Decentralized identity authentication method, system, device and medium

By registering decentralized identity identifiers and generating identity credentials on the blockchain, combined with smart contract verification, the privacy leakage, identity theft and other problems of traditional centralized identity verification systems are solved, and higher security and user control are achieved.

CN119939547APending Publication Date: 2025-05-06SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202411782476.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Traditional centralized identity verification systems have problems such as privacy leakage risks, identity theft and fraud, relying on third-party trust and lack of data control.

Method used

By combining blockchain technology with identity verification, decentralized verification of user identity is achieved. The specific steps include registering and generating a decentralized identity identifier (DID) on the blockchain, generating and issuing identity credentials by the identity provider, and verifying the validity of the identity credentials through smart contracts and blockchain.

Benefits of technology

It effectively protects users' privacy, improves the security of identity verification, reduces dependence on central institutions, reduces the risk of data breaches and abuse, and simplifies the user's identity management process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939547A_ABST
    Figure CN119939547A_ABST
Patent Text Reader

Abstract

The invention provides a decentralized identity authentication method, system and device and a medium, and belongs to the technical field of information security. The method comprises the following steps: registering and generating a decentralized identity identifier on a block chain based on user information, and taking the decentralized identity identifier as a digital representation of a user identity; an identity provider generates and issues an identity certificate for a corresponding user based on a decentralized identity identifier, and encrypts, stores and shares the identity certificate; when a user tries to log in or access an online service, a decentralized identity identifier and a related identity credential are submitted to a service provider, and the service provider verifies the validity of the identity credential through an intelligent contract and a block chain; after the verification is passed, the service provider confirms the identity of the user and grants access authority to the user; and recording verification and use information of the identity credential in an audit log, and carrying out encrypted storage through a block chain. According to the invention, the block chain technology is combined with identity verification, so that decentralized verification of the user identity is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology, and more specifically relates to a decentralized identity authentication method, system, device and medium. Background Art

[0002] In the current digital age, identity authentication is a core component of user interactions on the Internet. Traditional identity authentication methods usually rely on centralized identity management systems (such as governments, banks, social platforms, etc.), which usually authenticate through usernames and passwords, SMS verification codes, or biometrics. However, centralized identity authentication methods have the following significant problems: 1. Risk of privacy leakage: In traditional identity management systems, users' sensitive information (such as personal information, passwords, transaction records, etc.) is stored in centralized servers, which makes this information easy to become a target of hacker attacks. Once these servers are attacked, users' personal information may be leaked or abused.

[0003] 2. Identity theft and fraud: Centralized identity authentication systems are vulnerable to data breaches, account hijacking, and identity forgery. For example, attackers steal users’ usernames and passwords, or obtain users’ login credentials through phishing attacks, and then use their identities to conduct illegal operations.

[0004] 3. Dependence on third-party trust: In a centralized system, all identity verification processes rely on third-party institutions (such as banks, government agencies, or social platforms). This trust reliance exposes users to the risks of technical failures, mismanagement, or misconduct that these institutions may encounter. In addition, user identity verification across multiple platforms requires repeated creation, verification, and management of multiple accounts, resulting in inefficiency and inconvenience.

[0005] 4. Lack of data control: Traditional identity management methods usually give control of identity data to identity authentication providers, and users have little control over their personal identity information. For example, users cannot fully decide who uses their data and how it is used, which increases the risk of information leakage, abuse or improper handling. Summary of the invention

[0006] In view of the above problems, the purpose of the present invention is to provide a decentralized identity authentication method, system, device and medium, which realizes decentralized verification of user identity by combining blockchain technology with identity authentication, effectively protects user privacy and improves security.

