attribute information to the blockchain network; and send an identity authentication success response message to the client when receiving the message allowing the identity authentication to pass sent by the blockchain network;

[0056] The blockchain network 03 is configured to judge the legality of the received user attribute information, and determine whether to allow the identity authentication of the to-be-registered user according to the judgment result. If it is determined to allow it to pass, send a message allowing the identity authentication to pass to the server.

[0057] User attributes can be any user characteristics. For example, name, gender, ID card, personal phone number, home address, educational background information, age, motor vehicle driving license, height, skin color, marital status, credit record, administrative penalty information, educational background, game account, Meituan account, Didi account, JD.com account, Taobao account, credit card, and so on.

[0058] Judging the legality of the received user attribute information may include judging whether the user attribute information is correct and whether there are any bad records. When the user attribute information is correct and there are no bad records, the identity authentication of the to-be-registered user may be allowed to pass. Otherwise, the identity authentication of the to-be-registered user may not be allowed to pass.

[0059] Due to the traceability of the blockchain network, it can retain a large amount of data. For example, it can make each step of data collection, transaction, circulation, and computational analysis be retained on the blockchain network. Therefore, judging the legality of user attribute information based on the blockchain network can effectively ensure the accuracy of the judgment. By judging the legality of user attribute information, users who meet the requirements can be screened out, ensuring the reliability of identity authentication.

[0060] In a possible implementation manner, the client 01 is further configured to receive a registration request and forward it to the server before receiving an identity authentication request and forwarding it to the server. The registration request carries the user identifier of the to-be-registered user and the real-name authentication information; the server 02 is further configured to encrypt the real-name authentication information using the public key corresponding to the generated user identifier according to the received registration request and publish it to the blockchain network. Among the real-name authentication information encrypted using the public key, part of the real-name authentication information is visible without decryption; and send a registration success response message to the client when receiving the message allowing the registration notification sent by the blockchain network;

[0061] The blockchain network 03 is further configured to determine corresponding user verification information based on the visible real-name authentication information in the received encrypted real-name authentication information, and determine whether to allow the to-be-registered user to register according to the determined user verification information. If it is determined to allow, a registration permission notification message is sent to the server.

[0062] That is to say, in this embodiment, registration can be performed before identity authentication. The client can submit real-name authentication information to the server, and the server can encrypt the real-name authentication information using the public key and send it to the blockchain network. The blockchain network determines whether to allow the user to register based on the visible information in the encrypted real-name authentication information. The server can pass the user registration when the blockchain network determines that the user registration is allowed.

[0063] Thus, user registration can be combined with the blockchain network, and the information sent by the server to the blockchain can be encrypted using the public key, ensuring the security and reliability of the registration authentication while ensuring the security of user information.

[0064] The client can further perform identity authentication after the user registration is passed to further improve the security and reliability of the identity authentication.

[0065] It should be noted that due to the traceability of the blockchain, the accuracy of the user verification information determined by the blockchain network during user registration verification is ensured, and thus the accuracy of the user registration verification is ensured.

[0066] In addition, it should be noted that if user registration is also performed before identity authentication, the server can generate a public key and a private key corresponding to the user identifier of the to-be-registered user when receiving a registration request and send them to the client. Subsequently, information encryption can be performed based on the generated public key, and the legitimacy verification of the client can be achieved based on the generated public key and private key. Of course, if only identity authentication is performed, the server can generate a public key and a private key corresponding to the user identifier of the to-be-registered user when receiving an identity authentication request and send them to the client.

[0067] In a possible implementation manner, the server 02 is further configured to determine the transaction authority of the to-be-registered user if it receives an identity authentication pass message sent by the blockchain network, and when it determines that the transaction authority of the to-be-registered user meets the set requirements, publish the real-name authentication information of the to-be-registered user to the blockchain network as transaction data.

[0068] That is to say, after the server authenticates the user's identity, it can further determine the user's trading permission. When the user's trading permission meets the trading requirements, the user information is published as trading data to the blockchain network, enabling users whose trading permissions meet the trading requirements to conduct data transactions, thereby further ensuring the security and reliability of data transactions.

