A distributed digital authentication system, method and related device

Through the distributed digital identity authentication system, blockchain technology and zero-knowledge proof are used to solve the problems of repeated authentication and data silos in centralized identity management, and the security, convenience and interoperability of user identities are achieved.

CN115632794BActive Publication Date: 2025-06-10AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211288928.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-20
Publication Date
2025-06-10
Estimated Expiration
2042-10-20

AI Technical Summary

Technical Problem

In the centralized digital identity management method, users need to repeat authentication, resulting in data silos, difficult to communicate with each other, and security issues of identity privacy data leakage.

Method used

A distributed digital identity authentication system is provided, including a first identity management unit of the target user, a second identity management unit of the target authenticator and a processing unit of the target issuing party. The system generates distributed digital identity verification requests, including identity identification, zero-knowledge proof and signature, performs attribute verification, and uses blockchain network to store and verify digital identity files to achieve data interoperability and privacy protection.

Benefits of technology

It realizes seamless identity verification between different institutions, avoids the problems of duplicate authentication and data silos, and ensures the security of user identity privacy through zero-knowledge proof and blockchain technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632794B_ABST
    Figure CN115632794B_ABST
Patent Text Reader

Abstract

The present application discloses a distributed digital identity authentication system, method and related device. The system includes a first identity management unit corresponding to a target user, a second identity management unit corresponding to a target verifier, and a processing unit corresponding to a target certificate issuer. The first identity management unit generates a distributed digital identity authentication request for the target user in response to a service request operation triggered by the target user. Then, the second identity management unit can perform attribute verification on the target user based on zero-knowledge proof, and when the attribute verification result is passed, generate a distributed digital identity read operation request for the target user. Then, the processing unit obtains the distributed digital identity file stored in the blockchain network according to the identity identifier, verifies the request verification information according to the distributed digital identity file, and sends the verification result to the target verifier. Throughout the process, the target user can initiate authentication to the target verifier using verifiable claims, thereby realizing data intercommunication based on this.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data processing, and in particular, to a distributed digital identity authentication system, method, and related device. Background Art

[0002] With the rapid development of the digital society, digital identity plays an important role in the network security and informatization of the digital society. Among them, digital identity is used to depict users recognizably through digital information, and can be used to bind, query, and verify the digital information generated by user behavior.

[0003] In traditional banking services, users initiate authentication to the banking institutions where they need to handle business. After the authentication is completed, the banking institutions store the digital identities of the users for verifying the user identities and other processing when the users handle business later. Currently, in the banking industry, the digital identities of users are usually managed in a centralized manner, which plays the roles of business control, operation supervision, and data auditing.

[0004] However, in the centralized management method, users need to repeat authentication to different institutions where they handle business. The digital identity information of users stored among institutions forms data islands, which are difficult to interoperate and are also prone to security problems such as leakage of users' identity privacy data. Summary of the Invention

[0005] To solve the above technical problems, the present application provides a distributed digital identity authentication system, method, and related device.

[0006] The embodiments of the present application disclose the following technical solutions:

[0007] On the one hand, the embodiments of the present application provide a distributed digital identity authentication system, which includes a first identity management unit corresponding to a target user, a second identity management unit corresponding to a target verifier, and a processing unit corresponding to a target issuer:

[0008] The first identity management unit is configured to generate a distributed digital identity authentication request for the target user in response to a service request operation triggered by the target user; the distributed digital identity authentication request includes the identity identifier of the target user, a zero-knowledge proof of the verifiable claim of the target user, and a signature of the overall message, and the overall message includes the identity identifier and the zero-knowledge proof of the verifiable claim;

[0009] The second identity management unit is configured to perform attribute verification on the target user according to the zero-knowledge proof. If the attribute verification result is passed, generate a distributed digital identity read operation request for the target user; the distributed digital identity read operation request includes the identity identifier of the target user and request verification information;

[0010] The processing unit is configured to obtain a distributed digital identity file stored in the blockchain network according to the identity identifier, verify the request verification information according to the distributed digital identity file to obtain a verification result, and send the verification result to the target verifier.

[0011] On the other hand, an embodiment of the present application provides a distributed digital identity verification method, which is applied to a distributed digital identity verification system. The distributed digital identity verification system includes a first identity management unit corresponding to a target user, a second identity management unit corresponding to a target verifier, and a processing unit corresponding to a target certificate issuer. The method includes:

[0012] Through the first identity management unit, in response to a service request operation triggered by the target user, a distributed digital identity verification request of the target user is generated; the distributed digital identity verification request includes the identity identifier of the target user, a zero-knowledge proof of the verifiable claim of the target user, and a signature of the overall message, and the overall message includes the identity identifier and the zero-knowledge proof of the verifiable claim;

[0013] Through the second identity management unit, attribute verification of the target user is performed according to the zero-knowledge proof. If the attribute verification result is passed, a distributed digital identity read operation request of the target user is generated; the distributed digital identity read operation request includes the identity identifier of the target user and request verification information;

[0014] Through the processing unit, a distributed digital identity file stored in the blockchain network is read according to the identity identifier, the request verification information is verified according to the distributed digital identity file to obtain a verification result, and the verification result is sent to the target verifier.

[0015] On yet another aspect, an embodiment of the present application provides a computer device, which includes a processor and a memory:

[0016] The memory is used to store program code and transmit the program code to the processor;

[0017] The processor is configured to execute the distributed digital identity verification method described in the above aspects according to the instructions in the program code.

[0018] On yet another aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store a computer program, and the computer program is used to execute the distributed digital identity verification method described in the above aspects.

[0019] In another aspect, an embodiment of the present application provides a computer program product including instructions, which when running on a computer, causes the computer to execute the distributed digital identity authentication method described in the above aspect.

