A method and system for realizing trusted data flow based on digital identity

By registering as a trusted issuing agency on the data circulation platform and issuing verifiable credentials, the problem of users repeatedly submitting identity proof during cross-platform data circulation is solved, and efficient and secure cross-platform data circulation and identity authentication are achieved.

CN119402263BActive Publication Date: 2025-10-10BEIJING INSPUR CLOUD COMPUTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411536119.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2025-10-10
Estimated Expiration
2044-10-31

AI Technical Summary

Technical Problem

Existing data circulation businesses lack a trusted digital identity management mechanism, which requires users to repeatedly submit identity documents between different platforms, increasing time costs and reducing the willingness to conduct multi-regional transactions.

Method used

By having digital identity issuers from all over the country register as trusted issuing agencies on the data circulation and utilization service platform, a unique DID is generated and a verifiable certificate VC is issued. By combining asymmetric keys and distributed evidence storage technology, cross-platform identity authentication and data circulation can be achieved.

Benefits of technology

It achieves high efficiency and security in cross-platform data flow, reduces the time cost of repeated registration for users, improves the credibility and traceability of data flow, and resolves identity authentication disputes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402263B_ABST
    Figure CN119402263B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data security, in particular to a trusted data circulation implementation method and system based on digital identity, which comprises the following steps: digital identity issuing parties in various places register as trusted issuing agencies through a data circulation utilization service platform, and the DID and a DID Document containing the public key of the issuing party of the DID are disclosed; the issuing party generates a unique DID for an individual or an enterprise, and issues a verifiable certificate VC for the enterprise according to requirements; beneficial effects are as follows: the trusted data circulation implementation method and system based on digital identity promote efficient data circulation, so that each participant does not need to register multiple types of users and repeatedly submit materials, time before the scene is saved; data circulation safety is improved, asymmetric keys and distributed storage technology are used, the identity of the participant is trusted, data tracing is helpful, and disputes are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a method and system for implementing trusted data circulation based on digital identity. Background Art

[0002] With the rapid development of information technology, multi-party data circulation is becoming a growing trend. From early single data sources to today's cross-platform and cross-industry data integration, data circulation not only enhances information transparency but also promotes scientific decision-making. Driven by technologies such as big data, privacy-preserving computing, and blockchain, data circulation will become more efficient and secure in the future, providing strong support for social development and governance.

[0003] However, existing data circulation businesses lack a reliable digital identity management mechanism. Data exchanges often operate in a siloed architecture, making it difficult to unify identities across platforms. After completing transactions at one data exchange, users must resubmit their identity documents when conducting business on the Zero One trading platform, increasing user time and reducing their willingness to trade across multiple regions. Summary of the Invention

[0004] The purpose of the present invention is to provide a method and system for implementing trusted data circulation based on digital identity to solve the problems raised in the above background technology.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for implementing trusted data circulation based on digital identity, the method comprising the following steps:

[0006] Digital identity issuers in various regions register as trusted issuing agencies through the data circulation and utilization service platform and disclose their DID and DID Document containing the issuer's public key;

[0007] The issuer generates a unique DID for an individual or enterprise and issues a verifiable certificate (VC) to the enterprise based on demand;

[0008] The issuer will encrypt and store the issued VC or centrally host it, and at the same time make public the DID Document and VC signature information of the individual or enterprise. The DID and private key of the individual or enterprise will be stored through a secure client and kept by the individual or enterprise for subsequent data circulation and verification.

[0009] Preferably, the following verification process is also included:

[0010] Users access the data circulation platform through a digital identity client and submit their personal or corporate DID as a login request;

[0011] The data circulation platform generates a login random code and login link, encrypts them with the personal or corporate public key, and returns them to the digital identity client;

[0012] The digital identity client uses the private key to decrypt the encrypted information and verify the legitimacy of the user's identity;

[0013] The digital identity client uses the private key to issue an authorization command, sends the random number, authorization command, and enterprise DID to Identity Hub, and agrees to send VC information to the login link;

[0014] After receiving the authorization command, Identity Hub sends the VC and random number to the login link of the data circulation platform so that the data circulation platform can verify the issuer of the VC and its credibility.

