Electronic bill processing method and device and electronic equipment
Through the distributed digital identity authentication strategy, electronic bills are encrypted and signed, which solves the problem of low security in the centralized organization of electronic bill encryption dependence, and achieves higher security and credibility.
Patent Information
- Application Number
- CN202510385132.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the encryption of electronic receipts depends on centralized third-party institutions, with low security, high complexity of identity authentication and data integrity verification, and is susceptible to single point of failure.
The distributed digital identity authentication strategy is used to encrypt and sign electronic tickets, and the decentralized digital identity identification strategy is used to manage public and private keys through a distributed platform to achieve secure transmission and verification of data.
It improves the security of electronic receipts, reduces the risk of data leakage, enhances the confidentiality and integrity of the transmission process, avoids single point of failure, and ensures the immutability and credibility of data.
Smart Images

Figure CN120342664A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and in particular, to a method, apparatus, and electronic device for processing electronic bills. Background Art
[0002] With the wide application of electronic bills, the security issues in the transmission process have become increasingly prominent. In the related art, the electronic bill transmission method mainly relies on centralized identity authentication and data encryption mechanisms. In this mode, all data and information need to be processed and stored by one or more centralized servers, increasing the risk of data leakage. For example, once the centralized server is attacked or maliciously invaded, the electronic bill data stored therein may face the risk of being stolen, tampered with, or misused.
[0003] In addition, the electronic bill transmission method in the related art also faces the problems of identity authentication and data integrity verification. For example, in the transmission process of electronic bills, how to ensure the authenticity and credibility of the identities of the sender and the receiver, and ensure that the electronic bills are not tampered with or damaged during the transmission process are the keys to ensuring the legal effect and credibility of electronic bills. However, in the related art, the identity authentication and data encryption mechanisms generally rely on centralized authoritative institutions or third-party authentication services, which not only increases the complexity and cost of data transmission, but is also easily affected by single-point failures, thus reducing the reliability and stability of the entire system.
[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a method, apparatus, and electronic device for processing electronic bills, so as to at least solve the technical problem of low security in the related art that the encryption of electronic bills depends on a centralized third-party institution.
[0006] According to an aspect of an embodiment of the present invention, a method for processing an electronic bill is provided, including: a bill issuer receives a verifiable credential submitted by a bill receiver, and verifies the validity of the verifiable credential to obtain a verification result; in the case that the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated, where the initial electronic bill includes: an unencrypted electronic bill; the initial electronic bill is encrypted and signed by using a distributed digital identity authentication strategy to obtain a target electronic bill, where the distributed digital identity authentication strategy is a decentralized digital identity identification strategy.
[0007] Further, encrypting and signing the initial electronic bill using a distributed digital identity authentication strategy to obtain a target electronic bill, including: querying the public key of the bill recipient from a target distributed platform, where the target distributed platform includes: a distributed platform for managing target digital identity data, and the target digital identity data includes: the public key of the issuer of any electronic bill, the public key of the recipient of any electronic bill; encrypting the initial electronic bill based on the public key of the bill recipient to obtain an encrypted initial electronic bill; signing the encrypted initial electronic bill based on the private key of the bill issuer to obtain the target electronic bill.
[0008] Further, the target digital identity data further includes: a plurality of target documents, and the public key of the issuer of any electronic bill and the public key of the recipient of any electronic bill are recorded in one of the target documents. Querying the public key of the bill recipient from the target distributed platform includes: querying the target document associated with the bill recipient from the target distributed platform and querying the public key of the bill recipient in the target document.
[0009] Further, after encrypting and signing the initial electronic bill using a distributed digital identity authentication strategy to obtain a target electronic bill, it further includes: determining a transmission strategy, where the transmission strategy includes: a transmission strategy for transmitting the target electronic bill; in the case where the transmission strategy is a storage-based transmission strategy, uploading the target electronic bill to a target storage platform, generating an access identifier, and transmitting the access identifier to the bill recipient, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier is used to access the target electronic bill stored in the target storage platform; in the case where the transmission strategy is a peer-to-peer transmission strategy, transmitting the target electronic bill to the bill recipient.
[0010] According to another aspect of the embodiments of the present invention, a method for processing an electronic bill is provided, including: the bill recipient submitting a verifiable credential to the bill issuer, where the bill issuer is used to verify the validity of the verifiable credential to obtain a verification result, and in the case where the verification result indicates that the verifiable credential is valid, generating an initial electronic bill, and encrypting and signing the initial electronic bill using a distributed digital identity authentication strategy to obtain a target electronic bill, where the initial electronic bill includes: an unencrypted electronic bill; obtaining the target electronic bill, and using the distributed digital identity authentication strategy to verify the signature and decrypt the target electronic bill to obtain the initial electronic bill.
[0011] Further, verifying and decrypting the target electronic bill using the distributed digital identity authentication strategy to obtain the original electronic bill, including: querying the public key of the bill issuer from the target distributed platform, where the target distributed platform includes: a platform for managing target digital identity data, and the target digital identity data includes: the public key of any electronic bill issuer, the public key of any electronic bill recipient; verifying the target electronic bill based on the public key of the bill issuer to obtain the verified target electronic bill; decrypting the verified target electronic bill based on the private key of the bill recipient to obtain the original electronic bill.
[0012] Further, obtaining the target electronic bill includes: when the bill recipient receives the access identifier, obtaining the target electronic bill from the target storage platform based on the access identifier, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier includes: an identifier for accessing the target electronic bill in the target storage platform.
[0013] According to another aspect of the embodiments of the present invention, there is also provided a processing device for electronic bills, including: a first processing unit, configured to receive a verifiable credential submitted by a bill recipient by a bill issuer and verify the validity of the verifiable credential to obtain a verification result; a generating unit, configured to generate an original electronic bill when the verification result indicates that the verifiable credential is valid, where the original electronic bill includes: an unencrypted electronic bill; an encrypting unit, configured to encrypt and sign the original electronic bill using a distributed digital identity authentication strategy to obtain a target electronic bill, where the distributed digital identity authentication strategy is a decentralized digital identity identification strategy.
