Digital identity management method and system based on block chain, and electronic equipment

By storing identity identifiers and hash values ​​on the blockchain and storing identity information in distributed databases, the problems of high cost and low efficiency of digital identity management in the prior art are solved, and safe and efficient identity information management is achieved.

CN120217334APending Publication Date: 2025-06-27THE HONG KONG POLYTECHNIC UNIV SHENZHEN RES INST +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510128497.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the prior art, digital identity management is costly and inefficient due to the large amount of computing and storage during identity authentication, and the identity information update management is complex.

Method used

The digital identity management method based on blockchain is adopted, and a unique identity identifier is generated by receiving user identity information, and the identity identifier and hash value are stored on the blockchain, while the identity information is stored in a distributed database under the blockchain.

Benefits of technology

It reduces storage costs, improves data access speed, simplifies the update and management process of identity information, and ensures the security and privacy of identity information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217334A_ABST
    Figure CN120217334A_ABST
Patent Text Reader

Abstract

The invention provides a digital identity management method and system based on a block chain and electronic equipment, and the method comprises the steps: receiving the identity information of a user, encrypting the identity information to generate a unique identity identifier, and storing the identity identifier and a hash value in the block chain. Meanwhile, the identity information is stored in a distributed database under the block chain, so that the identity information of the user is managed. According to the method provided by the invention, by combining the non-tampering property and transparency of the block chain and a mode of respectively storing the identity information on the block chain and under the block chain, while the security and privacy of the identity information are ensured, the updating and management process of the identity information is simplified, so that the identity information of the user can be quickly accessed and queried.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and particularly to a digital identity management method, system and electronic device based on blockchain. Background Art

[0002] Current identity authentication systems usually ensure the security and privacy of identity information through complex cryptographic mechanisms. However, cryptographic mechanisms often incur high computational and storage costs in identity management. The high costs not only increase the burden on users but also may lead to delays in the identity verification process, thereby affecting verification efficiency. In addition, the update and management of identity information are also restricted. When users make identity changes, they need to consume a large amount of resources for re-signing and verification, further reducing the verification efficiency of the system.

[0003] Therefore, the existing technology needs to be further improved. Summary of the Invention

[0004] In view of the above deficiencies in the prior art, the purpose of the present invention is to provide a digital identity management method, system and electronic device based on blockchain, so as to solve the defects in the prior art that when performing identity authentication in digital identity management, due to large amounts of computation and storage, high costs are incurred and the identity verification efficiency is low.

[0005] In a first aspect, this embodiment discloses a digital identity management method based on blockchain, which includes:

[0006] Receiving the identity information of a user and encrypting the identity information to generate a unique identity identifier;

[0007] Storing the identity identifier and hash value on the blockchain, and at the same time storing the identity information in a distributed database under the blockchain.

[0008] Optionally, the step of storing the identity identifier and hash value on the blockchain includes:

[0009] When any node in the blockchain receives a user identity credential, verifying the signature of the issuer;

[0010] Synchronizing the verified user identity identifier, the hash value of the identity information, and the hash value of the identity credential to other nodes in the blockchain for storage.

[0011] Optionally, the step of storing the identity information in a distributed database under the blockchain includes:

[0012] Dividing the identity information into target sensitive information and non-target sensitive information;

[0013] Store the target sensitive information in ciphertext form and the non-target sensitive information in plaintext form in a distributed database under the blockchain.

[0014] Optionally, establish a digital identity index tree for the identity identifiers and hash values stored on the blockchain and the identity information stored in the distributed database under the blockchain in the form of a Merkle prefix tree structure.

[0015] Optionally, after the step of storing the identity identifier and hash value on the blockchain and storing the identity information in the distributed database under the blockchain, further include:

[0016] Receive an identity information verification request sent by the user;

[0017] Verify the identity identifier and hash value in the blockchain according to the identity information included in the identity information verification request, compare the hash value stored on the blockchain with the hash value corresponding to the identity information stored under the blockchain to determine whether they are consistent, and output the verification result.

[0018] Optionally, after the step of storing the identity identifier and hash value on the blockchain and storing the identity information in the distributed database under the blockchain, further include:

[0019] Receive an identity information query request sent by the user;

[0020] Split the information contained in the identity information query request to obtain multiple split sub-questions;

[0021] Use the keywords in each sub-question to query in the blockchain respectively to obtain multiple storage nodes corresponding to the keywords;

[0022] Construct a sub-graph with variables according to the information contained in each sub-question, and use the constructed sub-graph to perform sub-graph matching on each storage node to obtain the query information matched by each sub-graph;

[0023] Take the intersection content between the query information matched in each sub-graph as the query result.

