Identity verification method, device, and electronic device
By receiving and utilizing trusted credentials, and leveraging blockchain technology and a distributed identity management system, the problem of repeated authentication of users across multiple operating organizations is resolved, cross-organizational identity information reuse is achieved, and user experience and information security are improved.
Patent Information
- Application Number
- CN202310652323.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-02
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2043-06-02
AI Technical Summary
In existing technologies, users need to independently authenticate their identity information with multiple operating organizations, resulting in low efficiency of repeated verification and the risk of information leakage.
By receiving and utilizing trusted credentials, users can reduce repeated identity authentication between different institutions, achieve cross-institutional identity information reuse, and use blockchain technology and distributed identity management systems to generate and manage trusted credentials to achieve cross-institutional identity authentication.
It reduces repeated identity authentication for users between different institutions, improves user experience and information security, and improves the efficiency and security of identity authentication.
Smart Images

Figure CN119067656B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of financial technology and blockchain technology, and in particular to an identity verification method, device, and electronic device. Background Art
[0002] Customer identity verification refers to the process by which financial institutions identify and conduct background checks on their customers when establishing business relationships with them. It is an effective means of detecting and preventing suspicious transactions with financial crime risks, and is also the first line of defense against illegal money transactions and terrorist financing.
[0003] However, existing customer identity verification methods present numerous issues and risks. For example, financial institutions need to ensure the authenticity of user identification data, while users are concerned about data security authorization and privacy protection. When using services from multiple financial institutions, users must independently verify their identity with each institution, resulting in a large number of repeated identity verifications and low verification efficiency, significantly impacting the user experience and posing risks such as information leakage.
[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0005] The embodiments of the present invention provide an identity authentication method, apparatus, and electronic device to at least solve the technical problem in the prior art that a user needs to independently authenticate identity information with multiple operating organizations, resulting in a large number of repeated authentications.
[0006] According to one aspect of an embodiment of the present invention, an identity authentication method is provided, including: receiving a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; in response to the first wallet account application, obtaining a first trusted credential of the digital wallet user, wherein the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account on the second operating server; sending the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the opening of the wallet account of the digital wallet user on the first operating server.
[0007] According to one aspect of an embodiment of the present invention, an identity authentication method is provided, including: receiving a first wallet account application sent by a target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server, and the first wallet account application carries a first trusted credential of the digital wallet user, and the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account on the second operating server; and processing the opening of the wallet account of the digital wallet user on the first operating server based on the first trusted credential.
[0008] According to one aspect of an embodiment of the present invention, an identity authentication method is provided, including: receiving a second wallet account application sent by a target terminal, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on a second operating server, and the second wallet account application carries the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on an identity credential issuing server; verifying the digital wallet user based on the first identity identifier and the identity credential information; if the verification is successful, generating a target wallet account for the digital wallet user on the second operating server, and generating a first trusted credential for the digital wallet user; sending the first trusted credential to the target terminal for the target terminal to store the first trusted credential.
[0009] According to one aspect of an embodiment of the present invention, an identity authentication method is provided, comprising: receiving a first public key of a digital wallet user sent by a target terminal, receiving a second public key of the first operating server, receiving a third public key of the second operating server, and receiving a fourth public key of an identity certificate issuing server; generating a first identity identifier for the digital wallet user, generating a second identity identifier for the first operating server, generating a third identity identifier for the second operating server, and generating a fourth identity identifier for the identity certificate issuing server; generating a first identity document for the digital wallet user, generating a second identity document for the first operating server, generating a third identity document for the second operating server, and generating a fourth identity document for the identity certificate issuing server, wherein the first identity document stores the first identity identifier and the third identity identifier. The first identity identifier and the correspondence between the first public key, the second identity document stores the second identity identifier of the first operation server, and the correspondence between the second identity identifier and the second public key, the third identity document stores the third identity identifier of the second operation server, and the correspondence between the third identity identifier and the third public key, the fourth identity document stores the fourth identity identifier of the identity certificate issuing server, and the correspondence between the fourth identity identifier and the fourth public key; receiving the first trusted certificate sent by the second operation server, and updating the first trusted certificate in the first identity document, wherein the first trusted certificate is used to identify that the second operation server has verified the digital wallet user and opened a wallet account in the second operation server.
[0010] According to one aspect of an embodiment of the present invention, an identity authentication method is provided, including: a target terminal receives a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; the target terminal obtains a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account in the second operating server; the target terminal sends the first trusted credential to the first operating server; the first operating server processes the opening of the wallet account of the digital wallet user on the first operating server based on the first trusted credential.
[0011] According to one aspect of an embodiment of the present invention, an identity authentication device is provided, including: a first receiving module, used to receive a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; a first obtaining module, used to obtain a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account in the second operating server; a first sending module, used to send the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the opening of the wallet account of the digital wallet user on the first operating server.
[0012] According to one aspect of an embodiment of the present invention, an identity authentication device is provided, including: a second receiving module, configured to receive a first wallet account application sent by a target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server, and the first wallet account application carries a first trusted credential of the digital wallet user, and the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account on the second operating server; and a first processing module, configured to process the opening of the wallet account of the digital wallet user on the first operating server based on the first trusted credential.
[0013] According to one aspect of an embodiment of the present invention, an identity authentication device is provided, including: a third receiving module, used to receive a second wallet account application sent by a target terminal, wherein the above-mentioned second wallet account application is used to apply for the wallet account of the above-mentioned digital wallet user on the second operating server, and the above-mentioned second wallet account application carries the first identity identifier of the above-mentioned digital wallet user, and the identity credential information of the above-mentioned digital wallet user on the identity credential issuing server; a verification module, used to verify the above-mentioned digital wallet user based on the above-mentioned first identity identifier and the above-mentioned identity credential information; a first generation module, used to generate a target wallet account for the above-mentioned digital wallet user on the second operating server and generate a first trusted credential for the above-mentioned digital wallet user if the verification is passed; a second sending module, used to send the above-mentioned first trusted credential to the above-mentioned target terminal, for the above-mentioned target terminal to store the above-mentioned first trusted credential and to apply for the wallet account of the above-mentioned digital wallet user on the first operating server.
[0014] According to one aspect of an embodiment of the present invention, an identity authentication device is provided, including: a fourth receiving module for receiving a first public key of a digital wallet user sent by a target terminal, receiving a second public key of the above-mentioned first operating server, receiving a third public key of the second operating server, and receiving a fourth public key of an identity certificate issuing server; a second generating module for generating a first identity identifier for the above-mentioned digital wallet user, generating a second identity identifier for the above-mentioned first operating server, generating a third identity identifier for the above-mentioned second operating server, and generating a fourth identity identifier for the above-mentioned identity certificate issuing server; a third generating module for generating a first identity document for the above-mentioned digital wallet user, generating a second identity document for the above-mentioned first operating server, generating a third identity document for the above-mentioned second operating server, and generating a fourth identity document for the above-mentioned identity certificate issuing server, wherein the above-mentioned first identity document stores the above-mentioned first identity The copy identifier, and the correspondence between the above-mentioned first identity identifier and the above-mentioned first public key, the above-mentioned second identity document stores the second identity identifier of the above-mentioned first operation server, and the correspondence between the above-mentioned second identity identifier and the above-mentioned second public key, the above-mentioned third identity document stores the third identity identifier of the above-mentioned second operation server, and the correspondence between the above-mentioned third identity identifier and the above-mentioned third public key, the above-mentioned fourth identity document stores the fourth identity identifier of the identity certificate issuing server, and the correspondence between the above-mentioned fourth identity identifier and the above-mentioned fourth public key; a fifth receiving module is used to receive the first trusted credential sent by the above-mentioned second operation server, and update the above-mentioned first trusted credential in the above-mentioned first identity document, wherein the above-mentioned first trusted credential is used to identify that the above-mentioned second operation server has verified the above-mentioned digital wallet user and opened a wallet account in the above-mentioned second operation server.
[0015] According to one aspect of an embodiment of the present invention, an identity authentication device is provided, including: a sixth receiving module, used for a target terminal to receive a first wallet account application, wherein the above-mentioned first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; a second obtaining module, used for the above-mentioned target terminal to respond to the above-mentioned first wallet account application and obtain a first trusted credential of the above-mentioned digital wallet user, wherein the above-mentioned first trusted credential is used to identify that the second operating server has verified the above-mentioned digital wallet user and opened a wallet account in the above-mentioned second operating server; a third sending module, used for the above-mentioned target terminal to send the above-mentioned first trusted credential to the above-mentioned first operating server; and a second processing module, used for the above-mentioned first operating server to process the wallet account opening of the above-mentioned digital wallet user on the first operating server based on the above-mentioned first trusted credential.
[0016] According to one aspect of an embodiment of the present invention, an identity authentication system is provided, comprising: a target terminal, configured to receive a first wallet account application; in response to the first wallet account application, obtaining a first trusted credential of the digital wallet user; and sending the first trusted credential to the first operation server; the first operation server, connected to the target terminal, configured to receive the first wallet account application sent by the target terminal, and process the opening of a wallet account for the digital wallet user on the first operation server based on the first trusted credential; the target terminal is further configured to receive a second wallet account application; obtain a first identity identifier of the digital wallet user, and identity credential information of the digital wallet user on an identity credential issuing server; sending the first identity identifier and the identity credential information to the second operation server; obtaining the first trusted credential generated by the second operation server and storing the first trusted credential; the second operation server, connected to the target terminal, configured to verify the digital wallet user based on the first identity identifier and the identity credential information, and if the verification is successful, generate a target wallet account, generate a first trusted credential for the digital wallet user, and send the first trusted credential to the target terminal.
[0017] According to one aspect of an embodiment of the present invention, a non-volatile storage medium is provided. The non-volatile storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing any one of the above-mentioned identity authentication methods.
[0018] According to one aspect of an embodiment of the present invention, an electronic device is provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the above-mentioned identity authentication methods.
[0019] In an embodiment of the present invention, by receiving a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; in response to the first wallet account application, obtaining a first trusted credential of the digital wallet user, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account on the second operating server; sending the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the wallet account opened by the digital wallet user on the first operating server, thereby achieving the purpose of reusing trusted credentials to reduce the repeated submission of information by users when applying for services from different institutions, thereby achieving the technical effect of reducing repeated identity verification, improving user experience, and improving user information security, and further solving the technical problem in the prior art that users need to independently authenticate their identity information to multiple operating institutions, resulting in a large number of repeated authentications. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0021] Figure 1 is a flow chart of a first identity authentication method according to an embodiment of the present invention;
[0022] Figure 2 is a timing diagram of the first customer identity identification and authentication according to an embodiment of the present invention;
[0023] Figure 3 is a flow chart of a second identity authentication method according to an embodiment of the present invention;
[0024] Figure 4 is a timing diagram of non-first-time customer identity identification and authentication according to an embodiment of the present invention;
[0025] Figure 5 is a flowchart of a third identity authentication method according to an embodiment of the present invention;
[0026] Figure 6 is a flowchart of a fourth identity authentication method according to an embodiment of the present invention;
[0027] Figure 7 is a flowchart of a fifth identity authentication method according to an embodiment of the present invention;
[0028] Figure 8 2 is a schematic structural diagram of an identity authentication method provided according to an embodiment of the present invention;
[0029] Figure 9is a schematic structural diagram of an identity authentication device according to an embodiment of the present invention;
[0030] Figure 10 is a schematic structural diagram of an identity authentication device according to an embodiment of the present invention;
[0031] Figure 11 is a schematic structural diagram of an identity authentication device according to an embodiment of the present invention;
[0032] Figure 12 is a schematic structural diagram of an identity authentication device according to an embodiment of the present invention;
[0033] Figure 13 is a schematic structural diagram of an identity authentication device according to an embodiment of the present invention;
[0034] Figure 14 2 is a schematic diagram of the architecture of an identity authentication system provided according to an embodiment of the present invention. DETAILED DESCRIPTION
[0035] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0036] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0037] Terminology
[0038] Customer Identity Verification: Customer identity verification refers to the process financial institutions conduct to identify and conduct background checks on customers before establishing a business relationship with them. Customer identity verification is an effective means of detecting and preventing suspicious transactions that could represent financial crime risks, and it serves as the first line of defense against illegal financial transactions and terrorist financing. Currently, relevant laws require financial institutions to conduct customer identity verification for all types of users applying for financial services.
