Blockchain-based data authorization method, device, equipment and medium

CN117201048BActive Publication Date: 2026-08-07TENPAY PAID TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENPAY PAID TECH
Filing Date
2022-05-31
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

然而,在一些实际场景(例如,商业场景等)中,可能会由于区块链系统中的参与方的特殊性,若将参与方的信息直接暴露在区块链上,会造成参与方信息的泄露,导致参与方的信息安全性过低

Benefits of technology

[0054]本申请实施例中,通过在区块链中获取数据发行对象为目标对象分发的数据凭证,该目标对象属于数据发行对象在区块链上为该数据凭证设置的第一查询权限范围;进而可以基于数据凭证和目标对象对应的对象私钥生成资产展示数据,将该资产展示数据存储至区块链,在该区块链中可以为资产展示数据设置第二查询权限范围,即可以将资产展示数据授权给第二查询权限范围内的数据验证对象。可见,第二查询权限范围内的数据验证对象才具备读取区块链中的资产展示数据的权限,即目标对象仅将资产展示数据授权给第二查询权限范围内的数据验证对象;数据验证对象在读取区块链中的资产展示数据时,可以通过区块链中的第一数字身份文件来验证资产展示数据的有效性,且第一数字身份文件可以包含第一身份证明机构为目标对象认证的对象公钥和目标数字身份标识,并不包含目标对象的真实身份信息,可以提高目标对象的数据安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117201048B_ABST
    Figure CN117201048B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a data authorization method and device based on a blockchain, equipment and a medium. The method comprises: obtaining a data credential distributed by a data issuing object for a target object in a blockchain; the target object belongs to a first query permission range set by the data issuing object for the data credential on the blockchain; generating asset display data corresponding to the target object according to the data credential and an object private key corresponding to the target object; storing the asset display data to the blockchain, and setting a second query permission range for the asset display data on the blockchain, so that a data verification object in the second query range verifies the validity of the asset display data based on a first digital identity file corresponding to the target object, and the first digital identity file comprises an object public key and a target digital identity identifier authenticated by a first identity certification authority. The embodiments of the present application can improve data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of blockchain technology, and in particular to a data authorization method, apparatus, device, and medium based on blockchain. Background Technology

[0002] Due to its traceability and immutability, blockchain is increasingly being used for data storage. Information from all participants in a blockchain system can be stored on the blockchain. Based on its decentralized nature, each participant can not only read their own information but also that of other participants; that is, all participants in a blockchain system can share all the data stored on the blockchain. However, in some real-world scenarios (e.g., commercial scenarios), due to the specific characteristics of the participants in the blockchain system, directly exposing their information on the blockchain could lead to information leakage and result in low information security. Summary of the Invention

[0003] This application provides a data authorization method, apparatus, device, and medium based on blockchain, which can improve data security.

[0004] This application provides a blockchain-based data authorization method, including:

[0005] Retrieve data credentials distributed by the data issuer to the target object in the blockchain; the target object belongs to the first query permission scope set by the data issuer for the data credentials on the blockchain;

[0006] Based on the data credentials and the private key of the target object, generate asset display data corresponding to the target object;

[0007] The asset display data is stored on the blockchain, and a second query permission range is set on the blockchain for the asset display data, so that the data verification object within the second query range can verify the validity of the asset display data based on the first digital identity file corresponding to the target object; the first digital identity file includes the object public key and the target digital identity identifier that have been certified by the first identity verification authority.

[0008] This application provides a blockchain-based data authorization method, including:

[0009] Receive business requests associated with the target object and obtain the target digital identity carried in the business request;

[0010] Based on the target digital identity identifier, the first digital identity file and asset display data corresponding to the target object are obtained from the blockchain; the asset display data is generated by the data certificate distributed by the data issuing object to the target object and the private key corresponding to the target object.

[0011] Obtain the public key of the target object from the first digital identity file, verify the validity of the asset display data based on the public key, and obtain the data verification result corresponding to the asset display data.

[0012] If the data verification result indicates that the asset display data verification is valid, then the business processing procedure indicated by the business request will be executed for the target object.

[0013] One embodiment of this application provides a blockchain-based data authorization device, including:

[0014] The credential acquisition module is used to retrieve data credentials distributed by the data issuing entity to the target object in the blockchain; the target object belongs to the first query permission scope set by the data issuing entity for the data credentials on the blockchain;

[0015] The data generation module is used to generate asset display data corresponding to the target object based on the data credentials and the private key of the target object.

[0016] The data authorization module is used to store the asset display data on the blockchain and set a second query permission range for the asset display data on the blockchain, so that the data verification objects within the second query range can verify the validity of the asset display data based on the first digital identity file corresponding to the target object; the first digital identity file includes the object public key and the target digital identity identifier that have been certified by the first identity verification authority.

[0017] The device also includes:

[0018] The credential application module is used to submit the target digital identity identifier corresponding to the target object to the data issuing object, so that the data issuing object can distribute data credentials to the target object based on the first digital identity file associated with the target digital identity identifier; the target digital identity identifier and the object public key in the first digital identity file have a corresponding relationship.

[0019] The certificate issuance result receiving module is used to receive the certificate issuance result returned by the data issuing object; the certificate issuance result is used to indicate that the data certificate has been successfully stored in the blockchain, and the certificate issuance result includes the identification information corresponding to the data certificate;

[0020] The credential acquisition module is specifically used for:

[0021] By using identification information, the data certificate issued by the data issuing entity is downloaded from the blockchain and distributed to the target object.

[0022] The device also includes:

[0023] The identity registration module is used to submit the initial digital identity file corresponding to the target object to the first identity verification authority, so that the first identity verification authority can sign the initial digital identity file and generate the first digital identity file when the identity verification result of the target object indicates that the identity is legitimate.

[0024] The registration result receiving module is used to receive the identity registration result returned by the first identity verification authority; the identity registration result is used to indicate that the first digital identity file has been successfully stored in the blockchain.

[0025] The data generation module includes:

[0026] The credential signing unit is used to encrypt data credentials based on the object private key corresponding to the target object and generate a digital signature of the target object.

[0027] The combination unit is used to combine data credentials and the digital signature of the target object into asset display data corresponding to the target object.

[0028] The data generation module includes:

[0029] The declaration information filtering unit is used to obtain M declaration information from the data voucher and filter out N declaration information for display from the M declaration information; M and N are both positive integers, and N is less than or equal to M;

[0030] The declaration information modification unit is used to hide MN declaration information (excluding N declaration information) out of M declaration information information to obtain the modified MN declaration information information.

[0031] The declaration information signing unit is used to encrypt N declaration information messages and the modified MN declaration information messages based on the object private key corresponding to the target object, and generate a digital signature of the target object.

[0032] The data generation unit is used to determine the asset display data corresponding to the target object by taking N declaration information, the modified MN declaration information, and the digital signature of the target object.

[0033] The data authorization module includes:

[0034] The block generation unit is used to encapsulate asset display data into transaction data and encapsulate the transaction data into data blocks according to the order of the transaction data in the transaction pool.

[0035] The block broadcasting unit is used to broadcast data blocks in the blockchain network so that the blockchain nodes in the blockchain network can perform consensus processing on the data blocks;

[0036] The block writing unit is used to add the data block to the blockchain if the consensus result of the block corresponding to the data block indicates that the consensus is successful, and to set a second query permission scope for the asset display data in the blockchain.

[0037] The device also includes:

[0038] The affirmative vote counting module is used to obtain the block voting information broadcast by blockchain nodes in the blockchain network and count the number of affirmative votes in the block voting information;

[0039] The consensus success module is used to determine the consensus result of the block corresponding to the data block as successful if the number of positive votes is greater than or equal to a threshold.

[0040] One embodiment of this application provides a blockchain-based data authorization device, including:

[0041] The request receiving module is used to receive business requests associated with the target object and obtain the target digital identity identifier carried in the business request.

[0042] The data acquisition module is used to acquire the first digital identity file and asset display data corresponding to the target object from the blockchain based on the target digital identity identifier; the asset display data is generated by the data certificate distributed by the data issuing object to the target object and the private key corresponding to the target object;

[0043] The data verification module is used to obtain the object public key corresponding to the target object from the first digital identity file, verify the validity of the asset display data based on the object public key, and obtain the data verification result corresponding to the asset display data.

[0044] The successful verification module is used to execute the business processing procedure indicated by the business request for the target object if the data verification result indicates that the asset display data verification is valid.

[0045] The data verification module includes:

[0046] The first signature verification unit is used to verify the digital signature in the asset display data based on the object's public key. If the digital signature in the asset display data is correct, the second digital identity file corresponding to the data issuing object is obtained from the blockchain. The second digital identity file corresponds to the digital identity identifier of the data issuing object.

[0047] The second signature verification unit is used to determine that the second digital identity document meets the legality conditions if the digital identity of the data issuing object is issued by the second identity verification authority, and to verify the digital signature in the data certificate based on the public key in the second digital identity document.

[0048] The verification result determination unit is used to determine that the data verification result of the asset display data is valid if the digital signature in the data certificate is correct.

[0049] The device also includes:

[0050] The invalid verification module is used to generate a failure message for the target object if the data verification result indicates that the asset display data verification is invalid, and to notify the target object of the failure message.

[0051] One aspect of this application provides a computer device, including a memory and a processor. The memory is connected to the processor, the memory is used to store computer programs, and the processor is used to call the computer programs so that the computer device executes the method provided in one aspect of this application.

[0052] One aspect of this application provides a computer-readable storage medium storing a computer program adapted to be loaded and executed by a processor, so that a computer device having a processor performs the method provided in one aspect of this application.

[0053] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method provided in the above aspect.

