Method for selective disclosure of information based on cryptographic techniques

By combining cryptographic transformation and hash processing with blockchain management, digital identity information can be selectively disclosed, solving the problem of information exposure in existing technologies and improving the security and privacy protection of information disclosure.

CN117579252BActive Publication Date: 2026-07-21四川启睿克科技有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
四川启睿克科技有限公司
Filing Date
2023-11-17
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In existing technologies, the information disclosure method for digital identities generally involves the holder presenting a digital certificate, which exposes all attributes, lacks selectivity and security, and cannot effectively protect privacy and information security.

Method used

The original information is transformed and hashed using cryptographic technology to generate a fixed-length target information, which is then signed by the issuer. The holder uses encrypted information to display and transmit the information when selectively disclosing it, thus introducing a distributed digital identity system based on blockchain to manage identity information.

Benefits of technology

It improves the security of information disclosure, avoids attacks such as rainbow tables, enables selective and secure information sharing, and protects privacy rights.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117579252B_ABST
    Figure CN117579252B_ABST
Patent Text Reader

Abstract

The application provides a method for selectively disclosing information based on cryptography, comprising: obtaining original information; the original information comprising at least one field; performing cryptography transformation on the field of the original information, and then performing hash processing on the ciphertext of the field; sorting and combining the hash values of the fields in a preset order to obtain target information with a fixed length; signing the target information based on an issuer; using the ciphertext to display the field that needs to be disclosed when a holder selectively discloses information, and using the hash of the ciphertext to display the field that needs to be protected; and transmitting the decryption method of the ciphertext of the disclosed field in a preset transmission mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of selective information disclosure technology based on cryptography, and more specifically to a method for selective information disclosure based on cryptography. Background Technology

[0002] Digital identity typically refers to digital information formed by the digital representation of an entity, such as personal identifiers and binding information that can be mapped one-to-one with those identifiers. Digital identities serve as credentials to prove the authenticity of an entity's identity (attributes) online. Different digital identities can be used for identification in different application services (such as mobile phone numbers, email addresses, and Weibo accounts associated with individuals; and device codes associated with objects). This identity information can assist business organizations in verifying identities. In the information age, privacy issues are receiving increasing attention. Selective disclosure of information aims to protect privacy and information security while sharing necessary information in specific circumstances. Selective disclosure of information can help protect privacy rights and reduce the risk of identity exposure and information leakage. Providing only necessary information to trusted entities or platforms reduces the risk of information misuse, theft, or malicious attacks. Selective disclosure of information is a compliant practice, provided it complies with the law.

[0003] The most common way to use digital identity now is for the holder to present their digital certificate, which contains all of their attributes and the issuer's signature, thus disclosing all of the holder's attributes.

[0004] Therefore, a method for selective information disclosure based on cryptographic technology is needed to enable holders to selectively disclose information and improve security. Summary of the Invention

[0005] The purpose of this invention is to provide a method and system for selective information disclosure based on cryptographic technology, in order to solve the technical problems existing in the background art.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] A method for selectively disclosing information based on cryptographic technology, comprising:

[0008] Obtain the original information; the original information includes at least one field;

[0009] After cryptographic transformation of the fields of the original information, the ciphertext of the fields is then hashed.

[0010] The hash values ​​of each field are sorted and combined in a preset order to obtain target information with a fixed length.

[0011] The target information is signed by the issuer;

[0012] Based on the holder's use of encrypted methods to display fields that need to be made public when selectively disclosing information, and the use of the hash of the encrypted data to display fields that need to be protected;

[0013] The decryption method for transmitting public field ciphertext using a preset transmission method.

[0014] In some embodiments, the method further includes:

[0015] The issuer generates its own public / private key pair locally.

[0016] The holder generates their own public / private key pair locally.

[0017] The validator generates a public / private key pair locally.

[0018] In some embodiments, the method further includes:

[0019] The issuer uses its public key to generate a unique issuer identifier on a blockchain-based distributed digital identity system.

[0020] Holders use their public key to generate a unique identifier for themselves on a blockchain-based distributed digital identity system.

[0021] Validators use their public keys to generate unique identifiers on a blockchain-based distributed digital identity system.

