Management method and system for distributed digital identity life cycle

By dividing the management links of the distributed digital identity life cycle into initial, within and end management links, dynamic management and complete destruction of distributed digital identity data is achieved, and the shortcomings of existing systems in data destruction and compliance are solved, and data security and user control are enhanced.

CN120068138APending Publication Date: 2025-05-30AISINO CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411951257.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing distributed digital identity (DID) and self-sovereign identity (SSI) systems have shortcomings in the full life cycle management of identity data, especially in the data destruction stage, which may lead to privacy leakage and difficult to meet legal compliance requirements.

Method used

A management method for the life cycle of distributed digital identity is proposed. Dynamic management and data destruction are achieved by dividing the management links of the life cycle into initial management links, management links within the life cycle and end management links. The specific steps include creating a unique distributed digital identity DID in the initial management process and establishing a management mechanism in the management process during the life cycle; at the end of the management process, verifying the legality of the destruction request, starting the destruction procedure, and providing destruction proof.

Benefits of technology

Through this method, the complete destruction of distributed digital identity data is achieved, the risk of privacy leakage is reduced, and the compliance of the system is ensured, which enhances users' control and protection of identity data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068138A_ABST
    Figure CN120068138A_ABST
Patent Text Reader

Abstract

The invention discloses a management method and system for a distributed digital identity life cycle, and belongs to the technical field of data management. The method comprises the following steps: aiming at the life cycle of a distributed digital identity (DID), dividing a plurality of management links of the life cycle into an initial management link, a management link in the life cycle and an end management link; in the initial management link, the distributed digital identity (DID) is stored in a decentralized network; performing dynamic management in a management link in the life cycle, and entering a management ending link when a destruction request of a user is received; and in the management ending link, determining whether the public key and the private key are associated or not, if so, starting a destruction program, destroying data related to a distributed digital identity (DID) in the decentralized network, and providing a destruction proof after the destruction is completed. According to the invention, the security of the digital identity information is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and more specifically, to a method and system for managing the life cycle of distributed digital identities. Background Art

[0002] With the development of the Internet and the improvement of personal information security awareness, digital identity management has become a key link in protecting user privacy and data security. Traditional digital identity management relies on centralized databases, which are usually maintained by governments or large enterprises. Although it is convenient for centralized management, there are also risks of data leakage and single point of failure problems. In addition, such systems often lack flexibility, and users have weak control over their personal information.

[0003] In recent years, with the rise of blockchain technology, a new decentralized identity management model has gradually attracted attention. Concepts such as Decentralized Identifiers (DID) and Self-Sovereign Identity (SSI) have proposed a new solution that allows users to control their identity data rather than relying on third-party institutions. The blockchain technology, with its decentralized and immutable characteristics, provides a technical foundation for realizing decentralized identity management.

[0004] However, although existing DID and SSI solutions give users more control, there are still deficiencies in the full life cycle management of identity data. Especially in the data destruction stage, existing methods are difficult to completely delete data traces, which may lead to privacy leakage. In addition, while ensuring user privacy, it is also a challenge for existing DID / SSI systems to meet the compliance requirements stipulated by laws. Summary of the Invention

[0005] In view of the above problems, the present invention proposes a method for managing the life cycle of distributed digital identities, including:

[0006] For the life cycle of a distributed digital identity DID, divide multiple management links of the life cycle into an initial management link, management links during the life cycle, and an end management link;

[0007] In the initial management link, based on the user's identity information, create a unique distributed digital identity DID, generate an associated public key and private key for the distributed digital identity DID, feedback the private key to the user, and store the distributed digital identity DID in a decentralized network;

[0008] In the management stage within the lifecycle, a management mechanism is established. After receiving a management request, based on the management mechanism, dynamic management is performed on the distributed digital identity (DID) stored in the decentralized network. When a user's destruction request is received, the management process enters the end stage.

[0009] In the end stage of management, the legitimacy of the destruction request is verified. If it is legitimate, the public key of the DID to be destroyed is obtained, and the user's private key is obtained. It is then determined whether the public key and the private key are associated. If so, the destruction process is initiated, and the data related to the DID in the decentralized network is destroyed. After the destruction is completed, a destruction certificate is provided.

