Identity management method and system based on distributed identity technology

By using distributed identity technology and verifiable credentials, the problems of untraceable identities and questionable authenticity of records during the service process are solved, enabling trusted verification and tamper-proof record traceability of the service process, thereby improving the transparency and credibility of the service.

CN117579284BActive Publication Date: 2026-07-21四川启睿克科技有限公司 +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
四川启睿克科技有限公司
Filing Date
2023-11-17
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

The existing technology cannot confirm whether the service is performed as required, the identity of the service personnel is untraceable, and the authenticity of the service records is questionable.

Method used

It adopts distributed identity technology and verifiable credentials, and realizes the issuance, authentication, storage and issuance of verifiable credentials through distributed identity infrastructure and blockchain nodes. Combined with identity terminal applications, it performs identity registration, authentication and credential verification, records the service process and performs tamper-proof trusted verification and traceability.

Benefits of technology

It enables trusted verification and traceability of the service process, ensuring the authenticity and immutability of service records, and improving the transparency and credibility of the service process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117579284B_ABST
    Figure CN117579284B_ABST
Patent Text Reader

Abstract

The application discloses an identity management method and system based on distributed identity technology, comprising a distributed identity infrastructure and an identity terminal application, wherein the distributed identity infrastructure comprises a distributed identity service node and a block chain node, is used for issuing, authenticating, storing and issuing a verifiable certificate of a distributed identity, and provides an identity authentication and certificate verification interface for connecting external third-party applications; the identity terminal application is used for facing users and service providers, is connected with the distributed identity service node, and realizes registration, authentication, application and sending of a verifiable certificate of an identity. The application realizes trusted verification and traceability of a service process by using a distributed identity service in combination with a verifiable certificate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of identity recognition and access management technology, specifically, to an identity management method and system based on distributed identity technology. Background Technology

[0002] This invention addresses the challenges of ensuring service providers deliver services according to user needs in scenarios such as domestic services, childcare, and elderly care. These challenges include verifying the accuracy of service delivery, tracing the identity of service personnel, and authenticating service records. Users urgently require reliable and trustworthy services. This invention, based on decentralized identifiers and verifiable credentials, solves these trust issues. Summary of the Invention

[0003] The purpose of this invention is to provide an identity management method and system based on distributed identity technology, which solves the problems in the prior art of being unable to confirm whether a service is performed as required, having untraceable identities of service personnel, and having questionable authenticity of service records.

[0004] The present invention solves the above problems through the following technical solution:

[0005] An identity management system based on distributed identity technology includes a distributed identity infrastructure and an identity terminal application. The distributed identity infrastructure includes distributed identity service nodes and blockchain nodes, which are used for the issuance, authentication, storage, and issuance of verifiable credentials of distributed identities, as well as providing identity authentication and credential verification interfaces for external third-party applications. The identity terminal application is used to connect with the distributed identity service nodes to users and service providers, and realizes identity registration, authentication, application for verifiable credentials, and credential verification.

[0006] This invention, based on decentralized identifiers and verifiable credentials, provides distributed identity authorization and solves the problems in existing technologies such as the inability to confirm whether services are performed as required, the untraceable identity of service personnel, and the questionable authenticity of service records, thereby enabling trusted verification and traceability of the service process.

[0007] An identity management method based on distributed identity technology includes:

[0008] Step A: The user downloads the identity terminal application and registers their identity by filling in personal information through the application.

[0009] Step B: The distributed identity service node receives the identity registration request sent by the identity terminal application, generates a unique decentralized identity identifier (DID) for the user, and creates an identity identifier document and corresponding identity verifiable credentials. The distributed identity service node returns the identity identifier and identity verifiable credentials to the identity terminal application, which then stores them securely.

[0010] Step C: The user applies for the corresponding service from the service provider, and the service provider obtains the necessary personal data from the user based on the user's application;

[0011] Step D: The user sends their identity verification credentials to the service provider, who then obtains the user's personal information using the credentials.

[0012] Step E: The service provider formulates a service plan based on the personal data provided by the user, applies for a service plan verification credential through the identity terminal application, and sends the credential to the user for confirmation. The user then confirms the service plan.

