Digital identity login method, device, computer equipment, and storage medium
Through the digital identity login method of blockchain technology, image code scanning is used to obtain digital identity identification and encrypt credentials for permission verification, which solves the tediousness and security risks of centralized identity login and achieves the effect of simplifying login and information security.
Patent Information
- Application Number
- CN202211516667.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-30
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2042-11-30
AI Technical Summary
In existing technologies, centralized identity login systems have risks such as cumbersome accounts, information leakage, and user privacy security, and third-party centralized IDs increase user security risks through big data analysis.
Using blockchain technology, digital identity identification is obtained by scanning the image code, the target credentials are encrypted using local encryption information and the encryption information of the target platform, and permission verification is performed after verification by the blockchain and data identity system to generate a jump result.
It realizes a simplified login process, highly secures user information, reduces the risk of information leakage, and allows users to control their own information. The login information is submitted to the Internet platform after verification, ensuring information security.
Smart Images

Figure CN116318776B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain technology, and in particular to a digital identity login method, apparatus, computer equipment, storage medium, and computer program product. Background Art
[0002] With the rapid development of Internet technology, the convenience and importance of automatic computer verification and application login to connect offline entities to online virtual identities are becoming increasingly prominent.
[0003] Currently, traditional technologies include centralized storage, centralized ID (Identity document), and third-party centralized ID. However, when logging into each internet platform with a centralized ID, users need to remember the account password for each platform. As the number of platforms increases, simple login becomes extremely cumbersome. Centrally stored data is controlled by centralized institutions. Once the centralized institution commits malicious acts or the centralized server is attacked, user personal information will be leaked, directly endangering the user's property and personal safety. Third-party centralized IDs will collect users' internet usage preferences and generate user profiles through big data analysis, greatly increasing user security risks. Summary of the Invention
[0004] Based on this, it is necessary to provide a digital identity login method, device, computer equipment, computer-readable storage medium and computer program product that can improve security in response to the above technical problems.
[0005] In a first aspect, the present application provides a digital identity login method applied to a client. The method comprises:
[0006] Scan the image code to obtain a digital identity;
[0007] Sending the digital identity to a digital identity system, and obtaining digital identity information from the blockchain through the digital identity system based on the digital identity;
[0008] receiving the digital identity information sent by the digital identity system, obtaining a target credential based on the digital identity information, and encrypting the target credential using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is encryption information of the target platform;
[0009] The encrypted target credential is sent to the target platform. The target platform is used to perform permission verification on the decrypted target credential after the data identity system and the blockchain successfully verify the decrypted target credential, and generate a jump result after the permission verification; and send the jump result to the client. The decrypted target credential is obtained after the target platform decrypts the encrypted target credential;
[0010] Receive the jump result, and jump to the target page according to the jump result.
[0011] In one embodiment, the method of encrypting the target credential using the local encryption information and the target encryption information to obtain the encrypted target credential includes:
[0012] Encrypt the target credential using local encryption information to obtain initial authentication information; the local encryption information is a local private key;
[0013] The initial authentication information is encrypted by target encryption information to obtain the encrypted target credential; the target encryption information is the public key of the target platform.
[0014] In one embodiment, obtaining the target credential based on the digital identity information includes:
[0015] Obtaining an initial credential based on the digital identity information query;
[0016] A selection instruction is received, and the target credential is obtained from the initial credential.
[0017] In a second aspect, the present application provides a method for digital identity login applied to a target platform. The method includes:
[0018] Receive an encrypted target credential sent by a client; the target credential carries a digital identity;
[0019] Decrypting the encrypted target certificate to obtain a decrypted target certificate;
[0020] Sending the decrypted target credential and the digital identity to a data identity system, wherein the data identity system is configured to parse the decrypted target credential and send the parsed decrypted target credential and the digital identity to the blockchain;
[0021] Receiving a verification result sent by the blockchain, the verification result being obtained after the blockchain verifies the decryption target credential and the digital identity;
[0022] According to the verification result, the user login authority is verified, and after the user login authority verification is successful, a jump result is generated and sent to the client; the jump result is used to instruct the client to jump to the target page.
[0023] In one embodiment, the above-mentioned verification of the user login authority based on the verification result, generating a jump result after the user login authority verification is successful, and sending the jump result to the client includes:
[0024] When the verification result is successful, verifying the user login authority using the verification information;
[0025] When the user login authority is successfully verified, the jump result is generated and sent to the client.
[0026] In a third aspect, the present application provides a digital identity login method applied to a digital identity system, the method comprising:
[0027] Receive the decrypted target credential and digital identity sent by the target platform, parse the decrypted target credential, and send the parsed decrypted target credential and digital identity to the blockchain; the blockchain is used to verify the parsed decrypted target credential and digital identity; the decrypted target credential is obtained after the target platform decrypts the encrypted target credential.
[0028] In a fourth aspect, the present application provides a digital identity login system applied to a blockchain, the method comprising:
[0029] Receiving an information query request sent by a digital identity system, the query request carrying a digital identity identifier; the query request is generated by the digital identity system after receiving the digital identity identifier sent by the client;
[0030] Perform a query based on the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier;
[0031] Sending the digital identity information to the digital identity system; the digital identity system parses the digital identity information and sends the parsed digital identity information to the client;
[0032] The parsed decrypted target credential and the digital identity identifier sent by the digital identity system are received for verification, a verification result is generated, and the verification result is sent to the target platform.
[0033] In a fifth aspect, the present application further provides a digital identity login device for a client. The device comprises:
[0034] The response module is used to scan the image code to obtain a digital identity;
[0035] A first sending module, configured to send the digital identity identifier to a digital identity system, and obtain digital identity information from the blockchain through the digital identity system based on the digital identity identifier;
[0036] A first receiving module is configured to receive the digital identity information sent by the digital identity system, obtain a target credential based on the digital identity information, and encrypt the target credential using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is encryption information of a target platform;
[0037] a credential sending module, configured to send the encrypted target credential to the target platform; the target platform is configured to perform permission verification on the decrypted target credential after the data identity system and the blockchain successfully verify the decrypted target credential, generate a redirect result after the permission verification, and send the redirect result to the client; the decrypted target credential is obtained after the target platform decrypts the encrypted target credential;
[0038] The jump module is used to receive the jump result and jump to the target page according to the jump result.
