Verification method and device in block chain system, storage medium and program product

By introducing identity authentication contracts and authentication agency backend services into the blockchain system, and unified management of user authentication information, the problem of multiple off-chain interactions in the blockchain system is solved, and the security and accuracy of the business are improved.

CN120378078APending Publication Date: 2025-07-25TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410098158.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-24
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the blockchain system, different business parties need to interact multiple times off-chain when authenticating user identity, resulting in an increase in the number of interactions and the accuracy cannot be guaranteed, affecting business security.

Method used

Introduce authentication contracts and authentication agency backend services in the blockchain system, call business contracts through management components, use authentication contracts to query and store user authentication identity information in the blockchain, reduce off-chain interactions, and uniformly manage the authentication results of different authentication agencies.

Benefits of technology

It reduces the number of interactions between blockchain systems and off-chain services, and improves the security and accuracy of services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378078A_ABST
    Figure CN120378078A_ABST
Patent Text Reader

Abstract

The invention relates to a verification method and device in a block chain system, a storage medium and a program product, and relates to the technical field of block chains. The block chain system comprises a management component, an identity verification contract, at least one business contract and at least one authentication mechanism background service. The method comprises the following steps: sending a business call request to the business contract through the management component; sending an identity verification request to the identity verification contract through the business contract; querying first authentication identity information in the block chain based on the address of the first user through the identity verification contract; sending the first authentication identity information to the business contract through the identity verification contract; and performing identity verification on the first user based on the first authentication identity information through the business contract. According to the scheme, the number of times of interaction between the block chain system and the service under the chain is reduced, and the security of the service in the block chain system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of blockchain technology, and particularly to a verification method, device, storage medium and program product in a blockchain system. Background Art

[0002] A blockchain system is a system composed of multiple blockchain nodes belonging to different interested parties. Business parties can deploy business contracts in the blockchain system to provide relevant business services for the users of the blockchain system.

[0003] Based on policy or security requirements, before a business party provides business services to a user through a business contract, it may be necessary to authenticate the user. In related technologies, when a user in a blockchain system initiates a transaction to call a business contract, the business party first authenticates the user through an off-chain identity verification service. In the case of successful identity verification, the business contract continues to execute the above transaction in the blockchain system.

[0004] However, the above solution requires business parties to implement identity verification outside the blockchain respectively. Each time different business parties perform verification, they need to call the identity verification service off-chain. The number of interactions between the blockchain system and the off-chain service is relatively large, and the accuracy of off-chain identity verification cannot be guaranteed, which affects the security of the business in the blockchain system. Summary of the Invention

[0005] Embodiments of this application provide a verification method, device, storage medium and program product in a blockchain system, which can simplify the complexity of the network architecture and improve the security of the business in the blockchain system. The technical solution is as follows:

[0006] On the one hand, a verification method in a blockchain system is provided. The blockchain system includes a management component, an identity verification contract, at least one business contract, and at least one certification authority background service. The method includes:

[0007] In response to a first user calling the business contract through the management component, sending a business call request to the business contract through the management component, where the business call request includes the address of the first user;

[0008] Sending an identity verification request to the identity verification contract through the business contract, where the identity verification request includes the address of the first user;

[0009] Query the first authentication identity information in the blockchain based on the address of the first user through the authentication contract; the first authentication identity information is the information requested by the background service of the authentication institution to be stored in the blockchain by the authentication contract after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user.

[0010] In response to the authentication contract querying the first authentication identity information, send the first authentication identity information to the business contract through the authentication contract.

[0011] Authenticate the first user based on the first authentication identity information through the business contract.

[0012] On the other hand, a verification method in a blockchain system is provided. The blockchain system includes a management component, an authentication contract, at least one business contract, and at least one background service of an authentication institution. The method includes:

[0013] Receive the authentication request sent by the business contract through the authentication contract. The authentication request is sent by the business contract when receiving the service call request sent by the management component; the authentication request is used to authenticate the first user, and the address of the first user is included in the authentication request.

[0014] Query the first authentication identity information in the blockchain based on the address of the first user through the authentication contract; the first authentication identity information is the information requested by the background service of the authentication institution to be stored in the blockchain by the authentication contract after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user.

[0015] In response to the authentication contract querying the first authentication identity information, send the first authentication identity information to the business contract through the authentication contract so that the business contract can authenticate the first user based on the first authentication identity information.

[0016] On the other hand, a verification method in a blockchain system is provided. The blockchain system includes a management component, an authentication contract, at least one business contract, and at least one background service of an authentication institution. The method includes:

[0017] Receive the identity authentication request sent by the management component through the background service of the authentication institution. The identity authentication request includes the address of the first user and the identity information of the first user.

[0018] Verify the identity information of the first user offline through the background service of the certification authority;

[0019] In response to the identity information of the first user passing the offline verification, generate first authentication identity information based on the identity information of the first user through the background service of the certification authority;

[0020] Through the background service of the certification authority, request the identity verification contract to store the address of the first user and the first authentication identity information in the blockchain in a corresponding manner, so that when the identity verification contract receives the identity verification request sent by the business contract, query the first authentication identity information in the blockchain based on the address of the first user included in the identity verification request, and send the first authentication identity information to the business contract, so that the business contract can authenticate the identity of the first user based on the first authentication identity information; the identity verification request is sent by the business contract when it receives the service call request sent by the management component; the identity verification request is used to authenticate the identity of the first user, and the address of the first user is included in the identity verification request.

[0021] On the other hand, a verification method in a blockchain system is provided. The blockchain system includes a management component, an identity verification contract, at least one business contract, and at least one background service of a certification authority. The method includes:

[0022] Receive the service call request sent by the management component through the business contract. The service call request includes the address of the first user and the identity information of the first user; the service call request is sent by the management component when the first user calls the business contract through the management component;

[0023] Send an identity verification request to the identity verification contract through the business contract. The identity verification request includes the address of the first user, so that the identity verification contract can query the first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is the information stored in the blockchain by the identity verification contract at the request of the background service of the certification authority after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user.

[0024] In response to receiving the first authentication identity information sent by the identity verification contract through the business contract, authenticate the identity of the first user based on the first authentication identity information through the business contract.

