Identity verification method and system, electronic equipment and storage medium
By storing and transmitting the identity and verifiable credentials of digital twins on the blockchain network, the problem of digital twins relying on a centralized server is solved, and higher authentication reliability and robustness are achieved.
Patent Information
- Application Number
- CN202311434829.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-31
- Publication Date
- 2025-05-02
AI Technical Summary
Authentication between existing digital twins relies on centralized servers, resulting in a single point of failure risk and affecting the reliability of authentication.
The identity identification and verifiable credentials of the first digital twin are sent to the second digital twin through the distributed files of the blockchain network, so that the second digital twin can perform identity verification, replacing the identity configuration and verification process of the central server.
Effectively reduce the impact of single point failure in centralized servers on digital twin authentication, and improve the reliability and robustness of authentication.
Smart Images

Figure CN119921963A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of distributed identity and digital twins, and specifically, to an identity authentication method, system, electronic device and storage medium. Background Art
[0002] At present, all physical devices may have at least one digital twin. Different digital twins of the same physical device can communicate with each other, and digital twins of different physical devices can also communicate with each other. In the specific practice process, it is found that these digital twins may belong to different manufacturers (such as battery manufacturers, electric vehicle manufacturers or battery energy storage station manufacturers, etc.). Digital twins of different manufacturers need to rely on centralized servers for identity authentication before they can communicate with each other. Therefore, the current identity authentication between digital twins depends on centralized servers, which may have single point failures, which will affect the identity authentication of digital twins. Summary of the invention
[0003] The purpose of the embodiments of the present application is to provide an identity authentication method, system, electronic device and storage medium, which are used to improve the problem that identity authentication between digital twins depends on a centralized server.
[0004] The embodiment of the present application provides an identity authentication method, including: obtaining a first identity identifier of a first digital twin and a verifiable credential generated based on the first identity identifier; storing the first identity identifier and the verifiable credential in a distributed file of a blockchain network; and sending the first identity identifier and the verifiable credential in the distributed file to the second digital twin for identity authentication. In the implementation process of the above scheme, the first identity identifier and the verifiable credential of the first digital twin are sent to the second digital twin through the distributed file of the blockchain network, so that the second digital twin can authenticate the first digital twin based on the first identity identifier in the distributed file and the proof information of the first digital twin, thereby using the generation and verification process of the verifiable credential to replace the identity configuration and verification process of the central server, improving the situation where the identity authentication between digital twins of different manufacturers needs to rely on a centralized server, and effectively reducing the impact of the single point failure of the centralized server on the identity authentication of the digital twin.
[0005] Optionally, in an embodiment of the present application, before obtaining the first identity of the first digital twin and the verifiable credential generated based on the first identity, it also includes: determining the certification information of the first digital twin based on the identity attribute value of the first digital twin; generating a verifiable credential based on the first identity and the certification information of the first digital twin. In the implementation process of the above scheme, by generating a verifiable credential based on the first identity and the certification information of the first digital twin, the second digital twin can perform identity authentication based on the first identity and the certification information of the first digital twin, thereby improving the situation where identity authentication between digital twins of different manufacturers needs to rely on a centralized server.
[0006] Optionally, in an embodiment of the present application, the proof information is a zero-knowledge proof; a verifiable credential is generated based on the proof information of the first identity identifier and the first digital twin, including: encapsulating the identity attribute value of the first identity identifier and the first digital twin to obtain a zero-knowledge proof of the identity attribute value encapsulation; and generating a verifiable credential based on the first identity identifier and the zero-knowledge proof. In the implementation process of the above scheme, by generating a verifiable credential based on the first identity identifier and the zero-knowledge proof, since the zero-knowledge proof can not disclose the specific identity information such as the identity attribute value of the first digital twin to the second digital twin, the privacy of the identity information of the first digital twin is effectively improved.
[0007] Optionally, in an embodiment of the present application, the first identity identifier and the identity attribute value of the first digital twin are encapsulated, including: committing to the identity attribute value of the first digital twin to obtain an identity commitment value; encapsulating the identity commitment value and the first identity identifier to obtain a zero-knowledge proof. In the implementation of the above scheme, by committing to the identity attribute value and encapsulating the committed identity commitment value and the first identity identifier, the zero-knowledge proof of the identity attribute value encapsulation is made more credible, thereby improving the reliability of the verifiable credential generated by the zero-knowledge proof.
[0008] Optionally, in an embodiment of the present application, before committing to the identity attribute value of the first digital twin, it also includes: receiving the device attribute value sent by the device to be verified, the first digital twin is constructed by the operation data or production data of the device to be verified; determining the identity attribute value of the first digital twin according to the device attribute value sent by the device to be verified. In the implementation process of the above scheme, by determining the identity attribute value of the first digital twin according to the device attribute value sent by the device to be verified, the device attribute value of the device to be verified can be recognized as an identity attribute value by other digital twins, which effectively enhances the robustness of identity authentication.
[0009] Optionally, in an embodiment of the present application, a verifiable credential is generated based on the first identity identifier and the certification information of the first digital twin, including: sending the first identity identifier and the identity attribute value to the identity service network, the certification information determined by the first identity identifier and the identity attribute value is used to generate a verifiable credential by the identity service network; receiving the verifiable credential sent by the identity service network. In the implementation process of the above scheme, a verifiable credential is generated based on the first identity identifier and the identity attribute value through the identity service network, so that other digital twins can authenticate the verifiable credential generated by the identity service network, effectively enhancing the robustness of the identity authentication.
[0010] Optionally, in an embodiment of the present application, after generating a verifiable credential based on the first identity identifier and the certification information of the first digital twin, it also includes: encapsulating the first identity identifier and the verifiable credential into an identity registration request; sending the identity registration request to the identity service network, the identity registration request is used to associate and store the first identity identifier with the verifiable credential. In the implementation process of the above scheme, the first identity identifier and the verifiable credential are associated and stored through the identity service network, so that other digital twins can authenticate the verifiable credential generated by the identity service network, effectively enhancing the robustness of the identity service.
[0011] Optionally, in an embodiment of the present application, the first identity identifier and verifiable credential in the distributed file are sent to the second digital twin for identity authentication, including: broadcasting a consensus request for the distributed file to the blockchain network, the consensus request is used for the blockchain network to reach a consensus on the distributed file and synchronize the first identity identifier and verifiable credential in the distributed file to the second digital twin. In the implementation process of the above scheme, by actively broadcasting a consensus request to the blockchain network, so that the blockchain network reaches a consensus on the distributed file and synchronizes the first identity identifier and verifiable credential in the distributed file to the second digital twin, the first identity identifier and verifiable credential can be recorded by the blockchain network in a timely manner and cannot be tampered with, thereby improving the security of identity authentication for the first digital twin.
[0012] Optionally, in an embodiment of the present application, the first identity identifier and the verifiable credential in the distributed file are sent synchronously to the second digital twin for identity authentication, including: after receiving the synchronization request broadcast by the second digital twin through the blockchain network, the first identity identifier and the verifiable credential in the distributed file are sent synchronously to the second digital twin. In the implementation process of the above scheme, the distributed file is synchronized and sent to the second digital twin only after passively receiving the synchronization request broadcast by the second digital twin through the blockchain network, thereby effectively increasing the synchronization flexibility of the distributed file.
[0013] Optionally, in an embodiment of the present application, after the first identity identifier and verifiable credentials in the distributed file are sent to the second digital twin for identity authentication, it also includes: obtaining the identity authentication result from the distributed file synchronized with the blockchain network, and the identity authentication result is stored by the second digital twin in the distributed file in the blockchain network. In the implementation process of the above scheme, by obtaining the identity authentication result from the distributed file synchronized with the blockchain network, it is confirmed that the second digital twin stores the identity authentication result in the distributed file in the blockchain network, so as to avoid being stored in the blockchain network by other blockchain nodes in the name of others, which effectively increases the security of identity authentication for the first digital twin.