[0015] Preferably, in the verification process, the data circulation platform further includes the following steps:

[0016] Obtain enterprise VC information and verify whether the issuer of VC is a registered and trusted issuing authority;

[0017] Request the data circulation and utilization service platform to verify whether the issuer is in the list of trusted issuing agencies. If so, the verification is passed and the user is allowed to perform data circulation operations.

[0018] Preferably, the overall architecture of the digital identity management platform includes a data resource layer, an application support layer, a business application layer, and a user interaction layer, wherein:

[0019] The data resource layer includes a user information library, an identity credential information library, a risk control strategy library, and an audit log library, which are used to store and manage various types of information related to data circulation;

[0020] The application support layer includes single sign-on, multi-factor authentication, data encryption, and multi-source verification technology components, providing secure technical support for data circulation;

[0021] The business application layer includes four business modules: identity management, agent management, access control, and audit supervision, providing comprehensive business management and risk control services;

[0022] The user interaction layer provides user registration, user login, user retrieval, user center and digital identity client modules, providing users with convenient account management and data circulation services.

[0023] Preferably, the digital identity client of the user interaction layer is a digital identity management APP or U shield, which is used to store user credential information and support credential presentation and verification functions so that users can prove their identity and authority during data circulation.

[0024] A digital identity-based trusted data circulation implementation system, applied to a digital identity-based trusted data circulation implementation method, the system comprising:

[0025] The trusted issuing authority registration module is used by digital identity issuers in various regions to register as trusted issuing authorities through the data circulation and utilization service platform and disclose their DID and DID Document containing the issuer's public key;

[0026] The DID generation and VC issuance module is used to generate a unique DID for an individual or enterprise, and issue a verifiable VC for the enterprise as needed;

[0027] The VC storage and publishing module is used to encrypt and store the issued VC or centrally host it, while making the DID document and VC signature information of individuals or enterprises public. The DID and private key of individuals or enterprises are stored in a secure client.

[0028] The digital identity authentication module is used to authenticate users through the digital identity client when they access the data circulation platform. This includes generating a random login code and the platform login URL, encrypting them with the public key, and returning them to the digital identity client. The client then uses the private key to decrypt and verify the user's identity.

[0029] The VC verification and issuing agency verification module is used to verify the VC issuer and its credibility after obtaining the enterprise VC information on the data circulation platform, and request the data circulation utilization service platform to verify whether the issuer is a trustworthy issuing agency.

[0030] Preferably, it also includes a data resource layer for storing a user information library, an identity credential information library, a risk control policy library and an audit log library to support the security and traceability of the entire data flow process.

[0031] Preferably, an application support layer is also included, which includes single sign-on, multi-factor authentication, data encryption, and multi-source verification technology components to provide secure technical support and ensure the security of data transmission and storage.

[0032] Preferably, it also includes a business application layer, including four business modules: identity management, agent management, access control, and audit supervision, to provide comprehensive identity management, risk control, and service support;

[0033] Among them, the identity management module provides information verification of the issuer, individual and corporate identities, and provides services for issuing, managing, updating and revoking certificates; the agent management module provides internal employee management, agent position certificate issuance, management, updating and revocation services; the access control module provides a variety of user authentication methods, and has the ability to manage blacklists and whitelists, and risk control strategies; the audit supervision module mainly focuses on user login operation log audits, certificate issuance and update log audits, and promptly discovers security risks of user identity information leakage.

[0034] Preferably, it also includes a user interaction layer, which provides user registration, user login, user retrieval, user center and digital identity client modules to provide users with one-stop account management services;

[0035] Among them, the user registration module is used by individuals or enterprises to complete user registration and submit authentication materials; the user login module provides a user login entrance to complete user login interaction; the user retrieval module provides a user account complaint entrance when the user account is lost; the user center module provides a user center to manage personal user information and credential information; the digital identity client module provides a digital identity management APP or U shield to store user credential information and support credential presentation and verification functions.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] The digital identity-based trusted data circulation implementation method and system proposed in the present invention promote efficient data circulation, eliminating the need for participants to register multiple types of users and repeatedly submit materials, saving pre-event time; improving data circulation security, using asymmetric keys and distributed evidence storage technology to ensure the credibility of the identities of participants, facilitating data tracing and resolving disputes. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 Flow chart of the knotting method of the present invention;

[0039] Figure 2 This is a system block diagram of the present invention. DETAILED DESCRIPTION

