A method, equipment, and medium for distributing and managing preferential treatment funds based on digital identity.

By acquiring the attribute information of veterans and generating attribute certificates to update their digital identities, the problem of identifying and distributing preferential treatment funds to special groups has been solved, and the automated distribution and secure authentication of preferential treatment funds have been achieved.

CN114493508BActive Publication Date: 2026-01-30浪潮工业互联网股份有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210035569.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-13
Publication Date
2026-01-30
Estimated Expiration
2042-01-13

AI Technical Summary

Technical Problem

In the current technology, it is difficult to obtain certification documents for special groups such as veterans who died of illness, veterans who sacrificed their lives, and veterans who are disabled, which makes it difficult to verify the distribution of preferential treatment funds.

Method used

By obtaining the attribute information of veterans, using designated institutions to authenticate them and generate attribute certificates, updating their initial digital identities, and determining and distributing preferential treatment funds based on the attribute certificates.

Benefits of technology

It has enabled the identification of eligibility and level for preferential treatment funds for special groups, reduced application steps, reduced the workload of approval departments, and ensured information security and data authenticity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114493508B_ABST
    Figure CN114493508B_ABST
Patent Text Reader

Abstract

This specification discloses a method, device, and medium for managing the disbursement of preferential treatment funds based on digital identity. The method includes: obtaining attribute information of a veteran provided by an applicant user and sending the attribute information to a designated institution corresponding to the attribute information, so that the designated institution can authenticate the attribute information; after successful authentication, converting the attribute information into an attribute credential; updating the veteran's initial digital identity based on the attribute credential to generate the veteran's current digital identity, wherein the pre-generated initial digital identity is based on the veteran's personal information; and determining the veteran's preferential treatment fund level based on the attribute credential in the current digital identity, so that the fund disbursement department can disburse the corresponding preferential treatment funds according to the veteran's preferential treatment fund level. This reduces the operational steps for applicants, determines the eligibility for preferential treatment fund disbursement and the corresponding disbursement level through digital identity, and reduces the workload of the approval department.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present specification relates to the technical field of computer technology, and particularly relates to a digital identity-based preferential treatment fund issuing management method, device and medium. BACKGROUND

[0002] The preferential treatment fund is a kind of pension and reward for specific personnel, and the preferential treatment object refers to active servicemen, disabled servicemen serving or withdrawing from active service, demobilized soldiers, veterans, bereaved families of martyrs, families of servicemen who died on duty or died of illness, and families of active servicemen.

[0003] The preferential treatment fund needs to be approved by various levels of institutions and departments, and various departments and institutions need to issue proof documents to verify whether the applicant is qualified for the preferential treatment fund. In the prior art, the retired soldiers usually go to the designated institution to issue the proof documents, but when the applicant is a special group, such as the bereaved family of the deceased retired soldier, the bereaved family of the sacrificed retired soldier, the disabled retired soldier, and other special groups who cannot go to the designated institution in person, it is difficult to issue various types of proof documents related to the retired soldiers, which leads to the failure to identify the preferential treatment fund issuing for such special groups. SUMMARY

[0004] One or more embodiments of the present specification provide a digital identity-based preferential treatment fund issuing management method, device and medium, which are used to solve the technical problem that it is difficult to identify the preferential treatment fund issuing for special groups such as the deceased retired soldier, the sacrificed retired soldier and the disabled retired soldier.

[0005] One or more embodiments of the present specification adopt the following technical solutions:

[0006] One or more embodiments of the present specification provide a digital identity-based preferential treatment fund issuing management method, which comprises: obtaining attribute information of a retired soldier provided by an application user, and sending the attribute information to a designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, wherein the attribute information comprises disability information of the retired soldier; after the authentication is passed, converting the attribute information into an attribute certificate, wherein the attribute certificate comprises an authentication signature of the attribute information by the designated institution; updating an initial digital identity corresponding to the retired soldier according to the attribute certificate to generate a current digital identity of the retired soldier; determining a preferential treatment fund level of the retired soldier according to the attribute certificate in the current digital identity, so that a fund issuing department issues corresponding preferential treatment funds according to the preferential treatment fund level of the retired soldier.

