Data processing method, apparatus and device, medium, product

CN117176354BActive Publication Date: 2026-09-22TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210598416.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-27
Publication Date
2026-09-22
Estimated Expiration
2042-05-27

AI Technical Summary

Technical Problem

[0003]身份验证场景中,当对象需使用某个服务时,通常情况下需要对象手动进行身份验证,例如输入手机号进行短信验证,又如填写账号、密码进行验证等等,这种方式费时费力

Benefits of technology

[0053]本申请实施例中,首先,可以获取针对目标对象的身份验证请求,从身份验证请求中获取验证数据,该验证数据是基于数字藏品协议生成的。然后,可以对验证数据进行解析,得到对象身份验证凭证,并对对象身份验证凭证进行验证。最后,若对该对象身份验证凭证验证通过,则生成验证通过指示信息。由此可见,当目标对象需要进行身份验证时,可以通过发送一个身份验证请求,并从该身份验证请求中获取对象身份验证凭证,即可对目标对象进行身份验证,相比于对象手动进行身份验证而言,本申请的身份验证方式更加简洁方便,从而提高身份验证的效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117176354B_ABST
    Figure CN117176354B_ABST
Patent Text Reader

Abstract

The application provides a data processing method, device and equipment, medium and product. The method comprises the following steps: obtaining an identity verification request for a target object, obtaining verification data from the identity verification request, wherein the verification data is generated based on a digital collectible protocol; analyzing the verification data to obtain an object identity verification credential, and verifying the object identity verification credential; and if the object identity verification credential is verified, generating verification pass indication information. The application can perform identity verification based on the object identity registration credential generated by the digital collectible protocol, thereby improving the efficiency and reliability of identity verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technology, and in particular to a data processing method, a data processing device, a computer device, a computer-readable storage medium, and a computer program product. Background Technology

[0002] In blockchain, the confirmation and transfer of ownership of off-chain assets is a hot research topic in the current blockchain field. Confirmation of off-chain asset ownership refers to verifying the identity of the person who owns the asset, a process that typically involves identity verification.

[0003] In identity verification scenarios, when an object needs to use a service, it typically requires manual authentication, such as entering a mobile phone number for SMS verification or filling in an account and password. This method is time-consuming and labor-intensive. Therefore, improving the efficiency of identity verification is a pressing technical problem that needs to be solved. Summary of the Invention

[0004] This application proposes a data processing method, apparatus, device, medium, and product that can perform identity verification based on the object identity registration certificate generated by the digital collection protocol, thereby improving the efficiency of identity verification.

[0005] On one hand, embodiments of this application provide a data processing method, the method comprising:

[0006] Obtain the authentication request for the target object, and retrieve the verification data from the authentication request. The verification data is generated based on the digital collection protocol.

[0007] The verification data is parsed to obtain the object authentication credentials, and the object authentication credentials are then verified.

[0008] If the object authentication credentials are successfully verified, a verification success indication message is generated.

[0009] On one hand, embodiments of this application provide a data processing method, the method comprising:

[0010] Obtain the identity registration request submitted by the target object, which carries the identity information of the target object;

[0011] The identity information of the target object is verified. If the verification is successful, an object identity registration certificate for the target object is generated based on the digital collection protocol.

[0012] The object identity registration credential of the target object is sent to the computer device so that the computer device can verify the object identity verification credential. If the object identity verification credential is successfully verified, a verification success indication message is generated.

[0013] Among them, object authentication credentials are obtained by parsing authentication data, which is obtained by the computer device from the authentication request after receiving the authentication request for the target object.

[0014] On one hand, embodiments of this application provide a data processing apparatus, the apparatus comprising:

[0015] The acquisition unit is used to acquire an authentication request for a target object and to acquire verification data from the authentication request, wherein the verification data is generated based on the digital collection protocol;

[0016] The processing unit is used to parse the verification data to obtain the object authentication credential and to verify the object authentication credential.

[0017] The processing unit is further configured to generate a verification success indication message if the object authentication credential is successfully verified.

[0018] In one possible implementation, before the acquisition unit acquires the authentication request for the target object, the processing unit is also used to perform the following operations:

[0019] Get the real-name authentication success notification message sent by the real-name server for the target object. The real-name authentication success notification message is generated by the real-name server after receiving the identity information submitted by the target object and calling the identity authentication platform interface to perform real-name authentication on the target object's identity information.

[0020] Associate the target object with the object identity registration credential generated for the target object;

[0021] Real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

[0022] In one possible implementation, the processing unit associates the target object with the object identity registration credential generated for the target object, for the following operations:

[0023] Receive an address registration request sent by the real-name server, the address registration request carrying the blockchain address of the target object;

[0024] Respond to the address registration request and obtain the object identity registration certificate generated by the identity service system for the target object based on the digital collection protocol;

[0025] Associate the object's identity registration certificate with the target object's blockchain address.

[0026] In one possible implementation, the processing unit verifies the object authentication credentials to perform the following operations:

[0027] Obtain the object identity registration certificate of the target object. The object identity registration certificate is generated by the identity service system based on the digital collection protocol after the identity information submitted by the target object to the identity service system is verified.

[0028] The object authentication credentials are verified based on the object's object identity registration credentials.

[0029] In one possible implementation, the verification data is obtained by signing the object authentication credential using the private key of the target object;

[0030] The processing unit parses the verification data to obtain object authentication credentials, which are used to perform the following operations:

[0031] The public key of the target object is used to verify the signature of the verification data. If the signature verification is successful, the object identity verification credential of the target object is obtained based on the digital collection protocol.

[0032] In one possible implementation, the authentication request is used to request login to an identity service system or at least one business service system, wherein any one of the at least one business service system refers to a system that has performed a trust endorsement operation on the identity information of the target object.

[0033] In one possible implementation, the processing unit is also used to perform the following operations:

[0034] Receive data acquisition requests submitted by the target business system. The data acquisition requests are used to request the acquisition of the identity information of the target object. The target business system includes an identity service system and at least one business service system.

[0035] Send a data retrieval request to the real-name server;

[0036] Receive the identity information of the target object sent by the real-name server, and send the identity information of the target object to the target business system;

[0037] The identity information of the target object is obtained by the real-name server after receiving the authorization success notification message returned by the target object.

[0038] On one hand, embodiments of this application provide a data processing apparatus, the apparatus comprising:

[0039] The acquisition unit is used to acquire the identity registration request submitted by the target object, which carries the identity information of the target object.

[0040] The processing unit is used to verify the identity information of the target object. If the verification is successful, it generates an object identity registration certificate for the target object based on the digital collection protocol.

[0041] The sending unit is used to send the object identity registration credential of the target object to the computer device so that the computer device can verify the object identity verification credential. If the object identity verification credential is verified successfully, a verification success indication message is generated.

[0042] Among them, object authentication credentials are obtained by parsing authentication data, which is obtained by the computer device from the authentication request after receiving the authentication request for the target object.

[0043] In one possible implementation, after the acquisition unit obtains the identity registration request submitted by the target object, the processing unit is further configured to perform the following operations:

[0044] The identity information of the target object is sent to the real-name server, so that the real-name server calls the identity authentication platform interface to perform real-name authentication on the identity information of the target object and generates a real-name authentication success notification message. The real-name authentication success notification message is then sent to the computer device, so that the computer device associates the target object with the object identity registration certificate generated for the target object.

[0045] Real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

[0046] In one possible implementation, the processing unit is also used to perform the following operations:

[0047] Generate a data retrieval request, which is used to request the identity information of the target object;

[0048] Sending a data acquisition request to the computer device causes the computer device to send the data acquisition request to the real-name server;

[0049] Receive the identity information of the target object sent by the computer device.

[0050] On one hand, embodiments of this application provide a computer device, which includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor performs the data processing method described above.

[0051] On one hand, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when read and executed by a processor of a computer device, causes the computer device to perform the aforementioned data processing method.

[0052] On one hand, embodiments of this application provide a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the aforementioned data processing method.

[0053] In this embodiment, firstly, an authentication request for the target object can be obtained, and verification data, generated based on the digital collection protocol, can be retrieved from the authentication request. Then, the verification data can be parsed to obtain the object authentication credential, and the object authentication credential can be verified. Finally, if the object authentication credential is successfully verified, a verification success indication message is generated. Therefore, when a target object needs to be authenticated, it can be authenticated by sending an authentication request and obtaining the object authentication credential from that request. Compared to manual object authentication, the authentication method of this application is simpler and more convenient, thereby improving the efficiency of authentication. Attached Figure Description

[0054] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those with ordinary technical skills in the art, other drawings can be obtained based on these drawings without creative effort.