[0054] In this embodiment, by obtaining data credentials distributed by a data issuing entity to a target object in the blockchain, and the target object falling within the first query permission range set by the data issuing entity for the data credentials on the blockchain, asset display data can be generated based on the data credentials and the target object's corresponding private key. This asset display data is then stored in the blockchain, where a second query permission range can be set for the asset display data. This means the asset display data can be authorized to data verification objects within the second query permission range. Therefore, only data verification objects within the second query permission range have the right to read the asset display data in the blockchain; that is, the target object only authorizes the asset display data to data verification objects within the second query permission range. When reading the asset display data in the blockchain, the data verification object can verify the validity of the asset display data through a first digital identity file in the blockchain. This first digital identity file may contain the object's public key and target digital identity identifier authenticated by a first identity verification authority, but does not contain the target object's real identity information, thus improving the target object's data security. Attached Figure Description

[0055] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0056] Figure 1 This is a schematic diagram of a network architecture provided in an embodiment of this application;

[0057] Figure 2 This is a schematic diagram of a layered structure of a blockchain network provided in an embodiment of this application;

[0058] Figure 3 This is a schematic diagram of a data authorization scenario based on decentralized digital identity provided in an embodiment of this application;

[0059] Figure 4 This is a flowchart illustrating a blockchain-based data authorization method provided in an embodiment of this application;

[0060] Figure 5 This is a schematic diagram of a decentralized identity recognition system provided in an embodiment of this application;

[0061] Figure 6 This is a schematic diagram of an identity authentication application process provided in an embodiment of this application;

[0062] Figure 7 This is a schematic diagram of a process for applying for an academic certificate, provided in an embodiment of this application.

[0063] Figure 8 This is a flowchart illustrating the authorization process for an academic certificate verification provided in an embodiment of this application;

[0064] Figure 9 This is a flowchart illustrating another blockchain-based data authorization method provided in an embodiment of this application;

[0065] Figure 10 This is a schematic diagram of a process for verifying asset display data provided in an embodiment of this application;

[0066] Figure 11 This is a schematic diagram of the structure of a blockchain-based data authorization device provided in an embodiment of this application;

[0067] Figure 12 This is a schematic diagram of another blockchain-based data authorization device provided in an embodiment of this application;

[0068] Figure 13This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0069] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0070] This application relates to blockchain technology. Blockchain is a decentralized infrastructure with distributed storage characteristics. Specifically, it is a data structure that organizes blocks in chronological order using a linked list-like manner. It can securely store data with sequential relationships that can be verified within the system, and uses cryptography to ensure that the data is immutable and unforgeable. Blockchain can be considered a distributed ledger, and the information data contained in each block on the blockchain is the ledger data of this distributed ledger.

[0071] The underlying blockchain platform can include processing modules such as basic services, smart contracts, and operation management. The basic service module is deployed on all blockchain node devices to verify the validity of business requests. After consensus is reached on valid requests, they are recorded in storage. For a new business request, the basic service first performs interface adaptation parsing and authentication (interface adaptation), then encrypts the business information using a consensus algorithm (consensus management), and transmits it completely and consistently to the shared ledger (network communication) for recording and storage. The smart contract module is responsible for contract registration, publication, triggering, and execution. Developers can define contract logic using a programming language and publish it to the blockchain (contract registration). Based on the contract terms, execution is triggered by calling keys or other events to complete the contract logic. It also provides functions for contract upgrades and cancellations. The operation management module is mainly responsible for deployment, configuration modification, contract settings, cloud adaptation, and real-time status visualization during product launch, such as alarms, network status management, and node device health status management.

[0072] This application also relates to cloud security, which can refer to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown behavior detection. It uses a large number of clients in a mesh network to detect anomalies in software behavior, obtain the latest information on Trojans and malicious programs on the Internet, and send it to the server for automatic analysis and processing.

[0073] Please see Figure 1 , Figure 1 This is a schematic diagram of a network architecture provided in an embodiment of this application. The network architecture may include a blockchain network, which may consist of multiple blockchain nodes. This application does not limit the number of blockchain nodes included in the blockchain network. Figure 1 Taking six blockchain nodes as an example, the blockchain nodes in the network are networked in a P2P (Peer-to-Peer) manner, and the blockchain nodes can communicate with each other according to the P2P protocol. All blockchain nodes in the network jointly follow the broadcast mechanism and consensus mechanism to ensure the immutability and forgery resistance of data on the blockchain, while realizing the decentralized and trustless characteristics of the blockchain.

[0074] In this application, blockchain nodes in the blockchain network can be user terminals, servers, or a system composed of user terminals and servers; no limitation is made in this regard. User terminals can include, but are not limited to, electronic devices such as PCs (Personal Computers), smartphones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices (such as smartwatches and smart bracelets), smart voice interaction devices, smart home appliances (such as smart TVs), and in-vehicle devices.

[0075] A server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0076] A blockchain, jointly maintained by blockchain nodes in a blockchain network, can consist of a series of blocks, also known as data blocks. After a block is created, consensus processing needs to be performed in the blockchain network. Only when consensus on the block is successful can the block be added to the blockchain (i.e., the distributed ledger). Blocks in the blockchain can be linked together in a chain structure according to their creation timestamps from smallest to largest.

[0077] In this context, visibility restrictions can be imposed on the data stored in the blockchain. For example, data A in the blockchain can be seen by a first object, and data B can be seen by both the first and second objects. Then, the first object has permission to read data A, while all other objects do not. Similarly, the first and second objects have permission to read data B, and so on. In other words, by restricting the visibility of data in the blockchain, the scope of authorization for data can be set to ensure data security.

[0078] It's important to note that decentralized digital identities (DIDs) for various objects can be registered through a decentralized identity authentication system. Within this system, a trusted higher-level authority can sign the DID documents of lower-level entities, and the certified DID documents (i.e., those signed by the higher-level authority) are stored on the blockchain. To verify the validity of a lower-level entity's DID, the DID document in the blockchain can be directly queried. This process allows for the issuance of DIDs sequentially from higher-level to lower-level entities. The lower-level entity's DID document displays its public key information, effectively binding the lower-level entity's DID identifier to its public key information.

[0079] Understandably, the aforementioned superior and subordinate organizations can be considered as objects that register decentralized digital identities in the decentralized identity authentication system. Based on the decentralized identity authentication system, by simply storing the decentralized digital identity files of each object on the blockchain, it is possible not only to ensure the authenticity and credibility of the identity data of each object, but also to protect the identity data of each object from being disclosed, and to ensure that the data of each object belongs to itself.

[0080] Please see Figure 2 , Figure 2 This is a schematic diagram of a layered structure of a blockchain network provided in an embodiment of this application. For example... Figure 2 As shown, combined with a decentralized identity authentication system, the layered structure of this blockchain network can consist of an application layer, a service interface layer, and a persistence layer.

[0081] The application layer can include decentralized digital identity issuers (DID issuers), decentralized digital identity holders (DID holders), and decentralized digital identity verifiers (DID verifiers). Decentralized digital identity issuers can issue verifiable claims (VCs), which are documents endorsing the attributes of certain objects. Decentralized digital identity holders are the holders of verifiable claims, and they can sign these claims to form verifiable presentations (VPs); these VPs can be used to demonstrate their identity to the decentralized digital identity verifiers. The decentralized digital identity verifiers can then verify the correctness of the verifiable presentations. All decentralized digital identity issuers, holders, and verifiers can be blockchain nodes within a blockchain network.

[0082] For ease of understanding, this application may refer to the decentralized digital identity issuer as the data issuing object, the decentralized digital identity holder as the target object, and the decentralized digital identity verification party as the data verification object. Verifiable statements can be considered as data credentials issued by authoritative institutions, such as graduation certificates issued by schools, ID cards, driver's licenses, marriage certificates, honorary certificates, and various types of qualification certificates issued by official institutions. This application does not limit this. Verifiable expressions can refer to the data that the decentralized digital identity holder wants to display to the decentralized digital identity verification party, that is, the asset display data that the target object authorizes to the data verification object.

[0083] The service interface layer may include a decentralized digital identity resolver (DID Resolver). This DID resolver can provide digital identity resolution services, query the corresponding decentralized digital identity file (e.g., DID Document) based on the decentralized digital identity identifier (e.g., DID), and also provide CRUD functions (e.g., create, search, update, delete, etc.) for the decentralized digital identity identifier.

[0084] The persistence layer can include a trusted blockchain and decentralized storage. The trusted blockchain can be used to store decentralized digital identity files of various objects in the application layer (decentralized digital identity issuers, decentralized digital identity holders, and decentralized digital identity verification providers, etc.), verifiable claims issued by decentralized digital identity issuers, and verifiable expressions generated by decentralized digital identity holders. Decentralized storage can refer to distributed storage, which can distribute data across multiple independent devices, meaning that numerous blockchain nodes can participate in data storage.

[0085] Please see Figure 3 , Figure 3 This is a schematic diagram illustrating a data authorization scenario based on decentralized digital identity, provided in an embodiment of this application. For example... Figure 3 As shown, the data authorization process based on decentralized digital identity can involve interaction between the target object 30a (decentralized digital identity holder), the data issuing object 30b (decentralized data identity issuer), the data verification object 30e (decentralized digital identity verification party), and the blockchain 30f. Before data authorization, the target object 30a, the data issuing object 30b, and the data verification object 30e all need to register their respective decentralized digital identity identifiers in the blockchain 30f, such as storing their corresponding decentralized digital identity files (e.g., DID files) in the blockchain 30f.

[0086] The decentralized digital identity (DID) can be formatted as "did:example:1234567abcde". The prefix "did" is fixed and indicates the type of the DID. "example" represents the DID method, which defines and manipulates the DID. "1234567abcde" represents the unique identifier string under the "example" method. A decentralized digital identity file (DID file) can be a detailed description of the DID. There is a one-to-one relationship between DID files. The DID file can include DID metadata and a DID public key, which can be used for digital signatures or encryption. Optionally, the DID can be stored by the object itself, while the DID file can be stored in Blockchain 30f to ensure its integrity. The DID can serve as an index for the DID file. The generation, querying, and updating of both the DID and the DID file can be handled by smart contracts.

