A Blockchain-Based Autonomous Identity Management Method

By adopting a blockchain-based autonomous identity management method in the network environment, the problem of user identity information protection in the prior art is solved, and the user's autonomous control of identity information and the security and privacy of identity authentication are realized.

CN115632795BActive Publication Date: 2025-06-03XIAN THERMAL POWER RES INST CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211289435.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-20
Publication Date
2025-06-03
Estimated Expiration
2042-10-20

AI Technical Summary

Technical Problem

The prior art is difficult to effectively protect user data and identities in a network environment. The centralized identity management system has the risk of data leakage and attacks, and it is impossible to achieve secure interaction between entities.

Method used

Adopting blockchain-based autonomous identity management methods, users can realize autonomous control over identity information through physical node deployment, authentication alliance formation and master key generation. Use proxy recryption technology and smart contracts to ensure the security and privacy of identity authentication and authorization.

Benefits of technology

It realizes complete autonomous control of identity information by users, ensures the security and privacy of identity authentication and authorization, reduces dependence on centralized systems, and improves the reliability and security of network identity management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632795B_ABST
    Figure CN115632795B_ABST
Patent Text Reader

Abstract

The present invention discloses a blockchain-based autonomous identity management method, including system initialization, registration and login, service acquisition, and evaluation and update; the system initialization includes the deployment of entity nodes, the formation of an authentication alliance, and the generation of a master key; registration and login include data source registration, management platform registration, and management platform login, and service acquisition includes user identity determination, identity authentication and authorization, and privacy protection. This method can enable interactions between entities and maintain user privacy and security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of identity management and relates to an autonomous identity management method based on blockchain. Background Art

[0002] With the development of technology, the world people live in is currently driven by various data. Therefore, protecting users' data and identities has become a top priority. With the continuous development of Internet technology, people need to address the security and privacy issues regarding identity management. In real life, identity cards, driver's licenses, passports, etc. can establish personal identities for users guaranteed by authoritative institutions. However, it is difficult to ensure the reliability and security of the establishment and authorization of digital identities in the network. As a third party, service providers often need to rely on an identity management system to authorize and authenticate users' identities. Users cannot directly control their identity data and need to have sufficient trust in the centralized identity management system. Problems such as personal data leakage and platform trafficking of users' identities emerge in an endless stream. When the centralized identity management institution is attacked or experiences operational failures, users' lives will be affected, and they cannot achieve interactions between entities and maintain users' privacy and security. Summary of the Invention

[0003] The purpose of the present invention is to overcome the above-mentioned drawbacks of the prior art and provide an autonomous identity management method based on blockchain, which can achieve interactions between entities and maintain users' privacy and security.

[0004] To achieve the above purpose, the autonomous identity management method based on blockchain described in the present invention includes system initialization, registration and login, service acquisition, and evaluation and update.

[0005] The system initialization includes the deployment of entity nodes, the formation of an authentication alliance, and the generation of a master key;

[0006] Among them, the specific process of the deployment of the entity nodes is as follows: Ethereum is used as the underlying blockchain, the data source is provided by government departments or social platforms, the service providers are cloud storage providers or financial service institutions, and the management platform is constructed by smart contracts and serves as a trusted third party;

[0007] The specific process of the formation of the authentication alliance is as follows: Proof of Authority is used as the consensus mechanism to customize Ethereum, an authentication alliance is formed, a secure channel is constructed for off-chain interactions between entities, and in the blockchain, the release of transactions and blocks requires alliance consensus;

[0008] The specific process of the generation of the master key is as follows: The user generates two basic keys as the initial keys for generating subsequent interaction sub-keys. Among them, the two basic keys include a data access key (DAK) and an identity authorization key (IAK).

[0009] Registration and login include data source registration, management platform registration, and management platform login.

[0010] The data source registration includes the following steps:

[0011] 1) The user generates independent data source keys DSK using the ECDSA key generation algorithm with the data access key DAK.