[0014] Optionally, in the embodiment of the present application, it also includes: if the identity authentication is passed, sending a data request to the second digital twin; receiving the data result corresponding to the data request returned by the second digital twin; and executing the application task according to the data result. In the implementation process of the above scheme, by executing the application task according to the data result, the unsafe risk of executing the application task without identity authentication is reduced, and the security of executing the application task is effectively improved.
[0015] Optionally, in the embodiment of the present application, it also includes: encapsulating the first identity identifier and the verifiable credential into an identity cancellation request; sending the identity cancellation request to the identity service network, the identity cancellation request is used to delete the associated storage of the first identity identifier and the verifiable credential. In the implementation process of the above scheme, the associated storage of the first identity identifier and the verifiable credential is deleted through the identity service network, thereby improving the identity cancellation function of the identity service network and enhancing the robustness of the identity service.
[0016] The embodiment of the present application also provides an identity authentication method, including: receiving a distributed file containing a first identity identifier and a verifiable credential of a first digital twin from a blockchain network, the verifiable credential being generated based on the first identity identifier; parsing the first identity identifier and the verifiable credential from the distributed file; and authenticating the first digital twin based on the first identity identifier and the verifiable credential. In the implementation process of the above scheme, the first digital twin is authenticated through the first identity identifier and the verifiable credential, thereby improving the situation where the identity authentication between digital twins of different manufacturers needs to rely on a centralized server, and removing third-party trust to increase the reliability of identity authentication.
[0017] Optionally, in an embodiment of the present application, the first digital twin is authenticated based on the first identity and the verifiable credential, including: parsing the certification information of the first digital twin from the verifiable credential; and authenticating the first digital twin using the first identity and the certification information of the first digital twin. In the implementation of the above scheme, the first digital twin is authenticated by using the first identity and the certification information of the first digital twin, thereby improving the situation where the identity authentication between digital twins of different manufacturers needs to rely on a centralized server.
[0018] Optionally, in an embodiment of the present application, the proof information is a zero-knowledge proof; the first digital twin is authenticated using the first identity identifier and the proof information of the first digital twin, including: parsing the identity identifier to be verified and the zero-knowledge proof from the verifiable credential; if the identity identifier to be verified is the same as the first identity identifier, performing knowledge verification on the zero-knowledge proof to obtain a knowledge verification result; and performing identity authentication based on the knowledge verification result. In the implementation process of the above scheme, identity authentication is performed based on the knowledge verification result of the zero-knowledge proof, thereby improving the situation where identity authentication between digital twins of different manufacturers needs to rely on a centralized server, and the zero-knowledge proof does not disclose the identity information of the first digital twin, effectively improving the privacy security of identity authentication.
[0019] Optionally, in an embodiment of the present application, the first digital twin is authenticated using the first identity identifier and the certification information of the first digital twin, including: storing the first identity identifier and the verifiable credential in a distributed file of the blockchain network; sending the first identity identifier and the verifiable credential in the distributed file to the identity service network, and the certification information in the first identity identifier and the verifiable credential is used for identity authentication. In the implementation process of the above scheme, by sending the first identity identifier and the verifiable credential in the distributed file to the identity service network for identity authentication, other digital twins can be authenticated through the identity service network, which effectively enhances the robustness of identity authentication.
[0020] The embodiment of the present application also provides an identity authentication method, which is applied to an identity service network, including: receiving a distributed file sent by a second digital twin; obtaining a first identity identifier of a first digital twin and a verifiable credential generated according to the first identity identifier from the distributed file; parsing the certification information of the first digital twin from the verifiable credential; and authenticating the first digital twin using the first identity identifier and the certification information of the first digital twin. In the implementation process of the above scheme, the first digital twin is authenticated by using the first distributed identity identifier and the certification information of the first digital twin through the identity service network, so that the second digital twin can be authenticated through the identity service network, which effectively enhances the robustness of the identity authentication.
[0021] Optionally, in an embodiment of the present application, it also includes: receiving an identity registration request sent by the first digital twin, the identity registration request including: the first identity identifier and the verifiable credential of the first digital twin; using the first identity identifier and the certification information of the first digital twin to authenticate the identity of the first digital twin; after the identity authentication is passed, the first identity identifier and the verifiable credential are associated and stored. In the implementation process of the above scheme, the first identity identifier and the verifiable credential are associated and stored through the identity service network, so that other digital twins can authenticate the verifiable credential generated by the identity service network, which effectively enhances the robustness of the identity service.
[0022] Optionally, in an embodiment of the present application, it also includes: receiving an identity cancellation request sent by the first digital twin, the identity cancellation request including: a first identity identifier and a verifiable credential; using the first identity identifier and the certification information of the first digital twin to authenticate the first digital twin; after the identity authentication is passed, deleting the associated storage of the first identity identifier and the verifiable credential. In the implementation process of the above scheme, after the identity authentication of the first identity identifier and the verifiable credential is passed through the identity service network, the associated storage of the first identity identifier and the verifiable credential is deleted, thereby improving the identity cancellation function of the identity service network and enhancing the robustness of the identity service.
[0023] An embodiment of the present application also provides an identity authentication system, including: a first digital twin, used to obtain a first identity of the first digital twin and a verifiable credential generated based on the first identity, and store the first identity and the verifiable credential in a distributed file of the blockchain network, and then send the first identity and the verifiable credential in the distributed file to a second digital twin for identity authentication; a second digital twin, used to receive a distributed file containing the first identity and the verifiable credential of the first digital twin from the blockchain network, and parse the first identity and the verifiable credential from the distributed file, and then authenticate the first digital twin based on the first identity and the verifiable credential.
[0024] An embodiment of the present application further provides an electronic device, including: a processor and a memory, wherein the memory stores machine-readable instructions executable by the processor, and when the machine-readable instructions are executed by the processor, the method described above is performed.
[0025] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described above is executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.
[0027] Figure 1 A flowchart of an identity verification method provided by an embodiment of the present application is shown;
[0028] Figure 2 A schematic diagram of a process for generating a verifiable credential based on an identity attribute value provided by an embodiment of the present application is shown;
[0029] Figure 3 A schematic diagram of a data model for data standardization provided by an embodiment of the present application is shown;
[0030] Figure 4 A schematic diagram of a flow chart of an identity authentication method performed by a second digital twin provided in an embodiment of the present application is shown;
[0031] Figure 5 A flow chart of an identity authentication method performed by an identity service network provided in an embodiment of the present application is shown;
[0032] Figure 6A schematic diagram of the structure of the identity authentication system provided by an embodiment of the present application is shown;
[0033] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0034] To make the purpose, technical scheme and advantages of the embodiment of the present application clearer, the technical scheme in the embodiment of the present application will be clearly and completely described below in conjunction with the drawings in the embodiment of the present application. It should be understood that the drawings in the embodiment of the present application only serve the purpose of explanation and description, and are not used to limit the protection scope of the embodiment of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in the embodiment of the present application shows the operation implemented according to some embodiments of the embodiment of the present application. It should be understood that the operation of the flowchart can be implemented out of order, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart under the guidance of the content of the embodiment of the present application, or remove one or more operations from the flowchart.
[0035] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all embodiments. The components of the embodiments of the present application described and shown in the drawings generally here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the embodiments of the present application claimed, but merely represents the selected embodiments of the embodiments of the present application.
