Distributed digital identity authentication method, system, computer storage medium and terminal
By adopting a distributed digital identity management method, the problem of identity authentication and attribute authentication that existing technologies cannot solve is solved, realizing the association and management of user and attribute information, and improving the efficiency and security of smart blockchain IoT services.
Patent Information
- Application Number
- CN202211249032.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-12
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2042-10-12
AI Technical Summary
Existing digital element configuration platforms cannot complete identity authentication, attribute authentication, and contract authentication at the digital authentication level, resulting in the inability to associate and manage user and attribute information, and thus failing to meet the needs of smart blockchain IoT services.
This paper provides a distributed digital identity management method. Through the communication network between the client and the distributed digital identity management system, digital certificate registration and approval system, attribute certificate issuance and management system and information security system, it generates and manages distributed attribute information and identity certificates, realizes the issuance, updating and querying of attribute certificates, and ensures the encryption and decryption of information.
Under the premise of privacy protection, we can achieve accurate business matching, reliable verification and optimized transaction models, improve business success rate, and realize the association and management of user and attribute information.
Smart Images

Figure CN115603916B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of Internet of Things, and relates to a management method and system, in particular to a distributed digital identity management method and system, a computer readable storage medium and a terminal. BACKGROUND
[0002] At present, the blockchain technology is developing rapidly. In the past 10 years, it has experienced 'blockchain 1.0' marked by encrypted digital currency, and 'blockchain 2.0' marked by smart contract. At present, it has entered the application stage of 'blockchain 3.0' for establishing cross-organizational mutual trust. The combination with various technologies is developing rapidly, and the industrial value in various traditional industries is gradually highlighted.
[0003] However, the existing digital element configuration platform cannot complete identity authentication, attribute authentication and contract authentication from the digital authentication level to establish an intelligent blockchain Internet of Things service, so that the user and attribute information cannot be associated and managed.
[0004] Therefore, how to provide a distributed digital identity management method, system, computer readable storage medium and terminal to solve the problem that the prior art cannot complete identity authentication, attribute authentication and contract authentication from the digital authentication level to establish an intelligent blockchain Internet of Things service, so that the user and attribute information cannot be associated and managed, has become a technical problem to be solved by those skilled in the art. SUMMARY
[0005] In view of the above-mentioned shortcomings of the prior art, the purpose of the present application is to provide a distributed digital identity management method, system, computer readable storage medium and terminal to solve the problem that the prior art cannot complete identity authentication, attribute authentication and contract authentication from the digital authentication level to establish an intelligent blockchain Internet of Things service, so that the user and attribute information cannot be associated and managed.
[0006] To achieve the above object and other related objects, the present application provides a distributed digital identity management method for managing distributed digital identity of a client, which is applied to a communication network including a distributed digital identity management system, a digital certificate registration and approval system, an attribute certificate issuing and management system and an information security system; the client sends an identity certificate application request to the distributed digital identity management system; the distributed digital identity management method comprises: forwarding the identity certificate application request to the digital certificate registration and approval system to obtain an identity certificate issued by the digital certificate registration and approval system for the client; generating distributed attribute information associated with the client based on past transaction records of the client, and generating an attribute certificate application request based on the distributed attribute information associated with the client and the identity certificate of the client; sending the attribute certificate application request to the attribute certificate issuing and management system, forwarding the attribute certificate application request to the information security system through the attribute certificate issuing and management system, and issuing the attribute certificate to the distributed digital identity management system after the information security system generates the attribute certificate; and issuing the attribute certificate to the client associated therewith.
[0007] In an embodiment of the present application, the distributed digital identity management method further comprises encrypting the distributed attribute information while generating the distributed attribute information associated with the client.
[0008] In an embodiment of the present application, the attribute certificate comprises a certificate owner identity code, a certificate generation code, a signature algorithm, a validity period, an attribute label, a credit feature and attributes of a certificate holder.
