An identity authentication method, device, equipment and storage medium
Through the relay chain and public key encryption and decryption and hash verification of blockchain technology, the identity authentication process is simplified, and the inefficiency and poor user experience caused by multiple verifications in the existing technology are solved, and efficient cross-chain authentication and multi-service access are achieved.
Patent Information
- Application Number
- CN202411439666.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-15
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2044-10-15
AI Technical Summary
Existing identity authentication methods require multiple verifications, resulting in inefficiency and poor user experience.
Through blockchain technology, the relay chain and public key encryption and decryption and hash verification are used to simplify the identity authentication process, reduce user operation steps, and realize the secure transmission and verification of cross-chain authentication requests.
Improves the efficiency of identity authentication, improves user experience, and allows users to access multiple associated services after registering and authenticating on one service.
Smart Images

Figure CN119324787B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of computer technology, and in particular, to an identity authentication method, apparatus, device, and storage medium. Background Art
[0002] Identity authentication is crucial for the secure operation of a system, which can ensure that only authorized personnel can access the system.
[0003] In the prior art, in order to improve the reliability of identity authentication, a multi-factor authentication method that combines multiple authentication methods is usually adopted to ensure the security of the system and the convenience of users. For example, the combination of username and password, two-factor authentication, and biometric recognition is used.
[0004] However, multi-factor authentication requires multiple identity verifications, resulting in low efficiency and poor user experience. Summary of the Invention
[0005] The present invention provides an identity authentication method, apparatus, device, and storage medium to improve the efficiency of identity authentication and user experience.
[0006] In a first aspect, an embodiment of the present invention provides an identity authentication method, including:
[0007] Determine a user identity identifier and user signature data according to the received authentication request, and determine a user public key and encrypted secret information according to the user identity identifier;
[0008] After determining that the user public key is consistent with the public key of the authentication initiator corresponding to the authentication request, decrypt the user signature data based on the user public key to obtain an encrypted authentication password and a password hash;
[0009] Perform a hash verification on the encrypted authentication password according to the password hash, and in the case of determining that the verification passes, determine the authentication result corresponding to the authentication request according to the first authentication password corresponding to the encrypted authentication password and the second authentication password corresponding to the encrypted secret information.
[0010] The technical solution of the embodiment of the present invention provides an identity authentication method. Compared with the multi-factor identity authentication method adopted in the prior art, it reduces the user operation steps, improves the authentication efficiency, and enhances the user experience. Moreover, after any service deployed on the blockchain determines that the identity authentication is passed, other services that are also deployed on the blockchain and associated with this service will synchronously determine that the identity authentication is passed. Users only need to register and authenticate once in one service to access multiple services associated with it, further enhancing the user experience.
[0011] Further, determining a user identity identifier and user signature data according to the received authentication request includes:
[0012] When determining that the authentication request is a forwarded authentication request, determining a cross-chain authentication request and a request hash according to the forwarded authentication request;
[0013] Performing hash verification on the cross-chain authentication request according to the request hash, and when it is determined that the verification passes, determining the user identity identifier and the user signature data according to the cross-chain authentication request.
[0014] Further, determining a cross-chain authentication request and a request hash according to the forwarded authentication request includes:
[0015] Decrypting the forwarded authentication request based on the relay public key of the relay chain that sent the authentication request to obtain the cross-chain authentication request and the request hash.
[0016] Further, determining a user public key and encrypted secret information according to the user identity identifier includes:
[0017] Searching in the registration information according to the user identity identifier to determine the user information corresponding to the user identity identifier, where the registration information includes the user identity identifiers and user information of each user registered in the current blockchain;
[0018] Determining the user public key and the encrypted secret information in the user information.
[0019] Further, the user signature data is obtained by encrypting an authentication password with a source public key of the source blockchain that received the authentication request to obtain an encrypted authentication password, and then signing the encrypted authentication password and the password hash corresponding to the encrypted authentication password based on a user private key.
[0020] Further, before determining the authentication result corresponding to the authentication request according to the first authentication password corresponding to the encrypted authentication password and the second authentication password corresponding to the encrypted secret information, it further includes:
[0021] Decrypting the encrypted authentication password based on the source private key of the source blockchain to obtain the first authentication password;
[0022] Decrypting the encrypted secret information based on the current private key of the current blockchain to obtain the second authentication password.
[0023] Further, determining the authentication result corresponding to the authentication request according to the first authentication password corresponding to the encrypted authentication password and the second authentication password corresponding to the encrypted secret information includes:
[0024] When it is determined that the first authentication password is the same as the second authentication password, determine that the authentication result corresponding to the authentication request is authentication successful;
[0025] When it is determined that the first authentication password is different from the second authentication password, determine that the authentication result corresponding to the authentication request is authentication failed.
[0026] In a second aspect, an embodiment of the present invention further provides an identity authentication device, including:
[0027] A determination module, configured to determine a user identity identifier and user signature data according to a received authentication request, and determine a user public key and encrypted secret information according to the user identity identifier;
[0028] A decryption module, configured to decrypt the user signature data based on the user public key to obtain an encrypted authentication password and a password hash;
[0029] An execution module, configured to perform a hash verification on the encrypted authentication password according to the password hash, and when it is determined that the verification passes, determine the authentication result corresponding to the authentication request according to the first authentication password corresponding to the encrypted authentication password and the second authentication password corresponding to the encrypted secret information.
[0030] In a third aspect, an embodiment of the present invention further provides a computer device, where the computer device includes:
[0031] At least one processor; and a memory communicatively connected to the at least one processor;
[0032] Wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the identity authentication method as described in any one of the first aspects.
