Blockchain-based identity authentication method, device and system
Through blockchain technology and smart contracts, the problems of information authenticity and security in cross-institutional identity authentication have been solved, the secure flow and authentication of identity attribute information across institutions have been achieved, and the security trust mechanism of identity authentication has been improved.
Patent Information
- Application Number
- CN202210743161.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-28
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2042-06-28
AI Technical Summary
In existing technologies, cross-institutional identity authentication relies on institutional credit, the authenticity and security of user information are difficult to guarantee, there is a risk of information leakage, and it is impossible to achieve cross-institutional identity information mutual recognition.
A blockchain-based identity authentication method is adopted to achieve the secure flow and authentication of identity attribute information across institutions through smart contracts. Identity providers are used to issue blank certificates and store them on the chain. Combined with DPKI and verifiable certificate technology, data authenticity and traceability are ensured.
It improves the security and trust mechanism of cross-institutional identity authentication, ensures the authenticity and integrity of user information, reduces the risk of information leakage, and realizes the accurate authorization and transparent traceability of identity information.
Smart Images

Figure CN115208642B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer data processing technology, in particular to the field of blockchain technology, and more particularly to a blockchain-based identity authentication method, device, and system. Background Art
[0002] Increasingly, business systems, based on their own security requirements, require identity verification of users seeking to conduct business. Only after successful verification can corresponding services be provided. When a business service process involves the business systems of multiple organizations, users must authorize cross-organizational identity authentication through an open authorization auth protocol. For example, if user information is stored in system A and a user authenticates with system B, which interacts with system A, the user authorizes system B to authenticate through system A, and system A then transmits the relevant user information to system B.
[0003] The third-party authorization login model, implemented through the open authorization auth protocol, is a leading cross-institutional identity authentication method in the existing technology. This method relies on authorization and user information interface interaction between institutions. Furthermore, the authenticity and accuracy of user information is entirely dependent on the creditworthiness of the institution storing the user information. The user identity information interaction process is also opaque to users, and the actual use of user identity information is also entirely dependent on the creditworthiness of the institution. If a channel cannot be established due to institutional systems or other reasons, mutual recognition of identity information between collaborating institutions is impossible, and there is a risk of user information leakage due to the scope of actual transmitted information exceeding the information required for actual user authentication. Summary of the Invention
[0004] The blockchain-based identity authentication method, device and system provided by the present invention realize the secure flow and authentication of identity attribute information across institutions. The identity provider issues a blank certificate for user identity authentication, and classifies and stores the identity attribute information and uploads fingerprints to the chain to ensure that the authenticity of the data can be verified. Through the full-process chain endorsement, the user information flow process is guaranteed to be open, transparent and traceable, thereby strengthening the security trust mechanism of cross-institutional identity authentication.
[0005] In order to achieve the above objectives, the present invention discloses, on one hand, a blockchain-based identity authentication method applicable to an identity authentication initiating node, which includes:
[0006] In response to a received user cross-node identity authentication request, forwarding the encrypted user cross-node identity authentication request to a node having user identity information in a blockchain, wherein a smart contract for performing user identity authentication is deployed in the blockchain;
[0007] Receiving the encrypted identity authentication result sent by the node having the user identity information;
[0008] Decrypt the identity authentication result and feed the identity authentication result back to the user.
[0009] Preferably, the blockchain-based identity authentication method further includes:
[0010] Forwarding the encrypted user cross-node identity authentication request to other nodes in the blockchain;
[0011] Receiving a consensus result of the other nodes regarding the user's cross-node identity authentication request;
[0012] When the consensus results of the other nodes are consistent, the identity authentication result is persisted on the blockchain.
[0013] Preferably, decrypting the identity authentication result includes:
[0014] Persistently record the user's public key and user identification information on the blockchain to generate a unique identifier;
[0015] The identity authentication result is decrypted according to the unique identifier.
[0016] On the other hand, the present invention also provides a blockchain-based identity authentication method applicable to an identity authentication node, the method comprising:
[0017] Receiving an encrypted user cross-node identity authentication request sent by a node in a blockchain; wherein a smart contract for performing user identity authentication is deployed in the blockchain;
[0018] When the user passes the identity authentication, generating an identity authentication result for the user's cross-node identity authentication request;
[0019] The identity authentication result is encrypted and sent to the node.
[0020] Generating an identity authentication result for the user cross-node identity authentication request includes:
[0021] Invoke the node to register a blank certificate in the blockchain;
[0022] Fill in the blank credential according to the user cross-node identity authentication request to generate the identity authentication result.
[0023] Preferably, when the user passes the identity authentication, before generating the identity authentication result for the user's cross-node identity authentication request, the process includes:
[0024] The user's cross-node identity authentication request is decrypted according to the unique identifier corresponding to the user in the blockchain to determine the user's identity.
[0025] Correspondingly, the present invention also discloses a blockchain-based identity authentication device applicable to an identity authentication initiating node, the device comprising:
[0026] a first request forwarding module configured to, in response to a received user cross-node identity authentication request, forward the encrypted user cross-node identity authentication request to a node in the blockchain having the user identity information; wherein the blockchain is deployed with a smart contract for performing user identity authentication;
[0027] An authentication result receiving module, configured to receive the encrypted identity authentication result sent by the node having the user identity information;
[0028] The authentication result decryption module is used to decrypt the identity authentication result and feed the identity authentication result back to the user.
[0029] Preferably, the blockchain-based identity authentication device applicable to the identity authentication initiation node further includes:
[0030] A second request forwarding module is used to forward the encrypted user cross-node identity authentication request to other nodes in the blockchain;
[0031] A consensus result receiving module, configured to receive the consensus result of the other nodes regarding the user's cross-node identity authentication request;
[0032] The authentication result persistence module is used to persist the identity authentication result on the blockchain when the consensus results of the other nodes are consistent.
[0033] Preferably, the authentication result decryption module includes:
[0034] An identifier generation unit, configured to generate a unique identifier persistently on the blockchain based on the user's public key and user identification information;
[0035] The authentication result generating unit is configured to decrypt the identity authentication result according to the unique identifier.
