Blockchain-based distributed digital identity authentication method, device and system

By using a blockchain-based distributed digital identity authentication method that combines user, terminal, and distributed digital identity verification, the problem of critical data leakage in banking operations is solved, achieving security and privacy in data transmission and storage.

CN116032561BActive Publication Date: 2026-03-03AGRI BANK OF CHINA CO LTD TIANJIN BRANCH +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211608421.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-14
Publication Date
2026-03-03
Estimated Expiration
2042-12-14

AI Technical Summary

Technical Problem

Existing technologies have not been able to effectively address how to ensure the security of critical data during storage, transmission, and sharing in banking operations, and prevent the leakage of sensitive data.

Method used

A blockchain-based distributed digital identity authentication method is adopted to verify the terminal's IP, MAC, and distributed digital identity, and to verify the user, terminal, and distributed digital identity to ensure the security of file operations.

Benefits of technology

It reduces the risk of critical data leakage, improves the security of file operations, and ensures the privacy and trustworthiness of data transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032561B_ABST
    Figure CN116032561B_ABST
Patent Text Reader

Abstract

The application provides a blockchain-based distributed digital identity authentication method, device and system. After a user is authenticated uniformly, if the user wants to initiate a file operation instruction through a terminal, the IP, MAC and distributed digital identity of the terminal need to be verified, so that the user, the terminal and the distributed digital identity are checked together, the security of file operation is ensured, and the risk of key data leakage is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and more specifically, to a blockchain-based distributed digital identity authentication method, apparatus, and system. Background Technology

[0002] Banking operations require different critical data in various application scenarios, and staff also need to use critical data in many situations during their daily work. This critical data generally includes sensitive data, and its leakage could cause significant losses. How to ensure the security of critical data during storage, transmission, and sharing has become an urgent technical problem to be solved in this field. Summary of the Invention

[0003] In view of this, the present invention provides a blockchain-based distributed digital identity authentication method, device and system, which realizes joint verification by users, terminals and distributed digital identities, ensuring the security of file operations and reducing the risk of leakage of critical data.

[0004] To achieve the above-mentioned objectives, the present invention provides the following specific technical solution:

[0005] In a first aspect, embodiments of the present invention provide a blockchain-based distributed digital identity authentication method, applied to a distributed digital identity server, the method comprising:

[0006] In response to an authentication request sent by the terminal, the IP and MAC addresses of the terminal are verified. The authentication request is sent by the terminal when it receives a file operation instruction from a user after the user has passed unified authentication.

[0007] If the IP and MAC verification of the terminal is successful, determine whether the terminal has already registered a distributed digital identity;

[0008] If the terminal has already registered a distributed digital identity, verify the distributed digital identity of the terminal;

[0009] If the distributed digital authentication of the terminal is successful, an authentication success message is sent to the terminal;

[0010] Execute the file operation corresponding to the file operation instruction.

[0011] In some embodiments, if the terminal has not registered a distributed digital identity, the method further includes:

[0012] Receive the distributed digital identity registration application sent by the terminal, and create the distributed digital identity information of the terminal;

[0013] Verify the distributed digital identity registration application of the terminal;

[0014] If the distributed digital identity registration application of the terminal is verified and approved, the distributed digital identity of the terminal is registered on the blockchain;

[0015] Verify the verifiable declaration registration application for the terminal;

[0016] If the verification of the application for registration of the verifiable claim of the terminal is approved, the verifiable claim of the terminal is registered on the blockchain.

[0017] In some embodiments, registering the distributed digital identity of the terminal on the blockchain includes:

[0018] Obtain the terminal's distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management terminal;

[0019] The blockchain is invoked to verify the terminal's distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management terminal;

[0020] If the verification is successful, the terminal's distributed digital identity identifier, public key, identity signature, and the issuing management terminal's distributed digital identity identifier and message signature are stored on the blockchain.