[0007] Specifically, before updating the initial digital identity according to the attribute credential, the method further comprises: presetting an identity authentication mode of the application user, wherein the identity authentication mode comprises any one or more of a secure password authentication and a specified operation authentication; when the secure password input by the application user is consistent with the preset secure password and the current operation of the application user is consistent with the preset specified operation, authenticating the identity of the application user and sending a user key to the application user to obtain the pre-generated initial digital identity through the user key.

[0008] Specifically, after the fund issuing department issues the corresponding preferential treatment fund according to the preferential treatment fund level of the retired soldier, the method further comprises: generating an issuing certificate according to the amount and time of the preferential treatment fund; signing the issuing certificate using the key of the fund issuing department and storing the signed issuing certificate to the blockchain; and generating the preferential treatment fund issuing record of the current retired soldier according to all signed issuing certificates in the blockchain.

[0009] Specifically, the fund issuing department issues the corresponding preferential treatment fund according to the preferential treatment fund level of the retired soldier, and specifically comprises: generating an identification certificate according to the current digital identity of the retired soldier, obtaining an identification timestamp in the identification certificate of the retired soldier, and determining whether the identification timestamp is within the valid period; if the identification timestamp is within the valid period, determining the amount of preferential treatment fund to be issued according to the preferential treatment fund level in the identification certificate; obtaining the preferential treatment fund record of the retired soldier, wherein the issued preferential treatment fund record includes multiple preferential treatment fund amounts and the corresponding issuing time of the multiple preferential treatment fund amounts; generating a fund issuing period according to the issuing time corresponding to each preferential treatment fund amount; determining whether the current fund issuing period corresponding to the identification timestamp has been completed, and if the current fund issuing period corresponding to the identification timestamp has not been issued, issuing the amount of preferential treatment fund to be issued to the application user.

[0010] Specifically, the attribute information is sent to the designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, specifically including: dividing the attribute information into designated attribute information and preset attribute information, wherein the designated attribute information is the information in the attribute information of the retired soldier that needs to be authenticated, and the preset attribute information is the identity information of the retired soldier; using the institution public key of the designated institution to encrypt the designated attribute information to obtain encrypted designated attribute information; sending the encrypted designated attribute information and the preset attribute information to the designated institution, so that the designated institution decrypts the encrypted private information according to the institution private key to obtain the designated attribute information; selecting the attribute file of the retired soldier in the designated database according to the identity information in the preset attribute information; comparing the designated attribute information with the attribute file, so as to authenticate the attribute information.

[0011] Specifically, after the authentication is passed, the attribute information is converted into attribute credentials, specifically including: receiving the authentication institution signature sent by the designated institution, verifying the authentication institution signature through the institution public key corresponding to the designated institution; after verification, generating a corresponding attribute signature according to the authentication signature of the designated institution, wherein the attribute signature is used to indicate that the authentication institution signature corresponding to the attribute information passes the verification; setting the attribute signature at a designated position of the attribute information to generate attribute credentials.

[0012] Specifically, before the initial digital identity corresponding to the retired soldier is updated according to the attribute credentials, the method further includes: extracting a plurality of fields in the personal information of the retired soldier, dividing the plurality of fields into text fields and numerical fields according to field types; numbering the text fields and the numerical fields according to the order of the text fields and the numerical fields in the personal information; generating a random key, encrypting the text fields using the random key to generate text field ciphertext; obtaining a user public key, encrypting the numerical fields using the user public key to generate numerical field ciphertext; sorting the corresponding text field ciphertext and the corresponding numerical field key according to the number of each text field and each numerical field to obtain the initial digital identity.

[0013] Specifically, the initial digital identity is updated according to the attribute credentials to generate the current digital identity of the retired soldier, specifically including: obtaining the attribute information in the attribute credentials; obtaining the verification signature of the attribute information through the designated institution corresponding to the attribute information; taking the attribute information and the verification signature as the attribute credentials, adding the attribute credentials to a designated position in the initial digital identity to generate the current digital identity of the retired soldier.

