Identity verification system and method based on block chain
By introducing blockchain technology into the identity authentication system, decentralized identity identifiers, zero-knowledge proofs and decentralized key management, the problem of the risk of traditional identity verification being easily theft and centralized is solved, and a secure and efficient identity verification experience is achieved.
Patent Information
- Application Number
- CN202510241926.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-06-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional identity verification methods are easily stolen or cracked, with high centralization risks and poor user experience, making it difficult to ensure the authenticity and security of the identity of meeting participants.
A blockchain-based identity authentication system is adopted, including identity generation and storage modules, smart contract authentication modules and decentralized key management modules, and a secure and efficient identity authentication system is built through decentralized identity identifiers, zero-knowledge proof authentication and decentralized key management.
Decentralized authentication is realized, reducing the risk of centralized attacks, improving the security and efficiency of authentication, reducing user steps, and improving user experience.
Smart Images

Figure CN120145353A_ABST
Abstract
Description
Background Art
[0002] With the popularity of remote work and online meetings, ensuring the authenticity and security of the identities of meeting participants has become crucial. Traditional authentication methods (such as usernames and passwords, one-time verification codes) have many defects, including:
[0003] Prone to theft or cracking: Usernames and passwords are vulnerable to phishing attacks or database leaks.
[0004] Centralization risk: Traditional authentication relies on a central server and is vulnerable to DDoS attacks or single points of failure.
[0005] Poor user experience: Multi-factor authentication (MFA) adds extra steps and affects the usage experience. Summary of the Invention
[0006] This application provides a blockchain-based identity authentication system and method for constructing a secure and efficient identity authentication system.
[0007] In the first aspect, a blockchain-based identity authentication system is provided, including:
[0008] An identity generation and storage module for generating a decentralized identity identifier and encrypting and storing the user's identity information;
[0009] A smart contract identity authentication module for performing zero-knowledge proof identity authentication on users;
[0010] A decentralized key management module for performing decentralized key management.
[0011] In the above technical solution, by setting an identity generation and storage module for generating a decentralized identity identifier and encrypting and storing the user's identity information; a smart contract identity authentication module for performing zero-knowledge proof identity authentication on users; a decentralized key management module for performing decentralized key management; a secure and efficient identity authentication system is constructed.
[0012] In a specific feasible implementation, it further includes:
[0013] A cross-chain identity authentication module for sharing identity authentication data in different blockchain ecosystems.
[0014] In a specific feasible implementation, it further includes:
[0015] A meeting access control module for defining access permissions through a smart contract and generating a blockchain-based access log.
[0016] In a specific feasible implementation, the identity generation and storage module includes:
[0017] An identity generation unit for generating a decentralized identity identifier and generating a key pair using an asymmetric encryption algorithm;
[0018] An encrypted storage unit for hashing and storing identity data using the SM3 hashing algorithm.
[0019] In a specific feasible implementation, the smart contract authentication module includes:
[0020] A ZKP authentication unit for performing zero-knowledge proof authentication on users;
[0021] A Multisig identity confirmation unit for performing multi-signature identity confirmation on users.
[0022] In a specific feasible implementation, the decentralized key management module includes:
[0023] A threshold cryptography unit for storing the private key in multiple nodes in a sharded manner using Shamir’s Secret Sharing technology;
[0024] A social recovery mechanism unit for users to specify trusted contacts to assist in recovering their identities when the private key is lost.
[0025] In a specific feasible implementation, the cross-chain identity authentication module includes:
[0026] A trustless relay unit for sharing identity authentication data in different blockchain ecosystems;
[0027] A DID standard compatibility unit for being compatible with the W3C DID specification.
[0028] In a specific feasible implementation, the meeting access control module includes:
[0029] A permission management unit for defining access permissions through smart contracts;
[0030] An access log unit for recording all identity authentication and meeting access logs and storing them in a Merkle Tree structure.
[0031] In a second aspect, a blockchain-based identity authentication method is provided, including the following steps:
[0032] Using the identity generation and storage module to generate a decentralized identity identifier and encrypt and store the user's identity information;
[0033] Using the smart contract authentication module to perform zero-knowledge proof authentication on users;
[0034] Perform decentralized key management using a decentralized key management module.
[0035] In the above technical solution, an identity generation and storage module is set up to generate a decentralized identity identifier and encrypt and store the user's identity information; a smart contract identity authentication module is used to perform zero-knowledge proof identity authentication on the user; a decentralized key management module is used to perform decentralized key management, thus constructing a secure and efficient identity authentication system.
