Credential issuance method and credential verification method in blockchain

By obtaining credential application requests and contracts in the blockchain, determining the authentication order of multiple issuers, and performing multiple verifications to generate credentials, the problem of a single authentication credential being difficult to prove multiple attributes is solved, and the standardization and traceability of the credential's multiple attribute proof and generation process are achieved.

CN114418573BActive Publication Date: 2025-09-30NETEASE (HANGZHOU) NETWORK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210056657.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-18
Publication Date
2025-09-30
Estimated Expiration
2042-01-18

AI Technical Summary

Technical Problem

The issuance of existing verifiable credentials is a single authentication method, which results in the user attributes proved by the credentials being relatively single, making it difficult to prove multiple attributes.

Method used

By obtaining the user's credential application request and credential contract in the blockchain, the authentication order of multiple issuers is determined, and the verification information is verified multiple times according to the credential contract, and finally the credential is generated and issued.

Benefits of technology

The credential can prove the multiple attributes of the user, and the credential generation process is standardized and easy to trace.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114418573B_ABST
    Figure CN114418573B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a credential issuance method and a credential verification method in a blockchain; the credential issuance method of the embodiment of the present application obtains a credential application request initiated by a user and a credential contract, the credential application request carries information to be verified, and the credential contract includes the authentication order of the issuers participating in the credential issuance; the current authentication order corresponding to the current issuer is obtained from the credential contract; according to the current authentication order, a target issuer is determined from the credential issuer, the credential issuer is the issuer participating in the credential issuance, and the target issuer includes the issuer whose authentication order is before the current authentication order and the current issuer; according to the target issuer, the information to be verified is verified to obtain a verification result; according to the verification result, a credential corresponding to the credential application request is generated, and the credential is issued to the user. In the embodiment of the present application, multiple issuers can be satisfied to participate in the generation of the credential.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computers, and in particular to a credential issuance method and a credential verification method in a blockchain. Background Art

[0002] Verifiable Credential (VC) provides a specification to describe certain attributes of an entity. Users can use VC to prove to other users (individuals, organizations, specific things, etc.) that certain attributes of their own are credible.

[0003] Currently, the issuance of verifiable credentials is a single authentication method. However, single authentication requires relatively simple verification materials, which results in the user attributes proved by the verifiable credentials also being relatively simple, making it difficult to use verifiable credentials to prove the user's multiple attributes. Summary of the Invention

[0004] The embodiments of the present application provide a credential issuance method and a credential verification method in a blockchain, which can enable a credential to prove multiple attributes of a user.

[0005] The present invention provides a method for issuing a certificate in a blockchain, including:

[0006] Obtain the credential application request initiated by the user and the credential contract. The credential application request carries the information to be verified, and the credential contract includes the authentication order of the issuers participating in the credential issuance.

[0007] Get the current authentication order corresponding to the current issuer from the certificate contract. The current issuer is the issuer corresponding to the receiving certificate application request;

[0008] According to the current authentication order, a target issuer is determined from the credential issuers. The credential issuer is the issuer that participates in the credential issuance. The target issuer includes the issuer whose authentication order is before the current authentication order and the current issuer.

[0009] Verify the information to be verified according to the target issuer and obtain the verification result;

[0010] Based on the verification results, a certificate corresponding to the certificate application request is generated and issued to the user.

[0011] The present application also provides a device for issuing a certificate in a blockchain, including:

[0012] An acquisition unit, configured to acquire a user-initiated credential application request and a credential contract, wherein the credential application request carries information to be verified and the credential contract includes the authentication order of the issuers participating in the credential issuance;

[0013] An order determination unit is used to obtain the current authentication order corresponding to the issuer from the certificate contract, where the current issuer is the issuer corresponding to the received certificate application request;

[0014] An issuer determination unit, configured to determine a target issuer from the credential issuers based on the current authentication order, wherein the credential issuer is an issuer that participates in the credential issuance, and the target issuer includes an issuer whose authentication order precedes the current authentication order and the current issuer;

[0015] An information verification unit is used to verify the information to be verified according to the target issuer and obtain a verification result;

[0016] The generating and issuing unit is used to generate a certificate corresponding to the certificate application request according to the verification result and issue the certificate to the user.

[0017] In some embodiments, the current authentication order is the first authentication order, and determining the target issuer from the credential issuers according to the current authentication order includes:

[0018] According to the first authentication sequence, the target issuer is determined from the credential issuers as the current issuer.

[0019] In some embodiments, the current authentication order is the last authentication order, and determining the target issuer from the credential issuers according to the current authentication order includes:

[0020] According to the last authentication sequence, the target issuers are determined from the credential issuers to be all issuers before the last authentication sequence and the current issuer.

[0021] In some embodiments, the target issuer includes an issuer corresponding to an authentication sequence before the current authentication sequence, the information to be verified includes first information to be verified and second information to be verified, the first information to be verified is a credential issued by the issuer corresponding to the authentication sequence before the current authentication sequence, and the second information to be verified is user information that the current issuer needs to verify, and the information verification unit is used to:

[0022] Verifying the credentials in the first information to be verified to obtain a credential verification result;

[0023] According to the credential verification result, the user information in the second information to be verified is verified to obtain a verification result.

[0024] In some embodiments, the target issuers do not include issuers corresponding to authentication orders prior to the current authentication order, the information to be verified is user information that the current issuer needs to verify, and the information verification unit is configured to:

[0025] Verify the user information in the verification information and obtain the verification result.

[0026] In some embodiments, the issuing unit is generated to:

[0027] According to the verification result, obtain the identity of the current issuer and the current authentication order;

[0028] The identity of the current issuer and the current authentication order are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained.

[0029] In some embodiments, the identity identifier of the current issuer and the current authentication order are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained, including:

[0030] Generate credential creation time and credential expiration time;

[0031] The credential creation time, credential expiration time, identity of the current issuer, and current authentication sequence are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained.

[0032] In some embodiments, the acquisition unit is configured to:

[0033] Obtain the certificate contract from the blockchain. The certificate contract includes the subject of the certificate, the issuers involved in the certificate issuance, and the authentication order corresponding to each issuer.

[0034] In some embodiments, after issuing the credential to the user, the method further includes:

[0035] Re-verify the information to be verified corresponding to the credential and obtain a re-verification result;

[0036] When the re-inspection result does not meet the preset conditions, the certificate contract corresponding to the certificate is revoked and the revocation information is obtained;

[0037] The revocation information is uploaded so that the verifier can determine that the certificate corresponding to the certificate contract is invalid based on the revocation information.

[0038] In some embodiments, revocation authentication is performed on the voucher contract corresponding to the voucher to obtain revocation information, including:

[0039] Get the identity of the current issuer and the contract number of the certificate contract corresponding to the certificate;

[0040] Use the current issuer's identity to revoke the contract number and obtain the revocation information.

[0041] In some embodiments, the revocation information is uploaded, and the device is used to:

[0042] The revocation information is uploaded to the revocation contract in the blockchain, and the revocation contract is associated with the voucher contract.

[0043] The present application also provides a method for verifying a credential in a blockchain, including:

[0044] Obtain a credential sent by a user, such as one of the credential issuance methods in a blockchain provided in the embodiments of the present application, wherein the credential includes authentication information and an authentication order of the issuer;

[0045] Query the certificate contract corresponding to the certificate;

[0046] According to the certificate contract, the authentication information in the certificate and the authentication order of the issuer are verified to obtain the certificate verification result;

[0047] According to the result of the credential verification, the credential is determined to be valid, so that the verification party can approve the user's application request based on the validity of the credential.

