Identity management method and system capable of supervising block chain

By using user private key signature verification and group public key combined with cross-contract call of smart contracts in blockchain applications, the problem of users needing to fill in their identity information repeatedly is solved, and the effect of using different applications can be achieved in one authentication, improving the review efficiency and standardization.

CN120217332APending Publication Date: 2025-06-27RICHFIT INFORMATION TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311824214.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In blockchain applications, users need to repeatedly fill in their identity information every time they use a new application, which increases complexity and privacy risks, while increasing operational and regulatory costs.

Method used

By receiving user requests, using user private key signature verification, combining group public key and smart contract for cross-contract calls, realizing one identity authentication can use different blockchain applications, reducing the need for duplicate authentication.

Benefits of technology

It has achieved the improvement of identity review efficiency, reduce the difficulty and cost of auditing while ensuring privacy and security, and at the same time, the standardization of blockchain identity services is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217332A_ABST
    Figure CN120217332A_ABST
Patent Text Reader

Abstract

The invention provides an identity management method and system capable of supervising a block chain. The method comprises the following steps: receiving a use request sent by a target user; wherein the use request comprises first signature data determined after a target user signs target information by using a user private key of the target user, the target information and group characteristics of a user group to which the target user belongs; querying a corresponding group public key from a target smart contract according to the group characteristics of the user group to which the target user belongs; performing signature verification processing according to the group public key, the first signature data and the target information, and determining verification information; and performing consistency comparison on the verification information and standard information in the first signature data, and if the verification information and the standard information are consistent, passing verification. Thus, through the technical scheme provided by the invention, the auditing efficiency can be effectively improved and the auditing difficulty can be effectively reduced on the premise of ensuring privacy security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain technology, and in particular, to an identity management method and system for a regulatory blockchain. Background Art

[0002] Due to the advantages of multi-party collaboration and immutability of blockchain technology, and the ability to build decentralized applications through smart contracts, it has been widely used in various fields such as finance, government affairs, and people's livelihood. While the blockchain applications are developing rapidly, there are also certain security risks. Therefore, the regulatory authorities attach great importance to the compliance of blockchain applications and have introduced relevant management regulations or laws, such as requiring blockchain information service providers to authenticate the real identity information of blockchain information service users. Therefore, in blockchain applications, blockchain information service providers require users to fill in information such as name and ID number when registering in the application, and they can use the blockchain application only after passing the review.

[0003] However, in practical applications, this identity authentication and management method has the following problems:

[0004] 1. Each time a blockchain information service user uses a new blockchain application, they need to repeatedly fill in personal identity information, which not only increases the complexity of use but also may cause the leakage of privacy information;

[0005] 2. Blockchain information service providers need to review the information provided by users, which greatly increases the operating cost of blockchain applications;

[0006] 3. When the regulatory authorities review users, the users' information is scattered in various blockchain information service providers, which greatly increases the regulatory cost and difficulty. Summary of the Invention

[0007] In view of this, the purpose of the present application is to provide an identity management method and system for a regulatory blockchain, which can effectively improve the review efficiency and reduce the review difficulty on the premise of ensuring privacy security.

[0008] The embodiment of the present application provides an identity management method for a regulatory blockchain. The identity management method includes:

[0009] Receiving a usage request sent by a target user; wherein, the usage request includes first signature data determined by the target user signing target information with the user's private key of the target user, the target information, and the group characteristics of the user group to which the target user belongs;

[0010] Querying the corresponding group public key from the target smart contract according to the group characteristics of the user group to which the target user belongs;

[0011] Perform signature verification processing based on the group public key, the first signature data, and the target information to determine verification information;

[0012] Use the verification information to perform a consistency comparison with the standard information in the first signature data. If the two are consistent, the verification passes.

[0013] Optionally, determine the user private key through the following steps:

[0014] Obtain the identity information of the target user; the identity information includes at least the user name and ID number;

[0015] Determine whether the target user meets the group characteristics based on the identity information of the target user;

[0016] If it meets the requirements, generate the user private key of the target user, and bind and store the user private key of the target user with the identity information.