[0036] In a specific feasible implementation, it further includes:
[0037] Use a cross-chain identity authentication module to share identity authentication data in different blockchain ecosystems;
[0038] Use a conference access control module to define access permissions through a smart contract and generate a blockchain-based access log. Description of the Drawings
[0039] Figure 1 It is a structural block diagram of the blockchain-based identity authentication system provided by the embodiment of the present application;
[0040] Figure 2 It is a flow block diagram of the blockchain-based identity authentication method provided by the embodiment of the present application;
[0041] Figure 3 It is a specific flow chart of the blockchain-based identity authentication method provided by the embodiment of the present application. Detailed Embodiment
[0042] The present application will be further described in detail below with reference to the drawings and embodiments. Through these descriptions, the features and advantages of the present application will become more clearly defined.
[0043] The special term "exemplary" here means "serving as an example, embodiment or illustrative". Any embodiment described as "exemplary" here does not have to be construed as superior or better than other embodiments. Although various aspects of the embodiments are shown in the drawings, the drawings do not have to be drawn to scale unless otherwise specified.
[0044] In addition, the technical features involved in different embodiments of the present application described below can be combined with each other as long as they do not conflict with each other.
[0045] To facilitate the understanding of the blockchain-based identity authentication system and method provided by the embodiments of the present application, its application scenario will be described first. The blockchain-based identity authentication system and method provided by the embodiments of the present application are used to construct a secure and efficient identity authentication system. With the popularization of remote work and online meetings, ensuring the authenticity and security of the identities of meeting participants has become crucial. Traditional identity authentication methods (such as usernames and passwords, one-time verification codes) have many defects, including: being easily stolen or cracked: usernames and passwords are vulnerable to phishing attacks or database leaks. Centralization risk: Traditional identity authentication relies on a centralized server and is vulnerable to DDoS attacks or single points of failure. Poor user experience: Multi-factor identity authentication (MFA) adds extra steps and affects the usage experience. Therefore, the embodiments of the present application provide a blockchain-based identity authentication system and method to construct a secure and efficient identity authentication system. The following will be described in detail with specific drawings by way of embodiments.
[0046] Reference Figures 1 to 3 , Figure 1 is the structural block diagram of the blockchain-based identity authentication system provided by the embodiments of the present application; Figure 2 is the flow block diagram of the blockchain-based identity authentication method provided by the embodiments of the present application; Figure 3 is the specific flow chart of the blockchain-based identity authentication method provided by the embodiments of the present application.
[0047] In Figure 1 , the embodiments of the present application provide a blockchain-based identity authentication system, including:
[0048] An identity generation and storage module, which is used to generate a decentralized identity identifier and encrypt and store the user's identity information;
[0049] A smart contract identity authentication module, which is used to perform zero-knowledge proof identity authentication on users;
[0050] A decentralized key management module, which is used to perform decentralized key management.
[0051] In the above technical solution, by setting an identity generation and storage module, which is used to generate a decentralized identity identifier and encrypt and store the user's identity information; a smart contract identity authentication module, which is used to perform zero-knowledge proof identity authentication on users; a decentralized key management module, which is used to perform decentralized key management; a secure and efficient identity authentication system is constructed.
[0052] In a specific feasible implementation solution, it further includes:
[0053] A cross-chain identity authentication module, which is used to share identity authentication data in different blockchain ecosystems.
[0054] In a specific feasible implementation, it further includes:
[0055] A meeting access control module, used to define access permissions through a smart contract and generate an access log based on the blockchain.
[0056] In a specific feasible implementation, the identity generation and storage module includes:
[0057] An identity generation unit, used to generate a decentralized identity identifier and generate a key pair using an asymmetric encryption algorithm;
[0058] An encrypted storage unit, used to perform hash processing on identity data using the SM3 hash algorithm and store it.
[0059] In a specific feasible implementation, the smart contract identity authentication module includes:
[0060] A ZKP identity authentication unit, used to perform zero-knowledge proof identity authentication on users;
[0061] A Multisig identity confirmation unit, used to perform multi-signature identity confirmation on users.
[0062] In a specific feasible implementation, the decentralized key management module includes:
[0063] A threshold cryptography unit, used to use Shamir’s Secret Sharing technology to fragment and store the private key in multiple nodes;
[0064] A social recovery mechanism unit, used for users to specify trusted contacts to assist in recovering their identities when the private key is lost.