[0010] Optionally, in the initial management stage, a unique DID is created in a disclosed manner based on the user's identity information.

[0011] Optionally, storing the DID in the decentralized network includes:

[0012] The DID is encrypted using a preset encryption algorithm to generate encrypted data, and the encrypted data is stored on multiple nodes of the decentralized network respectively.

[0013] Optionally, the management mechanism includes: an identity verification mechanism, an access control mechanism, and a data update mechanism.

[0014] Optionally, an identity verification mechanism is established based on zero-knowledge proof technology.

[0015] The identity verification mechanism includes:

[0016] By proving to the verifier the authenticity of a specific decentralized information of the user, the authenticity of the user's identity information can be verified.

[0017] The specific decentralized information includes: age, height, weight, or a certain qualification.

[0018] Optionally, an access control mechanism is established by introducing a smart contract and according to the smart contract and preset rules.

[0019] The access control mechanism includes:

[0020] Controlling the access of a third party to the user's identity information and only allowing authorized third parties to access the user's identity information.

[0021] Optionally, the data update mechanism includes:

[0022] Allow users to update, delete, and modify identity information. After the user updates, deletes, or modifies the identity information, recreate a unique distributed digital identity DID based on the updated, deleted, or modified identity information of the user.

[0023] In another aspect, the present invention also proposes a management system for the life cycle of a distributed digital identity, including:

[0024] An initial unit for dividing multiple management links in the life cycle into an initial management link, in-life management links, and end management links for the life cycle of the distributed digital identity DID;

[0025] A first management unit for creating a unique distributed digital identity DID based on the user's identity information in the initial management link, generating an associated public key and private key for the distributed digital identity DID, feeding back the private key to the user, and storing the distributed digital identity DID in a decentralized network;

[0026] A second management unit for establishing a management mechanism in the in-life management links and, after receiving a management request, dynamically managing the distributed digital identity DID stored in the decentralized network based on the management mechanism, and entering the end management link when receiving a destruction request from the user;

[0027] A third management unit for verifying the legality of the destruction request in the end management link. If it is legal, obtaining the public key of the distributed digital identity DID to be destroyed and the private key of the user, determining whether the public key and the private key are associated. If so, starting a destruction program to destroy the data related to the distributed digital identity DID in the decentralized network and providing a destruction certificate after the destruction is completed.

[0028] Optionally, in the initial management link, create a unique distributed digital identity DID in a disclosed manner based on the user's identity information.

[0029] Optionally, storing the distributed digital identity DID in a decentralized network includes:

[0030] Encrypting the distributed digital identity DID with a preset encryption algorithm to generate encrypted data and storing the encrypted data on multiple nodes of the decentralized network respectively.

[0031] Optionally, the management mechanism includes: an identity verification mechanism, an access control mechanism, and a data update mechanism.

[0032] Optionally, establish an identity verification mechanism based on zero-knowledge proof technology

[0033] The authentication mechanism includes:

[0034] By proving the authenticity of a certain decentralized specific information of the user to the verifier, the authenticity of the user's identity information can be verified;

[0035] The decentralized specific information includes: age, height, weight or a certain qualification.

[0036] Optionally, by introducing a smart contract and establishing an access control mechanism according to the smart contract and preset rules;

[0037] The access control mechanism includes:

[0038] Controlling the access of a third party to the user's identity information and only allowing authorized third parties to access the user's identity information.

[0039] Optionally, the data update mechanism includes:

[0040] Allowing the user to update, delete, and modify the identity information. When the user updates, deletes, or modifies the identity information, a unique distributed digital identity DID is recreated according to the user's updated, deleted, or modified identity information.

[0041] On the other hand, the present invention also provides a computing device, including: one or more processors;

[0042] The processor is used to execute one or more programs;

[0043] When the one or more programs are executed by the one or more processors, the method described above is implemented.

[0044] On the other hand, the present invention also provides a computer-readable storage medium with a computer program stored thereon. When the computer program is executed, the method described above is implemented.

