Identity Authentication System, Method, and Computer Device for Multi-Party Secure Computation

By building an alliance chain between the portal platform, audit node and multiple institutional nodes, storing and managing distributed digital identity information, the problem of the fragmentation of the identity authentication system in the existing technology is solved, and the full process identity authentication and management is realized, which enhances security and flexibility.

CN114238882BActive Publication Date: 2025-05-27SHANGHAI PUDONG DEVELOPMENT BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111319122.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-09
Publication Date
2025-05-27
Estimated Expiration
2041-11-09

AI Technical Summary

Technical Problem

In the prior art, the portal platform is separated from the identity authentication system of multi-party security computing nodes, resulting in incomplete user security vulnerabilities and the overall identity authentication process of data collaborative computing.

Method used

By introducing a alliance chain, the portal platform, audit node and multiple institutional nodes form an alliance chain, storing distributed digital identity information, and implementing node binding application, audit material transmission and identity authentication through secure transmission through declarations through encryption and decryption mechanisms.

Benefits of technology

It realizes full-process identity authentication and management between cross-portal platform and multiple distributed nodes, enhances communication security, reduces the risk of privacy leakage, and supports dynamic addition and cancellation of participating nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238882B_ABST
    Figure CN114238882B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security technology, and discloses an identity authentication system, method, computer device and storage medium for multi-party secure computing, including a portal platform, an audit node and multiple institutional nodes. The distributed digital identity is introduced, and the distributed digital identity information of the portal platform, the audit node and multiple institutional nodes is stored using the consortium blockchain. After an institutional node sends a node binding application to the portal platform, the portal platform will send the audit node information, and instruct the institutional node to send the audit materials to the audit node for qualification review. When the audit materials pass the qualification review, the portal platform binds the distributed digital identity information of the institutional node with the platform user identity of the institutional node to complete the distributed digital identity authentication. The above identity authentication method for multi-party secure computing can optimize aspects such as identity management and authentication processes in the distributed multi-party secure data collaborative computing network, enhance communication security, and reduce the risk of privacy leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an identity authentication system, method, computer device, storage medium and computer program product for multi-party secure computing. Background Art

[0002] Since the portal platform and the multi-party secure computing nodes have different actual functions, different deployment methods, and a physically separated relationship, the existing technical solutions generally separate the portal platform from the identity authentication system of the multi-party secure computing nodes. The management of the institution's identity is performed on the portal platform, including registration and login. The multi-party secure computing nodes deployed in various institutions by default perform computing tasks with the identity of the institution.

[0003] However, the existing technical solutions have loopholes in user security because the identity authentication and permission management system of the institutions participating in the distributed multi-party secure data collaborative computing is only on the portal platform, while there is no identity authentication and permission management system on the multi-party secure computing nodes. In addition, the overall identity authentication process of data collaborative computing is split between the portal platform and the multi-party secure computing nodes. Summary of the invention

[0004] Based on this, it is necessary to provide an identity authentication system, method, computer device, storage medium and computer program product for multi-party secure computing to address the security issues existing in existing technical solutions.

[0005] A multi-party secure computing identity authentication system comprises a portal platform, an audit node and a plurality of institutional nodes, wherein the portal platform, the audit node and the plurality of institutional nodes constitute an alliance chain, wherein the alliance chain stores the first distributed digital identity information of the portal platform, the second distributed digital identity information and the audit node information of the audit node, and the third distributed digital identity information of the institutional node; the institutional node is used to register a platform user identity on the portal platform, and is also used to obtain the first distributed digital identity information from the alliance chain, encrypt a node binding application according to the first distributed digital identity information and send it to the portal platform; the node binding application comprises the platform user identity and the third distributed digital identity information; the portal platform is used to receive the encrypted node binding application, and is also used to decrypt the encrypted node binding application according to the first distributed digital identity information, and is also used to send the audit node information to the institutional node; the institutional node is used to register a platform user identity on the portal platform, and is also used to obtain the first distributed digital identity information from the alliance chain ... used to obtain the first distributed digital identity information from the alliance chain, and is used to obtain the first distributed digital identity information from the alliance chain, and is used to obtain the first distributed digital identity information from the alliance chain, and is used to obtain the first distributed digital identity information from the alliance chain, and is The structure node is also used to receive the audit node information sent by the portal platform, and obtain the second distributed digital identity information from the alliance chain according to the audit node information, and is also used to encrypt the audit materials according to the second distributed digital identity information and send them to the audit node for qualification review; the audit node is used to receive the encrypted audit materials, decrypt the encrypted audit materials according to the second distributed digital identity information, and perform qualification review on the audit materials. When the audit materials pass the qualification review, it is also used to encrypt the identity review statement according to the second distributed digital identity information and store it on the chain; the portal platform is also used to obtain the second distributed digital identity information and the encrypted identity review statement from the alliance chain, decrypt the encrypted identity review statement according to the second distributed digital identity information, and bind the platform user identity with the third distributed digital identity information.

[0006] A method for identity authentication of multi-party secure computing is applied to any institutional node in an alliance chain composed of a portal platform, an audit node and multiple institutional nodes. The method includes storing the first distributed digital identity information of the portal platform and the second distributed digital identity information and audit node information of the audit node on the alliance chain; registering a platform user identity on the portal platform; generating a third distributed digital identity information, and storing the third distributed digital identity information on the chain; obtaining the first distributed digital identity information from the alliance chain; encrypting a node binding application based on the first distributed digital identity information and sending it to the portal platform; the node binding application includes the platform user identity and the third distributed digital identity information; receiving the audit node information sent by the portal platform, and obtaining the second distributed digital identity information from the alliance chain based on the audit node information; encrypting audit materials based on the second distributed digital identity information and sending them to the audit node for qualification review; when the audit materials pass the qualification review, completing the distributed digital identity authentication.

[0007] In one of the embodiments, after completing the distributed digital identity authentication, the method further includes encrypting a node deregistration application based on the first distributed digital identity information and sending it to the portal platform; the node deregistration application includes the platform user identity and the third distributed digital identity information.

[0008] In one of the embodiments, the generating of the third distributed digital identity information includes generating an asymmetric public-private key pair of an institution node through the alliance chain; generating the third distributed digital identity information according to the asymmetric public-private key pair, and the third distributed digital identity information includes an identifier, a uniform resource locator and public key information of the institution node.