[0065] In a specific feasible implementation, the cross-chain identity authentication module includes:
[0066] A trustless relay unit, used to share identity authentication data in different blockchain ecosystems;
[0067] A DID standard compatibility unit, used to be compatible with the W3C DID specification.
[0068] In a specific feasible implementation, the meeting access control module includes:
[0069] A permission management unit, used to define access permissions through a smart contract;
[0070] An access log unit, used to record all identity authentication and meeting access logs and store them using a Merkle Tree structure.
[0071] Specifically, the blockchain-based identity authentication system adopts decentralized identity authentication (DID), combines decentralized storage, smart contract-driven identity authentication, SM3 hash encryption to protect identity data, SM4 symmetric encryption for secure communication, and cross-chain multi-factor authentication to achieve secure and reliable conference identity management. It includes:
[0072] I. Identity Generation and Storage Module, used for:
[0073] 1. Generate identity based on DID:
[0074] When a user registers, the system generates a decentralized identity identifier (DID).
[0075] An asymmetric encryption (ECC) is used to generate a key pair. The public key is stored in the blockchain, and the private key is held by the user.
[0076] 2. Store identity information with SM3 hash encryption:
[0077] Before storage, the SM3 hash algorithm is used to hash the identity data to ensure data immutability.
[0078] Combined with the blockchain Merkle tree structure, efficient data integrity verification is achieved.
[0079] II. Smart Contract Identity Authentication Module, used for:
[0080] 1. Zero-Knowledge Proof (ZKP) identity authentication:
[0081] When a user authenticates their identity, they submit a zero-knowledge proof to the smart contract to prove that they have a legitimate identity without revealing specific identity information.
[0082] Avoid the risk of privacy leakage in traditional identity authentication.
[0083] 2. Multi-signature (Multisig) identity confirmation:
[0084] In important conference authentication, a multi-party signature mechanism is introduced to improve security.
[0085] For example, corporate executives need additional authorized signatures to join sensitive conferences.
[0086] III. Decentralized Key Management Module, used for:
[0087] 1. Threshold Cryptography:
[0088] The Shamir’s Secret Sharing (SSS) technique is adopted to fragment and store the private key in multiple nodes.
[0089] Only partial nodes are required to recover the private key, avoiding single point of failure.
[0090] 2. Social recovery mechanism:
[0091] Users can specify trusted contacts to assist in recovering their identities when the private key is lost.
[0092] Multi-Party Computation (MPC) is adopted to ensure that the original key is not exposed during the key recovery process.
[0093] IV. Cross-chain identity authentication module, used for:
[0094] 1. Trustless Relay:
[0095] Allows different blockchain ecosystems to share identity authentication data.
[0096] Decentralized relay nodes are adopted to ensure the secure transmission of data.
[0097] 2. DID standard compatibility:
[0098] Complies with the W3C DID specification, enabling cross-platform interoperability of identity information.
[0099] V. Conference access control module, used for:
[0100] 1. Smart contract-driven permission management:
[0101] The conference creator defines access permissions through smart contracts.
[0102] Only users who meet the authentication conditions can join the conference.
[0103] 2. Blockchain-based access logs:
[0104] Record all identity authentication and conference access logs to ensure traceability.
[0105] Stored in a Merkle Tree structure to prevent log tampering.
[0106] In the above technical solutions, a decentralized identity authentication system is constructed, eliminating the security risks of centralized servers; using Zero-Knowledge Proof (ZKP), the user data is not exposed during the identity authentication process; the identity information is stored by SM3 hash encryption to ensure data integrity and immutability; SM4 encryption communication improves the security of identity authentication data; cross-chain identity authentication is supported, allowing users to seamlessly switch identities in different blockchain ecosystems; the key management mechanism is optimized, and the threshold cryptography + social recovery method is adopted to prevent key loss.
[0107] In Figure 2 and Figure 3In this application, an embodiment provides a blockchain-based identity authentication method, including the following steps:
[0108] Use the identity generation and storage module to generate a decentralized identity identifier and encrypt and store the user's identity information;
[0109] Use the smart contract identity authentication module to perform zero-knowledge proof identity authentication on the user;
[0110] Use the decentralized key management module to perform decentralized key management.
[0111] In the above technical solution, by setting up an identity generation and storage module for generating a decentralized identity identifier and encrypting and storing the user's identity information; a smart contract identity authentication module for performing zero-knowledge proof identity authentication on the user; and a decentralized key management module for performing decentralized key management, a secure and efficient identity authentication system is constructed.