[0055] Figure 1a This is a schematic diagram of the structure of a blockchain system provided in an embodiment of this application;

[0056] Figure 1b This is a schematic diagram of a blockchain structure provided in an embodiment of this application;

[0057] Figure 1c This is a schematic diagram of a standard protocol in a blockchain provided in an embodiment of this application;

[0058] Figure 2 This is a schematic diagram of the architecture of a data processing system provided in an embodiment of this application;

[0059] Figure 3 This is a flowchart illustrating a data processing method provided in an embodiment of this application;

[0060] Figure 4 This is a schematic diagram of a data acquisition scenario provided in an embodiment of this application;

[0061] Figure 5 This is a flowchart illustrating another data processing method provided in an embodiment of this application;

[0062] Figure 6 This is an interactive flowchart of a data processing method provided in an embodiment of this application;

[0063] Figure 7 This is a schematic diagram of another data acquisition scenario provided in an embodiment of this application;

[0064] Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;

[0065] Figure 9 This is a schematic diagram of another data processing device provided in an embodiment of this application;

[0066] Figure 10 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0067] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application.

[0068] This application proposes a data processing scheme, primarily relying on the TrustSQL open chain (an underlying platform providing basic blockchain services for upper-layer application scenarios) and the asset issuance platform of the Digital Collections Protocol. The general principle of this data processing scheme is as follows: First, an authentication request for the target object can be obtained, and verification data can be retrieved from the authentication request. This verification data is generated based on the Digital Collections Protocol (e.g., the ERC-721 (Etherum Request for Comments 721, a protocol proposal numbered 721 for warrant submissions) standard protocol and the ERC-1155 (Etherum Request for Comments 1155, a protocol proposal numbered 1155 for warrant submissions) standard protocol). Then, the verification data can be parsed to obtain the object authentication credential, and the object authentication credential can be verified. Finally, if the object authentication credential is successfully verified, a verification success indication message is generated.

[0069] Therefore, when the target object needs to be authenticated, it can be authenticated by sending an authentication request and obtaining the object authentication credentials from the authentication request. Compared with manually authenticating the object, the authentication method of this application is simpler and more convenient, thereby improving the efficiency of authentication.

[0070] The data processing solution in this application can be combined with blockchain technology. The following section provides a detailed introduction to the blockchain technology involved in the data processing solution provided in this application:

[0071] The blockchain system involved in this application embodiment can be a distributed system formed by connecting clients and multiple nodes (any form of computing device accessing the network, such as servers and terminal devices) through network communication. The following is a reference to the appendix... Figure 1a -Appendix Figure 1c This section provides an introduction to blockchain-related technologies.

[0072] I. Blockchain System:

[0073] Please see Figure 1a , Figure 1a This is a schematic diagram of the structure of a blockchain system provided in an embodiment of this application. Figure 1a The blockchain system shown can be a data sharing system 100, which refers to a system for data sharing between nodes. This data sharing system 100 can include multiple nodes 101, which can refer to various clients within the data sharing system. Each node 101, during normal operation, can receive input information (e.g., any node 101 can receive an identity registration request submitted by a target object to a first business service system; or, any node 101 can receive a data acquisition request submitted by a target business service system, etc.), and maintains the shared data within the data sharing system based on the received input information. To ensure information interoperability within the data sharing system, information connections can exist between each node, allowing for information transmission between nodes. For example, when any node in the data sharing system receives input information, other nodes in the system obtain this input information according to a consensus algorithm and store it as data in the shared data, ensuring consistency of data stored on all nodes in the data sharing system.

[0074] Each node in the data sharing system has a corresponding node identifier, and each node can also store the node identifiers of other nodes in the data sharing system. This allows for the subsequent broadcasting of generated blocks to other nodes in the data sharing system based on their node identifiers. Each node can maintain a node identifier list as shown in the table below, storing the node name and node identifier in this list. The node identifier can be an IP (Internet Protocol) address or any other information that can be used to identify the node. Table 1 only uses IP addresses as an example.

[0075] Table 1. Node Identifier List

[0076] Node 1 000.000.000.000 Node 2 111.111.111.111 … … Node N xx.xx.xx.xx

[0077] II. The Structure of Blockchain:

[0078] Each node in the data-sharing system stores the same blockchain. A blockchain consists of multiple blocks; see [link to blockchain documentation]. Figure 1b , Figure 1b This is a schematic diagram of a blockchain structure provided in an embodiment of this application. For example... Figure 1b The blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores input information feature values, version number, timestamp, and difficulty value, while the block body stores the input information. The next block after the genesis block takes the genesis block as its parent block. The next block also includes a block header and a block body. The block header stores the input information feature values ​​of the current block, the block header feature values ​​of the parent block, version number, timestamp, and difficulty value, and so on. This ensures that the block data stored in each block of the blockchain is associated with the block data stored in the parent block, guaranteeing the security of the input information in the blocks.

[0079] In one possible implementation, this application can upload the target object's identity information, object authentication credentials, object identity registration credentials, etc., to the blockchain of the blockchain network for storage, so as to prevent the internal data of computer devices (such as blockchain nodes) from being tampered with, thereby improving the security and reliability of the data.

[0080] III. Intelligent Transportation Systems:

[0081] Intelligent Traffic Systems (ITS), also known as Intelligent Transportation Systems, effectively integrate advanced science and technology (information technology, computer technology, data communication technology, sensor technology, electronic control technology, automatic control theory, operations research, artificial intelligence, etc.) into transportation, service control, and vehicle manufacturing. This strengthens the connection between vehicles, roads, and users, thereby forming a comprehensive transportation system that ensures safety, improves efficiency, enhances the environment, and saves energy.

[0082] In one possible implementation, the solution provided in this application can be applied to the transportation field. For example, if city A and city B are located in the same province, then based on the method provided in this application, if the target object completes identity registration in the first business service system (e.g., traffic management platform 1 where city A is located), it can obtain a designated identity registration credential assigned by the first business service system. Subsequently, based on this identity registration credential, it can simultaneously log in to both the first and second business service systems (e.g., traffic management platform 2 where city B is located). In this way, the target object's identity information does not need to be fully registered on the traffic management platforms of each city, thereby improving the convenience and efficiency of managing intelligent transportation systems.

[0083] IV. Detailed introduction to digital collection protocols (such as the ERC-721 standard protocol and the ERC-1155 standard protocol):

[0084] It should be noted that the data processing solution provided in this application is based on a digital collection protocol, such as the ERC-721 standard protocol or the ERC-1155 standard protocol. Therefore, the following will combine... Figure 1c The two standard protocols mentioned above will be introduced.

[0085] Please see Figure 1c , Figure 1c This is a schematic diagram of a standard protocol in a blockchain provided in an embodiment of this application. For example... Figure 1c As shown, the warrants (e.g., tokens) used in blockchain platforms (currently the mainstream smart contract platforms on public chains) can include: Fungible Tokens (FTs) and Non-Fungible Tokens (NFTs). Fungible Tokens are issued based on the ERC-20 standard protocol (a standard protocol for fungible warrants in smart contracts on a blockchain), while NFTs are issued based on the ERC-721 and ERC-1155 standard protocols.

[0086] Both the ERC-721 and ERC-1155 standard protocols are standard protocols for non-fungible tokens (NFTs) in smart contracts on the blockchain. The ERC-721 standard protocol instructs the issuance of one NFT for a given off-chain digital collectible asset, while the ERC-1155 standard protocol instructs the issuance of multiple NFTs for a given off-chain digital collectible asset on the blockchain. Since the blockchain is a public blockchain platform, the unique identifier for an object is solely its on-chain address corresponding to its private key. Therefore, neither of these standard protocols requires real-name authentication of the object, and all on-chain operations on digital collectible assets are anonymous.