[0013] Step F: The service provider provides services according to the service plan, records the service process, generates a service record verification credential for each service record, and sends it to the user for confirmation;

[0014] Step G: The user verifies the credentials in the service record and completes the service confirmation.

[0015] Furthermore, the personal information includes the user's real name, age, gender, username, password, and biometrics, wherein: the username, password, and biometrics are used to achieve multi-factor authentication for user login terminal applications and secondary identity verification for obtaining key information, and the real name, age, and gender are used to apply for verifiable identity credentials.

[0016] Furthermore, the verifiable identity credential includes information such as the user's identity identifier, real name, age, and gender, and is issued by a distributed identity service node. The verifiable identity credential also includes distributed identity service signature information and has an expiration date, which is specified by the user during registration. If it expires, the user needs to reapply. The user's identity identifier and identity identifier document are synchronized through blockchain nodes.

[0017] Furthermore, step D specifically includes the following steps:

[0018] Step D1: The user sends the verifiable identity credentials to the service provider, which can be done via email or the service provider's business software.

[0019] Step D2: The service provider initiates credential verification to the distributed identity service node by calling the credential verification interface through the identity terminal application or its own business software using the credential verification credential of the user.

[0020] Step D3: The distributed identity service node verifies the credential signature. If the verification is successful, it continues to verify the credential validity period. If the verification is successful, it returns that the credential is trustworthy; otherwise, it returns that the credential is untrustworthy.

[0021] Step D4: Based on the verification results of the distributed identity service node, the service provider retrieves the user information from the credentials if the credentials are trustworthy; otherwise, the process is terminated and the user is requested to provide the credentials again.

[0022] Furthermore, the service plan verification credential includes the user's identity identifier, real name, age, gender, and service plan content, and is issued by a distributed identity service node; the service plan verification credential also includes distributed service signature information, and the service plan verification credential has an expiration date, after which the user needs to reapply; binding the user's identity identifier with the service plan ensures that the service and the user correspond correctly.

[0023] Furthermore, step F specifically includes the following steps:

[0024] Step F1: Service personnel log in to the identity terminal application. If they have not registered, they need to fill in the relevant personal information to register their identity.

[0025] Step F2: Service personnel can verify the credibility of credentials by verifying the service plan through the identity terminal application;

[0026] Step F3: If the service plan verification credentials are credible, the service personnel obtain the user identity information within the service plan verification credentials, verify the user's identity, perform the service according to the service plan, and record the service process;

[0027] Step F4: Service personnel apply to the distributed identity node for a verifiable service record credential by submitting their identity identifier and service record information through the identity terminal application. The distributed identity node generates the verifiable service record credential based on the application information and returns it to the service provider.

[0028] Step F5: The service provider sends the service record verification credential to the user. The user verifies the credibility of the service record verification credential through the identity terminal application, confirms the service, and evaluates the service content and satisfaction.

[0029] Furthermore, the service record verification credentials include information such as user identity identifier, service provider personnel identity identifier, service time, and proof document hash value, which are used for post-service event tracing.

[0030] Furthermore, in step G, the user imports the service record verifiable credentials and proof documents into the identity terminal application. The identity terminal application verifies whether the credential signature information is credible. If it is credible, the hash value of the proof document is compared with the hash value in the credential. If they match, the verification is successful, and the service confirmation and evaluation are completed.

[0031] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0032] (1) The present invention uses distributed identity service combined with verifiable credentials to realize trusted verification and traceability of service process.

[0033] (2) The present invention realizes the recording and immutability of the service process based on blockchain, and realizes the secure verification, recording and traceability of the service process by combining verifiable credentials. Attached Figure Description

[0034] Figure 1 This is a system principle block diagram of the present invention;

[0035] Figure 2 This is a flowchart of the present invention. Detailed Implementation

[0036] The present invention will be further described in detail below with reference to embodiments, but the implementation of the present invention is not limited thereto.

[0037] Example 1:

[0038] Combined with appendix Figure 1 As shown, an identity management system based on distributed identity technology includes a distributed identity infrastructure and an identity terminal application; wherein:

[0039] The distributed identity infrastructure, including distributed identity service nodes and blockchain nodes, enables the issuance, authentication, storage, and issuance of verifiable credentials of distributed identities. The distributed identity infrastructure can also connect to external third-party applications to provide identity authentication and credential verification interfaces.

