Identity authentication method and device based on block chain, storage medium and electronic equipment
By configuring multiple identity authentication subservices for the blockchain system and providing different information authentication methods, the problem of inflexible identity authentication methods based on blockchain is solved, and higher flexibility and adaptability are achieved.
Patent Information
- Application Number
- CN202311594552.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-27
AI Technical Summary
The blockchain-based identity authentication method is not flexible enough to support users to choose different authentication methods.
The blockchain identity information is authenticated by configuring at least two identity authentication subservices for the blockchain system and providing different information authentication methods by these subservices.
It realizes the support of users to choose different authentication methods in the blockchain environment, and improves the flexibility of blockchain-based identity authentication.
Smart Images

Figure CN120046130A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computers, and more specifically, to a blockchain-based identity authentication method, device, storage medium, and electronic device. Background Art
[0002] In the blockchain-based identity authentication scenario, the blockchain system will verify the user's identity. Only when the verification is passed can the user's request (or transaction) be processed. However, the blockchain system can usually only select one identity authentication method, and does not support users to select different identity authentication methods to complete identity authentication, which leads to the problem that the blockchain-based identity authentication method is not flexible enough. Therefore, there is a problem that the blockchain-based identity authentication method is not flexible enough.
[0003] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0004] The embodiments of the present application provide a blockchain-based identity authentication method, device, storage medium, and electronic device to at least solve the technical problem that the blockchain-based identity authentication method is not flexible enough.
[0005] According to one aspect of an embodiment of the present application, a blockchain-based identity authentication method is provided, comprising: obtaining an identity authentication request triggered on a blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, the identity authentication request is used to request the use of the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information; in response to the identity authentication request, determining a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include the first authentication sub-service and at least one second authentication sub-service, and the information authentication method of the first authentication sub-service is different from the information authentication method of the second authentication sub-service; using the information authentication method of the first authentication sub-service to authenticate the blockchain identity information, and obtain an identity authentication result, wherein the identity authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
[0006] According to another aspect of an embodiment of the present application, a blockchain-based identity authentication device is also provided, including: an acquisition unit, used to acquire an identity authentication request triggered on a blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request the use of the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information; a determination unit, used to respond to the identity authentication request, and determine a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include the first authentication sub-service and at least one second authentication sub-service, and the information authentication method of the first authentication sub-service is different from the information authentication method of the second authentication sub-service; a verification unit, used to use the information authentication method of the first authentication sub-service to authenticate the blockchain identity information and obtain an identity authentication result, wherein the identity authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
[0007] As an optional scheme, the above-mentioned determination unit includes: a first determination module, used to determine the sub-service information that matches the above-mentioned identity authentication sub-service identifier from a pre-configured sub-service information set, wherein the above-mentioned sub-service information includes a sub-service address identifier and the above-mentioned service public key; a second determination module, used to determine the authentication sub-service that matches the above-mentioned sub-service address identifier from the above-mentioned at least two identity authentication sub-services, and use the authentication sub-service that matches the above-mentioned sub-service address identifier as the above-mentioned first authentication sub-service; the above-mentioned verification unit includes: an encryption module, used to encrypt the above-mentioned blockchain identity information using the above-mentioned service public key, and send the encrypted blockchain identity information to the above-mentioned first authentication sub-service, which performs decryption and identity authentication to obtain the above-mentioned identity authentication result.
[0008] As an optional solution, the above-mentioned device also includes: a deployment module, which is used to deploy the above-mentioned at least two identity authentication sub-services for the above-mentioned blockchain system before the above-mentioned acquisition of the identity authentication request triggered by the blockchain system, and set the above-mentioned at least two identity authentication sub-services to replace the identity authentication module to perform the identity authentication of the above-mentioned blockchain system, wherein the above-mentioned blockchain system includes the above-mentioned identity authentication module, the information authentication method of the above-mentioned identity authentication module is the information authentication method supported by the above-mentioned blockchain system, and the information authentication method of the above-mentioned at least two identity authentication sub-services includes the information authentication method of the above-mentioned identity authentication module.
[0009] As an optional solution, the above-mentioned device also includes: a first acquisition module, which is used to obtain the above-mentioned sub-service information set sent by the blockchain client before determining the sub-service information matching the above-mentioned identity authentication sub-service identifier from the pre-configured sub-service information set, wherein the above-mentioned blockchain client is used to establish a data transmission channel between the above-mentioned blockchain system and the above-mentioned at least two identity authentication sub-services; the above-mentioned encryption module includes: a sending sub-module, which is used to send the above-mentioned encrypted blockchain identity information to the above-mentioned first authentication sub-service through the above-mentioned data transmission channel.
[0010] As an optional solution, the encryption module includes: a reverse deduction submodule, which is used for the first authentication subservice to perform reverse calculation on the subservice address identifier to obtain the identity authentication result, wherein the identity authentication result is obtained by calculating the subservice address identifier.
[0011] As an optional solution, the above-mentioned acquisition unit includes: a second acquisition module, used to obtain the above-mentioned identity authentication request when the user account requests to conduct a transaction with the above-mentioned blockchain system, wherein the above-mentioned identity authentication sub-service identifier is used to indicate the information authentication method used by the above-mentioned user account when registering the identity in the above-mentioned blockchain system, and the above-mentioned blockchain identity information is used to prove that the identity obtained by the above-mentioned user account registered in the above-mentioned blockchain system is legal.
[0012] As an optional solution, the second acquisition module includes: an acquisition submodule, used to obtain the identity authentication request, and the transaction data structure carried by the identity authentication request, the identity authentication information includes the transaction data structure, the transaction data structure is used to present the transaction between the user account request and the blockchain system, the transaction data structure includes a transaction body and a transaction signature, the transaction body includes the identity authentication sub-service identifier, the blockchain identity information includes the transaction signature, and the transaction signature is identity information generated by the user account using a private key based on a cryptographic algorithm for the transaction body.
[0013] As an optional scheme, the above-mentioned determination unit includes at least one of the following: a third determination module, used to determine the public key identity authentication sub-service from the above-mentioned at least two identity authentication sub-services when the above-mentioned identity authentication sub-service identifier indicates the use of registration authentication method, wherein the above-mentioned public key identity authentication sub-service is used to verify the blockchain identity information obtained based on user registration; a fourth determination module, used to determine the certificate identity authentication sub-service from the above-mentioned at least two identity authentication sub-services when the above-mentioned identity authentication sub-service identifier indicates the use of certificate authentication method, wherein the above-mentioned certificate identity authentication sub-service is used to verify the blockchain identity information obtained based on the digital certificate.
[0014] As an optional solution, the above-mentioned device also includes: a first sending unit, which is used to send the business data of the above-mentioned first platform to the node in the above-mentioned blockchain system for chain operation in response to the chain request triggered by the first platform to the above-mentioned blockchain system before the above-mentioned acquisition of the identity authentication request triggered by the blockchain system; a second sending unit, which is used to send the business data of the above-mentioned second platform to the node in the above-mentioned blockchain system for chain operation in response to the chain request triggered by the second platform to the above-mentioned blockchain system before the above-mentioned acquisition of the identity authentication request triggered by the blockchain system, wherein the information authentication method of the above-mentioned second platform is different from the information authentication method of the above-mentioned first platform.
[0015] According to another aspect of the embodiments of the present application, a computer program product or a computer program is provided, the computer program product or the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device performs the above blockchain-based identity authentication method.
[0016] According to another aspect of an embodiment of the present application, there is also provided an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the blockchain-based identity authentication method through the computer program.
