A blockchain-based identity authorization method and device

By binding authorized information stored on the blockchain with the decentralized digital identity of the identity verification provider, a traceable authorization record is generated and encrypted, solving the problem of identity verification abuse in the decentralized digital identity system and realizing traceable identity authorization and privacy protection.

CN116647371BActive Publication Date: 2026-03-31ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-04
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In decentralized digital identity systems, existing technologies struggle to achieve traceable identity authorization, leading to the potential misuse or impersonation of identity verification, and a lack of effective tracking mechanisms.

Method used

By storing authorization information on the blockchain and binding it to the decentralized digital identity of the identity verification provider, a traceable authorization record is generated, and privacy-related data is encrypted to ensure that the authorization record cannot be tampered with.

Benefits of technology

It enables traceable identity authorization in decentralized digital identity scenarios, ensuring that each authorization is traceable, protecting user privacy, and preventing the abuse of identity verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116647371B_ABST
    Figure CN116647371B_ABST
Patent Text Reader

Abstract

The application discloses a kind of identity authorization methods based on blockchain, it is applied to the service end corresponding to the blockchain of centerless digital identity, blockchain member in the blockchain includes identity provider, identity user and identity verification party;The method comprises: receiving any identity user initiates the authorization request of identity authorization to identity verification party;Wherein, the authorization request includes the authorization information related to the traceable identity certificate stored locally, and the decentralized digital identity of identity provider providing the traceable identity certificate;In response to the authorization request, generate authorization record based on the authorization information and the decentralized digital identity of identity provider, and store the authorization record in blockchain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to blockchain technology, and more particularly to a blockchain-based identity authorization method and apparatus. Background Technology

[0002] Decentralized Digital Identity (DID) is a digital identity system based on blockchain technology, which features guaranteed data authenticity and trustworthiness, protection of user privacy and security, and strong portability.

[0003] A DID user can endorse certain identity information of another DID user and generate an identity certificate for that other DID user. The DID user providing the identity certificate can be called the identity certificate provider, while the other DID user can be called the identity certificate user.

[0004] Furthermore, the user of the identity certificate can authorize other DID users to verify the authenticity of their identity with the endorsement of the identity certificate provider. These other DID users whose identity certificates are authorized can be called identity verification parties.

[0005] Since identity verification is backed by the credit of the identity verification provider, a traceable identity authorization scheme is needed to prevent identity verification from being misused or misused. Summary of the Invention

[0006] One of the objectives of this invention is to provide a blockchain-based identity authorization method that enables traceable identity authorization in decentralized digital identities.

[0007] Based on the aforementioned objectives, this invention proposes a blockchain-based identity authorization method, applied to a server-side architecture corresponding to a decentralized digital identity blockchain. The blockchain members include identity verification providers, identity verification users, and identity verification verifiers. The method includes:

[0008] Receive any authorization request initiated by an identity verification user to authorize an identity verification provider; wherein, the authorization request includes authorization information related to locally stored traceable identity verification, and the decentralized digital identity of the identity verification provider that provides the traceable identity verification;

[0009] In response to the authorization request, an authorization record is generated based on the authorization information and the decentralized digital identity of the identity verification provider, and the authorization record is stored in the blockchain.

[0010] In this invention, the authorization record generated by binding the authorization information with the decentralized digital identity of the identity verification provider is stored on the blockchain, so that the identity verification user can trace every time he / she authorizes the identity verification, and the authorization record cannot be tampered with.

[0011] Furthermore, in some embodiments, the identity verification user also locally stores an untraceable identity verification provided by the identity verification provider;

[0012] The traceable and non-traceable identity certificates have the same identity information and are set with a traceability field indicating whether they are traceable;

[0013] Wherein, the field value of the traceability field in the traceable identity certificate is a first field value, and the field value of the traceability field in the untraceable identity certificate is a second field value; the first field value indicates traceability, and the second field value indicates untraceability.

