Systems and methods for identity verification in a metaverse and online services using identity non-fungible tokens
By using non-fungible tokens (NFTs) for identity authentication on the blockchain, combined with a user interface and modular system, the issues of authenticity and privacy protection in virtual environments are solved, enabling comprehensive verification of user identity and information control, and enhancing security and transparency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HONG KONG APPLIED SCI & TECH RES INST
- Filing Date
- 2024-07-18
- Publication Date
- 2026-04-17
AI Technical Summary
Existing authentication methods are insufficient to ensure the authenticity of user identities and the protection of privacy in virtual environments. Traditional methods are easily forged or stolen, and user information is at risk of being leaked in unreliable online services.
It uses non-fungible tokens (NFTs) for identity authentication on the blockchain. Through a user interface, identity NFT minting module, and verifiable credential issuance module, combined with blockchain wallets and decentralized identifiers, it achieves identity verification and credential management, ensures users' control over information disclosure, and enhances security through zero-knowledge proofs and multi-factor authentication.
It enables comprehensive verification of user identity in a virtual environment, ensuring identity authenticity and privacy protection, enhancing users' control over information disclosure, improving the reliability and transparency of identity verification, and preventing identity forgery and theft.
Smart Images

Figure CN119384814B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to authentication using blockchain technology; and more particularly to systems and methods for authentication in the metaverse and online services using identity nonfungible tokens. Background Technology
[0002] Identity verification is a critical area of cybersecurity, ensuring that individual users are consistent with their claimed identities when accessing digital services and platforms. In today's digital environment, rampant identity theft and fraud underscore the importance of strong authentication mechanisms for protecting users' personal information and privacy.
[0003] A key consideration in identity verification is protecting user privacy while verifying their identity. Traditional identity verification methods that rely on image or video capture are easily vulnerable to forged or stolen IDs, or even deepfake images or other misleading information. Furthermore, in some less reputable online services, users are required to disclose their complete personal information, which can also be insecure. To address these issues, users must be given greater control over the disclosure of their personal attributes.
[0004] Furthermore, the emergence of virtual environments (such as the metaverse and Web3 projects, like social ecosystems) has brought new challenges to identity verification. In these immersive digital spaces, users interact with each other and participate in various activities using digital avatars. However, verifying the real identities behind these digital avatars presents significant challenges because existing identity verification mechanisms may not be suitable for virtual environments.
[0005] Therefore, it is necessary to develop innovative identity verification solutions tailored to the unique characteristics of the virtual environment in order to maintain online security and protect users' personal information, and further ensure the security and authenticity of users' identities. Summary of the Invention
[0006] According to a first aspect of the present invention, a system for blockchain identity authentication using non-fungible tokens (NFTs) is provided. The system includes a user interface, an identity NFT minting module, and a verifiable credential issuance module. The user interface allows a user to link a blockchain wallet and a credential wallet to the user interface, provides an online service identity identifier (or online service ID), and is configured to request the user to create a signature using the private key of the blockchain wallet and a signature using the signing key of the credential wallet, wherein the user's credential wallet is identified by the user's decentralized identifier (DID), and the user's blockchain wallet is identified by its blockchain wallet address. The Identity NFT Minting Module is configured to receive information, requests, and signatures from the user interface. This module verifies the user's online service identity identifier (Online Service ID) and verifies the user's two signatures using the blockchain wallet address and the DID, respectively. Upon successful verification, the module is further configured to mint an Identity NFT on the blockchain network, storing the online service identity identifier (Online Service ID), the blockchain wallet address, and the DID as metadata within the Identity NFT. The Verifiable Credential Issuance Module is configured to receive information, requests, and signatures from the user interface. This user interface enables the user to provide the DID and personal status information to the Verifiable Credential Issuance Module and request its issuance of a credential. The credential issuance module is further configured to issue a verifiable credential to the user upon confirmation of the request from the user interface and trigger the Identity NFT Minting Module, causing the Identity NFT minter to add credential metadata associated with the issued verifiable credential to the Identity NFT.
[0007] According to a second aspect of the present invention, a method for blockchain identity authentication using NFTs is provided. The method includes the following steps: requesting a user to associate a blockchain wallet and a credential wallet with the user interface and provide an online service identity identifier (online service ID); requesting the user to create a signature using the private key of the blockchain wallet and a signature using the signing key of the credential wallet, wherein the user's credential wallet is identified by the user's decentralized identifier (DID), and the user's blockchain wallet is identified by its blockchain wallet address; an identity NFT minting module receiving information, requests, and signatures from the user interface; the identity NFT minting module verifying the online service identity identifier (online service ID) possessed by the user; and the identity NFT minting module verifying the user's two credentials using the blockchain wallet address and the DID, respectively. The identity NFT minting module, through the identity NFT minter, mints an identity NFT on the blockchain network, and when verification is successful, saves the online service identity identification code (online service ID), the blockchain wallet address, and the DID in the identity NFT as metadata; the verifiable credential issuance module receives the user's DID, personal status information, and credential issuance request from the user through the user interface; the verifiable credential issuance module issues verifiable credentials to the user; when the request sent by the user interface to the verifiable credential issuance module is confirmed, the verifiable credential issuance module triggers the identity NFT minting module, which, through the identity NFT minter, adds the credential metadata related to the issued verifiable credential to the identity NFT.