[0007] In order to achieve the above object, the present invention is implemented through the following technical solutions: In a first aspect, an embodiment of the present application provides a decentralized identity authentication method, comprising: Based on user information, a decentralized identity identifier is registered and generated on the blockchain as a digital representation of the user's identity; The identity provider generates and issues identity credentials for the corresponding users based on the decentralized identity identifier, and performs encrypted storage and sharing; When a user attempts to log in or access an online service, they submit a decentralized identity identifier and related identity credentials to the service provider, who verifies the validity of the identity credentials through smart contracts and blockchain; After verification, the service provider confirms the user's identity and grants access rights to the user; The verification and use information of identity credentials are recorded in the audit log and stored encrypted via blockchain.

[0008] Archive and back up audit logs regularly.

[0009] In an optional embodiment, the registering and generating a decentralized identity identifier on a blockchain based on user information as a digital representation of the user identity includes: Create user identities through a centralized identity management platform and verify user information through encryption algorithms; After verification, a key pair is generated for the user, a decentralized identity identifier is generated through the public key, and registered on the blockchain.

[0010] In an optional implementation, the identity provider generates and issues identity credentials for corresponding users based on the decentralized identity identifier, and encrypts and stores and shares them through a blockchain, including: Initiate a credential application request to an identity provider through a decentralized identity management platform; the credential application request includes a decentralized identity identifier and user information verified by a blockchain; The identity provider verifies the user information through the relevant database or institutional data. After the verification is passed, it generates and issues an identity certificate and signs the identity certificate with a private key; the identity certificate includes identity information and related attributes; Store identity credentials on the blockchain.

[0011] In an optional implementation, the service provider verifies the validity of the identity credential through a smart contract and a blockchain, including: The service provider resolves the DID identifier submitted by the user through smart contracts or by querying the distributed ledger on the blockchain; According to the DID identifier, query the corresponding DID document; Obtaining the public key based on the DID document to verify the validity of the signature of the identity credential; If the validity verification of the signature passes, the user information is obtained based on the identity credential, the user information is verified according to the preset verification rules, and the validity period of the identity credential is used to determine whether the user credential has expired; If the user information meets the preset verification rules and the user credentials have not expired, the identity credentials are valid.

[0012] In an optional implementation, the preset verification rule uses zero-knowledge proof.

[0013] In an optional implementation, the verification and use information of the identity credentials is recorded in an audit log and encrypted and stored via a blockchain, including: Triggering the recording of audit logs through smart contracts to record the verification and use information of identity credentials in the audit logs; the verification and use information of identity credentials includes: issuance, revocation, authorization and verification failure information of identity credentials; Encrypt user information in the audit log and set the encrypted information to be visible only to authorized parties; Through smart contracts or decentralized applications, audit logs are submitted to the blockchain network for encrypted storage.

[0014] In an optional implementation, the periodic archiving and backing up of the audit logs includes: Regularly archive and back up audit logs through external storage services; The external storage services include but are not limited to the Interplanetary File System and the Arweave network.

[0015] In a second aspect, the embodiment of the present application further provides a decentralized identity authentication system, including: DID creation and registration module, which is used to register and generate a decentralized identity identifier on the blockchain based on user information as a digital representation of the user's identity; The identity credential issuance module is used to generate and issue identity credentials for corresponding users based on decentralized identity identifiers through identity providers, and encrypt and store and share them through blockchain; The identity verification module is used to submit a decentralized identity identifier and related identity credentials to the service provider when the user attempts to log in or access an online service. The service provider verifies the validity of the identity credentials through smart contracts and blockchain; Authorization module, which is used by the service provider to confirm the user's identity and grant access rights to the user after verification; The data recording module is used to record the verification and usage information of identity credentials in the audit log and store them encrypted through the blockchain.

[0016] The backup module is used to archive and back up audit logs regularly.

[0017] In a third aspect, an embodiment of the present application further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the decentralized identity authentication method as described in any one of the above items are implemented.

[0018] In a fourth aspect, an embodiment of the present application further provides a storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of the decentralized identity authentication method as described in any one of the above items are implemented.