[0012] 2) The user registers with the data source and distributes the keys, associating the data source key DSK with the data source.

[0013] The specific process of the management platform registration is as follows:

[0014] 3) The user generates independent identity management keys IMK using the ECDSA key generation algorithm with the identity authorization key IAK.

[0015] 4) The user inputs parameters to register the management platform, where the input parameters include the username, password, and identity management key IMK.

[0016] The login process of the management platform is as follows:

[0017] 5) The user inputs the registered username and password into the client. When the username and password are correct, the client jumps to the two-factor authentication stage, sends a two-factor authentication verification code to the user side, and then proceeds to step 6); otherwise, it jumps to the login failure state.

[0018] 6) The user feeds back the two-factor authentication verification code to the management platform. When the two-factor verification passes, it proceeds to step 7); otherwise, it jumps to the failure state.

[0019] 7) The user generates a corresponding login key using the identity management key IMK. Among them, the user generates a login key for each positioning parameter i each time, and then sends the login key and the positioning parameter i to the management platform together.

[0020] 8) The management platform pre-stores the identity management key IMK provided by the user during registration. Using this identity management key IMK and the positioning parameter i, it verifies and generates the login key. When the login key generated by the management platform matches the login key input by the user, the user authentication is successful; otherwise, the user identity login authentication fails.

[0021] Service acquisition includes user identity recognition, identity authentication authorization, and privacy protection;

[0022] Among them, the process of the user identity recognition is as follows:

[0023] 9) The user registers and logs in to the service provider and sends a service acquisition request.

[0024] 10) The service provider redirects the user to the management platform. After the user logs in to the management platform, the user selects the identity attributes to be provided to the service provider.

[0025] 11) The user selects the corresponding data source according to their service acquisition needs and obtains the corresponding identity attribute authentication from the data source.

[0026] The specific process of step 11) is as follows:

[0027] 12) The user generates a proxy re-encryption key PREK.

[0028] 13) The user encrypts the identity data and the data source key DSK using the proxy re-encryption key PREK, and sends the encrypted content INF prek to the management platform.

[0029] 14) The user encrypts PREK using the public key of the data source, re-encrypts the data source key DSK and the required identity information using the public key encrypted PREK, and then sends the encrypted content INF2DS prek to the data source.

[0030] 15) After the data source receives the encrypted content INF2DS prek sent by the user, it decrypts it using the private key, performs in-system matching based on the key DSK, and checks according to the required identity information and the information at the time of user registration. When the check passes, the data source sends a user identity authentication passed flag Flag suc ;

[0031] 16) The data source writes the current user's data access into a transaction and then sends it to the blockchain for recording.

[0032] 17) After the management platform receives the authentication passed signal Flag suc from the data source, when the user's client interface synchronously receives an authentication success reminder, the user sends the re-encryption key PREK to the management platform, and the management platform decrypts the saved information INF prek using the re-encryption key PREK.

[0033] The specific process of evaluation and update is as follows:

[0034] 18) The management platform conducts a reputation assessment on the decrypted identity attributes and sends the identity information and the corresponding assessment results to the service provider.

[0035] 19) Before providing the service, the service provider sets a reputation threshold. When the identity attributes and reputation assessment results sent by the management platform meet the reputation threshold, the service provider provides the service to the user.

[0036] 20) After the user and service provider complete a complete identity authentication, the management platform establishes and stores the mapping relationship consisting of the four-tuple (user, service provider, data source, identity attribute);

[0037] 21) When any user attribute is used multiple times, the reputation value of the identity attribute will increase; when any identity attribute is rejected after being provided to the service provider, the reputation value of the attribute will decrease;

[0038] 22) For identity attributes that cannot meet the service provider's reputation threshold, the identity manager will separately save the (user, service provider, data source, identity attribute) four-tuple using the existence proof mechanism to facilitate subsequent rapid access and attribute screening.