[0008] Through various embodiments of this invention, user identity can be tightly integrated with comprehensive data to ensure the system has a complete understanding of user identity. The system can verify authenticated identity IDs and credentials, thereby ensuring authenticity. Users can control the scope of publicly available credentials, enhancing their privacy. Reliable identity verification via a public blockchain enhances trust strength. Cryptography protects privacy and prevents forgery. Real-time interaction between parties ensures up-to-date verification results. Identity IDs and credentials can be seamlessly attached to user avatars. Attached Figure Description
[0009] Embodiments of the present invention will be described in detail with reference to the accompanying drawings, wherein:
[0010] Figure 1 A schematic architecture of a system according to an embodiment of the present invention is shown, which is used for identity authentication on a blockchain using non-fungible tokens (NFTs);
[0011] Figure 2A schematic diagram illustrating the interaction between users in a system according to an embodiment of the present invention is shown.
[0012] Figure 3 A flowchart is shown according to an embodiment of the present invention, which is the casting identity NFT of stage (a);
[0013] Figure 4 A flowchart is shown according to an embodiment of the present invention, which is stage (b) of issuing verifiable credentials to an identity NFT;
[0014] Figure 5 A schematic diagram of stage (b) according to an embodiment of the present invention is shown;
[0015] Figure 6 A flowchart is shown according to an embodiment of the present invention, which is for the generation and verification of verifiable credential proof in stage (c);
[0016] Figure 7 The illustration shows a schematic diagram of the first stage of private key verification for a blockchain wallet according to an embodiment of the present invention;
[0017] Figure 8 The illustration shows a schematic diagram of the second stage of zero-knowledge proof ownership authentication according to an embodiment of the present invention; and
[0018] Figure 9 The illustration depicts a real-world scenario for verifying ownership of an identity NFT and verifiable credentials, according to an embodiment of the present invention. Detailed Implementation
[0019] In the following description, systems and methods for authentication in the metaverse and online services using identity non-fungible tokens (NFTs) are used as preferred examples. Those skilled in the art will understand that modifications, including additions and / or substitutions, can be made without departing from the scope and spirit of the invention. Specific details may be omitted so as not to obscure the invention; however, this disclosure is prepared to enable those skilled in the art to practice the teachings herein without undue experimentation.
[0020] refer to Figure 1The following description applies. System 100 has an architecture formed by deploying a user interface 110, a proof and verification module 120, a verifiable credential issuance module 130, and an identity NFT minting module 140. These functional components can typically communicate with each other over the Internet, allowing information or digital data to be transferred between them. These functional components can also interact with on-chain data through smart contracts 150; for example, at least one of the functional components can perform zero-knowledge proof (ZKP) authentication operations 152 or self-sovereign identity (SSI) verifiable credential operations 154 on the blockchain, or further upload data to the blockchain network 156 for storage.
[0021] User interface 110 can be displayed on a web browser for user operation. In one embodiment, user interface 110 is a web browser that utilizes browser extensions to allow users to operate the verifiable credential wallet 112 and blockchain wallet 114, such as MetaMask, Phantom, or other decentralized wallets. User interface 110 can also be implemented as a mobile application on a portable electronic device. The prover can use user interface 110 to initiate authentication. For example, user interface 110 allows the user to link verifiable credential wallet 112 and blockchain wallet 114 to user interface 110 and provide the user's online service identification code (online service ID, such as avatar identification code / ID). When any signature request is required, user interface 110 can request the user to create a signature for the blockchain wallet private key and a signature for the credential wallet signing key.
[0022] According to various embodiments of the present invention, the proof and verification module 120, the verifiable credential issuance module 130, and the identity NFT minting module 140 can collaborate to provide users with identity NFTs and enable authentication based on the same NFT. Each identity NFT uniquely represents a user and securely connects user identities across the metaverse, online services, blockchain, and the real world. The proof and verification module 120, the verifiable credential issuance module 130, and the identity NFT minting module 140 are configured to receive information, requests, and signatures from the user interface 110, or request necessary actions or information from it.
[0023] The Identity NFT Minting Module 140 is used to issue Identity NFTs to users. For example, an Identity NFT minter can provide an Identity NFT to a user through the Identity NFT Minting Module 140. In one embodiment, metadata of the user's identity and verifiable credentials, such as name, national identity number, income, age, avatar ID, online service user ID, blockchain wallet address, and decentralized identifier (DID), can be stored in the issued Identity NFT.
[0024] The verification module 120 is used to authenticate the user holding the identity NFT upon receiving a request from the user. Through the verification module 120, the verifier can locate the identity NFT of the avatar / online service user, confirm the user's ownership of the NFT, and verify its real-world credentials.
[0025] The verifiable credential issuance module 130 is configured to receive credential issuance requests from at least one user via a user interface 110 and determine whether to issue verifiable credentials to the user. When the request is confirmed, the verifiable credential issuance module 130 also triggers the identity NFT minting module 140 to add credential metadata to the identity NFT.
[0026] exist Figure 2 The provided diagram depicts the various users interacting with each other in system 100. The following will serve as an example to further illustrate the details of the process described above. These processes include: Phase (a), where the identity NFT minter 220 mints an identity NFT for a user (the user being the prover 200); Phase (b), where the verifiable credential issuer 210 issues a verifiable credential to the user and triggers the identity NFT minter 220 to store the metadata (metadata only) of the verifiable credential into the identity NFT; and Phase (c), where the verifier 230 generates and verifies the verifiable credential proof.
[0027] In stage (a) of casting identity NFTs, it essentially involves the interaction between the user and the identity NFT caster 220, such as Figure 3 The flowchart is shown. Stage (a) includes steps S100, S110, S120, S130, and S140. These steps of stage (a) can be executed by at least the identity NFT casting module 140.
[0028] In step S100, the user prepares a credential wallet identified by a DID (e.g., verifiable credential wallet 112), which is cryptographically associated with a wallet signing key known only to the user. The user also creates a blockchain wallet (e.g., blockchain wallet 114), identified by its own wallet address and associated with a private key known only to the user. Furthermore, based on an example involving an application on a metaverse platform or online service, the user has also completed registration for the metaverse platform / online service and received a corresponding avatar ID / online server user ID.