[0021] In some embodiments, the method further includes:

[0022] Receive distributed digital identity registration applications sent by the issuing and management terminal, and create distributed digital identity information for the issuing and management terminal;

[0023] Verify and issue distributed digital identity registration applications to the management system;

[0024] If the distributed digital identity registration application of the issuing and management terminal is verified and approved, the distributed digital identity of the issuing and management terminal is registered on the blockchain;

[0025] Verify the registration application for a verifiable declaration issued by the management system;

[0026] If the verification application for the verifiable claim registration of the issuing management terminal is approved, the verifiable claim of the issuing management terminal is registered on the blockchain.

[0027] In some embodiments, the method further includes:

[0028] If a user is found to have violated the rules, the corresponding credit points will be deducted from the blockchain according to the preset points rules.

[0029] If a user's account is detected to have been cancelled, the user's credit score record will be deleted from the blockchain.

[0030] Upon receiving a credit score query request, the system retrieves the corresponding credit score details from the blockchain.

[0031] In some embodiments, performing the file operation corresponding to the file operation instruction includes:

[0032] Select the file upload scenario and determine the file recipient;

[0033] Fill out the file upload form according to the file operation instructions. The file upload form includes file information and configuration information. The file configuration information includes at least the start date and end date of use.

[0034] Store the file on the local server;

[0035] The execution file is uploaded to the blockchain, and the file information and configuration information are stored on the blockchain.

[0036] In some embodiments, performing the file operation corresponding to the file operation instruction includes:

[0037] Obtain the identifier of the target file corresponding to the file operation instruction;

[0038] Authenticate the terminal;

[0039] If the terminal has file operation permissions for the target file, the file operation corresponding to the file operation instruction is executed. The file operation includes: modifying file uplink information and downloading the file.

[0040] In some embodiments, performing the file operation corresponding to the file operation instruction includes:

[0041] Send a request to the blockchain to query the list of on-chain operation information storage;

[0042] The terminal receives a list of operation information from the blockchain, which includes query results, timestamps, operator information, operation type, and hash address of the evidence storage information.

[0043] Secondly, embodiments of the present invention provide a blockchain-based distributed digital identity authentication device, applied to a distributed digital identity server, the device comprising:

[0044] The first verification unit is used to verify the IP and MAC of the terminal in response to the authentication request sent by the terminal. The authentication request is sent by the terminal when it receives a file operation instruction from the user after the user has passed unified authentication.

[0045] The registration judgment unit is used to determine whether the terminal has registered a distributed digital identity if the IP and MAC verification of the terminal is successful.

[0046] The second verification unit is used to verify the distributed digital identity of the terminal if the terminal has already registered a distributed digital identity.

[0047] The authentication result feedback unit is used to send authentication success information to the terminal if the distributed digital authentication of the terminal is successful.

[0048] The file operation execution unit is used to execute the file operation corresponding to the file operation instruction.

[0049] In some embodiments, the apparatus further includes:

[0050] A terminal registration unit is configured to receive a distributed digital identity registration application sent by the terminal, create distributed digital identity information of the terminal; verify the distributed digital identity registration application of the terminal; register the distributed digital identity of the terminal on the blockchain if the verification of the distributed digital identity registration application of the terminal is successful; verify the verifiable declaration registration application of the terminal; and register the verifiable declaration of the terminal on the blockchain if the verification of the verifiable declaration registration application of the terminal is successful.

[0051] In some embodiments, the terminal registration unit is configured to: receive a distributed digital identity registration application sent by the terminal; create distributed digital identity information for the terminal; verify the distributed digital identity registration application of the terminal; if the verification of the distributed digital identity registration application of the terminal is successful, obtain the distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management end of the terminal; call the blockchain to verify the distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management end of the terminal; if the verification is successful, store the distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management end of the terminal on the blockchain; verify the verifiable declaration registration application of the terminal; if the verification of the verifiable declaration registration application of the terminal is successful, register the verifiable declaration of the terminal on the blockchain.

[0052] In some embodiments, the apparatus further includes:

[0053] The issuing management terminal registration unit is used to receive distributed digital identity registration applications sent by the issuing management terminal, create distributed digital identity information of the issuing management terminal; verify the distributed digital identity registration applications of the issuing management terminal; register the distributed digital identity of the issuing management terminal on the blockchain if the verification of the distributed digital identity registration applications of the issuing management terminal is successful; verify the verifiable declaration registration applications of the issuing management terminal; and register the verifiable declaration of the issuing management terminal on the blockchain if the verification of the verifiable declaration registration applications of the issuing management terminal is successful.

