Trusted Identity Authentication Method for Academic Participant Based on Blockchain Verifiable Credentials
By building an alliance network in the digital academic service platform and using hash encryption and public-private key mechanisms, verified verifiable credentials are solved, identity and behavior credibility issues are realized, credibility and behavior monitoring of identity authentication are improved, academic integrity and data security are improved.
Patent Information
- Application Number
- CN202411654718.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-19
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-11-19
AI Technical Summary
In the existing digital academic service platform, the authenticity of the identity and credibility of the participants' behavior cannot be effectively guaranteed, and there is a risk of academic misconduct or false results.
By pre-built a consortium network, blockchain technology is used to generate and verify verified credentials, including hash encryption processing and auxiliary data structures, ensuring the authenticity and integrity of credentials, and using public-private key mechanisms for identity authentication and behavior monitoring.
It enhances the credibility and behavioral credibility of identity authentication, ensures the identity authenticity and behavioral authenticity of participants, prevents academic misconduct, and improves academic integrity and data security.
Smart Images

Figure CN119561696B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain, and in particular to a method for authenticating the trusted identity of academic participants based on blockchain verifiable credentials. Background Art
[0002] In the rapid development of digital academic service platforms, ensuring the authenticity of the identities of participants and the credibility of their behaviors has become the key to maintaining academic integrity and ensuring data security. As an important channel for academic exchanges and resource sharing, digital academic service platforms need to ensure that each participant (including scholars, research institutions, etc.) can interact with a true and trustworthy identity to guarantee the authenticity and reliability of research results. Currently, digital academic platforms based on blockchain attempt to ensure the authenticity of the identities of participants and the credibility of their behaviors through blockchain technology. However, the identity information provided during user registration still needs to be verified by other means. If the identity information provided by the user is false or there is fraud, then even if a digital identity is registered on the blockchain, the authenticity of their identity cannot be guaranteed. Moreover, the existing technology lacks an effective monitoring and evaluation mechanism for the behaviors of users on the platform. Even if the identity of the user is verified, their behaviors on the platform still cannot be guaranteed, and academic misconduct or false results may occur.
[0003] In the related technologies at the current stage, there are technical problems that the authenticity of identities and the credibility of behaviors cannot be guaranteed in the trusted identity authentication of digital academic participants. Summary of the Invention
[0004] The present application provides a method for authenticating the trusted identity of academic participants based on blockchain verifiable credentials. By adopting a pre-constructed consortium network, a first participant node serves as a proof node and sends a first credential request to a first authoritative node. The first authoritative node generates a first verifiable credential and performs a hash encryption process on the first credential statement in the first verifiable credential. After receiving the first hash-verifiable credential and the first auxiliary data structure, the first participant node generates a second hash-verifiable credential and a second auxiliary data structure. A second participant node serves as a verification node to receive and verify the second hash-verifiable credential and the second auxiliary data structure to obtain a first verification result. If the first verification result is passed, it is confirmed that the first participant node has a first academic permission and other technical means, achieving the technical effect of enhancing the credibility of identity authentication and the credibility of behaviors.
[0005] The present application provides a method for authenticating the trusted identity of academic participants based on blockchain verifiable credentials, including:
[0006] Pre-construct a consortium network, where the consortium network includes a blockchain ledger, multiple authoritative nodes, and multiple participating entity nodes; a first participating entity node, as a proof node, sends a first credential request to a first authoritative node; after receiving the first credential request, the first authoritative node generates a first verifiable credential, where the first verifiable credential consists of first credential information, a first credential statement, and a first issuance proof; the first authoritative node performs a hash encryption process on the first credential statement in the first verifiable credential to generate a first hash-verifiable credential and a first auxiliary data structure; after receiving the first hash-verifiable credential and the first auxiliary data structure, the first participating entity node generates a second hash-verifiable credential and a second auxiliary data structure; a second participating entity node, as a verification node, receives and verifies the second hash-verifiable credential and the second auxiliary data structure to obtain a first verification result; if the first verification result is passed, it is confirmed that the first participating entity node has a first academic permission.
[0007] In a possible implementation, the pre-constructed consortium network performs the following processing:
[0008] Initialize a blockchain network, where the blockchain network includes the blockchain ledger and multiple authoritative nodes; after a first subject to be registered generates a first pair of public and private keys and a second pair of public and private keys locally, extracts a first set of private keys and a first set of public keys from the first pair of public and private keys and the second pair of public and private keys, locally stores the first set of private keys, and uploads the first set of public keys to the blockchain ledger; the first authoritative node receives and reviews the identity verification materials sent by the first subject to be registered to obtain a first review result; if the first review result is passed, the first authoritative node generates a first DID and a first document for the first subject to be registered, stores the first DID and the first document in the blockchain ledger to complete the registration of the first participating entity node in the blockchain network; the first authoritative node sends the first document to the first subject to be registered; and so on, registering multiple participating entity nodes of multiple subjects to be registered in the blockchain network to complete the pre-construction of the consortium network.