[0017] Optionally, determine the group public key through the following steps:

[0018] According to regulatory requirements, construct user groups through group characteristics, create at least one user group, and generate a group administrator private key and a group public key for each user group;

[0019] For each user group, publish the group characteristics and group public key of the user group in the target smart contract.

[0020] Optionally, the constructing at least one user group through group characteristics according to regulatory requirements includes:

[0021] According to regulatory requirements, create user groups through a group signature algorithm based on group characteristics, creating at least one user group.

[0022] Optionally, the identity management method further includes:

[0023] Receive the second signature data of the user to be traced sent by the regulatory department, and the signature message corresponding to the second signature data;

[0024] Use the administrator private key, the group public key corresponding to the user to be traced, and the signature message to decrypt the second signature data to determine the user private key of the user to be traced;

[0025] Determine the true identity information of the user to be traced through the user private key of the user to be traced, and feedback the true identity information of the user to be traced to the regulatory department.

[0026] Optionally, the querying the corresponding group public key from the target smart contract according to the user group to which the target user belongs includes:

[0027] Invoke the target smart contract in a cross - contract manner;

[0028] Query the corresponding group public key from the target smart contract according to the user group to which the target user belongs.

[0029] The embodiment of the present application also provides a regulatory blockchain identity management system, and the identity management system includes:

[0030] A receiving module, configured to receive a usage request sent by a target user; wherein, the usage request includes first signature data determined after the target user signs target information using the user's private key, the target information, and the user group to which the target user belongs;

[0031] A query module, configured to query the corresponding group public key from the target smart contract according to the user group to which the target user belongs;

[0032] A determination module, configured to perform signature verification processing according to the group public key, the first signature data, and the target information to determine verification information;

[0033] A verification module, configured to perform a consistency comparison between the verification information and the standard information in the first signature data, and if the two are consistent, pass the verification.

[0034] Optionally, the identity management system is further configured to:

[0035] Obtain the identity information of the target user; the identity information at least includes the user name and the ID number;

[0036] Determine whether the target user meets the group characteristics according to the identity information of the target user;

[0037] If it meets the requirements, generate the user private key of the target user, and bind and store the user private key of the target user with the identity information.

[0038] Optionally, the identity management system is further configured to:

[0039] According to regulatory requirements, construct user groups through group characteristics, create at least one user group, and generate a group administrator private key and a group public key for each user group;

[0040] For each user group, publish the group characteristics and the group public key of the user group in the target smart contract.

[0041] Optionally, when the identity management system is used to construct user groups through group characteristics according to regulatory requirements and create at least one user group, the identity management system is configured to:

[0042] According to regulatory requirements, at least one user group is created through a group signature algorithm based on group characteristics.

[0043] Optionally, the identity management system further includes a supervision module, and the supervision module is used for:

[0044] Receiving second signature data of a user to be traced sent by a supervision department, and a signature message corresponding to the second signature data;

[0045] Using the administrator's private key, the group public key corresponding to the user to be traced, and the signature message to decrypt the second signature data to determine the user private key of the user to be traced;

[0046] Determining the true identity information of the user to be traced through the user private key of the user to be traced, and feeding back the true identity information of the user to be traced to the supervision department.

[0047] Optionally, when the query module is used to query the corresponding group public key from a target smart contract according to the user group to which the target user belongs, the query module is used for:

[0048] Invoking the target smart contract in a cross-contract manner;

[0049] Querying the corresponding group public key from the target smart contract according to the user group to which the target user belongs.

[0050] An embodiment of the present application further provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps of the identity management method as described above are executed.

[0051] An embodiment of the present application further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is run by a processor, the steps of the identity management method as described above are executed.

