Methods, devices, equipment and storage media for entity identity management and credit assessment
By establishing mapping relationships and credit contract calls between entities within the blockchain system, the interoperability problem of entity identity systems in distributed systems is solved, achieving comprehensiveness and accuracy in cross-domain identity authentication and credit assessment.
Patent Information
- Application Number
- CN202210273342.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-18
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2042-03-18
AI Technical Summary
The existing entity identity system lacks identity information interoperability within a distributed system, making it difficult to meet cross-domain identity authentication requirements, and credit assessment has limitations.
Within the blockchain system, a mapping relationship is established between network entities and their associated entities. By calling the identity contract through the credit contract within the blockchain system, behavioral data is obtained, and a credit score is determined.
It enables comprehensive and convenient management among different entities, and improves the comprehensiveness and accuracy of entity credit assessment.
Smart Images

Figure CN114925341B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, specifically to a method, apparatus, device, and storage medium for entity identity management and credit assessment. Background Technology
[0002] With the rapid development of technologies such as the Internet of Things, the Internet, and big data, information interaction among users across various social applications is increasing daily. Therefore, to ensure the security of this information exchange, it is typically necessary to reliably identify the identities of users on both sides of the exchange, thereby establishing mutual trust between different users on social networks.
[0003] Currently, when users have corresponding business needs across various distributed business applications, they often frequently register identity accounts within different distributed systems. This results in a lack of interoperability of identity information within the existing identity system, making it difficult to meet users' cross-domain identity authentication needs. Furthermore, when using the existing identity system to assess the creditworthiness of individual users, certain "data silos" exist, limiting the current credit assessment capabilities. Summary of the Invention
[0004] This application provides a method, apparatus, device, and storage medium for entity identity management and credit assessment. It establishes a mapping relationship between the two related entities within their respective identity contracts, thereby more realistically and accurately reflecting the relationship between different entities, ensuring comprehensive and convenient management of different entity identities, and improving the comprehensiveness and accuracy of entity credit assessment.
[0005] In a first aspect, embodiments of this application provide an entity identity management method applied to a blockchain system, the method comprising:
[0006] In response to an identity management request from any network entity, a mapping relationship is established between the network entity and its associated entities within the first identity contract generated by the network entity on the blockchain system.
[0007] A mapping relationship between the associated entity and the network entity is established within the second identity contract already generated on the blockchain system by the associated entity.
[0008] Secondly, embodiments of this application provide an entity credit assessment method applied to a blockchain system, the method comprising:
[0009] In response to a credit assessment request for any network entity, obtain the identity contract generated for the network entity using the entity identity management method provided in the first aspect above;
[0010] The associated entities of the network entity are identified by invoking the identity contract of the network entity through the credit contract already generated within the blockchain system;
[0011] The network entity's behavioral data within the associated entity is obtained through the credit contract;
[0012] Based on the behavioral data, a credit score is determined for the network entity.
[0013] Thirdly, embodiments of this application provide an entity identity management device configured in a blockchain system, the device comprising:
[0014] The first identity management module is used to respond to the identity management request of any network entity and establish a mapping relationship between the network entity and its associated entities within the first identity contract generated by the network entity on the blockchain system.
[0015] The second identity management module is used to establish a mapping relationship between the associated entity and the network entity within the second identity contract generated by the associated entity on the blockchain system.
[0016] Fourthly, embodiments of this application provide an entity credit assessment device configured in a blockchain system, the device comprising:
[0017] The identity contract determination module is used to obtain the identity contract generated for the network entity using the entity identity management method provided in the first aspect above in response to a credit assessment request for any network entity.
[0018] The associated entity determination module is used to determine the associated entities of the network entity by invoking the identity contract of the network entity through the credit contract generated within the blockchain system.
[0019] The data acquisition module is used to acquire the behavioral data of the network entity within the associated entity through the credit contract;
[0020] The credit assessment module is used to determine the credit score of the network entity based on the behavioral data.
[0021] Fifthly, embodiments of this application provide an electronic device, which includes:
[0022] A processor and a memory, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the entity identity management method provided in the first aspect of this application, or the entity credit assessment method provided in the second aspect of this application.
[0023] In a sixth aspect, embodiments of this application provide a computer-readable storage medium for storing a computer program that causes a computer to execute an entity identity management method as provided in the first aspect of this application, or an entity credit assessment method as provided in the second aspect of this application.
[0024] In a seventh aspect, embodiments of this application provide a computer program product, including a computer program / instructions, characterized in that, when the computer program / instructions are executed by a processor, they implement the entity identity management method provided in the first aspect of this application, or the entity credit assessment method provided in the second aspect of this application.