[0009] In an embodiment of the present application, the distributed digital identity management method further comprises: sending an attribute certificate update request to the attribute certificate issuing and management system when the distributed attribute information is changed, forwarding the attribute certificate update request to the information security system through the attribute certificate issuing and management system, reissuing the updated attribute certificate to the distributed digital identity management system after the information security system generates the updated attribute certificate, and issuing the updated attribute certificate to the client associated therewith by the distributed digital identity management system.
[0010] In an embodiment of the present application, the distributed digital identity management method further comprises: revoking the issued attribute certificate after the information security system generates the updated attribute certificate.
[0011] In an embodiment of the present application, the distributed digital identity management method further comprises: after the client receives the attribute certificate or the updated attribute certificate, receiving an attribute query request sent by a first client; the attribute query request is a request of the first client querying attribute information of a second client with which the first client intends to transact; according to the attribute query request, searching for the attribute certificate of the second client; after receiving the attribute certificate or the updated attribute certificate submitted by the first client, decrypting the attribute certificate or the updated attribute certificate to obtain the authority of the first client; according to the authority of the first client, extracting the attribute information of the second client matched with the authority.
[0012] In an embodiment of the present application, the attribute query request comprises a type of certificate, a certificate number, a name or an identity certificate of the second client with which the first client intends to transact.
[0013] In another aspect of the present application, a distributed digital identity management system is provided for managing a distributed digital identity of a client; the distributed digital identity management system is included in a communication network; the communication network further comprises a digital certificate registration and approval system, an attribute certificate issuing and management system and an information security system; the distributed digital identity management system comprises: a communication module for forwarding the identity certificate application request to the digital certificate registration and approval system to obtain an identity certificate issued by the digital certificate registration and approval system for the client; an attribute information generation module for generating distributed attribute information associated with the client based on past transaction records of the client, and generating an attribute certificate application request comprising the distributed attribute information associated with the client and the identity certificate of the client; after generating the attribute certificate application request, sending the attribute certificate application request to the attribute certificate issuing and management system by using the communication module, forwarding the attribute certificate application request to the information security system by the attribute certificate issuing and management system, and after the information security system generates an attribute certificate, issuing the attribute certificate to the distributed digital identity management system, and then sending the attribute certificate to the client associated therewith by using the communication module.
[0014] In still another aspect of the present application, a computer readable storage medium is provided, which stores a computer program; when the computer program is executed by a processor, the distributed digital identity management method is implemented.
[0015] In the last aspect of the present application, a terminal is provided, which comprises: a processor and a memory; the memory is used for storing a computer program, and the processor is used for executing the computer program stored in the memory to make the terminal execute the distributed digital identity management method.
[0016] As described above, the distributed digital identity management method, system, computer readable storage medium and terminal of the present application have the following beneficial effects:
[0017] The distributed digital identity management method, system, computer readable storage medium and terminal of the present application can conduct business precise matching, reliable verification and optimized transaction mode under the premise of privacy protection according to the distributed digital identity including attribute label and credit characteristics in actual application scenarios, improve the success rate of business, and realize the association and management of user and attribute information. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 The application scenario of the present application is shown.
[0019] Figure 2A The distributed digital identity management method of the present application is shown.
[0020] Figure 2B The distributed digital identity management method of the present application is shown.
[0021] Figure 2C The distributed digital identity management method of the present application is shown.
[0022] Figure 3 The principle structure of the distributed digital identity management system of the present application in one embodiment is shown.
[0023] Element number explanation
[0024] 1 communication network
[0025] 11 distributed digital identity management system
[0026] 12 digital certificate registration and approval system
[0027] 13 attribute certificate issuing and management system
[0028] 14 information security system
[0029] 15 client
[0030] 3 distributed digital identity management system
[0031] 31 communication module
[0032] 32 attribute information generation module
[0033] 33 update module
[0034] 34 query processing module
[0035] S21-S24 steps
[0036] S25-S27 steps
[0037] S28-S31 steps DETAILED DESCRIPTION
[0038] Other advantages and benefits of the present application will become apparent to those skilled in the art upon consideration of the disclosure or can be learned by practice of the application. The application can be realized and achieved by means of the structures and combinations of the features set forth in the description above. Various modifications and changes can be made thereto without departing from the spirit and scope of the application. It is to be understood that the following examples and features thereof can be combined with each other, if not in conflict.
