Unified identity authentication and supervision traceability method and system based on SSI system
Through the unified identity authentication method of the SSI system, verifiable credentials and decentralized identifiers are used to achieve identity authentication interoperability between blockchain platforms, solving the compatibility issues between different traceability chains, ensuring data security and traceability accuracy, and is suitable for traditional Internet applications.
Patent Information
- Application Number
- CN202410602917.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-15
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2044-05-15
AI Technical Summary
Existing blockchain traceability platforms are independent and incompatible with each other. Identity authentication cannot be recognized on different traceability chains, and traceability information cannot be verified on the traditional Internet. There are problems such as information being easily tampered with and inconsistent certificate structures.
A unified identity authentication method based on the SSI system is adopted. By generating a public-private key pair for verifiable credential signatures and a public-private key pair for DID, verifiable credentials (VC) and decentralized identifiers (DID) are constructed. Blockchain data interaction is carried out between core nodes, and a verifiable storage center and regulatory components are introduced to ensure the interoperability of identity authentication and the immutability of data.
It realizes the identity authentication interoperability and data security between different traceability chains, improves the uniformity and accuracy of traceability, enables traceability and supervision to be applied on the traditional Internet, and enhances the compatibility of the traceability chain and the accuracy of verification.
Smart Images

Figure CN118869213B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing and data transmission, and in particular to a unified identity authentication and supervision traceability method and system based on an SSI system. Background Art
[0002] Traceability is a production control system that connects all stages of product production, inspection, supervision, and consumption. It enables forward, reverse, and non-directional tracking of products, making their origins traceable and their destinations traceable, thereby ensuring product quality and safety. However, traditional traceability systems suffer from issues such as susceptibility to tampering of traceability information, insufficient data sharing within the supply chain, and difficulty building user trust. Blockchain technology, with its unique advantages of decentralization, open autonomy, distributed fault tolerance, full-process record-keeping, and immutability, effectively addresses these shortcomings of traditional traceability and has been applied to traceability. Consequently, various blockchain-based traceability platforms have emerged. However, these blockchain traceability platforms are independent and incompatible, operating within separate, closed blockchains. Most blockchain traceability platforms use smart contracts for real-name authentication to monitor traceability information. However, this real-name authentication only exists within a single blockchain and is not interoperable with other blockchain platforms. If different manufacturers on a product's production line operate on different traceability chains, this identity authentication will not be recognized by other chains. At the same time, identity authentication exists in the form of smart contracts, which means that other attempts to verify identity have to participate in the blockchain and use blockchain for verification. However, blockchain technology is not popular at present, and the Internet is still the mainstream of the network system. Whether the identity verification on the traceability chain can be correctly verified on the Internet that is not based on blockchain is also a problem that needs to be solved.
[0003] Most blockchain traceability platforms use smart contracts on the chain to authenticate identities. This authentication model is very simple. Any node deployed with the traceability chain can authenticate the identity of an entity. This brings a risk: if a dishonest node allows the entry of a bad entity, then the network is actually attacked; the verification of smart contracts can only exist in the blockchain, which is not suitable for traditional traceability methods; the structure of digital certificates and operations such as construction and creation have no clear standards, which can easily cause confusion.
[0004] For example, the Chinese invention patent application publication number CN117254982A discloses a blockchain-based digital identity authentication method and system, which specifically includes: obtaining an identity authentication request submitted by a user during a transaction, and digitally signing the identity authentication request based on a random number generated by the blockchain and sending it to an identity authentication node in the blockchain; retrieving an execution contract based on the identity authentication node, and decrypting the digital signature based on the execution contract to obtain an identity verification certificate, and mapping and comparing the identity authentication certificate with the digital identity information registered in the blockchain to obtain a digital identity authentication result; feeding back the digital identity authentication result to the transaction terminal, and recording and retaining the entire identity authentication process parameters in a recording node in the blockchain based on the feedback result; in this scheme, the identity authentication certificate is mapped and compared with the digital identity information registered in the blockchain to construct an identity feature vector, and the method of obtaining similarity through the cosine value of the vector has certain errors, and comparison errors may still occur; this scheme does not standardize the structure of the identity authentication certificate, and there is a problem of inconsistent certificates in different application scenarios.
[0005] In order to solve the above problems, it is necessary to study a method that can achieve unified identity authentication and supervision of each traceability chain, so that identity verification can be recognized on different traceability chains and authenticated on the traditional Internet, avoiding the traceability information from being tampered with during the traceability process. Summary of the Invention
[0006] The purpose of the present invention is to address the deficiencies in the prior art and provide a unified identity authentication and regulatory traceability method and system based on the SSI system.