[0069] Limiting data transactions to users whose trading permissions meet the set requirements can effectively protect the privacy of the counterparty users in the transaction and prevent illegal users from obtaining the information of the counterparty users in the transaction.

[0070] In addition, through processes such as user registration, user identity authentication, and trading permission setting, user judgment can be better achieved, ensuring the security and reliability of data transactions, enabling strangers to conduct data transactions securely, simplifying the data transaction process, and reducing the risks of data transactions.

[0071] Based on the same inventive concept as the system provided in the previous embodiment, from the client side, the embodiment of the present invention further provides an identity authentication method. The step process of this method can be as Figure 2 shown, including:

[0072] Step 101, receive an identity authentication request and forward it.

[0073] In this step, the client can receive the identity authentication request submitted by the user and forward it to the server. The identity authentication request carries the user identifier of the user to be registered.

[0074] Step 102, decrypt the information.

[0075] In this step, the client can receive the encrypted list of user attributes to be filled sent by the server and decrypt the encrypted list of user attributes to be filled using the private key corresponding to the saved user identifier.

[0076] The private key corresponding to the user identifier saved in the client can be the public key and private key generated by the server for the user identifier of the user to be registered and sent to the client. That is to say, the server's authentication of the client can be achieved by decrypting the public key encrypted information sent by the server using the private key saved by the client.

[0077] Step 103, submit the information.

[0078] In this step, the client can receive the user attribute information corresponding to the list of user attributes to be filled submitted by the user and send it to the server.

[0079] Step 104, receive an identity authentication success response message.

[0080] In this step, the client can receive the identity authentication success response message sent by the server to implement user identity authentication.

[0081] Furthermore, before step 101, the following steps may also be included:

[0082] Step 201: Receive the registration request and forward it.

[0083] In this step, the client can receive the registration request submitted by the user and forward it to the server. The registration request carries the user identifier of the user to be registered and the real-name authentication information.

[0084] Step 202: Receive the registration success response message.

[0085] In this step, the client can receive the registration success response message sent by the server to complete user registration.

[0086] Based on the same inventive concept as the system provided in the previous embodiment, from the server side, the embodiment of the present invention further provides an identity authentication method. The step flow of this method can be as Figure 3 shown, including:

[0087] Step 301: Receive the identity authentication request.

[0088] In this step, the server can receive the identity authentication request sent by the client. The identity authentication request carries the user identifier of the user to be registered.

[0089] Step 302: Send the encrypted information.

[0090] In this step, the server can use the public key corresponding to the generated user identifier to encrypt the to-be-filled user attribute list and send it to the client.

[0091] Step 303: Send the user attribute information.

[0092] In this step, the server can send the user attribute information sent by the client to the blockchain network.

[0093] Step 304: Send the identity authentication success response message.

[0094] In this step, when the server receives the message allowing the identity authentication to pass sent by the blockchain network, it can send the identity authentication success response message to the client.

[0095] It should be noted that in a possible implementation, when the server receives the message allowing identity authentication to pass sent by the blockchain network, it can determine the transaction permissions of the user to be registered, and when it determines that the transaction permissions of the user to be registered meet the set requirements, it can publish the real-name authentication information of the user to be registered to the blockchain network as transaction data, so that users whose transaction permissions meet the requirements can conduct data transactions.

[0096] Further, before step 301, the following steps may also be included:

[0097] Step 401: Receive a registration request.

[0098] In this step, the server can receive the registration request sent by the client, and the user identification and real-name authentication information of the user to be registered are carried in the registration request.

[0099] Step 402: Send encrypted real-name authentication information.

[0100] In this step, the server can use the public key corresponding to the generated user identification to encrypt the real-name authentication information and then publish it to the blockchain network. Among the real-name authentication information encrypted with the public key, some real-name authentication information is visible without decryption.

