An identity authentication method and device in an offline transaction scenario

By generating a public-private key pair in a hard wallet and using a blockchain identity management system and an identity certificate issuing authority for dual authentication, the problem of transaction risks in offline transactions using hard wallets is solved, achieving a safer and more reliable transaction process.

CN119067667BActive Publication Date: 2025-10-17THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310651252.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-02
Publication Date
2025-10-17
Estimated Expiration
2043-06-02

AI Technical Summary

Technical Problem

In offline transaction scenarios, existing hard wallet transaction authentication methods cannot effectively guarantee the legitimacy of hard wallet terminal devices and applications, and there are hidden dangers of transaction risks and information leakage.

Method used

Generate a public and private key pair in the hard wallet, and generate and verify the identity and credentials of the hard wallet user and terminal through the blockchain identity management system and identity credential issuing agency, perform double trusted authentication, and ensure the legitimacy of both parties to the transaction.

Benefits of technology

It enhances the security and reliability of offline payment processes using hard wallets, ensures transaction security through multimodal authentication, and leverages blockchain technology to ensure that authentication relationships cannot be tampered with, supporting traceability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119067667B_ABST
    Figure CN119067667B_ABST
Patent Text Reader

Abstract

The application discloses an identity authentication method and device in an offline transaction scene, and relates to the technical field of digital wallets. A specific embodiment of the method comprises the following steps: identity certificate issuing requests are respectively sent to a hard wallet user identity certificate issuing agency and a hard wallet terminal identity certificate issuing agency; a hard wallet user identity certificate issued by the hard wallet user identity certificate issuing agency and a hard wallet terminal identity certificate issued by the hard wallet terminal identity certificate issuing agency are received; and identity authentication is performed based on the hard wallet user identity certificate and the hard wallet terminal identity certificate in an offline transaction scene. The embodiment can solve the technical problem of transaction risks.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of digital wallet, in particular to an identity authentication method and device in an offline transaction scenario. BACKGROUND

[0002] A digital hard wallet is generally based on a secure chip and the like to implement digital wallet related functions, and relies on an IC card, a mobile terminal, a wearable device, an Internet of Things device and the like to provide services for users. Supporting point-to-point offline transactions is a basic feature of a hard wallet. In a hard wallet transaction process, transaction authentication, message authentication and the like are usually performed based on signature and encryption and the like cryptographic techniques. However, these authentication methods only implement transaction process authentication at the message level, and if a transaction is performed with a non-legitimate hard wallet terminal, risks such as user fund loss and information leakage may occur, and the legitimacy of the hard wallet terminal device and the legitimacy of the hard wallet application on the hard wallet terminal cannot be guaranteed in the transaction process. SUMMARY

[0003] Therefore, the embodiments of the present application provide an identity authentication method and device in an offline transaction scenario to solve the technical problem of transaction risks.

[0004] To achieve the above object, according to one aspect of the embodiments of the present application, an identity authentication method in an offline transaction scenario is provided, applied to a hard wallet, comprising:

[0005] generating a first public-private key pair of a hard wallet user and a second public-private key pair of a hard wallet terminal in a secure chip respectively;

[0006] submitting the first public key of the hard wallet user and the second public key of the hard wallet terminal to a blockchain identity management system, and receiving a hard wallet user identity and a hard wallet terminal identity returned by the blockchain identity management system;

[0007] sending an identity certificate issuing request to a hard wallet user identity certificate issuing agency and a hard wallet terminal identity certificate issuing agency respectively, and receiving a hard wallet user identity certificate issued by the hard wallet user identity certificate issuing agency and a hard wallet terminal identity certificate issued by the hard wallet terminal identity certificate issuing agency;

[0008] In an offline transaction scenario, identity authentication is performed based on the hard wallet user identity certificate and the hard wallet terminal identity certificate.

[0009] In addition, according to another aspect of the embodiments of the present application, an identity authentication method in an offline transaction scenario is provided, applied to a hard wallet user identity certificate issuing agency, comprising:

[0010] generating a third public-private key pair, and submitting a third public key to a blockchain identity management system;

[0011] receiving a hard wallet user identity credential issuing agency identity returned by the blockchain identity management system;

[0012] receiving a hard wallet user identity credential issuing request sent by the hard wallet;

[0013] issuing a hard wallet user identity credential by using the third private key, and returning the hard wallet user identity credential to the hard wallet.

[0014] In addition, according to another aspect of the embodiment of the present application, a method for identity authentication in an offline transaction scenario is provided, which is applied to a hard wallet terminal identity credential issuing agency, and includes:

[0015] generating a fourth public-private key pair, and submitting a fourth public key to a blockchain identity management system;

[0016] receiving a hard wallet terminal identity credential issuing agency identity returned by the blockchain identity management system;

[0017] receiving a hard wallet terminal identity credential issuing request sent by the hard wallet;

[0018] issuing a hard wallet terminal identity credential by using the fourth private key, and returning the hard wallet terminal identity credential to the hard wallet.

[0019] In addition, according to another aspect of the embodiment of the present application, a method for identity authentication in an offline transaction scenario is provided, which is applied to a blockchain identity management system, and includes:

[0020] receiving a first public key of a hard wallet user and a second public key of a hard wallet terminal submitted by the hard wallet;

[0021] generating a hard wallet user identity and an identity document thereof, and a hard wallet terminal identity and an identity document thereof, and returning the hard wallet user identity and the hard wallet terminal identity to the hard wallet;

[0022] respectively receiving a third public key submitted by a hard wallet user identity credential issuing agency and a fourth public key submitted by a hard wallet terminal identity credential issuing agency;

[0023] respectively generating a hard wallet user identity credential issuing agency identity and an identity document thereof, and a hard wallet terminal identity credential issuing agency identity and an identity document thereof, and returning the hard wallet user identity credential issuing agency identity and the hard wallet terminal identity credential issuing agency identity to the hard wallet user identity credential issuing agency and the hard wallet terminal identity credential issuing agency respectively;

[0024] The identity document is used for storing a binding relationship between the identity and the public key.

[0025] In addition, according to another aspect of the embodiments of the present application, there is provided an identity authentication device in an offline transaction scenario, arranged in a hard wallet, comprising:

[0026] a wallet public key module, configured to generate a first public-private key pair of a hard wallet user and a second public-private key pair of a hard wallet terminal in a secure chip respectively;

[0027] a wallet identity module, configured to submit the first public key of the hard wallet user and the second public key of the hard wallet terminal to a blockchain identity management system, and receive a hard wallet user identity and a hard wallet terminal identity returned by the blockchain identity management system;

[0028] a wallet identity module, configured to respectively send an identity credential issuing request to a hard wallet user identity credential issuing agency and a hard wallet terminal identity credential issuing agency, and receive a hard wallet user identity credential issued by the hard wallet user identity credential issuing agency and a hard wallet terminal identity credential issued by the hard wallet terminal identity credential issuing agency;

[0029] an authentication module, configured to perform identity authentication based on the hard wallet user identity credential and the hard wallet terminal identity credential in an offline transaction scenario.

[0030] In addition, according to another aspect of the embodiments of the present application, there is provided an identity authentication device in an offline transaction scenario, arranged in a hard wallet user identity credential issuing agency, comprising:

[0031] a first generation module, configured to generate a third public-private key pair, submit a third public key to a blockchain identity management system, and receive a hard wallet user identity credential issuing agency identity returned by the blockchain identity management system;

[0032] a first issuing module, configured to receive a hard wallet user identity credential issuing request sent by a hard wallet, issue a hard wallet user identity credential by using a third private key, and return the hard wallet user identity credential to the hard wallet.

[0033] In addition, according to another aspect of the embodiments of the present application, there is provided an identity authentication device in an offline transaction scenario, arranged in a hard wallet terminal identity credential issuing agency, comprising:

[0034] a second generation module, configured to generate a fourth public-private key pair, submit a fourth public key to a blockchain identity management system, and receive a hard wallet terminal identity credential issuing agency identity returned by the blockchain identity management system;

[0035] a second issuing module, configured to receive a hard wallet terminal identity credential issuing request sent by a hard wallet, issue a hard wallet terminal identity credential by using a fourth private key, and return the hard wallet terminal identity credential to the hard wallet.

[0036] In addition, according to another aspect of the embodiments of the present application, there is provided an identity authentication device in an offline transaction scenario, arranged in a blockchain identity management system, comprising:

[0037] A third generation module is configured to receive a first public key of a hard wallet user and a second public key of a hard wallet terminal submitted by the hard wallet, and generate an identity of the hard wallet user and identity documents thereof, an identity of the hard wallet terminal and identity documents thereof, and return the identity of the hard wallet user and the identity of the hard wallet terminal to the hard wallet.

[0038] A fourth generation module is configured to receive a third public key submitted by a hard wallet user identity credential issuing authority and a fourth public key submitted by a hard wallet terminal identity credential issuing authority, and generate an identity of the hard wallet user identity credential issuing authority and identity documents thereof, an identity of the hard wallet terminal identity credential issuing authority and identity documents thereof, and return the identity of the hard wallet user identity credential issuing authority and the identity of the hard wallet terminal identity credential issuing authority to the hard wallet user identity credential issuing authority and the hard wallet terminal identity credential issuing authority, respectively; wherein the identity documents are used to store the binding relationship between the identity and the public key thereof.