[0039] A blockchain is a chain of blocks. Each block contains a specific piece of information, linked together in chronological order. This chain is stored across all servers, and as long as at least one server in the system is functioning, the entire blockchain remains secure. These servers, called nodes in the blockchain system, provide storage space and computing power. Modifying information in the blockchain requires the consent of more than half of the nodes and the modification of all nodes. These nodes are often controlled by different entities, making tampering with blockchain information extremely difficult. Compared to traditional networks, blockchains possess two core advantages: data tampering resistance and decentralization. These two characteristics make the information recorded in blockchains more authentic and reliable, helping to address issues of mutual trust.
[0040] A signature certificate is a public key certificate that contains a public key. The public key is used to authenticate digital signatures but cannot encrypt data or perform other cryptographic functions.
[0041] Digital wallet users: Consumers who use digital wallet applications (incorporating security capabilities such as secure chips or trusted execution environments) to make transactions and pay, fulfilling customer identity identification obligations.
[0042] Operator: Responsible for opening user digital wallet app accounts, with one user corresponding to one app account. Financial institutions provide account opening and payment services for digital wallet app users. They issue distributed identity credentials to users of their own operator and verify the distributed identity credentials of users at other operators. A single digital wallet app user account can open multiple different wallet accounts at each operator.
[0043] Blockchain distributed identity management system: A system based on blockchain technology that issues distributed identity identifiers (DIDs) to relevant parties and generates and manages distributed identity documents.
[0044] Viable certificate issuing agency: an agency that provides various credible certificates to users (individual users or corporate users), verifies users online, and issues verifiable electronic certificates corresponding to the credible certificates.
[0045] The aforementioned identity verification method is applied to a two-tiered operating system: central bank-operating institution-user, with the central bank responsible for issuance and the operating institution responsible for circulation to users. The roles and systems within this system include: a digital wallet application (user), a blockchain-based distributed identity management system (a distributed system jointly established by the central bank and the operating institution), the central bank's business system, the digital wallet operating institution's business system, and a trusted credential issuing authority. This invention combines distributed identity, blockchain, cryptography, and other technologies to propose a joint customer identity verification method within this two-tiered operating model.
[0046] According to an embodiment of the present invention, an embodiment of a method for identity authentication is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0047] Figure 1 : is a flow chart of a first identity authentication method according to an embodiment of the present invention. Figure 1 As shown, the method includes the following steps:
[0048] Step S102: Receive a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operator server;
[0049] Step S104: In response to the first wallet account application, obtaining a first trusted credential of the digital wallet user, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account on the second operating server;
[0050] Step S106: Send the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the digital wallet user opening a wallet account on the first operating server.
[0051] In an embodiment of the present invention, the execution subject of the identity authentication method provided in the above steps S102 to S106 is the target terminal. The user triggers an application for activation of a first digital wallet account to the first operating institution in the above target terminal. The above target terminal responds to the above first wallet account application, obtains the first trusted credential stored in the digital wallet user already in the above target terminal, and sends the above first trusted credential to the above first operating server for verification processing.
[0052] It should be noted that the above-mentioned first wallet account application is used to apply for a wallet account of a digital wallet user on the first operating server; the above-mentioned first trusted certificate is used to identify that the second operating server has verified the above-mentioned digital wallet user and opened a wallet account on the above-mentioned second operating server; the above-mentioned first trusted certificate is used by the above-mentioned first operating server to process the above-mentioned digital wallet user's application for opening a wallet account on the first operating server.
[0053] It should also be noted that the above-mentioned target terminal is an intelligent electronic device used by the user, and the above-mentioned target terminal is used to run the application where the digital wallet user is located, and the above-mentioned application is used to send the above-mentioned first wallet account application; the above-mentioned first wallet account is a wallet account that can be opened on the above-mentioned first operating server; before opening the first wallet account for the user, the above-mentioned first operating server needs to verify the first trusted credential of the user, and after the verification is passed, the above-mentioned first wallet account is opened for the user, and a new trusted credential is created and sent to the user for storage.
[0054] As an optional embodiment, a user wants to open a first digital wallet account at a first operating institution (operating institution B) and submits an activation application in the digital wallet APP. The above-mentioned target terminal responds to the above-mentioned first wallet account application, obtains the first trusted credential stored in the existing digital wallet user in the above-mentioned target terminal, and sends the above-mentioned first trusted credential to the above-mentioned first operating server for verification.
[0055] Through the embodiments of the present invention, various identity information of users is converted into verifiable credentials. By reusing verifiable credentials, users can reduce the need to repeatedly submit information when applying for services from different institutions. After the second financial institution completes the verification of the verifiable credentials, the identity management system updates the user document and adds the second financial institution's verification relationship for the user's credentials. When the first financial institution verifies the user's credentials, it can find the credential verification of the second financial institution and verify the credentials it issued to the user, thereby completing a collaborative identity information authentication. At the same time, the identity management system updates the user document and adds the second financial institution's verification relationship for the user's credentials, and the user's credentials are accumulated in this way.
[0056] In an optional embodiment, before the above-mentioned response to the above-mentioned first wallet account application and obtaining the first trusted credential of the above-mentioned digital wallet user, it also includes: receiving a second wallet account application, wherein the above-mentioned second wallet account application is used to apply for a wallet account of the above-mentioned digital wallet user on a second operating server; obtaining the first identity identifier of the above-mentioned digital wallet user, and the identity credential information of the above-mentioned digital wallet user on the identity credential issuing server; sending the above-mentioned first identity identifier and the above-mentioned identity credential information to the above-mentioned second operating server; obtaining the above-mentioned first trusted credential generated by the above-mentioned second operating server and storing the above-mentioned first trusted credential.
[0057] In the embodiment of the present invention, before the user triggers the application for opening the first digital wallet account to the first operating institution in the target terminal, the user may have opened a second wallet account with the second operating institution, such as Figure 2 As shown in the first customer identity identification and authentication sequence diagram, the steps for opening a second wallet account at the second operating institution are as follows: the above-mentioned target terminal receives and responds to the above-mentioned second wallet account application, obtains the first identity identifier and the above-mentioned identity credential information stored in the digital wallet user already in the above-mentioned target terminal, and sends the above-mentioned first identity identifier and the above-mentioned identity credential information to the above-mentioned second operating server for verification processing. After the above-mentioned second operating institution verifies the first trusted credential, it generates the above-mentioned first trusted credential and sends the above-mentioned first trusted credential to the above-mentioned target terminal for storage.
[0058] It should be noted that the above-mentioned second wallet account application is used to apply for a wallet account of the above-mentioned digital wallet user on the second operating server; the above-mentioned first trusted certificate is used to identify that the second operating server has verified the above-mentioned digital wallet user and opened a wallet account on the above-mentioned second operating server. The above-mentioned second wallet account is the first digital wallet account opened by the target user.
[0059] It should also be noted that the above-mentioned target terminal is an intelligent electronic device used by the user, and the above-mentioned target terminal is used to run the application where the digital wallet user is located, and the above-mentioned application is used to send the above-mentioned second wallet account application; the above-mentioned second wallet account is a wallet account that can be opened on the above-mentioned second operating server; before opening the second wallet account for the user, the above-mentioned second operating server needs to verify the user's first identity identifier and the above-mentioned identity credential information, and after the verification is passed, the above-mentioned second wallet account is opened for the user, and a first trusted credential is created and sent to the user for storage.
[0060] As an optional embodiment, a user wants to open a second digital wallet account at a second operating institution (operating institution A) and submits an activation application in the digital wallet APP. The above-mentioned target terminal responds to the above-mentioned second wallet account application, obtains the first identity identifier and the above-mentioned identity credential information pre-created and applied for in the above-mentioned target terminal, and sends the above-mentioned first identity identifier and the above-mentioned identity credential information to the above-mentioned second operating server for verification processing.
[0061] In an optional embodiment, the obtaining of the first trusted credential generated by the second operation server includes: downloading the first trusted credential from the blockchain distributed identity management server, wherein the first trusted credential is generated by the second operation server and sent to the blockchain distributed identity management server; downloading the first trusted credential from the second operation server, wherein the first trusted credential is generated by the second operation server and stored in the second operation server.
[0062] In an embodiment of the present invention, the above-mentioned first trusted credential generated by the above-mentioned second operation server can be sent to the target terminal of the target user for storage and can also be sent to the blockchain distributed identity management server for storage; therefore, the above-mentioned first trusted credential generated by the above-mentioned second operation server can be obtained, and the above-mentioned first trusted credential can also be downloaded from the blockchain distributed identity management server.
[0063] It should be noted that the above-mentioned first trusted certificate is generated by the above-mentioned second operation server and sent to the above-mentioned blockchain distributed identity management server for storage.
[0064] As an optional embodiment, the above-mentioned target user can use the target terminal to send a digital wallet account application to multiple of the above-mentioned second operating servers. After verifying the user's first identity identifier and the above-mentioned identity credential information (which can be credential information generated after verification by other operating institutions), the above-mentioned multiple second operating servers create a digital wallet account for the user and generate a trusted credential corresponding to the operating institution.
[0065] Optionally, when a user generates trusted credentials corresponding to an operating organization on multiple second operating servers, the storage space of the digital wallet application in the target terminal may not be able to store multiple trusted credentials, or multiple trusted credentials occupy too much storage space and seriously affect the user experience. In this case, the trusted credentials generated by the operating organization can be sent to the above-mentioned blockchain distributed identity management server for storage.
[0066] In an optional embodiment, the blockchain distributed identity management server stores the first identity document of the digital wallet user, the second identity document of the first operating server, the third identity document of the second operating server, and the fourth identity document of the identity certificate issuing server, wherein the first identity document stores the first identity identifier and the correspondence between the first identity identifier and the first public key, and the first public key is the public key of the digital wallet user; the second identity document stores the second identity identifier of the first operating server and the correspondence between the second identity identifier and the second public key, and the second public key is the public key of the first operating server; the third identity document stores the third identity identifier of the second operating server and the correspondence between the third identity identifier and the third public key, and the third public key is the public key of the second operating server; the fourth identity document stores the fourth identity identifier of the identity certificate issuing server and the correspondence between the fourth identity identifier and the fourth public key, and the fourth public key is the public key of the identity certificate issuing server.
[0067] In an embodiment of the present invention, the above-mentioned target users, multiple operating organizations, identity certificate issuing servers, etc. all need to generate a key pair and send the public key of the above-mentioned key pair to the above-mentioned blockchain distributed identity management server. The blockchain distributed identity management system generates the identity identification of each system and creates an identity document.
[0068] It should be noted that the identity document is a key-value database table, and each identity document records attributes such as the binding relationship between each ID and its public key.
[0069] As an optional embodiment, each institution generates a key for registering a user's distributed identity identifier TID, where: digital wallet user a generates a key pair Pk_user_a / Sk_user_a; operating institution A generates a key pair Pk_Regi_A / Sk_Regi_A and operating institution B generates a key pair Pk_Regi_B / Sk_Regi_B, as well as the central bank-side business system Pk_Regi_C / Sk_Regi_C; the certificate issuing institution and the operating institution generate a certificate verifiable certificate issuance public key, and generate public and private keys for the n identity certificate issuing institutions that issue certificates to users, represented by Pk_issuer_1 / Sk_issuer_1, Pk_issuer_2 / Sk_issuer_2..., Pk_issuer_n / Sk_issuer_n respectively; the operating institution generates the corresponding public and private keys for the verifiable certificate issued to the user as Pk_issuer_A / Sk_issuer_A and Pk_issuer_B / Sk_issuer_B.
[0070] Optionally, digital wallet user a, operating institution A and operating institution B, and the central bank-side business system submit public keys Pk_user_a, Pk_Regi_A, Pk_Regi_B, and Pk_Regi_C to the blockchain distributed identity management system respectively; the blockchain distributed identity management system generates the identity identifiers TID_wallet_a, TID_A, TID_B, and TID_C of their respective systems, and generates identity documents for digital wallet user a, operating institution A, operating institution B, and the central bank-side business system: TID-Doc_Wallet_a, TID-Doc_A, and TID-Doc_C. c_B, TID-Doc_C, the identity document is a key-value database table. Each identity document records the binding relationship between each ID and its public key and other attributes, including: the corresponding binding relationship between wallet user a's identity TID: TID_wallet_a and wallet user a's public key Pk_user_a; the corresponding binding relationship between the identity documents of operating institutions A and operating institutions B, and the central bank-side business system C and their public keys; the blockchain distributed identity management system issues respective TIDs to digital wallet user a, operating institutions A and operating institutions B, and the central bank-side business system C; identity documents are automatically synchronized through the blockchain to prevent tampering.