[0040] In order to clearly and completely describe the objectives and technical solutions of the present invention and make the advantages more clearly understood, the embodiments of the present invention are further described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are part of the embodiments of the present invention, not all of them, and are only used to explain the embodiments of the present invention, not to limit the embodiments of the present invention. All other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0041] In a first embodiment, the present invention provides a technical solution: a method for implementing trusted data circulation based on digital identity, the method comprising the following steps:

[0042] Digital identity issuers in various regions register as trusted issuing agencies through the data circulation and utilization service platform and disclose their DID and DID Document containing the issuer's public key;

[0043] The issuer generates a unique DID for an individual or enterprise and issues a verifiable certificate (VC) to the enterprise based on demand;

[0044] The issuer will encrypt and store the issued VC or centrally host it, and at the same time make public the DID Document and VC signature information of the individual or enterprise. The DID and private key of the individual or enterprise will be stored through a secure client and kept by the individual or enterprise for subsequent data circulation and verification.

[0045] It also includes the following verification process: the user accesses the data circulation platform through the digital identity client and submits the personal or corporate DID as a login request; the data circulation platform generates a login random code and login link, and returns it to the digital identity client after encrypting it with the personal or corporate public key; the digital identity client uses the private key to decrypt the encrypted information and verify the legitimacy of the user's identity; the digital identity client uses the private key to issue an authorization command, sends the random number, authorization command and corporate DID to the Identity Hub, and agrees to send the VC information to the login link; after receiving the authorization command, the Identity Hub sends the VC and random number to the login link of the data circulation platform so that the data circulation platform can verify the issuer of the VC and its credibility.

[0046] In the verification process, the data circulation platform also includes the following steps: obtaining the enterprise VC information and verifying whether the issuer of the VC is a registered trusted issuing agency; requesting the data circulation utilization service platform to verify whether the issuer is in the list of trusted issuing agencies. If it is in the list, the verification is passed and the user is allowed to perform data circulation operations.

[0047] The overall architecture of the digital identity management platform includes the data resource layer, application support layer, business application layer and user interaction layer, among which: the data resource layer contains the user information library, identity credential information library, risk control policy library and audit log library, which are used to store and manage various types of information related to data circulation; the application support layer contains single sign-on, multi-factor authentication, data encryption, and multi-source verification technology components to provide secure technical support for data circulation; the business application layer includes four business modules: identity management, agent management, access control and audit supervision, providing comprehensive business management and risk control services; the user interaction layer provides user registration, user login, user retrieval, user center and digital identity client modules to provide users with convenient account management and data circulation services.

[0048] The digital identity client of the user interaction layer is a digital identity management APP or U shield, which is used to store user credential information and supports the presentation and verification of credentials so that users can prove their identity and authority during data circulation.

[0049] Example 2, refer to the attached Figure 1 As shown, based on the first embodiment, it is proposed to use distributed digital identity (DID) to build a digital identity management system, which mainly includes two steps: issuance and verification. The technical implementation process is as follows:

[0050] 1. Certification process

[0051] (1) Digital identity issuers in various regions register as trusted issuing agencies through the data circulation and utilization service platform and disclose the DID and the DID Document containing the issuer's public key.

[0052] (2) The issuing party generates a DID for the individual / enterprise and issues a VC for Enterprise A

[0053] (3) The VC issued by the issuer is encrypted and stored by the individual / enterprise (or centrally managed); the DIDDocument and VC signature information of the individual / enterprise are publicly released; the DID and private key of the individual / enterprise are stored by the individual or enterprise (person in charge) through the client and carried with them.

[0054] 2. Verification Process

[0055] (1) Users access the data circulation platform, scan and log in through the digital identity client, and initiate a login request to the platform (providing personal / enterprise DID).

[0056] (2) The data circulation platform generates a login random code + platform loginUrl, encrypts it with the personal / enterprise public key, and generates an encrypted string that is returned to the digital identity client.

[0057] (3) The digital identity client decrypts the encrypted string using the personal / enterprise private key and uses the decrypted result to prove the legitimacy of the user's identity.

[0058] (4) The digital identity client uses the personal / enterprise private key to issue an authorization command, sends the random number, authorization command, and enterprise DID to the Identity Hub, and agrees to send the enterprise VC information to the loginUrl.

[0059] (5) Identity Hub receives the authorization command and sends the enterprise VC and random number to the circulation platform loginUrl.