[0036] The present invention also discloses a blockchain-based identity authentication device suitable for performing identity authentication on a node, the device comprising:
[0037] An authentication request receiving module, configured to receive an encrypted user cross-node identity authentication request sent by a node in a blockchain; wherein a smart contract for user identity authentication is deployed in the blockchain;
[0038] An authentication result generation module, configured to generate an identity authentication result for a cross-node identity authentication request of the user when the user passes the identity authentication;
[0039] The authentication result encryption module is used to encrypt the identity authentication result and send it to the node.
[0040] Preferably, the authentication result generation module includes:
[0041] A blank certificate registration unit, configured to call the node to register a blank certificate in the blockchain;
[0042] The authentication result generating unit is used to fill in the blank credential according to the user cross-node identity authentication request to generate the identity authentication result.
[0043] Preferably, the blockchain-based identity authentication device suitable for performing identity authentication node further includes:
[0044] The user identity determination module is used to decrypt the user cross-node identity authentication request according to the unique identifier corresponding to the user in the blockchain to determine the user identity.
[0045] The present invention also discloses a blockchain node, which is configured to respond to a received user cross-node identity authentication request, forward the encrypted user cross-node identity authentication request to a node with user identity information in the blockchain; receive the encrypted identity authentication result sent by the node with user identity information; decrypt the identity authentication result, and feed the identity authentication result back to the user, wherein a smart contract for user identity authentication is deployed in the blockchain, and
[0046] The invention relates to a method for receiving an encrypted user cross-node identity authentication request sent by a node in a blockchain; generating an identity authentication result for the user cross-node identity authentication request when the user passes the identity authentication; encrypting the identity authentication result and sending it to the node, wherein a smart contract for user identity authentication is deployed in the blockchain.
[0047] The present invention also discloses an identity authentication system based on blockchain, comprising an identity authentication request node, an identity authentication node and a blockchain;
[0048] The identity authentication request node is configured to respond to a received user cross-node identity authentication request by forwarding the encrypted user cross-node identity authentication request to a node in the blockchain that has the user's identity information; receive the encrypted identity authentication result sent by the node that has the user's identity information; decrypt the identity authentication result, and feed the identity authentication result back to the user;
[0049] The identity authentication node is used to receive an encrypted user cross-node identity authentication request sent by a node in the blockchain; when the user passes the identity authentication, generate an identity authentication result for the user cross-node identity authentication request; encrypt the identity authentication result and send it to the node;
[0050] A smart contract for user identity authentication is deployed in the blockchain.
[0051] The present invention also discloses an electronic device, comprising a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, the steps of the blockchain-based identity authentication method are implemented.
[0052] The present invention also discloses a computer-readable medium on which a computer program is stored. When the program is executed by a processor, the method described above is implemented.
[0053] From the above description, it can be seen that, first, an embodiment of the present invention provides a blockchain-based identity authentication method suitable for an identity authentication initiating node, the method including responding to a received user cross-node identity authentication request, forwarding the encrypted user cross-node identity authentication request to a node with user identity information in the blockchain, wherein a smart contract for user identity authentication is deployed in the blockchain; receiving the encrypted identity authentication result sent by the node with user identity information; decrypting the identity authentication result, and feeding back the identity authentication result to the user.
[0054] Next, an embodiment of the present invention also provides a blockchain-based identity authentication method suitable for an identity authentication node, including: receiving an encrypted user cross-node identity authentication request sent by a node in the blockchain; wherein a smart contract for user identity authentication is deployed in the blockchain; when the user passes the identity authentication, an identity authentication result is generated for the user's cross-node identity authentication request; and the identity authentication result is encrypted and sent to the node.
[0055] This invention realizes the secure transfer and authentication of identity attribute information across institutions based on technologies such as DPKI, verifiable credentials, and data fingerprints. First, the identity provider issues a blank certificate for user identity authentication, then the identity attribute information is classified and stored, and the fingerprint is uploaded to the chain to ensure that the authenticity of the data can be verified. Finally, the user can freely choose to disclose information and sign for precise authorization. The openness, transparency, and traceability of the user information flow process are guaranteed through full-process chain endorsement, thereby strengthening the security and trust mechanism of cross-institutional identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0057] Figure 1 The process diagram of the blockchain-based identity authentication method in an embodiment of the present invention is as follows: Figure 1 (Applicable to identity authentication initiation node);
[0058] Figure 2 The process diagram of the blockchain-based identity authentication method in an embodiment of the present invention is as follows: Figure 2 (Applicable to identity authentication initiation node);
[0059] Figure 3 This is a flowchart of step 300 of the blockchain-based file transmission method in an embodiment of the present invention;
[0060] Figure 4 The process diagram of the blockchain-based identity authentication method in an embodiment of the present invention is as follows: Figure 1 (Applicable to identity authentication nodes);
[0061] Figure 5 This is a flowchart of step B of the blockchain-based file transfer method in an embodiment of the present invention;
[0062] Figure 6 The process diagram of the blockchain-based identity authentication method in an embodiment of the present invention is as follows: Figure 2 (Applicable to identity authentication nodes);
[0063] Figure 7 This is a structural diagram of the identity authentication system based on blockchain in a specific embodiment of the present invention;
[0064] Figure 8 This is a structural diagram of blockchain node 2 in a specific embodiment of the present invention;
[0065] Figure 9 This is a flowchart of a blockchain-based identity authentication method in a specific embodiment of the present invention;
[0066] Figure 10 This is a schematic diagram of the verification process of the identity certificate of blockchain node 2 in a specific embodiment of the present invention;
[0067] Figure 11 This is an identity authentication device based on blockchain in an embodiment of the present invention. Figure 1 (applicable to the sender of the file);
[0068] Figure 12 This is an identity authentication device based on blockchain in an embodiment of the present invention. Figure 2 (applicable to the sender of the file);
[0069] Figure 13 This is a block diagram of the authentication result decryption module 30 of the blockchain-based identity authentication device in an embodiment of the present invention;
[0070] Figure 14 This is an identity authentication device based on blockchain in an embodiment of the present invention. Figure 1 (Applicable to identity authentication nodes);
[0071] Figure 15 4 is a block diagram of a blockchain-based authentication result generation module B in an embodiment of the present invention;
[0072] Figure 16 This is an identity authentication device based on blockchain in an embodiment of the present invention. Figure 2 (Applicable to identity authentication nodes);
[0073] Figure 17 Schematic diagram of the structure of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION
[0074] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0075] It should be noted that the blockchain-based identity authentication method, device and system disclosed in this application can be used in the field of artificial intelligence technology, and can also be used in any field other than the field of artificial intelligence technology. The application field of the blockchain-based identity authentication method, device and system disclosed in this application is not limited.