[0054] In some embodiments, the apparatus further includes:

[0055] The points management unit is used to deduct the corresponding credit points from the blockchain according to preset points rules when a user's violation is detected; to delete the user's credit points record from the blockchain when a user's account has been cancelled; and to query the corresponding credit points details from the blockchain when a credit points query request is received.

[0056] In some embodiments, the file operation execution unit is specifically used for:

[0057] Select the file upload scenario and determine the file recipient;

[0058] Fill out the file upload form according to the file operation instructions. The file upload form includes file information and configuration information. The file configuration information includes at least the start date and end date of use.

[0059] Store the file on the local server;

[0060] The execution file is uploaded to the blockchain, and the file information and configuration information are stored on the blockchain.

[0061] In some embodiments, the file operation execution unit is specifically used for:

[0062] Obtain the identifier of the target file corresponding to the file operation instruction;

[0063] Authenticate the terminal;

[0064] If the terminal has file operation permissions for the target file, the file operation corresponding to the file operation instruction is executed. The file operation includes: modifying file uplink information and downloading the file.

[0065] In some embodiments, the file operation execution unit is specifically used for:

[0066] Send a request to the blockchain to query the list of on-chain operation information storage;

[0067] The terminal receives a list of operation information from the blockchain, which includes query results, timestamps, operator information, operation type, and hash address of the evidence storage information.

[0068] Thirdly, embodiments of the present invention provide a blockchain-based distributed digital identity authentication system, comprising: a distributed digital identity server, a terminal, an issuance management terminal, and a super management terminal;

[0069] The super management terminal corresponds to at least one of the issuance management terminals;

[0070] The issuance management terminal corresponds to at least one of the terminals;

[0071] The distributed digital identity server is used to implement the blockchain-based distributed digital identity authentication method described in any of the implementation methods in the first aspect.

[0072] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0073] This invention discloses a blockchain-based distributed digital identity authentication method. After a user completes unified authentication, if they want to initiate a file operation command through a terminal, the terminal's IP address, MAC address, and distributed digital identity must be verified. This method combines the verification of the user, the terminal, and the distributed digital identity to ensure the security of file operations and reduce the risk of critical data leakage. Attached Figure Description

[0074] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0075] Figure 1 This is a flowchart illustrating a blockchain-based distributed digital identity authentication method disclosed in an embodiment of the present invention.

[0076] Figure 2 This is a flowchart illustrating a method for terminal registration of a distributed digital identity disclosed in an embodiment of the present invention;

[0077] Figure 3 This is a flowchart illustrating a method for issuing and registering distributed digital identities at a management terminal, as disclosed in an embodiment of the present invention.

[0078] Figure 4 This is a schematic diagram of the structure of a blockchain-based distributed digital identity authentication device disclosed in an embodiment of the present invention. Detailed Implementation

[0079] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0080] To facilitate understanding of the specific technical solutions provided by this invention, the key technical terms involved in the technical solutions are explained below:

[0081] Distributed Digital Identity Authentication: Distributed Digital Identity (DID) leverages an underlying distributed infrastructure to change the way application vendors control digital identities, shifting the focus to user control and management. By returning ownership of identity data to users, it fundamentally solves the privacy issue of user identity data, while also ensuring the authenticity and trustworthiness of identity data and strong portability. A distributed digital identity generally comprises three key components: a DID identifier, a DID document, and a Verifiable Credential (VC). The DID identifier represents the user's identity; the DID document contains key information and verification methods related to DID verification; and the Verifiable Credential is a descriptive statement issued by one DID endorsing certain attributes of another DID, and includes its own digital signature to prove the authenticity of these attributes.

[0082] Super Management Terminal: A management terminal with super management privileges, primarily responsible for issuing and managing distributed digital identities.