[0033] In a fourth aspect, an embodiment of the present invention further provides a storage medium including computer-executable instructions, characterized in that the computer-executable instructions are used to execute the identity authentication method as described in any one of the first aspects when executed by a computer processor.
[0034] In a fifth aspect, the present application provides a computer program product, which includes computer instructions, and when the computer instructions run on a computer, the computer is caused to execute the identity authentication method provided in the first aspect.
[0035] It should be noted that the above computer instructions can be stored in whole or in part on a computer-readable storage medium. Among them, the computer-readable storage medium can be packaged together with the processor of the identity authentication device or separately packaged from the processor of the identity authentication device. This application does not make any limitations in this regard.
[0036] For the descriptions of the second, third, fourth, and fifth aspects in this application, reference can be made to the detailed description of the first aspect; moreover, for the beneficial effects of the descriptions of the second, third, fourth, and fifth aspects, reference can be made to the analysis of the beneficial effects of the first aspect, and details will not be elaborated here.
[0037] In this application, the names of the above-mentioned identity authentication devices do not constitute limitations on the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those of this application and fall within the scope of the claims of this application and their equivalent technologies.
[0038] These aspects or other aspects of this application will be more clearly understood in the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0040] Figure 1 It is a flowchart of an identity authentication method provided by an embodiment of the present invention;
[0041] Figure 2 It is a schematic structural diagram of an identity authentication system provided by an embodiment of the present invention;
[0042] Figure 3 It is a schematic structural diagram of an identity authentication device provided by an embodiment of the present invention;
[0043] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] The following will further elaborate on the present invention in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. Additionally, it should be noted that for the sake of convenience of description, only parts related to the present invention rather than all structures are shown in the drawings.
[0045] As used herein, the term "and / or" is merely a description of the relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three cases: A exists alone, A and B exist simultaneously, and B exists alone.
[0046] In the description of this application and the accompanying drawings, terms such as "first" and "second" are used to distinguish different objects or different treatments of the same object, rather than to describe a specific order of the objects.
[0047] In addition, the terms "comprising" and "having" and any variations thereof mentioned in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include other unlisted steps or units, or may optionally further include other steps or units inherent to these processes, methods, products, or devices.
[0048] Before discussing the exemplary embodiments in more detail, it should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the operations (or steps) as sequential processes, many of the operations can be implemented in parallel, concurrently, or simultaneously. In addition, the order of the operations can be rearranged. The process can be terminated when its operations are completed, but it may also have additional steps not included in the drawings. The process can correspond to a method, function, procedure, subroutine, subprogram, etc. In addition, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0049] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0050] In the description of this application, unless otherwise specified, the meaning of "a plurality of" refers to two or more.
[0051] Common identity authentication methods include username and password, two-factor authentication, multi-factor authentication, biometric recognition, smart card / e-ID, etc. Username and password are the most basic identity authentication methods, which are verified by the username and password provided by the user. Although this method is simple, it is vulnerable to security issues such as password leakage and weak passwords. Two-factor authentication adds an extra authentication step on top of the username and password, such as SMS verification code, email verification code, or one-time password (TOTP) generated by an authentication application. This method significantly improves security. Multi-factor authentication (MFA) requires users to provide multiple different types of authentication methods, such as passwords, biometric recognition (fingerprint, facial recognition, etc.), smart cards / e-ID, greatly reducing the risk of unauthorized access and further enhancing security. Biometric recognition uses the user's unique biometric features for identity authentication, such as fingerprint, facial recognition, iris recognition, and voice recognition. It has high security but requires dedicated hardware support. Smart cards / e-ID use smart cards or e-IDs embedded with encrypted chips for identity authentication. These cards are usually combined with PIN codes or biometric recognition to ensure the uniqueness and authenticity of the cardholder's identity.
[0052] Multiple authentication methods adopted by the prior art require users to perform multiple identity verifications, such as entering passwords, receiving SMS verification codes, using fingerprint recognition, etc. Each time authentication is performed, users need to spend time to complete the authentication steps, resulting in low authentication efficiency and poor user experience.
[0053] Therefore, this application proposes an identity authentication method to improve the identity authentication efficiency.
[0054] The identity authentication method proposed in this application will be described in detail below with reference to the diagrams and embodiments.
[0055] Figure 1 FIG. is a flowchart of an identity authentication method provided by an embodiment of the present invention. This embodiment is applicable to situations where the identity authentication efficiency needs to be improved. This method can be executed by an identity authentication device, such as Figure 1 As shown, it specifically includes the following steps:
[0056] Step 110: Receive an authentication request.
[0057] Step 120: Determine whether the authentication request is a forwarded authentication request.
[0058] Various services accessible to users can be deployed on the blockchain. Data is transmitted between the blockchains on which each service is deployed through a relay chain. After any service authenticates a user, the user can access other services associated with that service.
[0059] Specifically, the forwarded authentication request is sent after being signed by the relay chain. The signature can be understood as a process of encrypting the request based on the relay private key of the relay chain. After the current blockchain receives the authentication request, it can use the relay public key of the relay chain to verify the signature of the authentication request to determine whether the authentication request comes from the relay chain. That is, when it is determined that the relay public key can decrypt the authentication request, it is determined that the authentication request is a forwarded authentication request.
[0060] In the embodiment of the present invention, the signature verification of the authentication request is performed through the relay chain public key to determine whether the authentication request is a forwarded authentication request.
[0061] When it is determined that the received authentication request is a forwarded authentication request, step 130 is executed; otherwise, step 150 is executed.
[0062] Step 130: Determine the cross-chain authentication request and the request hash according to the forwarded authentication request.