[0045] Compared with the prior art, the beneficial effects of the present invention are:

[0046] The present invention proposes a management method for the distributed digital identity life cycle, including: for the life cycle of the distributed digital identity DID, dividing multiple management links of the life cycle into an initial management link, an in-life cycle management link, and an end management link; in the initial management link, based on the user's identity information, creating a unique distributed digital identity DID, generating an associated public key and private key for the distributed digital identity DID, feeding back the private key to the user, and storing the distributed digital identity DID in a decentralized network; in the in-life cycle management link, establishing a management mechanism, and after receiving a management request, dynamically managing the distributed digital identity DID stored in the decentralized network based on the management mechanism. When receiving a destruction request from the user, enter the end management link; in the end management link, verifying the legality of the destruction request. If it is legal, obtaining the public key of the distributed digital identity DID to be destroyed, and obtaining the user's private key, and determining whether the public key and the private key are associated. If so, starting a destruction program to destroy the data related to the distributed digital identity DID in the decentralized network, and after the destruction is completed, providing a destruction certificate. The present invention enhances the security of digital identity information. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is a flowchart of a management method for the distributed digital identity life cycle of the present invention;

[0048] Figure 2 It is a logic diagram of a management method for the distributed digital identity life cycle of the present invention;

[0049] Figure 3 It is a structural diagram of a management system for the distributed digital identity life cycle of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0050] Now, exemplary embodiments of the present invention will be introduced with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely, and to fully convey the scope of the present invention to those skilled in the art. The terms in the exemplary embodiments shown in the drawings are not limitations on the present invention. In the drawings, the same units / components use the same reference numerals.

[0051] Unless otherwise specified, the terms (including scientific and technical terms) used herein have the ordinary meaning understood by those skilled in the art. In addition, it can be understood that the terms defined in the commonly used dictionary should be understood as having a consistent meaning with the context of their related fields, and should not be understood as idealized or overly formal meanings.

[0052] Example 1:

[0053] The present invention proposes a management method for the distributed digital identity life cycle, as Figure 1 shown, including:

[0054] Step 1. For the life cycle of the distributed digital identity DID, divide multiple management links of the life cycle into an initial management link, a management link during the life cycle, and an end management link;

[0055] Step 2. In the initial management link, based on the user's identity information, create a unique distributed digital identity DID, generate an associated public key and private key for the distributed digital identity DID, feedback the private key to the user, and store the distributed digital identity DID in a decentralized network;

[0056] Step 3. In the management link during the life cycle, establish a management mechanism, and based on the management mechanism, dynamically manage the distributed digital identity DID stored in the decentralized network after receiving a management request. When a destruction request from the user is received, enter the end management link;

[0057] Step 4. In the end management link, verify the legality of the destruction request. If it is legal, obtain the public key of the distributed digital identity DID to be destroyed, and obtain the user's private key. Determine whether the public key and the private key are associated. If so, start the destruction program, destroy the data related to the distributed digital identity DID in the decentralized network, and provide a destruction certificate after the destruction is completed.

[0058] Among them, in the initial management link, based on the user's identity information, create a unique distributed digital identity DID in a disclosed manner.

[0059] Among them, storing the distributed digital identity DID in a decentralized network includes:

[0060] Encrypt the distributed digital identity DID with a preset encryption algorithm to generate encrypted data, and store the encrypted data on multiple nodes of the decentralized network respectively.

[0061] Among them, the management mechanism includes: an identity verification mechanism, an access control mechanism, and a data update mechanism.

[0062] Among them, based on the zero-knowledge proof technology, establish an identity verification mechanism

[0063] The identity verification mechanism includes:

[0064] By proving to the verifier the authenticity of a certain decentralized specific information of the user, the authenticity of the user's identity information can be verified;

[0065] The decentralized specific information includes: age, height, weight or a certain qualification.

[0066] Among them, by introducing a smart contract and establishing an access control mechanism according to the smart contract and preset rules;

[0067] The access control mechanism includes:

[0068] Controlling the access of a third party to the user's identity information and only allowing authorized third parties to access the user's identity information.

[0069] Among them, the data update mechanism includes:

[0070] Allowing the user to update, delete, and modify identity information. After the user updates, deletes, or modifies the identity information, a unique distributed digital identity DID is re-created according to the user's updated, deleted, or modified identity information.