[0048] The present application also provides a credential verification device in a blockchain, including:

[0049] A credential acquisition unit, configured to acquire a credential sent by a user, such as a credential issuance method in a blockchain provided in any of the embodiments of the present application, wherein the credential includes authentication information and an authentication order of the issuer;

[0050] Contract query unit, used to query the certificate contract corresponding to the certificate;

[0051] The certificate verification unit is used to verify the authentication information in the certificate and the authentication order of the issuer according to the certificate contract to obtain the certificate verification result;

[0052] The credential determination unit is used to determine whether the credential is valid based on the credential verification result, so that the verification party can approve the user's application request based on the validity of the credential.

[0053] In some embodiments, the credential determination unit is configured to:

[0054] Get revocation information associated with the voucher contract;

[0055] Based on the revocation information and the certificate verification result, it is determined that the certificate corresponding to the certificate contract is valid.

[0056] In some embodiments, the credential further includes the identity identifiers of the user and the issuer, and the credential determination unit is configured to:

[0057] Obtain an identity information cluster, which consists of the user and issuer's identities.

[0058] Verify the identity of the user and the issuer in the credential using the identity information cluster to obtain an identity verification result;

[0059] Based on the identity verification results and the credential verification results, it is determined that the credential is valid.

[0060] An embodiment of the present application also provides a terminal, comprising a memory storing a plurality of instructions; the processor loads instructions from the memory to execute the steps of any one of the methods for issuing certificates in a blockchain provided in the embodiments of the present application and to execute the steps of any one of the methods for verifying certificates in a blockchain provided in the embodiments of the present application.

[0061] An embodiment of the present application also provides a computer-readable storage medium, which stores multiple instructions, and the instructions are suitable for a processor to load to execute the steps of any one of the credential issuance methods in the blockchain provided by the embodiment of the present application and to execute the steps of any one of the credential verification methods in the blockchain provided by the embodiment of the present application.

[0062] The embodiment of the present application can obtain a credential application request initiated by a user and a credential contract, wherein the credential application request carries information to be verified, and the credential contract includes the authentication order of the issuers participating in the credential issuance; obtain the current authentication order corresponding to the current issuer from the credential contract, wherein the current issuer is the issuer corresponding to the received credential application request; determine the target issuer from the credential issuers based on the current authentication order, wherein the credential issuer is the issuer participating in the credential issuance, and the target issuer includes the issuer whose authentication order is before the current authentication order and the current issuer; verify the information to be verified based on the target issuer to obtain a verification result; generate a credential corresponding to the credential application request based on the verification result, and issue the credential to the user.

[0063] In this application, the verification process of multiple issuers when participating in the issuance of a certificate is limited according to the certificate contract. Therefore, in this scheme, the certificate issuance process can be restricted by the certificate contract, making the certificate issuance process more standardized and easy to trace. In addition, the certificate can reflect the participation of multiple issuers, so multiple issuers can participate in the generation of the certificate, so that the certificate can prove the multiple attributes of the user. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0065] Figure 1a It is an interactive diagram of existing credential issuance and credential verification;

[0066] Figure 1bIt is a schematic diagram of the existing credential issuance and credential verification scenarios;

[0067] Figure 1c is an interaction diagram of the certificate issuance method provided in an embodiment of the present application;

[0068] Figure 1d Schematic diagram of the process of issuing a certificate according to an embodiment of the present application;

[0069] Figure 2 Schematic diagram of the process of verifying the credentials provided in the embodiment of the present application;

[0070] Figure 3 is an interaction diagram of a credential issuance and verification system provided by an embodiment of the present application;

[0071] Figure 4 It is a structural diagram of the certificate issuing device provided in an embodiment of the present application;

[0072] Figure 5 It is a structural diagram of a credential verification device provided in an embodiment of the present application;

[0073] Figure 6 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0074] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.

[0075] The embodiments of the present application provide a credential issuance method and a credential verification method in a blockchain.

[0076] The credential issuing device and credential verification device may be integrated into an electronic device, such as a terminal or a server. The terminal may be a mobile phone, tablet computer, smart Bluetooth device, laptop computer, or personal computer (PC); the server may be a single server or a server cluster consisting of multiple servers.

[0077] In some embodiments, the certificate issuing device and the certificate verification device can also be integrated into multiple electronic devices. For example, the certificate issuing device and the certificate verification device can be integrated into multiple servers, and the certificate issuing method and the certificate verification method of this application are implemented by multiple servers.

[0078] In some embodiments, the server may also be implemented in the form of a terminal.

[0079] For example, see Figure 1a Currently, users can only apply for credentials from a single issuer. The issuer verifies the information sent by the user through the blockchain. Once the verification is successful, the issuer generates a credential and sends it to the user. At this point, the user submits a service request to the verifier, who verifies the credential based on the service request. The verifier verifies the identity information of the user and the issuer, as well as the authentication information on the credential, through the blockchain. Once the verification is successful, the issuer provides the user with the service requested.

[0080] For example, reference Figure 1b For example, a user applies for a voucher and uses the voucher to shop on a shopping website:

[0081] 1. Before applying for a credential, the user registers their identity information on the blockchain and obtains the identity information.

[0082] 2. The user will apply for a certificate from the issuer (certificate issuing agency) and send identity information for verification by the certificate issuing agency.

[0083] 3. The credential issuing agency verifies the validity of the user’s identity information.

[0084] 4: After verification, the certificate issuing agency will issue a certificate to the user.

[0085] 5: The certificate issuing agency returns the certificate to the user, who saves it locally and keeps it for himself.

[0086] 6: The user goes to a verification party (shopping website) to shop. Before shopping, the user needs to register and provide the credentials to the shopping website.

[0087] 7: The shopping website verifies the validity of the identity information of the user and the issuing institution on the certificate on the blockchain.

[0088] 8: If the verification in step 7 is successful, the shopping website verifies whether the authentication information of the issuer is present on the voucher.

[0089] 9: Once the credential is verified, the user's validity can be determined and the verifier can provide shopping services to the user.

[0090] Since the above-mentioned method is currently a single authentication method, it is impossible for the certificate to prove the user's multiple attributes. The embodiment of the present application proposes to obtain a certificate application request initiated by the user and a certificate contract. The certificate application request carries information to be verified, and the certificate contract includes the authentication order of the issuers participating in the certificate issuance; the current authentication order corresponding to the current issuer is obtained from the certificate contract, and the current issuer is the issuer corresponding to the received certificate application request; according to the current authentication order, the target issuer is determined from the certificate issuers, and the certificate issuer is the issuer participating in the certificate issuance, and the target issuer includes the issuer with an authentication order before the current authentication order and the current issuer; according to the target issuer, the information to be verified is verified to obtain a verification result; according to the verification result, a certificate corresponding to the certificate application request is generated, and the certificate is issued to the user.

[0091] Then, refer to Figure 1c If the generation of credential b requires the participation of both issuer A and issuer B, the authentication order of issuer A recorded in the credential contract is 1, and the authentication order of issuer B is 2. When the current issuer is issuer B, issuer B determines the current authentication order as 2 according to the credential contract. Based on the current authentication order being 2, issuer B can determine the issuer A corresponding to authentication order 1, which precedes the current authentication order 2. Issuer B verifies the information to be verified, the information of issuer A, and the user information. Based on the verification results, issuer B generates credential b and sends it to the user. In this way, the generation of credential b involves the participation of both issuer A and issuer B. As can be seen from the above, according to the credential contract, the generation of a credential can involve multiple issuers, allowing the credential to prove the user's multiple attributes.