[0060] (6) Obtain the enterprise VC information and verify that the VC is indeed issued by Beijing.

[0061] (7) Request the data circulation and utilization service platform to verify whether Beijing is a trusted issuing agency. If it is on the list of trusted issuing agencies, the verification is successful.

[0062] Example 3, refer to the attached Figure 2 As shown, based on the first embodiment, a system for implementing trusted data circulation based on digital identity is proposed, which is applied to a method for implementing trusted data circulation based on digital identity. The system includes:

[0063] The trusted issuing authority registration module is used by digital identity issuers in various regions to register as trusted issuing authorities through the data circulation and utilization service platform and disclose their DID and DID Document containing the issuer's public key;

[0064] The DID generation and VC issuance module is used to generate a unique DID for an individual or enterprise, and issue a verifiable VC for the enterprise as needed;

[0065] The VC storage and publishing module is used to encrypt and store the issued VC or centrally host it, while making the DID document and VC signature information of individuals or enterprises public. The DID and private key of individuals or enterprises are stored in a secure client.

[0066] The digital identity authentication module is used to authenticate users through the digital identity client when they access the data circulation platform. This includes generating a random login code and the platform login URL, encrypting them with the public key, and returning them to the digital identity client. The client then uses the private key to decrypt and verify the user's identity.

[0067] The VC verification and issuing agency verification module is used to verify the VC issuer and its credibility after obtaining the enterprise VC information on the data circulation platform, and request the data circulation utilization service platform to verify whether the issuer is a trustworthy issuing agency.

[0068] It also includes a data resource layer for storing user information database, identity credential information database, risk control policy database and audit log database to support the security and traceability of the entire data flow process.

[0069] It also includes an application support layer, which includes single sign-on, multi-factor authentication, data encryption, and multi-source verification technology components to provide secure technical support and ensure the security of data transmission and storage.

[0070] It also includes a business application layer, which includes four business modules: identity management, agent management, access control, and audit supervision, to provide comprehensive identity management, risk control, and service support;

[0071] Among them, the identity management module provides information verification of the issuer, individual and corporate identities, and provides services for issuing, managing, updating and revoking certificates; the agent management module provides internal employee management, agent position certificate issuance, management, updating and revocation services; the access control module provides a variety of user authentication methods, and has the ability to manage blacklists and whitelists, and risk control strategies; the audit supervision module mainly focuses on user login operation log audits, certificate issuance and update log audits, and promptly discovers security risks of user identity information leakage.

[0072] It also includes a user interaction layer, which provides user registration, user login, user retrieval, user center and digital identity client modules, providing users with one-stop account management services;

[0073] Among them, the user registration module is used by individuals or enterprises to complete user registration and submit authentication materials; the user login module provides a user login entrance to complete user login interaction; the user retrieval module provides a user account complaint entrance when the user account is lost; the user center module provides a user center to manage personal user information and credential information; the digital identity client module provides a digital identity management APP or U shield to store user credential information and support credential presentation and verification functions.

[0074] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A method for implementing trusted data circulation based on digital identity, characterized by: The method comprises the following steps: Digital identity issuers in various regions register as trusted issuing agencies through the data circulation and utilization service platform and disclose their DID and DID Document containing the issuer's public key; The issuer generates a unique DID for an individual or enterprise and issues a verifiable certificate (VC) to the enterprise based on demand; The issuer will encrypt and store the issued VC or centrally host it, while making the individual or enterprise's DID Document and VC signature information public. The individual or enterprise's DID and private key will be stored and kept by the individual or enterprise through a secure client for subsequent data circulation and verification. The following verification processes are also included: Users access the data circulation platform through a digital identity client and submit their personal or corporate DID as a login request; The data circulation platform generates a login random code and login link, encrypts them with the personal or corporate public key, and returns them to the digital identity client; The digital identity client uses the private key to decrypt the encrypted information and verify the legitimacy of the user's identity; The digital identity client uses the private key to issue an authorization command, sends the random number, authorization command, and enterprise DID to Identity Hub, and agrees to send VC information to the login link; After receiving the authorization command, Identity Hub sends the VC and random number to the login link of the data circulation platform so that the data circulation platform can verify the issuer of the VC and its credibility.

