Blockchain-based Distributed Identity Authentication Method and System
By obtaining and processing the identity data blocks of target users and their propagation path data in the blockchain network, generating an authentication vector for authentication, and allocating permissions through state estimation of multiple verification nodes, the problem of neglecting propagation paths and context information in the prior art is solved, and more accurate and reliable identity authentication and dynamic permission management are achieved.
Patent Information
- Application Number
- CN202411071154.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-06
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-08-06
AI Technical Summary
The existing blockchain-based identity authentication method ignores the propagation path and context information of data blocks in the blockchain network, resulting in the limitation of the accuracy and comprehensiveness of identity authentication.
By obtaining the target identity data block to be verified by the target user in the blockchain network and its corresponding distributed linkage path data, embedding representations generate linkage path representation vectors and target authentication vectors, combining these vectors for distributed identity authentication, and generating state feature space through the state estimation of multiple verification nodes, and dynamically allocating permission levels.
It improves the accuracy and efficiency of identity authentication, enhances the reliability of identity authentication, prevents the risks of identity forgery and data tampering, and ensures the security of the blockchain network and the privacy of data through a dynamic permission allocation mechanism.
Smart Images

Figure CN118890194B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to a blockchain-based distributed identity authentication method and system. Background Art
[0002] With the rapid development of information technology and the wide application of the Internet, network security and user identity authentication have become increasingly important issues. Traditional identity authentication methods, such as username and password verification, dynamic tokens, etc., although they can protect user security to a certain extent, have many deficiencies such as being easy to forget and easy to be stolen, and can no longer meet the growing security needs. Therefore, it is particularly important to seek a more secure and reliable identity authentication method.
[0003] In related technologies, the rise of blockchain technology has brought new opportunities to the field of identity authentication. Blockchain technology has characteristics such as decentralization, immutability, and anonymity, which make blockchain have natural advantages in the field of identity verification. In a blockchain network, each node can participate in data storage and verification, and once the data is on the chain, it cannot be tampered with, which greatly improves the authenticity and credibility of the data.
[0004] However, existing blockchain-based identity authentication methods often only focus on the verification of the data block itself, while ignoring the propagation path and context information of the data block in the blockchain network, which to a certain extent limits the accuracy and comprehensiveness of identity authentication. Summary of the Invention
[0005] In view of this, the purpose of this application is to provide a blockchain-based distributed identity authentication method and system.
[0006] According to the first aspect of this application, a blockchain-based distributed identity authentication method is provided, and the method includes:
[0007] Obtain the target identity data block to be verified by the target user in the blockchain network and the distributed linkage path data corresponding to the target identity data block;
[0008] Perform embedded representation on the distributed linkage path data to generate a linkage path representation vector, and perform embedded representation on the target identity data block to generate a target identity verification vector;
[0009] Perform distributed identity authentication based on the linkage path representation vector and the target identity verification vector to generate the distributed identity authentication status of the target user;
[0010] Perform state estimation based on multiple verification nodes of the target identity data block to generate a state feature space in the distributed identity authentication status;
[0011] According to the distributed identity authentication status and the status feature space, allocate corresponding permission levels for the target user in the blockchain network.
[0012] In a possible implementation manner of the first aspect, the multiple verification nodes of the target identity data block include: data complexity, verification frequency, and hash map;
[0013] The state estimation is performed based on the multiple verification nodes of the target identity data block to generate a state feature space in the distributed identity authentication state, including:
[0014] Perform state estimation based on the data complexity, verification frequency, and hash map of the target identity data block to generate a state feature space in the distributed identity authentication state.
[0015] In a possible implementation manner of the first aspect, the performing state estimation based on the data complexity, verification frequency, and hash map of the target identity data block to generate a state feature space in the distributed identity authentication state includes:
[0016] Determine the data complexity feature space, verification frequency feature space, and hash map feature space of the target identity data block;
[0017] Fuse the data complexity feature space, verification frequency feature space, and hash map feature space, and perform a normalization transformation on the fusion result to generate a state feature space in the distributed identity authentication state.
[0018] In a possible implementation manner, determining the data complexity feature space of the target identity data block includes:
[0019] Decompose the target identity data block to generate multiple identity data segments;
[0020] For each identity data segment, determine the information entropy of the identity data segment;
[0021] Integrate and output the multiple information entropies corresponding to the multiple identity data segments as the data complexity feature space of the target identity data block;
[0022] Determining the verification frequency feature space of the target identity data block includes:
[0023] Decompose the target identity data block to generate multiple identity data segments;
[0024] Statistically analyze the historical verification records of each identity data segment to determine the verification frequency of the identity data segment;
[0025] Integrate the multiple corresponding verification frequencies of the multiple identity data segments into the verification frequency feature space of the target identity data block;
[0026] Determine the hash map feature space of the target identity data block, including:
[0027] Decompose the target identity data block to generate multiple identity data segments;
[0028] Perform a hash operation on each identity data segment to generate a corresponding hash value sequence, and convert the hash value sequence into a hash map;
[0029] Integrate the multiple hash maps corresponding to the multiple identity data segments into the hash map feature space of the target identity data block.