[0040] Identity terminal applications are designed for users and service providers. They connect with distributed identity service nodes to enable identity registration, authentication, application for verifiable credentials, and credential verification.

[0041] Example 2:

[0042] Combined with appendix Figure 2 As shown, an identity management method based on distributed identity technology, taking the implementation of trusted services in elderly care scenarios as an example, specifically includes the following steps:

[0043] S1. Users download the identity terminal application, log in to the identity terminal application, and fill in relevant personal information to register their identity.

[0044] Specifically, family members register the identity on behalf of the elderly, fill in personal information, including the elderly's name, gender, age, and physical health status, and enter the validity period of the identity verification certificate.

[0045] S2. Distributed identity service nodes generate identity identifiers and verifiable identity credentials;

[0046] The distributed identity service node generates an elderly person's identity identifier and verifiable identity certificate, and returns the identity identifier and verifiable identity certificate to the family member's identity terminal application for secure storage;

[0047] S3. When a user applies for a service, the service provider requests the user to obtain the necessary personal data based on the user's application.

[0048] Specifically, family members select corresponding care services through the service provider's business application. Based on the user's service request, the service provider obtains the user's personal data to develop a care plan.

[0049] S4. The user sends a verifiable identity credential, the service provider formulates a service plan based on the identity information, and the user confirms the service plan.

[0050] Specifically, family members send the elderly person's verifiable identity credentials to the service provider via email or a service provider's application. The service provider then imports the verifiable identity credentials into the identity terminal application for credential verification and to obtain user information.

[0051] Based on user information, the service provider develops a care plan, including care periods and medication schedules. This care plan, along with the elderly person's identification, is then submitted via an identity terminal application to a distributed identity node to request a verifiable service plan credential. The distributed identity node then issues the credential.

[0052] The service provider sends the credentials to the elderly person's family members via email or the service provider's application. The family members verify the credentials using their identity terminal application. If the credentials are credible, the plan details are confirmed; otherwise, the service provider is required to provide them again.

[0053] S5. The service provider provides services according to the service plan, records the service process, and sends verifiable credentials of the service record to the user for confirmation.

[0054] Specifically, service providers log in to the identity terminal application, identify personnel through biometrics, bind biometrics to identity identifiers, and import verifiable credentials for the service plan into the identity terminal application after successful login. The application verifies the credibility of the credentials, and if they are credible, it retrieves the service plan content from the credentials and executes the service according to the plan.

[0055] During the service process, service personnel record service information, including photos, voice recordings, and text descriptions. They then use an identity terminal application to request and obtain verifiable service record credentials from a distributed identity node by submitting the service personnel's identification, the elderly person's identification, the service time, the text description of the service, and the hash values ​​of supporting documents such as photos and voice recordings.

[0056] Service providers send verifiable service records and supporting documents (photos, audio recordings, etc.) to the elderly person's family members via email or the service provider's application. The family members then import the credentials and supporting documents into their identity terminal application. The identity terminal application verifies the authenticity of the signature information on the credentials. If it is authentic, it compares the hash value of the supporting document with the hash value in the credentials. If they match, the verification is successful, and the family member completes the service confirmation and evaluation.

[0057] This invention employs a distributed identity service combined with verifiable credentials to achieve trusted verification and traceability of the service process; it uses blockchain to record and ensure the immutability of the service process, and combines verifiable credentials to achieve secure verification, recording, and traceability of the service process.

[0058] Although the present invention has been described herein with reference to illustrative embodiments, the above embodiments are merely preferred embodiments of the present invention, and the implementation of the present invention is not limited to the above embodiments. It should be understood that those skilled in the art can devise many other modifications and implementations, which will fall within the scope and spirit of the principles disclosed in this application.

