Identity verification method and device, nonvolatile storage medium and electronic equipment

By generating the target public and private keys and determining the association relationship with the identity declaration information, the problem of decentralized authentication in the prior art is solved, and the effect of protecting user privacy and enhancing authentication security is achieved.

CN120074920APending Publication Date: 2025-05-30CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510220777.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing technology cannot achieve decentralized authentication, resulting in the risk of information leakage during the authentication process.

Method used

The target public key and the target private key are generated by the target object, the target public key is used as the identity identifier, and the association relationship between the identity identifier and the first declaration information is determined. The authentication request contains the centralized identity and verification method associated with the identity, and the target server verifies it based on the identity identity and verification method.

Benefits of technology

A decentralized identity authentication mechanism has been implemented to protect user privacy and enhance the security of identity authentication. Users can independently control identity information and reduce the risk of information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074920A_ABST
    Figure CN120074920A_ABST
Patent Text Reader

Abstract

The invention discloses an identity verification method and device, a nonvolatile storage medium and electronic equipment. The method comprises the steps that a target object generates a target public key and a target private key, and the target public key is used as an identity label of the target object; the association relationship between the identity label and first declaration information of the target object is determined, the first declaration information comprises self-declaration information and third-party declaration information, and the third-party declaration information comprises identity information issued by a third-party mechanism; and an identity verification request is sent to a target server, the identity verification request is signed by the target private key and comprises a centralized identity having an association relationship with the identity identifier and a verification mode corresponding to the first declaration information, and the target server is used for verifying the signature of the identity verification request according to the identity identifier. According to the method and the device, the technical problem that an information leakage risk possibly exists in an identity verification process due to the fact that decentralized identity verification cannot be realized in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of identity verification, and more particularly, to an identity verification method, apparatus, non-volatile storage medium, and electronic device. Background Art

[0002] Currently, in application scenarios such as NFT, Defi, and digital collections in the metaverse, it is usually still necessary for a centralized third-party entity to provide verification services to verify the target object, and decentralized identity verification cannot be achieved. Moreover, the centralized identity verification in related technologies has relatively high requirements for the third-party entity, and there is a risk of information leakage during the verification process.

[0003] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of this application provide an identity verification method, apparatus, non-volatile storage medium, and electronic device to at least solve the technical problem of possible information leakage risks during the identity verification process due to the inability to achieve decentralized identity verification in related technologies.

[0005] According to one aspect of the embodiments of this application, an identity verification method is provided, including: a target object generates a target public key and a target private key, and uses the target public key as the identity identifier of the target object; determines the association relationship between the identity identifier and the first statement information of the target object, where the first statement information includes self-declaration information and third-party statement information, and the third-party statement information includes identity information issued by a third-party institution; when the operation that the target object expects to perform requires verification of the identity of the target object, sends an identity verification request to a target server, where the identity verification request is signed by the target private key, and the identity verification request includes a centralized identity associated with the identity identifier and a verification method corresponding to the first statement information, and the target server is used to verify the signature of the identity verification request based on the identity identifier and verify the first statement information based on the verification method.

[0006] Optionally, the target server verifies the centralized identity based on the verification method, including: the target server determines a verification party for verifying the third-party statement information according to the verification method; calls the verification party to verify the third-party statement information and obtains the verification result of the third-party statement information; when the verification result of the third-party statement information fails, determines that the verification result of the identity verification request fails.

[0007] Optionally, determining the association relationship between the identity identifier and the first declaration information of the target object includes: when a third-party institution provides a verification certificate, obtaining the verification certificate corresponding to the identity information and verifying the verification certificate corresponding to the identity information; after the verification is passed, determining the association relationship between the identity information and the identity identifier, and storing the verification certificate corresponding to the identity information, where the verification method includes the verification certificate corresponding to the identity information.

[0008] Optionally, the method further includes: the target object storing the verification certificate corresponding to the identity information in a digital storage medium, and the digital storage medium includes a wallet.

[0009] Optionally, determining the association relationship between the identity identifier and the first declaration information of the target object includes: when a third-party institution does not provide a verification certificate, generating a second declaration information for declaring the existence of an association between the identity identifier and the identity information, and determining a verification service party for verifying the second declaration information, so as to determine the association relationship between the identity identifier and the third-party declaration information.

[0010] Optionally, the verification method includes the second declaration information and the information of the verification service party for verifying the second declaration information.

