Identity management method and device of cross-chain gateway
By registering identities and generating verifiable credentials on various application chains through cross-chain gateways, the issues of uniformity and security in identity management in cross-chain transactions are resolved, thereby improving the security of cross-chain transactions.
Patent Information
- Application Number
- CN202411676261.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-21
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-11-21
AI Technical Summary
The lack of uniformity and security in identity management across different blockchain platforms makes it difficult to guarantee the security of cross-chain transactions.
Cross-chain gateways register identity information in various application chains, construct distributed digital identity information, and generate verifiable credentials through the registration end to ensure that the cross-chain gateway holds a legitimate identity on each chain and uses the verifiable credentials of the application chain for identity verification.
It enhances the security of cross-chain transactions, avoids identity theft issues caused by inconsistent signature algorithms, and ensures the legitimate identity authentication of cross-chain gateways across multiple application chains.
Smart Images

Figure CN119602927B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of blockchain, in particular to an identity management method and device of cross-chain gateway. BACKGROUND
[0002] With the development of blockchain technology, there are many different blockchain platforms, however, these blockchains are usually independent of each other. In order to enable different blockchains to realize transactions, cross-chain transactions have thus been generated.
[0003] Cross-chain transactions are usually based on cross-chain gateways to complete the delivery of cross-chain messages. Since the cross-chain gateway needs to interface at least two application chains, it is necessary to register the corresponding digital identity in the corresponding blockchain of each application chain, but from the perspective of the application chain, it cannot be known whether the cross-chain gateway holds a legal identity in another application chain.
[0004] Therefore, how to manage the digital identity of the cross-chain gateway to improve the security of cross-chain transactions is a problem that needs to be solved at present. SUMMARY
[0005] The embodiments of the present application provide an identity management method and device of cross-chain gateway, which are used to ensure that the cross-chain gateway can hold legal identities of multiple application chains at the same time, solve the problem of identity impersonation that may be caused by inconsistent signature algorithms between multiple application chains, and improve the security of cross-chain transactions.
[0006] In a first aspect, the embodiments of the present application provide an identity management method of cross-chain gateway, comprising:
[0007] The cross-chain gateway sends a registration request to at least two application chains and receives identity identifiers returned by the at least two application chains;
[0008] The cross-chain gateway forms distributed digital identity information based on the identity identifiers corresponding to the at least two application chains, and sends the distributed digital identity information to a registration end for registration;
[0009] The cross-chain gateway receives and stores the verifiable credentials corresponding to each application chain fed back by the registration end, wherein the verifiable credentials corresponding to each application chain are generated after the identity identifiers in the distributed digital identity information are verified by the registration end;
[0010] For a first application chain in the at least two application chains, the cross-chain gateway sends the verifiable credentials corresponding to a second application chain to the first application chain, wherein the second application chain is an application chain other than the first application chain in the at least two application chains, and the verifiable credentials corresponding to the second application chain are used by the first application chain to verify the identity of the cross-chain gateway in cross-chain transactions.
[0011] In the embodiment of the application, the cross-chain gateway needs to register identity information in each application chain first, and based on the identity information, a distributed digital identity information is formed and sent to the registration end for registration. After receiving the distributed digital identity information, the registration end queries each application chain to determine whether the identity information corresponding to each application chain in the distributed digital identity information is correct, and generates a verifiable credential for the identity information corresponding to each application chain when the identity information corresponding to each application chain is correct. The verifiable credential can verify whether the corresponding identity information is correct. The verifiable credential corresponding to the second application chain is sent to the first application chain, so that the first application chain can verify the identity information in the cross-chain gateway according to the stored verifiable credential corresponding to the second application chain when initiating a cross-chain transaction, to determine that the cross-chain gateway holds the legal identity of the second application chain, thereby solving the problem of identity impersonation that may be caused by inconsistent signature algorithms between multiple application chains, and improving the security of cross-chain transactions.
[0012] Optionally, the registration request includes an application public key in an application key pair generated by the cross-chain gateway for each application chain.
[0013] Optionally, the method further comprises:
[0014] The cross-chain gateway receives a cross-chain transaction request initiated by any application chain in the at least two application chains;
[0015] The cross-chain gateway generates a signature of the distributed digital identity information based on the application private key corresponding to the application chain, and sends the distributed digital identity information and the signature to the application chain for identity verification by the application chain.