[0025] On the other hand, a verification method in a blockchain system is provided. The blockchain system includes a management component, an identity verification contract, at least one business contract, and at least one certification authority background service. The method includes:

[0026] Receiving, by the management component, an operation of a first user invoking the business contract;

[0027] Sending, by the management component, a business call request to the business contract. The business call request includes the address of the first user and the identity information of the first user, so that the business contract sends an identity verification request including the address of the first user to the identity verification contract, enabling the identity verification contract to query first authentication identity information in the blockchain based on the address of the first user, and in response to querying the first authentication identity information, sending the first authentication identity information to the business contract, so that the business contract authenticates the first user based on the first authentication identity information; the first authentication identity information is information requested by the certification authority background service to be stored in the blockchain by the identity verification contract after successfully authenticating the first user; the first authentication identity information is used to indicate the identity of the first user.

[0028] On the further hand, a verification device in a blockchain system is provided. The blockchain system includes a management component, an identity verification contract, at least one business contract, and at least one certification authority background service. The device includes:

[0029] An identity verification request receiving module, configured to receive, by the identity verification contract, the identity verification request sent by the business contract. The identity verification request is sent by the business contract when receiving the business call request sent by the management component; the identity verification request is used to authenticate the first user, and the identity verification request includes the address of the first user;

[0030] A query module, configured to query, by the identity verification contract, first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is information requested by the certification authority background service to be stored in the blockchain by the identity verification contract after successfully authenticating the first user; the first authentication identity information is used to indicate the identity of the first user;

[0031] An authentication identity information sending module, configured to, in response to the identity verification contract querying the first authentication identity information, send the first authentication identity information to the business contract through the identity verification contract, so that the business contract authenticates the first user based on the first authentication identity information.

[0032] On the other hand, a verification device in a blockchain system is provided. The blockchain system includes a management component, an identity verification contract, at least one business contract, and at least one certification authority back-end service. The device includes:

[0033] An identity authentication request receiving module, configured to receive, through the certification authority back-end service, an identity authentication request sent by the management component. The identity authentication request includes the address of the first user and the identity information of the first user.

[0034] An offline verification module, configured to perform offline verification on the identity information of the first user through the certification authority back-end service.

[0035] An authenticated identity information generation module, configured to, in response to the identity information of the first user passing the offline verification, generate first authenticated identity information based on the identity information of the first user through the certification authority back-end service.

[0036] A storage module, configured to, through the certification authority back-end service, request the identity verification contract to store the address of the first user and the first authenticated identity information in the blockchain in a corresponding manner, so that when the identity verification contract receives an identity verification request sent by the business contract, it queries the first authenticated identity information in the blockchain based on the address of the first user included in the identity verification request, and sends the first authenticated identity information to the business contract, so that the business contract can perform identity verification on the first user based on the first authenticated identity information. The identity verification request is sent by the business contract when it receives a service call request sent by the management component. The identity verification request is used to perform identity verification on the first user, and the identity verification request includes the address of the first user.

[0037] On the other hand, a verification device in a blockchain system is provided. The blockchain system includes a management component, an identity verification contract, at least one business contract, and at least one certification authority back-end service. The device includes:

[0038] A service call request receiving module, configured to receive, through the business contract, a service call request sent by the management component. The service call request includes the address of the first user and the identity information of the first user. The service call request is sent by the management component when the first user calls the business contract through the management component.

[0039] An authentication request sending module, configured to send an authentication request to the authentication contract through the service contract, where the authentication request includes the address of the first user, so that the authentication contract queries first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is information requested by the authentication agency background service to be stored in the blockchain in the authentication contract after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user.

[0040] An authentication module, configured to, in response to receiving the first authentication identity information sent by the authentication contract through the service contract, authenticate the identity of the first user through the service contract based on the first authentication identity information.

[0041] On the other hand, a verification device in a blockchain system is provided. The blockchain system includes a management component, an authentication contract, at least one service contract, and at least one authentication agency background service. The device includes:

[0042] An instruction receiving module, configured to receive an instruction for the first user to call the service contract through the management component.

[0043] A service call request sending module, configured to send a service call request to the service contract through the management component. The service call request includes the address of the first user and the identity information of the first user, so that the service contract sends an authentication request including the address of the first user to the authentication contract, causing the authentication contract to query first authentication identity information in the blockchain based on the address of the first user, and in response to querying the first authentication identity information, sending the first authentication identity information to the service contract, so that the service contract authenticates the identity of the first user based on the first authentication identity information; the first authentication identity information is information requested by the authentication agency background service to be stored in the blockchain in the authentication contract after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user.

[0044] On the other hand, a computer device is provided. The computer device includes a processor and a memory. The memory stores at least one computer program, and the at least one computer program is loaded and executed by the processor to implement the verification method in the above blockchain system.

[0045] On the other hand, a computer-readable storage medium is provided, in which at least one computer program is stored. The computer program is loaded and executed by a processor to implement the authentication method in the above blockchain system.

[0046] On the other hand, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the authentication method in the blockchain system provided in the above various optional implementation manners.

[0047] The technical solution provided by this application may include the following beneficial effects:

[0048] In the blockchain system, an identity authentication contract is set up. Each user identity authentication party can set up an authentication agency background service in the blockchain system respectively. After the authentication agency background server successfully authenticates the user, it can request the identity authentication contract to store the user's authenticated identity information in the blockchain. Subsequently, when the user calls the business contract through the management component, the business contract can send an identity authentication request containing the user's address to the identity authentication contract based on the address of the user carried in the service call request. The identity authentication contract queries the corresponding authenticated identity information in the blockchain based on the user's address and returns it to the business contract. The business contract can authenticate the user according to the authenticated identity information. In the above process, after the authentication agency background server authenticates the user once, it can store the user's authenticated identity information in the blockchain through the identity authentication contract, and the identity authentication contract can uniformly manage the authenticated identity information obtained by different authentication agency background servers and respond to the identity authentication requests of different business contracts, and feedback the requested authenticated identity information to different business contracts. That is to say, when different business contracts authenticate the user respectively later, they do not need to verify off-chain separately, but all obtain the authenticated identity information in the blockchain through the unified identity authentication contract, reducing the number of interactions between the blockchain system and off-chain services and improving the security of the services in the blockchain system. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The accompanying drawings here are incorporated into the specification and form a part of the specification, showing embodiments consistent with this application and used together with the specification to explain the principles of this application.