[0014] Further, the encrypting unit includes: a first querying subunit, configured to query the public key of the bill recipient from the target distributed platform, where the target distributed platform includes: a distributed platform for managing target digital identity data, and the target digital identity data includes: the public key of the issuer of any electronic bill, the public key of the recipient of any electronic bill; an encrypting subunit, configured to encrypt the original electronic bill based on the public key of the bill recipient to obtain the encrypted original electronic bill; a signing subunit, configured to sign the encrypted original electronic bill based on the private key of the bill issuer to obtain the target electronic bill.
[0015] Further, the target digital identity data further includes: a plurality of target documents, in which the public key of the issuer of any electronic bill and the public key of the recipient of any electronic bill are recorded in one of the target documents. The query subunit includes: a processing module, configured to query the target document associated with the bill recipient from the target distributed platform, and query the public key of the bill recipient in the target document.
[0016] Further, the processing device for electronic bills further includes: a determination unit, configured to determine a transmission policy after encrypting and signing the initial electronic bill by using a distributed digital identity authentication policy to obtain a target electronic bill, where the transmission policy includes: a transmission policy for transmitting the target electronic bill; a first transmission unit, configured to, when the transmission policy is a storage-based transmission policy, upload the target electronic bill to a target storage platform, generate an access identifier, and transmit the access identifier to the bill recipient, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier is used to access the target electronic bill stored in the target storage platform; a second transmission unit, configured to, when the transmission policy is a peer-to-peer transmission policy, transmit the target electronic bill to the bill recipient.
[0017] According to another aspect of the embodiments of the present invention, there is also provided a processing device for electronic bills, including: a submission unit, configured to submit a verifiable credential from a bill recipient to a bill issuer, where the bill issuer is configured to verify the validity of the verifiable credential to obtain a verification result, and generate an initial electronic bill when the verification result indicates that the verifiable credential is valid, and encrypt and sign the initial electronic bill by using a distributed digital identity authentication policy to obtain a target electronic bill, where the initial electronic bill includes: an unencrypted electronic bill; a second processing unit, configured to obtain the target electronic bill, and verify the signature and decrypt the target electronic bill by using the distributed digital identity authentication policy to obtain the initial electronic bill.
[0018] Further, the second processing unit includes: a second query subunit, configured to query the public key of the bill issuer from a target distributed platform, where the target distributed platform includes: a platform for managing target digital identity data, and the target digital identity data includes: the public key of any electronic bill issuer, the public key of any electronic bill recipient; a verification subunit, configured to verify the signature of the target electronic bill based on the public key of the bill issuer to obtain a target electronic bill after signature verification; a decryption subunit, configured to decrypt the target electronic bill after signature verification based on the private key of the bill recipient to obtain the initial electronic bill.
[0019] Further, the second processing unit includes: an obtaining subunit, configured to obtain the target electronic bill from a target storage platform based on the access identifier when the bill recipient receives the access identifier, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier includes: an identifier for accessing the target electronic bill in the target storage platform.
[0020] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, including: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the processing method of the electronic bill of any one of the above via executing the executable instructions.
[0021] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium storing a computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the processing method of the electronic bill of any one of the above.
[0022] In the present invention, the bill issuer receives the verifiable credential submitted by the bill recipient and verifies the validity of the verifiable credential to obtain a verification result; when the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated, where the initial electronic bill includes: an unencrypted electronic bill; the initial electronic bill is encrypted and signed by using a distributed digital identity authentication strategy, and the target electronic bill is obtained, where the distributed digital identity authentication strategy is a decentralized digital identity identification strategy. Furthermore, the technical problem in the related art that the encryption of the electronic bill depends on a centralized third-party institution and the security is low is solved. In the present invention, based on the decentralized distributed digital identity authentication strategy, the original electronic bill is encrypted and signed, avoiding the situation in the related art that the encryption of the electronic bill depends on a centralized third-party institution and the risk of data leakage is high, thereby achieving the technical effect of improving the security of the electronic bill. Description of the Drawings
[0023] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0024] Figure 1 is a flowchart of an alternative processing method of an electronic bill according to an embodiment of the present invention;
[0025] Figure 2 is a flowchart of another alternative processing method of an electronic bill according to an embodiment of the present invention;
[0026] Figure 3It is a schematic diagram of an optional electronic bill processing system according to an embodiment of the present invention;
[0027] Figure 4 It is a processing flow chart of an optional electronic bill processing system according to an embodiment of the present invention;
[0028] Figure 5 It is a schematic diagram of an optional electronic bill processing device according to an embodiment of the present invention;
[0029] Figure 6 It is a schematic diagram of another optional electronic bill processing device according to an embodiment of the present invention;
[0030] Figure 7 It is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed implementation manners
[0031] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] For the convenience of description, some terms related to the present invention are explained below.
[0034] Distributed digital identity: It refers to storing the user's identity information on a blockchain or a public content storage platform and protecting the user's privacy and security through encryption algorithms. Each user has a unique digital identity identifier, which can be used in different applications and networks to achieve cross-platform and cross-application identity authentication and management. The core components include a distributed digital identity identifier (DID) and a verifiable credential (VC).
[0035] Distributed Digital Identifier: Abbreviated as DID, it uniquely identifies a user's data identity, which corresponds to a DID Document.
[0036] Verifiable Credential: Abbreviated as VC, a verifiable credential is a digital certificate issued by an authoritative institution, used to record information such as the issuer, validity period, and proven attributes. The "zero-knowledge proof" technology is used to achieve data invisibility.
[0037] Blockchain: It is a decentralized distributed ledger technology, characterized by being tamper-proof, transparent, and secure. By packaging data into blocks to form a chain-like data structure, it ensures the security and consistency of data.
[0038] Digital Signature: It is an identity authentication technology based on the public key cryptosystem. It allows the sender of information to encrypt data using their own private key to generate a specific data string, i.e., the digital signature, to ensure the authenticity and integrity of the information source and prevent the information from being tampered with during transmission.