Claims

1. An identity management method based on distributed identity technology, characterized in that, An identity management system based on distributed identity technology is used. This system includes a distributed identity infrastructure and an identity terminal application. The distributed identity infrastructure includes distributed identity service nodes and blockchain nodes, used for the issuance, authentication, storage, and verification of distributed identities and for providing interfaces for identity authentication and credential verification to external third-party applications. The identity terminal application is used by users and service providers, connecting to the distributed identity service nodes to register, authenticate, apply for, and send verifiable credentials for verification. The identity management method includes: Step A: The user downloads the identity terminal application and registers their identity by filling in personal information through the application. Step B: The distributed identity service node receives the identity registration request sent by the identity terminal application, generates a unique decentralized identity identifier for the user, and creates an identity identifier document and corresponding verifiable identity credential. The distributed identity service node returns the decentralized identity identifier and verifiable identity credential to the identity terminal application, which then stores them securely. Step C: The user requests the corresponding service from the service provider, and the service provider obtains the user's personal data based on the user's request; Step D: The user sends their identity verification credentials to the service provider, who then uses these credentials to obtain personal information. This process includes the following steps: Step D1: The user sends the verifiable identity credentials to the service provider, either via email or through the service provider's business software. Step D2: The service provider initiates credential verification to the distributed identity service node by calling the credential verification interface through the identity terminal application or its own business software using the credential verification credential of the user. Step D3: The distributed identity service node verifies the credential signature. If the verification is successful, it continues to verify the credential validity period. If the verification is successful, it returns that the credential is trustworthy; otherwise, it returns that the credential is untrustworthy. Step D4: Based on the verification results of the distributed identity service node, if the credentials are trustworthy, the service provider will retrieve the personal information from the credentials; if the credentials are untrustworthy, the process will be terminated and the user will be asked to provide them again. Step E: The service provider formulates a service plan based on the personal data provided by the user, applies for a service plan verification credential through the identity terminal application, and sends the service plan verification credential to the user for confirmation. The user confirms the service plan. Step F: The service provider provides services according to the service plan, records the service process, generates a service record verification credential for each service record, and sends it to the user for confirmation; Step G: The user verifies the credentials in the service record and completes the service confirmation.

2. The identity management method based on distributed identity technology as described in claim 1, characterized in that, The personal information includes the user's real name, age, gender, username, password, and biometric features. The username, password, and biometric features are used to achieve multi-factor authentication for user login to the terminal application and secondary authentication for obtaining key information. The real name, age, and gender are used to apply for verifiable identity credentials.

3. The identity management method based on distributed identity technology as described in claim 1, characterized in that, The verifiable identity credential includes the user's identity identifier, real name, age, and gender, and is issued by a distributed identity service node. The verifiable identity credential also includes distributed identity service signature information and has an expiration date, which is specified by the user during registration. If it expires, the user needs to reapply. The user's identity identifier and identity identifier document are synchronized through blockchain nodes.

4. The identity management method based on distributed identity technology as described in claim 1, characterized in that, The service plan verification credential includes the user's identity identifier, real name, age, gender, and service plan content, and is issued by a distributed identity service node. The service plan verification credential also includes distributed service signature information. The service plan verification credential has an expiration date, and the user needs to reapply after it expires. Binding the user's identity identifier to the service plan ensures that the service and the user correspond correctly.

5. The identity management method based on distributed identity technology as described in claim 1, characterized in that, Step F specifically includes the following steps: Step F1: Service personnel log in to the identity terminal application. If they have not registered, they need to fill in the relevant personal information to register their identity. Step F2: Service personnel can verify the credibility of credentials by verifying the service plan through the identity terminal application; Step F3: If the service plan verification credentials are credible, the service personnel obtain the user identity information within the service plan verification credentials, verify the user's identity, execute the service according to the service plan, and record the service process; Step F4: Service personnel apply to the distributed identity node for a verifiable service record credential by submitting their identity identifier and service record information through the identity terminal application. The distributed identity node generates the verifiable service record credential based on the application information and returns it to the service provider. Step F5: The service provider sends the service record verification credential to the user. The user verifies the credibility of the service record verification credential through the identity terminal application, confirms the service, and evaluates the service content and satisfaction.

6. The identity management method based on distributed identity technology as described in claim 1, characterized in that, The service record verification credentials include user identity identifier, service provider personnel identity identifier, service time, and proof document hash value, which are used for post-service event tracing.

7. The identity management method based on distributed identity technology as described in claim 1, characterized in that, In step G, the user imports the service record verifiable credential and proof document into the identity terminal application. The identity terminal application verifies whether the signature information of the service record verifiable credential is credible. If it is credible, the hash value of the proof document is compared with the hash value in the service record verifiable credential. If they match, the verification is successful, and the service confirmation and evaluation are completed.