[0017] In an embodiment of the present application, an identity authentication request triggered on a blockchain system is obtained, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request the use of the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information; in response to the identity authentication request, a first authentication sub-service corresponding to the identity authentication sub-service identifier is determined from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include the first authentication sub-service and at least one second authentication sub-service, and the information authentication method of the first authentication sub-service is different from the information authentication method of the second authentication sub-service; the blockchain identity information is authenticated using the information authentication method of the first authentication sub-service to obtain an identity authentication result, wherein the identity authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system. By configuring multiple identity authentication sub-services for the blockchain system and having different identity authentication sub-services provide different information authentication methods, the above-mentioned blockchain identity information is authenticated, so that the blockchain system is no longer limited to a single identity authentication method, thereby achieving the purpose of supporting users to choose different identity authentication methods in the blockchain environment, thereby achieving the technical effect of improving the flexibility of blockchain-based identity authentication, and thus solving the technical problem that the blockchain-based identity authentication method is not flexible enough. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0019] Figure 1 is a schematic diagram of an application environment of an optional blockchain-based identity authentication method according to an embodiment of the present application;
[0020] Figure 2 It is a schematic diagram of a process of an optional blockchain-based identity authentication method according to an embodiment of the present application;
[0021] Figure 3 is a schematic diagram of an optional blockchain-based identity authentication method according to an embodiment of the present application;
[0022] Figure 4 is a schematic diagram of another optional blockchain-based identity authentication method according to an embodiment of the present application;
[0023] Figure 5 is a schematic diagram of another optional blockchain-based identity authentication method according to an embodiment of the present application;
[0024] Figure 6 is a schematic diagram of another optional blockchain-based identity authentication method according to an embodiment of the present application;
[0025] Figure 7 is a schematic diagram of another optional blockchain-based identity authentication method according to an embodiment of the present application;
[0026] Figure 8 is a schematic diagram of another optional blockchain-based identity authentication method according to an embodiment of the present application;
[0027] Fig. 9 is a schematic diagram of another optional blockchain-based identity authentication method according to an embodiment of the present application;
[0028] Fig.10 is a schematic diagram of an optional blockchain-based identity authentication device according to an embodiment of the present application;
[0029] Fig.11 It is a schematic diagram of the structure of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0030] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0032] For ease of understanding, the following terms are explained:
[0033] A data sharing system refers to a system for sharing data between nodes, and the data sharing system may include multiple nodes, which may refer to individual clients in the data sharing system. Each node can receive input information during normal operation, and maintain the shared data in the data sharing system based on the received input information. In order to ensure information intercommunication within the data sharing system, an information connection may exist between each node in the data sharing system, and information can be transmitted between nodes through the above information connection. For example, when any node in the data sharing system receives input information, other nodes in the data sharing system obtain the input information according to the consensus algorithm, and store the input information as data in the shared data, so that the data stored on all nodes in the data sharing system are consistent.
[0034] Each node in the data sharing system has a corresponding node identifier, and each node in the data sharing system can store the node identifiers of other nodes in the data sharing system, so that the generated blocks can be broadcast to other nodes in the data sharing system according to the node identifiers of other nodes. Each node can maintain a node identifier list as shown in the following table, and store the node name and node identifier in the node identifier list accordingly. Among them, the node identifier can be an IP (Internet Protocol, a protocol for interconnecting networks) address and any other information that can be used to identify the node. The following table only uses the IP address as an example for explanation.
[0035] Node Name Node ID Node 1 117.114.151.174 Node 2 117.116.189.145 … … Node N 119.123.789.258
[0036] Each node in the data sharing system stores an identical blockchain. The blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores input information feature values, version numbers, timestamps, and difficulty values, and the block body stores input information. The next block of the genesis block uses the genesis block as its parent block. The next block also includes a block header and a block body. The block header stores the input information feature values of the current block, the block header feature values, version numbers, timestamps, and difficulty values of the parent block, and so on. This makes the block data stored in each block in the blockchain associated with the block data stored in the parent block, ensuring the security of the input information in the block.
[0037] When generating each block in the blockchain, the node where the blockchain is located verifies the input information when it receives it. After verification, it stores the input information in the memory pool and updates the hash tree used to record the input information. After that, it updates the update timestamp to the time when the input information is received, tries different random numbers, and calculates the eigenvalues multiple times so that the calculated eigenvalues can satisfy the following formula:
[0038] SHA256(SHA256(version+prev_hash+merkle_root+ntime+nbits+x))<TARGET
[0039] Among them, SHA256 is the eigenvalue algorithm used to calculate the eigenvalue; version (version number) is the version information of the relevant block protocol in the blockchain; prev_hash is the block header eigenvalue of the parent block of the current block; merkle_root is the eigenvalue of the input information; ntime is the update time of the update timestamp; nbits is the current difficulty, which is a fixed value within a period of time and is determined again after exceeding the fixed time period; x is a random number; TARGET is the eigenvalue threshold, which can be determined based on nbits.
[0040] In this way, when the random number that satisfies the above formula is calculated, the information can be stored accordingly, the block header and block body can be generated, and the current block can be obtained. Subsequently, the node where the blockchain is located sends the newly generated block to other nodes in the data sharing system according to the node identification of other nodes in the data sharing system. Other nodes verify the newly generated block and add the newly generated block to the blockchain stored in them after the verification is completed.
[0041] According to one aspect of the embodiments of the present application, a blockchain-based identity authentication method is provided. Optionally, as an optional implementation, the blockchain-based identity authentication method can be applied to, but is not limited to, Figure 1 In the environment shown, the environment may include, but is not limited to, a user device 102 and a server 112 . The user device 102 may include, but is not limited to, a display 104 , a processor 106 , and a memory 108 . The server 112 includes a database 114 and a processing engine 116 .
[0042] The specific process can be as follows:
[0043] Step S102, the user device 102 obtains an identity authentication request triggered to the blockchain system;
[0044] Step S104, sending the position information of the rope point of the target rope 1002 to the server 112 via the network 110;
[0045] Steps S106-S108, the server 112 responds to the identity authentication request through the processing engine 116, determines the first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, and further uses the information authentication method of the first authentication sub-service to authenticate the blockchain identity information to obtain an identity authentication result;
[0046] Step S110 , sending the identity authentication result to the user device 102 via the network 110 , the user device 102 displays the identity authentication result on the display 104 via the processor 106 , and stores the identity authentication result in the memory 108 .
[0047] remove Figure 1 In addition to the examples shown, the user device 102 includes but is not limited to handheld devices (such as mobile phones), laptops, tablet computers, desktop computers, vehicle-mounted devices, smart TVs, etc., and the present application does not limit the specific implementation of the user device 102. The server 112 can be a single (blockchain) server or a server cluster composed of multiple servers, or a cloud server.
[0048] Optionally, as an optional implementation, as Figure 2 As shown, the blockchain-based identity authentication method can be performed by an electronic device, which can be, for example, Figure 1 The user device or server shown in the figure comprises:
[0049] S202, obtaining an identity authentication request triggered on the blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request to use the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information;
[0050] S204, responding to the identity authentication request, determining a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include a first authentication sub-service and at least one second authentication sub-service, and an information authentication method of the first authentication sub-service is different from an information authentication method of the second authentication sub-service;
[0051] S206, using the information authentication method of the first authentication sub-service to authenticate the blockchain identity information and obtain an authentication result, wherein the authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
[0052] Optionally, in this embodiment, the above blockchain-based identity authentication method can be, but is not limited to, applied in a consortium chain system. In the consortium chain system, the blockchain node will verify the user's identity. Only when the verification is passed can the user request (or transaction) be processed. However, the current mainstream consortium chain user identity authentication mechanism is generally solidified in the node service in the form of code, and cannot be dynamically expanded (adding more identity authentication methods), nor can it support multiple user identity authentications at the same time. This embodiment is intended to make no major changes to the basic framework of the consortium chain system, but to configure multiple identity authentication sub-services additionally, so that the user identity authentication mechanism of the mainstream consortium chain can be dynamically expanded and support multiple user identity authentications.