[0022] In some embodiments, the method further includes:

[0023] The issuer registers as an issuer on a blockchain-based distributed digital identity system;

[0024] The issuer registers the type of credential statement issued on a blockchain-based distributed digital identity system;

[0025] Administrators operating a blockchain-based distributed digital identity system verify the issuer's qualifications through offline and online methods;

[0026] Upon successful verification, the issuer becomes the authoritative issuer.

[0027] A blockchain-based distributed digital identity system manages issuers and publicly discloses existing issuer information.

[0028] In some embodiments, the method further includes:

[0029] Validators register basic information on a blockchain-based distributed digital identity system;

[0030] A blockchain-based distributed digital identity system manages validators and makes existing validator information public.

[0031] In some embodiments, the method further includes:

[0032] Holders can obtain a publicly available list of issuers and select the corresponding issuer to generate verifiable digital credentials.

[0033] The issuer generates a verifiable digital certificate upon the holder's request;

[0034] The holder stores verifiable digital credentials;

[0035] Holders use verifiable digital credentials;

[0036] When using different business systems, holders may selectively disclose their attribute information according to the needs of the business systems.

[0037] The verifier verifies the verifiable expression.

[0038] In some embodiments, the issuer generating a verifiable digital certificate upon the holder's request includes:

[0039] Using the issuer's private key, the ciphertext containing the key information is decrypted to obtain the key information.

[0040] The ciphertext of the attribute value is decrypted using the key decryption information to obtain the original attribute information;

[0041] Verify the original attribute information online or offline;

[0042] In response to verification failure, an error message is returned;

[0043] In response to successful verification, add additional information to verify the digital credential.

[0044] Perform secure hashing on each field;

[0045] The hash values ​​of each field are combined in a preset order and then hashed again to generate data of a fixed length.

[0046] The issuer uses its private key to sign;

[0047] The generated verifiable digital credential is returned to the holder.

[0048] In some embodiments, the holder's selective disclosure of its attribute information according to the needs of the business system includes:

[0049] For information that needs to be disclosed, the ciphertext of the attribute values ​​is generated using the encryption algorithm and key recorded when generating verifiable digital credentials;

[0050] For information that does not need to be disclosed, the ciphertext of the attribute value is generated using the encryption algorithm and key of the field recorded when generating the verifiable digital credential, and then the attribute value is replaced by a hash value after secure hashing.

[0051] Verifiable digital credentials and other information remain in their original form;

[0052] Obtain the verifier's basic information on a blockchain-based distributed digital identity system;

[0053] The disclosed fields, along with the corresponding encryption algorithms and keys, and the undisclosed fields, form the key information for decryption.

[0054] The verifier's public key is used to encrypt the key information for decryption, generating the ciphertext of the key information for decryption.

[0055] The holder's private key is used to sign the selectively disclosed verifiable digital credentials to generate a verifiable representation.

[0056] Send the verifiable representation to the service address in the DID doc verifier.

[0057] In some embodiments, signing the selectively disclosed verifiable digital credential using the holder's private key includes:

[0058] Generate security hashes for each field;

[0059] The hashes of each field are combined according to a preset formula, and then hashed to generate a fixed length.

[0060] The holder then uses their private key to sign.

[0061] In some embodiments, the verifier's verification of verifiable expressions includes:

[0062] The verifier uses the verification algorithm in the verifiable representation to verify whether the signatures of the verifiable representations are consistent;

[0063] If there is an inconsistency, an error message is returned;

[0064] In response to consistency, the verifier obtains the selectively disclosed verifiable digital credentials from the verifiable representation and verifies whether the verifiable digital credentials are consistent.

[0065] If there is an inconsistency, an error message is returned;

[0066] In response to consistency, the verifier's private key is used to decrypt the ciphertext of the key information to obtain the decrypted key information;

[0067] The verifier uses the decryption key information to decrypt the corresponding disclosed fields in order to perform relevant business operations.

[0068] Meanwhile, this invention also discloses a selective information disclosure system based on cryptographic technology, comprising:

[0069] An acquisition module is used to acquire raw information; the raw information includes at least one field.

[0070] The processing module is used to perform cryptographic transformation on the fields of the original information, and then perform hash processing on the ciphertext of the fields;

[0071] The sorting module is used to sort and combine the hash values ​​of each field according to a preset order to obtain target information with a fixed length.

[0072] The signature module is used to sign the target information based on the issuer's signature.