[0087] Next, we will introduce the main interfaces involved in the ERC-721 and ERC-1155 standard protocols respectively:

[0088] (1) Main interfaces of the ERC-721 standard protocol:

[0089] ERC721: Main contract interface;

[0090] ERC721Enumerable: An enumeration data query interface, mainly used to count all tokenIds in the contract, and which account each tokenId belongs to;

[0091] ERC721Receiver: The receiver callback implementation interface, mainly used to verify the recipient's contract address to avoid "dead accounts";

[0092] ERC721MetaData: Main contract metadata interface (name, symbol, tokenURI).

[0093] ERC721Pausable: Contract Pause Interface;

[0094] ERC721Burnable: The warrant destruction interface;

[0095] ERC721URIStorage: tokenURI storage interface.

[0096] ERC721PresetMinterPauserAutoId: The contract owner authorizes the Minter (maker) and Pauser (pauser) interfaces;

[0097] ERC721Holder: The default implementation interface of ERC721Receiver, used to receive any token.

[0098] (2) Main interfaces of the ERC-1155 standard protocol:

[0099] ERC1155: Main contract interface;

[0100] ERC1155MetadataURI: The main contract metadata URI (Uniform Resource Identifier, URI) interface;

[0101] ERC1155Receiver: The receiver callback implementation interface is used to verify the receiving account address to avoid "dead accounts";

[0102] ERC1155Pausable: Contract Pause Interface;

[0103] ERC1155Burnable: Certificate destruction interface;

[0104] ERC1155Supply: Interface for calculating total supply data for each type of token;

[0105] ERC1155PresetMinterPauserAutoId: The contract owner authorizes the Minter (manufacturer) and Pauser (pauser) interfaces;

[0106] ERC1155Holder: The default implementation interface of ERC721Receiver, used to receive any token.

[0107] In addition, the ERC-1155 standard protocol differs from the ERC-721 standard protocol in that the ERC-1155 standard protocol supports bulk transfers and bulk issuance of warrants. That is, one off-chain asset minted through the ERC-1155 standard protocol can correspond to the minting of multiple object identity registration certificates on the chain.

[0108] It should be noted that in the subsequent specific embodiments of this application, data related to object information (such as the identity information of the target object) is involved. When the above embodiments of this application are applied to specific products or technologies, permission or consent from the object is required, and the collection, use and processing of related data must comply with the relevant laws and standards of the relevant countries and regions.

[0109] Next, the architecture diagram of the data processing system involved in this application will be described accordingly. Please refer to... Figure 2 , Figure 2 This is a schematic diagram of the architecture of a data processing system provided in an embodiment of this application. Figure 2As shown in the diagram, the system architecture diagram may include at least: a blockchain system, an identity service system 204, and a terminal device 205. Specifically, the blockchain system may be a consortium blockchain. More specifically, the consortium blockchain may include a first business service system 201, a second business service system 202, and blockchain nodes 203. It is understood that the number of first business service systems 201 and second business service systems 202 in the blockchain system is merely illustrative; similarly, the number of blockchain nodes 203 may be one or more, and this application does not specifically limit the number of business service systems or blockchain nodes in the blockchain system. Furthermore, the blockchain nodes 203 in the blockchain system are directly or indirectly connected to the first business service system 201 and the second business service system 202 via wired or wireless communication, and this application does not impose any restrictions on this; similarly, the identity service system 204 is directly or indirectly connected to the blockchain nodes 203 and the terminal device 205 via wired or wireless communication, and this application also does not impose any restrictions on this.

[0110] It should be noted that the identity service system 204 may refer to a system independent of the first business service system 201 and the second business service system 202; the identity service system 204 may also be a system integrated with the first business service system 201 or the second business service system 202 in the same computer device. This application embodiment does not specifically limit this.

[0111] The identity service system 204, the blockchain node 203 in the blockchain system, the first business service system 201, and the second business service system 202 can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms, etc.

[0112] Terminal device 205, blockchain node 203 in the blockchain system, first business service system 201, and second business service system 202 may also include, but are not limited to: mobile phones, tablets, laptops, handheld computers, mobile internet devices (MID), intelligent voice interaction devices, vehicle terminals, roadside devices, aircraft, wearable devices, smart home appliances, or wearable devices with data processing functions such as smartwatches, smart bracelets, and pedometers, etc.

[0113] It is understood that the device types of the first business service system 201, the second business service system 202, the blockchain node 203, the identity service system 204, and the terminal device 205 can be the same or different, and this application embodiment does not specifically limit this. For example, the blockchain node 203 and the identity service system 204 can be servers, and the first business service system 201, the second business service system 202, and the terminal device 205 can all be terminal devices. Alternatively, the first business service system 201, the second business service system 202, the blockchain node 203, and the identity service system 204 can all be servers, and the terminal device 205 can be a terminal device.

[0114] In one possible implementation, the target object can send an authentication request to the identity service system 204 via terminal device 205. The identity service system 204 can then forward this authentication request to blockchain node 203. Blockchain node 203 receives the authentication request for the target object and extracts verification data from it. This verification data is generated based on the digital collection protocol. Next, blockchain node 203 parses the verification data to obtain the object authentication credential and verifies it. If the object authentication credential is successfully verified, a verification success indication message is generated.

[0115] In another possible implementation, the identity service system 204 can receive the identity information submitted by the target object through the terminal device 205; the identity service system 204 verifies the target object's identity information, and if the verification is successful, generates an object identity registration certificate for the target object based on the digital collection protocol; the identity service system 204 sends the object identity registration certificate to the blockchain node 203, so that the blockchain node 203 verifies the verification data based on the object identity registration certificate, and if the verification data is successful, generates a verification success indication message. The verification data is obtained by the blockchain node 203 from the identity verification request after receiving the identity verification request for the target object.

[0116] It should be noted that the target object can also send an authentication request to the first business service system 201 or the second business service system 202 through the terminal device 205, and then the first business service system 201 or the second business service system 202 can send the authentication request to the blockchain node 203.

[0117] It is understood that the system architecture diagrams described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0118] Based on the above description of the data processing scheme and data processing system, this application proposes a data processing method. See also... Figure 3 As shown, Figure 3 This is a flowchart illustrating a data processing method provided in an embodiment of this application. The data processing method can be derived from the above... Figure 2 The data processing system mentioned is executed by blockchain nodes within the blockchain or by other electronic devices outside the blockchain. For ease of explanation, the embodiments of this application will subsequently be described using a computer device as an example. The data processing method may include the following steps S301 to S303:

[0119] S301: Obtain an authentication request for the target object, and retrieve authentication data from the authentication request. The authentication data is generated based on the Digital Collections Protocol.

[0120] In this embodiment, the authentication request can be generated by the target object when logging into the identity service system. After receiving the authentication request for the target object, the identity service system can send the authentication request to a computer device. The computer device mentioned in this embodiment can be any node in a blockchain, which can be a consortium blockchain. The digital collectibles protocol refers to a protocol proposed for digital collectibles (e.g., the ERC-721 standard protocol, the ERC-1155 standard protocol, etc.). Digital collectibles are the ownership and certificates of virtual digital goods, and can include, but are not limited to, digital paintings, pictures, music, videos, 3D models, and other forms.

[0121] Furthermore, the identity verification request mentioned in the embodiments of this application can be used to request login to an identity service system or at least one business service system. Any one of the at least one business service system refers to a system that has performed a trust endorsement operation on the identity information of the target object. The so-called trust endorsement operation means that during the real-name authentication process of the identity service system on the target object's identity information, any business service system needs to authorize and trust the real-name authentication result of the target object; that is, if the identity service system successfully authenticates the target object's identity information, the business service system also needs to trust the successful real-name authentication result. For ease of explanation, the embodiments of this application will now use the example of requesting login to the identity service system for corresponding description.

[0122] In one possible implementation, the computer device can receive an authentication request for a target object sent by an identity service system, which may carry authentication data. Furthermore, this authentication request is generated based on a digital collection protocol, which may include, but is not limited to, the ERC-721 standard protocol and the ERC-1155 standard protocol.

[0123] In one possible implementation, before obtaining the authentication request for the target object, the computer device further includes: obtaining a real-name authentication success notification message for the target object sent by a real-name authentication server. This real-name authentication success notification message is generated by the real-name authentication server after receiving the identity information submitted by the target object and calling the identity authentication platform interface to perform real-name authentication on the target object's identity information. Then, the computer device associates the target object's real-name information with the object identity registration credential generated for the target object. Real-name authentication includes at least one of the following: verification of the validity of the identity information and verification of the security of the identity information. The real-name authentication success notification message can be generated after successful real-name authentication of the target object.