[0063] In one implementation, step 130 may specifically include:
[0064] Decrypt the forwarded authentication request based on the relay public key of the relay chain that sent the authentication request to obtain the cross-chain authentication request and the request hash.
[0065] After the relay chain receives the forwarded authentication request Request_Transfer_1 signed by the source private key sent by the source blockchain, it decrypts and verifies the hash of the forwarded authentication request based on the source public key of the source blockchain, and signs it based on the relay private key of the relay chain, and can obtain the forwarded authentication request Request_Transfer_2 signed by the relay private key.
[0066] First, the relay chain decrypts the forwarded authentication request signed with the source private key based on the source public key to obtain the cross-chain authentication request and the request hash, that is, it can be determined that Hash_Result = SM2(Public_Key_BlockA, Request_Transfer_1), where Query represents the cross-chain authentication request, Hash_Result represents the hash value corresponding to the cross-chain authentication request, that is, the request hash, SM2 represents the national cryptographic algorithm SM2, and Public_Key_BlockA represents the source public key of the source blockchain A. Second, in order to ensure the integrity and correctness of the received cross-chain authentication request, the relay chain can perform a hash verification on the cross-chain authentication request based on Hash_Result. Specifically, by determining whether the hash value obtained by hashing Query is consistent with Hash_Result, the hash verification of Query is realized. When it is determined that Result = Equal(Hash_Result, SM3(Query)) is True, it is determined that Query passes the hash verification. When it is determined that Result is False, it is determined that Query fails the hash verification, and the relay chain will reject forwarding the request, where SM3 represents the national cryptographic algorithm SM3. Furthermore, the relay chain signs the cross-chain authentication request and the hash value corresponding to the cross-chain authentication request based on the relay private key to obtain the forwarded authentication request signed with the relay private key, that is, it can be determined that Request_Transfer_2 = SM2(Private_Key_Middle, Query, Hash_Result).
[0067] Specifically, when the current blockchain determines that the received authentication request is a forwarded authentication request, and the forwarded authentication request is a forwarded authentication request signed with the relay private key, therefore, the forwarded authentication request can be decrypted based on the relay public key to obtain the cross-chain authentication request and the request hash.
[0068] In the embodiment of the present invention, it is realized to decrypt the forwarded authentication request according to the relay public key of the relay chain that sends the authentication request to obtain the cross-chain authentication request and the request hash.
[0069] Step 140: Perform a hash verification on the cross-chain authentication request according to the request hash, and when it is determined that the verification passes, determine the user identity identifier and the user signature data according to the cross-chain authentication request.
[0070] Among them, the user signature data is obtained by the source blockchain that receives the authentication request encrypting the authentication password according to the source public key to obtain the encrypted authentication password, and then signing the encrypted authentication password and the password hash corresponding to the encrypted authentication password based on the user private key.
[0071] Specifically, in order to ensure the integrity and correctness of the cross-chain authentication request obtained by decryption, the cross-chain authentication request can be hash-verified according to the request hash obtained by decryption. Specifically, the Query can be hash-verified based on the Hash_Result. The hash verification of the Query is achieved by determining whether the hash value obtained by hashing the Query is consistent with the Hash_Result. When it is determined that the Result in Result = Equal(Hash_Result, SM3(Query)) is True, it is determined that the Query has passed the hash verification. When it is determined that the Result in Result = Equal(Hash_Result, SM3(Query)) is False, it is determined that the Query has not passed the hash verification, and the current blockchain will reject the request.
[0072] Query is determined by the source blockchain by packaging the initial authentication request, and the initial authentication request includes the user identity and user signature data. The user identity is determined by the current blockchain when the user registers based on the current blockchain. The user signature data is obtained by the source blockchain encrypting the authentication password based on the source public key, and then signing the encrypted authentication password and the password hash corresponding to the encrypted authentication password based on the user private key.
[0073] Therefore, after determining that the hash verification of the cross-chain authentication request has passed, the user identity and user signature data contained in the cross-chain authentication request can be determined.
[0074] In actual applications, after any blockchain receives an initial authentication request, it can search the registration information of the blockchain according to the user identity contained in the initial authentication request. If an identity consistent with the user identity is found, it indicates that the initial authentication request is used to request the blockchain. Otherwise, it indicates that the initial authentication request is used to request other blockchains. At this time, the initial authentication request can be packaged to generate a cross-chain authentication request, which includes the request type, source blockchain identifier, target blockchain identifier, user identity identifier, and user signature data. The request type is used to indicate that the authentication request is an identity authentication request, the source blockchain identifier is used to indicate the blockchain that initiates the identity authentication request, and the target blockchain identifier is used to indicate the direction for the relay chain to forward the request.
[0075] In addition, when the user device initiates identity authentication based on the source blockchain, it first encrypts the authentication password using the source public key of the source blockchain to obtain the encrypted authentication password, that is, it can be determined that Encrypt_Password = SM2(Public_Key_BlockA, Password), where Encrypt_Password represents the encrypted authentication password and Password represents the authentication password. Secondly, it performs a hash calculation on the encrypted authentication password to determine the hash value corresponding to the encrypted authentication password, that is, it can be determined that Hash_Result = SM3(Encrypt_Password), where Hash_Result represents the hash value corresponding to the encrypted authentication password. Then, it signs the encrypted authentication password and the hash value corresponding to the encrypted authentication password using the user private key to obtain the user signature data, that is, it can be determined that Sign_Request = SM2(Private_Key_User, Encrypt_Password, Hash_Result), where Sign_Request represents the user signature data and Private_Key_User represents the user private key. Furthermore, it determines the initial authentication request based on the user identity identifier and the user signature data.