[0092] It should be noted that the serial numbers of the following embodiments are not intended to limit the preferred order of the embodiments.

[0093] In this embodiment, a method for issuing a certificate in a blockchain is provided, such as Figure 1d As shown, the specific process of the certificate issuance method can be as follows:

[0094] 110. Obtain the credential application request initiated by the user and the credential contract. The credential application request carries information to be verified. The credential contract includes the authentication order of the issuers participating in the credential issuance.

[0095] The credential is a text that describes certain attributes of a user. For example, the text can prove to other users that certain attributes of the user are trustworthy. For example, the credential can be an ID card, passport, personal assets, etc.

[0096] The user is the person who applies for the certificate. For example, the user can be an individual, a company leader, an organization leader, etc.

[0097] The credential application request is a request initiated to apply for a credential, for example, an identity card application request, a passport application request, a personal asset authentication request, etc.

[0098] The credential contract is the text that restricts credential generation. For example, the credential contract can restrict the issuers involved in credential generation, the order in which issuers must be authenticated for credential generation, and the content of each issuer's authentication.

[0099] The information to be verified is information waiting to be verified, for example, information related to identity, information related to education, information related to assets, etc.

[0100] The issuer is used to issue a certificate authenticated by the issuer to a certain attribute of the user. For example, the issuer can be a government agency, a certification company, etc.

[0101] The authentication sequence is used to limit the authentication sequence of the issuer.

[0102] The acquisition of the credential application request is to receive the credential application request initiated by the user through the user terminal.

[0103] Among them, the certificate contract can be obtained by the issuer from local, blockchain, server, cloud server, etc.

[0104] In some embodiments, any one of the issuers participating in the issuance of a credential establishes a credential contract.

[0105] 120. Obtain the current authentication order corresponding to the current issuer from the certificate contract. The current issuer is the issuer corresponding to the received certificate application request.

[0106] The current issuer is the sender of the credential application request sent by the user at this time.

[0107] The current authentication order is the order in which the current issuer participates in the issuance of the certificate.

[0108] For example, the generation of this certificate requires the participation of issuer A and issuer B. The certificate b issued by issuer B requires the participation of issuer A. The certificate contract records the authentication order of issuer A and issuer B required when generating certificate b. Among them, the authentication order of issuer A is 1, and the authentication order of issuer B is 2. Issuer B can obtain the current authentication order of 2 from the certificate contract.

[0109] 130. According to the current authentication order, a target issuer is determined from the credential issuers, where the credential issuer is an issuer that participates in the credential issuance. The target issuer includes an issuer whose authentication order is before the current authentication order and the current issuer.

[0110] The target issuer is the issuer required to generate the certificate.

[0111] For example, if the current authentication order is 2, the generation of the certificate requires the participation of issuer A and issuer B, and the target issuers are issuer A and issuer B.

[0112] In some embodiments, in order to achieve the effect of determining the target issuer when the authentication order is ranked first, the current authentication order is the first authentication order, and determining the target issuer from the credential issuers based on the current authentication order includes:

[0113] According to the first authentication sequence, the target issuer is determined from the credential issuers as the current issuer.

[0114] For example, the generation of the certificate requires the participation of issuer A and issuer B. The authentication order of issuer A ranks first, and the authentication order of issuer B ranks second. If the current issuer is issuer A, there is no other issuer before issuer A, so the target issuer is issuer A.

[0115] In some embodiments, in order to achieve the effect of determining the target issuer when the authentication order is ranked last, the current authentication order is the last authentication order, and determining the target issuer from the credential issuers based on the current authentication order includes:

[0116] According to the last authentication sequence, the target issuers are determined from the credential issuers to be all issuers before the last authentication sequence and the current issuer.

[0117] For example, generating the certificate requires the participation of issuer A, issuer B, and issuer C. The authentication order of issuer A ranks first, the authentication order of issuer B ranks second, and the authentication order of issuer C ranks last. If the current issuer is issuer C, then issuer A and issuer B are before issuer C, so the target issuers are issuer A, issuer B, and issuer C.

[0118] 140. Verify the information to be verified according to the target issuer and obtain a verification result.

[0119] The verification result is used to reflect the verified information to be verified. For example, the verification result can be valid or invalid, where valid is used to indicate that the information to be verified has been verified, and invalid is used to indicate that the information to be verified has not been verified.

[0120] In some embodiments, in order to achieve the effect of the issuer verifying the information to be verified, the target issuer includes the issuer corresponding to the authentication order before the current authentication order, the information to be verified includes first information to be verified and second information to be verified, the first information to be verified is the certificate issued by the issuer corresponding to the authentication order before the current authentication order, and the second information to be verified is the user information that the current issuer needs to verify, and the information verification unit is used to:

[0121] Verifying the credentials in the first information to be verified to obtain a credential verification result;

[0122] According to the credential verification result, the user information in the second information to be verified is verified to obtain a verification result.

[0123] The credential verification result is used to reflect the result of the credential verification. For example, the credential verification result can be valid or invalid. A valid credential verification result indicates that the credential has been verified, and an invalid credential verification result indicates that the credential has not been verified.

[0124] The user information is information related to the user. For example, when applying for an ID card, the user information may be a household registration booklet.

[0125] In some embodiments, the issuer's signature in the credential is verified to obtain a credential verification result.

[0126] The issuer signature is used to indicate that the credential has been verified by the corresponding issuer. For example, the issuer signature can be the issuer's official seal, the signature of the issuer's person in charge, etc.

[0127] For example, if there is an issuer among the target issuers whose authentication order is before the current authentication order, then the target issuers include issuer A and issuer B, among which the current issuer is B. Issuer B needs to verify the certificate a issued by issuer A. When the certificate a is verified, the user information is verified to obtain the verification result.

[0128] In some embodiments, in order to achieve the effect of the issuer verifying the information to be verified, the target issuers do not include the issuers corresponding to the authentication order before the current authentication order, the information to be verified is the user information that the current issuer needs to verify, and the information verification unit is used to:

[0129] Verify the user information in the verification information and obtain the verification result.

[0130] For example, if there is no issuer in the target issuer whose authentication order is before the current authentication order, then the target issuer is issuer A, and issuer A only needs to verify the user information submitted by the user to obtain the verification result.

[0131] 150. Based on the verification result, generate a certificate corresponding to the certificate application request and issue the certificate to the user.

[0132] In some embodiments, in order to protect the credentials, generating a credential corresponding to the credential application request and issuing the credential to the user includes:

[0133] Get the encryption key;

[0134] Using the encryption key, encrypt the credential corresponding to the credential application request to obtain an encrypted credential;

[0135] Issue encrypted credentials to users.

[0136] The encryption key is used to encrypt the credential. For example, the encryption key may be a private key, etc.

[0137] The encrypted credential is an encrypted credential, for example, a credential encrypted using a private key.

[0138] For example, if the current issuer is issuer B, issuer B issues credential b to the user.

[0139] In some embodiments, in order to achieve the effect of generating a credential, the generating and issuing unit is configured to:

[0140] According to the verification result, obtain the identity of the current issuer and the current authentication order;

[0141] The identity of the current issuer and the current authentication order are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained.

[0142] The identity identifier of the current issuer is used to represent the identity of the current issuer. For example, the identity identifier of the current issuer can be the name of the issuer, a number representing the identity of the issuer, etc.

[0143] Among them, authentication is used to prove the authenticity of the information to be verified.

[0144] For example, when the verification structure is valid, the current issuer is issuer B. Issuer B obtains its own identity and current authentication sequence 2, and uses issuer B's identity and current authentication sequence 2 to sign and authenticate the verification information. The certificate obtained in this way records issuer B's identity and current authentication sequence 2.