[0014] Furthermore, in some embodiments, the authorization information includes all or part of the identity information in the traceable identity document selected for authorization by the identity document user; wherein, during the process of the identity document user selecting identity information, the identity document requesting authorization is displayed to the identity document user in a visual manner as a traceable identity document.

[0015] Furthermore, in some embodiments, the method further includes:

[0016] Receive a tracing request initiated by any identity verification provider; wherein the tracing request includes the decentralized digital identity of the identity verification provider;

[0017] In response to the traceability request, query the target authorization record with the decentralized digital identity of the identity provider from among all the authorization records stored by the identity proof users in the blockchain;

[0018] The target authorization record is returned to the identity verification provider for their review.

[0019] Furthermore, in some embodiments, the blockchain stores the public key of the identity corresponding to the decentralized digital identity of the identity verification provider;

[0020] The generation of authorization records based on the authorization information and the decentralized digital identity of the identity verification provider includes:

[0021] Retrieve the public key of the identity corresponding to the decentralized digital identity of the identity verification provider from the blockchain;

[0022] The authorization information is encrypted based on the public key of the identity.

[0023] Authorization records are generated based on the encrypted authorization information and the decentralized digital identity of the identity verification provider.

[0024] Furthermore, in some embodiments, returning the target authorization record to the identity verification provider for viewing includes:

[0025] The target authorization record is returned to the identity verification provider, so that the identity verification provider can decrypt the encrypted authorization information in the target authorization record based on the locally stored identity private key.

[0026] Furthermore, in some embodiments, the authorization request includes the decentralized digital identity of the identity verification party, and the blockchain stores the public key corresponding to the decentralized digital identity of the identity verification party; the method further includes:

[0027] In response to the authorization request, retrieve the identity public key corresponding to the decentralized digital identity of the identity verification party from the blockchain;

[0028] The authorization information is encrypted using the public key of the identity, and the encrypted authorization information is sent to the identity verification party; so that the identity verification party can decrypt the encrypted authorization information using the locally stored private key of the identity to obtain the authorization information authorized by the identity user.

[0029] Furthermore, in some embodiments, the server includes a blockchain-as-a-service platform.

[0030] The present invention also provides a blockchain-based identity authorization device, applied to a server corresponding to a decentralized digital identity blockchain, wherein blockchain members include identity verification providers, identity verification users, and identity verification verifiers; the device includes:

[0031] The receiving module receives an authorization request initiated by any identity verification user to authorize an identity verification provider; wherein, the authorization request includes authorization information related to locally stored traceable identity verification, and the decentralized digital identity of the identity verification provider that provides the traceable identity verification;

[0032] The response module, in response to the authorization request, generates an authorization record based on the authorization information and the decentralized digital identity of the identity verification provider, and stores the authorization record in the blockchain.

[0033] The present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the blockchain-based identity authorization methods described above.

[0034] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the blockchain-based identity authorization methods described above.

[0035] The blockchain-based identity authorization method and apparatus described in this invention have the following beneficial effects:

[0036] This invention binds authorization information to the decentralized digital identity of the identity verification provider. On one hand, the authorization records generated based on the bound authorization information and the decentralized digital identity of the identity verification provider are stored on the blockchain, ensuring that every authorization by the identity verification user is traceable and that the authorization records cannot be tampered with. On the other hand, the identity verification provider can query the blockchain to find all authorization records bound to its own decentralized digital identity, and through these records, it can ascertain the authorization status of each issued identity verification document. Thus, traceable identity authorization is achieved in a decentralized digital identity scenario. Attached Figure Description

[0037] Figure 1 A schematic diagram of an identity authorization system under blockchain is shown as an example;

[0038] Figure 2 An exemplary flowchart of the blockchain-based identity authorization method of the present invention is shown;

[0039] Figure 3 An exemplary schematic diagram of the improved blockchain-based identity authorization system of the present invention is shown;

[0040] Figure 4 An example shows in Figure 3 A schematic diagram illustrating encryption and decryption based on the existing technology;

[0041] Figure 5 An exemplary schematic diagram of the blockchain-based identity authorization device described in this invention is shown. Detailed Implementation

[0042] The following detailed description of the blockchain-based identity authorization method and apparatus, computer-readable storage medium, and electronic device of the present invention, in conjunction with the accompanying drawings and specific embodiments, shall not constitute a limitation thereof.