[0076] The user identity identifier is determined by the blockchain when the user registers based on the blockchain. For the user identity identifier corresponding to the forwarding authentication request forwarded to the current blockchain, it is determined by the current blockchain when the user registers based on the current blockchain. Specifically, the user device can generate a user public key and a user private key, secretly store the user private key in the user device for subsequent identity verification, and publish the user public key for subsequent communication. When registering the user based on the current blockchain, the current blockchain first encrypts the user's private identity information and authentication password based on the current public key to obtain the encrypted password information, preventing the private identity information and authentication password of the user from being leaked due to being eavesdropped by a third-party attacker during the transmission process. That is, it can be determined that Encrypt_Secret = SM2(Public_Key_BlockB, Secret_Info, Password), where Encrypt_Secret represents the encrypted secret information, Public_Key_BlockB represents the current public key of the current blockchain B, and Secret_Info represents the user's private identity information. Calculate the hash value of the user's basic identity information and the encrypted secret information to obtain the hash value corresponding to the basic identity information and the encrypted secret information. That is, it can be determined that Hash_Result = SM3(Basic_Info, Encrypt_Secret), where Basic_Info represents the user's basic identity information. Sign the basic identity information, the encrypted secret information, and the hash value corresponding to the basic identity information and the encrypted secret information based on the user private key to obtain the registration request. That is, it can be determined that Requst = SM2(Private_Key_User, Basic_Info, Encrypt_Secret, Hash_Result), where Requst represents the registration request. Furthermore, the user device can send the registration request to the current blockchain.
[0077] It should be noted that the user's basic identity information can be understood as publicly available user information for daily use, such as name, gender, etc. The user's secret identity information can be understood as non-public personal privacy information, such as ID card, etc.
[0078] After the current blockchain's registration contract receives a registration request, it first decrypts the registration request based on the user's public key to obtain the basic identity information, encrypted secret information, and the hash values corresponding to the basic identity information and the encrypted secret information, so as to determine that the sender of the registration request is the user device rather than a third-party attacker, that is, it can be determined that Basic_Info, Encrypt_Secret, Hash_Result = SM2(Public_Key_User, Request). To ensure the integrity and correctness of the received basic identity information and encrypted secret information, hash verification can be performed on the basic user information and encrypted password information based on Hash_Result. Specifically, by determining whether the hash value obtained by performing a hash calculation on the basic user information and encrypted password information is consistent with Hash_Result, the hash verification of the basic user information and encrypted password information is realized. When it is determined that Result = Equal(Hash_Result, SM3(Basic_Info, Encrypt_Secret)) is True, it is determined that the hash verification is passed. When it is determined that Result is False, it is determined that the hash verification fails, and the current blockchain will reject the request.
[0079] The current blockchain can also store the user's basic identity information, encrypted secret information, authentication password, and user public key. Specifically, it is determined that User_ID = SM3((Basic_Info, Encrypt_Secret, Password, Public_Key_User)), where User_ID represents the user identity identifier, and the User_ID and the user's basic identity information, encrypted secret information, authentication password, and user public key are stored as registration information in the form of key-value.
[0080] In the embodiments of the present invention, hash verification is performed on the cross-chain authentication request according to the request hash, and when it is determined that the verification is passed, the user identity identifier and user signature data are determined according to the cross-chain authentication request, and on the premise of ensuring the integrity and correctness of the cross-chain authentication request, the user identity identifier and user signature data are determined.
[0081] Step 160 is executed after step 140.
[0082] Step 150: Determine the user identity identifier and user signature data according to the authentication request.
[0083] Specifically, when the received authentication request is a direct authentication request sent by a user device, the authentication request is determined by the user device based on the user identity and user signature data and sent to the current blockchain. Therefore, the user identity and user signature data can be directly determined based on the authentication request.
[0084] In the embodiment of the present invention, the user identity and user signature data are determined according to the authentication request.
[0085] Step 160: Determine the user public key and encrypted secret information according to the user identity.
[0086] In one implementation, step 160 may specifically include:
[0087] Search the registration information according to the user identity to determine the user information corresponding to the user identity; determine the user public key and encrypted secret information in the user information.
[0088] Among them, the registration information includes the user identity and user information of each user registered in the current blockchain.
[0089] Specifically, the registration information includes User_ID and user information stored in key-value format. Therefore, the registration information can be searched according to User_ID, and the value corresponding to the key consistent with User_ID in the registration information is determined as the user information. The user information includes the user's basic identity information, encrypted secret information, authentication password and user public key storage. Then, the user public key and encrypted secret information can be determined in the user information.
[0090] In an embodiment of the present invention, the user public key and encrypted secret information are determined according to the user identity in the registration information of the current blockchain.
[0091] Step 170: After determining that the user public key is consistent with the public key of the authentication initiator corresponding to the authentication request, the user signature data is decrypted based on the user public key to obtain the encrypted authentication password and password hash.
[0092] Specifically, it is first possible to determine whether the user public key determined in the registration information of the current blockchain is consistent with the public key of the authentication initiator, that is, it is possible to determine whether the user public key determined in the aforementioned step 150 is consistent with the user public key corresponding to the user device that initiates the authentication request, and when it is determined to be consistent, the user signature data is decrypted based on the user public key to obtain the encrypted authentication password and password hash, that is, to determine Encrypt_Password, Hash_Result = SM2 (Public_Key_User, Sign_Request). When it is determined to be inconsistent, the current blockchain can reject the request.