[0009] In a possible implementation, when the first authoritative node performs a hash encryption process on the first credential statement in the first verifiable credential to generate a first hash-verifiable credential and a first auxiliary data structure, the following processing is performed:
[0010] The first authoritative node performs hash encryption processing on the first credential statement in the first verifiable credential to generate a first encrypted statement; the first authoritative node stores the first credential statement in a structured manner to obtain the first auxiliary data structure; after the first authoritative node updates the first verifiable credential by replacing the first credential statement with the first encrypted statement, the first authoritative node signs the updated first verifiable credential with the first private key of the first authoritative node to generate a first hash-verifiable credential.
[0011] In a possible implementation manner, the first set of private keys includes a first signature private key and a first encryption private key.
[0012] In a possible implementation manner, the second participating subject node, as a verification node, receives and verifies the second hash-verifiable credential and the second auxiliary data structure to obtain a first verification result, and performs the following processing:
[0013] After receiving the first hash-verifiable credential and the first auxiliary data structure, the first participating subject node calls the second auxiliary data structure from the first auxiliary data structure; signs the second auxiliary data structure with the first signature private key in the first set of private keys to generate the second hash-verifiable credential, where the second hash-verifiable credential includes the first hash-verifiable credential; the first participating subject node sends the second hash-verifiable credential and the second auxiliary data structure to the second participating subject node; after receiving the second hash-verifiable credential, the second participating subject node uses the first public key to perform an issuance verification on the first hash-verifiable credential in the second hash-verifiable credential; if the verification passes, the second auxiliary data structure is verified for content using the second hash-verifiable credential and the first hash-verifiable credential; if the verification passes, the first verification result is passed, and the first participating subject node has a first academic authority.
[0014] In a possible implementation manner, the following processing is performed:
[0015] While the blockchain network completes the registration of the first participating subject node, a first counter is initialized for the first participating subject node; when the first participating subject node sends the first credential request to the first authoritative node, the first count value of the first counter is synchronously sent; the first authoritative node adds 1 to the first count value to obtain a second count value; the first authoritative node embeds the second count value into the generated first verifiable credential and uploads the second count value associated with the first DID to the blockchain ledger.
[0016] In a possible implementation, after receiving the second hash-verifiable credential as a verification node, the second participating entity node performs the following processing after performing signature verification on the first hash-verifiable credential in the second hash-verifiable credential using the first public key:
[0017] As a verification node, after receiving the second hash-verifiable credential, the second participating entity node obtains the second count value of the first hash-verifiable credential in the second hash-verifiable credential; compares the increment relationship between the first hash-verifiable credential and the two second count values in the blockchain ledger. If it is an increment relationship, the second auxiliary data structure is content-verified using the second hash-verifiable credential and the first hash-verifiable credential.
[0018] In a possible implementation, the following processing is performed:
[0019] The second participating entity node evaluates the authenticity of the behavior of the first participating entity node based on the first verification result and outputs a behavior authenticity score; if the first participating entity node has a first academic permission, the first participating entity node and the second participating entity node perform academic interaction, and the second participating entity node evaluates the performance of the academic interaction of the first participating entity node based on the performance of the academic interaction and outputs an academic interaction performance score; a pre-constructed trust rule processes the behavior authenticity score and the academic interaction performance score to obtain a comprehensive trust score; the first authoritative node generates a first trust credential for the first participating entity node based on the comprehensive trust score and uploads the first trust credential associated with the first DID to the blockchain ledger.
[0020] The academic participant trusted identity authentication method based on blockchain verifiable credentials proposed in this application first pre - constructs a consortium network. Among them, the consortium network includes a blockchain ledger, multiple authoritative nodes, and multiple participant nodes. Then, the first participant node, as a proof node, sends a first credential request to the first authoritative node. After receiving the first credential request, the first authoritative node generates a first verifiable credential. Among them, the first verifiable credential consists of a first credential information, a first credential statement, and a first issuance proof. At the same time, the first authoritative node performs a hash encryption process on the first credential statement in the first verifiable credential to generate a first hash - verifiable credential and a first auxiliary data structure. After receiving the first hash - verifiable credential and the first auxiliary data structure, the first participant node generates a second hash - verifiable credential and a second auxiliary data structure. Furthermore, the second participant node, as a verification node, receives and verifies the second hash - verifiable credential and the second auxiliary data structure to obtain a first verification result. If the first verification result is passed, it is confirmed that the first participant node has the first academic authority, achieving the technical effect of enhancing the credibility of identity authentication and the credibility of behavior. Brief Description of the Drawings
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings of the embodiments of the present invention will be briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the methods according to the embodiments of this application. It should be understood that the operations before or below do not necessarily need to be executed precisely in sequence. On the contrary, according to needs, they can be executed in reverse order or simultaneously. At the same time, other operations can also be added to these processes, or one or several operations can be removed from these processes.
[0022] Figure 1 It is a schematic flowchart of the academic participant trusted identity authentication method based on blockchain verifiable credentials provided by the embodiments of this application.