[0039] According to another aspect of the embodiments of the present application, there is also provided an electronic device, comprising:

[0040] One or more processors;

[0041] A storage device is configured to store one or more programs,

[0042] When the one or more programs are executed by the one or more processors, the one or more processors implement the method of any of the above embodiments.

[0043] According to another aspect of the embodiments of the present application, there is also provided a computer readable medium having stored thereon a computer program, which, when executed by a processor, implements the method of any of the above embodiments.

[0044] According to another aspect of the embodiments of the present application, there is also provided a computer program product comprising a computer program, which, when executed by a processor, implements the method of any of the above embodiments.

[0045] An embodiment of the above application has the following advantages or beneficial effects: because the identity credential issuing request is sent to the hard wallet user identity credential issuing agency and the hard wallet terminal identity credential issuing agency respectively, the hard wallet user identity credential issued by the hard wallet user identity credential issuing agency and the hard wallet terminal identity credential issued by the hard wallet terminal identity credential issuing agency are received, and the identity authentication is performed based on the hard wallet user identity credential and the hard wallet terminal identity credential in the offline transaction scenario, the technical means of the prior art that has the technical problem of transaction risk is overcome. In the offline payment mode of the hard wallet, terminal authentication and application (user) authentication are introduced before transaction payment, and the security and reliability of the subsequent hard wallet offline payment process are enhanced through multi-modal authentication protection. Moreover, the blockchain technology is introduced to enhance the trusted authentication, the authentication relationship is ensured to be tamper-proof, and the authentication process can be stored and proved, so that the authentication behavior can be traced.

[0046] The further effects of the above non-conventional optional mode will be described below in conjunction with the specific embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed in the embodiments or the prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor. Among them:

[0048] Figure 1 is a schematic diagram of the main process of the identity authentication method in the offline transaction scenario according to an embodiment of the present application;

[0049] Figure 2 is a schematic diagram of the system architecture of the identity authentication method in the offline transaction scenario according to an embodiment of the present application;

[0050] Figure 3 is a schematic diagram of the main process of the identity authentication method in the offline transaction scenario according to a reference embodiment of the present application;

[0051] Figure 4 is a schematic diagram of the main process of the identity authentication method in the offline transaction scenario according to another embodiment of the present application;

[0052] Figure 5 is a schematic diagram of the main process of the identity authentication method in the offline transaction scenario according to another embodiment of the present application;

[0053] Figure 6is a schematic diagram of the main flow of the identity authentication method in the offline transaction scenario according to another embodiment of the present application;

[0054] Figure 7 is a schematic diagram of the main flow of the identity authentication method in the offline transaction scenario according to another embodiment of the present application;

[0055] Figure 8 is a schematic diagram of the main modules of the identity authentication device in the offline transaction scenario according to an embodiment of the present application;

[0056] Figure 9 is a schematic diagram of the main modules of the identity authentication device in the offline transaction scenario according to another embodiment of the present application;

[0057] Figure 10 is a schematic diagram of the main modules of the identity authentication device in the offline transaction scenario according to another embodiment of the present application;

[0058] Figure 11 is a schematic diagram of the main modules of the identity authentication device in the offline transaction scenario according to another embodiment of the present application;

[0059] Figure 12 is an exemplary system architecture diagram to which embodiments of the present application can be applied;

[0060] Figure 13 is a structural schematic diagram of a computer system of a terminal device or a server suitable for implementing embodiments of the present application. DETAILED DESCRIPTION

[0061] Exemplary embodiments of the present application are described below with reference to the accompanying drawings, which include various details of the embodiments of the present application to aid in understanding, and should be considered as merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present application. Also, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0062] Security and privacy protection are the key to the offline payment function of a digital terminal, and the premise of a secure transaction is that the transaction counterpart should first be a secure and trusted hardware wallet terminal and hardware wallet application. Therefore, the security of the hardware wallet offline point-to-point transaction needs to be guaranteed from multiple dimensions and multiple levels, especially the security authentication of the terminal device and the application.

[0063] In the embodiments of the present application, the roles and systems involved include: a hardware wallet application (an embedded application, that is, a hardware wallet user, installed in a hardware wallet terminal), a hardware wallet terminal (an Internet of Things device with a secure chip, such as a mobile phone), an identity certificate issuing authority (for example, for a mobile terminal, the terminal manufacturer is its identity certificate issuing authority), and a blockchain identity management system. The hardware wallet terminal is the carrier of the hardware wallet transaction, and is generally a related device with a secure chip, such as a mobile phone or other Internet of Things devices. The hardware wallet user holds the hardware wallet terminal and opens a hardware wallet account based on the hardware wallet application installed on the terminal, and can conduct offline transactions with other hardware wallet users. The identity certificate issuing authority includes a hardware wallet terminal identity certificate issuing authority and a hardware wallet application identity certificate issuing authority. The hardware wallet terminal identity certificate issuing authority is generally the production or operation authority of the hardware wallet terminal, such as a mobile terminal manufacturer or an Internet of Things device manufacturer. The hardware wallet user identity certificate issuing authority generally refers to an authority that issues certain identity proof attributes to users, such as an authority that issues identity cards, driver's licenses, and educational credentials to users. The blockchain identity management system mainly issues identity identifiers for various roles, creates and updates identity documents, etc.

[0064] Before the two hardware wallets conduct offline transactions, the embodiments of the present application first perform authentication of the hardware wallet terminal device, and then perform authentication of the hardware wallet application, thereby enhancing the security and reliability of the subsequent hardware wallet offline payment process through double trusted authentication.

[0065] For ease of understanding, in the embodiments of the present application, the following related parameters are defined:

[0066] HWID: an identity identifier issued by a blockchain management system. HWID_Device_d1 and HWID_Device_d2 represent the identity identifiers of the hardware wallet terminals d1 and d2; HWID_User_a1 and HWID_User_a2 represent the identity identifiers of the hardware wallet users a1 and a2; HWID_DeviceIssuer_D1 and HWID_DeviceIssuer_D2 represent the identity identifiers D1 and D2 of the hardware wallet terminal identity certificate issuing authorities; and HWID_UserIssuer_A1 and HWID_UserIssuer_A2 represent the identity identifiers A1 and A2 of the hardware wallet user identity certificate issuing authorities. Among them, the hardware wallet terminal of the hardware wallet user a1 is d1, the hardware wallet terminal identity certificate issuing authority D1 issues an identity certificate for the hardware wallet terminal d1, and the hardware wallet user identity certificate issuing authority A1 issues an identity certificate for the hardware wallet user a1. Among them, the hardware wallet terminal of the hardware wallet user a2 is d2, the hardware wallet terminal identity certificate issuing authority D2 issues an identity certificate for the hardware wallet terminal d2, and the hardware wallet user identity certificate issuing authority A2 issues an identity certificate for the hardware wallet user a2.

[0067] Pk_Device and Sk_Device: refer to the public and private keys of the hardware wallet terminal, which are generated in the secure chip of the hardware wallet terminal. Pk_Device_d1 / Sk_Device_d1 and Pk_Device_d2 / Sk_Device_d2 represent the public and private key pairs of hardware wallet terminals d1 and d2, respectively.

[0068] Pk_user and Sk_user: refer to the public and private keys of the hardware wallet user, which are generated in the secure chip of the hardware wallet terminal. Pk_user_a1 / Sk_user_a1 and Pk_user_a2 / Sk_user_a2 represent the public and private key pairs of hardware wallet users a1 and a2, respectively.

[0069] Pk_UserIssuer / Sk_UserIssuer and Pk_DeviceIssuer / Sk_DeviceIssuer: refer to the public and private keys of the hardware wallet user identity credential issuing agency and the hardware wallet terminal identity credential issuing agency, respectively. Pk_UserIssuer_A1 / Sk_UserIssuer_A1 and Pk_UserIssuer_A2 / Sk_UserIssuer_A2 represent the public and private key pairs of hardware wallet user identity credential issuing agencies A1 and A2, respectively. Pk_DeviceIssuer_D1 / Sk_DeviceIssuer_D1 and Pk_DeviceIssuer_D2 / Sk_DeviceIssuer_D2 represent the public and private key pairs of hardware wallet terminal identity credential issuing agencies D1 and D2, respectively.

[0070] HWID-DOC (Identity Document): In the blockchain identity management system, each HWID-DOC is a table of a Key-Value database, and the corresponding HWID-DOC can be found through the HWID. When the hardware wallet user, hardware wallet terminal, and identity credential issuing agency apply for a HWID, the blockchain identity management system will write the corresponding binding relationship information such as the HWID and the public key of the hardware wallet user, Pk_user_a1 and HWID_User_a1, Pk_Device_d1 and HWID_Device_D1, etc. in the identity document. The HWID-DOC is synchronized through the blockchain ledger to ensure its non-tamperability.

[0071] HWID-DOC update: after the hardware wallet terminal and the hardware wallet user add identity credentials, the blockchain identity management system updates the HWID-DOC identity document of the user, such as the identity credential issuing agency issuing a new identity credential Credential to the hardware wallet user a1, the HWID-DOC adds the identifier of the credential Credential, the identifier of the credential Credential and the verification relationship with the identity credential issuing agency public key, etc. After the update of the HWID-DOC identity document, the synchronization of the blockchain ledger is guaranteed to be tamper-proof.