[0071] The following combines with the logic diagram, as Figure 2 shown, to further illustrate the present invention:

[0072] The present invention aims to fundamentally enhance the user's control and protection of identity data. Traditional DID and self-sovereign identity (SSI) systems have many deficiencies in the full life cycle management of identity data, especially in the data destruction stage, often unable to completely delete data traces, thus causing potential privacy leakage risks.

[0073] In the data destruction link, the present invention designs a strict data destruction process to ensure that identity information is completely cleared at the end of the life cycle and prevent data from remaining. In addition, through the built-in compliance check module, the system will regularly update laws and regulations related to data privacy to ensure that it always meets the latest compliance requirements. This series of measures not only enhances the user's trust in identity data but also provides them with a more reliable and secure identity management tool, thus realizing true self-sovereign identity in the digital age.

[0074] The life cycle management part is as follows:

[0075] Data creation:

[0076] User registration: The user creates a DID through the way of selective disclosure. The system generates a unique DID and generates corresponding public and private keys.

[0077] Identity data storage: The user encrypts identity information (such as name, address, etc.) and stores it in a decentralized storage network to ensure the security of the data.

[0078] Data Usage:

[0079] Authentication: When authentication is required, users can use zero - knowledge proof technology to prove the authenticity of specific information (such as age, qualifications, etc.) without disclosing specific identity data.

[0080] Access Control: Introduce smart contracts to control access to identity data according to preset rules, ensuring that only authorized parties can access.

[0081] Data Update:

[0082] Dynamic Management: Users can update their identity data at any time. The system will automatically generate new identity certificates and ensure the invalidation of old data.

[0083] Traceability and Auditing: The system retains all update records of identity data, but uses encryption and zero - knowledge proof technology to protect user privacy, ensuring that the auditing process does not disclose sensitive information.

[0084] Data Destruction:

[0085] Data Destruction Request: Users initiate a data destruction request. After the system verifies the legitimacy of the request, it starts the destruction process.

[0086] Complete Deletion: The system uses multiple encryption algorithms and the characteristics of distributed storage to ensure that all relevant data is completely deleted, avoiding the retention of data traces.

[0087] Proof of Destruction: Generate a zero - knowledge proof of data destruction to provide verification to users and necessary regulatory agencies to ensure compliance.

[0088] Compliance Assurance:

[0089] Legal Compliance Module: The system has a built - in legal compliance module that regularly updates laws and regulations related to data privacy to ensure that the system's operation always complies with the latest compliance requirements.

[0090] User Right to Know: Ensure that users have the right to know at every stage of identity data usage, providing a transparent information disclosure mechanism.

[0091] The main technologies involved in this invention include:

[0092] Zero - Knowledge Proof Technology: Zero - Knowledge Proof (ZKP) is a powerful cryptographic technology that allows one party (the prover) to prove the truth of a statement to another party (the verifier) without revealing any other information. In this invention, ZKP is applied to the authentication process, enabling users to prove specific identity characteristics (such as age or qualifications) without disclosing their personal sensitive data. This significantly reduces the risk of data leakage and enhances user privacy protection.

[0093] Decentralized storage: By adopting a decentralized storage network, identity data is distributed across multiple nodes, enhancing data security and censorship resistance. Even if some nodes are attacked, the data can still maintain integrity and availability. In addition, the decentralized feature also reduces the risk of single-point failures, ensuring that users can securely access their identity data at any time.

[0094] Dynamic data management: The present invention supports users in real-time updating of identity data throughout the entire identity lifecycle, ensuring the accuracy and timeliness of information. Users can easily add, modify, or delete identity information, and the system will automatically generate new identity credentials and invalidate old data. This flexibility not only meets user needs but also enhances the efficiency of data management.

[0095] Data destruction mechanism: After a user initiates a data destruction request, the system starts a strict destruction process to ensure that identity data is completely deleted and prevent the residue of data traces. By adopting multiple encryption algorithms and the characteristics of distributed storage, the data is physically cleared. In addition, the data destruction proof generated by the system can be provided to users and relevant regulatory agencies for verification, ensuring transparency and compliance.

[0096] Compliance guarantee: The present invention has a built-in legal compliance module that regularly updates laws and regulations related to data privacy to ensure that the system always meets the latest compliance requirements. Through automated compliance checks, the system can promptly identify potential risks and make adjustments, thereby enhancing user trust. In addition, users will be informed of relevant legal information during the usage process to protect their right to know.

