A method for corresponding the user identity identifier of an informatization application system to a blockchain account
By corresponding to the user identity identification of the information application system with the blockchain chain account, the security and credibility of the user identity identification during operation is solved, and higher security and credibility are achieved, and it is applicable to a wide range of IT or DT fields.
Patent Information
- Application Number
- CN202210315843.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-03-29
- Filing Date
- 2022-03-28
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-03-28
AI Technical Summary
In an information application system, how to improve the security and credibility of user identity identification, especially in a wider field, the prior art is difficult to effectively solve the security problems of users during operation.
Through a method, the user identity identification of the information application system is corresponded to the blockchain chain account. The specific steps include registering a user, generating a public and private key, sending a public and digital signature to the CA server, verifying a digital signature, generating a user certificate and verifying a certificate signature, and finally saving the certificate in the U-Shield.
It significantly improves the security and trustworthiness of user identity identification during use, ensures the security and trustworthiness of user names through blockchain technology, and makes this method suitable for various IT or DT fields.
Smart Images

Figure CN114900309B_ABST
Abstract
Description
Technical Field
[0001] This disclosure belongs to the field of information security, and particularly relates to a method for corresponding the user identity identifier of an information application system to a blockchain account. Background Art
[0002] With the continuous development of information technology, the problems exposed in current information security are also increasing. Although products such as USB tokens have been widely used in financial fields such as securities and banking to improve security, how to enable users to operate more securely in a wider range of fields remains an urgent problem to be solved. Summary of the Invention
[0003] In view of this, this disclosure discloses a method for corresponding the user identity identifier of an information application system to a blockchain account, including the following steps:
[0004] S100: Register a user:
[0005] Input the username, send a user registration request to the CA server of the blockchain. The CA server queries whether the username already exists. If it exists, it prompts that registration is not allowed. If it does not exist, the registration of this username continues;
[0006] S200: Generate the public key and private key of the user:
[0007] The first service generates the public key and private key of the user through a public-private key generation algorithm;
[0008] S300: Send the public key, username, and digital signature to the CA server:
[0009] The first service reads the public key, signs the public key and username, calculates the first hash value based on the public key and username, and then signs this first hash value with the private key to generate the first digital signature;
[0010] And send the public key, username, and the first digital signature to the CA server;
[0011] S400: Verify the first digital signature:
[0012] The CA server decrypts the first digital signature with the public key sent in step S300 to obtain the first hash value,
[0013] And the CA server calculates the second hash value based on the hash value of the public key and username. If the first hash value is equal to the second hash value, it indicates that the public key and username have not been tampered with, and the signature verification passes;
[0014] S500: Generate the user's certificate:
[0015] The CA server generates a certificate for the user, where the certificate includes a second digital signature;
[0016] Calculate the hash value of the certificate, and then sign the hash value of the certificate with the private key of the CA server to generate the second digital signature;
[0017] And the CA server returns the certificate;
[0018] S600: Verify the second digital signature:
[0019] The first service decrypts the second digital signature using the public key of the CA server to obtain a third hash value, and calculates the hash value of the certificate to obtain a fourth hash value. If the third hash value is equal to the fourth hash value, the signature verification passes;
[0020] If the verification passes, the first service saves the certificate.
[0021] Preferably,
[0022] In step S600, the first service saves the certificate in the USB key, so that the storage medium is implemented as a blockchain USB key.
[0023] Preferably,
[0024] Register the user by registering the blockchain USB key.
[0025] Preferably,
[0026] The first service is a USB key service.
[0027] Preferably,
[0028] In step S200, the USB key service calls the key generation interface in the blockchain USB key, so that the blockchain USB key generates a public key and a private key through the public-private key generation algorithm.
[0029] Through the above method, the present disclosure significantly improves the security and credibility of the user identity identifier during use, and can be used in various IT or DT fields. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 is a schematic flowchart of an embodiment of the present disclosure;
[0031] Figure 2 is a schematic structural diagram of a shield in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0032] In order to enable those skilled in the art to understand the technical solutions disclosed in the present disclosure, the following will be combined with embodiments and relevant drawings Figures 1 to 2, the technical solutions of each embodiment are described. The described embodiments are part of the embodiments of the present disclosure, rather than all of the embodiments. The terms "first", "second", etc. used in the present disclosure are for distinguishing different objects, rather than for describing a specific order. In addition, "including" and "having" and any variations thereof are intended to cover and inclusively include without exclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include unlisted steps or units, or may optionally further include other steps or units inherent to these processes, methods, systems, products, or devices.