[0039] It is to be noted that the drawings provided in the following examples are only schematic and are intended to provide a general understanding of the present application. In particular, the shape, relative scale, and proportions of the illustrated components are not intended to be limiting. The figures are only meant to be illustrative and are not intended to limit the scope of the application.
[0040] Example 1
[0041] The present embodiment provides a distributed digital identity management method for managing distributed digital identity of a client. The distributed digital identity management method is applied to a communication network comprising a distributed digital identity management system, a digital certificate registration and approval system, an attribute certificate issuing and management system, and an information security system. The client sends an identity certificate application request to the distributed digital identity management system. The distributed digital identity management comprises:
[0042] forwarding the identity certificate application request to the digital certificate registration and approval system to obtain an identity certificate issued by the digital certificate registration and approval system for the client;
[0043] generating distributed attribute information associated with the client based on past transaction records of the client, and generating an attribute certificate application request based on the distributed attribute information associated with the client and the identity certificate of the client;
[0044] sending the attribute certificate application request to the attribute certificate issuing and management system, forwarding the attribute certificate application request to the information security system through the attribute certificate issuing and management system, and issuing the attribute certificate to the distributed digital identity management system after the information security system generates the attribute certificate;
[0045] issuing the attribute certificate to the client associated therewith.
[0046] The following will describe in detail the distributed digital identity management method provided in this embodiment with reference to the illustrations. The distributed digital identity management method described in this embodiment is used to manage the distributed digital identity of clients. The distributed digital identity in this embodiment is an information identifier that authenticates system users' identity characteristics, attribute characteristics, and credit characteristics based on blockchain distributed technology. Distributed digital identity is not only for individual and enterprise users but also for intelligent machines; that is, machines also have identities within the system. In addition to basic user information, distributed identity also includes user attribute characteristics and credit characteristics. These characteristics are presented in the form of tags and scores at the system front end, relying on trusted and limited-value data sources and special artificial intelligence algorithms, and completing verification and matching based on privacy protection, i.e., obtaining only partial data.
[0047] The clients include, for example, electrolytic copper suppliers, electrolytic aluminum suppliers, and bulk asset financing parties.
[0048] The distributed digital identity management method described in this embodiment is applied to, for example... Figure 1 In the communication network 1 shown, the communication network includes a distributed digital identity management system 11, a digital certificate registration and approval system 12 (hereinafter referred to as the RA system), an attribute certificate issuance and management system 13 (hereinafter referred to as the AC system), and an information security system 14 (hereinafter referred to as the CA system). The client 15 sends an identity certificate application request to the distributed digital identity management system 11. The distributed digital identity management system 11 is used to issue identity certificates through the RA system 12. Simultaneously, the distributed digital identity management system 11 records identity certificate information, generates and encrypts attribute information based on the client's past information, and initiates an attribute certificate application to the AC system 13. The request information includes information such as the identity certificate DN or serial number to complete the binding of the identity certificate and the attribute certificate. The AC system 13 sends the request to the CA system 14 for issuance, and after receiving a reply, returns the attribute certificate to the distributed digital identity management system 11. The AC system 13 and the RA system 14 jointly complete the issuance of the identity certificate and the attribute certificate. The attribute certificate issued by the AC system 13 needs to be bound to the identity certificate information to achieve the binding between the attribute certificate and the identity certificate. The attribute information is encrypted and decrypted by the distributed digital identity management system 11. When the attribute certificate is updated, the distributed digital identity management system 11 updates the attribute information through the AC system 13.
[0049] In this embodiment, the AC system 13 can provide users with attribute certificate application, registration and management functions. Users can use a browser to apply for a certificate through the administrator or the platform through the API interface, and can manage attribute certificates, including certificate query, certificate update and certificate revocation functions.
[0050] The AC system 13 issues attribute certificates based on the identity certificates issued by the RA system 12, and is connected to the CA system 14 in the back end. The functions of issuing, updating, and revoking certificates need to be communicated with the CA system 14 to ensure the consistency of the certificate status.