[0023] Figure 2 It is a schematic flowchart of generating the first hash - verifiable credential and the first auxiliary data structure in the academic participant trusted identity authentication method based on blockchain verifiable credentials provided by the embodiments of this application. Detailed Embodiments
[0024] The above description is only an overview of the technical solutions of this application. In order to be able to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of this application more obvious and understandable, the detailed embodiments of this application are specifically listed below.
[0025] To make the objectives, technical solutions, and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. The described embodiments should not be construed as limitations on this application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of this application.
[0026] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments and can be combined with each other without conflict. The terms "first / second" are only used to distinguish similar objects and do not represent a specific order for the objects. The terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products, or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field of this application. The terms used herein are only for the purpose of describing the embodiments of this application.
[0027] Embodiments of this application provide a method for authenticating the trusted identity of academic participation subjects based on blockchain verifiable credentials, as Figure 1 shown, the method includes:
[0028] Step S100, pre-construct a consortium network, where the consortium network includes a blockchain ledger, multiple authoritative nodes, and multiple participating subject nodes. Specifically, initialize the blockchain network, and set up the blockchain ledger and multiple authoritative nodes. Among them, the blockchain ledger is a data structure that records all transactions and events and is the core component of the blockchain network. The authoritative node is a node responsible for reviewing identity proof materials, generating, and issuing verifiable credentials, and has read and write data permissions. The consortium network is used to implement blockchain-based verifiable credentials and identity authentication. The participating subject node is a node to be registered and a registered node that has joined the consortium network, and can be a researcher, auditor, ordinary user, etc.
[0029] In a possible implementation, a pre-constructed consortium network is used. Step S100 further includes step S110 of initializing a blockchain network, where the blockchain network includes the blockchain ledger and multiple authoritative nodes. Specifically, a blockchain platform is selected or created. Blockchain network parameters such as the consensus mechanism, the number of nodes, the block size, etc. are configured. The blockchain ledger is initialized to provide a basis for subsequent transactions and data storage. For example, the blockchain network is created and maintained by an academic consortium, and the authoritative institutions of the academic consortium act as authoritative nodes to form an initial blockchain network, which has the permission to read and write data. In step S120, after the first subject to be registered generates a first pair of public and private keys and a second pair of public and private keys locally, a first set of private keys and a first set of public keys are extracted from the first pair of public and private keys and the second pair of public and private keys. The first set of private keys is locally saved, and the first set of public keys is uploaded to the blockchain ledger. The first set of private keys includes a first signature private key and a first encryption private key. Specifically, the first subject to be registered (such as an individual, a company, etc.) uses a key generation tool to generate two pairs of public and private keys. One pair (for example, the first pair) is selected from these two pairs of public and private keys as the key pair for identity authentication and transaction signing, and the other pair is used for end-to-end communication encryption. That is, the first set of private keys includes a first signature private key and a first encryption private key. The private key in each pair is saved in a local secure storage to ensure no leakage. The public key in each pair is uploaded to the blockchain ledger and associated with the identity identifier (such as a username, an email, etc.) of the subject to be registered.
[0030] Step S130: The first authoritative node receives and reviews the identity proof materials sent by the first subject to be registered, and obtains a first review result. Specifically, the first subject to be registered submits the identity proof materials (such as ID cards, passports, business licenses, etc.) to the first authoritative node through a reliable channel (a channel that ensures that data is not eavesdropped or tampered with during transmission, such as HTTPS, encrypted emails, etc.). After receiving the materials, the first authoritative node conducts manual or automated reviews to confirm the authenticity and legality of the materials. After the review is completed, a first review result is generated, indicating whether the subject to be registered has passed the review. Step S140: If the first review result is that the review is passed, the first authoritative node generates a first DID and a first document for the first subject to be registered, and stores the first DID and the first document in the blockchain ledger to complete the registration of the first participating subject node in the blockchain network. Specifically, if the first review result is that the review is passed, the first authoritative node generates a unique decentralized identifier (the first DID) for the first subject to be registered. At the same time, a document (the first document) containing the registration information of the subject to be registered and the signature information of the first authoritative node is generated. The first DID and the first document are stored in the blockchain ledger to ensure the immutability and traceability of the information. For example, they are saved with the first DID as the key and the first document as the value, and each node in the consortium network can query the first DID and the first document of the first subject to be registered. Step S150: The first authoritative node sends the first document to the first subject to be registered. Specifically, the first authoritative node sends the generated first document to the first subject to be registered through a reliable channel, indicating that the registration is successful. Step S160: By analogy, multiple participating subject nodes of multiple subjects to be registered are registered in the blockchain network to complete the pre-construction of the consortium network. Specifically, steps 120 to 150 are repeated to complete the registration process for multiple subjects to be registered. Each subject to be registered obtains a unique DID and document, which are stored in the blockchain ledger. In this way, a consortium network containing multiple authoritative nodes and multiple participating subject nodes is constructed. This implementation method combines public-private key pairs and blockchain technology to achieve secure authentication of the identities of participating subjects and the immutability of data. The local storage of private keys and the blockchain storage of public keys ensure the uniqueness and security of identity information.