[0072] Credential (identity credential): refers to the identity credential issued by the identity credential issuing agency, such as the hardware wallet user a submitting relevant information to the agency granting it certain identity attributes (physical certificate) and performing relevant verification (password / facial recognition / ID verification, etc.), and the identity credential issuing agency generates an electronic certificate and performs electronic signature, indicating that the user has these identity attributes.

[0073] Blockchain identity management system: a blockchain platform responsible for issuing trusted identity identifiers to various roles, creating and maintaining their identity documents. Identity credential issuing agencies, hardware wallets, etc. interact with the blockchain identity management system through a secure channel.

[0074] SEID: unique identifier of the secure chip SE, including chip manufacturer, chip type, card business, OS release date, etc.

[0075] Figure 1 is the main flowchart of the identity authentication method in the offline transaction scenario according to an embodiment of the present application. As an embodiment of the present application, as shown in Figure 1 , the identity authentication method in the offline transaction scenario is applied to a hardware wallet and can include:

[0076] Step 101: generating a first public-private key pair of the hardware wallet user and a second public-private key pair of the hardware wallet terminal in the secure chip respectively.

[0077] In the initialization phase (online phase), the hardware wallet user and the hardware wallet terminal generate their respective public-private key pairs, i.e. the first public-private key pair of the hardware wallet user and the second public-private key pair of the hardware wallet terminal.

[0078] In this step, the hardware wallet terminal and the hardware wallet user are initialized, and the hardware wallet and the hardware wallet user respectively generate a public-private key pair, wherein: the hardware wallet terminal d1 (d1 is a device manufactured by terminal manufacturer institution D1) and the hardware wallet terminal d2 (d2 is a device manufactured by terminal manufacturer institution D2) respectively generate a public-private key pair Pk_Device_d1 / Sk_Device_d1, Pk_Device_d2 / Sk_Device_d2 in the hardware wallet secure chip; the hardware wallet user a1 (holding the hardware wallet terminal d1) and the hardware wallet user a2 (holding the hardware wallet terminal d2) respectively generate a public-private key pair Pk_user_a1 / Sk_user_a1, Pk_user_a2 / Sk_user_a2 in the hardware wallet secure chip.

[0079] It should be noted that the hardware wallet can also submit the secure chip identifier SEID to the blockchain identity management system.

[0080] Step 102, submit the first public key of the hardware wallet user and the second public key of the hardware wallet terminal to the blockchain identity management system, and receive the hardware wallet user identity identifier and the hardware wallet terminal identity identifier returned by the blockchain identity management system.

[0081] As shown in Figure 2 After generating the public-private key pair, the hardware wallet submits the first public key of the hardware wallet user and the second public key of the hardware wallet terminal to the blockchain identity management system in a secure manner, and after the submission is successful, the hardware wallet user identity identifier and the hardware wallet terminal identity identifier returned by the blockchain identity management system are received.

[0082] In this step, the hardware wallet terminal and the hardware wallet user respectively submit the public keys Pk_Device_d1, Pk_Device_d2, Pk_user_a1, Pk_user_a2 to the blockchain identity management system, the blockchain identity management system generates the identity identifiers HWID_Device_d1, HWID_Device_d2, HWID_User_a1, HWID_User_a2, HWID of the above respective roles, and returns the identity identifiers to the respective roles respectively.

[0083] Step 103, send an identity certificate issuance request to the hardware wallet user identity certificate issuance institution and the hardware wallet terminal identity certificate issuance institution respectively, receive the hardware wallet user identity certificate issued by the hardware wallet user identity certificate issuance institution and the hardware wallet terminal identity certificate issued by the hardware wallet terminal identity certificate issuance institution.

[0084] As shown in Figure 2As shown, the hardware wallet terminal conducts identity verification with its identity credential issuing authority (usually mobile terminal and IoT device manufacturers), and after verification, the hardware wallet terminal identity credential issuing authority generates and signs the identity- verifiable credential for the hardware wallet terminal, and the signed identity credential is issued to the hardware wallet terminal and saved in the secure chip. The hardware wallet user applies for different identity credential proofs (such as driver's license, etc.) from its identity credential issuing authority, and the hardware wallet user identity credential issuing authority generates and signs the identity- verifiable credential, and the signed identity credential is issued to the hardware wallet user and saved in the secure chip of the hardware wallet terminal.

[0085] Optionally, the hardware wallet terminals d1 and d2 apply for their respective trusted identity credentials from the hardware wallet terminal identity credential issuing authorities D1 and D2 (usually terminal manufacturers) through the GP standard secure communication and authentication protocol SCP03 (a remote communication authentication protocol between secure chips and secure chip terminal manufacturers formulated by the international organization GP). The hardware wallet terminal identity credential issuing authorities D1 and D2 first verify that the hardware wallet terminals d1 and d2 are their respective production devices through the SCP02 protocol. Then, the hardware wallet terminal identity credential issuing authorities (terminal manufacturers) D1 and D2 generate the identity credentials Credential_DeviceIssuer_d1 and Credential_DeviceIssuer_d2 of the hardware wallet terminals according to the identity- verifiable credential template, and sign them using their private keys Sk_DeviceIssuer_D1 and Sk_DeviceIssuer_D2, indicating that the hardware wallet terminal devices have passed the authentication verification of the terminal manufacturers. Finally, the hardware wallet terminal identity credential issuing authorities D1 and D2 (terminal manufacturers) issue the identity credentials to the hardware wallet terminals d1 and d2, and the hardware wallet terminals d1 and d2 save the identity credentials in the secure chips of the terminals respectively.

[0086] Optionally, the hardware wallet user a1 brings the identity HWID_User_a1 and the corresponding SEID of the hardware wallet terminal to apply for identity verification from the hardware wallet user identity credential issuing authority A1 corresponding to its identity attribute, and after verification, obtains the identity- verifiable credential Credential_UserIssuer_a1 issued by the authority A1; the hardware wallet user a2 brings the identity HWID_User_a2 and the corresponding SEID of the hardware wallet terminal to apply for identity verification from the hardware wallet user identity credential issuing authority A2 corresponding to its identity attribute, and after verification, obtains the identity- verifiable credential Credential_UserIssuer_a2 issued by the authority A2.

[0087] Step 104, in the offline transaction scenario, identity authentication is conducted based on the hardware wallet user identity credential and the hardware wallet terminal identity credential.

[0088] In the offline transaction scenario, the two hardware wallet terminals interact through short-distance communication modes such as Bluetooth and NFC. Before the two hardware wallet terminals perform a transaction, the payee and the payer exchange the hardware wallet terminal identity credentials and the hardware wallet user identity credentials, and the two identity credentials are verified. After the double identity authentication is passed, log information is saved in the hardware wallet secure chip, and the two hardware wallet users enter the next step of offline transaction operation.

[0089] According to the various embodiments described above, it can be seen that the embodiments of the present application send an identity credential issuing request to a hardware wallet user identity credential issuing agency and a hardware wallet terminal identity credential issuing agency respectively, receive a hardware wallet user identity credential issued by the hardware wallet user identity credential issuing agency and a hardware wallet terminal identity credential issued by the hardware wallet terminal identity credential issuing agency, thereby performing identity authentication based on the hardware wallet user identity credential and the hardware wallet terminal identity credential in the offline transaction scenario, solving the technical problem of transaction risk existing in the prior art. The embodiments of the present application introduce terminal authentication and application (user) authentication before transaction payment in the offline payment mode of the hardware wallet, and enhance the security and reliability of the subsequent hardware wallet offline payment process through multi-modal authentication protection. Moreover, the embodiments of the present application introduce blockchain technology to enhance trusted authentication, ensure the non-tamperability of the authentication relationship, and enable the authentication behavior to be traceable by storing and proving the process of the authentication behavior.

[0090] Figure 3 is a schematic diagram of the main process of the identity authentication method in the offline transaction scenario according to a reference embodiment of the present application. As another embodiment of the present application, as shown in Figure 3 , the identity authentication method in the offline transaction scenario is applied to a hardware wallet and can include:

[0091] Step 301: generating a first public-private key pair of a hardware wallet user and a second public-private key pair of a hardware wallet terminal in a secure chip.

[0092] Step 302: submitting the first public key of the hardware wallet user and the second public key of the hardware wallet terminal to a blockchain identity management system, and receiving a hardware wallet user identity and a hardware wallet terminal identity returned by the blockchain identity management system.

[0093] Step 303: sending an identity credential issuing request to a hardware wallet user identity credential issuing agency and a hardware wallet terminal identity credential issuing agency respectively, and receiving a hardware wallet user identity credential issued by the hardware wallet user identity credential issuing agency and a hardware wallet terminal identity credential issued by the hardware wallet terminal identity credential issuing agency.

[0094] Step 304, receiving the third public key and the fourth public key issued by the blockchain identity management system.

[0095] The third public key is generated by the hard wallet user identity credential issuing agency and submitted to the blockchain identity management system; and the fourth public key is generated by the hard wallet terminal identity credential issuing agency and submitted to the blockchain identity management system.