[0009] A method for identity authentication of multi-party secure computing is applied to an audit node in an alliance chain composed of a portal platform, an audit node and multiple institutional nodes. The method includes storing the first distributed digital identity information of the portal platform on the alliance chain; generating the second distributed digital identity information, and storing the second distributed digital identity information and the audit node information on the chain; receiving the audit materials encrypted and sent by the institutional node according to the second distributed digital identity information; decrypting the encrypted audit materials according to the second distributed digital identity information; performing a qualification audit on the audit materials of the institutional node; and when the audit materials pass the qualification audit, encrypting the identity audit pass statement according to the second distributed digital identity information and storing it on the chain.

[0010] A method for identity authentication of multi-party secure computing is applied to a portal platform in an alliance chain composed of a portal platform, an audit node and multiple institutional nodes. The method includes storing the second distributed digital identity information and audit node information of the audit node on the alliance chain; generating the first distributed digital identity information, and storing the first distributed digital identity information on the chain; receiving a node binding application encrypted and sent by the institutional node based on the first distributed digital identity information; the node binding application includes the platform user identity and the third distributed digital identity information; decrypting the encrypted node binding application based on the first distributed digital identity information; sending the audit node information to the institutional node; obtaining the second distributed digital identity information and an identity audit pass statement encrypted based on the second distributed digital identity information from the alliance chain; decrypting the encrypted identity audit pass statement based on the second distributed digital identity information; and binding the platform user identity to the third distributed digital identity information.

[0011] In one of the embodiments, after binding the platform user identity with the third distributed digital identity information, the method further includes receiving a node deregistration application sent by the institution node according to the encrypted first distributed digital identity information; the node deregistration application includes the platform user identity and the third distributed digital identity information; determining whether the data collaboration task related to the institution node has ended; when the data collaboration task related to the institution node has ended, updating the status of the institution node to be deregistered.

[0012] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of the identity authentication method of multi-party secure computing described in any one of the above embodiments are implemented.

[0013] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the identity authentication method for multi-party secure computing described in any one of the above embodiments.

[0014] A computer program product includes a computer program, wherein when the computer program is executed by a processor, the steps of the identity authentication method for multi-party secure computing described in any one of the above embodiments are implemented.

[0015] The above-mentioned identity authentication system, method, computer device, storage medium and computer program product for multi-party secure computing introduces distributed digital identity and uses the alliance chain to store the distributed digital identity information of the portal platform, the audit node and multiple institutional nodes. After the institutional node sends a node binding application to the portal platform, the portal platform will send the audit node information, and instruct the institutional node to send the audit materials to the audit node for qualification review. After the audit materials pass the qualification review, the portal platform binds the distributed digital identity information of the institutional node with the platform user identity of the institutional node to complete the distributed digital identity authentication. The above-mentioned identity authentication method for multi-party secure computing can optimize the identity management, authentication process and system of the distributed multi-party secure data collaborative computing network, while maintaining the loose coupling characteristics of the distributed system, realizing the full-process identity authentication and management system across a portal platform and multiple distributed nodes, increasing communication security, reducing the risk of privacy leakage, and realizing flexible and dynamic addition and cancellation of participating nodes. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the implementation methods of this specification or the technical solutions in the prior art, the drawings required for use in the implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some implementation methods recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0017] Figure 1 This is a structural block diagram of an identity authentication system according to one embodiment of the present disclosure;

[0018] Figure 2 A structural block diagram of an identity authentication system according to another embodiment of the present disclosure;

[0019] Figure 3 A schematic diagram of a method flow of an identity authentication method for multi-party secure computing according to one embodiment of the present disclosure;

[0020] Figure 4 A schematic diagram of a method flow for generating third distributed digital identity information according to one embodiment of the present disclosure;

[0021] Figure 5 A schematic diagram of a method flow of an identity authentication method for multi-party secure computing corresponding to an audit node in one of the embodiments of the present disclosure;

[0022] Figure 6 A method flow chart of an identity authentication method for multi-party secure computing corresponding to a portal platform of one of the embodiments of the present disclosure;

[0023] Figure 7This is a flowchart of a method for canceling identity authentication according to one embodiment of the present disclosure;

[0024] Figure 8 A block diagram of an identity authentication device or system according to one embodiment of the present disclosure. DETAILED DESCRIPTION

[0025] In order to facilitate the understanding of the present invention, the present invention will be described more fully below with reference to the relevant drawings. The preferred embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to understand the disclosure of the present invention more thoroughly and comprehensively.

[0026] It should be noted that when an element is referred to as being "fixed to" another element, it may be directly on the other element or there may also be a central element. When an element is considered to be "connected to" another element, it may be directly connected to the other element or there may be a central element at the same time. The terms "vertical", "horizontal", "left", "right", "upper", "lower", "front", "rear", "circumferential" and similar expressions used herein are based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention.

[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more related listed items.

[0028] In a typical distributed multi-party secure data collaborative computing, the portal platform is generally responsible for publishing computable data, initiating computing tasks, scheduling computing processes, and viewing computing status. Each organization deploys its own multi-party secure computing nodes in a distributed manner to perform operations such as plaintext data storage, actual multi-party data collaborative computing, and plaintext data result viewing. However, under such a deployment architecture, there will be problems such as the separation of portal platform user identity and multi-party secure computing node identity authentication.

[0029] Since the portal platform and the multi-party secure computing nodes have different actual functions, different deployment methods, and a physically separated relationship, the existing technical solutions generally separate the portal platform from the identity authentication system of the multi-party secure computing nodes. That is, institutional users register and log in to the portal platform with their user identities, and initiate computing tasks on the portal platform with this identity. The portal platform schedules the distributed multi-party secure data collaborative computing tasks by maintaining the mapping relationship between the institutional identity and the multi-party secure computing node address, so that the result party can obtain the computing results according to the authorized content from its own multi-party secure computing node.

[0030] However, the identity authentication and permission management system of institutions participating in distributed multi-party secure data collaborative computing is only on the portal platform, and there is no identity authentication and permission management system on the multi-party secure computing nodes. Therefore, there are loopholes in the security of user information. At the same time, the overall identity authentication process of data collaborative computing is split between the portal platform and the multi-party secure computing nodes, and it is impossible to cover the security authentication and permission review of the institution's identity in the entire process of data collaborative computing. In order to protect the identity security of multi-party data collaborative computing, institutional users usually need to upload photos of their business licenses when registering their identities on the portal platform, but this information is retained on the platform, which poses a risk of institutional privacy data leakage.