[0039] In a sixth aspect, the present application further provides a digital identity login device applied to a target platform, the device comprising:
[0040] A second receiving module is configured to receive an encrypted target certificate sent by a client; the target certificate carries a digital identity identifier;
[0041] A decryption module, configured to decrypt the encrypted target credential to obtain a decrypted target credential;
[0042] A second sending module is used to send the decrypted target credential and the digital identity to a data identity system, and the data identity system is used to parse the decrypted target credential and send the parsed decrypted target credential and the digital identity to the blockchain;
[0043] A third receiving module is configured to receive a verification result sent by the blockchain, where the verification result is obtained after the blockchain verifies the decryption target credential and the digital identity;
[0044] The permission verification module is used to verify the user login permission according to the verification result, and after the user login permission verification is successful, generate a jump result and send the jump result to the client; the jump result is used to instruct the client to jump to the target page.
[0045] In a seventh aspect, the present application further provides a device for use in a digital identity system, the device comprising:
[0046] The fourth receiving module is used to receive the decrypted target certificate and digital identity sent by the target platform, parse the decrypted target certificate, and send the parsed decrypted target certificate and the digital identity to the blockchain; the blockchain is used to verify the parsed decrypted target certificate and the digital identity; the decrypted target certificate is obtained after the target platform decrypts the encrypted target certificate.
[0047] In an eighth aspect, the present application further provides a digital identity login device applied to a blockchain, the device comprising:
[0048] a fifth receiving module, receiving an information query request sent by a digital identity system, wherein the query request carries a digital identity identifier; the query request is generated by the digital identity system after receiving the digital identity identifier sent by the client;
[0049] A query module, configured to query the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier;
[0050] A third sending module is configured to send the digital identity information to the digital identity system; the digital identity system parses the digital identity information and sends the parsed digital identity information to the client;
[0051] The sixth receiving module is configured to receive the parsed decrypted target credential and the digital identity identifier sent by the digital identity system for verification, generate a verification result, and send the verification result to the target platform.
[0052] In a ninth aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method in any one of the above embodiments when executing the computer program.
[0053] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method in any one of the above embodiments.
[0054] In a fifth aspect, the present application further provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the method in any one of the above embodiments.
[0055] The above-mentioned digital identity login method, device, computer device, storage medium and computer program product are as follows: the client first scans the image code to obtain a digital identity identifier, then sends the digital identity identifier to the digital identity system, and the digital identity system obtains digital identity information from the blockchain based on the data identity identifier. The client then receives the digital identity information sent by the digital identity system and obtains a target credential based on the digital identity information. The target credential is encrypted using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is the encryption information of the target platform; the encrypted target credential is sent to the target platform, which is used to perform permission verification on the decrypted target credential after the data identity system and the blockchain successfully verify the decrypted target credential, and generates a jump result after the permission verification; and sends the jump result to the client; the decrypted target credential is obtained after the target platform decrypts the encrypted target credential; the jump result is received and the client jumps to the target page based on the jump result. First, this login method is relatively simple; second, based on the distributed digital identity scanning login, the login information is controlled by the user himself, and after the user manually selects and confirms, it is submitted to the Internet platform for verification, which can ensure the security of user information. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 A diagram showing an application environment of a digital identity login method in one embodiment;
[0057] Figure 2 1 is a flow chart of a digital identity login method according to an embodiment;
[0058] Figure 3 Schematic diagram of a digital identity login method according to another embodiment;
[0059] Figure 4 Schematic diagram of the flow of digital identity login method in other embodiments;
[0060] Figure 5 A flowchart of the steps of a digital identity login method in one embodiment;
[0061] Figure 6 A schematic diagram of the steps before scanning a QR code to log in in one embodiment;
[0062] Figure 7 This is a structural block diagram of a digital identity login device in one embodiment;
[0063] Figure 8is a structural block diagram of a digital identity login device in another embodiment;
[0064] Figure 9 It is a structural block diagram of a digital identity login device in other embodiments;
[0065] Figure 10 FIG. 4 is a diagram showing the internal structure of a client in one embodiment. DETAILED DESCRIPTION
[0066] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0067] The digital identity login method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, client 102, target platform 104, digital identity system 106, and blockchain 108 communicate. Client 102 scans the image code to obtain a digital identity identifier, and then sends the digital identity identifier to digital identity system 106. Digital identity system 106 queries blockchain 108 based on the digital identity identifier and obtains digital identity information corresponding to the digital identity system identifier. Blockchain 108 sends the obtained digital identity information to digital identity system 106. Digital identity system 106 sends the digital identity information to client 102 and obtains a target credential based on the digital identity information. It then encrypts the target credential using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is the encryption information of the target platform. Client 102 sends the encrypted target credential to target platform 104. Target platform 104 is configured to perform permission verification on the decrypted target credential after successful verification by data system 106 and blockchain 108. Upon successful permission verification, it generates a redirect result and sends the redirect result to client 102. The decrypted target credential is obtained by the target platform decrypting the encrypted target credential. Client 102 receives the redirect result and redirects to the target page based on the redirect result. Client 102 may be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, and smart car devices. Portable wearable devices may include smart watches, smart bracelets, and head-mounted devices. Target platform 104 and digital identity system 106 may be implemented using a standalone server or a server cluster consisting of multiple servers.
[0068] In one embodiment, Figure 2 As shown, a digital identity login method is provided, which is applied to Figure 1 The client 102 in the example is used for illustration, and the steps include the following steps S202 to S210.
[0069] S202, scanning the image code to obtain a digital identity.
[0070] An image code is a code that can be scanned to obtain information and can be a one-dimensional or two-dimensional code. A digital identity is a new type of distributed digital identity based on blockchain technology that can define any entity in the real world. A distributed digital identity typically consists of a distributed digital identity identifier and a verifiable declaration. Digital identities are unique within an application and self-discoverable across applications, making them suitable for DID representation.