[0020] As can be seen from the above technical solutions, when a target user needs to handle relevant services at a target verifier, relevant verification can be performed through a distributed digital identity authentication system for business handling and the like. Specifically, the system includes a first identity management unit corresponding to the target user, a second identity management unit corresponding to the target verifier, and a processing unit corresponding to the target certificate issuer. In practical applications, the first identity management unit can generate a distributed digital identity authentication request for the target user in response to a service request operation triggered by the target user, including the identity identifier of the target user, the zero-knowledge proof of the verifiable claim, and the signature of the overall message. The overall message refers to the identity identifier and the zero-knowledge proof of the verifiable claim. Furthermore, the second identity management unit can perform attribute verification on the target user based on the zero-knowledge proof, thereby completing the attribute verification of the target user without disclosing the user privacy data of the target user. And when the attribute verification result is passed, a distributed digital identity read operation request for the target user is generated, including the identity identifier of the target user and the request verification information. Then, the processing unit obtains the distributed digital identity file stored in the blockchain network according to the identity identifier, verifies the request verification information according to the distributed digital identity file, and sends the verification result to the target verifier. It can be seen that a distributed digital identity authentication mechanism is provided. Specifically, through the above system, when a target user needs to handle services at a target verifier, the target user can initiate authentication to the target verifier by using the pre-authorized and issued verifiable claim and the zero-knowledge proof of the verifiable claim. Furthermore, the target verifier can complete the verification through the target certificate issuer by using the distributed digital identity file stored in the blockchain network based on the data interaction with the target certificate issuer. The target verifier can perform subsequent service handling and other operations according to the verification result. In the whole process, the target user can directly use the verifiable claim issued by the target certificate issuer and the zero-knowledge proof of the verifiable claim for verification, without submitting its own identity data to the target verifier. Correspondingly, the target verifier does not need to verify the identity data of the target user, but directly obtains the verification result by means of data interaction with the target certificate issuer. In the whole verification process, the data used can be the data that the target user has pre-authorized and authenticated. Therefore, data interconnection can be achieved through the above verification mechanism. At the same time, attribute verification based on zero-knowledge proof can avoid problems such as leakage of users' identity privacy data. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0022] Figure 1 Structural diagram of a distributed digital identity authentication system provided by an embodiment of the present application;

[0023] Figure 2 Flow diagram of a verifiable claim write operation provided by an embodiment of the present application;

[0024] Figure 3 Flow diagram of a distributed digital identity write operation provided by an embodiment of the present application;

[0025] Figure 4 Structural diagram of a distributed digital identity authentication device provided by an embodiment of the present application;

[0026] Figure 5 Structural diagram of an identity manager provided by an embodiment of the present application;

[0027] Figure 6 Structural diagram of a reader provided by an embodiment of the present application;

[0028] Figure 7 Structural diagram of an identity writer provided by an embodiment of the present application;

[0029] Figure 8 Structural diagram of a claim writer provided by an embodiment of the present application;

[0030] Figure 9 Flowchart of a distributed digital identity authentication method provided by an embodiment of the present application;

[0031] Figure 10 Flow diagram of a distributed digital identity authentication operation provided by an embodiment of the present application. Detailed implementation manners

[0032] To enable those skilled in the art to better understand the solutions of the present application, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.

[0033] The specific description is given through the following embodiments:

[0034] Figure 1 The figure is a structural diagram of a distributed digital identity authentication system provided by an embodiment of the present application. The system includes a first identity management unit corresponding to a target user, a second identity management unit corresponding to a target verifier, and a processing unit corresponding to a target certificate issuer:

[0035] The first identity management unit is configured to generate a distributed digital identity authentication request for the target user in response to a service request operation triggered by the target user.

[0036] Among them, the target user can be any user who needs to handle relevant services, and the target verifier can be an institution corresponding to the relevant service that the target user needs to handle. That is, the target user needs to handle relevant services at the target verifier. At this time, the target user can trigger a service request operation. Correspondingly, the first identity management unit corresponding to the target user can generate a distributed digital identity authentication request for the target user in response to the service request operation triggered by the target user, so as to perform authentication to the target verifier. The distributed digital identity authentication request includes the identity identifier of the target user, the zero-knowledge proof of the verifiable claim of the target user, and the signature of the overall message. The overall message refers to the identity identifier and the zero-knowledge proof of the verifiable claim. In practical applications, the private key of the target user can be used to sign the overall message, so that it can be verified later whether the target user is the person interacting in this session based on the signature.

[0037] The verifiable claim refers to a tamper-proof certificate signed and encrypted by the certificate issuer, usually including attribute information associated with the user's digital identity such as the user's name, age, education level, occupation, etc., and has the characteristics of cryptographic security, privacy protection, and machine readability. The zero-knowledge proof can make the verifier believe that a certain assertion is correct without providing any useful information to the verifier, and has the properties of completeness, reliability, and zero-knowledge. Therefore, the target user can use the zero-knowledge proof of the verifiable claim to authenticate to the target verifier, while ensuring data security when the authentication is completed.

[0038] The second identity management unit is configured to perform attribute verification on the target user according to the zero-knowledge proof. If the attribute verification result is passed, a distributed digital identity read operation request for the target user is generated.

[0039] When the target verifier receives a distributed digital identity authentication request from the target user, the second identity management unit corresponding to the target verifier can verify the attributes of the target user based on zero-knowledge proof. If the attribute verification result is passed, it indicates that the target user meets the conditions for the target verifier to handle relevant services for it. Furthermore, a distributed digital identity read operation request for the target user can be generated. The distributed digital identity read operation request includes the identity identifier of the target user and the request verification information, so as to further verify the identity of the target user. For example, verify the signature of the overall message using the public key obtained according to the identity identifier to further verify whether the target user is the person interacting in this session, and verify whether the authoritative authorization of the verifiable claim is legal by verifying the signature. It can be understood that when the attribute verification result is not passed, it indicates that the target user does not meet the conditions for the target verifier to handle relevant services for it. At this time, the operation can be directly interrupted, and a verification failure message can be directly returned to the target user, and the operation of handling relevant services for the target user will no longer continue.