[0019] It can be seen from the above technical solutions that the present invention has the following advantages: The decentralized identity authentication method provided in this application combines blockchain technology with identity authentication to provide a more secure, privacy-protecting and decentralized identity authentication method that is suitable for multiple industry fields such as finance, medical care, social networking, and e-commerce.

[0020] Through decentralized control, this application enables users to have full control over their own identity information, reduces dependence on central agencies, and reduces the risk of data leakage and abuse.

[0021] This application is based on the immutability and encryption technology of blockchain, which can ensure the security and integrity of identity data and reduce the possibility of data theft and tampering.

[0022] This application protects user privacy while ensuring the effectiveness of identity authentication through selective data disclosure and zero-knowledge proof.

[0023] This application simplifies the user authentication process through decentralized identity authentication, and users do not need to manage multiple accounts and passwords separately on each platform.

[0024] This application supports cross-platform authentication. Users can use the same decentralized identity for authentication on multiple service platforms, improving user experience and authentication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solution of the present invention, the accompanying drawings required for use in the description will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0026] Figure 1 A flowchart of the decentralized identity authentication method provided for this application.

[0027] Figure 2 A schematic diagram of the structure of the decentralized identity authentication system provided for this application.

[0028] Figure 3 A schematic diagram of the structure of the electronic device provided in this application. DETAILED DESCRIPTION

[0029] In the specific steps of the decentralized identity authentication method described in detail below, various embodiments of the present disclosure will be described more fully. The present disclosure may have various embodiments, and adjustments and changes may be made therein. However, it should be understood that there is no intention to limit the various embodiments of the present disclosure to the specific embodiments disclosed herein, but rather the present disclosure should be understood to cover all adjustments, equivalents and / or alternatives that fall within the spirit and scope of the various embodiments of the present disclosure.

[0030] Hereinafter, the terms "include" or "may include" used in various embodiments of the present disclosure indicate the presence of disclosed functions, operations, or elements, and do not limit the addition of one or more functions, operations, or elements. In addition, as used in various embodiments of the present disclosure, the terms "include", "have", and their cognates are intended only to indicate specific features, numbers, steps, operations, elements, components, or a combination of the foregoing, and should not be understood as first excluding the presence of one or more other features, numbers, steps, operations, elements, components, or a combination of the foregoing or the possibility of adding one or more features, numbers, steps, operations, elements, components, or a combination of the foregoing.

[0031] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0032] See also Figure 1 The figure is a flowchart of a decentralized identity authentication method in a specific embodiment, the method comprising: S1: Based on user information, a decentralized identity identifier is registered and generated on the blockchain as a digital representation of the user's identity.

[0033] In a specific implementation, first, a user identity is created through a centralized identity management platform, and user information is verified through an encryption algorithm. Specifically, the user accesses a decentralized identity management platform (such as uPort, Sovrin, etc.) and chooses to create a new identity. The user provides necessary user information (such as email, mobile phone number, etc.), and the decentralized identity management platform verifies it through encryption, but does not require the user to provide any centrally stored personal information.

[0034] After verification, a key pair is generated for the user, and a decentralized identity identifier is generated through the public key and registered on the blockchain. Specifically, after verification, an encrypted key pair (public key and private key) is generated for the user, where the private key is stored on the user's device and is not public; the public key is used to generate a unique DID and is publicly registered on the blockchain.

[0035] It should be noted that DID generation uses public and standardized algorithms (such as key pairs generated based on RSA, ECDSA and other algorithms). The platform uses the user's public key to generate the DID identifier.

[0036] DID identifiers follow a standard format, specifically: did: <method> : <id>.in, <method>Specify the blockchain or distributed network (such as Ethereum, Hyperledger, etc.) to which the DID belongs. <id>It is the unique identifier part, usually generated by the public key.

[0037] Example: did:ethr:0x123abc456def..., which indicates a DID based on the Ethereum network.

