Digital wallet account application verification method, device and electronic device
By obtaining and verifying the credit credentials and identity credential information of the target account and generating a digital wallet account, the problems of low efficiency in user identity authentication and high risk of privacy leakage are solved, and efficient and secure user identity authentication is achieved.
Patent Information
- Application Number
- CN202310652315.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-02
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2043-06-02
AI Technical Summary
The existing technology has the problems of low efficiency of user identity authentication, low data credibility and high risk of user privacy leakage.
By receiving the application operation of the target account, its credit credential information and identity credential information on the first operating server are obtained, and sent to the second operating server for verification to generate a target digital wallet account.
It improves the efficiency of user identity authentication, enhances data credibility, ensures user privacy and security, simplifies the digital wallet account application process, and improves user experience.
Smart Images

Figure CN119067655B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of financial technology and blockchain technology, and in particular to a method, device, and electronic device for verifying an application for a digital wallet account. Background Art
[0002] Customer identity verification is an effective means of detecting and preventing financial risks and suspicious transactions, and is the first line of defense against unusual financial activities. Currently, relevant international and domestic laws require financial institutions to conduct customer identity verification for all types of users when applying for financial services.
[0003] Current customer identity verification methods have many problems and risks. For example, financial institutions need to ensure the credibility of user customer identity verification data; users are concerned about data security authorization and privacy protection; users use the services of multiple financial institutions and need to independently verify their customer identity with each institution, resulting in a large amount of repeated customer identity verification and low identity verification efficiency. This process not only affects the user experience, but may also lead to risks such as information leakage.
[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0005] Embodiments of the present invention provide a method, device, and electronic device for verifying an application for a digital wallet account, to at least address the technical problems existing in related technologies of low user identity authentication efficiency, low data credibility, and high risk of user privacy leakage.
[0006] According to one aspect of an embodiment of the present invention, a method for applying for and verifying a digital wallet account is provided, comprising: receiving an application operation for applying for a digital wallet account based on a target account; in response to the application operation, obtaining credit credential information of the target account on a first operating server, wherein the first operating server is the operating server to which the target account belongs; obtaining pre-stored identity credential information of the target account on an identity credential issuing server; sending the first identity identifier, the credit credential information, and the identity credential information of the target account to a second operating server, so that the second operating server authenticates the target account based on the credit credential information and the identity credential information, wherein the second operating server is a digital wallet account issuing server; receiving an application result returned by the second operating server, wherein the application result includes a target digital wallet account, and the target digital wallet account is generated by the second operating server when the target account is successfully verified based on the first identity identifier, the credit credential information, and the identity credential information.
[0007] According to another aspect of an embodiment of the present invention, a method for applying for and verifying a digital wallet account is provided, comprising: receiving a request from a target account to apply for a digital wallet account, wherein the request carries the first identity identifier of the target account, the credit credential information of the target account on the first operating server, and the identity credential information of the target account on the identity credential issuing server, wherein the identity credential information is pre-stored in the target terminal, wherein the first operating server is the operating server to which the target account belongs; verifying the target account based on the first identity identifier, the credit credential information and the identity credential information; if the verification is successful, generating a target digital wallet account, and returning the target digital wallet account to the target terminal in the application result.
[0008] According to another aspect of an embodiment of the present invention, a method for applying for and verifying a digital wallet account is also provided, including: receiving a request from a target account to apply for a digital wallet account; generating credit credential information of the target account on a first operating server in response to the request, wherein the first operating server is the operating server to which the target account belongs; feeding back the credit credential information to a target terminal, for the target terminal to apply for a digital wallet account from a second operating server in combination with a first identity identifier and identity credential information pre-stored in the target terminal, wherein the identity credential information is the identity credential of the target account on an identity credential issuing server, wherein the second operating server is a digital wallet account issuing server.
[0009] According to another aspect of an embodiment of the present invention, a method for applying for and verifying a digital wallet account is also provided, including: receiving a request from a target account to apply for an identity credential, wherein the request carries the identity information of the target account; in response to the request, obtaining the identity credential information of the target account on the identity credential issuing server based on the identity information; sending the identity credential information to a target terminal and storing it on the target terminal, wherein the target terminal is used to apply for identity authentication to a second operating server based on the first identity identifier of the target account, the credit credential information of the target account on the first operating server, and the pre-stored identity credential information when applying for a digital wallet account based on the target account, wherein the first operating server is the operating server to which the target account belongs, and the second operating server is the digital wallet account issuing server.
[0010] According to another aspect of an embodiment of the present invention, a method for applying for and verifying a digital wallet account is also provided, including: receiving a verification request from a second operating server for applying for a digital wallet for a target account, wherein the verification request carries the first identity identifier of the target account, the second identity identifier of the first operating server, and the fourth identity identifier of the identity certificate issuing server, the first operating server is the operating server to which the target account belongs, and the second operating server is the digital wallet account issuing server; based on the first identity document of the target account, the second identity document of the first operating server, and the fourth identity document of the identity certificate issuing server, finding the first public key corresponding to the first identity identifier, the third public key corresponding to the second identity identifier, and the fourth public key corresponding to the fourth identity identifier, wherein the first identity document includes the first public key and the fourth public key. The correspondence between the first identity identifiers, the second identity document includes the correspondence between the third public key and the second identity identifier, and the fourth identity document includes the correspondence between the fourth public key and the fourth identity identifier; the first public key, the third public key and the fourth public key are sent to the second operation server, for the second operation server to verify the signature ciphertext, credit signature and identity signature of the target account, wherein the signature ciphertext is obtained by the target terminal using the first private key to sign the first identity identifier, the credit signature is obtained by the first operation server using the third private key to sign the credit certificate of the target account, and the identity signature is obtained by the identity certificate issuing server using the fourth private key to sign the identity certificate of the target account, and the identity signature is pre-stored in the target terminal.
[0011] According to one aspect of an embodiment of the present invention, a method for applying for and verifying a digital wallet account is provided, comprising: a target terminal receiving an application operation for applying for a digital wallet account based on a target account; the target terminal, in response to the application operation, sends a request for applying for a digital wallet account to a first operating server, wherein the first operating server is the operating server to which the target account belongs; the first operating server, in response to the request, obtains credit credential information of the target account on the first operating server, and feeds back the credit credential information to the target terminal; the target terminal obtains pre-stored identity credential information of the target account on an identity credential issuing server; the target terminal sends a first identity identifier, the credit credential information, and the identity credential information to a second operating server, wherein the second operating server is a digital wallet account issuing server; the second operating server verifies the target account based on the first identity identifier, the credit credential information, and the identity credential information, and generates a target digital wallet account if the verification passes; the second operating server returns an application result including the target digital wallet account to the target terminal.
[0012] According to one aspect of an embodiment of the present invention, a digital wallet account application verification device is provided, comprising: a first receiving module for receiving an application operation for applying for a digital wallet account based on a target account; a first obtaining module for obtaining, in response to the application operation, credit credential information of the target account on a first operating server, wherein the first operating server is the operating server to which the target account belongs; a second obtaining module for obtaining pre-stored identity credential information of the target account on an identity credential issuing server; a first sending module for sending the first identity identifier, the credit credential information, and the identity credential information of the target account to a second operating server, so that the second operating server authenticates the target account based on the credit credential information and the identity credential information, wherein the second operating server is a digital wallet account issuing server; a first result returning module for receiving an application result returned by the second operating server, wherein the application result includes a target digital wallet account, and the target digital wallet account is generated by the second operating server when the target account is successfully verified based on the first identity identifier, the credit credential information, and the identity credential information.
[0013] According to one aspect of an embodiment of the present invention, a digital wallet account application verification device is provided, including: a second receiving module, used to receive a request from a target account to apply for a digital wallet account, wherein the request carries the first identity identifier of the target account, the credit credential information of the target account on the first operating server, and the identity credential information of the target account on the identity credential issuing server, the identity credential information is pre-stored in the target terminal, wherein the first operating server is the operating server to which the target account belongs; a first verification module, used to verify the target account based on the first identity identifier, the credit credential information and the identity credential information; a second result returning module, used to generate a target digital wallet account if the verification is passed, and return the target digital wallet account to the target terminal in the application result.
[0014] According to one aspect of an embodiment of the present invention, a digital wallet account application verification device is provided, including: a third receiving module for receiving a request from a target account to apply for a digital wallet account; a first generating module for generating, in response to the above request, credit credential information of the above target account on a first operating server, wherein the above first operating server is the operating server to which the above target account belongs; a first feedback module for feeding back the above credit credential information to a target terminal, so that the above target terminal applies for a digital wallet account from a second operating server in combination with a first identity identifier and identity credential information pre-stored in the above target terminal, wherein the above identity credential information is the identity credential of the above target account on an identity credential issuing server, wherein the above second operating server is a digital wallet account issuing server.
[0015] According to one aspect of an embodiment of the present invention, a digital wallet account application verification device is provided, including: a fourth receiving module for receiving a request from a target account to apply for an identity credential, wherein the above request carries the identity information of the above target account; a third obtaining module for obtaining, in response to the above request, the identity credential information of the above target account on the identity credential issuing server based on the above identity information; a second sending module for sending the above identity credential information to a target terminal and storing it on the above target terminal, wherein the above target terminal is used to apply for identity authentication to a second operating server based on the first identity identifier of the above target account, the credit credential information of the above target account on the first operating server, and the pre-stored identity credential information when applying for a digital wallet account based on the above target account, wherein the above first operating server is the operating server to which the above target account belongs, and the above second operating server is the digital wallet account issuing server.
[0016] According to one aspect of an embodiment of the present invention, a digital wallet account application verification device is provided, including: a fifth receiving module, used to receive a verification request from a second operating server for a target account to apply for a digital wallet, wherein the verification request carries the first identity identifier of the target account, the second identity identifier of the first operating server and the fourth identity identifier of the identity certificate issuing server, the first operating server is the operating server to which the target account belongs, and the second operating server is the digital wallet account issuing server; a first searching module, used to find the first public key corresponding to the first identity identifier, the third public key corresponding to the second identity identifier, and the fourth public key corresponding to the fourth identity identifier based on the first identity document of the target account, the second identity document of the first operating server, and the fourth identity document of the identity certificate issuing server, wherein the first identity document includes the first The correspondence between the public key and the above-mentioned first identity identifier, the correspondence between the above-mentioned third public key and the above-mentioned second identity identifier included in the above-mentioned second identity document, and the correspondence between the above-mentioned fourth public key and the above-mentioned fourth identity identifier included in the above-mentioned fourth identity document; a third sending module, used to send the above-mentioned first public key, the above-mentioned third public key and the above-mentioned fourth public key to the above-mentioned second operation server, for the above-mentioned second operation server to verify the signature ciphertext, credit signature, and identity signature of the above-mentioned target account, wherein the above-mentioned signature ciphertext is obtained by the target terminal using the first private key to sign the above-mentioned first identity identifier, the above-mentioned credit signature is obtained by the above-mentioned first operation server using the third private key to sign the credit certificate of the above-mentioned target account, and the above-mentioned identity signature is obtained by the above-mentioned identity certificate issuing server using the fourth private key to sign the identity certificate of the above-mentioned target account, and the above-mentioned identity signature is pre-stored in the target terminal.
[0017] According to one aspect of an embodiment of the present invention, a digital wallet account application verification device is provided, comprising: a sixth receiving module, configured for a target terminal to receive an application operation for applying for a digital wallet account based on a target account; a first application module, configured for the target terminal to respond to the application operation and send a request for applying for a digital wallet account to a first operating server, wherein the first operating server is an operating server to which the target account belongs; a fourth acquisition module, configured for the first operating server to respond to the request and obtain credit credential information of the target account on the first operating server, and to feed back the credit credential information to the target terminal; a fifth acquisition module, configured for the target terminal to obtain The pre-stored identity credential information of the above-mentioned target account on the identity credential issuing server; the fourth sending module, which is used for the above-mentioned target terminal to send the first identity identifier, the above-mentioned credit credential information and the above-mentioned identity credential information to the second operation server, wherein the above-mentioned second operation server is the digital wallet account issuing server; the second verification module, which is used for the above-mentioned second operation server to verify the above-mentioned target account based on the above-mentioned first identity identifier, the above-mentioned credit credential information and the above-mentioned identity credential information, and generate a target digital wallet account if the verification is successful; the third result returning module, which is used for the above-mentioned second operation server to return the application result including the above-mentioned target digital wallet account to the above-mentioned target terminal.
[0018] According to one aspect of an embodiment of the present invention, a digital wallet account application verification system is provided, comprising: a target terminal, configured to receive an application operation for a digital wallet account based on a target account; in response to the application operation, sending a request for applying for a digital wallet account to a first operating server, wherein the first operating server is the operating server to which the target account belongs; the first operating server, connected to the target terminal, configured to obtain credit credential information of the target account on the first operating server in response to the request, and feed back the credit credential information to the target terminal; the target terminal is further configured to obtain pre-stored identity credential information of the target account on an identity credential issuing server; sending a first identity identifier, the credit credential information, and the identity credential information to a second operating server, wherein the second operating server is a digital wallet account issuing server; the second operating server, connected to the target terminal, configured to verify the target account based on the first identity identifier, the credit credential information, and the identity credential information, and generate a target digital wallet account if the verification passes; and returning an application result including the target digital wallet account to the target terminal.
[0019] According to one aspect of an embodiment of the present invention, a non-volatile storage medium is provided, wherein the non-volatile storage medium stores a plurality of instructions, and the instructions are suitable for being loaded and executed by a processor for executing any one of the above-mentioned digital wallet account application verification methods.
[0020] According to one aspect of an embodiment of the present invention, an electronic device is provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the above-mentioned digital wallet account application verification methods.