[0087] The data issuer 30b can be a trusted authoritative institution, such as schools or government departments; the target object 30a can submit its decentralized digital identity (which can be referred to as the target digital identity for ease of understanding) to the data issuer 30b to apply for a verifiable declaration, such as a graduation certificate and degree certificate issued by a school, or an ID card or qualification certificate issued by an official department; the data issuer 30b can obtain the target digital identity submitted by the target object 30a and, through methods such as... Figure 2 The decentralized digital identity parser in the service interface layer illustrates parsing the target digital identity identifier. Based on the parsing result, it can query the corresponding decentralized digital identity file (which can be referred to as the first digital identity file, such as a DID file) from blockchain 30f. In other words, it reads the first digital identity file corresponding to the target digital identity identifier from blockchain 30f. When the data issuing object 30b confirms the correctness of the target object 30a's identity based on the first digital identity file, the data issuing object 30b can issue a verifiable statement (VC) for the target object 30a.

[0088] Target object 30a can store verifiable claims issued by data issuing object 30b. Of course, target object 30a can also apply for different types of verifiable claims from data issuing object 30b, or from other data issuing objects; that is, target object 30a can hold one or more verifiable claims, such as verifiable claim 30c, verifiable claim 30d, etc. The format of a verifiable claim can include claim metadata, the claim itself, and a proof. The claim metadata can include information such as data issuing object 30b, issuance date, and claim type. The claim can refer to one or more descriptions of a subject (e.g., a graduation certificate), such as the graduation certificate's claim including the object name, school name, graduation year, etc. The proof can store the digital signature of data issuing object 30b, used to verify the correctness and origin of the verifiable claim. Verifiable claims can be stored in specific software applications, or can be kept by the holder (target object 30a) themselves, or can be stored on the blockchain as personal private data.

[0089] When target object 30a cannot directly display the verifiable statement to data verification object 30e, it can package part of the information in the verifiable statement into a verifiable expression (VP). That is, target object 30a only authorizes part of the information in the verifiable statement to data verification object 30e, hiding the other part of the information. Alternatively, when target object 30a needs to display multiple verifiable statements to data verification object 30e, it can package multiple verifiable statements into a verifiable expression. After obtaining the verifiable expression authorized by target object 30a, data verification object 30e can read the corresponding first digital identity file based on the target digital identity identifier of target object 30a, verify the digital signature of the verifiable expression based on the public key in the first digital identity file, and verify whether the data issuing object of the verifiable statement associated with the verifiable expression is trustworthy. If the digital signature of the verifiable expression is correct, and the data issuing object of the verifiable statement associated with the verifiable expression is a trustworthy authority, then the verifiable expression can be determined to have passed verification.

[0090] The format of a verifiable expression may include expression metadata, a list of verifiable declarations, and a proof. The expression metadata may include information such as version, the list of verifiable declarations contains the content of the verifiable declarations shown to the data verification object 30e, and the proof may refer to the signature information of the target object 30a on the verifiable expression.

[0091] In this embodiment of the application, the validity of the asset display data is verified by the first digital identity file in the blockchain. The first digital identity file may contain the public key of the target object and the target digital identity identifier certified by the first identity verification authority, but does not contain the real identity information of the target object, which can improve the data security of the target object.

[0092] Please see Figure 4 , Figure 4 This is a flowchart illustrating a blockchain-based data authorization method provided in an embodiment of this application. It can be understood that this method can be executed by a computer device, which can be an electronic device used by the target object, and the computer device can be any blockchain node in the blockchain network. Figure 4 As shown, this blockchain-based data authorization method may include at least the following steps S101-S103:

[0093] Step S101: Obtain the data certificate distributed by the data issuing object to the target object in the blockchain; the target object belongs to the first query permission scope set by the data issuing object for the data certificate on the blockchain.

[0094] Specifically, in data authorization scenarios, after the data issuer releases a data certificate (such as a verifiable claim) for the target object, the data certificate can be stored on the blockchain (e.g., the aforementioned). Figure 3 In the corresponding embodiment, blockchain 30f is used, and a first query permission range is set on the blockchain for the data credential. Only objects within this first query permission range have the permission to read the data credential in the blockchain; objects outside this range do not have the permission to read the data credential in the blockchain. It is understood that the data credential is issued by the data issuing object to the target object; therefore, the first query permission range set for the data credential can include at least the target object and the data issuing object, meaning that both the target object and the data issuing object can read the data credential in the blockchain.

[0095] Furthermore, after the data certificate issued by the data issuing entity is successfully stored on the blockchain, the identification information of the data certificate can be returned to the target object. The target object can then retrieve its corresponding data certificate from the blockchain based on this identification information; that is, the identification information can serve as an index for retrieving the data certificate stored in the blockchain. In other words, when the target object requests to read its corresponding data certificate from the blockchain based on the identification information, it can be verified whether the target object has the permission to read the data certificate. If the target object falls within the first query permission range corresponding to the data certificate, it can be determined that the target object has the permission to read the data certificate, allowing it to retrieve the data certificate in the blockchain that matches the identification information. Each data certificate can correspond to a single identification information, which can be used to uniquely represent the data certificate.

[0096] Optionally, after the data issuing object issues a data certificate to the target object, it can directly return the data certificate to the target object, which will then save the data certificate. This application does not limit the storage method of the data certificate.

[0097] In one or more embodiments, before performing step S101, the target object first needs to apply for identity authentication from the first identity verification authority. After identity authentication is completed, it then applies for its own data credentials from the data issuing object. Specifically, the target object's identity authentication process may include: submitting an initial digital identity file (DID file) corresponding to the target object to the first identity verification authority, so that the first identity verification authority, when determining that the target object's identity authentication result indicates that the identity is legitimate, signs the initial digital identity file to generate a first digital identity file; at this time, the target object can receive the identity registration result returned by the first identity verification authority, which can be used to indicate that the first digital identity file has been successfully stored in the blockchain. Optionally, if the first identity verification authority determines that the target object's identity authentication result indicates that the identity is illegitimate, it can return an identity registration failure message to the target object, which is used to instruct the target object to reapply for identity authentication from the first identity verification authority.

[0098] The first identity verification authority (CREA) can refer to an authoritative institution used for identity authentication. The CREA's own digital identity file is certified by a trusted superior institution. After obtaining the initial digital identity file submitted by the target object, the CREA can verify the target object's identity. If the target object's identity is legitimate, it can sign the initial digital identity file to generate a first digital identity file. This first digital identity file contains the CREA's digital signature, indicating that it has been certified by the CREA. The CREA can store the first digital identity file on the blockchain. After successful storage on the blockchain, it can return an identity registration result to the target object, indicating that the target object's identity has been certified by the CREA. The first digital identity file corresponds to a target digital identity identifier, which can be stored by the target object itself and used as index information for reading the first digital identity file stored on the blockchain. The first digital identity file may also contain the target object's public key and recovery public key information in case the public key is lost.

[0099] The data credential application process for a target object may include: after obtaining authentication from a first identity verification authority, the target object may submit a target digital identity identifier to a data issuing object, so that the data issuing object can distribute data credentials to the target object based on a first digital identity file associated with the target digital identity identifier; the target digital identity identifier has a corresponding relationship with the object's public key in the first digital identity file; receiving the credential issuance result returned by the data issuing object; the credential issuance result is used to indicate that the data credential has been successfully stored in the blockchain, and the credential issuance result includes the identification information corresponding to the data credential.

[0100] When a data issuing entity obtains the target digital identity identifier submitted by a target object, it can parse the target digital identity identifier using a decentralized digital identity parser to obtain the parsing result. This parsing result is then passed to the blockchain, allowing the reading of the first digital identity file corresponding to the target digital identity identifier. The digital signature of the first identity verification authority within the first digital identity file can then be verified. For example, by using the public key in the digital identity file corresponding to the first identity verification authority, the digital signature in the first digital identity file can be decrypted. If decryption is successful, it indicates that the digital signature in the first digital identity file is correct, meaning the first digital identity file was indeed certified by the first identity verification authority. This confirms the target object's identity, and a data certificate can be issued to the target object. This data certificate can be stored on the blockchain and set to be visible to the target object, meaning the first query permission scope corresponding to the data certificate includes the target object. Of course, the data certificate is also visible to the data release object, meaning the data release object also falls within the first query permission scope corresponding to the data certificate.

[0101] Optionally, if the decryption of the digital signature in the first digital identity file using the public key in the digital identity file corresponding to the first identity verification authority fails, it indicates that the authenticity of the target object's identity cannot be determined temporarily, and the data issuing object cannot issue the data credential for it; then, a prompt message indicating that the credential issuance has failed can be returned to the target object. This prompt message is used to instruct the target object to reapply for the same data credential from the data issuing object, or to reapply for identity authentication.

[0102] After successfully storing a data credential in the blockchain and setting a first query permission scope for it, a credential publication result can be returned to the target object. This result may include the identification information corresponding to the data credential, as well as the first query permission scope corresponding to that data credential. The identification information can refer to the unique identifier generated for the data credential after it is successfully uploaded to the blockchain, serving as an index for the data credential stored in the blockchain. The first query permission scope can also be considered the authorization scope of the data credential; the data credential is only visible to objects within the first query permission scope.

[0103] Step S102: Generate asset display data corresponding to the target object based on the data certificate and the object private key corresponding to the target object.

[0104] Specifically, when a target object needs to apply for business processing from a data verification object, it needs to submit the required materials, such as one or more data credentials held by the target object. Based on the target object's private key, the data credentials held by the target object can be encrypted to generate a digital signature for the target object. Then, the data credentials and the target object's digital signature can be combined to form asset display data (verifiable representation) corresponding to the target object. The asset display data can involve one or more data credentials, and this asset display data can contain the full information of one or more data credentials, meaning the target object can authorize the data verification object to read the complete information from one or more data credentials. The target object's private key and the object's public key in the aforementioned first digital identity file form a key pair. The object's private key is managed by the target object itself and can be used to perform digital signature operations; the object's public key can be used to decrypt the digital signature generated by the object's private key.