[0043] First, let me introduce some of the technical concepts involved in this invention.

[0044] Decentralized Digital Identity (DID) is a digital identity system based on blockchain technology, which features guaranteed data authenticity and trustworthiness, protection of user privacy and security, and strong portability.

[0045] In implementation, DID typically requires the use of a decentralized public key infrastructure (DPKI). A blockchain based on DPKI can provide the infrastructure for secure services based on cryptographic technology. Specifically, it generates a public-private key pair associated with the DID and encrypts and decrypts the data to be transmitted based on the public-private key pair to ensure the authenticity and trustworthiness of the transmitted data.

[0046] Please refer to the following. Figure 1 The diagram illustrates an identity authorization system based on blockchain technology.

[0047] Based on their roles, blockchain members can be divided into identity verification providers, identity verification users, and identity verification verifiers.

[0048] First, the provider, user, and verifier of identity verification all need to register their own DID in the blockchain.

[0049] Registration here can refer to a blockchain member storing their existing DID on the blockchain, or it can refer to a new blockchain member registering their DID through the blockchain to obtain a DID generated by the blockchain.

[0050] An identity verification provider can endorse certain identity information of an identity verification user and generate an identity verification document for that user.

[0051] Furthermore, users of identity verification can authorize identity verification providers to use the endorsement of the identity verification provider to prove the authenticity of their identity.

[0052] Since identity verification is backed by the credit of the identity verification provider, a traceable identity authorization scheme is needed to prevent identity verification from being misused or misused.

[0053] In one embodiment of the present invention, a blockchain-based identity authorization method is proposed, which can achieve traceable identity authorization.

[0054] Figure 2The flowchart of the blockchain-based identity authorization method described in this invention is illustrated in one implementation, and can be applied to the server corresponding to a decentralized digital identity blockchain.

[0055] Please refer to the following: Figure 3 The diagram illustrates the improved blockchain-based identity authorization system.

[0056] like Figure 3 As shown, an identity authorization system may include a blockchain for implementing decentralized digital identity. Figure 3 The blockchain shown in the figure contains decentralized digital identities registered on their respective blockchain members; the blockchain members may include identity proof providers, identity proof users, and identity proof verifiers.

[0057] Authorization records used for traceability by the identity verification provider can be stored on a blockchain containing authorization records. This blockchain can be the same as the DID blockchain, or it can be a different blockchain.

[0058] When belonging to the same blockchain, the authorization record of the generated identity certificate user can be directly stored in the DID blockchain.

[0059] If they do not belong to the same blockchain, then the authorization record of the generated identity certificate user needs to be stored separately on another blockchain (e.g., Figure 3 The aforementioned server needs to be connected to both the DID blockchain and the authorization record blockchain.

[0060] In some embodiments, the server (not shown in the figure) may be located between the identity verification provider, the identity verification user, and the identity verification verifier, since the identity verification provider, the identity verification user, and the identity verification verifier can interact with the blockchain through the server.

[0061] In some embodiments, the server may include a Blockchain as a Service (BaaS) platform. This BaaS platform, often referred to as a BaaS cloud, provides pre-written software for activities occurring on the blockchain (such as subscriptions and notifications, user authentication, database management, and remote updates). It offers easy-to-use, one-click deployment, rapid verification, and flexible customizable blockchain services, such as query services, verification services, registration services, and evidence storage services, to identity providers, users, and verifiers connected to the BaaS platform.