[0040] In a possible implementation manner, the system may further include a parsing unit:

[0041] The parsing unit is used to parse the distributed digital identity authentication request, determine the target verifier corresponding to the service request operation, and send the distributed digital identity authentication request to the second identity management unit;

[0042] The parsing unit is further used to parse the distributed digital identity read operation request, determine the target issuer corresponding to the distributed digital identity read operation request, and send the distributed digital identity read operation request to the processing unit.

[0043] Since the target user may handle different services for different verifiers, a parsing unit can be deployed to parse the distributed digital identity authentication request of the target user to determine the target verifier corresponding to the service request operation triggered by the target user. Then, the parsing unit distributes the distributed digital identity authentication request of the target user to the second identity management unit corresponding to the target verifier. Similarly, the parsing unit can also parse the distributed digital identity read operation request, determine the target issuer corresponding to the distributed digital identity read operation request, and distribute the distributed digital identity read operation request to the target issuer.

[0044] The verifiable claim of the target user can be issued by a verifiable claim issuer. In a possible implementation manner, the system may further include an issuing processing unit corresponding to the verifiable claim issuer:

[0045] The first identity management unit is further configured to send a verifiable claim write operation request to the parsing unit in response to a verifiable claim write operation request triggered by a target user; the verifiable claim write operation request includes the identity identifier of the target user, the to-be-authorised attribute of the target user, and a signature.

[0046] The parsing unit is further configured to parse the verifiable claim write operation request, determine the verifiable claim issuer corresponding to the verifiable claim write operation request, and send the verifiable claim write operation request to the verifiable claim issuer.

[0047] The certification processing unit is configured to verify the verifiable claim information corresponding to the target user according to the identity identifier. If the verification is passed, a verifiable claim for the target user is generated and the verifiable claim is sent to the first identity management unit.

[0048] Among them, the to-be-authorised attribute may be an identity attribute that the target user wants to have authoritatively certified by the verifiable claim issuer. For example, when the target user wants to have his age attribute authoritatively certified by the verifiable claim issuer, the age attribute can be set as the to-be-authorised attribute. The signature can also be generated by signing the identity identifier and the to-be-authorised attribute based on the user's private key, so that the verifiable claim issuer can verify whether the target user is the person interacting in this session by verifying the signature.

[0049] In actual data interaction, in order to ensure data security, in a possible implementation manner, the identity identifier of the target user, the to-be-authorised attribute of the target user, and the signature included in the verifiable claim write operation request may also be encrypted as a whole, so that in the data interaction process, the data can be transmitted in ciphertext form, improving data security.

[0050] When the target user needs to generate a verifiable claim, a verifiable claim write operation request can be triggered. Then, the parsing unit parses the verifiable claim write operation request to determine the corresponding verifiable claim issuer, and then distributes the verifiable claim write operation request to the verifiable claim issuer. Correspondingly, after the verifiable claim issuer receives the verifiable claim request of the target user, the certification processing unit can verify the verifiable claim information corresponding to the target user. The verifiable claim information can be identity attribute information such as the target user wants to prove its authenticity based on the verifiable claim. Then, when the verification is passed, a verifiable claim is generated for the target user and returned to the first identity management unit corresponding to the target user. Based on this, authoritative endorsement and guarantee of the identity attribute information of the target user are achieved. Correspondingly, if the verification fails, the relevant operations of the target user are terminated. It can be understood that in addition to applying for a verifiable claim, the verifiable claim write operation request may also include operations such as updating and revoking the verifiable claim.

[0051] In practical applications, an operation process can be written based on verifiable claims to implement the issuance of verifiable claims. Specifically, reference can be made to Figure 2 As shown, the operation process for writing verifiable claims may include: the target user sends a verifiable claim write operation request through the first identity management unit. The verifiable claim write operation request includes an application, update, or revocation operation of the verifiable claim. After being parsed by the parsing unit, the verifiable claim write operation request is distributed to the designated verifiable claim issuer, specifically, it may be distributed to the issuance processing unit corresponding to the verifiable claim issuer. After receiving the verifiable claim write operation request, the verifiable claim issuer first verifies the verifiable claim information through the verification unit. If the verification passes, the issuance processing unit signs and generates the verifiable claim to achieve an authoritative endorsement and guarantee of the identity attribute information of the target user. If the verification fails, the relevant operations of the user are terminated. At the same time, the issued verifiable claim can also be returned.

[0052] The processing unit is used to obtain the distributed digital identity file stored in the blockchain network according to the identity identifier, verify the request verification information according to the distributed digital identity file, obtain the verification result, and send the verification result to the target verifier.

[0053] Blockchain is an innovative application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms in the Internet era. By using its characteristics of decentralized architecture, immutability of data on the chain, and consistent synchronization of all network nodes, the digital identity infrastructure can be transformed in a distributed manner. On the basis of ensuring the security and integrity of digital identity information, the identity authentication mode of banking users is optimized to solve problems such as the difficulty of intercommunication of user identity data and the low efficiency of cross-bank institutional operations. Therefore, data intercommunication can be achieved by using the blockchain network. Specifically, nodes of the blockchain network can be maintained at the target issuer to facilitate related operations such as verification by the target issuer.

[0054] The processing unit corresponding to the target issuer can obtain the distributed digital identity file of the target user stored in the blockchain network, and then verify the request verification information of the target user sent by the target verifier according to the distributed digital identity file, obtain the verification result, and send the verification result to the target verifier, so that the target verifier can perform subsequent business processing operations for the target user according to the verification result. For example, if the verification result is passed, the target verifier can provide the handling service corresponding to the business request operation for the target user (for example, if the business request operation triggered by the target user is to purchase a financial product, the target verifier provides the purchase service of the financial product for the target user). If the verification result is not passed, the handling service corresponding to the business request operation is refused to be provided to the target user.