[0036] It is understandable that the "first" and "second" in the embodiments of the present application are used to distinguish similar objects. Those skilled in the art will understand that the words "first" and "second" do not limit the quantity and execution order, and the words "first" and "second" do not necessarily limit the difference. In the description of the embodiments of the present application, the term "and / or" is merely a description of the association relationship of associated objects, indicating that there may be three relationships, such as A and / or B, which can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the related objects before and after are in an "or" relationship. The term "multiple" refers to more than two (including two), and similarly, "multiple groups" refers to more than two groups (including two groups).
[0037] Before introducing the identity authentication method provided in the embodiment of the present application, some concepts involved in the embodiment of the present application are first introduced:
[0038] Digital Twin, also known as digital twin, digital twin or digital mirror, refers to a virtual twin built using the data of physical entities, such as batteries, electric vehicles, energy storage charging stations, etc. The data between the virtual twin and the physical entity flows in both directions. If the physical entity is an electric vehicle, the electric vehicle can send sensor data to the virtual twin through real-time monitoring sensors. The virtual twin can analyze the sensor data and send control instructions to the electric vehicle based on the analysis results to control the operation of the electric vehicle.
[0039] A distributed identity (Decentralized IDentity, DID) is an identifier for the secure identity of a digital twin in a digital twin system. The same digital twin can use the same distributed identity in different distributed information systems, or it can use different distributed identities.
[0040] Blockchain network refers to the network composed of all node devices in the blockchain. Blockchain can be divided into private chain and public chain according to the different participants.
[0041] In related technologies, most business entities (such as battery manufacturers, electric vehicle manufacturers, or used car platform providers) may use their own data to build digital twins. Due to security factors such as data privacy protection and laws and regulations, most business entities use centralized servers recognized by both parties to the communication (such as digital certificate certification authority servers, etc.) for identity authentication and share relevant data after the identity authentication is passed, resulting in the identity authentication between digital twins relying on centralized servers.
[0042] For example, a battery manufacturer may use the manufacturing data of the battery to build a battery digital twin, while an electric vehicle manufacturer may also use the battery operation data and the manufacturing data of the electric vehicle to build an electric vehicle digital twin. When the electric vehicle digital twin wants to communicate with the battery digital twin during the operation of the battery, the electric vehicle digital twin usually needs to be authenticated by the authentication server confirmed by the battery manufacturer before it can communicate with the battery digital twin to obtain the battery manufacturing data. Therefore, the identity authentication and data communication between the electric vehicle digital twin and the battery digital twin need to rely on a centralized authentication server.
[0043] In response to the above problems, in an embodiment of the present application, an identity identifier and a verifiable credential are sent to the digital twin through a distributed file of the blockchain network. Since the digital twin can use the identity identifier and the verifiable credential to verify the authenticity, consistency and availability of the identity attribute value, the digital twin can authenticate other digital twins through the identity identifier and the verifiable credential without being authenticated by a centralized server, thereby improving the situation where identity authentication between digital twins of different manufacturers needs to rely on a centralized server.
[0044] See also Figure 1 A flow chart of the identity authentication method provided in the embodiment of the present application is shown; the identity authentication method can be executed by an electronic device, which can be a blockchain node in a blockchain network, a system node in a distributed system, or a cluster node in a cloud computing cluster, so the role of the electronic device is not limited. The electronic device here refers to a device terminal with the function of executing a computer program or the above-mentioned server, such as a smart phone, a personal computer, a tablet computer, a personal digital assistant, or a mobile Internet device. A server refers to a device that provides computing services through a network, such as an x86 server and a non-x86 server, and non-x86 servers include mainframes, minicomputers, and UNIX servers. The implementation method of the above-mentioned identity authentication method may include the following steps:
[0045] Step S110: Obtain a first identity identifier of the first digital twin and a verifiable credential generated based on the first identity identifier.
[0046] It is understandable that the identity in the embodiment of the present application can be a distributed identity or a non-distributed identity, wherein a distributed identity refers to an identity that can uniquely identify an identity in a distributed system, and the difference between a distributed identity and a non-distributed identity is that a distributed identity can be generated by itself or by other nodes in a distributed system. However, the use scenario of a non-distributed identity is not a scenario used in a distributed system, and can only be generated by other nodes. There are many ways to generate the above-mentioned distributed identity (DID), including but not limited to: a DID generation algorithm based on a hardware identifier (Hardware ID), a DID generation algorithm based on a secure chip integrated circuit (Secure Integrated Circuit, SIC), a DID generation algorithm based on a private key signature (Private KeySignature, PKS) or a DID generation algorithm based on a hardware security module (Hardware Security Module, HSM), etc. The format of the distributed identity (DID) also has many formats, including but not limited to: eXtensible Markup Language (eXtensible Markup Language, XML) format or script object notation (JavaScriptObject Notation, JSON) format, etc.
[0047] It is understandable that there can be multiple different identities for the same digital twin. For example, when the battery digital twin is used for internal local area network communication of the battery manufacturer, one of the identities of the battery digital twin is used for communication, and when the battery digital twin is used to communicate with other electric vehicle digital twins, another identity of the battery digital twin can be used for communication. Therefore, the number of identities of the same digital twin can be set according to specific scenarios and specific needs.
[0048] The above-mentioned Verifiable Credential (VC) can be generated based on the zero-knowledge proof encapsulated by the digital twin's own identity attribute value, or it can be generated based on the zero-knowledge proof encapsulated by the factory attribute value of the physical device corresponding to the digital twin. For example: if the battery manufacturer uses the battery manufacturing data to build a battery digital twin, then the battery digital twin can generate a verifiable credential based on the zero-knowledge proof encapsulated by its own identity attribute value. For another example: after the battery is manufactured and shipped, the manufacturing equipment of the battery (such as a winding machine or a die-cutting machine, etc.) can also generate a verifiable credential based on the zero-knowledge proof encapsulated by the factory attribute value of the battery.
[0049] It is understandable that the same identity identifier can generate different verifiable credentials, and different identity identifiers can also be generated in the same verifiable credential. For example, the battery digital twin can use the identity identifier of the digital twin to generate verifiable credentials for communicating with other digital twins (such as electric vehicle digital twins), and can also use the identity identifier of the digital twin to generate verifiable credentials for communicating with traditional physical devices (such as digital certificate service devices or identity authentication servers).
[0050] Step S120: Storing the first identity identifier and the verifiable credential in a distributed file of the blockchain network.
[0051] The implementation method of the above step S120 is, for example: It can be understood that the distributed files of the blockchain network include many block files. When storing information, the latest block file can be found from the distributed files of the blockchain network, and the first identity and the verifiable credential can be stored in the latest block file. The latest block file here can reach a consensus with other blockchain nodes in the blockchain network. After reaching a consensus, the latest block file can be actively synchronized with other blockchain nodes (for example, broadcasting consensus requests and synchronization requests), or passively synchronized with other blockchain nodes (for example, after receiving a consensus request or a synchronization request, broadcasting a consensus request and synchronizing). In actual operation, the above distributed file can be sent to the second digital twin in an incremental manner through the blockchain network (that is, only the latest consensus block file is sent to the second digital twin), such as the above active synchronization method or passive synchronization method, and of course it can also be directly sent to the second digital twin in full through the Internet for identity authentication (that is, all distributed files including multiple block files are sent to the second digital twin).
[0052] Step S130: Send the first identity identifier and verifiable credentials in the distributed file to the second digital twin for identity authentication.