[0011] Optionally, the verification method includes a deterministic verification method and a probabilistic verification method.

[0012] According to another aspect of the embodiments of the present application, there is also provided an identity authentication device, including: a first processing module, configured to generate a target public key and a target private key, and use the target public key as the identity identifier of the target object; a second processing module, configured to determine the association relationship between the identity identifier and the first declaration information of the target object, where the first declaration information includes self-declaration information and third-party declaration information, and the third-party declaration information includes identity information issued by a third-party institution; a third processing module, configured to send an identity authentication request to a target server when the operation expected to be performed by the target object requires authentication of the identity of the target object, where the identity authentication request is signed by the target private key, and the identity authentication request includes a centralized identity associated with the identity identifier and a verification method corresponding to the first declaration information, and the target server is configured to verify the signature of the identity authentication request according to the identity identifier and verify the first declaration information according to the verification method.

[0013] According to another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, where a program is stored in the non-volatile storage medium, and when the program runs, it controls the device where the non-volatile storage medium is located to execute an identity authentication method.

[0014] According to another aspect of the embodiments of the present application, an electronic device is further provided, including: a memory and a processor, where the processor is configured to run a program stored in the memory, and when the program runs, it executes an authentication method.

[0015] According to another aspect of the embodiments of the present application, a computer program product is further provided, including a computer program, and when the computer program is executed by a processor, it implements an authentication method.

[0016] In the embodiments of the present application, a target public key and a target private key are generated using a target object, and the target public key is used as the identity identifier of the target object; the association relationship between the identity identifier and the first statement information of the target object is determined, where the first statement information includes self-declared information and third-party statement information, and the third-party statement information includes identity information issued by a third-party institution; when the operation that the target object expects to execute requires authentication of the identity of the target object, an authentication request is sent to the target server, where the authentication request is signed by the target private key, and the authentication request includes a centralized identity associated with the identity identifier and a verification method corresponding to the first statement information. The target server is used to verify the signature of the authentication request based on the identity identifier and the verification method for verifying the first statement information. Through a decentralized authentication mechanism, the purpose of protecting user privacy and enhancing the security of identity authentication is achieved, thereby realizing the technical effect of users' autonomous control of identity information, and further solving the technical problem of the risk of information leakage that may exist in the process of identity authentication due to the inability to achieve decentralized identity authentication in related technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0018] Figure 1 is a schematic structural diagram of a computer terminal (mobile terminal) provided according to an embodiment of the present application;

[0019] Figure 2 is a schematic flowchart of an authentication method provided according to an embodiment of the present application;

[0020] Figure 3 is a schematic flowchart of an authentication process provided according to an embodiment of the present application;

[0021] Figure 4 is a schematic flowchart of another authentication process provided according to an embodiment of the present application;

[0022] Figure 5It is a schematic structural diagram of an identity authentication device provided according to an embodiment of the present application. Detailed implementation manners

[0023] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present application.

[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0025] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are explained as follows:

[0026] Decentralization: Decentralization is a social relationship form and content generation form formed during the development of the Internet. It is a new network content production process relative to "centralization". Decentralization is to store data dispersedly on multiple nodes in the network. The more nodes there are, the higher the security of the data. In a decentralized system, each node is a center, and each node can connect to and affect other nodes. This flattened, open-source and equalized structure is decentralization.

[0027] Identity management (ID) is an integral part of the computer technology infrastructure, and ID technology is also the infrastructure of the computer. When the Internet has developed from a means of information acquisition to an important means of work efficiency such as e-commerce and e-government, identity authentication is everywhere. When accessing any website, most operations require entering a username and password, or facial recognition, mobile phone number verification, etc.

[0028] With the advent of the Web3.0 metaverse era, due to its decentralized characteristics based on blockchain underlying technology, corresponding decentralized identity verification methods are required.

[0029] Currently, in various scenarios such as NFT, Defi, and digital collections, user login is almost completely anonymous. Due to the lack of support for user identity, users cannot enter more usage scenarios, or enter the metaverse scenario in a more traditional way, which is not truly decentralized.