[0033] Reference to "embodiment" herein means that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the present disclosure. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art can understand that the embodiments described herein can be combined with other embodiments.
[0034] In one embodiment, the present disclosure discloses a method for corresponding the user identity identifier of an information application system with a blockchain account, including the following steps:
[0035] S100. Register a user:
[0036] Enter a username and send a user registration request to the CA server of the blockchain. The CA server queries whether the username already exists. If it exists, it prompts that registration is not allowed. If it does not exist, the registration of this username continues;
[0037] S200. Generate the public key and private key of the user:
[0038] The first service generates the public key and private key of the user through a public-private key generation algorithm (such as SM2, SM3, SM4, or other algorithms);
[0039] S300. Send the public key, username, and digital signature to the CA server:
[0040] The first service reads the public key, signs the public key and username, calculates the first hash value based on the public key and username, and then signs the first hash value with the private key to generate the first digital signature;
[0041] And send the public key, username, and the first digital signature to the CA server;
[0042] S400: Verify the first digital signature:
[0043] The CA server decrypts the first digital signature using the public key sent in step S300 to obtain the first hash value.
[0044] Moreover, the CA server calculates a second hash value based on the public key and the hash value of the username. If the first hash value is equal to the second hash value, it indicates that the public key and the username have not been tampered with, and the signature verification passes.
[0045] S500: Generate a user certificate:
[0046] The CA server generates a certificate for the user, where the certificate includes a second digital signature.
[0047] Calculate the hash value of the certificate, and then sign the hash value of the certificate with the private key of the CA server to generate the second digital signature.
[0048] Moreover, the CA server returns the certificate.
[0049] S600: Verify the second digital signature:
[0050] The first service decrypts the second digital signature using the public key of the CA server to obtain a third hash value, and calculates the hash value of the certificate to obtain a fourth hash value. If the third hash value is equal to the fourth hash value, the signature verification passes.
[0051] If the verification passes, the first service saves the certificate.
[0052] Thus, through the above embodiments, the present disclosure realizes a method for corresponding the user identity identifier of an information application system with a blockchain account, thereby improving the security and trust level of the associated username via blockchain technology. This means that any operation and usage trace of the username can be further verified via the blockchain for its usage status. In addition, since the certificate is stored, this method can be used in various secure interaction scenarios. Considering that the username is associated with the chain, this embodiment realizes a secure and reliable processing method for user identity identifiers based on blockchain.
[0053] Furthermore, if sensitive information such as certificates is saved to a USB flash drive or other removable storage devices through the first service, especially storage devices whose own security level has reached a certain level, such as saving to a USB key to obtain a blockchain USB key, then when the blockchain USB key can be called by any external system or external interface outside the key, for example, when the external interface is the corresponding interface of various Web Services, this key can be used for various Web Services, thereby greatly improving the security of users using various Web Services and effectively controlling various user identity identifiers.
[0054] Preferably,
[0055] Register users by registering the blockchain USB token.
[0056] Preferably,
[0057] The first service is a USB token service.
[0058] Preferably,
[0059] In step S200, the USB token service calls the key generation interface in the blockchain USB token, so that the blockchain USB token generates a public key and a private key through an algorithm for generating public and private keys (such as the SM2 algorithm. It can be understood that the SM2 algorithm can also be replaced by SM3, SM4 or other algorithms as needed).
[0060] In another embodiment,
[0061] The blockchain USB token can also be implemented as a blockchain-based token other than the USB interface, such as a token based on Bluetooth or audio interface.
[0062] In another embodiment,
[0063] The blockchain-based token can also be implemented as a software digital token other than a hardware entity token.
[0064] When it is a software digital token, the digital token includes at least one or more interfaces for interacting with systems or interfaces outside the digital token.