[0024] Optionally, the step of querying in the blockchain according to the identity information included in the identity information query request to obtain the query result further includes:

[0025] Verify the query information matched by each sub-graph to obtain a verifiable proof corresponding to the query result of each sub-graph;

[0026] Use a preset verifiable aggregation algorithm to verify the intersection content corresponding to each sub-graph to obtain a provable set corresponding to the intersection content, and synchronously return the query result and the provable set to the user.

[0027] Optionally, after the step of storing the identity identifier and the hash value on the blockchain and storing the identity information in a distributed database under the blockchain, the method further includes:

[0028] When receiving a user identity update request, obtaining new information of the user identity, encrypting the new information of the user identity and storing it in the distributed database under the blockchain, and saving version information of the user identity information in the blockchain.

[0029] In a second aspect, the present application discloses a blockchain-based digital identity management system, which includes:

[0030] An identity information receiving module, configured to receive the identity information of a user and encrypt the identity information to generate a unique identity identifier;

[0031] An information storage module, configured to store the identity identifier and the hash value on the blockchain, and store the identity information in a distributed database under the blockchain at the same time.

[0032] In a third aspect, the present application discloses an electronic device, where the electronic device includes a processor and a memory; a computer-readable program executable by the processor is stored on the memory; when the processor executes the computer-readable program, the blockchain-based digital identity management method as described above is implemented.

[0033] Beneficial effects: The present invention provides a blockchain-based digital identity management method, system and device. By receiving the identity information of a user, encrypting the identity information to generate a unique identity identifier, and storing the identity identifier and the hash value on the blockchain, and storing the identity information in a distributed database under the blockchain at the same time, the management of the user identity information is realized. The method of the present application combines the immutability and transparency of the blockchain and the method of storing identity information on-chain and off-chain respectively, while ensuring the security and privacy of the identity information, simplifies the update and management process of the identity information, and facilitates the quick access and query of the user identity information. Description of the Drawings

[0034] Figure 1 is a step flowchart of a blockchain-based digital identity management method provided by the present invention;

[0035] Figure 2 is a principle architecture diagram of the digital identity management method provided by the present invention;

[0036] Figure 3 is a schematic diagram of the principle of blockchain-based distributed identity query provided by the present invention;

[0037] Figure 4 It is a schematic diagram of the principle of identity information indexing and storage in a specific application embodiment provided by the present invention;

[0038] Figure 5 It is a block diagram of the principle of a blockchain-based digital identity management system provided by the present invention. Detailed implementation manners

[0039] To make the objectives, technical solutions and advantages of the present invention clearer and more definite, the following further describes the present invention in detail with reference to the accompanying drawings and by way of examples. It should be understood that the specific examples described herein are only used to explain the present invention and are not used to limit the present invention.

[0040] Since the distributed identity management systems in the prior art usually ensure the security and privacy of identity information through complex cryptography mechanisms. However, complex cryptography encrypts identity information through encryption algorithms to ensure the security of identity information. Therefore, a large amount of calculations often need to be performed during the management of identity information, and a large amount of calculations will generate more data information, which not only leads to a high computing cost but also requires a large storage cost. And relatively complex calculations may also lead to low identity verification efficiency, resulting in delays in the identity verification process and reducing the efficiency of the identity management system.

[0041] To overcome the above defects, this embodiment provides a blockchain-based digital identity management method, system and storage medium. By encrypting the user's identity information to generate a unique identity identifier, and storing the identity identifier and the hash value of the identity information on the blockchain, while storing the identity information in a distributed database under the blockchain, the storage cost is optimized and the data access speed is increased.

[0042] The following further describes in more detail a blockchain-based digital identity management method, system and storage medium provided by this embodiment with reference to the accompanying drawings.

[0043] In the first aspect, this embodiment discloses a blockchain-based digital identity management method, as Figure 1 shown, including:

[0044] Step S1: Receive the user's identity information and encrypt the identity information to generate a unique identity identifier.

[0045] The digital identity management method provided by this embodiment can be applied to the user identity information management system used by the identity issuing authority to realize storage, query, etc. of the user identity information stored in the system. The user's identity information includes: name, age, ID number, mobile phone number or facial features, etc.