[0014] One or more embodiments of the present specification provide a digital identity-based preferential fund distribution management device, comprising:

[0015] at least one processor; and,

[0016] a memory in communication connection with the at least one processor; wherein,

[0017] the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:

[0018] obtain attribute information of a retired soldier provided by an application user, and send the attribute information to a designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, wherein the attribute information includes disability information of the retired soldier; after authentication, convert the attribute information into an attribute certificate, wherein the attribute certificate includes an authentication signature of the attribute information by the designated institution; according to the attribute certificate, update an initial digital identity corresponding to the retired soldier to generate a current digital identity of the retired soldier; according to the attribute certificate in the current digital identity, determine the preferential fund level of the retired soldier, so that a fund distribution department distributes corresponding preferential funds according to the preferential fund level of the retired soldier.

[0019] One or more embodiments of the present specification provide a non-volatile computer storage medium, which stores computer executable instructions, and the computer executable instructions are configured to: obtain attribute information of a retired soldier provided by an application user, and send the attribute information to a designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, wherein the attribute information includes disability information of the retired soldier; after authentication, convert the attribute information into an attribute certificate, wherein the attribute certificate includes an authentication signature of the attribute information by the designated institution; according to the attribute certificate, update an initial digital identity corresponding to the retired soldier to generate a current digital identity of the retired soldier; according to the attribute certificate in the current digital identity, determine the preferential fund level of the retired soldier, so that a fund distribution department distributes corresponding preferential funds according to the preferential fund level of the retired soldier.

[0020] The at least one technical solution adopted by the embodiments of the present specification can achieve the following beneficial effects: the attribute information of the initial digital identity is updated, the current digital identity is generated, the current digital identity includes not only the personal information and attribute information required for applying for preferential funds, but also the attribute certificate after the authentication of the designated institution, thereby reducing the operation steps of the applicant user, avoiding the situation that special groups such as the deceased retired soldiers, the sacrificed retired soldiers, and the disabled retired soldiers cannot issue proof documents, realizing the identification of the preferential fund issuing qualification and the corresponding issuing level of the special groups such as the deceased retired soldiers, the sacrificed retired soldiers, and the disabled retired soldiers, and determining the preferential fund issuing qualification and the corresponding issuing level in the form of digital identity, thereby reducing the workload of the approval department. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments described in the present specification, and other drawings can be obtained by those skilled in the art without creative labor. In the drawings:

[0022] Figure 1 A flowchart of a preferential fund issuing management method based on digital identity provided by the embodiments of the present specification;

[0023] Figure 2 A structural schematic diagram of a preferential fund issuing management device based on digital identity provided by the embodiments of the present specification. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the technical solutions in the present specification, the technical solutions in the embodiments of the present specification will be described clearly and completely in conjunction with the drawings in the embodiments of the present specification. Obviously, the described embodiments are only some of the embodiments of the present specification, not all. Based on the embodiments of the present specification, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present specification.

[0025] Preferential funds are a kind of consolation and reward for specific personnel. The preferential objects refer to active soldiers, disabled soldiers serving or withdrawing from active service, demobilized soldiers, retired soldiers, martyr dependents, families of soldiers who died on duty or died of illness, and families of active soldiers.

[0026] In the prior art, the issuance of preferential funds needs to be approved by various levels of institutions and departments, and multiple departments and institutions need to issue certification documents at the same time to verify whether the applicant has the qualification for the issuance of preferential funds. When the applicant is a special group, such as the family members of the deceased and disabled retired soldiers, it is difficult to issue various types of certification documents related to the retired soldiers, which leads to difficulty in qualification identification of such preferential funds.

[0027] The embodiment of the present specification provides a preferential fund issuance management method based on digital identity. It should be noted that the execution subject in the embodiment of the present specification can be a server or a device with data processing function. Figure 1 The flowchart of the preferential fund issuance management method based on digital identity provided by the embodiment of the present specification is shown in Figure 1 The method mainly includes the following steps:

[0028] In step S101, the attribute information of the retired soldier provided by the application user is obtained, and the attribute information is sent to the designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information.