[0039] DID Resolver: The DID resolver is a software and / or hardware component that takes a DID as input and produces a compliant DID document as output to perform the DID resolution function.
[0040] DID Document: It can contain the public key of the DID holder, service endpoints, identity proofs, and other descriptive information. Through the DID Resolver, the public key of the DID holder can be obtained to encrypt data or verify signatures, the service endpoints can be obtained to establish communication, and other identity proof information can be checked to confirm the legitimacy and eligibility of the DID holder.
[0041] DID Domain: The DID domain name is used to provide a globally unique human-readable alias for the DID, usually following the domain name naming convention. The corresponding DID can be queried through the DID DOMAIN.
[0042] It should be noted that the user information (including but not limited to user device information, user personal information, etc.), collected information and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. And the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, all comply with the relevant laws, regulations, and standards of the relevant regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0043] Example 1
[0044] According to an embodiment of the present invention, there is provided a method embodiment of an optional method for processing electronic bills. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0045] Figure 1 is a flowchart of an optional method for processing electronic bills according to an embodiment of the present invention, as Figure 1 shown, the method includes the following steps:
[0046] Step S101, the bill issuer receives the verifiable credential submitted by the bill recipient, and verifies the validity of the verifiable credential to obtain a verification result.
[0047] The above bill issuer can be the object that issues electronic bills. The bill issuer can include but is not limited to: the system related to electronic bills in airlines. The above bill recipient can be the one who requests the bill issuer to issue an electronic bill. The verifiable credential submitted by the above bill recipient can be a verifiable credential (abbreviated as VC) issued to the bill recipient by using a distributed digital identity platform (which can be abbreviated as the target distributed platform in this embodiment) for verifying the identity of the bill recipient. In this embodiment, it is also possible to use the distributed digital identity platform to verify whether the verifiable credential of the bill recipient is valid to obtain a verification result.
[0048] Verifying the validity of the verifiable credential can include but is not limited to: (1) Identity verification, checking the identity information contained in the VC to confirm whether the bill recipient is a legitimate user and has the qualification to receive electronic bills; (2) VC integrity verification, using the digital signature in the VC for integrity check to ensure that the VC has not been tampered with or damaged during transmission; (3) VC source verification: The bill issuer will verify the issuing agency of the VC to confirm whether it is a legitimate and trustworthy issuer and whether the VC is within the validity period, etc.; (4) Attribute verification, checking the attribute information in the VC to confirm whether the recipient meets certain specific conditions or criteria (such as credit rating, account status, etc.).
[0049] Step S102, when the verification result indicates that the verifiable credential is valid, generate an initial electronic bill, where the initial electronic bill includes: an unencrypted electronic bill.
[0050] The types of the above initial electronic bills can include but are not limited to: electronic bills issued by airlines (for example, electronic itinerary receipts, electronic tickets, etc.), and can also be electronic bills issued by other institutions, which are not limited here.
[0051] When the above verification result indicates that the verifiable credential is valid, the bill issuer can issue an electronic bill to obtain an initial electronic bill. For example, the content of the electronic bill can be generated according to a preset business rule to obtain the initial electronic bill. Specifically, first, the necessary data information for the initial electronic bill to be generated can be collected. Then, based on the collected data information, the initial electronic bill is generated according to the business rule.
[0052] Step S103, encrypt and sign the initial electronic bill using a distributed digital identity authentication strategy to obtain a target electronic bill, where the distributed digital identity authentication strategy is a decentralized digital identity identification strategy.
[0053] To improve the security of the electronic bill during transmission, in this embodiment, a distributed digital identity technology (Decentralized Identifiers, DIDs) (i.e., the distributed digital identity authentication strategy) can be used to achieve the secure transmission of the electronic bill. DIDs is a decentralized digital identity identification technology that allows entities (such as individuals, organizations, or devices, etc.) to own and control their digital identities without relying on a centralized authority. Through the DID document, an entity can publicly disclose its public key, authentication information, and other service endpoints, so as to conduct secure communication and data exchange without revealing the private key. Through this decentralized identity authentication and data encryption mechanism, not only can the risk of data leakage be effectively reduced, but also the efficiency and credibility of data transmission can be improved.
[0054] In this embodiment, a distributed digital identity authentication strategy can be used to encrypt and sign the initial electronic bill to obtain a target electronic bill. For example, the public key of the bill recipient can be queried from a distributed digital identity platform (referred to as the target distributed platform), the initial electronic bill is encrypted using the public key of the bill recipient, and the encrypted initial electronic bill is signed using the private key of the bill issuer locally to obtain the target electronic bill.
[0055] It should be noted that in this embodiment, the public key of the bill recipient and the public key of the bill issuer can both be stored in the target distributed platform, while the private key of the bill recipient is only recorded locally by the bill recipient, and the private key of the bill issuer can also be only recorded locally by the bill issuer to avoid the situation of low data security due to the transmission of the private key over the network.
[0056] In this embodiment, through the above steps, the original electronic bill is encrypted and signed based on the decentralized distributed digital identity authentication strategy, avoiding the situation in related technologies where the encryption of electronic bills depends on a centralized third-party institution and the risk of data leakage is high, thereby achieving the technical effect of improving the security of electronic bills. Furthermore, it solves the technical problem in related technologies that the encryption of electronic bills depends on a centralized third-party institution and the security is low.
[0057] Optionally, encrypting and signing the initial electronic bill using the distributed digital identity authentication strategy to obtain the target electronic bill includes: querying the public key of the bill recipient from the target distributed platform, where the target distributed platform includes: a distributed platform for managing target digital identity data, and the target digital identity data includes: the public key of the issuer of any electronic bill, the public key of the recipient of any electronic bill; encrypting the initial electronic bill based on the public key of the bill recipient to obtain the encrypted initial electronic bill; signing the encrypted initial electronic bill based on the private key of the bill issuer to obtain the target electronic bill.