[0051] The AC system 13 will follow the CA system construction specification, and the system deployment and logical division will be strictly deployed according to the relevant specification, and a hierarchical and modular structure design will be implemented. The final user can apply for and issue attribute certificates through the AC system 13 center, and the AC system 13 will approve the final user's attribute certificate application to meet the needs of enterprise use.
[0052] Please refer to Figure 2A , which shows a schematic diagram of an implementation process of a distributed digital identity management method. As shown in Figure 2A , the distributed digital identity management method specifically includes the following steps:
[0053] S21, forwarding the identity certificate application request to the digital certificate registration and approval system to obtain the identity certificate issued by the digital certificate registration and approval system for the client.
[0054] In this embodiment, the identity certificate application request includes identity information such as the identity code of the client. After the RA system 12 receives the identity certificate application request, the client sending the request is subjected to qualification examination, and it is decided whether to agree to issue an identity certificate to the client.
[0055] S22, based on the identity code of the client, the past transaction records of the client are searched, and based on the past transaction records of the client, the distributed attribute information associated with the client is generated. The distributed attribute information is encrypted, and the distributed attribute information associated with the client and the identity certificate of the client are used to generate an attribute certificate application request.
[0056] S23, send the attribute certificate application request to the attribute certificate issuing and management system (AC system), and forward the attribute certificate application request to the information security system through the attribute certificate issuing and management system. After the information security system generates an attribute certificate, the attribute certificate is issued to the distributed digital identity management system. In this embodiment, the attribute certificate includes the identity code of the certificate owner, the occurrence certificate code, the signature algorithm, the validity period, the attribute label, the credit feature, and the attributes of the certificate holder, etc. In this embodiment, in the actual application scenario of the distributed digital identity, through the specific innovative feature dimension AI algorithm, the attribute label and the credit feature are generated under the condition of only obtaining local data, which can accurately depict the user identity dimension, business feature, transaction preference, and other information.
[0057] In the embodiment, the AC system 13 and the RA system 12 jointly complete the identity certificate and attribute certificate issuance, the attribute certificate issued by the AC system 13 needs to be bound with the identity certificate information, so as to achieve the binding of the attribute certificate and the identity certificate, and the attribute information is processed by the distributed digital identity management system 11.
[0058] S24, the attribute certificate is issued to the client associated therewith.
[0059] Please refer to Figure 2B , which shows another implementation flow diagram of the distributed digital identity management method. As shown in Figure 2B , the distributed digital identity management method further includes:
[0060] S25, when the distributed attribute information is changed, a new distributed attribute information associated with the client is generated, the new distributed attribute information is encrypted, and an attribute certificate update request is generated based on the new distributed attribute information associated with the client and the identity certificate of the client.
[0061] S26, the attribute certificate update request is sent to the attribute certificate issuance management system, and the attribute certificate update request is forwarded to the information security system through the attribute certificate issuance management system.
[0062] S27, after the information security system generates the updated attribute certificate, the issued attribute certificate is revoked, and the updated attribute certificate is reissued to the distributed digital identity management system, so that the distributed digital identity management system issues the updated attribute certificate to the client associated therewith.
[0063] In the embodiment, the attribute information can be encrypted by the distributed digital identity management system using its own institution certificate, and when the client needs to view the attribute of the other party (i.e., the client wants to trade with other clients), the viewing request is sent by a client, and the other party gives authorization after receiving the request. After the distributed digital identity management system is authorized, the attribute information is decrypted, and the part that can be viewed is displayed according to the authority level of different clients. The encryption of the attribute information not only realizes the confidentiality of the information, but also cooperates with the business system to realize the hierarchical management of the authority.
[0064] Please refer to Figure 2C , which shows another implementation flow diagram of the distributed digital identity management method. As shown in Figure 2C , the distributed digital identity management method includes:
[0065] S28, after receiving the attribute certificate or the updated attribute certificate of the client, receiving an attribute query request sent by a first client; the attribute query request is a request of the first client to query attribute information of a second client with which the first client intends to transact.
[0066] S29, according to the attribute query request, searching for the attribute certificate of the second client.