[0031] In addition, existing technical solutions cannot dynamically adjust the composition status of the multi-party data collaborative computing network. Since the current multi-party secure computing nodes do not have an identity system, if a new organization joins, a new multi-party secure computing node needs to be deployed. It is impossible to synchronize the organization's configuration information and authentication relationship on the platform through digital and automated methods, resulting in the problem of user authentication fragmentation and the inability to dynamically maintain the identity of the new organization. In the process of identity authentication between the portal platform and the multi-party secure computing node, the information is transmitted in plain text and the organization's identity authentication process is missing, resulting in security vulnerabilities in the distributed mutual communication link.

[0032] In order to solve the above problems, the present disclosure provides an identity authentication system for multi-party secure computing, which may include a system (including a distributed system), software (application), module, component, server, client, etc. using the method described in the embodiments of this specification and combined with necessary implementation hardware. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0033] Figure 1This is a structural block diagram of an identity authentication system of one embodiment of the present disclosure. In one embodiment, the identity authentication device can be a terminal, a server, or a module, component, device, unit, etc. integrated in the terminal. The identity authentication device can include a portal platform 10, an audit node 20, and multiple institution nodes 30. Among them, the portal platform 10, the audit node 20, and the multiple institution nodes 30 can all be terminals, servers, or modules, components, devices, units, etc. integrated in the terminal.

[0034] The portal platform 10, the audit node 20 and multiple institutional nodes 30 constitute an alliance chain, which stores the first distributed digital identity information of the portal platform 10, the second distributed digital identity information and audit node information of the audit node 20, and the third distributed digital identity information of the institutional node 30. The portal platform 10, the audit node 20 and multiple institutional nodes 30 are all locally deployed with multi-party secure computing nodes. Among them, the multi-party secure computing nodes mainly include distributed digital identity modules.

[0035] The distributed digital identity module can be used to issue distributed digital identities to the portal platform 10, the audit node 20 and the local multi-party secure computing nodes of multiple institution nodes 30. The distributed digital identity module can include a consortium chain node and an identity key module. The identity key module is mainly used to generate and use the public and private key pairs of the institution. The consortium chain node is mainly used to store and call the public keys of each institution on the chain.

[0036] Figure 2 : is a structural block diagram of an identity authentication system according to another embodiment of the present disclosure, in which the multiple institution nodes 30 may further include a multi-party secure computing module and a multi-party secure computing node. The multi-party secure computing module may be used to perform confidential processing on the original data of each institution node, and perform distributed multi-party data collaborative secure computing according to the specific implementation of the multi-party secure computing.

[0037] Multi-party secure computing nodes are distributed and deployed in each institution. Each institutional node participating in data collaborative computing deploys a multi-party secure computing node, and each distributed digital identity corresponds to a multi-party secure computing node. Since the institutional node 30 is a participant in data collaborative computing, a multi-party secure computing module and a multi-party secure computing node are deployed. Audit institutions that do not participate in data collaborative computing do not need to deploy multi-party secure computing modules and multi-party secure computing nodes.

[0038] The portal platform 10 may further include a user management module, which is used to connect the platform user system and the distributed digital identity system in series to manage the binding and cancellation of the platform user identity and the distributed digital identity.

[0039] The portal platform 10 generates the first distributed digital identity information corresponding to the portal platform 10 and stores it on the chain. After deploying the multi-party secure computing node, the audit institution 20 generates the second distributed digital identity information corresponding to the audit institution 20 and stores it on the chain, and synchronizes the audit node information and the second distributed digital identity information with the portal platform 10 and other institution nodes 30 through the alliance chain.

[0040] The organization node 30 registers and logs in as a user on the portal platform 10. The platform user identity registered on the portal platform 10 is a traditional centralized user identity that uses a password to log in. After registering the platform identity, the organization node 30 can browse feasible tasks on the portal platform 10. When the organization node 30 needs to perform data collaborative computing, the portal platform 10 will prompt the organization node 30 to deploy a multi-party secure computing node locally in the organization and bind a distributed digital identity. After the organization node 30 deploys the multi-party secure computing node, it generates the third distributed digital identity information of the organization node and stores it on the chain. After completing the identity authentication, the organization node 30 can initiate a multi-party secure computing task on the portal platform 10.

[0041] In order to ensure the security of the distributed mutual communication link, during the communication process between the portal platform and the multi-party secure computing node of the organization or with the multi-party secure computing node of other organizations, the distributed digital identity of the designated organization is used to encrypt the information and transmit it in the form of ciphertext. The organization node 30 obtains the first distributed digital identity information corresponding to the portal platform 10 from the alliance chain, and encrypts the node binding application according to the first distributed digital identity information, and sends the encrypted node binding application to the portal platform 10. The node binding application may include the platform user identity and the third distributed digital identity information.

[0042] Considering that if the institution node 30 uploads a photo of the company's business license for identity verification when registering its identity on the portal platform 10, the company information of the institution node 30 will be retained on the platform, which will pose a risk of leakage of the institution's privacy data. Therefore, in this embodiment, in order to protect the identity security of multi-party data collaborative computing, a third-party audit agency completes the identity verification of the node 30. After the portal platform 10 receives the encrypted node binding application sent by the institution node 30, it decrypts it according to the first distributed digital identity information, and can obtain the decrypted node binding application. After obtaining the node binding application, the portal platform 10 will reply to the institution node 30 with the audit node information of the audit node 20 to remind the institution node 30 to send the audit materials to the audit node 20 for qualification review.

[0043] The institution node 30 can obtain the second distributed digital identity information from the alliance chain according to the audit node information. The audit materials are encrypted according to the second distributed digital identity information and sent to the audit node 20 for qualification review. When the audit materials pass the qualification review, the distributed digital identity authentication is completed;

[0044] The audit node 20 can be used to receive the audit materials encrypted and sent by the institution node 30 according to the second distributed digital identity information, and decrypt according to the second distributed digital identity information to obtain the audit materials of the institution node 30. The audit node 20 conducts a qualification review on the audit materials of the institution node 30 to determine whether the institution node 30 can join the distributed multi-party secure data collaborative computing network. When the audit materials of the institution node 30 pass the qualification review, the audit node 20 can issue an identity review statement, encrypt the identity review statement according to the second distributed digital identity information, and store it on the chain.

[0045] The portal platform 10 can obtain the second distributed digital identity information of the audit node 20 and the encrypted identity audit statement issued by the audit node 20 from the alliance chain. The portal platform 10 can decrypt according to the second distributed digital identity information to obtain the identity audit statement. After the portal platform 10 determines that the institution node 30 has completed the participating institution's distributed digital identity authentication based on the identity audit statement, the portal platform 10 can bind the platform user identity of the institution node 30 with the third distributed digital identity information of the institution node 30. After the institution node 30 passes the application review and successfully joins the network, it can initiate a distributed data collaborative computing request.