[0105] Optionally, the required materials for the aforementioned business processing may only focus on a portion of the information in the data certificate. For example, if the data certificate is a graduation certificate, the required materials may only focus on the school and major information on the certificate. This allows the target object to hide or modify the remaining information in the data certificate, except for the school and major, to generate asset display data for presentation to the data verification object. For instance, M declarations can be obtained from the data certificate, and N declarations can be selected for display, where M and N are both positive integers, and N is less than or equal to M. Furthermore, the remaining MN declarations can be hidden, resulting in modified MN declarations. Based on the target object's private key, the N declarations and the modified MN declarations are encrypted to generate the target object's digital signature. The N declarations, the modified MN declarations, and the target object's digital signature are then used to determine the asset display data corresponding to the target object. Here, the asset display data may contain only a portion of the information in the data certificate, i.e., selectively authorizing only a portion of the data certificate, effectively protecting the target object's information and improving data security. Whether the asset display data contains full information about the data certificate or only partial information about the data certificate, the target object needs to sign it using its private key. In other words, the asset display data can carry the target object's digital signature.

[0106] Step S103: Store the asset display data on the blockchain and set a second query permission range for the asset display data on the blockchain so that the data verification object within the second query range can verify the validity of the asset display data based on the first digital identity file corresponding to the target object; the first digital identity file includes the object public key and the target digital identity identifier that have been certified by the first identity verification authority.

[0107] Specifically, after generating asset display data, the target object can store the asset display data on the blockchain and set the asset display data to be visible to the data verification object on the blockchain. That is, the second query permission scope set for the asset display data can include the data verification object.

[0108] The process of storing asset display data on the blockchain can be described as follows: The asset display data is encapsulated into transaction data, and then, according to the order of the transaction data in the transaction pool, it is encapsulated into data blocks. Each data block can contain multiple transactions from the transaction pool; that is, in addition to packaging the transaction data corresponding to the asset display data, it can also package other transaction data. The packaged data blocks can then be broadcast in the blockchain network to enable consensus processing among the blockchain nodes. In other words, each blockchain node participating in the data block consensus process can vote on the data block. If a blockchain node agrees with the data block, it can vote in favor; if it disagrees, it can vote against. Regardless of whether a blockchain node votes in favor or against a data block, it needs to broadcast its voting information so that each blockchain node in the network can collect the voting information from all other blockchain nodes.

[0109] The target object can be considered a blockchain node in the blockchain network. Therefore, the target object can obtain the block voting information broadcast by the blockchain nodes in the blockchain network and count the number of "yes" votes in the block voting information (i.e., the number of blockchain nodes in the blockchain network that voted in favor). If the number of "yes" votes is greater than or equal to a threshold, the consensus result of the data block is determined to be successful, and the data block can then be added to the blockchain. If the number of "yes" votes is less than the threshold, the consensus result of the data block is determined to be unsuccessful, i.e., the asset display data storage on the blockchain failed, and the storage operation on the blockchain needs to be performed again. The aforementioned threshold can be determined by the number of blockchain nodes participating in the consensus in the blockchain network and the consensus algorithm used. Different consensus algorithms may result in different thresholds.

[0110] It is understood that the on-chain storage process of the aforementioned first digital identity file and data certificate is the same as the on-chain storage process of asset display data. This application embodiment only uses asset display data as an example for description, and the on-chain storage process of other data will not be repeated.

[0111] The process of storing asset display data on the blockchain can essentially be understood as the consensus processing of data blocks containing that asset display data. Consensus processing in a blockchain network is the process of keeping the distributed ledger consistent across all blockchain nodes. All or some blockchain nodes in a blockchain network can participate in the consensus processing. These participating blockchain nodes collectively form the consensus committee of the blockchain network, and each participating blockchain node is a member of the consensus committee. In other words, the consensus committee of a blockchain network includes multiple participating blockchain nodes, and the consensus processing in the blockchain network is executed by the blockchain nodes within the consensus committee. For example, when a target object participates in the consensus processing of the aforementioned data block as a blockchain node, that target object can be considered a member of the consensus committee.

[0112] Specifically, the consensus processing in a blockchain network can be implemented based on a consensus algorithm, which may include, but is not limited to, Proof of Work (PoW), Proof of Stake (PoS), Delegated Proof of Stake (DPoS), and Practical Byzantine Fault Tolerance (PBFT) algorithms. This application does not limit the specific algorithms used. Each blockchain node in the consensus committee can execute the corresponding process of the consensus processing by running the consensus algorithm.

[0113] It's important to note that at a certain block height in a blockchain, one or more consensus processes are required to reach agreement among the various blockchain nodes in the consensus committee. Block height represents the number of blocks connected to the blockchain; it's a marker indicating the block's position within the blockchain. The default block height for the genesis block is 0. The first block after the genesis block has a block height of 1 (referred to as block 1), the second block after the genesis block has a block height of 2 (referred to as block 2), and so on. For example, if the current block height of a blockchain is 100 (referred to as block 100), this means that 100 blocks have been stacked on top of the genesis block, resulting in 101 blocks on the blockchain from the genesis block to block 100.

[0114] The consensus process at a specific block height in a blockchain refers to the process of reaching consensus on blocks awaiting inclusion in the blockchain network when the blockchain is at that particular block height. If the consensus on the block to be included is successful, the block is added to the blockchain, and the block height is incremented by 1. For example, the consensus process at block height 10 refers to the process of reaching consensus on blocks awaiting inclusion in the blockchain network (e.g., the aforementioned data block) when the blockchain is at block height 10. If the consensus on the data block is successful, the data block is added to the blockchain, making the block height increase from 10 to 11. If the consensus on the data block fails, the data block can be discarded, and a new block containing asset display data can be generated in the blockchain network, initiating a new round of consensus processing at block height 10.

[0115] When a data block is added to the blockchain, it indicates that the asset display data within that block has been successfully stored on the blockchain. This allows for the setting of a second query permission scope for the asset display data on the blockchain, specifying which objects can read the asset display data stored there. This application refers to all objects within the second query permission scope, excluding the target object itself, as data verification objects. These data verification objects can refer to business entities used to process business requests. The target object can proactively submit asset display data to the data verification object and initiate a business request (e.g., an onboarding request); alternatively, the target object can directly initiate a business request to the data verification object, allowing the data verification object to read the asset display data stored on the blockchain. The data verification object can verify the validity of the asset display data based on the target object's first digital identity file stored on the blockchain. When the asset display data passes the validity verification, it can execute the business processing procedure indicated by the aforementioned business request for the target object. The validity verification process for the asset display data can be found in [reference needed]. Figure 9 The relevant descriptions in the corresponding embodiments.

[0116] The following example uses an academic certificate as proof of data, and combines it with... Figures 5 to 8 A detailed description of the data authorization process based on decentralized digital identity is provided.

[0117] Please see Figure 5 , Figure 5 This is a schematic diagram of a decentralized identity recognition system provided in an embodiment of this application. For example... Figure 5As shown, Level 1 Institution A can be considered a trusted authoritative institution, such as a nationally recognized official institution. Level 1 Institution A can issue decentralized digital identity tokens (hereinafter referred to as digital identity tokens) to subordinate institutions or users (objects) based on its own private key. The subordinate institutions of Level 1 Institution A can include Level 2 Institutions B, C, and D, etc.; the private key of Level 1 Institution A and the public key in its own digital identity file form the master key pair in the decentralized identity recognition system; issuance refers to the process by which Level 1 Institution A uses its own private key to sign the digital identity file of a subordinate institution, indicating that the subordinate institution has passed the identity authentication of Level 1 Institution A. The authenticated digital identity file can be stored on the blockchain.

[0118] like Figure 5 As shown, Level 1 institution A can use its own private key to sign the digital identity file of Level 2 institution B, that is, to authenticate the identity of Level 2 institution B and determine its digital identity identifier. This process can be considered as Level 1 institution A issuing a digital identity identifier for Level 2 institution B. Similarly, Level 1 institution A can also issue digital identity identifiers for Level 2 institution C and Level 2 institution D.

[0119] Furthermore, each second-level institution can also use its own private key to issue digital identity identifiers to its subordinate institutions or users; for example, second-level institution B can issue a digital identity identifier to third-level institution E, second-level institution C can issue a digital identity identifier to user F, and second-level institution D can issue a digital identity identifier to third-level institution G. In short, each higher-level institution can use its own private key to issue digital identity identifiers to its subordinate institutions or users. Each institution's or user's digital identity file can bind a digital identity identifier to a specific public key, and all authenticated digital identity files can be stored on the blockchain. It should be noted that... Figure 5 The first-level, second-level, and third-level organizations shown are merely illustrative examples in the embodiments of this application. This application may also include more organizations or users at different levels, and this application does not limit them.

[0120] After obtaining a digital identity issued by a second-level institution C, user F can use this digital identity to apply for an academic certificate from a third-level institution E. In this case, user F can be considered the target, third-level institution E can be considered the data issuing object (e.g., a school), and the academic certificate can be considered a data credential. Third-level institution E can use a decentralized digital identity parser to query the digital identity file corresponding to user F's digital identity in the blockchain. If user F's identity is confirmed to be legitimate based on the digital identity file, then an academic certificate can be issued to user F. Third-level institution G can also use a decentralized digital identity parser to query the digital identity file corresponding to user F's digital identity in the blockchain and verify the academic certificate submitted by user F based on the digital identity file. In this case, third-level institution G can be considered the data verification object, and this third-level institution G can be a company.