[0038] It can be seen that in this step, the user generates a unique DID through the decentralized identity management platform, and the DID is registered and stored on the blockchain as a digital representation of the user's identity. Among them, the DID is generated by the blockchain platform or distributed network, and an encryption algorithm is used to ensure the uniqueness and security of the DID. Each DID is associated with a public key and a private key pair, and the user manages and verifies his or her identity through the key pair. The DID document contains the DID identifier, the user's public key information, the authentication service endpoint, and other metadata. All information is encrypted and stored on the blockchain to ensure its immutability and transparency.

[0039] S2: The identity provider generates and issues identity credentials for the corresponding users based on the decentralized identity identifier, and encrypts and stores them and shares them.

[0040] In a specific implementation, first, a credential application request is initiated to an identity provider through a decentralized identity management platform; the credential application request includes a decentralized identity identifier and user information verified by blockchain. For example, a user initiates a credential application request through a decentralized identity management platform (e.g., uPort, Sovrin, etc.), and chooses to apply for a specific identity credential (e.g., academic certificate, identity certificate, etc.) from an identity provider (e.g., university, government agency, etc.). The user proves that his DID (decentralized identity identifier) ​​is valid through blockchain or encryption, and provides the necessary identity information (e.g., name, academic qualification, certificate number, etc.) to the identity provider. This information is usually transmitted in encrypted form to ensure privacy protection.

[0041] The identity provider then verifies the user information through the relevant database or institutional data. Once the verification is successful, it generates and issues an identity certificate and signs the identity certificate with a private key; the identity certificate includes identity information and related attributes. For example, the identity provider verifies the authenticity of the user information. Once the user's identity information is verified, the identity provider confirms the correctness of the information and prepares to issue the certificate. For example, if a user applies for an academic certificate, the identity provider needs to verify whether the user has actually completed his studies at the institution. The identity provider can verify the user information by accessing its internal database or by exchanging data with other trusted institutions.

[0042] Finally, the identity credentials are stored on the blockchain. The identity credentials are encrypted and stored through blockchain technology, and users can choose to store the credentials in a decentralized digital wallet. Users control when, how, and with whom to share their credential information through smart contracts, ensuring privacy while meeting authentication requirements.

[0043] S3: When a user attempts to log in or access an online service, he submits a decentralized identity identifier and related identity credentials to the service provider, and the service provider verifies the validity of the identity credentials through smart contracts and blockchain.

[0044] In this step, when the user needs to authenticate their identity, the service provider verifies the validity of the credentials and identity information provided by the user through the blockchain smart contract. The service provider verifies the authenticity and integrity of the credentials by consulting the public key and credential signature on the blockchain.

[0045] Specifically, first, the service provider parses the DID identifier submitted by the user through a smart contract or by querying the distributed ledger on the blockchain. Then, based on the DID identifier, the corresponding DID document is queried. The DID document contains information such as the user's public key and the authentication service endpoint, which is used to verify whether the signature in the request is valid.

[0046] At this time, the public key is obtained based on the DID document to verify the validity of the signature of the identity credential; if the validity of the signature is verified, the user information is obtained based on the identity credential, the user information is verified according to the preset verification rules, and whether the user credential has expired is determined by the validity period of the identity credential; if the user information meets the preset verification rules and the user credential has not expired, the identity credential is valid.

[0047] It should be noted that the verification of identity credentials includes credential signature verification, credential content verification and credential validity period verification. The specific verification process is as follows: Credential signature verification: The service provider verifies whether the credential is signed by the identity provider (such as a school, bank, etc.). By using the public key of the trusted party to verify the validity of the credential signature, it ensures that the credential has not been forged or tampered with.

[0048] Credential content verification: The service provider checks whether the information in the credential (such as user name, education level, etc.) complies with the predetermined verification rules (for example, verifying whether the education level meets the requirements, whether the age meets the standards, etc.) based on the content in the credential.

[0049] Credential validity period: Verify whether the validity period of the credential has expired and ensure that the credential is used within the valid time range.

