Data storage method based on distributed digital identity

By creating distributed digital identities in smart homes and generating DID digital identities, the problems of incoordination and poor security of data storage in smart homes are solved, and the coordinated use of storage resources and data security between smart home devices of different manufacturers are achieved.

CN116028575BActive Publication Date: 2025-07-01四川启睿克科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211694108.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2025-07-01
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

Existing smart homes are difficult to implement distributed storage of data, and the security of data storage is poor, especially smart home devices from different manufacturers cannot use storage resources together and are inconvenient to identity authentication.

Method used

By creating distributed digital identities for users and smart home devices, a distributed digital identity service chain is used to generate DID digital identities, and based on this, the distributed storage of data is realized. Users and devices ensure data security and identity verification through signature verification.

Benefits of technology

It realizes the coordinated use of storage resources between smart home devices from different manufacturers, improving the security of data storage and the convenience of identity verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116028575B_ABST
    Figure CN116028575B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of smart home, and discloses a data storage method based on distributed digital identities, aiming at the problems that it is difficult to achieve distributed storage of data in existing smart homes and the security of data storage is relatively poor. The solution mainly includes: creating distributed digital identities for users and each smart home device; storing the user's stored data in a smart home device with storage capabilities based on the distributed digital identities. The present invention enables smart home devices from different manufacturers to share the home storage resources, and at the same time uses the method of signature verification to verify identities, improving the security of data storage. It is particularly applicable to smart homes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart home, and more particularly to a data storage method based on distributed digital identities. Background Art

[0002] Distributed storage is a data storage technology that uses the disk space on each machine in an organization through a network and forms these scattered storage resources into a virtual storage device. The data is scattered and stored in various corners of the organization. By using multiple storage servers to share the storage load and a location server to locate the stored information, the reliability, availability, and access efficiency of the system can be improved.

[0003] A smart home integrates technologies such as the Internet, computing processing, network communication, sensing, and control, and connects various communication devices, household appliances, home security, and other smart home devices in the home to a home intelligent system for centralized communication, monitoring, control, and home affairs management. A smart home can be considered as a system that organically integrates multiple devices and integrates computing, storage, and network capabilities.

[0004] Since the smart home devices in the existing smart home usually come from different manufacturers, it is impossible to coordinate the storage resources of the devices, resulting in a lot of waste of storage resources. In addition, there are identity differences between the devices of different manufacturers, and it is impossible to perform cross-manufacturer identity authentication, and the security of data storage and reading is also poor. Summary of the Invention

[0005] The present invention aims to solve the problems that it is difficult to achieve distributed storage of data in the existing smart home and the security of data storage is poor, and proposes a data storage method based on distributed digital identities.

[0006] The technical solution adopted by the present invention to solve the above technical problems is: a data storage method based on distributed digital identities, the method comprising:

[0007] Create distributed digital identities for users and each smart home device;

[0008] Based on the distributed digital identities, store the storage data of the user in the smart home device with storage capabilities.

[0009] Further, the creation of distributed digital identities for the user terminal and each smart home device specifically includes:

[0010] The user and each smart home device respectively generate their corresponding public and private key pairs, and apply for distributed digital identities to the distributed digital identity service chain based on the corresponding public keys;

[0011] The distributed digital identity service chain generates corresponding DID digital identities, uploads the DID digital identities to the blockchain and returns them to the corresponding users or smart home devices. The DID digital identities include: DID accounts, DID documents, and verifiable credentials.

[0012] Furthermore, the DID document includes the hash values of the key information of the user or smart home device. The key information includes at least one type of user feature information or device feature information. The verifiable credential includes the public key corresponding to the user or device.

[0013] Furthermore, based on the distributed digital identity, user data is stored in a smart home device with storage capabilities. Specifically, it includes:

[0014] The user signs the stored data with the corresponding private key and sends the signed stored data, hash value, and corresponding verifiable credential to the first smart home device, which is a smart home device with storage capabilities.