[0071] It should be noted that the above-mentioned central bank-side business system can also be responsible for opening user digital wallet App accounts and other businesses to prevent some operating institutions from being unable to complete account opening and other operations. The central bank-side business system must also follow the principle that one user corresponds to one App account, and one App account can have multiple wallet accounts.
[0072] It should also be noted that the user's distributed identity identifier (TID) is an identity ID issued by the distributed identity management system. TID_wallet_a represents the ID of the digital wallet user, TID_A and TID_B represent the identity IDs of operating institutions A and B, respectively, representing the ID of the digital wallet server. TID_Y represents the distributed identity ID of the central bank, and TID_issuer represents the ID of the trusted issuing institution of the identity credential.
[0073] Optionally, the public and private keys of the digital wallet user, Pk_user / Sk_user, are generated locally in the digital wallet. The public and private keys of user a are Pk_user_a / Sk_user_a, respectively. The key pair of digital wallet user a is mainly used to declare to the digital wallet server through a signature that the TID submitted by it belongs to this user. (The private key generated by the wallet user can be protected by the TEE trusted solution or collaborative signature solution currently in the industry. The idea of collaborative signature is that the communicating parties each store part of the private key, and the two parties can jointly sign or decrypt the message, and neither party can obtain any information about the other party's private key.) To enhance security, in the embodiment of this application, the public keys are all public key certificates.
[0074] Optional, Pk_Regi / Sk_Regi is mainly used by each institution to apply for a TID from the blockchain distributed identity management system (the public key is used to apply for the TID, and the private key can be used for self-signing to prove to others that the TID belongs to the institution). Among them, Pk_Regi_A / Sk_Regi_A, Pk_Regi_B / Sk_Regi_B, and Pk_Regi_C / Sk_Regi_C are the public and private keys of operating institutions A and B and the central bank, respectively.
[0075] Optional, public and private keys of the identity certificate issuing agency Pk_issuer / Sk_issuer: When there are n generalized identity certificate issuing agencies, the public and private key pairs are represented by Pk_issuer_1 / Sk_issuer_1, Pk_issuer_2 / Sk_issuer_2…, Pk_issuer_n / Sk_issuer_n respectively. In the embodiment of the present application, the operating agency can also issue verifiable credentials to users, and the corresponding public and private keys are Pk_issuer_A / Sk_issuer_A, Pk_issuer_B / Sk_issuer_B.
[0076] Optional TID-DOC identity document initialization: Each TID-DOC is a table in a key-value database stored in the blockchain distributed identity management system. The corresponding TID-DOC can be found by using the TID. When digital wallet users, digital wallet servers, and generalized identity credential issuing institutions apply for a TID, the distributed identity management system will write the corresponding binding relationship between their TID and public key into the document, such as the relationship between Pk_user_a and TID_wallet_a, and the relationship between TID_Veri and Pk_issuer_TIDRegi. The TID-DOC is synchronized with the blockchain ledger to ensure that it cannot be tampered with.
[0077] Optional TID-DOC Update: When a digital wallet user adds a new credential issued by a generalized identity credential issuing authority, the blockchain distributed identity management system will update the user's TID-DOC identity document. For example, if trusted institution Veri1 issues a trusted credential Credential_V1_a to digital wallet user a, TID-DOC will add the validity period of Credential_V1_a and the verification relationship between Credential_V1_a and the public key Pk_Veri1_veri. After the TID-DOC identity document is updated, it is synchronized with the blockchain ledger to ensure that it cannot be tampered with.
[0078] Optional, verifiable identity credential: refers to an identity credential signed by a generalized identity credential issuing authority. For example, if digital wallet user A submits relevant information to the authority that grants them certain identity attributes (physical documents), and performs relevant verification (password / face / ID card verification, etc.), the generalized identity credential issuing authority will electronically sign the credential, indicating that the user has been authenticated as possessing these identity attributes. In this embodiment of the application, the credential identity credential includes identity attribute information and a signature on the identity attribute information.
[0079] Optional: Blockchain Distributed Identity Management System: A blockchain platform responsible for issuing DIDs to various roles and creating and maintaining DID documents. Digital wallet clients, digital wallet servers, and generalized identity credential issuing authorities securely interact with the blockchain distributed system through APIs.
[0080] In an optional embodiment, the sending of the first identity identifier and the identity credential information to the second operation server includes: obtaining the first private key and the second public key of the digital wallet user; signing the first identity identifier using the first private key to obtain the signed first identity identifier, and encrypting the identity credential information using the second public key to obtain the encrypted identity credential information; sending the signed first identity identifier and the encrypted identity credential information to the second operation server, for the second operation server to decrypt the encrypted identity credential information using the second private key of the second operation server to obtain the identity credential information, and verifying the signed first identity identifier using the first public key of the digital wallet user to obtain the first identity identifier after verification.
[0081] In an embodiment of the present invention, when user a opens a new wallet at the second operating institution A, the second public key is used to encrypt the identity credential information, and the first private key is used to sign the first identity identifier; the signed first identity identifier and the encrypted identity credential information are sent to the second operating server, and the second operating server decrypts and verifies the information to obtain the identity credential information and the first identity identifier.
[0082] As an optional embodiment, the digital wallet user signs TID_a with the private key Sk_user_a to obtain the signed first identity identifier. The user then encrypts the trusted credentials Credential_V1_a, Credential_V2_a, ... Credential_Vn_a issued by multiple trusted credential issuing institutions related to the customer's identity identification requirements with Pk_Regi_A to obtain the encrypted identity credential information and submit it to operator A. Operator A decrypts the information using its private key to obtain the trusted credentials Credential_V1_a, Credential_V2_a, ... Credential_Vn_a used for customer identity identification. The signature is then verified using the user's public key Pk_user_a to confirm that TID_a belongs to user a.
[0083] In an optional embodiment, the obtaining of the identity credential information of the digital wallet user on the identity credential issuing server includes: obtaining the identity credential information in the form of an identity credential ciphertext, wherein the identity credential ciphertext is obtained by encrypting the identity credential information using the fourth private key of the identity credential issuing server.
[0084] In an embodiment of the present invention, the operating organization needs to query the identity document of the target user on the blockchain distributed identity management system, obtain the fourth private key of the above-mentioned identity certificate in the identity document, and use the fourth private key to decrypt the identity certificate ciphertext to obtain the identity certificate information of the above-mentioned digital wallet user on the identity certificate issuing server.
[0085] It should be noted that the above-mentioned identity credential ciphertext is obtained by encrypting the above-mentioned identity credential information using the fourth private key of the above-mentioned identity credential issuing server.
[0086] As an optional embodiment, operating organization A queries the user's identity document TID-Doc_Wallet_a on the blockchain distributed identity management system based on the user's distributed identity TID_a, obtains the credential verification public keys Pk_issuer_1, Pk_issuer_2..., Pk_issuer_n, and verifies the validity of the signatures of Credential_V1_a, Credential_V2_a,...Credential_Vn_a.
[0087] In an optional embodiment, after sending the above-mentioned first trusted credential to the above-mentioned first operating server, the above-mentioned method further includes: receiving a second trusted credential returned by the above-mentioned first operating server, wherein the above-mentioned second trusted credential is used to identify that the first operating server has verified the above-mentioned digital wallet user and opened a wallet account in the above-mentioned first operating server.
[0088] Optionally, after completing customer identity authentication, the operator A opens a wallet account for the target user. According to the joint customer identity authentication rules between operators, after operator A completes customer identity authentication for user a and activates the service, operator A uses its credential issuance key Sk_issuer_A to issue a new verifiable credential Credential_A_a for user a (the credential may indicate a trust or proof relationship). The distributed identity blockchain system updates user a's distributed identity document, obtains the new verifiable credential Credential_A_a, and securely stores it on the client.
[0089] Figure 3 : is a flow chart of the second identity authentication method according to an embodiment of the present invention. Figure 3 As shown, the method includes the following steps:
[0090] Step S202: Receive a first wallet account application sent by the target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operator server, and the first wallet account application carries a first trusted credential of the digital wallet user, which is used to identify that the second operator server has verified the digital wallet user and opened a wallet account on the second operator server;
[0091] Step S204: Based on the first trusted certificate, the digital wallet user is processed to open a wallet account on the first operating server.
[0092] In an embodiment of the present invention, the execution entity of the identity authentication method provided in the above steps S202 to S204 is the first operating server. The above first operating server receives the first wallet account application sent by the target terminal, and processes the wallet account opening of the above digital wallet user on the above first operating server based on the above first trusted certificate.
[0093] It should be noted that the above-mentioned first wallet account application is used to apply for a wallet account of a digital wallet user on the first operating server. The above-mentioned first wallet account application carries the first trusted credential of the above-mentioned digital wallet user. The above-mentioned first trusted credential is used to identify that the second operating server has verified the above-mentioned digital wallet user and opened a wallet account on the above-mentioned second operating server.
[0094] As an optional embodiment, Figure 4 As shown in the non-first-time customer identity authentication sequence diagram, when user a opens a new wallet at another operating institution B (user a has already opened a digital wallet account at operating institution A): the verifiable certificate Credential_A_a issued by operating institution A can be sent to operating institution B for verification. After B verifies that another institution has completed the relevant customer identity authentication for the user, operating institution B may require the user to submit a customer identity authentication certificate, for example, it may reduce the number of customer identity authentication items to be submitted. After the user completes the customer identity authentication at institution B, operating institution B opens the digital wallet service. Institution B can also continue to issue new trusted credentials to the user for verification by other operating institutions, thereby forming an ever-enriching, jointly conducted trusted customer identity authentication.
[0095] In an optional embodiment, the above method also includes: when the digital wallet user is verified to have opened a wallet account on the above-mentioned first operating server based on the above-mentioned first trusted credential and the wallet account is opened on the above-mentioned first operating server, generating a second trusted credential for the above-mentioned digital wallet user, wherein the above-mentioned second trusted credential is used to identify that the above-mentioned first operating server has verified the above-mentioned digital wallet user and opened a wallet account on the above-mentioned first operating server.
[0096] In an embodiment of the present invention, when the first trusted credential is verified successfully, the first operating server activates the digital wallet user for the target user and generates a second trusted credential for the digital wallet user.
[0097] It should be noted that the second trusted certificate is used to identify that the first operating server has verified the digital wallet user and opened a wallet account in the first operating server.
[0098] It should also be noted that the above-mentioned second trusted credential is generated by the above-mentioned first operation server and can be sent to the above-mentioned blockchain distributed identity management server for storage.
[0099] In an optional embodiment, the processing of the digital wallet user opening a wallet account on the first operator server based on the first trusted credential includes: obtaining a third private key from the first operator server; decrypting the encrypted first trusted credential using the third private key of the first operator server to obtain the first trusted credential; verifying the signed first trusted credential using the digital wallet user's first public key to obtain the verified first trusted credential; and generating the second trusted credential and wallet account of the digital wallet user. In an optional embodiment, the digital wallet user signs the identity TID_a using the private key Sk_user_a to obtain the signed first identity identifier; encrypting the first trusted credential Credential_A_a related to the customer identification request using Pk_Regi_B to obtain the encrypted identity credential information, which is submitted to financial institution B; operator B decrypts the information using its private key to obtain the first trusted credential Credential_A_a used by the user for customer identification. The signature is then verified using the user's public key Pk_user_a to confirm that TID_a belongs to user a. Operator B may, depending on the circumstances, require the user to submit customer identity verification credentials, for example, by reducing the number of customer identity verification items to be submitted. After the user completes the customer identity verification with Operator B, Operator B activates the digital wallet service. Operator B may also continue to issue new trusted credentials to the user for verification by other operators, thereby forming a continuously enriched, jointly conducted trusted customer identity verification system.
[0100] It should be noted that after generating the above-mentioned second trusted credential of the above-mentioned digital wallet user, the above-mentioned method also includes: sending the above-mentioned second trusted credential to the above-mentioned target terminal for storage, and sending the above-mentioned second trusted credential to the blockchain distributed identity management server for updating.
[0101] As an optional embodiment, according to the rules for joint customer identity identification between operating institutions, after operating institution B (the first operating server or the first operating institution) completes the customer identity authentication of user a and activates the service, operating institution B uses its credential issuance key Sk_issuer_B to issue a new verifiable credential for user a, namely the above-mentioned second trusted credential Credential_B_a (this credential can indicate a trust or certification relationship between operating institution B and the user); the distributed identity blockchain system updates user a's distributed identity document, obtains the new verifiable credential Credential_B_a, and securely stores it on the client.