[0053] Optionally, in this embodiment, the blockchain system can be understood as a distributed database, which manages data in a decentralized manner and has the characteristics of being difficult to tamper with and decentralized. The blockchain system can be composed of blocks, each of which stores certain information and is connected into a chain in the order of their generation. This chain is stored in all servers, and as long as there is a server in the entire system that can work, the entire blockchain is safe. In the blockchain system, each node stores all the information of the entire blockchain, and the security and integrity of the data are guaranteed by cryptographic hash functions and asymmetric encryption.
[0054] Optionally, in this embodiment, the identity authentication request can be understood as, but not limited to, a security authentication mechanism using blockchain technology. Through this mechanism, a user can request an identity authentication service to verify the authenticity of his blockchain identity information. In a blockchain system, each user has a unique blockchain identity identifier, usually a specific sequence of characters, called a public key or address. This identifier corresponds to the user's private key, which can be used to sign and verify transactions. When a user needs to perform identity authentication, a request can be sent to the identity authentication subservice, and the user's blockchain identity information and the relevant identity authentication subservice identifier can be provided. The identity authentication subservice will use the corresponding algorithm and key to verify whether the identity information provided by the user matches the user's real identity on the blockchain. If the verification is successful, the user will be granted the corresponding permissions or services. This can include access to a specific blockchain network, access rights to a specific account, initiation and confirmation of transactions, etc.
[0055] Optionally, in this embodiment, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, wherein the identity authentication sub-service identifier can be used but is not limited to finding an identity authentication sub-service that is compatible with the information authentication method of the blockchain identity information, and the blockchain identity information can be used but is not limited to representing the identity information to be authenticated by the blockchain system.
[0056] Optionally, in this embodiment, the blockchain system configures a first authentication sub-service and at least one second authentication sub-service, wherein the first and second in the first authentication sub-service and at least one second authentication sub-service may be but are not limited to being used for illustration only, and the quantity is not limited, such as Figure 3 As shown, the blockchain system 302 is configured with a first authentication sub-service 304 and at least one second authentication sub-service 306, wherein the first authentication sub-service 304 is authentication sub-service 1, and the at least one second authentication sub-service 306 may include but is not limited to authentication sub-service 2, authentication sub-service 3, and authentication sub-service n, and the information authentication method of the first authentication sub-service 304 is different from the information authentication method of the second authentication sub-service 306, such as the information authentication method of authentication sub-service 1 is different from the information authentication method of authentication sub-service 2. In addition, the information authentication methods of each second authentication sub-service 306 in the at least one second authentication sub-service 306 may also be different from each other, such as the information authentication method of authentication sub-service 2 is different from the information authentication method of authentication sub-service 3, etc.
[0057] Optionally, in this embodiment, at least two identity authentication sub-services may include but are not limited to at least one of the following: a public key identity authentication sub-service, a certificate identity authentication sub-service, a multi-factor identity authentication sub-service, etc., wherein the authentication method of the public key identity authentication sub-service is based on the principle of public key cryptography. In public key cryptography, everyone has a pair of public and private keys. The public key can be made public and used to encrypt or verify signatures, while the private key is kept confidential and used for decryption or signing. In the blockchain system, a user can make his public key public and use the private key for signing operations. Other users can use the public key to verify the legitimacy of the signature, thereby confirming the identity of the user; the authentication method of the certificate identity authentication sub-service is based on the digital certificate mechanism. A digital certificate is an electronic file used to prove identity and authorization, issued by an authoritative certificate authority (CA). In the blockchain system, a user can bind his digital certificate to a public key and make the public key of the certificate authority public. Other users can use the public key of the certificate authority to verify the authenticity of the digital certificate, thereby confirming the identity of the user; the authentication method of the multi-factor identity authentication sub-service combines multiple identity authentication methods, including passwords, dynamic passwords, biometrics, etc. In the blockchain system, multi-factor identity authentication can provide a higher level of security. Users need to pass multiple authentication methods at the same time to be authorized to access the blockchain system or perform transactions.
[0058] Optionally, in this embodiment, the information authentication method of the first authentication sub-service is used to authenticate the blockchain identity information and obtain the authentication result. For example, the user provides the blockchain identity information and the relevant identity authentication sub-service identifier to the identity authentication sub-service, and the identity authentication sub-service uses a specific algorithm and key to verify whether the identity information provided by the user matches the user's real identity on the blockchain, involving comparing public keys, addresses and other information, or using other forms of identity authentication technology. If the verification is successful, the identity authentication sub-service will return the corresponding identity authentication result, such as "authentication passed" or "authentication failed". If the verification fails, further processing may be required, such as requiring the user to re-enter the information or provide more supporting documents.
[0059] It should be noted that by configuring multiple identity authentication sub-services for the blockchain system and having different identity authentication sub-services provide different information authentication methods, the blockchain identity information is authenticated, so that the blockchain system is no longer limited to a single identity authentication method. Instead, in the blockchain environment, it supports users to choose different identity authentication methods, thereby achieving the technical effect of improving the flexibility of blockchain-based identity authentication.
[0060] To further illustrate, the optional Figure 3 The scenario shown, continuing with e.g. Figure 4 As shown, an identity authentication request triggered on the blockchain system 302 is obtained, wherein the identity authentication request carries identity authentication information 402, and the identity authentication information 402 includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request to use the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information; in response to the identity authentication request, a first authentication sub-service 304 corresponding to the identity authentication sub-service identifier is determined from at least two identity authentication sub-services configured in the blockchain system 302, wherein the at least two identity authentication sub-services include a first authentication sub-service 304 and at least one second authentication sub-service 306, and the information authentication method of the first authentication sub-service 304 is different from the information authentication method of the second authentication sub-service 306; the information authentication method of the first authentication sub-service 304 is used to authenticate the blockchain identity information to obtain an identity authentication result 404.
[0061] Through the embodiment provided by the present application, an identity authentication request triggered on a blockchain system is obtained, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request the use of the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information; in response to the identity authentication request, a first authentication sub-service corresponding to the identity authentication sub-service identifier is determined from at least two identity authentication sub-services configured by the blockchain system, wherein the at least two identity authentication sub-services include a first authentication sub-service and at least one second authentication sub-service, and the information authentication method of the first authentication sub-service is different from the information authentication method of the second authentication sub-service; using the information authentication method of the first authentication sub-service, the blockchain identity information is authenticated to obtain an identity authentication result, wherein the identity authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system. By configuring multiple identity authentication sub-services for the blockchain system, and providing different information authentication methods by different identity authentication sub-services, the blockchain identity information is authenticated, so that the blockchain system is no longer limited to a single identity authentication method, thereby achieving the purpose of supporting users to select different identity authentication methods in a blockchain environment, thereby achieving the technical effect of improving the flexibility of blockchain-based identity authentication.