[0065] It can be understood that typically, a hardware entity token can be various products with hardware interfaces, such as a hardware entity token in the form of a USB flash drive, or a card-type unified authentication with a USB interface, or a hardware entity token with a Bluetooth interface or an audio interface. However, it should be further noted that a software digital token can be digital files in various formats, and its interface is implemented by a digital interface for reading and writing files or other suitable API technologies, so as to realize the interaction between the software digital token and systems or interfaces outside the digital token through access to such digital files. Obviously, hardware entity tokens generally have higher security than software digital tokens. However, this does not prevent the present disclosure from adopting existing digital encryption technologies, monitoring technologies or other digital security technologies to improve the security of software digital tokens.
[0066] In one embodiment, the present disclosure discloses a blockchain-based token, including:
[0067] A key generation interface, which is used to be called by a first interface outside the token, and generate a user public key and a user private key according to a user name and a first algorithm and store them in the key storage unit of the token;
[0068] Exemplarily, the first interface is a USB token service interface, including: interfaces provided by Services corresponding to various services such as the USB token service of a bank and the USB token service for online government office work; and the first algorithm may be the SM2 algorithm or other national cryptographic algorithms (such as SM3, SM4) or any other algorithms, etc.;
[0069] Wherein, when the token is registered to the blockchain, the user name is pre-checked by the CA server for duplication. When it is confirmed that there is no identical user name, this user name is used as the user name associated with the token, and then the key generation interface is called by the first interface.
[0070] Thus, through the above embodiments, the present disclosure realizes a token based on the blockchain. As a product, it facilitates the association or correspondence between the user identity identifier and the blockchain through this product. This means that the token can further verify the usage status of relevant user identity identifiers in information application systems or even any digital world via the blockchain. In addition, the key storage unit of the token itself stores the user public key and user private key generated according to the user name and the first algorithm, so that the token can be used in various security interaction scenarios. Considering that the user name is associated with the chain, this embodiment realizes a secure and reliable token based on the blockchain and can be called by the first interface outside the token. It can be understood that when the first interface is the corresponding interface of various Web Services, the token can be used for various Web Services, thereby greatly improving the security of users' use of various Web Services.
[0071] In another embodiment,
[0072] The token further includes a first hash value calculation unit and a first signature unit;
[0073] The first hash value calculation unit is used to calculate a first hash value according to the user name and the user public key;
[0074] The first signature unit is used to generate a first digital signature for the first hash value according to the user private key.
[0075] For the above embodiments, it gives a way to further utilize the hash technology of the blockchain to implement the first digital signature on the token, so that the token becomes a product with more blockchain characteristics.
[0076] In another embodiment,
[0077] The token further includes a first sending unit;
[0078] The first sending unit sends at least the user public key and the first digital signature to the CA server via the first interface.
[0079] It can be understood that in this embodiment, the first sending unit and the first interface are used to send relevant signatures to the CA server. Exemplarily, the first interface is a USB key service interface. In this way, the USB key docks with the CA server through the first interface docked to it, and the first interface can be an interface facing various Web Services or even various applications, which means that the USB key can be widely used in various services and / or applications. It should be noted that the CA server can be a server independent of the blockchain or a CA server of the blockchain.
[0080] In another embodiment,
[0081] The USB key further includes a certificate storage unit.
[0082] After the first interface uses the public key of the CA server to verify the signature through the first digital signature, the storage unit stores the user name and the user certificate generated by the CA server.
[0083] For this embodiment, it reveals how the USB key based on the blockchain as a new type of USB key generates and stores its user certificate as described above.
[0084] In another embodiment,
[0085] The USB key includes a national cryptography security chip module, and the national cryptography security chip includes a key generation function, and / or an encryption function, and / or a signature function.
[0086] It can be understood that when using the national cryptography security chip module, the USB key based on the blockchain can be implemented more quickly through various existing national cryptography security chip modules with higher integration.
[0087] In another embodiment,
[0088] The USB key further includes a second sending unit;
[0089] When the USB key is coupled to an external data processing system, at a certain time or during a certain period, the second sending unit sends at least the user name stored in the USB key, the user's operations on the data processing system, and time information (such as a timestamp) to the blockchain for uploading through the first interface (such as the USB key service interface described above as the first interface).