[0039] The assessment update also includes:

[0040] 23) The user initiates an anonymous update request to the management platform. The management platform periodically asks the user to authorize anonymous updates. The user sends an anonymous update request PUReq = (Sig usr ,Req PU ,P usr ), where Sig is the user’s digital signature, Req PU is an anonymous update request with a timestamp, P usr For the old anonymity of the user;

[0041] 24) After receiving the anonymous update request, the management platform verifies the user's signature and the old anonymous. When the verification is successful, the management platform changes the (user, service provider, data source, identity attribute) four-tuple and cuckoo filter stored in the system. Then, when the user accesses the data source or obtains the service, he will receive the new anonymous from the management platform; when the old anonymous verification fails, the management platform returns a new anonymous as the new identity NP for the user's request. usr =Enc(P usr ,Sig usr ).

[0042] The present invention has the following beneficial effects:

[0043] When the blockchain-based autonomous identity management method described in the present invention is specifically operated, it includes system initialization, registration and login, service acquisition, and evaluation and update. Users can completely independently control their own identity information, and select different data sources as authentication parties through the management platform for application to different service providers. Additionally, it should be noted that in the process of identity authentication and authorization, to ensure that user privacy is not leaked, through proxy re-encryption technology, without completely relying on a third party for identity information, identity authentication and authorization are achieved, and identity management is carried out in a fine-grained and secure manner to enable interaction between entities and maintain user privacy and security, ensure the smoothness of service provision, and reduce the occupation of redundant space. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 is an overview diagram of the present invention;

[0045] Figure 2 is a schematic diagram of key generation of the present invention;

[0046] Figure 3 is a flowchart of service acquisition of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, not all of the embodiments, and are not intended to limit the scope of the present invention disclosure. In addition, in the following description, the description of well-known structures and technologies is omitted to avoid unnecessarily confusing the concepts disclosed in the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.

[0048] The structural schematic diagrams according to the disclosed embodiments of the present invention are shown in the drawings. These figures are not drawn to scale, and for the purpose of clear expression, some details are enlarged and some details may be omitted. The shapes of various regions and layers shown in the figures and their relative sizes and positional relationships are only exemplary. In practice, there may be deviations due to manufacturing tolerances or technical limitations, and those skilled in the art can design regions / layers with different shapes, sizes, and relative positions according to actual needs.

[0049] The blockchain-based autonomous identity management system described in the present invention includes users, a management platform, service providers, and data sources. Among them, users obtain identity authentication through the management platform with the help of data sources, and service providers and users interact through the management platform.

[0050] The blockchain-based autonomous identity management method described in the present invention includes registering with a data source, interacting with a management platform, and obtaining services from service providers, which are specifically implemented through an initialization module, a registration and login module, a service acquisition module, and an evaluation and update module.

[0051] Among them, the initialization module is used for building the system infrastructure and realizing the system startup conditions, including entity node deployment, authentication alliance formation function, and master key generation function.

[0052] Entity node deployment function: In this embodiment, each entity serves as a node of a private blockchain. The present invention uses Ethereum as the underlying blockchain. Among them, the data source is provided by a government department or a social platform, the service provider is a cloud storage provider or a financial service institution, and the management platform is constructed by a smart contract and serves as a trusted third party. The private chain in this embodiment has an access mechanism, and nodes need to register when joining the system.

[0053] Authentication alliance formation function, aiming at the user's need for autonomous control of identity attributes and considering the characteristics of multi-data source combination, the present invention uses Proof of Authority (PoA) as the consensus mechanism to customize Ethereum and form an authentication alliance. In addition, a secure and reliable channel is constructed during off-chain interaction between entities. In the blockchain, the release of transactions and blocks requires alliance consensus, which has higher security compared to public blockchains; compared to the Proof of Work (PoW) mechanism, consensus can be achieved without consuming a large amount of computing.