[0029] In step S110, the user requests an Identity NFT from the Identity NFT maker. To request an Identity NFT, the user can provide information to the Identity NFT maker 220 via the operating user interface 110 and the Identity NFT maker module 140, including at least (1) avatar ID / online server user ID; (2) the address of the blockchain wallet 114; (3) DID; and (4) two ZKP commitment values for the user's two secrets. In one embodiment, the two secrets include an identity secret and a dynamic secret, and one of the secrets is a time-limited secret. The user needs to periodically use different secrets and corresponding commitment values for identification purposes. The user can create a signature for the request using the blockchain wallet private key and the credential wallet signing key through the operating user interface 110.
[0030] In step S120, the Identity NFT Maker 220 verifies whether the user truly possesses the Avatar ID / Online Service User ID. The verification method depends on the methods supported by the Metaverse / Online Service. In one embodiment, if the mentioned ID includes an email address or phone number, the Identity NFT Maker 220 can send a verification code to the user via email or SMS to verify the ID and request the user to reply with the verification code. In another embodiment, the user operates the user interface 110 at the location of the Identity NFT Maker 220, then logs into the Metaverse / Online Service, displaying their Avatar ID / Online Service User ID to the Identity NFT Maker 220. Simultaneously, the Identity NFT Maker 220 can operate the Identity NFT Maker module 140, using the blockchain wallet address and DID respectively to verify the user's two signatures.
[0031] In step S130, once the identity NFT minting module 140 verifies the identity NFT in step S120, the next step is step S140. The identity NFT minting module is configured to mint identity NFTs on a blockchain network via identity NFT minter 220. When verification is successful, the avatar ID / online server user ID, blockchain wallet address (e.g., the wallet address that issued the NFT), and DID (e.g., the ID of a credential wallet containing a set of verifiable credentials) are stored as metadata in the minted identity NFT. In various embodiments, the mentioned wallet address can be located in a blockchain network that supports smart contracts, including any first- or second-layer chain. For “minting an identity NFT,” the identity NFT minter 220 records the identity NFT on a private or public blockchain. The identity NFT contains a data element that indicates that the aforementioned blockchain wallet address is the holder of the identity NFT. If step S130 shows verification failure, the process is aborted. After stage (a), the user can check the status of their identity NFT in blockchain wallet 114.
[0032] In phase (b), verifiable credentials are issued, which essentially involves interactions between the user, the verifiable credential issuer 210, and the identity NFT maker 220, such as... Figure 4 The flowchart shown is shown. Stage (b) includes steps S200, S210, S220, S230, S240, and S250. These steps in stage (b) can be performed by the verifiable credential issuance module 130 and the identity NFT casting module 140.
[0033] In step S200, the user prepares their identifiable credential wallet and the minted identity NFT from stage (a).
[0034] In step S210, in order to apply for the issuance of a verifiable credential, the user can provide their information to the verifiable credential issuer 210 through the user interface 110 and further request the issuance of credentials containing that information. In one embodiment, this information includes DID, age, income, etc.
[0035] After step S210, the verifiable credential issuance module 130 determines whether the information in step S210 is DID information. If so, it proceeds to step S220. In step S220, the verifiable credential issuer 210 verifies whether the user truly owns their DID. For example, the verifiable credential issuer 210 sends a challenge message to the user, requesting the user to sign the same challenge message using the signature key of the credential wallet. Then, the verifiable credential issuer uses its DID to verify the signature. After verifying that the signature is correct, it proceeds to step S240.
[0036] After step S210, if the verifiable credential issuance module 130 determines that the information in step S210 is not DID information, then step S230 is executed. In step S230, the verifiable credential issuer 210 verifies the correctness of the information provided in step S210 using other methods it deems appropriate. Then, the verifiable credential issuer 210 verifies the verified information and confirms its correctness.
[0037] Once the verification result in step S220 or S230 is positive, step S240 is then executed. In step S240, since the information provided by the user has been verified (i.e. confirmed / accepted), the verifiable credential issuer 210 can use the verifiable credential issuance module 130 to issue a credential to achieve: (1) signing the credential; (2) storing the credential validity status in the blockchain; (3) sending the credential to the user; and (4) sending / forwarding the credential metadata to the identity NFT issuer 220 through the identity NFT minting module 140.
[0038] In step S250, the user saves the credentials to their own credential wallet (e.g., credential wallet 112) via user interface 110, while the identity NFT maker 220 adds the credential metadata to the identity NFT. If the result is negative (i.e., verification fails), the process is aborted.
[0039] Figure 5 A schematic diagram of stage (b) according to an embodiment of the present invention is shown. The “user” refers to the identity NFT holder and the credential wallet holder, who creates a credential wallet with a unique DID and stores credential data in the wallet. Data storage can be implemented through any private, access-only storage method and is identified by the DID. In this regard, the DID is cryptographically associated with the holder's wallet master key and signing key. The wallet holder uses the signing key to prove their ownership of the DID and uses the master key to create credential proof.
[0040] Once the information provided by the user is verified, confirmed, and accepted, the verifiable credential issuer 210 forwards the information to the identity NFT minter 220. This allows the identity NFT minter 220 to interact with the identity NFT smart contract deployed on the blockchain, generating a record for the target identity NFT and storing the metadata (metadata only) of the verifiable credential into the identity NFT. Conversely, the content of the verifiable credential is also stored in the user's credential wallet. The identity NFT record includes data including its holder's identity, identity NFT ownership authentication settings, and credential metadata. This data storage can be implemented using a blockchain ledger with public access and identified by the identity NFT's ID (i.e., each identity NFT has a unique ID). In one embodiment, the credential metadata for each identity NFT is stored in the identity NFT record on the blockchain. In another embodiment, the credential metadata is stored in off-chain storage. For example, as... Figure 2 As shown, in order to reduce the use of blockchain resources, identity NFTs can choose to store metadata in off-chain storage, such as the interplanetary filesystem (IPFS).