[0050] In addition, in this step, if the service provider requires privacy protection, zero-knowledge proof (ZKP) verification can also be used. Zero-knowledge proof (ZKP) is used to prove its identity attributes (for example, proving that the age is over 18 years old), without providing complete personal information or viewing the user's sensitive information.

[0051] As an example, in this step, according to the conditions set by the smart contract, the service provider automatically performs identity authentication and grants or denies access rights. The specific implementation process is as follows: 1. When a user accesses a service (such as an e-commerce platform, banking system, etc.), he or she chooses to use decentralized identity authentication and submits his or her DID or verifiable credentials.

[0052] 2. The service provider verifies whether the DID provided by the user is valid and whether the signature of the credential is legal. After the verification is passed, the user's identity is confirmed.

[0053] 3. The service provider or other trusted institution issues the user's identity certificate (such as academic certificate, professional qualification certification, age certificate, etc.). The identity certificate contains the user's identity information (such as name, education, age, etc.) and ensures its authenticity through signature. The identity certificate will be stored in the user's decentralized identity wallet, and the user can choose to share the certificate in specific scenarios.

[0054] S4: After verification, the service provider confirms the user's identity and grants access rights to the user.

[0055] S5: The verification and usage information of identity credentials is recorded in the audit log and stored encrypted via blockchain.

[0056] In a specific implementation, first, the recording of the audit log is triggered by a smart contract to record the verification and use information of the identity credential in the audit log; the verification and use information of the identity credential includes: the issuance, revocation, permission granting and verification failure information of the identity credential. For example, the recording of the audit log is triggered by using the automation function of the smart contract and the decentralized identity authentication system. For example, each time a user passes the identity authentication or authorization operation, the system automatically generates an audit log and records the relevant information. Among them, all key events (such as credential issuance, revocation, permission granting, identity authentication failure, etc.) will be recorded on the blockchain.

[0057] Then, the user information in the audit log is encrypted and the encrypted information is set to be visible only to authorized parties. For example, sensitive data in the audit log is encrypted to ensure that user privacy is protected. The encrypted and stored sensitive data is visible only to authorized parties. In addition, zero-knowledge proof (ZKP) technology can be used to record only necessary audit information (such as verification results) without exposing the user's complete credential information or sensitive data.

[0058] Finally, the audit log is submitted to the blockchain network for encrypted storage through smart contracts or decentralized applications. For example, the audit log is submitted to the blockchain network through smart contracts or decentralized applications (DApp). The immutable nature of the blockchain ensures that all audit records cannot be changed once written. The integrity of the audit records can be ensured through the hash value on the blockchain, and the audit log can be indexed and queried through a suitable query interface (such as a blockchain-based query tool or a decentralized database).

[0059] S6: Archive and back up audit logs regularly.

[0060] In the specific implementation, during the log storage process, considering the limitation of blockchain storage space, the detailed contents of the audit log can be archived through external storage services (such as IPFS, Arweave, etc.) to ensure that the log can be stored for a long time and remain accessible. At the same time, the audit log is backed up regularly to ensure that the log data will not be lost and to ensure the feasibility of the disaster recovery plan.

[0061] The purpose of this invention is to provide a decentralized identity authentication method, which aims to overcome many problems in existing centralized identity authentication systems, especially in terms of privacy protection, security, data control and trust dependence. Specifically, the purpose of this method is to provide a more secure, efficient and user-sovereign identity authentication solution through improvements in the following aspects: 1. Enhanced privacy protection: Through decentralized identity management, users can fully control the storage and use of their identity data to prevent personal sensitive information from being abused or leaked by third parties. Users can selectively share personal information as needed and only authorize trusted parties to access relevant data, which greatly enhances privacy protection.

[0062] 2. Improve the security of identity authentication: The immutability and distributed ledger characteristics of blockchain technology ensure the security of identity data. In the decentralized identity authentication method, the identity authentication process does not need to rely on a single centralized institution, thereby reducing the risk of identity data being tampered with, stolen or leaked. The use of smart contract technology can automatically verify identity and perform corresponding authorization to ensure the accuracy and reliability of identity authentication.