[0046] The above-mentioned multi-party secure computing identity authentication system provides a distributed network multi-party secure computing identity authentication system that is efficient, secure, and privacy-protected throughout the entire process when multiple participating institutions and auditing institutions jointly construct distributed multi-party secure data collaborative computing. All institutions participating in distributed multi-party secure data collaborative computing have a corresponding distributed digital identity, which is used to implement special identity authentication, identity management, security protection, etc., providing an identity security foundation for subsequent distributed multi-party data collaborative actual computing.

[0047] The above-mentioned multi-party secure computing identity authentication system combines the alliance chain and the distributed key system to form a decentralized, self-controlled, and portable digital identity system. Each institution participating in the distributed multi-party secure data collaborative computing has a corresponding unique distributed digital identity, and the distributed digital identities of all users are publicly stored on the alliance chain nodes. Any institution can verify the identity of other institutions through the alliance chain. By utilizing the characteristics of the alliance chain, it can be achieved that no node can modify any distributed digital identity information, and the identity system of the portal platform and the multi-party secure computing nodes can be connected in series while avoiding information aggregation. Through the digital credentials of the distributed digital identity, privacy-protected and minimized application information dissemination and authentication can be carried out to enhance data security.

[0048] At the same time, in the communication process between the portal platform and the multi-party secure computing nodes of the institution or with the multi-party secure computing nodes of other institutions, the public key corresponding to the distributed digital identity of the designated institution is used to encrypt information, and other parties except the designated recipient cannot obtain the plaintext information, thereby improving the communication security of the distributed system. Information interaction in the form of ciphertext can increase communication security while maintaining flexibility. With the loose coupling characteristics of distributed digital identity, the identity authentication of any institution node can be dynamically added or deleted without affecting the normal operation of the original system.

[0049] Based on the description of the embodiment of the identity authentication system for multi-party secure computing described above, the present disclosure also provides an identity authentication method for multi-party secure computing. Based on the same innovative concept, the method in one or more embodiments provided in the embodiments of the present disclosure is as described in the following embodiments. Since the implementation scheme of the method to solve the problem is similar to that of the device, the implementation of the specific method in the embodiments of this specification can refer to the implementation of the aforementioned device, and the repeated parts will not be repeated.

[0050] An identity authentication method for multi-party secure computing is applied to any one of the institutional nodes 30 in the alliance chain composed of a portal platform 10, an audit node 20 and a plurality of institutional nodes 30. The alliance chain stores the first distributed digital identity information of the portal platform 10, the second distributed digital identity information of the audit node 20 and the audit node information. Each institution participating in the distributed multi-party secure data collaborative computing has a distributed digital identity. The distributed digital identity stores the user's public identity on the alliance chain node, and can achieve uniqueness without the need for a central registration agency, and any of the institutions can verify the identity of other institutions.

[0051] Figure 3 The method flow chart of the identity authentication method of multi-party secure computing according to one embodiment of the present disclosure is as follows: The identity authentication method of multi-party secure computing may include the following steps S110 to S170.

[0052] Step S110: registering a platform user identity on the portal platform.

[0053] The organization node 30 registers the platform user identity on the portal platform 10. The platform user identity is a traditional centralized user identity that uses a password to log in. After registering the platform identity, the organization node 30 can browse feasible tasks on the portal platform 10. When the organization node 30 wants to initiate data collaborative computing, the portal platform 10 will prompt the organization node 30 to deploy a multi-party secure computing node locally in the organization. After the organization node 30 binds its platform identity and distributed digital identity, the organization node 30 can perform distributed multi-party secure data collaborative computing with other organizations.

[0054] Step S120: Generate third distributed digital identity information, and store the third distributed digital identity information on the chain.

[0055] After the institution node 30 deploys the multi-party secure computing node locally, it can use the multi-party secure computing node to generate the third distributed digital identity information corresponding to the institution node 30. The alliance chain node in the institution node 30 stores the third distributed digital identity information and synchronizes the consensus between the alliance chain nodes to achieve the third distributed digital identity information on-chain storage. Other institutions can obtain the latest third distributed digital identity information corresponding to the institution node 30 from the local alliance chain node, thereby maintaining the uniqueness of the third distributed digital identity information corresponding to the institution node 30.

[0056] Step S130: Obtain the first distributed digital identity information from the alliance chain.

[0057] The portal platform 10 uses the multi-party secure computing node to generate the first distributed digital identity information corresponding to the portal platform 10 in advance, and stores the first distributed digital identity information on the chain. The institution node 30 can obtain the first distributed digital identity information from the alliance chain through the local alliance chain node.

[0058] Step S140: encrypting a node binding application according to the first distributed digital identity information and sending it to the portal platform, wherein the node binding application includes the platform user identity and the third distributed digital identity information.

[0059] The organization node 30 uses the first distributed digital identity information corresponding to the portal platform 10 obtained in step S130 to encrypt the node binding application, and sends the encrypted node binding application to the portal platform 10. In one embodiment, the first distributed digital identity information may include key information such as the distributed digital identity file record identifier, url (Uniform Resource Locator), and public key of the portal platform 10. The organization node 30 uses the public key of the portal platform 10 to encrypt the node binding application and sends it to the portal platform 10. The node binding application may include the platform user identity corresponding to the organization node 30 and the third distributed digital identity information, etc.

[0060] Step S150: Receive the audit node information sent by the portal platform, and obtain the second distributed digital identity information from the alliance chain according to the audit node information.

[0061] Considering that if an institutional user uploads a photo of the company's business license for identity verification when registering on the portal platform, the company information of the institutional user will be retained on the platform, which will lead to the risk of leakage of the institutional privacy data. Therefore, in this embodiment, in order to protect the identity security of multi-party data collaborative computing, the third-party auditing agency 20 completes the identity verification of the institutional user.

[0062] After the portal platform 10 receives the encrypted node binding application sent by the institution node 30, it uses the private key of the portal platform 10 to decrypt and obtain the decrypted node binding application. After the portal platform 10 obtains the node binding application, it replies to the institution node 30 with the audit node information of the audit node 20. In some embodiments of the present disclosure, the audit node information may be a distributed digital identity identifier corresponding to the audit node 20. After receiving the audit node information, the institution node 30 may obtain the second distributed digital identity information of the audit node 20 from the alliance chain node according to the audit node information.