[0041] In other words, users and the verifiable credential issuer 210 invoke the functions of the SSI verifiable credential utility within the SSI verifiable credential operation 154 to achieve decentralized management of digital identity. The SSI verifiable credential operation 154 enables users to manage their verifiable credentials themselves without relying on a third-party provider to store and centrally manage data. Specifically, the SSI verifiable credential operation 154 for SSI management includes: (1) the verifiable credential issuer 210 issuing real-world credentials to users; (2) users controlling the disclosure of their own real-world credentials; (3) users publicly disclosing the content of their verifiable credentials or simply proving that their verifiable credentials meet certain standards; and (4) verifiable credential verification being protected by blockchain security.
[0042] Following phase (b), the state is defined as the user already owning an Identity NFT, where the function of the Identity NFT is to manage and verify digital identities and credentials. Specifically, the enabling capabilities of Identity NFTs include: authenticating ownership of the Identity NFT using zero-knowledge proofs; storing the holder's ID (avatar ID / online service user ID, blockchain wallet address, DID); and storing verifiable credential metadata (personal information). In this way, NFT holders can establish identities in three domains (i.e., the metaverse / online service, the blockchain, and the real world). Identity NFTs provide multi-factor authentication to verify NFT ownership, support the issuance and verification of verifiable credentials, and are non-transferable (e.g., soul-bound tokens).
[0043] In phase (c), verifiable credential proofs are generated and verified, which essentially involves interactions between the user, the identity NFT maker 220, and the verifier 230, such as... Figure 6 The flowchart shown is illustrated. Phase (c) includes steps S300, S310, S320, and S330. These steps in Phase (c) are performed by the proof and verification module 120. In Phase (c), the objective is to provide an identity NFT ownership authentication mechanism that is protected by using blockchain public key encryption and multi-factor authentication based on zero-knowledge proofs; the provided mechanism also includes enabling verifiers to locate the identity NFTs of their virtual avatars / online service users and authenticate the user's ownership of the identity NFTs, as well as verify the user's real-world credentials.
[0044] In step S300, the user already possesses the identity NFT minted in stage (a) and has stored the information as described above in stage (b). In this regard, when the identity NFT minter 220 mints the identity NFT, the identity NFT holder can create two secret values and apply zero-knowledge proofs to generate two corresponding commitment values, which are then stored within the identity NFT by the identity NFT minter 220. In one embodiment, the identity NFT minter 220 can perform ownership authentication to verify the user's proof and commitment values before storing the commitment values in the identity NFT.
[0045] In step S310, the user, as the holder of the identity NFT, can first log in to the metaverse world and the WEB 3 project environment, then become a prover 200, and present the identity NFT to the validator 230 to complete the ownership authentication step. When the validator 230 encounters the prover 200 in the corresponding metaverse or online service, the validator 230 can retrieve the prover 200's avatar ID or online service user ID. In one embodiment, the validator 230's search in the blockchain includes the identity NFT containing the prover 200's avatar ID or online service user ID. In another embodiment, the prover 200 provides the validator 230 with the ID of their own identity NFT, which includes a paired avatar ID or online service user ID.
[0046] Validator 230 verifies Proveer 200's ownership of the Identity NFT. Proveer 200 needs to prove that they own the private key to a blockchain wallet (e.g., blockchain wallet 114) and that the Identity NFT is held within this wallet. Proveer 200 signs the claim using their blockchain wallet private key, and this claim includes a challenge message from Validator 230. This signature is also verified by Validator 230 using the blockchain wallet address in the Identity NFT.
[0047] Then, prover 200 proves that they know the two secrets behind the two commitment values in the identity NFT, which can begin by verifier 230 sending a one-time challenge code to prover 200; accordingly, prover 200 uses zero-knowledge proof cryptography to create a ZKP proof using the two secret values and the challenge code. After creating the ZKP proof, verifier 230 verifies the ZKP proof by applying zero-knowledge proof cryptography to the two commitment values and the challenge code.
[0048] In one embodiment, to prove ownership of an identity NFT, a multi-factor authentication of ownership of the identity NFT based on zero-knowledge proof can be adopted. For this, the prover 200 needs to go through two stages, including stage I "blockchain wallet private key verification" and stage II "zero-knowledge proof ownership authentication".
[0049] Figure 7 A schematic diagram of blockchain wallet private key verification in Phase I according to an embodiment of the present invention is shown. Phase I includes steps S400, S410, and S420. In step S400, the verifier 230 sends a one-time challenge code to the prover 200. In step S410, the prover 200 signs the one-time challenge code from the verifier 230 using their own blockchain wallet private key and sends the signature back to the verifier 230; for example, in Figure 7 The content shows that the prover 200 has a blockchain wallet with the address "0x9e…" and a private key "zb0t…". In step S420, the verifier 230 verifies the signature using the blockchain wallet address in the identity NFT to confirm that the prover 200 possesses the corresponding private key. In the accompanying diagram, a one-time challenge code is used to prevent the signature from being reused.