[0054] Master key generation function, the user generates two basic keys as the initial keys for subsequent generation of interaction sub-keys, including a data access key DAK and an identity authorization key IAK.

[0055] The registration and login module realizes the interaction between the user and the data source and the management platform, including the data source registration function, the management platform registration, and the management platform login function.

[0056] Among them, the data source registration includes the following steps:

[0057] 1) As Figure 2 shown, the user uses the data access key DAK to generate independent data source keys DSK through the ECDSA key generation algorithm.

[0058] 2) The user registers with the data source and distributes the key, associating the data source key DSK with the data source.

[0059] Among them, for the management platform registration function, the management platform provides a client for the user to register and log in. The user interacts with the management platform through the front-end page of this client, as Figure 2As shown below, the specific process is as follows:

[0060] 3) The user generates mutually independent identity management keys IMK by using the identity authorization key IAK through the ECDSA key generation algorithm;

[0061] Among them, the management platform consists of multiple identity management nodes, and each identity management node is associated with multiple data sources; the management platform is implemented by a smart contract. The identity management nodes publish and deploy the contract to the Ethereum blockchain and open a client interface to users;

[0062] 4) The user inputs parameters to register the management platform, where the input parameters include the username, password, and identity management key IMK.

[0063] Among them, for the login function of the management platform, a two-factor authentication mechanism (Two-Factor Authentication, 2FA) is set up. The specific implementation process is as follows:

[0064] 5) The user inputs the registered username and password into the client. When the username and password are correct, the client jumps to the two-factor verification stage, sends a two-factor authentication verification code to the user side, and then proceeds to step 6); otherwise, it jumps to the login failure state;

[0065] 6) The user feeds back the two-factor authentication verification code (such as a text message verification code) to the management platform; when the two-factor verification passes, step 7) is executed; otherwise, it jumps to the failure state;

[0066] 7) As Figure 1 shown below, the user generates a corresponding login key by using the identity management key IMK. Among them, the key generation is hierarchical. Each time the user generates a login key corresponding to a positioning parameter i, and then sends the login key and the positioning parameter i to the management platform together;

[0067] 8) The management platform pre-stores the identity management key IMK provided by the user during registration. Using this identity management key IMK and the positioning parameter i, it verifies and generates the login key. When the login key generated by the management platform matches the login key input by the user, the user authentication is successful; otherwise, the user identity login authentication fails.

[0068] The service acquisition module described in this embodiment is used for the user to obtain the required services from the service provider. The service provider needs to determine that the user identity is authenticated, which involves issues such as authentication authorization and privacy protection of the identity. The specific operation process is as follows:

[0069] 9) The user registers and logs in to the service provider and sends a service acquisition request;

[0070] 10) The service provider redirects the user to the management platform. After the user logs in to the management platform, the user selects the identity attributes to be provided to the service provider.

[0071] 11) The user selects the corresponding data source according to their own service needs and obtains the corresponding identity attribute authentication from the data source.

[0072] In this embodiment, the identity is defined as consisting of multiple attributes, such as name, date of birth, and age, etc. The attribute content and authenticity provided by different data sources are different, and the management platform performs identity attribute identification and evaluation.

[0073] The identity authenticity in this embodiment is reflected in the authority and reliability of the data source for each identity attribute. For example, when a user needs to log in to a certain bank service and requires a name and ID number, the data source selected by the user through the management platform can be the resident identity information registered by the public security department; when the user needs to log in to a certain cloud service provider, only a name or nickname is required, and the identity information of social media, such as the personal information of WeChat, can be selected as the data source.

[0074] The main idea of identity authentication and authorization in this embodiment is: i) The user selects a data source according to the identity attributes to be provided to the service provider; ii) The data source receives the user's identity attributes and the information stored in its own system, and authenticates the user's identity information; iii) The data source sends the authentication result to the management platform; iv) The management platform, as the communication bridge between the service provider and the user, authorizes the user to obtain the service of the service provider according to the identity authentication result.