[0093] In an embodiment of the present invention, by determining whether the public key of the user is the same as the public key of the authentication initiator corresponding to the authentication request, the rejection of the authentication request not registered in the current blockchain is achieved, improving the security of identity authentication. The user signature data is decrypted based on the user public key, and if the encrypted authentication password and the password hash are successfully decrypted, it indicates that the authentication request is initiated by the user device corresponding to the user public key.
[0094] Step 180: Perform a hash verification on the encrypted authentication password based on the password hash, and when it is determined that the verification passes, determine a first authentication password based on the encrypted authentication password, and determine a second authentication password based on the encrypted secret information.
[0095] In one implementation, determining a first authentication password based on the encrypted authentication password and determining a second authentication password based on the encrypted secret information includes:
[0096] Decrypt the encrypted authentication password based on the source private key of the source blockchain to obtain the first authentication password; decrypt the encrypted secret information based on the current private key of the current blockchain to obtain the second authentication password.
[0097] Specifically, to ensure the integrity and correctness of the encrypted authentication password, a hash verification can be performed on the encrypted authentication password based on the password hash. Specifically, by determining whether the hash value obtained by performing a hash calculation on the encrypted authentication password is the same as the password hash, the hash verification of the encrypted authentication password is achieved. When it is determined that Result in Result = Equal(Hash_Result, SM3(Encrypt_Password)) is True, it is determined that the encrypted authentication password passes the hash verification; when it is determined that Result is False, it is determined that the encrypted authentication password fails the hash verification, and the current blockchain will reject forwarding the request.
[0098] When it is determined that the encrypted authentication password passes the hash verification, the first authentication password corresponding to the encrypted authentication password can be determined. Specifically, since the encrypted authentication password is encrypted based on the source public key, the encrypted authentication password can be decrypted based on the source private key to obtain the first authentication password. The second authentication password corresponding to the encrypted secret information can also be determined. The encrypted secret information is obtained by the current blockchain encrypting the user's private identity information and the authentication password based on the current public key when the user registers on the current blockchain. Therefore, the encrypted secret information can be decrypted based on the current private key of the current blockchain to obtain the second authentication password.
[0099] In an embodiment of the present invention, the encrypted authentication password is hash-verified through password hashing to achieve rejection of incomplete or incorrectly formatted authentication requests, determine the first authentication password based on the encrypted authentication password, and determine the second authentication password based on the encrypted secret information, thereby providing a data basis for determining the authentication result.
[0100] Step 190: Determine an authentication result corresponding to the authentication request according to the first authentication password and the second authentication password.
[0101] In one implementation, step 190 may specifically include:
[0102] When it is determined that the first authentication password is consistent with the second authentication password, the authentication result corresponding to the authentication request is determined to be authentication success; when it is determined that the first authentication password is inconsistent with the second authentication password, the authentication result corresponding to the authentication request is determined to be authentication failure.
[0103] Specifically, when the first authentication password determined according to the user signature data determined by the authentication request is consistent with the second password information determined according to the user identity determined by the authentication request, it indicates that the user corresponding to the user device that initiates the authentication request is the user registered in the current blockchain, and the authentication result of the authentication request can be determined as successful authentication. When the first authentication password determined according to the user signature data determined by the authentication request is inconsistent with the second password information determined according to the user identity determined by the authentication request, it indicates that the user corresponding to the user device that initiates the authentication request is not a user registered in the current blockchain, and the authentication result of the authentication request can be determined as failed authentication.
[0104] In an embodiment of the present invention, an authentication result corresponding to an authentication request is determined based on a first authentication password and a second authentication password, and the determination of the first authentication password undergoes multiple encryption and decryption and multiple hash verifications, thereby ensuring the security and correctness of the first authentication password, and further ensuring the security of the identity authentication process and the correctness of the identity authentication result.
[0105] The identity authentication method provided by the embodiments of the present invention, after the current blockchain receives an authentication request, first determines whether the authentication request is a forwarded authentication request. In the case where it is determined that the authentication request is a forwarded authentication request, it is determined that the current blockchain is not the source blockchain that directly received the authentication request. The forwarded authentication request is that the relay chain decrypts and performs hash verification on the forwarded authentication request signed by the source private key sent by the received source blockchain and then signs and sends it to the current blockchain. The forwarded authentication request signed by the source private key is obtained after the source blockchain determines that the initial authentication request sent by the user device does not belong to the source blockchain, packs the initial authentication request to obtain a cross-chain authentication request, performs hash calculation and signing, and then sends it to the relay chain. Therefore, the forwarded authentication request can be decrypted based on the relay public key of the relay chain that sent the authentication request to obtain the cross-chain authentication request and the request hash. Through the decryption and hash authentication of the cross-chain authentication request by the source blockchain and the relay blockchain, the security, integrity, and correctness of the cross-chain authentication request are ensured. The cross-chain authentication request is verified based on the request hash, and in the case where the verification passes, the user identity identifier and user signature data are determined based on the cross-chain authentication request. On the premise of ensuring the integrity and correctness of the cross-chain authentication request, the user identity identifier and user signature data are determined. Of course, in the case where it is determined that the authentication request is not a forwarded authentication request, it is determined that the current blockchain is the source blockchain that received the authentication request. The current blockchain can determine the user identity identifier and user signature data based on the direct authentication request. Furthermore, in the registration information of the current blockchain, the user public key and the encrypted secret information are determined based on the user identity identifier. After determining that the user public key is consistent with the public key of the authentication initiator corresponding to the authentication request, the user signature data is decrypted based on the user public key to obtain the encrypted authentication password and the password hash. By determining whether the user public key is consistent with the public key of the authentication initiator corresponding to the authentication request, the rejection of the authentication request not registered in the current blockchain is achieved, improving the security of identity authentication. Decrypting the user signature data based on the user public key to obtain the encrypted authentication password and the password hash indicates that the authentication request is initiated by the user device corresponding to the user public key. The encrypted authentication password is verified based on the password hash to reject incomplete or incorrect authentication requests. The first authentication password is determined based on the encrypted authentication password, and the second authentication password is determined based on the encrypted secret information. The authentication result corresponding to the authentication request is determined based on the first authentication password and the second authentication password. The determination of the first authentication password undergoes multiple encryption and decryption processes and multiple hash verification processes, ensuring the security and correctness of the first authentication password, and further ensuring the security of the identity authentication process and the correctness of the identity authentication result. Compared with the multiple identity authentication methods adopted by the prior art, this application reduces the user operation steps, improves the authentication efficiency, and enhances the user experience.Moreover, after any service deployed on the blockchain determines that the identity authentication is passed, other services that are also deployed on the blockchain and associated with this service will also synchronously determine that the identity authentication is passed. Users only need to register and authenticate once on one service to access multiple services associated with it, further enhancing the user experience.