[0050] Figure 8 A schematic diagram of zero-knowledge proof ownership authentication in Phase II according to an embodiment of the present invention is shown. In one embodiment, a secret and a commitment are used in this phase; however, the identity NFT only stores the zero-knowledge proof commitment (i.e., it does not store the secret itself), and the identity secret and dynamic secret are reserved only for the prover. For example, the authorized issuer stores two zero-knowledge proof commitment values in the prover's identity NFT, and: (1) the identity secret, whose range ∈ Zp; and (2) the dynamic secret, whose range ∈ Zp, and which is never disclosed to any verifier. In the figures, the blocks labeled "ZKP transformation" are operations used for zero-knowledge proof computation. These blocks are constructed using elliptic curve point addition / multiplication for the transformation: P1+P s nP, discrete log p n; for example, z = SHA2(n)mod(p)*G + 2m*P1.
[0051] Phase II includes steps S500, S510, and S520. In step S500, the prover sends a message to the verifier declaring that the prover possesses the target identity NFT. In step S510, the verifier sends the challenge code {0,1}. n=<Zp space The proof is used to verify the prover's knowledge of the promised secrets, including knowledge of the identity secret and the dynamic secret. In one embodiment, a challenge-response protocol is applied to prevent the proof from being reused. In step S520, the prover proves to the verifier their knowledge of the two secrets. In one embodiment, the prover may also optionally prove knowledge by using a new dynamic secret; for example, if the verifier is an authorized issuer, the verifier can adopt a new dynamic secret. In this regard, for better protection, the dynamic secret is periodically updated with a new secret. In one embodiment, each secret (e.g., the identity secret) is designed to contain multiple sub-secrets, thereby increasing the difficulty of hacking, where the sub-secrets can be combined into a single secret with corresponding secret promises. After step S520, the verifier verifies the proof from the prover and outputs a result indicating whether the proof is valid or invalid. Once the proof from the prover is verified, the prover's possession of both secrets is verified, and ownership of the identity NFT is also authenticated.
[0052] Stage II enables the use of zero-knowledge proofs to establish mathematical foundations, such as elliptic curve cryptography curves: y 2 =x 3 +ax+bmod(p), with order n, cofactor h, base point G, and field size p. The relevant setup information will be described here.
[0053] An identity NFT contains two commitment values, which can be added during minting. The commitment values are generated as follows.
[0054] (1) The prover sets two secrets and keeps them secret. The secrets are:
[0055] a) Identity secret, The prover calculates the identity secret commitment using ZKP transformation 1: Z = k·G;
[0056] b) Dynamic secrets The prover calculates the dynamic secret commitment using ZKP transformation 2: X = r·G;
[0057] (2) The prover discloses commitments Z and X to the identity NFT maker, who stores them in the identity NFT and makes them public.
[0058] Proof and verification procedures:
[0059] When the prover subsequently claims ownership of the identity NFT to the validator, the following will happen:
[0060] (a) The certifier declares ownership of the identity NFT;
[0061] (b) The validator selects a challenge code. And pass it on to the prover;
[0062] (c) The prover applies ZKP transformation 3 to the two secret and challenge codes and generates the following proof: t = (k·e+r)modp;
[0063] (d) The verifier retrieves two commitments (Z and X) from the identity NFT and then applies the proof to the subsequent ZKP Transform 4 operation: res = y·Ge·Z;
[0064] (e) The verifier checks whether “res” and X are the same; if they are, the verification is valid.
[0065] The following explains why res and X should be the same:
[0066] y·Ge·Z=(ke+r)·Ge·k·G=e·k·G+r·Ge·k·G=r·G=X
[0067] In one embodiment, if the dynamic secret has been set for a long time, the prover can change their own dynamic secret r to further enhance security.
[0068] refer to Figure 6 Following step S310, when verifier 230 successfully verifies ownership of prover 200's identity NFT, the process proceeds to step S320. In step S320, verifier 230 examines the credential metadata in the identity NFT to obtain a list of credentials (i.e., the names and types of credentials). For each credential, verifier 230 requests proof from the prover of the complete content of the credential or proof of a credential that meets certain requirements. Similarly, the request includes a unique challenge code to prevent secondary use of the proof. In step S330, prover 200 can generate a proof using the verifier's proof request, the credential metadata stored in the identity NFT, and the credentials from the prover's credential wallet. After step S330, once verifier 230 verifies the proof from prover 200 as true, the recognition phase (c) (i.e., generating and verifying the verifiable credential proof) succeeds; otherwise, the verification fails.
[0069] In one embodiment, in steps S320 and S330, verifier 230 verifies the prover's ownership of the DID stored in the identity NFT by challenging prover 200. This includes requesting prover 200 to sign a challenge message using a credential wallet signing key. Verifier 230 then verifies the signature using the DID. Verifier 230 also requests prover 200 to create a verifiable credential proof confirming its own DID value. Furthermore, verifier 230 can continue to verify prover 200's real-world information by requesting prover 200 to disclose prover's credentials. In one embodiment, verifier 230 requests prover 200 to disclose the full contents of a subset of verifiable credentials and generates a proof of another subset of verifiable credentials to demonstrate that they meet specific requirements.
[0070] In phase (c), a credential proof cannot be constructed, or the credential proof is rejected by the proof and verification module 120, if any of the following occurs:
[0071] (a) The certificate proves that the contents of the issued certificate are inconsistent; or
[0072] (b) The certificate is constructed from a certificate that has been revoked by the issuer; or
[0073] (c) The credential proof is constructed from a credential of another DID owned by the prover; or
[0074] (d) The certificate is constructed from a certificate issued by an unrecognized certificate issuer; or
[0075] (e) The credentials were constructed from another user's credentials; or
[0076] (f) The credential is a copy of the credential of another individual / organization; or
[0077] (g) The credential has been modified and is linked to the validity status of another user credential (in the region).
[0078] (in the blockchain).