[0096] In order to be able to verify the identity credential in the offline transaction scenario, the blockchain identity management system issues the public keys Pk_DeviceIssuer_D1, Pk_DeviceIssuer_D2, Pk_UserIssuer_A1, and Pk_UserIssuer_A2 of the identity credential issuing agencies D1, D2, A1, and A2 to all hard wallet terminals, and the hard wallet terminal can save the public keys in the hard wallet application or the secure chip.

[0097] Step 305, in the offline transaction scenario, identity authentication is performed based on the hard wallet user identity credential and the hard wallet terminal identity credential.

[0098] In the offline transaction scenario, two hard wallet terminals interact through short-distance communication methods such as Bluetooth and NFC. Before the two hard wallet terminals perform a transaction, the payee and the payer exchange hard wallet terminal identity credentials and hard wallet user identity credentials, and the two identity credentials are verified respectively.

[0099] Optionally, if the hard wallet is the payer, identity authentication is performed based on the hard wallet user identity credential and the hard wallet terminal identity credential, including: sending an identity authentication request to the payee hard wallet; receiving the hard wallet user identity credential and the hard wallet terminal identity returned by the payee hard wallet; performing identity authentication on the hard wallet user identity credential and the hard wallet terminal identity credential returned by the payee hard wallet based on the third public key and the fourth public key respectively; returning an authentication result to the payee hard wallet; receiving an identity authentication request sent by the payee hard wallet; returning the hard wallet user identity credential and the hard wallet terminal identity to the payee hard wallet; and receiving an authentication result returned by the payee hard wallet.

[0100] Before two hard wallets perform offline point-to-point transactions through wireless communication technologies such as NFC and Bluetooth (assuming that the hard wallet user a1 makes a payment to the hard wallet user a2), the two parties first perform trusted authentication of the terminal and the application, which can include the following steps:

[0101] First step: the hard wallet user a1 initiates an identity authentication request to a2, and a2 sends its user identity credential Credential_UserIssuer_a2 and the identity credential Credential_DeviceIssuer_d2 of the hard wallet terminal d2 to a1.

[0102] Second step: the hard wallet application calls the public key Pk_DeviceIssuer_D2 pre-installed on the hard wallet terminal to verify the signature of the terminal identity credential Credential_DeviceIssuer_d2. If the verification fails, the transaction is aborted, and the user a1 is prompted that the opposite party may be a non-trustworthy terminal. After the verification is passed, the public key Pk_UserIssuer_A2 pre-installed on the hard wallet terminal is called to verify the user identity credential Credential_UserIssuer_a2. If the verification fails, the transaction is aborted, and the user a1 is prompted that the opposite party may be a non-trustworthy hard wallet application. The hard wallet terminal d1 locally saves the operation log above.

[0103] Third step: after the hard wallet user a1 successfully verifies the identity credentials of the payee hard wallet terminal d2 and the application a2, the hard wallet user a2 initiates an authentication request to a1.

[0104] Fourth step: the hard wallet user a1 sends its user identity credential Credential_UserIssuer_a1 and the terminal identity credential Credential_DeviceIssuer_d1 of the hard wallet terminal d1 to a2.

[0105] Fifth step: the hard wallet application calls the public key Pk_DeviceIssuer_D1 pre-installed on the hard wallet terminal to verify the signature of the terminal identity credential Credential_DeviceIssuer_d1. If the verification fails, the transaction is aborted, and the user a2 is prompted that the opposite party may be a non-trustworthy terminal. After the verification is passed, the public key Pk_UserIssuer_A1 pre-installed on the hard wallet terminal is called to verify the user identity credential Credential_UserIssuer_a1. If the verification fails, the transaction is aborted, and the user a2 is prompted that the opposite party may be a non-trustworthy hard wallet application. The hard wallet terminal d2 locally saves the operation log above.

[0106] Sixth step: after a1 / a2, d1 / d2 respectively verify their identity credentials, the subsequent transaction payment process can be entered.

[0107] Optionally, if the hard wallet is a payee, identity authentication is performed based on the hard wallet user identity credential and the hard wallet terminal identity credential, including: receiving an identity authentication request sent by a payer hard wallet; returning the hard wallet user identity credential and the hard wallet terminal identity to the payer hard wallet; receiving an authentication result returned by the payer hard wallet; sending an identity authentication request to the payer hard wallet; receiving the hard wallet user identity credential and the hard wallet terminal identity returned by the payer hard wallet; performing identity authentication on the hard wallet user identity credential and the hard wallet terminal identity returned by the payer hard wallet based on the third public key and the fourth public key respectively; and returning an authentication result to the payer hard wallet. Similar to the above process, details are not repeated here.

[0108] Step 306: In the case of restoring networking, the operation log in the identity authentication process is reported to the blockchain identity management system.

[0109] When networking is restored, the hard wallet terminals d1 and d2 upload the operation log to the blockchain identity management system, which can be used as a reference basis for subsequent security audit and risk traceability.

[0110] In addition, the specific implementation content of the identity authentication method in the offline transaction scenario in one of the embodiments of the present application has been described in detail in the identity authentication method in the offline transaction scenario described above, and therefore repeated content is not described here.

[0111] Figure 4 is a schematic diagram of the main process of the identity authentication method in the offline transaction scenario according to another embodiment of the present application. As another embodiment of the present application, as shown in Figure 4 the identity authentication method in the offline transaction scenario is applied to a hard wallet user identity credential issuing agency, and can include:

[0112] Step 401: generating a third public-private key pair and submitting the third public key to the blockchain identity management system.

[0113] As shown in Figure 2 the hard wallet user identity credential issuing agencies A1 and A2 respectively generate public-private key pairs Pk_UserIssuer_A1 / Sk_UserIssuer_A1 and Pk_UserIssuer_A2 / Sk_UserIssuer_A2 in a secure server environment, and then submit their respective public keys Pk_UserIssuer_A1 and Pk_UserIssuer_A2 to the blockchain identity management system.

[0114] Step 402: receiving the hard wallet user identity credential issuing agency identity returned by the blockchain identity management system.

[0115] The blockchain identity management system generates the identity identifiers HWID_UserIssuer_A1 and HWID_UserIssuer_A2 of the above institutions and returns the identity identifiers to each institution respectively.

[0116] Step 403: Receive a hard wallet user identity credential issuance request sent by the hard wallet.

[0117] Step 404: Use the third private key to issue a hard wallet user identity certificate, and return the hard wallet user identity certificate to the hard wallet.

[0118] like Figure 2 As shown, the hard wallet user applies for different identity credentials (such as a driver's license, etc.) from his or her identity credential issuing agency. The hard wallet user's identity credential issuing agency generates a credential that can verify the identity and signs it. The signed identity credential is issued to the hard wallet user and stored in the security chip of the hard wallet terminal.

[0119] Optionally, hard wallet user a1 brings the identity identifier HWID_User_a1 and the SEID of the corresponding hard wallet terminal, and applies for identity verification to the hard wallet user identity certificate issuing agency A1 corresponding to a certain identity attribute of the user. After the verification is passed, the user obtains the verifiable identity certificate Credential_UserIssuer_a1 issued by agency A1; hard wallet user a2 brings the identity identifier HWID_User_a2 and the SEID of the corresponding hard wallet terminal, and applies for identity verification to the hard wallet user identity certificate issuing agency A2 corresponding to a certain identity attribute of the user. After the verification is passed, the user obtains the verifiable identity certificate Credential_UserIssuer_a2 issued by agency A2.

[0120] Optionally, after step 404, the method further includes: submitting the hard wallet user identity credential to the blockchain identity management system. After receiving the hard wallet user identity credential, the blockchain identity management system stores the identity credential and updates the hard wallet user identity credential to the corresponding identity document.

[0121] In addition, the specific implementation content of the identity authentication method in an offline transaction scenario in another embodiment of the present invention has been described in detail in the identity authentication method in the offline transaction scenario described above, so the repeated content will not be described again here.

[0122] Figure 5 Schematic diagram of the main process of the identity authentication method in an offline transaction scenario according to another embodiment of the present invention. As another embodiment of the present invention, Figure 5 As shown, the identity authentication method in the offline transaction scenario is applied to the hard wallet terminal identity certificate issuing agency and may include:

[0123] Step 501, generate a fourth public-private key pair, and submit the fourth public key to the blockchain identity management system.

[0124] As shown in Figure 2 The hardware wallet terminal identity credential issuing agencies D1 and D2 respectively generate public-private key pairs Pk_DeviceIssuer_D1 / SK_DeviceIssuer_D1 and Pk_DeviceIssuer_D2 / SK_DeviceIssuer_D2 in a secure server environment, and then submit their respective public keys Pk_DeviceIssuer_D1 and Pk_DeviceIssuer_D2 to the blockchain identity management system.

[0125] Step 502, receive the hardware wallet terminal identity credential issuing agency identity returned by the blockchain identity management system.

[0126] The blockchain identity management system generates the identities HWID_DeviceIssuer_D1 and HWID_DeviceIssuer_D2 of the above agencies, and returns the identities to the respective agencies.

[0127] Step 503, receive the hardware wallet terminal identity credential issuing request sent by the hardware wallet.