[0097] Access control: Through the technology of smart contracts, fine-grained access control is achieved to ensure that identity data is only open to authorized parties. Users can independently set access permissions in different scenarios to ensure that only clearly authorized third parties can access their identity data. This flexible permission management not only improves data security but also enhances users' sense of control over their personal data.

[0098] The beneficial effects of the present invention include:

[0099] Enhanced privacy protection: By using zero-knowledge proofs, users can complete identity verification without disclosing specific identity information, fundamentally reducing the risk of privacy leakage.

[0100] Improved data security: The decentralized storage mechanism reduces the risk of single-point failures, ensuring that users' identity data is stored dispersedly in the network, thereby enhancing data security.

[0101] Flexible identity management: Supports real-time updates and dynamic management of identity data. Users can conveniently maintain and modify personal information to ensure the accuracy and validity of the data.

[0102] Thorough data destruction: Provides a strict data destruction process to ensure that identity data is completely cleared at the end of its life cycle, avoiding data remnants and potential leaks.

[0103] Compliance guarantee: Built-in legal compliance module to ensure that the system always complies with relevant regulations, enhance user trust, and reduce legal risks caused by non-compliance.

[0104] Fine-grained access control: Through access management implemented by smart contracts, users can flexibly set access permissions, improve data security, and ensure the controllability of personal data.

[0105] Embodiment 2:

[0106] On the other hand, the present invention also proposes a management system 200 for the life cycle of distributed digital identities, as Figure 3 shown, including:

[0107] An initial unit 201, for the life cycle of the distributed digital identity DID, divides multiple management links of the life cycle into an initial management link, a management link during the life cycle, and an end management link;

[0108] A first management unit 202, for the initial management link, creates a unique distributed digital identity DID based on the user's identity information, generates an associated public key and private key for the distributed digital identity DID, feeds the private key back to the user, and stores the distributed digital identity DID in a decentralized network;

[0109] A second management unit 203, for the management link during the life cycle, establishes a management mechanism, and based on the management mechanism, dynamically manages the distributed digital identity DID stored in the decentralized network after receiving a management request. When receiving a user's destruction request, it enters the end management link;

[0110] A third management unit 204, for the end management link, verifies the legality of the destruction request. If it is legal, it obtains the public key of the distributed digital identity DID to be destroyed, obtains the user's private key, determines whether the public key and the private key are associated. If so, it starts the destruction program, destroys the data related to the distributed digital identity DID in the decentralized network, and provides a destruction certificate after the destruction is completed.

[0111] Among them, in the initial management process, based on the user's identity information, a unique distributed digital identity DID is created in a disclosed manner.

[0112] Among them, storing the distributed digital identity DID in a decentralized network includes:

[0113] Encrypting the distributed digital identity DID with a preset encryption algorithm to generate encrypted data, and storing the encrypted data on multiple nodes of the decentralized network respectively.

[0114] Among them, the management mechanism includes: an identity authentication mechanism, an access control mechanism, and a data update mechanism.

[0115] Among them, an identity authentication mechanism is established based on zero-knowledge proof technology

[0116] The identity authentication mechanism includes:

[0117] By proving to the verifier the authenticity of a certain decentralized specific information of the user, the authenticity of the user's identity information can be verified;

[0118] The decentralized specific information includes: age, height, weight, or a certain qualification.

[0119] Among them, an access control mechanism is established by introducing a smart contract and according to the smart contract and preset rules;

[0120] The access control mechanism includes:

[0121] Controlling the access of a third party to the user's identity information, and only allowing authorized third parties to access the user's identity information.

[0122] Among them, the data update mechanism includes:

[0123] Allowing the user to update, delete, and modify identity information. After the user updates, deletes, or modifies the identity information, a unique distributed digital identity DID is recreated according to the user's updated, deleted, or modified identity information.

[0124] The present invention enhances the security of digital identity information.

[0125] Embodiment 3:

[0126] Based on the same inventive concept, the present invention further provides a computer device, which includes a processor and a memory. The memory is used to store a computer program, and the computer program includes program instructions. The processor is used to execute the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method process or corresponding function, so as to implement the steps of the method in the above embodiments.