[0145] In some embodiments, in order to achieve the effect of generating a credential, the identity identifier of the current issuer and the current authentication order are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained, including:

[0146] Generate credential creation time and credential expiration time;

[0147] The credential creation time, credential expiration time, identity of the current issuer, and current authentication sequence are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained.

[0148] The credential creation time is the time when the credential is created.

[0149] The certificate expiration time is the expiration time of the certificate.

[0150] For example, when the credential creation time and the credential expiration time are used to authenticate the information to be verified, the obtained credential is time-sensitive.

[0151] In some embodiments, the acquisition unit is configured to:

[0152] Obtain the certificate contract from the blockchain. The certificate contract includes the subject of the certificate, the issuers involved in the certificate issuance, and the authentication order corresponding to each issuer.

[0153] The subject of the credential is used to represent the content of the credential.

[0154] For example, the issuer participating in the certificate issuance can access the blockchain and obtain the certificate contract from the blockchain.

[0155] In some embodiments, in order to enable any issuer to control the validity of the credential, after issuing the credential to the user, the following steps are further included:

[0156] Re-verify the information to be verified corresponding to the credential and obtain a re-verification result;

[0157] When the re-inspection result does not meet the preset conditions, the certificate contract corresponding to the certificate is revoked and the revocation information is obtained;

[0158] The revocation information is uploaded so that the verifier can determine that the certificate corresponding to the certificate contract is invalid based on the revocation information.

[0159] Re-verification refers to verification after the previous verification. For example, the issuer verifies the information to be verified for the first time and then verifies it again for the second time.

[0160] The re-verification result is the corresponding result after the information to be verified is re-verified.

[0161] The preset condition is used to limit the retest result. For example, the preset condition can be that the retest result is unquestionable or that the retest result is questionable.

[0162] Revocation authentication is used to provide credit guarantee for revocation. For example, when the issuer invalidates the certificate contract corresponding to the certificate, the issuer ensures that the certificate is invalid through its own authentication.

[0163] The revocation information is used to indicate the revocation of the certificate.

[0164] Among them, the revocation information can be uploaded on the blockchain, cloud server, server, local, etc.

[0165] For example, after a credential is issued, if the issuer involved in issuing the credential re-verifies the credential and the re-verification result does not meet the preset conditions, the issuer will revoke the authentication of all parties involved in the generation of the credential, thereby invalidating the credential. For example, the issuers of credential b include issuer A and issuer B. The generation of credential b requires credential a issued by issuer A, that is, the credential contract is associated with credential a. Issuer A re-verifies the information to be verified sent by the user. If the re-verification result does not meet the preset conditions, issuer A will revoke the authentication of the credential contract corresponding to credential a, making the credential b associated with the credential contract invalid.

[0166] In some embodiments, the revocation information is uploaded, and the device is further configured to:

[0167] The revocation information is uploaded to the revocation contract in the blockchain, and the revocation contract is associated with the voucher contract.

[0168] Among them, the revocation contract is used to represent the issuer's recognition of the revocation information.

[0169] For example, when there is revocation information in the revocation contract, the certificate contract associated with the revocation contract is invalid. In this way, the certificate associated with the certificate contract is invalid.

[0170] In some embodiments, a revocation contract is created for an issuer that participates in the issuance of a credential.

[0171] In some embodiments, in order to invalidate a credential, the credential contract corresponding to the credential is revoked and authentication is performed to obtain revocation information, including:

[0172] Get the identity of the current issuer and the contract number of the certificate contract corresponding to the certificate;

[0173] Use the current issuer's identity to revoke the contract number and obtain the revocation information.

[0174] The contract number is the identifier of the voucher contract.

[0175] For example, the certificate corresponding to the certificate contract is certificate b, and the certificate contract involves the authentication of issuer A and issuer B when participating in the generation of certificate b. The generation of certificate b requires certificate a issued by issuer A. In this way, certificate a and the certificate contract are associated. After issuer A re-verifies the information to be verified, issuer A revokes the authentication of the contract number of the certificate contract corresponding to certificate a, making the certificate contract corresponding to the contract number invalid, which is conducive to verifying the validity of certificate b based on the revocation information.

[0176] The credential issuance scheme provided by the embodiment of the present application can be applied in various credential generation scenarios. For example, taking the issuance of identity credentials as an example, obtain the credential application request initiated by the user and the credential contract, the credential application request carries information to be verified, and the credential contract includes the authentication order of the issuers participating in the credential issuance; obtain the current authentication order corresponding to the current issuer from the credential contract, the current issuer is the issuer corresponding to the received credential application request; according to the current authentication order, determine the target issuer from the credential issuer, the credential issuer is the issuer participating in the credential issuance, the target issuer includes the issuer whose authentication order is before the current authentication order and the current issuer; according to the target issuer, verify the information to be verified and obtain the verification result; according to the verification result, generate the credential corresponding to the credential application request, and issue the credential to the user. The scheme provided by the embodiment of the present application can meet the needs of multiple issuers participating in the generation of credentials, and at the same time, it can also enable the credential generation process to be traced.

[0177] As can be seen from the above, the embodiment of the present application relies on the certificate contract to limit the authentication order of each issuer in the certificate generation process when generating the certificate, which can meet the needs of multiple issuers to participate in the generation of the certificate, so that the certificate can prove the multiple attributes of the user, and at the same time facilitate the traceability of the certificate based on the certificate contract.

[0178] In this embodiment, a method for verifying a certificate in a blockchain is provided, such as Figure 2 As shown, the specific process of the credential verification method can be as follows:

[0179] 210. Obtain a certificate sent by a user according to any of the certificate issuance methods in the blockchain provided in the embodiments of the present application, where the certificate includes authentication information and an authentication order of the issuer.

[0180] The authentication information is used to indicate that the credential is valid. For example, the authentication information may include the official seal, logo, signature of the person in charge of the issuer, etc.

[0181] 220. Query the voucher contract corresponding to the voucher.

[0182] In some embodiments, to query a voucher contract corresponding to a voucher, the apparatus is configured to:

[0183] Query the voucher contract corresponding to the voucher from the blockchain.

[0184] 230. According to the certificate contract, the authentication information in the certificate and the authentication order of the issuer are verified to obtain the certificate verification result.

[0185] In some embodiments, after the credential is encrypted by the encryption key, the authentication information in the credential and the authentication order of the issuer are verified according to the credential contract to obtain a credential verification result, including:

[0186] Get the decryption key;

[0187] Decrypt the certificate using the decryption key to obtain the decrypted certificate;

[0188] According to the certificate contract, the authentication information in the decrypted certificate and the authentication order of the issuer are verified to obtain the certificate verification result.

[0189] The decryption key is used to decrypt the credential. For example, the decryption key may be a public key, etc.

[0190] 240. Determine that the credential is valid based on the credential verification result, so that the verification party approves the user's application request based on the validity of the credential.

[0191] The verification party is used to verify the credentials. For example, the verification party can be a government, enterprise, institution, etc.

[0192] In some embodiments, in order to achieve the effect of the verification party verifying the credential, the credential determination unit is configured to:

[0193] Get revocation information associated with the voucher contract;

[0194] Based on the revocation information and the certificate verification result, it is determined that the certificate corresponding to the certificate contract is valid.

[0195] For example, after the verifier verifies the certificate, it obtains the revocation information associated with the certificate contract of the certificate. When the revocation information contains the revocation certification of the issuer, it can be determined that the certificate corresponding to the certificate contract is invalid.