[0046] The user submits personal identity information through the client of the identity information management system of the identity issuing agency to achieve user registration and the creation of identity information. The personal identity information input by the user is submitted to the server of the identity information management system through the client. Any server of the identity information management system can serve as a node of the blockchain, and each server serving as a node can receive the personal identity information submitted by the client and encrypt and store the received identity information.

[0047] Specifically, when any server of the identity issuing agency obtains the user's identity information, the obtained identity information is encrypted to generate a unique identity identifier. This identity identifier serves as the unique identifier of the user's identity information and can be stored on each node of the blockchain.

[0048] When encrypting the identity information, multiple encryption algorithms can be selected. For example, a unique identity identifier can be generated using the hash algorithm, or the symmetric encryption algorithm or the asymmetric encryption algorithm can also be selected. If the hash algorithm is used, the hash function can convert the identity information into a hash value. If the symmetric encryption algorithm or the asymmetric encryption algorithm is used, the encrypted identity information can be obtained. To ensure the security of the identity information, in this step, the hash algorithm is used to encrypt the identity information to generate a unique identity identifier, for example: SHA-256.

[0049] Step S2: Store the identity identifier and the hash value on the blockchain, and at the same time store the said identity information in the distributed database under the blockchain.

[0050] To improve the security of identity information storage, in this step, a hybrid storage method is adopted to save the identity information separately. First, the identity identifier and the hash value are stored on the blockchain. Based on the immutability of the information on the blockchain, the identity information is prevented from being tampered with. In addition, the identity information is stored in the distributed database, thereby optimizing the storage cost and improving the data access speed.

[0051] Furthermore, the step of storing the identity identifier and the hash value on the blockchain includes:

[0052] Step S21: When any node in the blockchain receives the user identity credential, verify the signature of the issuing party.

[0053] Combined Figure 2 As shown, the storage system on the identity issuing agency includes a blockchain, which contains multiple review nodes. The review nodes receive the user identity credential issued by the issuing party and verify the signature of the issuing party.

[0054] Step S22: Synchronize the user identity identifier, the hash value of the identity information, and the hash value of the identity credential that have passed the verification to other nodes in the blockchain for storage.

[0055] When the reviewer node successfully authenticates the signature of the issuer, on the one hand, store the user credential and identity information in the off-chain decentralized storage system, and on the other hand, synchronize the user identity identifier, the hash value of the identity information, and the hash value of the identity credential to other reviewer nodes in the blockchain. Store these three parts of information in the ledger of the blockchain.

[0056] Specifically, the step of storing the identity information in the distributed database under the blockchain includes:

[0057] Divide the identity information into target sensitive information and non-target sensitive information, and store the target sensitive information in ciphertext form and the non-target sensitive information in plaintext form in the distributed database under the blockchain.

[0058] When storing the identity information in the distributed database, first divide the identity information into two parts. One part is the encrypted and more sensitive target sensitive information, such as gender and age, and the other part is the non-target sensitive information other than the sensitive identity information, such as username, email, etc. In this step, dividing the identity information into target sensitive information and non-target sensitive information can be achieved by analyzing the importance of each piece of information, classifying the importance levels of each piece of information in the user information, taking the information with a high importance level as target sensitive information, and taking other identity information as non-target sensitive information. It is also possible to divide the identity information according to the attribute categories of each piece of information in the identity information, dividing the information into natural information, social information, family information, online identity information, etc. according to the nature of the information. It is also possible to divide the identity information according to the application scenarios, dividing the personal identity information into: personal basic profile information (such as name, birthday, age, gender, nationality, etc.), personal education and work information (such as education level, degree information, and work unit information, etc.). Then, based on the above information attributes or information types and the sensitivity or importance of the individual, divide the identity information into target sensitive information and non-target sensitive information.

[0059] After dividing the identity information into target sensitive information and non-target sensitive information, store the target sensitive information encrypted in the distributed database under the blockchain, and store the non-target sensitive information in plaintext form in the distributed database under the blockchain.

[0060] Since hybrid storage and a decentralized form are adopted in this step, the storage cost of identity information is optimized. Encryption processing is not required for non-target sensitive information. At the same time, when querying this part of information, it is not necessary to specify the encryption algorithm used, nor to decrypt it, thus improving the data access speed.

[0061] In this method, in order to better query user identity information and improve the query efficiency of identity information, when storing identity information, a digital identity index tree is established in the form of a Merkle prefix tree structure for the identity identifiers and hash values stored on the blockchain and the identity information stored in the distributed database under the blockchain.