[0102] In an optional embodiment, the above-mentioned processing of opening a wallet account for the digital wallet user on the above-mentioned first operating server based on the above-mentioned first trusted certificate includes: obtaining the first identity identification of the above-mentioned digital wallet user, and the identity credential information of the above-mentioned digital wallet user on the identity credential issuing server; processing the opening of the wallet account for the above-mentioned digital wallet user on the above-mentioned first operating server based on the above-mentioned first trusted certificate, or processing the opening of the wallet account for the above-mentioned digital wallet user on the above-mentioned first operating server based on the above-mentioned first trusted certificate and either the above-mentioned first identity identification information or the above-mentioned identity credential information.
[0103] In an embodiment of the present invention, when the first operating server processes the wallet account activation, the first operating server may, depending on the circumstances, require the user to submit a customer identity identification credential. For example, the submission of customer identity identification authentication items may be reduced, and the wallet account activation of the digital wallet user on the first operating server may be processed based on the first trusted credential.
[0104] In an embodiment of the present invention, when the first operating server processes the wallet account activation, the first operating server may, depending on the circumstances, require the user to submit a customer identity identification credential, and process the wallet account activation of the digital wallet user on the first operating server based on the first trusted credential and either the first identity identification information or the identity credential information.
[0105] Figure 5 : is a flow chart of the third identity authentication method according to an embodiment of the present invention. Figure 5 As shown, the method includes the following steps:
[0106] Step S302: Receive a second wallet account application sent by the target terminal, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on the second operator server, and the second wallet account application carries the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server;
[0107] Step S304: Verify the digital wallet user based on the first identity identifier and the identity credential information;
[0108] Step S306: If the verification is successful, a target wallet account is generated for the digital wallet user on the second operator server, and a first trusted credential is generated for the digital wallet user;
[0109] Step S308: Send the first trusted credential to the target terminal, so that the target terminal stores the first trusted credential and uses it to apply for a wallet account of the digital wallet user on the first operating server.
[0110] In an embodiment of the present invention, the execution entity of the identity authentication method provided in the above steps S302 to S108 is the second operating server. The above second operating server receives the second wallet account application sent by the target terminal, and processes the wallet account opening of the above digital wallet user on the above second operating server based on the above first identity identifier and identity credential information.
[0111] It should be noted that the above-mentioned second wallet account application is used to apply for a wallet account of a digital wallet user on a second operating server. The above-mentioned second wallet account application carries the first identity identifier and identity credential information of the above-mentioned digital wallet user. The above-mentioned identity credential information is used to indicate that the identity credential issuing server has verified the above-mentioned digital wallet user.
[0112] As an optional embodiment, when user a opens a wallet account for the first time at operator A (user a has not opened a digital wallet account at any operator), multiple verifiable credentials (Credential_V1_a, Credential_V2_a, ... Credential_Vn_a) issued by identity credential issuing servers can be sent to operator A for verification. Operator A verifies that multiple or one issuing agency has completed relevant customer identity authentication for the user. Based on the user's distributed identity TID_a, operator A queries the user's identity document TID-Doc_Wallet_a on the blockchain distributed identity management system, obtains the identity credential verification public keys Pk_issuer_1, Pk_issuer_2..., Pk_issuer_n, and verifies the validity of the signatures of Credential_V1_a, Credential_V2_a, ... Credential_Vn_a. After the user completes customer identity authentication at institution A, operator A activates the digital wallet service. Institution A can continue to issue new trusted credentials to the user, namely the first trusted credentials mentioned above, for verification by other operating institutions (for example, operating institution B), thereby forming an increasingly rich and jointly conducted trusted customer identity authentication.
[0113] In an optional embodiment, sending the first trusted credential to the target terminal includes sending the first trusted credential to a blockchain distributed identity management server, so that the target terminal can download the first trusted credential from the blockchain distributed identity management server.
[0114] In an embodiment of the present invention, the above-mentioned first trusted credential generated by the above-mentioned second operation server can be sent to the target terminal of the target user for storage and can also be sent to the blockchain distributed identity management server for storage; therefore, the above-mentioned first trusted credential generated by the above-mentioned second operation server can be obtained, and the above-mentioned first trusted credential can also be downloaded from the blockchain distributed identity management server.
[0115] It should be noted that the above-mentioned first trusted certificate is generated by the above-mentioned second operation server and sent to the above-mentioned blockchain distributed identity management server for storage.
[0116] As an optional embodiment, the above-mentioned target user can use the target terminal to send a digital wallet account application to multiple of the above-mentioned second operating servers. After verifying the user's first identity identifier and the above-mentioned identity credential information (which can be credential information generated after verification by other operating institutions), the above-mentioned multiple second operating servers create a digital wallet account for the user and generate a trusted credential corresponding to the operating institution.
[0117] Optionally, when a user generates trusted credentials corresponding to an operating organization on multiple second operating servers, the storage space of the digital wallet application in the target terminal may not be able to store multiple trusted credentials, or multiple trusted credentials occupy too much storage space and seriously affect the user experience. In this case, the trusted credentials generated by the operating organization can be sent to the above-mentioned blockchain distributed identity management server for storage, so that the above-mentioned target terminal can download the above-mentioned first trusted credentials from the above-mentioned blockchain distributed identity management server.
[0118] In an optional embodiment, the blockchain distributed identity management server stores the first identity document of the digital wallet user, the second identity document of the first operating server, the third identity document of the second operating server, and the fourth identity document of the identity certificate issuing server, wherein the first identity document stores the first identity identifier and the correspondence between the first identity identifier and the first public key, and the first public key is the public key of the digital wallet user; the second identity document stores the second identity identifier of the first operating server and the correspondence between the second identity identifier and the second public key, and the second public key is the public key of the first operating server; the third identity document stores the third identity identifier of the second operating server and the correspondence between the third identity identifier and the third public key, and the third public key is the public key of the second operating server; the fourth identity document stores the fourth identity identifier of the identity certificate issuing server and the correspondence between the fourth identity identifier and the fourth public key, and the fourth public key is the public key of the identity certificate issuing server.
[0119] In an embodiment of the present invention, the above-mentioned target users, multiple operating organizations, identity certificate issuing servers, etc. all need to generate a key pair and send the public key of the above-mentioned key pair to the above-mentioned blockchain distributed identity management server. The blockchain distributed identity management system generates the identity identification of each system and creates an identity document.
[0120] It should be noted that the identity document is a key-value database table, and each identity document records attributes such as the binding relationship between each ID and its public key.
[0121] As an optional embodiment, each institution generates a key for registering a user's distributed identity identifier TID, where: digital wallet user a generates a key pair Pk_user_a / Sk_user_a; operating institution A generates a key pair Pk_Regi_A / Sk_Regi_A and operating institution B generates a key pair Pk_Regi_B / Sk_Regi_B, as well as the central bank-side business system Pk_Regi_C / Sk_Regi_C; the certificate issuing institution and the operating institution generate a certificate verifiable certificate issuance public key, and generate public and private keys for the n identity certificate issuing institutions that issue certificates to users, represented by Pk_issuer_1 / Sk_issuer_1, Pk_issuer_2 / Sk_issuer_2..., Pk_issuer_n / Sk_issuer_n respectively; the operating institution generates the corresponding public and private keys for the verifiable certificate issued to the user as Pk_issuer_A / Sk_issuer_A and Pk_issuer_B / Sk_issuer_B.
[0122] Optionally, digital wallet user a, operating institution A and operating institution B, and the central bank-side business system submit public keys Pk_user_a, Pk_Regi_A, Pk_Regi_B, and Pk_Regi_C to the blockchain distributed identity management system respectively; the blockchain distributed identity management system generates the identity identifiers TID_wallet_a, TID_A, TID_B, and TID_C of their respective systems, and generates identity documents for digital wallet user a, operating institution A, operating institution B, and the central bank-side business system: TID-Doc_Wallet_a, TID-Doc_A, TID-Doc_B, and TID-Doc_C. The identity document is a key-value database table. Each identity document records attributes such as the binding relationship between each ID and its public key, including: wallet user a identity TID The corresponding binding relationship between TID_wallet_a and the public key Pk_user_a of wallet user a; the corresponding binding relationship between the identity documents of operating institutions A and B, and the central bank-side business system C and their public keys; the blockchain distributed identity management system issues respective TIDs to digital wallet user a, operating institutions A and B, and the central bank-side business system C; identity documents are automatically synchronized through the blockchain to prevent tampering.
[0123] In an optional embodiment, after receiving the second wallet account application sent by the target terminal, it also includes: extracting the encrypted identity credential information and the signed first identity identifier from the second wallet account application, wherein the encrypted identity credential information is obtained by encrypting the identity credential information using the second public key, and the signed first identity identifier is obtained by signing the first identity identifier using the first private key of the digital wallet user; decrypting the encrypted identity credential information using the second private key of the second operating server to obtain the identity credential information, and verifying the signed first identity identifier using the first public key of the digital wallet user to obtain the first identity identifier after verification.
[0124] In an embodiment of the present invention, when the second operating institution A receives an application from user a to open a new wallet, it sends the second public key to the user so that the user can encrypt the identity credential information, and uses the first private key to sign the first identity identifier; the signed first identity identifier and the encrypted identity credential information are sent to the second operating server, and the second operating server decrypts and verifies the information to obtain the identity credential information and the first identity identifier.
[0125] As an optional embodiment, the digital wallet user signs TID_a with the private key Sk_user_a to obtain the signed first identity identifier. The user then encrypts the trusted credentials Credential_V1_a, Credential_V2_a, ... Credential_Vn_a issued by multiple trusted credential issuing institutions related to the customer's identity identification requirements with Pk_Regi_A to obtain the encrypted identity credential information and submit it to operator A. Operator A decrypts the information using its private key to obtain the trusted credentials Credential_V1_a, Credential_V2_a, ... Credential_Vn_a used for customer identity identification. The signature is then verified using the user's public key Pk_user_a to confirm that TID_a belongs to user a.
[0126] In an optional embodiment, the above-mentioned verification of the digital wallet user based on the above-mentioned first identity identifier and the above-mentioned identity credential information includes: when the above-mentioned identity credential information exists in the form of identity credential ciphertext, using the fourth public key of the above-mentioned identity credential issuing server to decrypt the identity credential ciphertext to obtain the above-mentioned identity credential information, wherein the above-mentioned identity credential ciphertext is obtained by encrypting the above-mentioned identity credential information using the fourth private key of the above-mentioned identity credential issuing server.
[0127] As an optional embodiment, operating organization A queries the user's identity document TID-Doc_Wallet_a on the blockchain distributed identity management system based on the user's distributed identity TID_a, obtains the credential verification public keys Pk_issuer_1, Pk_issuer_2..., Pk_issuer_n, and uses the above public keys to verify the identity credential ciphertext Credential_V1_a, Credential_V2_a,...Credential_Vn_a to verify the validity of the signature.
[0128] Optionally, after completing customer identity authentication, the operator A opens a wallet account for the target user. According to the joint customer identity authentication rules between operators, after operator A completes customer identity authentication for user a and activates the service, operator A uses its credential issuance key Sk_issuer_A to issue a new verifiable credential Credential_A_a for user a (the credential may indicate a trust or proof relationship). The distributed identity blockchain system updates user a's distributed identity document, obtains the new verifiable credential Credential_A_a, and securely stores it on the client.
[0129] Figure 6 : is a flow chart of a fourth identity authentication method according to an embodiment of the present invention. Figure 6 As shown, the method includes the following steps:
[0130] Step S402: receiving the first public key of the digital wallet user sent by the target terminal, receiving the second public key of the first operating server, receiving the third public key of the second operating server, and receiving the fourth public key of the identity certificate issuing server;
[0131] Step S404: Generate a first identity identifier for the digital wallet user, generate a second identity identifier for the first operating server, generate a third identity identifier for the second operating server, and generate a fourth identity identifier for the identity credential issuing server;
[0132] Step S406: Generate a first identity document for the digital wallet user, a second identity document for the first operating server, a third identity document for the second operating server, and a fourth identity document for the identity credential issuing server, wherein the first identity document stores the first identity identifier and the corresponding relationship between the first identity identifier and the first public key, the second identity document stores the second identity identifier of the first operating server and the corresponding relationship between the second identity identifier and the second public key, the third identity document stores the third identity identifier of the second operating server and the corresponding relationship between the third identity identifier and the third public key, and the fourth identity document stores the fourth identity identifier of the identity credential issuing server and the corresponding relationship between the fourth identity identifier and the fourth public key;
[0133] Step S408: Receive the first trusted credential sent by the second operating server and update the first trusted credential in the first identity document. The first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account in the second operating server.