[0124] In one possible implementation, the computer device receiving the real-name authentication success notification message sent by the real-name authentication server for the target object may include the following specific process: The target object can perform real-name authentication by logging into a real-name authentication mini-program (wherein, a real-name authentication mini-program refers to an application that does not require installation). Then, the real-name authentication mini-program can obtain the identity information entered by the target object in the real-name authentication mini-program. For example, the target object's identity information may include, but is not limited to: name, age, gender, identity identification number, place of residence, etc. Then, the real-name authentication mini-program can send the target object's identity information to the real-name authentication server, so that after receiving the identity information submitted by the target object, the real-name authentication server calls the identity authentication platform interface to perform real-name authentication on the target object's identity information, generates a real-name authentication success notification message, and sends the real-name authentication success notification message to the computer device.

[0125] Specifically, by calling the identity authentication platform interface, the real-name information of the target object can be obtained. This real-name information may include, but is not limited to, identity identifiers (such as avatars or names), age, and gender. Then, based on the obtained real-name information, the target object's identity can be authenticated. This can involve comparing each of the identity identifier, age, and gender from the real-name information with each of the identity identifier, age, and gender from the identity document. If all match, the real-name authentication of the target object is considered successful, and a successful authentication notification message can be generated; if any item differs, the real-name authentication of the target object is considered to have failed. It should be noted that before obtaining the target object's real-name information, authorization from the target object is required; that is, the corresponding real-name information can only be obtained after obtaining the target object's authorization.

[0126] In one possible implementation, the computer device associates the real-name information of the target object with the object identity registration certificate generated for the target object, including: first, receiving an address registration request sent by a real-name server, the address registration request carrying the blockchain address of the target object; responding to the address registration request and obtaining the object identity registration certificate generated for the target object based on the digital collection protocol; and associating the object identity registration certificate with the blockchain address of the target object.

[0127] It is understandable that a computer device obtaining an object identity registration certificate generated for a target object based on a digital collection protocol may include:

[0128] (1) If the business service system does not have the ability to issue object identity registration certificates, the business service system may entrust computer equipment to generate object identity registration certificates for the target object. Specifically, the computer equipment may obtain the entrustment request for identity registration certificates for the target object sent by the business service system, and then the computer equipment responds to the entrustment request for identity registration certificates and generates object identity registration certificates for the target object based on the digital collection protocol.

[0129] (2) If the business service system has the capability to issue object identity registration certificates, the business service system can directly generate object identity registration certificates for the target object based on the digital collection protocol. Then, the computer device receives the object identity registration certificate sent by the business service system. It should be noted that subsequent embodiments of this application will provide corresponding descriptions for situation (2).

[0130] In one possible implementation, the computer device can continuously monitor the process of associating the object's identity registration credential with the target object's blockchain address. If it detects that the association between the object's identity registration credential and the target object's blockchain address has been successfully completed, it generates a successful identity registration notification message for the target object. This message is then sent to a real-name authentication server, which in turn forwards it to a real-name authentication mini-program. This mini-program can then display the object's identity registration credential to the target object.

[0131] By employing the above methods, when a target object registers its identity with the identity service system, its identity information can first be verified through a real-name server. Only after successful verification will the on-chain object identity registration credential be transferred (i.e., associating the target object's identity registration credential with the object's address), thereby improving the accuracy of identity verification. It should also be noted that before obtaining the target object's identity information, the real-name server can send an identity information retrieval request to the target object in advance, and only after receiving confirmation and authorization from the target object can it obtain the target object's identity information.

[0132] S302: Parse the verification data to obtain the object authentication credentials, and verify the object authentication credentials.

[0133] It is understood that the specific execution steps for verifying the object identity registration certificate of the target object and then associating the object identity registration certificate with the target object after the verification is successful can be referred to in detail in the specific steps described in step S301 above. This application embodiment does not make specific limitations on this.

[0134] In one possible implementation, the verification data is obtained by signing the object authentication credential using the target object's private key. The computer device parses the verification data to obtain the object authentication credential, including: verifying the signature using the target object's public key; if the signature verification is successful, the target object's object authentication credential is obtained based on the digital collection protocol. In other words, the verification data is encrypted using the target object's private key. After obtaining the encrypted verification data, the computer device can decrypt it using the target object's public key. If decryption is successful, the target object's object authentication credential can be obtained based on the digital collection protocol.

[0135] Specifically, the computer device verifies the object authentication credential by: first, obtaining the target object's object identity registration credential, which is generated by the identity service system based on the digital collection protocol after the target object's submitted identity information has been verified. Then, verifying the object authentication credential based on the target object's object identity registration credential. This can be achieved by comparing the object identity registration credential and the object authentication credential; if they match, the object authentication credential verification is considered successful; otherwise, it is considered a failure. It should be noted that the target object's object identity registration credential can be stored in a blockchain.

[0136] In another possible implementation, the verification of object authentication credentials by the computer device may further include: first, obtaining verification information (e.g., carrying partial or complete identity information of the target object) based on the object authentication credentials; then, requesting the target object's identity information from the real-name server (it should be noted that prior permission from the target object must be obtained before requesting the identity information); and verifying the verification information based on the target object's identity information. Specifically, the computer device can compare the obtained identity information with the verification information; if they match, the object authentication credential verification is deemed successful; if they do not match, the object authentication credential verification is deemed unsuccessful.

[0137] In one possible implementation, if the computer device is any blockchain node in the blockchain, then the computer device can also send the object authentication credentials to other nodes in the blockchain, so that the other nodes in the blockchain can verify the verification data based on the object authentication credentials in the blockchain and obtain the verification results; if the number of successful verifications received by the other nodes in the blockchain is greater than or equal to a preset number threshold, then it is determined that the verification data has been verified.

[0138] In a specific implementation, a computer device can send the object identity credential to some or all of the nodes in the blockchain. For example, if the blockchain includes 20 computer devices, the object identity credential can be sent to the other 19 nodes in the blockchain, or the object identity credential can be randomly sent to 15 nodes in the blockchain. This application embodiment does not specifically limit this.

[0139] In this way, blockchain consensus can be achieved based on some or all nodes in the blockchain to ensure that the object authentication credentials submitted by the target object are the same as the object identity registration credentials assigned to the target object. This proves the uniqueness of the object identity registration credentials of the target object and thus ensures the reliability of the authentication process.

[0140] S303: If the object authentication credentials are successfully verified, a verification success indication message is generated.

[0141] In one possible implementation, after the computer device determines that the object's authentication credentials have been successfully verified, it can generate a verification success indication message. The computer device can then send this verification success indication message to the business service system, whereby the business service system can display a verification success interface, which can show a message indicating that the target object has successfully logged into the business service system.

[0142] It is understood that the authentication request mentioned in the embodiments of this application can be used to request login to an identity service system or at least one business service system. The above embodiments of this application use the example of requesting login to an identity service system for explanation. Similarly, for requesting login to any business service system, the specific execution steps can be referred to the above steps in detail, and will not be repeated here. Wherein, any business service system refers to a system that has performed a trust endorsement operation on the identity information of the target object. The so-called trust endorsement operation means that during the real-name authentication process of the identity service system on the target object's identity information, any business service system needs to authorize and trust the real-name authentication result of the target object. That is, if the identity service system successfully authenticates the target object's identity information, the business service system also needs to trust the successful real-name authentication result.

[0143] In one possible implementation, firstly, the computer device receives a data retrieval request submitted by a target business system. This request seeks to obtain the identity information of a target object. The target business system includes an identity service system and at least one business service system. Then, the computer device sends the data retrieval request to a real-name authentication server. Finally, the computer device receives the target object's identity information from the real-name authentication server and forwards this information to the target business system.