[0062] As an optional solution, determining a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system includes:
[0063] S1-1, determining sub-service information matching the identity authentication sub-service identifier from a pre-configured sub-service information set, wherein the sub-service information includes a sub-service address identifier and a service public key;
[0064] S1-2, determining an authentication sub-service whose sub-service address identifier matches from at least two identity authentication sub-services, and using the authentication sub-service whose sub-service address identifier matches as a first authentication sub-service;
[0065] As an optional solution, the information authentication method of the first authentication sub-service is used to authenticate the blockchain identity information and obtain the authentication result, including: using the service public key to encrypt the blockchain identity information, and sending the encrypted blockchain identity information to the first authentication sub-service, which decrypts and authenticates the information and obtains the authentication result.
[0066] It should be noted that since this embodiment does not make major changes to the blockchain system, but instead configures multiple authentication sub-services for the blockchain system, data transmission is required between the blockchain system and the authentication sub-services. However, security issues are prone to occur during data transmission, and security issues are an important part of the blockchain system. Therefore, this embodiment will first use the service public key to encrypt the blockchain identity information, and send the encrypted blockchain identity information to the first authentication sub-service, which will decrypt and authenticate the identity to obtain the identity authentication result to overcome the above security issues.
[0067] To further illustrate, the system may query a pre-configured sub-service information set to find the sub-service information that matches the identity authentication sub-service identifier provided by the user. These sub-service information may include sub-service address identifiers and service public keys. Then, from the pre-configured multiple identity authentication sub-services, match them according to the sub-service address identifiers, and select one of them as the first authentication sub-service. This selection process may be based on a certain priority or load balancing strategy. The blockchain identity information provided by the user is further encrypted using the service public key that matches the first authentication sub-service, and then sent to the first authentication sub-service. This encryption process can ensure the security of the identity information during transmission. The first authentication sub-service will use the corresponding private key to decrypt the received encrypted information, and then authenticate the identity based on the decrypted information. If the authentication is successful, the first authentication sub-service will return the corresponding identity authentication result.
[0068] Through the embodiments provided by the present application, sub-service information that matches the identity authentication sub-service identifier is determined from a pre-configured sub-service information set, wherein the sub-service information includes a sub-service address identifier and a service public key; an authentication sub-service that matches the sub-service address identifier is determined from at least two identity authentication sub-services, and the authentication sub-service that matches the sub-service address identifier is used as the first authentication sub-service; the blockchain identity information is encrypted using the service public key, and the encrypted blockchain identity information is sent to the first authentication sub-service, which decrypts and authenticates the identity to obtain an authentication result, thereby achieving the purpose of overcoming the security issues existing in the blockchain-based identity authentication process, thereby realizing the technical effect of improving the security of identity authentication.
[0069] As an optional solution, before obtaining the identity authentication request triggered to the blockchain system, the method further includes:
[0070] At least two identity authentication sub-services are deployed for the blockchain system, and at least two identity authentication sub-services are set to replace the identity authentication module to perform identity authentication of the blockchain system, wherein the blockchain system includes the identity authentication module, the information authentication method of the identity authentication module is the information authentication method supported by the blockchain system, and the information authentication methods of at least two identity authentication sub-services include the information authentication method of the identity authentication module.
[0071] It should be noted that, considering that a large-scale modification of the blockchain system may easily cause instability in the blockchain system, this embodiment deploys at least two identity authentication sub-services for the blockchain system, and sets at least two identity authentication sub-services to replace the identity authentication module to perform identity authentication of the blockchain system. In other words, the original blockchain system performs identity authentication of the blockchain system through the identity authentication module, while the blockchain system of this embodiment performs identity authentication of the blockchain system through the identity authentication sub-service, and there is no need to delete the identity authentication module or modify the identity authentication module, thereby improving the stability of the blockchain system.
[0072] To further illustrate, the optional Figure 3 The scenario shown, continuing with e.g. Figure 5 As shown, at least two identity authentication sub-services (such as the first authentication sub-service 304 and the second authentication sub-service 306) are set in the blockchain system 302. These sub-services can run independently of the identity authentication module 502 and provide support for the identity authentication of the blockchain system 302. When users need to perform identity authentication, they no longer request authentication from the traditional identity authentication module 502, but make requests to at least two identity authentication sub-services deployed previously. These sub-services will take over the function of identity authentication and process it. In the current blockchain system 302, there is still an identity authentication module 502, but its information authentication method is consistent with the information authentication method supported by the blockchain system 302. This means that although the present embodiment adds additional identity authentication sub-services, the original identity authentication module 502 still has certain functions and effects. In other words, the at least two identity authentication sub-services deployed not only support the information authentication method adopted by the blockchain system 302, but also include the information authentication method used by the original identity authentication module 502. This can ensure the compatibility and interoperability between different services.
[0073] Through the embodiments provided in the present application, at least two identity authentication sub-services are deployed for the blockchain system, and at least two identity authentication sub-services are arranged to replace the identity authentication module to perform identity authentication of the blockchain system, wherein the blockchain system includes an identity authentication module, the information authentication method of the identity authentication module is the information authentication method supported by the blockchain system, and the information authentication methods of at least two identity authentication sub-services include the information authentication method of the identity authentication module, thereby achieving the purpose of avoiding large-scale modification of the blockchain system, thereby realizing the technical effect of improving the stability of the blockchain system.
[0074] As an optional solution, before determining the subservice information matching the identity authentication subservice identifier from the pre-configured subservice information set, the method further includes: obtaining a subservice information set sent by a blockchain client, wherein the blockchain client is used to establish a data transmission channel between the blockchain system and at least two identity authentication subservices;
[0075] As an optional solution, sending the encrypted blockchain identity information to the first authentication sub-service includes: sending the encrypted blockchain identity information to the first authentication sub-service through a data transmission channel.
[0076] Optionally, in this embodiment, the blockchain client may refer to, but is not limited to, software or applications used to help users interact with the blockchain system.
[0077] It should be noted that in order to improve the convenience of identity authentication based on blockchain, a blockchain client is set up to assist users in data interaction with the blockchain system, such as using the blockchain client to establish a data transmission channel between the blockchain system and at least two identity authentication sub-services, and further sending the encrypted blockchain identity information to the first authentication sub-service through the data transmission channel.
[0078] Through the embodiments provided in the present application, a sub-service information set sent by a blockchain client is obtained, wherein the blockchain client is used to establish a data transmission channel between a blockchain system and at least two identity authentication sub-services; through the data transmission channel, the encrypted blockchain identity information is sent to the first authentication sub-service, thereby achieving the purpose of setting up and using a blockchain client to assist users in data interaction with the blockchain system, thereby achieving the technical effect of improving the convenience of identity authentication based on blockchain.
[0079] As an optional solution, the first authentication sub-service performs decryption and identity authentication to obtain an identity authentication result, including:
[0080] The first authentication sub-service performs reverse calculation on the sub-service address identifier to obtain an identity authentication result, wherein the identity authentication result is obtained by calculating the sub-service address identifier.
[0081] It should be noted that the identity authentication result is obtained by calculating the sub-service address identifier, or it can be understood that the sub-service address identifier is calculated according to specific calculation rules to obtain the identity authentication result. Then, when the above-mentioned calculation rules and the sub-service address identifier are known, this embodiment allows the first authentication sub-service to perform reverse calculations on the sub-service address identifier to obtain the identity authentication result, thereby improving the efficiency of decryption and identity authentication.
[0082] Through the embodiments provided in the present application, the first authentication sub-service performs reverse calculations on the sub-service address identifier to obtain an identity authentication result, wherein the identity authentication result is obtained by calculation on the sub-service address identifier, thereby achieving the purpose of allowing the first authentication sub-service to perform reverse calculations on the sub-service address identifier to obtain an identity authentication result, thereby achieving the technical effect of improving the efficiency of decryption and identity authentication.