[0030] In a possible implementation manner of the first aspect, the allocating corresponding permission levels for the target user in the blockchain network according to the distributed identity authentication status and the status feature space includes:
[0031] Obtain the operation permissions corresponding to the distributed identity authentication status;
[0032] Regulate the operation behaviors of the target user at different permission levels in the blockchain network through the eigenvalue mapping bitmap in the status feature space.
[0033] In a possible implementation manner of the first aspect, the target identity data block includes multiple identity data segments;
[0034] The regulating the operation behaviors of the target user at different permission levels in the blockchain network through the eigenvalue mapping bitmap in the status feature space includes:
[0035] When regulating the operation corresponding to each identity data segment of the target user, obtain the eigenvalue mapping bitmap corresponding to the identity data segment on the status feature space;
[0036] Determine the permission level of the operation behavior based on the eigenvalue mapping bitmap, and regulate the target user to perform the corresponding operation behavior according to the permission level.
[0037] In a possible implementation manner of the first aspect, the performing distributed identity authentication according to the linkage path representation vector and the target identity verification vector to generate the distributed identity authentication status of the target user includes:
[0038] Verify the propagation path of the target identity data block in the blockchain network based on the linked path representation vector, detect the authorization status data of each node on the propagation path, and generate a first verification result;
[0039] Use the target identity authentication vector to verify whether the hash value of the target identity data block matches the previously recorded hash value, and verify the cryptographic signature on the target identity data block to generate a second verification result;
[0040] Generate the distributed identity authentication status of the target user based on the first verification result and the second verification result.
[0041] In a possible implementation manner of the first aspect, the steps of performing an embedding representation on the distributed linked path data to generate a linked path representation vector and performing an embedding representation on the target identity data block to generate a target identity authentication vector include:
[0042] Extract the node information of each node in the distributed linked path data, where the node information includes the type, attributes, and relationships with other nodes of the node;
[0043] Extract the global path structure data of the distributed linked path data, where the global path structure data includes the path length, connection relationships between nodes, and time series patterns;
[0044] Map the node information of each node in the distributed linked path data and the global path structure data of the distributed linked path data into a low-dimensional vector space, and through an embedding model, convert the distributed linked path data into a vector form to generate the linked path representation vector;
[0045] And extract the key data in the target identity data block, where the key data at least includes the user ID, public key, and signature;
[0046] Construct first feature data based on the data block content according to the extracted key data, where the first feature data includes a data hash value and a cryptographic signature verification parameter;
[0047] Construct second feature data based on the context content based on the context information of the target identity data block in the blockchain network, where the second feature data includes the location and timestamp of the target identity data block;
[0048] Map the first feature data and the second feature data into a low-dimensional vector space, and through an embedding model, convert the target identity data block into a vector form to generate the target identity authentication vector.
[0049] According to the second aspect of the present application, a blockchain service system is provided. The blockchain service system includes a machine-readable storage medium and a processor. The machine-readable storage medium stores machine-executable instructions. When the processor executes the machine-executable instructions, the blockchain service system implements the aforementioned blockchain-based distributed identity authentication method.
[0050] According to the third aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are executed, the aforementioned blockchain-based distributed identity authentication method is implemented.
[0051] According to any of the above aspects, the technical effect of the present application is as follows:
[0052] By performing embedded representation on the distributed linkage path data and the target identity data block to generate a linkage path representation vector and a target identity verification vector, not only is the data complexity reduced, but also the data processing efficiency is improved, making the identity authentication process more rapid and accurate. Secondly, performing distributed identity authentication based on the linkage path representation vector and the target identity verification vector can ensure the authenticity of the user identity and the security of the data, greatly enhancing the reliability of the identity authentication and effectively preventing the risks of identity forgery and data tampering. Furthermore, by performing state estimation based on multiple verification nodes of the target identity data block to generate a state feature space in the distributed identity authentication state, and according to the distributed identity authentication state and the state feature space, allocating corresponding permission levels for the target user in the blockchain network, this dynamic permission allocation mechanism can ensure that users can only access the resources they are authorized to, thereby effectively protecting the security of the blockchain network and the privacy of the data. Thus, not only is the accuracy and efficiency of identity authentication improved, but also a scientific permission allocation mechanism provides a strong guarantee for the secure operation of the blockchain network. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other corresponding drawings can be obtained based on these drawings.
[0054] Figure 1 Shows a schematic flowchart of the blockchain-based distributed identity authentication method provided by the embodiments of the present application;
[0055] Figure 2The figure shows a schematic diagram of the component structure of a blockchain service system provided by an embodiment of the present application for implementing the above-mentioned blockchain-based distributed identity authentication method. Detailed implementation manners
[0056] The embodiments of the present application will be described below with reference to the accompanying drawings in the present application. It should be understood that the embodiments described below in conjunction with the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions of the embodiments of the present application.
[0057] Those skilled in the art of the present technology can understand that unless specifically stated, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements, and / or components, but do not exclude the implementation of other features, information, data, steps, operations, elements, components, and / or their combinations supported by the art of the present technology. It should be understood that when an element is "connected" or "coupled" to another element, the one element can be directly connected or coupled to the other element, or it can mean that the one element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used herein can include a wireless connection or a wireless coupling. The term "and / or" used herein indicates at least one of the items defined by the term. For example, "A and / or B" can be implemented as "A", or implemented as "B", or implemented as "A and B".