[0021] In an embodiment of the present invention, a digital wallet account application verification method is adopted, by receiving an application operation for a digital wallet account based on a target account; in response to the above application operation, obtaining the credit credential information of the above target account on a first operating server, wherein the above first operating server is the operating server to which the above target account belongs; obtaining the pre-stored identity credential information of the above target account on the identity credential issuing server; sending the first identity identifier of the above target account, the above credit credential information and the above identity credential information to a second operating server, so that the above second operating server authenticates the above target account based on the above credit credential information and the above identity credential information, wherein the above second operating server is a digital wallet account Issuing server; receiving the application result returned by the above-mentioned second operating server, wherein the above-mentioned application result includes the target digital wallet account, and the above-mentioned target digital wallet account is generated by the above-mentioned second operating server when the above-mentioned target account is verified based on the above-mentioned first identity identifier, the above-mentioned credit credential information and the above-mentioned identity credential information. The purpose of authenticating the target account based on the pre-acquired credit credential information and identity credential information when the target account applies for a digital wallet account is achieved, thereby achieving the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, thereby solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage existing in related technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0023] Figure 1 1 is a schematic diagram of the architecture of a digital wallet account application verification system provided according to an embodiment of the present invention;
[0024] Figure 2is a flow chart of a method for applying for and verifying a digital wallet account according to an embodiment of the present invention;
[0025] Figure 3 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention;
[0026] Figure 4 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention;
[0027] Figure 5 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention;
[0028] Figure 6 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention;
[0029] Figure 7 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention;
[0030] Figure 8 is a timing flow chart of an optional digital wallet account application verification method according to an embodiment of the present invention;
[0031] Figure 9 2. It is a structural diagram of a digital wallet account application verification system according to an embodiment of the present invention;
[0032] Figure 10 2 is a schematic diagram of the structure of another digital wallet account application verification system according to an embodiment of the present invention;
[0033] Figure 11 2. It is a schematic structural diagram of a digital wallet account application verification device according to an embodiment of the present invention;
[0034] Figure 12 2 is a schematic diagram of the structure of another digital wallet account application verification device according to an embodiment of the present invention;
[0035] Figure 13 2 is a schematic diagram of the structure of another digital wallet account application verification device according to an embodiment of the present invention;
[0036] Figure 14 2 is a schematic diagram of the structure of another digital wallet account application verification device according to an embodiment of the present invention;
[0037] Figure 15 2 is a schematic diagram of the structure of another digital wallet account application verification device according to an embodiment of the present invention;
[0038] Figure 162 is a schematic diagram of the structure of another digital wallet account application verification device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0039] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0040] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0041] First, to facilitate understanding of the embodiments of the present invention, some of the terms or nouns involved in the present invention are explained below:
[0042] Customer identity identification refers to the process by which financial institutions identify and conduct background checks on customers when establishing business relationships with them.
[0043] The digital RMB operates on a two-tiered system, with a limited number of second-tier operating institutions. To enable more users to use the digital RMB, an ecosystem has been formed: the central bank, second-tier operating institutions, 2.5-tier operating institutions, and users. Users of a 2.5-tier operating institution can apply to a second-tier operating institution to open a digital RMB wallet and access digital RMB services.
[0044] Digital wallet users, consumers who use digital wallet applications (combined with security capabilities such as security chips or trusted execution environments) to make transactions and payments, must fulfill their customer identity identification obligations.
[0045] 2.5-layer operating organizations participate in the circulation of digital currencies but are not responsible for opening wallet accounts.
[0046] The second-tier operating organization, the operating organization of the digital RMB, is responsible for wallet account opening, circulation and other matters.
[0047] Blockchain distributed identity management system: A system based on blockchain technology that issues distributed identity identifiers (DIDs) to relevant parties and generates and manages distributed identity documents.
[0048] A trusted certificate issuing agency is an agency that provides various trusted certificates to users (individual users or corporate users). In this solution, it mainly verifies users online and issues verifiable electronic certificates corresponding to the trusted certificates.
[0049] A blockchain is a chain of blocks. Each block contains a specific piece of information, linked together in chronological order. This chain is stored across all servers, and as long as at least one server in the system is functioning, the entire blockchain remains secure. These servers, called nodes in the blockchain system, provide storage space and computing power. Modifying information in the blockchain requires the consent of more than half of the nodes and the modification of all nodes. These nodes are often controlled by different entities, making tampering with blockchain information extremely difficult. Compared to traditional networks, blockchains possess two core advantages: data tampering resistance and decentralization. These two characteristics make the information recorded in blockchains more authentic and reliable, helping to address issues of mutual trust.
[0050] Figure 1 : is a schematic diagram of the architecture of a digital wallet account application verification system provided according to an embodiment of the present invention. Figure 1As shown, the application verification system for the digital wallet account includes: a blockchain distributed identity management system, a first operating server corresponding to the 2.5-layer operating organization, a second operating server corresponding to the second-layer operating organization, an identity certificate issuing server corresponding to the trusted certificate issuing structure, and a target terminal corresponding to the 2.5-layer operating organization user. The specific interaction process is: the 2.5-layer operating organization, the second-layer operating organization and the target terminal generate their own public keys and submit them to the blockchain distributed identity management system. The blockchain identity management system generates corresponding distributed identity identification and identity documents for the 2.5-layer operating organization, the second-layer operating organization and the target terminal; the target terminal sends public keys to the 2.5-layer operating organization and the trusted certificate issuing organization respectively. Initiate a credential application, and the 2.5-layer operating organization and the trusted credential issuing organization return a verifiable credit credential and a verifiable identity credential respectively, and save them to the target terminal; when the 2.5-layer operating organization user initiates a digital wallet account application based on the target terminal, the second-layer operating organization queries the corresponding identity document in the blockchain distributed identity management system based on the user's distributed digital identity identifier DID, and obtains the corresponding public key; the second-layer operating organization decrypts and verifies the user's verifiable credit credential and verifiable identity credential based on the obtained data. If both the verified credit credential and the verifiable identity credential are verified successfully, the second-layer operating organization returns the application result to the target terminal, where the application result includes the digital wallet account.
[0051] It should be noted that the multiple computing nodes on the distributed processing cluster are provided or deployed based on various virtualization technologies supported by the multiple computing nodes. In some embodiments, services can be provided based on virtual machine (VM)-based virtualization, container-based virtualization and / or similar methods. Virtual machine-based virtualization can be to simulate a real computer by initializing a virtual machine, and execute programs and applications without directly contacting any actual hardware resources. While the virtual machine virtualizes the machine, according to container-based virtualization, a container can be started to virtualize the entire operating system (OS) so that multiple workloads can run on a single operating system instance.
[0052] According to an embodiment of the present invention, an embodiment of a method for application verification of a digital wallet account is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in an order different from that shown here.
[0053] Figure 2 : is a flow chart of a method for applying for and verifying a digital wallet account according to an embodiment of the present invention. Figure 2 As shown, the method includes the following steps:
[0054] Step S202: receiving an application for a digital wallet account based on the target account;
[0055] Step S204: In response to the application operation, obtain the credit credential information of the target account on the first operating server;
[0056] Step S206: Obtain the pre-stored identity credential information of the target account on the identity credential issuing server;
[0057] Step S208: Send the first identity identifier of the target account, the credit credential information, and the identity credential information to the second operating server, so that the second operating server performs identity authentication on the target account based on the credit credential information and the identity credential information.
[0058] Step S210: Receive the application result returned by the second operating server, wherein the application result includes a target digital wallet account, and the target digital wallet account is generated by the second operating server when the target account is verified based on the credit credential information and the identity credential information.
[0059] It is understood that the execution entity of steps S202 to S210 is the target terminal corresponding to the target account. The target account may be, but is not limited to, a bank account or a payment account. The first operation server is the operation server to which the target account belongs; the second operation server is the digital wallet account issuing server; and the operation service level of the second operation server is higher than that of the first operation server. The operation service level indicates the service capabilities of the operation server. The higher the operation service level, the richer the service capabilities. For example, the second operation server has the service capability to open a digital wallet account for the target account, while the second operation server does not. For example, the target account is the target account corresponding to a digital wallet user of a 2.5-tier operation institution; the first operation server is the server corresponding to the 2.5-tier operation institution; the identity credential issuing server is the server corresponding to the trusted credential issuing institution; and the second operation server is the server corresponding to the second-tier operation institution. The credit credential information may be a verifiable credit credential of the target account issued by the first operation server; and the identity credential information may be a verifiable identity credential of the target account issued by the trusted credential issuing institution.
[0060] Optionally, the credit credential information is determined based on historical transactions and historical credit of the target account on the first operating server; and the identity credential information is obtained from at least one identity credential issuing server.
[0061] Through the above steps, from the perspective of the target terminal, after receiving the application operation for a digital wallet account based on the target account, the target terminal responds to the digital wallet account application operation of the target account, obtains the first identity identifier, credit credential information and pre-stored identity credential information of the target account, and sends the first identity identifier, credit credential information and the pre-stored identity credential information to the second operation server to authenticate the target account. When the first identity identifier, the credit credential information and the pre-stored identity credential information are all verified, the target terminal receives the application result of the target digital wallet account application success from the second operation server. It can be seen that in this embodiment of the present invention, the customer identity identification information (i.e., credit credential information and identity credential information) of the target account is pre-stored securely in the target terminal. When the target account applies for a digital wallet account of any second-tier operating institution, the target terminal can verify the credit credential information and the pre-stored identity credential information to determine whether to open a digital wallet account for the target user, thereby avoiding the user from submitting the same customer identity identification information multiple times, simplifying the digital wallet account application process, improving the efficiency of user identity authentication and thus improving the user experience.
[0062] In an embodiment of the present invention, a digital wallet account application verification method is adopted, by receiving an application operation for applying for a digital wallet account based on a target account; in response to the above application operation, obtaining the credit credential information of the above target account on the first operating server; obtaining the identity credential information of the above target account on the identity credential issuing server that is pre-stored; sending the first identity identifier, the above credit credential information and the above identity credential information of the above target account to the second operating server; receiving the application result returned by the above second operating server, wherein the above application result includes the target digital wallet account, and the above target digital wallet account is generated by the above second operating server when the above target account is verified based on the above first identity identifier, the above credit credential information and the above identity credential information. This achieves the purpose of authenticating the target account based on the pre-acquired credit credential information and identity credential information when the target account applies for a digital wallet account, thereby realizing the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, thereby solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage existing in the related technology.
[0063] In an optional embodiment, in response to the application operation, obtaining the credit credential information of the target account on the first operating server includes:
[0064] In response to the application operation, sending a digital wallet account application request to the first operator server;
[0065] receiving the credit credential information of the target account on the first operating server returned by the first operating server;
[0066] Optionally, the credit credential information is determined based on the historical transactions and historical credit of the target account on the first operating server, and the credit credential information includes the credit credential of the target account and the credit signature corresponding to the credit credential.
[0067] Optionally, after receiving the application operation for applying for a digital wallet account based on the target account, the target terminal sends the digital wallet account application request to the first operating server, and the above-mentioned first operating server obtains credit credential information based on the historical transactions and historical credit of the target account; the target terminal receives the above-mentioned credit credential information.
[0068] In an optional embodiment, before obtaining the pre-stored identity credential information of the target account on the identity credential issuing server, the method further includes:
[0069] Sending a request to verify the identity certificate to the above-mentioned identity certificate issuing server;
[0070] Receive the identity credential information returned by the identity credential issuing server and store the identity credential information.
[0071] Optionally, the above-mentioned identity credential information includes the identity credential of the above-mentioned target account and the identity signature corresponding to the above-mentioned identity credential.
[0072] Optionally, the above-mentioned identity credential information can be a verifiable credit credential issued by a trusted credential issuing agency, that is, a verifiable credit credential returned by an identity credential issuing server; it can also be multiple verifiable credit credentials issued by multiple trusted credential issuing agencies, that is, multiple verifiable credit credentials returned by multiple identity credential issuing servers.
[0073] Optionally, when there are multiple identity credential issuing servers, the target terminal sends an identity credential verification request to the multiple identity credential issuing servers. The multiple identity credential issuing servers authenticate the target account based on the identity authentication information submitted by the target user, and generate multiple verifiable credentials as the above-mentioned identity credential information. The target terminal receives the identity credential information returned by the multiple identity credential issuing servers.
[0074] In an optional embodiment, sending the first identity identifier of the target account, the credit credential information, and the identity credential information to the second operation server includes:
[0075] Obtaining the first public-private key pair of the target account and the second public key of the second operating server, wherein the first public-private key pair includes a first public key and a first private key;
[0076] Encrypting the credit credential information and the identity credential information using the second public key to obtain a credential ciphertext, and signing the first identity identifier using the first private key to obtain a signature ciphertext;
[0077] The above-mentioned certificate ciphertext, the above-mentioned signature ciphertext, and the above-mentioned first public key are sent to the above-mentioned second operation server, so that the above-mentioned second operation server uses the second private key of the above-mentioned second operation server to decrypt the above-mentioned certificate ciphertext, obtain the above-mentioned credit certificate information and the above-mentioned identity certificate information, and use the above-mentioned first public key to verify the above-mentioned signature.
[0078] It can be understood that the above-mentioned first public-private key pair is the public-private key pair Pk_user_a / Sk_user_a corresponding to the target account a of the digital wallet user, wherein Pk_user_a is the first public key and Sk_user_a is the first private key, which is mainly used to declare to the digital wallet server (i.e., the second operating server) by signing that the distributed digital identity (DID, Distributed Identity) submitted by it belongs to the user. In order to enhance data security, the public keys in the embodiments of the present invention are all public key certificates. The above-mentioned second operating server corresponds to the second public-private key pair Pk_Regi_B / Sk_Regi_B, and the above-mentioned second public key Pk_Regi_B is the public key corresponding to the second-tier operating organization.
[0079] Optionally, the first identity identifier of the target account may be, but is not limited to, a distributed digital identity identifier DID_wallet_a corresponding to the target account.
[0080] Optionally, the target terminal obtains the first public-private key pair Pk_user_a / Sk_user_a of the target account, and the second public key Pk_Regi_B corresponding to the second-layer operating organization; uses the above-mentioned second public key Pk_Regi_B to encrypt the credit certificate information issued by the 2.5-layer operating organization and the identity certificate information issued by the trusted certificate issuing organization to obtain the certificate ciphertext, and uses the first private key Sk_user_a to sign the first identity identifier DID_wallet_a of the target account to obtain the signature ciphertext; sends the above-mentioned certificate ciphertext, the above-mentioned signature ciphertext, and the above-mentioned first public key Pk_user_a to the second operating server corresponding to the second-layer operating organization, thereby improving the security of data transmission and effectively ensuring the privacy of users.
[0081] Figure 3is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention. Figure 3 As shown, the method includes the following steps:
[0082] Step S302: Receive a request from a target account to apply for a digital wallet account, wherein the request carries a first identity identifier of the target account, credit credential information of the target account on a first operating server, and identity credential information of the target account on an identity credential issuing server, wherein the identity credential information is pre-stored in the target terminal, wherein the first operating server is the operating server to which the target account belongs;
[0083] Step S304: Verify the target account based on the first identity identifier, the credit credential information, and the identity credential information;
[0084] Step S306: If the verification is successful, a target digital wallet account is generated, and the target digital wallet account is included in the application result and returned to the target terminal.
[0085] It can be understood that the execution entity of the above steps S302 to S306 is the second operating server, that is, the server corresponding to the second-tier operating organization; the above-mentioned target account is the target account corresponding to the digital wallet user; the above-mentioned first operating server is the server corresponding to the 2.5-tier operating organization; the above-mentioned identity certificate issuing server is the server corresponding to the trusted certificate issuing organization; the above-mentioned credit certificate information can be a verifiable credit certificate of the target account issued by the first operating server; the above-mentioned identity certificate information can be a verifiable identity certificate of the target account issued by the trusted certificate issuing organization.
