Method and device for processing account information

By generating and signing public and private key pairs for digital wallets, combined with a blockchain identity management system, the problem of user account information leakage is solved, anonymization is achieved, user privacy is protected, and regulatory requirements are met.

CN119067659BActive Publication Date: 2025-10-03THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310651319.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-02
Publication Date
2025-10-03
Estimated Expiration
2043-06-02

AI Technical Summary

Technical Problem

User account information is easily leaked during C2C/C2B transactions, leading to privacy risks and regulatory challenges.

Method used

By generating a registered public-private key pair for a digital wallet and issuing a public-private key pair, submitting the public key to the blockchain identity management system, receiving a distributed identity account, and using the private key to sign the account binding relationship, a self-signed identity certificate is generated and submitted to the blockchain identity management system to achieve anonymization.

Benefits of technology

It realizes trusted anonymous payment, protects user privacy, meets regulatory requirements, and prevents account information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119067659B_ABST
    Figure CN119067659B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and apparatus for processing account information, relating to the field of digital wallet technology. A specific implementation of the method includes: sending an identity credential issuance request to a first financial institution, the identity credential issuance request carrying the binding relationship between a first digital wallet account and a first digital wallet distributed identity account; receiving a first digital wallet institution identity credential issued by the first financial institution; signing the binding relationship between the first digital wallet account and the first digital wallet distributed identity account using the first digital wallet issuance private key to obtain a first digital wallet self-signed identity credential; and submitting the first digital wallet issuance public key and the first digital wallet self-signed identity credential to the blockchain identity management system. This implementation can address the technical issue of user account information being easily leaked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of digital wallet technology, and in particular to a method and device for processing account information. Background Art

[0002] In modern society, people open fixed accounts in many financial institutions. During each transaction in the C2C / C2B model, the fixed account information of personal payments will flow between different entities, which may lead to the leakage of user account information. Summary of the Invention

[0003] In view of this, an embodiment of the present invention provides a method and apparatus for processing account information to solve the technical problem that user account information is easily leaked.

[0004] To achieve the above-mentioned object, according to one aspect of an embodiment of the present invention, a method for processing account information is provided, which is applied to a first digital wallet and includes:

[0005] Generate a first digital wallet registration public and private key pair and a first digital wallet issuance public and private key pair respectively;

[0006] Submitting the first digital wallet registration public key to the blockchain identity management system, and receiving the first digital wallet distributed identity account number returned by the blockchain identity management system;

[0007] Sending an identity certificate issuance request to the first financial institution, the identity certificate issuance request carrying the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, and receiving the first digital wallet institution identity certificate issued by the first financial institution;

[0008] The first digital wallet is used to issue a private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet self-signed identity certificate, and submit the first digital wallet issuance public key and the first digital wallet self-signed identity certificate to the blockchain identity management system.

[0009] In addition, according to another aspect of an embodiment of the present invention, a method for processing account information is provided, which is applied to a second digital wallet, comprising:

[0010] Generate a second digital wallet registration public and private key pair and a second digital wallet issuance public and private key pair respectively;

[0011] Submitting the second digital wallet registration public key to the blockchain identity management system and receiving the second digital wallet distributed identity account number returned by the blockchain identity management system;

[0012] Send an identity certificate issuance request to the second financial institution, the identity certificate issuance request carrying the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and receive the second digital wallet institution identity certificate issued by the second financial institution;

[0013] The second digital wallet issuance private key is used to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, to obtain the second digital wallet self-signed identity certificate, and the second digital wallet issuance public key and the second digital wallet self-signed identity certificate are submitted to the blockchain identity management system.

[0014] In addition, according to another aspect of an embodiment of the present invention, a method for processing account information is provided, which is applied to a first financial institution, comprising:

[0015] Generate a first financial institution registration public-private key pair and a first financial institution signature public-private key pair, submit the first financial institution registration public key to the blockchain identity management system, and receive the first financial institution distributed identity account number returned by the blockchain identity management system;

[0016] Receive an identity credential issuance request from the first digital wallet, where the identity credential issuance request carries a binding relationship between the first digital wallet account and the first digital wallet distributed identity account;

[0017] Using the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtaining the first digital wallet institution identity certificate, and returning the first digital wallet institution identity certificate to the first digital wallet;

[0018] The binding relationship between the first digital wallet account and the first digital wallet distributed identity account is stored in the background, and the first financial institution signature public key and the first digital wallet institution identity certificate are submitted to the blockchain identity management system.

[0019] In addition, according to another aspect of an embodiment of the present invention, a method for processing account information is provided, which is applied to a second financial institution, comprising:

[0020] Generate a second financial institution registration public-private key pair and a second financial institution signature public-private key pair, submit the second financial institution registration public key to the blockchain identity management system, and receive the second financial institution distributed identity account number returned by the blockchain identity management system;

[0021] Receive an identity credential issuance request from the second digital wallet, the identity credential issuance request carrying a binding relationship between the second digital wallet account and the second digital wallet distributed identity account;

[0022] Using the second financial institution's signature private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtaining the second digital wallet institution identity certificate, and returning the second digital wallet institution identity certificate to the second digital wallet;

[0023] Store the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and submit the second financial institution signature public key and the second digital wallet institution identity certificate to the blockchain identity management system.

[0024] In addition, according to another aspect of an embodiment of the present invention, a method for processing account information is provided, which is applied to a blockchain identity management system, comprising:

[0025] Receiving respectively the first digital wallet registration public key submitted by the first digital wallet, the second digital wallet registration public key submitted by the second digital wallet, the first financial institution registration public key submitted by the first financial institution, and the second financial institution registration public key submitted by the second financial institution;

[0026] Generate a first digital wallet distributed identity account and its identity document, a second digital wallet distributed identity account and its identity document, a first financial institution distributed identity account and its identity document, and a second financial institution distributed identity account and its identity document respectively;

[0027] The identity document is used to store the binding relationship between the identity account and its public key.

[0028] In addition, according to another aspect of an embodiment of the present invention, there is provided an apparatus for processing account information, which is provided in a first digital wallet and includes:

[0029] A first generation module is configured to generate a first digital wallet registration public-private key pair and a first digital wallet issuance public-private key pair, respectively; submit the first digital wallet registration public key to the blockchain identity management system, and receive the first digital wallet distributed identity account number returned by the blockchain identity management system;

[0030] A first request module is configured to send an identity credential issuance request to a first financial institution, the identity credential issuance request carrying a binding relationship between a first digital wallet account and a first digital wallet distributed identity account, and receive a first digital wallet institution identity credential issued by the first financial institution;

[0031] The first issuing module is used to use the first digital wallet to issue a private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet self-signed identity certificate, and submit the first digital wallet issuance public key and the first digital wallet self-signed identity certificate to the blockchain identity management system.

[0032] In addition, according to another aspect of an embodiment of the present invention, there is provided an apparatus for processing account information, which is provided in a second digital wallet and includes:

[0033] The second generation module is used to generate a second digital wallet registration public and private key pair and a second digital wallet issuance public and private key pair respectively; submit the second digital wallet registration public key to the blockchain identity management system, and receive the second digital wallet distributed identity account number returned by the blockchain identity management system;

[0034] A second request module is configured to send an identity credential issuance request to a second financial institution, the identity credential issuance request carrying a binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and receive a second digital wallet institution identity credential issued by the second financial institution;

[0035] The second issuing module is used to use the second digital wallet to issue a private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet self-signed identity certificate, and submit the second digital wallet issuance public key and the second digital wallet self-signed identity certificate to the blockchain identity management system.

[0036] In addition, according to another aspect of an embodiment of the present invention, there is provided an apparatus for processing account information, which is provided in a first financial institution and includes:

[0037] A third generation module is configured to generate a first financial institution registration public-private key pair and a first financial institution signature public-private key pair, submit the first financial institution registration public key to the blockchain identity management system, and receive the first financial institution distributed identity account number returned by the blockchain identity management system;

[0038] The third issuance module is used to receive an identity certificate issuance request sent by the first digital wallet, where the identity certificate issuance request carries the binding relationship between the first digital wallet account and the first digital wallet distributed identity account; use the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet institution identity certificate, and return the first digital wallet institution identity certificate to the first digital wallet; store the binding relationship between the first digital wallet account and the first digital wallet distributed identity account in the background, and submit the first financial institution's signature public key and the first digital wallet institution identity certificate to the blockchain identity management system.

[0039] In addition, according to another aspect of an embodiment of the present invention, there is provided an apparatus for processing account information, which is provided in a second financial institution and includes:

[0040] A fourth generation module is configured to generate a second financial institution registration public-private key pair and a second financial institution signature public-private key pair, submit the second financial institution registration public key to the blockchain identity management system, and receive the second financial institution distributed identity account number returned by the blockchain identity management system;

[0041] The fourth issuance module is used to receive an identity certificate issuance request sent by the second digital wallet, where the identity certificate issuance request carries the binding relationship between the second digital wallet account and the second digital wallet distributed identity account; use the second financial institution signature private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet institution identity certificate, and return the second digital wallet institution identity certificate to the second digital wallet; store the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and submit the second financial institution signature public key and the second digital wallet institution identity certificate to the blockchain identity management system.

[0042] In addition, according to another aspect of an embodiment of the present invention, a device for processing account information is provided, which is provided in a blockchain identity management system, including:

[0043] A receiving module, configured to respectively receive a first digital wallet registration public key submitted by the first digital wallet, a second digital wallet registration public key submitted by the second digital wallet, a first financial institution registration public key submitted by the first financial institution, and a second financial institution registration public key submitted by the second financial institution;

[0044] The identity module is used to generate a first digital wallet distributed identity account and its identity document, a second digital wallet distributed identity account and its identity document, a first financial institution distributed identity account and its identity document, and a second financial institution distributed identity account and its identity document, respectively; wherein the identity document is used to store the binding relationship between the identity account and its public key.

[0045] According to another aspect of an embodiment of the present invention, there is further provided an electronic device, including:

[0046] one or more processors;

[0047] a storage device for storing one or more programs,

[0048] When the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any one of the above embodiments.

[0049] According to another aspect of the embodiments of the present invention, a computer-readable medium is provided, on which a computer program is stored. When the program is executed by a processor, the method described in any one of the above embodiments is implemented.

[0050] According to another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the method described in any one of the above embodiments is implemented.

[0051] One embodiment of the above invention has the following advantages or beneficial effects: By adopting the technical means of sending an identity credential issuance request carrying the binding relationship between the first digital wallet account and the first digital wallet distributed identity account to a first financial institution, receiving the first digital wallet institution identity credential issued by the first financial institution, and signing the binding relationship between the first digital wallet account and the first digital wallet distributed identity account using the first digital wallet issuance private key, thereby obtaining a self-signed identity credential from the first digital wallet, the technical problem of user account information being easily leaked in the prior art is overcome. This embodiment of the present invention anonymizes the original account number of the digital wallet, thereby realizing trusted anonymous payment, thereby protecting user privacy and meeting regulatory requirements.