[0025] This application provides a method, apparatus, device, and storage medium for entity identity management and credit assessment. When managing the identity of any network entity, a mapping relationship between the network entity and its associated entities is established within the blockchain system in the first identity contract of the network entity. A mapping relationship between the associated entity and the network entity is also established in the second identity contracts of each associated entity. This more accurately reflects the relationships between different entities and ensures comprehensive and convenient management of different entity identities using the blockchain system. Furthermore, by calling the identity contracts of different entities through the credit contract within the blockchain system, the behavioral data of any network entity is comprehensively obtained to determine its credit score, ensuring the comprehensiveness and accuracy of entity credit assessment. Attached Figure Description
[0026] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a flowchart illustrating an entity identity management method according to an embodiment of this application;
[0028] Figure 2 This is a schematic diagram illustrating the entity identity management architecture in an embodiment of this application;
[0029] Figure 3 This is a flowchart illustrating an entity credit assessment method as shown in an embodiment of this application;
[0030] Figure 4 This is a schematic block diagram illustrating an entity identity management device according to an embodiment of this application;
[0031] Figure 5 This is a schematic block diagram illustrating a physical credit assessment device according to an embodiment of this application;
[0032] Figure 6 This is a schematic block diagram of the electronic device provided in the embodiments of this application. Detailed Implementation
[0033] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.
[0035] Considering that existing entity identity systems lack interoperability within distributed systems, making it difficult to meet users' cross-domain identity authentication needs, and that using existing entity identity systems for credit assessment has certain limitations, this application introduces a blockchain system to construct identity systems for different entities. While establishing a mapping relationship between any network entity and its associated entities within the first identity contract of the blockchain system, a mapping relationship between each associated entity and its network entity is also established within the second identity contract of the blockchain system. This more accurately reflects the relationships between different entities and ensures comprehensive and convenient management of different entity identities. Simultaneously, by calling the identity contracts of different entities through the credit contract within the blockchain system, behavioral data of any network entity is obtained to determine its credit score, improving the comprehensiveness and accuracy of entity credit assessment.
[0036] Figure 1 This is a flowchart illustrating an entity identity management method according to an embodiment of this application. (Refer to...) Figure 1 The method may specifically include the following steps:
[0037] S110, in response to any identity management request from a network entity, establishes a mapping relationship between the network entity and its associated entities within the first identity contract already generated by the network entity on the blockchain system.
[0038] Considering that information exchange in different scenarios may involve interactions between multiple users, between a single user and an organization within a supply chain, or between multiple organizations within any supply chain, both parties in any scenario need to assess each other's creditworthiness within the network system to ensure the security of information exchange. Therefore, the network entity in this application can be any user or organization within a supply chain that requires credit assessment, such as a company or an individual within a company within a supply chain.
[0039] As an optional implementation of this application, the associated entity of each network entity can be an entity that can record various behavioral data performed by the network entity during the interaction process when interacting with the network entity.
[0040] On the one hand, if a network entity is any user, various organizations will authorize the corresponding user, allowing the user to register a personal account within each authorized organizational structure. Then, the user logs in to that personal account to perform corresponding business within that organization. At this point, the user can perform corresponding business across multiple organizations, generating various behavioral data, which is then stored within the respective organizations. Therefore, when a network entity is any user, its associated entities can be the various organizations used to record the behavioral data performed by that user. For example, user X could be an employee of company A or a member of a product of company B; therefore, when user X is a network entity, its associated entities could be company A and company B.
[0041] On the other hand, if the network entity is an organization within any supply chain, since multiple users exist within the organization, and the user end, as a lower-level application of the organization, does not record the organization's behavioral data. Therefore, if the network entity is an organization within a supply chain, such as a company, its associated entities will not be users. In this case, considering the business transactions between organizations within the same supply chain, and to ensure the normal operation of the organization, it will register corresponding accounts with various public service entities such as authorized patent offices and tax offices. Then, companies and other organizations log in to these accounts to execute corresponding business within these public service entities. At this time, when organizations within the same supply chain execute corresponding business transactions, they will store shared behavioral data on both sides. The behavioral data generated by the organization executing corresponding business within the public service entity will also be stored within that public service entity. Therefore, if the network entity is an organization within any supply chain, its associated entities are other organizations within the same supply chain as the network entity, that is, other organizations upstream and downstream of the network entity's supply chain.
[0042] It should be noted that, to ensure the decentralization and security of different entity identities, this application will use a blockchain system to construct the identity system for each network entity. First, to accurately distinguish each network entity within the blockchain system, this application will generate a unique decentralized identity (DID) for each network entity. Then, each network entity uses its DID to initiate a corresponding identity request to the blockchain system, thereby generating an identity contract for each network entity on the blockchain system. This identity contract records the network entity's DID, the accounts registered by the network entity with various associated entities, and the behavioral data of other network entities related to the network entity within that network entity.
[0043] As an optional implementation of this application, when it is necessary to manage the identity information of each network entity within the blockchain system, the network entity will proactively initiate a corresponding identity management request to the blockchain system. In order to accurately describe the identity contracts of the network entity and its associated entities during the identity management process, this application will use the identity contract of the network entity currently initiating the identity management request to the blockchain system as the first identity contract, and the identity contracts of each of the network entity's associated entities as the second identity contracts, for ease of differentiation.
[0044] Furthermore, upon receiving an identity management request from any network entity, the blockchain system first retrieves the first identity contract already generated by that network entity on the blockchain system. Then, using the account information already present under the network entity's own DID, it identifies all associated entities. Next, it establishes a mapping relationship between the network entity and each associated entity within the network entity's first identity contract, enabling the rapid retrieval of each associated entity according to this mapping relationship. For example, if the network entity initiating the identity management request is a user, then the first identity contract establishes a mapping relationship between the user and each enterprise registered with that user's account. If the network entity initiating the identity management request is an organization, then the first identity contract establishes a mapping relationship between the organization and each public service entity registered with that organization's account, as well as mapping relationships between the organization and other organizations in the upstream and downstream of the supply chain.