[0086] Through the above steps, from the perspective of the second operating server, after receiving the target account's request to apply for a digital wallet account, the second operating server verifies the target account's first identity identifier, credit credential information, and identity credential information carried in the request. If the first identity identifier, credit credential information, and identity credential information are all verified, the digital wallet account is opened for the target account and the target digital wallet account is returned to the target terminal along with the application result. It can be seen that in this embodiment of the present invention, the target account's customer identity identification information (i.e., credit credential information and identity credential information) is pre-securely stored in the target terminal. When the target account applies for a digital wallet account at any second-tier operating institution, the target account's first identity identifier and the customer identity identification information are sent to the second operating server corresponding to the corresponding second-tier operating institution. The target account's application for a digital wallet account at any second-tier operating institution can be verified by verifying the credit credential information and identity credential information pre-stored in the target terminal to determine whether to open a digital wallet account for the target user. This avoids users from submitting the same type of customer identity identification information multiple times, simplifies the digital wallet account application process, improves user identity authentication efficiency, and thus enhances user experience.
[0087] In an embodiment of the present invention, a request for applying for a digital wallet account from a target account is received, wherein the request carries the first identity identifier of the target account, the credit credential information of the target account on the first operating server, and the identity credential information of the target account on the identity credential issuing server, and the identity credential information is pre-stored in the target terminal; the target account is verified based on the first identity identifier, the credit credential information and the identity credential information; if the verification is successful, a target digital wallet account is generated, and the target digital wallet account is returned to the target terminal along with the application result, thereby achieving the purpose of authenticating the target account based on the pre-acquired credit credential information and identity credential information when the target account applies for a digital wallet account, and determining the corresponding application result based on the verification result, thereby achieving the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, thereby solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage existing in the related art.
[0088] In an optional embodiment, the receiving of the target account's request to apply for a digital wallet account includes:
[0089] Obtain a second public-private key pair from a second operating server, wherein the second public-private key pair includes a second public key and a second private key, and wherein the second operating server is a digital wallet account issuing server;
[0090] Sending the second public key to the target terminal, wherein the second public key is used to encrypt the credit credential information and the identity credential information to obtain a credential ciphertext;
[0091] Receive a request sent by the target terminal to apply for a digital wallet account based on the target account, wherein the request carries the credential ciphertext, the signature ciphertext, and the first public key of the target account, and the signature ciphertext is obtained by signing the first identity identifier using the first private key.
[0092] It can be understood that the above-mentioned second public-private key is the public-private key pair Pk_Regi_B / Sk_Regi_B corresponding to the second-layer operating organization, where Pk_Regi_B is the second public key and Sk_Regi_B is the second private key. In order to enhance data security, the above-mentioned second public key can be set to the form of a public key certificate.
[0093] Optionally, the second operating server sends the second public key Pk_Regi_B to the target terminal, wherein the target terminal is used to use the second public key Pk_Regi_B to encrypt the credit credential information issued by the 2.5-layer operating agency and the identity credential information issued by the trusted credential issuing agency to obtain the credential ciphertext; on this basis, the target terminal receives the request sent by the above-mentioned target terminal to apply for a digital wallet account based on the target account, and the request carries the above-mentioned credential ciphertext, signature ciphertext, and the first public key of the above-mentioned target account, thereby improving data transmission security and effectively ensuring user privacy.
[0094] In an optional embodiment, the verification of the target account based on the first identity identifier, the credit credential information, and the identity credential information includes:
[0095] Decrypting the credential ciphertext using the second private key to obtain the credit credential information and the identity credential information, and verifying the signature ciphertext using the first public key to obtain the first identity identifier, wherein the credit credential information includes the credit credential of the target account and the credit signature corresponding to the credit credential, and the identity credential information includes the identity credential of the target account and the identity signature corresponding to the identity credential;
[0096] If the signature ciphertext verification passes, the identity document of the target account is queried on the blockchain distributed identity management system based on the first identity identifier, wherein the identity document stores the correspondence between the target account and the first public key of the target account, the correspondence between the first operating server and the third public key of the first operating server, and the correspondence between the identity certificate issuing server and the fourth public key of the identity certificate issuing server;
[0097] The third public key is used to verify the credit signature, and the fourth public key is used to verify the identity signature.
[0098] Optionally, the third public key is the public key corresponding to the credit credential information, that is, the credential verification public key Pk_issuer_A corresponding to the verifiable credit credential issued by the layer 2.5 operating organization (that is, the first operating server); the fourth public key is the public key corresponding to the identity credential information, that is, the identity credential verification public keys Pk_issuer_1, Pk_issuer_2,…, Pk_issuer_n corresponding to multiple verifiable identity credentials issued by multiple trusted credential issuing organizations (that is, identity credential issuing servers).
[0099] Optionally, the second operating server corresponding to the second operating organization uses the first public key Pk_user_a of the target account carried in the request to decrypt the signed ciphertext to obtain the first identity identification DID_wallet_a of the target account; uses the second private key Sk_Regi_B to decrypt the credential ciphertext carried in the request to obtain the credit credential information and identity credential information corresponding to the target account; according to the identification information DID_wallet_a corresponding to the target account, the identity document DID-Doc_Wallet_a of the target account is queried on the blockchain distributed identity management system, and the credit credential verification public key Pk_issuer_A corresponding to the verifiable credit credential and the identity credential verification public keys Pk_issuer_1, Pk_issuer_2,…, Pk_issuer_n corresponding to the verifiable identity credential are obtained, and the validity of the signatures corresponding to the verifiable credit credential Credential_A-a and the verifiable identity credentials Credential_V1_a, Credential_V2_a,…, Credential_Vn_a are verified.
[0100] Figure 4 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention. Figure 4 As shown, the method includes the following steps:
[0101] Step S402: receiving a request from a target account to apply for a digital wallet account;
[0102] Step S404: In response to the request, generating credit credential information of the target account on a first operating server, wherein the first operating server is the operating server to which the target account belongs;
[0103] Step S406: Feedback the credit credential information to the target terminal, so that the target terminal can apply for a digital wallet account from the second operator server in combination with the first identity identifier and the identity credential information pre-stored in the target terminal, wherein the identity credential information is the identity credential of the target account on the identity credential issuing server, and the second operator server is the digital wallet account issuing server.
[0104] It can be understood that the execution entity of the above steps S402 to S406 is the first operating server, that is, the server corresponding to the 2.5-layer operating organization; the above target account is the target account corresponding to the digital wallet user; the above second operating server is the server corresponding to the second-layer operating organization; the above identity certificate issuing server is the server corresponding to the trusted certificate issuing organization; the above credit certificate information can be a verifiable credit certificate of the target account issued by the first operating server; the above identity certificate information can be a verifiable identity certificate of the target account issued by the trusted certificate issuing organization.
[0105] Optionally, the credit credential information is determined based on the target account's historical transactions and credit history on the first operating server. The credit credential information may include, but is not limited to, the target account's credit rating at a Tier 2.5 operating institution (e.g., the target account is a user with good credit), the time the target account underwent customer identity authentication, and the like.
[0106] Through the above steps, from the side of the first operating server, after receiving the target account's request to apply for a digital wallet account, the first operating server generates the credit credential information of the target account on the first operating server, and returns the generated credit credential information of the target account on the first operating server to the target terminal. It can be seen that in the embodiment of the present invention, the credit credential information issued by the first operating server is pre-safely stored in the target terminal. When the target account applies for a digital wallet account of any second-tier operating institution, the credit credential information is sent to the second operating server corresponding to the corresponding second-tier operating institution. When the target account submits an application for a digital wallet account of any second-tier operating institution, it can determine whether to open a digital wallet account for the target user by verifying the credit credential information pre-stored in the target terminal, thereby avoiding the user from submitting the same type of credit credential information multiple times, simplifying the digital wallet account application process, improving the efficiency of user identity authentication, and thus improving the user experience.
[0107] In an embodiment of the present invention, a request for applying for a digital wallet account from a target account is received; in response to the above request, credit credential information of the above target account on the above first operating server is generated; the above credit credential information is fed back to the above target terminal, so that the above target terminal applies for a digital wallet account from the second operating server in combination with the first identity identifier and the identity credential information pre-stored in the above target terminal, thereby achieving the purpose of sending the pre-acquired credit credential information to the target terminal so as to facilitate identity authentication of the target account when the target account applies for a digital wallet account, thereby realizing the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, and further solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage existing in the related technology.
[0108] In an optional embodiment, the credit credential information includes the credit credential of the target account and a credit signature corresponding to the credit credential. The generating, in response to the request, the credit credential information of the target account on the first operating server includes:
[0109] In response to the request, obtaining historical transactions and historical credit of the target account on the first operating server;
[0110] Generate a credit certificate for the target account based on the historical transactions and the historical credit.
[0111] The credit certificate is signed using the third private key of the first operating server to obtain the credit signature corresponding to the credit certificate.
[0112] In an optional embodiment, generating the credit certificate of the target account based on the historical transactions and the historical credit includes:
[0113] Determine whether there is account privacy information in the above historical transactions and the above historical credit;
[0114] If the above-mentioned account privacy information exists in the above-mentioned historical transactions and the above-mentioned historical credit, the above-mentioned credit certificate is generated by zero-knowledge proof based on the above-mentioned historical transactions and the above-mentioned historical credit.
[0115] Optionally, when it is detected that the historical transactions and historical credit of the target account in the first operating server contain private information, a credit credential of the target account in the first operating server is generated based on the historical transactions and historical credit using a zero-knowledge proof method.
[0116] It should be noted that the credit credential information generated by zero-knowledge proof allows the prover to convince the verifier that the credit credential information is correct without providing any useful information to the verifier. This means that during the proof process, no historical transaction history or credit history of the target account needs to be disclosed to the verifier, effectively protecting user privacy.
[0117] Optionally, when the target account of a 2.5-layer operating institution wants to apply for a digital wallet account from a second-layer operating institution, the first operating server corresponding to the 2.5-layer operating institution generates a credit certificate that can verify the target account based on the historical transactions and historical evaluations of the target account, and uses the third private key of the first operating server to sign the above credit certificate to obtain the above credit signature corresponding to the above credit certificate, and uses the above credit certificate and the above credit signature as the credit certificate information corresponding to the target account.
[0118] In an optional embodiment, feeding back the credit credential information to the target terminal includes:
[0119] Receive the first public key of the target account;
[0120] Encrypting the credit certificate information using the first public key to obtain a credit certificate ciphertext;
[0121] The credit certificate ciphertext is sent to the target terminal.
[0122] Optionally, when the target account of a 2.5-layer operating institution wants to apply for a digital wallet account from a second-layer operating institution, the first operating server corresponding to the 2.5-layer operating institution receives the first public key from the target account, generates a verifiable credit certificate as the credit certificate information of the target account based on the historical transactions and historical evaluations of the target account, and uses the first public key to encrypt the above credit certificate information to obtain the credit certificate ciphertext, and securely transmits the above credit certificate ciphertext to the above target terminal, thereby improving data transmission security and effectively ensuring user privacy.
[0123] In an optional embodiment, the above method further includes:
[0124] Obtain the third public key of the first operating server;
[0125] The above-mentioned third public key, the correspondence between the above-mentioned first operation server and the above-mentioned third public key, and the correspondence between the above-mentioned third public key and the above-mentioned target account are sent to the blockchain distributed identity management system, so that the above-mentioned blockchain distributed identity management system updates the above-mentioned third public key, the correspondence between the above-mentioned first operation server and the above-mentioned third public key, and the correspondence between the above-mentioned third public key and the above-mentioned target account in the second identity document corresponding to the above-mentioned first operation server.
[0126] Optionally, the third public key is the public key corresponding to the credit credential information, that is, the credential verification public key Pk_issuer_A corresponding to the verifiable identity credential issued by the layer 2.5 operating organization (that is, the first operating server); the second identity document can be used to store the correspondence between the first operating server and the third public key, as well as the correspondence between the third public key and the target account. When the target account applies for a digital wallet account, the second operating organization directly determines the third public key based on the correspondence stored in the second identity document, and uses the third public key to decrypt and verify the identity information of the target account.
[0127] It should be noted that, in an embodiment of the present invention, the blockchain distributed identity management system can also update the above-mentioned third public key, the correspondence between the above-mentioned first operating server and the above-mentioned third public key, and the correspondence between the above-mentioned third public key and the above-mentioned target account in the first identity document corresponding to the above-mentioned target account. When the target account applies for a digital wallet account, the second operating institution determines and obtains the above-mentioned third public key based on the correspondence stored in the above-mentioned first identity document, and uses the above-mentioned third public key to decrypt and verify the identity information of the target account.
[0128] Figure 5 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention. Figure 4 As shown, the method includes the following steps:
[0129] Step S502: receiving a request from a target account to apply for identity credentials, wherein the request carries the identity information of the target account;
[0130] Step S504: In response to the request, based on the identity information, obtain the identity credential information of the target account on the identity credential issuing server;
[0131] Step S506: Send the above-mentioned identity credential information to the above-mentioned target terminal and store it on the above-mentioned target terminal, wherein the above-mentioned target terminal is used to apply for identity authentication from the second operating server based on the credit credential information of the above-mentioned target account on the first operating server and the above-mentioned identity credential information stored in advance when the above-mentioned target account applies for a digital wallet account based on the first identity identifier of the above-mentioned target account.
[0132] Optionally, the first operation server is the operation server to which the target account belongs, the second operation server is a digital wallet account issuing server, and the operation service level of the second operation server is higher than that of the first operation server.
[0133] It can be understood that the execution entity of the above steps S502 to S506 is the identity credential issuing server, that is, the server corresponding to the trusted credential issuing institution; the above target account is the target account corresponding to the digital wallet user; the above first operation server is the server corresponding to the 2.5-layer operation institution; the above second operation server is the server corresponding to the second-layer operation institution; the above credit credential information can be the verifiable credit credential of the target account issued by the first operation server; the above identity credential information can be the verifiable identity credential of the target account issued by the trusted credential issuing institution.
[0134] Through the above steps, from the perspective of the identity credential issuing server, after receiving the target account's request to apply for a digital wallet account, the identity credential issuing server determines the target account's identity credential information based on the target account's identity information, wherein the above identity credential can be, but is not limited to, a verifiable identity credential issued for the target account by one or more trusted credential issuing institutions, and securely stores the above identity credential information on the target terminal corresponding to the target account. It can be seen that in this embodiment of the present invention, the target account's identity credential information is securely stored in advance in the target terminal. When the target account applies for a digital wallet account of any second-tier operating institution, the above identity credential information is sent to the second operating server corresponding to the corresponding second-tier operating institution. When the target account submits a digital wallet account application for any second-tier operating institution, the target account can verify the identity credential information pre-stored in the target terminal to determine whether to open a digital wallet account for the target user, thereby avoiding users from submitting the same type of identity credential information multiple times, simplifying the digital wallet account application process, improving user identity authentication efficiency, and thus improving user experience.