[0101] In a possible implementation, when the server receives the registration request sent by the client, it can generate the public key and private key corresponding to the user identification of the user to be registered and send them to the client for subsequent legal verification of the client based on the generated public key and private key.

[0102] In addition, in this step, the server can encrypt the real-name authentication information sent to the blockchain network based on the generated public key, ensuring the security of the user's real-name authentication information while implementing user registration and authentication using the blockchain network.

[0103] Step 403: Send a registration success response message.

[0104] In this step, when the server receives the registration permission notification message sent by the blockchain network, it can send a registration success response message to the client.

[0105] Based on the same inventive concept as the system provided in the previous embodiment, from the perspective of the blockchain network side, the embodiment of the present invention further provides an identity authentication method, and the step flow of this method can be as Figure 4 shown, including:

[0106] Step 501: Receive user attribute information.

[0107] In this step, the blockchain network can receive the user attribute information sent by the server.

[0108] Step 502: Perform a legality check.

[0109] In this step, the blockchain network can determine the legality of the received user attribute information and, based on the judgment result, decide whether to allow the identity authentication of the user to be registered.

[0110] Determining the legality of the received user attribute information may include checking whether the user attribute information is correct and whether there are any negative records. When the user attribute information is correct and there are no negative records, the identity authentication of the user to be registered can be allowed; otherwise, it cannot be allowed.

[0111] Step 503: Send a message allowing the identity authentication to pass.

[0112] In this step, when the blockchain network determines that it is allowed, it can send a message allowing the identity authentication to pass to the server.

[0113] Furthermore, before step 501, the following steps are also included:

[0114] Step 601: Receive real-name authentication information.

[0115] In this step, the blockchain network can receive the encrypted real-name authentication information sent by the server.

[0116] Step 602: Perform a legality check.

[0117] In this step, the blockchain network can determine the corresponding user verification information based on the visible real-name authentication information in the received encrypted real-name authentication information, and based on the determined user verification information, decide whether to allow the user to be registered to register.

[0118] In this step, the blockchain network can collect data based on the visible real-name authentication information in the received encrypted real-name authentication information to obtain the corresponding user verification information, and based on the determined user verification information, decide whether to allow the user to be registered to register.

[0119] It should be noted that the traceability of the blockchain enables every step record of data collection, transaction, circulation, and computational analysis to be stored on the blockchain, ensuring the integrity and accuracy of the data collection in the blockchain network, and thus ensuring the accuracy of the user registration verification in the blockchain network.

[0120] Step 603: Send a registration approval notice message.

[0121] In this step, when the blockchain network determines that it is allowed, it can send a registration approval notice message to the server.

[0122] Corresponding to the various methods provided above, the following devices are respectively provided.

[0123] An embodiment of the present invention provides an identity authentication device, which can be integrated into a client. The structure of the device can be as Figure 5 shown, including a transceiver module 11 and a decryption module 12:

[0124] The transceiver module 11 is configured to receive an identity authentication request and forward it to the server. The identity authentication request carries the user identifier of the user to be registered; receive the encrypted user attribute list to be filled sent by the server; receive the user attribute information corresponding to the user attribute list to be filled obtained after decryption by the decryption module, and send it to the server; receive the identity authentication success response message sent by the server;

[0125] The decryption module 12 is configured to use the private key corresponding to the saved user identifier to decrypt the encrypted user attribute list to be filled sent by the server received by the transceiver module.

[0126] In a possible implementation, the transceiver module 11 is further configured to receive a registration request and forward it to the server. The registration request carries the user identifier of the user to be registered and the real-name authentication information; and receive the registration success response message sent by the server.

[0127] An embodiment of the present invention provides an identity authentication device, which can be integrated into a server. The structure of the device can be as Figure 6 shown, including a receiving module 21, an encryption module 22 and a sending module 23:

[0128] The receiving module 21 is configured to receive an identity authentication request sent by the client. The identity authentication request carries the user identifier of the user to be registered;

[0129] The encryption module 22 is configured to encrypt the user attribute list to be filled using the public key corresponding to the generated user identifier and send it to the client;

[0130] The sending module 23 is configured to send the user attribute information sent by the client received to the blockchain network, and when the receiving module receives the message allowing the identity authentication to pass sent by the blockchain network, send an identity authentication success response message to the client.