[0079] Figure 9 The illustration depicts a real-world scenario according to an embodiment of the present invention, which verifies ownership and verifiable credentials of an identity NFT. In the scenario, the prover is set to have DID: abc34; Name: Bob; Age: 21; Salary: 45k, all stored in a credential wallet, and the prover owns the identity NFT. To perform verification, the prover first operates the user interface (e.g., ...). Figure 1 The user interface 110 presents Alice with her identity NFT (i.e., the prover's identity NFT), and Alice is the verifier in the scene. The proof and verification modules (e.g., Figure 1The proof and verification module 120 receives the presentation from the prover. The verifier then verifies the prover's ownership of the identity NFT through the proof and verification module, which interacts with the blockchain network, and ensures that the prover's ID matches the ID recorded in this identity NFT. After verifying ownership of the identity NFT and receiving the result from the blockchain network via the proof and verification module, the verifier can request proof from the prover through the user interface and the proof and verification module. The proof includes: DID: abc34; Name: Bob; Age >= 18; Salary >= 30k. The prover then retrieves the identity NFT from the blockchain network by operating the user interface. The result of the identity NFT retrieval is sent back from the blockchain network to calculate the proof using the credential wallet content. The prover then presents the proof to the verifier, which can be received and displayed by the proof and verification module: DID: abc34; Name: Bob; Age >= 18; Salary >= 30k. In the final stage, the validator requests the necessary information from the blockchain (such as credential metadata and credential validity status) and performs verification using the prover and validator modules; then the validator checks whether the verification was successful or failed.
[0080] In various embodiments, the proof and verification module (e.g., Figure 1 The proof and verification module 120 is configured to reject or defend against possible attacks by forgers, including theft of ownership of identity NFTs, forgery of verifiable credential proofs, verifiable credential proofs with incorrect credential information, verifiable credential proofs inconsistent with issued credentials, verifiable credential proofs constructed from issued credentials that have been revoked by the credential issuer, verifiable credential proofs constructed from credentials of another DID owned by the same prover, verifiable credential proofs constructed from credentials issued by a credential issuer that has never been recognized, theft of verifiable credential proofs, using another user's credential proof as the prover's own credential, constructing proofs using another user's credentials, and creating credential proofs but linking them to the validity status (in the blockchain) of another user's credential.
[0081] Regarding the prevention of ownership theft of identity NFTs, various embodiments of the present invention provide the following multi-factor authentication of ownership: (a) Cryptographic private key authentication by the identity NFT holder: The identity NFT holder needs to sign the verifier's challenge message using a blockchain wallet private key known only to themselves. The verifier can use the blockchain wallet address marked within the identity NFT to verify the authentication code. (b) Ownership authentication using zero-knowledge proof (ZKP): The identity NFT contains two unique digital codes called commitments, which are generated by encrypting two secret values known only to the identity NFT holder; the identity NFT holder needs to use zero-knowledge proof cryptography to create a ZKP proof using these two secret values; the ZKP proof can be verified by another party by applying zero-knowledge proof cryptography to the proof against the two commitments.
[0082] To prevent identity forgers from guessing the secrets, in various embodiments of the invention, a time-limited secret can be provided within one of the secrets. The holder needs to periodically allocate different secrets and corresponding commitment values for the verifier to identify.
[0083] To prevent identity forgers from reusing another user's ZKP proof, various embodiments of the present invention stipulate that each ZKP proof is constructed from a one-time unique challenge code specified by the verifier. A reused ZKP proof detected by the verifier will not match the challenge code.
[0084] Regarding the prevention of credential forgery, various embodiments of the present invention provide the following rules: (a) verifiable credentials must be issued by a credential issuer recognized by the verifier; and (b) verifiable credential provers must use a one-time unique code specified by the verifier to create the proof.
[0085] For (a) a verifiable credential issued by a credential issuer recognized by the verifier, there are four possible scenarios and corresponding results. (ai) The verifiable credential proof is inconsistent with the content of the issued credential: When the credential data content claimed by the prover is inconsistent with the credential content signed by the credential issuer, the proof cannot be generated. (a-ii) A verifiable credential proof constructed from a credential that has been revoked by the credential issuer: The verifier can detect invalidity by verifying it against the credential validity status in the blockchain. (a-iii) A verifiable credential proof constructed from a credential of another DID owned by the prover: The verifier will be able to verify this situation because this proof cannot be proven by a DID belonging to the identity NFT. (a-iv) A verifiable credential proof constructed from a credential issued by an unidentified credential issuer: The proof detected by the verifier is not constructed from a credential issued and signed by the credential issuer designated by the verifier.
[0086] For (b) where a verifiable credential prover is required to create a proof using a one-time unique code specified by the verifier, there are three possible scenarios and corresponding results. (bi) Using another user's credential proof as their own: Each credential proof is constructed based on a one-time unique challenge code specified by the verifier. Therefore, the verifier will detect a reused credential proof because it does not match the challenge code specified by the verifier. (b-ii) Constructing a proof using another user's credentials: The other user's credentials are cryptographically incompatible with the prover's credential wallet and master key. Therefore, the prover cannot store the credentials in the prover's credential wallet, nor can they successfully construct a proof using the prover's master key. (b-iii) Constructing a credential proof and then manually linking it to the validity state of another user's credentials (in the blockchain): In a maliciously modified proof, the altered validity state link will make the proof inconsistent with the prover's cryptographic fingerprint. The verifier can detect that this proof is invalid.
[0087] Based on the above configuration, this invention offers several positive benefits. First, it emphasizes the tight integration of multiple user identities to create a comprehensive user identity profile. This ensures a more holistic understanding of user identities. Furthermore, this invention can verify a user's authenticated identity ID and credentials, thereby ensuring their authenticity. Importantly, users retain control over the scope of credentials disclosed to the verifier, thus enhancing privacy protection. In addition, this invention provides reliable identity verification to the public through a public blockchain, thereby enhancing trust and transparency. By utilizing cryptographic technology, this invention effectively protects privacy while preventing identity forgery and theft. Furthermore, real-time interaction between credential issuers, identity holders, and verifiers ensures that verification is based on the latest information. Moreover, this invention allows identity IDs and credentials to be attached to avatars without distorting their images, thus seamlessly integrating identities into the virtual environment.