[0058] To make the objectives, technical solutions, and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings. The technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application will be described below through the description of several exemplary embodiments. It should be noted that the following embodiments can be referenced, learned from, or combined with each other. For the same terms, similar features, and similar implementation steps in different embodiments, they will not be described repeatedly.
[0059] Figure 1 The figure shows a schematic flowchart of a blockchain-based distributed identity authentication method and system provided by an embodiment of the present application. It should be understood that in other embodiments, the order of some steps of the blockchain-based distributed identity authentication method in this embodiment can be shared according to actual needs, or some of the steps can also be omitted or maintained. The detailed steps of the blockchain-based distributed identity authentication method include:
[0060] Step S110, obtaining a target identity data block to be verified by a target user in a blockchain network and distributed linkage path data corresponding to the target identity data block.
[0061] In this embodiment, the blockchain service system retrieves from the blockchain network that a target user with the user name "Admin" has submitted a transaction in a certain smart contract, and this transaction is attached with a target identity data block to be verified. This target identity data block contains Admin's public key, digital signature, and other identity authentication information. At the same time, the blockchain service system also obtains the propagation path of this target identity data block in the blockchain network, that is, the distributed linkage path data, and these distributed linkage path data detail each node and propagation step from the generation of the data block to its reception by the blockchain service system.
[0062] Step S120, perform an embedding representation on the distributed linkage path data to generate a linkage path representation vector, and perform an embedding representation on the target identity data block to generate a target identity authentication vector.
[0063] In this embodiment, the blockchain service system starts to process the obtained distributed linkage path data and target identity data block. First, use an embedding model to perform an embedding representation on the distributed linkage path data. This embedding model can capture the characteristics of each node in the distributed linkage path data and the relationships between nodes, and finally generate a linkage path representation vector. Similarly, the blockchain service system also performs an embedding representation on the target identity data block, extracts key information in the target identity data block, such as user ID, public key, and signature, and combines the context information of the target identity data block in the blockchain, such as location and timestamp, to generate a target identity authentication vector.
[0064] Step S130, perform distributed identity authentication based on the linkage path representation vector and the target identity authentication vector to generate the distributed identity authentication status of the target user.
[0065] In this embodiment, the blockchain service system now has a linkage path representation vector and a target identity authentication vector. First, use the linkage path representation vector to verify the propagation path of the target identity data block in the blockchain network. The blockchain service system checks whether each node on the propagation path has a legal authorization status to ensure that the target identity data block has not been tampered with or illegally propagated. Then, the blockchain service system uses the target identity authentication vector to verify whether the hash value of the data block matches the hash value of the previous target identity data block, and verify whether the cryptographic signature on the data block is valid. Combining the results of these two verifications, the blockchain service system generates the distributed identity authentication status of Admin, indicating whether her identity is valid and whether the target identity data block is trustworthy.
[0066] Step S140, perform state estimation based on multiple verification nodes of the target identity data block to generate a state feature space in the distributed identity authentication status.
[0067] In this embodiment, after confirming the identity authentication status of Admin, the blockchain service system further performs state estimation based on multiple verification nodes of the target identity data block (such as data complexity, verification frequency, and hash map). The blockchain service system first analyzes the complexity of the target identity data block to understand the richness of its structure and content. Then, it checks the frequency at which the target identity data block has been verified in the past to evaluate its reliability and stability. Finally, the blockchain service system generates a hash map of the target identity data block to check its data integrity and consistency. By integrating the information of these nodes, the blockchain service system generates a state feature space in the distributed identity authentication state, which comprehensively reflects the state and characteristics of Admin's identity data block.
[0068] Step S150, allocate corresponding permission levels for the target user in the blockchain network according to the distributed identity authentication state and the state feature space.
[0069] In this embodiment, based on the distributed identity authentication state and state feature space of Admin, the blockchain service system now determines her permission level in the blockchain network. If her identity authentication status is good and the state feature space shows high complexity, high verification frequency, and a consistent hash map, then the blockchain service system can grant her a higher permission level, allowing her to perform more sensitive or important operations. Conversely, if her identity authentication status is in doubt or the state feature space shows low complexity, low verification frequency, or an inconsistent hash map, then her permission level can be lowered to limit the potential risks she may pose to the network.
[0070] Based on the above steps, by performing embedding representation on the distributed linkage path data and the target identity data block, generating a linkage path representation vector and a target identity verification vector, not only reduces the data complexity, but also improves the data processing efficiency, making the identity authentication process faster and more accurate. Secondly, performing distributed identity authentication based on the linkage path representation vector and the target identity verification vector can ensure the authenticity of the user's identity and the security of the data, greatly enhancing the reliability of the identity authentication and effectively preventing the risks of identity forgery and data tampering. Furthermore, by performing state estimation based on multiple verification nodes of the target identity data block, generating a state feature space in the distributed identity authentication state, and allocating corresponding permission levels for the target user in the blockchain network according to the distributed identity authentication state and the state feature space, this dynamic permission allocation mechanism can ensure that users can only access the resources they are authorized to, thus effectively protecting the security and data privacy of the blockchain network. Thereby, not only improves the accuracy and efficiency of identity authentication, but also provides a strong guarantee for the secure operation of the blockchain network through a scientific permission allocation mechanism.