[0128] Step 504, issue a hardware wallet terminal identity credential using the fourth private key, and return the hardware wallet terminal identity credential to the hardware wallet.

[0129] As shown in Figure 2 The hardware wallet terminal conducts identity verification with its identity credential issuing agency (usually the mobile terminal and Internet of Things device manufacturer), and after the verification is passed, the hardware wallet terminal identity credential issuing agency generates a verifiable identity credential for it and signs it. The signed identity credential is issued to the hardware wallet terminal and saved in the secure chip.

[0130] Optionally, the hardware wallet terminals d1 and d2 apply for their respective trusted identity credentials from the hardware wallet terminal identity credential issuing agencies D1 and D2 (generally terminal manufacturers) through the GP standard secure communication and authentication protocol SCP03 (an international organization GP formulated secure chip and secure chip terminal manufacturer remote communication authentication protocol), and the hardware wallet terminal identity credential issuing agencies D1 and D2 first verify that the hardware wallet terminals d1 and d2 are the devices produced by them through the SCP02 protocol. Then, the hardware wallet terminal identity credential issuing agencies (terminal manufacturers) D1 and D2 generate the identity credentials Credential_DeviceIssuer_d1 and Credential_DeviceIssuer_d2 of the hardware wallet terminals according to the verifiable identity credential template, and sign them using their private keys Sk_DeviceIssuer_D1 and Sk_DeviceIssuer_D2 to indicate that the hardware wallet terminal devices have been verified and authenticated by the terminal manufacturers. Finally, the hardware wallet terminal identity credential issuing agencies D1 and D2 (terminal manufacturers) issue the identity credentials to the hardware wallet terminals d1 and d2, and the hardware wallet terminals d1 and d2 save the identity credentials in the respective secure chips of the terminals.

[0131] Optionally, after step 504, further comprising: submitting the hardware wallet terminal identity credential to the blockchain identity management system. After receiving the hardware wallet terminal identity credential, the blockchain identity management system stores the identity credential and updates the hardware wallet terminal identity credential to the corresponding identity document.

[0132] In addition, in another embodiment of the application, the specific implementation of the identity authentication method in the offline transaction scenario has been described in detail in the above-mentioned identity authentication method in the offline transaction scenario, and therefore the repeated content will not be described here.

[0133] Figure 6 is a schematic diagram of the main process of the identity authentication method in the offline transaction scenario according to another embodiment of the application. As shown in Figure 6 the identity authentication method in the offline transaction scenario is applied to the blockchain identity management system and can include:

[0134] Step 601: receiving the first public key of the hardware wallet user and the second public key of the hardware wallet terminal submitted by the hardware wallet.

[0135] Step 602: generating the identity of the hardware wallet user and the identity document thereof, and the identity of the hardware wallet terminal and the identity document thereof, and returning the identity of the hardware wallet user and the identity of the hardware wallet terminal to the hardware wallet; wherein the identity document is used to store the binding relationship between the identity and the public key thereof.

[0136] Step 603, respectively receiving the third public key submitted by the hardware wallet user identity credential issuing institution and the fourth public key submitted by the hardware wallet terminal identity credential issuing institution;

[0137] Step 604, respectively generating the identity identification of the hardware wallet user identity credential issuing institution and the identity document thereof, the identity identification of the hardware wallet terminal identity credential issuing institution and the identity document thereof, and returning the identity identification of the hardware wallet user identity credential issuing institution and the identity identification of the hardware wallet terminal identity credential issuing institution to the hardware wallet user identity credential issuing institution and the hardware wallet terminal identity credential issuing institution respectively; wherein the identity document is used to store the binding relationship between the identity identification and the public key thereof.

[0138] As described above, each role and each institution submits its own public key Pk_Device_d1, Pk_Device_d2, Pk_user_a1, Pk_user_a2, Pk_DeviceIssuer_D1, Pk_DeviceIssuer_D2, Pk_UserIssuer_A1, Pk_UserIssuer_A2 to the blockchain identity management system. After the blockchain identity management system receives the public keys of each role and each institution, it generates the identity identification HWID_Device_d1, HWID_Device_d2, HWID_User_a1, HWID_User_a2, HWID_DeviceIssuer_D1, HWID_DeviceIssuer_D2, HWID_UserIssuer_A1, HWID_UserIssuer_A2 for each role and each institution respectively.

[0139] At the same time, the blockchain identity management system generates the identity document of the hardware wallet terminal, the hardware wallet user, and the identity credential issuing institution, HWID-DOC_User_a1, HWID-DOC_User_a2, HWID-DOC_Device_d1, HWID-DOC_Device_d2, HWID-DOC_UserIssuer_A1, HWID-DOC_UserIssuer_A2, HWID-DOC_DeviceIssuer_D1, HWID-DOC_DeviceIssuer_D2 respectively.

[0140] The identity document is a key-value pair database table, each identity document records the binding relationship of each identity and its public key and other attributes, including: the binding relationship of the identity of the hardware wallet terminal d1 / d2 and its public key, the binding relationship of the identity of the hardware wallet terminal d1 / d2 and the SEID; the binding relationship of the identity of the hardware wallet user a1 / a2 and its public key; the binding relationship of the identity of the hardware wallet terminal identity certificate issuing agency D1 / D2 and its public key; and the binding relationship of the identity of the hardware wallet user identity certificate issuing agency A1 / A2 and its public key.

[0141] Then, the blockchain identity management system issues the respective identity of the hardware wallet terminal, the hardware wallet user and the identity certificate issuing agency to the hardware wallet terminal, the hardware wallet user and the identity certificate issuing agency; at the same time, the respective identity document is automatically synchronized through the blockchain, so that the identity document is tamper-proof.

[0142] It should be pointed out that the embodiment of the application only exemplarily shows the order of the steps, but the execution order of the step 601 and the step 603 is not limited.

[0143] In addition, the specific implementation content of the identity authentication method in the offline transaction scenario in another embodiment of the application has been described in detail in the above identity authentication method in the offline transaction scenario, and therefore the repeated content will not be described here.

[0144] Figure 7 It is the main flow diagram of the identity authentication method in the offline transaction scenario according to another reference embodiment of the application. As another embodiment of the application, as shown in Figure 7 The identity authentication method in the offline transaction scenario is applied to a blockchain identity management system and can include:

[0145] Step 701, receiving the first public key of the hardware wallet user and the second public key of the hardware wallet terminal submitted by the hardware wallet.

[0146] Step 702, generating the identity of the hardware wallet user and its identity document, the identity of the hardware wallet terminal and its identity document, and returning the identity of the hardware wallet user and the identity of the hardware wallet terminal to the hardware wallet.

[0147] Step 703, respectively receiving the third public key submitted by the hardware wallet user identity certificate issuing agency and the fourth public key submitted by the hardware wallet terminal identity certificate issuing agency.

[0148] Step 704, respectively generate the hard wallet user identity credential issuing agency identity and its identity document, the hard wallet terminal identity credential issuing agency identity and its identity document, return the hard wallet user identity credential issuing agency identity and the hard wallet terminal identity credential issuing agency identity to the hard wallet user identity credential issuing agency and the hard wallet terminal identity credential issuing agency respectively.

[0149] Step 705, receive the hard wallet user identity credential submitted by the hard wallet user identity credential issuing agency.

[0150] Step 706, store the hard wallet user identity credential, and write the binding relationship between the hard wallet user identity credential and the third public key into the hard wallet user identity document.

[0151] Step 707, receive the hard wallet terminal identity credential submitted by the hard wallet terminal identity credential issuing agency.

[0152] Step 708, store the hard wallet terminal identity credential, and write the binding relationship between the hard wallet terminal identity credential and the fourth public key into the hard wallet user identity document.

[0153] Step 709, issue the third public key and the fourth public key to the hard wallet.

[0154] The hard wallet user applies for different identity credential certificates (such as driver's license, etc.) to its identity credential issuing agency, the hard wallet user identity credential issuing agency generates a verifiable identity credential and signs it, the signed identity credential is issued to the hard wallet user and saved in the secure chip of the hard wallet terminal. The hard wallet terminal performs identity verification to its identity credential issuing agency (generally the mobile terminal and Internet of Things device manufacturer), and after the verification is passed, the hard wallet terminal identity credential issuing agency generates a verifiable identity credential and signs it, and the signed identity credential is issued to the hard wallet terminal and saved in the secure chip.

[0155] After the identity credential is issued, the hard wallet terminal identity credential issuing agency and the hard wallet user identity credential issuing agency D1, D2, A1, A2 respectively interact with the blockchain identity management system, the blockchain identity management system performs the hard wallet terminal d1 and d2 identity document update work, and performs the hard wallet application a1, a2 identity document update work. Among them:

[0156] For the hard wallet terminal d1, the identity document update work is to write the binding relationship between the verification public key Pk_DeviceIssuer_1 of the hard wallet terminal identity credential issuing agency D1 and the identity credential into the identity document; for the hard wallet terminal d2, the same operation is performed;

[0157] For the hard wallet user a1, the identity document updating work is to write the binding relationship between the verification public key Pk_UserIssuer_1 of the hard wallet user identity credential issuing agency A1 and the identity credential into the identity document; for the hard wallet user a2, the same operation is performed;

[0158] The updated identity document is synchronously updated through the blockchain system.