[0063] Step S160: Encrypt the review materials according to the second distributed digital identity information and send them to the review node for qualification review.

[0064] In order to ensure the security of the distributed mutual communication link, the institution node 30 can encrypt the audit materials using the second distributed digital identity information of the audit node 20 before sending the audit materials to the audit node, and transmit them in ciphertext. In some embodiments of the present disclosure, the second distributed digital identity information may include the public key and URL of the audit node 20. The institution node 30 encrypts the audit materials using the public key of the audit node 20, and sends the encrypted audit materials to the audit node. In some embodiments of the present disclosure, the audit materials of the institution node 30 are mainly key materials such as the business license of the institution node 30.

[0065] Step S170: When the review materials pass the qualification review, the distributed digital identity authentication is completed.

[0066] When the audit materials of the institution node 30 pass the qualification review, the institution node 30 completes the distributed digital identity authentication of the participating institution. The portal platform 10 binds the platform user identity of the institution node 30 with the third distributed digital identity information of the institution node 30. After the institution node 30 passes the application review and successfully joins the network, it can initiate a distributed data collaborative computing request.

[0067] The above-mentioned identity authentication method for multi-party secure computing provides an identity authentication method for distributed network multi-party secure computing that is efficient, secure, and privacy-protected throughout the entire process when multiple participating institutions and auditing institutions jointly construct distributed multi-party secure data collaborative computing. All institutions participating in distributed multi-party secure data collaborative computing have a corresponding distributed digital identity, which is used to implement special identity authentication, identity management, security protection, etc., providing an identity security foundation for subsequent distributed multi-party data collaborative actual computing.

[0068] In one embodiment, after completing the distributed digital identity authentication, the method may further include encrypting a node cancellation application according to the first distributed digital identity information and sending it to the portal platform. The above-mentioned multi-party secure computing identity authentication method can not only bind the identity of the institution node 30, but also cancel the identity of the institution node 30, and flexibly realize the dynamic addition and cancellation of participating nodes without affecting the normal operation of the original system.

[0069] When any institution node 30 in the distributed data collaborative computing network wants to exit the network, the institution node 30 submits a node deregistration application for the institution node 30 from the local multi-party secure computing node. In some embodiments of the present disclosure, the node deregistration application may include the platform user identity and the third distributed digital identity information corresponding to the institution node.

[0070] In order to better illustrate the experimental steps of exiting the distributed data collaborative computing network in this application, institution A is taken as an example for illustration, but this should not be understood as a limitation on the scope of the invention patent. Institution A obtains the first distributed digital identity information corresponding to the portal platform 10 from the alliance chain. The first distributed digital identity information may include the public key and URL of the portal platform 10. Institution A encrypts the node deregistration application with the public key, and sends the encrypted node deregistration application to the portal platform 10. The node deregistration application may include the access URL of the multi-party secure computing node of institution A, the institutional information of institution A, etc. After the portal platform 10 receives the node deregistration application sent by institution A, it decrypts it with the private key of the portal platform 10 to obtain the decrypted node deregistration application, thereby completing the identity deregistration of institution A.

[0071] Figure 4 This is a flowchart of a method for generating third distributed digital identity information according to one embodiment of the present disclosure. In one embodiment, generating the third distributed digital identity information may include the following steps S121 to S123.

[0072] Step S121: Generate an asymmetric public-private key pair for the institution’s node through the alliance chain.

[0073] Step S123: Generate third distributed digital identity information according to the asymmetric public-private key pair, where the third distributed digital identity information includes an identifier of the institution node, a uniform resource locator and public key information.

[0074] The institution node 30 deploys a multi-party secure computing node locally, and generates an asymmetric public-private key pair corresponding to the institution node 30 through the alliance chain node. According to the asymmetric public-private key pair corresponding to the institution node 30, a third distributed digital identity information is generated. In some embodiments of the present disclosure, the third distributed digital identity information may include a unique identifier consisting of a string and a distributed digital identity file. An identifier represents a digital identity. The third distributed digital identity information records key information such as the identifier, URL, public key, etc. corresponding to the institution node 30. The institution node 30 can send the third distributed digital identity information to the alliance chain node. The alliance chain node stores the third distributed digital identity information corresponding to the institution node 30, and synchronizes consensus between the alliance chain nodes. Other institutions can obtain the latest distributed digital identity information corresponding to the institution node 30 from the local alliance chain node.

[0075] The present disclosure also provides another identity authentication method for multi-party secure computing, which is applied to the audit node in the alliance chain composed of a portal platform 10, an audit node 20 and multiple agency nodes 30. Figure 5This is a method flow chart of an identity authentication method for multi-party secure computing corresponding to an audit node of one of the embodiments of the present disclosure. In one of the embodiments, the identity authentication method for multi-party secure computing may include the following steps S210 to S250.

[0076] Step S210: Generate the second distributed digital identity information, and store the second distributed digital identity information and audit node information on the chain.

[0077] After the audit node 20 deploys the multi-party secure computing node locally, it can use the multi-party secure computing node to generate the second distributed digital identity information corresponding to the audit node 20. The alliance chain node in the audit node 20 stores the second distributed digital identity information and synchronizes the consensus between the alliance chain nodes to achieve the storage of the second distributed digital identity information on the chain. Other institutions can obtain the latest second distributed digital identity information corresponding to the audit node from the local alliance chain node, thereby maintaining the uniqueness of the second distributed digital identity information corresponding to the audit node.

[0078] In one of the embodiments, the method for the audit node 20 to generate the second distributed digital identity information is the same as the method for the institution node 30 to generate the third distributed digital identity information. The audit node 20 deploys a multi-party secure computing node locally, and generates an asymmetric public-private key pair corresponding to the audit node through the alliance chain node. According to the asymmetric public-private key pair corresponding to the audit node 20, the second distributed digital identity information is generated. In some embodiments of the present disclosure, the second distributed digital identity information may include a unique identifier composed of a string and a distributed digital identity file. The second distributed digital identity information records key information such as the identifier, url, and public key corresponding to the audit node 20.

[0079] Step S220: The receiving institution node encrypts and sends the audit materials based on the second distributed digital identity information.

[0080] After the institution node 30 receives the audit node information sent by the portal platform 10, it can obtain the second distributed digital identity information of the audit node 20 from the alliance chain node according to the audit node information. In order to ensure the security of the distributed mutual communication link, the institution node 30 can use the second distributed digital identity information of the audit node 20 to encrypt the audit materials before sending them to the audit node, and transmit them in ciphertext. In some embodiments of the present disclosure, the second distributed digital identity information may include the public key and URL of the audit node. The institution node 30 encrypts the audit materials using the public key of the audit node 20, and sends the encrypted audit materials to the audit node 20.