[0071] In a possible implementation, the multiple verification nodes of the target identity data block include: data complexity, verification frequency, and hash map.
[0072] Step S140 may include:
[0073] Perform state estimation based on the data complexity, the verification frequency, and the hash map of the target identity data block to generate a state feature space in the distributed identity authentication state.
[0074] In this embodiment, the blockchain service system first focuses on the data complexity of the target identity data block. This data complexity reflects the richness of the internal information and the structural diversity of the target identity data block. The blockchain service system disassembles the target identity data block and analyzes in detail various information elements contained therein, such as user personal profiles, transaction records, digital signatures, etc. The blockchain service system evaluates the quantity, type, and the complexity of the association between these information, so as to have a comprehensive understanding of the data complexity of the target identity data block.
[0075] Next, the blockchain service system checks the verification frequency of the target identity data block. The verification frequency refers to the number of times the target identity data block has been verified in the blockchain network. The blockchain service system queries the records of the blockchain to understand how many nodes have verified this target identity data block, as well as the time distribution and frequency of the verification. A high verification frequency means that this target identity data block has been widely recognized in the network, increasing its credibility and stability.
[0076] Finally, the blockchain service system generates and analyzes the hash map of the target identity data block. The hash map is a graphical representation generated based on the hash values of the data block content, which can visually display the structure and association of the internal data of the data block. The blockchain service system performs a hash operation on the target identity data block to generate a corresponding sequence of hash values, and presents these hash values in the form of a map. By analyzing the hash map, the blockchain service system can detect the integrity and consistency of the data block to ensure that the data block has not been tampered with during the transmission process.
[0077] After analyzing the data complexity, the verification frequency, and the hash map of the target identity data block, the blockchain service system begins to generate a state feature space in the distributed identity authentication state based on this information. It integrates and fuses the feature values of the data complexity, the verification frequency, and the hash map to form a multi-dimensional feature vector space. This feature vector space not only contains the characteristics of the data block itself, but also reflects the propagation and verification of the data block in the blockchain network.
[0078] Specifically, the blockchain service system can quantify characteristic values such as the level of data complexity, the frequency of verification, and the degree of consistency of the hash map, and then perform weighted summation according to a certain weight or perform feature fusion through a machine learning algorithm to finally generate a feature space that can comprehensively describe the state of the target identity data block. This feature space will provide an important basis for subsequent permission allocation and risk management.
[0079] In a possible implementation manner, the state estimation is performed based on the data complexity, the verification frequency, and the hash map of the target identity data block, and the state feature space in the distributed identity authentication state is generated, including:
[0080] Step S141, determining the data complexity feature space, the verification frequency feature space, and the hash map feature space of the target identity data block.
[0081] Step S142, fusing the data complexity feature space, the verification frequency feature space, and the hash map feature space, and performing a normalization transformation on the fusion result to generate the state feature space in the distributed identity authentication state.
[0082] In a possible implementation manner, determining the data complexity feature space of the target identity data block includes: disassembling the target identity data block to generate a plurality of identity data segments. For each of the identity data segments, determining the information entropy of the identity data segment. Integrating the plurality of information entropies corresponding to the plurality of identity data segments respectively and outputting them as the data complexity feature space of the target identity data block.
[0083] In this embodiment, the blockchain service system first obtains the target identity data block, and then disassembles it, dividing it into a plurality of identity data segments, which may include the user's personal information, transaction data, login records, etc.
[0084] For each identity data segment, the blockchain service system can calculate its information entropy. Information entropy is an index to measure data complexity and uncertainty. For example, if an identity data segment contains a large number of different information elements and the occurrence probabilities of these elements are relatively uniform, then the information entropy of this identity data segment will be relatively high, indicating a high data complexity.
[0085] The blockchain service system can integrate the information entropies of all identity data segments to form a multi-dimensional feature space, and this space represents the data complexity feature of the target identity data block.
[0086] Determine the verification frequency feature space of the target identity data block, including: disassembling the target identity data block to generate multiple identity data segments. Statistically analyze the historical verification records of each identity data segment to determine the verification frequency of the identity data segment. Integrate and output the multiple verification frequencies corresponding to the multiple identity data segments respectively as the verification frequency feature space of the target identity data block.
[0087] Similar to the above steps, the blockchain service system first disassembles the target identity data block to generate multiple identity data segments. The blockchain service system can query the historical verification records of each identity data segment on the blockchain and count the number of times each data segment is verified. These verification records may be scattered on multiple blockchain nodes, and the blockchain service system needs to communicate with these nodes to collect data. According to the collected verification frequency data, the blockchain service system can integrate these data to form a verification frequency feature space. This space can reflect the degree of trust of different data segments in the network.