[0076] To facilitate understanding of the technical solution provided by this application, the relevant contents of the technical solution of this application are first described below. The blockchain-based identity authentication method provided by the embodiment of the present invention is based on the existing blockchain structured on-chain data storage technology, and further uses DPKI and verifiable credentials and data fingerprints to achieve the secure flow and authentication of identity attribute information across institutions. The identity provider issues a blank certificate for user identity authentication, and the identity attribute information is classified and stored and fingerprinted on the chain to ensure that the data authenticity can be verified. The user can freely choose to disclose information and sign for accurate authorization, thereby obtaining a blockchain-based identity authentication method.
[0077] The acquisition, storage, use, and processing of data in this application's technical solution comply with relevant national laws and regulations.
[0078] According to one aspect of the present invention, this embodiment discloses a blockchain-based identity authentication method applicable to an identity authentication initiating node. Figure 1As shown, in this embodiment, the method includes:
[0079] Step 100: In response to a received user cross-node identity authentication request, forward the encrypted user cross-node identity authentication request to a node having user identity information in a blockchain, wherein a smart contract for performing user identity authentication is deployed in the blockchain;
[0080] Specifically, a consortium chain is formed between an identity authentication initiation node (the node that receives the user's cross-institutional identity authentication request) and a verification agency with the user's identity information. The identity authentication initiation node encrypts and sends the cross-institutional identity authentication request to the verification agency node with the user's identity information.
[0081] Step 200: Receive the encrypted identity authentication result sent by the node having the user identity information;
[0082] Each alliance organization (blockchain node) generates its own public-private key pair for interacting with user identity information, registers the public key information on the blockchain, and records the on-chain addressing information. After the user uploads their identity attribute information to the identity information provider and the provider authenticates the identity, the user's public-private key pair is also recorded on the blockchain and the on-chain addressing information is returned to the user.
[0083] Step 300: Decrypt the identity authentication result and feed the identity authentication result back to the user.
[0084] When a user authenticates his / her identity at a verification agency, the user completes the cross-agency authentication process by having the disclosure of information authorized by the providing agency and then encrypted by the providing agency before transmitting it to the verification agency.
[0085] In a preferred embodiment, Figure 2 As shown, a blockchain-based identity authentication method applicable to an identity authentication initiating node also includes:
[0086] Step 400: Forward the encrypted user cross-node identity authentication request to other nodes in the blockchain;
[0087] Step 500: Receive the consensus result of the other nodes regarding the user's cross-node identity authentication request;
[0088] Blockchain nodes are allocated to different business systems. Each blockchain node has a consistent structure and is deployed with an identity authentication service smart contract. For example, the total number of blockchain nodes in a business chain is 3f+1, where f represents the number of supported fault-tolerant nodes, with a minimum value of 1. Smart contract transaction requests use the PBFT Byzantine Fault Tolerance algorithm for consensus. A transaction consensus request must be received by each blockchain node in the business chain after receiving at least 2f+1 consistent confirmation messages from other blockchain nodes. Only then can the transaction be completed and the execution result be generated as legal data and persisted in a new block.
[0089] Step 600: When the consensus results of the other nodes are consistent, the identity authentication result is persisted on the blockchain.
[0090] On the other hand, the user's cross-node identity authentication request can also be replaced by business transaction requests such as public key registration, digital certificate issuance, and data directory registration. The internal structure of all blockchain nodes is consistent. The transaction is verified for permissions and repeated submission and parameter legitimacy verification are completed. After the verification is passed, the transaction is broadcast to all other blockchain nodes in business chain 1, and the consensus transaction request broadcast notification from other blockchain nodes is received. The consensus transaction is verified for parameter legitimacy. After the verification is passed, consensus is entered. Each blockchain node must receive consistent confirmation messages from 2f+1 other blockchain nodes before consensus can be completed. New block data is generated according to the data processed according to the logic in the contract, and the world state is updated.
[0091] In a preferred embodiment, Figure 3 As shown, step 300 specifically includes:
[0092] Step 301: Persistently store the user's public key and user identification information on the blockchain to generate a unique identifier;
[0093] The public key information of the organization and the user is registered on the chain, and a PubID unique identifier is generated on the chain, which serves as the unique identifier for addressing the public key information of the organization and the user on the chain.
[0094] Step 302: Decrypt the identity authentication result according to the unique identifier.
[0095] In a preferred embodiment, after the user receives the identity authentication result, the user also needs to sign the identity authentication result and select the information that needs to be authorized to achieve accurate authorization.
[0096] According to one aspect of the present invention, this embodiment discloses a blockchain-based identity authentication method suitable for performing identity authentication on a node. Figure 4 As shown, in this embodiment, the method includes:
[0097] Step A: receiving an encrypted user cross-node identity authentication request sent by a node in a blockchain; wherein a smart contract for user identity authentication is deployed in the blockchain;
[0098] Specifically, the identity authentication node calls the identity authentication request initiation node to register the organization's public key information. The identity authentication request initiation node verifies the legitimacy of the identity authentication node. Upon successful verification, it generates a public key addressing index (PubID) for the organization. Using the PubID as the key, it updates the organization's public key information, organization identification information, and additional custom attribute information such as the organization description on the chain. The private key is stored by the identity authentication node.