[0196] In some embodiments, obtaining revocation information associated with a voucher contract, the apparatus is configured to:

[0197] Determine the revocation contract associated with the voucher contract based on the blockchain;

[0198] Get revocation information from the revocation contract.

[0199] In some embodiments, in order to achieve the effect of the credential being verified by the verifier, the credential also includes the identity identifiers of the user and the issuer, and the credential determination unit is configured to:

[0200] Obtain an identity information cluster, which consists of the user and issuer's identities.

[0201] Verify the identity of the user and the issuer in the credential using the identity information cluster to obtain an identity verification result;

[0202] Based on the identity verification results and the credential verification results, it is determined that the credential is valid.

[0203] The identity information cluster is a cluster composed of identity information.

[0204] Among them, the identity identifier is used to represent identity information.

[0205] For example, the verifier may query the identity information of the user and the issuer in the identity information cluster, thereby enabling the verifier to determine the correctness of the user and the issuer identities in the credential.

[0206] The credential verification scheme provided by the embodiment of the present application can be applied in various credential verification scenarios. For example, taking the verification of a credential on a shopping website, specifically when a user is shopping on a website, the user needs to register a shopping identity on the website. At this time, the user needs to provide a credential to the website, and the website verifies the credential through the blockchain. When the credential verification is valid, the website sends the shopping identity to the user. For example, obtain the credential sent by the user in any of the credential issuance methods in the blockchain provided by the embodiment of the present application, the credential contains authentication information and the authentication order of the issuer; query the credential contract corresponding to the credential; according to the credential contract, verify the authentication information in the credential and the authentication order of the issuer to obtain the credential verification result; according to the credential verification result, determine that the credential is valid, so that the verifier can pass the user's application request based on the validity of the credential. The scheme provided by the embodiment of the present application enables the verifier to verify the credential issued by multiple issuers based on the credential contract, thereby improving the verification ability of the verifier to the credential.

[0207] As can be seen from the above, the embodiment of the present application enables the verifier to verify credentials issued by multiple issuers, that is, it can verify credentials with multiple attributes. Therefore, this solution can improve the verifier's ability to verify credentials.

[0208] The method described in the above embodiment will be further described below.

[0209] In this embodiment, the method of the embodiment of the present application will be described in detail by taking the certificate issuance and verification system as an example.

[0210] In the credential issuance and verification system provided in the embodiment of the present application, it is possible to trace back the credentials issued by multiple issuers. Figure 3As shown in the figure, the interaction between the issuance and verification systems of the certificate can be seen. The specific interaction process is as follows:

[0211] (1) Multiple issuers form an alliance and agree to register a certificate contract. The certificate contract is used to issue the certificate and the authentication order of the issuers participating in the certificate issuance.

[0212] In some embodiments, the credential contract is registered on the blockchain by any issuer participating in the credential issuance.

[0213] In some embodiments, registering a credential contract needs to include the contract name, the address of each issuer, and the order in which the issuers are authorized to participate in the credential issuance.

[0214] (2) Each issuer participating in the certificate issuance obtains the certificate contract from the blockchain.

[0215] (3) The user initiates a credential application request to the first issuer, where the credential application request carries information to be verified.

[0216] For example, the user first submits a certificate application request to the village committee issuer, and the information to be verified can be information related to the user's identity.

[0217] (4) The first issuer authenticates the information to be verified according to the certificate application request, obtains the certificate V0, and issues the certificate V0 to the user.

[0218] In some embodiments, the issuer authenticates the information to be verified, the authentication order of the first issuer, the credential creation time, and the credential expiration time to obtain the credential V0.

[0219] In some embodiments, an elliptic curve signature algorithm is used to authenticate the information to be verified.

[0220] In some embodiments, the credential V0 is encrypted using an encryption key.

[0221] (5) The user initiates a credential application request to the next issuer, and the credential application request carries information to be verified, and the information to be verified includes the credential V0 and user information.

[0222] (6) The next issuer authenticates the credential V0 and the user information in the verification information, obtains the credential V1, and issues the credential V1 to the user.

[0223] (7) Until the last issuer authenticates the information to be verified sent by the user, obtains the certificate V2, and issues the certificate V2 to the user.

[0224] In some embodiments, if any of the issuers participating in the issuance of Certificate V2 has doubts about the information to be verified, the issuer revokes the certificate number of the certificate contract, obtains revocation information, and uploads the revocation information to the blockchain.

[0225] In some embodiments, when the issuer uploads the revocation information, the blockchain needs to confirm that the upload address is the issuer's address.

[0226] (8) The user holds the certificate V2 and verifies it with the verification party.

[0227] (9) The verifier determines the list of issuers of the participating certificate V2 from the certificate contract.

[0228] In some embodiments, the verifier obtains the credential contract from the blockchain.

[0229] (10) The verifier verifies whether the issuer in the certificate V2 matches the list of issuers in the certificate contract, and whether the authentication order of the issuer matches the authentication order in the certificate contract, and verifies the identity information of each issuer and the identity information of the user in the certificate V2 to obtain the certificate verification result.

[0230] In some embodiments, after the credential verification result, the method further includes:

[0231] The verifier obtains the revocation information related to the voucher contract from the blockchain and verifies the revocation information;

[0232] If the revocation information is valid, the certificate V2 will be invalid;

[0233] If the revocation information is invalid, the verifier determines that the certificate V2 is valid based on the certificate verification result.

[0234] (11) After the credential verification result is passed, the verification party provides services to the user.

[0235] As can be seen above, the certificate contract ensures that the issuance of a certificate requires the joint control of multiple issuers, rather than a single issuer. Revocation information ensures that any of the participating issuers can revoke the certificate if they have questions about it. Verifiers no longer need to verify a single piece of authentication information; they must verify the certificate against the list of issuers specified in the certificate contract and the associated revocation information. This ensures the validity of the certificate, enabling traceability for certificates issued by multiple issuers.

[0236] To better implement the above method, the present application also provides a credential issuance device in a blockchain. The credential issuance device can be integrated into an electronic device, such as a terminal or a server. The terminal can be a mobile phone, tablet computer, smart Bluetooth device, laptop computer, personal computer, etc. The server can be a single server or a server cluster consisting of multiple servers.

[0237] For example, in this embodiment, the method of the embodiment of the present application will be described in detail by taking the specific integration of the certificate issuing device in the blockchain into a terminal as an example.

[0238] For example, Figure 4 As shown, the credential issuance device in the blockchain may include an acquisition unit, an order determination unit, an issuer determination unit, an information verification unit, and a generation and issuance unit, for generating credentials with multiple issuers involved, as follows:

[0239] (1) an acquisition unit 410;

[0240] The acquisition unit 410 is configured to acquire a credential application request initiated by a user and a credential contract. The credential application request carries information to be verified, and the credential contract includes an authentication order of issuers participating in the credential issuance.

[0241] (2) sequence determination unit 420;

[0242] The order determination unit 420 is used to obtain the current authentication order corresponding to the issuer from the certificate contract, where the current issuer is the issuer corresponding to the received certificate application request.

[0243] (3) Issuer determination unit 430;

[0244] The issuer determination unit 430 is configured to determine a target issuer from the credential issuers according to the current authentication order. The credential issuer is an issuer that participates in credential issuance. The target issuer includes an issuer whose authentication order is before the current authentication order and the current issuer.

[0245] (4) information verification unit 440;

[0246] The information verification unit 440 is used to verify the information to be verified according to the target issuer and obtain a verification result.