[0062] The present invention uses the Merkle prefix tree structure, which not only supports efficient data integrity verification but also enables rapid incremental updates and queries. Due to the characteristics of the Merkle tree, any modification of a single data block will cause changes in the tree structure, ensuring the integrity and consistency of the data. The use of the prefix tree optimizes the rapid search for identity information, further enhancing the overall performance of the system.

[0063] Specifically, after the step of storing the identity identifier and hash value on the blockchain and storing the identity information in the distributed database under the blockchain, the following steps are further included:

[0064] Step S3: Receive an identity information verification request sent by the user; verify the identity identifier and hash value in the blockchain according to the identity information included in the identity information verification request, and compare the hash value stored on the blockchain with the hash value corresponding to the identity information stored under the blockchain to determine whether they are consistent, and output the verification result.

[0065] Calculate the hash value to be verified for the identity information included in the query result using a hash function; compare the hash value to be verified with the hash value stored on the blockchain to determine whether they are the same, and return the identity verification result.

[0066] Since in this method, after the identity information is stored separately in the distributed database on the blockchain and under the blockchain, when receiving an identity information verification request sent by the user, first verify the identity identifier and hash value in the blockchain according to the information corresponding to the identity information verification request, and then compare the identity information on the chain and under the chain, so as to return the verification result. Specifically, the hash value corresponding to the user's identity information is stored on the blockchain, and the identity information is stored under the blockchain. Therefore, the reviewer node calculates the hash value corresponding to the identity information under the blockchain using a hash function and compares the calculated hash value with the hash value stored on the blockchain. If they are consistent, it indicates that the identity information stored under the chain has not been tampered with, and the verification information is returned.

[0067] Further, as Figure 3 shown, the steps of querying in the blockchain according to the identity information included in the identity information query request to obtain a query result include:

[0068] Step S41: When receiving an identity information query request sent by a user, split the information included in the identity information query request to obtain multiple sub-questions after splitting.

[0069] When receiving an identity information query request sent by a user, divide the information included in the query request information into multiple small sub-questions, so as to locate the identity information keywords in the current query request information according to each sub-question.

[0070] Step S42: Respectively use the keywords in each sub-question to query in the blockchain to obtain multiple storage nodes corresponding to the keywords.

[0071] When obtaining each sub-question, use the keywords included in each sub-question to query identity information in the blockchain to obtain storage nodes corresponding to each keyword.

[0072] To achieve better information query efficiency, in this embodiment, an index structure based on a prefix tree is used for querying. The prefix tree can merge words with the same prefix into the same branch to reduce the size of the index. As Figure 4 shown, through the prefix "Alice", the storage node 1 storing personal information related to Alice can be found, and through the prefix "ABCDEF", the storage node 2 storing company information related to ABCDEF can be found. Similarly, the index based on the identity identifier can also be implemented with a prefix tree, except that the content of the prefix is replaced with an identity identifier symbol.

[0073] Step S43: Construct a sub-graph with variables according to the information included in each sub-question, and use the constructed sub-graph to perform sub-graph matching on each storage node to obtain the query information matched by each sub-graph.

[0074] When multiple storage nodes corresponding to the keywords of the sub-questions are queried, construct a sub-graph with variables according to the information in the sub-questions, and perform sub-graph matching between the sub-graph and the storage node information to find the query information matched by each sub-graph.

[0075] For example, when the user's query is "Who are Alice's friends who work at ABCDEF Company?", the user's query is split into two sub-questions: "Who are Alice's friends?" and "Who are the people who work at ABCDEF Company?". Then, the two keywords Alice and ABCDEF are used to find storage node 1 and storage node 2 from the off-chain distributed database respectively. In the entire relationship graph of storage node 1, a sub-graph with variables <Alice, friend,?who> is used for sub-graph matching to find Alice's friends. Similarly, in storage node 2, the people who work at ABCDEF are found.

[0076] Step S44: Use the intersection content between the query information matched in each sub-graph as the query result.

[0077] Use the intersection between the query information matched in each sub-graph as the query result corresponding to the current user identity information query request. For example: When the query information corresponding to the two sub-questions is obtained, take the intersection of the query information corresponding to these two sub-questions, and use the overlapping content as the query result for this time.

[0078] Combined with Figure 3 As shown, in the step of querying in the blockchain according to the identity information included in the identity information query request to obtain the query result, it further includes:

[0079] Verify the query information matched in each sub-graph to obtain a verifiable proof corresponding to the query result of each sub-graph; use a preset verifiable aggregation algorithm to verify the intersection content corresponding to each sub-graph to obtain a provable set corresponding to the intersection content, and synchronously return the query result and the provable set to the user.

