Trust origin-based identity mutual recognition system and method, terminal and storage medium

CN117240577BActive Publication Date: 2026-09-29CHINESE PEOPLES LIBERATION ARMY UNIT 91776
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311308582.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-10
Publication Date
2026-09-29
Estimated Expiration
2043-10-10

AI Technical Summary

Technical Problem

[0003]当不同的器材管理信息化系统之间,如果需要完成彼此间的器材调拨或调配时,为了保证数据真实性,必然首先要保证彼此身份的真实性,这种情况下,通常采用线下书面函件、电子邮件、电话等沟通方式进行交互,虽然能保证用户的真实性,但因无便捷验证手段,导致协作效率低下、用户真实性验证成本较高、不便于一对多或多对多跨区域协作

Benefits of technology

[0024]本发明的上述技术方案至少具有如下优点:本发明提供的基于信任原点的身份互认方法,以加入区块链服务平台的器材管理系统的强信任力作为基础原点,为后续通过该器材管理系统加入的协同节点的身份真实性进行背书,进而建立不同的器材管理系统之间的协同节点的相互信任基础。基于该信任基础下,可以实现多种业务的相互协同。而且,该方法和系统可以将已验证身份真实性的协同节点的相关信息广播至其他各协同节点,可以避免重复进行身份验证流程,提升业务协作的效率、成本较低。本系统具有良好的扩展性,可以适用于联接多个不同的器材管理系统,实现多个不同的器材管理系统之间的身份验证信息的共享。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117240577B_ABST
    Figure CN117240577B_ABST
Patent Text Reader

Abstract

The application provides a trust origin-based identity mutual recognition system, method, terminal and storage medium, wherein the system comprises a plurality of cooperative nodes, a blockchain basic service and a plurality of cooperative interaction systems; the cooperative nodes comprise mutually connected identity authentication service systems and business service systems; the blockchain service platform comprises a blockchain communication service module, an identity authentication service module connected with the blockchain communication service module and an identity information updating module connected with the identity authentication service module; the cooperative interaction systems comprise identity authentication service modules and man-machine interaction modules, each identity authentication service module is connected with the blockchain service platform and the corresponding cooperative node, and the man-machine interaction module is connected with the blockchain communication service module. The application takes the strong trust of the equipment management system of the platform as the basis, endorses the identity authenticity of the subsequent cooperative nodes, and can effectively guarantee the credibility of the identities of the cooperative nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information system technology, and more specifically, to an identity mutual recognition system, method, terminal, and storage medium based on the origin of trust. Background Technology

[0002] Traditional equipment management information systems are centralized platform systems built on trust. Users simply need to open the login interface, enter their username and password, and they can access the system to handle equipment-related business. The authenticity of their identity is guaranteed by the centralized system itself, which usually has its own CA (Certificate of Authorization) system to support the authentication of users' identities within the system.

[0003] When different equipment management information systems need to transfer or allocate equipment between each other, in order to ensure the authenticity of the data, it is necessary to first ensure the authenticity of each other's identities. In this case, offline written letters, emails, telephones and other communication methods are usually used for interaction. Although the authenticity of users can be guaranteed, the lack of convenient verification methods leads to low collaboration efficiency, high cost of verifying user authenticity, and inconvenience for one-to-many or many-to-many cross-regional collaboration.

[0004] Existing solutions typically involve building a centralized system or platform for equipment collaborative management within an internet environment, encompassing more stakeholders. This allows more participants to log in to the same platform for collaborative business processing. Essentially, this is similar to a independently built centralized platform; if the scope of stakeholders exceeds this initial one, the aforementioned problems remain unresolved. Summary of the Invention

[0005] (a) Technical problems to be solved

[0006] The technical problem that this invention aims to solve is that existing technologies cannot achieve cross-domain identity recognition between multiple different equipment management information systems.

[0007] (II) Technical Solution

[0008] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0009] Firstly, an identity mutual recognition system based on the origin of trust includes multiple collaborative nodes, blockchain basic services, and multiple collaborative interaction systems; the collaborative nodes include interconnected identity authentication service systems and business service systems; the blockchain service platform includes a blockchain communication service module, an identity verification service module connected to the blockchain communication service module, and an identity information update module connected to the identity verification service module; the collaborative interaction system includes an identity verification service module and a human-computer interaction module, each of the identity verification service modules is connected to the blockchain service platform and its corresponding collaborative node, and the human-computer interaction module is connected to the blockchain communication service module.