[0071] Optionally, the image code is a pre-generated login QR code for the target platform, which contains information such as the callback URL after scanning the code, the target platform's DID, the authentication type, and the QR code ID (UUID). The target platform can be any internet platform, such as Meituan or Weibo.
[0072] Optionally, the client scans the QR code and obtains relevant information carried by the QR code, such as the callback address URL, the Internet platform DID and the QR code number UUID, and then uses the digital identity identifier to initiate a request to query the DID document to the distributed digital identity system.
[0073] S204: Send the digital identity to the digital identity system, and obtain the digital identity information from the blockchain based on the digital identity through the digital identity system.
[0074] Specifically, the client sends the DID to the digital identity system, and the distributed digital identity system queries the blockchain network for the DID document related to the Internet platform based on the digital identity identifier.
[0075] Optionally, the client generates a query request for digital identity information based on the DID. The query request includes a waiting time. For example, if the digital identity system takes longer than the waiting time to query the blockchain for digital identity information based on the digital identity identifier, a "please try again" result is returned to the client, and the client generates a new query request for digital identity information. This prevents resources from being continuously occupied, preventing other requests from being responded to.
[0076] Alternatively, the client can directly send the DID to the blockchain, which will directly obtain the digital identity information, but this will increase the coupling of the system and make development and output inconvenient.
[0077] S206, receiving the digital identity information sent by the digital identity system, obtaining a target credential based on the digital identity information, and encrypting the target credential using the local encryption information and the target encryption information to obtain an encrypted target credential; the target encryption information is the encryption information of the target platform.
[0078] The target credential is selected by the client from the initial credential. Both the target credential and the initial credential are essentially verifiable credentials. Verifiable credentials are open standards for digital identity that can represent all the information in a physical credential and can be used to prove anything, such as citizen identity (ID card credential), student identity (student card credential), property (property credential), etc. Verifiable credentials can be issued by any person or organization. The entity that generates the credential is called the issuer, the entity that owns the credential is called the holder, and the entity that verifies the credential is called the verifier. The holder can present the credential to anyone for verification, thereby proving something related to them. Verifiable credentials consist of three parts: metadata, declaration, and proof. Metadata describes the credential's attributes, such as the issuer, issuance time, expiration time, and credential type; declaration describes the statement about the subject; and proof describes the information required to verify the credential.
[0079] The encrypted target credential is generated by encrypting the target credential using the local encryption information and the target encryption information.
[0080] The local encryption information refers to the encryption information of the client, which may be a local private key; the target encryption information refers to the encryption information of the target platform, which may be the public key of the target platform.
[0081] Optionally, the target encrypted information is the digital identity information and the target encrypted information returned by the blockchain together when the digital identity system queries the digital identity information from the blockchain according to the digital identity identifier.
[0082] Optionally, the blockchain can encode the target encrypted information obtained from the digital identity query according to preset encoding rules. The encoded target encrypted information and the digital identity information are then sent together to the digital identity system. After parsing by the digital identity system, the encoded target encrypted information and the digital identity information are sent to the client, which decodes them according to preset decoding rules. The preset encoding rules refer to the pre-set rules for encoding the target encrypted information, and correspondingly, the preset decoding rules refer to the pre-set rules for decoding the encoded target encrypted information. Blockchain encoding of the target encrypted information can prevent third parties from obtaining the target encrypted information during transmission, thereby ensuring the security of the target encrypted information.
[0083] Optionally, the blockchain can encode the digital identity information and the target encrypted information using preset encoding rules.
[0084] Optionally, the encoding method for the digital identity information and the encoding method for the target encrypted information may be different, which can further ensure the security of the digital identity information and the target encrypted information.
[0085] Specifically, when the client receives the digital identity information sent by the digital identity system, it can obtain the target certificate based on the digital identity information, then encrypt the target certificate using local encryption information, and then encrypt it using target encryption information to obtain the encrypted target certificate, where the target encryption information is the encryption information of the target platform.
[0086] S208, the encrypted target credential is sent to the target platform. The target platform is used to perform permission verification on the decrypted target credential after the data identity system and the blockchain successfully verify the decrypted target credential, and generate a jump result after the permission verification; and send the jump result to the client; the decrypted target credential is obtained after the target platform decrypts the encrypted target credential.
[0087] Optionally, after the client sends the encrypted target credential to the target platform, the target platform decrypts it using a local private key to obtain a decrypted target credential, and then sends a verification request for the decrypted target credential to the digital identity system.
[0088] Exemplarily, the digital identity system sends the digital identity identifier and the verification request to the blockchain, which verifies the decrypted target credential based on the digital identity identifier and generates a verification result. The verification result is sent to the target platform, which performs further authority verification based on the verification result.
[0089] Optionally, the digital identity system initiates a verification request to the DID and the verifiable claim in a synchronous manner, and the digital identity system obtains the digital identity information from the blockchain and sends the verification result of the decrypted target certificate to the target platform.
[0090] It's important to note that verification of the target decrypted credentials must be performed on the blockchain to facilitate access to the target platform. Directly operating the chain layer would involve blockchain SDK-related technologies, increasing the cost of platform modification. However, managing through a distributed digital identity system simplifies upper-layer application development costs and facilitates technology adoption.
[0091] S210: Receive a jump result, and jump to a target page according to the jump result.
[0092] Exemplarily, the client receives a jump result, and when the jump result is passed, jumps to the target platform according to the jump link carried in the jump result.
[0093] Exemplarily, the client receives the jump result, and when the jump result is failure, a result indicating unsuccessful login is displayed.
[0094] In the above digital identity login method, the client first scans the image code to obtain a digital identity identifier, and then sends the digital identity identifier to the digital identity system. The digital identity system obtains digital identity information from the blockchain based on the data identity identifier, and then receives the digital identity information sent by the digital identity system, and obtains the target certificate based on the digital identity information. The target certificate is encrypted using local encryption information and target encryption information to obtain an encrypted target certificate; the target encryption information is the encryption information of the target platform; the encrypted target certificate is sent to the target platform, and the target platform is used to verify the authority of the decrypted target certificate after the data identity system and the blockchain successfully verify the decrypted target certificate, and generate a jump result after the authority verification; and send the jump result to the client; the decrypted target certificate is obtained after the target platform decrypts the encrypted target certificate; the jump result is received and the jump to the target page is based on the jump result. First, this login method is relatively simple; second, based on the distributed digital identity scanning login, the login information is controlled by the user himself, and after the user manually selects and confirms, it is submitted to the Internet platform for verification, which can ensure the security of user information.