[0030] Un-decentralized identity verification often needs to be associated with the verification service of a centralized third-party entity, which must provide corresponding query verification services, such as the query verification service website for relevant certificates. If the query verification is not convenient enough, it will stimulate the forgery of certificates and affect the use efficiency of certificates; if the issuing entity stops providing services, it will affect the use of certificates; if the certificate validity period often needs to be updated, it will be even more troublesome. The main core of the Web3.0 metaverse era is that users are the owners of data, that is, users need to be able to independently control their own data. Therefore, users need an identity entity that is generated and used without relying on any centralized entity.

[0031] To solve the above problems, relevant solutions are provided in the embodiments of this application, which will be described in detail below.

[0032] According to the embodiments of this application, a method embodiment of an identity verification method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0033] The method embodiments provided by the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing the identity verification method is shown. As Figure 1 shown, the computer terminal 10 (or mobile device 10) may include one or more (shown as 102a, 102b,..., 102n in the figure) processors 102 (the processor 102 may include, but is not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand, Figure 1The structure shown is only schematic and does not limit the structure of the above electronic device. For example, the computer terminal 10 may further include more or fewer components than those shown in Figure 1 or have a different configuration from that shown in Figure 1 .

[0034] It should be noted that one or more of the above processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" herein. The data processing circuit can be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistor terminal path connected to an interface).

[0035] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the authentication method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above authentication method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0036] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0037] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables a user to interact with the user interface of the computer terminal 10 (or mobile device).

[0038] Under the above operating environment, the embodiments of the present application provide an authentication method, as Figure 2As shown, the method includes the following steps:

[0039] Step S202: The target object generates a target public key and a target private key, and uses the target public key as the identity identifier of the target object.

[0040] As an alternative implementation, the target object can be a user's account or the terminal device running the account.

[0041] In the technical solution provided in step S202, the target private key can be used as proof that the target object controls the corresponding target public key. And the target object can use the target public key as the identity identifier of its distributed identity.

[0042] Step S204: Determine the association relationship between the identity identifier and the first statement information of the target object, where the first statement information includes self-declared information and third-party statement information, and the third-party statement information includes identity information issued by a third-party institution.

[0043] In the technical solution provided in step S204, the steps of determining the association relationship between the identity identifier and the first statement information of the target object include: when the third-party institution provides a verification certificate, obtain the verification certificate corresponding to the identity information and verify the verification certificate corresponding to the identity information; after the verification passes, determine the association relationship between the identity information and the identity identifier, and store the verification certificate corresponding to the identity information, where the verification method includes the verification certificate corresponding to the identity information.

[0044] It should be noted that the third-party institution (issuer) also needs to provide query and verification services. And the identity identifier of the target object is verified by an encryption algorithm. Specifically, after receiving the information signed with the target private key sent by the target object, the encryption algorithm can be used to determine whether the target public key and the signature match, so as to determine whether the target object actually owns the decentralized identity represented by the target public key. That is to say, in the identity verification method provided in this application, the identity identifier of the target object is generated by the target object itself through an encryption algorithm and includes a pair of public key and private key. When the operation that the target object expects to execute requires identity verification, the target object can use its private key to sign the operation request and send the signature and the request to the target server together. After receiving the request, the target server will use the public key of the target object to verify the signature to confirm that the signature is generated by the entity holding the private key corresponding to the public key.

[0045] In such a decentralized framework, the verification of the public key does not require direct querying of the issuer, but relies on mathematical encryption algorithms and the consensus mechanism of the distributed network. It can be seen that the identity verification method provided by the embodiments of the present application ensures the transparency and security of the identity verification process. Since both the signature and verification processes are based on encryption algorithms, as long as the algorithm itself is not compromised, the verification result is credible. At the same time, due to the separation of the public key and the private key, and the fact that the public key information can be publicly obtained in the distributed network, the dependence on a single trust point in the verification process is reduced, enhancing the security and decentralization characteristics of the entire verification process.

[0046] As an alternative implementation, the target object stores the verification certificate corresponding to the identity information in a digital storage medium, and the digital storage medium includes a wallet.

[0047] In some embodiments of the present application, the step of determining the association relationship between the identity identifier and the first statement information of the target object includes: in the case where the third party institution does not provide a verification certificate, generating a second statement information for declaring the existence of an association between the identity identifier and the identity information, and determining the verification service party for verifying the second statement information, so as to determine the association relationship between the identity identifier and the third party statement information.

[0048] As an alternative implementation, the verification method includes the second statement information and the information of the verification service party for verifying the second statement information.