[0131] In a possible implementation, the receiving module 21 is further configured to receive a registration request sent by the client. The registration request carries the user identifier of the user to be registered and the real-name authentication information;

[0132] The encryption module 22 is further configured to use the public key corresponding to the generated user identifier to encrypt the real-name authentication information and then publish it to the blockchain network. Among them, in the real-name authentication information encrypted with the public key, part of the real-name authentication information is visible without decryption;

[0133] The sending module 23 is further configured to send a registration success response message to the client when the receiving module receives the permission registration notification message sent by the blockchain network.

[0134] In a possible implementation manner, the sending module 23 is further configured to, if the receiving module receives the permission identity authentication passed message sent by the blockchain network, determine the transaction permission of the user to be registered, and when it is determined that the transaction permission of the user to be registered meets the set requirements, publish the real-name authentication information of the user to be registered to the blockchain network as transaction data.

[0135] An embodiment of the present invention provides an identity authentication device, which can be integrated in a blockchain network, and the structure of the device can be as Figure 7 shown, including a receiving module 31, a verification module 32 and a sending module 33:

[0136] The receiving module 31 is configured to receive user attribute information sent by a server;

[0137] The verification module 32 is configured to judge the legality of the received user attribute information, and determine whether to allow the identity authentication of the user to be registered according to the judgment result;

[0138] The sending module 33 is configured to send a permission identity authentication passed message to the server if it is determined to be allowed.

[0139] In a possible implementation manner, the receiving module 31 is further configured to receive the encrypted real-name authentication information sent by the server;

[0140] The verification module 32 is further configured to determine the corresponding user verification information according to the visible real-name authentication information in the received encrypted real-name authentication information, and determine whether to allow the user to be registered according to the determined user verification information;

[0141] The sending module 33 is further configured to send a permission registration notification message to the server if it is determined to be allowed.

[0142] The functions of the functional units of each device provided in the above embodiments of the present invention can be realized by the steps of the corresponding methods above. Therefore, the specific working processes and beneficial effects of each unit in each device provided in the embodiments of the present invention will not be repeated here.

[0143] Based on the same inventive concept, the embodiments of the present invention provide the following devices and media.

[0144] The embodiments of the present invention provide an identity authentication device, and the structure of the device may be as Figure 8 shown, including a processor 41, a communication interface 42, a memory 43, and a communication bus 44. Among them, the processor 41, the communication interface 42, and the memory 43 complete mutual communication through the communication bus 44;

[0145] The memory 43 is used to store computer programs;

[0146] When the processor 41 is used to execute the program stored on the memory, it implements the steps described in the above method embodiments of the present invention.

[0147] Optionally, the processor 41 may specifically include a central processing unit (CPU), an application specific integrated circuit (ASIC, Application Specific Integrated Circuit), and may be one or more integrated circuits for controlling program execution, may be a hardware circuit developed using a field programmable gate array (FPGA, Field Programmable Gate Array), or may be a baseband processor.

[0148] Optionally, the processor 41 may include at least one processing core.

[0149] Optionally, the memory 43 may include a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), and a disk memory. The memory 43 is used to store data required for at least one processor 41 to run. The number of memories 43 may be one or more.

[0150] The embodiments of the present invention also provide a non-volatile computer storage medium. The computer storage medium stores an executable program, and when the executable program is executed by a processor, it implements the methods provided in the above method embodiments of the present invention.

[0151] In a specific implementation process, the computer storage medium may include: a universal serial bus flash drive (USB, Universal Serial Bus Flash Drive), a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc, etc., various storage media that can store program codes.

[0152] In the embodiments of the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical or other form.

[0153] In the embodiments of the present invention, each functional unit can be integrated in a processing unit, or each unit can also be an independent physical module.