[0095] In one embodiment, the above-mentioned use of local encryption information and target encryption information to encrypt the target credential to obtain the encrypted target credential includes: using the local encryption information to sign the target credential to obtain initial authentication information; the local encryption information is a local private key; the initial authentication information is encrypted by the target encryption information to obtain the encrypted target credential; the target encryption information is the public key of the target platform.
[0096] Optionally, the initial authentication information refers to information obtained by the client after signing the target credential using a local private key. For example, the client can use an asymmetric key encryption algorithm to sign the target credential, which can ensure the integrity, identity authentication and non-repudiation of the sent information, and can ensure the confidentiality of the sent information.
[0097] Optionally, the client encrypts the initial authentication information using the target platform's public key to obtain an encrypted target credential. For example, the client may encrypt the initial authentication information using an encryption algorithm such as DES (Data Encryption Standard), AES (Advanced Encryption Standard), or HMAC-SHA256 (Hash-based Message Authentication Code).
[0098] One thing that needs to be explained is that the local encryption information must be used for signing first, and then the target encryption information must be used for encryption. Since the target encryption information is the public key of the target platform, if the target encryption information is used to sign the target certificate, then other clients can also obtain the public key from the blockchain and tamper with the initial authentication information.
[0099] In the above embodiment, the client first uses the local encryption information to sign the target credential, which can ensure that the initial authentication information cannot be tampered with; then, the target encryption information is used to encrypt the initial encrypted information, further ensuring the security of the initial authentication information.
[0100] In one embodiment, the initial credential is obtained based on the query of the digital identity information; and a selection instruction is received to obtain the target credential from the initial credential.
[0101] Optionally, a distributed digital identity configuration module is pre-stored in the client, and a variety of verifiable credentials are stored in the distributed digital identity configuration module.
[0102] Optionally, the client queries the distributed digital identity configuration module based on the digital identity information to obtain initial credentials. Initial credentials refer to verifiable credentials required by the target platform. For example, the client can query the distributed digital identity configuration module for the verifiable credentials required by Meituan based on Meituan's digital identity information.
[0103] The selection instruction refers to an instruction received by the client when the user operates on the display screen, and the target credential can be obtained from the initial credential according to the operation instruction.
[0104] Exemplarily, the client screens out initial credentials for the user to select based on the digital identity information. After receiving the selection instruction, the client obtains the target credentials from the initial credentials.
[0105] Optionally, when selecting the initial credential, the user may make a selection according to the description corresponding to the initial credential, which makes it easier for the user to select the desired credential.
[0106] In the above embodiment, the client can accurately obtain the initial credential based on the digital identity information, and then obtain the target credential from the initial credential by selecting an instruction, so that the credential required by the user can be accurately obtained.
[0107] In one embodiment, Figure 3 As shown, a digital identity login method is provided, which is applied to Figure 1 Taking the target platform 104 in FIG. 1 as an example, the method includes the following steps S302 to S310:
[0108] S302, receiving the encrypted target certificate sent by the client; the target certificate carries a digital identity.
[0109] Exemplarily, the target platform receives the encrypted target credential sent by the client, and the specific process of obtaining the target credential and encrypting the target credential can refer to the method described in the above embodiment.
[0110] S304: Decrypt the encrypted target certificate to obtain a decrypted target certificate.
[0111] Exemplarily, the target platform uses the local private key to decrypt the target credential to obtain a decrypted target credential. The decrypted target credential refers to a verifiable credential obtained by decrypting the encrypted target credential. It should be noted that the local private key is the private key of the target platform.
[0112] S306: Send the decrypted target credential and the digital identity to the data identity system. The data identity system is used to parse the decrypted target credential and send the parsed decrypted target credential and the digital identity to the blockchain.
[0113] Optionally, the target platform sends a verification request to the data identity system, which carries the decrypted target credentials and the data identity system. The verification request refers to a request sent by the target platform to verify the decrypted target credentials. For example, the verification request may verify the authenticity and validity of the decrypted target credentials.
[0114] Optionally, the target platform sends the verification request to the digital identity system, which parses the verification request to obtain a digital identity identifier and a data identity identifier, and then sends the parsed decrypted target credential and data identity identifier to the blockchain, where the decrypted target credential is verified based on the digital identity identifier.
[0115] Optionally, the target platform can set the waiting time for the verification request. For example, the waiting time can be set to 60 seconds. When the waiting time is exceeded, the target platform sends a timeout reminder to the client, which can avoid resources being occupied all the time.
[0116] S308, receiving the verification result sent by the blockchain, which is obtained after the blockchain verifies the decryption target certificate and the digital identity.
[0117] The target platform receives the verification result of the decrypted target certificate sent by the blockchain, wherein the verification result is obtained after the blockchain verifies the decrypted target certificate and the digital identity.
[0118] S310, based on the verification result, verify the user login authority, and after the user login authority verification is successful, generate a jump result and send the jump result to the client; the jump result is used to instruct the client to jump to the target page.
[0119] Optionally, after the target platform receives the verification result returned by the blockchain, it verifies the login permission based on the information content in the decrypted target credential. When the login permission verification is successful, a jump result is generated and sent to the client. The client can jump to the target page based on the jump result.
[0120] Optionally, after the login authority is successfully verified, a jump result is generated, which is the address of the target page. The client can jump to the corresponding page according to the address of the target page.
[0121] Optionally, when the login authority verification is unsuccessful, a jump result is generated, which is a page where the login failed.
[0122] For example, after the target platform passes the verification, a token (structure) is generated and sent to the client, and the client logs in based on the token.
[0123] In the above implementation, the target platform obtains the encrypted target credential, decrypts the encrypted target credential with its private key, obtains the decrypted target credential, and performs login verification on the decrypted target credential after verification. This can simplify the entire login process because the target platform only needs to verify the user's login authority.