[0088] Determine the hash map feature space of the target identity data block, including: disassembling the target identity data block to generate multiple identity data segments. Perform a hash operation on each identity data segment to generate a corresponding hash value sequence, and convert the hash value sequence into a hash map. Integrate and output the multiple hash maps corresponding to the multiple identity data segments respectively as the hash map feature space of the target identity data block.
[0089] Similarly, the blockchain service system can disassemble the target identity data block to obtain multiple identity data segments. For each identity data segment, the blockchain service system can perform a hash operation to generate a unique hash value sequence, and these hash value sequences will then be converted into a graphical hash map. Each node in the map represents a hash value, and the connection between nodes represents the association between hash values. The blockchain service system can integrate the hash maps of all identity data segments to form a hash map feature space. This space not only contains the hash value information of the data segments, but also shows the structure and association between the data segments in the form of a map.
[0090] After determining the data complexity feature space, the verification frequency feature space, and the hash map feature space, the blockchain service system can perform the fusion of the feature spaces. This process may involve weighted summation, feature splicing, or other more complex machine learning algorithms to ensure that the information of different feature spaces can be effectively integrated.
[0091] Finally, the blockchain service system can perform a standardization transformation on the fused feature space to eliminate the dimensional difference and value range difference between different features, making the feature space more regular and facilitating subsequent processing and analysis by machine learning models or algorithms. The generated state feature space will comprehensively reflect the comprehensive characteristics of the target identity data block in the distributed identity authentication state.
[0092] In a possible implementation manner, step S150 may include:
[0093] Step S151, obtaining the operation permissions corresponding to the distributed identity authentication state.
[0094] In this embodiment, the blockchain service system will first query a preset correspondence table or database, which stores different distributed identity authentication states and the corresponding operation permissions. For example, a high-level authentication state may correspond to higher operation permissions, such as initiating transactions, creating smart contracts, etc., while a low-level authentication state may only allow users to view public information on the blockchain.
[0095] On this basis, the blockchain service system can determine the current state of the target user according to the previously generated distributed identity authentication state. This state can be comprehensively determined based on multiple factors such as the verification result of the user's identity data block, historical behavior records, credit scores, etc.
[0096] According to the distributed identity authentication state of the target user, the blockchain service system can retrieve the corresponding operation permissions from the correspondence table or database and prepare to assign these permissions to the target user.
[0097] Step S152, regulating the operation behaviors of the target user with different permission levels in the blockchain network through the eigenvalue mapping bitmap in the state feature space.
[0098] In this embodiment, the blockchain service system can first parse the previously generated state feature space, which contains multiple eigenvalues of the target identity data block, such as data complexity, verification frequency, and hash map. The blockchain service system can map these eigenvalues to an eigenvalue mapping bitmap, which can intuitively display the distribution of different eigenvalues. For example, eigenvalues with high data complexity may occupy a larger area on the bitmap, indicating that this feature has a greater impact on user permissions.
[0099] Based on this eigenvalue mapping bitmap, the blockchain service system can formulate a set of rules to regulate the operation behavior of the target user in the blockchain network. For example, if a certain eigenvalue (such as the verification frequency) is low, the blockchain service system may restrict the user from performing some high-risk operations, such as large-value transactions or the deployment of smart contracts. Conversely, if the eigenvalue is high, the blockchain service system may grant the user more operation freedoms.
[0100] During the process of the user's operation in the blockchain network, the blockchain service system can monitor the user's operation behavior in real time and dynamically adjust the user's permission level according to the changes in the state feature space. For example, if the verification frequency of the user's identity data block suddenly increases, the blockchain service system may correspondingly raise the user's permission level.
[0101] In this way, the blockchain service system can accurately allocate corresponding permission levels to users based on the distributed identity authentication status of users and the state feature space, and perform real-time monitoring and dynamic adjustment during the user's operation process, thereby ensuring the security and efficiency of the blockchain network.
[0102] In a possible implementation manner, the target identity data block includes multiple identity data segments.
[0103] Step S152 includes:
[0104] Step S1521, when regulating the target user to execute the operation corresponding to each identity data segment, obtain the eigenvalue mapping bitmap corresponding to the identity data segment on the state feature space.
[0105] Step S1522, based on the eigenvalue mapping bitmap, determine the permission level of the operation behavior, and regulate the target user to execute the corresponding operation behavior according to the permission level.
[0106] In this embodiment, the target identity data block processed by the blockchain service system is a complex data structure, which contains multiple identity data segments of the user. These identity data segments may represent different identity information or attributes of the user, such as personal basic information, transaction records, asset status, credit scores, etc. Each data segment has a clear position and identification in the identity data block, which is convenient for the blockchain service system to perform precise management and operation.
[0107] Specifically, when the blockchain service system needs to regulate the target user to operate on a specific identity data segment, it will first access the previously generated state feature space. In this space, each identity data segment corresponds to a set of eigenvalues, and these eigenvalues reflect the characteristics of the data segment, such as data complexity, verification frequency, etc.
[0108] The blockchain service system can extract corresponding eigenvalue from the state feature space according to the segmented identity data that the target user wants to operate on, and map these eigenvalues to a bitmap. This bitmap can visually display the feature distribution of this data segment, helping the blockchain service system quickly and accurately evaluate the operation permission level.
