Method and system for accessing DID system based on DID
By obtaining and verifying user identity data in the DID system, creating DID identifiers and generating identity credentials, the problem of difficult user identity mutual recognition across systems in the prior art is solved, and efficient and secure identity authentication and access are achieved.
Patent Information
- Application Number
- CN202411951254.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-13
AI Technical Summary
Existing online service platforms are difficult to achieve cross-system mutual recognition of user identities, which leads to users need to remember multiple account passwords and pose a risk of personal data consistency and privacy leakage.
In the decentralized identification DID system, the user's identity data is obtained for verification, the DID identifier is created, and the identity data is forwarded to a trusted three-party organization to generate identity credentials, and the DID identifier is associated to achieve cross-system identity authentication.
It realizes cross-system mutual recognition of user identities, improves user access efficiency, reduces the risk of personal information leakage, and enhances the authenticity and consistency of identity data.
Smart Images

Figure CN119995890A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of identity authentication technology, and more specifically, to a method and system for accessing a DID system based on a DID identifier. Background Art
[0002] Currently, many online service platforms require users to provide personal identity data to register an account. However, these accounts can often only be used within the scope of their respective services, resulting in users having to remember multiple account passwords and difficulty ensuring the consistency of personal data. In addition, the centralized storage of data also increases the risk of privacy leakage. Therefore, it is particularly necessary to explore a method that can achieve identity mutual recognition across different systems. Summary of the invention
[0003] In view of the above problems, the present invention proposes a method for accessing a DID system based on a DID identifier, comprising:
[0004] When a user accesses the decentralized identification DID system for the first time, the user's identity data is obtained based on the DID system, and the identity data is verified to determine the authenticity of the identity data. If the identity data is determined to be true, a DID is created for the user based on the identity data;
[0005] Based on the DID system, the user's identity data is forwarded to a trusted third-party organization, and the third-party organization generates the user's identity credential based on the identity data, and associates the DID identifier with the identity credential;
[0006] Based on the DID system, the DID identifier and identity credential are issued to the user, and the DID identifier is issued to the cross-system DID system;
[0007] When the user accesses the DID system again or accesses a cross-system DID system, the DID system or the cross-system DID system obtains the user's DID identifier to verify the identity of the user. If the verification is qualified, the user's identity credentials are obtained, and the user is authenticated based on the identity credentials. After the authentication is passed, the user is allowed to access.
[0008] Optionally, the DID system obtains the user's identity data, including:
[0009] The user's ID data or entered identity data.
[0010] The entered identity data includes: name and identity document number;
[0011] If the user's identity data is the user's identification document data, the identification document data is identified based on the DID system to extract the name and identification document number in the identification document data.
[0012] Optionally, verifying the identity data to determine the authenticity of the identity data includes:
[0013] Through the DID system, the user's facial image information is collected to determine whether the identity data is consistent with the facial image information. If they are consistent, the identity data is true, otherwise it is false.
[0014] Optional, trusted third-party institutions, including: trusted certification authorities and banking institutions.
[0015] Optionally, the DID created for the user and the identity credential generated for the user are both unique.
[0016] Optionally, the user's identity credentials, including: decentralized identity data;
[0017] The decentralized identity data includes: name and age.
[0018] Optionally, the method further includes: building a DID system network;
[0019] Allow users to access the DID system in the DID system network through unique identification and identity credentials.
[0020] Optionally, the method further includes:
[0021] The user's identity credentials are entrusted to a trusted escrow institution. When the user accesses the DID system, the user retrieves the identity credentials through the trusted escrow institution, or the user grants a time-limited authorization to the DID system, and within the time limit, the DID system retrieves the identity credentials through the trusted escrow institution.
[0022] Optional: User identity certificate, which is time-sensitive and signed by a trusted third-party organization;
[0023] When the user's identity certificate becomes invalid, it is necessary to apply for a new identity certificate.
[0024] On the other hand, the present invention also proposes a system for accessing a DID system based on a DID identifier, comprising:
[0025] An identity creation unit, used for obtaining the identity data of the user based on the DID system when the user first accesses the decentralized identification DID system, and verifying the identity data to determine the authenticity of the identity data. If the identity data is determined to be true, a DID identifier is created for the user based on the identity data;
[0026] A credential creation unit, configured to forward the identity data of the user to a trusted third-party institution based on the DID system, generate the identity credential of the user based on the identity data by the third-party institution, associate the DID identifier and the identity credential, issue the DID identifier and the identity credential to the user based on the DID system, and issue the DID identifier to a cross-system DID system;
[0027] The authentication unit is used for when the user accesses the DID system again or accesses a cross-system DID system, the DID system or the DID system accessing the cross-system obtains the DID identifier of the user to verify the identity of the user, and if the verification is qualified, obtains the user's identity credentials, authenticates the user based on the identity credentials, and allows the user to access after the authentication is passed.
