A management method for distributed digital identity identifiers
By generating the main private key and DID calculating the user's private key, and using the elliptic curve bilinear pair algorithm, the problems of DID document maintenance and mapping relationship in distributed digital identity management are solved, and simplified DID management and offline signature verification are realized.
Patent Information
- Application Number
- CN202210834230.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-14
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-07-14
AI Technical Summary
In the prior art, distributed digital identity management requires maintaining the mapping relationship between DID documents and DID and public keys, making it difficult to realize offline signature verification.
By generating the main private key and DID, the user's private key is calculated, the binding process between DID and public key is simplified, and the public key is generated by the elliptic curve bilinear pairing algorithm, and the user's public key is directly obtained through DID for verification.
It simplifies the generation and maintenance steps of DID documents, realizes the possibility of offline sign verification, and reduces the dependence on the DID and public key mapping relationship.
Smart Images

Figure CN115134091B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and more particularly to a method for managing distributed digital identity identifiers. Background Art
[0002] A distributed digital identity identifier (DID) is an identifier composed of a string that represents a digital identity and can achieve global uniqueness without a central registration authority. Generally, an entity can have multiple identities, and each identity is assigned a unique DID value and an associated asymmetric key. There is no associated information between different identities, thus effectively avoiding the aggregation of the owner's identity information.
[0003] Distributed Identifiers (DID) is a decentralized and verifiable digital identifier with characteristics such as being distributed, autonomously controllable, and cross-chain reusable. An entity can independently complete operations such as registration, resolution, update, or revocation of a DID. A DID is specifically resolved into a DID Document, and the DID Document includes the unique identification code of the DID, a list of public keys, and detailed information about the public keys (holder, encryption algorithm, key status, etc.), as well as other attribute descriptions of the DID holder.
[0004] A DID is associated with a DID Document. The DID infrastructure can be considered a global key-value database, where the database is all DID-compatible blockchains, distributed ledgers, or decentralized networks. In this virtual database, the key is the DID, and the value is the DID Document. The purpose of the DID Document is to describe the public keys, authentication protocols, and service endpoints, which are necessary to initiate a cryptographically verifiable interaction with the identified entity. In the prior art, during the process of distributed digital identity management, it is necessary to maintain the DID Document, and at the same time, it is also necessary to maintain the mapping relationship between the DID and the public key, that is, it is necessary to bind one or more public keys to each DID, and it is difficult to implement the process of offline signature verification.
[0005] Therefore, how to provide a simplified method for managing distributed digital identity identifiers is an urgent problem that those skilled in the art need to solve. Summary of the Invention
[0006] In view of this, the present invention provides a method for managing distributed digital identity identifiers to achieve simplified management of distributed digital identities.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] A method for managing distributed digital identity identifiers includes the following steps:
[0009] S1. Obtain user registration information;
[0010] S2. Generate a master private key, a public-private key, and a unique DID according to the user registration information. Generate a user private key through the master private key and the DID, and return and save the DID, the user private key, and the master public key;
[0011] S3. The verifier obtains the user's DID, and obtains the user's public key through the DID to implement signature verification.
[0012] Preferably, the user registration information in S1 includes the user's ID number, mobile phone number, region, and / or company.
[0013] Preferably, in S2, the key generation center generates the master private key and the public-private key through random numbers and saves them.
[0014] Preferably, when the DID in S2 is generated by the server:
[0015] When the user registers the DID, the server generates a new DID, and queries whether the new DID exists in the current storage. If it does not exist, the current user is associated and bound with the newly generated DID.
[0016] Preferably, when the DID in S2 is generated by the user:
[0017] The user generates a DID and submits the DID to the server when registering with the server. After receiving the DID, the server queries whether the DID exists in the current storage. If it exists, an error message is returned; if it does not exist, the registration logic continues to be executed.
[0018] Preferably, the algorithms for generating the DID include auto-incrementing ID, UUID, and snowflake algorithm.
[0019] Preferably, the specific content of S3 includes:
[0020] S31. The user signs the business information with their own user private key, and sends the business information and the signature to the verifier;
[0021] S32. The verifier obtains the user DID from the business information, generates the user public key using the master public key and the DID, and then verifies using the user public key, the business information, and the signature information.
[0022] Through the above technical solutions, compared with the prior art, the present invention discloses a method for managing distributed digital identity identifiers, which has the following beneficial effects:
[0023] 1. The present invention provides a more convenient distributed digital identity management method. Instead of binding a public key to a DID, the public key is deduced from the master public key and the DID, simplifying the steps of generating and maintaining a DID document in the digital identity management method of the prior art.