[0121] Please see Figure 6 , Figure 6 This is a schematic diagram illustrating a process for applying for identity authentication provided in an embodiment of this application. For example... Figure 6 As shown, the application identity authentication process can be implemented by the following steps S201 to S205.

[0122] S201, User F submits their own digital identity document.

[0123] Specifically, when user F (the target object) wants to apply for identity verification from the second-level institution C (the first identity verification institution), he / she can submit his / her own digital identity file (initial digital identity file) to the second-level institution C; the digital identity file may contain user F's target digital identity identifier and user F's public key and other information.

[0124] S202, Level 2 agency C verifies the identity of user F and signs the digital identity document.

[0125] Specifically, the second-level institution C can receive the initial digital identity file submitted by user F and verify the information contained in the initial digital identity file and user F's identity to obtain the authentication result of user F. When the authentication result indicates that the identity is valid, the second-level institution C can use its private key to sign the digital identity file submitted by user F, obtaining a digital identity file carrying a digital signature (the first digital identity file), meaning that user F's digital identity has been authenticated by the second-level institution C. When the authentication result indicates that the identity is invalid, it means that there is a temporary problem with user F's identity, and authentication cannot be performed, that is, the digital identity file submitted by user F cannot be signed, and an authentication failure message is returned to user F.

[0126] S203, Level 2 institution C stores the signed digital identity file on the blockchain.

[0127] Specifically, after the second-level institution C signs the digital identity file of user F, the signed digital identity file can be stored in the blockchain. The storage process of the signed digital identity file can be referred to the relevant description in the aforementioned step S103, and will not be repeated here.

[0128] S204 returns the blockchain storage result.

[0129] Specifically, after the signed digital identity document is successfully stored on the blockchain, the blockchain can return the blockchain storage result to the second-level institution C. The blockchain storage result can be used to indicate that the signed digital identity document has been successfully stored on the blockchain, or it can be used to indicate that the signed digital identity document has failed to be stored on the blockchain.

[0130] S205, returns the identity registration result.

[0131] Specifically, after receiving the blockchain storage result returned by the blockchain, the second-level institution C can return the identity registration result to user F. If the blockchain storage result indicates successful on-chain storage, the identity registration result can be used to indicate that user F's identity authentication was successful; if the blockchain storage result indicates failed on-chain storage, the identity registration result can be used to indicate that user F's identity authentication was unsuccessful.

[0132] Please see Figure 7 , Figure 7 This is a schematic diagram illustrating a process for applying for an academic certificate, as provided in an embodiment of this application. Figure 7 As shown, the application identity authentication process can be implemented by the following steps S301 to S306.

[0133] S301, User F submits their target digital identity.

[0134] Specifically, after user F's identity is certified by the second-level institution C, he / she can submit his / her target digital identity to the third-level institution E (the data issuing object) in order to apply for an academic certificate.

[0135] S302, Level 3 entity E queries user F's digital identity file on the blockchain using the target digital identity identifier.

[0136] Specifically, the third-level institution E can obtain the target digital identity identifier submitted by user F. Based on the target digital identity identifier, it can query the digital identity file of user F from the blockchain (the digital identity file here carries the digital signature of the second-level institution C).

[0137] S303 returns the blockchain query results.

[0138] Specifically, after retrieving user F's digital identity file from the blockchain, the blockchain can return the query result, i.e., user F's digital identity file, to a third-level institution E.

[0139] S304, verify the signature of user F's digital identity document, confirm user F's identity, and issue an academic certificate.

[0140] Specifically, the third-level institution E can verify the correctness of the digital signature in user F's digital identity file based on the public key in the digital identity file of the second-level institution C. If the digital signature in user F's digital identity file is correct, user F's identity can be confirmed, and an academic certificate can be issued to user F. If the digital signature in user F's digital identity file is incorrect, user F's identity can be confirmed as incorrect, and an academic certificate will not be issued to user F at this time; that is, user F does not meet the conditions for issuing an academic certificate at this time.

[0141] S305, Level 3 institution E stores user F's academic certificate on the blockchain and sets the academic certificate to be visible to user F.

[0142] Specifically, third-level institution E can store the academic certificate issued to user F on the blockchain and set a first query permission scope for the academic certificate on the blockchain. This first query permission scope includes user F, meaning that the academic certificate is visible to user F. For example, the first query permission scope can only include user F and third-level institution E. In this case, only user F and third-level institution E can query the academic certificate on the blockchain. Other institutions or users do not have the right to query the academic certificate, which can effectively protect user F's academic certificate from being leaked.

[0143] S306, Return to setting results.

[0144] Specifically, the third-level institution E can return the first query permission range set for the academic certificate on the blockchain and the identification information of the academic certificate to user F. If user F belongs to the first query permission range, it means that he or she has the right to query the academic certificate in the blockchain; if user F does not belong to the first query permission range, it means that he or she does not have the right to query the academic certificate in the blockchain.

[0145] Optionally, in addition to returning the identification information of the academic certificate to user F, the third-level institution E may not need to return the first query permission scope to user F. It only needs to notify user F whether it has the permission to query the academic certificate in the blockchain. This application does not limit this.

[0146] Please see Figure 8 , Figure 8 This is a flowchart illustrating the authorization process for an academic certificate verification provided in an embodiment of this application. For example... Figure 8 As shown, the application identity authentication process can be implemented by the following steps S401 to S404.

[0147] S401, User F reads academic certificate proof.

[0148] Specifically, when user F falls within the scope of the first query authority, user F can query the academic certificate on the blockchain through the identification information to obtain the academic certificate issued by the third-level institution E for user F.

[0149] S402, User F generates a verifiable representation based on the learning certificate.

[0150] Specifically, user F can use their private key to encrypt the learning certificate proof in order to generate a verifiable representation (asset display data) for display to the authorized object (data verification object). The process of generating this verifiable representation can be found in the relevant description in step S102 above, and will not be repeated here.

[0151] S403, User F stores the verifiable representation to the blockchain and sets the visibility of the verifiable representation on the blockchain.

[0152] S404 indicates that the expression settings were successfully verified.

[0153] Specifically, user F can store a verifiable representation on the blockchain. When the verifiable representation is successfully stored on the blockchain, the blockchain can set the visibility of the verifiable representation, that is, set a second query permission range for the verifiable representation, and then return a prompt message to user F indicating that the setting is successful.

[0154] Understandably, multiple objects can store data that requires authorization on the blockchain, and by setting visibility for the data stored on the blockchain, they can exchange data on the blockchain.

[0155] In this embodiment, only data verification objects within the second query permission scope have the right to read asset display data in the blockchain. That is, the target object only authorizes asset display data to data verification objects within the second query permission scope. When reading asset display data in the blockchain, the data verification object can verify the validity of the asset display data through the first digital identity file in the blockchain. The first digital identity file can contain the public key of the target object certified by the first identity verification authority and the target digital identity identifier, and use it to prove its identity to the data verification object without having to provide the real identity information of the target object, which can improve the data security of the target object. The target object can generate full or partial information according to actual needs and authorize the corresponding data verification object, that is, selectively authorize its own information on the blockchain, thereby improving the flexibility of the data authorization scope and further enhancing data security. It has the characteristics of decentralization, identity self-control, and trusted on-chain data exchange.

[0156] Please see Figure 9 , Figure 9 This is a flowchart illustrating another blockchain-based data authorization method provided in this application embodiment. It can be understood that this method can be executed by a computer device, which can be an electronic device used by the data verification object, and the computer device can be any blockchain node in the blockchain network. Figure 9 As shown, this blockchain-based data authorization method may include at least the following steps S501-S504:

[0157] Step S501: Receive a business request associated with the target object and obtain the target digital identity identifier carried in the business request.

[0158] Specifically, when a target object wants to apply for a service from a data verification object, it can provide the data verification object with the necessary materials and information for the service (e.g., proof of academic qualifications) and initiate a service request. This service request can be for employment, a loan, a purchase, etc., and this application does not limit its scope. After the target object initiates a service request to the data verification object, the data verification object can receive the service request and obtain the target's digital identity identifier carried in the service request.

[0159] Step S502: Based on the target digital identity identifier, obtain the first digital identity file and asset display data corresponding to the target object in the blockchain; the asset display data is generated by the data certificate distributed by the data issuing object to the target object and the object private key corresponding to the target object.

[0160] Specifically, the data verification object can use the target digital identity identifier as index information to query the first digital identity file and asset display data corresponding to the target object from the blockchain. The blockchain can return the query results to the data verification object, which are the first digital identity file and asset display data. The asset display data can refer to a verifiable representation generated by the target object using its own object private key to encrypt the data credentials distributed by the data issuing object to the target object. The asset display data can be considered as data authorized by the target object to the data verification object, and can contain full information of one or more data credentials, or partial information of one or more data credentials. The generation process of the asset display data can be found in the relevant description in step S102 above, and will not be repeated here.

[0161] Step S503: Obtain the object public key corresponding to the target object from the first digital identity file, verify the validity of the asset display data based on the object public key, and obtain the data verification result corresponding to the asset display data.

[0162] Specifically, the data verification object can obtain the public key corresponding to the target object from the first digital identity file. This public key can then be used to verify the correctness of the digital signature in the asset display data. Furthermore, the data verification object can also verify the second digital identity file of the data issuing object to ensure that the public key in the second digital identity file is trustworthy. This confirms that the first digital identity file issued by the data issuing object is valid. If the first digital identity file is determined to be valid, and the digital signature in the asset display data is correct, then the data verification result corresponding to the asset display data is considered valid. If the digital signature in the asset display data is incorrect, then the data verification result corresponding to the asset display data is considered invalid.