[0052] The further effects of the above-mentioned non-conventional optional manner will be described below in conjunction with specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. Among them:

[0054] Figure 1 is a schematic diagram of the main process of a method for processing account information according to one embodiment of the present invention;

[0055] Figure 2 is a schematic diagram of a system architecture of a method for processing account information according to an embodiment of the present invention;

[0056] Figure 3 is a schematic diagram of the main process of a method for processing account information according to a reference embodiment of the present invention;

[0057] Figure 4 is a schematic diagram of the main process of a method for processing account information according to another embodiment of the present invention;

[0058] Figure 5 is a schematic diagram of the main process of a method for processing account information according to another reference embodiment of the present invention;

[0059] Figure 6is a schematic diagram of the main process of a method for processing account information according to yet another embodiment of the present invention;

[0060] Figure 7 is a schematic diagram of the main flow of a method for processing account information according to yet another reference embodiment of the present invention;

[0061] Figure 8 is a schematic diagram of the main process of a method for processing account information according to yet another embodiment of the present invention;

[0062] Figure 9 is a schematic diagram of the main flow of a method for processing account information according to yet another reference embodiment of the present invention;

[0063] Figure 10 is a schematic diagram of the main process of a method for processing account information according to yet another embodiment of the present invention;

[0064] Figure 11 is a schematic diagram of main modules of an apparatus for processing account information according to one embodiment of the present invention;

[0065] Figure 12 is a schematic diagram of main modules of an apparatus for processing account information according to another embodiment of the present invention;

[0066] Figure 13 is a schematic diagram of main modules of an apparatus for processing account information according to yet another embodiment of the present invention;

[0067] Figure 14 is a schematic diagram of main modules of an apparatus for processing account information according to yet another embodiment of the present invention;

[0068] Figure 15 is a schematic diagram of main modules of an apparatus for processing account information according to yet another embodiment of the present invention;

[0069] Figure 16 is an exemplary system architecture diagram in which embodiments of the present invention may be applied;

[0070] Figure 17 It is a schematic diagram of the structure of a computer system of a terminal device or a server suitable for implementing an embodiment of the present invention. DETAILED DESCRIPTION

[0071] The following description of exemplary embodiments of the present invention is made in conjunction with the accompanying drawings, in which various details of the embodiments of the present invention are included to facilitate understanding. These details should be considered as merely exemplary. Therefore, it should be appreciated by those skilled in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0072] In every payment transaction, we hope that the user's identity will only be known to the payer's bank, the payee's bank and the interconnection agency (usually the regulatory agency), and not be disclosed to relevant entities in other intermediate links. Even if the transaction identity information is leaked, it cannot be linked to the real-name identity.

[0073] To achieve the above objectives, the embodiment of the present invention uses distributed identity technology to assign a trusted and anonymous distributed identity account to the original account of the payee user and the payer user (previously KYC certified by a financial institution) for each transaction. Anonymous means that institutions other than the payer bank, the payee bank, and the interconnection institution cannot know the ownership and association of the distributed identity account; trusted means that the payer bank, the payee bank, and the interconnection institution know that the distributed identity account is associated with the original account of the payee user and the payer user, and this relationship is irrefutable and undeniable. Based on this approach, the identity information of both parties to the transaction can be effectively protected.

[0074] The roles and institutions involved in the embodiments of the present invention include: digital wallets (users), blockchain identity management systems (established by neutral interconnection institutions, such as central banks), and financial institutions (such as payee banks, payer banks, and neutral interconnection systems).

[0075] Digital wallet: Consumers who use digital wallet apps (combined with security capabilities such as secure chips or trusted execution environments) to make transactions and payments.

[0076] Blockchain identity management system: A system based on blockchain technology that issues distributed identity IDs to relevant parties, generates and manages distributed identity documents, and saves user identity credentials.

[0077] Beneficiary Bank, Payer Bank: Financial institutions that provide users with account opening and transaction payment services; issue identity credentials for users of the bank and verify the identity credentials of users of other banks.

[0078] Neutral interconnection system: provides functions such as transaction forwarding.

[0079] Assume that a transaction is conducted between digital wallets a and b, where a is the payer and b is the payee. The banks to which a and b's accounts belong are payer bank A and payee bank B, respectively. In this embodiment of the present invention, the following relevant parameters are defined:

[0080] WID: The real-name account of the digital wallet. WID_a and WID_b represent the real-name accounts of digital wallets a and b respectively.

[0081] TX-DID: Digital wallet distributed identity account, a distributed identity account ID issued by the blockchain distributed identity system. It is an alternative account after the WID real-name account is anonymized. TX-DID_user_a / TX-DID_user_b represent the distributed identity account IDs of digital wallets a and b; TX-DID_bank_A and TX-DID_bank_B represent the distributed identity IDs of the digital wallet payer bank, and TX-DID_bank represents the distributed identity ID of the digital wallet payee bank.

[0082] Pk_user / Sk_user: Refers to the public and private keys of a digital wallet. These keys are generated locally on the digital wallet, while the private key is stored in the wallet terminal's secure chip or a secure, trusted environment. In this embodiment, two types of keys are generated. One type is used to apply for a TX-DID and is associated with its corresponding TX-DID, namely Pk_user_a / Sk_user_a. The other type is used by the digital wallet to issue credentials to its own TX-DID, namely Pk_user_a_veri and SK_user_a_sign.

[0083] Pk_bank / Sk_bank: The public and private keys of the paying and receiving banks. Each bank typically requires two pairs of public and private keys. Assuming the paying and receiving banks are A and B, one key pair is used to issue identity certificates for their respective digital wallets: Pk_bank_A_veri / SK_bank_A_sign and Pk_bank_B_veri / SK_bank_B_sign. The other key pair is used to apply for a TX-DID from the blockchain identity management system: Sk_bank_A_Regi / Pk_bank_A_Regi and Sk_bank_B_Regi / Pk_bank_B_Regi. These two key pairs form a certificate chain relationship. That is, / Pk_bank_A_Regi is signed by SK_bank_A_sign; the same applies to institution B.

[0084] TX-DID DOC (Identity Document): Stored in the blockchain identity management system, each TX-DID DOC is a table in a key-value database. The corresponding TX-DID DOC can be found by using the TX-DID. When digital wallets or paying banks apply for a TX-DID, the blockchain identity management system will write information such as the binding relationship between the TX-DID and the public key used to apply for the TX-DID into the identity document. The TX-DID DOC is synchronized with the blockchain ledger to ensure data immutability.

[0085] TID-DOC update: When a new identity credential is added to a digital wallet, the blockchain identity management system will update the TID-DOC identity document of the digital wallet, recording its issuance and verification relationship, etc.

[0086] Credential: refers to a verifiable credential issued by a relevant party. For example, digital wallet a applies to the bank that granted its account to map and bind the real-name WID account and the anonymous TX-DID account. After digital wallet a submits relevant information and undergoes relevant verification (password / face / ID card verification, etc.), the bank will record the binding relationship between the real-name WID account and the anonymous TX-DID account in the background database after verification. The bank uses the private key signature to generate a corresponding identity credential. Other parties can verify the binding relationship between the real-name WID account and the anonymous TX-DID account by verifying this identity credential.

[0087] Blockchain Identity Management System: A blockchain platform responsible for distributing TX-DIDs to various roles, creating and maintaining TX-DID identity documents, and storing digital wallet identity credentials. Digital wallet clients and paying banks securely interact with the blockchain identity management system through interfaces.

[0088] Figure 1 FIG. 1 is a schematic diagram of the main flow of a method for processing account information according to an embodiment of the present invention. As an embodiment of the present invention, Figure 1 As shown, the method for processing account information is applied to the second digital wallet and may include:

[0089] Step 101: Generate a second digital wallet registration public and private key pair and a second digital wallet issuance public and private key pair respectively.

[0090] Digital wallet b (i.e., the second digital wallet) generates two pairs of keys in a secure environment (client security chip or trusted execution environment). One pair is used to apply for a distributed identity account, namely Pk_user_b / Sk_user_b (i.e., the second digital wallet registers a public-private key pair); the other pair is used to issue identity credentials to itself, namely Pk_user_b_veri and SK_user_b_sign (i.e., the second digital wallet issues a public-private key pair).

[0091] Step 102: Submit the second digital wallet registration public key to the blockchain identity management system, and receive the second digital wallet distributed identity account number returned by the blockchain identity management system.

[0092] like Figure 2 As shown, digital wallet b submits its public key Pk_user_b, which is used to generate a distributed identity account, to the blockchain identity management system. The blockchain identity management system generates a distributed identity account TX-DID_user_b for digital wallet b and then sends the distributed identity account to digital wallet b.

[0093] Step 103: Send an identity certificate issuance request to the second financial institution, where the identity certificate issuance request carries the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and receive the second digital wallet institution identity certificate issued by the second financial institution.

[0094] like Figure 2 As shown, digital wallet b applies to bank B (i.e., the second financial institution) to which the account belongs to associate and bind the original real-name wallet account WID_b and the distributed identity account TX-DID_user_b. After authentication and verification (such as payment password, etc.), bank B uses the private key SK_bank_B_sign to issue the identity certificate Credential_B-b (signing the correspondence between WID_b and TX-DID_user_b), and saves the mapping relationship between WID_b and TX-DID_user_b in the background server.

[0095] Step 104: Use the second digital wallet issuance private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet self-signed identity certificate, and submit the second digital wallet issuance public key and the second digital wallet self-signed identity certificate to the blockchain identity management system.

[0096] Digital wallet b self-signs the correspondence between the original real-name wallet account WID_b and the distributed identity account TX-DID_user_b. Using the credential signature private key SK_user_b_sign stored in the secure area of ​​the wallet terminal, digital wallet b signs the correspondence between the original real-name wallet account WID_b and the distributed identity account TX-DID_user_b, generating the identity credential Credential_b-b (b has issued an identity credential for its own anonymous account).

[0097] Next, digital wallet b sends the identity credential verification public key Pk_user_b_veri and the self-signed identity credential Credential_b-b to the blockchain identity management system through a secure channel (encrypted and uploaded using the public key of the blockchain identity management system).

[0098] Based on the various embodiments described above, it can be seen that the embodiments of the present invention address the technical problem of user account information being easily leaked in the prior art by sending an identity credential issuance request carrying the binding relationship between the first digital wallet account and the first digital wallet distributed identity account to the first financial institution, receiving the first digital wallet institution identity credential issued by the first financial institution, and using the first digital wallet issuance private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account to obtain the first digital wallet self-signed identity credential. The embodiments of the present invention anonymize the original account of the digital wallet, realizing trusted anonymous payment, protecting user privacy and meeting regulatory requirements.

[0099] Figure 3 Schematic diagram of the main process of a method for processing account information according to a reference embodiment of the present invention. As another embodiment of the present invention, Figure 3 As shown, the method for processing account information is applied to the second digital wallet and may include:

[0100] Step 301: Generate a second digital wallet registration public-private key pair and a second digital wallet issuance public-private key pair respectively.

[0101] Step 302: Submit the second digital wallet registration public key to the blockchain identity management system, and receive the second digital wallet distributed identity account number returned by the blockchain identity management system.

[0102] Step 303: Send an identity certificate issuance request to the second financial institution, where the identity certificate issuance request carries the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and receive the second digital wallet institution identity certificate issued by the second financial institution.

[0103] Step 304: Use the second digital wallet issuance private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet self-signed identity certificate, and submit the second digital wallet issuance public key and the second digital wallet self-signed identity certificate to the blockchain identity management system.

[0104] Step 305: Use the second digital wallet registration private key to sign the second digital wallet distributed identity account to obtain the second digital wallet transaction certificate.

[0105] Step 306: Send a transaction request to the second financial institution, where the transaction request carries the transaction amount, the second digital wallet distributed identity account number, and the second digital wallet transaction voucher.

[0106] Two digital wallets, A and B, initiate a trusted anonymous transaction. The recipient, Digital Wallet B, sends the transaction amount, Digital Wallet B's distributed identity account TX-DID_user_b (TX-DID serves as an anonymous account), and Sk_user_b's signature on Digital Wallet B's distributed identity account TX-DID_user_b (as a transaction receipt) to the recipient, Bank B.