[0081] Step S230: decrypt the encrypted audit material according to the second distributed digital identity information.

[0082] Step S240: Conduct qualification review on the review materials of the institution node.

[0083] Step S250: When the audit materials pass the qualification review, the identity review pass statement is encrypted according to the second distributed digital identity information and stored on the chain.

[0084] After receiving the encrypted audit materials, the audit node 20 can decrypt them with the private key corresponding to the second distributed digital identity information to obtain the audit materials sent by the institution node 30. The audit materials mainly include key materials such as the business license photo of the institution node 30. The audit node 20 can verify the key materials such as the business license photo of the institution node 30 to realize the qualification audit of the institution node 30.

[0085] When the audit materials of the institution node 30 pass the qualification review, the audit node 20 can approve the audit material information and participation qualifications of the institution node 30. The audit node 20 uses its own private key to issue an identity review statement for the institution node 30. The identity review statement is an authentication credential within a distributed digital identity system. In one embodiment, the identity review statement may include authentication information such as the content of the authentication information, the authentication object, the issuance time, the validity period, and the issuing institution's private key for the institution node 30. The audit node 20 can upload the identity review statement for the institution node 30 to the alliance chain node for chain storage, so that other participants in the distributed multi-party secure data collaborative computing network can obtain the statement from the alliance chain.

[0086] In one embodiment, when the audit materials of the institution node 30 do not pass the qualification review, the audit materials of the institution node 30 fail to be authenticated, and the audit node 20 returns the audit materials to the institution node 30, and the application for joining of the institution node 30 fails.

[0087] In the identity verification process of an institution, the above-mentioned multi-party secure computing identity authentication method uses the declaration function of distributed digital identity to view key audit materials, such as key information such as the institution's business license, through the designated auditor, while other relevant parties only need to verify the signature of the auditor to authenticate the authenticity of the declaration, and cannot directly obtain the institution's key information. This can not only realize the verification of the institution's identity, but also reduce the scope of dissemination of the institution's key sensitive data and reduce the risk of privacy leakage.

[0088] The present disclosure also provides another identity authentication method for multi-party secure computing, which is applied to a portal platform in an alliance chain composed of a portal platform 10, an audit node 20 and multiple agency nodes 30. Figure 6This is a method flow chart of an identity authentication method for multi-party secure computing corresponding to a portal platform of one of the embodiments of the present disclosure. In one of the embodiments, the identity authentication method for multi-party secure computing may include the following steps S310 to S370.

[0089] Step S310: Generate the first distributed digital identity information, and store the first distributed digital identity information on the chain.

[0090] After the portal platform 10 deploys the multi-party secure computing node locally, it can use the multi-party secure computing node to generate the first distributed digital identity information corresponding to the portal platform 10. The alliance chain node in the portal platform 10 stores the first distributed digital identity information and synchronizes the consensus between the alliance chain nodes to achieve the first distributed digital identity information on-chain storage. Other institutions can obtain the latest first distributed digital identity information corresponding to the portal platform 10 from the local alliance chain node, thereby maintaining the uniqueness of the first distributed digital identity information corresponding to the portal platform 10.

[0091] In one of the embodiments, similarly, the method by which the portal platform 10 generates the first distributed digital identity information is the same as the method by which the institutional node 30 generates the third distributed digital identity information. The portal platform 10 generates an asymmetric public-private key pair through the alliance chain node, and generates the first distributed digital identity information based on the generated asymmetric public-private key pair. In some embodiments of the present disclosure, the first distributed digital identity information may also include a unique identifier consisting of a string and a distributed digital identity file. The first distributed digital identity information records key information such as the identifier, URL, public key, etc. corresponding to the audit node.

[0092] Step S320: The receiving institution node sends a node binding application encrypted according to the first distributed digital identity information; the node binding application includes the platform user identity and the third distributed digital identity information.

[0093] The organization node 30 uses the first distributed digital identity information corresponding to the portal platform 10 obtained from the alliance chain to encrypt the node binding application, and sends the encrypted node binding application to the portal platform 10. In one embodiment, the first distributed digital identity information may include key information such as the distributed digital identity file record identifier, url (Uniform Resource Locator), and public key of the portal platform 10. The organization node 30 uses the public key of the portal platform 10 to encrypt the node binding application and sends it to the portal platform 10. The node binding application may include the platform user identity corresponding to the organization node 30 and the third distributed digital identity information, etc.

[0094] Step S330: decrypt the encrypted node binding application according to the first distributed digital identity information.

[0095] After the portal platform 10 receives the encrypted node binding application sent by the organization node 30 , it can use the private key of the portal platform 10 to decrypt it to obtain the node binding application initiated by the organization node 30 .

[0096] Step S340: Send the audit node information to the institution node.

[0097] Considering that when an institutional user registers on the portal platform 10, he uploads a photo of his business license for identity verification, the corporate information of the institutional user is retained on the platform, which will lead to the risk of leakage of the institutional privacy data. Therefore, in this embodiment, in order to protect the identity security of multi-party data collaborative computing, a third-party auditing agency completes the identity verification of the institutional user.

[0098] After obtaining the node binding application, the portal platform replies the audit node information of the audit node to the organization node 30. In some embodiments of the present disclosure, the audit node information may be a distributed digital identity identifier corresponding to the organization node 30.

[0099] Step S350: Obtain the second distributed digital identity information and the identity review pass statement encrypted according to the second distributed digital identity information from the alliance chain.

[0100] Step S360: decrypt the encrypted identity verification statement according to the second distributed digital identity information.

[0101] Step S370: Bind the platform user identity with the third distributed digital identity information.

[0102] After the institution node 30 receives the audit node information sent by the portal platform 10, it can obtain the second distributed digital identity information of the audit node 20 from the alliance chain node according to the audit node information. The institution node 30 uses the second distributed digital identity information of the audit node 20 to encrypt the audit materials and transmit them to the audit node 20 in ciphertext. After the audit node 20 receives the encrypted audit materials, the audit node can decrypt them with a private key to obtain the audit materials sent by the institution node 30. The audit materials mainly include key materials such as the business license photo of the institution node 30. The audit node 20 can verify the qualifications of the institution node 30 by verifying key materials such as the business license photo of the institution node 30.