[0144] The identity information of the target object is obtained by the real-name server after receiving a successful authorization notification message from the target object. In practice, the real-name server stores a large amount of object identity information; when it needs to obtain the identity information of a target object, it must first request authorization from that target object. Please refer to the following section. Figure 4 , Figure 4 This is a schematic diagram illustrating a data acquisition scenario provided in an embodiment of this application. For example... Figure 4As shown, before the computer device receives the target object's identity information sent by the real-name server, the real-name server can send an authorization request to the terminal device used by the target object. When the terminal device receives this authorization request, it can display an authorization interface S400. This authorization interface S400 prompts the target object whether to confirm the information acquisition operation of the target business system. For example, the authorization interface S400 may include a confirmation control 401 and a denial control 420. Specifically, if the target object clicks the confirmation control 401, it means that the target object allows the target business system to obtain its identity information; if the target object clicks the denial control 402, it means that the target object denies the target business system's request for identity information. After the target object clicks the confirmation control 401, the terminal device can generate an authorization success notification message and send it to the real-name server. The real-name server can only obtain the target object's identity information after receiving the authorization success notification message. In this way, when the target business system needs to obtain the target object's identity information, it must request authorization from the target object. However, the target object can only obtain the corresponding identity information after successfully authorizing it, thus ensuring the reliability of the target object's identity information.

[0145] In this embodiment, firstly, an authentication request for the target object can be obtained, and verification data, generated based on the digital collection protocol, can be retrieved from the authentication request. Then, the verification data can be parsed to obtain the object authentication credential, which is then verified. Finally, if the object authentication credential is successfully verified, a verification success indication is generated. Therefore, when a target object needs authentication, it can be authenticated by sending an authentication request and obtaining the object authentication credential from that request. Compared to manual authentication, this method is simpler and more convenient, thus improving authentication efficiency. In this application, the object's identity information does not need to be fully registered across various login systems, making it more decentralized than traditional login methods (based on accounts and passwords, SMS, and facial recognition), thus ensuring authentication security. Furthermore, after obtaining the specified object identity registration credential once on the blockchain, the object can log in to all decentralized application systems on the blockchain platform, connecting the authentication systems on the blockchain platform and improving the efficiency and reliability of authentication.

[0146] Please see Figure 5 , Figure 5 This is a flowchart illustrating another data processing method provided in an embodiment of this application. This data processing method can be derived from the above... Figure 2The data processing system mentioned is executed by the identity service system or any business service system. For ease of explanation, the following description will take the execution by the identity service system as an example. The data processing method may include the following steps S501 to S503:

[0147] S501: Obtain the identity registration request submitted by the target object, which carries the identity information of the target object.

[0148] When a target object registers its identity with the identity service system, it can submit an identity registration request. The identity service system can then receive this request, which may contain the target object's identity information. This identity information may include, but is not limited to, name, age, gender, identification number, and place of residence.

[0149] In one possible implementation, the identity service system can send an authorization request to the terminal device used by the target object before obtaining the target object's identity information. Then, after receiving the authorization request, the terminal device can display an authorization interface (e.g., ...) on the terminal device. Figure 4 The interface S400 is shown below. Specifically, if the target object clicks the confirmation control 401 in the authorization interface S400, it means that the target object allows the identity service system to obtain its identity information. In this way, when the identity service system needs to obtain the target object's identity information, it must request authorization from the target object. However, the system can only obtain the corresponding identity information after the target object successfully authorizes it, thus ensuring the reliability of the target object's identity information.

[0150] S502: Verify the identity information of the target object. If the verification is successful, generate an object identity registration certificate for the target object based on the digital collection protocol.

[0151] In one possible implementation, after the identity service system obtains the identity registration request submitted by the target object, it further includes: sending the target object's identity information to a real-name server, so that the real-name server calls the identity authentication platform interface to perform real-name authentication on the target object's identity information, generates a real-name authentication success notification message, and sends the real-name authentication success notification message to a computer device, so that the computer device associates the target object with the object identity registration credential generated for the target object. Real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

[0152] In practice, the identity service system can perform real-name authentication on the target object's identity information through a real-name server. If the real-name server confirms successful authentication, it sends a successful authentication notification message to the computer device and the identity service system. Upon receiving the successful authentication notification message, the identity service system confirms that the target object's identity information has been verified and can then generate an object identity registration certificate based on the digital collectibles protocol. Specifically, the object identity registration certificate can be a digital collectible, which can be the aforementioned non-fungible certificate. This method of real-name authentication during target object registration ensures the validity and reliability of the target object's identity information.

[0153] S503: Send the object identity registration credential of the target object to the computer device so that the computer device can verify the object identity verification credential. If the object identity verification credential is successful, a verification success indication message is generated.

[0154] Among them, the object authentication credential is obtained by parsing the verification data. The verification data is obtained by the computer device from the authentication request after receiving the authentication request for the target object. The verification data is generated based on the digital collection protocol.

[0155] In one possible implementation, the identity service system can respond to an authentication request for a target object. The system can then send this request to a computer device, allowing the device to retrieve verification data from the request. The device parses the verification data to obtain the object's authentication credentials and verifies them. If the authentication is successful, a verification success indication is generated. Subsequently, the identity service system can receive the verification success indication from the computer device, thus proving the target object's identity and achieving identity recognition based on the object's registration credentials within the blockchain.

[0156] It should be noted that the embodiments of this application take the registration of the target object with the identity service system as an example for detailed explanation. It can be understood that for the registration of the target object with any business service system, the specific execution steps can refer to the relevant steps of the registration of the target object with the identity service system in the embodiments of this application, and will not be repeated here.

[0157] In one possible implementation, the identity service system can generate a data retrieval request to obtain the identity information of a target object. The identity service system can then send the data retrieval request to a computer device, which in turn forwards the request to a real-name server. Finally, the identity service system receives the target object's identity information from the computer device. It should be noted that before obtaining the target object's identity information, the identity service system needs to obtain the target object's permission and authorization; details of this process can be found in [link to relevant documentation]. Figure 4 The process shown is not described in detail here.

[0158] In this embodiment, when a target object registers its identity with the identity service system, it can undergo real-name authentication through a real-name server. Only after successful real-name authentication can a corresponding object identity registration credential be generated for the target object. Subsequently, when the target object needs to verify its identity, it can submit an authentication request to the identity service system or any business service system based on the identity registration credential. If the verification is successful, it can log in to the identity service system or any business service system. Therefore, when a target object registers its identity in a specific system (identity service system or any business service system), after completing real-name authentication, the system will issue a specific object identity registration credential to the target object. When the target object logs in to the system again, or needs to prove its identity to a third party, proving its on-chain ownership of the specific object identity registration credential is sufficient to prove its identity and log in to the specific system. Compared to traditional login methods based on accounts and passwords, mobile SMS, and facial recognition, this solution is more decentralized. The target's identity information does not need to be fully registered across various login systems. After the target's identity is verified once on the blockchain and a specified target identity registration credential is obtained, the target can log in to all decentralized application systems on the blockchain platform, thus improving the efficiency of identity verification.

[0159] Combination Figure 3 and Figure 5 The document describes the specific workflow of the data processing method. Please refer to the following section. Figure 6 , Figure 6 This is a schematic diagram of the interaction flow of a data processing method provided in an embodiment of this application. This data processing method can be jointly executed by a computer device, a real-name server, an identity service system, or any one of the business service systems (which can be represented as business system 1 or business system 2). The interaction flow of this data processing method may include the following steps S1 to S13:

[0160] S1: The target user logs into the mini-program to complete real-name authentication.

[0161] In practice, the target user can log in to a mini-program (specifically, a real-name authentication mini-program) to complete real-name authentication. This real-name authentication mini-program is an installation-free application that can be embedded within other installed applications (such as social media applications). The target user can first log in to the social media application, then find and open the real-name authentication mini-program within that application to complete the real-name authentication process.

[0162] S2: The real-name server obtains the real-name authentication request for the target object.

[0163] In practice, after the target object logs into the real-name authentication mini-program, it can generate a real-name authentication request, and then the real-name server can receive the real-name authentication request sent by the real-name authentication mini-program.

[0164] S3: The real-name server performs real-name authentication on the identity information of the target object.

[0165] In one possible implementation, the real-name server responds to the real-name authentication request and obtains the target object's identity information. However, before obtaining the target object's identity information, the real-name server needs to send an authorization request to the target object. This authorization request is used to request authorization from the target object. If the target object confirms authorization, then the real-name server obtains the target object's identity information. If the target object does not confirm authorization, then the real-name server cannot obtain the target object's identity information.