[0031] Step S200: The first participating subject node, as a proof node, sends a first credential request to the first authoritative node. Specifically, when the first participating subject node needs to prove that it has a certain qualification or permission, it sends a credential request to the first authoritative node.
[0032] Step S300, after receiving the first credential request, the first authoritative node generates a first verifiable credential, wherein the first verifiable credential is composed of first credential information, first credential statement and first issuance certificate. Specifically, after receiving the request, the first authoritative node generates a verifiable credential including credential information, credential statement and issuance certificate after verifying the identity information, DID and DID document of the first participating subject node according to the request content. Among them, the credential information is the basic information describing the credential, including metadata such as the context, credential ID and type of the credential; the credential statement contains the specific information and authority of the declaring subject, such as identity information, qualification certification, etc.; the issuance certificate is the endorsement of the credential by the authority, including the digital signature of the issuer, which is used to verify the authenticity and integrity of the credential.
[0033] Step S400, the first authoritative node performs hash encryption processing on the first credential declaration in the first verifiable credential to generate a first hash verifiable credential and a first auxiliary data structure. Specifically, the first authoritative node uses a hash algorithm to perform hash encryption on the credential declaration part in the first verifiable credential to generate a new hash verifiable credential (first hash verifiable credential), in which the credential declaration part is replaced with a hash value, and an auxiliary data structure (first auxiliary data structure) is generated at the same time. The first auxiliary data structure is an auxiliary data structure that is matched with the first hash verifiable credential and is used to support the selective disclosure and verification process. It contains the original declaration content, the corresponding hash value, and the key used to generate the hash value.
[0034] like Figure 2 As shown, in a possible implementation, the first authoritative node performs hash encryption processing on the first credential statement in the first verifiable credential to generate a first hashed verifiable credential and a first auxiliary data structure. Step S400 further includes step S410, in which the first authoritative node performs hash encryption processing on the first credential statement in the first verifiable credential to generate a first encrypted statement. Specifically, the first authoritative node performs hash encryption processing on the first credential statement in the first verifiable credential. Hash encryption is a one-way encryption function that converts input data of any length into output data of a fixed length (called a hash value or digest). This conversion is irreversible, that is, the original input data cannot be restored from the hash value, which ensures the integrity and authenticity of the data. For example, hash encryption is performed using the message authentication code HMAC(H, key, m), where H is a hash function, key is a random key, and m is the content to be hashed. For each claim in the first credential statement, i Content value i , using K bits of random key key to calculate the hash value Hash v =HMAC(H,key i, value i ). Step S420: The first authoritative node stores the first credential statement in a structured manner to obtain the first auxiliary data structure. Specifically, after generating the first encrypted statement, the first authoritative node stores the first credential statement in a structured manner, that is, organizes the information into a format that is easy to query and manage. For example, the key i , value i and the path path(claim i ) used to reach each statement in the credential are stored in a separate data structure SciAttributes and stored in the form of a triple as [path(claim i ), key i , value i for subsequent selective disclosure. Step S430: After the first authoritative node replaces the first credential statement with the first encrypted statement to update the first verifiable credential, the first authoritative node signs the updated first verifiable credential with the first private key of the first authoritative node to generate the first hash-verifiable credential. Specifically, the first authoritative node replaces the first credential statement with the first encrypted statement, thereby updating the first verifiable credential. Then, the first authoritative node uses its own first private key to sign the updated first verifiable credential to generate the first hash-verifiable credential. This implementation method ensures that any changes to the first credential statement can be detected through hash encryption processing, thus guaranteeing the integrity of the data. The use of structured storage and auxiliary data structures improves the efficiency of data retrieval and verification, making the verification process faster and more convenient.
[0035] Step S500: After receiving the first hash-verifiable credential and the first auxiliary data structure, the first participating entity node generates a second hash-verifiable credential and a second auxiliary data structure. Specifically, the first authoritative node sends the first hash-verifiable credential and the first auxiliary data structure to the first participating entity node through a secure channel. The first participating entity node can independently choose to disclose the content of the required statement to the data owner. The first participating entity node selects the statement to be disclosed and signs the first hash-verifiable credential and the first auxiliary data structure with its own private key to generate a new hash-verifiable credential and auxiliary data structure, that is, the second hash-verifiable credential and the second auxiliary data structure. For example, the first participating entity node selects the statement to be disclosed and selects the corresponding triple in SciAttributes to form disclosedSciAttr.
[0036] Step S600: The second participating entity node, acting as a verification node, receives and verifies the second hash-verifiable credential and the second auxiliary data structure to obtain a first verification result. Specifically, the second participating entity node verifies the second hash-verifiable credential and the second auxiliary data structure sent by the first participating entity node. After successful verification, a first verification result is obtained.