[0058] The above-mentioned target distributed platform can be responsible for storing and managing distributed identity data such as DID documents (recording public keys) and VCs (corresponding to target digital identity data), and providing services such as DID query and VC verification. The service content provided in this embodiment can include but is not limited to: (1) providing services such as DID registration, update, and query for electronic bill issuers and recipients (bill recipients); (2) storing and managing verifiable credentials (VCs), supporting operations such as VC issuance and verification; (3) providing implementations of encryption, signature, and verification algorithms based on DID to ensure the security of data transmission and storage.
[0059] Using the target distributed platform to manage the target digital identity data of the bill issuer and the bill recipient achieves the purpose of distributed management of the identity data of the bill issuer and the bill recipient, realizes the effect of owning and controlling one's own digital identity without relying on a centralized authoritative institution. Through the DID document, an entity can disclose its service endpoints such as public keys and authentication information, and the private key is stored locally, so as to conduct secure communication and data exchange without leaking the private key, effectively reducing the risk of data leakage.
[0060] In this embodiment, the public key of the bill recipient can be queried from the target distributed platform. After querying the public key of the bill recipient, the initial electronic bill can be encrypted using the public key of the bill recipient to ensure the confidentiality of data during transmission. Then, the encrypted initial electronic bill can be signed using the private key of the bill issuer to obtain the target electronic bill to ensure the integrity of the data and the authenticity of the source.
[0061] Optionally, the target digital identity data further includes: multiple target documents, where the public key of the issuer of any electronic bill and the public key of the recipient of any electronic bill are recorded in one of the target documents. Querying the public key of the bill recipient from the target distributed platform includes: querying the target document associated with the bill recipient from the target distributed platform and querying the public key of the bill recipient in the target document.
[0062] In this embodiment, the electronic bill is encrypted using the public key in the DID document (corresponding to the target document) of the bill recipient, and the encrypted data is signed using the private key of the bill issuer. For obtaining the public key of the bill recipient, its DID document can be queried through the DID domain name of the bill recipient to obtain the public key / certificate information.
[0063] Optionally, after encrypting and signing the initial electronic bill using the distributed digital identity authentication strategy to obtain the target electronic bill, it further includes: determining a transmission strategy, where the transmission strategy includes: a transmission strategy for transmitting the target electronic bill; in the case where the transmission strategy is a storage-based transmission strategy, uploading the target electronic bill to the target storage platform, generating an access identifier, and transmitting the access identifier to the bill recipient, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier is used to access the target electronic bill stored in the target storage platform; in the case where the transmission strategy is a peer-to-peer transmission strategy, transmitting the target electronic bill to the bill recipient.
[0064] For example, transmitting the encrypted and signed electronic bill data from the issuer to the recipient of the electronic bill, the optional transmission modes may include but are not limited to: peer-to-peer transmission (corresponding to the peer-to-peer transmission strategy), indirect transmission based on a public network storage device. Specifically, it may include:
[0065] (1) Decide whether to adopt the peer-to-peer transmission mode or the transmission mode based on public network storage according to the configuration or user selection.
[0066] (2) In the peer-to-peer transmission mode, the encrypted and signed electronic bill data (corresponding to the target electronic bill) can be directly sent to the bill recipient through the network.
[0067] (3) In the transmission mode based on public network storage (corresponding to storage-based transmission), the encrypted and signed electronic bill data is uploaded to the target storage platform. The target storage platform can be a public network storage device such as the InterPlanetary File System, blockchain network, etc., or a storage system of high-performance distributed object storage, or other distributed file systems, and a unique access identifier (for example, the hash value of the data of the target electronic bill) is generated and sent to the home party (corresponding to the bill recipient), and the target electronic bill is distributedly stored, which can avoid the loss of the target electronic bill.
[0068] Utilize the immutability of blockchain or distributed ledger technology to ensure that once the electronic bill is generated, its content cannot be changed, enhancing the credibility of the data.
[0069] In this embodiment, by adopting distributed digital identity technology and decentralized design, the risks of single-point failure and centralized data storage are avoided. Even if some nodes are attacked, the entire system can still operate normally, and the data security is greatly improved. By using public key encryption and private key signature technology, the confidentiality, integrity, and authenticity of the electronic bill during the transmission process are ensured, effectively preventing the data from being stolen or tampered with. Through the use of verifiable credentials (VC), strong authentication of user identities is achieved, ensuring that only legitimate users can participate in the process of issuing and receiving electronic bills, improving the security, efficiency, credibility, digital transformation, flexibility, and scalability of the electronic bill generation and transmission process.
[0070] Embodiment Two
[0071] According to an embodiment of the present invention, a method embodiment of an optional method for processing electronic bills is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0072] Figure 2 is a flowchart of another optional method for processing electronic bills according to an embodiment of the present invention. As Figure 2 shown, the method includes the following steps:
[0073] Step S201, the bill recipient submits a verifiable credential to the bill issuer. Among them, the bill issuer is used to verify the validity of the verifiable credential to obtain a verification result. In the case where the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated, and the initial electronic bill is encrypted and signed using a distributed digital identity authentication strategy to obtain a target electronic bill. Among them, the initial electronic bill includes: an unencrypted electronic bill.
[0074] The above-mentioned bill recipient may initiate a request to the bill issuer for issuing an electronic bill, and the request may carry a verifiable credential of the bill recipient.
[0075] The above-mentioned bill issuer may receive the VC (verifiable credential) submitted by the bill recipient, query the DID document corresponding to the recipient from the distributed digital identity service platform, confirm and verify the validity of the VC. If the VC verification passes, the bill issuer may generate the content of the electronic bill according to the preset business rules, obtain the initial electronic bill, and may also query the DID document of the bill recipient through the DID domain name of the bill recipient to obtain the public key / certificate information. Then, use the public key of the bill recipient obtained to encrypt the initial electronic bill to ensure the confidentiality of the data during the transmission process. After that, use the private key of the bill issuer to digitally sign the encrypted initial electronic bill to ensure the integrity of the data and the authenticity of the source. In this way, the target electronic bill is obtained.
[0076] Step S202, obtain the target electronic bill, and use the distributed digital identity authentication strategy to verify the signature and decrypt the target electronic bill to obtain the initial electronic bill.