[0007] In order to achieve the above object, the present invention is achieved through the following technical solutions:
[0008] In a first aspect, the present invention provides a unified identity authentication and regulatory traceability method based on the SSI system, the method comprising the following steps:
[0009] In step 1, each core node generates its own public-private key pair for verifiable credential signatures and public-private key pair for DID generation. The DID metadata module then uses the DID generation public key based on the DID generation algorithm to generate the core node's DID and DID document. The DID document stores the core node's public key for verifiable credential signatures and DID generation public key. The consensus algorithm is then executed until the core node's DID document is added to the blockchain of its own verifiable storage center component and broadcast to the blockchains of other core nodes, enabling blockchain data exchange between the core nodes.
[0010] Step 2: The relevant government department's terminal obtains the relevant government department's verifiable credential signature public-private key pair and the DID generation public-private key pair. The core node then runs the DID generation algorithm based on the relevant government department's DID generation public key to generate the relevant government department's DID and DID document. The DID document stores the relevant government department's verifiable credential signature public key and DID generation public key. The DID document is then added to the blockchain of the core node's verifiable storage center component and broadcast to the blockchains of other core nodes.
[0011] Step 3: Based on the traceability chain service provider terminal obtained by each traceability chain service provider, a public-private key pair for the verifiable credential signature of the traceability chain service provider and a public-private key pair for DID generation will be generated; each traceability chain service provider controls the generation of the traceability chain through the corresponding traceability chain service provider terminal, and provides a public-private key pair for the verifiable credential signature and a public-private key pair for DID generation for the traceability chain; based on the manufacturer terminal obtained by each manufacturer, a public-private key pair for the manufacturer's verifiable credential signature and a public-private key pair for DID generation will be generated;
[0012] Step 4: The relevant government departments implement unified identity authentication of the traceability chain service provider, traceability chain and production enterprises through the core nodes of the relevant government departments, and create respective DIDs and DID documents for the traceability chain service provider, traceability chain and production enterprises;
[0013] Step 5: After completing the unified identity authentication, the manufacturer transmits the data to the traceability chain through the manufacturer's terminal. The traceability chain interacts with the core node to generate a verifiable certificate VC1 for the manufacturer and sends it to the core node. The core node verifies the verifiable certificate VC1 and interacts with the traceability chain to ensure that the correct data is received. Considering that the verification of data on different traceability chains must rely on specific traceability chains, it is not convenient for traditional Internet applications to verify. For this reason, verifiable certificates are used as the carrier of traceability data. The traceability chain is required to interact with the system node through verifiable certificates after generating a piece of data. This interaction implements a double locking mechanism to ensure that the traceability chain will not tamper with the data privately.
[0014] Step 6: Construct a verifiable expression VP based on the verifiable credential VC1 verified in step 5, and attach the VP to the corresponding product;
[0015] In step 7, the user uses the obtained verification node to read the verifiable expression VP and sends a verification request to the core node. The core node uses the DID resolution algorithm to resolve the verifiable expression VP, complete the traceability, and perform visualization.
[0016] Furthermore, step 4 specifically includes the following steps:
[0017] Step 4.1: The traceability chain service provider, traceability chain, and manufacturer submit a request for authentication to the relevant government department terminal and submit relevant information, including their respective identity information and their respective DID generated public keys;
[0018] Step 4.2: Verify the authenticity of the corresponding identity information provided by the traceability chain service provider, traceability chain and manufacturer through the terminal of the relevant government department. If it fails, notify the traceability chain service provider, traceability chain and manufacturer; if it passes, proceed to the next step;
[0019] Step 4.3: The terminal of the relevant government department runs the core node based on the DID generation algorithm, and uses the DID generation public keys of the traceability chain service provider, the traceability chain, and the manufacturer to generate the DID and DID documents of the traceability chain service provider, the traceability chain, and the manufacturer respectively, and stores the respective DID documents in the blockchain of the verifiable storage center component of the core node. The DID documents contain the respective verifiable credential signature public key and DID generation public key;
[0020] Step 4.4: Run the core node through the terminal of the relevant government department to generate a verifiable certificate VC for the information submitted by the traceability chain service provider, the traceability chain, and the manufacturer. The digital signature process uses the private key of the verifiable certificate signature of the relevant government department;
[0021] In step 4.5, the traceability chain service provider, the traceability chain, and the manufacturer retain their respective DIDs and verifiable credentials VC, and then use the DID of the traceability chain service provider, the DID of the manufacturer, and the DID of the traceability chain to provide a uniform resource locator URI for their respective verifiable credentials VC.
[0022] Furthermore, it is characterized in that step 5 specifically includes the following steps:
[0023] Step 5.1: The manufacturer transmits a piece of data to the traceability chain through the manufacturer’s terminal;
[0024] Step 5.2: The traceability chain interacts with the core node. After receiving the data, the traceability chain formats the data and then calculates the hash value 1.