[0247] In some embodiments, the target issuer includes an issuer corresponding to an authentication sequence before the current authentication sequence, the information to be verified includes first information to be verified and second information to be verified, the first information to be verified is a credential issued by the issuer corresponding to the authentication sequence before the current authentication sequence, and the second information to be verified is user information that the current issuer needs to verify, and the information verification unit is used to:

[0248] Verifying the credentials in the first information to be verified to obtain a credential verification result;

[0249] According to the credential verification result, the user information in the second information to be verified is verified to obtain a verification result.

[0250] In some embodiments, the target issuers do not include issuers corresponding to authentication orders prior to the current authentication order, the information to be verified is user information that the current issuer needs to verify, and the information verification unit is configured to:

[0251] Verify the user information in the verification information and obtain the verification result.

[0252] (5) generating an issuing unit 450;

[0253] The generating and issuing unit 450 is configured to generate a certificate corresponding to the certificate application request according to the verification result and issue the certificate to the user.

[0254] In some embodiments, the issuing unit is generated to:

[0255] According to the verification result, obtain the identity of the current issuer and the current authentication order;

[0256] The identity of the current issuer and the current authentication order are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained.

[0257] In some embodiments, the identity identifier of the current issuer and the current authentication order are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained, including:

[0258] Generate credential creation time and credential expiration time;

[0259] The credential creation time, credential expiration time, identity of the current issuer, and current authentication sequence are used to authenticate the information to be verified, and the credential corresponding to the credential application request is obtained.

[0260] In some embodiments, the acquisition unit is configured to:

[0261] Obtain the certificate contract from the blockchain. The certificate contract includes the subject of the certificate, the issuers involved in the certificate issuance, and the authentication order corresponding to each issuer.

[0262] In some embodiments, after issuing the credential to the user, the method further includes:

[0263] Re-verify the information to be verified corresponding to the credential and obtain a re-verification result;

[0264] When the re-inspection result does not meet the preset conditions, the certificate contract corresponding to the certificate is revoked and the revocation information is obtained;

[0265] The revocation information is uploaded so that the verifier can determine that the certificate corresponding to the certificate contract is invalid based on the revocation information.

[0266] In some embodiments, revocation authentication is performed on the voucher contract corresponding to the voucher to obtain revocation information, including:

[0267] Get the identity of the current issuer and the contract number of the certificate contract corresponding to the certificate;

[0268] Use the current issuer's identity to revoke the contract number and obtain the revocation information.

[0269] In some embodiments, the revocation information is uploaded, and the device is used to:

[0270] The revocation information is uploaded to the revocation contract in the blockchain, and the revocation contract is associated with the voucher contract.

[0271] In some embodiments, a revocation contract is created for an issuer that participates in the issuance of a credential.

[0272] In specific implementation, the above units can be implemented as independent entities, or can be arbitrarily combined to be implemented as the same or several entities. The specific implementation of the above units can be found in the previous method embodiments and will not be repeated here.

[0273] As can be seen from the above, the certificate issuing device in the blockchain of this embodiment obtains the certificate application request initiated by the user and the certificate contract by the acquisition unit. The certificate application request carries information to be verified, and the certificate contract includes the authentication order of the issuers participating in the certificate issuance; the order determination unit obtains the current authentication order corresponding to the issuer from the certificate contract, and the current issuer is the issuer corresponding to the received certificate application request; the issuer determination unit determines the target issuer from the certificate issuers according to the current authentication order, and the certificate issuer is the issuer participating in the certificate issuance, and the target issuer includes the issuer whose authentication order is before the current authentication order and the current issuer; the information verification unit verifies the information to be verified according to the target issuer to obtain a verification result; the generation and issuance unit generates a certificate corresponding to the certificate application request according to the verification result, and issues the certificate to the user.

[0274] Therefore, the embodiment of the present application can satisfy the requirements of multiple issuers participating in the generation of credentials, so that the credentials can prove the multiple attributes of the user.

[0275] To better implement the above method, the present application also provides a credential verification device in a blockchain. The credential verification device can be integrated into an electronic device, such as a terminal or a server. The terminal can be a mobile phone, tablet computer, smart Bluetooth device, laptop computer, personal computer, etc. The server can be a single server or a server cluster consisting of multiple servers.

[0276] For example, in this embodiment, the method of the embodiment of the present application will be described in detail by taking the specific integration of the credential verification device in the blockchain into a terminal as an example.

[0277] For example, Figure 5 As shown, the credential verification device in the blockchain may include a credential acquisition unit, a contract query unit, a credential verification unit, and a credential determination unit, which are used to verify the credential issued by the issuer, as follows:

[0278] (1) a credential acquisition unit 510;

[0279] A credential acquisition unit 510 is configured to acquire a credential sent by a user, such as one of the credential issuance methods in the blockchain provided in the embodiments of the present application, wherein the credential includes authentication information and an authentication order of the issuer;

[0280] (2) contract query unit 520;

[0281] A contract query unit 520 is used to query the voucher contract corresponding to the voucher;

[0282] In some embodiments, to query a voucher contract corresponding to a voucher, the apparatus is configured to:

[0283] Query the voucher contract corresponding to the voucher from the blockchain.

[0284] (3) credential verification unit 530;

[0285] The certificate verification unit 530 is used to verify the authentication information in the certificate and the authentication order of the issuer according to the certificate contract to obtain a certificate verification result;

[0286] (4) a credential determination unit 540;

[0287] The credential determination unit 540 is configured to determine whether the credential is valid based on the credential verification result, so that the verification party can approve the user's application request based on the validity of the credential.

[0288] In some embodiments, the credential determination unit is configured to:

[0289] Obtaining revocation information associated with the voucher contract;

[0290] Based on the revocation information and the certificate verification result, it is determined that the certificate corresponding to the certificate contract is valid.

[0291] In some embodiments, obtaining revocation information associated with a voucher contract, the apparatus is configured to:

[0292] Determine the revocation contract associated with the voucher contract based on the blockchain;

[0293] Get revocation information from the revocation contract.

[0294] In some embodiments, the credential further includes the identity identifiers of the user and the issuer, and the credential determination unit is configured to:

[0295] Obtain an identity information cluster, which consists of the user and issuer's identities.

[0296] Verify the identity of the user and the issuer in the credential using the identity information cluster to obtain an identity verification result;

[0297] Based on the identity verification results and the credential verification results, it is determined that the credential is valid.

[0298] In specific implementation, the above units can be implemented as independent entities, or can be arbitrarily combined to be implemented as the same or several entities. The specific implementation of the above units can be found in the previous method embodiments and will not be repeated here.

[0299] As can be seen from the above, the credential verification device of this embodiment obtains the credential sent by the user in any of the credential issuance methods in the blockchain provided in the embodiments of the present application by the credential acquisition unit, and the credential contains authentication information and the authentication order of the issuer; the contract query unit queries the credential contract corresponding to the credential; the credential verification unit verifies the authentication information in the credential and the authentication order of the issuer according to the credential contract to obtain the credential verification result; the credential determination unit determines that the credential is valid based on the credential verification result, so that the verifier can approve the user's application request based on the validity of the credential.

[0300] Therefore, the embodiment of the present application enables the verifier to verify the credentials issued by multiple issuers, so that the credentials can prove the multiple attributes of the user.

[0301] Accordingly, an embodiment of the present application also provides an electronic device, which may be a terminal or a server, and the terminal may be a smart phone, tablet computer, laptop computer, touch screen, game console, personal computer, personal digital assistant (PDA) and other terminal devices.

[0302] like Figure 6 As shown, Figure 6This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device 600 includes a processor 610 having one or more processing cores, a memory 620 having one or more computer-readable storage media, and a computer program stored in the memory 620 and executable on the processor. The processor 610 is electrically connected to the memory 620. Those skilled in the art will understand that the electronic device structure shown in the figure does not constitute a limitation of the electronic device, and may include more or fewer components than shown, or combine certain components, or arrange the components differently.