[0073] The display module is used to display fields that need to be made public using encrypted methods when the holder selectively discloses information, and to display fields that need to be protected using the hash of the encrypted information.

[0074] The transmission module is used to transmit the decryption method of the public field ciphertext in a preset transmission mode.

[0075] Meanwhile, the present invention also discloses an information selective disclosure device based on cryptographic technology, the device including a processor and a memory; the memory is used to store instructions, and when the instructions are executed by the processor, the device causes the device to implement any of the above-described information selective disclosure methods based on cryptographic technology.

[0076] Meanwhile, the present invention also discloses a computer-readable storage medium that stores computer instructions. When a computer reads the computer instructions in the storage medium, the computer executes any of the above-described methods for selectively disclosing information based on cryptographic technology.

[0077] Beneficial effects

[0078] The significant advantages of this invention compared to existing technologies are:

[0079] This invention proposes a more secure improvement to existing selective disclosure methods. The solution incorporates cryptographic techniques: after cryptographic transformation of each field of the original information, the ciphertext of each field is hashed. Then, the hashes of each field are combined in a specific order (either by field order or by hash result) to generate a fixed-length result (e.g., rehashing). Finally, the issuer signs the result. When selectively disclosing information, the holder uses the ciphertext to display the fields to be disclosed and the hash of the ciphertext to display the fields to be protected. Simultaneously, the decryption method for the ciphertext of the disclosed fields is transmitted securely. This invention expands the information space through cryptographic transformation, avoiding attacks such as rainbow tables. A basic usage process is also provided. This invention significantly improves the security of selective information disclosure. Attached Figure Description

[0080] Figure 1 This is a schematic diagram of an information selective disclosure system based on cryptographic technology, which is part of this embodiment;

[0081] Figure 2 This is a flowchart illustrating the selective information disclosure method based on cryptographic technology involved in this embodiment;

[0082] Figure 3 This is a schematic diagram illustrating the hash generation process of the original information in an embodiment of the present invention.

[0083] Figure 4 This is a schematic diagram illustrating selectively disclosed information composed of disclosure fields and non-disclosure fields, according to an embodiment of the present invention.

[0084] Figure 5 This is a schematic diagram illustrating the selective disclosure information fragment hash generation process according to an embodiment of the present invention. Detailed Implementation

[0085] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0086] Conversely, this application covers any substitutions, modifications, equivalent systems, and solutions made within the spirit and scope of this application as defined in the claims. Furthermore, to provide a better understanding of this application, certain specific details are described in detail below. However, this application will be fully understood by those skilled in the art even without these detailed descriptions.

[0087] The following will combine Figure 1-5This application provides a detailed description of a method and system for selective information disclosure based on cryptographic technology, as illustrated in the embodiments of this application. It is worth noting that the following embodiments are merely illustrative of this application and do not constitute a limitation thereof.

[0088] Example 1

[0089] like Figure 1 The diagram shown is a schematic of the cryptographic-based selective information disclosure system 100 of this embodiment. Figure 1 As shown, the information selective disclosure system 100 based on cryptographic technology includes:

[0090] Acquisition module 110 is used to acquire raw information; the raw information includes at least one field;

[0091] The processing module 120 is used to perform cryptographic transformation on the fields of the original information, and then perform hash processing on the ciphertext of the fields;

[0092] The sorting module 130 is used to sort and combine the hash values ​​of each field according to a preset order to obtain target information with a fixed length.

[0093] The signature module 140 is used to sign the target information based on the issuer;

[0094] Display module 150 is used to display fields that need to be made public in encrypted form when the holder selectively discloses information, and to display fields that need to be protected in encrypted form using the hash of the encrypted text.

[0095] The transmission module 160 is used to transmit the decryption method of the public field ciphertext in a preset transmission mode.

[0096] It should be noted that the above description of the selective information disclosure system and its modules based on cryptographic technology is for convenience only and should not be construed as limiting this specification to the scope of the illustrated embodiments. It is understood that those skilled in the art, after understanding the principles of the system, may arbitrarily combine the various modules or construct subsystems connected to other modules without departing from these principles. In some embodiments, Figure 1 The acquisition module 110 and processing module 120 disclosed herein can be different modules within a single system, or a single module can implement the functions of two or more of the aforementioned modules. For example, the modules can share a single storage module, or each module can have its own separate storage module. Such variations are all within the scope of protection of this specification.