[0028] Optionally, the DID system obtains the user's identity data, including:
[0029] The user's ID data or entered identity data.
[0030] The entered identity data includes: name and identity document number;
[0031] If the user's identity data is the user's identification document data, the identification document data is identified based on the DID system to extract the name and identification document number in the identification document data.
[0032] Optionally, verifying the identity data to determine the authenticity of the identity data includes:
[0033] Through the DID system, the user's facial image information is collected to determine whether the identity data is consistent with the facial image information. If they are consistent, the identity data is true, otherwise it is false.
[0034] Optional, trusted third-party institutions, including: trusted certification authorities and banking institutions.
[0035] Optionally, the DID created for the user and the identity credential generated for the user are both unique.
[0036] Optionally, the user's identity credentials, including: decentralized identity data;
[0037] The decentralized identity data includes: name and age.
[0038] Optionally, the authentication unit is also used to: build a DID system network;
[0039] Allow users to access the DID system in the DID system network through unique identification and identity credentials.
[0040] Optionally, the credential creation unit is further configured to:
[0041] The user's identity credentials are entrusted to a trusted escrow institution. When the user accesses the DID system, the user retrieves the identity credentials through the trusted escrow institution, or the user grants a time-limited authorization to the DID system, and within the time limit, the DID system retrieves the identity credentials through the trusted escrow institution.
[0042] Optional: User identity certificate, which is time-sensitive and signed by a trusted third-party organization;
[0043] When the user's identity certificate becomes invalid, it is necessary to apply for a new identity certificate.
[0044] In yet another aspect, the present invention further provides a computing device, comprising: one or more processors;
[0045] a processor for executing one or more programs;
[0046] When the one or more programs are executed by the one or more processors, the above-described method is implemented.
[0047] In yet another aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed, the method described above is implemented.
[0048] Compared with the prior art, the present invention has the following beneficial effects:
[0049] The present invention provides a method for accessing a DID system based on a DID identifier, comprising: when a user accesses a decentralized identifier DID system for the first time, obtaining the identity data of the user based on the DID system, and verifying the identity data to determine the authenticity of the identity data, and if it is determined that the identity data is true, creating a DID identifier for the user based on the identity data; forwarding the identity data of the user to a trusted third-party organization based on the DID system, generating the user's identity credential based on the identity data by the third-party organization, and associating the DID identifier and the identity credential; issuing the DID identifier and the identity credential to the user based on the DID system, and issuing the DID identifier to a cross-system DID system; when the user accesses the DID system again or accesses a cross-system DID system, the DID system or the cross-system DID system verifies the identity of the user by obtaining the DID identifier of the user, and if the verification is qualified, obtaining the user's identity credential, and authenticating the user based on the identity credential, and allowing the user to access after the authentication is passed. The present invention has interoperability, that is, cross-system access can be performed after DID is established, which greatly improves the user's access efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 A flowchart of a method for accessing a DID system based on a DID identifier according to the present invention;
[0051] Figure 2 A flowchart of an embodiment of a method for accessing a DID system based on a DID identifier according to the present invention;
[0052] Figure 3 This is a structural diagram of a system for accessing a DID system based on a DID identifier according to the present invention. DETAILED DESCRIPTION
[0053] Now, exemplary embodiments of the present invention are described with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely and to fully convey the scope of the present invention to those skilled in the art. The terms used in the exemplary embodiments shown in the accompanying drawings are not intended to limit the present invention. In the accompanying drawings, the same units / elements are marked with the same reference numerals.
[0054] Unless otherwise specified, the terms (including technical terms) used herein have the commonly understood meanings to those skilled in the art. In addition, it is understood that the terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.
[0055] Embodiment 1:
[0056] The present invention proposes a method for accessing a DID system based on a DID identifier, such as Figure 1 As shown, including:
[0057] Step 1: When a user accesses the decentralized identification DID system for the first time, the user's identity data is obtained based on the DID system, and the identity data is verified to determine the authenticity of the identity data. If the identity data is determined to be true, a DID is created for the user based on the identity data;
[0058] Step 2: Based on the DID system, the user's identity data is forwarded to a trusted third-party organization. The third-party organization generates the user's identity certificate based on the identity data, and associates the DID identifier with the identity certificate.
[0059] Step 3: Based on the DID system, the DID identification and identity credentials are sent to the user, and the DID identification is sent to the cross-system DID system;
[0060] Step 4: When the user accesses the DID system again or accesses a cross-system DID system, the DID system or the cross-system DID system obtains the user's DID identifier to verify the identity of the user. If the verification is qualified, the user's identity credentials are obtained, and the user is authenticated based on the identity credentials. After the authentication is passed, the user is allowed to access.