[0107] In addition, the specific implementation content of the method for processing account information in a reference embodiment of the present invention has been described in detail in the method for processing account information described above, so the repeated content will not be described again here.

[0108] Figure 4 Schematic diagram of the main process of a method for processing account information according to another embodiment of the present invention. As another embodiment of the present invention, Figure 4 As shown, the method for processing account information is applied to the first digital wallet and may include:

[0109] Step 401: Generate a first digital wallet registration public and private key pair and a first digital wallet issuance public and private key pair respectively.

[0110] Digital wallet a (i.e. the first digital wallet) generates two pairs of keys in a secure environment (client security chip or trusted execution environment). One pair is used to apply for a distributed identity account, namely Pk_user_a / Sk_user_a (i.e. the first digital wallet registers a public-private key pair); the other pair is used to issue identity credentials to itself, namely Pk_user_a_veri and SK_user_a_sign (i.e. the first digital wallet issues a public-private key pair).

[0111] Step 402: Submit the first digital wallet registration public key to the blockchain identity management system, and receive the first digital wallet distributed identity account number returned by the blockchain identity management system.

[0112] like Figure 2 As shown, digital wallet a submits its public key Pk_user_a, which is used to generate a distributed identity account, to the blockchain identity management system. The blockchain identity management system generates a distributed identity account TX-DID_user_a for digital wallet a and then sends the distributed identity account to digital wallet a.

[0113] Step 403: Send an identity certificate issuance request to the first financial institution, the identity certificate issuance request carries the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, and receive the first digital wallet institution identity certificate issued by the first financial institution.

[0114] like Figure 2 As shown, digital wallet a applies to bank A (i.e., the second financial institution) to which the account belongs to associate and bind the original real-name wallet account WID_a and the distributed identity account TX-DID_user_a. After authentication and verification (such as payment password, etc.), bank A uses the private key SK_bank_A_sign to issue the certificate Credential_A-a (signing the correspondence between WID_a and TX-DID_user_a), and saves the mapping relationship between WID_a and TX-DID_user_a in the background server.

[0115] Step 404: Use the first digital wallet to issue a private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet self-signed identity certificate, and submit the first digital wallet to the blockchain identity management system.

[0116] Digital wallet a self-signs the correspondence between the original real-name wallet account WID_a and the distributed identity account TX-DID_user_a. Using the credential signature private key SK_user_a_sign stored in the secure area of ​​the wallet terminal, digital wallet a signs the correspondence between the original real-name wallet account WID_a and the distributed identity account TX-DID_user_a, generating the identity credential Credential_a-a (a has issued an identity credential for its own anonymous account).

[0117] Next, digital wallet a sends the identity credential verification public key Pk_user_a_veri and the self-signed identity credential Credential_a-a to the blockchain identity management system through a secure channel (encrypted and uploaded using the public key of the blockchain identity management system).

[0118] In addition, the specific implementation content of the method for processing account information in another embodiment of the present invention has been described in detail in the method for processing account information described above, so the details will not be repeated here.

[0119] Figure 5 Schematic diagram of the main process of the method for processing account information according to another reference embodiment of the present invention. As another embodiment of the present invention, Figure 5 As shown, the method for processing account information is applied to the first digital wallet and may include:

[0120] Step 501: Generate a first digital wallet registration public and private key pair and a first digital wallet issuance public and private key pair respectively.

[0121] Step 502: Submit the first digital wallet registration public key to the blockchain identity management system, and receive the first digital wallet distributed identity account number returned by the blockchain identity management system.

[0122] Step 503: Send an identity certificate issuance request to the first financial institution, where the identity certificate issuance request carries the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, and receive the first digital wallet institution identity certificate issued by the first financial institution.

[0123] Step 504: Use the first digital wallet to issue a private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet self-signed identity certificate, and submit the first digital wallet to the blockchain identity management system.

[0124] Step 505: Receive a payment request sent by the first financial institution, where the payment request carries the transaction amount and the second digital wallet distributed identity account number.

[0125] Two digital wallets, A and B, initiate a trusted anonymous transaction. After confirming the association between the receiving account information, the receiving bank, B, generates a transaction request. The transaction request is sent to the payer, Bank A, through the interconnection mechanism, and then to the terminal of digital wallet A through Bank A.

[0126] Step 506: Use the first digital wallet registration private key to sign the first digital wallet distributed identity account to obtain the first digital wallet transaction certificate.

[0127] Step 507: Send a payment response to the first financial institution, where the payment response carries the first digital wallet distributed identity account and the first digital wallet transaction voucher.

[0128] Digital wallet (user) a selects trusted anonymous payment. Wallet a carries the distributed identity account TX-DID_user_a (the account to be paid this time) and Sk_user_a's signature on TX-DID_user_a (as a transaction voucher) and sends it to its bank A. Payer Bank A confirms the legitimacy of the payment account.

[0129] In addition, the specific implementation content of the method for processing account information in another reference embodiment of the present invention has been described in detail in the method for processing account information described above, so the repeated content will not be described again here.

[0130] Figure 6 FIG. 1 is a schematic diagram of the main flow of a method for processing account information according to another embodiment of the present invention. As another embodiment of the present invention, Figure 6 As shown, the method for processing account information is applied to a second financial institution and may include:

[0131] Step 601: Generate a second financial institution registration public-private key pair and a second financial institution signature public-private key pair, submit the second financial institution registration public key to the blockchain identity management system, and receive the second financial institution distributed identity account returned by the blockchain identity management system.

[0132] like Figure 2 As shown, Bank B (the second financial institution) generates two pairs of keys, one pair is used to apply for a distributed identity account, namely Sk_bank_B_Regi / Pk_bank_B_Regi; the other pair is used to issue identity certificates to digital wallet users, namely Pk_bank_B_veri / SK_bank_B_sign.

[0133] Bank B submits its public key Sk_bank_B_Regi, used to generate a distributed identity account, to the blockchain identity management system. The blockchain identity management system generates Bank B's distributed identity account number TX-DID_bank_B and then sends the distributed identity account number to Bank B.

[0134] Step 602: Receive an identity credential issuance request sent by the second digital wallet, where the identity credential issuance request carries a binding relationship between the second digital wallet account and the second digital wallet distributed identity account.

[0135] like Figure 2 As shown, digital wallet b applies to bank B (i.e., the second financial institution) to which the account belongs to associate and bind the original real-name wallet account WID_b and the distributed identity account TX-DID_user_b.

[0136] Step 603: Use the second financial institution's signature private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet institution identity certificate, and return the second digital wallet institution identity certificate to the second digital wallet.

[0137] Bank B first authenticates and verifies digital wallet b. After passing the authentication and verification (such as payment password, etc.), Bank B uses the private key SK_bank_B_sign to issue the identity certificate Credential_B-b (signing the correspondence between WID_b and TX-DID_user_b).

[0138] Step 604: Store the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and submit the second financial institution signature public key and the second digital wallet institution identity certificate to the blockchain identity management system.

[0139] Bank B saves the mapping relationship between WID_b and TX-DID_user_b in the background server, and sends the signature public key Pk_bank_B_veri and the issued identity certificate Credential_B-b to the blockchain identity management system through a secure channel (encrypted and uploaded using the public key of the blockchain identity management system).

[0140] In addition, the specific implementation content of the method for processing account information in another embodiment of the present invention has been described in detail in the above-mentioned method for processing account information, so the repeated content will not be described again here.

[0141] Figure 7 Schematic diagram of the main process of a method for processing account information according to another reference embodiment of the present invention. As another embodiment of the present invention, Figure 7 As shown, the method for processing account information is applied to a second financial institution and may include:

[0142] Step 701: Generate a second financial institution registration public-private key pair and a second financial institution signature public-private key pair, submit the second financial institution registration public key to the blockchain identity management system, and receive the second financial institution distributed identity account returned by the blockchain identity management system.

[0143] Step 702: Receive an identity credential issuance request sent by the second digital wallet, where the identity credential issuance request carries a binding relationship between the second digital wallet account and the second digital wallet distributed identity account.

[0144] Step 703: Use the second financial institution's signature private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet institution identity certificate, and return the second digital wallet institution identity certificate to the second digital wallet.

[0145] Step 704: Store the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and submit the second financial institution signature public key and the second digital wallet institution identity certificate to the blockchain identity management system.

[0146] Step 705: Receive a transaction request sent by the second digital wallet, where the transaction request carries the transaction amount, the second digital wallet distributed identity account number, and the second digital wallet transaction voucher.

[0147] Step 706: Obtain a second digital wallet registration public key from the blockchain identity management system through the second digital wallet distributed identity account, and use the second digital wallet registration public key to verify the second digital wallet transaction credential; if the verification is successful, match the second digital wallet account according to the first digital wallet distributed identity account.

[0148] Step 1: Two digital wallets, A and B, initiate a trusted anonymous transaction. The recipient, Digital Wallet B, sends the amount, the corresponding distributed identity account TX-DID_user_b (TX-DID acts as an anonymous account), and Sk_user_b's signature on the distributed identity account to Bank B. Bank B confirms the legitimacy of the recipient account.

[0149] Optionally, matching the second digital wallet account according to the second digital wallet distributed identity account includes: obtaining the second financial institution signature public key, the second digital wallet institution identity certificate, the second digital wallet issuance public key and the second digital wallet self-signed identity certificate from the blockchain identity management system through the second digital wallet distributed identity account, and verifying the second digital wallet institution identity certificate and the second digital wallet self-signed identity certificate; if the verification is successful, obtaining the binding relationship between the second digital wallet account and the second digital wallet distributed identity account from the blockchain identity management system, and comparing it with the binding relationship between the second digital wallet account and the second digital wallet distributed identity account obtained by the blockchain identity management system stored in the background; if they are the same, matching the second digital wallet account. Specifically, it can include the following steps:

[0150] 1) Verify that TX-DID_user_b belongs to digital wallet b: Use TX-DID_user_b to find the identity document TX-DID_Doc_user_b in the blockchain identity management system, retrieve its public key Pk_user_b, and verify the signature of TX-DID_user_b (proving that TX-DID_user_b belongs to digital wallet b).

[0151] 2) Verify digital wallet b's credentials Credential_b-b and Credential_B-b: Use its TX-DID_user_b to find the two identity credentials Credential_b-b and Credential_B-b in the blockchain identity management system, extract the public keys Pk_bank_B_veri and Pk_user_b_veri from the identity document TX-DID_Doc_user_b, and verify the signatures of Credential_B-b and Credential_b-b respectively. After verification, obtain the relationship between digital wallet b's original account WID-b and distributed identity account TX-DID_user_b, and compare it with the mapping relationship saved in Bank B's backend to confirm whether the mapping relationship is consistent.

[0152] Step 707: Generate a payment request, which carries the transaction amount and the second digital wallet distributed identity account number, and send the payment request to the first financial institution.

[0153] After confirming the association between the receiving account information, the receiving bank B generates a payment request. The payment request is sent to the payer bank A through the interconnection mechanism, and then to the terminal of digital wallet A through the payer bank A.

[0154] Step 708: Receive a transaction message returned by the first financial institution, where the transaction message includes the payment amount, the first digital wallet distributed identity account number, and the second digital wallet distributed identity account number.

[0155] After the payer's bank A confirms the identity of the payer's digital wallet a, it generates a transaction message. Payer's digital wallet a confirms the payment (using conventional methods such as entering a payment password). Bank A signs the transaction message and sends it to the payee's bank B via the interconnection system. The key information in the transaction message includes: the payer's distributed identity account number TX-DID_user_a (the payer's anonymous account number), the payment amount, the payer's bank code, the payee's distributed identity account number TX-DID (the payee's anonymous account number TX-DID_user_b), and the payee and payee's bank codes.