[0097] like Figure 2The diagram illustrates a flowchart 200 of the cryptographic-based selective information disclosure method of this embodiment. In some embodiments, flowchart 200 can be executed by a cryptographic-based selective information disclosure system 100. Figure 2 As shown, process 200 includes:

[0098] Step 210, obtain the original information; the original information includes at least one field;

[0099] Step 220: After performing cryptographic transformation on the fields of the original information, the ciphertext of the fields is then hashed.

[0100] Step 230: Sort and combine the hash values ​​of each field according to a preset order to obtain target information with a fixed length;

[0101] Step 240: The issuer signs the target information;

[0102] Step 250: Based on the holder's use of encrypted methods to display the fields that need to be disclosed when selectively disclosing information, the fields that need to be protected are displayed using the hash of the encrypted data;

[0103] Step 260: Transmit the decryption method of the public field ciphertext using a preset transmission method.

[0104] The implementation of this scheme involves three roles: issuer, holder, and verifier. In some embodiments, the method further includes:

[0105] The issuer generates its public-private key pair locally; the holder generates its public-private key pair locally; and the verifier generates its public-private key pair locally.

[0106] For example, the issuer generates its own public-private key pair locally (public key: Public issuer, private key: Private issuer); the holder generates its own public-private key pair locally (public key: Public holder, private key: Private holder); and the verifier generates its own public-private key pair locally (public key: Public verifier, private key: Private verifier).

[0107] In some embodiments, the method further includes:

[0108] The issuer uses its public key to generate a unique issuer identifier on a blockchain-based distributed digital identity system; the holder uses its public key to generate a unique holder identifier on the same system; and the verifier uses its public key to generate a unique verifier identifier on the same system.

[0109] For example, the issuer uses its own public key (Public issuer) to generate a unique identifier on the blockchain-based distributed digital identity system: DID issuer; the holder uses its own public key (Public holder) to generate a unique identifier on the blockchain-based distributed digital identity system: DID holder; and the verifier uses its own public key (Public verifier) ​​to generate a unique identifier on the blockchain-based distributed digital identity system: DID verifier.

[0110] In some embodiments, the method further includes:

[0111] The issuer registers as an issuer on the blockchain-based distributed digital identity system; the issuer registers the type of credential statement to be issued on the blockchain-based distributed digital identity system; the administrator operating the blockchain-based distributed digital identity system verifies the issuer's qualifications through offline and online methods; in response to successful verification, the issuer becomes an authoritative issuer; the blockchain-based distributed digital identity system manages issuers and publishes existing issuer information.

[0112] For example, issuers register the Claim Protocol Type (CPT) they can issue on a blockchain-based distributed digital identity system. This primarily includes the fields supported by the credential (e.g., identity CPTs include name and date of birth; education CPTs include name and education level). Administrators of the blockchain-based distributed digital identity system verify the issuer's qualifications offline and online. Once verified, the issuer becomes an authoritative issuer. The blockchain-based distributed digital identity system manages issuers and publicly discloses existing issuer information: DID issuer, the issuer's registered CPT, the DID document issuer (including the public key: Public issuer, supported encryption algorithms, and service address), and optional remarks (describing the issuer information).

[0113] In some embodiments, the method further includes:

[0114] Validators register basic information on a blockchain-based distributed digital identity system; the blockchain-based distributed digital identity system manages validators and makes existing validator information public.

[0115] For example, validators register their basic information on a blockchain-based distributed digital identity system. This system manages validators and publicly discloses existing validator information: DID validators, DID doc validators (containing public keys: Public validators, supported encryption algorithms, and service addresses), and optional remarks (describing the validator).

[0116] In some embodiments, the method further includes:

[0117] The holder obtains a publicly available list of issuers and selects the corresponding issuer to generate a verifiable digital certificate; the issuer generates a verifiable digital certificate according to the holder's request; the holder stores the verifiable digital certificate; the holder uses the verifiable digital certificate; when using different business systems, the holder selectively discloses its attribute information according to the needs of the business system; the verifier verifies the verifiable certificate.