[0134] In an embodiment of the present invention, the execution entity of the identity authentication method provided in the above steps S402 to S408 is a blockchain distributed identity management server, which receives the first public key of the digital wallet user sent by the target terminal, receives the second public key of the above first operation server, receives the third public key of the second operation server, and receives the fourth public key of the identity certificate issuing server; generates a first identity identifier for the above digital wallet user, a second identity identifier for the above first operation server, a third identity identifier for the above second operation server, and a fourth identity identifier for the above identity certificate issuing server; generates a first identity document for the above digital wallet user, a second identity document for the above first operation server, a third identity document for the above second operation server, and a fourth identity document for the above identity certificate issuing server, receives the first trusted certificate sent by the above second operation server, and updates the above first trusted certificate in the above first identity document.
[0135] In an embodiment of the present invention, the above-mentioned target users, multiple operating organizations, identity certificate issuing servers, etc. all need to generate a key pair and send the public key of the above-mentioned key pair to the above-mentioned blockchain distributed identity management server. The blockchain distributed identity management system generates the identity identification of each system and creates an identity document.
[0136] It should be noted that the identity document is a key-value database table, and each identity document records attributes such as the binding relationship between each ID and its public key.
[0137] As an optional embodiment, each institution generates a key for registering a user's distributed identity identifier TID, where: digital wallet user a generates a key pair Pk_user_a / Sk_user_a; operating institution A generates a key pair Pk_Regi_A / Sk_Regi_A and operating institution B generates a key pair Pk_Regi_B / Sk_Regi_B, as well as the central bank-side business system Pk_Regi_C / Sk_Regi_C; the certificate issuing institution and the operating institution generate a certificate verifiable certificate issuance public key, and generate public and private keys for the n identity certificate issuing institutions that issue certificates to users, represented by Pk_issuer_1 / Sk_issuer_1, Pk_issuer_2 / Sk_issuer_2..., Pk_issuer_n / Sk_issuer_n respectively; the operating institution generates the corresponding public and private keys for the verifiable certificate issued to the user as Pk_issuer_A / Sk_issuer_A and Pk_issuer_B / Sk_issuer_B.
[0138] Optionally, digital wallet user a, operating institution A and operating institution B, and the central bank-side business system submit public keys Pk_user_a, Pk_Regi_A, Pk_Regi_B, and Pk_Regi_C to the blockchain distributed identity management system respectively; the blockchain distributed identity management system generates the identity identifiers TID_wallet_a, TID_A, TID_B, and TID_C of their respective systems, and generates identity documents for digital wallet user a, operating institution A, operating institution B, and the central bank-side business system: TID-Doc_Wallet_a, TID-Doc_A, TID-Doc_B, and TID-Doc_C. The identity document is a key-value database table. Each identity document records attributes such as the binding relationship between each ID and its public key, including: wallet user a identity TID The corresponding binding relationship between TID_wallet_a and the public key Pk_user_a of wallet user a; the corresponding binding relationship between the identity documents of operating institutions A and B, and the central bank-side business system C and their public keys; the blockchain distributed identity management system issues respective TIDs to digital wallet user a, operating institutions A and B, and the central bank-side business system C; identity documents are automatically synchronized through the blockchain to prevent tampering.
[0139] Optionally, the above-mentioned blockchain distributed identity management server can also receive the first trusted certificate sent by the above-mentioned second operation server, and update the above-mentioned first trusted certificate in the above-mentioned first identity document; and receive multiple trusted certificates issued by the above-mentioned trusted certificate issuing agency, and update them in the above-mentioned first identity document.
[0140] In an optional embodiment, the above method also includes: receiving a certificate download request sent by the above-mentioned first operating server; in response to the above-mentioned certificate download request, sending the above-mentioned first trusted certificate to the above-mentioned first operating server for processing the above-mentioned digital wallet user's application for a wallet account in the above-mentioned first operating server.
[0141] In an optional embodiment, the above method also includes: receiving a second trusted credential sent by the above-mentioned first operating server, and updating the above-mentioned second trusted credential in the above-mentioned second identity document, wherein the above-mentioned second trusted credential is used to identify that the above-mentioned first operating server has verified the above-mentioned digital wallet user and opened a wallet account in the above-mentioned first operating server.
[0142] In an embodiment of the present invention, the above-mentioned blockchain distributed identity management server can also receive a certificate download request sent by the above-mentioned first operation server, and send the above-mentioned first trusted certificate to the above-mentioned first operation server.
[0143] Figure 7: is a flow chart of a fifth identity authentication method according to an embodiment of the present invention. Figure 7 As shown, the method includes the following steps:
[0144] Step S502: The target terminal receives a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operator server;
[0145] In step S504, the target terminal obtains a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to indicate that the second operator server has verified the digital wallet user and opened a wallet account on the second operator server.
[0146] Step S506: the target terminal sends the first trusted certificate to the first operation server;
[0147] In step S508, the first operating server processes the digital wallet user's wallet account opening on the first operating server based on the first trusted certificate.
[0148] In an embodiment of the present invention, the execution subject of the identity authentication method provided in the above steps S502 to S508 is the above target terminal, which receives the first wallet account application triggered by the user in the application and responds in a timely manner, obtains the first trusted credential stored in the digital wallet application or the blockchain distributed identity management server, and sends the above first trusted credential to the above first operation server. The above first operation server processes the wallet account opening of the digital wallet user on the first operation server based on the above first trusted credential.
[0149] It should be noted that the above-mentioned first wallet account application is used to apply for a wallet account of a digital wallet user on the first operating server; the above-mentioned first trusted certificate is used to identify that the second operating server has verified the above-mentioned digital wallet user and opened a wallet account on the above-mentioned second operating server.
[0150] In an optional embodiment, before the target terminal responds to the first wallet account application and obtains the first trusted credential of the digital wallet user, the method further includes: the target terminal receives a second wallet account application, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on the second operating server; the target terminal obtains the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server; the target terminal sends the first identity identifier and the identity credential information to the second operating server; the second operating server verifies the digital wallet user based on the first identity identifier and the identity credential information, and if the verification is successful, generates a target wallet account, generates the first trusted credential, and sends the first trusted credential to the target terminal; the target terminal stores the first trusted credential.
[0151] In an embodiment of the present invention, the target terminal receives a second wallet account application triggered by a user in an application and responds promptly, obtains the first identity identifier and the identity credential information stored in the digital wallet application or the blockchain distributed identity management server, and sends the first identity identifier and the identity credential information to the second operation server. The second operation server processes the opening of a wallet account for the digital wallet user on the second operation server based on the first identity identifier and the identity credential information.
[0152] It should be noted that, if the verification is successful, a target wallet account is generated, the first trusted credential is generated, and the first trusted credential is sent to the target terminal; the target terminal stores the first trusted credential.
[0153] In an optional embodiment, the above method also includes: the above-mentioned second operation server sends the above-mentioned first trusted certificate to the above-mentioned blockchain distributed identity management server; when the above-mentioned blockchain distributed identity management server receives the identity request of the digital wallet user sent by the first operation server, the above-mentioned first trusted certificate is sent to the above-mentioned first operation server; the above-mentioned first operation server sends the above-mentioned second trusted certificate to the above-mentioned blockchain distributed identity management server.
[0154] In an embodiment of the present invention, the first trusted credential generated by the second operating server can be sent to the target terminal of the target user for storage and can also be sent to the blockchain distributed identity management server for storage; therefore, when the blockchain distributed identity management server receives the identity request of the digital wallet user sent by the first operating server, it can send the first trusted credential to the first operating server.
[0155] It should be noted that the above-mentioned first trusted certificate is generated by the above-mentioned second operation server and sent to the above-mentioned blockchain distributed identity management server for storage.
[0156] In an optional embodiment, the method further includes: the blockchain distributed identity management server receives the first public key of the digital wallet user sent by the target terminal, receives the second public key of the first operating server, receives the third public key of the second operating server, and receives the fourth public key of the identity certificate issuing server; the blockchain distributed identity management server generates a first identity identifier for the digital wallet user, a second identity identifier for the first operating server, a third identity identifier for the second operating server, and a fourth identity identifier for the identity certificate issuing server; the blockchain distributed identity management server generates a first identity document for the digital wallet user, and generates a second identity document for the first operating server. document, generates a third identity document for the above-mentioned second operation server, and generates a fourth identity document for the above-mentioned identity certificate issuing server, wherein the above-mentioned first identity document stores the above-mentioned first identity identifier, and the corresponding relationship between the above-mentioned first identity identifier and the above-mentioned first public key, the above-mentioned second identity document stores the second identity identifier of the above-mentioned first operation server, and the corresponding relationship between the above-mentioned second identity identifier and the above-mentioned second public key, the above-mentioned third identity document stores the third identity identifier of the above-mentioned second operation server, and the corresponding relationship between the above-mentioned third identity identifier and the above-mentioned third public key, and the above-mentioned fourth identity document stores the fourth identity identifier of the identity certificate issuing server, and the corresponding relationship between the above-mentioned fourth identity identifier and the above-mentioned fourth public key.
[0157] The above-mentioned target users, multiple operating organizations, identity credential issuing servers, etc. all need to generate a key pair and send the public key of the above-mentioned key pair to the above-mentioned blockchain distributed identity management server. The blockchain distributed identity management system generates the identity identification of each system and creates an identity document.
[0158] It should be noted that the identity document is a key-value database table, and each identity document records attributes such as the binding relationship between each ID and its public key.
[0159] As an optional embodiment, each institution generates a key for registering a user's distributed identity identifier TID, where: digital wallet user a generates a key pair Pk_user_a / Sk_user_a; operating institution A generates a key pair Pk_Regi_A / Sk_Regi_A and operating institution B generates a key pair Pk_Regi_B / Sk_Regi_B, as well as the central bank-side business system Pk_Regi_C / Sk_Regi_C; the certificate issuing institution and the operating institution generate a certificate verifiable certificate issuance public key, and generate public and private keys for the n identity certificate issuing institutions that issue certificates to users, represented by Pk_issuer_1 / Sk_issuer_1, Pk_issuer_2 / Sk_issuer_2..., Pk_issuer_n / Sk_issuer_n respectively; the operating institution generates the corresponding public and private keys for the verifiable certificate issued to the user as Pk_issuer_A / Sk_issuer_A and Pk_issuer_B / Sk_issuer_B.
[0160] Optionally, digital wallet user a, operating institution A and operating institution B, and the central bank-side business system submit public keys Pk_user_a, Pk_Regi_A, Pk_Regi_B, and Pk_Regi_C to the blockchain distributed identity management system respectively; the blockchain distributed identity management system generates the identity identifiers TID_wallet_a, TID_A, TID_B, and TID_C of their respective systems, and generates identity documents for digital wallet user a, operating institution A, operating institution B, and the central bank-side business system: TID-Doc_Wallet_a, TID-Doc_A, TID-Doc_B, and TID-Doc_C. The identity document is a key-value database table. Each identity document records attributes such as the binding relationship between each ID and its public key, including: wallet user a identity TID The corresponding binding relationship between TID_wallet_a and the public key Pk_user_a of wallet user a; the corresponding binding relationship between the identity documents of operating institutions A and B, and the central bank-side business system C and their public keys; the blockchain distributed identity management system issues respective TIDs to digital wallet user a, operating institutions A and B, and the central bank-side business system C; identity documents are automatically synchronized through the blockchain to prevent tampering.
[0161] It should be noted that the above-mentioned central bank-side business system can also be responsible for opening user digital wallet App accounts and other businesses to prevent some operating institutions from being unable to complete account opening and other operations. The central bank-side business system must also follow the principle that one user corresponds to one App account, and one App account can have multiple wallet accounts.
[0162] In an optional embodiment, the target terminal obtains the identity credential information of the digital wallet user on the identity credential issuing server, including: the target terminal sends an identity authentication request to the identity credential issuing server; the identity credential issuing server responds to the identity authentication request and feeds back the identity credential information of the digital wallet user on the identity credential issuing server to the target terminal.
[0163] In an embodiment of the present invention, digital wallet user a initiates a verifiable electronic identity credential application to n identity credential issuing agencies (identity credential issuing servers) based on the identity document (physical document) issued to him by the generalized identity credential issuing agency. The user submits relevant information according to the generalized identity credential issuing agency, executes relevant verification measures, and performs identity verification; the generalized identity credential issuing agency (such as agency 1) generates the identity credential Credential_V1_a of user a based on the verifiable identity credential template, and signs it with its private key Sk_issuer_1. Other agencies repeatedly generate other verifiable credentials Credential_V2_a,...Credential_Vn_a.