[0050] Figure 1 is an optional structural schematic diagram of the blockchain system provided by the embodiment of this application;

[0051] Figure 2It is an optional schematic diagram of the block structure provided by the embodiments of the present application;

[0052] Figure 3 It is a schematic diagram of the architecture of a blockchain system related to the present application;

[0053] Figure 4 It is a flowchart of the verification method in the blockchain system shown in an exemplary embodiment of the present application;

[0054] Figure 5 It is a flowchart of the verification method in the blockchain system shown in an exemplary embodiment of the present application;

[0055] Figure 6 It is a flowchart of the verification method in the blockchain system shown in an exemplary embodiment of the present application;

[0056] Figure 7 It is an architecture diagram of the supervision of decentralized applications related to the present application;

[0057] Figure 8 It is a flowchart of the supervision of decentralized applications related to the present application;

[0058] Figure 9 It is a framework diagram of identity authentication in a blockchain system related to the present application;

[0059] Figure 10 It is a block diagram of the verification device in the blockchain system shown in an exemplary embodiment of the present application;

[0060] Figure 11 It is a block diagram of the verification device in the blockchain system shown in an exemplary embodiment of the present application;

[0061] Figure 12 It is a block diagram of the verification device in the blockchain system shown in an exemplary embodiment of the present application;

[0062] Figure 13 It is a block diagram of the verification device in the blockchain system shown in an exemplary embodiment of the present application;

[0063] Figure 14 It shows the block diagram of the computer device shown in an exemplary embodiment of the present application. Detailed implementation manners

[0064] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0065] It should be understood that the term "plurality" as used herein refers to two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0066] For ease of understanding, several terms related to the present application are explained below.

[0067] 1. Blockchain system

[0068] It refers to a blockchain network system formed by establishing peer-to-peer connections among multiple blockchain nodes.

[0069] Specifically, for example, the blockchain system involved in the embodiments of the present application can be formed by connecting a client and multiple nodes (any form of computing device accessing the network, such as a server, user terminal) through network communication.

[0070] See Figure 1 , Figure 1 is an optional structural schematic diagram of the blockchain system 100 provided by the embodiments of the present application, formed by multiple nodes 200 (any form of computing device accessing the network, such as a server, user terminal) and a client 300. A peer-to-peer network is formed among the nodes, and the peer-to-peer protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In the blockchain system, any machine such as a server or terminal can join and become a node, and the node includes a hardware layer, an intermediate layer, an operating system layer, and an application layer.

[0071] See Figure 1 for the functions of each node in the blockchain system shown, and the functions involved include:

[0072] 1) Routing, a basic function of a node, used to support communication between nodes.

[0073] In addition to the routing function, a node can also have the following functions:

[0074] 2) An application, which is used to be deployed in a blockchain, implements specific business according to actual business requirements, records data related to the implemented functions to form recorded data, carries a digital signature in the recorded data to indicate the source of the task data, and sends the recorded data to other nodes in the blockchain system. When other nodes verify the source and integrity of the recorded data successfully, they add the recorded data to a temporary block.

[0075] For example, the businesses implemented by the application include:

[0076] 2.1) A management component, which can be used to manage the blockchain addresses and resources of each user in the blockchain system. For example, it can be used to provide a function for resource transactions, including initiating a transaction, that is, sending the transaction record of the current transaction to other nodes in the blockchain system. After other nodes verify successfully, as a response to acknowledging the validity of the transaction, they deposit the recorded data of the transaction into the temporary block of the blockchain. Of course, the management component also supports querying the remaining resources in the address.

[0077] 2.2) A shared ledger, which is used to provide functions such as storing, querying, and modifying account data. It sends the recorded data of the operations on the account data to other nodes in the blockchain system. After other nodes verify its validity, as a response to acknowledging the validity of the account data, they deposit the recorded data into the temporary block, and can also send a confirmation to the node that initiated the operation.

[0078] 2.3) A smart contract, which is a computerized protocol that can execute the terms of a certain contract. It is implemented by code deployed on the shared ledger and executed when certain conditions are met. According to actual business requirements, the code is used to complete automated transactions. For example, querying the logistics status of the goods purchased by the buyer and transferring the buyer's resources to the merchant's address after the buyer signs for the goods. Of course, smart contracts are not limited to executing contracts for transactions, but can also execute contracts for processing received information.

[0079] 3) A blockchain includes a series of blocks (Blocks) that are sequentially connected in the order of generation. Once a new block is added to the blockchain, it will not be removed again. The block records the recorded data submitted by nodes in the blockchain system.

[0080] See Figure 2 , Figure 2It is an optional schematic diagram of the block structure provided by the embodiments of the present application. Each block includes the hash value of the transaction records stored in this block (the hash value of this block) and the hash value of the previous block. Each block is connected through the hash value to form a blockchain. In addition, the block may also include information such as the timestamp when the block is generated. A blockchain, essentially a decentralized database, is a series of data blocks generated by using cryptographic methods. Each data block contains relevant information for verifying the validity of its information (anti-counterfeiting) and generating the next block.

[0081] 2. Blockchain Nodes

[0082] Servers running blockchain programs form a peer-to-peer network with each other, run a consensus mechanism, and participate in block production or voting to maintain the growth of the blockchain ledger.

[0083] 3. System Contracts

[0084] Different from the smart contracts deployed by users, system contracts are smart contracts built into the blockchain system.

[0085] 4. Transactions

[0086] A transaction refers to the transfer of an asset, contract, or data between users in a blockchain system. It can be used to transfer resources and assets between users or execute the business logic encoded in a smart contract. A transaction involves information such as the sender, receiver, and the quantity transferred, and it contains a signature, a timestamp, and data required for cross-chain transfer, such as an address, a transaction type, and the address of the asset owner, etc.

[0087] 5. System Transactions

[0088] Different from ordinary transactions initiated by users, system transactions are transactions initiated by the blockchain system and invoking system contracts.

[0089] Please refer to Figure 3 which shows a schematic diagram of the architecture of a blockchain system involved in the present application. As Figure 3 shown, the above blockchain system includes a management component 310, an identity authentication contract 320, at least one business contract 330, and at least one authentication agency back-end service 340.

[0090] Among them, two or more of the above-mentioned management component 310, identity authentication contract 320, business contract 330, and certification authority background service 340 can run simultaneously on a blockchain node device; for example, the above-mentioned management component 310, identity authentication contract 320, and business contract 330 can run simultaneously on a blockchain node device, and the management component 310, identity authentication contract 320, business contract 330, and certification authority background service 340 can run simultaneously on another blockchain node device. Alternatively, the above-mentioned management component 310, identity authentication contract 320, business contract 330, and certification authority background service 340 can run on different blockchain node devices respectively.