[0063] 3. Reduce reliance on third-party trust: Traditional identity authentication relies on central agencies or third-party service providers to verify and store user identity information. The present invention adopts a decentralized identity authentication method based on blockchain, eliminating the reliance on a single trusted agency, de-trusting the verification process, ensuring the credibility of identity authentication through the consensus mechanism and smart contracts of blockchain, and reducing the risk of third-party abuse of authority.

[0064] 4. Simplify identity management and cross-platform authentication: This invention uses decentralized identity identifiers (DID) and verifiable credentials (VC) technology to enable users to easily authenticate their identities across different platforms and services. Users do not need to frequently create and manage multiple identity accounts, which avoids redundancy and inconvenience in the multi-authentication process and improves user experience.

[0065] 5. Improve data control and transparency: Users have full control over their own data in the blockchain-based identity authentication system. All identity data sharing and authorization are automatically executed through smart contracts, ensuring the transparency and traceability of the data usage process. Users can view and manage data access records at any time to ensure data security and compliance.

[0066] Through these innovations, the present invention aims to provide a decentralized, transparent, secure and easy-to-use decentralized identity authentication method to solve the problems of privacy protection, security, trust dependence and management efficiency in the prior art, and promote the widespread application of digital identity authentication in multiple fields (such as finance, social networking, e-commerce, medical care, etc.).

[0067] like Figure 2 As shown, the following is an embodiment of the decentralized identity authentication system provided by the embodiment of the present disclosure. The system and the decentralized identity authentication methods of the above-mentioned embodiments belong to the same inventive concept. For details not described in detail in the embodiment of the decentralized identity authentication system, please refer to the embodiment of the above-mentioned decentralized identity authentication method.

[0068] A decentralized identity authentication system includes: a DID creation and registration module 1, an identity credential issuance module 2, an identity authentication module 3, an authorization module 4, a data recording module 5 and a backup module 6.

[0069] DID creation and registration module 1 is used to register and generate a decentralized identity identifier on the blockchain based on user information as a digital representation of the user's identity.

[0070] The identity credential issuance module 2 is used to generate and issue identity credentials for corresponding users based on the decentralized identity identifier through the identity provider, and encrypt and store and share them through the blockchain.

[0071] The identity authentication module 3 is used to submit a decentralized identity identifier and related identity credentials to the service provider when the user attempts to log in or access an online service. The service provider verifies the validity of the identity credentials through smart contracts and blockchain.

[0072] Authorization module 4 is used to confirm the user's identity and grant access rights to the user after the verification is passed by the service provider.

[0073] The data recording module 5 is used to record the verification and usage information of the identity credentials in the audit log and store them in encrypted form through the blockchain.

[0074] The backup module 6 is used to regularly archive and back up the audit logs.

[0075] The decentralized identity authentication method system provided in this embodiment ensures the security and privacy of user identities through blockchain technology, realizes effective verification and sharing of identity credentials, and enhances system transparency and traceability. It improves the security and reliability of the overall authentication process through encrypted storage and regular archiving and backup of audit logs. This system significantly improves the security and autonomy of identity management, removes the dependence on centralized institutions through blockchain technology, realizes distributed verification and storage of identity credentials, enhances users' control over their identity information, and ensures the transparency and non-tamperability of the verification process.

[0076] Figure 3 A schematic diagram of the hardware structure of an electronic device for implementing various embodiments of the present invention.

[0077] The decentralized identity authentication method provided in the embodiment of the present application can be applied to electronic devices. It will be appreciated by those skilled in the art that the electronic device structure involved in the embodiment of the present invention does not constitute a limitation on the electronic device, and the electronic device may include more or less components than shown, or combine certain components, or arrange different components. In an embodiment of the present invention, the electronic device includes but is not limited to a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples, and are not intended to limit the implementation of the embodiments of the present application described and / or required herein.