[0077] The bill recipient may receive the encrypted and signed electronic bill data (i.e., the target electronic bill) from the bill issuer, perform decryption and signature verification to ensure the authenticity and integrity of the data, and thus obtain the original electronic bill content (corresponding to the initial electronic bill).
[0078] Through the above steps, in this embodiment, the original electronic bill is encrypted and signed based on the decentralized distributed digital identity authentication strategy, and the encrypted and signed electronic bill is verified for signature and decrypted using the decentralized distributed digital identity authentication strategy, avoiding the situation in the related technology where the encryption and decryption of the electronic bill rely on a centralized third-party institution and the risk of data leakage is high, thereby achieving the technical effect of improving the security of the electronic bill. Furthermore, it solves the technical problem in the related technology that the encryption and decryption of the electronic bill rely on a centralized third-party institution and the security is low.
[0079] Optionally, using the distributed digital identity authentication strategy to verify the signature and decrypt the target electronic bill to obtain the initial electronic bill includes: querying the public key of the bill issuer from the target distributed platform, where the target distributed platform includes: a platform for managing the target digital identity data, and the target digital identity data includes: the public key of any electronic bill issuer, the public key of any electronic bill recipient; verifying the signature of the target electronic bill based on the public key of the bill issuer to obtain the target electronic bill after signature verification; decrypting the target electronic bill after signature verification based on the private key of the bill recipient to obtain the initial electronic bill.
[0080] In this embodiment, it is possible to query / receive the encrypted and signed electronic bill data packet (including the target electronic bill) sent by the bill issuer, and then query its DID document through the DID domain name of the bill issuer to obtain the public key of the bill issuer for signature verification. After that, the public key of the bill issuer can be used to verify the signature in the target electronic bill to confirm that the data has not been tampered with and comes from a legitimate bill issuer. If the signature verification passes, the private key of itself can be used to decrypt the encrypted electronic bill data (corresponding to the target electronic bill after signature verification) to obtain the original electronic bill content and obtain the initial electronic bill.
[0081] Optionally, obtaining the target electronic bill includes: when the bill receiver receives the access identifier, obtaining the target electronic bill from the target storage platform based on the access identifier, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier includes: an identifier for accessing the target electronic bill in the target storage platform.
[0082] The above-mentioned target storage platform may include, but is not limited to, public network storage devices such as InterPlanetary File System, blockchain network, etc., may also be a storage system for high-performance distributed object storage, or may also be other distributed file systems.
[0083] For example, in the transmission mode of the target electronic bill based on public network storage (corresponding to storage-based transmission), the target electronic bill can be queried from the target storage platform according to the access identifier (for example, the hash value of the content of the target electronic bill).
[0084] In an alternative manner, in the transmission mode of the target electronic bill that is point-to-point, the bill receiver can directly receive the target electronic bill sent by the bill issuer.
[0085] In this embodiment, by adopting distributed digital identity technology and decentralized design, the risks of single-point failure and centralized data storage are avoided. Even if some nodes are attacked, the entire system can still operate normally, and the data security is greatly improved. By using public key encryption and private key signature technology, the confidentiality, integrity, and authenticity of the electronic bill during transmission are ensured, effectively preventing data from being stolen or tampered with. Through the use of verifiable credentials (VC), strong authentication of user identities is achieved, ensuring that only legitimate users can participate in the process of issuing and receiving electronic bills, improving the security, efficiency, credibility, digital transformation, flexibility, and scalability of the electronic bill generation and transmission process.
[0086] Embodiment Three
[0087] Embodiment 3 of the present invention provides an optional electronic bill processing system, which can be used to execute the electronic bill processing methods provided in Embodiment 1 and Embodiment 2. Figure 3 It is a schematic diagram of an optional electronic bill processing system according to an embodiment of the present invention, as Figure 3 shown. The processing system mainly consists of an issuer (corresponding to the bill issuer), a receiver (corresponding to the bill recipient), a storage platform (corresponding to the target storage platform), and a distributed digital identity service platform (corresponding to the target distributed platform), specifically as follows:
[0088] 1. Electronic bill issuance:
[0089] The electronic bill issuer (i.e., the bill issuer) is responsible for receiving the verifiable credential (VC) from the electronic bill owner (bill recipient), verifying its authenticity, and generating an electronic bill accordingly. The electronic bill issuance process is as follows:
[0090] (1) Receive the VC submitted by the electronic bill recipient, query the DID document corresponding to the bill recipient from the distributed digital identity service platform, and confirm and verify the validity of the VC.
[0091] (2) If the VC verification passes, generate the electronic bill content according to the business rules.
[0092] (3) Preprocess the generated electronic bill data to prepare for subsequent encryption and signature operations.
[0093] The electronic bill needs to be preprocessed (i.e., encrypted and signed) before being transmitted over the public network. The goal is to ensure the confidentiality and integrity of the electronic bill data during storage and transmission through encryption and signature.
[0094] Encrypt the electronic bill using the public key in the DID document of the bill recipient, and at the same time sign the encrypted data using the private key of the bill issuer. The specific process is as follows:
[0095] (1) Query the DID document through the DID domain name of the recipient (such as the unique identifier defined by the recipient in its DID document) to obtain the public key / certificate information.
[0096] (2) Use the obtained public key to encrypt the electronic bill data to ensure the confidentiality of the data during transmission.
[0097] (3) Use the private key of the issuer to digitally sign the encrypted electronic bill data to ensure the integrity and authenticity of the data source.
[0098] 2. Electronic bill transmission:
[0099] Transmit the encrypted and signed electronic bill data (corresponding to the target electronic bill) from the bill issuer to the recipient of the electronic bill. There are multiple optional transmission modes, such as: point-to-point transmission, indirect transmission based on a public network storage device. The specific process includes:
[0100] (1) According to the configuration or user selection, determine whether to adopt the point-to-point transmission mode or the transmission mode based on public network storage.
[0101] (2) In the point-to-point transmission mode, directly send the encrypted and signed electronic bill data to the recipient through the network.