[0015] The first smart home device verifies the user's first signature information according to the public key in the user's verifiable credential. If the verification passes, it saves the stored data, signs the first signature information with the corresponding private key, and returns the second signature information of the first smart home device and the corresponding verifiable credential to the user.

[0016] The user verifies the second signature information of the first smart home device according to the public key in the verifiable credential of the first smart home device. If the verification passes, the user adds the storage information to the additional field in the user's verifiable credential and uploads it to the distributed digital identity service chain.

[0017] Furthermore, the method further includes:

[0018] The second smart home device reads the stored data from the first smart home device based on the distributed digital identity.

[0019] Furthermore, the second smart home device reads the stored data from the first smart home device based on the distributed digital identity. Specifically, it includes:

[0020] The second smart home device obtains the user's verifiable credential and verifies the user's verifiable credential on the distributed digital identity service chain. After the verification passes, it sends a request to the first smart home device to obtain the stored data according to the storage information in the user's verifiable credential.

[0021] After receiving the data acquisition request, the first smart home device sends response data to the second smart home device.

[0022] The second smart home device sends a request for authorization to use the stored data to the user, and the request contains the response data;

[0023] The user signs the response data using the corresponding private key and returns the authorization information to the second smart home device, and the authorization information contains the signed response data;

[0024] The second smart home device requests data from the first smart home device according to the third signature information of the response data;

[0025] The first smart home device verifies whether the third signature information is consistent with the first signature information of the stored data. If so, it returns the stored data and the signed hash value to the second smart home device.

[0026] Furthermore, the method further includes:

[0027] After the second smart home device obtains the stored data and the signed hash value, it verifies whether the stored data is the user's stored data according to the hash value and the corresponding signature information. If so, it uses the stored data.

[0028] Furthermore, the response data is a random number.

[0029] The beneficial effects of the present invention are as follows: The data storage method based on distributed digital identity described in the present invention realizes the unified identity of users and each smart home device through distributed digital identity, and realizes the distributed storage of data based on the distributed data identities of users and each smart home device, enabling smart home devices from different manufacturers to share the home storage resources. At the same time, the signature verification method is used to verify identities, improving the security of data storage. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 It is a schematic diagram of the application scenario of the data storage method based on distributed digital identity described in the embodiment of the present invention;

[0031] Figure 2 It is a schematic diagram of the creation process of the distributed digital identity described in the embodiment of the present invention;

[0032] Figure 3 It is a schematic diagram of the data storage process described in the embodiment of the present invention;

[0033] Figure 4 It is a schematic diagram of the data reading process described in the embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0034] Digital identity refers to the digital information that can uniquely identify an individual, and condenses the real identity information into a digital code form of a key, so as to bind, query, and verify the behavior information of the subject. The development stage of digital identity generally goes through four stages: centralized identity, federated identity, user-centered identity, and distributed digital identity. Distributed digital identity, that is, blockchain digital identity, adopts blockchain authentication technology, and its characteristic is online joint identity authentication. It is an identity authentication service network platform that can carry the digital age in the future. Based on this, the present invention proposes a data storage method based on distributed digital identity, by creating the distributed digital identities of users and various smart home devices, and storing the stored data of users in the smart home devices with storage capabilities based on the distributed digital identities. Thus, smart home devices from different manufacturers can share the home storage resources. For the convenience of understanding, the following explains the technical terms that may appear in the present invention:

[0035] DID (Decentralized Identifiers) digital identity, that is, distributed digital identity, refers to the distributed digital identity that conforms to the W3C DID sv1.0 specification in the present invention. The DID digital identity includes three parts: DID identifier, DID document, and verifiable credential. Each DID must have a unique DID document, but can have an indefinite number of verifiable credentials.

[0036] DID identifier: The digital identity is identified by the DID. Therefore, the DID identifier should have the characteristics of uniqueness within the application and cross-application self-discovery. The DID identifier conforms to the W3C specification and mainly includes three parts: the fixed prefix "did:hpc", the partition identifier "chain_id", and the unique number identifier "account_address".