2. A method for implementing trusted data circulation based on digital identity according to claim 1, characterized in that: In the verification process, the data circulation platform also includes the following steps: Obtain enterprise VC information and verify whether the issuer of VC is a registered and trusted issuing authority; Request the data circulation and utilization service platform to verify whether the issuer is in the list of trusted issuing agencies. If so, the verification is passed and the user is allowed to perform data circulation operations.

3. The method for implementing trusted data circulation based on digital identity according to claim 1, characterized in that: The overall architecture of digital identity management includes the data resource layer, application support layer, business application layer, and user interaction layer, among which: The data resource layer includes a user information library, an identity credential information library, a risk control strategy library, and an audit log library, which are used to store and manage various types of information related to data circulation; The application support layer includes single sign-on, multi-factor authentication, data encryption, and multi-source verification technology components, providing secure technical support for data circulation; The business application layer includes four business modules: identity management, agent management, access control, and audit supervision, providing comprehensive business management and risk control services; The user interaction layer provides user registration, user login, user retrieval, user center and digital identity client modules, providing users with convenient account management and data circulation services.

4. The method for implementing trusted data circulation based on digital identity according to claim 1, characterized in that: The digital identity client of the user interaction layer is a digital identity management APP or U shield, which is used to store user credential information and supports the presentation and verification of credentials so that users can prove their identity and authority during data circulation.

5. A system for implementing trusted data circulation based on digital identity, applied to a method for implementing trusted data circulation based on digital identity according to any one of claims 1 to 4, characterized in that: The system comprises: The trusted issuing authority registration module is used by digital identity issuers in various regions to register as trusted issuing authorities through the data circulation and utilization service platform and disclose their DID and DID Document containing the issuer's public key; The DID generation and VC issuance module is used to generate a unique DID for an individual or enterprise, and issue a verifiable credential (VC) to the enterprise as needed; The VC storage and publishing module is used to encrypt and store the issued VC or centrally host it, while making the DIDDocument and VC signature information of individuals or enterprises public. The DID and private key of individuals or enterprises are stored in a secure client. The digital identity authentication module is used to authenticate users through the digital identity client when they access the data circulation platform. This includes generating a random login code and the platform login URL, encrypting them with the public key, and returning them to the digital identity client. The client then uses the private key to decrypt and verify the user's identity. The VC verification and issuing agency verification module is used to verify the VC issuer and its credibility after obtaining the enterprise VC information on the data circulation platform, and request the data circulation utilization service platform to verify whether the issuer is a trustworthy issuing agency.

6. A digital identity-based trusted data circulation implementation system according to claim 5, characterized in that: It also includes a data resource layer for storing user information database, identity credential information database, risk control policy database and audit log database to support the security and traceability of the entire data flow process.

7. The digital identity-based trusted data circulation implementation system according to claim 5, characterized in that: It also includes an application support layer, which contains single sign-on, multi-factor authentication, data encryption, and multi-source verification technology components to provide secure technical support and ensure the security of data transmission and storage.

8. The digital identity-based trusted data circulation implementation system according to claim 5, characterized in that: It also includes a business application layer, which includes four business modules: identity management, agent management, access control, and audit supervision, to provide comprehensive identity management, risk control, and service support; Among them, the identity management module provides information verification of the issuer, individual and corporate identities, and provides services for issuing, managing, updating and revoking certificates; the agent management module provides internal employee management, agent position certificate issuance, management, updating and revocation services; the access control module provides a variety of user authentication methods, and has the ability to manage blacklists and whitelists, and risk control strategies; the audit supervision module focuses on user login operation log audits, certificate issuance and update log audits, and promptly discovers security risks of user identity information leakage.

9. The digital identity-based trusted data circulation implementation system according to claim 5, characterized in that: It also includes a user interaction layer, which provides user registration, user login, user retrieval, user center and digital identity client modules, providing users with one-stop account management services; Among them, the user registration module is used by individuals or enterprises to complete user registration and submit authentication materials; the user login module provides a user login entrance to complete user login interaction; the user retrieval module provides a user account complaint entrance when the user account is lost; the user center module provides a user center to manage personal user information and credential information; the digital identity client module provides a digital identity management APP or U shield to store user credential information and support credential presentation and verification functions.

Citation Information

Patent Citations

  • Digital certificate system based software version trusted management method

    CN105447390A

  • Multi-dimensional digital identity authentication system based on block chain

    CN112580102A