[0088] Functional units and modules of the apparatus and methods according to the embodiments disclosed herein can be implemented using computing devices, computer processors, or electronic circuits, including but not limited to application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), microcontrollers, and other programmable logic devices configured or programmed according to the teachings of this disclosure. Those skilled in the art of software or electronics can readily prepare computer instructions or software code to run in computing devices, computer processors, or programmable logic devices based on the teachings of this disclosure.
[0089] All or part of the methods according to the embodiments can be executed in one or more computing devices, including server computers, personal computers, laptops, and mobile computing devices (such as smartphones and tablets).
[0090] Embodiments may include computer storage media, transient and non-transient memory devices storing computer instructions or software code, which can be used to program or configure computing devices, computer processors, or electronic circuits to perform any of the processes of the present invention. Storage media, transient and non-transient memory devices may include, but are not limited to, floppy disks, optical disks, Blu-ray discs, DVDs, CD-ROMs, magneto-optical disks, ROMs, RAMs, flash memory devices, or any type of medium or device suitable for storing instructions, code, and / or data.
[0091] Each functional unit and module according to various embodiments can also be implemented in a distributed computing environment and / or cloud computing environment, wherein all or part of the machine instructions can be executed in a distributed manner by one or more processing devices interconnected by a communication network, such as an intranet, a wide area network (WAN), a local area network (LAN), the Internet, and other forms of data transmission media.
[0092] The foregoing description of the present invention is provided for illustrative purposes. It is not intended to be exhaustive or to limit the invention to the precise forms disclosed. Many modifications and variations will be apparent to those skilled in the art.
[0093] These embodiments were chosen and described in order to best explain the principles of the invention and its practical application, thereby enabling those skilled in the art to understand the various embodiments of the invention and the various modifications suitable for particular purposes.
Claims
1. A system, characterized in that, Utilize non-fungible tokens; NFTs are used for blockchain identity verification, including: The user interface allows users to link blockchain wallets and credential wallets to the user interface, provides an online service identification code, and is configured to request the user to create a signature using the private key of the blockchain wallet and the signing key of the credential wallet, wherein the user's credential wallet is identified by the user's decentralized identifier (DID), and the user's blockchain wallet is identified by its blockchain wallet address; An identity NFT minting module is configured to receive information, requests, and signatures from the user interface. This module is configured to verify the online service identity identifier possessed by the user and to verify the user's two signatures using the blockchain wallet address and the DID, respectively. Upon successful verification, the identity NFT minting module is further configured to mint an identity NFT on the blockchain network, thereby storing the online service identity identifier, blockchain wallet address, and DID as metadata in the identity NFT. A verifiable credential issuance module is configured to receive information, requests, and signatures from the user interface, wherein the user interface enables the user to provide the DID and personal status information to the verifiable credential issuance module and request the verifiable credential issuance module to issue a credential, wherein the verifiable credential issuance module is further configured to issue a verifiable credential to the user after the request issued by the user interface to the verifiable credential issuance module is confirmed, and to trigger the identity NFT minting module, such that the identity NFT minting module adds credential metadata related to the issued verifiable credential to the identity NFT.
2. The system according to claim 1, characterized in that, The identity NFT minting module mints the identity NFT, and the identity NFT contains data elements indicating that the blockchain wallet address is the holder of the identity NFT.
3. The system according to claim 1, characterized in that, After successfully verifying the user's ownership of the DID, the verifiable credential issuer module accepts requests from the user interface to the verifiable credential issuer module.
4. The system according to claim 3, characterized in that, During the verification of the user's ownership of the DID, the verifiable credential issuance module sends a challenge message to the user and requests the user to sign the challenge message using the signing key of the credential wallet. The verifiable credential issuance module is also configured to verify the signature of the challenge message using the DID.
5. The system according to claim 3, characterized in that, The verifiable credentials include: Document metadata, including document name and type; Validity status, which indicates whether the credential is valid or has been revoked; and The credentials data are related to the information provided by the user.
6. The system according to claim 5, characterized in that, The verifiable credential issuance module is also configured to: The credential metadata is forwarded to the identity NFT casting module for storage in the identity NFT; The validity status is stored in a blockchain network accessible to public users; as well as The credential data is forwarded to the user and stored in the user's credential wallet, making the user the holder of the credential.
7. The system according to claim 1, characterized in that, The user interface is also configured to request the user to create two secret values and apply zero-knowledge proofs (ZKP) to generate two corresponding commitment values to be stored within the identity NFT by the identity NFT minter, and the identity NFT minting module is also configured to mint the identity NFT, which contains the two corresponding commitment values.
8. The system according to claim 7, characterized in that, Also includes: The proof and verification module is configured to request the user to prove, through the user interface, their knowledge of the two secrets behind the corresponding commitment value in the identity NFT.
9. The system according to claim 8, characterized in that, The proof and verification module is also configured to: Send a one-time challenge code to the user through the user interface; The user is requested to create a ZKP proof using the two secret values and the challenge code, employing zero-knowledge proof cryptography. as well as The ZKP proof is verified by applying zero-knowledge proof cryptography to verify the ZKP proof against the two corresponding commitment values and the challenge code.