[0037] DID document: The DID document is used to describe the characteristics of the digital identity and has a one-to-one correspondence with the DID identifier. The DID document records the account public key, account status, authorization management account, and provides extensible fields for users to flexibly configure according to the business scenario. The signature verification behavior of related transactions of the digital identity service will be based on the public key in the DID document.

[0038] Verifiable credential: It includes verifiable claim (VC, Verifiable Credential) and verifiable presentation (VP, Verifiable Presentation), which refers to the verifiable information generated based on the distributed digital identity and is used to describe the identity attributes of the holder of a certain digital identity in the real world. Information such as the issuer, validity period, and proven attributes will be recorded.

[0039] The following will describe the implementation manner of the present invention in detail in conjunction with the drawings and embodiments.

[0040] Please refer to Figure 1 , the data storage method based on distributed digital identity provided in this embodiment is applied to a smart home, which includes users and multiple smart home devices, at least one of which has the ability to store data, and each smart home device can come from different manufacturers.

[0041] Based on the above application scenario, this embodiment describes the creation, data storage, and data reading of distributed digital identities.

[0042] Please refer to Figure 2 , this embodiment first creates the distributed digital identities of users and each smart home device, which specifically includes the following steps:

[0043] Step 21: The user and each smart home device respectively generate their corresponding public-private key pairs, and apply for distributed digital identities to the distributed digital identity service chain based on the corresponding public keys;

[0044] Step 22: The distributed digital identity service chain generates the corresponding DID digital identity, uploads the DID digital identity to the chain and returns it to the corresponding user or smart home device. The DID digital identity includes: DID account, DID document, and verifiable credential.

[0045] Among them, the user can apply for a distributed digital identity through the corresponding smart home device or mobile terminal.

[0046] In this embodiment, the DID document includes the hash value of the key information of the user or smart home device. Among them, the key information corresponding to the user includes at least one user feature information, and the key information of the smart home device includes at least one device feature information. The verifiable credential includes the public key corresponding to the user or device.

[0047] The distributed digital identity service chain provides a unified identity management service for users and smart home devices, is responsible for generating a unique identity ID to identify the unique identity, and issues a verifiable credential to support device identity verification.

[0048] Please refer to Figure 3 , after the creation of the distributed digital identities of the user and each smart home device is completed, the user can store user data in the smart home device with storage capacity, which specifically includes the following steps:

[0049] Step 31: The user signs the stored data with the corresponding private key, and sends the signed stored data, hash value, and the corresponding verifiable credential to the first smart home device;

[0050] Step 32: The first smart home device verifies the user's first signature information based on the public key in the user's verifiable credential. If the verification passes, it saves the stored data, signs the first signature information with the corresponding private key, and then returns the second signature information of the first smart home device and the corresponding verifiable credential to the user.

[0051] Step 33: The user verifies the second signature information of the first smart home device based on the public key in the verifiable credential of the first smart home device. If the verification passes, the user adds the stored information to the additional field in the user's verifiable credential and uploads it to the distributed digital identity service chain.

[0052] Among them, the first smart home device is a smart home device with storage capabilities. It can provide general storage services externally, and at the same time can encrypt the stored information and perform self-signature based on identity, thereby improving the security of data storage.

[0053] Please refer to Figure 4 , after the user stores user data in a smart home device with storage capabilities, other smart home devices can read the user data stored in this smart home device, which specifically includes the following steps:

[0054] Step 41: The second smart home device obtains the user's verifiable credential and verifies the user's verifiable credential on the distributed digital identity service chain. After the verification passes, it sends a request to obtain the stored data to the first smart home device according to the stored information in the user's verifiable credential.

[0055] Step 42: After receiving the data acquisition request, the first smart home device sends a random number to the second smart home device.

[0056] Step 43: The second smart home device sends a request for authorization to use the stored data to the user, and this request contains the random number.

[0057] Step 44: The user signs the random number with the corresponding private key and returns the authorization information to the second smart home device. The authorization information contains the signed random number.

[0058] Step 45: The second smart home device requests data from the first smart home device according to the third signature information of the random number.