[0091] Or rather, the above-mentioned management component 310 runs on the first blockchain node device, the above-mentioned identity authentication contract 320 runs on the second blockchain node device, the above-mentioned business contract 330 runs on the third blockchain node device, and the above-mentioned certification authority background service 340 runs on the fourth blockchain node device. The first blockchain node device, the second blockchain node device, the third blockchain node device, and the fourth blockchain node device can be different physical devices respectively; or, the above-mentioned certification authority background service 340 runs on the fourth blockchain node device. Two or more of the first blockchain node device, the second blockchain node device, the third blockchain node device, and the fourth blockchain node device can be implemented as the same physical device.

[0092] Among them, the above-mentioned management component 310 is also called the management component, which can be used to manage virtual assets such as the addresses (also called blockchain addresses) of each user in the blockchain system and virtual resources; the above-mentioned management component 310 can also initiate transactions in the blockchain system.

[0093] The above-mentioned certification authority background service 340 can provide identity authentication services to users. After the identity of a user is authenticated by the certification authority background service 340, the certification authority background service 340 can generate the authentication identity information of the user and store the authentication identity information of the user on the chain through the identity authentication contract 320. Among them, different certification authority background services 340 can call the same identity authentication contract 320 to store the generated authentication identity information on the chain respectively; correspondingly, the above-mentioned identity authentication contract 320 uniformly stores the authentication identity information generated by multiple different certification authority background services 340 on the chain.

[0094] The above authentication contract 320 is a smart contract for authenticating users. The authentication contract 320 can be called by at least one authentication agency background service 340 to store the authentication identity information generated after the authentication by the authentication agency background service 340 into the blockchain. The authentication contract 320 can also be called by at least one business contract 330 to query the authentication identity information stored in the blockchain and return the queried authentication identity information to the business contract 330.

[0095] The above business contract 330 can provide business services to users in the blockchain system. Before providing business services to users in the blockchain system, the business contract 330 can call the authentication contract 320 to obtain the authentication identity information of the user for user authentication. Among them, different business contracts 330 can call the same authentication contract 320 to obtain the authentication identity information of their respective corresponding users. Correspondingly, the above authentication contract 320 respectively feedbacks the authentication identity information of the corresponding users to multiple different business contracts 330.

[0096] In the embodiment of the present application, for the blockchain node device running the above authentication contract, during the process that a user calls a business contract and the business contract authenticates the user, the following operations can be performed:

[0097] Step A1, through the authentication contract, receive the authentication request sent by the business contract. The authentication request is sent by the business contract when receiving the business call request sent by the management component. The authentication request is used to authenticate the first user, and the address of the first user is included in the authentication request.

[0098] Step A2, through the authentication contract, query the first authentication identity information in the blockchain based on the address of the first user. The first authentication identity information is the information that the authentication agency background service requests the authentication contract to store in the blockchain after successfully authenticating the first user. The first authentication identity information is used to indicate the identity of the first user.

[0099] Step A3, in response to the authentication contract querying the first authentication identity information, send the first authentication identity information to the business contract through the authentication contract so that the business contract authenticates the first user based on the first authentication identity information.

[0100] In the embodiment of the present application, for the blockchain node device running the above authentication agency background service, during the process that a user calls a business contract and the business contract authenticates the user, the following operations can be performed:

[0101] Step B1: Receive, through the back-end service of the certification authority, the identity authentication request sent by the management component. The identity authentication request includes the address of the first user and the identity information of the first user.

[0102] Step B2: Conduct offline verification of the identity information of the first user through the back-end service of the certification authority.

[0103] Step B3: In response to the identity information of the first user passing the offline verification, generate the first authentication identity information based on the identity information of the first user through the back-end service of the certification authority.

[0104] Step B4: Through the back-end service of the certification authority, request the identity verification contract to store the address of the first user and the first authentication identity information in the blockchain in a corresponding manner. When the identity verification contract receives the identity verification request sent by the business contract, query the first authentication identity information in the blockchain based on the address of the first user included in the identity verification request, and send the first authentication identity information to the business contract, so that the business contract can authenticate the first user based on the first authentication identity information. The identity verification request is sent by the business contract when it receives the business call request sent by the management component. The identity verification request is used to authenticate the first user, and the address of the first user is included in the identity verification request.

[0105] In the embodiment of the present application, for the blockchain node device running the above business contract, during the process where the user calls the business contract and the business contract authenticates the user, the following operations can be performed:

[0106] Step C1: Receive, through the business contract, the business call request sent by the management component. The business call request includes the address of the first user and the identity information of the first user. The business call request is sent by the management component when the first user calls the business contract through the management component.

[0107] Step C2: Send an identity verification request to the identity verification contract through the business contract. The identity verification request includes the address of the first user, so that the identity verification contract can query the first authentication identity information in the blockchain based on the address of the first user. The first authentication identity information is the information stored in the blockchain by the identity verification contract at the request of the back-end service of the certification authority after successfully authenticating the first user. The first authentication identity information is used to indicate the identity of the first user.

[0108] Step C3: In response to receiving the first authentication identity information sent by the identity verification contract through the business contract, authenticate the first user based on the first authentication identity information through the business contract.

[0109] In the embodiment of the present application, for the blockchain node device running the above management component, during the process that a user calls a business contract and the business contract authenticates the user's identity, the following operations can be performed:

[0110] Step D1: Receive an instruction for the first user to call a business contract through the management component;

[0111] Step D2: Send a business call request to the business contract through the management component. The business call request includes the address of the first user and the identity information of the first user, so that the business contract sends an identity verification request including the address of the first user to the identity verification contract, enabling the identity verification contract to query the first authentication identity information in the blockchain based on the address of the first user, and in response to querying the first authentication identity information, sending the first authentication identity information to the business contract, so that the business contract authenticates the first user based on the first authentication identity information; the first authentication identity information is information that the authentication institution's background service requests the identity verification contract to store in the blockchain after successfully authenticating the first user; the first authentication identity information is used to indicate the identity of the first user.