[0099] Step B: When the user passes the identity authentication, generating an identity authentication result for the user's cross-node identity authentication request;
[0100] Specifically, different nodes make standard agreements on identity information exchange based on the requirements for the use of identity attribute information. The identity authentication node classifies the user identity information by attributes and extracts fingerprints, and issues blank certificates for identity information exchange. When the identity authentication node needs to obtain user identity information, the user signs and authorizes the corresponding classified identity attribute information, and then the identity authentication node fills in the blank certificate, encrypts it, and sends it to the node initiating the identity authentication request. The identity authentication node obtains the user attribute information after decryption, signature verification, fingerprint verification and other processes.
[0101] Step C: Encrypt the identity authentication result and send it to the node.
[0102] At the identity authentication node, users select identity disclosure information by category. After confirming the information and signing it with their private key, an identity authentication credential is generated. The identity provider transmits the identity credential, or the user directly submits it to the authentication agency. Transmission by the identity provider uses the authentication agency's on-chain public key for encryption. The authentication agency decrypts the identity credential and verifies it using the on-chain public key and data fingerprint information, obtaining the user's true identity attributes and completing user authentication.
[0103] In one embodiment, if Figure 5 As shown, step B includes:
[0104] Step B1: calling the node to register a blank certificate in the blockchain;
[0105] Step B2: Fill in the blank credential according to the user cross-node identity authentication request to generate the identity authentication result.
[0106] In steps B1 and B2, the identity authentication node calls the district identity authentication request initiation node to register the blank credential information. After verifying the legitimacy of the identity authentication node, the district identity authentication request initiation node generates a unique index (VCid) for the blank credential. Using the VCid and the institution's PubID as keys, it updates the credential fingerprint information and institution information on the blockchain.
[0107] In one embodiment, if Figure 6 As shown, the blockchain-based identity authentication method applicable to the identity authentication node also includes:
[0108] Step D: Decrypt the user's cross-node identity authentication request based on the unique identifier corresponding to the user in the blockchain to determine the user's identity.
[0109] The identity authentication node uses its own private key that matches the public key corresponding to the PubID on the chain to decrypt the identity certificate.
[0110] The present invention realizes the secure transfer and authentication of identity attribute information across institutions based on technologies such as DPKI, verifiable credentials, and data fingerprints. Institutions and users all have their own public and private key pair information, store the public key information on the blockchain, and return the on-chain addressing information of the public key information. Institutions make standard agreements on identity information interaction based on the use requirements of identity attribute information. The user identity information provider classifies the user identity information by attribute and extracts fingerprints, and issues blank certificates for identity information interaction. When the certification agency needs to obtain user identity information, the user signs and authorizes the corresponding classified identity attribute information, and the provider then fills in the blank certificate, encrypts it, and sends it to the certification agency. The verification agency obtains the user attribute information after processes such as decryption, signature verification, and fingerprint verification. Endorsement on the entire process chain ensures the accuracy of the user authorization scope, the verifiable identity information, and the traceability of the interactive information, thereby strengthening the security and trust mechanism of cross-institutional authentication.
[0111] In a specific embodiment, the present invention also provides a specific embodiment of a blockchain-based identity authentication method, which specifically includes the following contents.
[0112] Brief introduction to terminology:
[0113] Alliance chain: Business cooperation organizations form a blockchain alliance network based on business needs, extract business rules into business smart contracts and deploy them on the blockchain alliance network to endorse specific business data.
[0114] Verifiable digital credentials: A credential is a description of an entity's attributes. A verifiable credential is a tamper-proof credential signed and encrypted by the issuer, offering cryptographic security and privacy protection. It typically consists of at least two pieces of information: the verifiable credential itself, which includes credential metadata and claims; and the digital signature of the verifiable credential.
[0115] DPKI: A decentralized public key infrastructure that associates public keys with entity identifiers and stores and retrieves public key information based on decentralized nodes.
[0116] Data fingerprint: refers to the compression of original data through hash function technology, and the extraction of the generated unique hash value, namely the hash value. Since the hash value generated by different original data is different, it can be used as a basis for determining whether the original data has been modified.
[0117] See also Figure 7 The specific embodiment of the present invention first provides an identity authentication system based on blockchain, which includes: a business chain 1, a blockchain node 2, and a business system 3.
[0118] Business Chain 1: This is organized based on the identity authentication requirements between business systems of different external institutions. Blockchain Node 2 is assigned to each business system. Each blockchain node has a consistent structure and is deployed with an identity authentication service smart contract. The total number of blockchain nodes in the business chain is 3f+1, where f represents the number of supported fault-tolerant nodes, with a minimum value of 1. Smart contract transaction requests use the PBFT Byzantine Fault Tolerance algorithm for consensus. A transaction consensus request must be received by each blockchain node in the business chain after receiving at least 2f+1 consistent confirmation messages from other blockchain nodes. Only then can the transaction reach consensus and the execution result be generated as legal data and persisted in a new block.
[0119] Blockchain Node 2: This node is used for identity authentication-related transaction requests initiated by Business System 3, including public key registration, digital certificate issuance, data directory registration, and other business transaction requests. All blockchain nodes have the same internal structure. They verify transaction permissions and complete duplicate submission and parameter legitimacy checks. Once verified, they broadcast the transaction to all other blockchain nodes 2 in Business Chain 1. They receive consensus transaction request broadcast notifications from other blockchain nodes 2 and perform parameter legitimacy checks on the consensus transaction. Once verified, they enter consensus. Each blockchain node 2 must receive consistent confirmation messages from 2f+1 other blockchain nodes 2 to reach consensus. The data processed according to the contract logic generates new block data and updates the world state.
[0120] Business system 3: Business transaction request initiation system, which integrates cryptographic components such as public and private key pairs and data fingerprint extraction. Based on the user's identity authorization and authentication operation request, it submits an identity authentication smart contract transaction request to blockchain node 2 of business chain 1, receives the transaction request processing return information from blockchain node 2, and performs a closed loop of related business logic.