[0067] S30, after receiving the attribute certificate or the updated attribute certificate submitted by the first client, decrypting the attribute certificate or the updated attribute certificate to obtain the authority of the first client. In this embodiment, after the distributed digital identity management 11 receives the attribute certificate or the updated attribute certificate submitted by the first client, it means that the distributed digital identity management 11 obtains the authorization of the first client and can decrypt the attribute information submitted by the first client to obtain the authority level to different clients.
[0068] S31, according to the authority of the first client, extracting the attribute information of the second client matched with the authority, so as to show the first client the attribute information that can be shown in this transaction, for example, showing the attribute label and the credit characteristic, and other attribute information irrelevant to the transaction is not shown.
[0069] The following is an example of another implementation process of the distributed digital identity management method:
[0070] The distributed digital identity management system issues identity certificates and attribute certificates to the first client A and the second clients B and C. The first client A intends to transact with the second clients B and C and needs to be identified. The first client A applies to view the attribute information of the second clients B and C. The first client A obtains the encrypted attribute information of the second clients B and C. The first client A submits the attribute information to the distributed digital identity management system. After decryption, the distributed digital identity management system sees that the first client A is a precious metal trader, and therefore, according to the authority management, shows the first client A the identity information of the second clients B and C that need to be shown in this transaction, for example, showing the experience years, customer praise degree, transaction size, payment habit, public country cycle, credit score, distributed independent credit score, and other attribute labels and credit characteristics of the second clients B and C, and the second clients B and C do not show attribute information about other aspects.
[0071] The distributed digital identity management method described in this embodiment can be used in actual application scenarios based on the distributed digital identity including attribute labels and credit characteristics. It can be used for precise business matching, trusted verification, and optimized transaction mode under the premise of privacy protection, improve the success rate of business, and realize the association and management of users and attribute information.
[0072] The embodiment also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the distributed digital identity management method as described in Figure 2A 2B and 2C.
[0073] At any possible technical detail level, the application can be system, method and / or computer program product. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present application.
[0074] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.
[0075] The computer readable program here can be downloaded from the computer readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer readable program instructions from the network and forwards the computer readable program instructions to be stored in the computer readable storage medium in each computing / processing device. The computer program instructions for performing the operations of the present application can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, integrated circuit configuration data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, and procedural programming languages such as "C" language or similar programming languages. Computer readable program instructions can be executed entirely on a user computer, partially on a user computer, as a separate software package, partially on a user computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet). In some embodiments, by utilizing the state information of the computer readable program instructions to individualize the electronic circuit, such as programmable logic circuit, field programmable gate array (FPGA) or programmable logic array (PLA), the electronic circuit can execute the computer readable program instructions to implement various aspects of the present application.
[0076] The embodiment further provides a distributed digital identity management system for managing the distributed digital identity of the client; the distributed digital identity management system is included in a communication network; the communication network further includes a digital certificate registration and approval system, an attribute certificate issuing and management system, and a communication network of an information security system; the distributed digital identity management system includes:
[0077] A communication module is configured to forward the identity certificate application request to the digital certificate registration and approval system to obtain the identity certificate issued by the digital certificate registration and approval system for the client;
[0078] The attribute information generation module is configured to generate distributed attribute information associated with the client based on the past transaction record of the client, and generate an attribute certificate application request based on the distributed attribute information associated with the client and the identity certificate of the client.
[0079] After the attribute certificate application request is generated, the communication module is used to send the attribute certificate application request to the attribute certificate issuing management system, the attribute certificate application request is forwarded to the information security system through the attribute certificate issuing management system, and after the attribute certificate is generated by the information security system, the attribute certificate is issued to the distributed digital identity management system, and the attribute certificate is then sent to the client associated therewith through the communication module.
[0080] The distributed digital identity management system provided by the present embodiment will be described in detail below. Please refer to Figure 3 , which shows that the distributed digital identity management system 3 includes a communication module 31, an attribute information generation module 32, an updating module 33, and a query processing module 34.