[0025] In step 5.3, the VC layer of the core node constructs a verifiable certificate VC1 based on the data and hash value 1. The digital signature process uses the verifiable certificate signature private key of the traceability chain service provider. At the same time, the verifiable certificate VC1 is retained by the manufacturer, and a uniform resource locator URI is provided by the manufacturer's DID.
[0026] In step 5.4, the verifiable certificate VC1 is then sent to the core node. The VC layer of the core node verifies the verifiable certificate VC1. If the verification passes, the supervisory component processes the verifiable certificate VC1 and calculates hash value 2. The VC layer constructs the verifiable certificate VC2 based on the verifiable certificate VC1 and hash value 2. The digital signature process uses the core node's verifiable certificate signature private key, and the uniform resource locator URI in the DID document corresponding to the core node's verifiable certificate signature public key is used as the value of "verificationMethod" in the verifiable certificate VC2. The "issuer" field in the verifiable certificate VC2 is the DID of the core node.
[0027] In step 5.5, the verifiable certificate VC2 is transmitted to the traceability chain to verify whether the core node has received the correct data; if the verification fails, the verifiable certificate VC1 is re-uploaded; if the verification passes, the interaction ends.
[0028] Furthermore, step 6 is specifically as follows: all the verifiable credentials VC involved in the product production, that is, the verifiable credential VC1 described in step 5, are used as the value of the "credentialSubject" field in the verifiable expression VP, and the uniform resource locator URI in the DID document corresponding to the manufacturer's verifiable credential signature private key and public key is used as the "proof" field in the verifiable expression VP to obtain the verifiable expression VP.
[0029] Furthermore, step 7 is specifically as follows:
[0030] In step 7.1, the user requests the core node through the verification node. The VC layer first verifies the "proof" field of the verifiable expression VP, obtains the uniform resource locator URI in the DID document from the proof field of the verifiable expression VP, and sends the uniform resource locator URI in the DID document to the core node. The core node's verifiable data storage center searches the blockchain for data corresponding to the uniform resource locator URI in the DID document based on the uniform resource locator URI in the DID document.
[0031] Step 7.2: If successful, continue to verify the "proof" field of each verifiable credential VC in the "credentialSubject" field and repeat the above verification steps. If unsuccessful, the verification fails. Otherwise, the verification succeeds and the found data is returned to the verification node, indicating that the traceability is successful.
[0032] Furthermore, the DID generation algorithm specifically includes: the core node retrieves the DID generation public key from the public key provided by the core node, relevant government departments, traceability chain service providers, traceability chain or production enterprises, performs the HASH160 algorithm on the DID generation public key to obtain a hash value hash1; uses the hash value hash1 to preliminarily construct a DID document, and then uses the HASH160 algorithm to calculate the hash value hash2; uses the HASH160 algorithm again to obtain the hash value hash3, and uses the hash value hash1 and the hash value hash3 to construct a DID document.
[0033] In the second aspect, the present invention provides a unified identity authentication and supervision traceability system based on the SSI system, which is used for the unified identity authentication and supervision traceability method, and is characterized in that the SSI system includes terminals of relevant government departments obtained by relevant government departments, traceability chain service provider terminals obtained by n traceability chain service providers, production enterprise terminals obtained by n production enterprises, n core nodes and verification nodes, and a traceability chain generated by the traceability chain service provider terminal control; the core node includes a verifiable storage center component and a supervision component, the verifiable storage center component includes a DID metadata module and a blockchain, the DID metadata module records the correspondence between the DID and the DID document; the supervision component includes a VC layer and a blockchain, the VC layer is used to realize interactions related to verifiable credentials VC; the verification node provides a system interface to the user for use and sends a verification request to the core node.
[0034] The present invention has the following beneficial effects: (1) The present invention provides a unified identity authentication and supervision method based on the self-sovereign identity (SSI) system. To address the problem that identity authentication and methods between various blockchain traceability systems cannot be unified and must rely on the traceability chain and the smart contracts on it, the present invention introduces decentralized identifiers, verifiable credentials, verifiable data storage centers and supervision components to ensure the interoperability, compliance, accuracy and security of identity authentication between traceability chains. In this way, identity authentication is no longer limited to a single traceability chain, which improves the uniformity of traceability.
[0035] (2) The present invention considers the use of the traceability chain for traceability and supervision by constructing a verifiable certificate as an abstract model for traceability and supervision. It requires the traceability chain to interact with the system node through the verifiable certificate after generating a piece of data. This interaction implements a double locking mechanism, which can ensure that the traceability chain will not tamper with the data privately and no longer rely on the smart contract on the traceability chain. In this way, traceability and supervision can be applied to traditional Internet applications, improving the compatibility and accuracy of the two.