[0052] An identity management method and system for a supervisable blockchain provided by an embodiment of the present application include: receiving a usage request sent by the target user; where the usage request includes first signature data determined by the target user using their own user private key to sign the target information, the target information, and the group characteristics of the user group to which the target user belongs; querying the corresponding group public key from the target smart contract according to the group characteristics of the user group to which the target user belongs; performing signature verification processing according to the group public key, the first signature data, and the target information to determine verification information; using the verification information to perform a consistency comparison with the standard information in the first signature data, and if the two are consistent, passing the verification.

[0053] In this way, through the technical solution provided by the present application, there are the following specific advantages:

[0054] There are the following advantages:

[0055] 1. The user only needs to complete identity authentication once using real identity information and can then use different blockchain applications without having to provide their real identity information every time they use a blockchain application. This not only reduces the usage cost but also protects privacy.

[0056] 2. During verification, only by cross-contractly invoking the verification service in the smart contract can the identity characteristics of the user be verified. This not only reduces the verification cost for user identity verification but also, compared with centralized identity services, using the blockchain identity verification service through cross-contract invocation has extremely low development costs and can maintain business coherence.

[0057] 3. When the regulatory department conducts a review, it can obtain the real identity of the user, thereby not only improving the standardization of blockchain identity services but also giving full play to the innovation of blockchain information services.

[0058] To make the above objects, features, and advantages of the present application more obvious and understandable, the following specific preferred embodiments are given and described in detail in conjunction with the accompanying drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] To more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0060] Figure 1 It is a flowchart of an identity management method for a supervisable blockchain provided by an embodiment of the present application;

[0061] Figure 2 One of the schematic structural diagrams of an identity management system for a regulatory blockchain provided by an embodiment of the present application;

[0062] Figure 3 Another schematic structural diagram of an identity management system for a regulatory blockchain provided by an embodiment of the present application;

[0063] Figure 4 Schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0064] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Components of the embodiments of the present application usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, every other embodiment obtained by those skilled in the art without creative efforts belongs to the scope of protection of the present application.

[0065] Since blockchain technology has advantages such as multi-party collaboration and immutability, and can build decentralized applications through smart contracts, it has been widely used in various fields such as finance, government affairs, and people's livelihood. While the blockchain applications are developing rapidly, there are also certain security risks. Therefore, regulatory authorities attach great importance to the compliance of blockchain applications and have issued relevant management regulations or laws, such as requiring blockchain information service providers to authenticate the true identity information of blockchain information service users. Therefore, in blockchain applications, blockchain information service providers require users to fill in information such as name and ID number when registering in the application, and they can use the blockchain application only after passing the review.

[0066] However, in actual applications, this identity authentication and management method has the following problems:

[0067] 1. Each time a blockchain information service user uses a new blockchain application, they need to repeatedly fill in personal identity information, which not only increases the complexity of use, but also may cause the leakage of privacy information;

[0068] 2. Blockchain information service providers need to review the information provided by users, which greatly increases the operating cost of blockchain applications;

[0069] 3. When the regulatory department reviews users, the information of users is scattered among various blockchain information service providers, which greatly increases the regulatory cost and difficulty.

[0070] Based on this, the embodiments of the present application provide an identity management method and system for a blockchain that can be regulated, which improve the audit efficiency and reduce the audit difficulty on the premise of ensuring privacy and security.

[0071] Please refer to Figure 1 , Figure 1 which is a flowchart of an identity management method for a blockchain that can be regulated provided by the embodiments of the present application. As Figure 1 shown in

[0072] S101. Receive a usage request sent by a target user.

[0073] In this step, the blockchain information service provider can receive the usage request sent by the target user.

[0074] A blockchain information service provider develops and operates blockchain applications on the blockchain and provides specific blockchain information services for target users (users), including but not limited to gas cylinders, etc. When providing blockchain information services, the identity authentication service provided by the blockchain identity service provider is used to verify the signature of the blockchain information service user, so as to obtain the true identity characteristics of the user, but the true identity of the user cannot be obtained.

