A method and system for storing evidence based on distributed real-name authentication digital identity and a storage medium

By generating evidence storage information on the user's client and calling the contract on the evidence storage blockchain, the problem of the inability to confirm ownership on the Internet is solved, realizing data ownership confirmation based on real-name digital identity and ensuring data security and accuracy.

CN119210768BActive Publication Date: 2026-01-27CHINA MOBILE GROUP DESIGN INST +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411144025.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-20
Publication Date
2026-01-27
Estimated Expiration
2044-08-20

AI Technical Summary

Technical Problem

In existing technologies, users cannot effectively use their real-name digital identities to confirm the ownership of their personal data on the Internet, making it difficult to verify the authenticity of the data.

Method used

The system obtains the file identifier information and user real name information of the target file through the user's client, generates evidence storage information, and uses the evidence storage server to call the contract on the evidence storage blockchain to generate evidence storage confirmation information, ensuring that the evidence storage information is recorded on the blockchain and realizing the confirmation of rights based on the user's real name identity.

Benefits of technology

It ensures the security and accuracy of user data ownership confirmation, and guarantees the authenticity and immutability of the data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119210768B_ABST
    Figure CN119210768B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on distributed real-name authentication digital identity's method and system and storage medium for storing evidence.The application embodiment obtains the file identification information of target file and user real-name information by the client of user, and generates the evidence storage information for the target file based on the user public key and file identification information therein, to send to evidence storage server, so that evidence storage server can call the evidence storage contract deployed on evidence storage blockchain according to evidence storage information, to execute evidence storage transaction based on evidence storage information, and generate evidence storage confirmation information to identify that evidence storage information is recorded on evidence storage blockchain, and evidence storage confirmation information and file identification information are forwarded to client by evidence storage server, therefore, according to the method for storing evidence based on distributed real-name authentication digital identity of the application embodiment, the target file of user can be stored on evidence storage blockchain using the real-name DID information of user, so that the evidence storage confirmation information of the target file of user is generated based on the real-name DID information of user, thus realizing the right processing based on user real-name identity, ensure the security and accuracy of the right of user data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network technology, and in particular to a method, system and storage medium for storing digital identities based on distributed real-name authentication. Background Technology

[0002] With the continuous advancement of trusted technologies, especially blockchain technology, distributed digital identity (DID) application solutions have emerged, bringing revolutionary changes to an increasing number of traditional IT systems. These systems can now leverage distributed digital identities to enable users to exercise self-control over their personal data and assets, and to achieve decentralized data sharing across departments, industries, and regions. Furthermore, as the most authoritative and influential standardization organization in the Web technology field, the World Wide Web Consortium (W3C) launched its first DID standard specification in 2019, marking a significant step forward in the standardization and normalization of DID technology.

[0003] With the widespread application of Digital Identity Registry (DID), especially the emergence of real-name DID, users can now possess verified digital identities on internet platforms. However, users often only use these identities for basic tasks like logging in, and cannot utilize them in many other application scenarios. Particularly when users send their personal data over the internet, the tamper-proof nature of electronic data makes it difficult for other users to verify the authenticity of the data received. Therefore, a technical solution is needed that can use a user's real-name digital identity to authenticate personal data. Summary of the Invention

[0004] This application provides a method, system, and storage medium for storing evidence based on distributed real-name authentication digital identity, in order to solve the defect in the prior art where it is impossible to use real-name identity to confirm the ownership of personal data.

[0005] To achieve the above objectives, embodiments of this application provide a method for storing evidence based on distributed real-name authentication digital identity, the method comprising:

[0006] The user's client obtains the file identification information and user real name information of the target file, wherein the user real name information includes the user's real name DID identifier and at least one user public key;

[0007] The client generates evidence storage information based on the user's public key and the file identification information, and sends it to the evidence storage server.

[0008] The evidence storage server invokes an evidence storage contract deployed on the evidence storage blockchain to generate evidence storage confirmation information based on the evidence storage information, wherein the evidence storage confirmation information identifies that the evidence storage information is recorded (e.g., based on consensus-generated blocks) on the evidence storage blockchain;

[0009] The evidence storage server receives the evidence storage confirmation information and the file identification information from the evidence storage blockchain and forwards them to the client.

[0010] This application also provides a notarization system based on distributed real-name authentication digital identity, including: a client, a notarization server, and a notarization blockchain.

[0011] The client is used to obtain the file identification information and user real name information of the target file, wherein the user real name information includes the user's real name DID identifier and at least one user public key; and generates evidence storage information based on the user public key and the file identification information to send to the evidence storage server.