[0045] As an optional implementation scheme in this application, considering that each network entity needs to register different accounts in different associated entities under different scenarios to be granted different business permissions, each network entity can correspond to multiple accounts under one DID to distinguish associated entities under different scenarios and to be granted different business permissions in different associated entities.
[0046] For example, user X is an employee of company A and also a member of a product of company B. User X has multiple accounts, such as account1 and account2. Here, account1 represents user X's identity under company A, and account2 represents user X's membership status in a product of company B.
[0047] Therefore, establishing a mapping relationship between the network entity and each associated entity within the first identity contract of the network entity can be specifically achieved by: binding the account identifier generated by the network entity with the identity identifier of the network entity within the first identity contract; and setting the identity identifier of the associated entity pointed to by each account identifier to obtain the mapping relationship between the network entity and the associated entities.
[0048] In other words, such as Figure 2As shown, the process first retrieves the accounts registered by the network entity that initiated the identity management request to the blockchain system across various associated entities. Then, within the first identity contract, each account identifier generated by the network entity is bound to its own identity identifier (DID). Simultaneously, based on the registration status of each account across different associated entities, the associated entity pointed to by each account identifier bound to the network entity's identity identifier (DID) can be determined. Furthermore, for each account identifier bound to the network entity's identity identifier (DID), the identity identifier (DID) of the associated entity pointed to by that account identifier is further set. Thus, by using the different accounts registered by the network entity across various associated entities, the network entity can be associated with each associated entity, obtaining the mapping relationship between the network entity and each associated entity.
[0049] It should be noted that, in this application, after a network entity registers corresponding accounts on each associated entity and generates public-private key pairs and account identifiers for each account, the network entity can initiate a corresponding identity management request to the blockchain system by invoking its own primary identity contract. Therefore, in this application, any identity management request from a network entity can be a call operation performed by that network entity on its own primary identity contract on the blockchain system.
[0050] S120 establishes a mapping relationship between the associated entity and the network entity within the second identity contract that the associated entity has generated on the blockchain system.
[0051] To ensure the interconnectivity of identities among different entities within the blockchain system, after establishing the mapping relationship between the network entity and each associated entity within the first identity contract of the network entity, the second identity contracts already generated by each associated entity on the blockchain system are further obtained. Then, according to the mapping relationship between the network entity and the associated entity within the first identity contract, a mapping relationship between the associated entity and the network entity is simultaneously established within the second identity contract. This ensures that the identity information of the other party can be quickly determined according to this mapping relationship within the identity contracts of both the network entity and the associated entity.
[0052] It should be noted that, to ensure the authenticity of the processing of the second identity contract for associated entities, this application requires authorization verification before establishing the mapping relationship between associated entities and network entities within the second identity contract. In this case, when a network entity initiates a corresponding identity management request to the blockchain system, it can carry the authorization information of the network entity for each associated entity. Then, the blockchain system directly and accurately calls the second identity contract of each associated entity according to the authorization information of each associated entity. However, if the network entity does not carry the authorization information of the network entity for each associated entity when initiating the corresponding identity management request to the blockchain system, then after establishing the mapping relationship between the network entity and each associated entity within the first identity contract, the blockchain system will return a call request for each associated entity to the network entity. Subsequently, the network entity, carrying the authorization information of each associated entity, successfully calls the second identity contract of each associated entity to the blockchain system.
[0053] Therefore, the invocation of the second identity contract of the associated entity in this application can be initiated by the blockchain system or by the network entity itself, and this application does not limit this.
[0054] As an optional implementation in this application, if a call to the second identity contract of any associated entity is detected, it indicates that the mapping relationship between the network entity and the network entity needs to be maintained within the second identity contract. In order to avoid attacks on the second identity contract by third-party systems, it is necessary to verify the validity of the mapping between the network entity and the associated entity through the first identity contract of the network entity.
[0055] In other words, upon detecting a call to the second identity contract of any associated entity, the system first calls the first identity contract of that network entity through the second identity contract to determine whether the first identity contract maintains a mapping relationship between the network entity and the associated entity. If the first identity contract contains a mapping relationship between the network entity and the associated entity, it means that the mapping between the network entity and the associated entity is valid, and the verification passes.
[0056] Therefore, establishing a mapping relationship between the associated entity and the network entity within the second identity contract can be specifically as follows: if the verification is successful, the target account identifier pointing to the associated entity within the account identifier generated by the network entity is bound to the identity identifier of the associated entity within the second identity contract; the identity identifier of the network entity is set under the target account identifier to obtain the mapping relationship between the associated entity and the network entity.
[0057] In other words, within the second identity contract of any related entity, such as Figure 2As shown, firstly, the target account identifier pointing to the associated entity is found from the various account identifiers already generated by the network entity. Then, within the second identity contract, the target account identifier is bound to the identity identifier (DID) of the associated entity. Furthermore, the identity identifier of the network entity is set under the target account identifier. Thus, by using the target account identifier of any associated entity within the various account identifiers of the network entity, the network entity and the associated entity can be associated within the second identity contract, obtaining the mapping relationship between the associated entity and the network entity.