[0163] The verification process for asset display data can include: the data verification object can verify the digital signature in the asset display data using the object's public key. If the digital signature in the asset display data is correct, a second digital identity file corresponding to the data issuing object is obtained from the blockchain. This second digital identity file corresponds to the digital identity identifier of the data issuing object. If the data verification object confirms that the digital identity identifier of the data issuing object was indeed issued by the second identity verification authority, the second digital identity file can be determined to meet the legitimacy conditions. Then, the digital signature in the data certificate can be verified using the public key in the second digital identity file. If the digital signature in the data certificate is correct, it can be determined that the data certificate was indeed issued by the data issuing authority, thus confirming that the data verification result of the asset display data is valid. Here, it can be assumed that the data issuing object is an object trusted by the data verification object. The legitimacy condition can be considered as the correctness of the digital signature in the data identity file, thus ensuring that the digital identity file was indeed issued by its superior object, meaning that the public key in the data identity file is trustworthy.

[0164] Optionally, data verification objects can be based on the trust chain corresponding to different levels of objects (e.g., Figure 5 The digital identity files of the first-level organization A, the second-level organization B, and the third-level organization E are shown below. The digital identity files of each object are verified sequentially from lower to higher levels. When all digital identity files of each object meet the legality requirements and the digital signature in the asset display data is correct, the data verification result corresponding to the asset display data can be determined as valid. When any digital identity file of any object fails to meet the legality requirements, or the digital signature in the asset display data is incorrect, the data verification result corresponding to the asset display data can be determined as invalid.

[0165] like Figure 5As shown, when the third-level institution G (the data verification object) verifies the asset display data of user F (the target object), which may include all or part of the information in the academic certificate, it can first verify the digital signature in the asset display data based on user F's public key. After confirming that the digital signature in the asset display data is correct, it can further verify the digital signature in the digital identity file of the third-level institution E (the data verification object). When the digital signature in the digital identity file corresponding to the third-level institution E is correct, it indicates that the digital identity file of the third-level institution E was indeed issued by the second-level institution B (the second identity verification authority), and it also indicates that the public key in the digital identity file of the third-level institution E is trustworthy. Furthermore, it can verify the digital signature in the digital identity file corresponding to the second-level institution B. When the digital signature in the digital identity file corresponding to the second-level institution B is correct, it indicates that the digital identity file of the second-level institution B was indeed issued by the first-level institution A (the third identity verification authority), and it also indicates that the public key in the digital identity file of the second-level institution B is trustworthy. Since Level 1 Institution A is an institution trusted by all objects in the decentralized identity recognition system, it can be determined that the data verification result corresponding to the asset display data is valid.

[0166] Step S504: If the data verification result indicates that the asset display data verification is valid, then execute the business processing procedure indicated by the business request for the target object.

[0167] Specifically, if the data verification result indicates that the asset display data verification is valid, it means that the asset display data provided by the target object has passed the verification by the data verification object, and the business processing procedure indicated by the business request can then be executed for the target object. If the data verification result indicates that the asset display data verification is invalid, it means that the asset display data provided by the target object has failed the verification by the data verification object, and a failure message can be generated for the target object and notified. Assuming the business request is an onboarding request, when the asset display data verification is valid, the onboarding procedures can be processed for the target object; when the asset display data verification is invalid, the target object can be notified that the onboarding application has not passed and the onboarding procedures cannot be processed.

[0168] Please see Figure 10 , Figure 10 This is a schematic diagram illustrating a process for verifying asset display data provided in an embodiment of this application. For example... Figure 10 As shown, the embodiments of this application are the same as those described above. Figure 5 As shown, taking the data credential as an academic certificate as an example, the verification process of the asset display data can be achieved by steps S601 to S607.

[0169] S601, Level 3 G reads the verifiable representation of user F.

[0170] Specifically, when user F (target object) authorizes a verifiable representation (asset display data) to a third-level institution G (data verification object), the third-level institution G can read the verifiable representation stored in the blockchain.

[0171] S602, Level 3 organization G reads user F's digital identity file based on user F's target digital identity identifier.

[0172] Specifically, the third-level institution G can obtain the target digital identity identifier of user F, and then use the target digital identity identifier of user F as index information to read the digital identity file (first digital identity file) of user F in the blockchain.

[0173] S603, Level 3 authority G verifies the signature in the verifiable representation based on user F's public key.

[0174] Specifically, the third-level organization G can obtain user F's public key from user F's digital identity file. Based on user F's public key, it can verify the digital signature in the verifiable expression. For example, it can use user F's public key to decrypt the digital signature in the verifiable expression. If the decryption is successful, it means that the digital signature in the verifiable expression is correct; if the decryption fails, it means that the digital signature in the verifiable expression is incorrect, and a verification failure message can be returned to user F.

[0175] S604, Level 3 organization G reads the digital identity file of Level 3 organization E and obtains that the issuing authority of the digital identity identifier of Level 3 organization E is Level 2 organization B.

[0176] Specifically, Level 3 institution G can read Level 3 institution E's digital identity file from the blockchain based on Level 3 institution E's (data issuing object) digital identity identifier, and based on Level 3 institution E's digital identity file, it can determine that Level 3 institution E's digital identity file was issued by Level 2 institution B.

[0177] S605 verifies the digital identity file of the third-level organization E, ensuring that the public key in the digital identity file of the third-level organization E is trustworthy.

[0178] Specifically, Level 3 institution G can verify the digital signature in the digital identity file corresponding to Level 3 institution E. If the digital signature in the digital identity file corresponding to Level 3 institution E is confirmed to be correct, then the public key in the digital identity file of Level 3 institution E can be determined to be trustworthy.

[0179] S606, using the public key of Level 3 Authority E to verify that the academic certificate was indeed issued by Level 3 Authority E.

[0180] S607, verification successful. Notify user F to complete the onboarding process.

[0181] Specifically, the third-level institution G can use the public key of the third-level institution E to verify the academic certificate associated with the verifiable expression. If the digital signature in the academic certificate is confirmed to be correct through the public key of the third-level institution E, it can be determined that the academic certificate was indeed issued by the third-level institution E. Consequently, it can be determined that the verifiable expression of user F has been successfully verified, and user F can be notified to complete the onboarding process.

[0182] In this embodiment, when a data verification object reads asset display data in the blockchain, it can verify the validity of the asset display data through a multi-layered identity trust chain associated with the first digital identity file in the blockchain. The first digital identity file can contain the object's public key and the target digital identity identifier, which are authenticated by the first identity verification institution for the target object, and use them to prove its identity to the data verification object without providing the target object's real identity information, thereby improving the target object's data security. The target object can generate full or partial information and authorize it to the corresponding data verification object according to actual needs, that is, selectively authorize its own information on the blockchain, thereby improving the flexibility of the data authorization scope and further enhancing data security. It has the characteristics of decentralization, autonomous and controllable identity, and trusted on-chain data exchange.

[0183] It is understood that the specific implementation of this application may involve the identity information of users or organizations. When the above embodiments of this application are applied to specific products or technologies, the permission or consent of the relevant users is required, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0184] Please see Figure 11 , Figure 11 This is a schematic diagram of a blockchain-based data authorization device provided in an embodiment of this application. It can be understood that this blockchain-based data authorization device 1 can be applied to a computer device used by a target object, and the computer device used by the target object can be any blockchain node in the blockchain network. For example... Figure 11 As shown, the blockchain-based data authorization device 1 may include: a credential acquisition module 11, a data generation module 12, and a data authorization module 13;

[0185] The credential acquisition module 11 is used to acquire data credentials distributed by the data issuing object to the target object in the blockchain; the target object belongs to the first query permission range set by the data issuing object for the data credentials on the blockchain;

[0186] Data generation module 12 is used to generate asset display data corresponding to the target object based on the data certificate and the object private key corresponding to the target object;

[0187] The data authorization module 13 is used to store the asset display data on the blockchain and set a second query permission range for the asset display data on the blockchain, so that the data verification object within the second query range can verify the validity of the asset display data based on the first digital identity file corresponding to the target object; the first digital identity file includes the object public key and the target digital identity identifier that have been certified by the first identity verification authority.

[0188] The specific functional implementation methods of the credential acquisition module 11, data generation module 12, and data authorization module 13 can be found in [reference needed]. Figure 4 Steps S101-S103 in the corresponding embodiments will not be described again here.

[0189] In one or more embodiments, the blockchain-based data authorization device 1 further includes: an identity registration module 14, a registration result receiving module 15, a credential application module 16, and a publication result receiving module 17;

[0190] The identity registration module 14 is used to submit the initial digital identity file corresponding to the target object to the first identity verification authority, so that the first identity verification authority can sign the initial digital identity file and generate the first digital identity file when the identity verification result of the target object indicates that the identity is legitimate.

[0191] The registration result receiving module 15 is used to receive the identity registration result returned by the first identity verification authority; the identity registration result is used to indicate that the first digital identity file has been successfully stored in the blockchain.

[0192] The credential application module 16 is used to submit the target digital identity identifier corresponding to the target object to the data issuing object, so that the data issuing object can distribute data credentials to the target object based on the first digital identity file associated with the target digital identity identifier; the target digital identity identifier has a corresponding relationship with the object public key in the first digital identity file.

[0193] The publishing result receiving module 17 is used to receive the certificate publishing result returned by the data issuing object; the certificate publishing result is used to indicate that the data certificate has been successfully stored in the blockchain, and the certificate publishing result includes the identification information corresponding to the data certificate;

[0194] The credential acquisition module 11 is specifically used for:

[0195] By using identification information, the data certificate issued by the data issuing entity is downloaded from the blockchain and distributed to the target object.

[0196] The specific implementation methods of the identity registration module 14, registration result receiving module 15, credential application module 16, and result publication receiving module 17 can be found in [link to relevant documentation]. Figure 4 Step S101 in the corresponding embodiment will not be described again here.

[0197] In one or more embodiments, the data generation module 12 includes: a credential signing unit 121, a combination unit 122, a declaration information filtering unit 123, a declaration information modification unit 124, a declaration information signing unit 125, and a data generation display unit 126.