10. The system according to claim 9, characterized in that, The proof and verification module is also configured to: Create verifiable credentials that confirm the user's DID; and The user's real-world information is verified by requesting the user to disclose their credentials through the user interface; The proof and verification module is allowed to request the user to disclose the full contents of a subset of verifiable credentials owned by the user through the user interface, and to generate proof of another subset of the verifiable credentials owned by the user to prove that the verifiable credentials meet specific requirements; The proof and verification module refuses to construct the verifiable credential proof under the following circumstances: The verifiable certificate is inconsistent with the content of the issued certificate from the verifiable certificate issuance module; or The verifiable credential is constructed from a credential that has been revoked by the verifiable credential issuance module; or The verifiable credentials are constructed from the credentials of another DID owned by the user; or Verifiable credentials are constructed from credentials issued by unapproved credential issuers, or The verifiable credentials were constructed from another user's credentials; or A verifiable credential is a copy of a credential from another individual or organization; or The validity status of a verifiable credential that has been modified and linked to another user's credential in a blockchain network.
11. A blockchain identity authentication method, characterized in that, Utilize non-fungible tokens; NFTs (Non-Finite Tokens) are used for blockchain identity verification, including: The user interface requests the user to associate their blockchain wallet and credential wallet with the user interface and provides an online service identification code; Through the user interface, the user is requested to create a signature using the private key of the blockchain wallet and the signing key of the credential wallet, wherein the user's credential wallet is identified by the user's decentralized identifier (DID) and the user's blockchain wallet is identified by its blockchain wallet address; The identity NFT casting module receives information, requests, and signatures from the user interface; The identity NFT casting module verifies the online service identity identification code possessed by the user; The identity NFT minting module uses the blockchain wallet address and the DID to verify the user's two signatures respectively; The identity NFT minting module mints identity NFTs on the blockchain network through identity NFT minters, and when the verification is successful, it saves the online service identity identification code, the blockchain wallet address and the DID in the identity NFT as metadata. The verifiable credential issuance module receives the user's DID, personal status information, and credential issuance request from the user through the user interface. The verifiable credential issuance module issues verifiable credentials to the user; Once the request sent by the user interface to the verifiable credential issuance module is confirmed, the verifiable credential issuance module triggers the identity NFT casting module, which adds the credential metadata related to the issued verifiable credential to the identity NFT through the identity NFT casting module.
12. The authentication method according to claim 11, characterized in that, The identity NFT minting module mints the identity NFT, and the identity NFT contains data elements indicating that the blockchain wallet address is the holder of the identity NFT.
13. The authentication method according to claim 11, characterized in that, After successfully verifying the user's ownership of the DID, the verifiable credential issuer module accepts requests from the user interface to the verifiable credential issuer module.
14. The authentication method according to claim 13, characterized in that, During the verification of the user's ownership of the DID, the verifiable credential issuance module sends a challenge message to the user and requests the user to sign the challenge message using the signing key of the credential wallet. The verifiable credential issuance module is also configured to verify the signature of the challenge message using the DID.
15. The authentication method according to claim 13, characterized in that, The verifiable credentials include: Document metadata, including document name and type; Validity status, which indicates whether the credential is valid or has been revoked; and The credentials data are related to the information provided by the user.
16. The authentication method according to claim 15, characterized in that, Also includes: The verifiable credential issuance module forwards the credential metadata to the identity NFT minting module. To be stored in the identity NFT; The verifiable credential issuance module stores the validity status in a blockchain network accessible to public users. as well as The verifiable credential issuance module forwards the credential data to the user for storage in the user's credential wallet, making the user the holder of the credential.
17. The authentication method according to claim 11, characterized in that, Also includes: Through the user interface, the user is requested to create two secret values and apply zero-knowledge proofs (ZKP) to generate two corresponding commitment values to be stored within the identity NFT by the identity NFT minter, and the identity NFT minting module is also configured to mint the identity NFT, which contains the two corresponding commitment values.
18. The authentication method according to claim 17, characterized in that, Also includes: Through the proof and verification module and the user interface, the user is asked to prove their knowledge of the two secrets behind the corresponding commitment value in the identity NFT.
19. The authentication method according to claim 18, characterized in that, Also includes: A one-time challenge code is sent to the user through the proof and verification module and the user interface; The proof and verification module requests the user to create a ZKP proof using the two secret values and the challenge code through zero-knowledge proof cryptography. as well as The ZKP proof is verified by the proof and verification module and also by applying zero-knowledge proof cryptography to verify the ZKP proof against the two corresponding commitment values and the challenge code.
20. The authentication method according to claim 19, characterized in that, Also includes: The proof and verification module creates a verifiable credential proof that confirms the user's DID. and Through the proof and verification module and the user interface, the user is requested to disclose the user's credentials, thereby verifying the user's real-world information; The proof and verification module is allowed to request the user to disclose the full contents of a subset of verifiable credentials owned by the user through the user interface, and to generate proof of another subset of the verifiable credentials owned by the user to prove that the verifiable credentials meet specific requirements; The proof and verification module refuses to construct the verifiable credential proof under the following circumstances: The verifiable certificate is inconsistent with the content of the issued certificate from the verifiable certificate issuance module; or The verifiable credential is constructed from a credential that has been revoked by the verifiable credential issuance module; or The verifiable credentials are constructed from the credentials of another DID owned by the user; or Verifiable credentials are constructed from credentials issued by unapproved credential issuers, or The verifiable credentials were constructed from another user's credentials; or A verifiable credential is a copy of a credential from another individual or organization; or The validity status of a verifiable credential that has been modified and linked to another user's credential in a blockchain network.
Citation Information
Patent Citations
Block chain digital identity authentication control system and method
CN117176361A
Method for securely printing one or more three-dimensional objects visualized in a computer simulated virtual environment communicatively coupled to a blockchain network
WO2024042066A1