[0164] Optionally, the identity certificate issuing agency issues a verifiable identity certificate to the digital wallet user a and securely stores it in the above-mentioned target terminal.
[0165] Optionally, the identity certificate issuing authority interacts with the blockchain distributed identity management system, and the blockchain distributed identity management system performs the update of the identity document of the digital wallet user a, writes the verification public key Pk_issuer_1 of multiple verifiable identity certificates into its user identity document, and also writes the verification relationship between Pk_issuer_1 and TID_a into the identity document of the digital wallet user a.
[0166] Optionally, the digital wallet user can repeatedly obtain verifiable credentials Pk_issuer_n from other institutions, all of which are securely stored in the above-mentioned target terminal.
[0167] Optionally, the above-mentioned user a obtains all verifiable credentials, and the blockchain distributed identity management system updates the identity document TID-Doc_Wallet_a of the digital wallet user a and synchronizes the update through the blockchain.
[0168] In an optional embodiment, the digital wallet app (user), the central bank's business system, and the digital wallet operator's business system each generate a public-private key pair and submit the public key to the blockchain distributed identity management system. The blockchain distributed identity management system then generates its corresponding distributed identity identifier (DID). Based on the specific requirements of customer identity identification, when the digital wallet app (user) applies for verification and authentication from multiple trusted credential issuing institutions, the trusted credential issuing institutions generate a corresponding customer identity verification credential for the user and sign it with the private key. The public key certificate is then submitted to the blockchain distributed identity management system. Based on the digital wallet user's distributed identity identifier (DID), the blockchain distributed identity management system generates the user's distributed identity document, updates it, and writes the credential issuance and verification relationship, etc., into the distributed identity document.
[0169] Optionally, when a user conducts customer identity authentication, they can apply for financial services from a financial institution using a digital wallet. In accordance with customer identity authentication requirements, they can submit a verifiable certificate of relevant customer identity authentication information (there is no need to enter the customer identity authentication information in plain text on the form) and a distributed identity identifier to the financial institution. The financial institution will then find the user's certificate verification public key in the blockchain distributed identity management system based on the user's distributed identity identifier. Once the verification is successful, customer identity authentication is complete. The financial institution will issue a verifiable certificate for the user that completes the customer identity authentication and will send it to the user. At the same time, the blockchain distributed identity management system will update the user's document and add the financial institution's verification relationship with the user's certificate.
[0170] Optionally, when a digital wallet user applies for services from another new financial institution, in accordance with its customer identity identification requirements, he or she shall submit to the new financial institution the customer identity identification information verifiable certificate issued by the relevant trusted certificate issuing institution, the verifiable certificate previously issued by other financial institutions that has passed the customer identity identification once, and the distributed identity identifier (this process does not require repeated submission and input of customer identity identification information). Based on the user's distributed identity identifier, the new financial institution finds the certificate verification public key of the trusted institution in the blockchain distributed identity management system, verifies its customer identity identification certificate, finds the certificate verification public key of the other financial institution, and verifies the certificate issued by it to the user. In this way, a collaborative customer identity identification is completed. (The new financial institution can continue to issue the certificate that has passed the customer identity identification authentication once for the user and send it to the user. At the same time, the blockchain distributed identity management system updates the user document, adds the verification relationship of the financial institution to the user's certificate, and accumulates the user's certificate in this way.)
[0171] Through the above steps, customer identity verification credentials can be reused, reducing the need for users to repeatedly submit the same customer identity information when applying for services at different institutions. Because users effectively aggregate more customer identity verification credentials, a single operating institution can obtain more customer identity information, thereby improving the customer identity verification capabilities of individual financial institutions.
[0172] Figure 8 Schematic diagram of an identity authentication method according to an embodiment of the present invention. Figure 8 As shown, the transaction information sharing system includes: a target terminal, a first operating server, and a second operating server. This identity verification system can be applied in financial scenarios, for example, in scenarios where transaction information is shared between financial institutions (e.g., between banks, or between a bank and a relevant financial regulatory agency). The following describes the system using the example of sharing transaction information between financial institutions.
[0173] The target terminal is configured to receive a first wallet account application; obtain a first trusted credential of the digital wallet user in response to the first wallet account application; and send the first trusted credential to the first operating server.
[0174] The first operating server is connected to the target terminal and is configured to receive a first wallet account application sent by the target terminal and process the digital wallet user's wallet account opening on the first operating server based on the first trusted certificate.
[0175] The above-mentioned target terminal is also used to receive an application for a second wallet account; obtain the first identity identifier of the above-mentioned digital wallet user, and the identity credential information of the above-mentioned digital wallet user on the identity credential issuing server; send the above-mentioned first identity identifier and the above-mentioned identity credential information to the above-mentioned second operation server; obtain the above-mentioned first trusted credential generated by the above-mentioned second operation server and store the above-mentioned first trusted credential.
[0176] The second operation server is connected to the target terminal and is used to verify the digital wallet user based on the first identity identifier and the identity credential information. If the verification is successful, a target wallet account is generated, and a first trusted credential is generated for the digital wallet user, and the first trusted credential is sent to the target terminal.
[0177] According to an embodiment of the present invention, there is also provided an embodiment of a device for implementing the above identity verification method. Figure 9 is a structural diagram of an identity authentication device according to an embodiment of the present invention. Figure 9 As shown, the above device includes: a first receiving module 70, a first obtaining module 72, and a first sending module 74, wherein:
[0178] A first receiving module 70 is configured to receive a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server;
[0179] A first obtaining module 72 is configured to obtain a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to indicate that the second operating server has verified the digital wallet user and opened a wallet account on the second operating server;
[0180] The first sending module 74 is configured to send the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the digital wallet user opening a wallet account on the first operating server.
[0181] It should be noted here that the above-mentioned first receiving module 70, first acquisition module 72, and first sending module 74 correspond to steps S102 to S106 in Example 1. The instances and application scenarios implemented by the above-mentioned modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiments.
[0182] According to an embodiment of the present invention, there is also provided an embodiment of a device for implementing the above identity verification method. Figure 10 is a structural diagram of an identity authentication device according to an embodiment of the present invention. Figure 10 As shown, the above device includes: a second receiving module 80 and a first processing module 82, wherein:
[0183] A second receiving module 80 is configured to receive a first wallet account application sent by a target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operator server, and the first wallet account application carries a first trusted credential of the digital wallet user, which is used to identify that the second operator server has verified the digital wallet user and opened a wallet account on the second operator server;
[0184] The first processing module 82 is configured to process the digital wallet user's wallet account opening on the first operating server based on the first trusted certificate.
[0185] It should be noted here that the above-mentioned second receiving module 80 and first processing module 82 correspond to steps S202 to S204 in Example 1. The examples and application scenarios implemented by the above-mentioned modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiments.
[0186] According to an embodiment of the present invention, there is also provided an embodiment of a device for implementing the above identity verification method. Figure 11 is a structural diagram of an identity authentication device according to an embodiment of the present invention. Figure 11 As shown, the above device includes: a third receiving module 90, a verification module 92, a first generating module 94 and a second sending module 96, wherein:
[0187] A third receiving module 90 is configured to receive a second wallet account application sent by a target terminal, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on a second operator server, and the second wallet account application carries the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on an identity credential issuing server;
[0188] Verification module 92, configured to verify the digital wallet user based on the first identity identifier and the identity credential information;
[0189] A first generating module 94 is configured to generate a target wallet account for the digital wallet user on the second operating server and a first trusted credential for the digital wallet user if the verification is successful;
[0190] The second sending module 96 is used to send the first trusted credential to the target terminal, so that the target terminal can store the first trusted credential and apply for a wallet account of the digital wallet user on the first operating server.
[0191] It should be noted here that the above-mentioned third receiving module 90, verification module 92, first generation module 94 and second sending module 96 correspond to steps S302 to S308 in Example 1. The instances and application scenarios implemented by the above-mentioned modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiments.
[0192] According to an embodiment of the present invention, there is also provided an embodiment of a device for implementing the above identity verification method. Figure 12 is a structural diagram of an identity authentication device according to an embodiment of the present invention. Figure 12 As shown, the above-mentioned apparatus includes: a fourth receiving module 100, a second generating module 102, a third generating module 104 and a fifth receiving module 106, wherein:
[0193] The fourth receiving module 100 is configured to receive the first public key of the digital wallet user sent by the target terminal, the second public key of the first operating server, the third public key of the second operating server, and the fourth public key of the identity certificate issuing server;
[0194] A second generating module 102 is configured to generate a first identity identifier for the digital wallet user, a second identity identifier for the first operating server, a third identity identifier for the second operating server, and a fourth identity identifier for the identity credential issuing server;
[0195] The third generating module 104 is configured to generate a first identity document for the digital wallet user, a second identity document for the first operating server, a third identity document for the second operating server, and a fourth identity document for the identity credential issuing server, wherein the first identity document stores the first identity identifier and the corresponding relationship between the first identity identifier and the first public key, the second identity document stores the second identity identifier of the first operating server and the corresponding relationship between the second identity identifier and the second public key, the third identity document stores the third identity identifier of the second operating server and the corresponding relationship between the third identity identifier and the third public key, and the fourth identity document stores the fourth identity identifier of the identity credential issuing server and the corresponding relationship between the fourth identity identifier and the fourth public key;
[0196] The fifth receiving module 106 is used to receive the first trusted credential sent by the second operating server and update the first trusted credential in the first identity document, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account in the second operating server.
[0197] It should be noted here that the above-mentioned fourth receiving module 100, second generating module 102, third generating module 104 and fifth receiving module 106 correspond to steps S402 to S408 in Example 1. The instances and application scenarios implemented by the above-mentioned modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiments.
[0198] According to an embodiment of the present invention, there is also provided an embodiment of a device for implementing the above identity verification method. Figure 13 is a structural diagram of an identity authentication device according to an embodiment of the present invention. Figure 13 As shown, the above device includes: a sixth receiving module 110, a second obtaining module 112, a third sending module 114 and a second processing module 116, wherein:
[0199] A sixth receiving module 110 is configured to receive, at the target terminal, a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server;
[0200] A second obtaining module 112 is configured for the target terminal to obtain a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to indicate that the second operating server has verified the digital wallet user and opened a wallet account on the second operating server;
[0201] A third sending module 114 is configured for the target terminal to send the first trusted credential to the first operation server;
[0202] The second processing module 116 is configured for the first operating server to process the digital wallet user's wallet account opening on the first operating server based on the first trusted certificate.
[0203] It should be noted here that the above-mentioned sixth receiving module 110, second acquisition module 112, third sending module 114 and second processing module 116 correspond to steps S502 to S508 in Example 1. The instances and application scenarios implemented by the above-mentioned modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiments.
[0204] Figure 14 FIG. 1 is a schematic diagram of an architecture of an identity authentication system provided according to an embodiment of the present invention. Figure 14 As shown, the transaction information sharing system includes: a target terminal, a first operating server, and a second operating server. This identity verification system can be applied in financial scenarios, for example, in scenarios where transaction information is shared between financial institutions (e.g., between banks, or between a bank and a relevant financial regulatory agency). The following describes the system using the example of sharing transaction information between financial institutions.
[0205] The target terminal is configured to receive a first wallet account application; obtain a first trusted credential of the digital wallet user in response to the first wallet account application; and send the first trusted credential to the first operating server;
[0206] The first operating server is connected to the target terminal and is configured to receive a first wallet account application from the target terminal, process the digital wallet user's wallet account opening on the first operating server based on the first trusted credential, generate a second trusted credential for the digital wallet user, and send the second trusted credential to the target terminal;
[0207] The target terminal is further configured to receive an application for a second wallet account; obtain the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server; send the first identity identifier and the identity credential information to the second operating server; obtain the first trusted credential generated by the second operating server and store the first trusted credential;
[0208] The second operation server is connected to the target terminal and is used to verify the digital wallet user based on the first identity identifier and the identity credential information. If the verification is successful, a target wallet account is generated, and a first trusted credential is generated for the digital wallet user, and the first trusted credential is sent to the target terminal.
[0209] According to an embodiment of the present invention, an embodiment of a computer-readable storage medium is further provided. Optionally, in this embodiment, the computer-readable storage medium can be used to store the program code executed by the identity authentication method provided in the first embodiment.
[0210] Optionally, in this embodiment, the computer-readable storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0211] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for executing the following steps: receiving a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; in response to the first wallet account application, obtaining a first trusted credential of the digital wallet user, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account in the second operating server; sending the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the opening of the wallet account of the digital wallet user on the first operating server.