[0012] The evidence storage server is used to invoke the evidence storage contract deployed on the evidence storage blockchain to generate evidence storage confirmation information based on the evidence storage information. The evidence storage confirmation information identifies that the evidence storage information is recorded (e.g., based on consensus-generated blocks) on the evidence storage blockchain, and sends the evidence storage confirmation information and the file identification information to the client.

[0013] The evidence storage blockchain is used to generate evidence storage confirmation information based on the evidence storage information, and to send the evidence storage confirmation information and the file identification information to the evidence storage blockchain.

[0014] This application also provides an electronic device, including:

[0015] Memory, used to store programs;

[0016] A processor is used to run the program stored in the memory, and when the program runs, it executes the evidence storage method based on distributed real-name authentication digital identity provided in the embodiments of this application.

[0017] This application also provides a computer-readable storage medium storing a computer program executable by a processor, wherein the program, when executed by the processor, implements the evidence storage method based on distributed real-name authentication digital identity as provided in this application.

[0018] The notarization method, system, and storage medium based on distributed real-name authentication digital identity provided in this application embodiment obtain file identification information and user real-name information of a target file from the user's client. Based on the user's public key and file identification information, notarization information for the target file is generated and sent to the notarization server. The notarization server can then invoke a notarization contract deployed on the notarization blockchain based on the notarization information to execute notarization transactions and generate notarization confirmation information to identify that the notarization information is recorded on the notarization blockchain. The notarization confirmation information and file identification information are then forwarded to the client through the notarization server. Therefore, the notarization method based on distributed real-name authentication digital identity according to this application embodiment can use the user's real-name DID information to notarize the user's target file on the notarization blockchain. The notarization confirmation information of the user's target file is generated based on the user's real-name DID information, thus realizing the confirmation of rights based on the user's real-name identity and ensuring the security and accuracy of the confirmation of user data rights.

[0019] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0020] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0021] Figure 1 This is a schematic diagram illustrating an application scenario of a digital identity storage scheme based on distributed real-name authentication according to an embodiment of this application;

[0022] Figure 2 A flowchart illustrating an embodiment of the evidence storage method based on distributed real-name authentication digital identity provided in this application;

[0023] Figure 3 A schematic diagram of the structure of the evidence storage system based on distributed real-name authentication digital identity provided in this application;

[0024] Figure 4 A schematic diagram of the structure of an embodiment of the electronic device provided in this application. Detailed Implementation

[0025] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0026] Example 1

[0027] The solutions provided in this application can be applied to any data system or server with encryption and decryption functions.

[0028] With the continuous advancement of trusted technologies, especially blockchain technology, distributed digital identity (DID) application solutions have emerged, bringing revolutionary changes to an increasing number of traditional IT systems. These systems can now leverage distributed digital identities to enable users to exercise self-control over their personal data and assets, and to achieve decentralized data sharing across departments, industries, and regions. Furthermore, as the most authoritative and influential standardization organization in the Web technology field, the World Wide Web Consortium (W3C) launched its first DID standard specification in 2019, marking a significant step forward in the standardization and normalization of DID technology.

[0029] With the widespread application of DID (Digital Identity), especially the emergence of real-name DID, users can now possess verified digital identities on internet platforms. However, users often only use these identities for basic tasks like logging in, and cannot utilize them in many other application scenarios. In particular, when users send their personal data over the internet, the tamper-proof nature of electronic data makes it difficult for other users to verify the authenticity of the data received.

[0030] To this end, this application proposes a notarization scheme based on distributed real-name authentication digital identity. This scheme allows users to store and verify the ownership of target files, such as photos and documents, generated or obtained through their clients, using the user's real-name authenticated digital identity. For example... Figure 1 As shown, Figure 1 This is a schematic diagram illustrating a scenario of a distributed real-name authentication-based digital identity evidence storage scheme according to an embodiment of this application. Figure 1In the scenario illustrated, a user can use a client application equipped with the distributed real-name authentication digital identity notarization method of this application to generate or obtain the target file to be notarized from an external source. For example, a user can use the camera application in the client to take a photo and use the generated photo file as the target file to be notarized. In the prior art, after a user takes a digital photo using their own client, the photo is accompanied by corresponding photo information, such as the shooting time, the device identifier of the shooting device, and the parameters of the photo. When the user transmits the photo obtained in this way over the Internet, other users who receive the photo can understand the shooting situation by viewing the photo information, especially confirming that the photo was taken by the user's device. However, due to the electronic file nature of digital photos, namely their tamperability, when transmitted over the Internet, anyone who obtains or maliciously intercepts the file can modify it using various digital tools. This makes it impossible for other users who ultimately obtain the photo to determine from the photo information itself whether the photo was taken by the user or to confirm whether the photo is the original file and has not been tampered with.