[0124] In one of the embodiments, the user login authority is verified according to the verification result, and after the user login authority verification is successful, a jump result is generated and the jump result is sent to the client, including: when the verification result is successful, the user login authority is verified using the verification information; when the user login authority verification is successful, a jump result is generated and the jump result is sent to the client.
[0125] For example, when the blockchain returns a successful verification result, the target platform verifies the user's login authority using the verification information obtained by the target platform from decoding the target credential.
[0126] Exemplarily, after the target user successfully verifies the user login authority, a jump result is generated and sent to the client, and the client jumps to the target platform according to the jump result.
[0127] Optionally, when the blockchain fails to verify the decoding target credential and the target platform fails to verify the login authority, a verification failure message is sent to the client.
[0128] In the above embodiment, the target platform can send the jump result to the client only after the verification result is successful and the user login authority verification is successful, which can ensure the security of the target platform.
[0129] In one embodiment, a digital identity login method is provided, which is applied to Figure 1 Taking the digital identity system 106 in the example as an example, the following steps are included: receiving the decrypted target certificate and digital identity identifier sent by the target platform, parsing the decrypted target certificate, and sending the parsed decrypted target certificate and digital identity identifier to the blockchain; the blockchain is used to verify the parsed decrypted target certificate and digital identity identifier; the decrypted target certificate is obtained after the target platform decrypts the encrypted target certificate.
[0130] Exemplarily, the digital identity system receives a decrypted target credential and a digital identity, parses the decrypted target credential, and sends the parsed decrypted target credential and the digital identity to a blockchain, which verifies the decrypted target credential based on the digital identity. The blockchain verifies the parsed decrypted target credential and the digital identity; the decrypted target credential is obtained by the target platform decrypting the encrypted target credential.
[0131] Exemplarily, the digital identity system receives a query request sent by a client. After receiving the query request, the digital identity system searches the blockchain for digital identity information corresponding to the digital identity identifier based on the digital identity identifier, and sends the digital identity information to the client.
[0132] Optionally, the digital identity system creates a digital identity for the user in advance. Optionally, the digital identity system needs to review the information submitted by the user, and only after the qualification review is passed can the digital identity system be created for the user.
[0133] Optionally, the digital identity system can send the information submitted by the user to the credential issuing authority for qualification review. After the qualification review is passed, a verifiable credential is generated and the status of the credential (issued, deleted, pending approval, etc.) is saved in the blockchain. After successful saving, the original credential information is sent to the client.
[0134] In the above embodiment, the digital identity system promptly parses the decrypted target credential and the digital identity identifier after receiving the decrypted target credential and the digital identity identifier, and sends the parsed decrypted target credential and the digital identity identifier to the blockchain, thereby providing verification management for the client.
[0135] In one embodiment, Figure 4 As shown, a digital identity login method is provided, which is applied to Figure 1The blockchain 108 in FIG. 1 is used as an example to illustrate the process, including the following steps S402 to S408.
[0136] S402, receiving an information query request sent by the digital identity system, the query request carrying the digital identity identifier; the query request is generated by the digital identity system after receiving the digital identity identifier sent by the client.
[0137] Exemplarily, the blockchain receives an information query request sent by a digital identity system, and the information query request carries a digital identity identifier.
[0138] S404: Perform a query based on the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier.
[0139] Exemplarily, the blockchain performs a query based on the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier.
[0140] Optionally, digital identity information corresponding to each digital identity identifier is pre-stored in the blockchain, so the corresponding digital identity information can be queried based on the digital identity identifier.
[0141] S406: Send the digital identity information to the digital identity system; the digital identity system parses the digital identity information and sends the parsed digital identity information to the client.
[0142] For example, after obtaining the digital identity information corresponding to the digital identity identifier, the blockchain sends the digital identity information to the digital identity system, which parses it and sends it to the client. Because the digital identity information is in a JSON-like format and cannot be accessed, it must be parsed into user-readable fields.
[0143] S408: Receive the parsed decrypted target credential and digital identity identifier sent by the digital identity system for verification, generate a verification result, and send the verification result to the target platform.
[0144] Exemplarily, the blockchain receives the parsed decrypted target credential and the digital identity identifier sent by the digital identity system, and verifies the authenticity and validity of the decrypted target credential based on the digital identity identifier.
[0145] Optionally, the blockchain pre-stores the status of the verifiable credentials (issued, deleted, pending approval, etc.), and the blockchain can verify the decrypted target credentials based on the status of each verifiable credential.
[0146] Optionally, the blockchain can verify the decrypted target credential based on the status of the verifiable credential. For example, if the status of the verifiable credential obtained by querying the digital identity identifier corresponding to the decrypted target credential is deleted, it indicates that the verification fails, and a corresponding verification result is generated and sent to the target platform.
[0147] In the above embodiment, the blockchain provides chain-layer storage services for the client, such as on-chain storage of digital identity information and on-chain storage of proof status, which can ensure the security of digital identity information and the status of verifiable credentials.
[0148] In one exemplary embodiment, in combination Figure 5 As shown, Figure 5 This is a flowchart of a digital identity login method in one embodiment. The specific process is as follows: Steps 1 to 14:
[0149] 1. The Internet platform generates a login QR code, and encapsulates the callback address URL after scanning the code, the Internet platform's DID, the authentication type type, the QR code number UUID and other information in the QR code.
[0150] 2. Scan the QR code on the wallet mini program to obtain relevant information carried by the QR code, such as the callback address URL, Internet platform DID, and QR code number UUID.
[0151] 3. The wallet applet uses the Internet platform did to initiate a request to query the did document from the distributed digital identity system.
[0152] 4. The distributed digital identity system queries the blockchain network for the DID documents related to the Internet platform.
[0153] 5. The blockchain network returns the DID document to the distributed digital identity system.
[0154] 6. The distributed digital identity system parses the did document and returns it to the wallet applet.
[0155] 7. The wallet applet queries the list of certificates required by the Internet platform from the distributed digital identity configuration module based on the DID information. The wallet applet selects the required verifiable credentials for the user to manually select and authorize.