[0010] Secondly, this application also provides an identity mutual recognition method based on trust origin, implemented through the trust origin-based identity mutual recognition system described in the above technical solution, the method comprising the following steps:

[0011] Step 1: Verify the authenticity of the organization's identity in the equipment management system to be connected to the blockchain service platform based on reliable information sources. If the identity is authentic, connect the corresponding equipment management system to the blockchain service platform and proceed to Step 2; otherwise, the process terminates.

[0012] Step 2: Node personnel enter their identity information into the corresponding equipment management system. The corresponding identity authentication service system verifies the identity information. If the verification is true, they are registered as platform users, a corresponding collaborative node is created, and Step 3 is executed. Otherwise, the registration fails and the process terminates.

[0013] Step 3: The first platform user initiates an identity verification request to the second platform user through the corresponding human-computer interaction module. The identity verification service module corresponding to the second platform user receives the identity verification request and sends an identity verification request to the collaborative node to which the second platform user belongs.

[0014] Step 4: The identity authentication service system of the collaborative node to which the second platform user belongs receives the identity verification request, verifies the identity information of the second platform user, and generates a verification result;

[0015] Step 5: The verification result is transmitted along the original path to the human-computer interaction module corresponding to the first platform user, and simultaneously to the identity information verification service module; the identity information verification service module records the verification result and updates the identity verification data of the second platform user in the human-computer interaction module;

[0016] Step 6: The identity information verification service module broadcasts the identity verification data to other human-computer interaction modules.

[0017] Preferably, the authentication data includes the number of successful authentications and the number of failed authentications.

[0018] Preferably, before step three, the method further includes: the blockchain service platform summarizing the identity information of the node personnel who have successfully registered on each collaborative node and forming a corresponding list.

[0019] Preferably, the identity recognition method further includes: when the first platform user needs to share data with the second platform user, constructing a secure data sharing transmission channel between the human-computer interaction module corresponding to the first platform user and the human-computer interaction module corresponding to the second platform user, and transmitting data through the secure data sharing transmission channel.

[0020] Preferably, after the data transmission is completed, the data collaborative secure transmission channel is dismantled.

[0021] Thirdly, this application also provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the identity mutual recognition methods based on trust origin described in the above technical solutions.

[0022] Fourthly, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the identity mutual recognition methods based on trust origins described above.

[0023] (III) Beneficial Effects

[0024] The above-mentioned technical solution of the present invention has at least the following advantages: The identity mutual recognition method based on the trust origin provided by the present invention takes the strong trust of the equipment management system joined by the blockchain service platform as the basic origin, and endorses the authenticity of the identity of the subsequent collaborative nodes joined through the equipment management system, thereby establishing a mutual trust foundation between collaborative nodes of different equipment management systems. Based on this trust foundation, various business collaborations can be realized. Moreover, the method and system can broadcast the relevant information of the verified collaborative nodes to other collaborative nodes, which can avoid repeating the identity verification process, improve the efficiency of business collaboration, and reduce costs. This system has good scalability and can be applied to connecting multiple different equipment management systems to realize the sharing of identity verification information between multiple different equipment management systems. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0026] Figure 1 This is a schematic diagram of the identity mutual recognition system based on the trust origin provided in an embodiment of the present invention.

[0027] Figure 2 This is one of the implementation principle diagrams of the identity mutual recognition system based on the trust origin provided in the embodiments of the present invention.

[0028] Figure 3 This is the second implementation principle diagram of the identity mutual recognition system based on trust origin provided in the embodiments of the present invention. Detailed Implementation

[0029] To make the technical problems to be solved, the technical solutions, and the beneficial effects of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the present invention and are not intended to limit the present invention.

[0030] It should be noted that when a component is referred to as "fixed to" or "set on" another component, it can be located directly on or indirectly on the other component. When a component is referred to as "connected to" another component, it can be directly or indirectly connected to the other component.

[0031] It should be understood that the terms "length", "width", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing the present invention, and do not indicate that the device or element must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention.

[0032] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating relative importance or the number of technical features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified. The specific implementation of this invention will be described in more detail below with reference to specific embodiments:

[0033] like Figure 1 and Figure 2 As shown, this embodiment of the invention provides an identity mutual recognition system based on a trust origin, including multiple collaborative nodes (such as... Figure 1 As shown: This includes a first collaborative node A, a second collaborative node B, and a third collaborative node N), a blockchain service platform 0, and multiple collaborative interaction systems; the collaborative nodes include interconnected identity authentication service systems (such as...). Figure 1 As shown: First identity authentication service system A1, second identity authentication service system B1, and third identity authentication service system N1) and business service system (such as... Figure 1 As shown: The system comprises a first business service system A2, a second business service system B2, and a third business service system N2; the blockchain service platform 0 includes a blockchain communication service module 1, an identity information verification service module 2 connected to the blockchain communication service module 1, and an identity information update module 3 connected to the identity information verification service module 2; the collaborative interaction system includes an identity verification service module (such as...). Figure 1 As shown: First authentication service module A3, second authentication service module B3, and third authentication service module N3) and human-computer interaction module (such as... Figure 1 As shown: the first human-computer interaction module A4, the second human-computer interaction module B4, and the third human-computer interaction module N4. Each identity verification service module is connected to the blockchain service platform and its corresponding collaborative node, and the human-computer interaction module is connected to the blockchain communication service module.