[0049] In some embodiments of the present application, in order to associate the public key of the target object with other identity information of the user corresponding to the target object, if the issuing entity of the identity information provides VC services, it can be associated by verifying the signature VC; if the issuing entity does not provide it, the identity verifier subject can claim to own a certain centralized ID or off-chain identity, and then associate it through a third-party verification (attestation) service. That is to say, when the target object claims to own a certain centralized ID or off-chain identity, it needs to give the way of verifying the claim and the relevant information of the third-party verification service provider. The above identity verifier, that is, the target object, is the issuer of the distributed identity (target public key).

[0050] Optionally, when the issuer does not provide Verifiable Credentials (VC) services, the subject can proactively declare that they possess a specific centralized identity identifier (such as an ID number, passport information, etc.), or can prove their identity in an off-chain environment (such as qualifications or professional certifications in the real world). To make this declaration credible, the user needs to seek verification from a third-party Attestation service. This third party can be an independent identity verification service provider or another trusted entity, such as a government agency, educational institution, or enterprise.

[0051] The role of the third-party Attestation service is to verify whether the user's declaration is accurate and usually ensures the authenticity of the declaration through a series of verification processes. For example: Verifying the user's centralized identity information: The third-party service may check official documents such as the user's ID card, passport, driver's license, etc. to confirm the authenticity of the centralized ID or off-chain identity declared by the user. Conducting biometric verification: For certain high-security identity declarations, the third-party verification service may require the user to perform facial recognition, fingerprint scanning, or other forms of biometric verification. Contacting the original issuing agency for confirmation: In some cases, the third-party verification service may directly contact the issuing agency of the centralized ID to confirm whether the user actually possesses the identity identifier. Using a secure online verification process: For off-chain identities, the third-party service may design a secure online verification process, such as requiring the user to complete a series of online tests or submit supporting documents to verify their true identity or qualifications.

[0052] Once the third-party Attestation service confirms the authenticity of the user's declaration, it provides an Attestation for this declaration, which is a form of proof or guarantee, usually also in the form of a Verifiable Credential. The user can associate this VC issued by the third party with their DID and use it as a basis for using the centralized or off-chain identity in metaverse applications or other Web3.0 environments. When a verifier needs to verify the user's identity, they can confirm the user's declared centralized or off-chain identity information by checking the VC associated with the DID and the signature provided by the third-party Attestation service for these VCs.

[0053] This approach ensures that even in the absence of direct VC services, the DID system can still support users in associating their centralized or off-chain identities with decentralized identity identifiers (public keys), thereby flexibly proving their identities in different scenarios and achieving identity interoperability and wide recognition.

[0054] In step S206, when the operation that the target object expects to execute requires authentication of the identity of the target object, an authentication request is sent to the target server. The authentication request is signed by the target private key. The authentication request includes a centralized identity associated with the identity identifier and the verification method corresponding to the first claim information. The target server is used to verify the signature of the authentication request based on the identity identifier and verify the first claim information based on the verification method.

[0055] In the technical solution provided in step S206, the steps for the target server to verify the centralized identity based on the verification method include: the target server determines the verifier for authenticating the third-party claim information according to the verification method; calls the verifier to verify the third-party claim information and obtains the verification result of the third-party claim information; when the verification result of the third-party claim information fails, it is determined that the verification result of the authentication request fails.

[0056] As an optional implementation manner, the process of verifying the identity information is as Figure 3 shown. It can be seen from Figure 3 that when the issuer (i.e., the target object) claims to be the holder of a certain identity information, such as the holder of a certain on-chain wallet, a decentralized network such as a public chain or a private chain can call the verifier to verify various identity information included in the claim information sent by the issuer.

[0057] In some embodiments of the present application, the verification methods include a deterministic verification method and a probabilistic verification method.

[0058] Optionally, the deterministic verification method usually includes the verification of digital signatures, the use of public key infrastructure (PKI), and proofs based on specific cryptographic algorithms, such as elliptic curve cryptography (ECC), RSA encryption, etc. The characteristic of this type of verification method is that the verification result is certain. If the verification passes, the authenticity of the claim can be unconditionally confirmed. The following is the specific verification process when using the deterministic verification method:

[0059] The first step, claim reception: The verifier receives a credential containing an assertion, and these credentials may come from users, service providers, or other entities.