[0031] Therefore, according to the embodiments of this application, after a user generates a target file, such as a photo, through various applications in their client or obtains it from an external source, the file identification information can be obtained based on the target file. For example, the photo ID of the photo mentioned above. This ID can be generated based on the hardware information of the client or based on the photo-taking application, as long as the ID can uniquely identify the photo. Then, the client can obtain the user's real-name information based on the user's information, such as the user's account information when logging into the application or the client. For example, in the embodiments of this application, the client can obtain information such as a real-name DID identity identifier issued to the user by an authoritative institution. For example, in the embodiments of this application, the user's real-name information can include the user's real-name DID identifier and at least one user public key. Specifically, in the embodiments of this application, the user can store the real-name DID identifier obtained from the authoritative institution and the corresponding real-name DID document on the client, so that the client can directly obtain the locally stored real-name DID identifier and determine a user public key from the corresponding real-name DID document as the public key used by the user to log in to the target blockchain. Furthermore, the client can also obtain the corresponding first private key based on the first public key determined in the DID document. For example, in this embodiment of the application, the public key information of the first public key may be the public key index of the first public key in the user's real-name DID document.

[0032] Then, the user can use the first public key determined in the DID document and the file identification information of the target file on their client to generate the evidence storage information for the target file. For example, in this embodiment, the client can use an application based on the distributed real-name authentication digital identity evidence storage method of this embodiment to calculate the hash value of the target file and use it as the file identification information of the target file. Furthermore, in this embodiment, the client can use the first private key obtained from the first public key determined in the DID document to sign the file identification information to obtain first signature data. Then, based on the first signature data, the hash value obtained from the file information of the target file, the user's real-name DID identifier, and the public key information of the first public key, evidence storage information can be generated. In this embodiment, since the evidence storage information contains the user's real-name DID information and the file identification information that uniquely identifies the target file, the user receiving the file can use such evidence storage information to confirm the ownership or origin of the target file. However, in this case, since the evidence storage information is still at risk of being tampered with, and the user's real-name DID information contained in the evidence storage information also needs to be verified to confirm the user's identity.

[0033] Therefore, in this embodiment, the client can send the generated evidence storage information to the evidence storage server, which can be a server located outside the evidence storage blockchain. The evidence storage server can then invoke the evidence storage contract deployed on the evidence storage blockchain based on the received evidence storage information. For example, the evidence storage server can send an evidence storage contract invocation instruction to the evidence storage blockchain. In this embodiment, the evidence storage contract invocation instruction can include evidence storage information, the invocation address of the evidence storage contract, and a real-name DID identifier. Thus, the evidence storage blockchain can invoke the evidence storage contract to execute corresponding evidence storage transactions on each node of the blockchain based on the evidence storage contract invocation instruction. When a block corresponding to the evidence storage transaction is generated on each node, the block generation time and the transaction result of the evidence storage transaction can be written into the block as evidence storage records. Evidence storage confirmation information is then generated based on the block generation time and the record information of the evidence storage records. Therefore, in this embodiment, the evidence storage confirmation information can identify that the evidence storage information is recorded on the evidence storage blockchain. Furthermore, in this embodiment of the application, the evidence storage blockchain can be a blockchain operated by an authoritative institution to issue real-name authenticated DID identities to users. Therefore, when the evidence storage contract is invoked, the evidence storage blockchain can verify the user's real-name identity based on the real-name DID identifier contained in the evidence storage contract invocation instruction, and execute the corresponding evidence storage transaction processing after the verification is successful.

[0034] Then, the evidence storage server can receive evidence confirmation information and file identification information from the evidence storage blockchain and forward them to the client. The client can then associate the evidence confirmation information with the target file based on the received file identification information, thus enabling the stored target file to have evidence confirmation information recorded on the evidence storage blockchain. Therefore, when a user transmits such a target file containing evidence confirmation information via the Internet through the client, another user who receives the target file can send a verification request to the evidence storage blockchain based on the file identification information of the target file. The evidence storage blockchain can then query the evidence confirmation information of the target file on the evidence storage blockchain based on the file identification information and send the evidence confirmation information to the user who received the target file. This user can then compare the received evidence confirmation information with the evidence confirmation information received along with the target file. If the comparison result is consistent, it can be confirmed that the target file is the original file generated or obtained by the original user on their client.