[0053] It is understandable that the first digital twin and the second digital twin mentioned above can be constructed based on the data of the same device in different life cycles (of course, they can also be constructed based on the data of different new devices, which will be described in detail below). For example, the first digital twin can be constructed based on the production data of the same battery, and the second digital twin can be constructed based on the operation data of the same battery. Alternatively, the first digital twin and the second digital twin can also be constructed based on the data of different devices. For example, the first digital twin can be constructed based on the production data of the battery, and the second digital twin can be constructed based on the operation data of an electric vehicle, which can be equipped with the battery. The first digital twin can send the first identity and verifiable credentials to the second digital twin through the blockchain network. Of course, the first digital twin can also send the first identity and verifiable credentials to the second digital twin through the Internet. The first digital twin can also encapsulate and / or encrypt the first identity and verifiable credentials before sending them to the second digital twin, and so on.
[0054] There are many ways for the above-mentioned second digital twin to authenticate the verifiable credential. The second digital twin can directly authenticate the verifiable credential, or the second digital twin can forward the verifiable credential to the identity service network and let the identity service network authenticate the verifiable credential. The specific identity authentication method will be described in detail below.
[0055] In the implementation process of the above scheme, the first digital twin sends the first identity and verifiable credentials to the second digital twin, so that the second digital twin can authenticate the first digital twin according to the first identity in the distributed file and the proof information of the first digital twin, so as to replace the identity configuration and verification process of the central server with the generation and verification process of the verifiable credentials. That is to say, the work of configuring the identity of the central server can be replaced by the credentials generated by the first digital twin according to the identity, and the work of verifying the identity of the central server can be replaced by the verification credentials of the second digital twin. The above method effectively improves the situation where the identity authentication between digital twins of different manufacturers needs to rely on centralized servers, and reduces the dependence of identity authentication between digital twins on centralized servers. Therefore, the use of decentralized identity and verifiable credentials enables each digital twin to authenticate its identity, effectively reducing the impact of single point failures of centralized servers on the identity authentication of digital twins.
[0056] As an optional implementation of the above identity authentication method, before obtaining the first identity identifier of the first digital twin and the verifiable credential generated according to the first identity identifier, it also includes:
[0057] Step S101: Determine the certification information of the first digital twin according to the identity attribute value of the first digital twin.
[0058] The proof information of the first digital twin refers to information used to prove that the identity attribute value of the digital twin is credible, such as a digital signature or zero-knowledge proof. For example, both a digital signature and a zero-knowledge proof can jointly prove that the identity attribute value of the digital twin is credible.
[0059] Zero-knowledge proof is a cryptographic technique used by a prover (e.g., the first digital twin) to prove the authenticity of a statement (e.g., the identity attribute value of a digital twin) without revealing additional information to the verifier (e.g., the second digital twin). That is, the prover can prove a fact to the verifier without revealing specific information related to the fact. For example, the first digital twin can prove the identity attribute value of the digital twin to the second digital twin without revealing any identity attribute value of the first digital twin to the second digital twin.
[0060] Step S102: Generate a verifiable credential based on the first identity identifier and the certification information of the first digital twin.
[0061] As an optional implementation of step S102, the above-mentioned proof information may include: zero-knowledge proof; the above-mentioned implementation of generating a verifiable credential based on the proof information of the first identity identifier and the first digital twin may include:
[0062] Step S102a: Encapsulate the first identity identifier and the identity attribute value of the first digital twin to obtain zero-knowledge proof of the identity attribute value encapsulation.
[0063] Step S102b: Generate a verifiable credential based on the first identity identifier and the zero-knowledge proof.
[0064] It is understandable that the same verifiable credential may include at least one zero-knowledge proof encapsulated in an identity attribute value; that is, the same verifiable credential may include only one zero-knowledge proof encapsulated in an identity attribute value, and of course may also include zero-knowledge proofs encapsulated in multiple identity attribute values, where the multiple identity attribute values are, for example: the issuer identification of the verifiable credential, validity period, proof attribute value, factory time and / or factory location number, etc.
[0065] As an optional implementation of the above step S102a, encapsulating the first identity identifier and the identity attribute value of the first digital twin includes:
[0066] Step S102c: Commit the identity attribute value of the first digital twin to obtain an identity commitment value.
[0067] Step S102d: Encapsulate the identity commitment value and the first identity identifier to obtain zero-knowledge proof.
[0068] An implementation example of the above steps S102c to S102d is: in order to protect its real identity (such as the specific value in the identity attribute value) from being leaked, the digital twin can use the above identity attribute value as a commitment object, commit to the identity attribute value, and obtain the identity commitment value; then, encapsulate the identity commitment value and the first distributed identity identifier to obtain a zero-knowledge proof of the identity attribute value encapsulation.
[0069] As an optional implementation of the above step S102a, before committing to the identity attribute value of the first digital twin, the identity attribute value may also be determined according to the device attribute value of the device to be verified, including:
[0070] Step S102e: receiving device attribute values sent by the device to be verified, where the first digital twin is constructed based on operation data or production data of the device to be verified.
[0071] The device to be verified refers to the device whose identity is to be verified. The device to be verified here can be new energy equipment, such as new energy batteries, new energy vehicles, energy storage charging stations, etc.; of course, the device to be verified here can also be a component of a new energy battery, such as a lithium battery pack and battery cell, etc.
[0072] An implementation example of the above step S102e is as follows: the first digital twin receives the device attribute value sent by the device to be verified through the HyperText Transfer Protocol (HTTP) or the HyperText Transfer Protocol Secure (HTTPS).
[0073] Step S102f: Determine the identity attribute value of the first digital twin according to the device attribute value sent by the device to be verified.
[0074] An implementation example of the above-mentioned step S102f is: the device to be verified sends device attribute values such as a physical serial number, a production time and / or a production location number to the first digital twin. Then, after receiving the device attribute values sent by the device to be verified, the first digital twin can concatenate the physical serial number, the production time and / or the production location number to obtain a concatenated string, and determine the concatenated string as the identity attribute value of the first digital twin; in addition to the physical serial number, the production time and / or the production location number of the device to be verified, the above-mentioned identity attribute value may also include other attribute values of the first digital twin, for example: the construction time, construction location or construction personnel identification of the digital twin, etc.
[0075] As an optional implementation of the above step S102f, the above device attribute value may include: a physical serial number of the device to be verified, a field name of the operation data, and / or a field name of the production data; an implementation method of determining the identity attribute value of the first digital twin according to the device attribute value sent by the device to be verified may include:
[0076] Step S102g: Perform hash processing on the field names of the operation data and / or the field names of the production data to obtain field hash values.
[0077] An implementation of the above step S102g is, for example: using a hash algorithm to hash the field names of the operation data and / or the field names of the production data to obtain field hash values; wherein the hash algorithms that can be used include but are not limited to: MD5 or WHIRLPOOL algorithms.
[0078] Step S102h: Determine the identity attribute value of the first digital twin based on the physical serial number and field hash value of the device to be verified.
[0079] The implementation method of the above step S102h is, for example: concatenating the physical serial number and the field hash value of the device to be verified to obtain a concatenated string, and determining the concatenated string as the identity attribute value of the first digital twin. Another example: using a secure hash algorithm (SHA) to perform a hash calculation on the physical serial number and the field hash value of the device to be verified to obtain a hash string, and determining the hash string as the identity attribute value of the first digital twin; wherein, the secure hash algorithm (SHA) that can be used is, for example: SHA-256 / 224, SHA-512 / 384, etc.
[0080] In the implementation process of the above scheme, the identity attribute value of the first digital twin is determined according to the physical serial number and field hash value of the device to be verified, so that the identity attribute value determined by the physical serial number and field hash value can be recognized by other digital twins, thereby effectively enhancing the robustness of identity authentication.