[0055] In a possible implementation manner, the system may further include a contract execution unit:

[0056] The processing unit is further configured to generate a smart contract call request according to the identity identifier and send the smart contract call request to the contract execution unit;

[0057] The contract execution unit is configured to read the distributed digital identity file according to the smart contract call request sent by the processing unit and send the distributed digital identity file to the processing unit.

[0058] Specifically, the processing unit generates a smart contract call request according to the identity identifier of the target user, and then sends the smart contract call request to the contract execution unit. Then, the contract execution unit can read the distributed digital identity file of the target user stored in the blockchain according to the smart contract unit call request and return the distributed digital identity file to the processing unit. That is to say, the processing unit corresponding to the target issuer can read the data stored in the blockchain through the contract execution unit based on the smart contract call request.

[0059] In a possible implementation manner, the contract execution unit may include a contract driver and a contract reading and writing pipeline. Specifically:

[0060] The contract driver is configured to execute the preset distributed digital identity smart contract code according to the smart contract call request to obtain an execution result;

[0061] The contract reading and writing pipeline is configured to read the distributed digital identity file according to the execution result.

[0062] That is to say, data interaction with the blockchain network can be performed through the contract driver and the contract reading and writing pipeline to read the distributed digital identity file stored in the blockchain network.

[0063] In order to achieve data interconnection, after the target user completes signature verification and obtains its own distributed digital identity file, it can upload and store its own distributed digital identity file to the blockchain network, so that after one verification, the generated identity data can be used subsequently to achieve the purpose of "one verification, multiple uses", and subsequent uses can be for different verifiers. Therefore, in a possible implementation manner, the system may further include a blockchain storage unit. Specifically:

[0064] The first identity management unit is further configured to generate a distributed digital identity write operation request in response to the distributed digital identity file on-chain storage operation triggered by the target user, and send the distributed digital identity write operation request to the processing unit; the distributed digital identity write operation request includes the distributed digital identity file;

[0065] The processing unit is further configured to verify the distributed digital identity file, and if the verification is passed, send the distributed digital identity file to the blockchain storage unit;

[0066] A blockchain storage unit for storing distributed digital identity files.

[0067] Based on this, upload and store its own distributed digital identity file to the blockchain network, so that after one verification, the data after this verification can be used subsequently to achieve data intercommunication.

[0068] In practical applications, the storage of distributed digital identity files can be implemented based on distributed digital identity write operations. Specifically, refer to Figure 3 As shown, the distributed digital identity write operation may include: the target user issues a distributed digital identity write operation request through the first identity management unit. The distributed digital identity write operation request may include operations such as application, update, or revocation of distributed digital identity files. Then, after the distributed digital identity write operation request is parsed and processed by the parsing unit, it is distributed to the processing unit corresponding to the designated issuer. After the issuer receives the distributed digital identity write operation request, it first verifies the distributed digital identity information through the verification unit corresponding to the issuer. If the verification passes, data is written to the blockchain network through the contract adapter. Specifically, the processing unit corresponding to the issuer calls the corresponding identity write operator and smart contract adapter to send the processing result to the contract execution unit. If the verification fails, the relevant operations of the user are terminated. Then, the contract execution unit calls the contract read / write pipeline through the contract driver to send the request processing result information to the blockchain storage unit. The blockchain storage unit stores the distributed digital identity file in the request processing result in the blockchain network and can also return the distributed digital identity file.

[0069] As can be seen from the above technical solution, when a target user needs to handle relevant services at a target verification party, relevant verification can be carried out through a distributed digital identity verification system for business handling and the like. Specifically, the system includes a first identity management unit corresponding to the target user, a second identity management unit corresponding to the target verification party, and a processing unit corresponding to the target certificate-issuing party. In practical applications, the first identity management unit can generate a distributed digital identity verification request for the target user in response to a service request operation triggered by the target user, including the identity identifier of the target user, the zero-knowledge proof of the verifiable claim, and the signature of the overall message. The overall message refers to the identity identifier and the zero-knowledge proof of the verifiable claim. Furthermore, the second identity management unit can perform attribute verification on the target user based on the zero-knowledge proof, thereby completing the attribute verification of the target user without disclosing the user privacy data of the target user. And when the attribute verification result is passed, a distributed digital identity read operation request for the target user is generated, including the identity identifier of the target user and the request verification information. Then, the processing unit obtains the distributed digital identity file stored in the blockchain network according to the identity identifier, verifies the request verification information according to the distributed digital identity file, and sends the verification result to the target verification party. It can be seen that a distributed digital identity verification mechanism is provided. Specifically, through the above system, when a target user needs to handle services at a target verification party, the target user can initiate authentication to the target verification party by using the pre-completed authorized and certified verifiable claim and the zero-knowledge proof of the verifiable claim. Then, the target verification party can complete the verification through the target certificate-issuing party by using the distributed digital identity file stored in the blockchain network based on the data interaction with the target certificate-issuing party. The target verification party can perform subsequent service handling and other operations according to the verification result. In the whole process, the target user can directly use the verifiable claim issued by the target certificate-issuing party and the zero-knowledge proof of the verifiable claim for verification, without submitting its own identity data to the target verification party. Correspondingly, the target verification party does not need to verify the identity data of the target user, but directly obtains the verification result by means of data interaction with the target certificate-issuing party. In the whole verification process, the data used can be the data that the target user has pre-completed authorized authentication. Therefore, data intercommunication can be achieved through the above verification mechanism. At the same time, based on the zero-knowledge proof for attribute verification, problems such as leakage of the user's identity privacy data can be avoided.