[0035] Furthermore, in this embodiment, when a user obtains a target file and wants to perform ownership verification, they can check whether it has already stored real-name DID identity information. For example, if the user confirms after checking that they have not yet applied for a real-name DID identity, the user can send a real-name DID identifier application request to, for example, a storage blockchain through a storage server. In this embodiment, the real-name DID identifier application request may contain at least the user's identity information; the storage blockchain generates a real-name DID identifier and a real-name DID document for the user based on the real-name DID identifier application request, and stores the real-name DID document in the blockchain. The real-name DID document contains at least a first public key, and then the real-name DID identifier and the real-name DID document can be sent to the client through the storage server.

[0036] The evidence storage scheme based on distributed real-name authentication digital identity provided in this application involves the user's client obtaining the file identifier information and user real-name information of the target file, and generating evidence storage information for the target file based on the user's public key and file identifier information. This information is then sent to the evidence storage server. The evidence storage server can then invoke the evidence storage contract deployed on the evidence storage blockchain to execute evidence storage transactions based on the evidence storage information and generate evidence storage confirmation information to identify that the evidence storage information is recorded on the evidence storage blockchain. The evidence storage confirmation information and file identifier information are then forwarded to the client through the evidence storage server. Therefore, according to the evidence storage method based on distributed real-name authentication digital identity in this application, the user's real-name DID information can be used to perform evidence storage processing on the user's target file on the evidence storage blockchain. This ensures that the evidence storage confirmation information for the user's target file is generated based on the user's real-name DID information, thus achieving rights confirmation processing based on the user's real-name identity and ensuring the security and accuracy of user data rights confirmation.

[0037] The above embodiments illustrate the technical principles and exemplary application framework of the embodiments of this application. The specific technical solutions of the embodiments of this application will be further described in detail below through multiple embodiments.

[0038] Example 2

[0039] Figure 2 The flowchart illustrates an embodiment of the distributed real-name authentication digital identity notation method provided in this application. The executing entity of this method can be various terminal or server devices with data encryption and decryption capabilities deployed on a blockchain, or it can be a device or chip integrated into these devices. Figure 2 As shown, this method for storing evidence based on distributed real-name authentication digital identity includes the following steps:

[0040] S201, the user's client obtains the file identification information and user real name information of the target file.

[0041] In step S201, the user can generate or obtain target files such as photos through various applications in their client or from external sources, and obtain file identification information based on the target file. For example, when the user takes a photo using the photo application in the client, the photo ID can be obtained based on the photo. The ID can be generated based on the hardware information of the client or based on the photo-taking application, as long as the ID can uniquely identify the photo.

[0042] The client can also obtain the user's real-name information based on the user's information, such as the user's account information when logging into the application or the client. For example, in this embodiment, the client can obtain information such as a real-name DID identity identifier issued to the user by an authoritative institution. For example, in this embodiment, the user's real-name information may include the user's real-name DID identifier and at least one user public key.

[0043] Specifically, in this embodiment, the user can store the real-name DID identifier obtained from an authoritative institution and the corresponding real-name DID document on the client. This allows the user to directly obtain the locally stored real-name DID identifier in step S201, and determine a user public key from the corresponding real-name DID document as the public key used for login to the target blockchain. Furthermore, the user can obtain the corresponding first private key based on this first public key determined in the DID document. For example, in this embodiment, the public key information of the first public key can be the public key index of the first public key in the user's real-name DID document.

[0044] S202 involves the client generating evidence storage information based on the user's public key and file identification information, and then sending it to the evidence storage server.

[0045] In step S202, the user can use the first public key determined from the DID document in step S201 and the obtained file identification information of the target file on the client to generate the evidence storage information of the target file. For example, in this embodiment, in step S202, the client can use an application based on the evidence storage method of distributed real-name authentication digital identity based on this embodiment to calculate the hash value of the target file and use it as the file identification information of the target file.

[0046] Furthermore, in step S202, the client can use the first private key obtained from the first public key determined from the DID document to sign the file identification information to obtain first signature data. Then, based on the first signature data, the hash value obtained from the file information of the target file, the user's real-name DID identifier, and the public key information of the first public key, evidence storage information can be generated. In this embodiment, because the evidence storage information contains the user's real-name DID information and the file identification information that uniquely identifies the target file, the user receiving the file can use this evidence storage information to confirm the ownership or origin of the target file. However, in this case, the evidence storage information still faces the risk of being tampered with, and the user's real-name DID information contained in the evidence storage information also needs to be verified to confirm the user's identity.

[0047] S203, the evidence storage server calls the evidence storage contract deployed on the evidence storage blockchain to generate evidence storage confirmation information based on the evidence storage information.