[0058] It should be noted that the write operations between various contracts within the blockchain system in this application are all agreed upon by the participants on the blockchain to ensure the verifiability of the operations.
[0059] The technical solution provided in this application, when managing the identity of any network entity, establishes a mapping relationship between the network entity and its associated entities within the first identity contract of the network entity in the blockchain system, and also establishes a mapping relationship between the associated entities and the network entity within the second identity contracts of each associated entity. This more accurately reflects the relationship between different entities and ensures comprehensive and convenient management of the identities of different entities by using the blockchain system.
[0060] Furthermore, if a network entity is an organization within any supply chain, then its associated entities can be other organizations upstream and downstream of that organization's supply chain. In this case, establishing a mapping relationship between the network entity and other organizations within its first identity contract would result in duplicate mappings. Therefore, to facilitate unified management of the relationships between organizations within the same supply chain, this application allows any organization within the same supply chain to proactively initiate a corresponding supply chain application to the blockchain system, generating a corresponding supply chain contract. This supply chain contract authorizes various organizations within the supply chain to invoke it, recording the unique identity attributes of each organization within the supply chain. In other words, if the blockchain system receives an invocation of the generated supply chain contract from any organization, it can record the network entity's supply chain attributes within the contract, thereby determining the network entity's associated entities upstream and downstream of the supply chain through the supply chain attributes of each organization within the contract.
[0061] For example, supply chain contracts are primarily designed for the characteristics of supply chain finance, storing and recording the specific attributes of each organization within the supply chain, such as a company's status as a primary distributor in a particular supply chain, to meet the specific needs of supply chain finance operations. Furthermore, other specific requirements for supply chain finance can also be stored as additional attributes of the network entity's identity ID within the supply chain contract.
[0062] After constructing the identity system of each network entity on the blockchain system using the entity identity management method provided above, the process of evaluating the credit status of each network entity using the network entity identity system already constructed on the blockchain system will be explained.
[0063] Figure 3 This is a flowchart illustrating an entity credit assessment method as shown in an embodiment of this application. (Refer to...) Figure 3 The method may specifically include the following steps:
[0064] S310, in response to a credit assessment request for any network entity, obtain the identity contract generated for the network entity using the entity identity management method provided in this application.
[0065] To achieve credit assessment of various network entities, this application allows a third-party institution (such as a credit reporting agency) to initiate a credit application to the blockchain system, generating a corresponding credit contract within the blockchain system. This credit contract is used to assess the creditworthiness of each network entity by executing a pre-defined credit assessment process.
[0066] As an optional implementation scheme in this application, when any network entity has a credit assessment need, the network entity can proactively initiate a corresponding credit assessment request to the blockchain system and authorize the credit contract, which will then execute the credit assessment process of the network entity. Alternatively, the credit contract can proactively request the corresponding credit assessment authorization from the network entity, and after receiving the authorization, the credit contract can initiate a corresponding credit assessment request to the blockchain system to execute the credit assessment process of the network entity.
[0067] It should be noted that the credit contract's authorization for credit assessment of a network entity is valid only once or for a short period of time, and the validity period of the authorization in this application is controlled by the network entity's identity contract.
[0068] At this point, upon detecting a credit assessment request for any network entity, the blockchain system first retrieves the identity contract pre-generated for that network entity using the entity identity management method provided in this application. This identity contract maintains the mapping relationships between the network entity and its associated entities.
[0069] S320 identifies the associated entities of a network entity by invoking the identity contract of a network entity through a credit contract already generated within the blockchain system.
[0070] After obtaining the identity contract generated within the blockchain system by the network entity requesting the credit assessment, the credit contract calls the network entity's identity contract to retrieve the mapping relationships between the network entity and its associated entities established within that identity contract. Then, based on the obtained mapping relationships, the network entity's associated entities are determined.
[0071] As an optional implementation of this application, the following steps are first taken: First, the account identifiers bound to the network entity's identity identifier (DID) within the network entity's identity contract are determined. Then, the identity identifiers already set under each account identifier are determined as the identity identifiers (DIDs) of the network entity's associated entities.
[0072] S330 obtains behavioral data of network entities within associated entities through credit contracts.
[0073] After identifying the various associated entities of the network entity, the credit contract can use the network entity's authorization to invoke the identity contract of each associated entity, and then obtain the behavioral data recorded in the identity contract of each associated entity when the network entity and each associated entity execute corresponding business transactions.
[0074] It should be noted that the network entity requesting credit assessment in this application can be a user or any organization within the supply chain, such as a corporate entity. However, different types of network entities have different associated entities, which means that the operations for obtaining behavioral data of the network entity from different types of associated entities will also differ.