[0083] As an optional solution, obtain the identity authentication request triggered by the blockchain system, including:
[0084] When a user account requests a transaction with the blockchain system, an identity authentication request is obtained, wherein the identity authentication sub-service identifier is used to indicate the information authentication method used when the user account registers its identity in the blockchain system, and the blockchain identity information is used to prove that the identity obtained by the user account registered in the blockchain system is legal.
[0085] It should be noted that when a user account wants to trade or interact with the blockchain system, the (blockchain) system will require the user to prove the user's identity and legitimacy. The identity authentication request provided by the user contains the identity authentication sub-service identifier, which is used to indicate the information authentication method used by the user when registering in the blockchain system. This identifier can be assigned by the system or set by the user. In addition, when providing an identity authentication request, the user also needs to provide blockchain identity information, such as public key, address, etc., which is used to prove that the user's identity in the blockchain system is legal and valid.
[0086] Through the embodiments provided by the present application, when a user account requests to conduct a transaction with a blockchain system, an identity authentication request is obtained, wherein the identity authentication sub-service identifier is used to indicate the information authentication method used when the user account registers its identity in the blockchain system, and the blockchain identity information is used to prove that the identity obtained by the user account registered in the blockchain system is legal, thereby achieving the purpose of providing a more flexible identity authentication method for the blockchain transaction process, thereby achieving the technical effect of improving the flexibility of transactions between user accounts and blockchain systems.
[0087] As an optional solution, obtain the authentication request, including:
[0088] Obtain an identity authentication request and the transaction data structure carried by the identity authentication request, wherein the identity authentication information includes a transaction data structure, which is used to present the transaction between the user account request and the blockchain system, and the transaction data structure includes a transaction body and a transaction signature, wherein the transaction body includes an identity authentication sub-service identifier, and the blockchain identity information includes a transaction signature, which is the identity information generated by the user account using a private key based on a cryptographic algorithm for the transaction body.
[0089] Optionally, in this embodiment, the transaction data structure is used to present the transaction between the user account request and the blockchain system. It includes two main parts: the transaction body and the transaction signature. The transaction body includes the identity authentication sub-service identifier, which is used to indicate the information authentication method used when the user account is registered in the blockchain system. At the same time, the transaction body also includes other information related to the transaction, such as the transaction amount, the recipient of the transaction, etc. The transaction signature is the identity information generated by the user account using the private key based on the cryptographic algorithm for the transaction body. This signature can be used to verify the legitimacy and source of the transaction, ensuring that the transaction is issued by a legitimate user. Through this signature, the identity and legitimacy of the user account can be verified, and the transaction can be ensured to be valid.
[0090] In addition, in this embodiment, the transaction data structure also includes blockHash (the block hash value of the current transaction), blockNumber (the block height of the current transaction), from (transaction initiator), gas (the gas spent on the current transaction), gasPrice (gas price), hash (the hash value of the current transaction), input (additional information), nonce (the total number of transactions initiated by the from account), to (transaction recipient) and transactionIndex (the packaging order of the current transaction in this block). These information together constitute the transaction data structure and ensure the validity of the transaction.
[0091] It should be noted that in order to improve the security of identity authentication when a user account conducts transactions with the blockchain system, this embodiment obtains the identity authentication request and also needs to obtain the transaction data structure transmitted together with the identity authentication request. In other words, when the user submits the identity authentication request, he needs to submit the transaction data structure together to prove the authenticity and legality of the transaction.
[0092] Through the embodiments provided by the present application, an identity authentication request and a transaction data structure carried by the identity authentication request are obtained, wherein the identity authentication information includes a transaction data structure, the transaction data structure is used to present the transaction between the user account request and the blockchain system, the transaction data structure includes a transaction body and a transaction signature, the transaction body includes an identity authentication sub-service identifier, and the blockchain identity information includes a transaction signature, and the transaction signature is the identity information generated by the user account using a private key based on a cryptographic algorithm for the transaction body, thereby achieving the purpose of requiring the user to submit a transaction data structure together with the identity authentication request to prove the authenticity and legality of the transaction, thereby achieving the technical effect of improving the security of identity authentication when a user account transacts with the blockchain system.
[0093] As an optional solution, determining a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system includes at least one of the following:
[0094] S2-1, when the identity authentication sub-service identifier indicates that a registration authentication method is used, determining a public key identity authentication sub-service from at least two identity authentication sub-services, wherein the public key identity authentication sub-service is used to verify the blockchain identity information obtained based on the user registration;
[0095] S2-2, when the identity authentication sub-service identifier indicates the use of certificate authentication, determine a certificate identity authentication sub-service from at least two identity authentication sub-services, wherein the certificate identity authentication sub-service is used to verify the blockchain identity information obtained based on the digital certificate.
[0096] Optionally, in this embodiment, the identity authentication sub-service identifier is obtained, and it is checked whether the authentication method indicated by it is a registration authentication method. If yes, proceed to the next step; if not, an error message is returned and the process ends. A public key identity authentication sub-service is selected from the list of available identity authentication sub-services. This can be selected by querying a configuration file, calling an interface, or according to a preset rule. The blockchain identity information obtained by the user registration is sent to the public key identity authentication sub-service. The public key identity authentication sub-service verifies the blockchain identity information using the corresponding algorithm and key. If the verification passes, a message indicating successful verification is returned; if the verification fails, an error message is returned. Based on the verification result, decide whether to allow the user to perform subsequent operations. If the verification is successful, other operations can be continued; if the verification fails, the user's request is rejected or the user is prompted to re-authenticate.
[0097] Optionally, in this embodiment, the identity authentication sub-service identifier is obtained, and it is checked whether the authentication method indicated by it is a certificate authentication method. If so, proceed to the next step; if not, return an error message and end the process. Select a certificate identity authentication sub-service from the list of available identity authentication sub-services. This can be selected by querying a configuration file, calling an interface, or according to preset rules. Send the user's digital certificate to the certificate identity authentication sub-service. The certificate identity authentication sub-service verifies the digital certificate using the corresponding algorithm and key. If the verification passes, a message indicating successful verification is returned; if the verification fails, an error message is returned. Based on the verification result, decide whether to allow the user to perform subsequent operations. If the verification is successful, other operations can be continued; if the verification fails, the user's request is rejected or the user is prompted to re-authenticate.
[0098] Through the embodiments provided by the present application, when the identity authentication sub-service identifier indicates the use of the registration authentication method, a public key identity authentication sub-service is determined from at least two identity authentication sub-services, wherein the public key identity authentication sub-service is used to verify the blockchain identity information obtained based on the user registration; when the identity authentication sub-service identifier indicates the use of the certificate authentication method, a certificate identity authentication sub-service is determined from at least two identity authentication sub-services, wherein the certificate identity authentication sub-service is used to verify the blockchain identity information obtained based on the digital certificate, thereby achieving the purpose of supporting users to choose different identity authentication methods in the blockchain environment, thereby realizing the technical effect of improving the flexibility of blockchain-based identity authentication.
[0099] As an optional solution, before obtaining the identity authentication request triggered to the blockchain system, the method further includes:
[0100] S3-1, in response to the on-chain request triggered by the first platform to the blockchain system, the business data of the first platform is sent to the node in the blockchain system for on-chain operation;
[0101] S3-2, in response to the on-chain request triggered by the second platform to the blockchain system, the business data of the second platform is sent to the nodes in the blockchain system for on-chain operation, wherein the information authentication method of the second platform is different from the information authentication method of the first platform.
[0102] It should be noted that in order to improve the availability of the blockchain system, platforms that use different information authentication methods can use the blockchain system to complete chain operations.