[0135] In an embodiment of the present invention, a request for applying for an identity credential from a target account is received, wherein the request carries the identity information of the target account; in response to the request, the identity credential information of the target account on the identity credential issuing server is obtained based on the identity information; the identity credential information is sent to the target terminal and stored on the target terminal, wherein the target terminal is used to apply for identity authentication from the second operating server based on the first identity identifier of the target account, the credit credential information of the target account on the first operating server, and the pre-stored identity credential information when applying for a digital wallet account based on the target account, thereby achieving the purpose of sending the pre-acquired identity credential information to the target terminal so as to authenticate the target account when the target account applies for a digital wallet account, thereby achieving the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, thereby solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage existing in the related technology.
[0136] In an optional embodiment, the identity credential information includes the identity credential of the target account and an identity signature corresponding to the identity credential. In response to the request, obtaining the identity credential information of the target account on the identity credential issuing server based on the identity information includes:
[0137] In response to the request, generating the identity credential of the target account based on the identity information;
[0138] Obtain the fourth private key of the identity certificate issuing server;
[0139] The identity certificate is signed using the fourth private key to obtain the identity signature corresponding to the identity certificate.
[0140] Optionally, the fourth public key is the public key corresponding to the identity credential information, that is, the identity credential verification public keys Pk_issuer_1, Pk_issuer_2, ..., Pk_issuer_n corresponding to multiple verifiable identity credentials issued by multiple trusted credential issuing agencies (i.e., identity credential issuing servers).
[0141] Optionally, the above-mentioned identity credential issuing server can be one or more. For example, when there are multiple identity credential issuing servers, the above-mentioned identity credential information includes multiple verifiable identity credentials. Multiple identity credential issuing servers respectively use corresponding identity credential verification public keys (i.e., the fourth private key) Pk_issuer_1, Pk_issuer_2,..., Pk_issuer_n to sign multiple verifiable identity credentials respectively, and obtain the above-mentioned identity signatures corresponding to the above-mentioned identity credentials, and use the above-mentioned identity credentials and the above-mentioned identity signatures as the identity credential information corresponding to the target account.
[0142] Optionally, the target account corresponding to the digital wallet user initiates a verifiable electronic identity certificate application to n trusted credential issuing agencies based on the identity information issued by the trusted credential issuing agency (such as an identity document, i.e., a physical document). The user submits relevant identity information according to the trusted credential issuing agency, executes relevant verification measures, and performs identity verification; the trusted credential issuing agency (such as agency 1) generates a verifiable identity credential Credential_V1_a corresponding to the target account based on the verifiable identity credential template, and signs it with its private key Sk_issuer_1. Other trusted credential issuing agencies generate other verifiable identity credentials Credential_V2_a,…, Credential_Vn_a in the same way, and use the above Credential_V1_a, Credential_V2_a,…, Credential_Vn_a as the identity credential information of the target account.
[0143] In an optional embodiment, the sending of the identity credential information to the target terminal and storing the identity credential information on the target terminal includes:
[0144] Receive the first public key of the target account;
[0145] Encrypt the identity credential information using the first public key to obtain an identity credential ciphertext;
[0146] Send the above identity credential ciphertext to the above target terminal.
[0147] Optionally, before the target account of the 2.5-tier operating organization applies for a digital wallet account from a second-tier operating organization, it must first obtain the identity credential information issued by a trusted credential issuing organization (i.e., the identity credential issuing server). The identity credential issuing server receives the first public key from the target account, generates identity credential information based on the identity information of the target account; uses the first public key to encrypt the above identity credential information to obtain the identity credential ciphertext; and securely transmits the above identity credential ciphertext to the above target terminal. For example, the above identity credential ciphertext is sent to the target account a corresponding to the digital wallet user, and saved to the digital wallet application APP where the target account a is located. This improves the security of data transmission and effectively ensures the privacy of users.
[0148] In an optional embodiment, the above method further includes:
[0149] Obtain the fourth public key of the identity certificate issuing server;
[0150] The above-mentioned fourth public key, the correspondence between the above-mentioned identity certificate issuing server and the above-mentioned fourth public key, and the correspondence between the above-mentioned fourth public key and the above-mentioned target account are sent to the blockchain distributed identity management system, so that the above-mentioned blockchain distributed identity management system updates the above-mentioned fourth public key, the correspondence between the above-mentioned identity certificate issuing server and the above-mentioned fourth public key, and the correspondence between the above-mentioned fourth public key and the above-mentioned target account in the fourth identity document corresponding to the above-mentioned identity certificate issuing server.
[0151] The above-mentioned fourth identity document can be used to store the above-mentioned fourth public key, the correspondence between the above-mentioned identity certificate issuing server and the above-mentioned fourth public key, and the correspondence between the above-mentioned fourth public key and the above-mentioned target account. When the target account applies for a digital wallet account, the trusted certificate issuing agency determines the above-mentioned fourth public key based on the correspondence stored in the above-mentioned identity document, and uses the above-mentioned fourth public key to decrypt and verify the identity information of the target account.
[0152] It should be noted that, in an embodiment of the present invention, the blockchain distributed identity management system can also update the above-mentioned fourth public key, the correspondence between the above-mentioned identity certificate issuing server and the above-mentioned fourth public key, and the correspondence between the above-mentioned fourth public key and the above-mentioned target account in the first identity document corresponding to the above-mentioned target account. When the target account applies for a digital wallet account, the second operating institution determines the above-mentioned third public key based on the correspondence stored in the above-mentioned first identity document, and uses the above-mentioned third public key to decrypt and verify the identity information of the target account.
[0153] Figure 6 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention. Figure 6As shown, the method includes the following steps:
[0154] Step S602: Receive a verification request from the second operator server for a digital wallet application for a target account, wherein the verification request carries the first identity identifier of the target account, the second identity identifier of the first operator server, and the fourth identity identifier of the identity credential issuing server;
[0155] Step S604: Based on the first identity document of the target account, the second identity document of the first operating server, and the fourth identity document of the identity credential issuing server, a first public key corresponding to the first identity identifier, a third public key corresponding to the second identity identifier, and a fourth public key corresponding to the fourth identity identifier are found, wherein the first identity document includes a correspondence between the first public key and the first identity identifier, the second identity document includes a correspondence between the third public key and the second identity identifier, and the fourth identity document includes a correspondence between the fourth public key and the fourth identity identifier;
[0156] Step S606: Send the first public key, the third public key and the fourth public key to the second operation server, so that the second operation server can verify the signature ciphertext, credit signature and identity signature of the target account, wherein the signature ciphertext is obtained by the target terminal signing the first identity identifier using the first private key, the credit signature is obtained by the first operation server signing the credit certificate of the target account using the third private key, and the identity signature is obtained by the identity certificate issuing server signing the identity certificate of the target account using the fourth private key, and the identity signature is pre-stored in the target terminal.
[0157] Optionally, the first operation server is the operation server to which the target account belongs, the second operation server is a digital wallet account issuing server, and the operation service level of the second operation server is higher than that of the first operation server.
[0158] It can be understood that the execution entity of the above steps S602 to S606 is the blockchain distributed identity management system; the above identity certificate issuing server is the server corresponding to the trusted certificate issuing agency; the above target account is the target account corresponding to the digital wallet user; the above first operation server is the server corresponding to the 2.5-layer operation agency; the above second operation server is the server corresponding to the second-layer operation agency; the above credit certificate information can be a verifiable credit certificate of the target account issued by the first operation server; the above identity certificate information can be a verifiable identity certificate of the target account issued by the trusted certificate issuing agency.
[0159] Through the above steps, from the perspective of the blockchain distributed identity management system, after the blockchain distributed identity management system receives the verification request from the second operating server for the target account to apply for a digital wallet, it searches for the relevant identity document based on the first identity identifier of the target account, the second identity identifier of the first operating server and the fourth identity identifier of the identity certificate issuing server carried in the verification request, and finds the corresponding public key in the corresponding identity document, and sends the public key (i.e., the first public key, the third public key and the fourth public key) to the second operating server, so that the second operating server can verify the signature ciphertext, credit signature and identity signature of the target account to complete the verification of the target account. It can be seen that in the embodiment of the present invention, the blockchain distributed identity management system pre-defines relevant identity documents. When the target account applies for a digital wallet account of any second-tier operating institution, the corresponding public key is quickly found through the document and sent to the second operating server corresponding to the corresponding second-tier operating institution. When the target account submits a digital wallet account application to any second-tier operating institution, the customer identity identification information (such as identity credential information and credit credential information) pre-stored in the target terminal can be directly verified by means of the public key to determine whether a digital wallet account is opened for the above-mentioned target user, thereby avoiding the user from submitting the same type of identity credential information multiple times, simplifying the digital wallet account application process while ensuring user privacy and security, reducing the risk of data leakage, improving user identity authentication efficiency and thus improving user experience.
[0160] It should be noted that, in an embodiment of the present invention, the blockchain distributed identity management system may also update the third public key, the correspondence between the first operating server and the third public key, the correspondence between the third public key and the target account, the fourth public key, the correspondence between the identity certificate issuing server and the fourth public key, and the correspondence between the fourth public key and the target account in the first identity document corresponding to the target account. When the target account applies for a digital wallet account, the second operating institution determines and obtains the third public key and the fourth public key based on the correspondence stored in the first identity document, and uses the third public key and the fourth public key to verify the identity signature and credit signature of the target account, respectively.
[0161] In an embodiment of the present invention, a verification request for applying for a digital wallet for a target account is received from a second operating server, wherein the verification request carries the first identity identifier of the target account, the second identity identifier of the first operating server and the fourth identity identifier of the identity certificate issuing server; based on the first identity document of the target account, the second identity document of the first operating server and the fourth identity document of the identity certificate issuing server, the first public key corresponding to the first identity identifier, the third public key corresponding to the second identity identifier, and the fourth public key corresponding to the fourth identity identifier are found, wherein the first identity document includes the correspondence between the first public key and the first identity identifier, the second identity document includes the correspondence between the third public key and the second identity identifier, and the fourth identity document includes the correspondence between the fourth public key and the fourth identity identifier; the first public key, the third public key and the fourth public key are sent to the first operating server. The second operation server is used for the above-mentioned second operation server to verify the signature ciphertext, credit signature, and identity signature of the above-mentioned target account, wherein the above-mentioned signature ciphertext is obtained by the target terminal using the first private key to sign the above-mentioned first identity identifier, the above-mentioned credit signature is obtained by the above-mentioned first operation server using the third private key to sign the credit certificate of the above-mentioned target account, and the above-mentioned identity signature is obtained by the above-mentioned identity certificate issuing server using the fourth private key to sign the identity certificate of the above-mentioned target account. The above-mentioned identity signature is pre-stored in the target terminal, so as to achieve the purpose of verifying the customer identity identification information (such as identity certificate information and credit certificate information) pre-stored in the target terminal by means of a public key, and determining whether a digital wallet account is opened for the above-mentioned target user, thereby achieving the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, and thus solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage existing in the relevant technology.
[0162] In an optional embodiment, before receiving the verification request from the second operation server for applying for a digital wallet for the target account, the method further includes:
[0163] Receive the public key corresponding to the target account's application for a digital wallet, where the public key includes the first public key of the target account, the third public key of the first operating server, the second public key of the second operating server, and the fourth public key of the identity certificate issuing server;
[0164] Generate the first identity identifier of the target account, the second identity identifier of the first operating server, the third identity identifier of the second operating server, and the fourth identity identifier of the identity certificate issuing server;
[0165] Generate the first identity document of the target account, the second identity document of the first operating server, the third identity document of the second operating server, and the fourth identity document of the identity credential issuing server.
[0166] Optionally, the blockchain distributed identity management system receives the first public key Pk_user_a of the target terminal from the digital wallet user, the third public key Pk_Regi_A of the first operating server of the 2.5-layer operating organization, the second public key Pk_Regi_B of the first operating server of the second-layer operating organization, and the fourth public key Pk_Regi_C of the identity certificate issuing server of the trusted certificate issuing organization; generates distributed digital identity identifiers DID_wallet_a, DID_A, DID_B, DID_C corresponding to the target account a, the 2.5-layer operating organization A, the second-layer operating organization B, and the trusted certificate issuing organization C respectively; and at the same time generates identity documents corresponding to the 2.5-layer operating organization A, the second-layer operating organization B, and the trusted certificate issuing organization C respectively: DID-Doc_Wallet_a, DID-Doc_A, DID-Doc_B, and DID-Doc_C.
[0167] It should be noted that the identity document is a key-value database table that records attributes such as the corresponding binding relationship between each identity ID and its public key. This includes: the binding relationship between the distributed digital identity DID_wallet_a and DID_wallet_a of the target account a corresponding to the digital wallet user and its public key Pk_user_a; as well as the corresponding binding relationship between the identity documents and public keys of the 2.5-layer operator A, the second-layer operator B, and the trusted credential issuing institution C. The blockchain distributed identity management system issues the respective distributed digital identity DIDs to the target account a corresponding to the digital wallet user, the 2.5-layer operator A, the second-layer operator B, and the trusted credential issuing institution C. Identity documents are automatically synchronized through the blockchain to prevent malicious data tampering and reduce the risk of information leakage.
[0168] Figure 7 is a flow chart of another digital wallet account application verification method according to an embodiment of the present invention. Figure 6 As shown, the method includes the following steps:
[0169] Step S702: The target terminal receives an application for a digital wallet account based on the target account, wherein the first operating server is the operating server to which the target account belongs;
[0170] Step S704: In response to the application operation, the target terminal sends a request to the first operator server to apply for a digital wallet account;
[0171] Step S706: In response to the request, the first operating server obtains the credit credential information of the target account on the first operating server and feeds the credit credential information back to the target terminal.
[0172] Step S708: The target terminal obtains the pre-stored identity credential information of the target account on the identity credential issuing server;
[0173] Step S710: The target terminal sends the first identity identifier, the credit credential information, and the identity credential information to a second operating server, where the second operating server is a digital wallet account issuing server.
[0174] Step S712: The second operating server verifies the target account based on the first identity identifier, the credit credential information, and the identity credential information, and generates a target digital wallet account if the verification passes.
[0175] In step S714, the second operating server returns the application result including the target digital wallet account to the target terminal.
[0176] It can be understood that the above-mentioned target account is the target account corresponding to the digital wallet user; the above-mentioned first operation server is the server corresponding to the 2.5-layer operation organization; the above-mentioned second operation server is the server corresponding to the second-layer operation organization; the above-mentioned identity certificate issuing server is the server corresponding to the trusted certificate issuing organization; the above-mentioned credit certificate information can be the verifiable credit certificate of the target account issued by the first operation server; the above-mentioned identity certificate information can be the verifiable identity certificate of the target account issued by the trusted certificate issuing organization.
[0177] In an embodiment of the present invention, a digital wallet account application verification method is adopted, and an application operation for applying for a digital wallet account based on a target account is received through a target terminal; in response to the application operation, the target terminal sends a request for applying for a digital wallet account to a first operating server; in response to the request, the first operating server obtains the credit credential information of the target account on the first operating server, and feeds back the credit credential information to the target terminal; the target terminal obtains the identity credential information of the target account on the identity credential issuing server that is pre-stored; the target terminal sends the first identity identifier, the credit credential information and the identity credential information to a second operating server; the second operating server The operation server verifies the target account based on the first identity identifier, the credit credential information and the identity credential information, and generates a target digital wallet account if the verification is successful; the second operation server returns the application result including the target digital wallet account to the target terminal, thereby achieving the purpose of authenticating the target account based on the pre-acquired credit credential information and identity credential information when the target account applies for a digital wallet account, thereby achieving the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, thereby solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage in related technologies.