[0016] In the embodiment of the application, after receiving a cross-chain transaction request of any application chain, the cross-chain gateway generates a signature of the distributed digital identity information based on the application private key, and sends the signature and the distributed digital identity information to the application chain, so that the application chain verifies the identity of the cross-chain gateway in other application chains to determine that the cross-chain gateway holds the legal identity of the other application chains.
[0017] In a second aspect, the embodiment of the application provides an identity management method of a cross-chain gateway, applied to at least two application chains, and specifically comprising:
[0018] For a first application chain in the at least two application chains, the first application chain receives a registration request initiated by the cross-chain gateway, and stores an application public key in the registration request;
[0019] The first application chain generates an identity identifier and sends it to the cross-chain gateway;
[0020] The first application chain receives the verifiable credential corresponding to the second application chain sent by the cross-chain gateway, and stores the verifiable credential, the second application chain being an application chain other than the first application chain in the at least two application chains, and the verifiable credential corresponding to the second application chain being generated after the registration end verifies the identity corresponding to the second application chain in the distributed digital identity information.
[0021] In the embodiment of the application, after receiving the registration request, the first application chain generates an identity in response to the registration request, and sends the identity to the cross-chain gateway. The first application chain receives the verifiable credential corresponding to the second application chain sent by the cross-chain gateway, and verifies whether the cross-chain gateway holds the legal identity of the second application chain based on the verifiable credential corresponding to the second application chain, thereby improving the security of cross-chain transactions.
[0022] Optionally, the method further comprises:
[0023] The first application chain sends a cross-chain transaction request to the cross-chain gateway.
[0024] The first application chain receives the distributed digital identity information and the signature sent by the cross-chain gateway in response to the cross-chain transaction request.
[0025] The first application chain verifies the distributed digital identity information and the signature based on the application public key and the verifiable credential corresponding to the second application chain, and if the verification is passed, the first application chain initiates a cross-chain transaction based on the cross-chain gateway.
[0026] In a third aspect, an identity management device of a cross-chain gateway is provided in the embodiments of the application, and the device comprises:
[0027] The obtaining module is configured to send a registration request to at least two application chains, and receive an identity returned by the at least two application chains.
[0028] The processing module is configured to form a distributed digital identity information based on the identities corresponding to the at least two application chains, and send the distributed digital identity information to a registration end for registration.
[0029] The processing module is configured to receive the verifiable credential corresponding to each application chain fed back by the registration end, and store the verifiable credential, the verifiable credential corresponding to each application chain being generated after the registration end verifies the identity in the distributed digital identity information.
[0030] For a first application chain in the at least two application chains, the verifiable credential corresponding to a second application chain is sent to the first application chain, the second application chain being an application chain other than the first application chain in the at least two application chains, and the verifiable credential corresponding to the second application chain being used by the first application chain to verify the identity of the cross-chain gateway in a cross-chain transaction.
[0031] Optionally, the application public key in the registration request comprises an application public key in an application key pair generated by the cross-chain gateway for each application chain.
[0032] Optionally, the processing module is further configured to:
[0033] receive a cross-chain transaction request initiated by any application chain in the at least two application chains;
[0034] generate a signature of the distributed digital identity information based on an application private key corresponding to the application chain, and send the distributed digital identity information and the signature to the application chain for identity verification.
[0035] In a fourth aspect, an embodiment of the present application provides an identity management apparatus of a cross-chain gateway, comprising:
[0036] an obtaining unit configured to receive a registration request initiated by the cross-chain gateway, and store an application public key in the registration request;
[0037] a processing unit configured to generate an identity identifier, and send the identity identifier to the cross-chain gateway;
[0038] receive a verifiable credential corresponding to a second application chain sent by the cross-chain gateway, and store the verifiable credential, the second application chain being an application chain other than the first application chain in the at least two application chains, and the verifiable credential corresponding to the second application chain being generated after the registration end verifies the identity identifier corresponding to the second application chain in the distributed digital identity information.
[0039] Optionally, the processing unit is further configured to:
[0040] send a cross-chain transaction request to the cross-chain gateway;
[0041] receive distributed digital identity information and a signature sent by the cross-chain gateway in response to the cross-chain transaction request;
[0042] verify the distributed digital identity information and the signature based on the application public key and the verifiable credential corresponding to the second application chain, and if the verification is passed, initiate a cross-chain transaction based on the cross-chain gateway.