[0090] For this embodiment, it reveals how the USB key interacts with the blockchain through the second sending unit when the USB key is used for secure interaction with a certain data processing system, such as how to upload relevant user information to the blockchain.
[0091] In another embodiment,
[0092] The second sending unit also sends the user's operations on the shield to the blockchain for uploading to the chain.
[0093] It can be understood that this embodiment shows that the shield can upload the user's operations on the shield to the chain. For example, assume that the shield includes an "ok" or "confirm" button. When the user presses the ok button once at a certain moment, this operation on the shield itself is also sent to the blockchain for uploading to the chain.
[0094] In another embodiment,
[0095] The shield further includes a second hash value calculation unit and a second signature unit;
[0096] The second hash value calculation unit is at least used to calculate a second hash value according to the username stored in the shield, the user's operations on the data processing system, time information, and the user's public key;
[0097] The second signature unit is used to generate a second digital signature for the second hash value according to the user's private key;
[0098] The second sending unit also sends the second digital signature to the blockchain for uploading to the chain.
[0099] For the above embodiment, it gives a way to further utilize the hash technology of the blockchain to implement the second digital signature on the shield, so that the shield becomes a product with more blockchain characteristics and realizes the uploading of the second digital signature to the chain.
[0100] In another embodiment, see Figure 2 , the blockchain-based shield described in the present disclosure is a consortium chain hardware U shield based on the national cryptography algorithm, including:
[0101] MCU main control chip module, universal serial bus USB, national cryptography security chip module, Bluetooth module, screen display module, keys, and battery module;
[0102] The MCU main control chip module serves as the main control unit, which is used to connect the national cryptography security chip module, Bluetooth module, screen, keys, and universal serial bus USB, and is used to parse the data sent through channels (such as through the universal serial bus USB, Bluetooth, etc.) and hand it over to a dedicated module for processing;
[0103] The national cryptography security chip module includes corresponding processing units and storage units, and is at least used to implement data storage functions, key generation and management functions, and encryption functions;
[0104] The universal serial bus USB or Bluetooth module is used to receive / send the interaction data between the external system or external interface of the shield and the U shield;
[0105] A screen display module, which is used to cooperate with the MCU main control chip module and the national cryptography security chip module to display operation information from users (such as account, transaction amount, etc.);
[0106] A key, which is used to cooperate with the MCU main control chip module and the national cryptography security chip module to implement user interaction functions (such as power on / off, confirmation, cancellation, up / down page turning, inputting PIN code, etc.);
[0107] A battery module, which is used to supply power to the U shield.
[0108] It can be understood that through the example of the specific hardware U shield, this embodiment discloses a way to implement the blockchain-based shield.
[0109] Furthermore, in another embodiment,
[0110] When the blockchain-based shield described in the present disclosure is implemented as a digital shield, in addition to the content related to the digital shield described above, the data processing ability of the digital shield can utilize the processing ability of the CPU or other processors of the device, equipment, computer, data processing system, cloud server, etc. where the digital shield is located, or can also utilize the processing ability of the external system that calls the digital shield itself; and the storage ability required by the digital shield can utilize the storage ability of the device, equipment, computer, data processing system, cloud server, etc. where the digital shield is located, or can also utilize the storage ability of the external system that calls the digital shield itself; as for the interaction interface required by the digital shield, it can be implemented by using I / O reading and writing for accessing digital files; if it is necessary to display such an interaction process, it can be implemented by using any display device that can receive the necessary information flow or data flow (such as the operation information of each other) generated during the interaction between the digital shield and the external system (or external interface), and when it is not necessary to display, the information flow or data flow generated during the interaction can also be saved as a file in a certain format (such as an operation log file).
[0111] Those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions, modules, and units involved are not necessarily essential to the present invention.
[0112] In the above embodiments, the descriptions of each embodiment have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0113] In several embodiments provided by the present disclosure, it should be understood that the disclosed shield can be implemented as corresponding functional units, processors, or even systems. Each part of the system can be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Additionally, each functional unit can be integrated into a processing unit, exist independently, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or software functional units. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which can be a smart phone, personal digital assistant, wearable device, laptop computer, tablet computer) to execute all or part of the steps of the methods described in the various embodiments of the present disclosure. The aforementioned storage medium includes: USB flash drives, read-only memories (ROM), random access memories (RAM), mobile hard disks, magnetic disks, or optical discs, etc., various media that can store program codes, and is not limited to different interfaces or transmission methods such as USB, Bluetooth, or audio.