[0048] In step S202, the client sends the evidence storage information to the evidence storage server, and in step S203, the evidence storage server can invoke the evidence storage contract deployed on the evidence storage blockchain based on the received evidence storage information. For example, the evidence storage server can send an evidence storage contract invocation instruction to the evidence storage blockchain. In this embodiment, the evidence storage contract invocation instruction can include evidence storage information, the invocation address of the evidence storage contract, and a real-name DID identifier, so that the evidence storage blockchain can invoke the evidence storage contract to execute the corresponding evidence storage transaction on each node of the evidence storage blockchain based on the evidence storage contract invocation instruction. When a block corresponding to the evidence storage transaction is generated on each node, the block generation time and the transaction result of the evidence storage transaction can be written into the block as evidence storage records, and evidence storage confirmation information is generated based on the block generation time and the record information of the evidence storage records. In this embodiment, the evidence storage confirmation information indicates that the evidence storage information is recorded (e.g., based on consensus-generated blocks) on the evidence storage blockchain.

[0049] Therefore, in this embodiment, the evidence confirmation information can identify that the evidence information is recorded on the evidence storage blockchain. Furthermore, in this embodiment, the evidence storage blockchain can be a blockchain operated by an authoritative institution to issue real-name authenticated DID identities to users. Therefore, when invoking the evidence storage contract, the evidence storage blockchain can verify the user's real-name identity based on the real-name DID identifier contained in the evidence storage contract invocation instruction, and execute the corresponding evidence storage transaction processing only after successful verification.

[0050] S204, the evidence storage server receives evidence storage confirmation information and document identification information from the evidence storage blockchain and forwards them to the client.

[0051] In step S204, the evidence storage server can receive evidence confirmation information and file identification information from the evidence storage blockchain and forward them to the client. The client can then associate the received file identification information with the target file and store it, thus ensuring that the stored target file has evidence confirmation information recorded on the evidence storage blockchain. Therefore, when a user transmits such a target file containing evidence confirmation information via the Internet through the client, another user who receives the target file can send a verification request to the evidence storage blockchain based on the file identification information of the target file. The evidence storage blockchain can then query the evidence confirmation information of the target file on the blockchain based on the file identification information and send the evidence confirmation information to the user who received the target file. This user can then compare the received evidence confirmation information with the evidence confirmation information received along with the target file. If the comparison result is consistent, it can be confirmed that the target file is the original file generated or obtained by the original user on their client.

[0052] Furthermore, in this embodiment, when a user obtains a target file and wants to perform ownership verification, they can check whether it has already stored real-name DID identity information. For example, if the user confirms after checking that they have not yet applied for a real-name DID identity, the user can send a real-name DID identifier application request to, for example, a storage blockchain through a storage server. In this embodiment, the real-name DID identifier application request may contain at least the user's identity information; the storage blockchain generates a real-name DID identifier and a real-name DID document for the user based on the real-name DID identifier application request, and stores the real-name DID document in the blockchain. The real-name DID document contains at least a first public key, and then the real-name DID identifier and the real-name DID document can be sent to the client through the storage server.

[0053] The evidence preservation method based on distributed real-name authentication digital identity provided in this application involves the user's client obtaining the file identifier information and user real-name information of the target file, and generating evidence preservation information for the target file based on the user's public key and file identifier information. This information is then sent to the evidence preservation server. The evidence preservation server can then invoke the evidence preservation contract deployed on the evidence preservation blockchain to execute evidence preservation transactions based on the evidence preservation information and generate evidence preservation confirmation information to identify that the evidence preservation information is recorded on the evidence preservation blockchain. The evidence preservation confirmation information and file identifier information are then forwarded to the client through the evidence preservation server. Therefore, according to the evidence preservation method based on distributed real-name authentication digital identity of this application, the user's real-name DID information can be used to perform evidence preservation processing on the user's target file on the evidence preservation blockchain. This ensures that the evidence preservation confirmation information for the user's target file is generated based on the user's real-name DID information, thus achieving rights confirmation processing based on the user's real-name identity and ensuring the security and accuracy of user data rights confirmation.

[0054] Example 3

[0055] Figure 3 The diagram below illustrates the structure of the distributed real-name authentication digital identity-based evidence storage system provided in this application. This system can be used to implement, for example, [reference needed]. Figure 2 The present application describes a method for storing evidence based on distributed real-name authentication digital identity. This system may include a client 31, an evidence storage server 32, and an evidence storage blockchain 33, wherein the evidence storage blockchain 33 may include multiple nodes.

[0056] Client 31 can be used to obtain the file identification information and user real name information of the target file; generate evidence storage information based on the user's public key and file identification information, and send it to the evidence storage server.