[0112] In summary, through the solution shown in the embodiment of the present application, an identity verification contract is set in the blockchain system. Each user identity authentication party can set up an authentication institution's background service in the blockchain system respectively. After the authentication institution's background server successfully authenticates a user, it can request the identity verification contract to store the user's authentication identity information in the blockchain. Subsequently, when the user calls a business contract through the management component, the business contract can send an identity verification request including the user's address to the identity verification contract through the address of the user carried in the business call request. The identity verification contract queries the corresponding authentication identity information in the blockchain based on the user's address and returns it to the business contract. The business contract can authenticate the user according to the authentication identity information. In the above process, after the authentication institution's background server authenticates a user once, it can store the user's authentication identity information in the blockchain through the identity verification contract, and the identity verification contract can uniformly manage the authentication identity information obtained by different authentication institution's background servers, and in response to the identity verification requests of different business contracts, feedback the requested authentication identity information to different business contracts. That is to say, when different business contracts authenticate a user respectively later, they do not need to verify off-chain separately, but all obtain the authentication identity information in the blockchain through the unified identity verification contract, reducing the number of interactions between the blockchain system and off-chain services and improving the security of the business in the blockchain system.

[0113] Based on Figure 3 the blockchain system shown Figure 4The figure shows a flowchart of a verification method in a blockchain system shown in an exemplary embodiment of the present application. The blockchain system includes a management component, an identity verification contract, at least one business contract, and at least one certification authority background service. This method can be executed by a blockchain node device that runs the above-mentioned management component, identity verification contract, at least one business contract, and at least one certification authority background service. For example, the blockchain node device can be Figure 1 Node 200 in the shown system; taking the above-mentioned management component running on the first blockchain node device, the above-mentioned identity verification contract running on the second blockchain node device, the above-mentioned business contract running on the third blockchain node device, and the above-mentioned certification authority background service running on the fourth blockchain node device as an example, the verification method in this blockchain system includes the following steps:

[0114] Step 410: In response to a first user invoking a business contract through the management component, the first blockchain node device sends a business invocation request to the business contract through the management component. The business invocation request contains the address of the first user.

[0115] Among them, the first blockchain node device can receive an instruction from the first user to invoke the business contract through the management component. When receiving the instruction from the first user to invoke the business contract, it can be determined that the first user invokes the business contract through the management component.

[0116] In an embodiment of the present application, a user invoking a business contract can log in to the management component (such as the management component), invoke the business contract through the management component, and request to use the service of the business contract, such as a resource transfer transaction, etc. At this time, the management component can send a business invocation request to the business contract. For example, the business invocation request can be a request to initiate a blockchain transaction corresponding to the business contract; the business invocation request carries the address of the user in the blockchain system (also called the blockchain address), and this address is managed by the management component.

[0117] Step 420: The third blockchain node device sends an identity verification request to the identity verification contract through the business contract. The identity verification request contains the address of the first user.

[0118] Among them, the third blockchain node device can receive the above-mentioned business invocation request through the business contract. After the business contract receives the above-mentioned business invocation request, it can extract the address of the first user who invokes the business contract from the business invocation request, and carry the address of the first user in the identity verification request and send it to the identity verification contract.

[0119] Among them, the above-mentioned identity verification contract can be a system contract in the blockchain system, or it can also be an ordinary smart contract.

[0120] Step 430: The second blockchain node device queries the first authentication identity information in the blockchain through the identity authentication contract based on the address of the first user; the first authentication identity information is the information stored in the blockchain by the identity authentication contract upon successful identity authentication of the first user by the background service of the authentication institution; the first authentication identity information is used to indicate the identity of the first user.

[0121] Among them, the background service of the authentication institution authenticates the identity of the user, which means that the background service of the authentication institution confirms whether the identity information of the user is correct. If the background service of the authentication institution confirms that the identity information of the user is correct, it can be determined that the identity information of the user passes the authentication of the background service of the authentication institution.

[0122] The user can pre-request the authentication institution's background service to authenticate their identity. After the background service of the authentication institution successfully authenticates the user's identity, it can generate the user's authentication identity information and store the user's authentication identity information on the chain through the identity authentication contract for subsequent business contracts to verify the identity of the user who calls the business contract. That is to say, after the user's identity information is once authenticated by the background service of the authentication institution, the authentication identity information stored in the blockchain can be generated, and the authentication identity information can be used for subsequent business contracts to verify the user's identity. Among them, when the same business contract verifies the user's identity multiple times in sequence, or different business contracts verify the user's identity one or more times in sequence, the authentication identity information of the user stored in the above blockchain can be used.

[0123] Among them, when the identity authentication contract in the second blockchain node device receives a request from the business contract to verify the identity of the first user, it can query the corresponding first authentication identity information from the blockchain according to the address of the first user.

[0124] Step 440: In response to the identity authentication contract querying the first authentication identity information, the second blockchain node device sends the first authentication identity information to the business contract through the identity authentication contract.

[0125] Among them, if the identity authentication contract queries that there is first authentication identity information corresponding to the address of the first user in the blockchain, the queried first authentication identity information is returned to the business contract.

[0126] In a possible implementation manner, the method further includes: in response to the identity authentication contract failing to query the first authentication identity information, sending a query failure response to the business contract through the identity authentication contract.

[0127] If the authentication contract fails to query the first authentication identity information corresponding to the address of the first user in the blockchain, it may be that the first user has not passed the identity authentication through the background service of the authentication institution. In this case, there is no corresponding authentication identity information in the blockchain system. In such a situation, the authentication contract can return a query failure response to the business contract, indicating that there is no first authentication identity information corresponding to the first user in the blockchain, so as to feedback the corresponding information to the business contract when the user has not been authenticated by the authentication institution, ensuring that the business contract can continue the identity authentication process when the user has not been authenticated by the authentication institution, thereby ensuring the accuracy of the identity authentication process.

[0128] Alternatively, if the authentication contract fails to query the first authentication identity information corresponding to the address of the first user in the blockchain, it may also not feedback information to the business contract.

[0129] Step 450: The third blockchain node device authenticates the first user through the business contract based on the first authentication identity information.

[0130] Among them, in response to the third blockchain node device receiving the first authentication identity information sent by the authentication contract through the business contract, the first user is authenticated through the business contract based on the first authentication identity information.

[0131] Among them, the above authentication of the first user based on the first authentication identity information may mean that the business contract verifies whether the first user has passed the authentication of the specified authentication institution's background service through the above first authentication identity information. For example, it verifies whether the first user has passed the authentication of the authentication institution's background service trusted by the business contract. If it is verified that the first user has passed the authentication of the specified authentication institution's background service, it is determined that the first user's identity authentication is passed. If it is verified that the first user has not passed the authentication of the specified authentication institution's background service based on the above first authentication identity information, it is determined that the first user's identity authentication fails.