[0060] Step 2, Public Key Acquisition: The verifier needs to obtain the public key associated with the claim, which can be achieved by directly including the public key information in the credential or by querying a Decentralized Identifier (DID) document. DID documents are usually stored in a decentralized network such as a blockchain, which lists the public keys and other metadata related to the DID.

[0061] Step 3, Digital Signature Verification: The verifier uses the obtained public key to verify the digital signature in the credential. If the signature passes the verification, it indicates that the credential has not been tampered with since issuance and was indeed created by the entity holding the corresponding private key (usually the issuer of the claim or the user themselves). The verification of the digital signature is deterministic, i.e., the result is either a pass or a failure.

[0062] Step 4, Credential Content Check: The verifier checks the credential content to confirm that the information in the claim is as expected. In addition, the verifier may also check metadata such as the validity period and revocation status of the credential to ensure that the credential is still in a valid state at the time of verification.

[0063] Step 5, Issuer Verification: If the credential contains a claim issued by a third-party institution, the verifier needs to confirm the credibility of the issuer. This may involve querying the issuer's public key certificate chain, checking its authentication status, and confirming whether it is on a predefined trust list.

[0064] Step 6, Verification Result Feedback: After verification, the verifier returns the verification result to the requester, usually a simple pass or fail status. If the verification passes, the user can continue to access or use the relevant service; if the verification fails, access is denied, and the user may need to resubmit the verification request or resolve the issues in the credential.

[0065] Optionally, probabilistic verification methods such as Zero-Knowledge Proof (ZKP) do not necessarily provide an absolute certainty in the verification result but guarantee the truthfulness of the claim with a certain probability. Zero-Knowledge Proof allows the verifier to confirm the correctness of the claim without obtaining any additional information, which is particularly important for protecting privacy. The following is the specific verification process when using a probabilistic verification method:

[0066] Step 1, Claim Reception: The verifier receives the claim, which may include a zero-knowledge proof from the user or service provider.

[0067] Step 2, Verification Protocol Selection: Between the verifier and the declarer, a pre-agreed verification protocol, such as zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) or zk-STARKs (Zero-Knowledge Scalable Transparent Argument of Knowledge), can be used to perform zero-knowledge proof.

[0068] Step 3, Proof Generation and Submission: The declarer generates a zero-knowledge proof and submits it to the verifier. This proof usually involves complex cryptographic operations but does not disclose the specific data on which the proof is based.

[0069] Step 4, Proof Verification: The verifier uses the public parameters during proof generation and a specific verification algorithm to check whether the zero-knowledge proof is correct. This process is probabilistic, meaning the verifier can confirm the authenticity of the claim with a high probability, but there is still a certain (minimal) error probability in theory.

[0070] Step 5, Multiple Verifications to Enhance Confidence: In some cases, to increase confidence in the authenticity of the claim, the verifier may request multiple verifications of the zero-knowledge proof, and the result of each verification is independent of others. By multiple independent verifications, the error probability can be reduced to an almost negligible level.

[0071] Step 6, Verification Result Feedback: Similar to the deterministic verification method, the verifier returns the verification result to the requester after completing the verification, but the result may include a probability value representing the verification confidence. If the verifier has sufficient confidence in the authenticity of the claim, the user can continue to access or use the relevant service; if the confidence is insufficient, the user may be required to provide more proofs or adopt other verification methods.

[0072] In some embodiments of the present application, a method for verifying the identity of a user in the metaverse as shown in Figure 4 is also provided, which specifically includes the following steps:

[0073] Step S402, The target object generates a public key and a private key, uses the public key as the ID of its decentralized identity, and uses the private key as the proof that it controls the public key;

[0074] Step S404: The target object associates its own ID with other centralized identities. And if the issuer of the centralized identity provides VC (Verifiable Credentials) services, it can be associated by verifying the signed VC; if the issuing entity does not provide it, the identity verifier subject can claim to own a certain centralized ID or off-chain identity, and then associate it through a third-party attestation service;

[0075] Step S406: The target object generates a claim stating that it owns the above ID and the centralized identity information associated with the ID, and the claim includes the verification mechanisms corresponding to each identity information;

[0076] Step S408: The target object sends an identity verification request signed with the target private key to the metaverse information, and the identity verification request also carries the claim information.