[0059] Step 46: The first smart home device verifies whether the third signature information is consistent with the first signature information of the stored data. If so, it returns the stored data and the signed hash value to the second smart home device.

[0060] Step 47: Verify whether the stored data is the user's stored data according to the hash value and the corresponding signature information. If so, use the stored data.

[0061] It can be understood that in the smart home, the second smart home device needs to use the storage service provider, that is, it needs to read the user data stored in the first smart home device. First, it needs to be verified through self-signature, that is, distributed data identity, and after the verification is passed, it can obtain the user data stored in the first smart home device to realize the reading of the stored data.

[0062] In summary, the data storage method based on distributed digital identity provided in this embodiment realizes the unified identity of users and each smart home device through distributed digital identity, and realizes the distributed storage of data based on the distributed data identities of users and each smart home device, enabling smart home devices from different manufacturers to share the home storage resources, and at the same time using the signature verification method to verify the identity, improving the security of data storage.

Claims

1. A data storage method based on distributed digital identities, characterized in that, The method includes: Creating distributed digital identities for the user and each smart home device; Storing the user's stored data in a smart home device with storage capabilities based on the distributed digital identities, specifically including: The user signs the stored data with the corresponding private key and sends the signed stored data, hash value, and corresponding verifiable credential to a first smart home device, which is a smart home device with storage capabilities; The first smart home device verifies the user's first signature information according to the public key in the user's verifiable credential. If the verification passes, it saves the stored data, signs the first signature information with the corresponding private key, and then returns the second signature information of the first smart home device and the corresponding verifiable credential to the user; The user verifies the second signature information of the first smart home device according to the public key in the verifiable credential of the first smart home device. If the verification passes, it adds the storage information to the additional field in the user's verifiable credential and uploads it to the distributed digital identity service chain.

2. The data storage method based on distributed digital identity according to claim 1, wherein The creation of the distributed digital identities for the user terminal and each smart home device specifically includes: The user and each smart home device respectively generate their corresponding public and private key pairs, and apply for distributed digital identities to the distributed digital identity service chain based on the corresponding public keys; The distributed digital identity service chain generates corresponding DID digital identities, uploads the DID digital identities to the chain and returns them to the corresponding user or smart home device. The DID digital identities include: DID accounts, DID documents, and verifiable credentials.

3. The data storage method based on distributed digital identity according to claim 2, wherein, The DID document includes the hash values of the key information of the user or smart home device, where the key information includes at least one user characteristic information or device characteristic information, and the verifiable credential includes the public key corresponding to the user or device.

4. The data storage method based on distributed digital identity according to claim 1, wherein The method further includes: A second smart home device reads the stored data from the first smart home device based on the distributed digital identity.

5. The data storage method based on distributed digital identity according to claim 4, wherein, The second smart home device reads the stored data from the first smart home device based on the distributed digital identity, specifically including: The second smart home device obtains the user's verifiable credential and verifies the user's verifiable credential on the distributed digital identity service chain. After the verification passes, it sends a request to obtain the stored data to the first smart home device according to the storage information in the user's verifiable credential; After receiving the data acquisition request, the first smart home device sends response data to the second smart home device; The second smart home device sends a request for authorization to use the stored data to the user, and the request contains the response data; The user signs the response data with the corresponding private key and returns authorization information to the second smart home device, and the authorization information contains the signed response data; The second smart home device requests data from the first smart home device according to the third signature information of the response data; The first smart home device verifies whether the third signature information is consistent with the first signature information of the stored data. If so, it returns the stored data and the signed hash value to the second smart home device.

6. The data storage method based on distributed digital identity according to claim 5, characterized in that, The method further includes: After the second smart home device obtains the stored data and the signed hash value, it verifies whether the stored data is the stored data of this user according to the hash value and the corresponding signature information. If so, it uses the stored data.

7. The data storage method based on distributed digital identity according to claim 5, wherein The response data is a random number.

Citation Information

Patent Citations

  • Authentication information processing method, device and equipment and storage medium

    CN112199721A

  • Block chain-based trusted terminal authentication method, system and device, and storage medium

    CN114826719A