[0043] In a fifth aspect, an embodiment of the present application further provides a computer device, comprising:
[0044] a memory configured to store program instructions;
[0045] a processor configured to invoke the program instructions stored in the memory, and perform the above-mentioned identity management method of the cross-chain gateway according to the obtained program execution.
[0046] In a sixth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores computer executable instructions for causing a computer to execute the identity management method of the cross-chain gateway.
[0047] In a seventh aspect, the embodiments of the present application further provide a computer program product, which comprises an executable program for executing the identity management method of the cross-chain gateway by a processor. BRIEF DESCRIPTION OF DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.
[0049] Figure 1 A system architecture schematic diagram is provided for the embodiments of the present application.
[0050] Figure 2 A flowchart of the identity management method of the cross-chain gateway is provided for the embodiments of the present application.
[0051] Figure 3 A flowchart of the identity management method of the cross-chain gateway is provided for the embodiments of the present application.
[0052] Figure 4 A structure schematic diagram of the identity management device of the cross-chain gateway is provided for the embodiments of the present application.
[0053] Figure 5 A structure schematic diagram of the identity management device of the cross-chain gateway is provided for the embodiments of the present application. DETAILED DESCRIPTION
[0054] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort fall within the scope of the present application.
[0055] The application scenarios described in the embodiments of the present application are used to more clearly illustrate the technical solutions protected by the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the appearance of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems. The terms "first" and "second" in the specification and claims of the present application and the above-described drawings are used to distinguish different objects, and are not used to describe a specific order. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0056] Before introducing the identity management method of the cross-chain gateway provided by the embodiments of the present application, in order to facilitate understanding, first, the background technology and terms related to the embodiments of the present application are introduced.
[0057] Application chain: a blockchain dedicated to a specific application, which can be called an application chain.
[0058] Distributed digital identity (DID): a new digital identity management mode based on distributed ledger technology (such as blockchain), aiming to solve many problems existing in traditional centralized identity management systems, such as the identity systems between different institutions are often incompatible, users need to register and authenticate repeatedly when switching between different platforms and services, which brings inconvenience. It uses distributed ledger technology and encryption technology to provide users with a more secure, private and interoperable digital identity solution.
[0059] Verifiable credential (VC): through encryption algorithms and digital signature technologies, the validity and portability of physical credentials are transferred to digital devices, and the content, signature and metadata declared can be digitally verified within a few seconds or even milliseconds.
[0060] With the development of blockchain technology, there are many different blockchain platforms, such as Bitcoin, Ethereum, Polka, etc. However, these blockchains are usually independent of each other, which brings some limitations: 1. Value island: Assets on different blockchains cannot be directly circulated, forming a value island. For example, assets on the Bitcoin network cannot be directly used on the Ethereum network, limiting the liquidity and application scenarios of assets. 2. Data isolation: The data on each blockchain is also isolated from each other, making it difficult to achieve cross-chain data sharing and interaction. This is a barrier for applications that need to integrate multi-chain data. 3. Application limitations: Different blockchains may have different characteristics and advantages, and a single blockchain often cannot meet the complex application requirements. At the same time, in the development process of blockchain, there are needs such as exchange and transaction between different blockchain digital currencies, and interaction needs such as recording and managing data between different blockchain platforms used by different links in the supply chain. Cross-chain technology is born to meet these cross-chain needs, aiming to realize the interconnection between different blockchains.
[0061] Currently, the commonly used cross-chain technologies include notary mechanism, hash locking, sidechain / relay chain, etc. Most cross-chain technologies rely on cross-chain gateways to complete the transmission of cross-chain messages. Since the cross-chain gateway needs to interface at least two application chains, it needs to register the corresponding digital identity in the two application chains, but from the perspective of the application chain, it cannot know whether the gateway holds a legal identity in the other chain.
[0062] Figure 1 An exemplary system architecture suitable for the embodiment of the present application is shown, which includes a cross-chain gateway 110, a registration terminal 120, and an application chain 130, which includes at least two application chains.