[0081] See also Figure 2 A schematic diagram of a process for generating a verifiable credential based on an identity attribute value provided by an embodiment of the present application is shown; as an optional implementation of the above step S102, the above-mentioned certification information may include: signature information; an implementation method for generating a verifiable credential based on the certification information of the first identity identifier and the first digital twin may include:
[0082] Step S102i: Use the private key of the first digital twin to sign the first identity identifier and identity attribute value to obtain signature information.
[0083] Step S102j: Generate a verifiable credential based on the first identity identifier and signature information.
[0084] The implementation method of the above steps S102i to S102j is, for example: using a hash algorithm to perform hash calculation on the first distributed identity and identity attribute value to obtain an identity hash value (such as f954bbffdee2ad59 in the figure), and then using the private key of the first digital twin as the input of the encryption algorithm, and using the encryption algorithm to encrypt the identity hash value to obtain the above-mentioned signature information (signature), for example, the identity hash value "f954bbffdee2ad59" is encrypted by MD5, and the obtained signature information is 9bda46fb78a44b1b. Among them, the hash algorithms that can be used include but are not limited to: MD5 or WHIRLPOOL algorithms, and the encryption algorithms that can be used include but are not limited to: RSA algorithm, SM2 algorithm, Diffie-Hellman algorithm or Elliptic Curve Digital Signature Algorithm (ECDSA), etc.
[0085] In the implementation process of the above scheme, the first digital twin itself generates a verifiable credential based on the signature information of the first identity identifier and identity attribute value, so that the verifiable credential generated by the first digital twin itself can be recognized by other digital twins, thereby effectively enhancing the robustness of identity authentication.
[0086] As an optional implementation of the above step S102, an implementation of generating a verifiable credential according to the first identity identifier and the certification information of the first digital twin may include:
[0087] Step S102k: Send the first identity identifier and identity attribute value to the identity service network, and the certification information determined by the first identity identifier and identity attribute value is used to generate a verifiable credential by the identity service network.
[0088] It is understandable that the above-mentioned identity service network can be a blockchain network composed of blockchain nodes, a computer cluster network composed of cluster computer nodes, or a distributed service network composed of cloud servers. After receiving the first distributed identity and identity attribute value sent by the first digital twin, the identity service network can use only the signature information to generate a verifiable credential, or only the zero-knowledge proof to generate a verifiable credential. Of course, the signature information and the zero-knowledge proof can also be used to jointly generate a verifiable credential. For simplicity, here only the use of signature information and zero-knowledge proof to jointly generate a verifiable credential is used as an example to illustrate, for example: use the private key of the identity service network to sign the first distributed identity and identity attribute value, obtain the signature information, and commit to the identity attribute value, obtain the identity commitment value, and encapsulate the identity commitment value and the first distributed identity to obtain the zero-knowledge proof of the identity attribute value encapsulation; then, generate a verifiable credential based on the zero-knowledge proof of the signature information and the identity attribute value encapsulation. After generating the verifiable credential, the identity service network can send the generated verifiable credential to the first digital twin. The first digital twin receives the verifiable credentials sent by the identity service network through the Transmission Control Protocol (TCP) protocol or the User Datagram Protocol (UDP) protocol.
[0089] Step S1021: Receive a verifiable credential sent by the identity service network.
[0090] An implementation example of the above step S1021 is as follows: the first digital twin receives a verifiable credential sent by the identity service network through the TCP protocol or the UDP protocol, and the verifiable credential is generated based on the first identity identifier and the identity attribute value. It can be understood that the identity attribute value can be a product name (name), a product production address (address) or a production batch number, etc. The figure takes the product production address (address) as an example for illustration, such as No. 12, Street A in the figure. The first distributed identity identifier is, for example, DID: Method: id1 in the figure; wherein DID indicates that the type of identity identifier is a distributed identity identifier, method indicates the way in which the distributed identity identifier is generated, and id1 indicates the specific value of the distributed identity identifier.
[0091] As an optional implementation of the above identity authentication method, after generating a verifiable credential according to the first identity identifier and the certification information of the first digital twin, it also includes:
[0092] Step S103: Encapsulate the first identity identifier and the verifiable credential into an identity registration request.
[0093] Step S104: sending an identity registration request to the identity service network, where the identity registration request is used to associate and store the first identity identifier with the verifiable credential.
[0094] The implementation method of the above steps S103 to S104 is, for example: the first digital twin encapsulates the first distributed identity and the verifiable credential into JSON format data, and then uses the private key of the first digital twin to digitally sign the JSON format data to obtain the signed JSON data. Finally, the signed JSON data is used as the payload to generate an identity registration request in the JWT (JSON Web Token) format. Then, the first digital twin can send the identity registration request to the identity service network through the HTTP protocol or the HTTPS protocol. The identity service network can first use the public key of the first digital twin to verify the digital signature in the JWT format identity registration request. After the signature verification is passed, the first distributed identity and the verifiable credential can also be authenticated. There are many implementation methods for identity authentication here, see the implementation method of step S220 below. After the identity authentication of the first distributed identity and the verifiable credential is passed, the identity service network can use an executable program compiled or interpreted in a preset programming language to associate and store the first distributed identity with the verifiable credential for use in verifying the identity of the first digital twin. Among them, the programming languages that can be used include: C, C++, Java, BASIC, JavaScript, LISP, Shell, Perl, Ruby, Python and PHP, etc.
[0095] It is understandable that in a decentralized distributed information system, the first digital twin can register its identity with the identity service network based on the first distributed identity and the verifiable credential, that is, after the identity authentication of the first distributed identity and the verifiable credential is passed, the identity service network associates and stores the first distributed identity and the verifiable credential, so that the identity service network can use the first distributed identity and the verifiable credential for identity authentication, etc. For example: if the second digital twin cannot parse the verifiable credential sent by the first digital twin, or if there is an error in parsing the verifiable credential sent by the first digital twin, the first distributed identity and the verifiable credential can be sent to the identity service network, so that the identity service network can authenticate the first distributed identity and the verifiable credential.
[0096] As an optional implementation of the above step S130, the above implementation of sending the first identity identifier and the verifiable credential in the distributed file to the second digital twin for identity authentication includes:
[0097] Step S131: Broadcast the consensus request of the distributed file to the blockchain network.
[0098] Step S132: After receiving the consensus request, the blockchain network reaches a consensus on the distributed file and synchronously sends the first identity identifier and verifiable credential in the distributed file to the second digital twin.
[0099] The implementation of the above steps S131 to S132 is, for example: the first digital twin broadcasts a consensus request for a distributed file to the blockchain network through a peer-to-peer (P2P) protocol. The blockchain network can receive the consensus request through the P2P protocol, reach a consensus on the distributed file, and synchronize the first identity and verifiable credentials in the distributed file to the second digital twin.
[0100] As an optional implementation of the above step S130, the above implementation of synchronously sending the first identity identifier and the verifiable credential in the distributed file to the second digital twin for identity authentication may include:
[0101] Step S133: Receive a synchronization request broadcast by the second digital twin through the blockchain network.
[0102] Step S134: Synchronously send the first identity identifier and verifiable credentials in the distributed file to the second digital twin according to the synchronization request.
[0103] An example of an implementation of the above-mentioned steps S133 to S134 is: the first digital twin receives a synchronization request broadcast by the second digital twin through the blockchain network through a peer-to-peer (Peer ToPeer, P2P) protocol, and then synchronizes the consensus block file in the distributed file to the second digital twin according to the synchronization request. It can be understood that the consensus block file includes a first identity identifier and a verifiable credential.