[0081] In an embodiment of the distributed digital identity management system 3, the communication module 31 is configured to forward the identity certificate application request to the digital certificate registration and approval system to obtain the identity certificate issued by the digital certificate registration and approval system for the client.
[0082] In the present embodiment, the identity certificate application request includes information representing identity such as the identity code of the client. After the RA system 12 receives the identity certificate application request, the client sending the request is subjected to qualification examination, and it is decided whether to agree to issue the identity certificate to the client.
[0083] The attribute information generation module 32 is configured to find the past transaction record of the client based on the identity code of the client, generate distributed attribute information associated with the client based on the past transaction record of the client, encrypt the distributed attribute information, and generate an attribute certificate application request based on the distributed attribute information associated with the client and the identity certificate of the client.
[0084] The communication module 31 sends an attribute certificate application request to the attribute certificate issuing management system (AC system), forwards the attribute certificate application request to the information security system through the attribute certificate issuing management system, and issues the attribute certificate to the distributed digital identity management system after the information security system generates the attribute certificate. In this embodiment, the attribute certificate includes certificate owner identity code, certificate generation code, signature algorithm, validity period, attribute label, credit characteristics, and attributes of the certificate holder, etc. In this embodiment, the distributed digital identity generates attribute labels and credit characteristics based on only partial data in the actual application scenario through specific innovative feature dimension AI algorithms, which can accurately depict user identity dimensions, business characteristics, transaction preferences, and other information.
[0085] In this embodiment, the AC system 13 and the RA system 12 jointly complete the issuance of identity certificates and attribute certificates. The attribute certificate issued by the AC system 13 needs to be bound with the identity certificate information, so as to achieve the binding of the attribute certificate and the identity certificate. The attribute information is processed by the distributed digital identity management system 11.
[0086] Finally, the communication module 31 issues the attribute certificate to the client associated therewith.
[0087] In another embodiment of the distributed digital identity management system 3, when the attribute information changes, the attribute information generation module 32 generates new distributed attribute information associated with the client, encrypts the new distributed attribute information, and generates an attribute certificate update request for the new distributed attribute information and the identity certificate of the client.
[0088] The communication module 31 sends an attribute certificate update request to the attribute certificate issuing management system, and forwards the attribute certificate update request to the information security system through the attribute certificate issuing management system.
[0089] The update module 33 is used to revoke the issued attribute certificate after the information security system generates the updated attribute certificate, and reissues the updated attribute certificate to the distributed digital identity management system, so that the communication module 31 issues the updated attribute certificate to the client associated therewith.
[0090] In another embodiment of the distributed digital identity management system 3, after the client receives the attribute certificate or the updated attribute certificate, the communication module 31 receives an attribute query request sent by a first client. The attribute query request is a request of the first client to query the attribute information of a second client with which the first client wants to transact.
[0091] The query processing module 34 is configured to search the attribute certificate of the second client according to the attribute query request.
[0092] After the communication module 31 receives the attribute certificate or the updated attribute certificate submitted by the first client, the query processing module 34 decrypts the attribute certificate or the updated attribute certificate to obtain the permission of the first client. According to the permission of the first client, the attribute information of the second client matched with the permission is extracted, so as to display the attribute information that can be displayed in this transaction to the first client, for example, display the attribute label and the credit characteristic, and other attribute information irrelevant to the transaction is not displayed.
[0093] It should be noted that the division of each module of the above system is only a logical functional division, and all or part of them can be integrated into one physical entity, or can be physically separated. These modules can all be implemented in the form of software called by a processing element, or all be implemented in the form of hardware, or part of the modules are implemented in the form of software called by a processing element, and part of the modules are implemented in the form of hardware. For example, the x module can be a separately established processing element, or can be integrated in a chip of the above system. In addition, the x module can also be stored in the form of program code in the memory of the above system, and the function of the above x module is called and executed by a processing element of the above system. The implementation of other modules is similar. These modules can be integrated together or implemented independently. The processing element described herein can be an integrated circuit with signal processing capability. In the implementation process, each step of the above method or each module can be completed by the integrated logic circuit of hardware or the instruction of software in the processing element. The above modules can be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASIC), one or more digital signal processors (DSP), one or more field programmable gate arrays (FPGA), etc. When a certain module is implemented in the form of program code called by a processing element, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. These modules can be integrated together to implement in the form of system on a chip (SOC).