[0036] (3) The present invention uses a verifiable credential as an identity credential, which standardizes the identity verification process and improves the accuracy of verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 This is a structural diagram of the unified identity authentication and supervision traceability system based on the SSI system of the present invention;
[0038] Figure 2 Flowchart of the DID generation algorithm;
[0039] Figure 3 A flowchart of the regulatory program;
[0040] Figure 4 Flowchart of the traceability scheme. DETAILED DESCRIPTION
[0041] In order to make the present invention easier to understand, the present invention is further described below with reference to specific embodiments and drawings, which do not limit the present invention in any way. These embodiments and drawings are only used to illustrate the present invention and are not used to limit the scope of the present invention. Without departing from the technical solution of the present invention, any changes or modifications made to the present invention that can be easily implemented by ordinary technicians in this field will fall within the scope of the claims of the present invention.
[0042] The present invention provides a unified identity authentication and regulatory traceability system based on the SSI system, which is implemented based on decentralized identifiers (DIDs) and verifiable credentials (VC). The two together with blockchain technology constitute the self-sovereign identity system (SSI).
[0043] The entire system is mainly divided into core nodes and verification nodes. The core nodes have complete system functions, complete blockchain data, and can realize the creation of DIDs and interaction with the traceability chain; the verification nodes are suitable for use during user verification.
[0044] The core node consists of a verifiable storage center component and a supervisory component. The verifiable storage center component includes a DID metadata module and a blockchain. The verifiable data storage center component is responsible for storing the identity information of five entities involved in traceability: manufacturers, traceability chains, traceability chain service providers, relevant government departments, and core nodes. This identity information is identified by decentralized identifiers. Each identifier is generated using a specific cryptographic algorithm and signed by the public key of the identifying entity. These public keys are recorded in the DID document, and the verifiable data storage center component is the database that stores these documents. Furthermore, to participate in traceability, manufacturers, traceability chains, and traceability chain service providers must obtain certification from relevant government departments. This certification is achieved through the issuance of verifiable credentials. The data traceability process includes verifying the information in the verifiable credentials accompanying the data. To accurately track the lifecycle of a DID document, the verifiable data storage center also requires a metadata module. The metadata module is essentially a relational database that records the correspondence between DIDs and DID documents, facilitating DID updates, expiration, and resolution.
[0045] The regulatory component includes the VC layer and the blockchain. The regulatory component is responsible for receiving any data generated by each traceability chain. This data will first be processed by the traceability chain to calculate the corresponding hash value. Then, a verifiable certificate for transmission will be constructed and sent to the core node. The core node will store the verifiable certificate for transmission. After successful verification by the core node, a verifiable certificate for reply will be constructed. This verifiable certificate is used by the traceability chain to verify whether the system node has received the correct data. The most important function of this component is to facilitate regulatory authorities or consumers to inquire about the source and destination of a piece of data. The VC layer is used to implement interactive functions related to verifiable certificates, including adding proof fields to verifiable certificates and verifying the proof fields of verifiable certificates.
[0046] A unified identity authentication and regulatory traceability method based on the SSI system, the SSI system includes terminals of relevant government departments obtained by relevant government departments, traceability chain service provider terminals obtained by n traceability chain service providers, production enterprise terminals obtained by n production enterprises, n core nodes and verification nodes, and the traceability chain service provider controls the generation of the traceability chain through the traceability chain service provider terminal; the verification node provides a system interface to the user for use and sends a verification request to the core node; the verification node is constructed by a verifiable storage center component, and the verifiable storage intermediate component has four types of operations including: DID generation, DID resolution, DID document identity authentication and authorization, and DID document update and effectiveness.
[0047] The method comprises the following steps:
[0048] Step 1, participation of core nodes: blockchain data interaction between core nodes;
[0049] First, run one of the core nodes. This core node obtains the blockchain data of other core nodes and joins the blockchain of its own verifiable storage center component after successful consensus algorithm verification. If there are no other core nodes or verification fails, proceed to the next step.
[0050] Afterwards, each core node will generate its own public-private key pair for identity authorization and authentication, public-private key pair for verifiable credential signature, and public-private key pair for DID generation (the public-private key generation algorithm needs to comply with W3C standards). The DID metadata module then generates a public key based on the core node's DID and generates the core node's DID and DID document based on the DID generation algorithm. The DID document stores the core node's identity authorization and authentication public key, verifiable credential signature public key, and DID generation public key, while the core node keeps its own private key. The consensus algorithm is then executed until the core node's DID document is added to the blockchain of its own core node's verifiable storage center component and broadcast to other core node blockchains. The consensus algorithm is specified by the specific blockchain and can be POW, POS, or other algorithms.