[0178] As an optional embodiment, Figure 8 This is a timing flow chart of an optional digital wallet account application verification method according to an embodiment of the present invention, such as Figure 8 As shown, the method specifically includes the following steps:
[0179] Step S801: The target account of the layer 2.5 operating organization initiates a request for identity credentials from the trusted credential issuing organization;
[0180] Step S802: The trusted credential issuing institution returns the generated identity credential information to the target account of the Layer 2.5 operating institution;
[0181] Step S803: The target account of the 2.5-layer operating institution initiates a request for a credit certificate to the 2.5-layer operating institution;
[0182] Step S804: The 2.5-layer operating institution returns the generated credit certificate information to the 2.5-layer operating institution target account;
[0183] Step S805: The target account of the 2.5-layer operator initiates a request to the second-layer operator for a digital wallet account, and simultaneously sends the credit credential information and identity credential information to the second-layer operator for identity verification of the target account of the 2.5-layer operator;
[0184] Step S806: After receiving the request to apply for a digital wallet account, the Layer 2 operator sends an identity authentication request for the Layer 2.5 operator's target account to the blockchain distributed identity management system, and simultaneously sends relevant identity identifiers (e.g., the first identity identifier corresponding to the Layer 2.5 operator's target account, the second identity identifier corresponding to the Layer 2.5 operator, and the fourth identity identifier corresponding to the trusted credential issuing authority) to the blockchain distributed identity management system;
[0185] Step S807: The blockchain distributed identity management system performs an identity document query based on the above identity identifiers and returns the corresponding public key (e.g., the first public key corresponding to the first identity identifier, the third public key corresponding to the second identity identifier, and the fourth public key corresponding to the fourth identity identifier) to the second-layer operating organization;
[0186] In step S808, the second-layer operating organization uses the public key from the blockchain distributed identity management system to authenticate the target account of the 2.5-layer operating organization, and returns the digital wallet account to the target account of the 2.5-layer operating organization if the authentication is successful.
[0187] It should be noted that, in the embodiment of the present invention, steps S801 to S804 may be executed in different orders, and the present invention does not impose any specific limitation thereto.
[0188] In an optional embodiment, the first operation server, in response to the request, obtains the credit credential information of the target account on the first operation server, including:
[0189] In response to the request, the first operating server obtains historical transactions and historical credit of the target account on the first operating server;
[0190] The first operating server generates the credit credential information of the target account on the first operating server based on the historical transactions and the historical credit, where the credit credential information includes the credit credential of the target account and a credit signature corresponding to the credit credential.
[0191] Optionally, when the target account of the 2.5-layer operating institution wants to apply for a digital wallet account from a second-layer operating institution, the first operating server corresponding to the 2.5-layer operating institution generates a verifiable identity certificate as the credit credential information of the target account based on the historical transactions and historical evaluations of the target account.
[0192] In an optional embodiment, before the target terminal obtains the pre-stored identity credential information of the target account in the identity credential issuing server, the method further includes:
[0193] The target terminal sends a request for verifying identity credentials to multiple identity credential issuing servers;
[0194] The multiple identity credential issuing servers return corresponding identity credential information to the target terminal;
[0195] The target terminal stores the identity credential information corresponding to the multiple identity credential issuing servers, wherein the identity credential information includes the identity credential of the target account and the identity signature corresponding to the identity credential.
[0196] Optionally, the target terminal sends an identity credential verification request to multiple identity credential issuing servers corresponding to multiple trusted credential issuing institutions; after receiving the target account's request to apply for a digital wallet account, the multiple identity credential issuing servers determine the identity credential information of the target account based on the identity information of the target account, and return the above identity credential information to the above target terminal; the above target terminal stores the above identity credential information.
[0197] In an optional embodiment, the target terminal sending the credit credential information and the identity credential information to the second operation server includes:
[0198] The target terminal obtains the first public-private key pair of the target account and the second public key of the second operating server, wherein the first public-private key pair includes a first public key and a first private key;
[0199] The target terminal encrypts the credit credential information and the identity credential information using the second public key to obtain a credential ciphertext, and signs the first identity identifier using the first private key to obtain a signature ciphertext;
[0200] The target terminal sends the certificate ciphertext, the signature ciphertext, and the first public key to the second operation server.
[0201] Optionally, the target terminal obtains the first public-private key pair Pk_user_a / Sk_user_a of the target account, and the second public key Pk_Regi_B corresponding to the second-layer operating organization; uses the above-mentioned second public key Pk_Regi_B to encrypt the credit certificate information issued by the 2.5-layer operating organization and the identity certificate information issued by the trusted certificate issuing organization to obtain the certificate ciphertext, and uses the first private key Sk_user_a to sign the first identity identifier DID_wallet_a of the target account to obtain the signature ciphertext; sends the above-mentioned certificate ciphertext, the above-mentioned signature ciphertext, and the above-mentioned first public key Pk_user_a to the second operating server corresponding to the second-layer operating organization, thereby improving the security of data transmission and effectively ensuring the privacy of users.
[0202] In an optional embodiment, the second operation server verifies the target account based on the credit credential information and the identity credential information, including:
[0203] The second operating server uses the second private key of the second operating server to decrypt the credential ciphertext to obtain the credit credential information and the identity credential information, and uses the first public key to verify the signature ciphertext;
[0204] When the signature ciphertext is verified, the second operation server verifies the target account based on the credit credential information and the identity credential information.
[0205] Optionally, the second operating server sends the second public key Pk_Regi_B to the target terminal, wherein the target terminal is used to use the second public key Pk_Regi_B to encrypt the credit credential information issued by the 2.5-layer operating agency and the identity credential information issued by the trusted credential issuing agency to obtain the credential ciphertext; receive the request sent by the above-mentioned target terminal to apply for a digital wallet account based on the target account, and use the first public key Pk_user_a of the target account carried in the above-mentioned request to verify the signature ciphertext; if the above-mentioned signature ciphertext verification passes, use the second private key Sk_Regi_B to decrypt the credential ciphertext carried in the above-mentioned request to obtain the above-mentioned credit credential information and the above-mentioned identity credential information, and verify the above-mentioned target account based on the identification information of the above-mentioned target account, the above-mentioned credit credential information and the above-mentioned identity credential information, thereby improving the security of data transmission and effectively ensuring the privacy of users.
[0206] In an optional embodiment, the above method further includes:
[0207] The target terminal obtains the first public key and the first private key of the target account, and sends the first public key to the blockchain distributed identity management system. The first operation server obtains the third public key and the third private key of the first operation server, and sends the third public key to the blockchain distributed identity management system. The second operation server obtains the second public key and the second private key of the second operation server, and sends the second public key to the blockchain distributed identity management system. The identity certificate issuing server obtains the fourth public key and the fourth private key of the identity certificate issuing server, and sends the fourth public key to the blockchain distributed identity management system.
[0208] The blockchain distributed identity management system generates a first identity identifier for the target account, a second identity identifier for the first operation server, a third identity identifier for the second operation server, and a fourth identity identifier for the identity credential issuing server;
[0209] The above-mentioned blockchain distributed identity management system generates a first identity document for the above-mentioned target account, a second identity document for the above-mentioned first operation server, a third identity document for the above-mentioned second operation server, and a fourth identity document for the above-mentioned identity certificate issuing server, wherein the above-mentioned first identity document includes the correspondence between the above-mentioned first public key and the above-mentioned first identity identifier, the above-mentioned second identity document includes the correspondence between the above-mentioned third public key and the above-mentioned second identity identifier, and the above-mentioned third identity document includes the correspondence between the above-mentioned second public key and the above-mentioned third identity identifier, and the above-mentioned fourth identity document includes the relationship between the above-mentioned fourth public key and the above-mentioned fourth identity identifier.
[0210] Optionally, the target account a corresponding to the digital wallet user generates a public-private key pair Pk_user_a / Sk_user_a. Layer 2.5 operator A, Layer 2 operator B, and the trusted credential issuing authority generate corresponding public-private key pairs Pk_Regi_A / Sk_Regi_A, Pk_Regi_B / Sk_Regi_B, and Pk_Regi_C / Sk_Regi_C, respectively. The trusted credential issuing authority and the Layer 2.5 operator generate a public-private key pair for verifiable credential issuance. The trusted credential issuing authority issues n public-private key pairs for verifiable identity credentials for digital wallet users, using Pk_issuer_1 / Sk_issuer_1, Pk_issuer_2 / Sk_issuer_2, ..., and Pk_issuer_n / Sk_issuer_n, respectively. The Layer 2.5 operator issues verifiable credit credentials to users, generating the corresponding public-private key pairs Pk_issuer_A / Sk_issuer_A.
[0211] Optionally, the blockchain distributed identity management system receives the first public key Pk_user_a of the target terminal from the digital wallet user, the third public key Pk_Regi_A of the first operating server of the 2.5-layer operating organization, the second public key Pk_Regi_B of the first operating server of the second-layer operating organization, and the fourth public key Pk_Regi_C of the identity certificate issuing server of the trusted certificate issuing organization; generates distributed digital identity identifiers DID_wallet_a, DID_A, DID_B, DID_C corresponding to the target account a, the 2.5-layer operating organization A, the second-layer operating organization B, and the trusted certificate issuing organization C respectively; and at the same time generates identity documents corresponding to the 2.5-layer operating organization A, the second-layer operating organization B, and the trusted certificate issuing organization C respectively: DID-Doc_Wallet_a, DID-Doc_A, DID-Doc_B, and DID-Doc_C.
[0212] Based on the above embodiments and optional embodiments, the present invention proposes an optional implementation mode, which can be applied to Figure 9 The digital wallet account application verification system shown includes a target terminal corresponding to the target account a of the digital wallet user, a first operating server corresponding to the 2.5-tier operating organization, a second operating server corresponding to the 2-tier operating organization, and an identity certificate issuing server corresponding to the trusted certificate issuing organization. The target terminal can be a data wallet application APP. This embodiment specifically includes:
[0213] Step S1, generating a distributed digital identity and identity document, specifically includes:
[0214] In step S11, each institution generates a key pair for registering the DID, where: the target account a corresponding to the digital wallet user generates a public-private key pair Pk_user_a / Sk_user_a; the 2.5-layer operating institution A, the second-layer operating institution B, and the trusted certificate issuing institution C generate corresponding public-private key pairs Pk_Regi_A / Sk_Regi_A, Pk_Regi_B / Sk_Regi_B, and Pk_Regi_C / Sk_Regi_C, respectively.
[0215] In step S12, the trusted credential issuing authority and the 2.5-layer operating organization generate a public-private key pair for issuing verifiable credentials, where: the trusted credential issuing authority issues n public-private key pairs of verifiable identity credentials for digital wallet users, using Pk_issuer_1 / Sk_issuer_1, Pk_issuer_2 / Sk_issuer_2, ..., Pk_issuer_n / Sk_issuer_n respectively; the 2.5-layer operating organization issues verifiable credit credentials to users and generates corresponding public-private keys Pk_issuer_A / Sk_issuer_A.
[0216] In step S13, the target account a, 2.5-layer operating organization A, and second-layer operating organization B corresponding to the digital wallet user submit public keys Pk_user_a, Pk_Regi_A, Pk_Regi_B, and Pk_Regi_C to the blockchain distributed identity management system respectively.
[0217] In step S14, the blockchain distributed identity management system generates distributed digital identity identifiers DID_wallet_a, DID_A, DID_B, and DID_C corresponding to the target account a, 2.5-layer operating organization A, second-layer operating organization B, and trusted certificate issuing organization C, respectively.
[0218] In step S15, the blockchain distributed identity management system generates identity documents corresponding to the target account a, the 2.5-layer operating organization A, the second-layer operating organization B, and the trusted certificate issuing organization C: DID-Doc_Wallet_a, DID-Doc_A, DID-Doc_B, and DID-Doc_C, respectively. The identity document is a key-value database table used to record attributes such as the corresponding binding relationship between each identity identifier ID and its public key, including: the binding relationship between the distributed digital identity identifiers DID_wallet_a and DID_wallet_a of the target account a corresponding to the digital wallet user and its public key Pk_user_a, as well as the corresponding binding relationship between the identity documents of the 2.5-layer operating organization A, the second-layer operating organization B, and the trusted certificate issuing organization C and their public keys.
[0219] In step S16, the blockchain distributed identity management system issues respective distributed digital identity identifiers (DIDs) to the target account a, 2.5-layer operating organization A, second-layer operating organization B, and trusted certificate issuing organization C corresponding to the digital wallet user; identity documents are automatically synchronized through the blockchain to prevent tampering.
[0220] Step S2, generating distributed identity credentials and updating distributed identity documents, specifically includes:
[0221] In step S21, the target account a corresponding to the digital wallet user initiates an application for a verifiable electronic identity certificate to n trusted certificate issuing agencies based on the identity information (such as an identity document, i.e., a physical document) issued to it by the trusted certificate issuing agency. The user submits relevant identity information to the trusted certificate issuing agency, executes relevant verification measures, and performs identity verification.
[0222] In step S22, the trusted credential issuing institution (such as institution 1) generates a verifiable identity credential Credential_V1_a corresponding to the target account a corresponding to the digital wallet user based on the verifiable identity credential template, and signs it using its private key Sk_issuer_1. Other trusted credential issuing institutions generate other verifiable identity credentials Credential_V2_a, ..., Credential_Vn_a in the same way.
[0223] In step S23, the verifiable identity certificate corresponding to the trusted certificate issuing agency is issued to and saved in the target account a corresponding to the digital wallet user, and is saved in the digital wallet application APP where the target account a is located.
[0224] In step S24, the target account a corresponding to the digital wallet user applies to the affiliated 2.5-layer operator A to open a digital wallet account. The user submits relevant verification information for verification. 2.5-layer operator A issues a verifiable credit credential, Credential_A-a, to user a based on the user's previous credit information (such as transaction history and credit status). Depending on the specific situation, if private information is involved, Credential_A-a can be generated using a zero-knowledge proof (i.e., no private information is leaked when verified by other operators).
[0225] In step S25, the 2.5-layer operating organization A sends the verifiable credit credential Credential_A-a to user a and securely stores it in the digital wallet application APP where the target account a is located.