[0062] Back Figure 2 The aforementioned blockchain-based identity authorization method may include the following steps:

[0063] 210: Receive an authorization request initiated by any identity verification user to authorize the identity verification party; wherein the authorization request includes authorization information related to locally stored traceable identity verification, and the decentralized digital identity of the identity verification provider that provides the traceable identity verification.

[0064] In this invention, the identity verification provider can generate an identity verification certificate for the identity verification user, send the generated identity verification certificate to the identity verification user, and store it locally on the identity verification user's device.

[0065] The identity verification can be represented as an endorsement by the identity verification provider of certain identity information of the identity verification user. The identity verification may include, for example, verifiable claims (or verifiable credentials, VCs). In addition to the endorsed identity information, the verifiable credential may also include the identity verification provider's digital signature.

[0066] In some embodiments, the identity verification user also locally stores an untraceable identity verification provided by the identity verification provider;

[0067] The traceable and non-traceable identity certificates have the same identity information and are set with a traceability field indicating whether they are traceable;

[0068] Wherein, the field value of the traceability field in the traceable identity certificate is a first field value, and the field value of the traceability field in the untraceable identity certificate is a second field value; the first field value indicates traceability, and the second field value indicates untraceability.

[0069] The following is an illustration using the VC example shown in Table 1:

[0070]

[0071] Table 1

[0072] The identity verification provider with DID issuer0001 generates and sends two VCs to the identity verification user with DID user0001. A traceability field, `trace`, is added to these two VCs to define whether the current VC can be traced.

[0073] When the field value is the first field value (e.g., 1 in Table 1), it means the VC is traceable; when the field value is the second field value (e.g., 0 in Table 1), it means the VC is not traceable. Generally, by default, the VC can be untraceable.

[0074] In some embodiments, the authorization information includes all or part of the identity information in the traceable identity document selected for authorization by the identity document user; wherein, during the process of the identity document user selecting identity information, the identity document requesting authorization is displayed to the identity document user in a visual manner as a traceable identity document.

[0075] In this invention, since the identity certificate may include several different pieces of identity information (such as name, ID number, date of birth, etc.), it may not be necessary to authorize all of the identity information in practical applications. Therefore, the client interface of the identity certificate user can display interactive options for the user to select which identity information to authorize. In this way, the authorization information carried in the authorization request can be the identity information selected by the user.

[0076] Additionally, as shown above, the identity verification user can store two VCs locally, so the client interface can also display interactive options for the user to choose which identity verification to authorize.

[0077] If the user selects non-traceable identity verification, the subsequent process will follow the aforementioned steps. Figure 1 The process shown in the diagram is carried out in a way that the identity verification provider will not be able to trace this authorization.

[0078] If the user selects traceable identity verification, the subsequent process will proceed as follows: Figure 2 The process shown proceeds, i.e., subsequent step 220 is executed. In this way, the identity verification provider can trace back to this authorization.

[0079] It should be noted that when a user selects a traceable identity document, the identity document being authorized can be visually prompted to the identity document user that it is a traceable identity document. For example, the client interface of the identity document user could display the message "This authorization process will be recorded and can be traced."

[0080] 220: In response to the authorization request, an authorization record is generated based on the authorization information and the decentralized digital identity of the identity verification provider, and the authorization record is stored in the blockchain.

[0081] In this invention, by binding authorization information with the decentralized digital identity of the identity verification provider, the authorization record generated based on the bound authorization information and the decentralized digital identity of the identity verification provider is stored on the blockchain, so that the identity verification user can trace the authorization every time they authorize the identity verification, and the authorization record cannot be tampered with.

[0082] Please refer to the authorization information shown in Table 2 below:

[0083]

[0084] Table 2

[0085] In this invention, the authorization information may include, in addition to the identity information in the traceable identity certificate selected for authorization by the identity certificate user ("name, ID number, date of birth" in Table 2), the decentralized digital identity of the identity certificate user ("User0001" in Table 2), the identifier of the identity certificate ("Vc001" in Table 2), the decentralized digital identity of the identity certificate verifier ("Sp001" in Table 2), and the authorization time ("2022-12-04 18:00:00" in Table 2).