[0114] As described above, the above embodiments are only used to illustrate the technical solutions of the present disclosure and are not intended to limit them. Although the present disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present disclosure.
Claims
1. A method for corresponding the user identity identifier of an information application system with a blockchain account, including the following steps: S100: Register a user: Input the username and send a user registration request to the CA server of the blockchain. The CA server queries whether the username already exists. If it exists, it prompts that registration is not allowed. If it does not exist, the registration of this username continues; S200: Generate the public key and private key of the user: The first service generates the public key and private key of the user through a public-private key generation algorithm, including SM2, SM3, and SM4; S300: Send the public key, username, and digital signature to the CA server: The first service reads the public key, signs the public key and username, calculates the first hash value based on the public key and username, and then signs the first hash value with the private key to generate the first digital signature; And send the public key, username, and the first digital signature to the CA server; S400: Verify the first digital signature: The CA server decrypts the first digital signature with the public key sent in step S300 to obtain the first hash value, And, the CA server calculates the second hash value based on the public key and username. If the first hash value is equal to the second hash value, it means that the public key and username have not been tampered with, and the signature verification passes; S500: Generate the user's certificate: The CA server generates a certificate for the user, where the certificate includes the second digital signature; Calculate the hash value of the certificate, and then sign the hash value of the certificate with the private key of the CA server to generate the second digital signature; And, the CA server returns the certificate; S600: Verify the second digital signature: The first service decrypts the second digital signature with the public key of the CA server to obtain the third hash value, and calculates the hash value of the certificate to obtain the fourth hash value. If the third hash value is equal to the fourth hash value, the signature verification passes; If the verification passes, the first service saves the certificate; Wherein, In step S600, the first service saves the certificate in a USB key, so that the storage medium is implemented as a blockchain USB key; Wherein, The user is registered by registering the blockchain USB key; Wherein, The first service is a USB key service; Wherein, In step S200, the USB key service calls the key generation interface in the blockchain USB key, so that the blockchain USB key generates a public key and a private key through a public-private key generation algorithm; Wherein, the blockchain USB key is a shield based on the blockchain, including: A key generation interface, which is used to be called by a first interface outside the shield, and generates a user public key and a user private key according to the username and the first algorithm and stores them in the key storage unit of the shield; Wherein, the first interface is a USB key service interface, including: interfaces provided by Services corresponding to various services such as the USB key service of a bank and the USB key service of online government affairs office; Wherein, when the shield is registered to the blockchain, the username is pre-checked by the CA server. When it is confirmed that there is no same username, this username is used as the username associated with the shield, and then the key generation interface is called by the first interface; Wherein, the shield includes a first sending unit; The first sending unit sends at least the user public key and the first digital signature to the CA server via the first interface; The shield further includes a second sending unit; When the shield is coupled to a certain data processing system outside it, at a certain time or during a certain time period, the second sending unit sends at least the user name stored in the shield, the operations of the user on the data processing system, and the timestamp to the blockchain for uploading to the chain via the first interface; The method improves the security and credibility of the associated user name via blockchain technology, which means that any operation and usage trace of the user name can be further verified for its usage status via the blockchain subsequently; in addition, since the certificate is stored, the method can be used in various security interaction scenarios; considering that the user name is associated with the chain, the method realizes a secure and reliable processing method for user identity identification based on blockchain; Saving the certificate to the USB shield through the first service obtains a blockchain USB shield. Then, when the blockchain USB shield can be called by any external system or external interface outside the shield, when the external interface is the corresponding interface of various Web Services, the shield can be used for various Web Services, thereby greatly improving the security of users using various Web Services and effectively managing various user identity identifications.
Citation Information
Patent Citations
Identity authentication method and system based on block chain and storage medium
CN110519062A
Identity association method based on block chain
CN111027036A
Service authorization method and device, computer equipment and storage medium
CN111708991A