[0061] Among them, the DID system obtains the user's identity data, including:
[0062] The user's ID data or entered identity data.
[0063] The entered identity data includes: name and identity document number;
[0064] If the user's identity data is the user's identification document data, the identification document data is identified based on the DID system to extract the name and identification document number in the identification document data.
[0065] The verification of the identity data to determine the authenticity of the identity data includes:
[0066] Through the DID system, the user's facial image information is collected to determine whether the identity data is consistent with the facial image information. If they are consistent, the identity data is true, otherwise it is false.
[0067] Among them, trusted third-party institutions include: trusted certification agencies and banking institutions.
[0068] Among them, the DID identifier created for the user and the identity credential generated for the user are both unique.
[0069] Among them, the user's identity credentials include: decentralized identity data;
[0070] The decentralized identity data includes: name and age.
[0071] The method further includes: building a DID system network;
[0072] Allow users to access the DID system in the DID system network through unique identification and identity credentials.
[0073] The method further includes:
[0074] The user's identity credentials are entrusted to a trusted escrow institution. When the user accesses the DID system, the user retrieves the identity credentials through the trusted escrow institution, or the user grants a time-limited authorization to the DID system, and within the time limit, the DID system retrieves the identity credentials through the trusted escrow institution.
[0075] Among them, the user's identity certificate is time-effective and signed by a trusted third-party organization;
[0076] When the user's identity certificate becomes invalid, it is necessary to apply for a new identity certificate.
[0077] The present invention will be further described below in conjunction with specific embodiments:
[0078] The process of the specific embodiment is as follows Figure 2 As shown, including:
[0079] Identity creation: Users can create their own DID in any system that supports DID, and the DID will serve as a unified identifier for the user in different systems.
[0080] Credential issuance: A trusted third-party organization (such as a government agency, bank, etc.) issues a credential containing the user’s basic information (such as name, age, etc.) and associates the credential with the user’s DID.
[0081] Storage and management of credentials: Users can store the received credentials in their own digital wallets or choose to host them with a trusted service provider.
[0082] Authentication: When users access other DID-supported systems, they can use their DID and related credentials to verify their identity.
[0083] Authentication process: The user provides his or her DID to the target system. The target system requests to view the credentials related to the DID to verify the user's identity. The user selects the specific credentials to be shared and authorizes the target system to access. The target system completes the identity confirmation by verifying the validity of the credentials.
[0084] The present invention has the following advantages:
[0085] Interoperability: The DID standard is developed by W3C, ensuring data format and compatibility between different systems.
[0086] Privacy protection: Users have full control over their own identity information and can selectively disclose information. There is no centralized data center, which effectively reduces the risk of personal information leakage.
[0087] Flexibility: Supports a variety of encryption algorithms and technology stacks, making it easy to integrate with existing IT infrastructure.
[0088] Scalability: Easy to integrate with other blockchain technologies or non-blockchain technologies to support future functional enhancements.
[0089] Embodiment 2:
[0090] The present invention also proposes a system 200 for accessing a DID system based on a DID identifier, such as Figure 3 As shown, including:
[0091] The identity creation unit 201 is used to obtain the identity data of the user based on the DID system when the user first accesses the decentralized identification DID system, and verify the identity data to determine the authenticity of the identity data. If the identity data is determined to be true, a DID identifier is created for the user based on the identity data;
[0092] A credential creation unit 202 is used to forward the identity data of the user to a trusted third-party institution based on the DID system, generate an identity credential of the user based on the identity data by the third-party institution, associate the DID identifier and the identity credential, issue the DID identifier and the identity credential to the user based on the DID system, and issue the DID identifier to a cross-system DID system;
[0093] The authentication unit 203 is used for, when the user accesses the DID system again or accesses a cross-system DID system, the DID system or the DID system accessing the cross-system obtains the DID identifier of the user to verify the identity of the user, and if the verification is qualified, obtains the identity credential of the user, authenticates the user based on the identity credential, and allows the user to access after the authentication is passed.
[0094] Among them, the DID system obtains the user's identity data, including:
[0095] The user's ID data or entered identity data.
[0096] The entered identity data includes: name and identity document number;
[0097] If the user's identity data is the user's identification document data, the identification document data is identified based on the DID system to extract the name and identification document number in the identification document data.
[0098] The verification of the identity data to determine the authenticity of the identity data includes:
[0099] Through the DID system, the user's facial image information is collected to determine whether the identity data is consistent with the facial image information. If they are consistent, the identity data is true, otherwise it is false.
[0100] Among them, trusted third-party institutions include: trusted certification agencies and banking institutions.
[0101] Among them, the DID identifier created for the user and the identity credential generated for the user are both unique.