[0037] In a possible implementation, when the second participating entity node, acting as a verification node, receives and verifies the second hash-verifiable credential and the second auxiliary data structure to obtain a first verification result, step S600 further includes step S610. After receiving the first hash-verifiable credential and the first auxiliary data structure, the first participating entity node calls the second auxiliary data structure from the first auxiliary data structure. Specifically, the first auxiliary data structure contains metadata related to the first verifiable credential, such as a timestamp, the hash value of the credential, the identity identifier of the issuer, etc. The second auxiliary data structure is extracted or generated from the first auxiliary data structure according to the need for disclosure after the first participating entity node receives the first hash-verifiable credential and the first auxiliary data structure, in order to selectively disclose some statements. Step S620: Sign the second auxiliary data structure using the first signature private key in the first group of private keys to generate the second hash-verifiable credential, where the second hash-verifiable credential contains the first hash-verifiable credential. Specifically, the first signature private key is used to sign the second auxiliary data structure. Signing is a mathematical operation that allows a verifier to use a public key to verify its signature, thereby confirming that the information was sent by the entity holding the corresponding private key and that the information has not been tampered with during transmission. Through signing, the second hash-verifiable credential is generated, which contains the first hash-verifiable credential (i.e., the credential information generated by the first authoritative node, the hash-encrypted credential statement, and the issuance proof) and the second auxiliary data structure. Step S630: The first participating entity node sends the second hash-verifiable credential and the second auxiliary data structure to the second participating entity node. Specifically, the first participating entity node sends the second hash-verifiable credential and the second auxiliary data structure it generated to the second participating entity node that needs to verify its identity.
[0038] Step S640: After receiving the second hash-verifiable credential as a verification node, the second participating entity node uses the first public key to perform signature verification on the first hash-verifiable credential in the second hash-verifiable credential. Specifically, the second participating entity node uses the first public key of the first authoritative node to verify whether the signature of the first hash-verifiable credential in the second hash-verifiable credential is valid, that is, whether it is issued by the first authoritative node. Step S650: If the verification passes, the content of the second auxiliary data structure is verified using the second hash-verifiable credential and the first hash-verifiable credential. Specifically, after the signature verification passes, the second participating entity node also needs to verify whether the content of the second auxiliary data structure is consistent with the information in the first hash-verifiable credential. This is achieved by hashing the second auxiliary data structure and comparing it with the hash value in the first hash-verifiable credential. For example, for each triple in disclosedSciAttr, check claim i whether it belongs to the first hash-verifiable credential, ensure that the claim is endorsed by the first authoritative institution, retrieve the corresponding hash value in the first hash-verifiable credential, and check whether the HMAC(H, key i , value i ) in the second auxiliary data structure is equal to the hash value to ensure the authenticity and integrity of the claim content. Step S660: If the verification passes, the first verification result is passed, and the first participating entity node has the first academic permission. Specifically, if all verifications pass, then the second participating entity node will confirm that the first participating entity node has the corresponding first academic permission. This implementation method ensures that only credentials that have been authenticated by an authoritative institution, have true claim content and have not been tampered with can be accepted, thereby protecting the security and integrity of the data and ensuring the reliability of the data source.
[0039] Step S700: If the first verification result is passed, confirm that the first participating entity node has the first academic permission. Specifically, if the first verification result is passed, confirm that the first participating entity node has the requested academic permission. In the embodiment of the present application, a pre-constructed consortium network is adopted. The first participating entity node, as a proof node, sends a first credential request to the first authoritative node. The first authoritative node generates a first verifiable credential and performs hash encryption processing on the first credential claim in the first verifiable credential. After receiving the first hash-verifiable credential and the first auxiliary data structure, the first participating entity node generates a second hash-verifiable credential and a second auxiliary data structure. The second participating entity node, as a verification node, receives and verifies the second hash-verifiable credential and the second auxiliary data structure to obtain the first verification result. If the first verification result is passed, confirm that the first participating entity node has the first academic permission and other technical means, achieving the technical effect of enhancing the credibility of identity authentication and the credibility of behavior.
[0040] In a possible implementation, it further includes step S800. While the blockchain network completes the registration of the first participating entity node, a first counter is initialized for the first participating entity node. Specifically, during the registration process of the first participating entity node, the system will assign a unique identity identifier to this participating entity node, that is, the first DID. At the same time, the system will initialize a counter for this participating entity node, and this counter is used to record the number of subsequent credential requests made by this participating entity node. Step S900, when the first participating entity node sends the first credential request to the first authoritative node, the first count value of the first counter is synchronously sent. Specifically, when the first participating entity node needs to request a credential (such as an academic certificate, qualification certificate, etc.) from the first authoritative node, it will synchronously send the value of its current counter, and this value is used as part of the request to identify how many times this is the credential request sent by the first participating entity node. Step S1000, the first authoritative node adds 1 to the first count value to obtain a second count value. Specifically, after receiving the credential request and its count value from the first participating entity node, the first authoritative node will first add 1 to this count value, and the value after adding 1 is used as the new count value to record that the first participating entity node has successfully requested a new credential. Step S1100, the first authoritative node embeds the second count value into the generated first verifiable credential, and associates the second count value with the first DID and uploads it to the blockchain ledger. Specifically, when the first authoritative node generates a verifiable credential, it will embed the new count value into the credential. At the same time, it will also associate this new count value with the DID of the first participating entity node and upload this association information to the blockchain ledger. In this way, any node can verify the number of credential requests and the identity of the first participating entity node by querying the blockchain ledger. For example, the first participating entity node, as the requester, initializes the counter cnt = 0 during identity registration, and sends the value of cnt when sending a request for a verifiable credential to the first authoritative node; after the first authoritative node verifies the information, it issues a verifiable credential, adds 1 to the cnt value and embeds it into the verifiable credential, and sends it to the requester through a reliable channel, associates it with the DID of this participating entity and uploads it to the blockchain network. This implementation method ensures the uniqueness and authenticity of the credential by associating the number of credential requests of the participating entity node with its DID and recording it on the blockchain, can prevent malicious entity nodes from trying to forge or abuse the credential by repeatedly requesting the same credential, and enhances the credibility and anti-tampering property of the credential.