[0057] In this embodiment of the application, the user can generate or obtain target files such as photos from external sources through various applications in the client 31, and obtain file identification information based on the target file. For example, when the user takes a photo using the photo application in the client 31, the photo ID can be obtained based on the photo. The ID can be generated based on the hardware information of the client 31 or based on the photo application, as long as the ID can uniquely identify the photo.

[0058] Client 31 can also obtain the user's real-name information based on the user's information, such as the user's account information when logging into the application or the client. For example, in this embodiment, client 31 can obtain information such as a real-name DID identity identifier issued to the user by an authoritative institution. For example, in this embodiment, the user's real-name information may include the user's real-name DID identifier and at least one user public key.

[0059] Specifically, in this embodiment, the user can store the real-name DID identifier obtained from an authoritative institution and the corresponding real-name DID document on the client 31. This allows the user to directly obtain the locally stored real-name DID identifier through the client 31 and determine a user public key from the corresponding real-name DID document as the public key used for login to the target blockchain. Furthermore, the user can obtain the corresponding first private key based on the first public key determined in the DID document. For example, in this embodiment, the public key information of the first public key can be the public key index of the first public key in the user's real-name DID document.

[0060] Users can use the first public key determined from the DID document and the obtained file identification information of the target file on the client 31 to generate the evidence information of the target file. For example, in this embodiment, the client 31 can calculate the hash value of the target file and use it as the file identification information of the target file.

[0061] Furthermore, client 31 can use the first private key obtained from the first public key determined from the DID document to sign the file identification information to obtain first signature data. Then, based on the first signature data, the hash value obtained from the file information of the target file, the user's real-name DID identifier, and the public key information of the first public key, it can generate evidence storage information. In this embodiment, because the evidence storage information contains the user's real-name DID information and the file identification information that uniquely identifies the target file, the user receiving the file can use this evidence storage information to confirm the ownership or origin of the target file. However, in this case, the evidence storage information still faces the risk of being tampered with, and the user's real-name DID information contained in the evidence storage information also needs to be verified to confirm the user's identity.

[0062] The evidence storage server 32 can be used to call the evidence storage contract deployed on the evidence storage blockchain to generate evidence storage confirmation information based on the evidence storage information and send the evidence storage confirmation information and file identification information to the client 31; the evidence storage server 32 can also call the evidence storage contract deployed on the evidence storage blockchain 33 to generate evidence storage confirmation information based on the evidence storage information.

[0063] After client 31 sends such evidence storage information to evidence storage server 32, evidence storage server 32 can invoke the evidence storage contract deployed on evidence storage blockchain 33 based on the received evidence storage information. For example, evidence storage server 32 can send an evidence storage contract invocation instruction to evidence storage blockchain 33. In this embodiment, the evidence storage contract invocation instruction can include evidence storage information, the invocation address of the evidence storage contract, and a real-name DID identifier. Therefore, evidence storage blockchain 33 can invoke the evidence storage contract to execute corresponding evidence storage transactions on each node of evidence storage blockchain 33 based on the evidence storage contract invocation instruction. When a block corresponding to the evidence storage transaction is generated on each node, the block generation time and the transaction result of the evidence storage transaction can be written into the block as evidence storage records. Evidence storage confirmation information is generated based on the block generation time and the record information of the evidence storage records. In this embodiment, the evidence storage confirmation information indicates that the evidence storage information is recorded (e.g., based on consensus-generated blocks) on evidence storage blockchain 33.

[0064] Therefore, in this embodiment, the evidence confirmation information can identify that the evidence information is recorded on the evidence storage blockchain 33. Furthermore, in this embodiment, the evidence storage blockchain 33 can be a blockchain operated by an authoritative institution to issue real-name authenticated DID identities to users. Therefore, when invoking the evidence storage contract, the evidence storage blockchain 33 can verify the user's real-name identity based on the real-name DID identifier contained in the evidence storage contract invocation instruction, and execute the corresponding evidence storage transaction processing after successful verification.

[0065] The evidence storage server 32 can receive evidence storage confirmation information and file identification information from the evidence storage blockchain 33 and forward them to the client 31. The client 31 can store the evidence storage confirmation information in association with the target file based on the received file identification information, so that the stored target file has evidence storage confirmation information recorded on the evidence storage blockchain 33. Therefore, when a user transmits such a target file with evidence storage confirmation information via the Internet through the client 31, another user who receives the target file can send a verification request to the evidence storage blockchain 33 based on the file identification information of the target file. The evidence storage blockchain 33 can query the evidence storage confirmation information of the target file on the evidence storage blockchain based on the file identification information and send the evidence storage confirmation information to the user who received the target file. The user can then compare the received evidence storage confirmation information with the evidence storage confirmation information received along with the target file. If the comparison result is consistent, it can be confirmed that the target file is the original file generated or obtained by the original user on their client.