[0109] Once the blockchain service system obtains the eigenvalue mapping bitmap corresponding to the segmented identity data, it can start analyzing this eigenvalue mapping bitmap to determine the operation permission level of the target user for this data segment. This determination process can be based on a series of preset rules and algorithms, such as the range, distribution, combination, etc. of the eigenvalues.
[0110] For example, if the eigenvalues of a certain segmented identity data show that its data complexity is very high and the verification frequency is also very high, then the blockchain service system may determine that the information contained in this data segment is very important and trustworthy, and thus will grant the target user a higher operation permission level. On the contrary, if the eigenvalues show low data complexity and low verification frequency, then the operation permission level may be correspondingly reduced.
[0111] After determining the permission level, the blockchain service system will regulate the target user to perform corresponding operation behaviors according to this permission level, which includes allowing or restricting the user to perform operations such as reading, modifying, deleting, etc. on the segmented identity data. The blockchain service system can monitor the user's operation behaviors in real time to ensure that they strictly conform to the determined permission level.
[0112] In this way, the blockchain service system can finely control the operation permissions of the target user for each segmented identity data, thereby ensuring the security and integrity of the data in the blockchain network.
[0113] In a possible implementation manner, step S130 includes:
[0114] Step S131, based on the linkage path representation vector, verify the propagation path of the target identity data block in the blockchain network, detect the authorization status data of each node on the propagation path, and generate a first verification result.
[0115] Step S132, use the target identity verification vector to verify whether the hash value of the target identity data block matches the previously recorded hash value, and verify the encryption signature on the target identity data block, and generate a second verification result.
[0116] Step S133, based on the first verification result and the second verification result, generate the distributed identity authentication status of the target user.
[0117] In this embodiment, the linkage path represents a vector that details the propagation path of the data block in the network, including each node it passes through. Using the linkage path representation vector, the blockchain service system starts to trace the propagation path of the target identity data block in the blockchain network. For example, in the order indicated by the linkage path representation, each node on the path is visited one by one. When visiting each node, the blockchain service system can check the authorization status data of the node, which indicates whether the node has the right to process and propagate the target identity data block. For example, the blockchain service system can verify the identity authentication information, permission certificates, etc. of the node. After checking the authorization status of all nodes on the entire propagation path, the blockchain service system can generate a first verification result. This first verification result reflects whether the propagation of the target identity data block in the blockchain network is legal and whether it has passed through correctly authorized nodes.
[0118] Meanwhile, the target identity authentication vector contains the key information for verifying the integrity and authenticity of the target identity data block. The blockchain service system uses the target identity authentication vector to verify whether the hash value of the target identity data block matches the previously recorded hash value, in order to ensure that the data block has not been tampered with during transmission. If the hash values are consistent, it indicates that the integrity of the data block is guaranteed. Next, the blockchain service system can verify the cryptographic signature on the target identity data block. This signature is usually generated by the original sender of the data block using their private key and is used to prove the authenticity and origin of the data block. The blockchain service system can use the public key of the sender to verify this signature. After completing the verification of the hash value and the cryptographic signature, the blockchain service system can generate a second verification result. This second verification result reflects whether the integrity and authenticity of the target identity data block are guaranteed.
[0119] The blockchain service system comprehensively analyzes the first verification result and the second verification result, and these two results together form the basis for a comprehensive evaluation of the target identity data block. Based on the above two verification results, the blockchain service system can generate the distributed identity authentication status of the target user. If both verification results indicate that the data block is legal, complete, and authentic, then the user's identity authentication status will be determined to be valid. Conversely, if there is a problem with any one of the verification results, the user's identity authentication status may be determined to be invalid or require further verification.
[0120] Thus, the blockchain service system can ensure the accuracy and security of distributed identity authentication in the blockchain network.
[0121] In a possible implementation manner, step S120 includes:
[0122] Step S121: Extract the node information of each node in the distributed linkage path data. The node information includes the type, attributes, and relationships with other nodes of the node.
[0123] In this embodiment, the blockchain service system first obtains the distributed linkage path data from the blockchain network. These distributed linkage path data detail the propagation paths of data blocks in the network, including how data blocks are propagated from one node to another.
[0124] The blockchain service system starts to analyze these distributed linkage path data and extracts the detailed information of each node. For example, for a specific node, the blockchain service system can record its type (such as a verification node, etc.), attributes (such as the computing power, reputation, etc. of the node), and its relationships with other nodes (such as directly connected nodes, indirectly connected nodes, etc.).
[0125] Step S122: Extract the global path structure data of the distributed linkage path data. The global path structure data includes path length, connection relationships between nodes, and time series patterns.
[0126] In this embodiment, in addition to node-level information, the blockchain service system can also extract the global structure data of the entire distributed linkage path data. For example, it can include the total length of the path (i.e., how many nodes the data block needs to pass through from the starting node to the target node), the specific connection relationships between nodes (which nodes are directly connected and which are indirectly connected through other nodes), and the time series pattern of data block propagation between each node (i.e., when the data block arrives at a certain node).
[0127] Step S123: Map the node information of each node in the distributed linkage path data and the global path structure data of the distributed linkage path data into a low-dimensional vector space. Through an embedding model, convert the distributed linkage path data into a vector form to generate the linkage path representation vector.