[0077] By generating a target public key and a target private key for the target object and using the target public key as the identity identifier of the target object; determining the association relationship between the identity identifier and the first claim information of the target object, where the first claim information includes self-claimed information and third-party claim information, and the third-party claim information includes identity information issued by a third-party institution; in the case where the operation that the target object expects to execute requires the verification of the identity of the target object, sending an identity verification request to the target server, where the identity verification request is signed by the target private key, and the identity verification request includes the centralized identity associated with the identity identifier and the verification method corresponding to the first claim information, and the target server is used to verify the signature of the identity verification request based on the identity identifier and verify the first claim information based on the verification method. Through the decentralized identity verification mechanism, the purpose of protecting user privacy and enhancing the security of identity verification is achieved, thus realizing the technical effect of the user's autonomous control of identity information, and further solving the technical problem of the possible risk of information leakage in the process of identity verification due to the inability to achieve decentralized identity verification in the related technologies.

[0078] Specifically, the DID mechanism provided by this application allows users to create a decentralized identity identifier using the generated public-private key pair. Users can independently decide how to associate and share their first claim information, including self-claims and third-party claims, such as educational background, work experience, etc., without relying on a single centralized institution to manage and verify this information. When performing identity verification, the user signs the verification request with the private key to ensure the integrity and authenticity of the request. The target server verifies the signature through the public key and checks the authenticity of the first claim information through the verification method provided by the user, realizing a mode of identity verification without a centralized database.

[0079] This mechanism not only reduces the centralized storage of users' personal information, lowering the risk of large-scale data breaches, but also enhances data security and non-repudiation through cryptographic techniques. At the same time, since users can independently decide which information to associate with their DID and when and where to share this information, personal control over data is improved and privacy protection is enhanced. In addition, the DID mechanism also supports cross-platform and cross-application interoperability. Users can freely use their identity identifiers in different metaverse scenarios, Web3.0 applications or services without having to re-register or verify, greatly enhancing user convenience and the flexibility of digital identity management.

[0080] In addition, decentralized identity authentication has the following advantages compared to centralized identity authentication:

[0081] Privacy protection: In decentralized identity authentication, users have full control over their identity data. Users can decide when, where, and to what extent to share identity information, avoiding the privacy leakage risks that may be faced by centralized databases. This increased control means that users can minimize the exposure of personal information and enhance privacy protection.

[0082] Security and immutability: Decentralized identity authentication is usually based on blockchain technology or similar distributed ledger technologies, which are characterized by the fact that once data is recorded, it is very difficult to tamper with or delete. Therefore, users' DID and related credentials are stored in a distributed network, increasing data security and reducing the possibility of identity information being stolen or tampered with.

[0083] Autonomy and sovereignty: In centralized identity authentication, users' identity information is stored in centralized institutions or platforms, and these institutions may have specific rules for the use of user data. In decentralized identity authentication, users are the sovereigns of their own identities and can independently manage identity information without being controlled or restricted by the rules of any single institution.

[0084] Interoperability and compatibility: Decentralized identity authentication is designed with cross-platform interoperability in mind and is usually based on open standards (such as the W3C's DID specification and the Verifiable Credentials data model). This means that users can carry and use their identity credentials between different applications, services, and platforms without having to re-register or verify, improving the user experience and the liquidity of data.

[0085] Reducing trust risks: Traditional centralized authentication relies on a single point of trust, that is, users need to trust that the centralized institution can manage identity information correctly and securely. In the DID method, users can verify the issuer and signature of credentials without directly trusting any centralized entity, and use cryptographic mechanisms to ensure the security of the verification process, reducing trust risks.

[0086] Cost-effectiveness: In a centralized system, the cost of maintaining and updating identity information can be high, including the expenses for managing and maintaining a centralized database. Decentralized authentication uses a distributed network, reducing the cost of maintaining and updating identity information and also reducing the risks arising from service interruptions or outages of centralized institutions.

[0087] Scalability and flexibility: Decentralized authentication methods allow users to add and manage different identity attributes in a modular way. Users can associate different types of credentials such as educational backgrounds, professional qualifications, and health records with a DID. This flexibility enables DIDs to adapt to various scenarios and requirements, from simple login verification to complex identity proofing.

[0088] Persistence and durability: DID is designed with the consideration of identity persistence. Even if the entity that issued the DID no longer exists or the service is interrupted, the DID and its associated credentials can still be verified because the verification logic is usually embedded in a blockchain or distributed ledger, providing users with continuous identity proofing capabilities.