[0029] In actual preferential fund application, the application user can be a disabled retired soldier himself, or a family member of a deceased or sacrificed retired soldier. Because the standards for issuing preferential funds are different, the user needs to provide information when applying for preferential funds, so as to determine the level of preferential funds that can be applied for and the qualification for preferential funds according to the provided information.

[0030] In the application scenario of preferential fund issuance for retired soldiers, in addition to the personal information of the retired soldier, the attribute information of the retired soldier needs to be involved in the audit. The attribute information here can be the disability condition of the retired soldier, the rank condition of the retired soldier, and also can be the family relationship condition of the applicant and the retired soldier.

[0031] In an embodiment of the present specification, when the application user submits a preferential fund application request in the form of submitting personal information, the attribute information of the retired soldier also needs to be submitted. Therefore, the attribute information of the retired soldier submitted by the application user in the preferential fund request needs to be obtained. In the prior art, the attribute information provided by the user needs to be stamped by various levels of institutions and departments, but for special cases such as deceased and disabled retired soldiers, it is difficult to be on the scene for authentication, which leads to difficulty in identification of such special groups.

[0032] In an embodiment of the present disclosure, the user only needs to provide attribute information, and the attribute information provided by the application user is sent to a designated institution, and the designated institution authenticates the attribute information. It should be noted that if the attribute information is the disability condition of the retired soldier, the corresponding designated institution is a medical institution; if the attribute information is the family relationship between the application user and the retired soldier, the corresponding designated institution is a civil affairs department.

[0033] In an embodiment of the present disclosure, the attribute information is divided into designated attribute information and preset attribute information, wherein the designated attribute information is the information in the attribute information of the retired soldier that needs to be authenticated, for example, the specific disabled part and the disabled area, and the preset attribute information is the identity information of the retired soldier, for example, the name and identity card of the retired soldier. It should be noted that the identity information of the retired soldier should be included in the attribute information, so as to determine the identity of the retired soldier when authenticating the attribute.

[0034] The designated attribute information is encrypted using the public key of the designated institution, to obtain encrypted designated attribute information. Taking the attribute information of the disability condition as an example, that is, the public key of the designated medical institution is used to encrypt the disabled part and the disabled area, to obtain the encrypted designated attribute information. Since the disabled part and the disabled area are private data of the retired soldier, the private data is encrypted and sent to the medical institution, so as to avoid data leakage in the data transmission process.

[0035] The encrypted designated attribute information and the preset attribute information are sent to the designated institution, and the designated institution decrypts the encrypted private information according to the private key of the institution to obtain the designated attribute information. According to the identity information in the preset attribute information, the attribute file of the retired soldier is selected in the designated database. It should be noted that the designated database can be a local database of the medical institution, or a database stored in a block chain node in advance. In addition, due to the particularity of the identity of the retired soldier, the information of the soldier is generally placed in a database. The designated attribute information is compared with the information in the attribute file. If the designated attribute information is inconsistent with the information in the attribute file, it means that the attribute information provided by the user is not credible, and the authentication is not passed; if the designated attribute information is consistent with the information in the attribute file, it means that the attribute information provided by the user is credible, and the authentication is passed.

[0036] In step S102, after the authentication is passed, the attribute information is converted into attribute credentials.

[0037] In an embodiment of the present disclosure, after the authentication by the designated institution, the designated institution generates a signature for the attribute information. After receiving the authentication institution signature sent by the designated institution, the authentication institution signature is verified by the public key of the designated institution to determine whether the signature is a legal signature.

[0038] After the verification, the attribute signature is generated according to the authentication signature of the specified organization. The attribute signature is used to indicate that the organization authentication signature of the attribute information has passed the verification, and the specified organization is guaranteed to be a recognized and legitimate organization with the qualification of attribute information verification through the attribute signature, and the authenticity of the attribute information is further guaranteed.