[0226] In step S26, the 2.5-layer operating organization and the trusted certificate issuing organization interact with the blockchain distributed identity management system. The blockchain distributed identity management system updates the identity document of the target account a corresponding to the digital wallet user, writes the verification public key Pk_issuer_1 of multiple verifiable identity credentials into the identity document DID-Doc_Wallet_a of the target account a, and also writes the verification relationship between Pk_issuer_1 and DID_wallet_a into the identity document of the target account a corresponding to the digital wallet user; writes the verifiable credit certificate issuing public key Pk_issuer_A of the 2.5-layer operating organization and the verification relationship between Pk_issuer_A and DID_wallet_a into the identity document DID-Doc_Wallet_a of the digital wallet user a.
[0227] In step S27, the digital wallet user repeats the process from step S21 to step S24 to obtain verifiable identity credentials Pk_issuer_n from other trusted credential issuing institutions, and securely saves them to the digital wallet application APP where the target account a is located.
[0228] Step S28: Obtain all verifiable identity credentials and verifiable credit credentials. The blockchain distributed identity management system updates the identity document DID-Doc_Wallet_a of the target account a corresponding to the digital wallet user and performs synchronous updates through the blockchain.
[0229] Step S3: Target user A applies to the second-tier operator B to open a digital wallet account, specifically including:
[0230] In step S31, before the target account a applies for a digital wallet account of the second-layer operating institution B, it needs to carry out customer identity authentication. The second-layer operating institution sends the public key Pk_Regi_B to the target account a.
[0231] In step S32, in accordance with the customer identity identification requirements, the target account a submits to the second-tier operating institution B a verifiable credit certificate Credential_A-a for customer identity identification, as well as multiple verifiable identity credentials Credential_V1_a, Credential_V2_a, ..., Credential_Vn_a, issued by the 2.5-tier operating institution A and the trusted certificate issuing institution, and encrypts all verifiable identity credentials and verifiable credit credentials with the public key Pk_Regi_B to obtain the encrypted verifiable credentials.
[0232] In step S33, the digital wallet user signs the digital identity DID_wallet_a corresponding to the target account a using the user private key Sk_user_a.
[0233] Step S34: Pass the encrypted verifiable credential, the signed DID_wallet_a, and the user public key Pk_user_a to the second-tier operator B.
[0234] In step S35, Layer 2 operator B decrypts the encrypted verifiable credentials using its private key Sk_Regi_B, obtaining the digital wallet user's verifiable credit credentials Credential_A-a and verifiable identity credentials Credential_V1_a, Credential_V2_a, ..., Credential_Vn_a. The signature is then verified using the digital wallet user's public key Pk_user_a to confirm that DID_wallet_a belongs to user a.
[0235] In step S36, the second-layer operating organization B queries the identity document DID-Doc_Wallet_a of the digital wallet user on the blockchain distributed identity management system based on the distributed digital identity identifier DID_wallet_a, obtains the credit credential verification public key Pk_issuer_A corresponding to the verifiable credit credential and the identity credential verification public keys Pk_issuer_1, Pk_issuer_2, ..., Pk_issuer_n corresponding to the verifiable identity credential, and verifies the validity of the corresponding signatures of Credential_A-a, Credential_V1_a, Credential_V2_a, ..., Credential_Vn_a.
[0236] Step S37: After verifying all customer identity credentials and all verifiable identity credentials and verifiable credit credentials, a digital wallet account can be opened for the target account.
[0237] It should be noted that the embodiments of the present invention utilize distributed identity technology (DID) to transform various customer identification information of users into verifiable and reliable credentials, thereby ensuring the credibility of customer identification data. Furthermore, by reusing customer identification information and verifiable credentials, users are less likely to submit the same customer identification information repeatedly when applying for services from different operating institutions. Furthermore, by collaboratively attaching customer identification certificates from other financial institutions, the customer identification capabilities of individual financial institutions are enhanced, reducing various risks.
[0238] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0239] According to an embodiment of the present invention, a system embodiment for implementing the above-mentioned digital wallet account application verification method is also provided. Figure 10 is a structural diagram of another digital wallet account application verification system according to an embodiment of the present invention. Figure 10 As shown, the digital wallet account application verification system includes: a target terminal 900, a first operating server 902 and a second operating server 904, wherein:
[0240] The target terminal 900 is configured to receive an application for a digital wallet account based on a target account; and in response to the application, send a request for a digital wallet account to a first operating server, wherein the first operating server is the operating server to which the target account belongs;
[0241] The first operating server 902 is connected to the target terminal and is configured to obtain the credit credential information of the target account on the first operating server in response to the request and feed the credit credential information back to the target terminal;
[0242] The target terminal 900 is further configured to obtain pre-stored identity credential information of the target account on the identity credential issuing server; send the first identity identifier, the credit credential information, and the identity credential information to the second operating server, wherein the second operating server is a digital wallet account issuing server;
[0243] The second operation server 904 is connected to the target terminal and is used to verify the target account based on the first identity identifier, the credit credential information and the identity credential information, and generate a target digital wallet account if the verification is successful; and return the application result including the target digital wallet account to the target terminal.
[0244] In an embodiment of the present invention, the target terminal 900 is configured to receive an application operation for applying for a digital wallet account based on a target account; in response to the application operation, a request for applying for a digital wallet account is sent to the first operating server; the first operating server 902 is connected to the target terminal and configured to obtain the credit credential information of the target account on the first operating server in response to the request, and feed back the first identity identifier and the credit credential information to the target terminal; the target terminal 900 is further configured to obtain the identity credential information of the target account on the identity credential issuing server that is pre-stored; send the credit credential information and the identity credential information to the second operating server; the second operating server Server 904 is connected to the target terminal and is used to verify the target account based on the first identity identifier, the credit credential information, and the identity credential information, and generate a target digital wallet account if the verification is successful; and returns the application result including the target digital wallet account to the target terminal, thereby achieving the purpose of authenticating the target account based on the pre-acquired credit credential information and identity credential information when the target account applies for a digital wallet account, thereby achieving the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, thereby solving the technical problems of low user identity authentication efficiency, low data credibility, and high risk of user privacy leakage existing in related technologies.
[0245] It should be noted that the present invention Figure 10 The specific structure of the digital wallet account application verification system shown in the figure is only for reference. In specific applications, the digital wallet account application verification system shown in the present invention can be compared with the Figure 10 The target terminal 900 , the first operating server 902 , and the second operating server 904 shown have more or less structures.
[0246] It should be noted that any optional or preferred method of the digital wallet account application verification system in the above embodiments can be executed or implemented in the digital wallet account application verification system provided in this embodiment.
[0247] In addition, it should be noted that the optional or preferred implementation of this embodiment can be found in the relevant description in the embodiment, which will not be repeated here.
[0248] This embodiment also provides a digital wallet account application verification device, which is used to implement the above-mentioned embodiments and preferred embodiments. Details that have already been described will not be repeated. As used below, the terms "unit" and "device" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0249] According to an embodiment of the present invention, there is also provided an embodiment of a device for implementing the above-mentioned digital wallet account application verification method. Figure 11 is a structural diagram of an application verification device for a digital wallet account according to an embodiment of the present invention. Figure 11 As shown, the above-mentioned digital wallet account application verification device includes: a first receiving module 1000, a first obtaining module 1002, a second obtaining module 1004, a first sending module 1006 and a first result returning module 1008, wherein:
[0250] The first receiving module 1000 is configured to receive an application for a digital wallet account based on a target account;
[0251] The first obtaining module 1002 is configured to obtain, in response to the application operation, the credit credential information of the target account on a first operating server, wherein the first operating server is the operating server to which the target account belongs;
[0252] The second obtaining module 1004 is configured to obtain the pre-stored identity credential information of the target account on the identity credential issuing server;
[0253] The first sending module 1006 is configured to send the first identity identifier of the target account, the credit credential information, and the identity credential information to a second operating server, so that the second operating server authenticates the target account based on the credit credential information and the identity credential information, wherein the second operating server is a digital wallet account issuing server;
[0254] The first result returning module 1008 is configured to receive the application result returned by the second operating server, wherein the application result includes a target digital wallet account, and the target digital wallet account is generated by the second operating server when the target account is verified successfully based on the first identity identifier, the credit credential information, and the identity credential information.
[0255] In an embodiment of the present invention, the first receiving module 1000 is configured to receive an application operation for applying for a digital wallet account based on a target account; the first obtaining module 1002 is configured to obtain the credit credential information of the target account on the first operating server in response to the application operation; the second obtaining module 1004 is configured to obtain the identity credential information of the target account on the identity credential issuing server that is pre-stored; the first sending module 1006 is configured to send the first identity identifier of the target account, the credit credential information, and the identity credential information to the second operating server; the first result returning module 1008 is configured to receive a response from the second operating server. The returned application result, wherein the above application result includes the target digital wallet account, and the above target digital wallet account is generated by the above second operating server when the above target account is verified based on the above first identity identifier, the above credit credential information and the above identity credential information. The purpose of authenticating the target account based on the pre-acquired credit credential information and identity credential information when the target account applies for a digital wallet account is achieved, thereby achieving the technical effect of improving user identity authentication efficiency and data credibility, and ensuring user privacy security, and thus solving the technical problems of low user identity authentication efficiency, low data credibility and high risk of user privacy leakage existing in related technologies.
[0256] According to an embodiment of the present invention, another device embodiment for implementing the above-mentioned digital wallet account application verification method is also provided. Figure 12 is a structural diagram of another digital wallet account application verification device according to an embodiment of the present invention, such as Figure 12 As shown, the above-mentioned digital wallet account application verification device includes: a second receiving module 1100, a first verification module 1102, and a second result returning module 1104, wherein:
[0257] The second receiving module 1100 is configured to receive a request from a target terminal to apply for a digital wallet account based on a target account, wherein the request carries a first identity identifier of the target account, credit credential information of the target account on a first operating server, and identity credential information of the target account on an identity credential issuing server, where the identity credential information is pre-stored in the target terminal.
[0258] The first verification module 1102 is configured to verify the target account based on the first identity identifier, the credit credential information, and the identity credential information;
[0259] The second result returning module 1104 is configured to generate a target digital wallet account if the verification is successful, and return the target digital wallet account to the target terminal along with the application result.
[0260] According to an embodiment of the present invention, another device embodiment for implementing the above-mentioned digital wallet account application verification method is also provided. Figure 13 is a structural diagram of another digital wallet account application verification device according to an embodiment of the present invention, such as Figure 14 As shown, the above-mentioned digital wallet account application verification device includes: a third receiving module 1200, a first generating module 1202, and a first feedback module 1204, wherein:
[0261] The third receiving module 1200 is configured to receive a request from a target terminal to apply for a digital wallet account based on a target account;
[0262] The first generating module 1202 is configured to generate credit credential information of the target account on the first operating server in response to the request;
[0263] The first feedback module 1204 is configured to feed back the credit credential information to the target terminal, so that the target terminal applies for a digital wallet account from the second operator server in combination with the first identity identifier and the identity credential information pre-stored in the target terminal, wherein the identity credential information is the identity credential of the target account on the identity credential issuing server.
[0264] According to an embodiment of the present invention, another device embodiment for implementing the above-mentioned digital wallet account application verification method is also provided. Figure 14 is a structural diagram of another digital wallet account application verification device according to an embodiment of the present invention, such as Figure 14 As shown, the above-mentioned digital wallet account application verification device includes: a fourth receiving module 1300, a third obtaining module 1302, and a second sending module 1304, wherein:
[0265] The fourth receiving module 1300 is configured to receive a request from a target terminal for applying for an identity credential based on a target account, wherein the request carries the identity information of the target account;
[0266] The third obtaining module 1302 is configured to obtain, in response to the request and based on the identity information, the identity credential information of the target account on the identity credential issuing server;
[0267] The above-mentioned second sending module 1304 is used to send the above-mentioned identity credential information to the above-mentioned target terminal and store it on the above-mentioned target terminal, wherein the above-mentioned target terminal is used to apply for identity authentication from the second operating server based on the first identity identifier of the above-mentioned target account, the credit credential information of the above-mentioned target account on the first operating server, and the pre-stored above-mentioned identity credential information when applying for a digital wallet account based on the above-mentioned target account.
[0268] According to an embodiment of the present invention, another device embodiment for implementing the above-mentioned digital wallet account application verification method is also provided. Figure 15 is a structural diagram of another digital wallet account application verification device according to an embodiment of the present invention, such as Figure 15 As shown, the above-mentioned digital wallet account application verification device includes: a fifth receiving module 1400, a first search module 1402 and a third sending module 1404, wherein:
[0269] The fifth receiving module 1400 is configured to receive a verification request from a second operating server for a target account applying for a digital wallet, wherein the verification request carries a first identity identifier of the target account, a second identity identifier of the first operating server, and a fourth identity identifier of the identity credential issuing server, where the first operating server is the operating server to which the target account belongs, and the second operating server is the digital wallet account issuing server;
[0270] The first search module 1402 is configured to search for a first public key corresponding to the first identity identifier, a third public key corresponding to the second identity identifier, and a fourth public key corresponding to the fourth identity identifier based on the first identity document of the target account, the second identity document of the first operating server, and the fourth identity document of the identity credential issuing server, wherein the first identity document includes a correspondence between the first public key and the first identity identifier, the second identity document includes a correspondence between the third public key and the second identity identifier, and the fourth identity document includes a correspondence between the fourth public key and the fourth identity identifier;
[0271] The above-mentioned third sending module 1404 is used to send the above-mentioned first public key, the above-mentioned third public key and the above-mentioned fourth public key to the above-mentioned second operation server, so that the above-mentioned second operation server can verify the signature ciphertext, credit signature and identity signature of the above-mentioned target account, wherein the above-mentioned signature ciphertext is obtained by the target terminal using the first private key to sign the above-mentioned first identity identification, the above-mentioned credit signature is obtained by the above-mentioned first operation server using the third private key to sign the credit certificate of the above-mentioned target account, and the above-mentioned identity signature is obtained by the above-mentioned identity certificate issuing server using the fourth private key to sign the identity certificate of the above-mentioned target account, and the above-mentioned identity signature is pre-stored in the target terminal.
[0272] According to an embodiment of the present invention, another device embodiment for implementing the above-mentioned digital wallet account application verification method is also provided. Figure 16 is a structural diagram of another digital wallet account application verification device according to an embodiment of the present invention, such as Figure 16 As shown, the above-mentioned digital wallet account application verification device includes: a sixth receiving module 1500, a first application module 1502, a fourth obtaining module 1504, a fifth obtaining module 1506, a fourth sending module 1508, a second verification module 1510 and a third result returning module 1512, wherein:
[0273] The sixth receiving module 1500 is configured to receive, by the target terminal, an application for a digital wallet account based on the target account;
[0274] The first application module 1502 is configured to send a request for applying for a digital wallet account to the first operating server in response to the application operation.
[0275] The fourth obtaining module 1504 is configured for the first operating server to obtain the credit credential information of the target account on the first operating server in response to the request, and to feed the credit credential information back to the target terminal;
[0276] The fifth obtaining module 1506 is configured for the target terminal to obtain the pre-stored identity credential information of the target account in the identity credential issuing server;
[0277] The fourth sending module 1508 is configured for the target terminal to send the first identity identifier, the credit credential information, and the identity credential information to the second operation server;
[0278] The second verification module 1510 is configured to enable the second operating server to verify the target account based on the first identity identifier, the credit credential information, and the identity credential information, and to generate a target digital wallet account if the verification passes.