[0041] In a possible implementation, after receiving the second hash-verifiable credential, when the second participating entity node acts as a verification node and uses the first public key to perform signing verification on the first hash-verifiable credential in the second hash-verifiable credential, step S640 further includes step S641. As a verification node, after receiving the second hash-verifiable credential, the second participating entity node obtains the second count value of the first hash-verifiable credential in the second hash-verifiable credential. Specifically, when the second participating entity node (verification node) receives the second hash-verifiable credential sent by the first participating entity node, it first parses this credential to obtain the content therein. In the second hash-verifiable credential, the first hash-verifiable credential is included, and in the first hash-verifiable credential, the second count value generated by the first authoritative node and uploaded to the blockchain ledger is embedded. The second participating entity node needs to extract this second count value from the second hash-verifiable credential for subsequent verification steps.
[0042] Step S642: Compare the increasing relationship between the first hash-verifiable credential and the two second count values in the blockchain ledger. If it is an increasing relationship, use the second hash-verifiable credential and the first hash-verifiable credential to perform content verification on the second auxiliary data structure. Specifically, the verification node obtains the second count value from the second hash-verifiable credential provided by the first participating entity node, that is, the second count value in the first hash-verifiable credential. The verification node checks whether this second count value is larger than the previously recorded count value, that is, checks whether it shows an increasing relationship. This ensures that the credential request of the first participating entity node is in the correct order and there is no situation of skipping or reusing old credentials. At the same time, the verification node compares the second count value provided by the first participating entity node with the second count value on the blockchain ledger. If the currently received second count value is less than or equal to the previous (or maximum) second count value recorded on the blockchain ledger, then the second participating entity node will consider this first hash-verifiable credential to be valid and consider that the first participating entity node has truly carried out academic behavior. After passing the verification, the second participating entity node continues to use the second hash-verifiable credential and the first hash-verifiable credential to perform content verification on the second auxiliary data structure to ensure that other parts of the credential are also true and complete. This implementation method ensures that the credential request of the first participating entity node is legal and not tampered with by verifying the increasing relationship of the second count value and comparing it with the second count value on the blockchain, enhancing the credibility and anti-tampering property of the credential.
[0043] In a possible implementation, it further includes step S1200. The second participating entity node evaluates the authenticity of the behavior of the first participating entity node based on the first verification result and outputs a behavior authenticity score. Specifically, after confirming that the first verification result passes, the second participating entity node evaluates the authenticity of the behavior of the first participating entity node according to the voucher information provided by the first participating entity node and its performance during the verification process. The evaluation can be based on multiple dimensions, such as the integrity of the voucher, the timeliness of the voucher, the matching degree between the voucher and the requested academic authority, etc. According to the evaluation dimensions and weights, a behavior authenticity score is output, which reflects the performance of the first participating entity node in terms of behavior authenticity. For example, the behavior authenticity can be divided into five levels from high to low: completely authentic, authentic, basically authentic, less authentic, and completely inauthentic, corresponding to scores of 5, 4, 3, 2, and 1 respectively. The behavior authenticity score of the first participating entity node is the average value of all authenticity scores accumulated within the most recent time period T. The specific calculation formula is:
[0044]
[0045] Among them, BAS Y represents the behavior authenticity score of the first participating entity node in the alliance network. BAS Y ∈[1, 5], n is the total number of authenticity scores accumulated by the first participating entity node within the most recent time period T. The set of accumulated authenticity scores sorted by time is
[0046] Step S1300. If the first participating entity node has the first academic authority, the first participating entity node and the second participating entity node conduct academic interactions. The second participating entity node evaluates the performance of the academic interactions of the first participating entity node according to the performance of the academic interactions and outputs an academic interaction performance score. Specifically, after confirming that the first participating entity node has the first academic authority, the two parties conduct academic interactions, such as academic exchanges, collaborative research, etc. During the academic interaction process, the second participating entity node observes and records the behavior performance of the first participating entity node, such as the cooperation attitude, academic contributions, communication quality, etc. According to the recorded behavior performance, an academic interaction performance score is output, which reflects the performance of the first participating entity node during the academic interaction process. For example, the interaction performance scores can be divided into five levels from high to low: very satisfied, relatively satisfied, generally satisfied, dissatisfied, and very dissatisfied, corresponding to interaction scores of 5, 4, 3, 2, and 1 respectively. Since the behavior performance of the first participating entity node changes continuously over time, the effectiveness of the scores from more distant times in correctly reflecting the entity's behavior performance will decrease accordingly. A time decay function is introduced when calculating the interaction performance score. The specific calculation formula for the time decay function and the interaction performance score of the first participating entity node within the most recent time period T is:
[0047]
[0048] w(t)=e -λ(T ' -t) ;
[0049] where w(t) represents the time exponential decay function, λ represents the time decay parameter, T' represents the current time calculated, t represents the time when the score is released, and PSS Y represents the academic interaction behavior performance score of the first participating subject node in the alliance network, and PSS Y ∈[1,5], k is the total number of cumulative interaction behavior scores of the first participating subject node within the recent period T, and the set of cumulative interaction behavior scores sorted by time is t i is the time point of the i-th score.