[0075] The blockchain identity service provider is an identity authentication and verification service provider, which authenticates the true identity information of users according to regulatory requirements, manages different types of user groups using the group signature cryptography algorithm, distributes group member private keys to users; provides an identity authentication service based on smart contracts on the blockchain for the blockchain information service provider, discloses the true identity characteristics and group public keys of each user group, and provides a signature verification function in the smart contract. The blockchain information service provider can verify the identity of the blockchain information service user through cross-contract calls.

[0076] Here, the usage request includes the first signature data determined after the target user signs the target information using the user's own private key, the target information, and the group characteristics of the user group to which the target user belongs.

[0077] For example, when the blockchain is a gas cylinder blockchain application, when a target user needs to access the gas cylinder blockchain application, after the target user selects the gas cylinder to be used in the gas cylinder blockchain application, generates transfer information, and packages the transfer information into a target message M, then uses the user's own private key gsk to sign M to obtain the first signature data. where \(T1, T2, T3\in G1\), \(c\), \(s\) α , \(s\) β , \(s\) x ,

[0078] where \(T1\) is the intermediate value \(u\) α , \(T2\) is the intermediate value \(u\) β , \(T3\) is the intermediate value \(Au\) α+β , \(c\) is a challenge value randomly generated from \(Z\) p , \(s\) α is the intermediate value \(r\) α +\(c\alpha\), \(s\) β is the intermediate value \(r\) α +\(c\beta\), \(s\) x is the intermediate value \(r\) α +\(cx\), is the intermediate value \(r\) α +\(c\delta1\), is the intermediate value \(r\) α +\(c\delta2\), \(G1\) is a bilinear multiplicative cyclic group of order \(p\), \(Z\) p is the integers modulo \(p\), \(p\) is a large prime number, \(\alpha\) is a private integer randomly generated from \(Z\) p , \(\beta\) is a private integer randomly generated from \(Z\) p , \(\delta1\) is the intermediate value \(x\alpha\), \(\delta2\) is the intermediate value \(x\beta\), \(r\) α is a blinding value randomly generated from \(Z\) p , \(A\) is the generator of \(G1\) \(x\) is from randomly generated private integers,[[]] is a positive integer modulo \(p\), \(g1\) is the generator of \(G1\).

[0079] Then the target user sends a usage request to the blockchain information service provider, and the usage request includes the first signature data, the target information, and the group characteristics of the user group to which the target user belongs.

[0080] S102. Query the corresponding group public key from the target smart contract according to the group characteristics of the user group to which the target user belongs.

[0081] In this step, the blockchain information service provider can query the corresponding group public key from the target smart contract according to the group characteristics of the user group to which the target user belongs.

[0082] In an implementation manner provided by the present application, the querying of the corresponding group public key from the target smart contract according to the user group to which the target user belongs includes: calling the target smart contract in a cross - contract manner; querying the corresponding group public key from the target smart contract according to the user group to which the target user belongs.

[0083] Here, the target smart contract can be a smart contract for identity authentication provided by a blockchain identity service provider, which is set in the blockchain.

[0084] In an implementation manner provided by this application, the user private key is determined through the following steps: obtaining the identity information of the target user; the identity information at least includes the user name and the ID number; determining whether the target user meets the group characteristics according to the identity information of the target user; if so, generating the user private key of the target user, and binding and storing the user private key of the target user with the identity information.

[0085] Here, the identity information of the target user includes one or more information such as name, ID number, ID photo, face recognition information, etc. that can represent the identity of the target user.

[0086] Continuing with the above example, if the blockchain identity service provider verifies that the identity information of the target user meets the characteristic requirements of the cylinder user group, select Let Obtain the user private key gsk of the target user = (A, x). Among them, γ is a privacy integer randomly generated from .

[0087] The blockchain identity service provider records the corresponding relationship between the user private key gsk and the user identity information locally according to the requirements of the regulatory department, and then sends the user private key gsk to the corresponding target user.