[0103] When the audit materials of the institution node 30 pass the qualification review, the audit node 20 can approve the audit material information and participation qualifications of the institution node 30. The audit node 20 uses its own private key to issue a statement of identity review for the institution node 30. The identity review statement is a kind of authentication certificate in the distributed digital identity system. The audit node 20 can also upload the identity review statement for the institution node 30 to the alliance chain node for chain storage, so that other participants in the distributed multi-party secure data collaborative computing network can obtain the statement from the alliance chain.

[0104] The portal platform 10 can obtain the second distributed digital identity information of the audit node 20, and can also obtain the identity review statement issued by the audit node 20 from the alliance chain node. After the portal platform 10 uses the public key of the audit node to verify that the signature of the issuing agency in the identity review statement is the audit node, it can be determined that the application review result of the audit node 20 for the institution node 30 is a successful application. The portal platform 10 will bind the platform user identity of the institution node 30 with the third distributed digital identity information of the institution node 30 to associate the node information of the institution node 30. At this time, the institution node 30 has successfully joined the network, and the institution node 30 can then initiate a distributed data collaborative computing request.

[0105] The multi-party secure computing identity authentication method provided by the present disclosure provides a multi-party secure computing identity authentication method for distributed data collaborative computing involving multiple institutions with the advantages of loose coupling, strong authentication, privacy protection, trustworthiness, high efficiency, and dynamic adjustment. Each participating institution deploys a multi-party secure computing node, that is, the distributed multi-party secure data collaborative computing network will consist of a portal platform and multiple multi-party secure computing nodes. The distributed digital identity is used to connect the multi-party secure computing nodes within the institution and the institutional identity authentication of the portal platform to ensure the consistency and credibility of the identity. The portal platform adopts the traditional centralized identity mode, while the distributed digital identity technology is used for unified identity authentication between the distributed terminals and the portal platform. Distributed digital identity files and declarations can be used for consistent identity authentication management for communications between distributed terminals and portal platforms, and between distributed terminals and other distributed terminals.

[0106] The identity authentication method for multi-party secure computing provided by the present invention introduces distributed digital identities, and uses distributed digital identities to solve the identity fragmentation problem in the distributed multi-party secure data collaborative computing system; it also optimizes the identity management, authentication process and other processes of the distributed multi-party secure data collaborative computing network, and can achieve a full-process identity authentication management system across a portal platform and multiple distributed nodes while maintaining the loose coupling characteristics of the distributed system.

[0107] In the communication between multi-party secure computing nodes deployed in a distributed manner by the organization, and between nodes and platforms, the public key encryption of the designated recipient is used. In addition to the designated recipient, other parties cannot obtain plain text information, which effectively improves the communication security of the distributed system. The entire process is communicated in ciphertext form, which increases communication security and reduces the risk of privacy leakage. The technical characteristics of distributed digital identity self-control, flexible management, and portability are utilized to increase the flexibility of the distributed multi-party secure data collaborative computing network, and participating nodes can be flexibly and dynamically added and deregistered without affecting the normal operation of the original system.

[0108] Figure 7 This is a flow chart of a method for canceling identity authentication according to one of the embodiments of the present disclosure. In one of the embodiments, after binding the platform user identity with the third distributed digital identity information, the method may further include the following steps S371 to S375.

[0109] Step S371: The receiving institution node encrypts and sends a node deregistration application to the receiving institution node based on the first distributed digital identity information; the node deregistration application includes the platform user identity and the third distributed digital identity information.

[0110] When any institution node 30 in the distributed data collaborative computing network wants to exit the network, the institution node submits a node deregistration application for the third distributed digital identity information corresponding to the institution node 30 from the local multi-party secure computing node. In some embodiments of the present disclosure, the node deregistration application may include the platform user identity corresponding to the institution node 30 and the third distributed digital identity information.

[0111] Step S373: Determine whether the data collaboration task related to the organization node has been completed.

[0112] After receiving the encrypted node deregistration application sent by the organization node 30, the portal platform 10 can use the private key of the portal platform 10 to decrypt it to obtain the decrypted node deregistration application. The portal platform 10 checks the data collaboration tasks related to the organization node 30 to determine whether there are any unfinished data collaboration tasks related to the organization node 30.

[0113] Step S375: When the data collaboration task related to the organization node is completed, the status of the organization node is updated to be cancelled.

[0114] When all data collaboration tasks related to the organization node 30 have ended, it is determined that the organization node 30 meets the deregistration conditions. The portal platform 10 updates the status of the organization node 30 and updates the status of the organization node 30 to deregistered. The platform user identity corresponding to the organization node 30 in the portal platform 10 does not need to be deleted, and the organization node 30 can still view the original task results through the account in the portal platform 10, but the deregistered organization node 30 will not be able to initiate or accept information data collaborative computing task requests.

[0115] In one embodiment, when there is an ongoing data collaboration task related to the organization node 30, or there is an ongoing data collaboration task initiated by the organization node 30, it is determined that the organization node 30 does not meet the deregistration conditions, and the deregistration application fails. The portal platform 10 can return the failure result of the deregistration application to the organization node 30.

[0116] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the indications of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of the steps or stages in other steps.

[0117] It is understandable that the various embodiments of the above methods, devices, etc. in this specification are described in a progressive manner, and the same / similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. For related parts, refer to the description of other method embodiments.

[0118] Figure 8 FIG. 1 is a block diagram of an identity authentication device or system according to one embodiment of the present disclosure. Figure 8 The identity authentication device or system S00 may include a processing component S20, which further includes one or more processors, and a memory resource represented by a memory S22 for storing instructions executable by the processing component S20, such as an application. The application stored in the memory S22 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component S20 is configured to execute instructions to perform the above method.

[0119] The identity authentication device or system S00 may also include: a power supply component S24 configured to perform power management of the identity authentication device or system S00, a wired or wireless network interface S26 configured to connect the identity authentication device or system S00 to a network, and an input / output (I / O) interface S28. The identity authentication device or system S00 may operate based on an operating system stored in the memory S22, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD or the like.

[0120] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory S22 including instructions, and the above instructions can be executed by a processor of the identity authentication device or system S00 to complete the above method. The storage medium can be a computer-readable storage medium, for example, the computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0121] In an exemplary embodiment, a computer program product is further provided. The computer program product includes instructions. The instructions can be executed by a processor of the identity authentication device or system S00 to complete the above method.

[0122] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the hardware + program embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0123] It should be noted that the above-mentioned devices, electronic devices, servers, etc. may also include other implementation methods according to the description of the method embodiments, and the specific implementation methods may refer to the description of the relevant method embodiments. At the same time, the new embodiments composed of the mutual combination of the features between the various methods and device, equipment, and server embodiments still fall within the scope of implementation covered by the present disclosure, and will not be described one by one here.