[0121] In a more specific embodiment, a blockchain node is responsible for the following operations:
[0122] 1. Public key registration: Register the public key information of the organization and the user on the chain, and generate a PubID unique identifier on the chain, which serves as the unique identifier for addressing the public key information of the organization and the user on the chain.
[0123] 2. Issuance of digital certificates: The organization implements the identity authentication business process to generate a blank certificate, which contains the signature information of the enterprise mutual recognition information and the template of the user's identity information: When the user needs to pass the identity information, fill in the identity information according to the blank certificate and generate an identity authentication certificate.
[0124] 3. Data directory registration: The cooperative institutions negotiate and agree on the classification of user identity attribute information, such as basic strong verification information (including the user's name and ID card information), basic weak verification information (including the user's name and date of birth), academic qualifications (graduation school, certificate number), hobbies (association membership information), etc. The identity provider classifies and stores user information according to the agreed classification, and uploads the fingerprint information of the classified metadata information to the chain.
[0125] It is understandable that the blank certificate can be designed with attribute fields based on the mutual recognition of institutions and user identities required to be disclosed between alliance institutions, see Table 1:
[0126] Table 1
[0127]
[0128] The identity credential is formed by superimposing the user's identity information on a blank credential. When sent, it is decrypted using the PubID on the verification agency chain. The specific structure is shown in Table 2:
[0129] Table 2
[0130]
[0131] Further, see Figure 8 The blockchain node 2 includes a transaction checking and routing device 11, an identity authentication service device 12 and a transaction consensus and processing device 13.
[0132] The transaction checking and routing device 11 is used for blockchain node initialization. When a blockchain node 2 starts up, it instantiates the identity verification smart contract, activates the identity verification service, and establishes trusted communication connections with all other blockchain nodes 2 in the blockchain 1. Once the blockchain nodes 2 are successfully networked, they can receive transaction requests initiated by the business system 3, authenticate the transaction certificate of the business system 3, and route authenticated, legitimate transactions to the identity verification service 12.
[0133] The identity authentication service device 12 is used to receive requests for user public key registration and query, certificate application and verification, data directory registration and query, etc. within the organization to which the blockchain node 2 belongs. Specifically, it includes a public key registration and query module 121, a certificate application and query module 122, and a directory registration and query module 123.
[0134] The public key registration and query module 121 is used to receive institution and user public key registration requests initiated by the business system 3. During registration, the public key information, institution and user identification information, and other attached custom attribute information of the institution and user are persisted on the chain, and a unique index key PubID is generated and returned to the business system 3. During query, the public key and attribute information at the time of registration are returned based on the PubID number, including the public key information, institution and user identification information, and other attached custom attribute information of the institution and user.
[0135] The credential application and query module 122 is used to receive blank credential application and verification requests initiated by the business system 3. During application, a globally unique credential ID (VCid) is generated for the credential and key information, such as the credential fingerprint and issuing authority, is persisted on the blockchain. During verification, a query is performed based on the credential ID, returning the credential attribute information registered on the blockchain, including key information such as the credential fingerprint and issuing authority.
[0136] The directory registration and query module 123 is used to register and query user information directories based on requests initiated by the business system 3. During registration, the organization's PubID, user's PubID, and data classification number are used as index keys. Registration is performed on the blockchain by user information classification, and the user's identity information directory and specific identity information fingerprint information are persisted on the blockchain.
[0137] The transaction consensus and processing device 14 is the core module for achieving consensus and persistence for update-related transactions. It uses the Byzantine consensus algorithm to perform a three-stage consensus process on transactions: the first stage is pre-prepare consensus, the second stage is prepare consensus, and the third stage is commit consensus. These three stages are executed sequentially. Consensus is completed after receiving consistent confirmation messages from 2f+1 other transaction consensus nodes in the current stage, and the next stage begins. Completion of all three stages of consensus indicates that the transaction request is valid. After successful consensus, the smart contract transaction logic is executed, and the transaction data is persisted to the world state. Specifically, this includes institution and user public key information, blank and identity credential information, and a user information directory.
[0138] See also Figure 9 Based on the above-mentioned blockchain-based identity authentication system, the blockchain-based identity authentication method provided by the specific application example of the present invention includes the following steps:
[0139] Step S201: Alliance cooperation organizations that need to participate in identity joint authentication establish an alliance business chain 1 and complete initialization.
[0140] Each institution deploys blockchain node 2 and connects its business system 3, which requires cross-institutional identity authentication, to its own blockchain node 2. Business chain 1 is initialized and launched. Each institution's blockchain node 2 completes node authentication, records the consensus communication secure connection, and registers client identity certificates for each business system client. The business system integrates public-private key pair cryptographic algorithms and data fingerprint extraction algorithm components, and configures the client identity certificates issued by business chain 1 within the system.
[0141] Step S202: Business system 3 calls blockchain node 2 to register the institution’s public key information.
[0142] Blockchain node 2 verifies the legitimacy of business system 3. Upon successful verification, it generates a public key addressing index (PubID) for the organization. Using the PubID as the key, it updates the blockchain with information including the organization's public key, identification information, and other custom attributes such as the organization's description. Business system 3 retains its own private key.
[0143] Step S203: Business system 3 calls blockchain node 2 to register blank credential information.
[0144] After blockchain node 2 verifies the legitimacy of business system 3, it generates a unique index, VCid, for the blank voucher. Using the VCid and the institution's PubID as keys, it updates the voucher's fingerprint information and the institution's information on the chain. The verification agency queries the chain for the public key corresponding to the provider's orgPubID, the public key corresponding to the user's userPubID, the blank voucher data fingerprint corresponding to the VCid, and the data fingerprint corresponding to the userPubID in the data category within userlabe.
[0145] Step S204: The business system 3 registers a public key for the user according to the user cross-institution identity authentication and authorization protocol.
[0146] After business system 3 authenticates the user, it registers the user's public key and identity information according to the user's cross-institutional identity authentication and identity information disclosure authorization agreement. Blockchain node 2 generates a public key addressing index (PubID) for the user based on the public key request. Using the PubID as the key, blockchain node 2 updates the user's public key information, institution identification information, and other additional custom attributes such as the user description on the blockchain. The user's private key is maintained by the user.