[0063] The cross-chain gateway 110 is used to send a registration request to at least two application chains in the application chain 130 and receive identity identifiers returned by at least two application chains in the application chain 130. Then, based on the identity identifiers corresponding to at least two application chains in the application chain 130, a distributed digital identity information is formed and sent to the registration terminal 120 for registration. The verifiable credentials corresponding to each application chain in the at least two application chains fed back by the registration terminal 120 are stored. Finally, for the first application chain in the at least two application chains, the verifiable credentials corresponding to the second application chain are sent to the first application chain in the application chain 130. Exemplarily, the verifiable credentials corresponding to the application chains in the application chain 130 except for the application chain A are sent to the application chain A in the application chain 130. It can be understood that the cross-chain gateway 110 includes application interfaces corresponding to each application chain, such as application chain SDK.
[0064] The registration end 120 includes a registration DID module, a DID verification module, and a VC issuing program. The registration end 120 can be an identifier registration authority, which is not specifically limited herein. The registration DID module is configured to receive the distributed digital identity information sent by the cross-chain gateway 110 for registration. The DID verification module is configured to verify whether the distributed digital identity information is valid, and to call a verification interface of each application chain in the at least two application chains of the application chain 130 to verify whether the identity in the distributed digital identity information is correct. It can be understood that verifying whether the identity in the distributed digital identity information is correct can be verifying whether the distributed digital identity information contains the identity issued by the corresponding application chain. The VC issuing program is configured to generate a verifiable credential for the identity corresponding to each application chain in the at least two application chains of the application chain 130 after the distributed digital identity information is verified, and to send the verifiable credential to the cross-chain gateway 110.
[0065] The application chain 130 includes a digital identity center and a smart contract center for any application chain in the at least two application chains. The digital identity center has a registration interface and a verification interface. The digital identity center is configured to generate an identity after receiving a registration request of the cross-chain gateway 110 based on the registration interface, and to send the identity to the cross-chain gateway 110. The digital identity center is also configured to call the verification interface by the registration end 120 to verify whether the identity in the distributed digital identity information is correct. The smart contract center is configured to store the verifiable credential of the application chain other than the application chain after obtaining the verifiable credential sent by the cross-chain gateway 110.
[0066] It should be noted that the structure shown in the above Figure 1 is only an example, and the embodiments of the present application are not limited thereto.
[0067] Based on the above description, Figure 2 an exemplary flowchart of an identity management method of a cross-chain gateway is shown, which can be executed by an identity management device of the cross-chain gateway.
[0068] As Figure 2 shown, the flow specifically includes:
[0069] In step 210, the cross-chain gateway sends a registration request to at least two application chains, and receives an identity returned by the at least two application chains.
[0070] In the technical solution of the present application, before cross-chain transaction is performed, the cross-chain gateway needs to register identity information in each application chain, i.e., to obtain a legal identity of the cross-chain gateway in each application chain. The cross-chain gateway sends a registration request to at least two application chains which need to perform cross-chain transaction.
[0071] In some embodiments, the application public key in the application key pair generated by the cross-chain gateway for each application chain is included in the registration request. Since the signature algorithm of different application chains can be different, the cross-chain gateway needs to generate the application key pair corresponding to the signature algorithm of each application chain, and send the application public key in the application key pair to the corresponding application chain. The application private key in the application key pair is used by the cross-chain gateway to generate the signature of the distributed digital identity information. The application public key in the application key pair is used by the application chain to verify whether the distributed digital identity information is complete based on the signature.
[0072] Then, each of the at least two application chains stores the application public key in the registration request after receiving the registration request of the cross-chain gateway, and then generates an identity identifier and sends it to the cross-chain gateway. The identity identifier can be a digital identity, which is not limited here.
[0073] In step 220, the cross-chain gateway forms distributed digital identity information based on the identity identifiers corresponding to the at least two application chains, and sends the distributed digital identity information to the registration end for registration.
[0074] In the technical solution of the present application, after receiving the identity identifiers corresponding to the at least two application chains sent by the cross-chain gateway for cross-chain transaction, the cross-chain gateway forms distributed digital identity information based on the identity identifiers corresponding to each application chain. Specifically, the cross-chain gateway adds the identity identifiers corresponding to each application chain to the distributed digital identity document to obtain the distributed digital identity information, and then sends the distributed digital identity information to the registration end for identity registration.