[0102] (3) In the transmission mode based on public network storage, upload the encrypted and signed electronic bill data to a storage platform, such as the InterPlanetary File System (IPFS), blockchain network and other public network storage platforms, and generate a unique access identifier (such as a hash value) to send to the owner (bill recipient).
[0103] 3. Electronic bill verification:
[0104] Responsible for receiving the encrypted and signed electronic bill data from the bill issuer, decrypting and verifying the signature to ensure the authenticity and integrity of the data. The specific process includes:
[0105] (1) The bill recipient receives the encrypted and signed electronic bill data packet sent by the bill issuer.
[0106] (2) Query the DID document of the bill issuer through its DID domain name to obtain the public key information for signature verification.
[0107] (3) Use the obtained public key to verify the signature to confirm that the data has not been tampered with and comes from a legitimate bill issuer.
[0108] (4) If the signature verification passes, use its own private key to decrypt the encrypted electronic bill data to obtain the original electronic bill content.
[0109] 4. Distributed digital identity service platform (corresponding to the target distributed platform):
[0110] As the support platform of the entire system, it can be responsible for storing and managing distributed identity data such as DID documents and VCs, and providing core services such as DID query and VC verification. In this embodiment, this platform can be used for: (1) providing services such as DID registration, update, and query for electronic bill issuers and recipients; (2) storing and managing verifiable credentials (VCs), supporting operations such as VC issuance and verification; (3) providing implementations of encryption, signature, and verification algorithms based on DID to ensure the security of data transmission and storage.
[0111] Through this embodiment, the whole process of electronic bills from issuance to transmission and then to verification is digitized, secured, and optimized, effectively solving the problems of security, efficiency, and credibility existing in the electronic bill system in related technologies.
[0112] 5. Storage platform (corresponding to the target storage platform):
[0113] Provide electronic bill data storage services, which can be directly accessed by both bill issuers and bill recipients. Storage systems such as IPFS anonymous file system, blockchain, or distributed file system can be used.
[0114] Figure 4 It is a processing flow chart of an optional electronic bill processing system according to an embodiment of the present invention. The processing flow of this system will be described below in conjunction with Figure 4 The processing flow of this system will be described, and the specific process explanation is as follows:
[0115] (1) The electronic bill recipient (corresponding to the Figure 4 recipient in
[0116] ) can submit an identity credential VC to the issuer to prove their true identity. Figure 4
[0117] (2) The bill issuer (corresponding to the
[0118] issuer in
[0119] ) verifies the authenticity of the VC. If it passes, an electronic bill is generated. (3) The bill issuer queries the recipient's DID document through the recipient's DID domain name, obtains the public key / certificate, and encrypts the electronic bill using the public key.
[0120] (4) The bill issuer signs the encrypted electronic bill data with its own private key to ensure the confidentiality, integrity, and authenticity of the data. (5) The bill issuer can choose the network peer-to-peer transmission mode and directly transmit the encrypted electronic bill data and signature to the recipient. Figure 4
[0121] (6) Alternatively, the bill issuer stores the packaged electronic bill in a public network storage device (e.g., InterPlanetary File System, blockchain network), generates a unique access identifier, and sends it to the owner. The recipient uses the access identifier (corresponding to the
[0122] TOKEN in
[0123] ) to obtain the encrypted electronic bill data and signature from the public network storage device. (7) The recipient receives the packaged data and decompresses it. (8) Query the issuer's DID document through the issuer's DID domain name, obtain the public key / certificate, and verify the signature.(9) If the signature verification passes, the home party (i.e., the receiver) uses its own private key to decrypt the encrypted data to obtain the original data of the electronic bill.
[0124] The electronic bill processing system proposed in this embodiment can issue and transmit electronic bills based on distributed digital identity technology. Compared with the electronic bill issuing and transmitting methods in related technologies, it has the following advantages:
[0125] (1) By adopting distributed digital identity technology and a decentralized design, the risks of single-point failure and centralized data storage are avoided. Even if some nodes are attacked, the entire system can still operate normally, and data security is greatly improved; (2) Using public key encryption and private key signature technologies to ensure the confidentiality, integrity, and authenticity of electronic bills during transmission, effectively preventing data from being stolen or tampered with; (3) Through the use of verifiable credentials (VCs), strong authentication of user identities is achieved, ensuring that only legitimate users can participate in the process of issuing and receiving electronic bills; (4) Utilizing the immutability of blockchain or distributed ledger technology to ensure that once an electronic bill is generated, its content cannot be changed, enhancing the credibility of the data.
[0126] The electronic bill processing system proposed in this embodiment has significant advantages over the methods of issuing and transmitting electronic bills in related technologies in terms of security, efficiency, credibility, digital transformation, and flexibility and scalability.
[0127] Embodiment 4
[0128] Embodiment 4 of the present invention provides an optional electronic bill processing device, and each implementation unit in this processing device corresponds to each implementation step in Embodiment 1.
[0129] Figure 5 is a schematic diagram of an optional electronic bill processing device according to an embodiment of the present invention, as Figure 5 shown, including: a first processing unit 51, a generating unit 52, and an encrypting unit 53.
[0130] Among them, the first processing unit 51 is used for the bill issuer to receive the verifiable credential submitted by the bill receiver and verify the validity of the verifiable credential to obtain a verification result.
[0131] The generating unit 52 is used to generate an initial electronic bill when the verification result indicates that the verifiable credential is valid, where the initial electronic bill includes: an unencrypted electronic bill.
[0132] An encryption unit 53 is configured to encrypt and sign an initial electronic bill by using a distributed digital identity authentication policy to obtain a target electronic bill, where the distributed digital identity authentication policy is a decentralized digital identity identification policy.