[0132] Alternatively, when the user calls the business contract and submits the identity information currently used by the user to the business contract, the above authentication of the first user based on the first authentication identity information may also mean that the business contract verifies whether the identity information currently used by the first user matches the authenticated identity information of the first user through the above first authentication identity information. If the identity information currently used by the first user matches the authenticated identity information of the first user, it is determined that the first user's identity authentication is passed. On the contrary, if the identity information currently used by the first user does not match the authenticated identity information of the first user, it can be determined that the first user's identity authentication fails.

[0133] In summary, through the solution shown in the embodiments of the present application, an identity verification contract is set up in the blockchain system. Each user identity authentication party can set up an authentication agency background service in the blockchain system respectively. After the authentication agency background server successfully authenticates the user, it can request the identity verification contract to store the user's authenticated identity information in the blockchain. Subsequently, when the user calls the business contract through the management component, the business contract can send an identity verification request containing the user's address to the identity verification contract based on the address of the user carried in the business call request. The identity verification contract queries the corresponding authenticated identity information in the blockchain based on the user's address and returns it to the business contract. The business contract can authenticate the user based on the authenticated identity information. In the above process, after the authentication agency background server authenticates the user once, it can store the user's authenticated identity information in the blockchain through the identity verification contract. Moreover, the identity verification contract can uniformly manage the authenticated identity information obtained by different authentication agency background servers and respond to the identity verification requests of different business contracts, feeding back the requested authenticated identity information to different business contracts. That is to say, when different business contracts authenticate the user respectively in the future, they do not need to verify off-chain separately, but all obtain the authenticated identity information in the blockchain through the unified identity verification contract, reducing the number of interactions between the blockchain system and off-chain services and improving the security of the business in the blockchain system.

[0134] In addition, in the solution shown in the embodiments of the present application, the authentication results (i.e., the above-mentioned authenticated identity information) of multiple authentication agency background services are stored, managed, and queried on the chain by the same identity verification contract, eliminating the need to deploy an identity verification contract separately for each authentication agency background service, reducing the complexity of the blockchain system, ensuring the storage efficiency of the user's authenticated identity information in the blockchain, and the efficiency of user identity verification by business contracts in the blockchain system.

[0135] Based on Figure 4 the embodiments shown, Figure 5 FIG. shows a flowchart of a verification method in a blockchain system shown in an exemplary embodiment of the present application. As Figure 5 shown, before step 410, steps 401 to 404 may further be included:

[0136] Step 401: The first blockchain node device sends an identity authentication request to the authentication agency background service through the management component; the fourth blockchain node device receives the identity authentication request sent by the management component through the authentication agency background service; the identity authentication request includes the address of the first user and the identity information of the first user.

[0137] Among them, the identity authentication request is used to trigger the offline verification of the identity information of the first user by the background service of the authentication institution, and generate the first authenticated identity information based on the identity information of the first user in the case that the identity information of the first user passes the offline verification, and request the identity verification contract to store the address of the first user and the first authenticated identity information in the blockchain correspondingly.

[0138] Among them, the user can request the background service of the authentication institution to authenticate his / her identity in advance. At this time, the first blockchain node device sends an identity authentication request including the address and identity information of the user to the background service of the authentication institution through the management component.

[0139] Among them, when there are at least two background services of the authentication institution in the above blockchain system, the user can choose to initiate identity authentication to one or more of the background services of the authentication institution. For example, after the user logs in to the management component (such as the management component), the user chooses to initiate identity authentication to one or more of the background services of the authentication institution successively or simultaneously. At this time, the management component sends identity authentication requests to the background services of the authentication institution selected by the user respectively. The identity authentication request includes the blockchain address of the first user and the identity information of the first user. For example, the above identity information may include information such as the name, mobile phone number, and ID card number of the first user.

[0140] Step 402: The fourth blockchain node device conducts offline verification of the identity information of the first user through the background service of the authentication institution.

[0141] Among them, the above fourth blockchain node device can conduct identity authentication to an identity authentication service outside the blockchain system through the background service of the authentication institution to determine whether the identity information of the first user is real identity information.

[0142] The above offline verification can also be called off-chain verification. The offline verification of the identity information of the first user refers to verifying whether the identity information of the first user is accurate through an identity authentication service outside the blockchain system.

[0143] For example, the above identity information includes the name, mobile phone number, and ID card number of the first user. The background service of the authentication institution can request the background of the communication operator outside the blockchain to verify whether the name and mobile phone number of the first user match, and request the background of the ID card management institution outside the blockchain to verify whether the name and ID card number of the first user match. If the background of the communication operator feedbacks that the name and mobile phone number of the first user match, and the background of the ID card management institution feedbacks that the name and ID card number of the first user also match, it can be determined that the identity information of the first user passes the offline verification.

[0144] Conversely, if the communication operator's backend feedback indicates that the name and mobile phone number of the first user do not match, or the identity card management agency's backend feedback indicates that the name and identity card number of the first user do not match, it can be determined that the identity information of the first user fails the offline verification.

[0145] Step 403: In response to the identity information of the first user passing the offline verification, the fourth blockchain node device generates first authentication identity information based on the identity information of the first user through the backend service of the certification authority.

[0146] In an embodiment of the present application, after the backend service of the certification authority determines that the identity information of the first user passes the offline verification, it can generate first authentication identity information based on the identity information of the first user. The first authentication identity information indicates the identity of the first user. At the same time, the first authentication identity information also indicates that the identity of the first user has passed the authentication of the backend service of the certification authority. Subsequently, the first authentication identity information can represent in the blockchain system that the first user is a user who has passed the authentication of the backend service of the certification authority.

[0147] Among them, the above-mentioned generation of the first authentication identity information based on the identity information of the first user may refer to the process of processing the identity information of the first user through a pre-set information generation algorithm to obtain encrypted information (i.e., the above-mentioned first authentication identity information).

[0148] In a possible implementation manner, the process of generating the first authentication identity information based on the identity information of the first user through the backend service of the certification authority in response to the identity information of the first user passing the offline verification may include:

[0149] In response to the identity information of the first user passing the offline verification, through the backend service of the certification authority, perform a hash calculation on the identity information of the first user according to the hash algorithm to obtain the hash value of the identity information of the first user;

[0150] Through the backend service of the certification authority, use the private key of the backend service of the certification authority to sign the hash value of the identity information of the first user to obtain the first authentication identity information.