[0106] Figure 2 FIG. is a schematic structural diagram of an identity authentication system provided by an embodiment of the present invention. As Figure 2 shown, the identity authentication system includes multiple blockchains and a relay chain connecting each blockchain. Each blockchain includes a registration contract, a cross-chain contract, and an authentication contract, and the relay chain includes a forwarding contract.
[0107] Any blockchain can be the source blockchain that receives the authentication request, and the blockchain for user registration is the target blockchain. The target blockchain can be understood as the current blockchain in the foregoing embodiment.
[0108] The registration contract of the target blockchain is used to, after receiving a registration request sent by a user device, decrypt the registration request based on the user public key corresponding to the user device to obtain the user's basic identity information, encrypted secret information, and encrypted hash, perform a hash verification on the user's basic identity information and encrypted secret information based on the encrypted hash, determine the hash verification result, and when determining that the hash verification result is consistent, determine the user identity identifier by performing a hash calculation on the user's basic identity information, encrypted secret information, authentication password, and user public key, and correspondingly store the user identity identifier and the user's basic identity information, encrypted secret information, authentication password, and user public key. It is also used to send the user identity identifier to the user device. It is also used to reject the registration request when determining that the hash verification result is inconsistent.
[0109] Among them, the registration request is determined based on the signature data obtained by signing the user's basic identity information, encrypted secret information, and encrypted hash with the user private key after the user device determines the user public key and user private key, encrypting the user's secret identity information and authentication password based on the target public key of the target blockchain to obtain the encrypted secret information, performing a hash calculation on the encrypted password information to obtain the encrypted hash.
[0110] The authentication contract of the source blockchain is used to, after receiving an authentication request, determine whether the authentication request belongs to the source blockchain according to the user identity identifier included in the authentication request and the registration information stored in the blockchain.
[0111] Among them, the authentication request is determined based on the user signature data and the user identity identifier obtained by the user device encrypting the authentication password with the source public key of the source blockchain to obtain the encrypted authentication password, calculating the hash of the encrypted authentication password to obtain the password hash, and signing the encrypted authentication password and the password hash based on the user private key.
[0112] The authentication contract of the source blockchain is also used to determine the user identity identifier and the user signature data according to the authentication request when it is determined that the authentication request belongs to the source blockchain.
[0113] The authentication contract of the source blockchain is also used to send the authentication request to the cross-chain contract of the source blockchain when it is determined that the authentication request does not belong to the source blockchain.
[0114] The cross-chain contract of the source blockchain is used to package the authentication request to generate a cross-chain authentication request, calculate the hash of the cross-chain authentication request, sign the cross-chain authentication request and the hash value corresponding to the cross-chain authentication request based on the source private key to obtain the forwarded authentication request encrypted with the source private key, and send the forwarded authentication request encrypted with the source private key to the relay chain.
[0115] The forwarding contract of the relay chain is used to decrypt the forwarded authentication request encrypted with the source private key based on the source public key to obtain the cross-chain authentication request and the hash value corresponding to the cross-chain authentication request, perform hash verification on the cross-chain authentication request based on the hash value corresponding to the cross-chain authentication request to determine the hash verification result. When it is determined that the hash verification result is verified successfully, sign the cross-chain authentication request and the hash value corresponding to the cross-chain authentication request based on the relay private key to obtain the forwarded authentication request encrypted with the relay private key, and send the forwarded authentication request encrypted with the relay private key to the target blockchain. It is also used to reject the forwarded authentication request encrypted with the source private key when it is determined that the hash verification result is not verified successfully.
[0116] The cross-chain contract of the target blockchain is used to decrypt the forwarded authentication request encrypted with the relay private key based on the relay public key to obtain the cross-chain authentication request and the hash value corresponding to the cross-chain authentication request, perform hash verification on the cross-chain authentication request based on the hash value corresponding to the cross-chain authentication request to determine the hash verification result. When it is determined that the hash verification result is verified successfully, send the cross-chain authentication request to the authentication contract. It is also used to reject the cross-chain authentication request when it is determined that the hash verification result is not verified successfully.
[0117] The authentication contract of the target blockchain is used to determine the user public key and the encrypted secret information in the registration information according to the user identity identifier included in the cross-chain authentication request. When it is determined that the user public key is consistent with the user device corresponding to the user public key, the user signature data included in the cross-chain authentication request is decrypted based on the user public key to obtain the encrypted authentication password and the password hash. The encrypted authentication password is verified by hashing according to the password hash to obtain the verification result. When it is determined that the hash verification result is verified to pass, the first authentication password is determined based on the encrypted authentication password, the second authentication password is determined based on the encrypted secret information, and the authentication result corresponding to the authentication request is determined according to the first authentication password and the second authentication password. It is also used to reject the cross-chain authentication request when it is determined that the hash verification result fails the verification.