[0156] Step 709: Obtain the first financial institution's signature public key, the first digital wallet's institutional identity certificate, the first digital wallet's issuance public key, and the first digital wallet's self-signed identity certificate from the blockchain identity management system through the first digital wallet's distributed identity account, and verify the first digital wallet's institutional identity certificate and the first digital wallet's self-signed identity certificate; if the verification is successful, confirm the transaction.

[0157] After receiving the transaction message, beneficiary Bank B verifies the transaction signature (using the payer's bank's public key certificate, following the standard process). Using the payer's digital wallet a's distributed identity account, TX-DID_user_a, it obtains the payer's two identity credentials and corresponding public key from the blockchain identity management system. It then verifies the two identity credentials, thereby verifying the legitimacy of the payer's identity. Once verification is successful, the transaction is confirmed, and beneficiary Bank B adds the corresponding amount to its user b's corresponding WID-b account.

[0158] After the transaction is completed, the payer, Bank A, notifies the blockchain identity management system to update the relevant operation records. All operations of digital wallets A / B and payer and payee Banks A and B can be synchronized on the blockchain for subsequent risk analysis and auditing.

[0159] In addition, the specific implementation content of the method for processing account information in another reference embodiment of the present invention has been described in detail in the method for processing account information described above, so the repeated content will not be described again here.

[0160] Figure 8 Schematic diagram of the main process of a method for processing account information according to another embodiment of the present invention. As another embodiment of the present invention, Figure 8 As shown, the method for processing account information is applied to a first financial institution and may include:

[0161] Step 801: Generate a first financial institution registration public-private key pair and a first financial institution signature public-private key pair, submit the first financial institution registration public key to the blockchain identity management system, and receive the first financial institution distributed identity account returned by the blockchain identity management system.

[0162] like Figure 2 As shown, Bank A (the first financial institution) generates two pairs of keys, one pair is used to apply for a distributed identity account, namely Sk_bank_A_Regi / Pk_bank_A_Regi; the other pair is used to issue identity certificates to digital wallet users, namely Pk_bank_A_veri / SK_bank_A_sign.

[0163] Bank A submits its public key Sk_bank_A_Regi, used to generate a distributed identity account, to the blockchain identity management system. The blockchain identity management system generates Bank A's distributed identity account number TX-DID_bank_A and then sends the distributed identity account number to Bank A.

[0164] Step 802: Receive an identity credential issuance request sent by the first digital wallet, where the identity credential issuance request carries a binding relationship between the first digital wallet account and the first digital wallet distributed identity account.

[0165] like Figure 2 As shown, digital wallet a applies to bank A (i.e., the first financial institution) to which the account belongs to associate and bind the original real-name wallet account WID_a and the distributed identity account TX-DID_user_a.

[0166] Step 803: Use the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet institution identity certificate, and return the first digital wallet institution identity certificate to the first digital wallet.

[0167] Bank A first authenticates and verifies digital wallet a. After passing the authentication and verification (such as payment password, etc.), Bank A uses the private key SK_bank_A_sign to issue the identity certificate Credential_A-a (signing the correspondence between WID_a and TX-DID_user_a).

[0168] Step 804: Store the binding relationship between the first digital wallet account and the first digital wallet distributed identity account in the background, and submit the first financial institution signature public key and the first digital wallet institution identity certificate to the blockchain identity management system.

[0169] Bank A saves the mapping relationship between WID_a and TX-DID_user_a in the background server, and sends the signature public key Pk_bank_A_veri and the issued identity certificate Credential_A-a to the blockchain identity management system through a secure channel (encrypted and uploaded using the public key of the blockchain identity management system).

[0170] In addition, the specific implementation content of the method for processing account information in another embodiment of the present invention has been described in detail in the method for processing account information described above, so the repeated content will not be described again here.

[0171] Figure 9 Schematic diagram of the main process of a method for processing account information according to another embodiment of the present invention. As another embodiment of the present invention, Figure 9 As shown, the method for processing account information is applied to a first financial institution and may include:

[0172] Step 901: Generate a first financial institution registration public-private key pair and a first financial institution signature public-private key pair, submit the first financial institution registration public key to the blockchain identity management system, and receive the first financial institution distributed identity account returned by the blockchain identity management system.

[0173] Step 902: Receive an identity credential issuance request sent by the first digital wallet, where the identity credential issuance request carries a binding relationship between the first digital wallet account and the first digital wallet distributed identity account.

[0174] Step 903: Use the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet institution identity certificate, and return the first digital wallet institution identity certificate to the first digital wallet.

[0175] Step 904: Store the binding relationship between the first digital wallet account and the first digital wallet distributed identity account in the background, and submit the first financial institution signature public key and the first digital wallet institution identity certificate to the blockchain identity management system.

[0176] Step 905: Receive a payment request sent by the second financial institution, the payment request carrying the transaction amount and the second digital wallet distributed identity account number, and forward the payment request to the first digital wallet.

[0177] After confirming the association between the receiving account information, the receiving bank B (the second financial institution) generates a payment request. The payment request is sent to the payer bank A (the first financial institution) through the interconnection mechanism, and then to the terminal of digital wallet A through the payer bank A.

[0178] Step 906: Receive a payment response returned by the first digital wallet, where the payment response carries the first digital wallet distributed identity account and the first digital wallet transaction voucher.

[0179] Digital wallet (user) a chooses trusted anonymous payment. Digital wallet a carries the distributed identity account TX-DID_user_a (the account to be paid this time) and Sk_user_a's signature on TX-DID_user_a (as a transaction certificate) and sends it to its bank A.

[0180] Step 907: Obtain the first digital wallet registration public key from the blockchain identity management system through the first digital wallet distributed identity account, and use the first digital wallet registration public key to verify the first digital wallet transaction credential; if the verification is successful, match the first digital wallet account according to the first digital wallet distributed identity account.

[0181] Optionally, matching the first digital wallet account according to the first digital wallet distributed identity account includes: obtaining the first financial institution signature public key, the first digital wallet institution identity certificate, the first digital wallet issuance public key and the first digital wallet self-signed identity certificate from the blockchain identity management system through the first digital wallet distributed identity account, and verifying the first digital wallet institution identity certificate and the first digital wallet self-signed identity certificate; if the verification is successful, obtaining the binding relationship between the first digital wallet account and the first digital wallet distributed identity account from the blockchain identity management system, and comparing it with the binding relationship between the first digital wallet account and the first digital wallet distributed identity account obtained by the blockchain identity management system stored in the background; if they are the same, matching the first digital wallet account.

[0182] Payer Bank A confirms the legitimacy of the payment account. Specifically, the following steps may be included:

[0183] 1) Verify that TX-DID_user_a belongs to digital wallet a: Use TX-DID_user_a to find the identity document TX-DID_Doc_user_a in the blockchain identity management system, retrieve its public key Pk_user_a, and verify the signature of TX-DID_user_a (proving that TX-DID_user_a belongs to digital wallet a).

[0184] 2) Verify the credentials Credential_a-a and Credential_A-a of digital wallet a: Use its TX-DID_user_a to find the two identity credentials Credential_a-a and Credential_A-a in the blockchain identity management system, extract the public keys Pk_bank_A_veri and Pk_user_a_veri from the identity document TX-DID_Doc_user_a, and verify the signatures of Credential_A-a and Credential_a-a respectively. After verification, obtain the relationship between the original account WID-a of digital wallet a and the distributed identity account TX-DID_user_a, and compare it with the mapping relationship saved in the background of bank A to confirm whether the mapping relationship is consistent.

[0185] Step 908: Generate a transaction message including the payment amount, the first digital wallet distributed identity account, and the second digital wallet distributed identity account, and send the transaction message to the second financial institution.

[0186] After the payer's bank A confirms the identity of the payer's digital wallet a, it generates a transaction message. Payer's digital wallet a confirms the payment (using conventional methods such as entering a payment password). Bank A signs the transaction message and sends it to the payee's bank B via the interconnection system. The key information in the transaction message includes: the payer's distributed identity account number TX-DID_user_a (the payer's anonymous account number), the payment amount, the payer's bank code, the payee's distributed identity account number TX-DID (the payee's anonymous account number TX-DID_user_b), and the payee and payee's bank codes.

[0187] In addition, the specific implementation content of the method for processing account information in another reference embodiment of the present invention has been described in detail in the method for processing account information described above, so the repeated content will not be described again here.

[0188] Figure 10 FIG. 1 is a schematic diagram of the main flow of a method for processing account information according to another embodiment of the present invention. As another embodiment of the present invention, Figure 10 As shown, the method for processing account information is applied to a blockchain identity management system and may include:

[0189] Step 1001, respectively receiving the first digital wallet registration public key submitted by the first digital wallet, the second digital wallet registration public key submitted by the second digital wallet, the first financial institution registration public key submitted by the first financial institution, and the second financial institution registration public key submitted by the second financial institution.

[0190] Step 1002, respectively generate the first digital wallet distributed identity account and its identity document, the second digital wallet distributed identity account and its identity document, the first financial institution distributed identity account and its identity document, and the second financial institution distributed identity account and its identity document; wherein the identity document is used to store the binding relationship between the identity account and its public key.

[0191] Digital wallets a and b, and banks A and B, respectively, submit their public keys Pk_user_a_Pk_user_b, Pk_bank_A_Regi, and Pk_bank_B_Regi to the blockchain identity management system for applying for distributed identity accounts. The blockchain identity management system generates distributed identity accounts TX-DID_user_a / TX-DID_user_b, TX-DID_bank_A, and TX-DID_bank_B for each digital wallet and financial institution, as well as corresponding identity documents TX-DID_Doc_user_a, TX-DID_Doc_user_b, TX-DID_Doc_A, and TX-DID_Doc_B.

[0192] An identity document is a key-value database table. Each identity document records the binding relationship between each TX-DID and its public key, such as the relationship between digital wallet a's identity account TX-DID_user_a and digital wallet a's public key Pk_user_a. (When an identity certificate is issued for a TX-DID, the identity document is updated to store the binding relationship between the certificate issuer's verification public key and the identity certificate identifier.)

[0193] The blockchain identity management system issues respective TX-DID distributed identity accounts to digital wallets a and b and their account-owning banks A and B.

[0194] Step 1003: Receive the first financial institution signature public key and the first digital wallet institution identity certificate submitted by the first financial institution, and the second financial institution signature public key and the second digital wallet institution identity certificate submitted by the second financial institution respectively.

[0195] Step 1004: Store the first digital wallet institution identity certificate and the second digital wallet institution identity certificate, and write the binding relationship between the first digital wallet institution identity certificate identifier and the first financial institution signature public key into the first digital wallet identity document, and write the binding relationship between the second digital wallet institution identity certificate identifier and the second financial institution signature public key into the second digital wallet identity document.

[0196] Step 1005: Receive the first digital wallet issuance public key and the first digital wallet self-signed identity certificate submitted by the first digital wallet, and the second digital wallet issuance public key and the second digital wallet self-signed identity certificate submitted by the second digital wallet.

[0197] Step 1006: Store the first digital wallet self-signed identity certificate and the second digital wallet self-signed identity certificate, and write the binding relationship between the first digital wallet self-signed identity certificate identifier and the first digital wallet issuance public key into the first digital wallet identity document, and write the binding relationship between the second digital wallet self-signed identity certificate identifier and the second digital wallet issuance public key into the second digital wallet identity document.