[0151] In an embodiment of the present application, the backend service of the certification authority may first perform a hash calculation on the identity information of the first user through a pre-set hash algorithm to obtain the hash value of the identity information of the first user, and then use the private key of the backend service of the certification authority to sign the hash value of the identity information of the first user to obtain the first authentication identity information.

[0152] Among them, different certification authority backend services correspond to their own private keys and public keys, and different certification authority backend servers can also correspond to their own hash algorithms; for the same user, if the user requests identity authentication from multiple different certification authority backend services respectively, the authentication identity information generated by different certification authority backend services for this user can be information with different contents. The public key of the above-mentioned certification authority backend service can be provided by the certification authority backend service to each business contract in the blockchain system.

[0153] Through the above solution, the certification authority backend service first processes the user's identity information through a hash algorithm, uses the obtained hash value to replace the user's identity information, reduces the space required for storing identity information, and at the same time, signs the hash value with its own private key to ensure the security of the authentication identity information, thus taking into account the efficiency and security of storing the user's authentication identity information in the blockchain.

[0154] In another possible implementation manner, in response to the identity information of the first user being verified offline, the process of generating the first authentication identity information by the certification authority backend service based on the identity information of the first user may include:

[0155] In response to the identity information of the first user being verified offline, the certification authority backend service signs the identity information of the first user with the private key of the certification authority backend service to obtain the first authentication identity information.

[0156] That is to say, the certification authority backend service can directly sign the identity information of the first user with its own private key, thereby improving the generation efficiency of the authentication identity information.

[0157] Step 404: The fourth blockchain node device requests the identity verification contract to store the address of the first user and the first authentication identity information in the blockchain through the certification authority backend service.

[0158] Subsequently, when the identity verification contract receives an identity verification request sent by the business contract, it can query the first authentication identity information in the blockchain based on the address of the first user included in the identity verification request, and send the first authentication identity information to the business contract so that the business contract can authenticate the first user based on the first authentication identity information.

[0159] In the embodiment of the present application, after the certification authority backend service running in the fourth blockchain node device generates the first authentication identity information of the first user, it can call the identity verification contract, thereby registering the user identity of the first user in the identity verification contract, so that the identity verification contract stores the address of the first user and the first authentication identity information in the blockchain in a corresponding manner.

[0160] For example, the back-end service of the certification authority sends a user identity registration request to the identity verification contract. The user identity registration request carries the address of the first user and the first authentication identity information. After receiving the user identity registration request, the identity verification contract stores the first authentication identity information corresponding to the address of the first user in the blockchain. That is to say, subsequently, the first authentication identity information can be queried in the blockchain through the address of the first user.

[0161] Optionally, if a user (such as the above-mentioned first user) requests identity authentication from different back-end services of the certification authority respectively, different back-end services of the certification authority will generate different authentication identity information for the user. In this case, the identity verification contract stores the authentication identity information generated by different back-end services of the certification authority for the user respectively, corresponding to the address of the user in the blockchain. That is to say, at this time, there will be multiple different authentication identity information corresponding to the address of the user in the blockchain.

[0162] In the solution shown in the above embodiments of the present application, the user can initiate identity authentication to the back-end service of the certification authority through the management component, so as to store the authentication identity information of the user in the blockchain, so that the subsequent business contract can verify the identity of the user on the chain, thus ensuring the feasibility of the business contract to verify the identity of the user on the chain. In addition, the user only needs to undergo offline authentication once, and then can store long-term valid authentication identity information in the blockchain, without the need to perform offline identity verification every time the business contract is called, reducing the number of on-chain and off-chain interactions required for identity verification, thus ensuring the security of the execution of the business contract in the blockchain.

[0163] In a possible implementation manner, the above-mentioned fourth blockchain node device can request the identity verification contract to store the address of the first user, the identification information of the back-end service of the certification authority, and the first authentication identity information in the blockchain through the back-end service of the certification authority.

[0164] For example, in addition to carrying the address of the first user and the first authentication identity information, the user identity registration request sent by the back-end service of the certification authority to the identity verification contract also carries the identification information of the back-end service of the certification authority. After receiving the user identity registration request, the identity verification contract stores the first authentication identity information and the identification information of the back-end service of the certification authority corresponding to the address of the first user in the blockchain. That is to say, subsequently, the first authentication identity information can be queried in the blockchain through the address of the first user, and at the same time, it can be identified which back-end service of the certification authority generated the first authentication identity information, improving the information volume of the data stored in the blockchain.

[0165] In this case, in the subsequent step 440, when the second blockchain node device queries the first authentication identity information in response to the authentication contract, it will also query the identification information of the authentication agency background service that generated the first authentication identity information. At this time, the authentication contract can compare the identification information of the authentication agency background service that generated the first authentication identity information with the identification information of the authentication agency background service trusted by the business contract. If the two are consistent, the first authentication identity information can be sent to the business contract through the authentication contract. On the contrary, if the identification information of the authentication agency background service that generated the first authentication identity information is inconsistent with the identification information of the authentication agency background service trusted by the business contract, the authentication contract can consider that the first authentication identity information is not generated by the authentication agency background service trusted by the business contract. At this time, the first authentication identity information may not be sent to the business contract. For example, a query failure response can be sent to the business contract, or no feedback information is sent to the business contract. That is to say, in the above solution, during the user authentication process, the user identity is verified once in the authentication contract and the business contract. Specifically, first in the authentication contract, the identity of the user is verified once through the matching situation between the identification information of the authentication agency background service that generated the first authentication identity information and the identification information of the authentication agency background service trusted by the business contract. After this verification is successful, the first authentication identity information will be sent to the business contract, and the business contract will verify the signature of the first authentication identity information through the public key of the authentication agency background service, so as to verify the identity of the user in the business contract once, thus ensuring the accuracy and reliability of the user authentication.