[0127] Embodiment 4:

[0128] Based on the same inventive concept, the present invention further provides a storage medium, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in a computer device and is used to store programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and, of course, the extended storage medium supported by the computer device. The computer-readable storage medium provides a storage space, and this storage space stores the operating system of the terminal. And, one or more instructions suitable for being loaded and executed by the processor are also stored in this storage space. These instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The one or more instructions stored in the computer-readable storage medium can be loaded and executed by the processor to implement the steps of the method in the above embodiments.

[0129] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code. The solutions in the embodiments of the present invention can be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript can be used.

[0130] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0131] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0132] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0133] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0134] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A method for managing a distributed digital identity lifecycle, characterized in that: include: For the life cycle of a distributed digital identity DID, multiple management links of the life cycle are divided into an initial management link, a management link within the life cycle, and an end management link; In the initial management phase, a unique distributed digital identity DID is created based on the user's identity information, and an associated public key and private key are generated for the distributed digital identity DID. The private key is fed back to the user, and the distributed digital identity DID is stored in a decentralized network; In the management phase of the life cycle, a management mechanism is established, and after receiving a management request, the distributed digital identity DID stored in the decentralized network is dynamically managed based on the management mechanism. When a destruction request from the user is received, the management phase is terminated; In the end management link, the legality of the destruction request is verified. If it is legal, the public key of the distributed digital identity DID to be destroyed is obtained, and the user's private key is obtained to determine whether the public key and private key are related. If so, the destruction program is started to destroy the data related to the distributed digital identity DID in the decentralized network, and after the destruction is completed, a destruction certificate is provided.

2. The management method according to claim 1, characterized in that: In the initial management phase, a unique distributed digital identity DID is created in a disclosed manner based on the user's identity information.

3. The management method according to claim 1, characterized in that: The distributed digital identity DID is stored in a decentralized network, including: The distributed digital identity DID is encrypted using a preset encryption algorithm to generate encrypted data, and the encrypted data is stored on multiple nodes of the decentralized network.

4. The management method according to claim 1, characterized in that: The management mechanism includes: identity authentication mechanism, access control mechanism and data update mechanism.

5. The management method according to claim 4, characterized in that: The identity verification mechanism is established based on zero-knowledge proof technology. The identity verification mechanism comprises: By proving the authenticity of a user's decentralized specific information to the verifier, the authenticity of the user's identity information can be verified; The decentralized specific information includes: age, height, weight or certain qualifications.

6. The management method according to claim 4, characterized in that: By introducing smart contracts and establishing access control mechanisms based on the smart contracts and preset rules; The access control mechanism comprises: Control third-party access to user identity information and only allow authorized third parties to access user identity information.

7. The management method according to claim 4, characterized in that: The data updating mechanism comprises: Allow users to update, delete and modify identity information. When users update, delete or modify their identity information, a unique distributed digital identity DID is recreated based on the user's updated, deleted or modified identity information.

8. A management system for a distributed digital identity lifecycle, characterized in that: include: The initial unit is used to divide the multiple management links of the life cycle of the distributed digital identity DID into an initial management link, a management link within the life cycle, and an end management link; The first management unit is used to create a unique distributed digital identity DID based on the user's identity information in the initial management phase, generate an associated public key and private key for the distributed digital identity DID, feed back the private key to the user, and store the distributed digital identity DID in a decentralized network; The second management unit is used to establish a management mechanism in the management link within the life cycle, and after receiving a management request, dynamically manage the distributed digital identity DID stored in the decentralized network based on the management mechanism, and enter the end management link when receiving a destruction request from the user; The third management unit is used to verify the legality of the destruction request in the end management link. If it is legal, obtain the public key of the distributed digital identity DID to be destroyed, and obtain the user's private key to determine whether the public key and private key are related. If so, start the destruction program to destroy the data related to the distributed digital identity DID in the decentralized network, and provide a destruction certificate after the destruction is completed.

9. A computer device, characterized in that: include: one or more processors; a processor for executing one or more programs; When the one or more programs are executed by the one or more processors, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed, the method according to any one of claims 1 to 7 is implemented.