[0133] In the device processing of the electronic bill provided in the fourth embodiment of the present invention, the first processing unit 51 can receive a verifiable credential submitted by a bill recipient through a bill issuer and verify the validity of the verifiable credential to obtain a verification result. When the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated by the generation unit 52. The initial electronic bill includes: an unencrypted electronic bill. The encryption unit 53 encrypts and signs the initial electronic bill by using a distributed digital identity authentication policy to obtain a target electronic bill, where the distributed digital identity authentication policy is a decentralized digital identity identification policy, thereby solving the technical problem in the related art that the encryption of the electronic bill depends on a centralized third-party institution and the security is low. In this embodiment, based on the decentralized distributed digital identity authentication policy, the original electronic bill is encrypted and signed, avoiding the situation in the related art that the encryption of the electronic bill depends on a centralized third-party institution and the risk of data leakage is high, thereby achieving the technical effect of improving the security of the electronic bill.
[0134] Optionally, in the device processing of the electronic bill provided in the fourth embodiment of the present invention, the encryption unit includes: a first query subunit, configured to query the public key of the bill recipient from a target distributed platform, where the target distributed platform includes: a distributed platform for managing target digital identity data, and the target digital identity data includes: the public key of the issuer of any electronic bill and the public key of the recipient of any electronic bill; an encryption subunit, configured to encrypt the initial electronic bill based on the public key of the bill recipient to obtain an encrypted initial electronic bill; a signature subunit, configured to sign the encrypted initial electronic bill based on the private key of the bill issuer to obtain a target electronic bill.
[0135] Optionally, in the device processing of the electronic bill provided in the fourth embodiment of the present invention, the target digital identity data further includes: a plurality of target documents, and the public key of the issuer of any electronic bill and the public key of the recipient of any electronic bill are recorded in one of the target documents. The query subunit includes: a processing module, configured to query the target document associated with the bill recipient from the target distributed platform and query the public key of the bill recipient in the target document.
[0136] Optionally, in the processing of the electronic bill device provided in the fourth embodiment of the present invention, the processing device of the electronic bill further includes: a determination unit, configured to determine a transmission policy after encrypting and signing the initial electronic bill using a distributed digital identity authentication policy to obtain a target electronic bill, where the transmission policy includes: a transmission policy for transmitting the target electronic bill; a first transmission unit, configured to upload the target electronic bill to a target storage platform and generate an access identifier and transmit the access identifier to the bill recipient when the transmission policy is a storage-type transmission policy, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier is used to access the target electronic bill stored in the target storage platform; a second transmission unit, configured to transmit the target electronic bill to the bill recipient when the transmission policy is a peer-to-peer transmission policy.
[0137] The above-mentioned processing device of the electronic bill may further include a processor and a memory. The above-mentioned first processing unit 51, generation unit 52, encryption unit 53, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.
[0138] The above-mentioned processor includes a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the original electronic bill is encrypted and signed based on the decentralized distributed digital identity authentication policy, avoiding the situation in the related technology where the encryption of the electronic bill depends on a centralized third-party institution and the risk of data leakage is high, thereby achieving the technical effect of improving the security of the electronic bill.
[0139] The above-mentioned memory may include non-permanent memory in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one memory chip.
[0140] Embodiment Five
[0141] The fifth embodiment of the present invention provides another optional processing device for electronic bills. Each implementation unit in this processing device corresponds to each implementation step in Embodiment Two.
[0142] Figure 6 It is a schematic diagram of an optional processing device for electronic bills according to an embodiment of the present invention, as Figure 6 shown, including: a submission unit 61 and a second processing unit 62.
[0143] Among them, the submission unit 61 is used for the bill receiver to submit a verifiable credential to the bill issuer. The bill issuer is used to verify the validity of the verifiable credential to obtain a verification result. When the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated, and the initial electronic bill is encrypted and signed using a distributed digital identity authentication strategy to obtain a target electronic bill. The initial electronic bill includes: an unencrypted electronic bill;
[0144] The second processing unit 62 is used to obtain the target electronic bill and verify and decrypt the target electronic bill using a distributed digital identity authentication strategy to obtain the initial electronic bill.
[0145] In the electronic bill processing device provided in Embodiment 5 of the present invention, the submission unit 61 can submit a verifiable credential to the bill issuer through the bill receiver. The bill issuer is used to verify the validity of the verifiable credential to obtain a verification result. When the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated, and the initial electronic bill is encrypted and signed using a distributed digital identity authentication strategy to obtain a target electronic bill. The initial electronic bill includes: an unencrypted electronic bill. The second processing unit 62 obtains the target electronic bill and verifies and decrypts the target electronic bill using a distributed digital identity authentication strategy to obtain the initial electronic bill, thereby solving the technical problem in the related art that the encryption and decryption of electronic bills rely on a centralized third-party institution and the security is low. In this embodiment, the original electronic bill is encrypted and signed based on a decentralized distributed digital identity authentication strategy, and the encrypted and signed electronic bill is verified and decrypted using a decentralized distributed digital identity authentication strategy, avoiding the situation in the related art that the encryption and decryption of electronic bills rely on a centralized third-party institution and the risk of data leakage is high, thereby achieving the technical effect of improving the security of electronic bills.
[0146] Optionally, in the electronic bill processing device provided in Embodiment 5 of the present invention, the second processing unit includes: a second query subunit, used to query the public key of the bill issuer from the target distributed platform, where the target distributed platform includes: a platform for managing target digital identity data, and the target digital identity data includes: the public key of any bill issuer and the public key of any bill receiver; a verification subunit, used to verify the signature of the target electronic bill based on the public key of the bill issuer to obtain the target electronic bill after signature verification; a decryption subunit, used to decrypt the target electronic bill after signature verification based on the private key of the bill receiver to obtain the initial electronic bill.
[0147] Optionally, in the electronic bill processing device provided in the fifth embodiment of the present invention, the second processing unit includes: an acquisition subunit, configured to, when the bill recipient receives an access identifier, obtain a target electronic bill from a target storage platform based on the access identifier, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier includes: an identifier for accessing the target electronic bill in the target storage platform.
[0148] The above-mentioned electronic bill processing device may further include a processor and a memory. The above-mentioned submission unit 61, second processing unit 62, etc. are all stored in the memory as program units, and the corresponding functions are implemented by the processor executing the above program units stored in the memory.