[0039] In an embodiment of the present specification, the attribute signature is set at a specified position of the attribute information, which can be the beginning of the attribute information or the end of the attribute information, and the attribute credential is generated according to the attribute information to which the attribute signature is added.

[0040] In step S103, the initial digital identity corresponding to the veteran is updated according to the attribute credential to generate the current digital identity of the veteran.

[0041] In an embodiment of the present specification, the application user can send a preferential fund application request by submitting personal information. The personal information of the veteran is included in the application request. When the application user is the family member of the veteran who died or sacrificed, the personal information of the application user is also included in the application request. In the preferential fund application request, the personal information of the veteran is obtained, and the obtained personal information of the veteran is converted into the initial digital identity corresponding to the veteran.

[0042] It should be noted that the digital identity can be a distributed digital identity, which is a new digital identity solution that uses distributed infrastructure to change the original centralized control mode to distributed control, so that users obtain personal identity and data sovereignty. By using blockchain as the infrastructure of digital identity, the current enterprise-led data market can be changed, the use right and ownership of data are separated, so that users control and manage their own digital identity. Distributed digital identity (DID) includes two parts of distributed digital identifier and digital identity credential.

[0043] In an embodiment of the present specification, after obtaining the personal information of the veteran, the personal information of the veteran is converted into the initial digital identity corresponding to the veteran. The initial digital identity includes identity identifier, identity attribute and verification statement. Since the identity attribute information is missing at this stage, the identity attribute information and the corresponding position of the verification statement can be set as blank to facilitate subsequent data filling according to the attribute information of the veteran.

[0044] Specifically, the initial digital identity corresponding to the retired soldier includes: extracting multiple fields in the personal information of the retired soldier, dividing the multiple fields into text fields and numerical fields according to the field types; numbering the text fields and numerical fields according to the order of the text fields and numerical fields in the personal information; generating a random key, encrypting the text fields using the random key to generate text field ciphertext; obtaining a user public key, encrypting the numerical fields using the user public key to generate numerical field ciphertext; and sorting the corresponding text field ciphertext and the corresponding numerical field key according to the numbering of each text field and each numerical field to obtain the initial digital identity.

[0045] In an embodiment of the present specification, the personal information of the retired soldier includes various types of identity information such as name, age, military information, officer certificate number, and ID number, and the personal information related to the preferential fund distribution is screened out from the various types of identity information, such as name, officer certificate number, and military information. The fields in the extracted various types of information are extracted, and multiple text fields and numerical fields are obtained according to the field types. And numbering the text fields and numerical fields according to the order of the text fields and numerical fields in the personal information, for example, the officer certificate number: 000000, the text field "officer certificate number" is set to number 1, and the numerical field "000000" is set to number 1-1. A random key is generated, and it should be noted that the random key here can be any positive integer of any number of digits, and the text fields are encrypted using the random key to generate text field ciphertext. Obtain a user public key, encrypt the numerical fields using the user public key to generate numerical field ciphertext, and encrypt the numerical fields using the user public key. Only the user private key can be decrypted, and through the above method, the security of the personal information of the retired soldier is ensured. According to the numbering of each text field and each numerical field, the corresponding text field ciphertext and the corresponding numerical field key are sorted to obtain the initial digital identity. The obtained initial digital identity can be stored in the blockchain, so as to facilitate the application of preferential funds when the attribute information of the retired soldier changes.

[0046] In an embodiment of the present specification, the attribute information in the attribute certificate is obtained; the verification signature of the attribute information is obtained through the specified institution corresponding to the attribute information; the attribute information and the verification signature are taken as the attribute certificate, and the attribute certificate is added to a specified position in the initial digital identity to generate the current digital identity of the retired soldier.

[0047] In actual application scenarios, there may be a situation where the attribute information of the application user needs to be applied for preferential funds under the current circumstances after changing. In this scenario, the default initial digital identity includes the previous attribute information, and the attribute certificate under the current circumstances is added to the position of the initial attribute certificate in the initial digital identity to replace the attribute certificate.