[0070] Correspondingly, an embodiment of the present application further provides a distributed digital identity verification device. The structure diagram of the device can be seen in Figure 4 As shown, each unit of the distributed digital identity verification device adopts a distributed deployment architecture, based on which it can be flexibly deployed on the user side, the verification party, and the certificate-issuing party. Specifically:

[0071] An identity management unit that can be used to manage the life cycle of a target user's distributed digital identity, verifiable claims, and zero-knowledge proofs of verifiable claims. It can be understood that the identity management unit includes an identity management unit on the user side (such as the first identity management unit) and an identity management unit on the verifier side (such as the second identity management unit). Specifically, the identity management unit mainly includes an identity manager and a memory. Among them, the identity manager is used for life cycle management requests for distributed digital identities and verifiable claims, as well as generation and verification requests for zero-knowledge proofs of verifiable claims. The life cycle management specifically includes application, update, and revocation, and can be classified into distributed digital identity write operations, verifiable claim write operations, and distributed digital identity verification operations according to functions. The memory is used to store the distributed digital identity file and verifiable claims of the target user.

[0072] See Figure 5 As shown, the identity manager mainly includes a distributed digital identity file management operator, a verifiable claim management operator, a zero-knowledge proof generation operator, and a zero-knowledge proof verification operator. Specifically:

[0073] The distributed digital identity file management operator is mainly used for the management of distributed digital identity files. Its main process includes: the target user generates distributed digital identity application, update, and revocation files through the distributed digital identity file management operator, and then encapsulates a distributed digital identity write operation request and specifies the address of the distributed digital identity issuer processing unit, and sends the request to the parsing unit, receives and parses the execution result returned by the parsing unit, and stores the result in the memory.

[0074] The verifiable claim management operator is mainly used for the management of verifiable claims. Its main process includes: the target user generates verifiable claim application, update, and revocation files through the verifiable claim management operator, and then encapsulates a verifiable claim write operation request and specifies the address of the distributed digital identity issuer processing unit, and sends the request to the parsing unit, receives and parses the execution result returned by the parsing unit, and stores the result in the memory.

[0075] The zero-knowledge proof generation operator is mainly used for the generation of zero-knowledge proofs of verifiable claims. Its main process includes: the target user generates a zero-knowledge proof of a verifiable claim through the zero-knowledge proof generation operator, and then encapsulates a distributed digital identity verification operation request and specifies the address of the distributed digital identity verifier identity management unit (such as the address of the second identity management unit), and sends the request to the parsing unit, and receives and parses the execution result returned by the parsing unit.

[0076] The zero-knowledge proof verification operator is mainly used for verifying the zero-knowledge proof of verifiable claims. Without obtaining the real identity attribute information of the target user, it can verify the identity attributes of the target user. Its main process includes: the verifier verifies the zero-knowledge proof of the verifiable claim through the zero-knowledge proof verification operator to verify the identity attribute information of the target user. If the verification passes, it encapsulates the distributed digital identity read operation and specifies the address of the distributed digital identity issuer processing unit (such as the address of the processing unit corresponding to the target issuer), and sends the request to the parsing unit. If the verification fails, it terminates the relevant operation, returns an error, and receives and parses the execution result returned by the parsing unit.

[0077] The parsing unit mainly includes a request filter and a request dispatcher. The request filter is used to parse the requests of the identity management unit (i.e., the distributed digital identity verification request sent by the first identity management unit and the distributed digital identity read operation request sent by the second identity management unit) and identify the target verifier and the target issuer. The request dispatcher is used to distribute the requests of the identity manager to the specified target verifier or target issuer according to the parsing result of the request filter. Specifically, it can send the corresponding requests according to the target address corresponding to the target verifier or the target address corresponding to the target issuer.

[0078] The processing unit is used to parse the on-chain operations in the distributed digital identity request and call the corresponding readers and blockchain adapters to process the request. The processing unit mainly includes a contract operation filter, a read operator, an identity write operator, a claim write operator, and a smart contract adapter.

[0079] Among them, the contract operation filter is used to parse the request operation type and distribute the request to the corresponding read and write operators to process the request. The read operator mainly includes a data parsing operator, a smart contract query operator, and a verification operator. For details, please refer to Figure 6 as shown. The data parsing operator is used to process the distributed digital identity read operation request of the user, and parse the distributed digital identity file and its identity identifier in the request; the smart contract query operator is used to initiate a distributed digital identity smart contract query operation and query the on-chain data through the smart contract adapter; the verification operator is used to send the request verification information and the on-chain information to the verification unit for correctness verification and return the verification result to the parsing unit. Its main process includes: parsing and obtaining the distributed digital identity read operation request distributed by the parsing unit, obtaining the identity identifiers of the target user and the issuer from the request, encapsulating the distributed digital identity contract query operation, obtaining the parsed on-chain public keys of the user and the issuer through the contract adapter, and then calling the verification unit to verify the correctness of the request verification information and the on-chain data and return the verification result to the parsing unit.

[0080] The identity write operator is used to process the distributed digital identity write operation requests of users, parse the distributed digital identity files in the requests, and perform identity legality verification through the verification unit. After the verification passes, the distributed digital identity files are uploaded to the blockchain network for storage through the smart contract adapter. Its main process mainly includes: parsing and obtaining the distributed digital identity write operation requests distributed by the parsing unit. If the request is in the distributed digital identity update and revocation stage, extract the distributed digital identity identifier from the request, encapsulate the distributed digital identity contract query operation, and obtain the parsed user public key on the chain through the contract adapter, and then call the verification unit to perform identity legality verification. If the verification passes, encapsulate the distributed digital identity contract update operation, and upload the authenticated distributed digital identity file through the contract adapter. If the verification fails, terminate the relevant operation, return an error, and at the same time return the processing result to the parsing unit. The identity write operator mainly includes a data parsing operator, a smart contract update operator, a smart contract query operator, and a verification operator. For details, please refer to Figure 7 as shown