[0083] Issuance Management Terminal: The management terminal with issuance management authority is mainly responsible for the distributed digital identity management of ordinary terminals.

[0084] Regular terminals are primarily used for data file uploads, downloads, viewing, and deactivation.

[0085] This invention provides a blockchain-based distributed digital identity authentication method applied to a distributed digital identity server. After a user completes unified authentication, if they want to initiate file operation commands through a terminal, the terminal's IP address, MAC address, and distributed digital identity must also be verified. This method combines the verification of the user, the terminal, and the distributed digital identity to ensure the security of file operations and reduce the risk of critical data leakage.

[0086] Please see Figure 1 This embodiment discloses a blockchain-based distributed digital identity authentication method, which includes the following steps:

[0087] S101: In response to the authentication request sent by the terminal, verify the terminal's IP and MAC addresses. The authentication request is sent by the terminal when it receives a file operation instruction from the user after the user has passed unified authentication.

[0088] In other words, after a user passes unified authentication, an identity authentication request is sent when initiating a file operation command. Only when the user's identity is successfully authenticated can the file operation be executed. Here, unified authentication refers to a set of security authentication operations required for a user to log in to the system. It can be account and password authentication or other authentication methods. This invention does not make any specific limitations.

[0089] File operations can include file upload, file download, etc.

[0090] The terminal's IP and MAC addresses are verified. The MAC address represents the Media Access Control address, and the IP address represents the Internet Protocol address. Verifying the MAC address verifies the terminal's physical address, while verifying the IP address verifies the terminal's logical address.

[0091] S102: If the IP and MAC verification of the terminal is successful, determine whether the terminal has registered a distributed digital identity;

[0092] Understandably, if the IP and MAC verification of the terminal fails, the authentication of the terminal will fail.

[0093] S103: If the terminal has already registered a distributed digital identity, verify the terminal's distributed digital identity;

[0094] If the terminal has not registered a distributed digital identity, it is necessary to register the terminal's distributed digital identity and then verify the terminal's distributed digital identity.

[0095] Verifying the distributed digital identity of a terminal specifically involves obtaining the terminal's verifiable credential and verifying the terminal's distributed digital identity. A verifiable credential (VC) is a descriptive statement issued by one DID to endorse certain attributes of another DID, and includes its own digital signature to prove the authenticity of these attributes. In this embodiment, the terminal's verifiable credential is a descriptive statement issued by the issuing management terminal to endorse the terminal, and includes the issuing management terminal's digital signature.

[0096] S104: If the distributed digital authentication of the terminal is successful, send authentication success information to the terminal;

[0097] S105: Perform the file operation corresponding to the file operation instruction.

[0098] As can be seen, the blockchain-based distributed digital identity authentication method disclosed in this embodiment requires the verification of the terminal's IP, MAC, and distributed digital identity before a user can initiate a file operation command through the terminal after unified authentication. This achieves joint verification of the user, terminal, and distributed digital identity, ensuring the security of file operations and reducing the risk of critical data leakage.

[0099] Please see Figure 2 This embodiment discloses a distributed digital identity registration method for a terminal, which specifically includes the following steps:

[0100] S201: Receive the distributed digital identity registration application sent by the terminal and create the terminal's distributed digital identity information;

[0101] The output data after creating the terminal's distributed digital identity information includes: success status, interface information, success / error response code, and digital identity generation result. The digital identity generation result includes: Distributed Digital Identity Identifier (DID), public key, private key, and other information.

[0102] S202: Request for Distributed Digital Identity Registration for Verification Terminal;

[0103] The input data for the distributed digital identity registration application of the verification terminal includes: the terminal's DID, public key, and identity signature, wherein the identity signature is generated using the terminal's private key; the output data includes: whether it was successful, interface information, success / error response code, and verification result.

[0104] S203: If the application for registration of the terminal's distributed digital identity is verified and approved, the terminal's distributed digital identity is registered on the blockchain;

[0105] The input data for registering a terminal's distributed digital identity on the blockchain includes: the terminal's DID, public key, identity signature, the DID of the issuing management terminal, and message signature; the output data includes: whether it was successful, interface information, success / error response code, and registration result.