[0089] Promoting innovation: The decentralized authentication architecture encourages the innovation of new business models and services because they are not restricted by the limitations of traditional centralized authentication. For example, DID can promote innovation in emerging fields such as decentralized data markets, decentralized financial services, decentralized games, and metaverse applications.

[0090] The embodiments of this application provide an authentication device. Figure 5 It is a schematic structural diagram of the device. From Figure 5As can be seen, the device includes: a first processing module 50, configured to generate a target public key and a target private key, and use the target public key as the identity identifier of the target object; a second processing module 52, configured to determine the association relationship between the identity identifier and the first declaration information of the target object, where the first declaration information includes self-declaration information and third-party declaration information, and the third-party declaration information includes identity information issued by a third-party institution; a third processing module 54, configured to send an identity verification request to the target server when the operation that the target object expects to execute requires verification of the identity of the target object, where the identity verification request is signed by the target private key, and the identity verification request includes a centralized identity associated with the identity identifier and a verification method corresponding to the first declaration information, and the target server is configured to verify the signature of the identity verification request based on the identity identifier and verify the first declaration information based on the verification method.

[0091] In some embodiments of the present application, the steps for the second processing module 52 to determine the association relationship between the identity identifier and the first declaration information of the target object include: when the third-party institution provides a verification certificate, obtaining the verification certificate corresponding to the identity information and verifying the verification certificate corresponding to the identity information; after the verification passes, determining the association relationship between the identity information and the identity identifier, and storing the verification certificate corresponding to the identity information, where the verification method includes the verification certificate corresponding to the identity information.

[0092] In some embodiments of the present application, the target object stores the verification certificate corresponding to the identity information in a digital storage medium, and the digital storage medium includes a wallet.

[0093] In some embodiments of the present application, the steps for the second processing module 52 to determine the association relationship between the identity identifier and the first declaration information of the target object include: when the third-party institution does not provide a verification certificate, generating a second declaration information for declaring the existence of an association between the identity identifier and the identity information, and determining a verification service party for verifying the second declaration information, so as to determine the association relationship between the identity identifier and the third-party declaration information.

[0094] In some embodiments of the present application, the verification method includes the second declaration information and information about the verification service party for verifying the second declaration information.

[0095] In some embodiments of the present application, the steps for the target server to verify the centralized identity based on the verification method include: the target server determines a verification party for authenticating the third-party declaration information based on the verification method; invoking the verification party to verify the third-party declaration information and obtaining the verification result of the third-party declaration information; when the verification result of the third-party declaration information fails, determining that the verification result of the identity verification request fails.

[0096] In some embodiments of the present application, the verification methods include a deterministic verification method and a probabilistic verification method.

[0097] It should be noted that each module in the above identity verification device can be a program module (for example, a set of program instructions for implementing a specific function), or a hardware module. For the latter, it can be presented in the following forms, but not limited to: the manifestation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0098] According to an embodiment of the present application, there is also provided a non-volatile storage medium in which a program is stored. When the program runs, it controls the device where the non-volatile storage medium is located to execute the following identity verification method: a target object generates a target public key and a target private key, and uses the target public key as the identity identifier of the target object; determines the association relationship between the identity identifier and the first declaration information of the target object, where the first declaration information includes self-declaration information and third-party declaration information, and the third-party declaration information includes identity information issued by a third-party institution; in the case where the operation that the target object expects to execute requires verification of the identity of the target object, sends an identity verification request to a target server, where the identity verification request is signed by the target private key, and the identity verification request includes a centralized identity associated with the identity identifier, and the verification method corresponding to the first declaration information, and the target server is used to verify the signature of the identity verification request based on the identity identifier, and verify the first declaration information based on the verification method.

[0099] According to an embodiment of the present application, there is also provided an electronic device including a storage medium and a processor. The processor is used to run a program stored in the memory. When the program runs, it executes the following identity verification method: a target object generates a target public key and a target private key, and uses the target public key as the identity identifier of the target object; determines the association relationship between the identity identifier and the first declaration information of the target object, where the first declaration information includes self-declaration information and third-party declaration information, and the third-party declaration information includes identity information issued by a third-party institution; in the case where the operation that the target object expects to execute requires verification of the identity of the target object, sends an identity verification request to a target server, where the identity verification request is signed by the target private key, and the identity verification request includes a centralized identity associated with the identity identifier, and the verification method corresponding to the first declaration information, and the target server is used to verify the signature of the identity verification request based on the identity identifier, and verify the first declaration information based on the verification method.