[0080] To ensure that the above process of query information can be verified by the user, a verifiable set operation algorithm in cryptography can also be added in this step to generate a verifiable proof that the above steps correctly execute a proof set operation. Combined with Figure 3 As shown, after using the digital identity index tree to query each sub-graph matching problem at the blockchain node, a corresponding verifiable proof can be obtained for each sub-graph. The blockchain can use the verifiable aggregation algorithm to obtain the final identity information query result, and the blockchain can return the final identity information query result and the corresponding verifiable proof to the user.

[0081] Further, after the step of storing the identity identifier and the hash value on the blockchain and storing the identity information in the off-chain distributed database, it further includes:

[0082] When a user identity update request is received, obtain the new information of the user identity, encrypt the new information of the user identity and store it in the distributed database under the blockchain, and save the version information of the user identity information in the blockchain.

[0083] When it is necessary to update the user identity information stored on and under the blockchain, the new identity information of the user can be first updated and stored under the blockchain, and the corresponding version information is recorded on the blockchain, which simplifies the processes of re-signing and verification. The Merkle prefix tree adopted in this embodiment adds the hash values of the child nodes of each node to the prefix tree. For example, in node A, the hash values of node lice and nodes BCDEF are stored. If the content of a certain node is tampered with, the verifier will find that the recalculated hash value of node A does not match the previously stored hash value when recalculating the hash value of node A, proving that a certain child node of node A has been tampered with. The implementation process of the version control index is realized due to the append feature of the blockchain. When new data is added, the blockchain generates a new blockchain and appends it to the previous block. Each block contains a timestamp and an index structure corresponding to the timestamp. Therefore, the block where the index structure of the previous version is located can be found through the timestamp for traceable query.

[0084] The method provided by the present invention innovatively combines blockchain technology with a hybrid storage mechanism, effectively solving problems such as high costs, inefficient verification, and insufficient user control rights in traditional identity management systems. The immutability and transparency of the blockchain ensure the security and integrity of identity information, enhance user trust, and provide a solid foundation for high-demand industries such as finance and healthcare. At the same time, the hybrid storage mechanism reduces storage costs and speeds up data retrieval by storing key information on the chain and non-sensitive data off the chain. The efficient index structure makes the access and update of identity information rapid and convenient, improving the efficiency of identity verification.

[0085] Furthermore, the method of the present invention also simplifies the update process of identity information. Users can modify information independently, enhancing the control over personal data, reducing the dependence on centralized services, and lowering the risks of potential service interruptions and data leaks. The decentralized design enables users to freely transfer identity information between multiple platforms and enjoy a seamless service experience. Therefore, the present invention provides a secure, efficient, and user-friendly digital identity management solution by integrating blockchain technology with a hybrid storage mechanism, meeting the diverse needs of identity management in the modern digital society and enhancing the security and reliability of the overall system.

[0086] In a second aspect, the present application discloses a blockchain-based digital identity management system, as Figure 5 shown, including:

[0087] An identity information receiving module 510, configured to receive the user's identity information and encrypt the identity information to generate a unique identity identifier; its function is as described in step S1.

[0088] An information storage module, configured to store the identity identifier and the hash value on the blockchain, and at the same time store the identity information in a distributed database under the blockchain, and its function is as described in step S2.

[0089] The digital identity management method and system provided in this embodiment address the problems of storage and query efficiency in traditional identity management systems, and provide a new data storage method, a knowledge graph representation of identity information, and an efficient index design based on the Merkle prefix tree structure. The main contents of the system provided in this application include: a unique identifier of the user's identity information, a hash value of the identity information stored on the chain, non-sensitive identity information stored off-chain, the connection relationship between various identity information in the knowledge graph, the structured index information of the Merkle prefix tree, and the version control and update mechanism of the identity information. The method and system provided in this application not only enhance the security and privacy of identity information, but also significantly improve the efficiency of identity query and management.

[0090] In a third aspect, this application discloses an electronic device, where the electronic device includes a processor and a memory; a computer-readable program executable by the processor is stored on the memory; when the processor executes the computer-readable program, the digital identity management method based on the blockchain as described above is implemented.

[0091] The present invention provides a digital identity management method, system and device based on the blockchain. By receiving the user's identity information, encrypting the identity information to generate a unique identity identifier, and storing the identity identifier and the hash value on the blockchain, and at the same time storing the identity information in a distributed database under the blockchain, the management of the user's identity information is realized. The method of this application combines the immutability and transparency of the blockchain and the method of storing identity information on and under the blockchain respectively, while ensuring the security and privacy of the identity information, simplifies the update and management process of the identity information, and facilitates the quick access and query of the user's identity information.