[0166] In practice, the real-name server stores a large amount of object identity information. When it is necessary to obtain the identity information of a target object, authorization must be requested from that target object in advance. For example, please refer to [link to example]. Figure 7 , Figure 7 This is a schematic diagram of another data acquisition scenario provided in an embodiment of this application. For example... Figure 7 As shown, when the real-name server needs to obtain the identity information of a target object, it can generate an authorization request and send it to the terminal device used by the target object. Upon receiving the authorization request, the terminal device can display an authorization interface S700, which requests authorization from the target object to obtain its identity information. The target object can click the confirmation control 701 in the authorization interface S700 to complete the authorization. The terminal device can then generate an authorization success notification message and send it to the real-name server. Only after receiving the authorization success notification message can the real-name server retrieve the target object's identity information from the identity information database. For example, the real-name server can retrieve the target object's identity information based on its identity identifier. In this way, prior authorization from the target object is required before obtaining its identity information, thus ensuring the reliability of the target object's identity information and preventing its leakage.

[0167] S4: Address registration on the object chain.

[0168] In practice, the real-name server sends an address registration request to the blockchain. Only after the real-name server successfully authenticates the target object's identity information can it submit an address registration request to the blockchain, which carries the target object's blockchain address. This blockchain address can be an account address in the blockchain determined based on the target object's public key. Specifically, the target object's blockchain address is determined by calculating the hash value of its public key using a hash algorithm (such as SHA-256, SHA-512, etc.). It is understood that the target object's blockchain address is unique on the blockchain.

[0169] S5: On-chain transfer of object identity registration credentials.

[0170] In practice, after responding to the address registration request, the computer device can obtain the object identity registration certificate generated by the identity service system for the target object based on the digital collection protocol, and associate the object identity registration certificate with the blockchain address of the target object.

[0171] S6: Identity registration certificate for objects transferred on the computer equipment monitoring chain.

[0172] In one possible implementation, the computer device can continuously monitor the process of associating the object's identity registration credential with the target object's blockchain address. If it detects that the object's identity registration credential has been successfully associated with the target object's blockchain address, it generates an identity registration success notification message for the target object and can send the identity registration success notification message to the real-name server.

[0173] S7: The real-name server sends the object identity registration certificate to the mini-program.

[0174] In practice, after receiving the identity registration success notification message, the real-name server confirms that the identity information of the target object has been successfully verified and sends the object identity registration certificate to the mini program.

[0175] S8: The mini-program displays the object's identity registration certificate.

[0176] S9: The target object logs into business system 1 and submits an authentication request.

[0177] In this embodiment, business system 1 can be the aforementioned identity service system. When a target object logs into the identity service system, it can send an authentication request to the identity service system.

[0178] S10: Business system 1 sends an authentication request to the computer device.

[0179] In one possible implementation, after receiving an authentication request, the identity service system can verify the authentication request on the blockchain by sending the authentication request to a computer device, which can be any node or execution node in the blockchain (e.g., a consortium blockchain).

[0180] S11: The computer device sends a verification success indication message to business system 1.

[0181] In one possible implementation, the computer device obtains verification data from the authentication request. This verification data is generated based on the digital collection protocol. The computer device then parses the verification data to obtain the object authentication credentials for the target object. Next, the computer device verifies the object authentication credentials. If the verification is successful, a verification success indication is generated. Finally, the computer device sends this verification success indication to the identity service system.

[0182] S12: Business system 1 returns the login result to the target object.

[0183] S13: The target object logs into business system 2 and submits an authentication request.

[0184] It is understood that the specific execution process of the target object logging into business system 2 can be referred to in detail in steps S9-S12 above, and this application embodiment does not specifically limit it. Business system 2 can be any of the business service systems mentioned above.

[0185] In this application, the target object can obtain a designated identity registration credential by completing real-name authentication once in business system 1. Subsequent logins to business system 1 only require on-chain verification of the object's identity registration credential to confirm its identity. Furthermore, based on this object's identity registration credential, login can also be performed in business system 2 (or even any other business system in the blockchain), thus enabling seamless identity login across the blockchain platform. Compared to traditional login methods based on accounts and passwords, SMS, or facial recognition, this application offers greater decentralization and higher login security.

[0186] Please see Figure 8 , Figure 8This is a schematic diagram of the structure of a data processing apparatus provided in an embodiment of this application. The data processing apparatus 800 can be applied to the computer device in the foregoing embodiments. The data processing apparatus 800 can be a computer program (including program code) running on the computer device; for example, the data processing apparatus 800 is an application software. The data processing apparatus 800 can be used to execute corresponding steps in the data processing method provided in the embodiments of this application. The data processing apparatus 800 may include:

[0187] The acquisition unit 801 is used to acquire an authentication request for the target object and obtain authentication data from the authentication request;

[0188] The processing unit 802 is used to verify the verification data based on the object identity registration certificate of the target object. The object identity registration certificate is generated by the identity service system based on the digital collection protocol after the identity information submitted by the target object to the identity service system has been verified.

[0189] The processing unit 802 is also used to generate a verification pass indication message if the verification data passes verification.

[0190] In one possible implementation, before the acquisition unit 801 acquires the authentication request for the target object, the processing unit 802 is further configured to perform the following operations:

[0191] Get the real-name authentication success notification message sent by the real-name server for the target object. The real-name authentication success notification message is generated by the real-name server after receiving the identity information submitted by the target object and calling the identity authentication platform interface to perform real-name authentication on the target object's identity information.

[0192] Associate the target object with the object identity registration credential generated for the target object;

[0193] Real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

[0194] In one possible implementation, processing unit 802 associates the target object with the object identity registration credential generated for the target object, for the following operations:

[0195] Receive an address registration request sent by the real-name server, the address registration request carrying the blockchain address of the target object;

[0196] Respond to the address registration request and obtain the object identity registration certificate generated by the identity service system for the target object based on the digital collection protocol;

[0197] Associate the object's identity registration certificate with the target object's blockchain address.

[0198] In one possible implementation, processing unit 802 verifies the object authentication credentials to perform the following operations:

[0199] Obtain the object identity registration certificate of the target object. The object identity registration certificate is generated by the identity service system based on the digital collection protocol after the identity information submitted by the target object to the identity service system is verified.

[0200] The object authentication credentials are verified based on the object's object identity registration credentials.

[0201] In one possible implementation, the verification data is obtained by signing the object authentication credential using the private key of the target object;

[0202] Processing unit 802 parses the verification data to obtain object authentication credentials, which are used to perform the following operations:

[0203] The public key of the target object is used to verify the signature of the verification data. If the signature verification is successful, the object identity verification credential of the target object is obtained based on the digital collection protocol.

[0204] In one possible implementation, the authentication request is used to request login to an identity service system or at least one business service system, wherein any one of the at least one business service system refers to a system that has performed a trust endorsement operation on the identity information of the target object.

[0205] In one possible implementation, the processing unit 802 is further configured to perform the following operations:

[0206] Receive data acquisition requests submitted by the target business system. The data acquisition requests are used to request the acquisition of the identity information of the target object. The target business system includes an identity service system and at least one business service system.

[0207] Send a data retrieval request to the real-name server;

[0208] Receive the identity information of the target object sent by the real-name server, and send the identity information of the target object to the target business system;

[0209] The identity information of the target object is obtained by the real-name server after receiving the authorization success notification message returned by the target object.

[0210] In this embodiment, firstly, an authentication request for the target object can be obtained, and verification data, generated based on the digital collection protocol, can be retrieved from the authentication request. Then, the verification data can be parsed to obtain the object authentication credential, and the object authentication credential can be verified. Finally, if the object authentication credential is successfully verified, a verification success indication message is generated. Therefore, when a target object needs to be authenticated, it can be authenticated by sending an authentication request and obtaining the object authentication credential from that request. Compared to manual object authentication, the authentication method of this application is simpler and more convenient, thereby improving the efficiency of authentication.

[0211] Please see Figure 9 , Figure 9 This is a schematic diagram of another data processing apparatus provided in an embodiment of this application. The data processing apparatus 900 can be applied to the identity service system (or business service system) in the foregoing embodiments. The data processing apparatus 900 can be a computer program (including program code) running in the identity service system; for example, the data processing apparatus 900 is an application software. The data processing apparatus 900 can be used to execute corresponding steps in the data processing method provided in the embodiments of this application. The data processing apparatus 900 may include:

[0212] The acquisition unit 901 is used to acquire the identity registration request submitted by the target object, and the identity registration request carries the identity information of the target object;

[0213] The processing unit 902 is used to verify the identity information of the target object. If the verification is successful, it generates an object identity registration certificate for the target object based on the digital collection protocol.