[0128] Next, the blockchain service system maps the extracted node information and global path structure data into a low-dimensional vector space. This process is completed by a pre-trained embedding model, which can convert complex network structure data into a concise vector form. Finally, the blockchain service system can obtain a linkage path representation vector, which greatly reduces the dimension and complexity of the data while retaining the main features of the original data.
[0129] And step S124: Extract the key data in the target identity data block. The key data includes at least user ID, public key, and signature.
[0130] Step S125: Construct first feature data based on the content of the data block according to the extracted key data. The first feature data includes a data hash value and an encrypted signature verification parameter.
[0131] Step S126: Construct second feature data based on the context content based on the context information of the target identity data block in the blockchain network. The second feature data includes the location and timestamp of the target identity data block.
[0132] Step S127: Map the first feature data and the second feature data to a low-dimensional vector space, and convert the target identity data block into a vector form through an embedding model to generate the target identity verification vector.
[0133] In this embodiment, when the blockchain service system processes the target identity data block, it first extracts the key data in the target identity data block, including at least the user's ID (a number used to uniquely identify the user), the public key (used to encrypt information and verify signatures), and the signature (used to confirm the identity of the data block sender and data integrity).
[0134] Based on the extracted key data, the blockchain service system can further construct first feature data. For example, it can include calculating the hash value of the data block (a method of converting the content of the data block into a fixed-length digital fingerprint through a specific algorithm to ensure data integrity) and generating an encrypted signature verification parameter (used to verify whether the signature on the data block is valid).
[0135] In addition to the first feature data based on the data block content, the blockchain service system can also construct second feature data according to the context information of the data block in the blockchain network, such as the location of the data block in the network (i.e., which block it is recorded in) and the timestamp (i.e., the specific time when the data block is created or recorded).
[0136] Finally, the blockchain service system can map the first feature data and the second feature data to a low-dimensional vector space and convert these feature data into a vector form through another embedding model. This vector is the target identity verification vector, which concisely and comprehensively represents the key information and context features of the target identity data block. This vector will be used in subsequent distributed identity authentication processes.
[0137] Figure 2 Fig. shows a blockchain service system 100 provided in an embodiment of the present application, including a processor 1001, a memory 1003, and program code stored on the memory 1003. The processor 1001 executes the above program code to implement the steps of the distributed identity authentication method based on the blockchain.
[0138] Figure 2 The blockchain service system 100 shown in the figure includes: a processor 1001 and a memory 1003. Among them, the processor 1001 and the memory 1003 are connected, such as being connected through a bus 1002. Optionally, the blockchain service system 100 may further include a transceiver 1004, and the transceiver 1004 may be used for data interaction between this blockchain service system and other blockchain service systems, such as sending and / or receiving data, etc. It should be noted that in actual scheduling, the transceiver 1004 is not limited to one, and the structure of the blockchain service system 100 does not constitute a limitation to the embodiments of the present application.
[0139] The processor 1001 may be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application-specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array), or other programmable logic devices, transistor logic devices, hardware data structures, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosed transaction records of the present application. The processor 1001 may also be a combination that implements computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0140] The bus 1002 may include a path for transmitting information between the above components. The bus 1002 may be a PCI (Peripheral Component Interconnect, peripheral data structure interconnect template) bus or an EISA (Extended Industry Standard Architecture, extended industry template structure) bus, etc. The bus 1002 may be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 2 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.
[0141] The memory 1003 can be a ROM (Read Only Memory), or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory), or other types of dynamic storage devices that can store information and instructions. It can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium that can be used to carry or store program code and can be read by a computer, which is not limited herein.
[0142] The memory 1003 is used to store the program code for implementing the embodiments of this application and is controlled by the processor 1001 for execution. The processor 1001 is used to execute the program code stored in the memory 1003 to implement the steps shown in the foregoing method embodiments.
[0143] The embodiments of this application provide a computer-readable storage medium, on which program code is stored. When the program code is executed by a processor, the steps and corresponding transaction records of the foregoing method embodiments can be implemented.
[0144] It should be understood that although the flowchart of the embodiments of this application indicates various operation steps by arrows, the execution order of these steps is not limited to the order indicated by the arrows. Unless there is a clear description in this article, in some implementation scenarios of the embodiments of this application, the implementation steps in each flowchart can be executed in other orders based on requirements. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages according to the actual implementation scenarios. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage of these sub-steps or stages can also be executed at different times. In the scenario where the execution times are different, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and the embodiments of this application do not limit this.
[0145] The above are only optional implementation manners of some implementation scenarios of this application. It should be noted that for those of ordinary skill in the art, without departing from the technical concept of the solution of this application, using other similar implementation means based on the technical idea of this application also belongs to the protection scope of the embodiments of this application.