[0118] For example, the holder obtains a publicly available list of issuers, selects the corresponding issuer, and generates a verifiable digital credential (VC), including:

[0119] First, the holder prepares the relevant information according to the CPT registered by the issuer (such as name, date of birth, etc. included in the identity CPT). Based on the information in the DID doc issuer, the holder independently selects the encryption algorithm and key for the fields of the corresponding information in the issuer-registered CPT according to security needs (different fields can use different encryption algorithms and keys; not encrypting can be considered a special encryption method). This information needs to be shared, therefore the encryption algorithm is a symmetric encryption algorithm. Simultaneously, the DID issuer, the issuer-registered CPT, the fields in the CPT, and the encryption algorithms and keys used for the fields in the CPT are recorded locally. The holder encrypts different fields according to the selection in the previous step, generating ciphertext of the field attribute values. The encryption algorithm and key used for the fields and field attribute values ​​in the CPT are then asymmetrically encrypted using the public key in the DID doc issuer information: Public issuer, generating ciphertext for decrypting key information. The ciphertext for decrypting key information, all fields, and the ciphertext of field attribute values ​​are sent to the service address in the DID doc issuer information, awaiting the issuer to generate a Verifiable Credential (VC).

[0120] In some embodiments, the issuer generating a verifiable digital certificate upon the holder's request includes:

[0121] Using the issuer's private key, the ciphertext of the key information is decrypted to obtain the key information; the ciphertext of the attribute values ​​is then decrypted using the key information to obtain the original attribute information; the original attribute information is verified online or offline; if verification fails, an error message is returned; if verification succeeds, other information for the verifiable digital credential is added; each field is securely hashed; the hash values ​​of each field are combined in a preset order and then hashed again to generate fixed-length data; the issuer signs the credential using their private key; and the generated verifiable digital credential is returned to the holder.

[0122] For example, using the issuer's private key (Private issuer), the ciphertext of the decryption key information is decrypted to obtain the decryption key information. This decryption key information is then used to decrypt the ciphertext of the attribute values ​​to obtain the original attribute information. The original attribute information is then verified online or offline. If verification fails, an error is returned. If verification succeeds, proceed to the next step: add other information to the Verifiable Credential (VC), such as the attribute fields and their ciphertext, CPT information, issuance time, expiration time, the VC's unique identifier ID, the issuer's DID, and the verification algorithm; perform a secure hash on each field (see reference). Figure 3 The process involves adding other information (in plaintext), then combining the hashes of each field in a specific order (either by field order or by hash result), hashing again to generate a fixed-length credential, and finally, the issuer signing it using their private key: Private Issuer. The resulting Verifiable Credential (VC) is then returned to the holder. The VC contains attribute fields and their ciphertext, CPT information, issuance time, expiration time, the VC's unique identifier ID, the issuer's DID, signature, verification algorithm, and other information.

[0123] In some embodiments, the holder's selective disclosure of their attribute information according to the needs of the business system includes: for information that needs to be disclosed, generating ciphertext of the attribute value using the encryption algorithm and key of the fields recorded when generating the verifiable digital certificate; for information that does not need to be disclosed, generating ciphertext of the attribute value using the encryption algorithm and key of the fields recorded when generating the verifiable digital certificate, and then performing a secure hash to replace the attribute value with the hash value; keeping the verifiable digital certificate and other information in their original form; obtaining the verifier's basic information on a blockchain-based distributed digital identity system; combining the fields of the disclosed information, the corresponding encryption algorithm and key, and the fields not disclosed into decryption key information; encrypting the decryption key information using the verifier's verifier public key to generate ciphertext of the decryption key information; signing the selectively disclosed verifiable digital certificate using the holder's holder private key to generate a verifiable representation; and sending the verifiable representation to the service address in the DID doc verifier.