[0078] The electronic device may include a processor, an external memory interface, an internal memory, a universal serial bus (USB) interface, a charging management module, a power management module, a battery, a wireless communication module, an audio module, a speaker, a microphone, a sensor module, buttons, a camera, a display, and a SIM card interface, etc.

[0079] The processor may include one or more processing units, for example, the processor may include a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated into one or more processors.

[0080] The processor can be the nerve center and command center of the electronic device. The controller can generate an operation control signal according to the instruction operation code and timing signal to complete the control of fetching and executing instructions.

[0081] A memory may also be provided in the processor for storing instructions and data. In some embodiments, the memory in the processor is a cache memory. The memory may store instructions or data that the processor has just used or is cyclically used. If the processor needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor, and thus improves system efficiency.

[0082] The external memory interface can be used to connect an external memory card, such as a MicroSD card, to expand the storage capacity of the electronic device. The external memory card communicates with the processor through the external memory interface to implement data storage functions. For example, files such as music and videos can be saved in the external memory card.

[0083] The internal memory can be used to store computer executable program codes, which include instructions. The processor executes various functional applications and data processing of the electronic device by running the instructions stored in the internal memory. The internal memory may include a program storage area and a data storage area. The internal memory may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0084] The wireless communication function of an electronic device can be realized through an antenna, a wireless communication module, a modem processor, and a baseband processor.

[0085] The wireless communication module can provide wireless communication solutions for electronic devices, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc.

[0086] Electronic devices can implement audio functions, etc. through audio modules, speakers, receivers, microphones, headphone jacks, and application processors.

[0087] Electronic devices can achieve shooting functions through ISP, camera, video codec, GPU, display and application processor.

[0088] Electronic devices can achieve display functions through GPU, display screen and application processor.

[0089] The GPU is a microprocessor for image processing that connects the display screen and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor may include one or more GPUs that execute program instructions to generate or change display information.

[0090] The display screen is used to display images, videos, etc. The display screen includes a display panel.

[0091] The above-mentioned electronic device implements the decentralized identity authentication method of the present application, realizes the distributed storage and verification of user identity through blockchain technology, effectively avoids the single point failure and security risks of centralized institutions, ensures that users have full control over their own identities, and achieves the beneficial effects of transparency, traceability and non-tamperability of identity information.

[0092] The storage medium provided in the present application stores a program product that can implement a decentralized identity authentication method.

[0093] The decentralized identity authentication method includes: based on user information, registering and generating a decentralized identity identifier on the blockchain as a digital representation of the user's identity; generating and issuing identity credentials for the corresponding user based on the decentralized identity identifier through an identity provider, and encrypting and storing and sharing them; when a user attempts to log in or access an online service, the decentralized identity identifier and related identity credentials are submitted to the service provider, and the service provider verifies the validity of the identity credentials through smart contracts and blockchain; after the verification is passed, the service provider confirms the user's identity and grants access rights to the user; the verification and use information of the identity credentials is recorded in the audit log and encrypted and stored through the blockchain; the audit log is archived and backed up regularly.

[0094] In some possible implementations, the decentralized identity authentication method of the present disclosure may be implemented in the form of a program product, which includes a program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps of various exemplary implementations of the present disclosure described in the above “Exemplary Methods” section of this specification.

[0095] The storage medium of the present disclosure can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, a system, device or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0096] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.< / id> < / method> < / id> < / method>

Claims

1. A decentralized identity authentication method, characterized in that: include: Based on user information, a decentralized identity identifier is registered and generated on the blockchain as a digital representation of the user's identity; The identity provider generates and issues identity credentials for the corresponding users based on the decentralized identity identifier, and performs encrypted storage and sharing; When a user attempts to log in or access an online service, they submit a decentralized identity identifier and related identity credentials to the service provider, who verifies the validity of the identity credentials through smart contracts and blockchain; After verification, the service provider confirms the user's identity and grants access rights to the user; Record the verification and use of identity credentials in the audit log and store them encrypted on the blockchain; Archive and back up audit logs regularly.