[0303] The processor 610 is the control center of the electronic device 600. It uses various interfaces and lines to connect various parts of the entire electronic device 600. By running or loading software programs and / or modules stored in the memory 620 and calling data stored in the memory 620, it executes various functions of the electronic device 600 and processes data, thereby monitoring the electronic device 600 as a whole.

[0304] In the embodiment of the present application, the processor 610 in the electronic device 600 loads instructions corresponding to one or more application processes into the memory 620 according to the following steps, and the processor 610 runs the application stored in the memory 620, thereby implementing the functions of credential issuance and credential verification in the blockchain:

[0305] The functions of certificate issuance in the blockchain include:

[0306] Obtain the credential application request initiated by the user and the credential contract. The credential application request carries the information to be verified, and the credential contract includes the authentication order of the issuers participating in the credential issuance.

[0307] Get the current authentication order corresponding to the current issuer from the certificate contract. The current issuer is the issuer corresponding to the receiving certificate application request;

[0308] According to the current authentication order, a target issuer is determined from the credential issuers. The credential issuer is the issuer that participates in the credential issuance. The target issuer includes the issuer whose authentication order is before the current authentication order and the current issuer.

[0309] Verify the information to be verified according to the target issuer and obtain the verification result;

[0310] Based on the verification results, a certificate corresponding to the certificate application request is generated and issued to the user.

[0311] Credential verification capabilities include:

[0312] Obtain a credential sent by a user, such as one of the credential issuance methods in a blockchain provided in the embodiments of the present application, wherein the credential includes authentication information and an authentication order of the issuer;

[0313] Query the certificate contract corresponding to the certificate;

[0314] According to the certificate contract, the authentication information in the certificate and the authentication order of the issuer are verified to obtain the certificate verification result;

[0315] According to the result of the credential verification, the credential is determined to be valid, so that the verification party can approve the user's application request based on the validity of the credential.

[0316] The specific implementation of the above operations can be found in the previous embodiments and will not be repeated here.

[0317] Optional, such as Figure 6 As shown, the electronic device 600 further includes: a touch screen 630, a radio frequency circuit 640, an audio circuit 650, an input unit 660, and a power supply 670. Among them, the processor 610 is electrically connected to the touch screen 630, the radio frequency circuit 640, the audio circuit 650, the input unit 660, and the power supply 670 respectively. Those skilled in the art will understand that Figure 6 The electronic device structure shown in the figure does not constitute a limitation to the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0318] The touch display screen 630 can be used to display a graphical user interface and receive operation instructions generated by the user acting on the graphical user interface. The touch display screen 630 may include a display panel and a touch panel. Among them, the display panel can be used to display information input by the user or information provided to the user and various graphical user interfaces of the electronic device, and these graphical user interfaces can be composed of graphics, text, icons, videos and any combination thereof. Optionally, the display panel can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like. The touch panel can be used to collect the user's touch operations on or near it (such as the user using any suitable object or accessory such as a finger, stylus, etc. on the touch panel or near the touch panel), and generate corresponding operation instructions, and the operation instructions execute the corresponding program. Optionally, the touch panel may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch direction, detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into the touch point coordinates, and then sends it to the processor 610, and can receive the command sent by the processor 610 and execute it. The touch panel can cover the display panel. When the touch panel detects a touch operation on or near it, it is transmitted to the processor 610 to determine the type of touch event. The processor 610 then provides a corresponding visual output on the display panel according to the type of touch event. In an embodiment of the present application, the touch panel and the display panel can be integrated into the touch display screen 630 to realize input and output functions. However, in some embodiments, the touch panel and the touch panel can be used as two independent components to realize input and output functions. That is, the touch display screen 630 can also be used as part of the input unit 660 to realize the input function.

[0319] In the embodiment of the present application, the processor 610 performs credential generation or credential verification of the control command transmitted through the touch screen 630 .

[0320] The radio frequency circuit 640 may be used to transmit and receive radio frequency signals, so as to establish wireless communication with a network device or other electronic devices through wireless communication, and to transmit and receive signals with the network device or other electronic devices.

[0321] The audio circuit 650 can be used to provide an audio interface between the user and the electronic device through a speaker and a microphone. The audio circuit 650 can convert the received audio data into an electrical signal and transmit it to the speaker, which then converts it into a sound signal for output. On the other hand, the microphone converts the collected sound signal into an electrical signal, which is received by the audio circuit 650 and converted into audio data. The audio data is then output to the processor 610 for processing, and then sent to another electronic device through the radio frequency circuit 640, or the audio data is output to the memory 620 for further processing. The audio circuit 650 may also include an earphone jack to provide communication between external headphones and the electronic device.

[0322] The input unit 660 may be used to receive input numbers, character information, or user feature information (such as fingerprint, iris, facial information, etc.), and to generate keyboard, mouse, joystick, optical, or trackball signal inputs related to user settings and function control.

[0323] The power supply 670 is used to supply power to the various components of the electronic device 600. Optionally, the power supply 670 can be logically connected to the processor 610 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The power supply 670 can also include one or more DC or AC power supplies, a recharging system, a power failure detection circuit, a power converter or inverter, a power status indicator, and other arbitrary components.

[0324] although Figure 6 Not shown in the figure, the electronic device 600 may further include a camera, a sensor, a wireless fidelity module, a Bluetooth module, etc., which will not be described in detail here.

[0325] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0326] As can be seen from the above, the electronic device provided in this embodiment can satisfy the requirements of multiple issuers participating in the generation of credentials, and can also enable a verifier to verify credentials issued by multiple issuers.

[0327] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be accomplished by instructions, or by controlling related hardware through instructions. The instructions may be stored in a computer-readable storage medium and loaded and executed by a processor.

[0328] To this end, embodiments of the present application provide a computer-readable storage medium storing a plurality of computer programs that can be loaded by a processor to execute the steps of any one of the methods for issuing credentials in a blockchain and any one of the methods for verifying credentials in a blockchain provided in embodiments of the present application. For example, the computer program may execute the following steps:

[0329] A method for issuing a certificate in a blockchain, comprising:

[0330] Obtain the credential application request initiated by the user and the credential contract. The credential application request carries the information to be verified, and the credential contract includes the authentication order of the issuers participating in the credential issuance.

[0331] Get the current authentication order corresponding to the current issuer from the certificate contract. The current issuer is the issuer corresponding to the receiving certificate application request;

[0332] According to the current authentication order, a target issuer is determined from the credential issuers. The credential issuer is the issuer that participates in the credential issuance. The target issuer includes the issuer whose authentication order is before the current authentication order and the current issuer.

[0333] Verify the information to be verified according to the target issuer and obtain the verification result;

[0334] Based on the verification results, a certificate corresponding to the certificate application request is generated and issued to the user.

[0335] And a credential verification method in a blockchain, comprising:

[0336] Obtain a credential sent by a user, such as one of the credential issuance methods in a blockchain provided in the embodiments of the present application, wherein the credential includes authentication information and an authentication order of the issuer;

[0337] Query the certificate contract corresponding to the certificate;

[0338] According to the certificate contract, the authentication information in the certificate and the authentication order of the issuer are verified to obtain the certificate verification result;

[0339] According to the result of the credential verification, the credential is determined to be valid, so that the verification party can approve the user's application request based on the validity of the credential.

[0340] The specific implementation of the above operations can be found in the previous embodiments and will not be repeated here.