[0198] The credential signing unit 121 is used to encrypt the data credential based on the object private key corresponding to the target object and generate a digital signature of the target object.

[0199] Combination unit 122 is used to combine data credentials and the digital signature of the target object into asset display data corresponding to the target object.

[0200] The declaration information filtering unit 123 is used to obtain M declaration information from the data certificate and filter out N declaration information for display from the M declaration information; M and N are both positive integers, and N is less than or equal to M;

[0201] The declaration information modification unit 124 is used to hide the MN declaration information (excluding the N declaration information) out of the M declaration information to obtain the modified MN declaration information.

[0202] The declaration information signing unit 125 is used to encrypt N declaration information and the modified MN declaration information based on the object private key corresponding to the target object, and generate a digital signature of the target object.

[0203] The data generation unit 126 is used to determine the asset display data corresponding to the target object by taking N declaration information, the modified MN declaration information, and the digital signature of the target object.

[0204] The specific functional implementation methods of the voucher signature unit 121, the combination unit 122, the declaration information filtering unit 123, the declaration information modification unit 124, the declaration information signature unit 125, and the display data generation unit 126 can be found in [reference needed]. Figure 4Step S102 in the corresponding embodiment will not be described again here. Specifically, when the credential signing unit 121 and the combination unit 122 perform their respective operations, the declaration information filtering unit 123, the declaration information modification unit 124, the declaration information signing unit 125, and the display data generation unit 126 all pause their operations; when the declaration information filtering unit 123, the declaration information modification unit 124, the declaration information signing unit 125, and the display data generation unit 126 perform their respective operations, the credential signing unit 121 and the combination unit 122 all pause their operations.

[0205] In one or more embodiments, the data authorization module 13 includes: a block generation unit 131, a block broadcasting unit 132, and a block writing unit 133;

[0206] Block generation unit 131 is used to encapsulate asset display data into transaction data and encapsulate transaction data into data blocks according to the order of transaction data in the transaction pool.

[0207] Block broadcasting unit 132 is used to broadcast data blocks in the blockchain network so that blockchain nodes in the blockchain network can perform consensus processing on the data blocks;

[0208] The block writing unit 133 is used to add the data block to the blockchain if the consensus result of the block corresponding to the data block indicates that the consensus is successful, and to set a second query permission range for the asset display data in the blockchain.

[0209] Optionally, the blockchain-based data authorization device 1 also includes: a vote counting module 18 and a consensus success module 19;

[0210] The affirmative vote counting module 18 is used to obtain the block voting information broadcast by the blockchain nodes in the blockchain network and count the number of affirmative votes in the block voting information.

[0211] The consensus success module 19 is used to determine the consensus result of the block corresponding to the data block as successful if the number of positive votes is greater than or equal to the threshold.

[0212] The specific implementation methods of the block generation unit 131, block broadcasting unit 132, block writing unit 133, vote counting module 18, and consensus success module 19 can be found in [reference needed]. Figure 4 Step S103 in the corresponding embodiment will not be described again here.

[0213] In this embodiment, only data verification objects within the second query permission scope have the right to read asset display data in the blockchain. That is, the target object only authorizes asset display data to data verification objects within the second query permission scope. When reading asset display data in the blockchain, the data verification object can verify the validity of the asset display data through the first digital identity file in the blockchain. The first digital identity file can contain the object public key and the target digital identity identifier certified by the first identity verification authority for the target object, and use it to prove its identity to the data verification object without having to provide the target object's real identity information, which can improve the data security of the target object. The target object can generate full or partial information according to actual needs and authorize the corresponding data verification object, that is, selectively authorize its own information on the blockchain, thereby improving the flexibility of the data authorization scope and further enhancing data security.

[0214] Please see Figure 12 , Figure 12 This is a schematic diagram of another blockchain-based data authorization device provided in this application embodiment. It can be understood that this blockchain-based data authorization device 2 can be applied to the computer device corresponding to the data verification object, and the computer device corresponding to the data verification object can be any blockchain node in the blockchain network. For example... Figure 12 As shown, the blockchain-based data authorization device 2 may include: a request receiving module 21, a data acquisition module 22, a data verification module 23, and a verification success module 24.

[0215] Request receiving module 21 is used to receive business requests associated with the target object and obtain the target digital identity identifier carried in the business request;

[0216] The data acquisition module 22 is used to acquire the first digital identity file and asset display data corresponding to the target object in the blockchain based on the target digital identity identifier; the asset display data is generated by the data certificate distributed by the data issuing object to the target object and the object private key corresponding to the target object;

[0217] Data verification module 23 is used to obtain the object public key corresponding to the target object from the first digital identity file, verify the validity of the asset display data based on the object public key, and obtain the data verification result corresponding to the asset display data.

[0218] The successful verification module 24 is used to execute the business processing procedure indicated by the business request for the target object if the data verification result indicates that the asset display data verification is valid.

[0219] The specific implementation methods of the request receiving module 21, data acquisition module 22, data verification module 23, and verification success module 24 can be found in [reference needed]. Figure 9 Steps S201-S204 in the corresponding embodiments will not be described again here.

[0220] In one or more embodiments, the data verification module 23 includes: a first signature verification unit 231, a second signature verification unit 232, and a verification result determination unit 233;

[0221] The first signature verification unit 231 is used to verify the digital signature in the asset display data based on the object's public key. If the digital signature in the asset display data is correct, the second digital identity file corresponding to the data issuing object is obtained from the blockchain. The second digital identity file corresponds to the digital identity identifier of the data issuing object.

[0222] The second signature verification unit 232 is used to determine that the second digital identity document meets the legality conditions if the digital identity of the data issuing object is issued by the second identity verification authority, and to verify the digital signature in the data certificate according to the public key in the second digital identity document.

[0223] Verification result determination unit 233 is used to determine that the data verification result of the asset display data is valid if the digital signature in the data certificate is correct.

[0224] Optionally, the blockchain-based data authorization device 2 further includes: an invalidation verification module 25;

[0225] The invalid verification module 25 is used to generate a failure message for the target object if the data verification result indicates that the asset display data verification is invalid, and to notify the target object of the failure message.

[0226] The specific functional implementation of the first signature verification unit 231, the second signature verification unit 232, the verification result determination unit 233, and the invalidation verification module 25 can be found in [reference needed]. Figure 9 Steps S203-S204 in the corresponding embodiments will not be described again here.

[0227] In this embodiment, when a data verification object reads asset display data in the blockchain, it can verify the validity of the asset display data through a multi-layered identity trust chain associated with the first digital identity file in the blockchain. The first digital identity file can contain the object's public key and the target digital identity identifier, which are authenticated by the first identity verification institution for the target object, and can be used to prove its identity to the data verification object without providing the target object's real identity information, thereby improving the data security of the target object. The target object can generate full or partial information and authorize the corresponding data verification object according to actual needs, that is, selectively authorize its own information on the blockchain, thereby improving the flexibility of the data authorization scope and further enhancing data security.

[0228] Please see Figure 13 , Figure 13 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 13 As shown, the computer device 1000 can be a user terminal or a server; this is not a limitation. For ease of understanding, this application takes the computer device as a user terminal as an example. The computer device 1000 may include: a processor 1001, a network interface 1004, and a memory 1005. Furthermore, the computer device 1000 may also include: a user interface 1003, and at least one communication bus 1002. The communication bus 1002 is used to implement communication between these components. The user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wi-Fi interface). The memory 1004 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk storage device. The memory 1005 may optionally be at least one storage device located remotely from the aforementioned processor 1001. Figure 13 As shown, the memory 1005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a device control application.

[0229] The network interface 1004 in the computer device 1000 can also provide network communication functions, and the optional user interface 1003 can also include a display screen and a keyboard. Figure 13 In the computer device 1000 shown, the network interface 1004 provides network communication functionality; the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application program stored in the memory 1005 to achieve:

[0230] Retrieve data credentials distributed by the data issuer to the target object in the blockchain; the target object belongs to the first query permission scope set by the data issuer for the data credentials on the blockchain;

[0231] Based on the data credentials and the private key of the target object, generate asset display data corresponding to the target object;

[0232] The asset display data is stored on the blockchain, and a second query permission range is set on the blockchain for the asset display data, so that the data verification object within the second query range can verify the validity of the asset display data based on the first digital identity file corresponding to the target object; the first digital identity file includes the object public key and the target digital identity identifier that have been certified by the first identity verification authority.

[0233] Alternatively, processor 1001 can achieve the following:

[0234] Receive business requests associated with the target object and obtain the target digital identity carried in the business request;

[0235] Based on the target digital identity identifier, the first digital identity file and asset display data corresponding to the target object are obtained from the blockchain; the asset display data is generated by the data certificate distributed by the data issuing object to the target object and the private key corresponding to the target object.

[0236] Obtain the public key of the target object from the first digital identity file, verify the validity of the asset display data based on the public key, and obtain the data verification result corresponding to the asset display data.

[0237] If the data verification result indicates that the asset display data verification is valid, then the business processing procedure indicated by the business request will be executed for the target object.

[0238] It should be understood that the computer device 1000 described in the embodiments of this application can execute the foregoing text. Figure 4 , Figures 6 to 10 The description of the blockchain-based data authorization method in any of the corresponding embodiments can also be performed as described above. Figure 12 The description of the blockchain-based data authorization device 1 in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.

[0239] Furthermore, it should be noted that this application embodiment also provides a computer-readable storage medium, which stores a computer program executed by the aforementioned blockchain-based data authorization device 1. The computer program includes program instructions, and when the processor executes the program instructions, it can execute the aforementioned... Figure 4 , Figures 6 to 10The description of the blockchain-based data authorization method in any corresponding embodiment is already provided and will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the computer-readable storage medium embodiments related to this application, please refer to the description of the method embodiments of this application. As an example, program instructions can be deployed and executed on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network. These multiple computing devices distributed across multiple locations and interconnected via a communication network can constitute a blockchain system.