[0066] Furthermore, in this embodiment, when a user obtains the target file and wants to perform ownership verification, they can check whether it has already stored real-name DID identity information. For example, if the user confirms after checking that they have not yet applied for a real-name DID identity, the user can send a real-name DID identifier application request to, for example, a storage blockchain through a storage server. In this embodiment, the real-name DID identifier application request may at least contain the user's identity information; the storage blockchain generates a real-name DID identifier and a real-name DID document for the user based on the real-name DID identifier application request, and stores the real-name DID document in the blockchain. The real-name DID document contains at least a first public key and a first private key, i.e., a key pair. Then, the storage blockchain can encrypt the first private key using the user's public key, which the user has pre-sent to the real-name digital identity blockchain, and then send the real-name DID identifier and the real-name DID document to the client through the storage server.

[0067] The evidence storage system based on distributed real-name authentication digital identity provided in this application embodiment obtains the file identifier information and user real-name information of the target file from the user's client, and generates evidence storage information for the target file based on the user's public key and file identifier information. This information is then sent to the evidence storage server. The evidence storage server can then invoke the evidence storage contract deployed on the evidence storage blockchain based on the evidence storage information to execute evidence storage transactions and generate evidence storage confirmation information to identify that the evidence storage information is recorded on the evidence storage blockchain. The evidence storage confirmation information and file identifier information are then forwarded to the client through the evidence storage server. Therefore, according to the evidence storage method based on distributed real-name authentication digital identity of this application embodiment, the user's real-name DID information can be used to perform evidence storage processing on the user's target file on the evidence storage blockchain. This ensures that the evidence storage confirmation information of the user's target file is generated based on the user's real-name DID information, thus realizing the confirmation of rights based on the user's real-name identity and ensuring the security and accuracy of user data confirmation.

[0068] Example 4

[0069] The above describes the internal functions and structure of a digital identity storage system based on distributed real-name authentication, which can be implemented as an electronic device. Figure 4 A schematic diagram illustrating the structure of an embodiment of the electronic device provided in this application. Figure 4 As shown, the electronic device includes a memory 41 and a processor 42.

[0070] Memory 41 is used to store programs. In addition to the programs described above, memory 41 can also be configured to store various other data to support operation on the electronic device. Examples of this data include instructions for any application or method used to operate on the electronic device, contact data, phonebook data, messages, pictures, videos, etc.

[0071] The memory 41 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0072] Processor 42 is not limited to a processor (CPU), but may also be a graphics processing unit (GPU), a field-programmable gate array (FPGA), an embedded neural network processor (NPU), or an artificial intelligence (AI) chip. Processor 42 is coupled to memory 41 and executes the program stored in memory 41 to perform the evidence storage method based on distributed real-name authentication digital identity in Embodiment 2 described above.

[0073] Furthermore, such as Figure 4 As shown, the electronic device may also include other components such as a communication component 43, a power supply component 44, an audio component 45, and a display 46. Figure 4 The diagram only shows some components and does not mean that the electronic device includes only these components. Figure 4 The components shown.

[0074] Communication component 43 is configured to facilitate wired or wireless communication between electronic devices and other devices. The electronic devices can access wireless networks based on communication standards, such as WiFi, 3G, 4G, or 5G, or combinations thereof. In one exemplary embodiment, communication component 43 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 43 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0075] Power supply component 44 provides power to various components of the electronic device. Power supply component 44 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device.

[0076] Audio component 45 is configured to output and / or input audio signals. For example, audio component 45 includes a microphone (MIC) configured to receive external audio signals when the electronic device is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 41 or transmitted via communication component 43. In some embodiments, audio component 45 also includes a speaker for outputting audio signals.

[0077] Display 46 includes a screen, which may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touchscreen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation.

[0078] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0079] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for storing evidence of digital identity based on distributed real-name authentication, characterized in that, The method includes: The user's client obtains the file identification information and user real name information of the target file, wherein the user real name information includes the user's real name DID identifier and at least one user public key; The client generates evidence storage information based on the user's public key and the file identification information, and sends it to the evidence storage server. The evidence storage server invokes the evidence storage contract deployed on the evidence storage blockchain to generate evidence storage confirmation information based on the evidence storage information, wherein the evidence storage confirmation information identifies that the evidence storage information is recorded on the evidence storage blockchain. The evidence storage server receives the evidence confirmation information and the file identification information from the evidence storage blockchain and forwards them to the client. The process of generating evidence storage information by the client based on the user's public key and the file identification information includes: The client uses a first private key to sign the file identification information to obtain first signature data, wherein the first private key corresponds to the first public key in the first real-name DID document of the user corresponding to the target file; The evidence storage information is generated based on the first signature data, hash value, real-name DID identifier, and public key information of the first public key, wherein the hash value is calculated using a first algorithm based on the file information of the target file.