[0279] The third result returning module 1512 is configured for the second operating server to return the application result including the target digital wallet account to the target terminal.
[0280] It should be noted that the above modules can be implemented by software or hardware. For example, for the latter, it can be implemented in the following ways: the above modules can be located in the same processor; or the above modules can be located in different processors in any combination.
[0281] It should be noted that the optional or preferred implementation of this embodiment can be found in the relevant description in the embodiment, which will not be repeated here.
[0282] The above-mentioned digital wallet account application verification device may further include a processor and a memory. The above-mentioned first receiving module 1000, first acquisition module 1002, second acquisition module 1004, first sending module 1006, first result return module 1008, second receiving module 1100, first verification module 1102, second result return module 1104, third receiving module 1200, first generation module 1202, first feedback module 1204, fourth receiving module 1300, third acquisition module 1302, second sending module 1304, fifth receiving module 1400, first search module 1402, third sending module 1404, sixth receiving module 1500, first application module 1502, fourth acquisition module 1504, fifth acquisition module 1506, fourth sending module 1508, second verification module 1510 and third result return module 1512 are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.
[0283] The processor includes a core, which retrieves the corresponding program unit from memory. There can be one or more cores. Memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory includes at least one memory chip.
[0284] According to an embodiment of the present invention, a non-volatile storage medium embodiment is also provided. Optionally, in this embodiment, the non-volatile storage medium includes a stored program, wherein, when the program is executed, the device containing the non-volatile storage medium is controlled to execute any of the above-mentioned digital wallet account application verification methods.
[0285] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group, and the non-volatile storage medium includes a stored program.
[0286] Optionally, when the program is running, the device where the non-volatile storage medium is located is controlled to perform the following functions: receiving an application operation for applying for a digital wallet account based on a target account; in response to the above application operation, obtaining the credit credential information of the above target account on the first operating server, wherein the above first operating server is the operating server to which the above target account belongs; obtaining the pre-stored identity credential information of the above target account on the identity credential issuing server; sending the first identity identifier of the above target account, the above credit credential information and the above identity credential information to the second operating server, so that the above second operating server authenticates the above target account based on the above credit credential information and the above identity credential information, wherein the above second operating server is a digital wallet account issuing server; receiving the application result returned by the above second operating server, wherein the above application result includes the target digital wallet account, and the above target digital wallet account is generated by the above second operating server when the above target account is verified successfully based on the above first identity identifier, the above credit credential information and the above identity credential information.
[0287] Optionally, when the program is running, the device where the non-volatile storage medium is located is controlled to perform the following functions: receiving a request from a target account to apply for a digital wallet account, wherein the request carries the first identity identifier of the target account, the credit credential information of the target account on the first operating server, and the identity credential information of the target account on the identity credential issuing server, and the identity credential information is pre-stored in the target terminal, wherein the first operating server is the operating server to which the target account belongs; verifying the target account based on the first identity identifier, the credit credential information and the identity credential information; if the verification is successful, generating a target digital wallet account, and returning the target digital wallet account to the target terminal in the application result.
[0288] Optionally, when the program is running, the device where the non-volatile storage medium is located is controlled to perform the following functions: receive a request from the target account to apply for a digital wallet account; in response to the above request, generate credit credential information of the above target account on the first operating server, wherein the above first operating server is the operating server to which the above target account belongs; and feed back the above credit credential information to the target terminal, so that the above target terminal can apply for a digital wallet account from the second operating server in combination with the first identity identifier and the identity credential information pre-stored in the above target terminal, wherein the above identity credential information is the identity credential of the above target account on the identity credential issuing server, wherein the above second operating server is the digital wallet account issuing server.
[0289] Optionally, when the program is running, the device where the non-volatile storage medium is located is controlled to perform the following functions: receiving a request from the target account to apply for an identity credential, wherein the request carries the identity information of the target account; in response to the request, based on the identity information, obtaining the identity credential information of the target account on the identity credential issuing server; sending the identity credential information to the target terminal and storing it on the target terminal, wherein the target terminal is used to apply for identity authentication to the second operating server based on the first identity identifier of the target account, the credit credential information of the target account on the first operating server, and the pre-stored identity credential information when applying for a digital wallet account based on the target account, wherein the first operating server is the operating server to which the target account belongs, and the second operating server is the digital wallet account issuing server.
[0290] Optionally, when the program is running, the device where the non-volatile storage medium is located is controlled to perform the following functions: receiving a verification request from the second operating server for applying for a digital wallet for the target account, wherein the verification request carries the first identity identifier of the target account, the second identity identifier of the first operating server and the fourth identity identifier of the identity certificate issuing server, the first operating server is the operating server to which the target account belongs, and the second operating server is the digital wallet account issuing server; based on the first identity document of the target account, the second identity document of the first operating server, and the fourth identity document of the identity certificate issuing server, find the first public key corresponding to the first identity identifier, the third public key corresponding to the second identity identifier, and the fourth public key corresponding to the fourth identity identifier, wherein the first identity document includes the first public key and the first The correspondence between the identity identifiers, the above-mentioned second identity document includes the correspondence between the above-mentioned third public key and the above-mentioned second identity identifier, and the above-mentioned fourth identity document includes the correspondence between the above-mentioned fourth public key and the above-mentioned fourth identity identifier; the above-mentioned first public key, the above-mentioned third public key and the above-mentioned fourth public key are sent to the above-mentioned second operation server, for the above-mentioned second operation server to verify the signature ciphertext, credit signature, and identity signature of the above-mentioned target account, wherein the above-mentioned signature ciphertext is obtained by the target terminal using the first private key to sign the above-mentioned first identity identifier, the above-mentioned credit signature is obtained by the above-mentioned first operation server using the third private key to sign the credit certificate of the above-mentioned target account, and the above-mentioned identity signature is obtained by the above-mentioned identity certificate issuing server using the fourth private key to sign the identity certificate of the above-mentioned target account, and the above-mentioned identity signature is pre-stored in the target terminal.
[0291] Optionally, when the program is running, the device where the non-volatile storage medium is located is controlled to perform the following functions: the target terminal receives an application operation for a digital wallet account based on the target account; the target terminal sends a request for applying for a digital wallet account to the first operation server in response to the application operation, wherein the first operation server is the operation server to which the target account belongs; the first operation server obtains the credit credential information of the target account on the first operation server in response to the request, and feeds back the credit credential information to the target terminal; the target terminal obtains the identity credential information of the target account pre-stored on the identity credential issuing server; the target terminal sends the first identity identifier, the credit credential information and the identity credential information to the second operation server, wherein the second operation server is a digital wallet account issuing server; the second operation server verifies the target account based on the first identity identifier, the credit credential information and the identity credential information, and generates a target digital wallet account if the verification passes; the second operation server returns the application result including the target digital wallet account to the target terminal.
[0292] Digital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet accountDigital wallet account
[0293] According to an embodiment of the present invention, a processor embodiment is also provided. Optionally, in this embodiment, the processor is used to run a program, wherein when the program is run, any of the above-mentioned digital wallet account application verification methods is executed.
[0294] According to an embodiment of the present invention, an embodiment of a computer program product is also provided. When executed on a data processing device, the program is suitable for executing the steps of the application verification method for initializing a digital wallet account of any one of the above-mentioned methods.
[0295] Optionally, the above-mentioned computer program product, when executed on a data processing device, is suitable for executing a program initialized with the following method steps: receiving an application operation for applying for a digital wallet account based on a target account; in response to the above-mentioned application operation, obtaining the credit credential information of the above-mentioned target account on a first operating server, wherein the above-mentioned first operating server is the operating server to which the above-mentioned target account belongs; obtaining the pre-stored identity credential information of the above-mentioned target account on the identity credential issuing server; sending the first identity identifier of the above-mentioned target account, the above-mentioned credit credential information and the above-mentioned identity credential information to a second operating server, so that the above-mentioned second operating server authenticates the above-mentioned target account based on the above-mentioned credit credential information and the above-mentioned identity credential information, wherein the above-mentioned second operating server is a digital wallet account issuing server; receiving the application result returned by the above-mentioned second operating server, wherein the above-mentioned application result includes the target digital wallet account, and the above-mentioned target digital wallet account is a digital wallet account generated by the above-mentioned second operating server when the above-mentioned target account is successfully verified based on the above-mentioned first identity identifier, the above-mentioned credit credential information and the above-mentioned identity credential information.
[0296] According to an embodiment of the present invention, an embodiment of an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute any one of the above-mentioned digital wallet account application verification methods.
[0297] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0298] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0299] In the several embodiments provided by the present invention, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the above-mentioned units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, and can be electrical or other forms.
[0300] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0301] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0302] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable non-volatile storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a non-volatile storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned non-volatile storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, and other media that can store program codes.
[0303] The above are only preferred embodiments of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for verifying an application for a digital wallet account, characterized in that: include: Receive an application for a digital wallet account based on a target account; In response to the application operation, obtaining credit credential information of the target account on a first operating server, wherein the first operating server is an operating server to which the target account belongs; Obtaining pre-stored identity credential information of the target account on the identity credential issuing server; Sending the first identity identifier of the target account, the credit credential information, and the identity credential information to a second operation server, so that the second operation server authenticates the target account based on the credit credential information and the identity credential information, wherein the second operation server is a digital wallet account issuing server, and the first identity identifier is a distributed digital identity identifier corresponding to the target account; Receive the application result returned by the second operating server, wherein the application result includes a target digital wallet account, and the target digital wallet account is generated by the second operating server when the target account is verified based on the first identity identifier, the credit credential information, and the identity credential information.
2. The method according to claim 1, characterized in that The step of obtaining, in response to the application operation, credit credential information of the target account on the first operating server includes: In response to the application operation, sending a digital wallet account application request to the first operating server; Receive the credit credential information of the target account on the first operating server returned by the first operating server, wherein the credit credential information is determined based on the historical transactions and historical credit of the target account on the first operating server, and the credit credential information includes the credit credential of the target account and a credit signature corresponding to the credit credential.
3. The method according to claim 1, characterized in that Before obtaining the pre-stored identity credential information of the target account on the identity credential issuing server, the method further includes: Sending an identity credential verification request to the identity credential issuing server; Receive the identity credential information returned by the identity credential issuing server, and store the identity credential information, wherein the identity credential information includes the identity credential of the target account and the identity signature corresponding to the identity credential.
4. The method according to claim 1, wherein The sending the first identity identifier of the target account, the credit credential information, and the identity credential information to the second operation server includes: Obtaining a first public-private key pair of the target account and a second public key of the second operating server, wherein the first public-private key pair includes a first public key and a first private key; Encrypting the credit credential information and the identity credential information using the second public key to obtain a credential ciphertext, and signing the first identity identifier using the first private key to obtain a signature ciphertext; The credential ciphertext, the signature ciphertext, and the first public key are sent to the second operating server, so that the second operating server uses the second private key of the second operating server to decrypt the credential ciphertext, obtain the credit credential information and the identity credential information, and use the first public key to verify the signature ciphertext.
5. A digital wallet account application verification method, characterized in that: include: Receive a request from a target account to apply for a digital wallet account, wherein the request carries a first identity identifier of the target account, credit credential information of the target account on a first operating server, and identity credential information of the target account on an identity credential issuing server, wherein the identity credential information is pre-stored in a target terminal, wherein the first operating server is an operating server to which the target account belongs, and the first identity identifier is a distributed digital identity identifier of the target account; Verifying the target account based on the first identity identifier, the credit credential information, and the identity credential information; If the verification is successful, a target digital wallet account is generated and the target digital wallet account is returned to the target terminal along with the application result.
6. The method according to claim 5, characterized in that The receiving a request from a target account to apply for a digital wallet account includes: Obtain a second public-private key pair from a second operating server, wherein the second public-private key pair includes a second public key and a second private key, wherein the second operating server is a digital wallet account issuing server; Sending the second public key to the target terminal, wherein the second public key is used to encrypt the credit credential information and the identity credential information to obtain a credential ciphertext; Receive a request sent by the target terminal to apply for a digital wallet account based on the target account, wherein the request carries the credential ciphertext, the signature ciphertext, and the first public key of the target account, and the signature ciphertext is obtained by signing the first identity identifier using the first private key.
7. The method according to claim 6, characterized in that The verifying the target account based on the first identity identifier, the credit credential information, and the identity credential information includes: Decrypting the credential ciphertext using the second private key to obtain the credit credential information and the identity credential information, and verifying the signature ciphertext using the first public key to obtain the first identity identifier, wherein the credit credential information includes the credit credential of the target account and the credit signature corresponding to the credit credential, and the identity credential information includes the identity credential of the target account and the identity signature corresponding to the identity credential; If the signature ciphertext verification passes, the identity document of the target account is queried on the blockchain distributed identity management system based on the first identity identifier, wherein the identity document stores a correspondence between the target account and the first public key of the target account, a correspondence between the first operating server and the third public key of the first operating server, and a correspondence between the identity credential issuing server and the fourth public key of the identity credential issuing server; The credit signature is verified using the third public key, and the identity signature is verified using the fourth public key.
8. A method for verifying a digital wallet account application, comprising: Receive a request from a target account to apply for a digital wallet account; In response to the request, generating credit credential information of the target account on a first operating server, wherein the first operating server is the operating server to which the target account belongs; The credit credential information is fed back to the target terminal, so that the target terminal applies for a digital wallet account from the second operating server in combination with the first identity identifier and the identity credential information pre-stored in the target terminal, wherein the identity credential information is the identity credential of the target account on the identity credential issuing server, wherein the second operating server is a digital wallet account issuing server, and the first identity identifier is the distributed digital identity identifier of the target account.
9. The method according to claim 8, characterized in that The credit credential information includes the credit credential of the target account and a credit signature corresponding to the credit credential. The generating, in response to the request, the credit credential information of the target account on the first operating server includes: In response to the request, obtaining historical transactions and historical credit of the target account on the first operating server; generating a credit credential for the target account based on the historical transactions and the historical credit; The credit certificate is signed using the third private key of the first operating server to obtain the credit signature corresponding to the credit certificate.
10. The method according to claim 9, characterized in that The generating of the credit credential of the target account based on the historical transactions and the historical credit includes: Determining whether there is account privacy information in the historical transactions and the historical credit; If the account privacy information exists in the historical transactions and the historical credit, the credit certificate is generated based on the historical transactions and the historical credit using a zero-knowledge proof method.
11. The method according to claim 8, characterized in that Feeding back the credit credential information to the target terminal includes: Receiving a first public key of the target account; Encrypting the credit credential information using the first public key to obtain a credit credential ciphertext; The credit certificate ciphertext is sent to the target terminal.