[0159] Finally, the public keys Pk_DeviceIssuer_D1, Pk_DeviceIssuer_D2, Pk_UserIssuer_A1 and Pk_UserIssuer_A2 of the identity credential issuing agencies D1, D2, A1 and A2 are issued by the blockchain identity management system and preloaded on all hard wallet terminals, which can be saved in the hard wallet application or the secure chip.

[0160] In addition, the detailed implementation of the identity authentication method in the offline transaction scenario in another embodiment of the present application has been described in detail in the identity authentication method in the offline transaction scenario described above, and therefore the repeated content will not be described here.

[0161] As an embodiment of the present application, the detailed steps of the identity authentication method in the offline transaction scenario of the embodiment of the present application are as follows:

[0162] First stage: hard wallet terminal and hard wallet identity generation and identity document generation

[0163] First step: initialization of the hard wallet terminal and the hard wallet user, the hard wallet terminal, the hard wallet user and the identity credential issuing agency each generate a public-private key pair, wherein:

[0164] 1). The hard wallet terminal d1 (d1 is a device manufactured by the terminal manufacturer agency D1) and the hard wallet terminal d2 (d2 is a device manufactured by the terminal manufacturer agency D2) each generate a public-private key pair Pk_Device_d1 / Sk_Device_d1, Pk_Device_d2 / Sk_Device_d2 in the hard wallet secure chip;

[0165] 2). The hard wallet user a1 (holding the hard wallet d1), the user a2 (holding the hard wallet d2) each generate a public-private key pair Pk_user_a1 / Sk_user_a1, Pk_user_a2 / Sk_user_a2 in the hard wallet secure chip;

[0166] 3). The hard wallet terminal identity credential issuing agencies D1 and D2 respectively generate public and private key pairs Pk_DeviceIssuer_D1 / SK_DeviceIssuer_D1 and Pk_DeviceIssuer_D2 / SK_DeviceIssuer_D2 in a secure server environment;

[0167] 4). The hard wallet user identity credential issuing agencies A1 and A2 respectively generate public and private key pairs Pk_UserIssuer_A1 / Sk_UserIssuer_A1 and Pk_UserIssuer_A2 / Sk_UserIssuer_A2 in a secure server environment.

[0168] Second step: submit the public key to the blockchain identity management system: the hard wallet terminal, the hard wallet user, and each identity credential issuing agency respectively submit the public key Pk_Device_d1, Pk_Device_d2, Pk_user_a1, Pk_user_a2, Pk_DeviceIssuer_D1, Pk_DeviceIssuer_D2, Pk_UserIssuer_A1, Pk_UserIssuer_A2 to the blockchain identity management system.

[0169] Third step: the blockchain identity management system generates the identity of the above agencies and roles HWID_Device_d1, HWID_Device_d2, HWID_User_a1, HWID_User_a2, HWID_DeviceIssuer_D1, HWID_DeviceIssuer_D2, HWID_UserIssuer_A1, HWID_UserIssuer_A2.

[0170] Fourth step: the blockchain identity management system respectively generates the identity documents of the hard wallet terminal, the hard wallet user, and each identity credential agency, HWID-DOC_User_a1, HWID-DOC_User_a2, HWID-DOC_Device_d1, HWID-DOC_Device_d2, HWID-DOC_UserIssuer_A1, HWID-DOC_UserIssuer_A2, HWID-DOC_DeviceIssuer_D1, HWID-DOC_DeviceIssuer_D2.

[0171] Fifth step: the blockchain identity management system issues the respective identity to the hard wallet terminal, the hard wallet user, and the identity credential issuing agency; the respective identity documents are automatically synchronized through the blockchain to ensure tamper resistance.

[0172] Second stage: identity credential generation and identity document update

[0173] First step: hard wallet terminal d1 and d2 apply for their own identity credentials through the GP standard secure communication and authentication protocol SCP03 (international organization GP remote communication authentication protocol between secure chip and secure chip terminal manufacturer) to the hard wallet terminal identity credential issuing agency D1 and D2 (usually terminal manufacturers) respectively, and the terminal manufacturers D1 and D2 first verify that the hard wallet terminals d1 and d2 are their own production equipment through the SCP02 protocol;

[0174] Second step: the hard wallet terminal identity credential issuing agency (terminal manufacturer) D1 and D2 generate the identity credentials Credential_DeviceIssuer_d1 and Credential_DeviceIssuer_d2 of the hard wallet terminal according to the verifiable identity credential template, and sign them with their private keys Sk_DeviceIssuer_D1 and Sk_DeviceIssuer_D2, indicating that the hard wallet terminal device has been verified by the terminal manufacturer;

[0175] Third step: the hard wallet terminal identity credential issuing agency D1 and D2 (terminal manufacturer) issues the identity credentials to the hard wallet terminals d1 and d2, which are saved in the respective secure chips of the terminals;

[0176] Fourth step: the hard wallet user a1 brings the identity HWID_User_a1 and the corresponding SEID of the hard wallet terminal to the hard wallet user identity credential issuing agency A1 corresponding to its certain identity attribute to apply for identity verification, and after the verification is passed, it obtains the identity credential Credential_UserIssuer_a1 issued by the agency A1; the hard wallet user a2 brings the identity HWID_User_a2 and the corresponding SEID of the hard wallet terminal to the hard wallet user identity credential issuing agency A2 corresponding to its certain identity attribute to apply for identity verification, and after the verification is passed, it obtains the identity credential Credential_UserIssuer_a2 issued by the agency A2;

[0177] Fifth step: the identity credential issuing agencies D1, D2, A1, A2 of the hard wallet terminal and the hard wallet user respectively interact with the blockchain identity management system, and the blockchain identity management system performs the identity document update work of the hard wallet terminals d1 and d2 and the user identity document update work of the hard wallet applications a1 and a2.

[0178] Sixth step: the updated identity documents are synchronized and updated through the blockchain system.

[0179] Step 7: The blockchain identity management system issues the public keys Pk_DeviceIssuer_D1, Pk_DeviceIssuer_D2, Pk_UserIssuer_A1, and Pk_UserIssuer_A2 of the identity credential issuing agencies D1, D2, A1, and A2 to all the hardware wallet terminals, which can be saved in the hardware wallet application or the secure chip.

[0180] Third stage: identity authentication for peer-to-peer transactions

[0181] Before two hardware wallets perform offline peer-to-peer transactions through wireless communication technologies such as NFC and Bluetooth (assuming that the hardware wallet user a1 makes a payment to the hardware wallet user a2), the two parties first perform trusted authentication of the terminals and applications.

[0182] After a1 / a2 and d1 / d2 verify their respective identity credentials, they can proceed to the subsequent transaction payment process.

[0183] When the network is restored, the hardware wallet terminals d1 and d2 upload the operation logs to the blockchain identity management system, which can serve as a reference basis for subsequent security audits and risk traceability.

[0184] Figure 8 is a schematic diagram of the main modules of an identity authentication device in an offline transaction scenario according to an embodiment of the present application. As shown in Figure 8 The identity authentication device 800 in the offline transaction scenario is arranged in a hardware wallet and includes a wallet public key module 801, a wallet identifier module 802, a wallet identity module 803, and an authentication module 804. The wallet public key module 801 is configured to generate a first public-private key pair of a hardware wallet user and a second public-private key pair of a hardware wallet terminal in a secure chip. The wallet identifier module 802 is configured to submit the first public key of the hardware wallet user and the second public key of the hardware wallet terminal to a blockchain identity management system and receive a hardware wallet user identity identifier and a hardware wallet terminal identity identifier returned by the blockchain identity management system. The wallet identity module 803 is configured to send an identity credential issuing request to a hardware wallet user identity credential issuing agency and a hardware wallet terminal identity credential issuing agency, respectively, and receive a hardware wallet user identity credential issued by the hardware wallet user identity credential issuing agency and a hardware wallet terminal identity credential issued by the hardware wallet terminal identity credential issuing agency. The authentication module 804 is configured to perform identity authentication based on the hardware wallet user identity credential and the hardware wallet terminal identity credential in an offline transaction scenario.

[0185] Optionally, the authentication module 804 is further configured to:

[0186] receive third and fourth public keys issued by the blockchain identity management system;

[0187] The third public key is generated by the hard wallet user identity credential issuing authority and submitted to the blockchain identity management system; and the fourth public key is generated by the hard wallet terminal identity credential issuing authority and submitted to the blockchain identity management system.

[0188] Optionally, if the hard wallet is a payment party, the authentication module 804 is further configured to:

[0189] send an identity authentication request to a payee hard wallet;

[0190] receive a hard wallet user identity credential and a hard wallet terminal identity returned by the payee hard wallet;

[0191] perform identity authentication on the hard wallet user identity credential and the hard wallet terminal identity returned by the payee hard wallet based on the third public key and the fourth public key respectively;

[0192] return an authentication result to the payee hard wallet;

[0193] receive an identity authentication request sent by the payee hard wallet;

[0194] return the hard wallet user identity credential and the hard wallet terminal identity to the payee hard wallet;

[0195] receive an authentication result returned by the payee hard wallet.