[0094] Embodiment Two
[0095] The embodiment provides a terminal, which comprises a processor, a memory, a transceiver, a communication interface or / and a system bus; the memory and the communication interface are connected with the processor and the transceiver through the system bus and complete communication with each other, the memory is used for storing a computer program, the communication interface is used for communicating with other devices, and the processor and the transceiver are used for running the computer program, so that the device executes various steps of the distributed digital identity management method as described in the embodiment one.
[0096] The system bus mentioned above can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus and the like. The system bus can be divided into an address bus, a data bus, a control bus and the like. For the convenience of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or only one type of bus. The communication interface is used for realizing communication between the database access device and other devices (such as a client, a read-write library and a read-only library). The memory can include a random access memory (RAM) and can also include a non-volatile memory such as at least one disk memory.
[0097] The processor mentioned above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP) and the like; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0098] The protection scope of the distributed digital identity management method is not limited to the step execution order listed in the embodiment, and any scheme realized by increasing, reducing or replacing steps of the prior art according to the principle of the present application is included in the protection scope of the present application.
[0099] The application further provides a distributed digital identity management system, which can implement the distributed digital identity management method of the application, but the implementation device of the distributed digital identity management method of the application includes but is not limited to the structure of the distributed digital identity management system listed in the embodiment, and any modification and replacement of the prior art according to the principle of the application is included in the protection scope of the application.
[0100] In summary, the distributed digital identity management method, system, computer readable storage medium and terminal of the application can conduct business precise matching, reliable verification and optimized transaction mode under the premise of privacy protection according to the distributed digital identity including attribute labels and credit characteristics, improve the business success rate, and realize the association and management of user and attribute information. Therefore, the application effectively overcomes the various shortcomings in the prior art and has high industrial utilization value.
[0101] The above embodiments only exemplarily illustrate the principle and effect of the application, and are not used to limit the application. Any person skilled in the art can modify or change the above embodiments without departing from the spirit and category of the application. Therefore, all equivalent modifications or changes completed by those skilled in the art without departing from the spirit and technical thought of the application should be covered by the claims of the application.
Claims
1. A method for distributed digital identity management, characterized by, The application relates to a distributed digital identity management method for managing clients; the distributed digital identity management method is applied to a communication network comprising a distributed digital identity management system, a digital certificate registration and approval system, an attribute certificate issuing and management system and an information security system. The client sends an identity certificate application request to the distributed digital identity management system; the distributed digital identity management comprises the following steps: The identity certificate application request is forwarded to the digital certificate registration and approval system to obtain an identity certificate issued by the digital certificate registration and approval system for the client; Based on the past transaction records of the client, distributed attribute information associated with the client is generated, and an attribute certificate application request is generated based on the distributed attribute information associated with the client and the identity certificate of the client; The attribute certificate application request is sent to the attribute certificate issuing and management system, the attribute certificate application request is forwarded to the information security system through the attribute certificate issuing and management system, and after the information security system generates an attribute certificate, the attribute certificate is issued to the distributed digital identity management system; The attribute certificate is issued to the client associated therewith.
2. The method of claim 1, wherein, The distributed digital identity management method further comprises encrypting the distributed attribute information when the distributed attribute information associated with the client is generated.
3. The distributed digital identity management method of claim 1, wherein, The attribute certificate comprises a certificate owner identity code, a certificate generation code, a signature algorithm, a validity period, an attribute label, a credit feature and the attributes of the certificate holder.
4. The method of claim 1, wherein, The distributed digital identity management further comprises the following steps: When the distributed attribute information is changed, an attribute certificate update request is sent to the attribute certificate issuing and management system, the attribute certificate update request is forwarded to the information security system through the attribute certificate issuing and management system, and after the information security system generates an updated attribute certificate, the updated attribute certificate is reissued to the distributed digital identity management system, so that the distributed digital identity management system issues the updated attribute certificate to the client associated therewith.