12. The method according to claim 11, characterized in that The method further comprises: Obtaining a third public key of the first operation server; The third public key, the correspondence between the first operation server and the third public key, and the correspondence between the third public key and the target account are sent to the blockchain distributed identity management system, so that the blockchain distributed identity management system updates the third public key, the correspondence between the first operation server and the third public key, and the correspondence between the third public key and the target account in the second identity document corresponding to the first operation server.
13. A method for verifying a digital wallet account application, comprising: Receive a request from a target account to apply for identity credentials, wherein the request carries identity information of the target account; In response to the request, obtaining identity credential information of the target account on an identity credential issuing server based on the identity information; The identity credential information is sent to the target terminal and stored on the target terminal, wherein the target terminal is used to apply for identity authentication from the second operation server based on the first identity identifier of the target account, the credit credential information of the target account on the first operation server, and the pre-stored identity credential information when applying for a digital wallet account based on the target account, wherein the first operation server is the operation server to which the target account belongs, the second operation server is the digital wallet account issuing server, and the first identity identifier is the distributed digital identity identifier of the target account.
14. The method according to claim 13, characterized in that The identity credential information includes the identity credential of the target account and an identity signature corresponding to the identity credential. The step of obtaining the identity credential information of the target account on the identity credential issuing server based on the identity information in response to the request includes: In response to the request, generating the identity credential of the target account based on the identity information; Obtaining a fourth private key of the identity credential issuing server; The identity certificate is signed using the fourth private key to obtain the identity signature corresponding to the identity certificate.
15. The method according to claim 13, characterized in that The sending the identity credential information to the target terminal and storing it on the target terminal includes: Receiving a first public key of the target account; Encrypting the identity credential information using the first public key to obtain an identity credential ciphertext; The identity credential ciphertext is sent to the target terminal.
16. The method according to claim 14, characterized in that The method further comprises: Obtaining a fourth public key of the identity credential issuing server; The fourth public key, the correspondence between the identity credential issuing server and the fourth public key, and the correspondence between the fourth public key and the target account are sent to the blockchain distributed identity management system, so that the blockchain distributed identity management system updates the fourth public key, the correspondence between the identity credential issuing server and the fourth public key, and the correspondence between the fourth public key and the target account in the fourth identity document corresponding to the identity credential issuing server.
17. A method for applying for and verifying a digital wallet account, comprising: Receive a verification request from a second operating server for a digital wallet application for a target account, wherein the verification request carries a first identity identifier of the target account, a second identity identifier of the first operating server, and a fourth identity identifier of an identity credential issuing server, the first operating server is the operating server to which the target account belongs, and the second operating server is a digital wallet account issuing server, wherein the first identity identifier is a distributed digital identity identifier of the target account, the second identity identifier is a distributed digital identity identifier of the first operating server, and the fourth identity identifier is a distributed digital identity identifier of the identity credential issuing server; Based on the first identity document of the target account, the second identity document of the first operating server, and the fourth identity document of the identity credential issuing server, a first public key corresponding to the first identity identifier, a third public key corresponding to the second identity identifier, and a fourth public key corresponding to the fourth identity identifier are found, wherein the first identity document includes a correspondence between the first public key and the first identity identifier, the second identity document includes a correspondence between the third public key and the second identity identifier, and the fourth identity document includes a correspondence between the fourth public key and the fourth identity identifier; The first public key, the third public key and the fourth public key are sent to the second operating server for the second operating server to verify the signature ciphertext, credit signature and identity signature of the target account, wherein the signature ciphertext is obtained by the target terminal signing the first identity identifier using the first private key, the credit signature is obtained by the first operating server signing the credit certificate of the target account using the third private key, and the identity signature is obtained by the identity certificate issuing server signing the identity certificate of the target account using the fourth private key, and the identity signature is pre-stored in the target terminal.
18. The method according to claim 17, characterized in that Before receiving the verification request for applying for a digital wallet for the target account from the second operation server, the method further includes: Receive the public key corresponding to the target account's application for a digital wallet, where the public key includes the first public key of the target account, the third public key of the first operating server, the second public key of the second operating server, and the fourth public key of the identity credential issuing server; Generate the first identity of the target account, the second identity of the first operating server, the third identity of the second operating server, and the fourth identity of the identity credential issuing server, wherein the third identity is a distributed digital identity of the second operating server; Generate the first identity document of the target account, the second identity document of the first operation server, the third identity document of the second operation server, and the fourth identity document of the identity credential issuing server.
19. A method for verifying an application for a digital wallet account, comprising: The target terminal receives an application operation for a digital wallet account based on the target account; In response to the application operation, the target terminal sends a request for applying for a digital wallet account to a first operating server, wherein the first operating server is the operating server to which the target account belongs; In response to the request, the first operating server obtains the credit credential information of the target account on the first operating server, and feeds the credit credential information back to the target terminal; The target terminal obtains pre-stored identity credential information of the target account on the identity credential issuing server; The target terminal sends the first identity identifier, the credit credential information, and the identity credential information to the second operation server, wherein the second operation server is a digital wallet account issuing server, and the first identity identifier is a distributed digital identity identifier of the target account; The second operation server verifies the target account based on the first identity identifier, the credit credential information, and the identity credential information, and generates a target digital wallet account if the verification passes; The second operating server returns an application result including the target digital wallet account to the target terminal.
20. The method according to claim 19, characterized in that The first operation server obtains, in response to the request, the credit credential information of the target account on the first operation server, including: In response to the request, the first operation server obtains historical transactions and historical credit of the target account on the first operation server; The first operation server generates the credit credential information of the target account on the first operation server based on the historical transactions and the historical credit, where the credit credential information includes the credit credential of the target account and a credit signature corresponding to the credit credential.
21. The method according to claim 19, wherein Before the target terminal obtains the pre-stored identity credential information of the target account on the identity credential issuing server, the method further includes: The target terminal sends an identity credential verification request to the identity credential issuing server; The identity credential issuing server returns corresponding identity credential information to the target terminal; The target terminal stores the identity credential information returned by the identity credential issuing server, wherein the identity credential information includes the identity credential of the target account and the identity signature corresponding to the identity credential.
22. The method according to claim 19, wherein The target terminal sending the credit credential information and the identity credential information to the second operation server includes: The target terminal obtains a first public-private key pair of the target account and a second public key of the second operating server, wherein the first public-private key pair includes a first public key and a first private key; The target terminal encrypts the credit credential information and the identity credential information using the second public key to obtain a credential ciphertext, and signs the first identity identifier using the first private key to obtain a signature ciphertext; The target terminal sends the credential ciphertext, the signature ciphertext, and the first public key to the second operation server.
23. The method according to claim 22, characterized in that The second operation server verifies the target account based on the credit credential information and the identity credential information, including: The second operating server uses the second private key of the second operating server to decrypt the credential ciphertext to obtain the credit credential information and the identity credential information, and uses the first public key to verify the signature ciphertext; When the signature ciphertext passes the verification, the second operation server verifies the target account based on the credit credential information and the identity credential information.
24. The method according to claim 22, characterized in that The method further comprises: The target terminal obtains the first public key and the first private key of the target account, and sends the first public key to the blockchain distributed identity management system. The first operation server obtains the third public key and the third private key of the first operation server, and sends the third public key to the blockchain distributed identity management system. The second operation server obtains the second public key and the second private key of the second operation server, and sends the second public key to the blockchain distributed identity management system. The identity credential issuing server obtains the fourth public key and the fourth private key of the identity credential issuing server, and sends the fourth public key to the blockchain distributed identity management system. The blockchain distributed identity management system generates a first identity identifier for the target account, a second identity identifier for the first operating server, a third identity identifier for the second operating server, and a fourth identity identifier for the identity credential issuing server, wherein the second identity identifier is a distributed digital identity identifier of the first operating server, the third identity identifier is a distributed digital identity identifier of the second operating server, and the fourth identity identifier is a distributed digital identity identifier of the identity credential issuing server; The blockchain distributed identity management system generates a first identity document for the target account, a second identity document for the first operation server, a third identity document for the second operation server, and a fourth identity document for the identity credential issuing server, wherein the first identity document includes a correspondence between the first public key and the first identity identifier, the second identity document includes a correspondence between the third public key and the second identity identifier, and the third identity document includes a correspondence between the second public key and the third identity identifier, and the fourth identity document includes a relationship between the fourth public key and the fourth identity identifier.
25. A digital wallet account application verification device, characterized in that: include: A first receiving module is configured to receive an application operation for applying for a digital wallet account based on a target account; a first acquisition module, configured to, in response to the application operation, acquire credit credential information of the target account on a first operation server, wherein the first operation server is the operation server to which the target account belongs; A second acquisition module is used to obtain the pre-stored identity credential information of the target account in the identity credential issuing server; a first sending module, configured to send the first identity identifier of the target account, the credit credential information, and the identity credential information to a second operation server, so that the second operation server authenticates the target account based on the credit credential information and the identity credential information, wherein the second operation server is a digital wallet account issuing server, and the first identity identifier is a distributed digital identity identifier of the target account; a first result returning module, configured to receive an application result returned by the second operating server, wherein the application result includes a target digital wallet account, and the target digital wallet account is generated by the second operating server when the target account is verified successfully based on the first identity identifier, the credit credential information, and the identity credential information.
26. A digital wallet account application verification device, characterized in that: include: a second receiving module, configured to receive a request from a target account to apply for a digital wallet account, wherein the request carries a first identity identifier of the target account, credit credential information of the target account on a first operating server, and identity credential information of the target account on an identity credential issuing server, wherein the identity credential information is pre-stored in a target terminal, wherein the first operating server is an operating server to which the target account belongs, and the first identity identifier is a distributed digital identity identifier of the target account; a first verification module, configured to verify the target account based on the first identity identifier, the credit credential information, and the identity credential information; The second result returning module is used to generate a target digital wallet account if the verification is passed, and return the target digital wallet account to the target terminal along with the application result.
27. A digital wallet account application verification device, comprising: A third receiving module is used to receive a request from a target account to apply for a digital wallet account; a first generating module, configured to generate, in response to the request, credit credential information of the target account on a first operating server, wherein the first operating server is the operating server to which the target account belongs; The first feedback module is used to feed back the credit credential information to the target terminal, so that the target terminal applies for a digital wallet account from the second operating server in combination with the first identity identifier and the identity credential information pre-stored in the target terminal, wherein the identity credential information is the identity credential of the target account on the identity credential issuing server, wherein the second operating server is a digital wallet account issuing server, and the first identity identifier is the distributed digital identity identifier of the target account.
28. A digital wallet account application verification device, comprising: a fourth receiving module, configured to receive a request from a target account for applying for identity credentials, wherein the request carries identity information of the target account; a third acquisition module, configured to, in response to the request and based on the identity information, acquire identity credential information of the target account on the identity credential issuing server; The second sending module is used to send the identity credential information to the target terminal and store it on the target terminal, wherein the target terminal is used to apply for identity authentication from the second operation server based on the first identity identifier of the target account, the credit credential information of the target account on the first operation server, and the pre-stored identity credential information when applying for a digital wallet account based on the target account, wherein the first operation server is the operation server to which the target account belongs, the second operation server is the digital wallet account issuing server, and the first identity identifier is the distributed digital identity identifier of the target account.
29. A digital wallet account application verification device, comprising: a fifth receiving module, configured to receive a verification request from a second operating server for an application for a digital wallet for a target account, wherein the verification request carries a first identity identifier of the target account, a second identity identifier of the first operating server, and a fourth identity identifier of an identity credential issuing server, the first operating server being the operating server to which the target account belongs, the second operating server being a digital wallet account issuing server, the first identity identifier being a distributed digital identity identifier of the target account, the second identity identifier being a distributed digital identity identifier of the first operating server, and the fourth identity identifier being a distributed digital identity identifier of the identity credential issuing server; a first search module, configured to search, based on a first identity document of the target account, a second identity document of the first operating server, and a fourth identity document of the identity credential issuing server, for a first public key corresponding to the first identity identifier, a third public key corresponding to the second identity identifier, and a fourth public key corresponding to the fourth identity identifier, wherein the first identity document includes a correspondence between the first public key and the first identity identifier, the second identity document includes a correspondence between the third public key and the second identity identifier, and the fourth identity document includes a correspondence between the fourth public key and the fourth identity identifier; The third sending module is used to send the first public key, the third public key and the fourth public key to the second operating server, so that the second operating server can verify the signature ciphertext, credit signature and identity signature of the target account, wherein the signature ciphertext is obtained by the target terminal using the first private key to sign the first identity identifier, the credit signature is obtained by the first operating server using the third private key to sign the credit certificate of the target account, and the identity signature is obtained by the identity certificate issuing server using the fourth private key to sign the identity certificate of the target account, and the identity signature is pre-stored in the target terminal.
30. A digital wallet account application verification device, comprising: A sixth receiving module, configured for the target terminal to receive an application operation for applying for a digital wallet account based on the target account; a first application module, configured for the target terminal to send a request for applying for a digital wallet account to a first operation server in response to the application operation, wherein the first operation server is the operation server to which the target account belongs; a fourth acquisition module, configured for the first operation server to obtain, in response to the request, the credit credential information of the target account on the first operation server, and to feed back the credit credential information to the target terminal; A fifth acquisition module, configured for the target terminal to acquire pre-stored identity credential information of the target account on the identity credential issuing server; a fourth sending module, configured for the target terminal to send the first identity identifier, the credit credential information, and the identity credential information to a second operation server, wherein the second operation server is a digital wallet account issuing server, and the first identity identifier is a distributed digital identity identifier of the target account; a second verification module, configured for the second operation server to verify the target account based on the first identity identifier, the credit credential information, and the identity credential information, and to generate a target digital wallet account if the verification passes; The third result returning module is configured for the second operating server to return the application result including the target digital wallet account to the target terminal.
31. A digital wallet account application verification system, comprising: The target terminal is configured to receive an application operation for a digital wallet account based on a target account; and in response to the application operation, send a request for applying for a digital wallet account to a first operating server, wherein the first operating server is the operating server to which the target account belongs; The first operating server is connected to the target terminal, and is configured to obtain, in response to the request, the credit credential information of the target account on the first operating server, and feed the credit credential information back to the target terminal; The target terminal is further configured to obtain pre-stored identity credential information of the target account on the identity credential issuing server; send the first identity identifier, the credit credential information, and the identity credential information to a second operating server, wherein the second operating server is a digital wallet account issuing server, and the first identity identifier is a distributed digital identity identifier of the target account; The second operating server is connected to the target terminal and is used to verify the target account based on the first identity identifier, the credit credential information and the identity credential information, and generate a target digital wallet account if the verification is successful; and return an application result including the target digital wallet account to the target terminal.
32. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executed by the digital wallet account application verification method described in any one of claims 1 to 24.
33. An electronic device, characterized in that: The device comprises one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the application verification method for a digital wallet account as described in any one of claims 1 to 24.
Citation Information
Patent Citations
Credit voucher generating method and system, and application authorization method and system
CN103854180A
System and method for digital currency storage, payment and credit
US20160335628A1