[0198] Banks A and B securely upload the signature public keys Pk_bank_A_veri and Pk_bank_B_veri of the identity credentials, as well as the identity credentials Credential_A-a and Credential_B-b issued to digital wallets a and b respectively, to the blockchain identity management system (encrypted by the public key of the distributed identity management system); digital wallets a and b send the signature public keys Pk_user_a_veri, Pk_user_b_veri and their self-signed identity credentials Credential_a-a and Credential_b-b to the blockchain identity management system through a secure channel.

[0199] The blockchain identity management system updates the digital wallet's identity document, TX-DID_DOC. Based on the distributed identity account TX-DID_user_a of digital wallet a, the public keys Pk_user_a_veri and Pk_bank_A_veri, along with two identity credential identifiers, are written to its corresponding identity document, TX-DID_Doc_user_a. The system then performs the same operation for digital wallet b. The updated identity document is synchronized via the blockchain.

[0200] In addition, the specific implementation content of the method for processing account information in another embodiment of the present invention has been described in detail in the method for processing account information described above, so the details will not be repeated here.

[0201] The detailed steps and process of the transaction are as follows:

[0202] Phase 1: Identity account and identity document generation

[0203] Step 1: Each digital wallet, A, or B, generates two pairs of keys in a secure environment (a client security chip or a trusted execution environment). One pair is used to apply for a distributed identity account: Pk_user_a / Sk_user_a and Pk_user_b / Sk_user_b. The other pair is used to issue identity certificates to the wallet: Pk_user_a_veri and SK_user_a_sign, and Pk_user_b_veri and SK_user_b_sign. Banks A and B each generate two pairs of keys: one for applying for a distributed identity account: Sk_bank_A_Regi / Pk_bank_A_Regi and Sk_bank_B_Regi / Pk_bank_B_Regi. The other pair is used to issue identity certificates to the digital wallet: Pk_bank_A_veri / SK_bank_A_sign and Pk_bank_B_veri / SK_bank_B_sign.

[0204] Step 2: Digital wallets a and b, banks A and B submit their public keys Pk_user_a_Pk_user_b, Pk_bank_A_Regi, and Pk_bank_B_Regi, respectively, for generating distributed identity accounts to the blockchain identity management system.

[0205] Step 3: The blockchain identity management system generates distributed identity accounts TX-DID_user_a / TX-DID_user_b, TX-DID_bank_A and TX-DID_bank_B for each digital wallet and financial institution, as well as corresponding identity documents TX-DID_Doc_user_a, TX-DID_Doc_user_b, TX-DID_Doc_A, and TX-DID_Doc_B.

[0206] Step 4: The blockchain identity management system issues respective TX-DID distributed identity accounts to digital wallets a and b and their respective banks A and B.

[0207] Phase 2: Digital wallet identity credential generation and identity document update

[0208] Step 1: The paying and receiving banks verify the correspondence between the real-name wallet account and the anonymous distributed identity account in the digital wallet and issue an identity certificate. Digital wallet a applies to bank A, to which the account belongs, to associate and bind the original real-name wallet account WID_a with the distributed identity account TX-DID_user_a. After authentication and verification (such as a payment password), bank A uses its private key SK_bank_A_sign to issue a certificate, Credential_A-a (signing the correspondence between WID_a and TX-DID_user_a), and stores the mapping between WID_a and TX-DID_user_a on the backend server. Digital wallet b applies to bank B (i.e., the second financial institution) to which the account belongs to associate and bind the original real-name wallet account WID_b and the distributed identity account TX-DID_user_b. After authentication and verification (such as payment password, etc.), bank B uses the private key SK_bank_B_sign to issue the identity certificate Credential_B-b (signing the correspondence between WID_b and TX-DID_user_b) and saves the mapping relationship between WID_b and TX-DID_user_b in the background server.

[0209] Step 2: Digital wallets a and b self-sign the correspondence between the real-name wallet account and the anonymous distributed identity account. Digital wallet a uses the credential signature private key SK_user_a_sign stored in the secure area of ​​the wallet terminal to sign the correspondence between the original real-name wallet account WID_a and the distributed identity account TX-DID_user_a, generating the identity credential Credential_a-a (a has issued an identity credential to its own anonymous account). Digital wallet b performs the same operation to generate a self-signed credential Credential_b-b.

[0210] Step 3: Banks A and B securely upload the identity certificate signature public keys Pk_bank_A_veri and Pk_bank_B_veri, as well as the identity certificates Credential_A-a and Credential_B-b issued to digital wallets a and b respectively, to the blockchain identity management system (encrypted by the public key of the distributed identity management system); digital wallets a and b send the signature public keys Pk_user_a_veri, Pk_user_b_veri and their self-signed identity certificates Credential_a-a and Credential_b-b to the blockchain identity management system through a secure channel.

[0211] Step 4: The blockchain identity management system updates the digital wallet's identity document, TX-DID_DOC. Based on the distributed identity account TX-DID_user_a of digital wallet a, the public keys Pk_user_a_veri and Pk_bank_A_veri, along with two identity credential identifiers, are written to its corresponding identity document, TX-DID_Doc_user_a. The system then performs the same operation for digital wallet b. The updated identity document is synchronized via the blockchain.

[0212] Phase 3: Digital wallets conduct anonymous transactions based on distributed identity accounts

[0213] Step 1: Two digital wallets a and b initiate a trusted anonymous transaction. The recipient's digital wallet b sends the transaction amount, the distributed identity account TX-DID_user_b of digital wallet b (TX-DID is used as an anonymous account), and Sk_user_b's signature on the distributed identity account TX-DID_user_b of digital wallet b (as a transaction certificate) to the recipient bank B. The recipient bank B confirms the legitimacy of the recipient account:

[0214] 1) Verify that TX-DID_user_b belongs to digital wallet b: Use TX-DID_user_b to find the identity document TX-DID_Doc_user_b in the blockchain identity management system, retrieve its public key Pk_user_b, and verify the signature of TX-DID_user_b (proving that TX-DID_user_b belongs to digital wallet b).

[0215] 2) Verify digital wallet b's credentials Credential_b-b and Credential_B-b: Use its TX-DID_user_b to find the two identity credentials Credential_b-b and Credential_B-b in the blockchain identity management system, extract the public keys Pk_bank_B_veri and Pk_user_b_veri from the identity document TX-DID_Doc_user_b, and verify the signatures of Credential_B-b and Credential_b-b respectively. After verification, obtain the relationship between digital wallet b's original account WID-b and distributed identity account TX-DID_user_b, and compare it with the mapping relationship saved in Bank B's backend to confirm whether the mapping relationship is consistent.

[0216] Step 2: After confirming the association of the receiving account information, beneficiary bank B generates a payment request. The payment request is sent to payer bank A through the interconnection mechanism, and then to digital wallet A's terminal through payer bank A.

[0217] Step 3: Digital wallet (user) a selects trusted anonymous payment. Digital wallet a carries the distributed identity account TX-DID_user_a (the account to be paid this time) and Sk_user_a's signature on TX-DID_user_a (as a transaction voucher) and sends it to its bank A. Payer bank A confirms the legitimacy of the payment account:

[0218] 1) Verify that TX-DID_user_b belongs to digital wallet b: Use TX-DID_user_b to find the identity document TX-DID_Doc_user_b in the blockchain identity management system, retrieve its public key Pk_user_b, and verify the signature of TX-DID_user_b (proving that TX-DID_user_b belongs to digital wallet b).

[0219] 2) Verify digital wallet b's credentials Credential_b-b and Credential_B-b: Use its TX-DID_user_b to find the two identity credentials Credential_b-b and Credential_B-b in the blockchain identity management system, extract the public keys Pk_bank_B_veri and Pk_user_b_veri from the identity document TX-DID_Doc_user_b, and verify the signatures of Credential_B-b and Credential_b-b respectively. After verification, obtain the relationship between digital wallet b's original account WID-b and distributed identity account TX-DID_user_b, and compare it with the mapping relationship saved in Bank B's backend to confirm whether the mapping relationship is consistent.

[0220] Step 4: After the payer's bank A confirms the identity of the payer's digital wallet a, it generates a transaction message. Payer's digital wallet a confirms the payment (using conventional methods such as entering a payment password). Bank A signs the transaction message and sends it to the payee's bank B via the interconnection system. The main information in the transaction message includes: the payer's distributed identity account number TX-DID_user_a (payer's anonymous account number), the payment amount, the payer's bank code, the payee's distributed identity account number TX-DID (payee's anonymous account number TX-DID_user_b), and the payee and payee's bank codes.

[0221] Step 5: After receiving the transaction message, beneficiary Bank B verifies the transaction signature (using the payer's bank's public key certificate, following the standard process). Using the payer's digital wallet a's distributed identity account, TX-DID_user_a, it obtains the payer's two identity credentials and corresponding public key from the blockchain identity management system. The two identity credentials are then verified, thereby verifying the legitimacy of the payer's identity. Once verification is successful, the transaction is confirmed, and beneficiary Bank B adds the corresponding amount to its user b's corresponding WID-b account.

[0222] Step 6: Once the transaction is complete, payer Bank A notifies the blockchain identity management system to update the relevant operation records. All operations between digital wallets A / B and payer Banks A and B are synchronized on the blockchain for subsequent risk analysis and auditing.

[0223] Optionally, the user can update the anonymous account as appropriate, that is, generate a new anonymous account based on the original account. Taking the first digital wallet as an example, the first digital wallet sends an identity account change request to the blockchain identity management system, and the identity account change request carries the first digital wallet distributed identity account; receives the third digital wallet distributed identity account returned by the blockchain identity management system; generates a third digital wallet registration public and private key pair, and submits the third digital wallet registration public key to the blockchain identity management system; sends an identity certificate issuance request to the first financial institution, and the identity certificate issuance request carries the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, and receives the third digital wallet institution identity certificate issued by the first financial institution; uses the first digital wallet issuance private key to sign the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, obtains the third digital wallet self-signed identity certificate, and submits the third digital wallet self-signed identity certificate to the blockchain identity management system. The first financial institution receives an identity credential issuance request sent by the first digital wallet, where the identity credential issuance request carries a binding relationship between the first digital wallet account and the third digital wallet distributed identity account; uses the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, obtains a third digital wallet institution identity credential, and returns the third digital wallet institution identity credential to the first digital wallet; stores the binding relationship between the first digital wallet account and the third digital wallet distributed identity account in the background, and submits the third digital wallet institution identity credential to the blockchain identity management system.

[0224] The blockchain identity management system receives an identity account change request sent by the first digital wallet, the identity account change request carries the first digital wallet distributed identity account; hashes the first digital wallet identity document to generate a third digital wallet distributed identity account; returns the third digital wallet distributed identity account to the first digital wallet; receives the third digital wallet registration public key submitted by the first digital wallet; generates a third digital wallet identity document, and writes the third digital wallet registration public key into the third digital wallet identity document. Furthermore, the blockchain identity management system receives the third digital wallet institution identity certificate submitted by the first financial institution; stores the third digital wallet institution identity certificate, and writes the binding relationship between the third digital wallet institution identity certificate identifier and the first financial institution signing public key into the third digital wallet identity document; receives the third digital wallet self-signed identity certificate submitted by the first digital wallet; stores the third digital wallet self-signed identity certificate, and writes the binding relationship between the third digital wallet self-signed identity certificate identifier and the first digital wallet issuance public key into the third digital wallet identity document.

[0225] Next, the first digital wallet sends a self-signed identity credential revocation request to the blockchain identity association system, the self-signed identity credential revocation request carrying the self-signed identity credential of the first digital wallet; the first financial institution sends an institutional identity credential revocation request to the blockchain identity association system, the institutional identity credential revocation request carrying the institutional identity credential of the first digital wallet. The blockchain identity management system receives the self-signed identity credential revocation request sent by the first digital wallet, the self-signed identity credential of the first digital wallet, and cancels the self-signed identity credential of the first digital wallet; receives the institutional identity credential revocation request sent by the second financial institution, the institutional identity credential revocation request carrying the institutional identity credential of the first digital wallet, and cancels the institutional identity credential of the first digital wallet.