5. The method of claim 4, wherein, After the information security system generates the updated attribute certificate, the distributed digital identity management method further comprises revoking the issued attribute certificate.
6. The method of claim 4, wherein, The distributed digital identity management method further comprises the following steps: After the client receives the attribute certificate or the updated attribute certificate, an attribute query request sent by a first client is received; the attribute query request is a request of the first client for querying attribute information of a second client to be traded with; According to the attribute query request, the attribute certificate of the second client is searched; After the attribute certificate or the updated attribute certificate submitted by the first client is received, the attribute certificate or the updated attribute certificate is decrypted to obtain the authority of the first client; According to the authority of the first client, the attribute information of the second client matched with the authority is extracted.
7. The method of claim 6, wherein, The attribute query request comprises a certificate type, a certificate number, a name or an identity certificate of the second client to be traded with.
8. A distributed digital identity management system, characterized in that, The application discloses a distributed digital identity management system for managing clients, and belongs to the field of information security. The distributed digital identity management system comprises a communication module, an attribute information generation module, a distributed digital identity generation module and a distributed digital identity management module. The communication module is used for forwarding an identity certificate application request to the digital certificate registration and approval system to obtain an identity certificate issued by the digital certificate registration and approval system for the client. The attribute information generation module is used for generating distributed attribute information associated with the client based on past transaction records of the client, and generating an attribute certificate application request of the distributed attribute information associated with the client and the identity certificate of the client.
9. A computer-readable storage medium having stored thereon a computer program, characterized in that, After the attribute certificate application request is generated, the attribute certificate application request is sent to the attribute certificate issuing and management system by the communication module, the attribute certificate application request is forwarded to the information security system by the attribute certificate issuing and management system, the attribute certificate is issued to the distributed digital identity management system after the information security system generates the attribute certificate, and the attribute certificate is distributed to the client associated therewith by the communication module.
10. A terminal, characterized by comprising: The program is executed by the processor to realize the distributed digital identity management method in any one of claims 1 to 7. The application discloses a distributed digital identity management system for managing clients, and belongs to the field of information security. The distributed digital identity management system comprises a communication module, an attribute information generation module, a distributed digital identity generation module and a distributed digital identity management module. The communication module is used for forwarding an identity certificate application request to the digital certificate registration and approval system to obtain an identity certificate issued by the digital certificate registration and approval system for the client. The attribute information generation module is used for generating distributed attribute information associated with the client based on past transaction records of the client, and generating an attribute certificate application request of the distributed attribute information associated with the client and the identity certificate of the client. After the attribute certificate application request is generated, the attribute certificate application request is sent to the attribute certificate issuing and management system by the communication module, the attribute certificate application request is forwarded to the information security system by the attribute certificate issuing and management system, the attribute certificate is issued to the distributed digital identity management system after the information security system generates the attribute certificate, and the attribute certificate is distributed to the client associated therewith by the communication module. The program is executed by the processor to realize the distributed digital identity management method in any one of claims 1 to 7. The application discloses a distributed digital identity management system for managing clients, and belongs to the field of information security. The distributed digital identity management system comprises a communication module, an attribute information generation module, a distributed digital identity generation module and a distributed digital identity management module. The communication module is used for forwarding an identity certificate application request to the digital certificate registration and approval system to obtain an identity certificate issued by the digital certificate registration and approval system for the client. The attribute information generation module is used for generating distributed attribute information associated with the client based on past transaction records of the client, and generating an attribute certificate application request of the distributed attribute information associated with the client and the identity certificate of the client. After the attribute certificate application request is generated, the attribute certificate application request is sent to the attribute certificate issuing and management system by the communication module, the attribute certificate application request is forwarded to the information security system by the attribute certificate issuing and management system, the attribute certificate is issued to the distributed digital identity management system after the information security system generates the attribute certificate, and the attribute certificate is distributed to the client associated therewith by the communication module. The program is executed by the processor to realize the
Citation Information
Patent Citations
Digital certificate use method, system and storage medium based on block chain
CN108881290A
Method and system for processing industrial internet digital certificate
CN112714121A