[0092] Those skilled in the art will readily think of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include the common general knowledge or conventional technical means in the technical field not disclosed in this application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present invention are pointed out by the following claims.

[0093] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "examples", "specific examples", or "some examples", etc., mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or N embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0094] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable storage medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or in combination with these instruction execution systems, apparatus, or devices.

[0095] It should be understood that each part of this application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiment, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following technologies well known in the art can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application specific integrated circuits with suitable combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0096] It can be understood that the above embodiments are exemplary and should not be construed as limitations to this application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A digital identity management method based on blockchain, characterized in that: include: Receive the user's identity information and encrypt the identity information to generate a unique identity identifier; The identity identifier and hash value are stored on the blockchain, and the identity information is stored in a distributed database under the blockchain.

2. The blockchain-based digital identity management method according to claim 1, characterized in that: The steps to store the identifier and hash value on the blockchain include: When any node in the blockchain receives the user's identity certificate, it verifies the signature of the issuer; The successfully verified user identifier, the hash value of the identity information, and the hash value of the identity credential are synchronized to other nodes in the blockchain for storage.

3. The blockchain-based digital identity management method according to claim 1 is characterized in that: The step of storing the identity information in a distributed database under the blockchain includes: Separate identity information into target sensitive information and non-target sensitive information; The target sensitive information is stored in a ciphertext form and the non-target sensitive information is stored in a distributed database under the blockchain in a plaintext form.

4. The blockchain-based digital identity management method according to any one of claims 1 to 3, characterized in that: The identity identifier and hash value stored on the blockchain are combined with the identity information stored in the distributed database under the blockchain to establish a digital identity index tree in the form of a Merkle prefix tree structure.

5. The blockchain-based digital identity management method according to claim 3 is characterized in that: After the step of storing the identity identifier and the hash value on the blockchain and storing the identity information in a distributed database under the blockchain, the method further includes: Receive identity information verification request from the user; Verify the identity identifier and hash value in the blockchain according to the identity information contained in the identity information verification request, and compare the stored hash value on the blockchain with the hash value corresponding to the identity information stored under the blockchain to determine whether they are consistent, and output the verification result.

6. The blockchain-based digital identity management method according to claim 3 is characterized in that: After the step of storing the identity identifier and the hash value on the blockchain and storing the identity information in a distributed database under the blockchain, the method further includes: Receive identity information query requests from users; Split the information contained in the identity information query request to obtain multiple sub-questions; Use the keywords in each sub-question to query the blockchain and obtain multiple storage nodes corresponding to the keywords; Construct a subgraph with variables based on the information contained in each sub-question, use the constructed subgraph to perform subgraph matching on each storage node, and obtain the query information matched by each subgraph; The intersection of the query information matched in each subgraph is taken as the query result.

7. The blockchain-based digital identity management method according to claim 6 is characterized in that: The step of querying the blockchain according to the identity information included in the identity information query request to obtain the query result also includes: Verify the query information matched by each subgraph to obtain verifiable proof of the query results corresponding to each subgraph; The preset verifiable aggregation algorithm is used to verify the intersection contents corresponding to each subgraph, and a provable set corresponding to the intersection contents is obtained, and the query results and the provable set are synchronously returned to the user.

8. The blockchain-based digital identity management method according to claim 1, characterized in that: After the step of storing the identity identifier and the hash value on the blockchain and storing the identity information in a distributed database under the blockchain, the method further includes: When a user identity update request is received, the new information of the user identity is obtained, the new information of the user identity is encrypted and stored in the distributed database under the blockchain, and the version information of the user identity information is saved in the blockchain.

9. A digital identity management system based on blockchain, characterized in that: include: An identity information receiving module is used to receive the user's identity information and encrypt the identity information to generate a unique identity identifier; The information storage module is used to store the identity identifier and hash value on the blockchain, and store the identity information in a distributed database under the blockchain.

10. An electronic device, characterized in that: The electronic device includes a processor and a memory; the memory stores a computer-readable program that can be executed by the processor; when the processor executes the computer-readable program, the blockchain-based digital identity management method as described in any one of claims 1 to 8 is implemented.

Citation Information

Cited By

  • Distributed trusted data space construction method and system based on block chain

    CN120850266A