[0088] S103. Perform signature verification processing according to the group public key, the first signature data, and the target information to determine the verification information.

[0089] In this step, the blockchain information service provider can perform signature verification processing according to the group public key, the first signature data, and the target information to determine the verification information.

[0090] Continuing with the above example, according to the group public key gpk, the target information M, and the parameters T1, T2, T3, s α , s β , s x , Calculate the verification information c'.

[0091] In an implementation manner provided by this application, the group public key is determined through the following steps: according to regulatory requirements, construct user groups through group characteristics, create at least one user group, and generate the group administrator private key and the group public key of each user group; for each user group, publish the group characteristics and the group public key of the user group in the target smart contract.

[0092] Here, the user group can be created by the blockchain identity service provider, determining the group administrator's private key, the group public key, and publishing the group characteristics and the group public key of each user group in the target smart contract. The target smart contract is a user identity authentication smart contract.

[0093] In an implementation provided by the present application, the constructing of the user group according to regulatory requirements and creating at least one user group includes: creating at least one user group based on the group characteristics through the group signature algorithm according to regulatory requirements.

[0094] Continuing with the above example, taking the cylinder transfer as an example, in the user group initialization stage, the blockchain identity service provider uses the BBS04 group signature algorithm to create a cylinder user group. Let G1 and G2 be bilinear groups of order p generated by g1 and g2, and select u, v ∈ G1 such that Select And let Then generate the group public key gpk = (g1, g2, h, u, v, w), and the group administrator's private key gmsk = (ξ1, ξ2). Then, the blockchain identity service provider publishes the group public key gpk and the group characteristics of the cylinder user group in the smart contract.

[0095] Among them, G2 is a bilinear multiplicative cyclic group of order p, g2 is a generator of G1, ξ1 is a private integer randomly generated from , ξ2 is a private integer randomly generated from , h is a random generator of G1 except u is a generator of G1 v is a generator of G1 w is a generator of G2

[0096] S104. Use the verification information to perform a consistency comparison with the standard information in the first signature data. If the two are consistent, the verification is passed.

[0097] Here, determining that the verification information is consistent with the standard information in the first signature data proves that the target user is in the target group where the blockchain application can be used, so that subsequent operations can be carried out.

[0098] Continuing with the above example, after determining the consistency, the permissions are released, and the target user can transfer cylinders normally in the cylinder blockchain application.

[0099] In another implementation provided by the present application, the identity management method further includes:

[0100] S201. Receive the second signature data of the user to be traced sent by the regulatory department, and the signature message corresponding to the second signature data.

[0101] S202. Use the administrator's private key, the group public key corresponding to the user to be traced, and the signature message to decrypt the second signature data, and determine the user private key of the user to be traced.

[0102] S203. Determine the real identity information of the user to be traced through the user private key of the user to be traced, and feedback the real identity information of the user to be traced to the regulatory department.

[0103] Here, the blockchain identity service provider can use the administrator's private key, the group public key corresponding to the user to be traced, and the signature message to determine the user private key of the user to be traced for the second signature data; then, in the smart contract, the real identity information of the user to be verified is determined through the user private key of the user to be traced.

[0104] An identity management method and system for a regulatory blockchain provided by an embodiment of the present application include: receiving a usage request sent by a target user; where the usage request includes first signature data determined by the target user signing target information with the user's own private key, the target information, and the group characteristics of the user group to which the target user belongs; querying the corresponding group public key from the target smart contract according to the group characteristics of the user group to which the target user belongs; performing signature verification processing according to the group public key, the first signature data, and the target information to determine verification information; using the verification information to perform a consistency comparison with the standard information in the first signature data, and if the two are consistent, the verification is passed.

[0105] In this way, through the technical solution provided by the present application, there are the following specific advantages:

[0106] It has the following advantages:

[0107] 1. Users only need to complete identity authentication once with real identity information to be able to use different blockchain applications, without having to provide their real identity information every time they use a blockchain application. This not only reduces the usage cost but also protects privacy.