[0196] Optionally, if the hard wallet is a payee, the authentication module 804 is further configured to:

[0197] receive an identity authentication request sent by a payer hard wallet;

[0198] return the hard wallet user identity credential and the hard wallet terminal identity to the payer hard wallet;

[0199] receive an authentication result returned by the payer hard wallet;

[0200] send an identity authentication request to the payer hard wallet;

[0201] receive a hard wallet user identity credential and a hard wallet terminal identity returned by the payer hard wallet;

[0202] perform identity authentication on the hard wallet user identity credential and the hard wallet terminal identity returned by the payer hard wallet based on the third public key and the fourth public key respectively;

[0203] return an authentication result to the payer hard wallet.

[0204] Optionally, the method further comprises a log module configured to:

[0205] When the network is restored, the operation log of the identity authentication process is reported to the blockchain identity management system.

[0206] Figure 9 FIG is a schematic diagram of the main modules of an identity authentication device in an offline transaction scenario according to another embodiment of the present invention. Figure 9 As shown, the identity authentication device 900 in the offline transaction scenario is set in the hard wallet user identity certificate issuing agency, including a first generation module 901 and a first issuance module 902; wherein, the first generation module 901 is used to generate a third public-private key pair, submit the third public key to the blockchain identity management system, and receive the identity identifier of the hard wallet user identity certificate issuing agency returned by the blockchain identity management system; the first issuance module 902 is used to receive a hard wallet user identity certificate issuance request sent by the hard wallet, use the third private key to issue the hard wallet user identity certificate, and return the hard wallet user identity certificate to the hard wallet.

[0207] The first issuing module 902 is further configured to:

[0208] Submit the hard wallet user identity credentials to the blockchain identity management system.

[0209] Figure 10 FIG. 1 is a schematic diagram of the main modules of an identity authentication device in an offline transaction scenario according to another embodiment of the present invention. Figure 10 As shown, the identity authentication device 1000 in the offline transaction scenario is set in the hard wallet terminal identity certificate issuing agency, including a second generation module 1001 and a second issuance module 1002; wherein, the second generation module 1001 is used to generate a fourth public-private key pair, submit the fourth public key to the blockchain identity management system, and receive the identity identifier of the hard wallet terminal identity certificate issuing agency returned by the blockchain identity management system; the second issuance module 1002 is used to receive a hard wallet terminal identity certificate issuance request sent by the hard wallet, use the fourth private key to issue the hard wallet terminal identity certificate, and return the hard wallet terminal identity certificate to the hard wallet.

[0210] Optionally, the second issuing module 1002 is further configured to:

[0211] Submit the hard wallet terminal identity credential to the blockchain identity management system.

[0212] Figure 11 FIG is a schematic diagram of the main modules of an identity authentication device in an offline transaction scenario according to another embodiment of the present invention. Figure 11As shown, the identity authentication device 1100 in the offline transaction scenario is arranged in a blockchain identity management system, and includes a third generation module 1101 and a fourth generation module 1102; the third generation module 1101 is configured to receive a first public key of a hard wallet user and a second public key of a hard wallet terminal submitted by a hard wallet, and generate an identity identifier of the hard wallet user and identity documents thereof, an identity identifier of the hard wallet terminal and identity documents thereof, and return the identity identifier of the hard wallet user and the identity identifier of the hard wallet terminal to the hard wallet; the fourth generation module 1102 is configured to receive a third public key submitted by a hard wallet user identity credential issuing agency and a fourth public key submitted by a hard wallet terminal identity credential issuing agency, respectively generate an identity identifier of the hard wallet user identity credential issuing agency and identity documents thereof, an identity identifier of the hard wallet terminal identity credential issuing agency and identity documents thereof, and return the identity identifier of the hard wallet user identity credential issuing agency and the identity identifier of the hard wallet terminal identity credential issuing agency to the hard wallet user identity credential issuing agency and the hard wallet terminal identity credential issuing agency, respectively; the identity documents are configured to store a binding relationship between an identity identifier and a public key thereof.

[0213] Optionally, the method further comprises:

[0214] an updating module configured to receive a hard wallet user identity credential submitted by the hard wallet user identity credential issuing agency, store the hard wallet user identity credential, and write a binding relationship between the hard wallet user identity credential and the third public key into the hard wallet user identity documents; receive a hard wallet terminal identity credential submitted by the hard wallet terminal identity credential issuing agency, store the hard wallet terminal identity credential, and write a binding relationship between the hard wallet terminal identity credential and the fourth public key into the hard wallet user identity documents;

[0215] a delivery module configured to deliver the third public key and the fourth public key to the hard wallet.

[0216] It should be noted that the specific implementation content of the identity authentication device in the offline transaction scenario described in the present application has been described in detail in the identity authentication method in the offline transaction scenario described above, and therefore the repeated content will not be described here.

[0217] Figure 12 An exemplary system architecture 1200 of the identity authentication method in the offline transaction scenario or the identity authentication device in the offline transaction scenario to which the embodiments of the present application can be applied is shown.

[0218] As Figure 12As shown, the system architecture 1200 can include terminal devices 1201, 1202, 1203, a network 1204 and a server 1205. The network 1204 is a medium for providing communication links between the terminal devices 1201, 1202, 1203 and the server 1205. The network 1204 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0219] The users can use the terminal devices 1201, 1202, 1203 to interact with the server 1205 through the network 1204 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 1201, 1202, 1203, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0220] The terminal devices 1201, 1202, 1203 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers and desktop computers, etc.

[0221] The server 1205 can be a server providing various services, such as a background management server supporting a shopping website browsed by the users using the terminal devices 1201, 1202, 1203 (only as an example). The background management server can analyze and process received item information query requests and other data, and feed back the processing results to the terminal devices.

[0222] It should be understood that Figure 12 The number of terminal devices, networks and servers in the system architecture 1200 is only illustrative. Any number of terminal devices, networks and servers can be provided according to the implementation needs.

[0223] Reference is made below to Figure 13 which shows a structural schematic diagram of a computer system 1300 of a terminal device suitable for use to implement embodiments of the present application. Figure 13 The terminal device shown is only an example and should not bring any limitation to the functions and use range of the embodiments of the present application.

[0224] As Figure 13As shown, the computer system 1300 includes a central processing unit (CPU) 1301 which can perform various suitable actions and processes in accordance with programs stored in a read only memory (ROM) 1302 or loaded from the storage section 1308 into a random access memory (RAM) 1303. Various programs and data required for the operation of the system 1300 are also stored in the RAM 1303. The CPU 1301, the ROM 1302, and the RAM 1303 are connected to each other through a bus 1304. An input / output (I / O) interface 1305 is also connected to the bus 1304.

[0225] Connected to the I / O interface 1305 are an input section 1306 including a keyboard, a mouse, etc.; an output section 1307 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1308 including a hard disk, etc.; and a communication section 1309 including a network interface card such as a LAN card, a modem, etc. The communication section 1309 performs communication processing via a network such as the Internet. A drive 1310 is also connected to the I / O interface 1305 as necessary. A removable recording medium 1311 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 1310 as necessary, so that a computer program read therefrom is installed into the storage section 1308 as necessary.

[0226] In particular, the processes described above with reference to the flow charts can be implemented as computer software programs in accordance with the embodiments of the present disclosure. For example, the embodiments of the present disclosure include a computer program which includes a computer program carried on a computer-readable medium, the computer program containing program codes for executing the methods shown in the flow charts. In such embodiments, the computer program can be downloaded and installed from a network by the communication section 1309, and / or installed from the removable recording medium 1311. When the computer program is executed by the central processing unit (CPU) 1301, the above-described functions defined in the system of the present disclosure are executed.

[0227] It should be noted that the computer-readable medium shown in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or instrument, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to, an electrical connection with one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or instrument. In the present application, the computer-readable signal medium can include a data signal propagating in a baseband or as a carrier wave part of a carrier wave, in which computer-readable program code is carried. Such a propagating data signal can take various forms, including but not limited to electromagnetic signals, optical signals or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or instrument. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0228] The flowcharts and block diagrams in the drawings illustrate the possible implementation architectures, functions and operations of the systems, methods and computer programs according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment or a part of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order than that shown in the drawings. For example, two blocks that are shown in succession can actually be executed substantially in parallel, and they can also be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0229] As another aspect, the present application also provides a computer readable medium, which can be included in the apparatus described in the above embodiments, or exist separately without being assembled into the apparatus. The computer readable medium carries one or more programs, which, when executed by the apparatus, implement the method described in any of the above embodiments.

[0230] As another aspect, the embodiments of the present application also provide a computer program product, which comprises a computer program, and the computer program, when executed by a processor, implements the method described in any of the above embodiments.

[0231] The specific embodiments described above do not constitute an limitation on the protection scope of the present application. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations, and substitutions can be made depending on design requirements and other factors. Any modification, equivalent replacement, and improvement made within the spirit and principles of the present application shall fall within the protection scope of the present application.