[0081] The claim write operator is used to process the verifiable claim write operation requests of users, parse the verifiable claims in the requests, and perform claim legality verification through the verification unit. After the verification passes, call the digital signature operator to sign the verifiable claim and return it to the parsing unit. Its main process includes: parsing and obtaining the verifiable claim write operation requests distributed by the parsing unit, extracting the distributed digital identity identifier from the request, encapsulating the distributed digital identity contract query operation, and obtaining the parsed user public key on the chain through the contract adapter, and then call the verification unit to perform claim legality verification. If the verification passes, continue to verify whether the user's identity attribute claim is true information. If the verification fails, terminate the relevant operation and return an error; if the verification passes, call the digital signature operator to sign and generate the verifiable claim, and return it to the parsing unit. If the verification fails, terminate the relevant operation and return an error. The claim write operator mainly includes a data parsing operator, a verification operator, a digital signature operator, and a smart contract query operator. For details, please refer to Figure 8 as shown

[0082] The verification unit is used to verify the legality or correctness of requests and on-chain data. The verification unit mainly includes an identity legality validator, a claim legality validator, and a correctness validator. Specifically as follows:

[0083] The identity validator is used to process distributed digital identity write operation requests, check the standardization of data such as distributed digital identity files and contract versions in the requests, and at the same time verify the validity of the signature information of the distributed digital identity files to confirm the relevance between the request initiator (such as the target user) and the request information. Its main processes include: receiving and parsing the distributed digital identity write operation request and the on-chain user public key information sent by the processing unit, obtaining the detailed distributed digital identity information, and performing data standardization verification on the information such as the distributed digital identity identifier, user public key, user signature, and contract version included in the detailed distributed digital identity information. If the verification passes, continue to verify the legality of the user signature information, verify the user signature information using the user public key during the application stage, and verify the user signature information using the user public key and the on-chain user public key during the update and revocation stages. If the verification fails, terminate the relevant operations and return an error. At the same time, return the verification result to the processing unit.

[0084] The claim validator is used to verify claim write operation requests, check the standardization of data such as claim request files and contract versions in the requests, and at the same time verify the signature information of the claim requests to confirm the relevance between the request initiator (such as the target user) and the request information (such as claim information). Its main processes include: receiving and parsing the claim write operation request and the on-chain user public key information sent by the processing unit, obtaining the detailed claim information, and performing data standardization verification on the information such as the distributed digital identity identifier, user attribute description, user signature, and contract version information included in the detailed information. If the verification passes, continue to verify the user signature information using the on-chain user public key. If the verification fails, terminate the relevant operations and return an error. At the same time, return the verification result to the processing unit.

[0085] The correctness validator is used for distributed digital identity read operation requests. For the requests sent by the processing unit, use the on-chain queried user public key and the issuer public key to verify the message signature and the signature information of the verifiable claim in the requests to confirm the correctness of the claim and the association between the claim and the initiator. Its main processes include: receiving and parsing the read operation request data, on-chain user public key, and authenticator public key information sent by the processing unit, obtaining the detailed information, and performing data standardization verification on the information such as the message signature, verifiable claim signature, and verifiable claim hash value information included in the detailed information. If the verification passes, calculate the request data hash value and use it together with the on-chain user public key as input to verify the legality of the message signature. If the verification fails, terminate the relevant operations and return an error. If the verification passes, continue to use the verifiable claim hash value and the on-chain issuer public key as input to verify the legality of the verifiable claim signature to ensure that the user claim is endorsed by an authoritative banking institution. If the verification fails, terminate the relevant operations and return an error. At the same time, return the verification result to the processing unit.

[0086] The contract execution unit mainly includes a contract driver and a contract read-write pipeline, which is used to interact with the blockchain network for data. Among them, the contract driver is used to execute the preset distributed digital identity smart contract code, which implements the distributed digital identity business logic function and the read-write function of the blockchain network; the contract read-write pipeline is used to write the execution result of the contract driver to the blockchain network (specifically, it can be a blockchain storage unit), or query the chain data from the blockchain network. Its main business process includes: the smart contract adapter of the processing unit sends a request to the contract driver of the corresponding contract execution unit, and then the contract adapter calls the corresponding distributed digital identity business contract method to process the request according to the method address of the distributed digital identity smart contract code in the request. After completing the business processing, the contract adapter calls the blockchain network read-write code method to write the execution result to the blockchain network, or read the corresponding data from the blockchain network (such as reading the distributed digital identity file). Among them, the smart contract adapter is used to adapt to different contract execution units, and can also transform the request processing result according to the actual blockchain network type and data protocol, and forward the processing result to the contract execution unit.

[0087] The blockchain storage unit is used to store the user's distributed digital identity files, which are mainly composed of distributed memory. The distributed memory provides a highly available storage environment for the distributed digital identity device, ensuring the authenticity and reliability of the distributed digital identity files on the blockchain network, while enabling the full network sharing of distributed digital identity files and data interoperability.

[0088] It is understandable that since the functions performed by the user side, the verifier and the issuer in the distributed digital identity authentication process are different, in actual deployment, it can be based on Figure 4 The device structure shown is dynamically adjusted and then deployed in a distributed manner. For example, the parsing unit can be deployed on the issuer and the verifier, and the address information of each issuer and the verifier in the distributed digital identity alliance can be maintained. The user and the verifier can configure the parsing unit address list in the identity management unit. For another example, the processing unit, the verification unit, the contract execution unit, and the blockchain storage unit can be deployed on the issuer server to implement one-party authentication and multi-party verification of the distributed digital identity for the user, thereby having identity portability. Among them, the distributed digital identity alliance can include the target user, target verifier, and target issuer as mentioned above. It can be understood that it can also include other users, verifiers, and issuers.

[0089] The distributed digital identity authentication method provided by the embodiments of the present application can be implemented by a computer device, which can be a terminal device or a server. Among them, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, etc. The terminal device and the server can be directly or indirectly connected through wired or wireless communication methods, and the present application does not impose any restrictions on this.