[0048] In an embodiment of the present specification, when the application user registers the application account of the preferential fund, the identity authentication mode of the application user is set in advance, wherein the identity authentication mode includes any one or more of the security password authentication and the specified operation authentication, that is, authentication can be performed in the form of setting a security password, or authentication can be performed through a specified operation method, such as a gesture password, a mnemonic word, and the like. The authentication mode is described by taking the mnemonic word as an example. A plurality of mnemonic words are displayed to the user, and the user selects all the mnemonic words in sequence to form a sentence composed of a plurality of mnemonic words. The security password authentication can be performed first, and then the specified operation authentication can be performed.

[0049] In an embodiment of the present specification, when the security password input by the application user is consistent with the security password set in advance, and the current operation of the application user is consistent with the specified operation set in advance, the identity of the application user is authenticated, and the user key is sent to the application user, so that the initial digital identity generated in advance is obtained through the user key.

[0050] In step S104, the preferential fund level of the retired soldier is determined according to the attribute certificate in the current digital identity, so that the corresponding preferential fund is distributed to the retired soldier according to the preferential fund level of the retired soldier.

[0051] In an embodiment of the present specification, the current digital identity of the retired soldier includes personal information of the retired soldier, and also includes attribute certificates corresponding to the application of the preferential fund. The preferential fund distribution level of the retired soldier can be determined through the current digital identity. It should be noted that, in order to protect the privacy of the retired soldier, the attribute information of the retired soldier can be generated according to the current digital identity of the retired soldier. In the identification certificate, the specific attribute information of the retired soldier is not displayed. For example, the attribute information of the retired soldier includes the disability part and the disability area of the retired soldier, and only the identification level that meets the requirements of the retired soldier is displayed in the identification certificate. That is, the fund distribution department cannot see the specific disability condition of the retired soldier, and can only obtain the identification level information from the identification level.

[0052] In an embodiment of the present specification, after the identification certificate is generated according to the current digital identity of the retired soldier, the identification timestamp in the identification certificate of the retired soldier is obtained, and it is judged whether the identification timestamp is within the valid period. Generally, the valid period is usually set to 24 hours, and can also be set according to the specific situation. If the identification timestamp is within the valid period, the amount of the preferential fund to be distributed is determined according to the preferential fund level in the identification certificate.

[0053] In an actual application scenario, in order to avoid the occurrence of repeated issuance, an issuance voucher can be generated according to the issuance situation, and the issuance voucher is saved on a chain. In an embodiment of the present specification, an issuance voucher is generated according to the amount of the preferential treatment fund and the issuance time. After the issuance voucher is generated, the use key of the fund issuance department signs the issuance voucher, and the signed issuance voucher is stored in the blockchain; according to all signed issuance vouchers corresponding to the retired soldier in the blockchain, the preferential treatment fund issuance record of the current retired soldier is generated. It should be noted that the generated preferential treatment fund issuance record can be stored in the blockchain, and the data security of the preferential treatment fund issuance record is ensured by using the tamper-proof feature of the blockchain.

[0054] In an actual issuance scenario, there may be a situation that multiple family members of a retired soldier repeatedly apply. In order to avoid such a situation, it can be determined whether the preferential treatment fund has been received in the current period according to the preferential treatment fund issuance record. Therefore, when the amount of the preferential treatment fund to be issued is determined and issued, it is determined whether the amount of the preferential treatment fund to be issued has been issued by using the preferential treatment fund issuance record. Specifically, the preferential treatment fund record of the retired soldier is obtained, wherein the preferential treatment fund record includes multiple amounts of preferential treatment funds and multiple issuance times corresponding to the amounts of preferential treatment funds. The fund issuance period is generated according to the issuance time corresponding to each amount of preferential treatment fund. It is determined whether the current fund issuance period corresponding to the determination time stamp has been issued. If the current fund issuance period corresponding to the determination time stamp has not been issued, the amount of the preferential treatment fund to be issued is issued to the application user.