[0240] Furthermore, it should be noted that this application also provides a computer program product or computer program, which may include computer instructions, which may be stored in a computer-readable storage medium. The processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor may execute the computer instructions, causing the computer device to perform the aforementioned actions. Figure 4 , Figures 6 to 10 The description of the blockchain-based data authorization method in any corresponding embodiment is already provided and will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the computer program products or computer program embodiments related to this application, please refer to the description of the method embodiments of this application.

[0241] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0242] The steps in the method of this application embodiment can be adjusted, combined, or deleted according to actual needs.

[0243] The modules in the device of this application embodiment can be merged, divided, and deleted according to actual needs.

[0244] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0245] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.

Claims

1. A data authorization method based on blockchain, characterized in that, include: In the blockchain, obtain data credentials distributed by the data issuing entity to the target object; The target object belongs to the first query permission range set by the data issuing object for the data certificate on the blockchain; Obtain M declaration information from the data certificate, and select N declaration information for display from the M declaration information; M and N are both positive integers, and N is less than or equal to M; Hide the MN declarations that are not part of the N declarations among the M declarations to obtain the modified MN declarations; Based on the private key of the target object, the N declaration information and the modified MN declaration information are encrypted to generate a digital signature of the target object; The N declarations, the modified MN declarations, and the digital signature of the target object are determined as the asset display data corresponding to the target object. The asset display data is stored in the blockchain. A second query permission range, determined by the target object, is set on the blockchain for the asset display data. This allows data verification objects within the second query range to verify the validity of the asset display data based on the first digital identity file corresponding to the target object. The first digital identity file includes a public key of an object certified by a first identity verification authority and a target digital identity identifier. The data verification object is used to verify the digital identity files of one or more objects sequentially from lower to higher levels according to the trust chain corresponding to one or more objects at different levels. It is also used to determine that the data verification result corresponding to the asset display data is valid when the digital identity files of one or more objects all meet the legality conditions and the digital signature in the asset display data is correct. The one or more objects include at least the data issuing object and the first identity verification authority.

2. The method according to claim 1, characterized in that, Also includes: The target digital identity identifier corresponding to the target object is submitted to the data issuing object, so that the data issuing object distributes the data credential to the target object based on the first digital identity file associated with the target digital identity identifier; the target digital identity identifier has a corresponding relationship with the object public key in the first digital identity file. Receive the certificate issuance result returned by the data issuing object; the certificate issuance result is used to indicate that the data certificate has been successfully stored in the blockchain, and the certificate issuance result includes the identification information corresponding to the data certificate; The process of obtaining data credentials distributed by the data issuing object to the target object in the blockchain includes: Using the identification information, the data credentials distributed by the data issuing object to the target object are downloaded from the blockchain.

3. The method according to claim 2, characterized in that, Also includes: The first identity verification authority submits the initial digital identity file corresponding to the target object to the first identity verification authority, so that the first identity verification authority signs the initial digital identity file when the identity verification result of the target object indicates that the identity is legitimate, thereby generating the first digital identity file; Receive the identity registration result returned by the first identity verification authority; the identity registration result is used to indicate that the first digital identity file has been successfully stored in the blockchain.

4. The method according to claim 1, characterized in that, The step of storing the asset display data in the blockchain and setting a second query permission range for the asset display data on the blockchain includes: The asset display data is encapsulated into transaction data, and the transaction data is encapsulated into data blocks according to the order of the transaction data in the transaction pool; The data block is broadcast in the blockchain network so that the blockchain nodes in the blockchain network can perform consensus processing on the data block; If the consensus result of the block corresponding to the data block indicates that the consensus was successful, then the data block is added to the blockchain, and a second query permission range is set for the asset display data in the blockchain.

5. A data authorization method based on blockchain, characterized in that, include: Within the scope of the second query permission set by the target object for the asset display data, receive business requests associated with the target object and obtain the target digital identity identifier carried by the business request; Based on the target digital identity identifier, the first digital identity file and asset display data corresponding to the target object are obtained in the blockchain; the asset display data is generated by the data certificate distributed by the data issuing object to the target object and the object private key corresponding to the target object; the target object is used to obtain M declaration information from the data certificate, and select N declaration information for display from the M declaration information; M and N are both positive integers, and N is less than or equal to M; the target object is also used to hide MN declaration information other than the N declaration information in the M declaration information to obtain modified MN declaration information, and based on the object private key corresponding to the target object, encrypt the N declaration information and the modified MN declaration information to generate the digital signature of the target object, and is also used to determine the N declaration information, the modified MN declaration information, and the digital signature of the target object as the asset display data corresponding to the target object; the target object belongs to the first query permission range set by the data issuing object for the data certificate on the blockchain; the first digital identity file includes the object public key and the target digital identity identifier that have been certified by the first identity verification authority; The public key corresponding to the target object is obtained from the first digital identity file. The validity of the asset display data is verified based on the public key to obtain the data verification result corresponding to the asset display data. The validity verification refers to the process of verifying the digital identity files of one or more objects in order from lower to higher levels according to the trust chain corresponding to one or more objects at different levels. When the digital identity files of one or more objects all meet the legality conditions and the digital signature in the asset display data is correct, the data verification result corresponding to the asset display data is determined to be valid. The one or more objects include at least the data issuing object and the first identity verification authority. If the data verification result indicates that the asset display data verification is valid, then the business processing procedure indicated by the business request will be executed for the target object.

6. The method according to claim 5, characterized in that, The step of validating the asset display data based on the object's public key to obtain the data verification result corresponding to the asset display data includes: The digital signature in the asset display data is verified using the object's public key. If the digital signature in the asset display data is correct, a second digital identity file corresponding to the data issuing object is obtained from the blockchain. The second digital identity file corresponds to the digital identity identifier of the data issuing object. If the digital identity of the data issuer is issued by a second identity verification authority, then the second digital identity document is determined to meet the legality conditions, and the digital signature in the data certificate is verified based on the public key in the second digital identity document. If the digital signature in the data certificate is correct, then the data verification result of the asset display data is determined to be valid.

7. A data authorization device based on blockchain, characterized in that, include: The credential acquisition module is used to obtain data credentials distributed by the data issuing object to the target object in the blockchain; The target object belongs to the first query permission range set by the data issuing object for the data certificate on the blockchain; The data generation module is used to obtain M declaration information from the data certificate, and select N declaration information for display from the M declaration information; M and N are both positive integers, and N is less than or equal to M; The data generation module is also used to hide MN declaration information other than the N declaration information among the M declaration information to obtain modified MN declaration information; The data generation module is further configured to encrypt the N declaration information and the modified MN declaration information based on the object private key corresponding to the target object, and generate a digital signature of the target object; The data generation module is further configured to determine the N declaration information, the modified MN declaration information, and the digital signature of the target object as the asset display data corresponding to the target object; A data authorization module is used to store the asset display data in the blockchain, and to set a second query permission range for the asset display data on the blockchain, determined by the target object, so that data verification objects within the second query range can verify the validity of the asset display data based on the first digital identity file corresponding to the target object; the first digital identity file includes the object public key and the target digital identity identifier certified by the first identity verification authority; the data verification object is used to verify the digital identity files of the one or more objects in order from lower to higher levels according to the trust chain corresponding to one or more objects at different levels, and is used to determine that the data verification result corresponding to the asset display data is valid when the digital identity files of the one or more objects all meet the legality conditions and the digital signature in the asset display data is correct; the one or more objects include at least the data issuing object and the first identity verification authority.

8. A data authorization device based on blockchain, characterized in that, include: The request receiving module is used to receive business requests associated with the target object within the second query permission range set by the target object for asset display data, and to obtain the target digital identity identifier carried by the business request. The data acquisition module is used to acquire, based on the target digital identity identifier, the first digital identity file and asset display data corresponding to the target object in the blockchain; the asset display data is generated by the data certificate distributed by the data issuer to the target object and the object private key corresponding to the target object; the target object is used to acquire M declaration information from the data certificate, and select N declaration information for display from the M declaration information; M and N are both positive integers, and N is less than or equal to M; the target object is also used to hide MN declaration information other than the N declaration information from the M declaration information. The process involves obtaining MN modified declaration messages, encrypting the N declaration messages and the modified MN declaration messages based on the object private key corresponding to the target object, generating a digital signature for the target object, and further using the N declaration messages, the modified MN declaration messages, and the digital signature of the target object to identify the asset display data corresponding to the target object; the target object belongs to the first query permission range set by the data issuing object for the data certificate on the blockchain; the first digital identity file includes the object public key and the target digital identity identifier that have been certified by the first identity verification authority; The data verification module is used to obtain the object public key corresponding to the target object from the first digital identity file, and to perform validity verification on the asset display data based on the object public key to obtain the data verification result corresponding to the asset display data. The validity verification refers to the process of verifying the digital identity files of one or more objects in order from lower to higher levels according to the trust chain corresponding to one or more objects at different levels, and determining that the data verification result corresponding to the asset display data is valid when the digital identity files of one or more objects all meet the legality conditions and the digital signature in the asset display data is correct. The one or more objects include at least the data issuing object and the first identity verification authority. The successful verification module is used to execute the business processing procedure indicated by the business request for the target object if the data verification result indicates that the asset display data verification is valid.

9. A computer device, characterized in that, Including memory and processor; The memory is connected to the processor, the memory is used to store computer programs, and the processor is used to invoke the computer programs so that the computer device performs the method according to any one of claims 1-6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-6.

11. A computer program product, characterized in that, Includes a computer program / instruction that, when executed by a processor, implements the method described in any one of claims 1-6.

Citation Information

Patent Citations

  • Asset verification method based on block chain and block chain network system

    CN110096903A

  • Multi-dimensional digital identity authentication system based on block chain

    CN112580102A