[0156] 8. The wallet applet uses the local private key to sign the selected certificate, encrypts the request message with the public key of the third-party Internet platform, and appends the user's own DID, and transmits it to the third-party Internet platform.
[0157] 9. After receiving the request information, the third-party Internet platform decrypts it using the local private key.
[0158] 10. The third-party internet platform synchronously initiates verification requests for the DID and verifiable claims to the distributed digital identity system until the distributed digital identity returns the verification result. The timeout waiting time can be set to 60 seconds.
[0159] 11. The distributed digital identity system queries DID documents and verifiable claims from the blockchain, parses and verifies the authenticity and validity of DIDs and verifiable claims.
[0160] 12. The distributed digital identity system returns the verification results to the third-party Internet platform.
[0161] 13. After the third-party Internet platform obtains the verification result, it verifies the user's login authority based on the information in the verifiable proof and jumps to the corresponding page based on the user's login authority; otherwise, it directly returns verification failure.
[0162] 14. After verification, a token is generated and a login success message is returned to the wallet applet, otherwise a login failure message is returned.
[0163] In this embodiment, the client is a wallet applet, the target platform is a third-party Internet platform, the digital identity system is a distributed digital identity system, the digital identity identifier is DID, and the digital identity information is a DID document.
[0164] Among them, before the user scans the image code, the digital identity system also includes generating a digital identity for the user. The specific process is as follows: Figure 6 As shown, Figure 6 This is a schematic diagram of the steps before scanning the code to log in in an embodiment.
[0165] (1) The digital identity system creates a distributed digital identity (DID) for the user. The user logs in to the wallet app. After WeChat authorization is successful, an identity is created for the user. After KYC (Know Your Customer, which means fully understanding your customers to confirm whether the customer complies with anti-money laundering laws and anti-terrorist financing regulatory requirements), this process is verified online with the ID card and name, and then the face recognition authentication is passed. Finally, a mnemonic is generated for the user (the form of a private key in plain text, generally used to retrieve the private key). After the user enters a security code (similar to a commonly used transaction password) and records the mnemonic, a distributed digital identity is created.
[0166] (2) The user applies for a login certificate in the Wallet Mini Program's certificate column and submits the relevant application materials to the certificate issuing agency for qualification review.
[0167] (3) The issuing agency logs in to the distributed digital identity background management system and reviews the information submitted by the user. After the qualification review is passed, the local private key is used to sign the applied certificate to generate a verifiable certificate, and the status of the certificate (issued, deleted, pending approval, etc.) is saved in the blockchain. After successful saving, the original certificate information is sent to the platform user.
[0168] (4) When the platform user logs in to the wallet applet and returns to the certificate list, he will see that the login credential he applied for has been successfully authenticated. The specific content includes: certificate name, certificate description, certificate status, certificate validity period, certificate issuer and issuance time, etc.
[0169] In the above embodiment, the digital identity system first creates a distributed digital identity for the user, generates a mnemonic phrase and public and private keys, and stores the public key on-chain. Second, the wallet app scans the QR code, parses the information within, and displays a list of required credentials. The user manually selects and confirms authorization to the internet platform. Furthermore, based on the DID within the QR code, the public key is retrieved from the blockchain and used to encrypt the transmitted message. This login method is relatively simple. Furthermore, with distributed digital identity-based scan-and-login, the user controls the login information themselves. After manual selection and confirmation, the information is submitted to the internet platform for verification, ensuring the security of user information.
[0170] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0171] Based on the same inventive concept, embodiments of the present application also provide a digital identity login device for implementing the aforementioned digital identity login method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more digital identity login device embodiments provided below can be found in the aforementioned limitations of the digital identity login method and will not be further elaborated here.
[0172] In one embodiment, Figure 7As shown, a digital identity login device for a client is provided, comprising: a response module 710, a first sending module 720, a first receiving module 730, a credential sending module 740 and a jump module 750, wherein:
[0173] The response module 710 is used to scan the image code to obtain a digital identity.
[0174] The first sending module 720 is used to send the digital identity identifier to the digital identity system, and the digital identity system obtains the digital identity information from the blockchain based on the digital identity identifier.
[0175] The first receiving module 730 is used to receive the digital identity information sent by the digital identity system, obtain the target certificate based on the digital identity information, and encrypt the target certificate using local encryption information and target encryption information to obtain an encrypted target certificate; the target encryption information is the encryption information of the target platform.
[0176] The credential sending module 740 is used to send the encrypted target credential to the target platform. The target platform is used to verify the permissions of the decrypted target credential after the data identity system and the blockchain successfully verify the decrypted target credential, and generate a jump result after the permission verification; and send the jump result to the client; the decrypted target credential is obtained after the target platform decrypts the encrypted target credential.
[0177] The jump module 750 is used to receive the jump result and jump to the target page according to the jump result.
[0178] In one embodiment, the first receiving module 730 includes:
[0179] The local encryption unit is used to encrypt the target credential using local encryption information to obtain initial authentication information; the local encryption information is a local private key.
[0180] The target encryption unit is used to encrypt the initial authentication information through the target encryption information to obtain the encrypted target certificate; the target encryption information is the public key of the target platform.
[0181] In one embodiment, the first receiving module 730 further includes:
[0182] The credential acquisition unit is used to acquire the initial credential.
[0183] The certificate selection unit is used to obtain a target certificate from the initial certificate according to the digital identity information.
[0184] In one embodiment, Figure 8As shown, the present application provides a digital identity login device applied to a target platform, comprising: a second receiving module 810, a decryption module 820, a second sending module 830, a third receiving module 840 and a third receiving module 840, wherein:
[0185] The second receiving module 810 is configured to receive an encrypted target credential sent by a client; the target credential carries a digital identity.
[0186] The decryption module 820 is used to decrypt the encrypted target certificate to obtain a decrypted target certificate.
[0187] The second sending module 830 is used to send the decrypted target certificate and the digital identity to the data identity system. The data identity system is used to parse the decrypted target certificate and send the parsed decrypted target certificate and the digital identity to the blockchain.
[0188] The third receiving module 840 is used to receive the verification result sent by the blockchain, and the verification result is obtained after the blockchain verifies the decryption target certificate and the digital identity.