[0086] Furthermore, the authorization information in Table 2 above, together with the decentralized digital identity of the identity verification provider, will be stored in the blockchain as an authorization record.

[0087] In some embodiments, the method further includes:

[0088] Receive a tracing request initiated by any identity verification provider; wherein the tracing request includes the decentralized digital identity of the identity verification provider;

[0089] In response to the traceability request, query the target authorization record with the decentralized digital identity of the identity provider from among all the authorization records stored by the identity proof users in the blockchain;

[0090] The target authorization record is returned to the identity verification provider for their review.

[0091] In this invention, the identity verification provider can initiate a traceability request to the server to query all target authorization records containing its own decentralized digital identity stored in the blockchain; and then obtain the authorization information in each target authorization record.

[0092] For different users of identity certificates issued by the same identity certificate provider, since each authorization record generated for a traceable identity certificate authorization contains the same identity certificate provider's DID;

[0093] Therefore, the identity verification provider can simultaneously obtain the authorization records stored by each of these different identity verification users.

[0094] Through the above embodiments, the identity verification provider can query the blockchain to find all authorization records bound to its own decentralized digital identity. These authorization records allow it to ascertain the authorization status of each issued identity verification document. This achieves traceable identity authorization in a decentralized digital identity scenario.

[0095] In some embodiments, the blockchain stores the public key of the identity corresponding to the decentralized digital identity of the identity proof provider;

[0096] The generation of authorization records based on the authorization information and the decentralized digital identity of the identity verification provider includes:

[0097] Retrieve the public key of the identity corresponding to the decentralized digital identity of the identity verification provider from the blockchain;

[0098] The authorization information is encrypted based on the public key of the identity.

[0099] Authorization records are generated based on the encrypted authorization information and the decentralized digital identity of the identity verification provider.

[0100] In practical applications, since everyone can access the data stored on the blockchain, including the aforementioned authorization records, and this authorization information involves user privacy; given the increasing concern for personal privacy, this invention can encrypt the authorization information before storing it on the blockchain. The specific encryption process is as follows:

[0101] In this invention, the identity proof provider, the identity proof user, and the identity proof verifier can all store their own DID-related identity public key in the blockchain, while the identity private key corresponding to the identity public key is stored locally by the blockchain members.

[0102] The following is combined Figure 4 As shown in Figure 3 Add encryption / decryption diagrams to the existing structure. For example... Figure 4 The public key of the identity provider (pubkey1), the public key of the identity user (pubkey2), and the public key of the identity verifier (pubkey3) can all be stored on the blockchain, while the private key of the identity provider (prikey1), the private key of the identity user (prikey2), and the private key of the identity verifier (prikey3) are stored locally by each party.

[0103] The server or the user of the identity certificate can query the identity public key pubkey1 corresponding to the identity certificate provider's DID from the blockchain; and encrypt the authorization information based on the identity public key pubkey1. Then, based on the encrypted authorization information and the identity certificate provider's DID, an authorization record is generated and stored on the blockchain.

[0104] Through the above embodiments, because the authorization information stored on the blockchain is encrypted, other third parties can only know that a user (i.e., the user of the identity certificate) has authorized the identity certificate, but they do not know which user, to whom the authorization was granted, or what content was authorized. Therefore, user privacy can be well protected.

[0105] Furthermore, in some embodiments, returning the target authorization record to the identity verification provider for viewing includes:

[0106] The target authorization record is returned to the identity verification provider, so that the identity verification provider can decrypt the encrypted authorization information in the target authorization record based on the locally stored identity private key.

[0107] As mentioned earlier, since the authorization information stored on the blockchain is encrypted, the identity verification provider needs to decrypt the authorization information in the target authorization record. Specifically, because the authorization information in the target authorization record is encrypted using the identity verification provider's public key, only the identity verification provider holding the private key corresponding to that public key can decrypt it and obtain all the decrypted authorization information.