[0104] As an optional implementation of the above identity authentication method, after sending the first identity identifier and the verifiable credential in the distributed file to the second digital twin for identity authentication, it also includes:
[0105] Step S140: Obtain the identity authentication result from the distributed file synchronized with the blockchain network. The identity authentication result is stored by the second digital twin in the distributed file in the blockchain network.
[0106] An example of an implementation of the above step S140 is: after completing the identity authentication of the first digital twin, the second digital twin can store the identity authentication result in a distributed file in the blockchain network, and synchronize with the first digital twin through the distributed file of the blockchain network, so that the first digital twin obtains the synchronized distributed file. After obtaining the synchronized distributed file, the first digital twin can obtain the identity authentication result from the synchronized distributed file of the blockchain network.
[0107] As an optional implementation of the above identity authentication method, the application task may be executed after the identity authentication is passed. The implementation may include:
[0108] Step S150: If the identity authentication is passed, a data request is sent to the second digital twin.
[0109] Step S160: Receive the data result corresponding to the data request returned by the second digital twin.
[0110] An example of an implementation of the above steps S150 to S160 is: if the first digital twin passes the identity authentication of the second digital twin, then a data request can be sent to the second digital twin. After receiving the data request sent by the first digital twin, the second digital twin can search and generate the data result corresponding to the data request, and send the data result corresponding to the data request to the first digital twin through the TCP protocol or the UDP protocol. The first digital twin receives the data result sent by the second digital twin through the TCP protocol or the UDP protocol, and then, can also perform corresponding application tasks according to the data structure.
[0111] Step S170: Execute application tasks according to the data results.
[0112] The implementation method of the above step S170 is, for example: Then, the first digital twin performs the task of evaluating the battery quality according to the data results, and / or the task of evaluating the insurance price. In some second-hand battery recycling scenarios, the second-hand battery recycling manufacturer can construct a first digital twin based on the battery data in the data results such as temperature, remaining life (State Of Health, SOH) and test reports, and use the first digital twin to evaluate the battery quality level, such as excellent, good, medium, poor, etc. For another example: In some battery insurance business scenarios, after obtaining the battery data, the insurance company can construct a first digital twin based on the battery data such as temperature, remaining life (State Of Health, SOH) and test reports, and use the first digital twin to evaluate the battery quality level, such as excellent, good, medium, poor, etc., and then evaluate the insurance price of the battery for different battery quality levels. Similarly, in some electric vehicle insurance businesses, insurance companies can also obtain electric vehicle manufacturing data from the digital twin constructed by the electric vehicle manufacturer, and obtain maintenance data during the use of the vehicle from the database of the electric vehicle repair manufacturer. Based on the above electric vehicle manufacturing data and maintenance data, a first digital twin is constructed, and the first digital twin is used to evaluate the insurance price of the electric vehicle.
[0113] See also Figure 3 The data model schematic diagram of data standardization provided by the embodiment of the present application is shown; optionally, in the above-mentioned process of identity authentication based on verifiable credentials, and in the process of executing application tasks based on data results, the data sent between the first digital twin and the second digital twin can be encapsulated using a data standardized data model, and the message encapsulated by the data model is used for interaction. The above-mentioned data model may include: an application model (Application Mode), a device model (Device Mode), a module model (Module Mode) and a unit model (UnitMode). The application model may include multiple application objects (Application Object), such as ApplicationObj1 to Application Objn in the figure, which may specifically be electric vehicle applications and lithium battery energy storage applications; the device model may include multiple device objects (Device Object), such as Device Obj1 to Device Objn in the figure; the module model may include multiple module objects (Module Object), such as Module Obj1 to Module Objn in the figure; the unit model may include multiple unit objects (Unit Object), such as Unit Obj1 to Unit Objn in the figure.
[0114] It is understandable that the above-mentioned application object, device object, module object and / or unit object can also be regarded as a more detailed data structure. Therefore, the above-mentioned application object, device object, module object and / or unit object can include multiple fields. Here, the application object is used as an example for explanation. These fields include but are not limited to: identification (id), attribute (Attribute), event (Event), measurement (Measurement), warning (Warning), message (Message) and result (Result), etc. Of course, in the implementation process of the screenshot, the above-mentioned data model can also include more fields or data structures, and the specific settings of the data model can be set according to the specific application scenario or business scenario.
[0115] As an optional implementation of the above identity authentication method, the following may also be included:
[0116] Step S180: Encapsulate the first identity identifier and the verifiable credential into an identity deregistration request.
[0117] Step S190: sending an identity deregistration request to the identity service network, where the identity deregistration request is used to delete the associated storage between the first identity identifier and the verifiable credential.
[0118] The implementation method of the above steps S180 to S190 is, for example: the first digital twin encapsulates the first distributed identity and the verifiable credential into JSON format data, and then uses the private key of the first digital twin to digitally sign the JSON format data to obtain the signed JSON data. Finally, the signed JSON data is used as the payload to generate an identity cancellation request in the JWT format. Then, the first digital twin can send the identity cancellation request to the identity service network through the HTTP protocol or the HTTPS protocol. The identity service network can first use the public key of the first digital twin to verify the digital signature in the JWT format identity cancellation request. After the signature verification is passed, the first distributed identity and the verifiable credential can also be authenticated. There are many implementation methods for identity authentication here, please refer to the implementation method of step S220 above. After the identity authentication of the first distributed identity and the verifiable credential is passed, the identity service network can use an executable program compiled or interpreted in a preset programming language to delete the associated storage of the first distributed identity and the verifiable credential. Among them, the programming languages that can be used include: C, C++, Java, BASIC, JavaScript, LISP, Shell, Perl, Ruby, Python and PHP, etc.
[0119] See also Figure 4 A flow chart of an identity authentication method performed by a second digital twin provided in an embodiment of the present application is shown; an identity authentication method is provided in an embodiment of the present application, and is applied to a second digital twin, including:
[0120] Step S210: The second digital twin receives a distributed file containing a first identity identifier and a verifiable credential of the first digital twin from the blockchain network, and the verifiable credential is generated based on the first identity identifier.
[0121] It is understandable that the second digital twin can receive the first distributed identity and verifiable credentials sent by the first digital twin from the blockchain network through the HTTP protocol or HTTPS protocol in the Internet. Of course, the second digital twin can also receive the first distributed identity and verifiable credentials sent by the first digital twin through the peer-to-peer (P2P) protocol in the blockchain.
[0122] Step S220: Parse the first identity identifier and the verifiable credential from the distributed file.
[0123] Step S230: Authenticate the first digital twin based on the first identity identifier and the verifiable credential.
[0124] Optionally, as an optional implementation of the above step S230, the implementation of authenticating the first digital twin may include:
[0125] Step S231: Parse the certification information of the first digital twin from the verifiable credential.
[0126] Step S232: Use the first identity identifier and the certification information of the first digital twin to authenticate the identity of the first digital twin.
[0127] As an optional implementation of the above step S232, the above-mentioned proof information may include: zero-knowledge proof; using the first identity identifier and the proof information of the first digital twin to authenticate the first digital twin, including:
[0128] Step S232a: Parse the identity to be verified and the zero-knowledge proof from the verifiable credential.
[0129] Step S232b: If the identity identifier to be verified is the same as the first identity identifier, knowledge verification is performed on the zero-knowledge proof to obtain a knowledge verification result.
[0130] Step S232c: Perform identity verification based on the knowledge verification result.
[0131] An implementation example of the above step S232c is: determine whether the knowledge verification result is passed. If the knowledge verification result is passed, determine that the identity authentication result of the first digital twin is passed; if the knowledge verification result is not passed, determine that the identity authentication result of the first digital twin is not passed.