[0034] Secondly, this application also provides an identity mutual recognition method based on the trust origin, implemented through the trust origin-based identity mutual recognition system in the above technical solution, the method including the following steps:

[0035] Step 1: Verify the authenticity of the organization's identity in the equipment management system to be connected to the blockchain service platform based on reliable information sources. If the identity is authentic, connect the corresponding equipment management system to the blockchain service platform and proceed to Step 2; otherwise, the process terminates. It should be noted that this application applies to entities with strong trust in social relationships (such as government agencies or military units); reliable information sources include, but are not limited to, the filing and registration information of each entity in relevant government departments.

[0036] Step Two: Node personnel enter their identity information into the corresponding equipment management system. The corresponding identity authentication service system verifies the identity information. If the verification is true, they register as platform users, create a corresponding collaborative node, and proceed to Step Three. Otherwise, registration fails, and the process terminates. The blockchain service platform summarizes the identity information of successfully registered node personnel on each collaborative node and forms a corresponding list. Different identity authentication service systems can be used to verify the identity information of different node personnel. For example, for for-profit enterprises, they have corresponding organizational records in the government's business registration system, and their identity authenticity is verified based on the relevant registration data. For non-profit enterprises, they have corresponding organizational records in the government's civil affairs system, and their identity authenticity is verified based on the relevant registration data. For ordinary individuals, they have corresponding identity records in the government's public security system, and their identity authenticity is verified based on the relevant registration data.

[0037] Step 3: The first platform user initiates an identity verification request to the second platform user through the corresponding human-computer interaction module. The identity verification service module corresponding to the second platform user receives the identity verification request and sends an identity verification request to the collaborative node to which the second platform user belongs.

[0038] Step 4: The identity authentication service system of the collaborative node to which the second platform user belongs receives the identity verification request, verifies the identity information of the second platform user, and generates a verification result;

[0039] Step 5: The verification result is transmitted along the original path to the human-computer interaction module corresponding to the first platform user, and simultaneously to the identity information verification service module; the identity information verification service module records the verification result and updates the identity verification data of the second platform user in the human-computer interaction module;

[0040] Step Six: The identity verification service module broadcasts the identity verification data to other human-computer interaction modules. Preferably, the identity verification data includes the number of successful identity verifications and the number of failed identity verifications.

[0041] Please see Figure 2The implementation process of this application embodiment is as follows: Preparation work: Collaborative nodes A, B, and N are all registered in the blockchain service platform and register their respective digital certificates. The second collaborative node B and the first collaborative node A will engage in business collaboration. The user of the second collaborative node B can query the digital certificate of the user of the first collaborative node A and needs to verify the authenticity of the user of the first collaborative node A. When a user of the second collaborative node B initiates identity verification for a user of the first collaborative node A through the second human-computer interaction module B4, the request information is transmitted to the first identity verification service module A3 via the blockchain communication service module 1 through the red dotted line channel. The first identity verification service module A3 then initiates identity verification for the first collaborative node A user through the first identity authentication service system A1. After the first identity authentication service system A1 completes the verification, it returns the result to the first identity verification service module A3 via the blue dotted line, and then the first identity verification service module A3 feeds back to the second human-computer interaction module B4. Simultaneously, it is sent to the identity information verification service module 2 via the blockchain communication service module 1. The identity information verification service module 2 increments the verification success count of the first collaborative node A user in the identity information update module 3 by 1. Then, module 2 pushes the verification status information of the first collaborative node A user in the identity information update module 3 to the third human-computer interaction module N4 and the human-computer interaction modules of other nodes via the green dotted line direction. The third human-computer interaction module N4 can then know that the authenticity of the first collaborative node A user has been verified, that is, its identity is real. This verification method is applicable to all participating nodes. Conversely, when the authenticity verification of user A in the first collaborative node fails, the identity information verification service module 2 increments the verification failure count of user A in the identity information update module 3 by 1 and broadcasts it to other nodes. For any user in a collaborative node, the more successful verifications a user has, the higher the user's authenticity; conversely, the more failed verifications a user has, the lower the user's authenticity. For other newly joined nodes, their identity verification information from before joining can be easily obtained.