[0051] Step 2: The relevant government departments generate DID documents through the core node controlled by the relevant government departments’ terminals;
[0052] The relevant government departments use the terminals of the relevant government departments to generate their own public-private key pairs for identity authorization and authentication, public-private key pairs for verifiable credential signatures, and public-private key pairs for DID generation. Then, they run the core nodes to generate public keys based on the DIDs of the relevant government departments. Based on the DID generation algorithm, the DIDs and DID documents of the relevant government departments are generated. The DID documents store the public keys for identity authorization and authentication, public keys for verifiable credential signatures, and public keys for DID generation of the relevant government departments. The private keys are kept by the relevant government departments themselves. The DID documents are then added to the blockchain of the core node's verifiable storage center component and broadcast to the blockchains of other core nodes.
[0053] Unified identity authentication solution:
[0054] Step 3: The relevant government departments generate respective DIDs and DID documents for the traceability chain service provider, traceability chain, and production enterprises, and issue their respective verifiable credentials (VC);
[0055] Step 3.1: The traceability chain service provider provides the traceability chain with the public-private key pair for identity authorization and authentication, the public-private key pair for verifiable credential signature, and the public-private key pair for DID generation through the traceability chain service provider terminal. The traceability chain service provider and the manufacturer generate the public-private key pair for identity authorization and authentication, the public-private key pair for verifiable credential signature, and the public-private key pair for DID generation through their respective terminals. The traceability chain service provider, the manufacturer, and the traceability chain submit a request for authentication to the terminal of the relevant government department, and attach the relevant materials, including their respective identity information and the public key generated by DID.
[0056] Step 3.2: The relevant government departments verify the authenticity of the corresponding identity materials of the corresponding entity, including the corresponding public key. If it fails, the traceability chain service provider, the generating enterprise and the traceability chain will be notified; if it passes, the next step will be carried out;
[0057] Step 3.3: The core node of the terminal operation of the relevant government department generates public keys based on the DIDs of the traceability chain service provider, production enterprise and traceability chain. Based on the DID generation algorithm, the DIDs and DID documents of the traceability chain service provider, production enterprise and traceability chain are generated respectively. The DID documents store their respective identity information and identity authorization and authentication public keys, verifiable credential signature public keys and DID generation public keys. The private key is kept by the individual who generates the public key.
[0058] In step 3.4, the relevant government departments use the core nodes of the relevant government departments’ terminals to generate verifiable certificates (VCs) for the information submitted by the traceability chain service provider, the generating enterprise, and the traceability chain (including identity information and identity authorization and authentication public keys, verifiable certificate signature public keys, and DID generation public keys). The digital signature process uses the verifiable certificate signature private key of the relevant government departments; that is, the signature generated by the verifiable certificate signature private key of the relevant government departments on the verifiable certificate VC is added to the proof field;
[0059] In step 3.5, the DID documents of the traceability chain service provider, manufacturer and traceability chain are stored in the blockchain of the verifiable storage center component of the core node, and the DID and verifiable certificate VC of the traceability chain service provider, manufacturer and traceability chain are returned to the traceability chain service provider, manufacturer and traceability chain for storage; the traceability chain service provider, manufacturer and traceability chain respectively construct a uniform resource locator URI for their respective verifiable certificate VC as the id field of the verifiable certificate VC, indicating its address on the Internet.
[0060] The basic format of the DID designed for this solution is "did:tracechain:[entity]:[method-specific-id]#address." Tracechain is the did-method field; the entity field can be producer (manufacturing enterprise), operator (traceability chain service provider), tracechain (traceability chain), authority (government department), or system (core node). The method-specific-id field serves as the generated address, algorithmically generated from the entity's public key and the hash of the DID document, enabling verification and resolution of its integrity and correctness. The #[address] field belongs to the [method-specific-id] field and is a fragment field in the DID standard. When [entity] is tracechain, it indicates the public key held by a specific enterprise; when it is any of the other four, it indicates a reference to the DID document.
[0061] DID generation algorithm (DID generation):
[0062] DID documents are subject to updates and expiration within verifiable data storage centers. Furthermore, when parsing a DID document from a DID, the parsed document must be integrity-verified. To achieve this, the present invention designs a DID generation algorithm as follows: a DID consists of two parts: a unique field in the DID that uniquely identifies the entity corresponding to the DID; and a hashing algorithm that combines the hash of the DID document and the current Unix timestamp. This creates a timestamped digital signature for the corresponding document. This algorithm uses the HASH160 algorithm, which first performs a SHA256 (Secure Hash Algorithm) operation followed by a RIPEMD160 (RACE Integrity Primitives Evaluation Message Digest) operation.
[0063] The specific steps are as follows:
[0064] 1) The core node will retrieve the public key DID provided by the core node, relevant government departments, traceability chain service providers, traceability chains or production enterprises to generate a public key, which will be used in the method-specific-id generation phase. The DID generation public key addressGeneration is subjected to the HASH160 algorithm to obtain hash1;
[0065] 2) The core node initially constructs a DID document that does not include the id field, and then uses the HASH160 algorithm to calculate the hash value hash2 for the DID document that does not include the id field;
[0066] 3) Use the HASH160 algorithm again, execute HASH160(hash2 + current Unix timestamp) to obtain hash3, and use hash1 + hash3 as the method-specific-id.