[0108] 2. During verification, only by cross-contractly invoking the verification service in the smart contract can the identity characteristics of the user be verified. This not only reduces the verification cost of identity verification for users, but also compared with centralized identity services, using blockchain identity verification services through cross-contract invocation has extremely low development costs and can maintain business continuity.

[0109] 3. When conducting reviews, the regulatory authorities can obtain the true identities of users, thereby not only enhancing the standardization of blockchain identity services but also giving full play to the innovation of blockchain information services.

[0110] Please refer to Figure 2 、 Figure 3 , Figure 2 which is one of the structural schematic diagrams of an identity management system for a regulatory blockchain provided by an embodiment of this application. Figure 3 which is the second structural schematic diagram of an identity management system for a regulatory blockchain provided by an embodiment of this application. As Figure 2 shown in

[0111] a receiving module 210, configured to receive a usage request sent by a target user; wherein, the usage request includes first signature data determined after the target user signs the target information using the user's private key, the target information, and the user group to which the target user belongs;

[0112] a query module 220, configured to query the corresponding group public key from the target smart contract according to the user group to which the target user belongs;

[0113] a determination module 230, configured to perform signature verification processing based on the group public key, the first signature data, and the target information to determine verification information;

[0114] a verification module 240, configured to perform a consistency comparison between the verification information and the standard information in the first signature data, and if the two are consistent, pass the verification.

[0115] Optionally, the identity management system 200 is further configured to:

[0116] obtain the identity information of the target user; the identity information at least includes the user name and the ID number;

[0117] determine whether the target user meets the group characteristics according to the identity information of the target user;

[0118] If so, generate the user private key of the target user, and bind and store the user private key of the target user with the identity information.

[0119] Optionally, the identity management system 200 is further configured to:

[0120] construct user groups through group characteristics according to regulatory requirements, create at least one user group, and generate a group administrator private key and a group public key for each user group;

[0121] For each user group, publish the group characteristics and the group public key of the user group in the target smart contract.

[0122] Optionally, when the identity management system 200 is used to construct user groups based on group characteristics according to regulatory requirements and create at least one user group, the identity management system 200 is used for:

[0123] Create at least one user group by performing user group creation based on group characteristics through a group signature algorithm according to regulatory requirements.

[0124] Optionally, the identity management system 200 further includes a supervision module 250, and the supervision module 250 is used for:

[0125] Receive the second signature data of the user to be traced sent by the supervision department, and the signature message corresponding to the second signature data;

[0126] Use the administrator's private key, the group public key corresponding to the user to be traced, and the signature message to decrypt the second signature data to determine the user private key of the user to be traced;

[0127] Determine the true identity information of the user to be traced through the user private key of the user to be traced, and feedback the true identity information of the user to be traced to the supervision department.

[0128] Optionally, when the query module 220 is used to query the corresponding group public key from the target smart contract according to the user group to which the target user belongs, the query module 220 is used for:

[0129] Call the target smart contract in a cross-contract manner;

[0130] Query the corresponding group public key from the target smart contract according to the user group to which the target user belongs.

[0131] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 4 shown in, the electronic device 400 includes a processor 410, a memory 420, and a bus 430.

[0132] The memory 420 stores machine-readable instructions executable by the processor 410. When the electronic device 400 runs, the processor 410 communicates with the memory 420 through the bus 430. When the machine-readable instructions are executed by the processor 410, the steps in the method embodiment as described above Figure 1 can be executed. For specific implementation manners, reference can be made to the method embodiment, which will not be elaborated here.

[0133] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it can execute the steps in the method embodiment as described above. Figure 1 For the specific implementation manners, reference may be made to the method embodiment, which will not be elaborated herein.

[0134] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above may refer to the corresponding processes in the foregoing method embodiments, which will not be elaborated herein.