[0103] To further illustrate, for example, when the first platform sends a request to the blockchain system to upload data, the blockchain system will receive and process the request. Specifically, the first platform sends the relevant business data to the nodes in the blockchain system, and these nodes perform the upload operation and write the data to the blockchain. Similarly, when the second platform sends a request to the blockchain system to upload data, the blockchain system will also receive and process the request. The second platform sends the relevant business data to the nodes in the blockchain system, and these nodes perform the upload operation and write the data to the blockchain.
[0104] Through the embodiments provided by the present application, in response to a chain request triggered by the first platform to the blockchain system, the business data of the first platform is sent to the node in the blockchain system for chain operation; in response to the chain request triggered by the second platform to the blockchain system, the business data of the second platform is sent to the node in the blockchain system for chain operation, wherein the information authentication method of the second platform is different from the information authentication method of the first platform, thereby achieving the purpose of platforms using different information authentication methods being able to use the blockchain system to complete the chain operation, thereby achieving the technical effect of improving the availability of the blockchain system.
[0105] As an optional solution, for ease of understanding, the above blockchain-based identity authentication method is applied to the transaction scenario of the blockchain system. This embodiment proposes an extensible blockchain user identity authentication solution, involving an identity authentication sub-service and a sub-service registration process, involving a new user transaction data structure, and involving a new user identity authentication process. Through the solution proposed in this embodiment, the blockchain system can dynamically expand the user identity authentication mechanism and support blockchain nodes to verify user identities in multiple ways.
[0106] Optionally, in this embodiment, if Figure 6 As shown, in the blockchain system, transactions involve three modules, such as a transaction receiving module, a transaction verification module, and a transaction execution module. The blockchain node receives blockchain transactions sent by users through the transaction receiving module. There are generally two forms of receiving, such as receiving through an end-to-end network and receiving through an RPC service. The blockchain node verifies the legality and validity of the transaction through the transaction verification module. The identity verification of the user sending the transaction is also in the transaction verification module. The blockchain node executes the verified transaction.
[0107] It should be noted that this embodiment is applicable to blockchain user identity authentication scenarios and supports users to choose different identity authentication methods.
[0108] To further illustrate, the optional Figure 7 As shown, the specific steps are as follows:
[0109] S702, configure and deploy sub-services. The blockchain node administrator configures and deploys identity authentication sub-services, such as certificate identity authentication sub-services, public key identity authentication sub-services, etc.
[0110] Among them, in this embodiment, the identity authentication sub-service identifier = the first 20 bytes (SHA256 (identity authentication sub-service public key)).
[0111] S704-S706, sub-service registration. The blockchain node administrator constructs a "sub-service registration" type transaction with the "blockchain client program" using the deployed "xx identity authentication sub-service information" and sends it to the blockchain node.
[0112] Among them, the identity authentication sub-service information includes: <service unique identifier, service IP address and port, service public key>, and the public key is used for confidential communication between subsequent blockchain nodes and the identity authentication sub-service.
[0113] After receiving the transaction, the blockchain node will verify the administrator's identity. After the verification is passed, the blockchain node will save the sub-service information to the sub-service registration list.
[0114] S708, the user sends a common transaction. The user uses the blockchain client to construct a common transaction (such as a transfer transaction, a certificate storage transaction, etc.) and sends it to the blockchain node;
[0115] In this embodiment, ordinary transactions involve a new transaction data structure, taking a transfer transaction as an example, Figure 8 As shown in the figure, in the transaction body of the transaction data structure, an "identity authentication sub-service identifier" is added, and the transaction signature is generated by the user using the private key based on the cryptographic algorithm for the transaction body.
[0116] S710, user identity verification. After receiving the transaction, the transaction receiving module of the blockchain node will send the transaction to the "transaction verification module". When performing user identity verification, the transaction will be encrypted and forwarded to the identity authentication sub-service;
[0117] S712, return the verification result. The blockchain node decides whether to proceed to the next step based on the verification result returned by the identity authentication sub-service. If the user's identity is legitimate, the transaction is executed; otherwise, the transaction is rejected.
[0118] S714, the blockchain node returns the transaction processing result to the user.
[0119] Optionally, in this embodiment, the specific user identity authentication process is as follows: Fig. 9 As shown, the specific steps are as follows:
[0120] S902, the blockchain node "identity authentication module" extracts the "identity authentication sub-service identifier" specified in the user transaction body;
[0121] S904, the blockchain node searches for the corresponding sub-service information <service unique identifier, service IP address and port, service public key> from the "sub-service registration list" according to the extracted "identity authentication sub-service identifier";
[0122] S906, the blockchain node uses the "service public key" to encrypt the transaction and sends it to the identity authentication sub-service through the service IP address and port;
[0123] S908, the identity authentication sub-service authenticates the user's identity and returns the "verification result" to the blockchain node;
[0124] S910, the blockchain node decides whether to proceed to the next step based on the "verification result". For example, if the identity verification is passed, the transaction is executed through the "transaction execution module".
[0125] Optionally, the "identity authentication sub-service" mentioned in this embodiment includes not only digital certificate authentication, but also user registration authentication, as well as other methods or a combination of multiple methods. The calculation method of the "identity authentication sub-service identifier" mentioned in this embodiment is not limited to the use of the SHA256 hash algorithm, and other hash algorithms, such as the national encryption SM3, etc., can also be used; at the same time, the implementation of this embodiment is not limited to software, hardware, or a combination of software and hardware.
[0126] Through the embodiments provided in this application, the blockchain system can more conveniently support and be compatible with a variety of user authentication methods, and the blockchain system user authentication is scalable and can support more application scenarios.
[0127] It is understandable that in the specific implementation of this application, related data such as user information is involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards of relevant countries and regions.
[0128] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0129] According to another aspect of the embodiment of the present application, a blockchain-based identity authentication device for implementing the above-mentioned blockchain-based identity authentication method is also provided. Fig.10As shown, the device comprises:
[0130] An acquisition unit 1002 is used to acquire an identity authentication request triggered on the blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request to use the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information;
[0131] The determining unit 1004 is used to respond to the identity authentication request and determine a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include a first authentication sub-service and at least one second authentication sub-service, and an information authentication method of the first authentication sub-service is different from an information authentication method of the second authentication sub-service;
[0132] The verification unit 1006 is used to use the information authentication method of the first authentication sub-service to authenticate the blockchain identity information and obtain an authentication result, wherein the authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
[0133] The specific implementation example can refer to the example shown in the above-mentioned blockchain-based identity authentication device, which will not be repeated here in this example.
[0134] As an optional solution, the determining unit 1004 includes:
[0135] A first determination module is used to determine sub-service information that matches the identity authentication sub-service identifier from a pre-configured sub-service information set, wherein the sub-service information includes a sub-service address identifier and a service public key;
[0136] A second determination module is used to determine an authentication sub-service whose sub-service address identifier matches from at least two identity authentication sub-services, and use the authentication sub-service whose sub-service address identifier matches as a first authentication sub-service;
[0137] The verification unit 1006 includes: an encryption module, which is used to encrypt the blockchain identity information using the service public key, and send the encrypted blockchain identity information to the first authentication sub-service, which decrypts and authenticates the identity to obtain an authentication result.
[0138] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0139] As an optional solution, the device also includes: a deployment module, which is used to deploy at least two identity authentication sub-services for the blockchain system before obtaining an identity authentication request triggered by the blockchain system, and set at least two identity authentication sub-services to replace the identity authentication module to perform identity authentication of the blockchain system, wherein the blockchain system includes an identity authentication module, the information authentication method of the identity authentication module is an information authentication method supported by the blockchain system, and the information authentication methods of at least two identity authentication sub-services include the information authentication method of the identity authentication module.