[0042] like Figure 3As shown, in one embodiment, the identity mutual recognition method further includes: when a first platform user needs to collaborate with a second platform user on data, a secure data collaboration transmission channel X is established between the human-computer interaction module (first human-computer interaction module A4) corresponding to the first platform user and the human-computer interaction module (second human-computer interaction module B4) corresponding to the second platform user, and data is transmitted through the secure data collaboration transmission channel X. Specifically, the implementation steps are as follows: taking the collaborative work between the first collaborative node A and the second collaborative node B as an example (the data collaboration method between other collaborative nodes is the same): when a first platform user needs to collaborate with a second platform user on data, the first human-computer interaction module A4 initiates a communication request to the second human-computer interaction module B4 through the blockchain communication service module 1. The second human-computer interaction module B4 responds to the communication request and establishes a secure data collaboration transmission channel X between the first human-computer interaction module A4 and the second human-computer interaction module B4. After the first human-computer interaction module A4 uploads the data to the blockchain, it transmits it to the second human-computer interaction module B4 through this secure data collaboration transmission channel X, thereby realizing secure data transmission between nodes. After the data transmission is completed, the secure data collaboration transmission channel X is dismantled.

[0043] Thirdly, this application also provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the above-mentioned identity mutual recognition methods based on the trust origin.

[0044] Fourthly, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the above-described identity mutual recognition methods based on trust origins.

[0045] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for mutual identity recognition based on the origin of trust, characterized in that, A trust-based identity verification system includes: Multiple collaborative nodes, wherein the collaborative nodes include interconnected identity authentication service systems and business service systems; A blockchain service platform includes a blockchain communication service module, an identity information verification service module connected to the blockchain communication service module, and an identity information update module connected to the identity information verification service module. Multiple collaborative interaction systems, each collaborative interaction system including an identity verification service module and a human-computer interaction module, each of the identity verification service modules being connected to the blockchain service platform and its corresponding collaborative node, and the human-computer interaction module being connected to the blockchain communication service module; The method includes the following steps: Step 1: Verify the authenticity of the organization's identity in the equipment management system to be connected to the blockchain service platform based on reliable information sources. If the identity is authentic, connect the corresponding equipment management system to the blockchain service platform and proceed to Step 2; otherwise, the process terminates. Step 2: Node personnel enter their identity information into the corresponding equipment management system. The corresponding identity authentication service system verifies the identity information. If the verification is true, they are registered as platform users, a corresponding collaborative node is created, and Step 3 is executed. Otherwise, the registration fails and the process terminates. Step 3: The first platform user initiates an identity verification request to the second platform user through the corresponding human-computer interaction module. The identity verification service module corresponding to the second platform user receives the identity verification request and sends an identity verification request to the collaborative node to which the second platform user belongs. Step 4: The identity authentication service system of the collaborative node to which the second platform user belongs receives the identity verification request, verifies the identity information of the second platform user, and generates a verification result; Step 5: The verification result is transmitted along the original path to the human-computer interaction module corresponding to the first platform user, and simultaneously to the identity information verification service module; the identity information verification service module records the verification result and updates the identity verification data of the second platform user in the human-computer interaction module; Step 6: The identity information verification service module broadcasts the identity verification data to other human-computer interaction modules.

2. The identity mutual recognition method based on the trust origin as described in claim 1, characterized in that, The authentication data includes the number of successful authentication attempts and the number of failed authentication attempts.

3. The identity mutual recognition method based on the trust origin as described in claim 1, characterized in that, Before step three, the method further includes: the blockchain service platform summarizing the identity information of the successfully registered node personnel on each collaborative node and forming a corresponding list.

4. The identity mutual recognition method based on the trust origin as described in claim 1, characterized in that, The identity recognition method further includes: when the first platform user needs to share data with the second platform user, a secure data sharing transmission channel is established between the human-computer interaction module corresponding to the first platform user and the human-computer interaction module corresponding to the second platform user, and data is transmitted through the secure data sharing transmission channel.

5. The identity mutual recognition method based on the trust origin as described in claim 4, characterized in that, After the data transmission is completed, the data collaborative secure transmission channel is dismantled.

6. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the identity mutual recognition method based on the trust origin as described in any one of claims 1 to 5.

7. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the identity mutual recognition method based on the trust origin as described in any one of claims 2 to 5.

Citation Information

Patent Citations

  • Multi-layer blockchain cross-domain authentication method in Internet of Things application scene

    CN112637189A

  • Block chain network based on trusted network, construction method and construction system

    CN112769817A