[0090] Figure 9 FIG. 4 is a flowchart of a distributed digital identity authentication method provided by an embodiment of the present application. The method is applied to a distributed digital identity authentication system, which includes a first identity management unit corresponding to a target user, a second identity management unit corresponding to a target verifier, and a processing unit corresponding to a target issuer. The method includes S901-S903:

[0091] S901: Through the first identity management unit, in response to a service request operation triggered by the target user, generate a distributed digital identity authentication request for the target user; the distributed digital identity authentication request includes the identity identifier of the target user, the zero-knowledge proof of the verifiable claim of the target user, and the signature of the overall message, and the overall message includes the identity identifier and the zero-knowledge proof of the verifiable claim;

[0092] S902: Through the second identity management unit, perform attribute verification on the target user according to the zero-knowledge proof. If the attribute verification result is passed, generate a distributed digital identity read operation request for the target user; the distributed digital identity read operation request includes the identity identifier of the target user and the request verification information;

[0093] S903: Through the processing unit, read the distributed digital identity file stored in the blockchain network according to the identity identifier, verify the request verification information according to the distributed digital identity file, obtain the verification result, and send the verification result to the target verifier.

[0094] In a possible implementation manner, the system further includes a parsing unit, and the method further includes:

[0095] Parse the distributed digital identity authentication request through the parsing unit to determine the target verifier corresponding to the service request operation, and send the distributed digital identity authentication request to the second identity management unit;

[0096] Parse the distributed digital identity read operation request through the parsing unit to determine the target issuer corresponding to the distributed digital identity read operation request, and send the distributed digital identity read operation request to the processing unit.

[0097] In a possible implementation, the system further includes an issuing processing unit corresponding to the verifiable claim issuer, and the method further includes:

[0098] In response to a verifiable claim write operation request triggered by the target user, the first identity management unit sends the verifiable claim write operation request to the parsing unit; the verifiable claim write operation request includes the identity identifier of the target user, the attributes to be authorized by the target user, and a signature.

[0099] The parsing unit parses the verifiable claim write operation request to determine the verifiable claim issuer corresponding to the verifiable claim write operation request, and sends the verifiable claim write operation request to the verifiable claim issuer.

[0100] The issuing processing unit verifies the verifiable claim information corresponding to the target user according to the identity identifier. If the verification is passed, a verifiable claim for the target user is generated and sent to the first identity management unit.

[0101] In a possible implementation, the system further includes a contract execution unit, and the method further includes:

[0102] The processing unit generates a smart contract call request according to the identity identifier and sends the smart contract call request to the contract execution unit.

[0103] The contract execution unit reads the distributed digital identity file according to the smart contract call request sent by the processing unit and sends the distributed digital identity file to the processing unit.

[0104] In a possible implementation, the contract execution unit includes a contract driver and a contract reading and writing pipeline. The step of the contract execution unit reading the distributed digital identity file according to the smart contract call request sent by the processing unit includes:

[0105] The contract driver executes the pre-set distributed digital identity smart contract code according to the smart contract call request to obtain an execution result.

[0106] The contract reading and writing pipeline reads the distributed digital identity file according to the execution result.

[0107] In a possible implementation, the system further includes a blockchain storage unit, and the method further includes:

[0108] In response to the distributed digital identity file uploading and storing operation triggered by the target user, the first identity management unit generates a distributed digital identity write operation request and sends the distributed digital identity write operation request to the processing unit; the distributed digital identity write operation request includes the distributed digital identity file.

[0109] The processing unit verifies the distributed digital identity file, and if the verification is passed, sends the distributed digital identity file to the blockchain storage unit.

[0110] The blockchain storage unit stores the distributed digital identity file.

[0111] It can be understood that it basically corresponds to the system embodiment, so the relevant parts can refer to the partial description of the system embodiment above.

[0112] Figure 10 This is a schematic flowchart of a distributed digital identity verification operation provided by an embodiment of the present application. The verification of the distributed digital identity can be completed based on the distributed digital identity verification operation. The distributed digital identity verification operation process may include: the target user generates a zero-knowledge proof of a verifiable claim by calling the first identity management unit, and generates a distributed digital identity verification request; the distributed digital identity verification request is distributed to the identity management unit of the designated verifier (the second identity management unit of the target verifier) through the parsing unit. The target verifier performs attribute verification on the target user, specifically, it may mean that the target verifier verifies the zero-knowledge proof of the verifiable claim by calling the second identity management unit. If the verification is passed, the second identity management unit issues a distributed digital identity read operation request. If the verification fails, the relevant operations of the target user are terminated. Then, the distributed digital identity read operation request is distributed to the processing unit of the designated issuer (the processing unit of the target issuer) through the parsing unit. After receiving the distributed digital identity read operation request distributed, the processing unit of the target issuer calls the contract execution unit to read the distributed digital identity file stored in the blockchain network. If the verification fails, the relevant operations of the target verifier are terminated. Specifically, the contract execution unit calls the contract read-write pipeline through the contract driver to read the distributed digital identity file in the blockchain network and returns it to the processing unit. Then, the processing unit calls the verification unit to verify the request verification information. If the verification is passed, the authentication is successful, and the target user is allowed to access and use the financial services provided by the target verifier. The target verifier provides the target user with business handling services that match the business request operation, etc.; if the verification fails, the relevant operations of the subsequent access of the target user are terminated, and the target user is no longer provided with business handling services that match the business request operation, etc.

[0113] It can be understood that it basically corresponds to the system embodiment, so for related parts, reference can be made to the partial description of the foregoing system embodiment.

[0114] On the other hand, an embodiment of the present application provides a computer device, which includes a processor and a memory:

[0115] The memory is used to store program code and transmit the program code to the processor;

[0116] The processor is used to execute the distributed digital authentication method provided in the foregoing embodiment according to the instructions in the program code.

[0117] This computer device may include a terminal device or a server, and the foregoing distributed digital authentication system may be configured in this computer device.

[0118] On the other hand, an embodiment of the present application further provides a storage medium, which is used to store a computer program, and the computer program is used to execute the distributed digital authentication method provided in the foregoing embodiment.

[0119] In addition, an embodiment of the present application further provides a computer program product including instructions, which when running on a computer, causes the computer to execute the distributed digital authentication method provided in the foregoing embodiment.