[0075] In step 230, the cross-chain gateway receives the verifiable credentials corresponding to each application chain fed back by the registration end and stores them. The verifiable credentials corresponding to each application chain are generated after the registration end verifies the identity identifiers in the distributed digital identity information.
[0076] In the embodiment of the present application, the verifiable credentials are used to verify the identity identifiers corresponding to them. The verifiable credentials corresponding to each application chain are generated after the registration end verifies the identity identifiers in the distributed digital identity information. Specifically, after receiving the distributed digital identity information, the registration end verifies whether the distributed digital identity information is valid, and then queries each application chain whether the identity identifiers in the distributed digital identity information are correct. When each identity identifier in the distributed digital identity information is verified, the registration end generates the verifiable credentials corresponding to the identity identifier of each application chain and sends them to the cross-chain gateway. After receiving the verifiable credentials corresponding to each application chain, the cross-chain gateway stores them.
[0077] At step 240, the cross-chain gateway sends the verifiable credential corresponding to the second application chain to the first application chain, the second application chain being an application chain other than the first application chain among the at least two application chains, the verifiable credential corresponding to the second application chain being used by the first application chain to authenticate the cross-chain gateway when performing cross-chain transactions.
[0078] In the embodiments of the present application, after receiving the verifiable credential corresponding to each application chain, the cross-chain gateway sends the verifiable credential corresponding to the second application chain to the first application chain among the at least two application chains. The second application chain is an application chain other than the first application chain among the at least two application chains. For example, there are three application chains: application chain A, application chain B and application chain C. After the cross-chain gateway receives the verifiable credential corresponding to each of the three application chains, it sends the verifiable credential corresponding to application chain B and application chain C to application chain A; sends the verifiable credential corresponding to application chain A and application chain C to application chain B; and sends the verifiable credential corresponding to application chain A and application chain B to application chain C.
[0079] The verifiable credential corresponding to the second application chain is used by the first application chain to authenticate the cross-chain gateway when performing cross-chain transactions.
[0080] In a possible implementation, after the cross-chain gateway is registered in each application chain, cross-chain transactions can be performed. Specifically, the cross-chain gateway receives a cross-chain transaction request initiated by any of the at least two application chains. The cross-chain gateway generates a signature of the distributed digital identity information based on the application private key corresponding to the application chain, and sends the distributed digital identity information and the signature to the application chain for identity authentication. When the identity authentication of the cross-chain gateway by the application chain is passed, cross-chain transactions can be performed based on the cross-chain gateway.
[0081] In the embodiments of the present application, a unified distributed digital identity management method is provided for application chains using different signature algorithms, the cross-chain gateway is given a unique distributed digital identity, and the distributed digital identity can be authenticated at any time. At the same time, the security problem similar to the intermediate person that may exist due to the inability of direct interaction between two application chains is avoided, and the security of cross-chain transactions is improved.
[0082] Based on the above description, Figure 3 An example of a flowchart of an identity management method of a cross-chain gateway provided by the embodiments of the present application is shown, which can be executed by an identity management device of the cross-chain gateway.
[0083] As Figure 3 shown, the flow specifically includes:
[0084] At step 310, the first application chain in the at least two application chains receives a registration request initiated by the cross-chain gateway, and stores the application public key in the registration request.
[0085] In the embodiment of the application, when the first application chain in the at least two application chains registers the identity in the cross-chain gateway, the registration request initiated by the cross-chain gateway is received, and the application public key in the registration request is stored. The application public key is used to verify the received distributed digital identity information and signature when the first application chain initiates a cross-chain transaction request.
[0086] At step 320, the first application chain generates an identity identifier and sends it to the cross-chain gateway.
[0087] In the embodiment of the application, the identity identifier generated by the first application chain can be a digital identity, and the specific content of the identity identifier is not limited herein.
[0088] At step 330, the first application chain receives the verifiable credential corresponding to the second application chain sent by the cross-chain gateway, and stores it, the second application chain being an application chain other than the first application chain in the at least two application chains, and the verifiable credential corresponding to the second application chain being generated after the registration end verifies the identity identifier corresponding to the second application chain in the distributed digital identity information.
[0089] In the embodiment of the application, after the first application chain receives the verifiable credential corresponding to the second application chain sent by the cross-chain gateway, the authentication before initiating the cross-chain transaction can be performed.