[0226] Assume that user a's first distributed identity account is TX-DID_user_a1, the key corresponding to the distributed identity account is Pk_user_a1 / Sk_user_a1, the two identity credentials are Credential_a-a1 and Credential_A-a1, and the corresponding identity document is TX-DID_Doc_user_a1. The detailed steps are as follows:

[0227] 1. Digital wallet a applies to update TX-DID as a transaction account: it uses the distributed identity account private key Sk_user_a1 of TX-DID_user_a1 (the first time) to sign. The blockchain identity management system finds its public key based on its identity account TX-DID_user_a1 and verifies its signature for the TX-DID change application.

[0228] 2. After the blockchain identity management system verifies the user's TX-DID change request, it hashes the existing distributed identity document TX-DID_Doc_user_a1 in digital wallet a to generate a new TX-DID_user_a2 and sends the new identity account to user wallet a.

[0229] 3. Digital wallet a generates a new key pair (Pk_user_a2 / Sk_user_a2) for associating the distributed identity, and submits the new distributed identity account public key Pk_user_a2 to the blockchain identity management system. The system generates a new distributed identity document TX-DID_Doc_user_a2 based on the public key and writes the user public key Pk_user_a2 into the document.

[0230] 4. Digital wallet a applies to its affiliated bank A to associate its original bank wallet account WID_a with the distributed identity identifier TX-DID_user_a2. After verification, the bank issues a new identity credential, Credential_A-a2, and stores the mapping between WID_a and the distributed identity account TX-DID_user_a2 on its backend server. The bank then stores the identity credential in the blockchain distributed identity system.

[0231] 5. Digital wallet a uses the certificate issuance private key SK_user_a_sign stored in the secure area of ​​the wallet terminal to sign the association between the original bank wallet account WID_a and the blockchain identity account TX-DID_user_a2, generating the certificate Credential_a-a2. The new identity certificate is uploaded and saved in the blockchain distributed identity system.

[0232] 6. The blockchain identity management system updates the identity document TX-DID_Doc_user_a2 of digital wallet a and saves the bank certificate signature public key Pk_bank_A_veri and the user self-signed public key Pk_user_a_veri in the identity document.

[0233] 7. After TX-DID_user_a2 takes effect, Digital Wallet A and Bank A apply to the blockchain identity management system to revoke the two identity credentials previously issued to TX-DID_user_a1. After verification, TX-DID_user_a1's identity credentials become invalid. The user can no longer use TX-DID_user_a1 as a transaction account (if TX-DID_user_a1 is used again, because the credentials have been cancelled and identity verification cannot be achieved, it cannot be used as a transaction account).

[0234] Figure 11 FIG is a schematic diagram of the main modules of an apparatus for processing account information according to an embodiment of the present invention. Figure 11 As shown, the device 1100 for processing account information is set in the first digital wallet, including a first generation module 1101, a first request module 1102 and a first issuance module 1103; wherein the first generation module 1101 is used to generate a first digital wallet registration public-private key pair and a first digital wallet issuance public-private key pair respectively; submit the first digital wallet registration public key to the blockchain identity management system, and receive the first digital wallet distributed identity account returned by the blockchain identity management system; the first request module 1102 is used to send an identity certificate issuance request to the first financial institution, the identity certificate issuance request carries the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, and receives the first digital wallet institution identity certificate issued by the first financial institution; the first issuance module 1103 is used to use the first digital wallet issuance private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet self-signed identity certificate, and submit the first digital wallet issuance public key and the first digital wallet self-signed identity certificate to the blockchain identity management system.

[0235] Optionally, the system further includes a first transaction module, configured to:

[0236] Receiving a payment request from the first financial institution, the payment request carrying a transaction amount and a second digital wallet distributed identity account number;

[0237] Sign the first digital wallet distributed identity account using the first digital wallet registration private key to obtain the first digital wallet transaction voucher;

[0238] Send a payment response to the first financial institution, where the payment response carries the first digital wallet distributed identity account number and the first digital wallet transaction credential.

[0239] Optionally, an account change module is also included, which is used to:

[0240] Sending an identity account change request to the blockchain identity management system, wherein the identity account change request carries the first digital wallet distributed identity account;

[0241] Receiving a third digital wallet distributed identity account number returned by the blockchain identity management system;

[0242] Generate a third digital wallet registration public and private key pair, and submit the third digital wallet registration public key to the blockchain identity management system;

[0243] Sending an identity credential issuance request to the first financial institution, the identity credential issuance request carrying the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, and receiving the third digital wallet institution identity credential issued by the first financial institution;

[0244] The first digital wallet is used to issue a private key to sign the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, obtain a third digital wallet self-signed identity certificate, and submit the third digital wallet self-signed identity certificate to the blockchain identity management system.

[0245] Optionally, the account change module is further configured to:

[0246] Send a self-signed identity certificate revocation request to the blockchain identity association system, where the self-signed identity certificate revocation request carries the first digital wallet self-signed identity certificate.

[0247] Figure 12 FIG is a schematic diagram of the main modules of an apparatus for processing account information according to another embodiment of the present invention. Figure 12 As shown, the device 1200 for processing account information is set in the second digital wallet, including a second generation module 1201, a second request module 1202, and a second issuance module 1203; wherein the second generation module 1201 is used to generate a second digital wallet registration public and private key pair and a second digital wallet issuance public and private key pair respectively; submit the second digital wallet registration public key to the blockchain identity management system, and receive the second digital wallet distributed identity account returned by the blockchain identity management system; the second request module 1202 is used to send an identity certificate issuance request to the second financial institution, the identity certificate issuance request carries the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and receives the second digital wallet institution identity certificate issued by the second financial institution; the second issuance module 1203 is used to use the second digital wallet issuance private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet self-signed identity certificate, and submit the second digital wallet issuance public key and the second digital wallet self-signed identity certificate to the blockchain identity management system.

[0248] Optionally, a second transaction module is further included, configured to:

[0249] Sign the second digital wallet distributed identity account using the second digital wallet registration private key to obtain a second digital wallet transaction voucher;

[0250] Send a transaction request to the second financial institution, where the transaction request carries the transaction amount, the second digital wallet distributed identity account number, and the second digital wallet transaction credential.

[0251] Figure 13 FIG. 1 is a schematic diagram of the main modules of an apparatus for processing account information according to another embodiment of the present invention. Figure 13 As shown, the device 1300 for processing account information is set in the first financial institution, including a third generation module 1301 and a third issuance module 1302; wherein the third generation module 1301 is used to generate a first financial institution registration public-private key pair and a first financial institution signature public-private key pair, submit the first financial institution registration public key to the blockchain identity management system, and receive the first financial institution distributed identity account returned by the blockchain identity management system; the third issuance module 1302 is used to receive an identity certificate issuance request sent by the first digital wallet, and the identity certificate issuance request carries the binding relationship between the first digital wallet account and the first digital wallet distributed identity account; use the first financial institution signature private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet institution identity certificate, and return the first digital wallet institution identity certificate to the first digital wallet; store the binding relationship between the first digital wallet account and the first digital wallet distributed identity account in the background, and submit the first financial institution signature public key and the first digital wallet institution identity certificate to the blockchain identity management system.

[0252] Optionally, the method further includes a first processing module, configured to:

[0253] Receiving a payment request from a second financial institution, the payment request carrying a transaction amount and a second digital wallet distributed identity account number;

[0254] The payment request is forwarded to the first digital wallet.

[0255] Optionally, the first processing module is further configured to:

[0256] Receive a payment response returned by the first digital wallet, the payment response carrying the first digital wallet distributed identity account and the first digital wallet transaction voucher;

[0257] Obtaining a first digital wallet registration public key from the blockchain identity management system through the first digital wallet distributed identity account, and using the first digital wallet registration public key to verify the first digital wallet transaction credential;

[0258] If the verification is successful, the first digital wallet account is matched according to the first digital wallet distributed identity account;

[0259] Generate a transaction message, the transaction message including the payment amount, the first digital wallet distributed identity account number, and the second digital wallet distributed identity account number, and send the transaction message to the second financial institution.

[0260] Optionally, the first processing module is further configured to:

[0261] Obtaining the first financial institution's signature public key, the first digital wallet's institutional identity certificate, the first digital wallet's issuance public key, and the first digital wallet's self-signed identity certificate from the blockchain identity management system through the first digital wallet's distributed identity account, and verifying the first digital wallet's institutional identity certificate and the first digital wallet's self-signed identity certificate;

[0262] If the verification is successful, the binding relationship between the first digital wallet account and the first digital wallet distributed identity account is obtained from the blockchain identity management system, and compared with the binding relationship between the first digital wallet account and the first digital wallet distributed identity account obtained by the blockchain identity management system stored in the background;

[0263] If they are the same, the first digital wallet account is matched.

[0264] Optionally, a credential change module is also included, which is used to:

[0265] Receive an identity credential issuance request from the first digital wallet, where the identity credential issuance request carries a binding relationship between the first digital wallet account and the third digital wallet distributed identity account;

[0266] Using the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, obtaining a third digital wallet institution identity certificate, and returning the third digital wallet institution identity certificate to the first digital wallet;

[0267] The binding relationship between the first digital wallet account and the third digital wallet distributed identity account is stored in the background, and the third digital wallet institutional identity certificate is submitted to the blockchain identity management system.

[0268] Optionally, the credential change module is further configured to:

[0269] Send an institutional identity certificate revocation request to the blockchain identity association system, where the institutional identity certificate revocation request carries the first digital wallet institutional identity certificate.

[0270] Figure 14 FIG is a schematic diagram of the main modules of an apparatus for processing account information according to another embodiment of the present invention. Figure 14 As shown, the device 1400 for processing account information is set in the second financial institution, including a fourth generation module 1401 and a fourth issuance module 1402; wherein the fourth generation module 1401 is used to generate a second financial institution registration public-private key pair and a second financial institution signature public-private key pair, submit the second financial institution registration public key to the blockchain identity management system, and receive the second financial institution distributed identity account returned by the blockchain identity management system; the fourth issuance module 1402 is used to receive an identity certificate issuance request sent by the second digital wallet, and the identity certificate issuance request carries the binding relationship between the second digital wallet account and the second digital wallet distributed identity account; use the second financial institution signature private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet institution identity certificate, and return the second digital wallet institution identity certificate to the second digital wallet; store the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and submit the second financial institution signature public key and the second digital wallet institution identity certificate to the blockchain identity management system.

[0271] Optionally, a second processing module is further included, configured to:

[0272] Receive a transaction request sent by the second digital wallet, the transaction request carrying the transaction amount, the second digital wallet distributed identity account number, and the second digital wallet transaction voucher;

[0273] Obtaining a second digital wallet registration public key from the blockchain identity management system through the second digital wallet distributed identity account, and using the second digital wallet registration public key to verify the second digital wallet transaction credential;

[0274] If the verification is successful, the second digital wallet account is matched based on the first digital wallet distributed identity account;

[0275] Generate a payment request, the payment request carrying the transaction amount and the second digital wallet distributed identity account number, and send the payment request to the first financial institution.