[0120] Those of ordinary skill in the art can understand that all or part of the steps of implementing the foregoing method embodiment can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium, and when the program is executed, it executes the steps including the foregoing method embodiment; and the foregoing storage medium can be at least one of the following media: read-only memory (English: Read-only Memory, abbreviation: ROM), RAM, magnetic disk, or optical disc and other media that can store program code.

[0121] For the device embodiment, since it basically corresponds to the method embodiment, for related parts, reference can be made to the partial description of the method embodiment. The device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative work.

[0122] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0123] The above has introduced in detail a distributed digital identity authentication system, method and related device provided by an embodiment of the present application. Specific examples are used in this text to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method of the present application. At the same time, for those of ordinary skill in the art, there will be changes in the specific implementation manner and application scope according to the method of the present application.

[0124] In summary, the content of this specification should not be construed as a limitation on the present application. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed by the present application should be covered within the protection scope of the present application. Moreover, based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners.

Claims

1. A distributed digital identity authentication system, characterized in that, the system includes a first identity management unit corresponding to the target user, a second identity management unit corresponding to the target verifier, and a processing unit corresponding to the target issuer: the first identity management unit is configured to generate a distributed digital identity authentication request for the target user in response to a service request operation triggered by the target user; the distributed digital identity authentication request includes the identity identifier of the target user, the zero-knowledge proof of the verifiable claim of the target user, and the signature of the overall message, and the overall message includes the identity identifier and the zero-knowledge proof of the verifiable claim; the second identity management unit is configured to perform attribute verification on the target user according to the zero-knowledge proof, and if the attribute verification result is passed, generate a distributed digital identity read operation request for the target user; the distributed digital identity read operation request includes the identity identifier of the target user and the request verification information; the processing unit is configured to obtain the distributed digital identity file stored in the blockchain network according to the identity identifier, verify the request verification information according to the distributed digital identity file, obtain a verification result, and send the verification result to the target verifier.

2. The system according to claim 1, characterized in that, the system further includes a parsing unit: the parsing unit is configured to parse the distributed digital identity authentication request, determine the target verifier corresponding to the service request operation, and send the distributed digital identity authentication request to the second identity management unit; the parsing unit is further configured to parse the distributed digital identity read operation request, determine the target issuer corresponding to the distributed digital identity read operation request, and send the distributed digital identity read operation request to the processing unit.

3. The system according to claim 2, characterized in that, the system further includes an issuing processing unit corresponding to the verifiable claim issuer: the first identity management unit is further configured to send the verifiable claim write operation request to the parsing unit in response to the verifiable claim write operation request triggered by the target user; the verifiable claim write operation request includes the identity identifier of the target user, the to-be-authorized attribute of the target user, and the signature; the parsing unit is further configured to parse the verifiable claim write operation request, determine the verifiable claim issuer corresponding to the verifiable claim write operation request, and send the verifiable claim write operation request to the verifiable claim issuer; the issuing processing unit is configured to verify the verifiable claim information corresponding to the target user according to the identity identifier, and if the verification is passed, generate the verifiable claim of the target user and send the verifiable claim to the first identity management unit.

4. The system according to claim 1, characterized in that, the system further includes a contract execution unit: the processing unit is further configured to generate a smart contract call request according to the identity identifier and send the smart contract call request to the contract execution unit; The contract execution unit is configured to read the distributed digital identity file according to the smart contract invocation request sent by the processing unit, and send the distributed digital identity file to the processing unit.

5. The system according to claim 4, wherein, the contract execution unit includes a contract driver and a contract reading / writing pipeline: the contract driver is configured to execute the preset distributed digital identity smart contract code according to the smart contract invocation request to obtain an execution result; the contract reading / writing pipeline is configured to read the distributed digital identity file according to the execution result.

6. The system according to any one of claims 1-5, wherein, the system further includes a blockchain storage unit: the first identity management unit is further configured to generate a distributed digital identity write operation request in response to a distributed digital identity file on-chain storage operation triggered by the target user, and send the distributed digital identity write operation request to the processing unit; the distributed digital identity write operation request includes the distributed digital identity file; the processing unit is further configured to verify the distributed digital identity file, and if the verification is passed, send the distributed digital identity file to the blockchain storage unit; the blockchain storage unit is configured to store the distributed digital identity file.

7. A distributed digital identity authentication method, wherein, the method is applied to a distributed digital identity authentication system, the distributed digital identity authentication system includes a first identity management unit corresponding to a target user, a second identity management unit corresponding to a target verifier, and a processing unit corresponding to a target issuer, and the method includes: through the first identity management unit, in response to a service request operation triggered by the target user, generate a distributed digital identity authentication request of the target user; the distributed digital identity authentication request includes an identity identifier of the target user, a zero-knowledge proof of a verifiable claim of the target user, and a signature of an overall message, and the overall message includes the identity identifier and the zero-knowledge proof of the verifiable claim; through the second identity management unit, perform attribute verification on the target user according to the zero-knowledge proof, and if the attribute verification result is passed, generate a distributed digital identity read operation request of the target user; the distributed digital identity read operation request includes the identity identifier of the target user and request verification information; through the processing unit, read a distributed digital identity file stored in a blockchain network according to the identity identifier, verify the request verification information according to the distributed digital identity file to obtain a verification result, and send the verification result to the target verifier.

8. A computer device, wherein, the computer device includes a processor and a memory: the memory is used to store program code and transmit the program code to the processor; the processor is used to execute the method according to claim 7 according to the instructions in the program code.

9. A computer-readable storage medium, wherein, The computer-readable storage medium is used to store a computer program, and the computer program is used to execute the method described in claim 7.

10. A computer program product including instructions, which, when running on a computer, causes the computer to execute the method described in claim 7.

Citation Information

Patent Citations

  • Data processing method, device and equipment based on block chain and storage medium

    CN112738253A

  • Information processing device and information processing method

    CN113892099A