[0075] If the network entity requesting credit assessment in this application is any user, then its associated entities are organizations within the corresponding supply chain. In this case, the behavioral data of the network entity and each associated entity during business transactions will be recorded in the identity contracts of each associated entity. However, if the network entity requesting credit assessment in this application is any organization within the supply chain, then its associated entities are public service entities or other organizations upstream or downstream of the network entity's supply chain. In this case, if the associated entity is a public service entity, then the behavioral data of the network entity and the public service entity during business transactions will be recorded in the public service entity's identity contract. However, if the associated entity is another organization upstream or downstream of the network entity's supply chain, then the behavioral data of the network entity and each associated entity during business transactions is shared data between the network entity and the associated entities and will be jointly recorded in the identity contracts of the network entity and the associated entities.
[0076] As can be seen from the above, the behavioral data of the network entity and its associated entities when performing business transactions in this application may be stored in two ways: either only in the identity contract of the associated entity or jointly in the identity contracts of both the network entity and the associated entities.
[0077] On the one hand, if the network entity is any user, or if the network entity is any organization in the supply chain, and the associated entity is a public service entity, then the behavioral data of the network entity and each associated entity when executing business transactions will be recorded in the identity contract of the associated entity. Therefore, the method of obtaining the behavioral data of the network entity within the associated entity through the credit contract in this application can be specifically as follows: in response to the credit contract's call operation to the associated entity, the identity contract of the network entity is called through the identity contract of the associated entity to verify the validity of the network entity's authorization to the credit contract; if the verification is successful, the behavioral data of the network entity within the associated entity is obtained through the identity contract of the associated entity.
[0078] In other words, since the behavioral data of network entities is recorded within the identity contracts of associated entities, the identity contracts of each associated entity are first invoked through the credit contract. Then, to analyze the authenticity of the credit contract's operation to obtain the network entity's behavioral data, each associated entity, in response to an invocation of its own identity contract, invokes the network entity's identity contract through that associated entity's identity contract to determine whether the credit contract has obtained authorization from the network entity, thus verifying the validity of the network entity's authorization to the credit contract. If the network entity's identity contract confirms authorization to the credit contract to obtain its behavioral data, then each associated entity receives a message indicating that the credit contract has passed verification. Subsequently, after successful verification, the recorded behavioral data of the network entity is retrieved from the identity contracts of each associated entity.
[0079] On the other hand, if the network entity is an organization in any supply chain, and the associated entities are other organizations located upstream or downstream of the network entity's supply chain, then the behavioral data of the network entity and each associated entity when executing business transactions will be jointly recorded in the identity contracts of the network entity and each associated entity. Therefore, obtaining the network entity's behavioral data within the associated entity through the credit contract in this application can specifically be as follows: in response to the credit contract's call operation to the network entity, the first behavioral data of the network entity within the associated entity is obtained through the network entity's identity contract; in response to the credit contract's call operation to the associated entity, the network entity's identity contract is called through the associated entity's identity contract to verify the validity of the network entity's authorization to the credit contract and the authenticity of the first behavioral data; if the verification is successful, the first behavioral data is used as the network entity's behavioral data within the associated entity.
[0080] In other words, since the behavioral data of the network entity and its associated entities during business transactions are jointly recorded in the identity contracts of both the network entity and its associated entities, the network entity's identity contract can be directly invoked through a credit contract. Then, in response to the credit contract's invocation of the network entity, the recorded behavioral data of the network entity can be directly obtained from its identity contract, serving as the first behavioral data in this application. However, since this first behavioral data is shared by the network entity and its associated entities, joint authorization from both parties is required to ensure its authenticity and accuracy. Therefore, after obtaining the first behavioral data from the network entity's identity contract, the associated entity's identity contract must be invoked through the credit contract to verify whether the network entity has authorized the credit contract to obtain its behavioral data and whether the first behavioral data is authentic and accurate. At this point, each associated entity, in response to the credit contract's invocation of its own identity contract, will invoke the network entity's identity contract through that associated entity's identity contract to determine whether the credit contract has obtained authorization from the network entity, thereby verifying the validity of the network entity's authorization to the credit contract. After confirming the authorization is valid, the first set of data can be verified using the public / private keys or decryption keys recorded in the identity contract of the associated entities. If the verification is successful, the first set of data can be used as the behavioral data of the network entity within the associated entities.
[0081] It should be noted that the first behavioral data obtained through the identity contract of a network entity exists in the following two scenarios.
[0082] Scenario 1: If the first line of data is ciphertext encrypted by the associated entity using its public key, the credit contract will invoke the associated entity's identity contract along with the network entity's authorization to the credit contract. Then, the associated entity's identity contract will invoke the network entity's identity contract to verify the validity of the network entity's authorization to the credit contract. After confirming the authorization is valid, the ciphertext will be decrypted using the private key within the associated entity's identity contract, and its authenticity will be verified. After successful verification, the decrypted plaintext will be returned to the credit contract as the network entity's action data within the associated entity.
[0083] Scenario 2: If the first action data is plaintext, the credit contract will invoke the associated entity's identity contract along with the network entity's authorization to the credit contract. Then, the associated entity's identity contract invokes the network entity's identity contract to verify the validity of the network entity's authorization to the credit contract. After confirming the authorization is valid, the associated entity's identity contract verifies the authenticity of the plaintext. Upon successful verification, the plaintext is returned to the credit contract as the network entity's action data within the associated entity.
[0084] S340, based on behavioral data, determines the credit score of network entities.