[0276] Optionally, the second processing module is further configured to:

[0277] Obtaining the second financial institution's signature public key, the second digital wallet's institutional identity certificate, the second digital wallet's issuance public key, and the second digital wallet's self-signed identity certificate from the blockchain identity management system through the second digital wallet's distributed identity account, and verifying the second digital wallet's institutional identity certificate and the second digital wallet's self-signed identity certificate;

[0278] If the verification is successful, the binding relationship between the second digital wallet account and the second digital wallet distributed identity account is obtained from the blockchain identity management system, and compared with the binding relationship between the second digital wallet account and the second digital wallet distributed identity account obtained by the blockchain identity management system stored in the background;

[0279] If they are the same, the second digital wallet account is matched.

[0280] Optionally, the second processing module is further configured to:

[0281] Receive a transaction message returned by the first financial institution, the transaction message including the payment amount, the first digital wallet distributed identity account number, and the second digital wallet distributed identity account number;

[0282] Obtaining the first financial institution's signature public key, the first digital wallet's institutional identity certificate, the first digital wallet's issuance public key, and the first digital wallet's self-signed identity certificate from the blockchain identity management system through the first digital wallet's distributed identity account, and verifying the first digital wallet's institutional identity certificate and the first digital wallet's self-signed identity certificate;

[0283] If the verification is successful, the transaction is confirmed.

[0284] Optionally, the second processing module is further configured to:

[0285] The transaction amount, the second digital wallet distributed identity account number, the payment amount and the first digital wallet distributed identity account number are synchronized to the blockchain identity management system.

[0286] Figure 15 FIG. 1 is a schematic diagram of the main modules of an apparatus for processing account information according to another embodiment of the present invention. Figure 15As shown, the device 1500 for processing account information is set in the blockchain management system, including a receiving module 1501 and an identity module 1502; wherein, the receiving module 1501 is used to respectively receive the first digital wallet registration public key submitted by the first digital wallet, the second digital wallet registration public key submitted by the second digital wallet, the first financial institution registration public key submitted by the first financial institution, and the second financial institution registration public key submitted by the second financial institution; the identity module 1502 is used to respectively generate the first digital wallet distributed identity account and its identity document, the second digital wallet distributed identity account and its identity document, the first financial institution distributed identity account and its identity document, and the second financial institution distributed identity account and its identity document; wherein, the identity document is used to store the binding relationship between the identity account and its public key.

[0287] Optionally, an update module is further included, configured to:

[0288] Receiving respectively the first financial institution signature public key and the first digital wallet institution identity certificate submitted by the first financial institution, and the second financial institution signature public key and the second digital wallet institution identity certificate submitted by the second financial institution;

[0289] Storing the first digital wallet institution identity credential and the second digital wallet institution identity credential, and writing the binding relationship between the first digital wallet institution identity credential identifier and the first financial institution's signature public key into the first digital wallet identity document, and writing the binding relationship between the second digital wallet institution identity credential identifier and the second financial institution's signature public key into the second digital wallet identity document;

[0290] Receiving respectively the first digital wallet issuance public key and the first digital wallet self-signed identity certificate submitted by the first digital wallet, and the second digital wallet issuance public key and the second digital wallet self-signed identity certificate submitted by the second digital wallet;

[0291] The first digital wallet self-signed identity credential and the second digital wallet self-signed identity credential are stored, and the binding relationship between the first digital wallet self-signed identity credential identifier and the first digital wallet issuance public key is written into the first digital wallet identity document, and the binding relationship between the second digital wallet self-signed identity credential identifier and the second digital wallet issuance public key is written into the second digital wallet identity document.

[0292] Optionally, the update module is further configured to:

[0293] receiving the third digital wallet institution identity certificate submitted by the first financial institution;

[0294] Storing the third digital wallet institution identity credential and writing the binding relationship between the third digital wallet institution identity credential identifier and the first financial institution signature public key into the third digital wallet identity document;

[0295] receiving a third digital wallet self-signed identity certificate submitted by the first digital wallet;

[0296] The third digital wallet self-signed identity certificate is stored, and the binding relationship between the third digital wallet self-signed identity certificate identifier and the first digital wallet issuance public key is written into the third digital wallet identity document.

[0297] Optionally, the update module is further configured to:

[0298] receiving a self-signed identity credential revocation request sent by the first digital wallet, wherein the self-signed identity credential revocation request carries the self-signed identity credential of the first digital wallet;

[0299] Cancel the self-signed identity certificate of the first digital wallet;

[0300] receiving an institution identity credential revocation request sent by the second financial institution, wherein the institution identity credential revocation request carries the first digital wallet institution identity credential;

[0301] Cancel the first digital wallet institution identity certificate.

[0302] It should be noted that the specific implementation content of the device for processing account information of the present invention has been described in detail in the method for processing account information described above, so the details will not be repeated here.

[0303] Figure 16 An exemplary system architecture 1600 is shown to which the method or apparatus for processing account information according to an embodiment of the present invention may be applied.

[0304] like Figure 16 As shown, system architecture 1600 may include terminal devices 1601, 1602, and 1603, a network 1604, and a server 1605. Network 1604 is used to provide a medium for communication links between terminal devices 1601, 1602, and 1603 and server 1605. Network 1604 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0305] Users can use terminal devices 1601, 1602, and 1603 to interact with server 1605 via network 1604 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 1601, 1602, and 1603, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0306] The terminal devices 1601 , 1602 , and 1603 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.

[0307] Server 1605 may be a server that provides various services, such as a backend management server (for example only) that supports shopping websites browsed by users using terminal devices 1601, 1602, and 1603. The backend management server may analyze and process received data such as item information query requests, and feed back the processing results to the terminal device.

[0308] It should be understood that Figure 16 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0309] Reference below Figure 17 , which shows a schematic structural diagram of a computer system 1700 of a terminal device suitable for implementing an embodiment of the present invention. Figure 17 The terminal device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0310] like Figure 17 As shown, computer system 1700 includes a central processing unit (CPU) 1701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1702 or a program loaded from a storage unit 1708 into a random access memory (RAM) 1703. Various programs and data required for the operation of system 1700 are also stored in RAM 1703. CPU 1701, ROM 1702, and RAM 1703 are connected to each other via a bus 1704. An input / output (I / O) interface 1705 is also connected to bus 1704.

[0311] The following components are connected to the I / O interface 1705: an input section 1706 including a keyboard, a mouse, and the like; an output section 1707 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and speakers; a storage section 1708 including a hard disk; and a communication section 1709 including a network interface card such as a LAN card or a modem. The communication section 1709 performs communication processing via a network such as the Internet. A drive 1710 is also connected to the I / O interface 1705 as needed. Removable media 1711, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 1710 as needed, so that computer programs read therefrom can be installed into the storage section 1708 as needed.

[0312] In particular, according to the embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present invention include a computer program comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1709, and / or installed from a removable medium 1711. When the computer program is executed by the central processing unit (CPU) 1701, the above-mentioned functions defined in the system of the present invention are performed.

[0313] It should be noted that the computer-readable medium described in the present invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media can include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. This propagated data signal can take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wireline, optical fiber cable, RF, or any suitable combination thereof.

[0314] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer programs according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0315] As another aspect, the present invention further provides a computer-readable medium, which may be included in the device described in the above embodiments, or may exist independently and not incorporated into the device. The computer-readable medium carries one or more programs, and when the one or more programs are executed by the device, the device implements the method described in any of the above embodiments.

[0316] As another aspect, an embodiment of the present invention further provides a computer program product, including a computer program, which implements the method described in any of the above embodiments when executed by a processor.

[0317] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for processing account information, characterized in that: Applied to the first digital wallet, including: Generate a first digital wallet registration public and private key pair and a first digital wallet issuance public and private key pair respectively; Submitting the first digital wallet registration public key to the blockchain identity management system, and receiving the first digital wallet distributed identity account number returned by the blockchain identity management system; Sending an identity certificate issuance request to the first financial institution, the identity certificate issuance request carrying the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, and receiving the first digital wallet institution identity certificate issued by the first financial institution; The first digital wallet is used to issue a private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet self-signed identity certificate, and submit the first digital wallet issuance public key and the first digital wallet self-signed identity certificate to the blockchain identity management system.

2. The method according to claim 1, characterized in that Also includes: Receiving a payment request from the first financial institution, the payment request carrying a transaction amount and a second digital wallet distributed identity account number; Sign the first digital wallet distributed identity account using the first digital wallet registration private key to obtain the first digital wallet transaction voucher; Send a payment response to the first financial institution, where the payment response carries the first digital wallet distributed identity account number and the first digital wallet transaction credential.

3. The method according to claim 1, characterized in that Also includes: Sending an identity account change request to the blockchain identity management system, wherein the identity account change request carries the first digital wallet distributed identity account; Receiving a third digital wallet distributed identity account number returned by the blockchain identity management system; Generate a third digital wallet registration public and private key pair, and submit the third digital wallet registration public key to the blockchain identity management system; Sending an identity credential issuance request to the first financial institution, the identity credential issuance request carrying the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, and receiving the third digital wallet institution identity credential issued by the first financial institution; The first digital wallet is used to issue a private key to sign the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, obtain a third digital wallet self-signed identity certificate, and submit the third digital wallet self-signed identity certificate to the blockchain identity management system.

4. The method according to claim 3, characterized in that Also includes: Send a self-signed identity certificate revocation request to the blockchain identity association system, where the self-signed identity certificate revocation request carries the first digital wallet self-signed identity certificate.

5. A method for processing account information, characterized in that: Applicable to the second digital wallet, including: Generate a second digital wallet registration public and private key pair and a second digital wallet issuance public and private key pair respectively; Submitting the second digital wallet registration public key to the blockchain identity management system and receiving the second digital wallet distributed identity account number returned by the blockchain identity management system; Send an identity certificate issuance request to the second financial institution, the identity certificate issuance request carrying the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and receive the second digital wallet institution identity certificate issued by the second financial institution; The second digital wallet issuance private key is used to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, to obtain the second digital wallet self-signed identity certificate, and the second digital wallet issuance public key and the second digital wallet self-signed identity certificate are submitted to the blockchain identity management system.

6. The method according to claim 5, characterized in that Also includes: Sign the second digital wallet distributed identity account using the second digital wallet registration private key to obtain a second digital wallet transaction voucher; Send a transaction request to the second financial institution, where the transaction request carries the transaction amount, the second digital wallet distributed identity account number, and the second digital wallet transaction credential.

7. A method for processing account information, characterized in that: Applied to first-tier financial institutions, including: Generate a first financial institution registration public-private key pair and a first financial institution signature public-private key pair, submit the first financial institution registration public key to the blockchain identity management system, and receive the first financial institution distributed identity account number returned by the blockchain identity management system; Receive an identity credential issuance request from the first digital wallet, where the identity credential issuance request carries a binding relationship between the first digital wallet account and the first digital wallet distributed identity account; Using the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtaining the first digital wallet institution identity certificate, and returning the first digital wallet institution identity certificate to the first digital wallet; The binding relationship between the first digital wallet account and the first digital wallet distributed identity account is stored in the background, and the first financial institution signature public key and the first digital wallet institution identity certificate are submitted to the blockchain identity management system.

8. The method according to claim 7, characterized in that Also includes: Receiving a payment request from a second financial institution, the payment request carrying a transaction amount and a second digital wallet distributed identity account number; The payment request is forwarded to the first digital wallet.

9. The method according to claim 8, characterized in that Also includes: Receive a payment response returned by the first digital wallet, the payment response carrying the first digital wallet distributed identity account and the first digital wallet transaction voucher; Obtaining a first digital wallet registration public key from the blockchain identity management system through the first digital wallet distributed identity account, and using the first digital wallet registration public key to verify the first digital wallet transaction credential; If the verification is successful, the first digital wallet account is matched according to the first digital wallet distributed identity account; Generate a transaction message, the transaction message including the payment amount, the first digital wallet distributed identity account number, and the second digital wallet distributed identity account number, and send the transaction message to the second financial institution.