[0050] Step S1400, pre-construct trust rules to process the behavior authenticity score and the academic interaction behavior performance score to obtain a comprehensive trust score. Specifically, pre-construct a set of trust rules, which define the weights and calculation methods of the behavior authenticity score and the academic interaction behavior performance score in the comprehensive trust score. According to the pre-constructed trust rules, the behavior authenticity score and the academic interaction behavior performance score are weighted and summed or other calculations are performed to obtain the comprehensive trust score. The comprehensive trust score reflects the comprehensive performance of the first participating subject node in terms of behavior authenticity and academic interaction behavior performance. For example, the calculation formula can be:
[0051] TS Y =(1 - μ)·BAS Y + μ·PSS Y ;
[0052] μ = α·β;
[0053]
[0054] where TS Y represents the comprehensive trust score of the first participating subject node, BAS Y represents the behavior authenticity score of the first participating subject node, PSS Y represents the academic interaction behavior performance score of the first participating subject node, α is the score breadth coefficient, α ∈ [0,1), representing the breadth of the source of the evaluation nodes, p is the total number of evaluation nodes from different sources, β is the score dispersion coefficient, β ∈ [0,1), representing the consistency degree of the evaluation nodes, and σ is the standard deviation of the set of cumulative evaluation scores.
[0055] Step S1500, the first authoritative node generates a first trust certificate for the first participating subject node according to the comprehensive trust score, and associates the first trust certificate with the first DID and uploads it to the blockchain ledger. Specifically, the first authoritative node receives the comprehensive trust score and generates a first trust certificate for the first participating subject node according to the comprehensive trust score and a preset trust certificate generation rule. For example, the score range of the comprehensive trust score is between [1, 5], and it is set that 0 ≤ TS Y <2.5 means distrust, 2.5 ≤ TS Y <3.5 means basic trust, 3.5 ≤ TS Y <5 means good trust. Associate the first trust certificate with the unique identifier (first DID) of the first participating subject node and upload it to the blockchain ledger for recording and storage. The immutability of the blockchain ledger ensures the authenticity and credibility of the first trust certificate. This implementation method comprehensively reflects the performance and behavioral characteristics of the participating subject node in the academic field through the evaluation of behavioral authenticity and the evaluation of academic interaction behavior performance. The comprehensive trust score quantifies these evaluation results and provides a reliable reference basis for academic cooperation and communication. At the same time, associating the trust certificate with the DID and uploading it to the blockchain ledger ensures the authenticity and credibility of the trust certificate and provides an efficient, secure, and trustworthy trust management mechanism for the academic field.
[0056] The above specific implementation manners do not constitute a limitation on the protection scope of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of this application shall be included within the protection scope of this application. In some cases, the actions or steps recorded in this application can be executed in a different order from that in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A method for authenticating the trusted identity of academic participants based on blockchain-verifiable credentials, characterized in that, The method includes: Pre - construct a consortium network, where the consortium network includes a blockchain ledger, multiple authoritative nodes, and multiple participating entity nodes; The first participating entity node, as a proof node, sends a first credential request to the first authoritative node; After receiving the first credential request, the first authoritative node generates a first verifiable credential, where the first verifiable credential consists of first credential information, a first credential statement, and a first issuance proof; The first authoritative node performs hash encryption processing on the first credential statement in the first verifiable credential to generate a first hash - verifiable credential and a first auxiliary data structure; After receiving the first hash - verifiable credential and the first auxiliary data structure, the first participating entity node generates a second hash - verifiable credential and a second auxiliary data structure; The second participating entity node, as a verification node, receives and verifies the second hash - verifiable credential and the second auxiliary data structure to obtain a first verification result; If the first verification result is passed, it is confirmed that the first participating entity node has the first academic permission.