[0341] The storage medium may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0342] Since the computer program stored in the storage medium can execute the steps of any one of the credential issuance methods and credential verification methods in the blockchain provided in the embodiments of the present application, the beneficial effects that can be achieved by any one of the credential issuance methods and credential verification methods in the blockchain provided in the embodiments of the present application can be achieved. For details, please refer to the previous embodiments and will not be repeated here.

[0343] The above is a detailed introduction to the certificate issuance method and certificate verification method in the blockchain provided by the embodiments of the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present application.

Claims

1. A method for issuing certificates in a blockchain, characterized in that: include: Obtaining a credential application request initiated by a user, wherein the credential application request carries information to be verified, and obtaining a credential contract from the blockchain, wherein the credential contract includes the authentication order of the issuers participating in the credential issuance; Obtaining a current authentication order corresponding to a current issuer from the credential contract, where the current issuer is the issuer corresponding to the receiving credential application request; Determining a target issuer from the credential issuers according to the current authentication order, the credential issuer being the issuer participating in the credential issuance, the target issuer including the issuer whose authentication order is before the current authentication order and the current issuer; According to the target issuer, the information to be verified is verified through the blockchain to obtain a verification result; A credential corresponding to the credential application request is generated based on the verification result, and the credential is issued to the user.

2. The method according to claim 1, wherein The current authentication order is a first authentication order, and determining the target issuer from the credential issuers according to the current authentication order includes: According to the first authentication sequence, a target issuer is determined from the credential issuers as the current issuer.

3. The method according to claim 1, wherein The current authentication order is the last authentication order, and determining the target issuer from the credential issuers according to the current authentication order includes: According to the last authentication sequence, target issuers are determined from the credential issuers to be all issuers before the last authentication sequence and the current issuer.

4. The method according to claim 1, wherein The target issuer includes an issuer corresponding to an authentication sequence before the current authentication sequence, the information to be verified includes first information to be verified and second information to be verified, the first information to be verified is a credential issued by the issuer corresponding to the authentication sequence before the current authentication sequence, and the second information to be verified is user information that the current issuer needs to verify, and the information to be verified is verified according to the target issuer to obtain a verification result, including: Verifying the credentials in the first information to be verified to obtain a credential verification result; According to the credential verification result, the user information in the second information to be verified is verified to obtain a verification result.

5. The method according to claim 1, wherein The target issuers do not include issuers corresponding to authentication orders preceding the current authentication order, the information to be verified is user information that the current issuer needs to verify, and the information to be verified is verified according to the target issuer to obtain a verification result, including: Verify the user information in the information to be verified to obtain a verification result.

6. The method according to claim 1, wherein Generating a credential corresponding to the credential application request according to the verification result includes: According to the verification result, the identity of the current issuer and the current authentication order are obtained; The information to be verified is authenticated using the identity identifier of the current issuer and the current authentication order to obtain a credential corresponding to the credential application request.

7. The method according to claim 6, wherein The authenticating the information to be verified by using the identity identifier of the current issuer and the current authentication order to obtain the credential corresponding to the credential application request includes: Generate credential creation time and credential expiration time; The information to be verified is authenticated using the credential creation time, the credential expiration time, the identity identifier of the current issuer, and the current authentication order to obtain a credential corresponding to the credential application request.

8. The method according to claim 1, wherein Get the certificate contract, including: A certificate contract is obtained from the blockchain, wherein the certificate contract includes the subject of the certificate, the issuers involved in issuing the certificate, and the authentication order corresponding to each of the issuers.

9. The method according to claim 1, wherein After issuing the certificate to the user, the method further includes: Re-verifying the information to be verified corresponding to the credential to obtain a re-verification result; When the re-inspection result does not meet the preset conditions, the certificate contract corresponding to the certificate is revoked to obtain revocation information; The revocation information is uploaded so that the verifier can determine that the certificate corresponding to the certificate contract is invalid based on the revocation information.

10. The method according to claim 9, wherein The revocation authentication of the certificate contract corresponding to the certificate to obtain revocation information includes: Obtaining the identity of the current issuer and the contract number of the certificate contract corresponding to the certificate; The contract number is revoked and authenticated using the identity identifier of the current issuer to obtain revocation information.

11. The method according to claim 9, wherein The uploading of the revocation information includes: The revocation information is uploaded to the revocation contract in the blockchain, and the revocation contract is associated with the voucher contract.

12. A method for verifying credentials in a blockchain, characterized in that: include: Obtaining the credential sent by the user in the credential issuance method in the blockchain according to any one of claims 1 to 8, wherein the credential includes authentication information and an authentication order of the issuer; Query the voucher contract corresponding to the voucher; Verify the authentication information in the certificate and the authentication order of the issuer according to the certificate contract to obtain a certificate verification result; According to the credential verification result, the credential is determined to be valid, so that the verification party approves the user's application request based on the validity of the credential.

13. The method according to claim 12, wherein: Determining, based on the verification result, that the credential is valid includes: Obtaining revocation information associated with the voucher contract; According to the revocation information and the certificate verification result, it is determined that the certificate corresponding to the certificate contract is valid.

14. The method according to claim 12, wherein: The credential also includes the identity identifiers of the user and the issuer. Determining the validity of the credential based on the credential verification result includes: Obtaining an identity information cluster, the identity information cluster consisting of the identity identifiers of the user and the issuer; Verifying the identities of the user and the issuer in the credential using the identity information cluster to obtain an identity verification result; The credential is determined to be valid based on the identity verification result and the credential verification result.

15. A certificate issuing device in a blockchain, characterized in that: include: An acquisition unit, configured to acquire a credential application request initiated by a user and to acquire a credential contract from a blockchain, wherein the credential application request carries information to be verified, and the credential contract includes an authentication order of issuers participating in the credential issuance; an order determination unit, configured to obtain, from the certificate contract, a current authentication order corresponding to a current issuer, the current issuer being the issuer corresponding to the receiving certificate application request; an issuer determining unit, configured to determine a target issuer from the credential issuers based on the current authentication order, the credential issuer being the issuer participating in the credential issuance, the target issuer including an issuer whose authentication order precedes the current authentication order and the current issuer; An information verification unit, configured to verify the information to be verified through a blockchain according to the target issuer, and obtain a verification result; A generating and issuing unit is used to generate a certificate corresponding to the certificate application request according to the verification result, and issue the certificate to the user.

16. A credential verification device in a blockchain, characterized in that: include: a credential acquisition unit, configured to acquire the credential sent by the user in the credential issuance method in the blockchain according to any one of claims 1 to 8, wherein the credential includes authentication information and an authentication order of the issuer; A contract query unit, used to query the certificate contract corresponding to the certificate; a credential verification unit, configured to verify the authentication information in the credential and the authentication order of the issuer according to the credential contract, and obtain a credential verification result; The credential determination unit is used to determine whether the credential is valid based on the credential verification result, so that the verification party approves the user's application request based on the validity of the credential.

17. A terminal, characterized in that: The method comprises a processor and a memory, wherein the memory stores a plurality of instructions; the processor loads instructions from the memory to execute the steps of the credential issuance method in the blockchain as described in any one of claims 1 to 11 or the steps of the credential verification method in the blockchain as described in any one of claims 12 to 14.

18. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, which are suitable for being loaded by a processor to execute the steps of the credential issuance method in a blockchain as described in any one of claims 1 to 11 or the steps of the credential verification method in a blockchain as described in any one of claims 12 to 14.

Citation Information

Patent Citations

  • Electronic certificate safety control method and device

    CN111507716A

  • Digital identity verification method, device, system and equipment and storage medium

    CN113312597A