[0140] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0141] As an optional solution, the device further includes: a first acquisition module, which is used to acquire a subservice information set sent by a blockchain client before determining the subservice information matching the identity authentication subservice identifier from a pre-configured subservice information set, wherein the blockchain client is used to establish a data transmission channel between the blockchain system and at least two identity authentication subservices;
[0142] The encryption module includes: a sending submodule, used to send the encrypted blockchain identity information to the first authentication subservice through a data transmission channel.
[0143] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0144] As an optional solution, the encryption module includes:
[0145] The reverse deduction submodule is used to perform reverse calculation on the subservice address identifier by the first authentication subservice to obtain an identity authentication result, wherein the identity authentication result is obtained by calculating the subservice address identifier.
[0146] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0147] As an optional solution, the acquisition unit 1002 includes:
[0148] The second acquisition module is used to obtain an identity authentication request when a user account requests to conduct a transaction with the blockchain system, wherein the identity authentication sub-service identifier is used to indicate the information authentication method used when the user account registers its identity in the blockchain system, and the blockchain identity information is used to prove that the identity obtained by the user account registered in the blockchain system is legal.
[0149] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0150] As an optional solution, the second acquisition module includes:
[0151] The acquisition submodule is used to obtain the identity authentication request and the transaction data structure carried by the identity authentication request. The identity authentication information includes the transaction data structure. The transaction data structure is used to present the transaction between the user account request and the blockchain system. The transaction data structure includes a transaction body and a transaction signature. The transaction body includes the identity authentication subservice identifier. The blockchain identity information includes a transaction signature. The transaction signature is the identity information generated by the user account using a private key based on a cryptographic algorithm for the transaction body.
[0152] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0153] As an optional solution, the determining unit 1004 includes at least one of the following:
[0154] A third determination module is used to determine a public key identity authentication subservice from at least two identity authentication subservices when the identity authentication subservice identifier indicates that a registration authentication method is used, wherein the public key identity authentication subservice is used to verify the blockchain identity information obtained based on user registration;
[0155] The fourth determination module is used to determine a certificate authentication subservice from at least two identity authentication subservices when the identity authentication subservice identifier indicates the use of a certificate authentication method, wherein the certificate identity authentication subservice is used to verify the blockchain identity information obtained based on the digital certificate.
[0156] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0157] As an optional solution, the device also includes:
[0158] A first sending unit is used to send the business data of the first platform to a node in the blockchain system for on-chain operation in response to an on-chain request triggered by the first platform to the blockchain system before obtaining the identity authentication request triggered to the blockchain system;
[0159] The second sending unit is used to send the business data of the second platform to the node in the blockchain system for chain operation in response to the chain request triggered by the second platform to the blockchain system before obtaining the identity authentication request triggered to the blockchain system, wherein the information authentication method of the second platform is different from the information authentication method of the first platform.
[0160] For specific embodiments, reference can be made to the examples shown in the above-mentioned blockchain-based identity authentication method, which will not be repeated here in this example.
[0161] According to another aspect of the embodiment of the present application, an electronic device for implementing the above-mentioned blockchain-based identity authentication method is also provided, and the electronic device can be but is not limited to Figure 1 The user device 102 or the server 112 shown in FIG. 1 is used as an example to illustrate the electronic device as the user device 102. Fig.11 As shown, the electronic device includes a memory 1102 and a processor 1104. The memory 1102 stores a computer program, and the processor 1104 is configured to execute the steps in any of the above method embodiments through the computer program.
[0162] Optionally, in this embodiment, the electronic device may be located in at least one network device among a plurality of network devices of a computer network.
[0163] Optionally, in this embodiment, the processor may be configured to perform the following steps through a computer program:
[0164] S1, obtaining an identity authentication request triggered on the blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request to use the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information;
[0165] S2, in response to the identity authentication request, determining a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include a first authentication sub-service and at least one second authentication sub-service, and an information authentication method of the first authentication sub-service is different from an information authentication method of the second authentication sub-service;
[0166] S3, using the information authentication method of the first authentication sub-service to authenticate the blockchain identity information and obtain an authentication result, wherein the authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
[0167] Alternatively, a person skilled in the art may understand that: Fig.11 The structure shown is for illustration only. Fig.11 The structure of the electronic device is not limited. Fig.11 More or fewer components (such as network interfaces, etc.) as shown in, or with Fig.11 Different configurations are shown.
[0168] Among them, the memory 1102 can be used to store software programs and modules, such as the program instructions / modules corresponding to the blockchain-based identity authentication method and device in the embodiment of the present application. The processor 1104 executes various functional applications and data processing by running the software programs and modules stored in the memory 1102, that is, to implement the above-mentioned blockchain-based identity authentication method. The memory 1102 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 1102 may further include a memory remotely located relative to the processor 1104, and these remote memories may be connected to the electronic device via a network. Examples of the above-mentioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. Among them, the memory 1102 may be specifically, but not limited to, used to store information such as identity authentication sub-service identifiers, blockchain identity information, and identity authentication results. As an example, such as Fig.11 As shown, the memory 1102 may include, but is not limited to, the acquisition unit 1002, the determination unit 1004, and the verification unit 1006 in the blockchain-based identity authentication device. In addition, it may also include, but is not limited to, other module units in the blockchain-based identity authentication device, which will not be repeated in this example.
[0169] Optionally, the transmission device 1106 is used to receive or send data via a network. Specific examples of the network may include a wired network and a wireless network. In one example, the transmission device 1106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices and routers via a network cable so as to communicate with the Internet or a local area network. In one example, the transmission device 1106 is a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0170] In addition, the above-mentioned electronic device also includes: a display 1108, which is used to display information such as the above-mentioned identity authentication sub-service identifier, blockchain identity information, and identity authentication results; and a connection bus 1110, which is used to connect the various module components in the above-mentioned electronic device.
[0171] In other embodiments, the user device or server may be a node in a distributed system, wherein the distributed system may be a blockchain system, and the blockchain system may be a distributed system formed by connecting the multiple nodes through network communication. Among them, a peer-to-peer network may be formed between the nodes, and any form of computing device, such as a server, user device, or other electronic device, may become a node in the blockchain system by joining the peer-to-peer network.
[0172] According to one aspect of the present application, a computer program product is provided, the computer program product comprising a computer program / instruction, the computer program / instruction comprising a program code for executing the method shown in the flow chart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication part, and / or installed from a removable medium. When the computer program is executed by a central processing unit, various functions provided by the embodiments of the present application are executed.
[0173] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0174] It should be noted that the computer system of the electronic device is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0175] The computer system includes a central processing unit (CPU), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) or the program loaded from the storage part to the random access memory (RAM). In the random access memory, various programs and data required for system operation are also stored. The central processing unit, the read-only memory and the random access memory are connected to each other through a bus. The input / output interface (I / O interface) is also connected to the bus.
[0176] The following components are connected to the input / output interface: an input part including a keyboard, a mouse, etc.; an output part including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage part including a hard disk, etc.; and a communication part including a network interface card such as a local area network card, a modem, etc. The communication part performs communication processing via a network such as the Internet. A drive is also connected to the input / output interface as needed. Removable media, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., are installed on the drive as needed so that the computer program read therefrom is installed into the storage part as needed.
[0177] In particular, according to an embodiment of the present application, the process described in each method flow chart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer readable medium, and the computer program contains a program code for executing the method shown in the flow chart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication part, and / or installed from a removable medium. When the computer program is executed by a central processing unit, various functions defined in the system of the present application are executed.