[0090] In a possible implementation, when the first application chain needs to initiate the cross-chain transaction, the cross-chain transaction request is sent to the cross-chain gateway. Then the distributed digital identity information and signature sent by the cross-chain gateway in response to the cross-chain transaction request are received. Then the first application chain verifies the distributed digital identity information and signature based on the application public key and the verifiable credential corresponding to the second application chain. Specifically, the first application chain verifies the integrity of the distributed digital identity information and signature based on the application public key, and after the verification is passed, verifies whether the identity identifier corresponding to the second application chain in the distributed digital identity information is correct based on the verifiable credential corresponding to the second application chain. If the verification is passed, the first application chain can initiate the cross-chain transaction based on the cross-chain gateway.
[0091] Based on the same technical concept, Figure 4 An exemplary structural schematic diagram of an identity management device of a cross-chain gateway provided by the embodiment of the application is shown, and the device can execute the flow of the identity management method of the cross-chain gateway.
[0092] As Figure 4 shown, the device specifically comprises:
[0093] The acquisition module 410 is configured to send a registration request to at least two application chains and receive identity identifiers returned by the at least two application chains;
[0094] The processing module 420 is configured to add the identity identifiers corresponding to the at least two application chains into distributed digital identity information and send the distributed digital identity information to a registration end for registration;
[0095] The processing module 420 is configured to add the identity identifiers corresponding to the at least two application chains into distributed digital identity information and send the distributed digital identity information to a registration end for registration;
[0096] The processing module 420 is configured to add the identity identifiers corresponding to the at least two application chains into distributed digital identity information and send the distributed digital identity information to a registration end for registration;
[0097] Optionally, the registration request includes an application public key in an application key pair generated by the cross-chain gateway for each application chain.
[0098] Optionally, the processing module 420 is further configured to:
[0099] The processing module 420 is configured to add the identity identifiers corresponding to the at least two application chains into distributed digital identity information and send the distributed digital identity information to a registration end for registration;
[0100] The processing module 420 is configured to add the identity identifiers corresponding to the at least two application chains into distributed digital identity information and send the distributed digital identity information to a registration end for registration.
[0101] Based on the same technical concept, Figure 5 An exemplary structural schematic diagram of an identity management apparatus of a cross-chain gateway is shown, which can execute the flow of the identity management method of the cross-chain gateway.
[0102] As Figure 5 shown, the apparatus specifically includes:
[0103] The acquisition unit 510 is configured to receive a registration request initiated by a cross-chain gateway and store an application public key in the registration request;
[0104] The processing unit 520 is configured to generate an identity identifier and send it to the cross-chain gateway;
[0105] receive the verifiable credential corresponding to the second application chain sent by the cross-chain gateway, and store the verifiable credential, the second application chain being an application chain other than the first application chain in the at least two application chains, the verifiable credential corresponding to the second application chain being generated after the registration end verifies the identity corresponding to the second application chain in the distributed digital identity information.
[0106] Optionally, the processing unit 520 is further configured to:
[0107] send a cross-chain transaction request to the cross-chain gateway;
[0108] receive the distributed digital identity information and the signature sent by the cross-chain gateway in response to the cross-chain transaction request;
[0109] verify the distributed digital identity information and the signature based on the application public key and the verifiable credential corresponding to the second application chain, and if the verification is passed, initiate a cross-chain transaction based on the cross-chain gateway.
[0110] Based on the same technical concept, the embodiments of the present application further provide a computer device, comprising:
[0111] a memory configured to store program instructions;
[0112] a processor configured to invoke the program instructions stored in the memory, and execute the identity management method of the cross-chain gateway according to the obtained program.
[0113] Based on the same technical concept, the embodiments of the present application further provide a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions are configured to make a computer execute the identity management method of the cross-chain gateway.
[0114] Based on the same technical concept, the embodiments of the present application further provide a computer program product, characterized in that the computer program product comprises an executable program, and the executable program is configured to execute the identity management method of the cross-chain gateway by a processor.
[0115] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.
[0116] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.
[0117] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.
[0118] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.