[0085] After obtaining behavioral data of a network entity within its various associated entities through credit contracts, this behavioral data represents the network entity's creditworthiness each time it executes a business transaction with an associated entity. Examples include the number of times a user has applied for loans recently, their utility bill payment history, and their social behavior. Therefore, by analyzing the network entity's behavioral data, its business behavior can be evaluated, thereby determining its credit score.
[0086] As an optional implementation of this application, in order to accurately assess the credit of network entities, this application pre-uses a large amount of behavioral data of network entities in their historical business transactions with various related entities as training samples. Then, using a large number of training samples, a credit assessment model is pre-constructed within the credit contract to accurately score the credit of network entities.
[0087] For example, determining a network entity's credit score based on behavioral data can be achieved by inputting the behavioral data into a pre-built credit assessment model within a credit contract, and then outputting the network entity's credit score. In other words, by analyzing the input variable requirements set within the credit assessment model, the credit contract can process various behavioral data points of the network entity to obtain the data variables needed for the credit assessment model. Then, the processed behavioral data variables are input into the credit assessment model to output the network entity's credit score.
[0088] For example, when the network entity is a user, the credit assessment model can be... Wherein, score i can be the credit score within the i-th dimension of the behavioral data. In this application, the scoring variables set for users in the credit assessment model can be:
[0089] 1. Rating 1: Rating based on the number of loan applications submitted in the past month.
[0090] 2. Rating 2: Rating related to the number of overdue payments in the past six months
[0091] 3. Rating 3: Performance evaluation of utility bills (water, electricity, gas)
[0092] 4. Rating 4: Social Network Behavior Rating
[0093] 5. Rating n: ...
[0094] However, when the network entity is an organization, such as a company, the scoring variables set for the user in the credit assessment model of this application can be:
[0095] 1. Rating 1: Public opinion-related rating over the past month
[0096] 2. Rating 2: Legal proceedings related to the past year
[0097] 3. Rating 3: Frequency of transactions in the upstream and downstream of the supply chain
[0098] 4. Rating 4: Supply Chain Upstream and Downstream Transaction Volume Rating
[0099] 5. Rating n: ...
[0100] The technical solution provided in this application embodiment calls the identity contracts of different entities through the credit contract in the blockchain system to comprehensively obtain the behavioral data of any network entity, so as to determine the credit score of the network entity and ensure the comprehensiveness and accuracy of entity credit assessment.
[0101] Figure 4 This is a schematic block diagram illustrating an entity identity management device according to an embodiment of this application. The entity identity management device 400 is configured in a blockchain system, such as... Figure 4 As shown, the device 400 may include:
[0102] The first identity management module 410 is used to respond to the identity management request of any network entity and establish a mapping relationship between the network entity and its associated entities within the first identity contract generated by the network entity on the blockchain system.
[0103] The second identity management module 420 is used to establish a mapping relationship between the associated entity and the network entity within the second identity contract generated by the associated entity on the blockchain system.
[0104] Furthermore, the aforementioned first identity management module 410 can be specifically used for:
[0105] Within the first identity contract, the account identifier generated by the network entity is bound to the identity identifier of the network entity;
[0106] Under each account identifier, the identity identifier of the associated entity that the account identifier points to is set, so as to obtain the mapping relationship between the network entity and the associated entity.
[0107] Furthermore, the aforementioned entity identity management device 400 may also include:
[0108] The mapping verification module is used to verify the mapping validity between the network entity and the associated entity through the first identity contract if a call operation to the second identity contract of the associated entity is detected.
[0109] Furthermore, the aforementioned second identity management module 420 can be specifically used for:
[0110] If the verification is successful, the target account identifier pointing to the associated entity in the account identifier generated by the network entity will be bound to the identity identifier of the associated entity within the second identity contract;
[0111] The identity identifier of the network entity is set under the target account identifier to obtain the mapping relationship between the associated entity and the network entity.
[0112] Furthermore, if the network entity is any organization in the supply chain, the entity identity management device 400 may further include:
[0113] The supply chain invocation module is used to respond to the invocation operation of the supply chain contract generated on the blockchain system, and to record the supply chain attributes of the network entity in the supply chain contract in order to determine the related entities of the network entity in the upstream and downstream of the supply chain.
[0114] Figure 5 This is a schematic block diagram illustrating a physical credit assessment device according to an embodiment of this application. The physical credit assessment device 500 is configured in a blockchain system, such as... Figure 5 As shown, the device 500 may include:
[0115] The identity contract determination module 510 is used to obtain the identity contract generated for the network entity using the entity identity management method provided in this application in response to a credit assessment request for any network entity.
[0116] The associated entity determination module 520 is used to determine the associated entities of the network entity by invoking the identity contract of the network entity through the credit contract generated within the blockchain system.
[0117] Data acquisition module 530 is used to acquire behavioral data of the network entity within the associated entity through the credit contract;
[0118] Credit assessment module 540 is used to determine the credit score of the network entity based on the behavioral data.