[0214] The sending unit 903 is used to send the object identity registration certificate of the target object to the computer device so that the computer device can verify the object identity verification certificate. If the object identity verification certificate is successful, a verification success indication message is generated.

[0215] Among them, the object authentication credential is obtained by parsing the verification data. The verification data is obtained by the computer device from the authentication request after receiving the authentication request for the target object. The authentication request is generated based on the digital collection protocol.

[0216] In one possible implementation, after the acquisition unit 901 acquires the identity registration request submitted by the target object, the processing unit 902 is further configured to perform the following operations:

[0217] The identity information of the target object is sent to the real-name server, so that the real-name server calls the identity authentication platform interface to perform real-name authentication on the identity information of the target object and generates a real-name authentication success notification message. The real-name authentication success notification message is then sent to the computer device, so that the computer device associates the target object with the object identity registration certificate generated for the target object.

[0218] Real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

[0219] In one possible implementation, the processing unit 902 is further configured to perform the following operations:

[0220] Generate a data retrieval request, which is used to request the identity information of the target object;

[0221] Sending a data acquisition request to the computer device causes the computer device to send the data acquisition request to the real-name server;

[0222] The system receives the identity information of the target object sent by the computer device. The identity information of the target object is obtained by the real-name server after receiving the authorization success notification message returned by the target object.

[0223] In this embodiment, when a target object registers its identity in a specific system (identity service system or any business service system), after completing real-name authentication, the system issues a specific object identity registration credential to the target object. When the target object logs into the system again, or needs to prove its identity to a third party, proving its on-chain ownership of the specific object identity registration credential is sufficient to prove its identity and log in to the specific system. Compared to traditional login methods based on accounts and passwords, mobile SMS, and facial recognition, this solution is more decentralized. The target object's identity information does not need to be fully registered across various login systems. After the object's identity is verified on the blockchain once and the specified object identity registration credential is obtained, it can log in to all decentralized application systems on the blockchain platform, thus connecting the identity login systems on the blockchain platform and improving the efficiency of identity verification.

[0224] Please see Figure 10 , Figure 10This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. The computer device 1000 is used to execute the steps performed by the computer device and identity service system (or business service system) in the aforementioned method embodiments. The computer device 1000 includes: one or more processors 1010; one or more input devices 1020; one or more output devices 1030; and a memory 1040. The processors 1010, input devices 1020, output devices 1030, and memory 1040 are connected via a bus 1050. The memory 1040 is used to store computer programs, which include program instructions. The processor 1010 is used to call the program instructions stored in the memory 1040 to perform the following operations:

[0225] Obtain the authentication request for the target object, and retrieve the verification data from the authentication request. The verification data is generated based on the digital collection protocol.

[0226] The verification data is parsed to obtain the object authentication credentials, and the object authentication credentials are then verified.

[0227] If the object authentication credentials are successfully verified, a verification success indication message is generated.

[0228] In one possible implementation, before obtaining the authentication request for the target object, the processor 1010 is also used to perform the following operations:

[0229] Get the real-name authentication success notification message sent by the real-name server for the target object. The real-name authentication success notification message is generated by the real-name server after receiving the identity information submitted by the target object and calling the identity authentication platform interface to perform real-name authentication on the target object's identity information.

[0230] Associate the target object with the object identity registration credential generated for the target object;

[0231] Real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

[0232] In one possible implementation, the processor 1010 associates the target object with the object identity registration credential generated for the target object, for the following operations:

[0233] Receive an address registration request sent by the real-name server, the address registration request carrying the blockchain address of the target object;

[0234] Respond to the address registration request and obtain the object identity registration certificate generated by the identity service system for the target object based on the digital collection protocol;

[0235] Associate the object's identity registration certificate with the target object's blockchain address.

[0236] In one possible implementation, the processor 1010 verifies the object authentication credentials for the following operations:

[0237] Obtain the object identity registration certificate of the target object. The object identity registration certificate is generated by the identity service system based on the digital collection protocol after the identity information submitted by the target object to the identity service system is verified.

[0238] The object authentication credentials are verified based on the object's object identity registration credentials.

[0239] In one possible implementation, the verification data is obtained by signing the object authentication credential using the private key of the target object;

[0240] Processor 1010 parses the verification data to obtain object authentication credentials, which are used to perform the following operations:

[0241] The public key of the target object is used to verify the signature of the verification data. If the signature verification is successful, the object identity verification credential of the target object is obtained based on the digital collection protocol.

[0242] In one possible implementation, the authentication request is used to request login to an identity service system or at least one business service system, wherein any one of the at least one business service system refers to a system that has performed a trust endorsement operation on the identity information of the target object.

[0243] In one possible implementation, the processor 1010 is also used to perform the following operations:

[0244] Receive data acquisition requests submitted by the target business system. The data acquisition requests are used to request the acquisition of the identity information of the target object. The target business system includes an identity service system and at least one business service system.

[0245] Send a data retrieval request to the real-name server;

[0246] Receive the identity information of the target object sent by the real-name server, and send the identity information of the target object to the target business system;

[0247] The identity information of the target object is obtained by the real-name server after receiving the authorization success notification message returned by the target object.

[0248] The processor 1010 is used to call program instructions stored in the memory 1040, and is also used to perform the following operations:

[0249] Obtain the identity registration request submitted by the target object, which carries the identity information of the target object;

[0250] The identity information of the target object is verified. If the verification is successful, an object identity registration certificate for the target object is generated based on the digital collection protocol.

[0251] The object identity registration credential of the target object is sent to the computer device so that the computer device can verify the object identity verification credential. If the object identity verification credential is successfully verified, a verification success indication message is generated.

[0252] Among them, the object authentication credential is obtained by parsing the verification data. The verification data is obtained by the computer device from the authentication request after receiving the authentication request for the target object. The authentication request is generated based on the digital collection protocol.

[0253] In one possible implementation, after obtaining the identity registration request submitted by the target object, the processor 1010 is also used to perform the following operations:

[0254] The identity information of the target object is sent to the real-name server, so that the real-name server calls the identity authentication platform interface to perform real-name authentication on the identity information of the target object and generates a real-name authentication success notification message. The real-name authentication success notification message is then sent to the computer device, so that the computer device associates the target object with the object identity registration certificate generated for the target object.

[0255] Real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

[0256] In one possible implementation, the processor 1010 is also used to perform the following operations:

[0257] Generate a data retrieval request, which is used to request the identity information of the target object;

[0258] Sending a data acquisition request to the computer device causes the computer device to send the data acquisition request to the real-name server;

[0259] The computer device receives the identity information of the target object. This identity information is obtained by the real-name server after receiving the authorization success notification message returned by the target object.

[0260] In this embodiment, firstly, an authentication request for the target object can be obtained, and verification data can be retrieved from the authentication request, which is generated based on the digital collection protocol. Then, the verification data can be processed to obtain the target object's object authentication credential. Next, the object authentication credential is verified based on the object identity registration credential in the blockchain. The object identity registration credential is generated by the identity service system based on the digital collection protocol and stored in the blockchain after the identity information submitted by the target object to the identity service system has been verified successfully. Finally, if the verification data is verified successfully, a verification success indication message is generated. Therefore, when a target object needs to be authenticated, it can send an authentication request to the identity service system, which can then complete the authentication through the blockchain. Compared to manual authentication, this method is simpler and more convenient, thus improving the efficiency of authentication; furthermore, the blockchain-based verification method also enhances the credibility of the authentication.

[0261] Furthermore, it should be noted that this application also provides a computer storage medium storing a computer program, which includes program instructions. When the processor executes these program instructions, it can perform the methods described in the preceding embodiments. Therefore, further details will not be provided here. For technical details not disclosed in the embodiments of the computer storage medium involved in this application, please refer to the description of the method embodiments of this application. As an example, the program instructions can be deployed on a computer device, executed on multiple computer devices located in one location, or executed on multiple computer devices distributed in multiple locations and interconnected through a communication network.

[0262] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods described in the preceding embodiments; therefore, further details will not be provided here.

[0263] Those skilled in the art will understand that implementing all or part of the processes in the above embodiments can be accomplished by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0264] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.