10. The method according to claim 9, characterized in that Matching the first digital wallet account according to the first digital wallet distributed identity account includes: Obtaining the first financial institution's signature public key, the first digital wallet's institutional identity certificate, the first digital wallet's issuance public key, and the first digital wallet's self-signed identity certificate from the blockchain identity management system through the first digital wallet's distributed identity account, and verifying the first digital wallet's institutional identity certificate and the first digital wallet's self-signed identity certificate; If the verification is successful, the binding relationship between the first digital wallet account and the first digital wallet distributed identity account is obtained from the blockchain identity management system, and compared with the binding relationship between the first digital wallet account and the first digital wallet distributed identity account obtained by the blockchain identity management system stored in the background; If they are the same, the first digital wallet account is matched.

11. The method according to claim 7, characterized in that Also includes: Receive an identity credential issuance request from the first digital wallet, where the identity credential issuance request carries a binding relationship between the first digital wallet account and the third digital wallet distributed identity account; Using the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the third digital wallet distributed identity account, obtaining a third digital wallet institution identity certificate, and returning the third digital wallet institution identity certificate to the first digital wallet; The binding relationship between the first digital wallet account and the third digital wallet distributed identity account is stored in the background, and the third digital wallet institutional identity certificate is submitted to the blockchain identity management system.

12. The method according to claim 11, characterized in that Also includes: Send an institutional identity certificate revocation request to the blockchain identity association system, where the institutional identity certificate revocation request carries the first digital wallet institutional identity certificate.

13. A method for processing account information, characterized in that: Applicable to second financial institutions, including: Generate a second financial institution registration public-private key pair and a second financial institution signature public-private key pair, submit the second financial institution registration public key to the blockchain identity management system, and receive the second financial institution distributed identity account number returned by the blockchain identity management system; Receive an identity credential issuance request from the second digital wallet, the identity credential issuance request carrying a binding relationship between the second digital wallet account and the second digital wallet distributed identity account; Using the second financial institution's signature private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtaining the second digital wallet institution identity certificate, and returning the second digital wallet institution identity certificate to the second digital wallet; Store the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and submit the second financial institution signature public key and the second digital wallet institution identity certificate to the blockchain identity management system.

14. The method according to claim 13, characterized in that Also includes: Receive a transaction request sent by the second digital wallet, the transaction request carrying the transaction amount, the second digital wallet distributed identity account number, and the second digital wallet transaction voucher; Obtaining a second digital wallet registration public key from the blockchain identity management system through the second digital wallet distributed identity account, and using the second digital wallet registration public key to verify the second digital wallet transaction credential; If the verification is successful, the second digital wallet account is matched according to the second digital wallet distributed identity account; Generate a payment request, the payment request carrying the transaction amount and the second digital wallet distributed identity account number, and send the payment request to the first financial institution.

15. The method according to claim 14, characterized in that Matching the second digital wallet account according to the second digital wallet distributed identity account includes: Obtaining the second financial institution's signature public key, the second digital wallet's institutional identity certificate, the second digital wallet's issuance public key, and the second digital wallet's self-signed identity certificate from the blockchain identity management system through the second digital wallet's distributed identity account, and verifying the second digital wallet's institutional identity certificate and the second digital wallet's self-signed identity certificate; If the verification is successful, the binding relationship between the second digital wallet account and the second digital wallet distributed identity account is obtained from the blockchain identity management system, and compared with the binding relationship between the second digital wallet account and the second digital wallet distributed identity account obtained by the blockchain identity management system stored in the background; If they are the same, the second digital wallet account is matched.

16. The method according to claim 14, characterized in that Also includes: Receive a transaction message returned by the first financial institution, the transaction message including the payment amount, the first digital wallet distributed identity account number, and the second digital wallet distributed identity account number; Obtaining the first financial institution's signature public key, the first digital wallet's institutional identity certificate, the first digital wallet's issuance public key, and the first digital wallet's self-signed identity certificate from the blockchain identity management system through the first digital wallet's distributed identity account, and verifying the first digital wallet's institutional identity certificate and the first digital wallet's self-signed identity certificate; If the verification is successful, the transaction is confirmed.

17. The method according to claim 16, characterized in that Also includes: The transaction amount, the second digital wallet distributed identity account number, the payment amount and the first digital wallet distributed identity account number are synchronized to the blockchain identity management system.

18. A method for processing account information, characterized in that: Applied to blockchain identity management systems, including: Receiving respectively the first digital wallet registration public key submitted by the first digital wallet, the second digital wallet registration public key submitted by the second digital wallet, the first financial institution registration public key submitted by the first financial institution, and the second financial institution registration public key submitted by the second financial institution; Generate a first digital wallet distributed identity account and its identity document, a second digital wallet distributed identity account and its identity document, a first financial institution distributed identity account and its identity document, and a second financial institution distributed identity account and its identity document respectively; The identity document is used to store the binding relationship between the identity account and its public key.

19. The method according to claim 18, characterized in that Also includes: Receiving respectively the first financial institution signature public key and the first digital wallet institution identity certificate submitted by the first financial institution, and the second financial institution signature public key and the second digital wallet institution identity certificate submitted by the second financial institution; Storing the first digital wallet institution identity credential and the second digital wallet institution identity credential, and writing the binding relationship between the first digital wallet institution identity credential identifier and the first financial institution's signature public key into the first digital wallet identity document, and writing the binding relationship between the second digital wallet institution identity credential identifier and the second financial institution's signature public key into the second digital wallet identity document; Receiving respectively the first digital wallet issuance public key and the first digital wallet self-signed identity certificate submitted by the first digital wallet, and the second digital wallet issuance public key and the second digital wallet self-signed identity certificate submitted by the second digital wallet; The first digital wallet self-signed identity credential and the second digital wallet self-signed identity credential are stored, and the binding relationship between the first digital wallet self-signed identity credential identifier and the first digital wallet issuance public key is written into the first digital wallet identity document, and the binding relationship between the second digital wallet self-signed identity credential identifier and the second digital wallet issuance public key is written into the second digital wallet identity document.

20. The method according to claim 18, wherein Also includes: Receive an identity account change request sent by the first digital wallet, where the identity account change request carries the first digital wallet distributed identity account; Hash the first digital wallet identity document to generate a third digital wallet distributed identity account; Returning the third digital wallet distributed identity account to the first digital wallet; receiving a third digital wallet registration public key submitted by the first digital wallet; Generate a third digital wallet identity document, and write the third digital wallet registration public key into the third digital wallet identity document.

21. The method according to claim 20, characterized in that Also includes: receiving the third digital wallet institution identity certificate submitted by the first financial institution; Storing the third digital wallet institution identity credential and writing the binding relationship between the third digital wallet institution identity credential identifier and the first financial institution signature public key into the third digital wallet identity document; receiving a third digital wallet self-signed identity certificate submitted by the first digital wallet; The third digital wallet self-signed identity certificate is stored, and the binding relationship between the third digital wallet self-signed identity certificate identifier and the first digital wallet issuance public key is written into the third digital wallet identity document.

22. The method according to claim 21, characterized in that Also includes: receiving a self-signed identity credential revocation request sent by the first digital wallet, wherein the self-signed identity credential revocation request carries the self-signed identity credential of the first digital wallet; Cancel the self-signed identity certificate of the first digital wallet; receiving an institution identity credential revocation request sent by the second financial institution, wherein the institution identity credential revocation request carries the first digital wallet institution identity credential; Cancel the first digital wallet institution identity certificate.

23. A device for processing account information, characterized in that: Set in the first digital wallet, including: A first generation module is configured to generate a first digital wallet registration public-private key pair and a first digital wallet issuance public-private key pair, respectively; submit the first digital wallet registration public key to the blockchain identity management system, and receive the first digital wallet distributed identity account number returned by the blockchain identity management system; A first request module is configured to send an identity credential issuance request to a first financial institution, the identity credential issuance request carrying a binding relationship between a first digital wallet account and a first digital wallet distributed identity account, and receive a first digital wallet institution identity credential issued by the first financial institution; The first issuing module is used to use the first digital wallet to issue a private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet self-signed identity certificate, and submit the first digital wallet issuance public key and the first digital wallet self-signed identity certificate to the blockchain identity management system.

24. A device for processing account information, characterized in that: Set in the second digital wallet, including: The second generation module is used to generate a second digital wallet registration public and private key pair and a second digital wallet issuance public and private key pair respectively; submit the second digital wallet registration public key to the blockchain identity management system, and receive the second digital wallet distributed identity account number returned by the blockchain identity management system; A second request module is configured to send an identity credential issuance request to a second financial institution, the identity credential issuance request carrying a binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and receive a second digital wallet institution identity credential issued by the second financial institution; The second issuing module is used to use the second digital wallet to issue a private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet self-signed identity certificate, and submit the second digital wallet issuance public key and the second digital wallet self-signed identity certificate to the blockchain identity management system.

25. A device for processing account information, characterized in that: Set up in the first financial institution, including: A third generation module is configured to generate a first financial institution registration public-private key pair and a first financial institution signature public-private key pair, submit the first financial institution registration public key to the blockchain identity management system, and receive the first financial institution distributed identity account number returned by the blockchain identity management system; The third issuance module is used to receive an identity certificate issuance request sent by the first digital wallet, where the identity certificate issuance request carries the binding relationship between the first digital wallet account and the first digital wallet distributed identity account; use the first financial institution's signature private key to sign the binding relationship between the first digital wallet account and the first digital wallet distributed identity account, obtain the first digital wallet institution identity certificate, and return the first digital wallet institution identity certificate to the first digital wallet; store the binding relationship between the first digital wallet account and the first digital wallet distributed identity account in the background, and submit the first financial institution's signature public key and the first digital wallet institution identity certificate to the blockchain identity management system.

26. A device for processing account information, characterized in that: Set up in the second financial institution, including: A fourth generation module is configured to generate a second financial institution registration public-private key pair and a second financial institution signature public-private key pair, submit the second financial institution registration public key to the blockchain identity management system, and receive the second financial institution distributed identity account number returned by the blockchain identity management system; The fourth issuance module is used to receive an identity certificate issuance request sent by the second digital wallet, where the identity certificate issuance request carries the binding relationship between the second digital wallet account and the second digital wallet distributed identity account; use the second financial institution signature private key to sign the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, obtain the second digital wallet institution identity certificate, and return the second digital wallet institution identity certificate to the second digital wallet; store the binding relationship between the second digital wallet account and the second digital wallet distributed identity account, and submit the second financial institution signature public key and the second digital wallet institution identity certificate to the blockchain identity management system.

27. A device for processing account information, characterized in that: Set up in the blockchain identity management system, including: A receiving module, configured to respectively receive a first digital wallet registration public key submitted by the first digital wallet, a second digital wallet registration public key submitted by the second digital wallet, a first financial institution registration public key submitted by the first financial institution, and a second financial institution registration public key submitted by the second financial institution; The identity module is used to generate a first digital wallet distributed identity account and its identity document, a second digital wallet distributed identity account and its identity document, a first financial institution distributed identity account and its identity document, and a second financial institution distributed identity account and its identity document, respectively; wherein the identity document is used to store the binding relationship between the identity account and its public key.

28. An electronic device, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 22.

29. A computer-readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 22 is implemented.

30. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 22 is implemented.

Citation Information

Patent Citations

  • Identity management method based on digital wallet, computer equipment and storage medium

    CN114862388A

  • Virtual account based new digital cash protocols with combined blind digital signature and pseudonym authentication

    US20080243703A1