[0119] Furthermore, if the network entity is any user, or the network entity is any organization in the supply chain, and the associated entity is a public service entity, the data acquisition module 530 can be specifically used for:
[0120] In response to the credit contract's call operation to the associated entity, the identity contract of the network entity is called through the identity contract of the associated entity to verify the validity of the network entity's authorization to the credit contract;
[0121] If the verification is successful, the network entity's behavior data within the associated entity is obtained through the associated entity's identity contract.
[0122] Furthermore, if the network entity is an organization in any supply chain, and the associated entity is another organization located upstream or downstream of the network entity's supply chain, the data acquisition module 530 can be specifically used for:
[0123] In response to the credit contract's call to the network entity, the first behavioral data of the network entity within the associated entity is obtained through the network entity's identity contract;
[0124] In response to the credit contract's call to the associated entity, the identity contract of the network entity is called through the identity contract of the associated entity to verify the validity of the network entity's authorization to the credit contract and the authenticity of the first behavioral data;
[0125] If the verification is successful, the first behavioral data will be used as the behavioral data of the network entity within the associated entity.
[0126] Furthermore, the aforementioned credit assessment module 540 can be specifically used for:
[0127] The behavioral data is input into a pre-built credit assessment model within the credit contract, and the credit score of the network entity is output.
[0128] In this embodiment, when managing the identity of any network entity, a mapping relationship between the network entity and its associated entities is established within the blockchain system in the first identity contract of the network entity. Similarly, a mapping relationship between the associated entity and the network entity is also established within the second identity contracts of each associated entity. This more accurately reflects the relationships between different entities, and the blockchain system ensures comprehensive and convenient management of the identities of different entities. Furthermore, by calling the identity contracts of different entities through the credit contract within the blockchain system, the behavioral data of any network entity is comprehensively obtained to determine its credit score, ensuring the comprehensiveness and accuracy of entity credit assessment.
[0129] It should be understood that the device embodiments and method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, further details will not be provided here. Specifically, Figure 4 The apparatus 400 shown can execute any of the entity identity management method embodiments provided in this application. Figure 5The apparatus 500 shown can execute any of the entity credit assessment method embodiments provided in this application, and the foregoing and other operations and / or functions of each module in apparatus 400 and apparatus 500 are respectively for implementing the corresponding processes in the various methods of the embodiments of this application. For the sake of brevity, they will not be described in detail here.
[0130] The apparatus 400 and apparatus 500 of the embodiments of this application have been described above from the perspective of functional modules in conjunction with the accompanying drawings. It should be understood that these functional modules can be implemented in hardware, in software instructions, or in a combination of hardware and software modules. Specifically, the steps of the method embodiments in this application can be completed by integrated logic circuits in the processor's hardware and / or by software instructions. The steps of the methods disclosed in the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps in the above method embodiments.
[0131] Figure 6 This is a schematic block diagram of the electronic device 600 provided in the embodiments of this application.
[0132] like Figure 6 As shown, the electronic device 600 may include:
[0133] The system includes a memory 610 and a processor 620. The memory 610 stores computer programs and transfers the program code to the processor 620. In other words, the processor 620 can retrieve and run the computer program from the memory 610 to implement the methods described in the embodiments of this application.
[0134] For example, the processor 620 can be used to execute the above-described method embodiments according to instructions in the computer program.
[0135] In some embodiments of this application, the processor 620 may include, but is not limited to:
[0136] General-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0137] In some embodiments of this application, the memory 610 includes, but is not limited to:
[0138] Volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).
[0139] In some embodiments of this application, the computer program may be divided into one or more modules, which are stored in the memory 610 and executed by the processor 620 to perform the method provided in this application. The one or more modules may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device.
[0140] like Figure 6 As shown, the electronic device may also include:
[0141] Transceiver 630, which can be connected to processor 620 or memory 610.
[0142] The processor 620 can control the transceiver 630 to communicate with other devices; specifically, it can send information or data to other devices or receive information or data sent by other devices. The transceiver 630 may include a transmitter and a receiver. The transceiver 630 may further include antennas, and the number of antennas may be one or more.
[0143] It should be understood that the various components in the electronic device are connected through a bus system, which includes a data bus, a power bus, a control bus, and a status signal bus.
[0144] This application also provides a computer storage medium storing a computer program thereon, which, when executed by a computer, enables the computer to perform the methods of the above-described method embodiments. Alternatively, this application also provides a computer program product containing instructions that, when executed by a computer, cause the computer to perform the methods of the above-described method embodiments.
[0145] When implemented using software, it can be implemented entirely or partially as a computer program product. This computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital video disc (DVD)), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0146] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0147] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.
[0148] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. For example, the functional modules in the various embodiments of this application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.
[0149] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for managing entity identity, characterized in that, When applied to a blockchain system, the method includes: In response to an identity management request from any network entity, a mapping relationship is established between the network entity and its associated entities within the first identity contract generated by the network entity on the blockchain system. A mapping relationship between the associated entity and the network entity is established within the second identity contract already generated by the associated entity on the blockchain system; The network entity is any user or organization in the supply chain that has a credit assessment need, and the associated entity of the network entity is an entity that records the various behavioral data performed by the network entity during the interaction process when interacting with the network entity. The step of establishing a mapping relationship between the network entity and its associated entities within the first identity contract already generated on the blockchain system includes: Within the first identity contract, the account identifier generated by the network entity is bound to the identity identifier of the network entity; Under each account identifier, the identity identifier of the associated entity that the account identifier points to is set, so as to obtain the mapping relationship between the network entity and the associated entity.