[0067] The regulatory scheme requires all traceability chains to exchange information with core nodes. Core nodes and a traceability chain serve as the two endpoints of this exchange. Different chains must interact with the core node and store information with each other. This interaction is achieved by exchanging verifiable credentials. This two-way interlocking mechanism ensures that traceability chains cannot tamper with data without authorization. Verifiable credentials used for interaction are divided into two types: transmission verifiable credentials (VC1) and response verifiable credentials (VC2). The former is used by the traceability chain to transmit to the core node, and the latter is used by the core node to reply to traceability chain messages.
[0068] Step 4: The generating enterprise transmits the data to the traceability chain and sends it to the core node through the production enterprise terminal;
[0069] Step 4.1: The manufacturer transmits a piece of data to the traceability chain through the manufacturer’s terminal;
[0070] Step 4.2: After the traceability chain receives the data, it formats it and then calculates the hash value 1. The algorithm for hash value 1 is specified by the traceability chain.
[0071] In step 4.3, the traceability chain interacts with the core node. The VC layer constructs a verifiable certificate VC1 based on the data and hash value 1. The digital signature process uses the traceability chain service provider's verifiable certificate signature private key. The traceability chain sends the verifiable certificate VC1 to the core node. The verifiable certificate VC1 is retained by the manufacturer and assigned an ID field by the manufacturer.
[0072] In step 4.4, the VC layer of the core node verifies the verifiable certificate VC1, including verification of hash value 1 and proof field of the verifiable certificate VC1. If the verification passes, it is added to the transaction pool (by decrypting the message using the sender's public key to obtain the message digest, and then the receiver hashes the message to obtain its own message digest. If the two message digests are consistent, the verification is considered to be successful). Then, the supervision component calculates hash value 2 of the verifiable certificate VC1. The VC layer constructs the verifiable certificate VC2 based on the verifiable certificate VC1 and hash value 2. The digital signature process uses the core node's verifiable certificate signing private key, and the DID URL corresponding to the core node's verifiable certificate signing private key in the DID document is used as the value of "verificationMethod" in the verifiable certificate VC2. The "issuer" field in the verifiable certificate VC2 is the DID of the core node. If the verification of VC1 fails, the VC1 is discarded.
[0073] In step 4.5, the verifiable certificate VC2 is transmitted to the traceability chain to verify whether the core node has received the correct data (including the verification of hash value 2 and the proof of VC2); if the verification fails, the verifiable certificate VC1 is uploaded again; if the verification passes, the interaction ends.
[0074] In this solution, the values and meanings of the credentialSubject fields of VC1 and VC2 are:
[0075] (1) VC1
[0076] 1) previous: the hash of the VC generated in the previous process in the production process;
[0077] 2) id: indicates the DID of the manufacturer in this link;
[0078] 3) data: data generated in this link, the specific format is defined by the traceability chain;
[0079] 4) hash: hash of data;
[0080] 5) hashsuite: specifies the hash algorithm used for the previous and hash fields;
[0081] (2) VC2
[0082] 1) data: VC1 itself;
[0083] 2) hash: hash value of VC1.
[0084] The purpose of VC1 is to confirm ownership, ensuring that a "transaction" is irrefutable and irrefutable. Furthermore, verification of verifiable credentials is independent of a specific blockchain, meaning traditional internet applications can easily verify the authenticity of a "transaction" without having to participate in a specific blockchain. Furthermore, the core nodes' use of verifiable credentials and the traceability chain's use of smart contracts or other methods for traceability are independent of each other, ensuring that the traceability chain's original traceability methods are not affected.
[0085] Provenance traceability scenario: Users run a verification node. To confirm the existence of a DID document or verifiable credential, the verification node requests a Merkle tree path from the core node and verifies the consensus algorithm on the blockchain. Product provenance can be traced by constructing a Verifiable Presentation (VP).
[0086] Step 5, construct a verifiable expression VP;
[0087] In step 5.1, after a product leaves the factory, the manufacturer provides all the VCs involved in the production of the product, namely the verifiable credential VC1 in step 4, and uses it as the value of the "credentialSubject" field in the verifiable expression VP. Then, the manufacturer uses the verifiable credential signature private key and the DID URL of the corresponding public key to add the proof field to the verifiable expression VP to obtain the verifiable expression VP.
[0088] In step 5.2, the verifiable expression VP is then attached to the product in some form, which can be a QR code, barcode or RFID.