[0118] The identity authentication system provided by the embodiments of the present invention has the corresponding beneficial effects of implementing the identity authentication method.
[0119] Figure 3 It is a schematic structural diagram of an identity authentication device provided by the embodiments of the present invention. This device can be applicable to situations where the identity authentication efficiency needs to be improved. This device can be implemented by software and / or hardware and is generally integrated in an electronic device, such as a computer device.
[0120] As Figure 3 shown, the device includes:
[0121] A determination module 310, configured to determine a user identity identifier and user signature data according to the received authentication request, and determine a user public key and encrypted secret information according to the user identity identifier;
[0122] A decryption module 320, configured to decrypt the user signature data based on the user public key to obtain an encrypted authentication password and a password hash;
[0123] An execution module 330, configured to perform hash verification on the encrypted authentication password according to the password hash, and when it is determined that the verification passes, determine the authentication result corresponding to the authentication request according to the first authentication password corresponding to the encrypted authentication password and the second authentication password corresponding to the encrypted secret information.
[0124] The identity authentication device provided in this embodiment reduces the user operation steps, improves the authentication efficiency, and enhances the user experience compared with the multi-factor identity authentication method adopted in the prior art. Moreover, after any service deployed on the blockchain determines that the identity authentication passes, other services that are also deployed on the blockchain and associated with this service will also synchronously determine that the identity authentication passes. The user only needs to register and authenticate once in one service to access multiple services associated with it, further enhancing the user experience.
[0125] Based on the above embodiments, the determination module 310 is specifically configured to:
[0126] When determining that the authentication request is a forwarded authentication request, determine a cross-chain authentication request and a request hash according to the forwarded authentication request; perform hash verification on the cross-chain authentication request according to the request hash, and when it is determined that the verification passes, determine the user identity identifier and the user signature data according to the cross-chain authentication request; search in the registration information according to the user identity identifier to determine the user information corresponding to the user identity identifier, where the registration information includes the user identity identifiers and user information of each user registered in the current blockchain; determine the user public key and the encrypted secret information in the user information.
[0127] In one implementation, determining a cross-chain authentication request and a request hash according to the forwarded authentication request includes:
[0128] Decrypt the forwarded authentication request based on the relay public key of the relay chain that sent the authentication request to obtain the cross-chain authentication request and the request hash.
[0129] In one implementation, the user signature data is obtained by the source blockchain that receives the authentication request encrypting an authentication password with a source public key to obtain an encrypted authentication password, and then signing the encrypted authentication password and the password hash corresponding to the encrypted authentication password based on a user private key.
[0130] Based on the above embodiments, the determination module 310 is specifically configured to:
[0131] Perform hash verification on the encrypted authentication password according to the password hash, and when it is determined that the verification passes, decrypt the encrypted authentication password based on the source private key of the source blockchain to obtain the first authentication password; decrypt the encrypted secret information based on the current private key of the current blockchain to obtain the second authentication password; when it is determined that the first authentication password is consistent with the second authentication password, determine that the authentication result corresponding to the authentication request is authentication success; when it is determined that the first authentication password is inconsistent with the second authentication password, determine that the authentication result corresponding to the authentication request is authentication failure.
[0132] The identity authentication device provided by the embodiments of the present invention can execute the identity authentication method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the identity authentication method.
[0133] It should be noted that in the embodiments of the above identity authentication device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.
[0134] Figure 4 FIG. 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Figure 4 FIG. 5 shows a block diagram of an exemplary electronic device 4 suitable for implementing the embodiments of the present invention. Figure 4 The shown electronic device 4 is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0135] As Figure 4 shown, the electronic device 4 is presented in the form of a general-purpose computing electronic device. The components of the electronic device 4 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).
[0136] The bus 18 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus architectures. For example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0137] The electronic device 4 typically includes a variety of computer system-readable media. These media can be any available media accessible by the electronic device 4, including volatile and non-volatile media, removable and non-removable media.
[0138] The system memory 28 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The electronic device 4 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 34 may be used for reading and writing non-removable, non-volatile magnetic media ( Figure 4 not shown, commonly referred to as a "hard disk drive"). Although Figure 4Not shown in the figure, a disk drive for reading and writing a removable non-volatile disk (such as a "floppy disk") and an optical disk drive for reading and writing a removable non-volatile optical disk (such as a CD-ROM, DVD-ROM or other optical medium) can be provided. In these cases, each drive can be connected to the bus 18 through one or more data medium interfaces. The system memory 28 may include at least one program product having a set (such as at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0139] The program / utility 40 having a set (at least one) of program modules 42 can be stored, for example, in the system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules 42 generally perform the functions and / or methods in the embodiments described in the present invention.
[0140] The electronic device 4 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 4, and / or communicate with any device that enables the electronic device 4 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 22. Moreover, the electronic device 4 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN) and / or a public network, such as the Internet) through the network adapter 20. As Figure 4 shown, the network adapter 20 communicates with other modules of the electronic device 4 through the bus 18. It should be understood that although Figure 4 not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 4, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0141] The processing unit 16 executes various functional applications and page displays by running the programs stored in the system memory 28. For example, it implements the identity authentication method provided by the embodiments of the present invention. The method includes:
[0142] Determining a user identity identifier and user signature data according to the received authentication request, and determining a user public key and encrypted secret information according to the user identity identifier;
[0143] After determining that the public key of the user is consistent with the public key of the authentication initiator corresponding to the authentication request, decrypt the user signature data based on the public key of the user to obtain an encrypted authentication password and a password hash;
[0144] Perform a hash verification on the encrypted authentication password according to the password hash, and when it is determined that the verification passes, determine the authentication result corresponding to the authentication request according to the first authentication password corresponding to the encrypted authentication password and the second authentication password corresponding to the encrypted secret information.