[0124] Figure 4This is a schematic diagram illustrating selectively disclosed information composed of disclosed and non-disclosed fields, according to an embodiment of the present invention. For example, for information requiring disclosure, the ciphertext of the attribute value is generated using the encryption algorithm and key of the fields recorded during the generation of the Verifiable Credential (VC) (consistent with the ciphertext of the Verifiable Credential (VC) generation, and can also be cached in advance); for information not requiring disclosure, the ciphertext of the attribute value is generated using the encryption algorithm and key of the fields recorded during the generation of the Verifiable Credential (VC), and then securely hashed to replace the attribute value with the hash value, which can also be cached in advance; other aspects of the Verifiable Credential (VC) can remain in their original form. Basic information of the verifier is obtained on a blockchain-based distributed digital identity system: DID verifier, DID doc verifier (including public key: Public verifier, supported encryption algorithms, service address), and optional remarks; the fields of the disclosed information, along with the corresponding encryption algorithms and keys, and the non-disclosed fields, are combined to form key decryption information. The public key of the verifier is used to encrypt the decryption key information, generating ciphertext. The selectively disclosed Verifiable Credential (VC) is then signed using the holder's private key, generating a Verifiable Presentation (VP). The VP contains the selectively disclosed VC, signature, signature algorithm, verification algorithm, holder's DID, holder's public key, creation time, and ciphertext of the decryption key information. The signing method is as follows: first, secure hashes are generated for each field (information that does not need to be disclosed has already used hash values, which are skipped here); then, the hashes of each field are combined in a certain order (either by field order or by hash result); then, a fixed-length hash is generated; finally, the holder signs the VP using their private key. The Verifiable Presentation (VP) is then sent to the service address in the DID doc verifier.

[0125] Figure 5 This is a schematic diagram illustrating the selective disclosure information fragment hash generation process according to an embodiment of the present invention. In some embodiments, signing the selectively disclosed verifiable digital certificate using the holder's private key includes: generating a secure hash for each field; combining the hashes of each field according to a preset combination, and then hashing to generate a fixed length; and the holder then signing using the holder's private key.

[0126] In some embodiments, the verifier's verification of the verifiable representation includes: the verifier using a verification algorithm in the verifiable representation to verify whether the signature of the verifiable representation is consistent; in response to inconsistency, returning an error message; in response to consistency, the verifier obtaining a selectively disclosed verifiable digital credential from the verifiable representation and verifying whether the verifiable digital credential is consistent; in response to inconsistency, returning an error message; in response to consistency, using the verifier's verifier private key to decrypt the ciphertext of the decryption key information to obtain the decryption key information; and the verifier using the decryption key information to decrypt the corresponding disclosed fields for relevant business operations.

[0127] For example, the verifier uses the verification algorithm in the VP to verify whether the VP's signature is consistent (generating the final hash in the same way and comparing it with the original signature after decryption using the Public holder). If they are inconsistent, an error is returned; otherwise, the process proceeds to the next step. The verifier obtains the selectively disclosed Verifiable Credential (VC) from the VP and verifies whether the VC's signature is consistent (generating the final hash in the same way as generating the VC and comparing it with the original signature after decryption using the Public issuer). If they are inconsistent, an error is returned; otherwise, the process proceeds to the next step. Using the verifier's private key, the Private verifier decrypts the ciphertext of the decryption key information to obtain the decryption key information. The verifier uses the decryption key information to decrypt the corresponding disclosed fields, and then can perform relevant business operations.

[0128] Meanwhile, the present invention also discloses an information selective disclosure device based on cryptographic technology, the device including a processor and a memory; the memory is used to store instructions, and when the instructions are executed by the processor, the device causes the device to implement any of the above-described information selective disclosure systems based on cryptographic technology.

[0129] Meanwhile, the present invention also discloses a computer-readable storage medium that stores computer instructions. When a computer reads the computer instructions in the storage medium, the computer runs the information selective disclosure system based on cryptographic technology described above.

[0130] In summary, the technical solution of this invention proposes a more secure improvement over existing selective disclosure methods. This invention introduces cryptographic techniques, performing cryptographic transformations on each field of the original information, then hashing the ciphertext of each field. The hashes of each field are then combined in a specific order (either by field order or by hash result) to generate a fixed-length result (e.g., rehashing). Finally, the issuer signs the result. When selectively disclosing information, the holder uses ciphertext to display the fields to be disclosed and the hash of the ciphertext to display the fields to be protected. Simultaneously, the decryption method for the ciphertext of the disclosed fields is transmitted securely. This method significantly improves the security of selective information disclosure.