[0124] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0125] In the description of this specification, the description with reference to the terms "some embodiments", "other embodiments", "ideal embodiments", etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example.

[0126] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0127] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the invention patent. It should be pointed out that for ordinary technicians in this field, several modifications and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be based on the attached claims.

Claims

1. An identity authentication system for multi-party secure computing, It is characterized in that It includes a portal platform, an audit node and multiple institution nodes, wherein the portal platform, the audit node and the multiple institution nodes constitute an alliance chain, and the alliance chain stores the first distributed digital identity information of the portal platform, the second distributed digital identity information and audit node information of the audit node, and the third distributed digital identity information of the institution node; The institution node is used to register the platform user identity on the portal platform, and is also used to obtain the first distributed digital identity information from the alliance chain, encrypt the node binding application according to the first distributed digital identity information and send it to the portal platform; the node binding application includes the platform user identity and the third distributed digital identity information; The portal platform is used to receive the encrypted node binding application, decrypt the encrypted node binding application according to the first distributed digital identity information, and send the audit node information to the institution node; The institution node is also used to receive the audit node information sent by the portal platform, and obtain the second distributed digital identity information from the alliance chain according to the audit node information, and is also used to encrypt the audit materials according to the second distributed digital identity information and send them to the audit node for qualification review; The audit node is used to receive the encrypted audit materials, decrypt the encrypted audit materials according to the second distributed digital identity information, conduct qualification audit on the audit materials, and encrypt the identity audit pass statement according to the second distributed digital identity information and store it on the chain when the audit materials pass the qualification audit; The portal platform is also used to obtain the second distributed digital identity information and the encrypted identity review statement from the alliance chain, decrypt the encrypted identity review statement according to the second distributed digital identity information, and bind the platform user identity with the third distributed digital identity information.

2. An identity authentication method for multi-party secure computing, applied to any institutional node in the alliance chain consisting of a portal platform, an audit node and multiple institutional nodes, It is characterized in that The method comprises: The alliance chain stores the first distributed digital identity information of the portal platform and the second distributed digital identity information and audit node information of the audit node; Registering a platform user identity on the portal platform; Generate third distributed digital identity information, and store the third distributed digital identity information on the chain; Acquire the first distributed digital identity information from the alliance chain; Encrypting a node binding application according to the first distributed digital identity information and sending it to the portal platform; the node binding application includes the platform user identity and the third distributed digital identity information; receiving the audit node information sent by the portal platform, and acquiring the second distributed digital identity information from the alliance chain according to the audit node information; Encrypt the audit materials according to the second distributed digital identity information and send them to the audit node for qualification review; When the review materials pass the qualification review, the distributed digital identity authentication is completed.

3. The identity authentication method for multi-party secure computing according to claim 2, It is characterized in that After completing the distributed digital identity authentication, the method further includes: A node deregistration application is encrypted according to the first distributed digital identity information and sent to the portal platform; the node deregistration application includes the platform user identity and the third distributed digital identity information.

4. The identity authentication method for multi-party secure computing according to claim 2, It is characterized in that Generating the third distributed digital identity information includes: Generate an asymmetric public and private key pair of the institution node through the alliance chain; The third distributed digital identity information is generated according to the asymmetric public-private key pair, and the third distributed digital identity information includes an identifier of an institution node, a uniform resource locator and public key information.

5. An identity authentication method for multi-party secure computing, applied to the audit node in the alliance chain consisting of the portal platform, the audit node and multiple institutional nodes, It is characterized in that The method comprises: The alliance chain stores the first distributed digital identity information of the portal platform; Generate a second distributed digital identity information, and store the second distributed digital identity information and audit node information on the chain; Receiving the audit materials encrypted and sent by the institution node according to the second distributed digital identity information; decrypting the encrypted audit material according to the second distributed digital identity information; Conduct qualification review on the review materials of the said institutional nodes; When the review materials pass the qualification review, the identity review pass statement is encrypted according to the second distributed digital identity information and stored on the chain.

6. An identity authentication method for multi-party secure computing, applied to a portal platform in a consortium chain consisting of a portal platform, an audit node, and multiple institutional nodes. It is characterized in that The method comprises: The alliance chain stores the second distributed digital identity information and audit node information of the audit node; Generate first distributed digital identity information, and store the first distributed digital identity information on a chain; Receiving a node binding application encrypted and sent by the institution node according to the first distributed digital identity information; the node binding application includes a platform user identity and a third distributed digital identity information; decrypting the encrypted node binding application according to the first distributed digital identity information; Sending the audit node information to the institution node; Obtaining the second distributed digital identity information and the identity verification statement encrypted according to the second distributed digital identity information from the alliance chain; decrypting the encrypted identity verification pass statement according to the second distributed digital identity information; Bind the platform user identity with the third distributed digital identity information.

7. The identity authentication method for multi-party secure computing according to claim 6, It is characterized in that After binding the platform user identity with the third distributed digital identity information, the method further includes: Receiving a node deregistration application sent by the institution node to the encrypted node according to the first distributed digital identity information; the node deregistration application includes the platform user identity and the third distributed digital identity information; Determining whether the data collaboration task related to the organization node has been completed; When the data collaboration task related to the organization node is completed, the status of the organization node is updated to be deregistered.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program. It is characterized in that When the processor executes the computer program, the steps of the identity authentication method for multi-party secure computing described in any one of claims 2-4 are implemented.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program. It is characterized in that When the processor executes the computer program, the steps of the identity authentication method for multi-party secure computing described in claim 5 are implemented.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program. It is characterized in that When the processor executes the computer program, the steps of the identity authentication method for multi-party secure computing described in any one of claims 6-7 are implemented.

11. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the steps of the identity authentication method for multi-party secure computing described in any one of claims 2 to 4 are implemented.

12. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the steps of the identity authentication method for multi-party secure computing described in claim 5 are implemented.

13. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the steps of the identity authentication method for multi-party secure computing described in any one of claims 6-7 are implemented.

14. A computer program product comprising a computer program, It is characterized in that When the computer program is executed by the processor, the steps of the identity authentication method for multi-party secure computing described in any one of claims 2 to 4 are implemented; Or, implementing the steps of the identity authentication method for multi-party secure computing described in claim 5; Alternatively, implement the steps of the identity authentication method for multi-party secure computing as described in any one of claims 6-7.