[0145] Of course, those skilled in the art can understand that the processor can also implement the technical solutions of the identity authentication method provided in any embodiment of the present invention.
[0146] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements, for example, the identity authentication method provided in the embodiment of the present invention. The method includes:
[0147] Determine the user identity identifier and the user signature data according to the received authentication request, and determine the public key of the user and the encrypted secret information according to the user identity identifier;
[0148] After determining that the public key of the user is consistent with the public key of the authentication initiator corresponding to the authentication request, decrypt the user signature data based on the public key of the user to obtain an encrypted authentication password and a password hash;
[0149] Perform a hash verification on the encrypted authentication password according to the password hash, and when it is determined that the verification passes, determine the authentication result corresponding to the authentication request according to the first authentication password corresponding to the encrypted authentication password and the second authentication password corresponding to the encrypted secret information.
[0150] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable media may be computer-readable signal media or computer-readable storage media. The computer-readable storage media may be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage media include: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this document, the computer-readable storage media may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, device, or component.
[0151] The computer-readable signal media may include data signals propagated in a baseband or as part of a carrier wave, which carry computer-readable program codes. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal media may also be any computer-readable medium other than the computer-readable storage media, and the computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, device, or component.
[0152] The program codes contained on the computer-readable media may be transmitted by any suitable medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0153] The computer program codes for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program codes may be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0154] Those of ordinary skill in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Optionally, they can be implemented with program codes executable by a computer device, so that they can be stored in a storage device and executed by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.
[0155] In addition, the acquisition, storage, use, processing, etc. of data in the technical solution of the present invention all comply with the relevant provisions of national laws and regulations.
[0156] Note that the above is only a preferred embodiment of the present invention and the applied technical principle. Those skilled in the art will understand that the present invention is not limited to the specific embodiments here. Various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, it can also include more other equivalent embodiments, and the scope of the present invention is determined by the scope of the appended claims.
Claims
1. An identity authentication method, characterized in that: include: Determine the user identity and user signature data according to the received authentication request, and determine the user public key and encrypted secret information according to the user identity; After determining that the user public key is consistent with the public key of the authentication initiator corresponding to the authentication request, decrypt the user signature data based on the user public key to obtain the encrypted authentication password and password hash; Performing hash verification on the encrypted authentication password according to the password hash, and when it is determined that the verification is passed, decrypting the encrypted authentication password based on the source private key of the source blockchain to obtain a first authentication password; decrypting the encrypted secret information based on the current private key of the current blockchain to obtain a second authentication password; When it is determined that the first authentication password is consistent with the second authentication password, determining that the authentication result corresponding to the authentication request is authentication success; When it is determined that the first authentication password is inconsistent with the second authentication password, it is determined that the authentication result corresponding to the authentication request is authentication failure.
2. The identity authentication method according to claim 1, characterized in that: Determine the user identity and user signature data based on the received authentication request, including: When it is determined that the authentication request is a forwarding authentication request, determining a cross-chain authentication request and a request hash according to the forwarding authentication request; The cross-chain authentication request is hash-verified according to the request hash, and when it is determined that the verification passes, the user identity and the user signature data are determined according to the cross-chain authentication request.
3. The identity authentication method according to claim 2, characterized in that: Determining a cross-chain authentication request and a request hash according to the forwarded authentication request includes: The forwarded authentication request is decrypted based on the relay public key of the relay chain that sends the authentication request to obtain the cross-chain authentication request and the request hash.
4. The identity authentication method according to claim 1, characterized in that: Determining the user public key and encrypted secret information according to the user identity identifier includes: Searching the registration information according to the user identity identifier to determine the user information corresponding to the user identity identifier, wherein the registration information includes the user identity identifier and user information of each user registered in the current blockchain; The user public key and the encrypted secret information are determined in the user information.
5. The identity authentication method according to claim 1, characterized in that: The user signature data is obtained by signing the encrypted authentication password and the password hash corresponding to the encrypted authentication password based on the user private key after the source blockchain that receives the authentication request encrypts the authentication password according to the source public key to obtain the encrypted authentication password.
6. An identity authentication device, characterized in that: include: A determination module, used to determine the user identity and user signature data according to the received authentication request, and determine the user public key and encrypted secret information according to the user identity; A decryption module, used to decrypt the user signature data based on the user public key to obtain an encrypted authentication password and a password hash; An execution module, configured to perform hash verification on the encrypted authentication password according to the password hash, and when it is determined that the verification is passed, decrypt the encrypted authentication password based on the source private key of the source blockchain to obtain a first authentication password; and decrypt the encrypted secret information based on the current private key of the current blockchain to obtain a second authentication password; When it is determined that the first authentication password is consistent with the second authentication password, determining that the authentication result corresponding to the authentication request is authentication success; When it is determined that the first authentication password is inconsistent with the second authentication password, it is determined that the authentication result corresponding to the authentication request is authentication failure.
7. A computer device, characterized in that: The computer device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the identity authentication method as described in any one of claims 1-5.
8. A storage medium containing computer executable instructions, characterized in that: The computer executable instructions are used to perform the identity authentication method as described in any one of claims 1-5 when executed by a computer processor.
Citation Information
Patent Citations
Block chain cross-chain authentication method, system, server, and readable storage medium
CN109257342A
Timing method and device based on block chain and storage medium
CN113609519A