[0178] According to one aspect of the present application, a computer-readable storage medium is provided, and a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the above-mentioned various optional implementations.
[0179] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for performing the following steps:
[0180] S1, obtaining an identity authentication request triggered on the blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request to use the identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information;
[0181] S2, in response to the identity authentication request, determining a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include a first authentication sub-service and at least one second authentication sub-service, and an information authentication method of the first authentication sub-service is different from an information authentication method of the second authentication sub-service;
[0182] S3, using the information authentication method of the first authentication sub-service to authenticate the blockchain identity information and obtain an authentication result, wherein the authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
[0183] Optionally, in this embodiment, a person of ordinary skill in the art may understand that all or part of the steps in the various methods of the above embodiments may be completed by instructing hardware related to the electronic device through a program, and the program may be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0184] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0185] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling one or more computer devices (which can be personal computers, servers or network devices, etc.) to execute all or part of the steps of the methods of each embodiment of the present application.
[0186] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0187] In the several embodiments provided in the present application, it should be understood that the disclosed user equipment can be implemented in other ways. Among them, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0188] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0189] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0190] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A blockchain-based identity authentication method, It is characterized in that include: Obtaining an identity authentication request triggered on a blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request to use an identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information; In response to the identity authentication request, determining a first authentication sub-service corresponding to the identity authentication sub-service identifier from at least two identity authentication sub-services configured in the blockchain system, wherein the at least two identity authentication sub-services include the first authentication sub-service and at least one second authentication sub-service, and an information authentication method of the first authentication sub-service is different from an information authentication method of the second authentication sub-service; The blockchain identity information is authenticated using the information authentication method of the first authentication sub-service to obtain an authentication result, wherein the authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
2. The method according to claim 1, It is characterized in that The step of determining, from the at least two identity authentication sub-services configured in the blockchain system, a first authentication sub-service corresponding to the identity authentication sub-service identifier comprises: Determine the sub-service information that matches the identity authentication sub-service identifier from a pre-configured sub-service information set, wherein the sub-service information includes a sub-service address identifier and the service public key; Determine, from the at least two identity authentication sub-services, an authentication sub-service whose sub-service address identifier matches, and use the authentication sub-service whose sub-service address identifier matches as the first authentication sub-service; The information authentication method using the first authentication sub-service is used to authenticate the blockchain identity information and obtain the identity authentication result, including: using the service public key to encrypt the blockchain identity information, and sending the encrypted blockchain identity information to the first authentication sub-service, which is decrypted and authenticated by the first authentication sub-service to obtain the identity authentication result.
3. The method according to claim 2, It is characterized in that Before obtaining the identity authentication request triggered on the blockchain system, the method further includes: The at least two identity authentication sub-services are deployed for the blockchain system, and the at least two identity authentication sub-services are arranged to replace the identity authentication module to perform identity authentication of the blockchain system, wherein the blockchain system includes the identity authentication module, the information authentication method of the identity authentication module is the information authentication method supported by the blockchain system, and the information authentication method of the at least two identity authentication sub-services includes the information authentication method of the identity authentication module.
4. The method according to claim 2, It is characterized in that Before determining the subservice information matching the identity authentication subservice identifier from the pre-configured subservice information set, the method further includes: obtaining the subservice information set sent by a blockchain client, wherein the blockchain client is used to establish a data transmission channel between the blockchain system and the at least two identity authentication subservices; The sending the encrypted blockchain identity information to the first authentication sub-service includes: sending the encrypted blockchain identity information to the first authentication sub-service through the data transmission channel.
5. The method according to claim 2, It is characterized in that The first authentication sub-service performs decryption and identity authentication to obtain the identity authentication result, including: The first authentication sub-service performs reverse calculation on the sub-service address identifier to obtain the identity authentication result, wherein the identity authentication result is obtained by calculating the sub-service address identifier.
6. The method according to claim 1, It is characterized in that The obtaining of the identity authentication request triggered on the blockchain system includes: In the case where a user account requests to conduct a transaction with the blockchain system, the identity authentication request is obtained, wherein the identity authentication sub-service identifier is used to indicate the information authentication method used by the user account when registering the identity in the blockchain system, and the blockchain identity information is used to prove that the identity obtained by the user account when registering the identity in the blockchain system is legal.
7. The method according to claim 6, It is characterized in that The obtaining of the identity authentication request comprises: The identity authentication request and the transaction data structure carried by the identity authentication request are obtained, wherein the identity authentication information includes the transaction data structure, and the transaction data structure is used to present the transaction between the user account request and the blockchain system, and the transaction data structure includes a transaction body and a transaction signature, and the transaction body includes the identity authentication sub-service identifier, and the blockchain identity information includes the transaction signature, and the transaction signature is identity information generated by the user account using a private key based on a cryptographic algorithm for the transaction body.
8. The method according to any one of claims 1 to 7, It is characterized in that The determining, from the at least two identity authentication sub-services configured in the blockchain system, a first authentication sub-service corresponding to the identity authentication sub-service identifier comprises at least one of the following: When the identity authentication sub-service identifier indicates that a registration authentication method is used, determining a public key identity authentication sub-service from the at least two identity authentication sub-services, wherein the public key identity authentication sub-service is used to verify the blockchain identity information obtained based on user registration; In a case where the identity authentication sub-service identifier indicates the use of a certificate authentication method, a certificate identity authentication sub-service is determined from the at least two identity authentication sub-services, wherein the certificate identity authentication sub-service is used to verify the blockchain identity information obtained based on the digital certificate.
9. The method according to any one of claims 1 to 7, It is characterized in that Before obtaining the identity authentication request triggered on the blockchain system, the method further includes: In response to a request for on-chaining triggered by the first platform to the blockchain system, the business data of the first platform is sent to a node in the blockchain system for on-chaining; In response to a chain request triggered by the second platform to the blockchain system, the business data of the second platform is sent to a node in the blockchain system for chain operation, wherein the information authentication method of the second platform is different from the information authentication method of the first platform.
10. An identity authentication device based on blockchain, It is characterized in that include: An acquisition unit, configured to acquire an identity authentication request triggered on a blockchain system, wherein the identity authentication request carries identity authentication information, the identity authentication information includes an identity authentication sub-service identifier and blockchain identity information, and the identity authentication request is used to request to use an identity authentication sub-service corresponding to the identity authentication sub-service identifier to verify the blockchain identity information; a determining unit, configured to respond to the identity authentication request and determine, from at least two identity authentication sub-services configured in the blockchain system, a first authentication sub-service corresponding to the identity authentication sub-service identifier, wherein the at least two identity authentication sub-services include the first authentication sub-service and at least one second authentication sub-service, and an information authentication method of the first authentication sub-service is different from an information authentication method of the second authentication sub-service; A verification unit is used to authenticate the blockchain identity information using the information authentication method of the first authentication sub-service to obtain an authentication result, wherein the authentication result is used to indicate the legitimacy of the blockchain identity information in the blockchain system.
11. A computer-readable storage medium, It is characterized in that The computer-readable storage medium includes a stored program, wherein the program executes the method described in any one of claims 1 to 9 when executed by an electronic device.
12. A computer program product comprising a computer program / instructions, It is characterized in that When the computer program / instructions are executed by a processor, the steps of the method described in any one of claims 1 to 9 are implemented.
13. An electronic device comprising a memory and a processor, It is characterized in that A computer program is stored in the memory, and the processor is configured to execute the method according to any one of claims 1 to 9 through the computer program.