[0100] According to an embodiment of the present application, there is also provided a computer program product, including a computer program, which when executed by a processor, implements the following authentication method: a target object generates a target public key and a target private key, and uses the target public key as the identity identifier of the target object; determines the association relationship between the identity identifier and the first statement information of the target object, where the first statement information includes self-declared information and third-party statement information, and the third-party statement information includes identity information issued by a third-party institution; in the case where the operation that the target object expects to execute requires authentication of the identity of the target object, sends an authentication request to the target server, where the authentication request is signed by the target private key, and the authentication request includes a centralized identity associated with the identity identifier, and the verification method corresponding to the first statement information, and the target server is used to verify the signature of the authentication request based on the identity identifier, and verify the first statement information based on the verification method.

[0101] In the above embodiments of the present application, the descriptions of the respective embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0102] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the units or modules can be in an electrical or other form.

[0103] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0104] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0105] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the related technology, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.

[0106] The foregoing are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. An identity authentication method, characterized in that: include: The target object generates a target public key and a target private key, and uses the target public key as the identity of the target object; Determine an association relationship between the identity identifier and first declaration information of the target object, wherein the first declaration information includes self-declaration information and third-party declaration information, and the third-party declaration information includes identity information issued by a third-party organization; In the case that the operation that the target object expects to perform requires verification of the identity of the target object, an identity authentication request is sent to the target server, wherein the identity authentication request is signed by the target private key, and the identity authentication request includes a centralized identity that has the association relationship with the identity identifier, and a verification method corresponding to the first declaration information, and the target server is used to verify the signature of the identity authentication request based on the identity identifier, and to verify the first declaration information based on the verification method.

2. The identity authentication method according to claim 1, characterized in that: The target server verifies the centralized identity according to the verification method, including: The target server determines a verification party for authenticating the third-party declaration information according to the verification method; Calling the verification party to verify the third-party declaration information and obtaining the verification result of the third-party declaration information; In a case where the verification result of the third-party declaration information is failed, it is determined that the verification result of the identity authentication request is failed.

3. The identity authentication method according to claim 1, characterized in that: Determining the association relationship between the identity identifier and the first declaration information of the target object includes: When the third-party institution provides a verification certificate, obtaining the verification certificate corresponding to the identity information, and verifying the verification certificate corresponding to the identity information; After the verification is passed, the association relationship between the identity information and the identity identifier is determined, and the verification certificate corresponding to the identity information is stored, wherein the verification method includes the verification certificate corresponding to the identity information.

4. The identity authentication method according to claim 1, characterized in that: The method further comprises: The target object stores the verification certificate corresponding to the identity information in a digital storage medium, and the digital storage medium includes a wallet.

5. The identity authentication method according to claim 1, characterized in that: Determining the association relationship between the identity identifier and the first declaration information of the target object includes: In the case that the third-party organization does not provide a verification certificate, second declaration information is generated for declaring that there is an association between the identity identifier and the identity information, and a verification service provider is determined for verifying the second declaration information, thereby determining the association relationship between the identity identifier and the third-party declaration information.

6. The identity authentication method according to claim 5, characterized in that: The verification method includes the second declaration information and information of the verification service provider that verifies the second declaration information.

7. The identity authentication method according to claim 1, characterized in that: The verification method includes a deterministic verification method and a probabilistic verification method.

8. An identity verification device, characterized in that: include: A first processing module, used to generate a target public key and a target private key, and use the target public key as an identity identifier of a target object; A second processing module is used to determine the association relationship between the identity identifier and first declaration information of the target object, wherein the first declaration information includes self-declaration information and third-party declaration information, and the third-party declaration information includes identity information issued by a third-party organization; The third processing module is used to send an identity authentication request to the target server when the operation that the target object expects to perform requires verification of the identity of the target object, wherein the identity authentication request is signed by the target private key, and the identity authentication request includes a centralized identity that has the association relationship with the identity identifier, and a verification method corresponding to the first declaration information, and the target server is used to verify the signature of the identity authentication request based on the identity identifier, and verify the first declaration information based on the verification method.

9. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the identity authentication method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the identity authentication method described in any one of claims 1 to 7 when running.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the identity authentication method according to any one of claims 1 to 7 when being executed by a processor.