[0055] Through the above technical solution, the attribute information of the initial digital identity is updated, and the current digital identity is generated. The current digital identity includes not only the personal information and attribute information required for applying for the preferential treatment fund, but also the attribute voucher after the specified agency authentication. The operation steps of the application user are reduced, and the situation that the special groups such as the sick and dead retired soldiers, the sacrificed retired soldiers and the disabled retired soldiers cannot be present to issue the proof documents is avoided. The preferential treatment fund issuance qualification and the corresponding issuance level of the special groups such as the sick and dead retired soldiers, the sacrificed retired soldiers and the disabled retired soldiers are determined, and the workload of the approval department is reduced.

[0056] The embodiment of the present specification also provides a preferential treatment fund issuance management device based on a digital identity, as shown in Figure 2 The device includes at least one processor; and

[0057] a memory in communication connection with the at least one processor; wherein

[0058] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:

[0059] obtain attribute information of the retired soldier provided by an application user, and send the attribute information to a designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, wherein the attribute information includes disability information of the retired soldier; after the authentication is passed, convert the attribute information into attribute credentials, wherein the attribute credentials include an authentication signature of the designated institution on the attribute information; update an initial digital identity corresponding to the retired soldier according to the attribute credentials, to generate a current digital identity of the retired soldier; and determine a preferential fund level of the retired soldier according to the attribute credentials in the current digital identity, so that a fund issuing department issues corresponding preferential funds according to the preferential fund level of the retired soldier.

[0060] The embodiments of the present specification also provide a non-volatile computer storage medium, which stores computer executable instructions, and the computer executable instructions are configured to: obtain attribute information of the retired soldier provided by an application user, and send the attribute information to a designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, wherein the attribute information includes disability information of the retired soldier; after the authentication is passed, convert the attribute information into attribute credentials, wherein the attribute credentials include an authentication signature of the designated institution on the attribute information; update an initial digital identity corresponding to the retired soldier according to the attribute credentials, to generate a current digital identity of the retired soldier; and determine a preferential fund level of the retired soldier according to the attribute credentials in the current digital identity, so that a fund issuing department issues corresponding preferential funds according to the preferential fund level of the retired soldier.

[0061] Each of the embodiments in the present specification is described in a progressive manner, and the same and similar parts of each embodiment can be referred to each other. Each embodiment focuses on the difference from other embodiments. Especially, the device, equipment and non-volatile computer storage medium embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

[0062] The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different than the order in the embodiments and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing can be advantageous or possible.

[0063] The above merely provides one or more embodiments of the present specification and is not intended to limit the present specification. One of ordinary skill in the art can make various modifications and changes to one or more embodiments of the present specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of one or more embodiments of the present specification should be included in the scope of claims of the present specification.

Claims

1. A digital identity-based management method for the distribution of preferential treatment funds, characterized in that, The method comprises: obtaining attribute information of a retired military personnel provided by an application user, and sending the attribute information to a designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, wherein the attribute information comprises disability information of the retired military personnel; after authentication, converting the attribute information into attribute credentials, wherein the attribute credentials comprise an authentication signature of the attribute information by the designated institution; updating an initial digital identity corresponding to the retired military personnel according to the attribute credentials, to generate a current digital identity of the retired military personnel; determining a preferential fund level of the retired military personnel according to the attribute credentials in the current digital identity, so that a fund issuing department issues corresponding preferential funds according to the preferential fund level of the retired military personnel; after the fund issuing department issues the corresponding preferential funds according to the preferential fund level of the retired military personnel, the method further comprises: generating an issuing credential according to the amount and time of the preferential funds; signing the issuing credential using a key of the fund issuing department, and storing the signed issuing credential in a blockchain; generating a preferential fund issuing record of the current retired military personnel according to all signed issuing credentials in the blockchain; the fund issuing department issues the corresponding preferential funds according to the preferential fund level of the retired military personnel, specifically comprising: generating a determination credential according to the current digital identity of the retired military personnel, obtaining a determination timestamp in the determination credential of the retired military personnel, and determining whether the determination timestamp is within a valid period; if the determination timestamp is within the valid period, determining the amount of preferential funds to be issued according to the preferential fund level in the determination credential; obtaining a preferential fund issuing record of the retired military personnel, wherein the issued preferential fund record comprises multiple preferential fund amounts and the corresponding issuing times of the multiple preferential fund amounts; generating a fund issuing period according to the issuing time corresponding to each preferential fund amount; determining whether the current fund issuing period corresponding to the determination timestamp has been completed, and if not, issuing the amount of preferential funds to be issued to the application user.