[0189] The permission verification module 850 is used to verify the user login permission based on the verification result, and after the user login permission verification is successful, generate a jump result and send the jump result to the client; the jump result is used to instruct the client to jump to the target page.
[0190] In one embodiment, the permission verification module 850 includes:
[0191] The first verification unit is configured to verify the user login authority using the verification information when the verification result is successful.
[0192] The second verification unit is used to generate a jump result after successfully verifying the user's login authority, and send the jump result to the client.
[0193] In one embodiment, the present application provides a digital identity login device applied to a digital identity system, comprising a fourth receiving module, wherein:
[0194] The fourth receiving module is used to receive the decrypted target certificate and digital identity sent by the target platform, parse the decrypted target certificate, and send the parsed decrypted target certificate and digital identity to the blockchain; the blockchain is used to verify the parsed decrypted target certificate and digital identity; the decrypted target certificate is obtained after the target platform decrypts the encrypted target certificate.
[0195] In one embodiment, Figure 9As shown, the present application provides a digital identity login device applied to a blockchain, comprising a fifth receiving module 910, a query module 920, a third sending module 930, and a sixth receiving module 940, wherein:
[0196] The fifth receiving module 910 receives an information query request sent by the digital identity system, where the query request carries the digital identity identifier. The query request is generated by the digital identity system after receiving the digital identity identifier sent by the client.
[0197] The query module 920 is used to query according to the digital identity identifier to obtain the digital identity information corresponding to the digital identity identifier.
[0198] The third sending module 930 is configured to send the digital identity information to the digital identity system; the digital identity system parses the digital identity information and sends the parsed digital identity information to the client.
[0199] The sixth receiving module 940 is configured to receive the parsed decrypted target credential and the digital identity identifier sent by the digital identity system for verification, generate a verification result, and send the verification result to the target platform.
[0200] Each module in the digital identity login device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.
[0201] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 10 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface, the display unit and the input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a digital identity login method is implemented.
[0202] Those skilled in the art will understand that Figure 10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0203] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps of the method in any one of the above embodiments when executing the computer program.
[0204] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method in any one of the above embodiments are implemented.
[0205] In one embodiment, a computer program product is provided, comprising a computer program, which implements the steps of the method in any one of the above embodiments when executed by a processor.
[0206] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0207] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0208] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A digital identity login method, characterized in that: Applied to a client, the method includes: Scan the image code to obtain a digital identity; Sending the digital identity to a digital identity system, and obtaining digital identity information from the blockchain through the digital identity system based on the digital identity; receiving the digital identity information sent by the digital identity system, obtaining a target credential based on the digital identity information, and encrypting the target credential using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is encryption information of the target platform; The encrypted target certificate is sent to the target platform, and the target platform is used to perform permission verification on the decrypted target certificate after the digital identity system and the blockchain successfully verify the decrypted target certificate, and generate a jump result after the permission verification; and send the jump result to the client; the decrypted target certificate is obtained after the target platform decrypts the encrypted target certificate; the target platform decrypts the encrypted target certificate to obtain the decrypted target certificate, and sends the decrypted target certificate and the digital identity to the digital identity system; the digital identity system parses the decrypted target certificate sent by the target platform, and sends the parsed decrypted target certificate and the digital identity to the blockchain; the blockchain verifies the parsed decrypted target certificate and the digital identity sent by the digital identity system, generates a verification result, and sends the verification result to the target platform; Receive the jump result, and jump to the target page according to the jump result.
2. The method according to claim 1, characterized in that The step of encrypting the target credential using the local encryption information and the target encryption information to obtain the encrypted target credential includes: Encrypt the target credential using local encryption information to obtain initial authentication information; the local encryption information is a local private key; The initial authentication information is encrypted by target encryption information to obtain the encrypted target credential; the target encryption information is the public key of the target platform.
3. The method according to claim 1, characterized in that Obtaining a target credential according to the digital identity information includes: Obtaining an initial credential based on the digital identity information query; A selection instruction is received, and the target credential is obtained from the initial credential.
4. A digital identity login method, characterized in that: Applied to the target platform, the method includes: Receive an encrypted target credential sent by a client; the target credential carries a digital identity; Decrypting the encrypted target credential to obtain a decrypted target credential; Sending the decrypted target credential and the digital identity to a digital identity system, wherein the digital identity system is configured to parse the decrypted target credential and send the parsed decrypted target credential and the digital identity to a blockchain; Receiving a verification result sent by the blockchain, the verification result being obtained after the blockchain verifies the decryption target credential and the digital identity; According to the verification result, the user login authority is verified, and after the user login authority verification is successful, a jump result is generated and sent to the client; the jump result is used to instruct the client to jump to the target page.
5. The method according to claim 4, characterized in that The step of verifying the user login authority according to the verification result, generating a jump result after the user login authority verification succeeds, and sending the jump result to the client includes: When the verification result is successful, verifying the user login authority using the verification information; When the user login authority is successfully verified, the jump result is generated and sent to the client.
6. A digital identity login method, characterized in that: Applied to a digital identity system, the method comprises: Receive a digital identity identifier sent by a client, generate an information query request based on the digital identity identifier, and send the information query request to the blockchain; after receiving the information query request, the blockchain performs a query based on the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier, and sends the digital identity information to the digital identity system; The digital identity information is sent to the client; the client obtains a target credential based on the digital identity information, and encrypts the target credential using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is encryption information of the target platform; Receive the decrypted target credential and digital identity sent by the target platform, parse the decrypted target credential, and send the parsed decrypted target credential and digital identity to the blockchain; the blockchain is used to verify the parsed decrypted target credential and digital identity, generate a verification result, and send the verification result to the target platform; the target platform is used to perform permission verification on the decrypted target credential after the digital identity system and the blockchain successfully verify the decrypted target credential, and generate a jump result after the permission verification; and send the jump result to the client; the jump result is used to instruct the client to jump to the target page according to the jump result; the decrypted target credential is obtained by the target platform after decrypting the encrypted target credential sent by the client.