2. The method for storing evidence based on distributed real-name authentication digital identity according to claim 1, characterized in that, Before the user's client obtains the file identifier information and user real-name information of the target file, the method further includes: The target file is obtained by the client. Based on the file information of the target file, the hash value of the target file is calculated using a first algorithm, and used as the file identification information.

3. The method for storing evidence based on distributed real-name authentication digital identity according to claim 2, characterized in that, The process of obtaining the file identification information of the target file and the user's real-name information from the user's client includes: The client obtains the user's identity identifier corresponding to the target file based on the file identification information; The client obtains the user's first real-name DID document based on the user's identity identifier; The client obtains the first public key from at least one public key in the first real-name DID document; The client obtains the first private key based on the first public key.

4. The method for storing evidence based on distributed real-name authentication digital identity according to claim 1, characterized in that, The step of the evidence storage server calling the evidence storage contract deployed on the evidence storage blockchain to generate evidence storage confirmation information based on the evidence storage information includes: The evidence storage server sends an evidence storage contract invocation instruction to the evidence storage blockchain, wherein the evidence storage contract invocation instruction includes the evidence storage information, the invocation address of the evidence storage contract, and the real-name DID identifier; The evidence storage blockchain invokes the evidence storage contract on each node of the evidence storage blockchain according to the evidence storage contract invocation instruction to execute the evidence storage transaction; When a block corresponding to the evidence storage transaction is generated on each of the nodes, the block generation time and the transaction result of the evidence storage transaction are written into the block as evidence storage records. Evidence confirmation information is generated based on the block generation time and the record information of the evidence storage record.

5. The method for storing evidence based on distributed real-name authentication digital identity according to claim 1, characterized in that, Before the user's client obtains the file identifier information and user real-name information of the target file, the method further includes: The client sends a real-name DID identifier application request through the evidence storage server, wherein the real-name DID identifier application request contains at least the user's identity information; The evidence storage blockchain generates a real-name DID identifier and a real-name DID document for the user based on the real-name DID identifier application request, and stores the real-name DID document in the evidence storage blockchain, wherein the real-name DID document contains at least a first public key; The evidence storage server sends the real-name DID identifier and the real-name DID document to the client.

6. A digital identity storage system based on real-name authentication, comprising: The client, the evidence storage server, and the evidence storage blockchain are characterized by, The client is used to obtain the file identification information and user real name information of the target file, wherein the user real name information includes the user's real name DID identifier and at least one user public key; and generates evidence storage information based on the user public key and the file identification information to send to the evidence storage server. The evidence storage server is used to invoke the evidence storage contract deployed on the evidence storage blockchain to generate evidence storage confirmation information based on the evidence storage information. The evidence storage confirmation information identifies that the evidence storage information is recorded on the evidence storage blockchain, and sends the evidence storage confirmation information and the file identification information to the client. The evidence storage blockchain is used to generate evidence storage confirmation information based on the evidence storage information, and to send the evidence storage confirmation information and the file identification information to the evidence storage blockchain. The generation of evidence storage information based on the user's public key and the file identification information includes: The client uses a first private key to sign the file identification information to obtain first signature data, wherein the first private key corresponds to the first public key in the first real-name DID document of the user corresponding to the target file; The evidence storage information is generated based on the first signature data, hash value, real-name DID identifier, and public key information of the first public key, wherein the hash value is calculated using a first algorithm based on the file information of the target file.

7. The digital identity storage system based on real-name authentication according to claim 6, characterized in that, The client is also used for: Obtain the target file; Based on the file information of the target file, the hash value of the target file is calculated using a first algorithm, and used as the file identification information.

8. The digital identity storage system based on real-name authentication according to claim 7, characterized in that, The client is also used for: Based on the file identification information, obtain the identity identifier of the user corresponding to the target file; Based on the user's identity identifier, obtain the user's first real-name DID document; Obtain the first public key from at least one public key in the first real-name DID document; Obtain the first private key based on the first public key.

9. A computer-readable storage medium having a computer program stored thereon that can be executed by a processor, characterized in that, When the program is executed by the processor, it implements the evidence storage method based on distributed real-name authentication digital identity as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data evidence-preserving method and system based on block chain technology

    CN107819777A

  • Charging pile transaction management method and system based on APP

    CN113506119A