[0212] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for executing the following steps: receiving a first wallet account application sent by the target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server, and the first wallet account application carries a first trusted credential of the digital wallet user, and the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account on the second operating server; and processing the opening of a wallet account for the digital wallet user on the first operating server based on the first trusted credential.
[0213] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for executing the following steps: receiving a second wallet account application sent by the target terminal, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on the second operating server, and the second wallet account application carries the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server; verifying the digital wallet user based on the first identity identifier and the identity credential information; if the verification is successful, generating a target wallet account for the digital wallet user on the second operating server, and generating a first trusted credential for the digital wallet user; sending the first trusted credential to the target terminal, so that the target terminal stores the first trusted credential and uses it to apply for a wallet account of the digital wallet user on the first operating server.
[0214] Optionally, in this embodiment, the computer-readable storage medium is configured to store program codes for executing the following steps: receiving a first public key of a digital wallet user sent by a target terminal, receiving a second public key of the first operating server, receiving a third public key of the second operating server, and receiving a fourth public key of an identity certificate issuing server; generating a first identity identifier for the digital wallet user, generating a second identity identifier for the first operating server, generating a third identity identifier for the second operating server, and generating a fourth identity identifier for the identity certificate issuing server; generating a first identity document for the digital wallet user, generating a second identity document for the first operating server, generating a third identity document for the second operating server, and generating a fourth identity document for the identity certificate issuing server, wherein the first identity document stores the first identity identifier , and the correspondence between the above-mentioned first identity identifier and the above-mentioned first public key, the above-mentioned second identity document stores the second identity identifier of the above-mentioned first operation server, and the correspondence between the above-mentioned second identity identifier and the above-mentioned second public key, the above-mentioned third identity document stores the third identity identifier of the above-mentioned second operation server, and the correspondence between the above-mentioned third identity identifier and the above-mentioned third public key, the above-mentioned fourth identity document stores the fourth identity identifier of the identity certificate issuing server, and the correspondence between the above-mentioned fourth identity identifier and the above-mentioned fourth public key; receive the first trusted certificate sent by the above-mentioned second operation server, and update the above-mentioned first trusted certificate in the above-mentioned first identity document, wherein the above-mentioned first trusted certificate is used to identify that the above-mentioned second operation server has verified the above-mentioned digital wallet user and opened a wallet account in the above-mentioned second operation server.
[0215] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for executing the following steps: the target terminal receives a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; the target terminal obtains a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account in the second operating server; the target terminal sends the first trusted credential to the first operating server; the first operating server processes the opening of the wallet account of the digital wallet user on the first operating server based on the first trusted credential.
[0216] According to an embodiment of the present invention, an embodiment of a processor is further provided. Optionally, in this embodiment, the computer-readable storage medium may be used to store program codes executed by the identity authentication method provided in the first embodiment.
[0217] An embodiment of the present application provides an electronic device, the device including a processor, a memory, and a program stored in the memory and executable on the processor, wherein the processor implements the following steps when executing the program: receiving a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; obtaining a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account on the second operating server; and sending the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the opening of the wallet account of the digital wallet user on the first operating server.
[0218] An embodiment of the present application provides an electronic device, the device including a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the following steps are implemented: receiving a first wallet account application sent by a target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server, the first wallet account application carries a first trusted credential of the digital wallet user, and the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account on the second operating server; and processing the opening of a wallet account for the digital wallet user on the first operating server based on the first trusted credential.
[0219] An embodiment of the present application provides an electronic device, the device including a processor, a memory, and a program stored in the memory and executable on the processor, wherein the processor implements the following steps when executing the program: receiving a second wallet account application sent by a target terminal, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on a second operating server, and the second wallet account application carries a first identity identifier of the digital wallet user and identity credential information of the digital wallet user on an identity credential issuing server; verifying the digital wallet user based on the first identity identifier and the identity credential information; if the verification is successful, generating a target wallet account for the digital wallet user on the second operating server and generating a first trusted credential for the digital wallet user; and sending the first trusted credential to the target terminal, so that the target terminal stores the first trusted credential and uses it to apply for a wallet account of the digital wallet user on the first operating server.
[0220] An embodiment of the present application provides an electronic device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the following steps are implemented: receiving a first public key of a digital wallet user sent by a target terminal, receiving a second public key of the first operating server, receiving a third public key of the second operating server, and receiving a fourth public key of an identity certificate issuing server; generating a first identity identifier for the digital wallet user, a second identity identifier for the first operating server, a third identity identifier for the second operating server, and a fourth identity identifier for the identity certificate issuing server; generating a first identity document for the digital wallet user, a second identity document for the first operating server, a third identity document for the second operating server, and a fourth identity document for the identity certificate issuing server, wherein the first identity document The first identity identifier and the corresponding relationship between the first identity identifier and the first public key are stored in the above-mentioned second identity document. The second identity identifier of the above-mentioned first operation server and the corresponding relationship between the second identity identifier and the second public key are stored in the above-mentioned third identity document. The third identity identifier of the above-mentioned second operation server and the corresponding relationship between the third identity identifier and the third public key are stored in the above-mentioned fourth identity document. The fourth identity identifier of the identity certificate issuing server and the corresponding relationship between the fourth identity identifier and the fourth public key are stored in the above-mentioned fourth identity document. The first trusted certificate sent by the above-mentioned second operation server is received, and the first trusted certificate is updated in the above-mentioned first identity document, wherein the above-mentioned first trusted certificate is used to identify that the above-mentioned second operation server has verified the above-mentioned digital wallet user and opened a wallet account in the above-mentioned second operation server.
[0221] An embodiment of the present application provides an electronic device, the device including a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the following steps are implemented: a target terminal receives a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; the target terminal obtains a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account on the second operating server; the target terminal sends the first trusted credential to the first operating server; and the first operating server processes the opening of a wallet account for the digital wallet user on the first operating server based on the first trusted credential.
[0222] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program that is initialized with the following method steps: receiving a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; in response to the first wallet account application, obtaining a first trusted credential of the digital wallet user, wherein the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account on the second operating server; sending the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the opening of the wallet account of the digital wallet user on the first operating server.
[0223] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program initialized with the following method steps: receiving a first wallet account application sent by a target terminal, wherein the above-mentioned first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server, and the above-mentioned first wallet account application carries a first trusted credential of the above-mentioned digital wallet user, and the above-mentioned first trusted credential is used to identify that the second operating server has verified the above-mentioned digital wallet user and opened a wallet account on the above-mentioned second operating server; based on the above-mentioned first trusted credential, processing the wallet account opening of the above-mentioned digital wallet user on the above-mentioned first operating server.
[0224] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program initialized with the following method steps: receiving a second wallet account application sent by a target terminal, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on the second operating server, and the second wallet account application carries the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server; verifying the digital wallet user based on the first identity identifier and the identity credential information; if the verification is successful, generating a target wallet account for the digital wallet user on the second operating server, and generating a first trusted credential for the digital wallet user; sending the first trusted credential to the target terminal, so that the target terminal stores the first trusted credential and uses it to apply for a wallet account of the digital wallet user on the first operating server.
[0225] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program initialized with the following method steps: receiving a first public key of a digital wallet user sent by a target terminal, receiving a second public key of the above-mentioned first operating server, receiving a third public key of the second operating server, and receiving a fourth public key of an identity certificate issuing server; generating a first identity identifier for the above-mentioned digital wallet user, generating a second identity identifier for the above-mentioned first operating server, generating a third identity identifier for the above-mentioned second operating server, and generating a fourth identity identifier for the above-mentioned identity certificate issuing server; generating a first identity document for the above-mentioned digital wallet user, generating a second identity document for the above-mentioned first operating server, generating a third identity document for the above-mentioned second operating server, and generating a fourth identity document for the above-mentioned identity certificate issuing server, wherein the above-mentioned first identity document stores the above-mentioned first identity document. The invention relates to a method for storing a digital wallet user through a trusted third party operation server and a digital wallet application server, and a digital wallet application server that has a plurality of trusted third party operation servers and a plurality of trusted third party operation servers. The method comprises: receiving a first trusted credential sent by the second operating server and updating the first trusted credential in the first identity document, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account in the second operating server.
[0226] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program initialized with the following method steps: a target terminal receives a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; the target terminal obtains a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to identify that a second operating server has verified the digital wallet user and opened a wallet account on the second operating server; the target terminal sends the first trusted credential to the first operating server; the first operating server processes the opening of the wallet account of the digital wallet user on the first operating server based on the first trusted credential.
[0227] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0228] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0229] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0230] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0231] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0232] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.
[0233] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. An identity authentication method, characterized in that: include: Receive a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operator server; In response to the first wallet account application, obtaining a first trusted credential of the digital wallet user, wherein the first trusted credential is used to identify that the second operating server has authenticated the digital wallet user and opened a wallet account on the second operating server; The first trusted credential is sent to the first operating server, wherein the first trusted credential is used by the first operating server to process the digital wallet user opening a wallet account on the first operating server.
2. The method according to claim 1, characterized in that Before obtaining the first trusted credential of the digital wallet user in response to the first wallet account application, the method further includes: Receive a second wallet account application, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on a second operator server; Obtaining a first identity identifier of the digital wallet user and identity credential information of the digital wallet user on an identity credential issuing server; Sending the first identity identifier and the identity credential information to the second operation server; Obtain the first trusted credential generated by the second operation server and store the first trusted credential.
3. The method according to claim 2, characterized in that The obtaining of the first trusted credential generated by the second operation server includes at least one of the following: Downloading the first trusted credential from a blockchain distributed identity management server, wherein the first trusted credential is generated by the second operation server and sent to the blockchain distributed identity management server; The first trusted credential is downloaded from the second operation server, wherein the first trusted credential is generated by the second operation server and stored in the second operation server.
4. The method according to claim 3, characterized in that The blockchain distributed identity management server stores the first identity document of the digital wallet user, the second identity document of the first operating server, the third identity document of the second operating server, and the fourth identity document of the identity certificate issuing server, wherein the first identity document stores the first identity identifier and the correspondence between the first identity identifier and the first public key, and the first public key is the public key of the digital wallet user; the second identity document stores the second identity identifier of the first operating server and the correspondence between the second identity identifier and the second public key, and the second public key is the public key of the first operating server; the third identity document stores the third identity identifier of the second operating server and the correspondence between the third identity identifier and the third public key, and the third public key is the public key of the second operating server; the fourth identity document stores the fourth identity identifier of the identity certificate issuing server and the correspondence between the fourth identity identifier and the fourth public key, and the fourth public key is the public key of the identity certificate issuing server.
5. The method according to claim 4, characterized in that The sending the first identity identifier and the identity credential information to the second operation server includes: Obtaining a first private key and a second public key of the digital wallet user; Signing the first identity identifier using the first private key to obtain the signed first identity identifier, and encrypting the identity credential information using the second public key to obtain encrypted identity credential information; The signed first identity identifier and the encrypted identity credential information are sent to the second operating server, so that the second operating server uses the second private key of the second operating server to decrypt the encrypted identity credential information to obtain the identity credential information, and uses the first public key of the digital wallet user to verify the signed first identity identifier to obtain the first identity identifier after verification.
6. The method according to claim 5, characterized in that The obtaining of the identity credential information of the digital wallet user from the identity credential issuing server includes: The identity credential information in the form of identity credential ciphertext is obtained, wherein the identity credential ciphertext is obtained by encrypting the identity credential information using a fourth private key of the identity credential issuing server.
7. The method according to claim 1, characterized in that After sending the first trusted credential to the first operation server, the method further includes: Receive a second trusted credential returned by the first operating server, wherein the second trusted credential is used to identify that the first operating server has verified the digital wallet user and opened a wallet account in the first operating server.
8. An identity authentication method, characterized in that: include: Receive a first wallet account application sent by a target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operator server, and the first wallet account application carries a first trusted credential of the digital wallet user, which is used to identify that the second operator server has verified the digital wallet user and opened a wallet account on the second operator server; Based on the first trusted credential, the digital wallet user is processed to open a wallet account on the first operating server.
9. The method according to claim 8, characterized in that The method further comprises: When the digital wallet user is successfully verified on the first operating server based on the first trusted credential and the wallet account is opened on the first operating server, a second trusted credential of the digital wallet user is generated, wherein the second trusted credential is used to identify that the first operating server has verified the digital wallet user and opened a wallet account on the first operating server.