[0131] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for selectively disclosing information based on cryptographic technology, characterized in that, include: Obtain the original information; The original information includes at least one field; After cryptographic transformation of the fields of the original information, the ciphertext of the fields is then hashed. The hash values ​​of each field are sorted and combined in a preset order to obtain target information with a fixed length. The target information is signed by the issuer; Based on the holder's use of encrypted methods to display fields that need to be made public when selectively disclosing information, and the use of the hash of the encrypted data to display fields that need to be protected; The decryption method for transmitting ciphertext of public fields using a preset transmission method; The method further includes: The issuer generates a verifiable digital certificate upon the holder's request; When using different business systems, holders may selectively disclose their attribute information according to the needs of the business systems. The verifier verifies the verifiable expression; The issuing authority generates verifiable digital credentials upon the holder's request, including: Using the issuer's private key, the ciphertext of the decryption key information is decrypted to obtain the decryption key information; the ciphertext of the decryption key information is generated by asymmetric encryption using the encryption algorithm and key used by the fields in CPT, the attribute values ​​of the fields in CPT, and the public key in the DIDdoc issuer information: Public issuer. The ciphertext of the attribute value is decrypted using the key decryption information to obtain the original attribute information; Verify the original attribute information online or offline; In response to verification failure, an error message is returned; In response to successful verification, add additional information to verify the digital credential. Perform secure hashing on each field; The hash values ​​of each field are combined in a preset order and then hashed again to generate data of a fixed length. The issuer uses its private key to sign; The generated verifiable digital certificate is returned to the holder. The holder's selective disclosure of their attribute information according to the needs of the business system includes: For information that needs to be disclosed, the ciphertext of the attribute values ​​is generated using the encryption algorithm and key recorded when generating verifiable digital credentials; For information that does not need to be disclosed, the ciphertext of the attribute value is generated using the encryption algorithm and key of the field recorded when generating the verifiable digital certificate, and then the attribute value is replaced by a hash value after secure hashing. Verifiable digital credentials and other information remain in their original form; Obtain the verifier's basic information on a blockchain-based distributed digital identity system; The disclosed fields, along with the corresponding encryption algorithms and keys, and the undisclosed fields, form the key information for decryption. The verifier's public key is used to encrypt the key information for decryption, generating the ciphertext of the key information for decryption. The holder's private key is used to sign the selectively disclosed verifiable digital credentials to generate a verifiable representation. Send the verifiable representation to the service address in the DID doc verifier; The verifier verifies verifiable expressions including: The verifier uses the verification algorithm in the verifiable representation to verify whether the signatures of the verifiable representations are consistent; If there is an inconsistency, an error message is returned; In response to consistency, the verifier obtains the selectively disclosed verifiable digital credentials from the verifiable representation and verifies whether the verifiable digital credentials are consistent. If there is an inconsistency, an error message is returned; In response to consistency, the verifier's private key is used to decrypt the ciphertext of the key information to obtain the decrypted key information; The verifier uses the decryption key information to decrypt the corresponding disclosed fields in order to perform relevant business operations.

2. The method according to claim 1, characterized in that, The method further includes: The issuer generates its own public / private key pair locally. The holder generates their own public / private key pair locally. The validator generates a public / private key pair locally.

3. The method according to claim 2, characterized in that, The method further includes: The issuer uses its public key to generate a unique issuer identifier on a blockchain-based distributed digital identity system. Holders use their public key to generate a unique identifier for themselves on a blockchain-based distributed digital identity system. Validators use their public keys to generate unique identifiers on a blockchain-based distributed digital identity system.

4. The method according to claim 3, characterized in that, The method further includes: The issuer registers as an issuer on a blockchain-based distributed digital identity system; The issuer registers the type of credential statement issued on a blockchain-based distributed digital identity system; Administrators operating a blockchain-based distributed digital identity system verify the issuer's qualifications through offline and online methods; Upon successful verification, the issuer becomes the authoritative issuer. A blockchain-based distributed digital identity system manages issuers and publicly discloses existing issuer information.

5. The method according to claim 4, characterized in that, The method further includes: Validators register basic information on a blockchain-based distributed digital identity system; A blockchain-based distributed digital identity system manages validators and makes existing validator information public.

6. The method according to claim 5, characterized in that, The method further includes: Holders can obtain a publicly available list of issuers and select the corresponding issuer to generate verifiable digital credentials. The holder stores verifiable digital credentials; Holders use verifiable digital credentials.

7. The method according to claim 1, characterized in that, The step of signing the selectively disclosed verifiable digital credentials using the holder's private key includes: Generate security hashes for each field; The hashes of each field are combined according to a preset formula, and then hashed to generate a fixed length. The holder then uses their private key to sign.