2. The academic participant trusted identity authentication method based on blockchain verifiable credentials according to claim 1, wherein, Pre - construct a consortium network, the method includes: Initialize a blockchain network, where the blockchain network includes the blockchain ledger and multiple authoritative nodes; After the first subject to be registered generates a first pair of public - private keys and a second pair of public - private keys locally, it extracts a first set of private keys and a first set of public keys from the first pair of public - private keys and the second pair of public - private keys, locally saves the first set of private keys, and uploads the first set of public keys to the blockchain ledger; The first authoritative node receives and reviews the identity proof materials sent by the first subject to be registered to obtain a first review result; If the first review result is passed, the first authoritative node generates a first DID and a first document for the first subject to be registered, stores the first DID and the first document in the blockchain ledger to complete the registration of the first participating entity node in the blockchain network; The first authoritative node sends the first document to the first subject to be registered; And so on, register the multiple participating entity nodes of multiple subjects to be registered in the blockchain network to complete the pre - construction of the consortium network.
3. The academic participant trusted identity authentication method based on blockchain verifiable credentials according to claim 2, wherein, The first authoritative node performs hash encryption processing on the first credential statement in the first verifiable credential to generate a first hash - verifiable credential and a first auxiliary data structure, the method includes: The first authoritative node performs hash encryption processing on the first credential statement in the first verifiable credential to generate a first encrypted statement; The first authoritative node performs structured storage on the first credential statement to obtain the first auxiliary data structure; After the first authoritative node replaces the first credential statement with the first encrypted statement to update the first verifiable credential, it signs the updated first verifiable credential with the first private key of the first authoritative node to generate a first hash - verifiable credential.
4. The method for authenticating the trusted identity of academic participants based on blockchain-verifiable credentials as claimed in claim 3, wherein, The first set of private keys includes a first signature private key and a first encryption private key.
5. The academic participant trusted identity authentication method based on blockchain verifiable credentials according to claim 4, characterized in that, The second participating entity node, acting as a verification node, receives and verifies the second hash-verifiable credential and the second auxiliary data structure to obtain a first verification result. The method includes: After receiving the first hash-verifiable credential and the first auxiliary data structure, the first participating entity node calls the second auxiliary data structure from the first auxiliary data structure; Sign the second auxiliary data structure using the first signature private key in the first group of private keys to generate the second hash-verifiable credential, where the second hash-verifiable credential contains the first hash-verifiable credential; The first participating entity node sends the second hash-verifiable credential and the second auxiliary data structure to the second participating entity node; After receiving the second hash-verifiable credential, the second participating entity node, acting as a verification node, uses the first public key to perform an issuance verification on the first hash-verifiable credential in the second hash-verifiable credential; If the verification passes, use the second hash-verifiable credential and the first hash-verifiable credential to perform a content verification on the second auxiliary data structure; If the verification passes, the first verification result is passed, and the first participating entity node has the first academic permission.
6. The academic participant trusted identity authentication method based on blockchain verifiable credentials according to claim 5, wherein, The method includes: While registering the first participating entity node in the blockchain network, initialize a first counter for the first participating entity node; When the first participating entity node sends the first credential request to the first authoritative node, synchronously send the first count value of the first counter; The first authoritative node adds 1 to the first count value to obtain a second count value; The first authoritative node embeds the second count value into the generated first verifiable credential and uploads the second count value associated with the first DID to the blockchain ledger.
7. The method for authenticating the trusted identity of academic participation subjects based on blockchain-verifiable credentials according to claim 6, wherein After receiving the second hash-verifiable credential, the second participating entity node, acting as a verification node, uses the first public key to perform an issuance verification on the first hash-verifiable credential in the second hash-verifiable credential. After that, the method includes: As a verification node, after receiving the second hash-verifiable credential, the second participating entity node obtains the second count value of the first hash-verifiable credential in the second hash-verifiable credential; Compare the increasing relationship between the first hash-verifiable credential and the two second count values in the blockchain ledger. If it is an increasing relationship, use the second hash-verifiable credential and the first hash-verifiable credential to perform a content verification on the second auxiliary data structure.
8. The method for authenticating the trusted identity of academic participants based on blockchain-verifiable credentials as claimed in claim 7, wherein The method includes: The second participating entity node evaluates the authenticity of the behavior of the first participating entity node based on the first verification result and outputs a behavior authenticity score; If the first participating entity node has the first academic permission, the first participating entity node conducts academic interaction with the second participating entity node, and the second participating entity node evaluates the performance of the academic interaction behavior of the first participating entity node based on the academic interaction behavior performance and outputs an academic interaction behavior performance score; The pre-built trust rules process the authenticity score of the behavior and the performance score of the academic interaction behavior to obtain a comprehensive trust score; The first authoritative node generates a first trust credential for the first participating subject node according to the comprehensive trust score, and uploads the first trust credential associated with the first DID to the blockchain ledger.
Citation Information
Patent Citations
Blockchain-based alliance trust distributed identity certificate management authentication method
CN112311530A
System for secure automated and accelerated resource allocation
US20220309412A1