[0132] As an optional implementation of the above step S232, the above certification information may include: signature information; if it is a verifiable credential generated by the signature information obtained by signing the public key of the first digital twin, then the public key of the first digital twin may be used for identity authentication. The above implementation of using the first identity identifier and the certification information of the first digital twin to authenticate the first digital twin may include:
[0133] Step S232d: Parse the identity identification and signature information to be verified from the verifiable credential.
[0134] Step S232e: If the identity to be verified is the same as the first identity, the signature information is verified using the public key of the first digital twin to obtain a signature verification result.
[0135] Step S232f: Perform identity verification based on the signature verification result.
[0136] An example of the implementation of the above steps S232d to S232f is: Since the signature information in the verifiable credential is obtained by signing the first distributed identity and identity attribute value using the private key of the first digital twin, the second digital twin can use the public key of the first digital twin to perform signature verification on the signature information to obtain a signature verification result, and perform knowledge verification on the zero-knowledge proof to obtain a knowledge verification result. After obtaining the signature verification result and the knowledge verification result, the second digital twin determines whether the signature verification result is signature verification passed, and whether the knowledge verification result is passed. If the signature verification result is signature verification passed, and the knowledge verification result is knowledge verification passed, then it is determined that the identity verification is passed. If the signature verification result is signature verification failed, or the knowledge verification result is knowledge verification failed, then it is determined that the identity verification is failed.
[0137] Optionally, if the verifiable credential is generated by the signature information obtained by signing the private key of the identity service network, the public key of the identity service network can be used for identity authentication. The implementation method here is similar to the above, so it will not be repeated.
[0138] Optionally, if it is a verifiable credential generated jointly by the signature information obtained by the private key signature of the identity service network and the zero-knowledge proof, then the implementation method of the credential verification is, for example: since the signature information in the verifiable credential is obtained by signing the first distributed identity identifier and identity attribute value using the private key of the identity service network, the second digital twin can use the public key of the identity service network to verify the signature information, obtain the signature verification result, and perform knowledge verification on the zero-knowledge proof to obtain the knowledge verification result, and perform identity authentication based on the signature verification result and the knowledge verification result.
[0139] As an optional implementation of the above step S232, if the verifiable credentials are generated by the identity service network, the identity service network may also be allowed to perform identity authentication. This implementation may include:
[0140] Step S232g: Store the first identity identifier and the verifiable credential in a distributed file of the blockchain network.
[0141] It is understandable that the second digital twin can send the first distributed identity and verifiable credentials to the identity service network through the HTTP protocol or HTTPS protocol in the Internet. Of course, the second digital twin can also send the first distributed identity and verifiable credentials to the identity service network through the peer-to-peer (P2P) protocol in the blockchain.
[0142] Step S232h: Send the first identity identifier and the verifiable credential in the distributed file to the identity service network, and the certification information in the first identity identifier and the verifiable credential is used for identity authentication.
[0143] An implementation example of the above step S232h is as follows: synchronizing the distributed file to the identity service network through the blockchain network, so that the identity service network verifies the identity of the first digital twin according to the first identity identifier and the verifiable credential in the distributed file. The identity service network authenticates the first digital twin using the first distributed identity identifier and the certification information of the first digital twin in the verifiable credential, and sends the result of the identity authentication to the second digital twin.
[0144] See also Figure 5 The flowchart of the identity authentication method performed by the identity service network provided in the embodiment of the present application is shown; the implementation method of the identity authentication method performed by the identity service network provided in the embodiment of the present application may include:
[0145] Step S310: Obtain a first identity identifier of the first digital twin and a verifiable credential generated based on the first identity identifier from a distributed file of the blockchain network.
[0146] An example of an implementation of the above step S310 is: the identity service network receives the distributed file of the blockchain network sent by the second digital twin, and obtains the first distributed identity and verifiable credentials of the first digital twin from the distributed file of the blockchain network. It can be understood that the identity service network can receive the first distributed identity and verifiable credentials sent by the second digital twin through the HTTP protocol or HTTPS protocol in the Internet. Of course, the identity service network can also receive the first distributed identity and verifiable credentials sent by the second digital twin through the peer-to-peer (P2P) protocol in the blockchain. The above-mentioned verifiable credentials can be generated based on the zero-knowledge proof encapsulated by the first distributed identity and the identity attribute value of the first digital twin.
[0147] Step S320: Parse the certification information of the first digital twin from the verifiable credential.
[0148] There are many situations for the above-mentioned proof information. The first situation is the signature information obtained by the first digital twin using the private key of the first digital twin to sign the first distributed identity identifier and identity attribute value of the first digital twin; the second situation is the signature information obtained by the identity service network using the private key of the identity service network to sign the first distributed identity identifier and identity attribute value of the first digital twin; the third situation is the zero-knowledge proof constructed by the first digital twin based on the identity attribute value; the fourth situation, combining the first and third situations, the signature information obtained by signing with the private key of the first digital twin and the zero-knowledge proof are used together as proof information.
[0149] Step S330: Use the first identity identifier and the certification information of the first digital twin to authenticate the identity of the first digital twin.
[0150] Among them, the implementation principle and implementation method of step S330 are similar to the implementation principle and implementation method of step S240. Therefore, its implementation principle and implementation method are not explained here again, and reference can be made to the description of step S240.
[0151] As an optional implementation of the above identity authentication method, the following may also be included:
[0152] Step S340: Receive an identity registration request sent by the first digital twin, where the identity registration request includes: a first identity identifier and a verifiable credential of the first digital twin.
[0153] Step S350: Use the first identity identifier and the certification information of the first digital twin to authenticate the identity of the first digital twin.
[0154] Step S360: After the identity authentication is passed, the first identity identifier is associated with the verifiable credential and stored in a configuration file or a database.
[0155] It is understandable that the identity service network can use the first distributed identity and the verifiable credential to authenticate the first digital twin, obtain the authentication result, and after the authentication result is passed, associate the first distributed identity with the verifiable credential and store it.
[0156] As an optional implementation of the above identity authentication method, the following may also be included:
[0157] Step S370: Receive an identity deregistration request sent by the first digital twin, where the identity deregistration request includes: a first identity identifier and a verifiable credential.
[0158] Step S380: Use the first identity identifier and the certification information of the first digital twin to authenticate the identity of the first digital twin.
[0159] Step S390: After the identity authentication is passed, the association between the first identity identifier and the verifiable credential is deleted from the configuration file or the database.
[0160] See also Figure 6 The structural diagram of the identity authentication system provided by the embodiment of the present application is shown; the embodiment of the present application provides an identity authentication system 400, including:
[0161] The first digital twin 410 is used to obtain the first identity of the first digital twin and the verifiable credential generated according to the first identity, and store the first identity and the verifiable credential in a distributed file of the blockchain network, and then send the first identity and the verifiable credential in the distributed file to the second digital twin for identity authentication.
[0162] The second digital twin 420 is used to receive a distributed file containing the first identity and verifiable credentials of the first digital twin from the blockchain network, parse the first identity and verifiable credentials from the distributed file, and then authenticate the first digital twin based on the first identity and verifiable credentials.
[0163] It should be understood that the system corresponds to the above-mentioned identity authentication method embodiment and can execute the various steps involved in the above-mentioned method embodiment. The specific functions of the system can be found in the description above, and the detailed description is appropriately omitted here. The system includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the operating system (OS) of the system.
[0164] See also Figure 7 An electronic device 500 provided in an embodiment of the present application includes: a processor 510 and a memory 520, wherein the memory 520 stores machine-readable instructions executable by the processor 510, and when the machine-readable instructions are executed by the processor 510, the above method is executed.