[0149] The above-mentioned processor includes a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set. By adjusting the kernel parameters, the original electronic bill is encrypted and signed based on the decentralized distributed digital identity authentication strategy, and the encrypted and signed electronic bill is verified and decrypted using the decentralized distributed digital identity authentication strategy, avoiding the situation in the related art where the encryption and decryption of electronic bills rely on a centralized third-party institution and the risk of data leakage is high, thereby achieving the technical effect of improving the security of electronic bills.
[0150] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0151] According to another aspect of the embodiments of the present invention, an electronic device is further provided, including: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the electronic bill processing method of any one of the above via executing the executable instructions.
[0152] According to another aspect of the embodiments of the present invention, a computer-readable storage medium is further provided. The computer-readable storage medium stores a computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the electronic bill processing method of any one of the above.
[0153] Figure 7 is a schematic diagram of an electronic device according to an embodiment of the present invention, as Figure 7 shown, the embodiments of the present invention provide an electronic device 70. The electronic device includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, it implements the electronic bill processing method of any one of the above.
[0154] The serial numbers of the above-described embodiments of the present invention are for description purposes only and do not represent the superiority or inferiority of the embodiments.
[0155] In the above embodiments of the present invention, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0156] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the units or modules can be in an electrical or other form.
[0157] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0158] In addition, the functional units in the various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0159] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs, etc., which can store program codes.
[0160] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for processing electronic bills, characterized in that, Including: The bill issuer receives the verifiable credential submitted by the bill recipient and verifies the validity of the verifiable credential to obtain a verification result. When the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated, where the initial electronic bill includes: an unencrypted electronic bill. The initial electronic bill is encrypted and signed using a distributed digital identity authentication strategy to obtain a target electronic bill, where the distributed digital identity authentication strategy is a decentralized digital identity identification strategy.
2. The processing method according to claim 1, wherein Using a distributed digital identity authentication strategy to encrypt and sign the initial electronic bill to obtain a target electronic bill includes: Query the public key of the bill recipient from the target distributed platform, where the target distributed platform includes: a distributed platform for managing target digital identity data, and the target digital identity data includes: the public key of the issuer of any electronic bill and the public key of the recipient of any electronic bill. Encrypt the initial electronic bill based on the public key of the bill recipient to obtain an encrypted initial electronic bill. Sign the encrypted initial electronic bill based on the private key of the bill issuer to obtain the target electronic bill.
3. The processing method according to claim 2, characterized in that The target digital identity data further includes: a plurality of target documents, and the public key of the issuer of any electronic bill and the public key of the recipient of any electronic bill are recorded in one of the target documents. Querying the public key of the bill recipient from the target distributed platform includes: Query the target document associated with the bill recipient from the target distributed platform and query the public key of the bill recipient in the target document.
4. The processing method according to claim 1, characterized in that After using a distributed digital identity authentication strategy to encrypt and sign the initial electronic bill to obtain a target electronic bill, it further includes: Determine a transmission strategy, where the transmission strategy includes: a transmission strategy for transmitting the target electronic bill. When the transmission strategy is a storage transmission strategy, upload the target electronic bill to the target storage platform, generate an access identifier, and transmit the access identifier to the bill recipient, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier is used to access the target electronic bill stored in the target storage platform. When the transmission strategy is a peer-to-peer transmission strategy, transmit the target electronic bill to the bill recipient.
5. A method for processing electronic bills, characterized in that, Including: The bill recipient submits a verifiable credential to the bill issuer, where the bill issuer is used to verify the validity of the verifiable credential to obtain a verification result. When the verification result indicates that the verifiable credential is valid, an initial electronic bill is generated, and the initial electronic bill is encrypted and signed using a distributed digital identity authentication strategy to obtain a target electronic bill, where the initial electronic bill includes: an unencrypted electronic bill. Obtain the target electronic bill and use the distributed digital identity authentication strategy to verify and decrypt the target electronic bill to obtain the initial electronic bill.
6. The processing method according to claim 5, characterized in that Verifying and decrypting the target electronic bill using the distributed digital identity authentication strategy to obtain the original electronic bill, including: Querying the public key of the bill issuer from the target distributed platform, where the target distributed platform includes: a platform for managing target digital identity data, and the target digital identity data includes: the public key of any electronic bill issuer and the public key of any electronic bill recipient; Verifying the signature of the target electronic bill based on the public key of the bill issuer to obtain the verified target electronic bill; Decrypting the verified target electronic bill based on the private key of the bill recipient to obtain the original electronic bill.
7. The processing method according to claim 5, characterized in that Obtaining the target electronic bill, including: When the bill recipient receives the access identifier, obtaining the target electronic bill from the target storage platform based on the access identifier, where the target storage platform includes at least one of the following: InterPlanetary File System, blockchain network, and the access identifier includes: an identifier for accessing the target electronic bill in the target storage platform.
8. An electronic bill processing device, characterized in that, Including: A first processing unit, configured to receive a verifiable credential submitted by a bill recipient by a bill issuer and verify the validity of the verifiable credential to obtain a verification result; A generating unit, configured to generate an original electronic bill when the verification result indicates that the verifiable credential is valid, where the original electronic bill includes: an unencrypted electronic bill; An encrypting unit, configured to encrypt and sign the original electronic bill using a distributed digital identity authentication strategy to obtain a target electronic bill, where the distributed digital identity authentication strategy is a decentralized digital identity identification strategy.
9. An electronic bill processing device, characterized in that, Including: A submitting unit, configured to submit a verifiable credential by a bill recipient to a bill issuer, where the bill issuer is configured to verify the validity of the verifiable credential to obtain a verification result, generate an original electronic bill when the verification result indicates that the verifiable credential is valid, and encrypt and sign the original electronic bill using a distributed digital identity authentication strategy to obtain a target electronic bill, where the original electronic bill includes: an unencrypted electronic bill; A second processing unit, configured to obtain the target electronic bill and verify and decrypt the target electronic bill using the distributed digital identity authentication strategy to obtain the original electronic bill.
10. An electronic device, characterized in that, Including: A memory, storing an executable program; A processor, configured to run the program, where when the program runs, it executes the method for processing an electronic bill according to any one of claims 1 to 7.