Claims

1. A data processing method, characterized in that, Performed by a computer device, the method includes: Obtain a real-name authentication success notification message sent by the real-name server for the target object. The real-name authentication success notification message is generated by the real-name server after receiving the identity information submitted by the target object and calling the identity authentication platform interface to perform real-name authentication on the identity information of the target object. Receive an address registration request sent by the real-name server, wherein the address registration request carries the blockchain address of the target object; In response to the address registration request, obtain the object identity registration certificate generated by the identity service system for the target object based on the digital collection protocol; Associate the object's identity registration certificate with the target object's blockchain address; If it is detected that the object identity registration credential has been successfully associated with the target object's blockchain address, an identity registration success notification message for the target object is generated and sent to the real-name server. The real-name server then sends the identity registration success notification message to the real-name authentication mini-program, which is used to display the object identity registration credential to the target object. The identity information is received by the real-name authentication mini-program and sent to the real-name server. Obtain an authentication request for the target object, and obtain verification data from the authentication request, wherein the verification data is generated based on the digital collection protocol; The verification data is parsed to obtain an object authentication credential, and the object authentication credential is verified; wherein, verifying the object authentication credential includes sending the object authentication credential to nodes in the blockchain, so that the nodes in the blockchain verify the verification data based on the object identity registration credential in the blockchain to obtain a verification result; If the object authentication credentials are successfully verified, a verification success indication message is generated.

2. The method as described in claim 1, characterized in that, The real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

3. The method as described in claim 1, characterized in that, The verification data is obtained by signing the object authentication credential using the target object's private key; The step of parsing the verification data to obtain object authentication credentials includes: The verification data is processed using the public key of the target object. If the verification is successful, the object authentication credential of the target object is obtained based on the digital collection protocol.

4. The method as described in claim 1, characterized in that, The authentication request is used to request login to the identity service system or at least one business service system, wherein any one of the at least one business service system refers to a system that has performed a trust endorsement operation on the identity information of the target object.

5. The method as described in claim 1, characterized in that, The method further includes: Receive a data acquisition request submitted by a target business system, the data acquisition request being used to request the acquisition of the identity information of the target object, the target business system including the identity service system and at least one business service system; Send the data retrieval request to the real-name server; Receive the identity information of the target object sent by the real-name server, and send the identity information of the target object to the target business system; The identity information of the target object is obtained by the real-name server after receiving the authorization success notification message returned by the target object.

6. A data processing method, characterized in that, The method is applied to an identity service system or any business service system, and the method includes: Obtain the identity registration request submitted by the target object, wherein the identity registration request carries the identity information of the target object; The identity information of the target object is sent to a real-name server. The real-name server then calls an identity authentication platform interface to perform real-name authentication on the target object's identity information, generating a successful authentication notification message. This message is then sent to a computer device, enabling the computer device to associate the target object with an object identity registration certificate generated for the target object. This association involves the computer device receiving an address registration request from the real-name server, which carries the blockchain address of the target object; responding to the address registration request; obtaining an object identity registration certificate generated by the identity service system based on a digital collection protocol for the target object; and associating the object identity registration certificate with the blockchain address of the target object. The identity information of the target object is verified. If the verification is successful, an object identity registration certificate for the target object is generated based on the digital collection protocol. The object identity registration credential of the target object is sent to the computer device so that the computer device can verify the object identity verification credential. If the object identity verification credential is successfully verified, a verification success indication message is generated. The object authentication credential is obtained by parsing the verification data, which is obtained by the computer device from the authentication request after receiving the authentication request for the target object. The verification of the object authentication credential includes the computer device sending the object authentication credential to nodes in the blockchain, so that the nodes in the blockchain can verify the verification data based on the object identity registration credential in the blockchain to obtain the verification result; and when the computer device detects that the object identity registration credential has been successfully associated with the blockchain address of the target object, it generates an identity registration success notification message for the target object and sends the identity registration success notification message to the real-name server, so that the real-name server sends the identity registration success notification message to the real-name authentication applet, which is used to display the object identity registration credential to the target object; the identity information is received by the real-name authentication applet and sent to the real-name server.

7. The method as described in claim 6, characterized in that, The real-name authentication includes at least one of the following: verification of the validity of identity information and verification of the security of identity information.

8. The method as described in claim 7, characterized in that, The method further includes: Generate a data acquisition request, the data acquisition request being used to request the acquisition of the identity information of the target object; The data acquisition request is sent to the computer device, so that the computer device sends the data acquisition request to the real-name server; The computer device receives the identity information of the target object, which is obtained by the real-name server after receiving the authorization success notification message returned by the target object.

9. A data processing apparatus, characterized in that, The device is used in a computer device, and the device includes: The acquisition unit is used to acquire an authentication request for a target object, and to acquire verification data from the authentication request, wherein the verification data is generated based on the digital collection protocol; The processing unit is used to parse the verification data to obtain the object authentication credential and to verify the object authentication credential. The processing unit is further configured to generate a verification success indication message if the object authentication credential is successfully verified. The processing unit is further configured to: obtain a real-name authentication success notification message for the target object sent by the real-name server; the real-name authentication success notification message is generated by the real-name server after receiving the identity information submitted by the target object and calling the identity authentication platform interface to perform real-name authentication on the target object's identity information; receive an address registration request sent by the real-name server, the address registration request carrying the blockchain address of the target object; respond to the address registration request and obtain an object identity registration certificate generated by the identity service system for the target object based on the digital collection protocol; and associate the object identity registration certificate with the blockchain address of the target object. The apparatus further includes: a unit for generating an identity registration success notification message for the target object if it is detected that the object identity registration certificate has been successfully associated with the blockchain address of the target object, and sending the identity registration success notification message to the real-name server, so that the real-name server sends the identity registration success notification message to the real-name authentication mini-program, the real-name authentication mini-program being used to display the object identity registration certificate to the target object; the identity information is received by the real-name authentication mini-program and sent to the real-name server.

10. A data processing apparatus, characterized in that, The device is applied to an identity service system or any business service system, and the device includes: The acquisition unit is used to acquire the identity registration request submitted by the target object, wherein the identity registration request carries the identity information of the target object; The processing unit is used to verify the identity information of the target object. If the verification is successful, it generates an object identity registration certificate for the target object based on the digital collection protocol. The sending unit is used to send the object identity registration credential of the target object to the computer device so that the computer device can verify the object identity verification credential. If the object identity verification credential is verified successfully, a verification success indication message is generated. The processing unit is further configured to send the identity information of the target object to the real-name server, so that the real-name server calls the identity authentication platform interface to perform real-name authentication on the identity information of the target object and generates a real-name authentication success notification message, and sends the real-name authentication success notification message to the computer device, so that the computer device associates the target object with the object identity registration certificate generated for the target object; wherein, associating the target object with the object identity registration certificate generated for the target object by the computer device means: the computer device receives an address registration request sent by the real-name server, the address registration request carrying the blockchain address of the target object; responds to the address registration request, obtains the object identity registration certificate generated for the target object by the identity service system based on the digital collection protocol; and associates the object identity registration certificate with the blockchain address of the target object; The object authentication credential is obtained by parsing the verification data, which is obtained by the computer device from the authentication request after receiving the authentication request for the target object. The verification of the object authentication credential includes the computer device sending the object authentication credential to nodes in the blockchain, so that the nodes in the blockchain can verify the verification data based on the object identity registration credential in the blockchain to obtain the verification result; and when the computer device detects that the object identity registration credential has been successfully associated with the blockchain address of the target object, it generates an identity registration success notification message for the target object and sends the identity registration success notification message to the real-name server, so that the real-name server sends the identity registration success notification message to the real-name authentication applet, which is used to display the object identity registration credential to the target object; the identity information is received by the real-name authentication applet and sent to the real-name server.

11. A computer device, characterized in that, include: Storage devices and processors; A memory, wherein one or more computer programs are stored; A processor for loading one or more computer programs to implement the data processing method as described in any one of claims 1-5 or 6-8.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded by a processor and to execute the data processing method as described in any one of claims 1-5 or 6-8.

13. A computer program product, characterized in that, The computer program product includes a computer program adapted to be loaded by a processor and execute the data processing method as described in any one of claims 1-5 or 6-8.

Citation Information

Patent Citations

  • Blockchain-based data sharing method, device and storage medium

    CN110493220A

  • Digital certificate issuing and verifying method based on NFT

    CN114201735A