[0089] Step 6: User traces the product;
[0090] Step 6.1: After purchasing the product, the user uses the verification node to read the verifiable expression VP;
[0091] In step 6.2, the verification node requests the core node to verify the proof field of the verification expression VP. That is, it asks the core node for the public key corresponding to the value of the verificationMethod field in the proof (that is, the DID url of the core node's verifiable signature public key); and sends the DID url to the core node.
[0092] Step 6.3: The core node's verifiable data storage center searches the blockchain for data in the field corresponding to the DID URL based on the DID URL.
[0093] Step 6.4: If successful, continue to verify the proof of each VC in the credentialSubject, the same as above; if unsuccessful, the verification fails, and it can be considered that there is a problem with the product traceability; if successful, the found data is returned to the verification node;
[0094] In step 6.5, only after the verification of the VP and all VCs contained in the credentialSubject of the VP is passed, can the traceability be considered successful, and the client will visualize the specific data contained in the VC.
[0095] The above shows and describes the basic principles, main features, and advantages of the present invention. However, the above is only a specific embodiment of the present invention, and the technical features of the present invention are not limited thereto. Any other implementation methods derived by any person skilled in the art without departing from the technical solution of the present invention should be included in the patent scope of the present invention.
Claims
1. A unified identity authentication and regulatory traceability method based on the SSI system, characterized by: The method comprises the following steps: In step 1, each core node generates its own public-private key pair for verifiable credential signatures and public-private key pair for DID generation. The DID metadata module then uses the DID generation public key based on the DID generation algorithm to generate the core node's DID and DID document. The DID document stores the core node's public key for verifiable credential signatures and DID generation public key. The consensus algorithm is then executed until the core node's DID document is added to the blockchain of its own verifiable storage center component and broadcast to the blockchains of other core nodes, enabling blockchain data exchange between the core nodes. Step 2: The relevant government department's terminal obtains the relevant government department's verifiable credential signature public-private key pair and the DID generation public-private key pair. The core node then runs the DID generation algorithm based on the relevant government department's DID generation public key to generate the relevant government department's DID and DID document. The DID document stores the relevant government department's verifiable credential signature public key and DID generation public key. The DID document is then added to the blockchain of the core node's verifiable storage center component and broadcast to the blockchains of other core nodes. Step 3: Based on the traceability chain service provider terminal obtained by each traceability chain service provider, a public-private key pair for the verifiable credential signature of the traceability chain service provider and a public-private key pair for DID generation will be generated; each traceability chain service provider controls the generation of the traceability chain through the corresponding traceability chain service provider terminal, and provides a public-private key pair for the verifiable credential signature and a public-private key pair for DID generation for the traceability chain; based on the manufacturer terminal obtained by each manufacturer, a public-private key pair for the manufacturer's verifiable credential signature and a public-private key pair for DID generation will be generated; Step 4: The relevant government departments run the core nodes through the terminals of the relevant government departments to realize the unified identity authentication of the traceability chain service provider, traceability chain and production enterprises, and create respective DIDs and DID documents for the traceability chain service provider, traceability chain and production enterprises; Step 5: After completing unified identity authentication, the manufacturer transmits data to the traceability chain through the manufacturer's terminal. The traceability chain interacts with the core node to generate a verifiable certificate VC1 for the manufacturer and sends it to the core node. The core node verifies the verifiable certificate VC1 and interacts with the traceability chain to ensure that the correct data is received. Step 6: Construct a verifiable expression VP based on the verifiable credential VC1 verified in step 5, and attach the VP to the corresponding product; In step 7, the user uses the obtained verification node to read the verifiable expression VP and sends a verification request to the core node. The core node uses the DID resolution algorithm to resolve the verifiable expression VP, complete the traceability, and perform visualization.
2. The unified identity authentication and supervision traceability method based on the SSI system according to claim 1 is characterized in that: Step 4 specifically includes the following steps: Step 4.1: The traceability chain service provider, traceability chain, and manufacturer submit a request for authentication to the relevant government department terminal and submit relevant information, including their respective identity information and their respective DID generated public keys; Step 4.2: Verify the authenticity of the corresponding identity information provided by the traceability chain service provider, traceability chain and manufacturer through the terminal of the relevant government department. If it fails, notify the traceability chain service provider, traceability chain and manufacturer; if it passes, proceed to the next step; Step 4.3: The terminal of the relevant government department runs the core node based on the DID generation algorithm, and uses the DID generation public keys of the traceability chain service provider, the traceability chain, and the manufacturer to generate the DID and DID documents of the traceability chain service provider, the traceability chain, and the manufacturer respectively, and stores the respective DID documents in the blockchain of the verifiable storage center component of the core node. The DID documents contain the respective verifiable credential signature public key and DID generation public key; Step 4.4: Run the core node through the terminal of the relevant government department to generate a verifiable certificate VC for the information submitted by the traceability chain service provider, the traceability chain, and the manufacturer. The digital signature process uses the private key of the verifiable certificate signature of the relevant government department; In step 4.5, the traceability chain service provider, the traceability chain, and the manufacturer retain their respective DIDs and verifiable credentials VC, and then use the DID of the traceability chain service provider, the DID of the manufacturer, and the DID of the traceability chain to provide a uniform resource locator URI for their respective verifiable credentials VC.