[0147] Step S205: the business system 3 registers an identity information directory for the user according to the user's cross-institution identity information disclosure authorization agreement.
[0148] Based on the user's authorized disclosure scope and the agreed standards between alliance organizations, the business system copies the identity information by information category and registers the information category and identity information fingerprint information on the chain, thus forming a data resource directory for user identity information disclosure. In response to the business system's request, blockchain node 2 uses the organization PubID, user PubID, and data category number as keys to persist the user's identity information fingerprint information under this category on the chain.
[0149] Step S206: The user requests the business system 3 of the identity provider to generate identity credentials for the user and perform cross-institutional identity authentication.
[0150] In business system 3, users select identity disclosure information by category. They confirm the information and sign it with their private key, generating an identity authentication credential. The identity provider transmits the credential, or the user directly submits it to the authentication authority. Transmission by the provider encrypts it using the authentication authority's on-chain public key. The authentication authority decrypts the credential and verifies it using the on-chain public key and data fingerprint information, obtaining the user's true identity attributes and completing user authentication. The authentication authority decrypts the credential using its own private key, which matches the public key corresponding to the on-chain PubID, and verifies the orgsigninfo information using the provider's public key, proving corporate endorsement.
[0151] Also, see Figure 10 The verification process of blockchain node 2 for identity credentials includes the following steps:
[0152] S100: Decrypt the verification certificate.
[0153] The verification authority uses its own private key that matches the public key corresponding to the PubID on the chain to decrypt the identity certificate
[0154] S200: On-chain information query.
[0155] The verification agency queries the public key corresponding to the provider's orgPubID, the public key corresponding to the user's userPubID, the blank certificate data fingerprint corresponding to VCid, and the data fingerprint corresponding to userPubID under the data category in userlabe on the chain.
[0156] S300: Verify the credential information.
[0157] Use the public key of the providing organization to verify the orgsigninfo information to prove that it is corporate endorsement; use the user's public key to verify the usersigninfo information to prove that it is information verified by the user; use the blank certificate fingerprint to verify the data integrity of the blank certificate; use the digital fingerprint of the user data to verify the integrity of the user's identity information.
[0158] S400: User attribute information verification.
[0159] Use user disclosed information to verify user identity and provide services based on the verification results.
[0160] From the above description, it can be seen that, first, an embodiment of the present invention provides a blockchain-based identity authentication method suitable for an identity authentication initiating node, the method including responding to a received user cross-node identity authentication request, forwarding the encrypted user cross-node identity authentication request to a node with user identity information in the blockchain, wherein a smart contract for user identity authentication is deployed in the blockchain; receiving the encrypted identity authentication result sent by the node with user identity information; decrypting the identity authentication result, and feeding back the identity authentication result to the user.
[0161] Next, an embodiment of the present invention also provides a blockchain-based identity authentication method suitable for an identity authentication node, including: receiving an encrypted user cross-node identity authentication request sent by a node in the blockchain; wherein a smart contract for user identity authentication is deployed in the blockchain; when the user passes the identity authentication, an identity authentication result is generated for the user's cross-node identity authentication request; and the identity authentication result is encrypted and sent to the node.
[0162] Specifically, the present invention has the following beneficial effects:
[0163] 1. Improve the authenticity of identity information: The identity provider will upload the fingerprint information of the identity metadata information to the chain. After receiving the data, the verification agency can verify the data through the fingerprint information on the chain to ensure the authenticity and integrity of the data.
[0164] 2. Reduce the risk of leakage of user identity information: The provider and verification agency agree on the identity information interaction standards, classify and manage user identity attribute information, and the user accurately authorizes the verification agency based on its actual usage needs to ensure that user identity information is disclosed to the minimum extent.
[0165] 3. Improve the trust mechanism of the entire process: The authorization and usage information of user information are permanently stored on the chain and disclosed to the institutions and users on the chain. At the same time, it can support the introduction of authoritative institutions to conduct supervision based on the on-chain information, thereby improving the trust mechanism of the entire verification process.
[0166] Based on the same principle, this embodiment also discloses a blockchain-based identity authentication method. The execution subject of this method is a blockchain node, and the method includes:
[0167] In response to a received user cross-node identity authentication request, forward the encrypted user cross-node identity authentication request to a node in the blockchain having the user's identity information; receive the encrypted identity authentication result sent by the node having the user's identity information; decrypt the identity authentication result, and feed the identity authentication result back to the user, wherein a smart contract for user identity authentication is deployed in the blockchain, and
[0168] The invention relates to a method for receiving an encrypted user cross-node identity authentication request sent by a node in a blockchain; generating an identity authentication result for the user cross-node identity authentication request when the user passes the identity authentication; encrypting the identity authentication result and sending it to the node, wherein a smart contract for user identity authentication is deployed in the blockchain.
[0169] Since the principle of solving the problem by this method is similar to that of the above method, the implementation of this method can refer to the implementation of the method, and will not be repeated here.
[0170] Based on the same principle, see Figure 11 This embodiment further discloses a blockchain-based identity authentication device applicable to an identity authentication initiating node, the device comprising:
[0171] A first request forwarding module 10 is configured to forward, in response to a received user cross-node identity authentication request, an encrypted user cross-node identity authentication request to a node in a blockchain having user identity information; wherein a smart contract for user identity authentication is deployed in the blockchain;
[0172] The authentication result receiving module 20 is used to receive the encrypted identity authentication result sent by the node having the user identity information;
[0173] The authentication result decryption module 30 is used to decrypt the identity authentication result and feed the identity authentication result back to the user.
[0174] Preferably, see Figure 12 , the blockchain-based identity authentication device applicable to the identity authentication initiation node also includes:
[0175] A second request forwarding module 40 is configured to forward the encrypted user cross-node identity authentication request to other nodes in the blockchain;
[0176] A consensus result receiving module 50 is configured to receive the consensus result of the other nodes regarding the user's cross-node identity authentication request;
[0177] The authentication result persistence module 60 is used to persist the identity authentication result on the blockchain when the consensus results of the other nodes are consistent.