[0119] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A method for identity management of cross-chain gateways, characterized in that, The method comprises: The cross-chain gateway sends a registration request to at least two application chains and receives identity labels returned by the at least two application chains; The cross-chain gateway forms distributed digital identity information based on the identity labels corresponding to the at least two application chains, and sends the distributed digital identity information to a registration terminal for registration; The cross-chain gateway receives verifiable credentials corresponding to each application chain fed back by the registration terminal and stores the verifiable credentials, wherein the verifiable credentials corresponding to each application chain are generated after the identity labels in the distributed digital identity information are verified by the registration terminal; For a first application chain in the at least two application chains, the cross-chain gateway sends verifiable credentials corresponding to a second application chain to the first application chain, wherein the second application chain is an application chain other than the first application chain in the at least two application chains, and the verifiable credentials corresponding to the second application chain are used by the first application chain to verify the identity of the cross-chain gateway in cross-chain transactions.
2. The method of claim 1, wherein, The application public key in the application key pair generated by the cross-chain gateway for each application chain is included in the registration request.
3. The method of any one of claims 1 to 2, wherein, The method further comprises: The cross-chain gateway receives a cross-chain transaction request initiated by any application chain in the at least two application chains; The cross-chain gateway generates a signature of the distributed digital identity information based on the application private key corresponding to the application chain, and sends the distributed digital identity information and the signature to the application chain for identity verification by the application chain.
4. An identity management method of a cross-chain gateway, characterized by, The method is applied to at least two application chains, comprising: For a first application chain in the at least two application chains, the first application chain receives a registration request initiated by the cross-chain gateway and stores the application public key in the registration request; The first application chain generates an identity label and sends it to the cross-chain gateway; The first application chain receives and stores the verifiable credentials corresponding to a second application chain sent by the cross-chain gateway, wherein the second application chain is an application chain other than the first application chain in the at least two application chains, and the verifiable credentials corresponding to the second application chain are generated after the identity label corresponding to the second application chain in the distributed digital identity information is verified by the registration terminal.
5. The method of claim 4, wherein, The method further comprises: The first application chain sends a cross-chain transaction request to the cross-chain gateway; The first application chain receives the distributed digital identity information and the signature sent by the cross-chain gateway in response to the cross-chain transaction request; The first application chain verifies the distributed digital identity information and the signature based on the application public key and the verifiable credentials corresponding to the second application chain, and if the verification is passed, the first application chain initiates a cross-chain transaction based on the cross-chain gateway.
6. An identity management apparatus of a cross-chain gateway, characterized by, The method comprises: An acquisition module is configured to send a registration request to at least two application chains and receive identity labels returned by the at least two application chains; A processing module is configured to form distributed digital identity information based on the identity labels corresponding to the at least two application chains, and send the distributed digital identity information to a registration terminal for registration; receive the verifiable credential corresponding to each application chain of the feedback of the registration end, and store the verifiable credential, wherein the verifiable credential corresponding to each application chain is generated after the registration end verifies the identity in the distributed digital identity information; for a first application chain in the at least two application chains, send the verifiable credential corresponding to a second application chain to the first application chain, wherein the second application chain is an application chain other than the first application chain in the at least two application chains, and the verifiable credential corresponding to the second application chain is used by the first application chain to verify the cross-chain gateway when performing cross-chain transaction.
7. An identity management apparatus of a cross-chain gateway, characterized by, comprising: an obtaining unit, configured to receive a registration request initiated by a cross-chain gateway, and store an application public key in the registration request; a processing unit, configured to generate an identity and send the identity to the cross-chain gateway; receive the verifiable credential corresponding to a second application chain sent by the cross-chain gateway, and store the verifiable credential, wherein the second application chain is an application chain other than a first application chain in at least two application chains, and the verifiable credential corresponding to the second application chain is generated after the registration end verifies the identity corresponding to the second application chain in the distributed digital identity information.
8. A computer device, comprising: comprising: a memory, configured to store program instructions; a processor, configured to invoke the program instructions stored in the memory, and execute the method according to any one of claims 1 to 3, or the method according to any one of claims 4 to 5.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer executable instructions, and the computer executable instructions are used to make the computer execute the method according to any one of claims 1 to 3, or the method according to any one of claims 4 to 5.
10. A computer program product, characterised in that, The computer program product comprises an executable program, and the executable program is executed by the processor to implement the method according to any one of claims 1 to 3, or the method according to any one of claims 4 to 5.
Citation Information
Patent Citations
Block chain cross-chain security access method and device
CN114499898A
Block chain cross-chain system and method based on distributed identity
CN117614640A