3. The unified identity authentication and supervision traceability method based on the SSI system according to claim 1 is characterized in that: Step 5 specifically includes the following steps: Step 5.1: The manufacturer transmits a piece of data to the traceability chain through the manufacturer’s terminal; Step 5.2: The traceability chain interacts with the core node. After receiving the data, the traceability chain formats the data and then calculates the hash value 1. In step 5.3, the VC layer of the core node constructs a verifiable certificate VC1 based on the data and hash value 1. The digital signature process uses the verifiable certificate signature private key of the traceability chain service provider. At the same time, the verifiable certificate VC1 is retained by the manufacturer, and a uniform resource locator URI is provided by the manufacturer's DID. In step 5.4, the verifiable certificate VC1 is then sent to the core node. The VC layer of the core node verifies the verifiable certificate VC1. If the verification passes, the supervisory component processes the verifiable certificate VC1 and calculates hash value 2. The VC layer constructs the verifiable certificate VC2 based on the verifiable certificate VC1 and hash value 2. The digital signature process uses the core node's verifiable certificate signature private key, and the uniform resource locator URI in the DID document corresponding to the core node's verifiable certificate signature public key is used as the value of "verificationMethod" in the verifiable certificate VC2. The "issuer" field in the verifiable certificate VC2 is the DID of the core node. In step 5.5, the verifiable certificate VC2 is transmitted to the traceability chain to verify whether the core node has received the correct data; if the verification fails, the verifiable certificate VC1 is re-uploaded; if the verification passes, the interaction ends.
4. The unified identity authentication and supervision traceability method based on the SSI system according to claim 1 is characterized in that: Step 6 is specifically as follows: all the verifiable credentials VC1 involved in the product production, that is, the verifiable credentials VC1 described in step 5, are used as the value of the "credentialSubject" field in the verifiable expression VP, and the uniform resource locator URI in the DID document corresponding to the manufacturer's verifiable credential signature private key and public key is used as the "proof" field in the verifiable expression VP to obtain the verifiable expression VP.
5. The unified identity authentication and supervision traceability method based on the SSI system according to claim 4 is characterized in that: Step 7 is as follows: In step 7.1, the user requests the core node through the verification node. The VC layer first verifies the "proof" field of the verifiable expression VP, obtains the uniform resource locator URI in the DID document from the proof field of the verifiable expression VP, and sends the uniform resource locator URI in the DID document to the core node. The core node's verifiable data storage center searches the blockchain for data corresponding to the uniform resource locator URI in the DID document based on the uniform resource locator URI in the DID document. Step 7.2: If successful, continue to verify the "proof" field of each verifiable credential VC in the "credentialSubject" field and repeat the above verification steps. If unsuccessful, the verification fails. Otherwise, the verification succeeds and the found data is returned to the verification node, indicating that the traceability is successful.
6. The unified identity authentication and supervision traceability method based on the SSI system according to claim 1 is characterized in that: The DID generation algorithm specifically includes: the core node retrieves the DID generation public key from the public key provided by the core node, relevant government departments, traceability chain service providers, traceability chain or production enterprises, performs the HASH160 algorithm on the DID generation public key to obtain a hash value hash1; uses the hash value hash1 to preliminarily construct a DID document, and then uses the HASH160 algorithm to calculate the hash value hash2; uses the HASH160 algorithm again to obtain the hash value hash3, and uses the hash value hash1 and the hash value hash3 to construct a DID document.
7. A unified identity authentication and supervision traceability system based on the SSI system implements the unified identity authentication and supervision traceability method according to any one of claims 1 to 6, characterized in that: The SSI system includes terminals of relevant government departments obtained by relevant government departments, traceability chain service provider terminals obtained by n traceability chain service providers, production enterprise terminals obtained by n production enterprises, n core nodes and verification nodes, and the traceability chain generated by the traceability chain service provider terminal control; the core node includes a verifiable storage center component and a supervision component, the verifiable storage center component includes a DID metadata module and a blockchain, the DID metadata module records the correspondence between the DID and the DID document; the supervision component includes a VC layer and a blockchain, the VC layer is used to realize interactions related to verifiable credentials VC; the verification node provides a system interface to the user for use and sends a verification request to the core node.
Citation Information
Patent Citations
Digital identity verification method and system based on block chain
CN117254982A
Product quality inspection traceability method and device based on block chain
CN116883024A
Commodity tracing method, device and equipment and storage medium
CN117314464A