[0075] In this embodiment, the process of the user obtaining the identity information certificate from the data source adopts the proxy re-encryption mechanism (ProxyRe-Encryption), which can authenticate the user's identity attributes while realizing ciphertext transmission, and the management platform can only access the user data after obtaining the identity authentication from the data source, ensuring the user's fine-grained autonomous control of the identity information. The specific process is as follows:

[0076] 12) The user generates a proxy re-encryption key PREK in the initialization module.

[0077] 13) The user encrypts the identity data and the data source key DSK with the proxy re-encryption key PREK, and sends the encrypted content INF prek to the management platform.

[0078] 131) The user sends the proxy re-encryption key PREK to the data source and the management platform.

[0079] 132) The user interacts with other entities through the management platform. Although the encrypted content INF prek passes through the management platform, it cannot be decrypted by the management platform before obtaining the PREK shared by the user.

[0080] 14) The user encrypts the PREK using the public key of the data source, re-encrypts the key DSK of the data source and the required identity information with the encrypted PREK using the public key, and then sends the encrypted content INF2DS prek to the data source;

[0081] 15) After receiving the encrypted content INF2DS sent by the user, prek the data source decrypts it using the private key, performs in-system matching based on the key DSK, checks according to the required identity information and the information at the time of user registration. When the check passes, the data source sends a user identity authentication passed flag Flag suc ;

[0082] 16) The data source writes the current user's data access into a transaction and then sends it to the blockchain for recording. The information included in the transaction includes the user access request, the declarations of the management platform and the service provider, and the required identity attribute declarations, where the service provider and the required attributes are included in the encrypted information sent by the user;

[0083] The data source entity can be regarded as the custodian and authenticator of the user identity information. Through fine-grained key exchange, it ensures the user's autonomous control over the identity information. In addition, the data source entity records the user's access to the identity information as an event in the blockchain for filing, ensuring the integrity and traceability of the data.

[0084] 17) After the management platform receives the authentication passed signal Flag suc from the data source, the user's client interface synchronously receives an authentication success reminder. The user sends the re-encryption key PREK to the management platform, and the management platform decrypts the saved information INF prek using the re-encryption key PREK.

[0085] The management platform has two functions. On the one hand, it receives and transfers the user's identity information; on the other hand, it evaluates the user's various identity attributes. In addition to the distributed peer-to-peer trust brought by the blockchain structure, the information stored by the data source in the blockchain adds trust guarantee for the user and the management platform.

[0086] The evaluation and update module aims to optimize and improve the identity management method, solve the problem of data redundancy in multiple user accesses, evaluate the reliability of identity attributes, and periodically update the user's anonymity. The specific implementation process is as follows:

[0087] 18) The management platform conducts a reputation evaluation on the decrypted identity attributes and sends the identity information and the corresponding evaluation results to the service provider;

[0088] 19) Before providing services, the service provider sets the required attributes that should be met by the credit threshold. When the identity attributes and credit evaluation results sent by the management platform meet the credit threshold, the service provider provides services to users;

[0089] 20) After the user and service provider complete a complete identity authentication, the management platform establishes and stores the mapping relationship consisting of the four-tuple (user, service provider, data source, identity attribute);

[0090] 21) When any user attribute is used multiple times, the reputation value of the identity attribute will increase; when any identity attribute is rejected after being provided to the service provider, the reputation value of the attribute will decrease;

[0091] 22) For identity attributes that cannot meet the service provider's reputation threshold, the identity manager will separately save the (user, service provider, data source, identity attribute) four-tuple using the existence proof mechanism to facilitate subsequent rapid access and attribute screening.