[0112] In a specific implementable embodiment, it further includes:
[0113] Use the cross-chain identity authentication module to share identity authentication data in different blockchain ecosystems;
[0114] Use the conference access control module to define access permissions through a smart contract and generate a blockchain-based access log.
[0115] In the above technical solution, the beneficial effects include:
[0116] 1. Quantum-resistant attack encryption: Adopt the ECC+SM3 hash chain mechanism to resist the risk of quantum computing cracking.
[0117] 2. Zero-knowledge proof + SM4 encrypted communication: Ensure that the user's identity information is not leaked during the identity authentication process.
[0118] 3. Decentralized storage + smart contract: Avoid centralized data leakage and improve security.
[0119] Those skilled in the art of the present technology know that this application can be implemented as a system, method, or computer program product.
[0120] Therefore, the present disclosure can be specifically implemented in the following forms: it can be completely hardware, can also be completely software (including firmware, resident software, microcode, etc.), and can also be a combination of hardware and software, generally referred to as "circuit", "module", or "system" in this article. In addition, in some embodiments, this application can also be implemented in the form of a computer program product in one or more computer-readable media, which contains computer-readable program code.
[0121] Any combination of one or more computer-readable media may be employed. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present document, a computer-readable storage medium may be any tangible medium that contains or stores a program which can be used by or in connection with an instruction execution system, apparatus, or device.
[0122] Although the embodiments of the present application have been shown and described above, it is to be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art may make variations, modifications, substitutions, and alterations to the above embodiments within the scope of the present application. On this basis, various substitutions and improvements may be made to the present application, and all of these fall within the scope of protection of the present application.
Claims
1. A blockchain-based identity authentication system, characterized in that: include: The identity generation and storage module is used to generate decentralized identity identifiers and encrypt and store user identity information; Smart contract authentication module, used to authenticate users through zero-knowledge proof; Decentralized key management module, used for decentralized key management.
2. The blockchain-based identity authentication system according to claim 1, characterized in that: Also includes: The cross-chain identity authentication module is used to share identity authentication data in different blockchain ecosystems.
3. The blockchain-based identity authentication system according to claim 2, characterized in that: Also includes: The conference access control module is used to define access rights through smart contracts and generate blockchain-based access logs.
4. The blockchain-based identity authentication system according to claim 3, characterized in that: The identity generation and storage module comprises: An identity generation unit, which is used to generate a decentralized identity identifier and generate a key pair using an asymmetric encryption algorithm; The encrypted storage unit is used to hash and store the identity data using the SM3 hash algorithm.
5. The blockchain-based identity authentication system according to claim 4, characterized in that: The smart contract identity authentication module includes: ZKP authentication unit, used to authenticate users through zero-knowledge proof; Multisig identity confirmation unit is used to perform multi-signature identity confirmation on users.
6. The blockchain-based identity authentication system according to claim 5, characterized in that: The decentralized key management module includes: Threshold cryptography unit, used to store private keys in multiple nodes using Shamir's Secret Sharing technology; The social recovery mechanism unit is used by users to designate trusted contacts to assist in recovering their identities when they lose their private keys.
7. The blockchain-based identity authentication system according to claim 6, characterized in that: The cross-chain identity authentication module includes: Trustless relay units for sharing identity authentication data across different blockchain ecosystems; DID standard compatibility unit, used to be compatible with W3C DID specifications.
8. The blockchain-based identity authentication system according to claim 7, characterized in that: The conference access control module includes: The permission management unit is used to define access rights through smart contracts; The access log unit is used to record all identity authentication and conference access logs and is stored in a Merkle Tree structure.
9. A blockchain-based identity authentication method, characterized in that: The following steps are involved: Use the identity generation and storage module to generate a decentralized identity identifier and encrypt and store the user's identity information; Use smart contract authentication module to authenticate users with zero-knowledge proof; Use the decentralized key management module to perform decentralized key management.
10. The blockchain-based identity authentication method according to claim 9, characterized in that: Also includes: Use cross-chain identity authentication modules to share identity authentication data in different blockchain ecosystems; The conference access control module is used to define access rights through smart contracts and generate blockchain-based access logs.
Citation Information
Patent Citations
Multi-dimensional digital identity authentication system based on block chain
CN112580102A
Decentralized identity identification verification method and system
CN117807573A
Block chain data sharing and security verification method based on DID
CN119210800A
Decentralization identity authentication method using DID technology
CN119483891A
Mushroom tea manufacturing method
KR1020240127687A