2. The method according to claim 1, characterized in that, Before establishing the mapping relationship between the associated entity and the network entity within the second identity contract already generated on the blockchain system, the method further includes: If a call to the second identity contract of the associated entity is detected, the mapping validity between the network entity and the associated entity is verified through the first identity contract.
3. The method according to claim 2, characterized in that, The step of establishing a mapping relationship between the associated entity and the network entity within the second identity contract already generated by the associated entity on the blockchain system includes: If the verification is successful, the target account identifier pointing to the associated entity in the account identifier generated by the network entity will be bound to the identity identifier of the associated entity within the second identity contract; The identity identifier of the network entity is set under the target account identifier to obtain the mapping relationship between the associated entity and the network entity.
4. The method according to claim 1, characterized in that, If the network entity is an organization in any supply chain, the method further includes: In response to a call to a supply chain contract already generated on the blockchain system, the supply chain attributes of the network entity are recorded within the supply chain contract to determine the network entity's associated entities in the upstream and downstream of the supply chain.
5. A method for assessing entity credit, characterized in that, When applied to a blockchain system, the method includes: In response to a credit assessment request for any network entity, obtain an identity contract generated for the network entity using the entity identity management method according to any one of claims 1-4; The associated entities of the network entity are identified by invoking the identity contract of the network entity through the credit contract already generated within the blockchain system; The network entity's behavioral data within the associated entity is obtained through the credit contract; Based on the behavioral data, a credit score is determined for the network entity.
6. The method according to claim 5, characterized in that, If the network entity is any user, or the network entity is any organization in the supply chain, and the associated entity is a public service entity, obtaining the network entity's behavioral data within the associated entity through the credit contract includes: In response to the credit contract's call operation to the associated entity, the identity contract of the network entity is called through the identity contract of the associated entity to verify the validity of the network entity's authorization to the credit contract; If the verification is successful, the network entity's behavior data within the associated entity is obtained through the associated entity's identity contract.
7. The method according to claim 5, characterized in that, If the network entity is an organization in any supply chain, and the associated entity is another organization located upstream or downstream of the network entity's supply chain, obtaining the network entity's behavioral data within the associated entity through the credit contract includes: In response to the credit contract's call to the network entity, the first behavioral data of the network entity within the associated entity is obtained through the network entity's identity contract; In response to the credit contract's call to the associated entity, the identity contract of the network entity is called through the identity contract of the associated entity to verify the validity of the network entity's authorization to the credit contract and the authenticity of the first behavioral data; If the verification is successful, the first behavioral data will be used as the behavioral data of the network entity within the associated entity.
8. The method according to claim 5, characterized in that, Determining the credit score of the network entity based on the behavioral data includes: The behavioral data is input into a pre-built credit assessment model within the credit contract, and the credit score of the network entity is output.
9. A physical identity management device, characterized in that, Configured in a blockchain system, the device includes: The first identity management module is used to respond to the identity management request of any network entity and establish a mapping relationship between the network entity and its associated entities within the first identity contract generated by the network entity on the blockchain system. The second identity management module is used to establish a mapping relationship between the associated entity and the network entity within the second identity contract generated by the associated entity on the blockchain system. The network entity is any user or organization in the supply chain that has a credit assessment need, and the associated entity of the network entity is an entity that records the various behavioral data performed by the network entity during the interaction process when interacting with the network entity. The first identity management module is specifically used for: Within the first identity contract, the account identifier generated by the network entity is bound to the identity identifier of the network entity; Under each account identifier, the identity identifier of the associated entity that the account identifier points to is set, so as to obtain the mapping relationship between the network entity and the associated entity.
10. A physical credit assessment device, characterized in that, Configured in a blockchain system, the method includes: An identity contract determination module is used to obtain an identity contract generated for the network entity using the entity identity management method according to any one of claims 1-4 in response to a credit assessment request for any network entity. The associated entity determination module is used to determine the associated entities of the network entity by invoking the identity contract of the network entity through the credit contract generated within the blockchain system. The data acquisition module is used to acquire the behavioral data of the network entity within the associated entity through the credit contract; The credit assessment module is used to determine the credit score of the network entity based on the behavioral data.
11. An electronic device, characterized in that, include: A processor and a memory, the memory being used to store a computer program, the processor being used to call and run the computer program stored in the memory to perform the entity identity management method of any one of claims 1-4, or to perform the entity credit assessment method of any one of claims 5-8.
12. A computer-readable storage medium, characterized in that, Used to store computer programs that cause a computer to perform the entity identity management method as described in any one of claims 1-4, or to perform the entity credit assessment method as described in any one of claims 5-8.
13. A computer program product comprising a computer program / instructions, characterized in that, When executed by a processor, the computer program / instruction implements the entity identity management method as described in any one of claims 1-4, or the entity credit assessment method as described in any one of claims 5-8.
Citation Information
Patent Citations
Account unifying method, device and storage medium
CN108235805A
Method for providing relational decentralized identifier service and blockchain node using the same
US20210011905A1