[0178] Preferably, see Figure 13 The authentication result decryption module 30 includes:
[0179] An identifier generation unit 301 is configured to generate a unique identifier persistently on the blockchain based on the user's public key and user identification information;
[0180] The authentication result generating unit 302 is configured to decrypt the identity authentication result according to the unique identifier.
[0181] In one embodiment, see Figure 14 The present invention also discloses a blockchain-based identity authentication device suitable for performing identity authentication on a node, the device comprising:
[0182] An authentication request receiving module A is configured to receive an encrypted user cross-node identity authentication request sent by a node in a blockchain; wherein a smart contract for user identity authentication is deployed in the blockchain;
[0183] Authentication result generation module B, used to generate an identity authentication result for the user's cross-node identity authentication request when the user passes the identity authentication;
[0184] The authentication result encryption module C is used to encrypt the identity authentication result and send it to the node.
[0185] Preferably, see Figure 15 , the authentication result generation module B includes:
[0186] A blank certificate registration unit B1 is used to call the node to register a blank certificate in the blockchain;
[0187] The authentication result generating unit B2 is configured to fill in the blank credential according to the user cross-node identity authentication request to generate the identity authentication result.
[0188] Preferably, see Figure 16 , the blockchain-based identity authentication device suitable for performing identity authentication nodes also includes:
[0189] The user identity determination module D is used to decrypt the user cross-node identity authentication request according to the unique identifier corresponding to the user in the blockchain to determine the user identity.
[0190] Since the principle of solving the problem by this device is similar to that of the above method, the implementation of this device can refer to the implementation of the method and will not be repeated here.
[0191] Based on the same principle, this embodiment also discloses a blockchain node. The blockchain node is configured to respond to a received user cross-node identity authentication request, forward the encrypted user cross-node identity authentication request to a node in the blockchain with user identity information; receive the encrypted identity authentication result sent by the node with user identity information; decrypt the identity authentication result, and feed the identity authentication result back to the user, wherein a smart contract for user identity authentication is deployed in the blockchain, and
[0192] The invention relates to a method for receiving an encrypted user cross-node identity authentication request sent by a node in a blockchain; generating an identity authentication result for the user cross-node identity authentication request when the user passes the identity authentication; encrypting the identity authentication result and sending it to the node, wherein a smart contract for user identity authentication is deployed in the blockchain.
[0193] Since the principle of solving the problem by this node is similar to the above method, the implementation of this node can refer to the implementation of the method and will not be repeated here.
[0194] Based on the same principle, this embodiment also discloses a blockchain-based identity authentication system. The blockchain-based identity authentication system includes an identity authentication request node, an identity authentication node, and a blockchain;
[0195] The identity authentication request node is configured to respond to a received user cross-node identity authentication request by forwarding the encrypted user cross-node identity authentication request to a node in the blockchain that has the user's identity information; receive the encrypted identity authentication result sent by the node that has the user's identity information; decrypt the identity authentication result, and feed the identity authentication result back to the user;
[0196] The identity authentication node is used to receive an encrypted user cross-node identity authentication request sent by a node in the blockchain; when the user passes the identity authentication, generate an identity authentication result for the user cross-node identity authentication request; encrypt the identity authentication result and send it to the node;
[0197] A smart contract for user identity authentication is deployed in the blockchain.
[0198] Since the principle of solving the problem by this system is similar to that of the above method, the implementation of this system can refer to the implementation of the method and will not be repeated here.
[0199] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer device. Specifically, the computer device may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0200] In a typical example, a computer device specifically includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the method executed by the client as described above is implemented, or when the processor executes the program, the method executed by the server as described above is implemented.
[0201] Reference below Figure 17 , which shows a structural schematic diagram of a computer device suitable for implementing an embodiment of the present application.
[0202] like Figure 17 As shown, the computer device includes a central processing unit (CPU) 601, which can perform various appropriate tasks and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage part 608 into the random access memory (RAM) 603. Various programs and data required for system operation are also stored in the RAM 603. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0203] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, and the like; an output section 607 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 608 including devices such as a hard disk; and a communication section 609 including a network interface card such as a LAN card or a modem. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. Removable media 611, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 610 as needed, so that computer programs read therefrom can be installed in the storage section 608 as needed.
[0204] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program tangibly embodied on a machine-readable medium, the computer program including program code for executing the methods illustrated in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication portion 609 and / or installed from removable media 611.
[0205] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0206] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0207] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0208] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0209] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0210] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0211] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0212] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0213] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0214] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A blockchain-based identity authentication method, characterized in that: Applicable to identity authentication initiation nodes, including: In response to a received user cross-node identity authentication request, forward the encrypted user cross-node identity authentication request to a node of a verification agency having user identity information in a blockchain, wherein a smart contract for performing user identity authentication is deployed in the blockchain; the blockchain is a consortium chain, and the consortium chain is formed between the local identity authentication initiating node and the node of the verification agency having user identity information; Receiving the encrypted identity authentication result sent by the node of the verification agency having the user identity information; Decrypting the identity authentication result and feeding the identity authentication result back to the user; Decrypting the identity authentication result includes: Persisting the public key of the node of the verification authority having the user identity information, the public key of the user, and the user identification information on the blockchain to generate a PubID unique identifier; Decrypting the identity authentication result according to the PubID unique identifier; The PubID unique identifier is used to address the public key of the node of the verification agency having the user identity information and the public key of the user on the blockchain; The node of the verification agency with the user's identity information uses the matching private key of the public key corresponding to the PubID unique identifier on the chain to decrypt the user's identity certificate.
2. The blockchain-based identity authentication method according to claim 1, characterized in that: Also includes: Forwarding the encrypted user cross-node identity authentication request to other nodes in the blockchain; Receiving a consensus result of the other nodes regarding the user's cross-node identity authentication request; When the consensus results of the other nodes are consistent, the identity authentication result is persisted on the blockchain.