[0092] In this embodiment, the existence proof needs to satisfy the characteristics of being deletable and easy to retrieve. The Bloom Filter used in the traditional existence proof cannot achieve deletability and has a high false alarm rate. The present invention uses an improved Cuckoo Filter to record bad identity attributes, achieves deletability and a low false alarm rate, and can be regarded as a retrieval table after data compression.

[0093] In this embodiment, when users register on the management platform, they use anonymity (which can be a random string generated by a public key). However, when static anonymity is maintained, the service provider may locate the user through blockchain records and its own service access records. This embodiment uses an anonymous update method to regularly update the anonymity of user registration, thereby optimizing and protecting user privacy. The anonymous update of this embodiment occurs in two situations: privacy leakage or regular updates of the management platform. The anonymous update of this embodiment does not add too much additional overhead, and can further protect user privacy and security. The specific implementation steps are as follows:

[0094] 23) The user initiates an anonymous update request to the management platform. The management platform periodically asks the user to authorize anonymous updates. The user sends an anonymous update request PUReq = (Sig usr ,Req PU ,P usr ), where Sig is the user’s digital signature, Req PU is an anonymous update request with a timestamp, P usr For the old anonymity of the user;

[0095] 24) After the management platform receives the anonymous update request, it verifies the user's signature and the old anonymity. When the verification passes, the management platform changes the (user, service provider, data source, identity attribute) quadruple stored in the system and the cuckoo filter. Then, when the user accesses the data source or obtains services, the user will receive a new anonymity from the management platform. When the verification of the old anonymity fails, the management platform returns a new anonymity as the new identity NP for the user's request. usr = Enc(P usr , Sig usr ).

[0096] It should be understood that the above description of the preferred embodiment is relatively detailed, and it should not be considered as a limitation to the protection scope of the present invention. Under the inspiration of the present invention, those of ordinary skill in the art can also make substitutions or deformations without departing from the protection scope defined by the claims of the present invention, and all fall within the protection scope of the present invention. The scope of protection requested by the present invention shall be subject to the appended claims.

Claims

1. A blockchain-based autonomous identity management method, characterized in that, it includes system initialization, registration and login, service acquisition, and evaluation and update; The initialization of the system includes the deployment of entity nodes, the formation of an authentication alliance, and the generation of a master key; Among them, the specific process of the deployment of the entity nodes is as follows: Ethereum is used as the basic blockchain, the data source is provided by the government department or social platform, the service provider is the cloud storage provider or financial service institution, and the management platform is constructed by smart contracts and serves as a trusted third party; The specific process of the formation of the authentication alliance is as follows: Proof of Authority is used as the consensus mechanism to customize Ethereum, an authentication alliance is formed, a secure channel is constructed during off-chain interaction between entities, and in the blockchain, the release of transactions and blocks requires alliance consensus; The specific process of the generation of the master key is as follows: The user generates two basic keys as the initial keys for subsequent generation of interaction sub-keys. Among them, the two basic keys include a data access key DAK and an identity authorization key IAK; Registration and login include data source registration, management platform registration, and management platform login; The data source registration includes the following steps: 1) The user generates independent data source keys DSK using the data access key DAK through the ECDSA key generation algorithm; 2) The user registers with the data source and distributes the key, associating the data source key DSK with the data source; The specific process of the management platform registration is as follows: 3) The user generates independent identity management keys IMK using the identity authorization key IAK through the ECDSA key generation algorithm; 4) The user inputs parameters to register the management platform, where the input parameters include the username, password, and identity management key IMK; The login process of the management platform is as follows: 5) The user inputs the registered username and password into the client. When the username and password are correct, the client jumps to the two-factor authentication stage, sends a two-factor authentication verification code to the user side, and then proceeds to step 6); otherwise, it jumps to the login failure state; 6) The user feeds back the two-factor authentication verification code to the management platform. When the two-factor verification passes, it proceeds to step 7); otherwise, it jumps to the failure state; 7) The user generates a corresponding login key using the identity management key IMK. Each time the user generates a login key corresponding to a positioning parameter i, and then sends the login key and the positioning parameter i to the management platform together; 8) The management platform pre-stores the identity management key IMK provided by the user during registration. Using this identity management key IMK and the positioning parameter i, it verifies and generates the login key. When the login key generated by the management platform matches the login key input by the user, the user authentication is successful; otherwise, the user identity login authentication fails; Service acquisition includes user identity recognition, identity authentication authorization, and privacy protection; Among them, the process of the user identity recognition is as follows: 9) The user registers and logs in to the service provider and sends a service acquisition request; 10) The service provider redirects the user to the management platform. After the user logs in to the management platform, the user selects the identity attributes to be provided to the service provider; 11) The user selects the corresponding data source according to their own service acquisition requirements and obtains the corresponding identity attribute authentication from the data source.