[0154] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solutions of the embodiments of the present invention can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device, such as a personal computer, a server, or a network device, etc., or a processor to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as Universal Serial Bus Flash Drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disc.

[0155] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0156] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0157] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0158] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0159] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0160] Obviously, those skilled in the art can make various changes and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. An identity authentication system, characterized in that, the system includes a client installed in a terminal, a server of the client, and a blockchain network, wherein: the client is configured to receive a registration request and forward it to the server, the registration request carrying the user identification of the user to be registered and real-name authentication information; receive the registration success response message sent by the server; receive an identity authentication request and forward it to the server, the identity authentication request carrying the user identification of the user to be registered; receive the encrypted user attribute list to be filled sent by the server, and use the private key corresponding to the saved user identification to decrypt the encrypted user attribute list to be filled; receive the user attribute information corresponding to the user attribute list to be filled and send it to the server; the server is configured to receive the registration request sent by the client, encrypt the real-name authentication information using the public key corresponding to the generated user identification, and publish it to the blockchain network, wherein, among the real-name authentication information encrypted using the public key, part of the real-name authentication information is visible without decryption; when receiving the allow registration notification message sent by the blockchain network, send a registration success response message to the client; according to the received identity authentication request, encrypt the user attribute list to be filled using the public key corresponding to the generated user identification and send it to the client; send the received user attribute information to the blockchain network; and when receiving the allow identity authentication passed message sent by the blockchain network, send an identity authentication success response message to the client; the blockchain network is configured to receive the encrypted real-name authentication information sent by the server; determine the corresponding user verification information according to the visible real-name authentication information in the received encrypted real-name authentication information, and determine whether to allow the user to be registered according to the determined user verification information; if it is determined to allow, send an allow registration notification message to the server; judge the legality of the received user attribute information, and determine whether to allow the identity authentication of the user to be registered according to the judgment result, if it is determined to allow to pass, send an allow identity authentication passed message to the server.

2. The system according to claim 1, characterized in that, before the client is further configured to receive an identity authentication request and forward it to the server, it receives a registration request and forwards it to the server, the registration request carrying the user identification of the user to be registered and real-name authentication information; the server is further configured to, according to the received registration request, encrypt the real-name authentication information using the public key corresponding to the generated user identification, and publish it to the blockchain network, wherein, among the real-name authentication information encrypted using the public key, part of the real-name authentication information is visible without decryption; and when receiving the allow registration notification message sent by the blockchain network, send a registration success response message to the client; The blockchain network is further configured to determine corresponding user verification information based on the visible real-name authentication information in the received encrypted real-name authentication information, and determine whether to allow the to-be-registered user to register according to the determined user verification information. If it is determined to allow, a registration permission notification message is sent to the server.

3. The system according to claim 2, wherein, the server is further configured to determine the transaction authority of the to-be-registered user if it receives the permission identity authentication passed message sent by the blockchain network, and when it is determined that the transaction authority of the to-be-registered user meets the set requirements, publish the real-name authentication information of the to-be-registered user to the blockchain network as transaction data.

4. An identity authentication method, wherein, the method includes: Receiving a registration request and forwarding it to the server, where the registration request carries the user identifier and real-name authentication information of the to-be-registered user; Receiving the registration success response message sent by the server; Receiving an identity authentication request and forwarding it to the server, where the identity authentication request carries the user identifier of the to-be-registered user; Receiving the encrypted to-be-filled user attribute list sent by the server, and decrypting the encrypted to-be-filled user attribute list using the private key corresponding to the saved user identifier; Receiving the user attribute information corresponding to the to-be-filled user attribute list and sending it to the server; Receiving the identity authentication success response message sent by the server.