[0106] Specifically, the distributed digital identity identifier, public key, identity signature of the blockchain verification terminal, and the distributed digital identity identifier and message signature of the issuing management terminal are invoked; if the verification is successful, the distributed digital identity identifier, public key, identity signature of the terminal, and the distributed digital identity identifier and message signature of the issuing management terminal are stored on the blockchain.

[0107] S204: Verifiable terminal declaration registration application;

[0108] The input data for the verifiable declaration registration application of the verification terminal includes: the terminal's DID, IP, MAC, IP type, message signature, and additional fields; the output data includes: whether it was successful, interface information, success / error response code, and verification result.

[0109] S205: If the verification of the terminal's verifiable claim registration application is approved, register the terminal's verifiable claim on the blockchain.

[0110] The input data for registering a verifiable claim for a terminal on the blockchain includes: the DID of the issuing management terminal, the issuance date, the expiration date, the terminal's DID, IP hash value, MAC hash value, device type, and the signature of the issuing management terminal; the output data includes: whether it was successful, interface information, success / error response code, registration result data, and on-chain claim address vcAddress.

[0111] Understandably, the distributed digital identity registration of a terminal requires information such as the DID of its corresponding issuing and management terminal. The issuing and management terminal also needs to register; please refer to [link / reference needed]. Figure 3 This embodiment discloses a method for issuing and registering distributed digital identities on a management terminal, including the following steps:

[0112] S301: Receive the distributed digital identity registration application sent by the issuing management terminal, and create the distributed digital identity information of the issuing management terminal;

[0113] The output data after creating the distributed digital identity information for the issuance management terminal includes: success status, interface information, success / error response code, and digital identity generation result. The digital identity generation result includes: Distributed Digital Identity Identifier (DID), public key, private key, and other information.

[0114] S302: Verify the distributed digital identity registration application issued by the management terminal;

[0115] The input data for verifying the distributed digital identity registration application of the issuing management terminal includes: the DID of the issuing management terminal, the public key, and the identity signature, wherein the identity signature is generated using the private key of the issuing management terminal; the output data includes: whether it was successful, interface information, success / error response code, and verification result.

[0116] S303: If the distributed digital identity registration application of the issuing management terminal is verified and approved, register the distributed digital identity of the issuing management terminal on the blockchain;

[0117] The input data for registering and issuing a distributed digital identity on the blockchain includes: the DID, public key, and identity signature of the issuing management terminal, as well as the DID and message signature of the super management terminal; the output data includes: whether it was successful, interface information, success / error response code, and registration result.

[0118] S304: Verify the registration application for a verifiable claim issued by the management system;

[0119] The input data for verifying the verifiable declaration registration application of the issuing management terminal includes: the issuing management terminal's DID, IP, MAC, IP type, additional fields, and message signature; the output data includes: whether it was successful, interface information, success / error response code, and verification result.

[0120] S305: If the verification of the verifiable claim registration application of the issuing management terminal is approved, register the verifiable claim of the issuing management terminal on the blockchain.

[0121] The input data for registering and issuing verifiable claims on the blockchain includes: the DID of the overdue management terminal, the issuance date, the expiration date, the DID of the issuing management terminal, the IP hash value, the MAC hash value, the device type, and the signature of the super management terminal; the output data includes: whether it was successful, interface information, success / error response code, registration result data, and on-chain claim address vcAddress.

[0122] Furthermore, the file operation corresponding to the file operation instruction executed in S105 of the above embodiment can be implemented in multiple ways:

[0123] Method 1: File Upload

[0124] Select a file upload scenario and specify the file recipient. You can create a new scenario if one has not been created. Scenarios can be created based on actual application needs. After the file upload is successful, the file recipient can download the file.

[0125] Fill out the file upload form according to the file operation instructions. The file upload form includes file information and configuration information. The file information includes: file identifier, file upload user account, DID of the terminal corresponding to the file upload user, terminal device type, and message signature, etc. The file configuration information includes at least the start date and end date of use, and may also include the file recipient account, DID of the terminal corresponding to the file recipient, timestamp, and file permissions.