[0165] The embodiment of the present application also provides a computer-readable storage medium 530, on which a computer program is stored, and the computer program is executed by the processor 510 to execute the above method. The computer-readable storage medium 530 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, disk or optical disk.
[0166] It should be noted that each embodiment in this specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same or similar parts between the embodiments can be referred to each other. For system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0167] In several embodiments provided by the embodiments of the present application, it should be understood that the disclosed system and method can also be implemented in other ways. The system embodiment described above is only schematic, for example, the flowchart and block diagram in the accompanying drawings show the possible implementation architecture, function and operation of the system, method and computer program product according to the multiple embodiments of the embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a part of a module, a program segment or a code, and a part of a module, a program segment or a code includes one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also be different from the order of occurrence marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which is mainly determined according to the functions involved.
[0168] In addition, each functional module of each embodiment in the embodiment of the present application can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part. In addition, in the description of this specification, the description of reference terms "one embodiment", "some embodiments", "example", "specific example", "some examples", etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the embodiment of the present application. In this specification, the schematic representation of the above terms does not necessarily target the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples without contradiction.
[0169] The above description is only an optional implementation manner of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or replacements within the technical scope disclosed in the embodiments of the present application, which should be covered within the protection scope of the embodiments of the present application.
Claims
1. An identity authentication method, characterized in that: include: Obtaining a first identity of a first digital twin and a verifiable credential generated based on the first identity; Storing the first identity and the verifiable credential in a distributed file of a blockchain network; The first identity identifier and the verifiable credential in the distributed file are sent to the second digital twin for identity authentication.
2. The method according to claim 1, characterized in that Before obtaining the first identity of the first digital twin and generating a verifiable credential based on the first identity, the method further includes: Determining certification information of the first digital twin according to the identity attribute value of the first digital twin; The verifiable credential is generated based on the first identity identifier and the certification information of the first digital twin.
3. The method according to claim 2, characterized in that The proof information is a zero-knowledge proof; and the generating the verifiable credential according to the first identity identifier and the proof information of the first digital twin includes: Encapsulating the first identity identifier and the identity attribute value of the first digital twin to obtain a zero-knowledge proof of the identity attribute value encapsulation; The verifiable credential is generated based on the first identity and the zero-knowledge proof.
4. The method according to claim 3, characterized in that The encapsulating the first identity identifier and the identity attribute value of the first digital twin includes: Committing the identity attribute value of the first digital twin to obtain an identity commitment value; The identity commitment value and the first identity identifier are encapsulated.
5. The method according to claim 4, characterized in that Before the commitment is made to the identity attribute value of the first digital twin, the method further includes: Receiving a device attribute value sent by a device to be verified, wherein the first digital twin is constructed by operation data or production data of the device to be verified; The identity attribute value of the first digital twin is determined according to the device attribute value sent by the device to be verified.
6. The method according to claim 2, characterized in that The generating the verifiable credential according to the first identity identifier and the certification information of the first digital twin includes: Sending the first identity identifier and the identity attribute value to an identity service network, wherein the certification information determined by the first identity identifier and the identity attribute value is used by the identity service network to generate the verifiable credential; The verifiable credential sent by the identity service network is received.
7. The method according to claim 2, characterized in that After generating the verifiable credential according to the first identity identifier and the certification information of the first digital twin, the method further includes: Encapsulating the first identity identifier and the verifiable credential into an identity registration request; The identity registration request is sent to an identity service network, where the identity registration request is used to associate and store the first identity identifier with the verifiable credential.
8. The method according to any one of claims 1 to 7, characterized in that: The sending the first identity identifier and the verifiable credential in the distributed file to the second digital twin for identity authentication includes: Broadcasting a consensus request for the distributed file to the blockchain network, wherein the consensus request is used for the blockchain network to reach a consensus on the distributed file and synchronize the first identity identifier and the verifiable credential in the distributed file to the second digital twin; or, After receiving the synchronization request broadcast by the second digital twin through the blockchain network, the first identity identifier and the verifiable credential in the distributed file are synchronously sent to the second digital twin.
9. The method according to any one of claims 1 to 7, characterized in that: After sending the first identity identifier and the verifiable credential in the distributed file to the second digital twin for identity authentication, the method further includes: The identity authentication result is obtained from the distributed file synchronized with the blockchain network, and the identity authentication result is stored by the second digital twin in the distributed file in the blockchain network.
10. The method according to any one of claims 1 to 7, characterized in that: Also includes: If the identity authentication is passed, sending a data request to the second digital twin; Receiving a data result corresponding to the data request returned by the second digital twin; Execute application tasks according to the data results.
11. The method according to any one of claims 1 to 7, characterized in that: Also includes: Encapsulating the first identity identifier and the verifiable credential into an identity deregistration request; The identity deregistration request is sent to an identity service network, where the identity deregistration request is used to delete the associated storage between the first identity identifier and the verifiable credential.
12. An identity authentication method, characterized in that: include: Receiving from a blockchain network a distributed file comprising a first identity and a verifiable credential of a first digital twin, the verifiable credential being generated based on the first identity; parsing the first identity and the verifiable credential from the distributed file; Authenticate the first digital twin based on the first identity and the verifiable credential.
13. The method according to claim 12, characterized in that The authenticating the first digital twin according to the first identity and the verifiable credential includes: Parsing certification information of the first digital twin from the verifiable credential; The first digital twin is authenticated using the first identity identifier and the certification information of the first digital twin.
14. The method according to claim 13, characterized in that The proof information is a zero-knowledge proof; and the identity verification of the first digital twin using the first identity identifier and the proof information of the first digital twin includes: Parsing the identity to be verified and the zero-knowledge proof from the verifiable credential; If the identity identifier to be verified is the same as the first identity identifier, performing knowledge verification on the zero-knowledge proof to obtain a knowledge verification result; Authentication is performed based on the knowledge verification result.
15. The method according to claim 13, characterized in that The using the first identity identifier and the certification information of the first digital twin to authenticate the first digital twin includes: Storing the first identity and the verifiable credential in a distributed file of a blockchain network; The first identity identifier and the verifiable credential in the distributed file are sent to an identity service network, and the first identity identifier and the certification information in the verifiable credential are used for identity authentication.
16. The method according to claim 12, characterized in that Also includes: Receiving an identity registration request sent by a first digital twin, the identity registration request comprising: a first identity identifier of the first digital twin and the verifiable credential; Authenticate the first digital twin using the first identity identifier and the certification information of the first digital twin; After the identity authentication is passed, the first identity identifier is associated with the verifiable credential and stored.
17. The method according to any one of claims 12 to 16, characterized in that: Also includes: Receiving an identity deregistration request sent by the first digital twin, the identity deregistration request including: the first identity identifier and the verifiable credential; Authenticate the first digital twin using the first identity identifier and the certification information of the first digital twin; After the identity authentication is passed, the association between the first identity identifier and the verifiable credential is deleted.
18. An identity authentication system, characterized in that: include: The first digital twin is used to obtain a first identity of the first digital twin and a verifiable credential generated according to the first identity, and store the first identity and the verifiable credential in a distributed file of the blockchain network, and then send the first identity and the verifiable credential in the distributed file to the second digital twin for identity authentication; The second digital twin is used to receive a distributed file containing the first identity identifier and the verifiable credential of the first digital twin from the blockchain network, parse the first identity identifier and the verifiable credential from the distributed file, and then authenticate the first digital twin based on the first identity identifier and the verifiable credential.
19. An electronic device, characterized in that: include: A processor and a memory, wherein the memory stores machine-readable instructions executable by the processor, and when the machine-readable instructions are executed by the processor, the method according to any one of claims 1 to 17 is performed.
20. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 17 is executed.