2. The digital identity-based management method for the preferential fund distribution according to claim 1, characterized in that, Before updating the initial digital identity according to the attribute credentials, the method further comprises: pre-setting an identity authentication mode of the application user, wherein the identity authentication mode comprises any one or more of a security password authentication and a designated operation authentication; when the security password input by the application user is consistent with the pre-set security password, and the current operation of the application user is consistent with the pre-set designated operation, authenticating the identity of the application user, and sending a user key to the application user, so as to obtain the pre-generated initial digital identity through the user key.

3. The digital identity-based management method for the preferential fund distribution according to claim 1, characterized in that, and sending the attribute information to a designated institution corresponding to the attribute information, so that the designated institution authenticates the attribute information, specifically comprising: The attribute information is divided into specified attribute information and preset attribute information, wherein the specified attribute information is information in the attribute information of the retired soldier that needs to be authenticated, and the preset attribute information is identity information of the retired soldier; The specified attribute information is encrypted using an institution public key of the specified institution to obtain encrypted specified attribute information; The encrypted specified attribute information and the preset attribute information are sent to the specified institution, so that the specified institution decrypts the encrypted private information according to an institution private key to obtain the specified attribute information; According to the identity information in the preset attribute information, an attribute file of the retired soldier is selected in a specified database; The specified attribute information is compared with the attribute file, so that the attribute information is authenticated.

4. The digital identity-based management method for the preferential fund distribution according to claim 3, characterized in that, After the authentication is passed, the attribute information is converted into an attribute credential, and specifically includes: An authentication institution signature sent by the specified institution is received, and the authentication institution signature is verified through an institution public key corresponding to the specified institution; After verification, an attribute signature corresponding to the authentication signature of the specified institution is generated, wherein the attribute signature is used to indicate that the authentication institution signature corresponding to the attribute information passes the verification; The attribute signature is set at a specified position of the attribute information to generate an attribute credential.

5. The digital identity-based management method for the preferential fund distribution according to claim 1, characterized in that, Before the initial digital identity corresponding to the retired soldier is updated according to the attribute credential, the method further includes: A plurality of fields in personal information of the retired soldier are extracted, and the plurality of fields are divided into text fields and numerical value fields according to field types; The text fields and the numerical value fields are numbered according to an order of the text fields and the numerical value fields in the personal information; A random key is generated, and the text fields are encrypted using the random key to generate text field ciphertexts; A user public key is obtained, and the numerical value fields are encrypted using the user public key to generate numerical value field ciphertexts; According to the number of each text field and each numerical value field, the corresponding text field ciphertext and the corresponding numerical value field key are sorted to obtain the initial digital identity.

6. The digital identity-based management method for the preferential fund distribution according to claim 4, characterized in that, According to the attribute credential, the initial digital identity is updated to generate a current digital identity of the retired soldier, and specifically includes: Attribute information in the attribute credential is obtained; The verification signature of the attribute information is obtained through the specified institution corresponding to the attribute information; The attribute information and the verification signature are taken as the attribute credential, and the attribute credential is added to a specified position in the initial digital identity to generate the current digital identity of the retired soldier.

7. A digital identity-based preferential fund distribution management device, characterized by, The device includes: at least one processor; and a memory connected with the at least one processor in communication; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-6.

8. A non-transitory computer storage medium having stored computer-executable instructions configured to perform the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Livelihood capital management system

    CN107274097A

  • Identity attribute certification system and method for privacy protection

    CN108769020A

  • Distributed digital identity system based on block chain

    CN110060037A