5. An identity authentication method, wherein, the method includes: Receiving a registration request sent by the client; Encrypting the real-name authentication information using the public key corresponding to the generated user identifier and publishing it to the blockchain network. Among the real-name authentication information encrypted using the public key, part of the real-name authentication information is visible without decryption; When receiving the registration permission notification message sent by the blockchain network, sending a registration success response message to the client; Receiving the identity authentication request sent by the client, where the identity authentication request carries the user identifier of the to-be-registered user; Encrypting the to-be-filled user attribute list using the public key corresponding to the generated user identifier and sending it to the client; Sending the user attribute information sent by the client received to the blockchain network; When receiving the permission identity authentication passed message sent by the blockchain network, sending an identity authentication success response message to the client.

6. An identity authentication method, wherein, the method includes: Receiving the encrypted real-name authentication information sent by the server; Determining corresponding user verification information based on the visible real-name authentication information in the received encrypted real-name authentication information, and determining whether to allow the to-be-registered user to register according to the determined user verification information; If it is determined to allow, sending a registration permission notification message to the server; Receiving the user attribute information sent by the server; Judging the legality of the received user attribute information, and determining whether to allow the identity authentication of the to-be-registered user to pass according to the judgment result; If it is determined to allow to pass, sending a permission identity authentication passed message to the server.

7. An identity authentication device, characterized in that, the device includes: a transceiver module, configured to receive a registration request and forward it to a server, where the registration request carries a user identifier of a user to be registered and real-name authentication information; receive a registration success response message sent by the server; the transceiver module is further configured to receive an identity authentication request and forward it to the server, where the identity authentication request carries the user identifier of the user to be registered; receive an encrypted user attribute list to be filled sent by the server; a decryption module, configured to decrypt the encrypted user attribute list to be filled sent by the server received by the transceiver module by using the private key corresponding to the saved user identifier; the transceiver module is further configured to receive user attribute information corresponding to the user attribute list to be filled obtained after decryption by the decryption module and send it to the server; receive an identity authentication success response message sent by the server.

8. An identity authentication device, characterized in that, the device includes: a receiving module, configured to receive a registration request sent by a client; an encryption module, configured to encrypt real-name authentication information by using a public key corresponding to a generated user identifier and publish it to a blockchain network, where, among the real-name authentication information encrypted by the public key, part of the real-name authentication information is visible without decryption; a sending module, configured to send a registration success response message to the client when receiving an allow registration notification message sent by the blockchain network; the receiving module is further configured to receive an identity authentication request sent by the client, where the identity authentication request carries the user identifier of the user to be registered; the encryption module is further configured to encrypt a user attribute list to be filled by using the public key corresponding to the generated user identifier and send it to the client; the sending module is further configured to send the user attribute information sent by the client received to the blockchain network, and send an identity authentication success response message to the client when the receiving module receives an allow identity authentication passed message sent by the blockchain network.

9. An identity authentication device, characterized in that, the device includes: a receiving module, configured to receive encrypted real-name authentication information sent by a server; a verification module, configured to determine corresponding user verification information according to the visible real-name authentication information in the received encrypted real-name authentication information, and determine whether to allow the user to be registered according to the determined user verification information; a sending module, configured to send an allow registration notification message to the server if it is determined to allow; the receiving module is further configured to receive user attribute information sent by the server; the verification module is further configured to judge the legality of the received user attribute information, and determine whether to allow the identity authentication of the user to be registered according to the judgment result; the sending module is further configured to send an allow identity authentication passed message to the server if it is determined to allow passing.

10. A non-volatile computer storage medium, characterized in that, The computer storage medium stores an executable program, and when the executable program is executed by a processor, the method according to any one of claims 4 to 6 is implemented.

11. An identity authentication device, characterized in that the device includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete communication with each other through the communication bus; the memory is used for storing a computer program; when the processor is used to execute the program stored on the memory, the method according to any one of claims 4 to 6 is implemented.

Citation Information

Patent Citations

  • Multi-party trusted identity authentication method and system based on block chain

    CN107196966A

  • Methods and Devices for Registering and Authenticating Miner Identity in a Blockchain Network

    US20220092592A1

  • Method and server for managing identity of user by using blockchain network, and method and terminal for authenticating user by using user identity based on blockchain network

    WO2020141782A1