[0108] Continue to combine Figure 4 After the identity verification provider finds the target authorization record associated with its own DID, it can use the locally stored identity private key prikey1 to decrypt the encrypted authorization information in each target authorization record.

[0109] Assuming the authorization information obtained through decryption is as shown in Table 2 above, the identity certificate provider can trace back to the identity certificate "Vc001" issued to the user with DID "User0001" through the above embodiment. It was then authorized to the user with DID "Sp001" at "2022-12-04 18:00:00", and the authorized content is "name, ID number, date of birth".

[0110] The above embodiments ensure that only the identity provider offering the authorized identity certificate can decrypt the encrypted authorization information. After decryption, detailed authorization information is obtained, which the identity provider can analyze to identify potential identity certificate abuse, impersonation, or other risky behaviors.

[0111] In some embodiments, the authorization request includes a decentralized digital identity of the identity verification party, and the blockchain stores a public key corresponding to the decentralized digital identity of the identity verification party; the method further includes:

[0112] In response to the authorization request, retrieve the identity public key corresponding to the decentralized digital identity of the identity verification party from the blockchain;

[0113] The authorization information is encrypted using the public key of the identity, and the encrypted authorization information is sent to the identity verification party; so that the identity verification party can decrypt the encrypted authorization information using the locally stored private key of the identity to obtain the authorization information authorized by the identity user.

[0114] In this invention, since the authorization is granted to the identity verification party, the authorization information needs to be sent to the identity verification party.

[0115] Similar to the aforementioned on-chain storage of authorization records, the authorization information involving privacy data also needs to be encrypted. The difference is that here, the encryption is performed using the identity verification party's public key. Correspondingly, after receiving the authorization information, the identity verification party also needs to decrypt it using its locally stored identity private key to obtain detailed authorization information.

[0116] Continue to refer to Figure 4 For example, the server or the user of the identity verification can query the public key pubkey3 corresponding to the identity verification party's DID from the blockchain; encrypt the authorization information based on the public key pubkey3, and then send the encrypted authorization information to the identity verification party. Further, the identity verification party uses its locally stored private key prikey3 to decrypt the encrypted authorization information.

[0117] Through the above embodiments, by encrypting the authorization information, the privacy of the identity verification user can be well protected, and it can be ensured that the identity verification party can decrypt and obtain detailed authorization information; thereby realizing the identity authorization process.

[0118] It should be noted that the above Figure 4 In the example, the public and private keys of the identity verification user are not used because they are not needed when acting as an identity verification user. In reality, the roles of identity verification provider, identity verification user, and identity verification party can change. Figure 4 When a blockchain member corresponding to the private key prikey2 acts as an identity proof provider or identity proof verifier, they will use the private key prikey2 and the public key pubkey2.

[0119] Corresponding to the aforementioned blockchain-based identity authorization method embodiments, the present invention also provides embodiments of blockchain-based identity authorization devices.

[0120] Please see Figure 5 This is a block diagram of a blockchain-based identity authorization device according to the present invention. The device corresponds to... Figure 2 The illustrated embodiment shows that the device can be applied to the server side of a decentralized digital identity blockchain, where blockchain members include identity verification providers, identity verification users, and identity verification verifiers; the device includes:

[0121] The receiving module 410 is configured to receive an authorization request initiated by any identity verification user to authorize the identity verification party; wherein, the authorization request includes authorization information related to locally stored traceable identity verification, and the decentralized digital identity of the identity verification provider that provides the traceable identity verification.

[0122] The response module 420 is used to respond to the authorization request, generate an authorization record based on the authorization information and the decentralized digital identity of the identity verification provider, and store the authorization record in the blockchain.