2. The blockchain-based autonomous identity management method according to claim 1, wherein, the specific process of step 11) is: 12) The user generates a proxy re-encryption key PREK; 13) The user encrypts the identity data and the data source key DSK using the proxy re-encryption key PREK, and sends the encrypted content INF prek to the management platform; 14) The user encrypts the PREK using the public key of the data source, re-encrypts the key DSK of the data source and the required identity information with the encrypted PREK by the public key, and then sends the encrypted content INF2DS prek to the data source; 15) The data source receives the encrypted content INF2DS sent by the user prek and then decrypts it using the private key, performs in-system matching based on the key DSK, and checks according to the required identity information and the information at the time of user registration. When the check passes, the data source sends the user identity authentication passed flag Flag to the management platform suc ; 16) The data source writes the current user's data access into a transaction and then sends it to the blockchain for recording; 17) When the management platform receives the authentication passed signal Flag from the data source suc and the user's client interface synchronously receives the authentication success reminder, the user sends the re-encryption key PREK to the management platform, and the management platform uses the re-encryption key PREK to decrypt the saved information INF prek for decryption.

3. The blockchain-based autonomous identity management method according to claim 2, wherein, the specific process of evaluation and update is: 18) The management platform conducts a reputation evaluation on the decrypted identity attributes and sends the identity information and the corresponding evaluation results to the service provider; 19) Before providing the service, the service provider sets a reputation threshold. When the identity attributes and reputation evaluation results sent by the management platform meet the reputation threshold, the service provider provides the service to the user; 20) After the user and the service provider complete a complete identity authentication, the management platform establishes and stores the mapping relationship composed of the quadruple of the user, the service provider, the data source, and the identity attributes; 21) When any user attribute is used multiple times, the reputation value of this identity attribute will increase; when any identity attribute is rejected after being provided to the service provider, the reputation value of this attribute will decrease; 22) For the identity attributes that cannot meet the service provider's reputation threshold, the identity manager separately saves the quadruple of the user, the service provider, the data source, and the identity attributes by using the existence proof mechanism for quick access and attribute screening in the later stage.

4. The blockchain-based autonomous identity management method according to claim 3, wherein, the evaluation and update further includes: 23) The user initiates an anonymous update request to the management platform. The management platform periodically asks the user to authorize anonymous updates. The user sends an anonymous update request PUReq = (Sig usr ,Req PU ,P usr ), where Sig is the user’s digital signature, Req PU is an anonymous update request with a timestamp, P usr For the old anonymity of the user; 24) After the management platform receives the anonymous update request, it verifies the user's signature and the old anonymity. When the verification passes, the management platform changes the quadruple of the user, service provider, data source, and identity attributes stored in the system, as well as the cuckoo filter. Then, when the user accesses the data source or obtains services, the user will receive a new anonymity from the management platform. When the old anonymity verification fails, the management platform returns a new anonymity as the new identity NP for the user's request usr = Enc(P usr , Sig usr ).

Citation Information

Patent Citations

  • A decentralized digital identity login management system based on an Ethereum block chain

    CN109936569A