2. The decentralized identity authentication method according to claim 1, characterized in that: Based on the user information, a decentralized identity identifier is registered and generated on the blockchain as a digital representation of the user's identity, including: Create user identities through a centralized identity management platform and verify user information through encryption algorithms; After verification, a key pair is generated for the user, a decentralized identity identifier is generated through the public key, and registered on the blockchain.

3. The decentralized identity authentication method according to claim 1, characterized in that: The identity provider generates and issues identity credentials for the corresponding user based on the decentralized identity identifier, and encrypts and stores and shares them through the blockchain, including: Initiate a credential application request to an identity provider through a decentralized identity management platform; the credential application request includes a decentralized identity identifier and user information verified by a blockchain; The identity provider verifies the user information through the relevant database or institutional data. After the verification is passed, it generates and issues an identity certificate and signs the identity certificate with a private key; the identity certificate includes identity information and related attributes; Store identity credentials on the blockchain.

4. The decentralized identity authentication method according to claim 3, characterized in that: The service provider verifies the validity of the identity credential through smart contracts and blockchain, including: The service provider resolves the DID identifier submitted by the user through smart contracts or by querying the distributed ledger on the blockchain; According to the DID identifier, query the corresponding DID document; Obtaining the public key based on the DID document to verify the validity of the signature of the identity credential; If the validity verification of the signature passes, the user information is obtained based on the identity credential, the user information is verified according to the preset verification rules, and the validity period of the identity credential is used to determine whether the user credential has expired; If the user information meets the preset verification rules and the user credentials have not expired, the identity credentials are valid.

5. The decentralized identity authentication method according to claim 4, characterized in that: The preset verification rule adopts zero-knowledge proof.

6. The decentralized identity authentication method according to claim 4, characterized in that: The verification and use information of the identity credentials is recorded in the audit log and encrypted and stored through the blockchain, including: Triggering the recording of audit logs through smart contracts to record the verification and use information of identity credentials in the audit logs; the verification and use information of identity credentials includes: issuance, revocation, authorization and verification failure information of identity credentials; Encrypt user information in the audit log and set the encrypted information to be visible only to authorized parties; Through smart contracts or decentralized applications, audit logs are submitted to the blockchain network for encrypted storage.

7. The decentralized identity authentication method according to claim 6, characterized in that: The periodic archiving and backing up of audit logs includes: Regularly archive and back up audit logs through external storage services; The external storage services include but are not limited to the Interplanetary File System and the Arweave network.

8. A decentralized identity authentication system, characterized in that: The system adopts the decentralized identity authentication method as described in any one of claims 1 to 7; The system comprises: DID creation and registration module, which is used to register and generate a decentralized identity identifier on the blockchain based on user information as a digital representation of the user's identity; The identity credential issuance module is used to generate and issue identity credentials for corresponding users based on decentralized identity identifiers through identity providers, and encrypt and store and share them through blockchain; The identity verification module is used to submit a decentralized identity identifier and related identity credentials to the service provider when the user attempts to log in or access an online service. The service provider verifies the validity of the identity credentials through smart contracts and blockchain; Authorization module, which is used by the service provider to confirm the user's identity and grant access rights to the user after verification; A data logging module is used to record the verification and use information of identity credentials in the audit log and store it encrypted through the blockchain; The backup module is used to archive and back up audit logs regularly.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the decentralized identity authentication method as described in any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the decentralized identity authentication method as described in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Cross-data-space distributed identity authentication system and method and electronic equipment

    CN120834945A

  • Large model authentication and authorization system and method based on remote networking

    CN120915601A

  • Large model authentication and authorization system and method based on remote networking

    CN120915601B

  • Decentralized identity strong binding and security recovery method and system

    CN121333825A

  • Decentralized identity strong binding and security recovery method and system

    CN121333825B