[0123] Furthermore, in some embodiments, the identity verification user also locally stores an untraceable identity verification provided by the identity verification provider;

[0124] The traceable and non-traceable identity certificates have the same identity information and are set with a traceability field indicating whether they are traceable;

[0125] Wherein, the field value of the traceability field in the traceable identity certificate is a first field value, and the field value of the traceability field in the untraceable identity certificate is a second field value; the first field value indicates traceability, and the second field value indicates untraceability.

[0126] Furthermore, in some embodiments, the authorization information includes all or part of the identity information in the traceable identity document selected for authorization by the identity document user; wherein, during the process of the identity document user selecting identity information, the identity document requesting authorization is displayed to the identity document user in a visual manner as a traceable identity document.

[0127] Furthermore, in some embodiments, the apparatus further includes:

[0128] The tracing module is used to receive a tracing request initiated by any identity verification provider; wherein the tracing request includes the decentralized digital identity of the identity verification provider;

[0129] The traceability response module is used to respond to the traceability request by querying the target authorization record with the decentralized digital identity of the identity provider from among all the authorization records stored by identity proof users in the blockchain; and returning the target authorization record to the identity proof provider for the identity proof provider to view.

[0130] Furthermore, in some embodiments, the blockchain stores the public key of the identity corresponding to the decentralized digital identity of the identity verification provider;

[0131] The response module 420 is further configured to query the public key of the identity corresponding to the decentralized digital identity of the identity provider from the blockchain; encrypt the authorization information based on the public key; and generate an authorization record based on the encrypted authorization information and the decentralized digital identity of the identity provider.

[0132] Furthermore, in some embodiments, the traceability response module is further configured to return the target authorization record to the identity verification provider, so that the identity verification provider can decrypt the encrypted authorization information in the target authorization record based on the locally stored identity private key.

[0133] Furthermore, in some embodiments, the authorization request includes the decentralized digital identity of the identity verification party, and the blockchain stores the identity public key corresponding to the decentralized digital identity of the identity verification party.

[0134] The response module 420 is further configured to respond to the authorization request by querying the public key of the identity corresponding to the decentralized digital identity of the identity verification party from the blockchain; encrypting the authorization information based on the public key of the identity, and sending the encrypted authorization information to the identity verification party; so that the identity verification party can decrypt the encrypted authorization information based on the locally stored private key of the identity to obtain the authorization information authorized by the identity verification user.

[0135] Furthermore, in some embodiments, the server includes a blockchain-as-a-service platform.

[0136] The specific implementation process of the functions and roles of each module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0137] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the present invention according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0138] Based on the described internal functional modules and structural diagram of the blockchain-based identity authorization device, its essential execution entity can be an electronic device, including:

[0139] processor;

[0140] Memory used to store processor-executable instructions;

[0141] The processor is configured to execute any of the above-described blockchain-based identity authorization methods.

[0142] In the embodiments of the above-described electronic device, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor, and the aforementioned memory can be read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or solid-state drive. The steps of the method disclosed in the embodiments of this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.

[0143] In addition, the present invention also provides a computer-readable storage medium, wherein the instructions in the computer-readable storage medium, when executed by a processor of an electronic device, enable the electronic device to perform any of the above-described embodiments of the blockchain-based identity authorization method.

[0144] It should be noted that the above examples are merely specific embodiments of the present invention, and the present invention is obviously not limited to the above embodiments, with many similar variations. All modifications that can be directly derived or conceived by those skilled in the art from the content disclosed in this invention should fall within the protection scope of this invention.