[0126] Store the file on the local server;

[0127] The execution file is uploaded to the blockchain, and the file information and configuration information are stored on the blockchain.

[0128] The input data for executing the file upload includes: file identifier, file upload user account, DID of the terminal corresponding to the file upload user, terminal device type and message signature, file recipient account, DID of the terminal corresponding to the file recipient, timestamp, file permissions, start date and end date of use; the output data includes: whether it was successful, interface information, success / error response code, and upload result.

[0129] Method 2: Modifying file uplink information and downloading files

[0130] Obtain the identifier of the target file corresponding to the file operation command;

[0131] Authenticate the terminal;

[0132] If the terminal has file operation permissions for the target file, execute the file operation corresponding to the file operation instruction. The file operation includes: modifying the file's uplink information and downloading the file.

[0133] It should be noted that, based on the above file upload, only the file recipient has the permission to download the file, and only users with the permission to modify the file's on-chain information can modify the file's on-chain information. Therefore, when such operation instructions are received, it is necessary to authenticate the terminal and user initiating such operation instructions.

[0134] Method 3: File Lifecycle Tracing

[0135] Send a request to the blockchain to query the list of on-chain operation information storage;

[0136] A list of operational information from terminals receiving blockchain feedback.

[0137] The output data for querying the on-chain operation information storage list includes whether it was successful, interface information, success / error response code, and query results.

[0138] The query result operation information list includes the query result, timestamp, operator information, operation type, and evidence storage information hash address. The operator information includes: unified authentication account, terminal device DID, terminal IP hash value, and terminal MAC hash value.

[0139] Furthermore, this embodiment also provides a user credit score management function. When a user is found to have violated regulations, the corresponding credit score of the user is deducted from the blockchain according to the preset score rules. When a user's account is found to have been cancelled, the user's credit score record is deleted from the blockchain. When a credit score query request is received, the corresponding credit score details are queried from the blockchain.

[0140] Based on the blockchain-based distributed digital identity authentication method disclosed in the above embodiments, this embodiment correspondingly discloses a blockchain-based distributed digital identity authentication device, applied to a distributed digital identity server. Please refer to [link to relevant documentation]. Figure 4 The device includes:

[0141] The first verification unit 401 is used to verify the IP and MAC of the terminal in response to the identity authentication request sent by the terminal. The identity authentication request is sent by the terminal when it receives a file operation instruction initiated by the user after passing unified authentication.

[0142] The registration judgment unit 402 is used to determine whether the terminal has registered a distributed digital identity if the IP and MAC verification of the terminal is successful.

[0143] The second verification unit 403 is used to verify the distributed digital identity of the terminal if the terminal has already registered a distributed digital identity.

[0144] The authentication result feedback unit 404 is used to send authentication success information to the terminal when the distributed digital authentication of the terminal is successful;

[0145] The file operation execution unit 405 is used to execute the file operation corresponding to the file operation instruction.

[0146] In some embodiments, the apparatus further includes:

[0147] A terminal registration unit is configured to receive a distributed digital identity registration application sent by the terminal, create distributed digital identity information of the terminal; verify the distributed digital identity registration application of the terminal; register the distributed digital identity of the terminal on the blockchain if the verification of the distributed digital identity registration application of the terminal is successful; verify the verifiable declaration registration application of the terminal; and register the verifiable declaration of the terminal on the blockchain if the verification of the verifiable declaration registration application of the terminal is successful.

[0148] In some embodiments, the terminal registration unit is configured to: receive a distributed digital identity registration application sent by the terminal; create distributed digital identity information for the terminal; verify the distributed digital identity registration application of the terminal; if the verification of the distributed digital identity registration application of the terminal is successful, obtain the distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management end of the terminal; call the blockchain to verify the distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management end of the terminal; if the verification is successful, store the distributed digital identity identifier, public key, identity signature, and the distributed digital identity identifier and message signature of the issuing management end of the terminal on the blockchain; verify the verifiable declaration registration application of the terminal; if the verification of the verifiable declaration registration application of the terminal is successful, register the verifiable declaration of the terminal on the blockchain.