[0024] 2. When the verifier verifies the signature, it is not necessary to query the mapping relationship between the corresponding DID and the public key in other systems, and offline signature verification can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for description in the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.
[0026] Figure 1 The attached drawing is a schematic diagram of the DID generation process in a distributed digital identity identifier management method provided by the present invention;
[0027] Figure 2 The attached drawing is a schematic diagram of the signature verification process in a distributed digital identity identifier management method provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0029] An embodiment of the present invention discloses a distributed digital identity identifier management method, including the following steps:
[0030] S1. Obtain user registration information;
[0031] S2. According to the user registration information, generate a master private key, a public-private key, and a unique DID. Generate a user private key from the master private key and the DID, and return and save the DID, the user private key, and the master public key;
[0032] S3. The verifier obtains the user DID and obtains the user public key through the DID to achieve signature verification.
[0033] It should be noted that:
[0034] In distributed digital identity logic, signature addition and signature verification are involved. In asymmetric encryption, when adding a signature, a private key is used to generate a signature value, and when verifying a signature, the signature value and the public key are used for verification. Therefore, in the W3C standard, after generating a DID, the DID and the public key need to be bound to verify whether the signature value belongs to the DID.
[0035] In this embodiment, the management of distributed digital identity is implemented through the elliptic curve bilinear pairing algorithm, and the purpose of the elliptic curve bilinear pairing algorithm is to maintain the generation of user public and private keys through the master public and private keys.
[0036] To further implement the above technical solution, the user registration information in S1 includes the user's ID number, mobile phone number, region and / or company.
[0037] To further implement the above technical solution, in S2, the key generation center generates and saves the master private key and public and private keys through random numbers.
[0038] To further implement the above technical solution, when the DID is generated by the server in S2:
[0039] The server generates a globally unique DID and saves it in the server's storage;
[0040] When the user registers a DID, the server generates a new DID and queries whether the new DID exists in the current storage. If it does not exist, the current user is associated and bound with the newly generated DID.
[0041] To further implement the above technical solution, when the DID is generated by the user in S2:
[0042] The user generates a DID and submits the DID to the server when registering with the server. After receiving the DID, the server queries whether the DID exists in the current storage. If it exists, an error message is returned; if it does not exist, the registration logic continues to be executed.
[0043] To further implement the above technical solution, the algorithms for generating DIDs include auto-incrementing IDs, UUIDs, and snowflake algorithms.
[0044] To further implement the above technical solution, the specific content of S3 includes:
[0045] S31. The user signs the business information with their own user private key and sends the business information and the signature to the verifier;
[0046] S32. The verifier obtains the user DID from the business information, generates the user public key using the master public key and the DID, and then verifies using the user public key, business information, and signature information.
[0047] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0048] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A management method for distributed digital identity identifiers, characterized in that, It includes the following steps: S1. Obtain user registration information; S2. Generate a master private key, a master public key, and a unique DID based on the user registration information. Generate a user private key using the master private key and the DID, and return and save the DID, the user private key, and the master public key; When the DID in S2 is generated by the user: The user generates a DID and submits the DID to the server when registering with the server. After receiving the DID, the server queries whether the DID exists in the current storage. If it exists, an error message is returned; if not, the registration logic continues to be executed; S3. The verifier obtains the user's DID and obtains the user public key through the DID to achieve signature verification; The specific content of S3 includes: S31. The user signs the business information using their user private key and sends the business information and the signature to the verifier; S32. The verifier obtains the user DID from the business information, generates the user public key using the master public key and the DID, and then verifies using the user public key, the business information, and the signature information; 2. The management method of a distributed digital identity identifier according to claim 1, characterized in that, The user registration information in S1 includes the user's ID number, mobile phone number, region, and / or company; 3. The management method of a distributed digital identity identifier according to claim 1, wherein, In S2, the key generation center generates the master private key and the master public key through random numbers and saves them; 4. A management method for a distributed digital identity identifier according to claim 1, characterized in that, When the DID in S2 is generated by the server: When the user registers the DID, the server generates a new DID and queries whether the new DID exists in the current storage. If it does not exist, the current user is associated and bound with the newly generated DID; 5. The management method of a distributed digital identity identifier according to claim 1, characterized in that, The algorithms for generating the DID include auto-incrementing ID, UUID, and Snowflake algorithm.
Citation Information
Patent Citations
Cross-platform registration method and device based on blockchain
CN113765674A