3. A blockchain-based identity authentication method, characterized in that: Applicable to nodes of verification agencies with user identity information, including: Receiving an encrypted user cross-node identity authentication request sent by an identity authentication initiating node in a blockchain; a smart contract for user identity authentication is deployed in the blockchain; the blockchain is a consortium chain, and the consortium chain is formed between a node of a local verification agency with user identity information and an identity authentication initiating node; the identity authentication initiating node is used to send the encrypted user cross-node identity authentication request to the node of the local verification agency with user identity information; When the user passes the identity authentication, generating an identity authentication result for the user's cross-node identity authentication request; Encrypting the identity authentication result and sending it to the identity authentication initiating node; The identity authentication initiating node is used to decrypt the identity authentication result; The decrypting the identity authentication result includes: Persisting the public key of the node of the verification authority having the user identity information, the public key of the user, and the user identification information on the blockchain to generate a PubID unique identifier; Decrypting the identity authentication result according to the PubID unique identifier; The PubID unique identifier is used to address the public key of the node of the verification agency with the user identity information and the user's public key on the blockchain; The node of the verification agency with the user's identity information uses the matching private key of the public key corresponding to the PubID unique identifier on the chain to decrypt the user's identity certificate.
4. The blockchain-based identity authentication method according to claim 3, characterized in that: Generating an identity authentication result for the user cross-node identity authentication request includes: The node of the verification agency having the user identity information registers a blank certificate in the blockchain; Fill in the blank credential according to the user cross-node identity authentication request to generate the identity authentication result.
5. The blockchain-based identity authentication method according to claim 3, characterized in that: When a user passes identity authentication, before generating an identity authentication result for the user's cross-node identity authentication request, the process includes: The user's cross-node identity authentication request is decrypted according to the PubID unique identifier corresponding to the user in the blockchain to determine the user's identity.
6. A blockchain-based identity authentication device, characterized in that: Applicable to identity authentication initiation nodes, including: a first request forwarding module configured to, in response to a received user cross-node identity authentication request, forward the encrypted user cross-node identity authentication request to a node of a verification authority having user identity information in a blockchain; wherein a smart contract for performing user identity authentication is deployed in the blockchain; and wherein the blockchain is a consortium chain, and wherein the consortium chain is formed between a local authentication initiating node and a node of a verification authority having user identity information; An authentication result receiving module, configured to receive the encrypted identity authentication result sent by the node of the verification agency having the user identity information; An authentication result decryption module is used to decrypt the identity authentication result and feed the identity authentication result back to the user; Decrypting the identity authentication result includes: Persisting the public key of the node of the verification authority having the user identity information, the public key of the user, and the user identification information on the blockchain to generate a PubID unique identifier; Decrypting the identity authentication result according to the PubID unique identifier; The PubID unique identifier is used to address the public key of the node of the verification agency with the user identity information and the user's public key on the blockchain; The node of the verification agency with the user's identity information uses the matching private key of the public key corresponding to the PubID unique identifier on the chain to decrypt the user's identity certificate.
7. A blockchain-based identity authentication device, characterized in that: Applicable to nodes of verification agencies with user identity information, including: An authentication request receiving module, configured to receive an encrypted user cross-node identity authentication request sent by an identity authentication initiating node in a blockchain; the blockchain being deployed with a smart contract for user identity authentication; the blockchain being a consortium chain, and the consortium chain being formed between a local node of a verification authority having user identity information and an identity authentication initiating node; the identity authentication initiating node being configured to send the encrypted user cross-node identity authentication request to the local node of the verification authority having user identity information; An authentication request generation module, configured to generate an identity authentication result for a cross-node identity authentication request of the user when the user passes the identity authentication; An authentication request encryption module, configured to encrypt the identity authentication result and send it to the identity authentication initiating node; The identity authentication initiating node is used to decrypt the identity authentication result; The decrypting the identity authentication result includes: Persisting the public key of the node of the verification authority having the user identity information, the public key of the user, and the user identification information on the blockchain to generate a PubID unique identifier; Decrypting the identity authentication result according to the PubID unique identifier; The PubID unique identifier is used to address the public key of the node of the verification agency with the user identity information and the user's public key on the blockchain; The node of the verification agency with the user's identity information uses the matching private key of the public key corresponding to the PubID unique identifier on the chain to decrypt the user's identity certificate.
8. A blockchain-based identity authentication system, characterized in that: It includes the identity authentication initiation node, the verification agency's node with user identity information, and the blockchain; An identity authentication initiating node, configured to respond to a received user cross-node identity authentication request and forward the encrypted user cross-node identity authentication request to a node of a verification authority in the blockchain that has the user identity information; Receiving the encrypted identity authentication result sent by the node of the verification agency having the user identity information; Decrypting the identity authentication result and feeding the identity authentication result back to the user; The node of the verification agency with the user identity information is used to receive the encrypted user cross-node identity authentication request sent by the identity authentication initiating node in the blockchain; When the user passes the identity authentication, generating an identity authentication result for the user's cross-node identity authentication request; Encrypting the identity authentication result and sending it to the identity authentication initiating node; A smart contract for user identity authentication is deployed in the blockchain; The blockchain is a consortium chain, and the consortium chain is formed between the identity authentication initiating node and the node of the verification agency having the user identity information; The decrypting the identity authentication result includes: Persisting the public key of the node of the verification authority having the user identity information, the public key of the user, and the user identification information on the blockchain to generate a PubID unique identifier; Decrypting the identity authentication result according to the PubID unique identifier; The PubID unique identifier is used to address the public key of the node of the verification agency with the user identity information and the user's public key on the blockchain; The node of the verification agency with the user's identity information uses the matching private key of the public key corresponding to the PubID unique identifier on the chain to decrypt the user's identity certificate.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the blockchain-based identity authentication method according to any one of claims 1 to 5 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the blockchain-based identity authentication method described in any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
User information processing method and device based on distributed storage
CN113836573A