[0149] In some embodiments, the apparatus further includes:

[0150] The issuing management terminal registration unit is used to receive distributed digital identity registration applications sent by the issuing management terminal, create distributed digital identity information of the issuing management terminal; verify the distributed digital identity registration applications of the issuing management terminal; register the distributed digital identity of the issuing management terminal on the blockchain if the verification of the distributed digital identity registration applications of the issuing management terminal is successful; verify the verifiable declaration registration applications of the issuing management terminal; and register the verifiable declaration of the issuing management terminal on the blockchain if the verification of the verifiable declaration registration applications of the issuing management terminal is successful.

[0151] In some embodiments, the apparatus further includes:

[0152] The points management unit is used to deduct the corresponding credit points from the blockchain according to preset points rules when a user's violation is detected; to delete the user's credit points record from the blockchain when a user's account has been cancelled; and to query the corresponding credit points details from the blockchain when a credit points query request is received.

[0153] In some embodiments, the file operation execution unit is specifically used for:

[0154] Select the file upload scenario and determine the file recipient;

[0155] Fill out the file upload form according to the file operation instructions. The file upload form includes file information and configuration information. The file configuration information includes at least the start date and end date of use.

[0156] Store the file on the local server;

[0157] The execution file is uploaded to the blockchain, and the file information and configuration information are stored on the blockchain.

[0158] In some embodiments, the file operation execution unit is specifically used for:

[0159] Obtain the identifier of the target file corresponding to the file operation instruction;

[0160] Authenticate the terminal;

[0161] If the terminal has file operation permissions for the target file, the file operation corresponding to the file operation instruction is executed. The file operation includes: modifying file uplink information and downloading the file.

[0162] In some embodiments, the file operation execution unit is specifically used for:

[0163] Send a request to the blockchain to query the list of on-chain operation information storage;

[0164] The terminal receives a list of operation information from the blockchain, which includes query results, timestamps, operator information, operation type, and hash address of the evidence storage information.

[0165] This invention also provides a blockchain-based distributed digital identity authentication system, comprising: a distributed digital identity server, a terminal, an issuance and management terminal, and a super management terminal;

[0166] The super management terminal corresponds to at least one of the issuance management terminals;

[0167] The issuance management terminal corresponds to at least one of the terminals;

[0168] The distributed digital identity server is used to implement the blockchain-based distributed digital identity authentication method described in any of the above embodiments.

[0169] This embodiment discloses a blockchain-based distributed digital identity authentication system. After a user completes unified authentication, if they want to initiate a file operation command through a terminal, the terminal's IP address, MAC address, and distributed digital identity must be verified. This system combines the verification of the user, the terminal, and the distributed digital identity to ensure the security of file operations and reduce the risk of critical data leakage.

[0170] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.

[0171] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0172] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0173] The above embodiments can be combined arbitrarily. The descriptions of the disclosed embodiments and the features recorded in the embodiments of this specification can be substituted or combined with each other, so that those skilled in the art can implement or use this application.

[0174] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A blockchain-based distributed digital identity authentication method, characterized in that, The method is applied to a distributed digital identity server, and comprises the following steps: In response to an identity authentication request sent by a terminal, the IP and MAC of the terminal are verified, the identity authentication request being sent by the terminal when the terminal receives a file operation instruction initiated by a user after passing through unified authentication; If the terminal has registered a distributed digital identity, a verifiable claim of the terminal is obtained, the distributed digital identity of the terminal is verified, the verifiable claim being a descriptive claim issued by an issuing management end for endorsement of the terminal and being additionally provided with a digital signature of the issuing management end; If the distributed digital identity of the terminal is verified, authentication passing information is sent to the terminal; The file operation instruction is executed to perform a corresponding file operation. If the terminal has not registered a distributed digital identity, the method further comprises the following steps:

2. The method of claim 1, wherein, A distributed digital identity registration application of the terminal is received, and distributed digital identity information of the terminal is created; The distributed digital identity registration application of the terminal is verified; If the distributed digital identity registration application of the terminal is verified, the distributed digital identity of the terminal is registered on a blockchain; A verifiable claim registration application of the terminal is verified; If the verifiable claim registration application of the terminal is verified, the verifiable claim of the terminal is registered on the blockchain. The distributed digital identity of the terminal is registered on the blockchain, comprising the following steps:

3. The method of claim 2, wherein, A distributed digital identity identifier, a public key, an identity signature of the terminal, and a distributed digital identity identifier and a message signature of the issuing management end are obtained; The distributed digital identity identifier, the public key, the identity signature of the terminal, and the distributed digital identity identifier and the message signature of the issuing management end are verified by calling a blockchain; If the verification is passed, the distributed digital identity identifier, the public key, the identity signature of the terminal, and the distributed digital identity identifier and the message signature of the issuing management end are stored on the blockchain. The method further comprises the following steps:

4. The method of claim 3, wherein, A distributed digital identity registration application of the issuing management end is received, and distributed digital identity information of the issuing management end is created; The distributed digital identity registration application of the issuing management end is verified; If the distributed digital identity registration application of the issuing management end is verified, the distributed digital identity of the issuing management end is registered on a blockchain; A verifiable claim registration application of the issuing management end is verified; If the verifiable claim registration application of the issuing management end is verified, the verifiable claim of the issuing management end is registered on the blockchain. The method further comprises the following steps:

5. The method of claim 1, wherein, If it is monitored that a user has a violation operation, corresponding credit points of the user are deducted in the blockchain according to a preset credit point rule; If it is monitored that an account of a user has been cancelled, credit point records of the user are deleted in the blockchain; If a credit point query request is received, corresponding credit point detail information is queried in the blockchain. The file operation instruction is executed to perform a corresponding file operation, comprising the following steps:

6. The method of claim 1, wherein, ​ A file uploading scenario is selected, and a file receiver is determined; A file uploading form is filled according to the file operation instruction, the file uploading form including file information and configuration information, and the configuration information of the file at least including a start date of use and an end date of use; The file is stored to a local server; File chaining is performed, and the file information and the configuration information are stored in a chain.

7. The method of claim 1, wherein, The file operation corresponding to the file operation instruction is performed, including: An identifier of a target file corresponding to the file operation instruction is acquired; The terminal is authenticated; In a case where the terminal has a file operation permission on the target file, the file operation corresponding to the file operation instruction is performed, and the file operation includes file chaining information modification and file downloading.

8. The method of claim 5, wherein, The file operation corresponding to the file operation instruction is performed, including: A chain operation information notarization list query request is sent to a blockchain; An operation information list of the terminal fed back by the blockchain is received, the operation information list including a query result, a timestamp, operator information, an operation type, and a notarization information hash address. 9.A blockchain-based distributed digital identity authentication apparatus characterized by comprising: The apparatus is applied to a distributed digital identity server, and the apparatus includes: A first verification unit configured to verify an IP and a MAC of a terminal in response to an identity authentication request sent by the terminal, the identity authentication request being sent by the terminal when the terminal initiates a file operation instruction after receiving a unified authentication by a user; A registration judgment unit configured to judge whether the terminal has registered a distributed digital identity in a case where the IP and the MAC of the terminal are verified; A second verification unit configured to acquire a verifiable claim of the terminal and verify the distributed digital identity of the terminal if the terminal has registered the distributed digital identity, the verifiable claim being a descriptive claim issued by an issuing management end for endorsement to the terminal and additionally including a digital signature of the issuing management end; An authentication result feedback unit configured to send authentication pass information to the terminal in a case where the distributed digital identity of the terminal is verified; A file operation execution unit configured to perform a file operation corresponding to the file operation instruction. 10.A blockchain-based distributed digital identity authentication system, characterized in that, The apparatus includes: A distributed digital identity server, a terminal, an issuing management end, and a super management end; The super management end corresponds to at least one of the issuing management ends; The issuing management end corresponds to at least one of the terminals; The distributed digital identity server is configured to perform the distributed digital identity authentication method based on the blockchain in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Distributed inter-bank card-free cash withdrawal method and device, equipment and medium

    CN113240417A