7. A digital identity login method, characterized in that: Applied to blockchain, the method includes: Receiving an information query request sent by a digital identity system, the query request carrying a digital identity identifier; the query request is generated by the digital identity system after receiving the digital identity identifier sent by the client; Perform a query based on the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier; The digital identity information is sent to the digital identity system; the digital identity system parses the digital identity information and sends the parsed digital identity information to the client; the client obtains a target credential based on the digital identity information, and encrypts the target credential using local encryption information and target encryption information to obtain an encrypted target credential, and sends the encrypted target credential to the target platform; the target encryption information is the encryption information of the target platform; the target platform decrypts the encrypted target credential to obtain a decrypted target credential, and sends the decrypted target credential and the digital identity to the digital identity system; the digital identity system parses the decrypted target credential sent by the target platform, and sends the parsed decrypted target credential and the digital identity to the blockchain; The parsed decrypted target credential and the digital identity identifier sent by the digital identity system are received for verification, a verification result is generated, and the verification result is sent to the target platform; the target platform is used to perform permission verification on the decrypted target credential after the digital identity system and the blockchain successfully verify the decrypted target credential, and generate a jump result after the permission verification; and send the jump result to the client; the decrypted target credential is obtained after the target platform decrypts the encrypted target credential; the jump result is used to instruct the client to jump to the target page according to the jump result.
8. A digital identity login device, applied to a client, comprising: The response module is used to scan the image code to obtain a digital identity; A first sending module, configured to send the digital identity identifier to a digital identity system, and obtain digital identity information from the blockchain through the digital identity system based on the digital identity identifier; A first receiving module is configured to receive the digital identity information sent by the digital identity system, obtain a target credential based on the digital identity information, and encrypt the target credential using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is encryption information of a target platform; A credential sending module, configured to send the encrypted target credential to the target platform. The target platform is configured to perform permission verification on the decrypted target credential after the digital identity system and the blockchain successfully verify the decrypted target credential, generate a redirect result after the permission verification, and send the redirect result to the client. The decrypted target credential is obtained by the target platform decrypting the encrypted target credential; the target platform decrypts the encrypted target credential to obtain the decrypted target credential, and sends the decrypted target credential and the digital identity to the digital identity system; the digital identity system parses the decrypted target credential sent by the target platform, and sends the parsed decrypted target credential and the digital identity to the blockchain; the blockchain verifies the parsed decrypted target credential and the digital identity sent by the digital identity system, generates a verification result, and sends the verification result to the target platform; The jump module is used to receive the jump result and jump to the target page according to the jump result.
9. A digital identity login device, applied to a target platform, comprising: A second receiving module is used to receive the encrypted target certificate sent by the client; The target credential carries a digital identity; A decryption module, configured to decrypt the encrypted target credential to obtain a decrypted target credential; A second sending module is used to send the decrypted target credential and the digital identity to a digital identity system, and the digital identity system is used to parse the decrypted target credential and send the parsed decrypted target credential and the digital identity to the blockchain; A third receiving module is configured to receive a verification result sent by the blockchain, where the verification result is obtained after the blockchain verifies the decryption target credential and the digital identity; The permission verification module is used to verify the user login permission according to the verification result, and after the user login permission verification is successful, generate a jump result and send the jump result to the client; The jump result is used to instruct the client to jump to the target page.
10. A digital identity login device, applied to a digital identity system, comprising: a fourth receiving module, configured to receive the decrypted target credential and digital identity sent by the target platform, parse the decrypted target credential, and send the parsed decrypted target credential and digital identity to the blockchain; the blockchain is configured to verify the parsed decrypted target credential and digital identity, generate a verification result, and send the verification result to the target platform; the target platform is configured to perform permission verification on the decrypted target credential after successful verification of the decrypted target credential by the digital identity system and the blockchain, and generate a jump result after the permission verification; And sending the jump result to the client; The jump result is used to instruct the client to jump to the target page according to the jump result; The decrypted target credential is obtained by the target platform decrypting the encrypted target credential sent by the client; The fourth receiving module is further configured to receive a digital identity identifier sent by a client, generate an information query request based on the digital identity identifier, and send the information query request to the blockchain; After receiving the information query request, the blockchain performs a query based on the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier, and sends the digital identity information to the digital identity system; and sends the digital identity information to the client; The client obtains a target credential based on the digital identity information, and encrypts the target credential using local encryption information and target encryption information to obtain an encrypted target credential; the target encryption information is encryption information of the target platform.
11. A digital identity login device, applied to a blockchain, comprising: A fifth receiving module receives an information query request sent by the digital identity system, wherein the query request carries the digital identity identifier; The query request is generated by the digital identity system after receiving the digital identity identifier sent by the client; A query module, configured to query the digital identity identifier to obtain digital identity information corresponding to the digital identity identifier; A third sending module is configured to send the digital identity information to the digital identity system; the digital identity system parses the digital identity information and sends the parsed digital identity information to the client; The client obtains a target credential based on the digital identity information, encrypts the target credential using local encryption information and target encryption information to obtain an encrypted target credential, and sends the encrypted target credential to the target platform; the target encryption information is encryption information of the target platform; the target platform decrypts the encrypted target credential to obtain a decrypted target credential, and sends the decrypted target credential and the digital identity to the digital identity system; the digital identity system parses the decrypted target credential sent by the target platform, and sends the parsed decrypted target credential and the digital identity to the blockchain; a sixth receiving module, configured to receive the parsed decrypted target credential and the digital identity identifier sent by the digital identity system, perform verification, generate a verification result, and send the verification result to the target platform; the target platform is configured to perform permission verification on the decrypted target credential after the digital identity system and the blockchain successfully verify the decrypted target credential, generate a jump result after the permission verification, and send the jump result to the client; The decrypted target credential is obtained by the target platform decrypting the encrypted target credential; The jump result is used to instruct the client to jump to the target page according to the jump result.
12. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 3 or 4 to 5 or 6 or 7 are implemented.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 3 or 4 to 5 or 6 or 7 are implemented.
14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 3 or 4 to 5 or 6 or 7 are implemented.
Citation Information
Patent Citations
Identity authentication method, device and apparatus based on block chain and readable storage medium
CN113297560A