Claims

1. An identity authentication method in an offline transaction scenario, characterized in that: Applicable to hard wallets, including: Generate a first public-private key pair of the hard wallet user and a second public-private key pair of the hard wallet terminal in the security chip respectively; Submitting the first public key of the hard wallet user and the second public key of the hard wallet terminal to the blockchain identity management system, and receiving the hard wallet user identity identifier and the hard wallet terminal identity identifier returned by the blockchain identity management system; Sending identity credential issuance requests to a hard wallet user identity credential issuing agency and a hard wallet terminal identity credential issuing agency respectively, and receiving a hard wallet user identity credential issued by the hard wallet user identity credential issuing agency and a hard wallet terminal identity credential issued by the hard wallet terminal identity credential issuing agency; Receive a third public key and a fourth public key issued by the blockchain identity management system; wherein the third public key is generated by the hard wallet user identity certificate issuing authority and submitted to the blockchain identity management system; the fourth public key is generated by the hard wallet terminal identity certificate issuing authority and submitted to the blockchain identity management system; In an offline transaction scenario, identity authentication is performed based on the third public key, the fourth public key, the hard wallet user identity certificate, and the hard wallet terminal identity certificate.

2. The method according to claim 1, characterized in that If the hard wallet is the payer, identity authentication is performed based on the third public key, the fourth public key, the hard wallet user identity certificate, and the hard wallet terminal identity certificate, including: Send an identity authentication request to the recipient's hard wallet; Receive the hard wallet user identity certificate and hard wallet terminal identity certificate returned by the payee's hard wallet; Perform identity authentication on the hard wallet user identity certificate and the hard wallet terminal identity certificate returned by the payee's hard wallet based on the third public key and the fourth public key respectively; Returning the authentication result to the payee's hard wallet; Receiving an identity authentication request sent by the payee's hard wallet; Returning the hard wallet user identity certificate and the hard wallet terminal identity certificate to the payee hard wallet; Receive the authentication result returned by the payee's hard wallet.

3. The method according to claim 1, characterized in that If the hard wallet is the payee, identity authentication is performed based on the third public key, the fourth public key, the hard wallet user identity certificate, and the hard wallet terminal identity certificate, including: Receive the identity authentication request sent by the payer's hard wallet; Returning the hard wallet user identity certificate and the hard wallet terminal identity certificate to the payer hard wallet; Receiving the authentication result returned by the payer's hard wallet; Sending an identity authentication request to the payer's hard wallet; Receive the hard wallet user identity certificate and hard wallet terminal identity certificate returned by the payer's hard wallet; Perform identity authentication on the hard wallet user identity credential and the hard wallet terminal identity credential returned by the payer's hard wallet based on the third public key and the fourth public key, respectively; The authentication result is returned to the payer's hard wallet.

4. The method according to claim 2 or 3, characterized in that Also includes: When the network is restored, the operation log of the identity authentication process is reported to the blockchain identity management system.

5. An identity authentication method in an offline transaction scenario, characterized in that: Applicable to the issuing institution of hard wallet user identity credentials, including: Generating a third public-private key pair, and submitting the third public key to the blockchain identity management system so that the blockchain identity management system issues the third public key to the hard wallet; Receiving the identity identifier of the hard wallet user identity certificate issuing agency returned by the blockchain identity management system; Receive a hard wallet user identity credential issuance request sent by the hard wallet; The third private key is used to issue a hard wallet user identity certificate, and the hard wallet user identity certificate is returned to the hard wallet.

6. The method according to claim 5, characterized in that After returning the hard wallet user identity certificate to the hard wallet, the method further includes: Submit the hard wallet user identity credentials to the blockchain identity management system.

7. An identity authentication method in an offline transaction scenario, characterized in that: Applicable to the issuing institution of identity certificate of hard wallet terminal, including: Generating a fourth public-private key pair, and submitting the fourth public key to the blockchain identity management system so that the blockchain identity management system issues the fourth public key to the hard wallet; Receiving the identity identifier of the hard wallet terminal identity certificate issuing agency returned by the blockchain identity management system; Receive a hard wallet terminal identity credential issuance request sent by the hard wallet; The fourth private key is used to issue a hard wallet terminal identity certificate, and the hard wallet terminal identity certificate is returned to the hard wallet.

8. The method according to claim 7, characterized in that After returning the hard wallet terminal identity certificate to the hard wallet, the method further includes: Submit the hard wallet terminal identity credential to the blockchain identity management system.

9. An identity authentication method in an offline transaction scenario, characterized in that: Applied to blockchain identity management systems, including: Receive the first public key of the hard wallet user and the second public key of the hard wallet terminal submitted by the hard wallet; Generate a hard wallet user identity and its identity document, a hard wallet terminal identity and its identity document, and return the hard wallet user identity and the hard wallet terminal identity to the hard wallet; Receiving the third public key submitted by the hard wallet user identity certificate issuing agency and the fourth public key submitted by the hard wallet terminal identity certificate issuing agency respectively; Generate an identity document for the hard wallet user identity credential issuing agency and a hard wallet terminal identity credential issuing agency, and a hard wallet terminal identity credential issuing agency, respectively, and return the identity document to the hard wallet user identity credential issuing agency and the hard wallet terminal identity credential issuing agency, respectively; wherein the identity document is used to store the binding relationship between the identity identifier and its public key; The third public key and the fourth public key are issued to the hard wallet.

10. The method according to claim 9, characterized in that Also includes: Receiving the hard wallet user identity certificate submitted by the hard wallet user identity certificate issuing institution; Storing the hard wallet user identity credential, and writing a binding relationship between the hard wallet user identity credential and the third public key into the hard wallet user identity document; Receiving the hard wallet terminal identity certificate submitted by the hard wallet terminal identity certificate issuing institution; The hard wallet terminal identity credential is stored, and a binding relationship between the hard wallet terminal identity credential and the fourth public key is written into the hard wallet user identity document.

11. An identity authentication device in an offline transaction scenario, characterized in that: Settings for use with hard wallets include: A wallet public key module, configured to generate a first public-private key pair of the hard wallet user and a second public-private key pair of the hard wallet terminal in the security chip; A wallet identification module is configured to submit the first public key of the hard wallet user and the second public key of the hard wallet terminal to the blockchain identity management system, and receive the hard wallet user identity and hard wallet terminal identity returned by the blockchain identity management system; A wallet identity module, configured to send identity credential issuance requests to a hard wallet user identity credential issuing authority and a hard wallet terminal identity credential issuing authority, respectively, and receive a hard wallet user identity credential issued by the hard wallet user identity credential issuing authority and a hard wallet terminal identity credential issued by the hard wallet terminal identity credential issuing authority; and receive a third public key and a fourth public key issued by the blockchain identity management system; wherein the third public key is generated by the hard wallet user identity credential issuing authority and submitted to the blockchain identity management system; and the fourth public key is generated by the hard wallet terminal identity credential issuing authority and submitted to the blockchain identity management system; An authentication module is used to perform identity authentication based on the third public key, the fourth public key, the hard wallet user identity certificate, and the hard wallet terminal identity certificate in an offline transaction scenario.

12. An identity authentication device in an offline transaction scenario, characterized in that: The issuing institution of the user identity certificate of the hard wallet includes: The first generation module is configured to generate a third public-private key pair, submit the third public key to the blockchain identity management system, so that the blockchain identity management system issues the third public key to the hard wallet, and receive an identity identifier of an issuing institution of the hard wallet user identity certificate returned by the blockchain identity management system; The first issuing module is configured to receive a hard wallet user identity credential issuance request sent by the hard wallet, use the third private key to issue the hard wallet user identity credential, and return the hard wallet user identity credential to the hard wallet.

13. An identity authentication device in an offline transaction scenario, characterized in that: The identity certificate issuing agency set up in the hard wallet terminal includes: The second generation module is configured to generate a fourth public-private key pair, submit the fourth public key to the blockchain identity management system, so that the blockchain identity management system issues the fourth public key to the hard wallet; and receive an identity identifier of an issuing authority for the hard wallet terminal identity certificate returned by the blockchain identity management system; The second issuing module is used to receive a hard wallet terminal identity certificate issuance request sent by the hard wallet, use the fourth private key to issue the hard wallet terminal identity certificate, and return the hard wallet terminal identity certificate to the hard wallet.

14. An identity authentication device in an offline transaction scenario, characterized in that: Set up in the blockchain identity management system, including: A third generation module is configured to receive the first public key of the hard wallet user and the second public key of the hard wallet terminal submitted by the hard wallet, generate a hard wallet user identity and its identity document, a hard wallet terminal identity and its identity document, and return the hard wallet user identity and the hard wallet terminal identity to the hard wallet; The fourth generation module is used to receive the third public key submitted by the hard wallet user identity credential issuing agency and the fourth public key submitted by the hard wallet terminal identity credential issuing agency, respectively, generate the hard wallet user identity credential issuing agency identity identifier and its identity document, the hard wallet terminal identity credential issuing agency identity identifier and its identity document, respectively, and return the hard wallet user identity credential issuing agency identity identifier and the hard wallet terminal identity credential issuing agency identity identifier to the hard wallet user identity credential issuing agency and the hard wallet terminal identity credential issuing agency, respectively; wherein the identity document is used to store the binding relationship between the identity identifier and its public key; and issue the third public key and the fourth public key to the hard wallet.

15. An electronic device, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 10.

16. A computer-readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

17. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

Citation Information

Patent Citations

  • Off-line payment method and consumption terminal for electronic purse

    CN102096967A

  • Digital wallet device and double offline transaction method thereof

    CN115689559A