[0102] Among them, the user's identity credentials include: decentralized identity data;
[0103] The decentralized identity data includes: name and age.
[0104] The authentication unit 203 is also used to: construct a DID system network;
[0105] Allow users to access the DID system in the DID system network through unique identification and identity credentials.
[0106] The credential creation unit 202 is further used for:
[0107] The user's identity credentials are entrusted to a trusted escrow institution. When the user accesses the DID system, the user retrieves the identity credentials through the trusted escrow institution, or the user grants a time-limited authorization to the DID system, and within the time limit, the DID system retrieves the identity credentials through the trusted escrow institution.
[0108] Among them, the user's identity certificate is time-effective and signed by a trusted third-party organization;
[0109] When the user's identity certificate becomes invalid, it is necessary to apply for a new identity certificate.
[0110] The present invention has interoperability, that is, cross-system access can be performed after DID is established, which greatly improves the user's access efficiency.
[0111] Embodiment 3:
[0112] Based on the same inventive concept, the present invention also provides a computer device, which includes a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, and is specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding functions, so as to implement the steps of the method in the above embodiment.
[0113] Embodiment 4:
[0114] Based on the same inventive concept, the present invention also provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It is understandable that the computer-readable storage medium here can include both a built-in storage medium in a computer device and an extended storage medium supported by the computer device. The computer-readable storage medium provides a storage space, which stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by a processor are also stored in the storage space, and these instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the steps of the method in the above embodiment.
[0115] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes. The schemes in the embodiments of the present invention may be implemented in various computer languages, for example, object-oriented programming language Java and literal scripting language JavaScript, etc.
[0116] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0117] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0118] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0119] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0120] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A method for accessing a DID system based on a DID identifier, characterized in that: The method comprises: When a user accesses the decentralized identification DID system for the first time, the user's identity data is obtained based on the DID system, and the identity data is verified to determine the authenticity of the identity data. If the identity data is determined to be true, a DID is created for the user based on the identity data; Based on the DID system, the user's identity data is forwarded to a trusted third-party organization, and the third-party organization generates the user's identity credential based on the identity data, and associates the DID identifier with the identity credential; Based on the DID system, the DID identifier and identity credential are issued to the user, and the DID identifier is issued to the cross-system DID system; When the user accesses the DID system again or accesses a cross-system DID system, the DID system or the cross-system DID system obtains the user's DID identifier to verify the identity of the user. If the verification is qualified, the user's identity credentials are obtained, and the user is authenticated based on the identity credentials. After the authentication is passed, the user is allowed to access.
2. The method according to claim 1, characterized in that The DID system obtains the user's identity data, including: The user's ID data or entered identity data. The entered identity data includes: name and identity document number; If the user's identity data is the user's identification document data, the identification document data is identified based on the DID system to extract the name and identification document number in the identification document data.
3. The method according to claim 1, characterized in that The verifying the identity data to determine the authenticity of the identity data includes: Through the DID system, the user's facial image information is collected to determine whether the identity data is consistent with the facial image information. If they are consistent, the identity data is true, otherwise it is false.
4. The method according to claim 1, characterized in that: The trusted third-party institutions include: trusted certification institutions and banking institutions.
5. The method according to claim 1, characterized in that The DID identifier created for the user and the identity credential generated for the user are both unique.
6. The method according to claim 1, characterized in that The user's identity credentials include: decentralized identity data; The decentralized identity data includes: name and age.
7. The method according to claim 1, characterized in that The method further includes: constructing a DID system network; Allow users to access the DID system in the DID system network through unique identification and identity credentials.
8. A system for accessing a DID system based on a DID identifier, characterized in that: The system comprises: An identity creation unit, used for obtaining the identity data of the user based on the DID system when the user first accesses the decentralized identification DID system, and verifying the identity data to determine the authenticity of the identity data. If the identity data is determined to be true, a DID identifier is created for the user based on the identity data; A credential creation unit, configured to forward the identity data of the user to a trusted third-party institution based on the DID system, generate the identity credential of the user based on the identity data by the third-party institution, associate the DID identifier and the identity credential, issue the DID identifier and the identity credential to the user based on the DID system, and issue the DID identifier to a cross-system DID system; The authentication unit is used for when the user accesses the DID system again or accesses a cross-system DID system, the DID system or the DID system accessing the cross-system obtains the DID identifier of the user to verify the identity of the user, and if the verification is qualified, obtains the user's identity credentials, authenticates the user based on the identity credentials, and allows the user to access after the authentication is passed.
9. A computer device, characterized in that: include: one or more processors; a processor for executing one or more programs; When the one or more programs are executed by the one or more processors, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
System and method for mapping decentration identifies to real entities
CN116910726A