[0135] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods may be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division manners in actual implementation. For another example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces. The indirect coupling or communication connection of the devices or units may be in an electrical, mechanical, or other form.

[0136] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0137] In addition, in each embodiment of the present application, the functional units may be integrated in one processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit.

[0138] When the above-mentioned functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.

[0139] Finally, it should be noted that the above-mentioned embodiments are only specific implementation manners of this application, used to illustrate the technical solutions of this application, rather than limiting it. The protection scope of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed in this application can still modify the technical solutions recorded in the foregoing embodiments or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. An identity management method for a supervised blockchain, characterized in that, The identity management method includes: Receiving a usage request sent by a target user; wherein, the usage request includes first signature data determined by the target user signing target information using the user's private key, the target information, and the group characteristics of the user group to which the target user belongs; Querying the corresponding group public key from the target smart contract according to the group characteristics of the user group to which the target user belongs; Performing signature verification processing according to the group public key, the first signature data, and the target information to determine verification information; Using the verification information to perform a consistency comparison with the standard information in the first signature data, and if the two are consistent, passing the verification.

2. The identity management method according to claim 1, wherein Determining the user private key through the following steps: Obtaining the identity information of the target user; the identity information includes at least the user name and ID number; Determining whether the target user meets the group characteristics according to the identity information of the target user; If it meets the requirements, generating the user private key of the target user and binding and storing the user private key of the target user with the identity information.

3. The identity management method according to claim 1, wherein Determining the group public key through the following steps: According to regulatory requirements, constructing user groups through group characteristics, creating at least one user group, and generating a group administrator private key and the group public key of each user group; For each user group, publishing the group characteristics and group public key of the user group in the target smart contract.

4. The identity management method according to claim 3, characterized in that, The constructing at least one user group through group characteristics according to regulatory requirements includes: According to regulatory requirements, creating user groups through a group signature algorithm based on group characteristics, creating at least one user group.

5. The identity management method according to claim 1, characterized in that, The identity management method further includes: Receiving the second signature data of the user to be traced sent by the regulatory department, and the signature message corresponding to the second signature data; Using the administrator private key, the group public key corresponding to the user to be traced, and the signature message to decrypt the second signature data to determine the user private key of the user to be traced; Determining the real identity information of the user to be traced through the user private key of the user to be traced and feeding back the real identity information of the user to be traced to the regulatory department.

6. The identity management method according to claim 1, wherein The querying the corresponding group public key from the target smart contract according to the user group to which the target user belongs includes: Calling the target smart contract in a cross-contract manner; Querying the corresponding group public key from the target smart contract according to the user group to which the target user belongs.

7. An identity management system for a supervisable blockchain, characterized in that The identity management system includes: A receiving module, configured to receive a usage request sent by a target user; wherein, the usage request includes first signature data determined by the target user signing target information using the user's private key, the target information, and the user group to which the target user belongs; A querying module, configured to query the corresponding group public key from the target smart contract according to the user group to which the target user belongs; A determining module, configured to perform signature verification processing according to the group public key, the first signature data, and the target information to determine verification information; A verification module, configured to perform a consistency comparison between the verification information and the standard information in the first signature data, and if the two are consistent, passing the verification.

8. The identity management system according to claim 7, wherein The identity management system further includes a supervision module, and the supervision module is configured to: Receive the second signature data of the user to be traced sent by the supervision department, and the signature message corresponding to the second signature data; Use the administrator's private key, the group public key corresponding to the user to be traced, and the signature message to decrypt the second signature data to determine the user private key of the user to be traced; Determine the true identity information of the user to be traced through the user private key of the user to be traced, and feedback the true identity information of the user to be traced to the supervision department.

9. An electronic device, characterized in that, Comprising: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are run by the processor, the steps of the identity management method according to any one of claims 1 to 6 are executed.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is run by the processor, the steps of the identity management method according to any one of claims 1 to 6 are executed.