10. The method according to claim 9, characterized in that The processing of opening a wallet account for the digital wallet user on the first operating server based on the first trusted credential includes: Obtaining a third private key of the first operating server; The encrypted first trusted credential is decrypted using the third private key of the first operating server to obtain the first trusted credential, and the first public key of the digital wallet user is used to verify the signed first trusted credential to obtain the verified first trusted credential, thereby generating the second trusted credential and wallet account of the digital wallet user.
11. The method according to claim 9, characterized in that After generating the second trusted credential of the digital wallet user, the method further includes: The second trusted credential is sent to the target terminal for storage, and the second trusted credential is sent to the blockchain distributed identity management server for updating.
12. The method according to claim 8, characterized in that The processing of opening a wallet account for the digital wallet user on the first operating server based on the first trusted credential includes: Obtaining a first identity identifier of the digital wallet user and identity credential information of the digital wallet user on an identity credential issuing server; The digital wallet user is processed for opening a wallet account on the first operating server based on the first trusted credential, or the digital wallet user is processed for opening a wallet account on the first operating server based on the first trusted credential and either the first identity identification information or the identity credential information.
13. An identity authentication method, characterized in that: include: Receive a second wallet account application sent by the target terminal, wherein the second wallet account application is used to apply for a wallet account of a digital wallet user on a second operator server, and the second wallet account application carries the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server; Verifying the digital wallet user based on the first identity identifier and the identity credential information; If the verification is successful, generating a target wallet account for the digital wallet user on the second operator server and generating a first trusted credential for the digital wallet user; The first trusted credential is sent to the target terminal, so that the target terminal stores the first trusted credential.
14. The method according to claim 13, characterized in that The sending the first trusted credential to the target terminal includes: The first trusted credential is sent to a blockchain distributed identity management server, so that the target terminal can download the first trusted credential from the blockchain distributed identity management server.
15. The method according to claim 14, characterized in that The blockchain distributed identity management server stores the first identity document of the digital wallet user, the second identity document of the first operating server, the third identity document of the second operating server, and the fourth identity document of the identity certificate issuing server, wherein the first identity document stores the first identity identifier and the correspondence between the first identity identifier and the first public key, and the first public key is the public key of the digital wallet user; the second identity document stores the second identity identifier of the first operating server and the correspondence between the second identity identifier and the second public key, and the second public key is the public key of the first operating server; the third identity document stores the third identity identifier of the second operating server and the correspondence between the third identity identifier and the third public key, and the third public key is the public key of the second operating server; the fourth identity document stores the fourth identity identifier of the identity certificate issuing server and the correspondence between the fourth identity identifier and the fourth public key, and the fourth public key is the public key of the identity certificate issuing server.
16. The method according to claim 15, characterized in that After receiving the second wallet account application sent by the target terminal, the method further includes: Extracting the encrypted identity credential information and the signed first identity identifier from the second wallet account application, wherein the encrypted identity credential information is encrypted using the second public key, and the signed first identity identifier is signed using the first private key of the digital wallet user; The encrypted identity credential information is decrypted using the second private key of the second operating server to obtain the identity credential information, and the signed first identity identifier is verified using the first public key of the digital wallet user to obtain the first identity identifier after verification.
17. The method according to claim 16, characterized in that The verifying the digital wallet user based on the first identity identifier and the identity credential information includes: When the identity credential information exists in the form of identity credential ciphertext, the identity credential ciphertext is verified using the fourth public key of the identity credential issuing server to obtain the identity credential information after verification, wherein the identity credential ciphertext is obtained by encrypting the identity credential information using the fourth private key of the identity credential issuing server.
18. An identity authentication method, characterized in that: include: Receive the first public key of the digital wallet user sent by the target terminal, receive the second public key of the first operating server, receive the third public key of the second operating server, and receive the fourth public key of the identity certificate issuing server; Generate a first identity identifier for the digital wallet user, generate a second identity identifier for the first operating server, generate a third identity identifier for the second operating server, and generate a fourth identity identifier for the identity credential issuing server; Generate a first identity document for the digital wallet user, generate a second identity document for the first operating server, generate a third identity document for the second operating server, and generate a fourth identity document for the identity credential issuing server, wherein the first identity document stores the first identity identifier and the corresponding relationship between the first identity identifier and the first public key, the second identity document stores the second identity identifier of the first operating server and the corresponding relationship between the second identity identifier and the second public key, the third identity document stores the third identity identifier of the second operating server and the corresponding relationship between the third identity identifier and the third public key, and the fourth identity document stores the fourth identity identifier of the identity credential issuing server and the corresponding relationship between the fourth identity identifier and the fourth public key; Receive the first trusted credential sent by the second operating server, and update the first trusted credential in the first identity document, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account in the second operating server.
19. The method according to claim 18, characterized in that The method further comprises: Receiving a credential download request sent by the first operation server; In response to the credential download request, the first trusted credential is sent to the first operating server for processing the digital wallet user's application for a wallet account in the first operating server.
20. The method according to claim 18, wherein The method further comprises: Receive a second trusted credential sent by the first operating server, and update the second trusted credential in the second identity document, wherein the second trusted credential is used to identify that the first operating server has verified the digital wallet user and opened a wallet account in the first operating server.
21. An identity authentication method, characterized in that: include: The target terminal receives a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; The target terminal obtains a first trusted credential of the digital wallet user in response to the first wallet account application, wherein the first trusted credential is used to identify that the second operation server has verified the digital wallet user and opened a wallet account in the second operation server; The target terminal sends the first trusted credential to the first operation server; The first operating server processes the digital wallet user's opening of a wallet account on the first operating server based on the first trusted credential.
22. The method according to claim 21, characterized in that Before the target terminal obtains the first trusted credential of the digital wallet user in response to the first wallet account application, the method further includes: The target terminal receives a second wallet account application, wherein the second wallet account application is used to apply for a wallet account of the digital wallet user on a second operating server; The target terminal obtains the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server; The target terminal sends the first identity identifier and the identity credential information to the second operation server; The second operation server verifies the digital wallet user based on the first identity identifier and the identity credential information, generates a target wallet account if the verification is successful, generates the first trusted credential, and sends the first trusted credential to the target terminal; The target terminal stores the first trusted credential.
23. The method according to claim 22, characterized in that The method further comprises: The second operation server sends the first trusted credential to the blockchain distributed identity management server; Upon receiving the identity request of the digital wallet user from the first operation server, the blockchain distributed identity management server sends the first trusted credential to the first operation server; The first operation server sends the second trusted credential to the blockchain distributed identity management server.
24. The method according to claim 23, wherein The method further comprises: The blockchain distributed identity management server receives the first public key of the digital wallet user sent by the target terminal, receives the second public key of the first operating server, receives the third public key of the second operating server, and receives the fourth public key of the identity certificate issuing server; The blockchain distributed identity management server generates a first identity identifier for the digital wallet user, a second identity identifier for the first operation server, a third identity identifier for the second operation server, and a fourth identity identifier for the identity credential issuing server; The blockchain distributed identity management server generates a first identity document for the digital wallet user, a second identity document for the first operating server, a third identity document for the second operating server, and a fourth identity document for the identity credential issuing server, wherein the first identity document stores the first identity identifier and the correspondence between the first identity identifier and the first public key, the second identity document stores the second identity identifier of the first operating server and the correspondence between the second identity identifier and the second public key, the third identity document stores the third identity identifier of the second operating server and the correspondence between the third identity identifier and the third public key, and the fourth identity document stores the fourth identity identifier of the identity credential issuing server and the correspondence between the fourth identity identifier and the fourth public key.
25. The method according to claim 22, wherein The target terminal obtains the identity credential information of the digital wallet user from the identity credential issuing server, including: The target terminal sends an identity authentication request to the identity credential issuing server; The identity credential issuing server responds to the identity authentication request and feeds back the identity credential information of the digital wallet user on the identity credential issuing server to the target terminal.
26. An identity verification device, characterized in that: include: A first receiving module is configured to receive a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; a first obtaining module, configured to obtain, in response to the first wallet account application, a first trusted credential of the digital wallet user, wherein the first trusted credential is used to indicate that the second operating server has authenticated the digital wallet user and opened a wallet account on the second operating server; The first sending module is configured to send the first trusted credential to the first operating server, wherein the first trusted credential is used by the first operating server to process the digital wallet user opening a wallet account on the first operating server.
27. An identity verification device, characterized in that: include: a second receiving module, configured to receive a first wallet account application sent by a target terminal, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operator server, and the first wallet account application carries a first trusted credential of the digital wallet user, which is used to identify that the second operator server has verified the digital wallet user and opened a wallet account on the second operator server; The first processing module is configured to process, based on the first trusted credential, an opening of a wallet account by the digital wallet user on the first operating server.
28. An identity verification device, characterized in that: include: a third receiving module, configured to receive a second wallet account application sent by the target terminal, wherein the second wallet account application is used to apply for a wallet account of a digital wallet user on a second operator server, and the second wallet account application carries the first identity identifier of the digital wallet user and the identity credential information of the digital wallet user on the identity credential issuing server; a verification module, configured to verify the digital wallet user based on the first identity identifier and the identity credential information; A first generating module is configured to generate a target wallet account for the digital wallet user on the second operating server and generate a first trusted credential for the digital wallet user if the verification is successful; The second sending module is configured to send the first trusted credential to the target terminal, so that the target terminal stores the first trusted credential.
29. An identity verification device, characterized in that include: a fourth receiving module, configured to receive a first public key of a digital wallet user sent by a target terminal, receive a second public key of a first operating server, receive a third public key of a second operating server, and receive a fourth public key of an identity certificate issuing server; a second generating module, configured to generate a first identity identifier for the digital wallet user, a second identity identifier for the first operating server, a third identity identifier for the second operating server, and a fourth identity identifier for the identity credential issuing server; a third generation module, configured to generate a first identity document for the digital wallet user, a second identity document for the first operating server, a third identity document for the second operating server, and a fourth identity document for the identity credential issuing server, wherein the first identity document stores the first identity identifier and the corresponding relationship between the first identity identifier and the first public key, the second identity document stores the second identity identifier of the first operating server and the corresponding relationship between the second identity identifier and the second public key, the third identity document stores the third identity identifier of the second operating server and the corresponding relationship between the third identity identifier and the third public key, and the fourth identity document stores the fourth identity identifier of the identity credential issuing server and the corresponding relationship between the fourth identity identifier and the fourth public key; The fifth receiving module is used to receive the first trusted credential sent by the second operating server and update the first trusted credential in the first identity document, wherein the first trusted credential is used to identify that the second operating server has verified the digital wallet user and opened a wallet account in the second operating server.
30. An identity verification device, characterized in that: include: A sixth receiving module, configured to receive, at the target terminal, a first wallet account application, wherein the first wallet account application is used to apply for a wallet account of a digital wallet user on a first operating server; a second obtaining module, configured for the target terminal to obtain, in response to the first wallet account application, a first trusted credential of the digital wallet user, wherein the first trusted credential is used to indicate that the second operating server has authenticated the digital wallet user and opened a wallet account on the second operating server; a third sending module, configured for the target terminal to send the first trusted credential to the first operation server; The second processing module is used for the first operation server to process the digital wallet user's wallet account opening on the first operation server based on the first trusted certificate.
31. An identity verification system comprising: A target terminal, configured to receive an application for a first wallet account; In response to the first wallet account application, obtaining a first trusted credential of a digital wallet user; Sending the first trusted credential to the first operation server; The first operating server is connected to the target terminal and is configured to receive a first wallet account application sent by the target terminal, process the digital wallet user's wallet account opening on the first operating server based on the first trusted credential, generate a second trusted credential for the digital wallet user, and send the second trusted credential to the target terminal; The target terminal is further configured to receive an application for a second wallet account; obtain a first identity identifier of the digital wallet user and identity credential information of the digital wallet user on an identity credential issuing server; send the first identity identifier and the identity credential information to a second operating server; obtain the first trusted credential generated by the second operating server and store the first trusted credential; The second operation server is connected to the target terminal and is used to verify the digital wallet user based on the first identity identifier and the identity credential information. If the verification is successful, a target wallet account is generated, and a first trusted credential is generated for the digital wallet user, and the first trusted credential is sent to the target terminal.
32. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the identity authentication method described in any one of claims 1 to 25.
33. An electronic device, characterized in that: It includes one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the identity authentication method described in any one of claims 1 to 25.
Citation Information
Patent Citations
Multi-system login method, apparatus, computer device, and storage medium
CN109274685A
Information processing method and device and storage medium
CN111277565A
Cited By
Method and credential for consent-based analysis of mobile wallet data
US20260073073A1