Claims
1. A distributed identity authentication method based on blockchain, characterized in that: The method comprises: Obtaining a target identity data block to be verified by a target user in a blockchain network and distributed linkage path data corresponding to the target identity data block, wherein the distributed linkage path data is a propagation path of the target identity data in the blockchain network; Embedding the distributed linkage path data to generate a linkage path representation vector, and embedding the target identity data block to generate a target identity authentication vector; Performing distributed identity authentication according to the linkage path representation vector and the target identity authentication vector to generate a distributed identity authentication state of the target user; Performing state estimation according to multiple verification nodes of the target identity data block to generate a state feature space under the distributed identity authentication state; According to the distributed identity authentication state and the state feature space, assigning a corresponding permission level to the target user in the blockchain network; The multiple verification nodes of the target identity data block include: data complexity, verification frequency, and hash map; The performing state estimation based on the multiple verification nodes of the target identity data block to generate the state feature space under the distributed identity authentication state includes: Performing state estimation according to the data complexity of the target identity data block, the verification frequency and the hash map to generate a state feature space under the distributed identity authentication state; The state estimation is performed based on the data complexity of the target identity data block, the verification frequency and the hash map to generate the state feature space under the distributed identity authentication state, including: Determine the data complexity feature space, verification frequency feature space and hash map feature space of the target identity data block; The data complexity feature space, the verification frequency feature space and the hash map feature space are merged, and the fusion result is standardized and converted to generate a state feature space under the distributed identity authentication state; Determining a data complexity feature space of the target identity data block includes: Decomposing the target identity data block to generate multiple identity data segments; For each of the identity data segments, determining the information entropy of the identity data segment; Integrate and output the plurality of information entropies corresponding to the plurality of identity data segments as a data complexity feature space of the target identity data block; Determining the verification frequency feature space of the target identity data block includes: Decomposing the target identity data block to generate multiple identity data segments; Collecting statistics on historical verification records of each of the identity data segments to determine the verification frequency of the identity data segments; Integrate and output the multiple verification frequencies corresponding to the multiple identity data segments as a verification frequency feature space of the target identity data block; Determining the hash map feature space of the target identity data block includes: Decomposing the target identity data block to generate multiple identity data segments; Performing a hash operation on each of the identity data segments to generate a corresponding hash value sequence, and converting the hash value sequence into a hash map; Integrate and output the plurality of hash graphs corresponding to the plurality of identity data segments into a hash graph feature space of the target identity data block; The steps of embedding the distributed linkage path data to generate a linkage path representation vector, and embedding the target identity data block to generate a target identity verification vector include: Extracting node information of each node in the distributed linkage path data, wherein the node information includes the type, attributes, and relationship with other nodes of the node; Extracting global path structure data of the distributed linkage path data, wherein the global path structure data includes path length, connection relationship between nodes, and time series pattern; Mapping node information of each node in the distributed linkage path data and global path structure data of the distributed linkage path data to a low-dimensional vector space, converting the distributed linkage path data into a vector form through an embedding model, and generating the linkage path representation vector; and, extracting key data from the target identity data block, the key data including at least a user ID, a public key, and a signature; Constructing first characteristic data based on the data block content according to the extracted key data, wherein the first characteristic data includes a data hash value and an encrypted signature verification parameter; Based on the context information of the target identity data block in the blockchain network, construct second feature data based on the context content, wherein the second feature data includes a location and a timestamp of the target identity data block; The first feature data and the second feature data are mapped to a low-dimensional vector space, and the target identity data block is converted into a vector form through an embedding model to generate the target identity authentication vector.
2. The distributed identity authentication method based on blockchain according to claim 1 is characterized in that: The allocating a corresponding permission level to the target user in the blockchain network according to the distributed identity authentication state and the state feature space includes: Obtaining operation permissions corresponding to the distributed identity authentication state; By mapping the feature value bitmap in the state feature space, the target user is regulated to perform operation behaviors of different authority levels in the blockchain network.
3. The distributed identity authentication method based on blockchain according to claim 2 is characterized in that: The target identity data block includes a plurality of identity data segments; The step of regulating the target user to perform operations of different authority levels in the blockchain network by mapping the feature value bitmap in the state feature space includes: When regulating the target user to perform an operation corresponding to each of the identity data segments, obtaining a feature value mapping bitmap corresponding to the identity data segment on the state feature space; The authority level of the operation behavior is determined based on the feature value mapping bitmap, and the target user is regulated to perform the corresponding operation behavior according to the authority level.
4. The distributed identity authentication method based on blockchain according to claim 1 is characterized in that: The performing distributed identity authentication according to the linkage path representation vector and the target identity authentication vector to generate the distributed identity authentication state of the target user includes: Verifying the propagation path of the target identity data block in the blockchain network based on the linkage path representation vector, detecting the authorization status data of each node on the propagation path, and generating a first verification result; using the target identity verification vector to verify whether the hash value of the target identity data block matches the hash value of the forward record, and verifying the encrypted signature on the target identity data block to generate a second verification result; A distributed identity authentication state of the target user is generated according to the first verification result and the second verification result.
5. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores machine-executable instructions, which, when executed by a processor, implement the distributed identity authentication method based on blockchain as described in any one of claims 1 to 4.
6. A blockchain service system, characterized in that: It includes a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores machine-executable instructions, and when the machine-executable instructions are executed by the processor, the distributed identity authentication method based on blockchain as described in any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Mobile platform distributed digital identity authentication method and device and medium
CN116886357A