Claims

1.A blockchain-based identity authorization method applied to a server corresponding to a blockchain of a decentralized digital identity, wherein blockchain members in the blockchain include identity certificate providers, identity certificate users and identity certificate verifiers; the method comprises: receiving an authorization request initiated by any identity certificate user to an identity certificate verifier for identity authorization, wherein the authorization request comprises authorization information related to a locally-stored traceable identity certificate and a decentralized digital identity of an identity certificate provider providing the traceable identity certificate; in response to the authorization request, generating an authorization record based on the authorization information and the decentralized digital identity of the identity certificate provider, and notarizing the authorization record in the blockchain; receiving a trace request initiated by any identity certificate provider, wherein the trace request comprises the decentralized digital identity of the identity certificate provider; in response to the trace request, querying a target authorization record having the decentralized digital identity of the identity certificate provider from authorization records notarized by all identity certificate users in the blockchain; returning the target authorization record to the identity certificate provider for viewing by the identity certificate provider. 2.The blockchain-based identity authorization method of claim 1, wherein the identity certificate user also locally stores a non-traceable identity certificate provided by the identity certificate provider; the traceable identity certificate and the non-traceable identity certificate have the same identity information, and a trace field indicating whether traceable is set; wherein a field value of the trace field in the traceable identity certificate is a first field value, and a field value of the trace field in the non-traceable identity certificate is a second field value; the first field value indicates traceable, and the second field value indicates non-traceable. 3.The blockchain-based identity authorization method of claim 2, wherein the authorization information comprises identity information of all or part of the traceable identity proofs selected for authorization by the identity proof user; and During selection of identity information by the identity certificate user, the identity certificate user is visually shown that the identity certificate requested for authorization is a traceable identity certificate. 4.The blockchain-based identity authorization method of claim 1, wherein an identity public key corresponding to the decentralized digital identity of the identity certificate provider is notarized in the blockchain; the generation of the authorization record based on the authorization information and the decentralized digital identity of the identity certificate provider comprises: querying the identity public key corresponding to the decentralized digital identity of the identity certificate provider from the blockchain; encrypting the authorization information based on the identity public key; generating the authorization record based on the encrypted authorization information and the decentralized digital identity of the identity certificate provider. 5.The blockchain-based identity authorization method of claim 4, wherein the returning of the target authorization record to the identity certificate provider for viewing by the identity certificate provider comprises: returning the target authorization record to the identity certificate provider to enable the identity certificate provider to decrypt the encrypted authorization information in the target authorization record based on a locally-stored identity private key. 6.The blockchain-based identity authorization method of claim 1, wherein the authorization request comprises a decentralized digital identity of an identity proof verifier, and an identity public key corresponding to the decentralized digital identity of the identity proof verifier is stored in the blockchain. The method further comprises: query, from a blockchain, an identity public key corresponding to a decentralized digital identity of the identity proof verifier, in response to the authorization request; encrypt the authorization information based on the identity public key, and send the encrypted authorization information to the identity proof verifier, so that the identity proof verifier decrypts the encrypted authorization information based on a locally stored identity private key to obtain the authorization information authorized by the identity proof user. 7.The blockchain-based identity authorization method of claim 1, wherein the service end comprises a blockchain-as-a-service platform. 8.A blockchain-based identity authorization apparatus, applied to a service end corresponding to a blockchain of a decentralized digital identity, wherein blockchain members in the blockchain comprise an identity proof provider, an identity proof user, and an identity proof verifier; and the apparatus comprises: a receiving module configured to receive an authorization request initiated by any identity proof user to an identity proof verifier for identity authorization, wherein the authorization request comprises authorization information related to a locally stored traceable identity proof, and a decentralized digital identity of an identity proof provider providing the traceable identity proof; a responding module configured to, in response to the authorization request, generate an authorization record based on the authorization information and the decentralized digital identity of the identity proof provider, and store the authorization record in the blockchain; the responding module is further configured to receive a trace request initiated by any identity proof provider, wherein the trace request comprises the decentralized digital identity of the identity proof provider; in response to the trace request, query a target authorization record having the decentralized digital identity of the identity proof provider from authorization records stored by all identity proof users in the blockchain, and return the target authorization record to the identity proof provider for viewing by the identity proof provider. 9.A computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program, when executed by a processor, implements the method of any one of claims 1-7. 10.An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method of any one of claims 1-7 when executing the program.

Citation Information

Patent Citations

  • Data authorization method and system based on DID and medium

    CN115208886A