[0166] Among them, before the identity verification contract compares the identification information of the background service of the certification authority that generates the first authenticated identity information with the identification information of the background service of the certification authority trusted by the business contract, the business contract can notify the identity verification contract of the identification information of the background service of the certification authority trusted by the business contract in advance. For example, in step 420 above, in the identity verification request sent by the business contract to the identity verification contract, in addition to including the address of the first user, it can also include the identification information of the background service of the certification authority trusted by the business contract. For another example, the business contract can send a registration request for the background service of the trusted certification authority to the identity verification contract in advance. The registration request includes the identification information of the background service of the certification authority trusted by the business contract. After receiving the registration request, the identity verification contract can save the identification information of the background service of the certification authority trusted by the business contract. For example, the identity verification contract stores the identification information of the background service of the certification authority trusted by the business contract corresponding to the identification information of the business contract in the blockchain. When receiving the identity verification request sent by the business contract subsequently, it can query the identification information of the background service of the certification authority trusted by the business contract from the blockchain through the identification information of the business contract.

[0167] The above solution provides two solutions for providing the identification information of the background service of the certification authority trusted by the business contract to the identity verification contract. Among them, the solution of carrying the identification information of the background service of the certification authority trusted by the business contract through the identity verification request does not require storing the identification information of the background service of the certification authority trusted by the business contract in the blockchain or the identity verification contract, which can reduce the data storage volume in the blockchain system and improve the data storage efficiency in the blockchain system; while the solution of the business contract registering and saving the identification information of the background service of the certification authority trusted by the identity verification contract in advance does not require sending the identification information of the background service of the certification authority trusted by the business contract to the identity verification contract every time verification is performed, which can reduce the data volume of the identity verification request and improve the transmission efficiency of the identity verification request.

[0168] Based on Figure 4 or Figure 5 the embodiments shown, Figure 6 shows a flowchart of a verification method in a blockchain system shown in an exemplary embodiment of the present application. As Figure 6 shown, the above step 450 can be implemented as step 450a and step 450b.

[0169] Step 450a: The third blockchain node device, in response to receiving the first authenticated identity information sent by the identity verification contract through the business contract, verifies the signature of the first authenticated identity information based on the public key of the background service of the certification authority through the business contract.

[0170] In an embodiment of the present application, after the business contract running in the third blockchain node device receives the first authenticated identity information sent by the identity authentication contract, it can verify the signature (or decrypt) the first authenticated identity information using the public key of the authentication agency's background service.

[0171] For example, if the business contract requires the authenticated identity information of a specific authentication agency's background service, the business contract can verify the signature of the received first authenticated identity information using the public key of the specific authentication agency's background service; if there are multiple pieces of authenticated identity information sent by the identity authentication contract to the business contract (that is, the user has passed the authentication of multiple authentication agency's background services), the business contract can verify the signatures of the multiple pieces of authenticated identity information respectively using the public key of the specific authentication agency's background service.

[0172] Step 450b: In response to successful verification of the signature of the first authenticated identity information, the third blockchain node device determines that the first user has passed the identity authentication.

[0173] Among them, if the business contract successfully verifies the signature of the received first authenticated identity information using the public key of a specific authentication agency's background service, it can be determined that the first user is a user who has passed the authentication of the specific authentication agency's background service, and it is determined that the first user has passed the identity authentication. Subsequently, corresponding business services can be provided for the user. For example, the blockchain transaction initiated by the first user can be continued.

[0174] For example, assume there are three business contracts (Business Contract 1, Business Contract 2, and Business Contract 3) and three authentication agency's background services (Authentication Agency Background Server 1, Authentication Agency Background Service 2, and Authentication Agency Background Service 3). Among them, Business Contract 1 trusts the authentication result of Authentication Agency Background Server 1, Business Contract 2 trusts the authentication result of Authentication Agency Background Service 2, and Business Contract 3 trusts both the authentication result of Authentication Agency Background Server 1 and the authentication result of Authentication Agency Background Service 2.

[0175] User 1 requests to call Business Contract 1. Business Contract 1 obtains the authenticated identity information 1 from the identity authentication contract and verifies the signature of the authenticated identity information 1 using the public key of Authentication Agency Background Server 1. If Business Contract 1 fails to verify the signature of the authenticated identity information 1 using the public key of Authentication Agency Background Server 1, it indicates that the authenticated identity information 1 is not the authentication result of Authentication Agency Background Server 1 for User 1, and User 1 has not passed the authentication of Authentication Agency Background Server 1. At this time, it can be determined that User 1 has not passed the identity authentication, and Business Contract 1 can prompt User 1 to perform identity authentication with Authentication Agency Background Server 1.

[0176] User 2 requests to invoke Business Contract 2. Business Contract 2 obtains Authentication Identity Information 2 and Authentication Identity Information 3 from the Identity Authentication Contract. The signature verification of Authentication Identity Information 2 and Authentication Identity Information 3 is respectively performed using the public key of the back-end server 2 of the authentication institution. If Business Contract 2 fails to successfully verify the signature of Authentication Identity Information 2 using the public key of the back-end server 2 of the authentication institution, but successfully verifies the signature of Authentication Identity Information 3, it indicates that Authentication Identity Information 2 is not the authentication result of the back-end server 2 of the authentication institution for this User 2, and Authentication Identity Information 3 is the authentication result of the back-end server 2 of the authentication institution for this User 2. At this time, it can be determined that User 2 has passed the identity authentication, and Business Contract 2 can continue to execute the blockchain transaction corresponding to User 2's invocation of Business Contract 2.

[0177] User 3 requests to invoke Business Contract 3. Business Contract 3 obtains Authentication Identity Information 4 from the Identity Authentication Contract. The signature verification of this Authentication Identity Information 4 is respectively performed using the public key of the back-end server 1 of the authentication institution and the public key of the back-end server 1 of the authentication institution. If Business Contract 3 fails to successfully verify the signature of Authentication Identity Information 4 using the public key of the back-end server 1 of the authentication institution, but successfully verifies the signature of Authentication Identity Information 4 using the public key of the back-end server 2 of the authentication institution, it indicates that Authentication Identity Information 4 is not the authentication result of the back-end server 1 of the authentication institution for this User 3, but the authentication result of the back-end service 2 of the authentication institution for this User 3. At this time, it can be determined that User 3 has passed the identity authentication, and Business Contract 3 can continue to execute the blockchain transaction corresponding to User 3's invocation of Business Contract 3.

[0178] Through the above solution, the business contract only needs to perform signature verification on the authentication identity information stored by the user on the blockchain using the public key of the back-end service of the authentication institution it trusts, and then it can determine whether the user's identity information has passed the authentication of the back-end service of the authentication institution trusted by the business contract, thereby completing the identity authentication of the user. The above identity authentication process is simple and convenient, and can verify whether the user has passed the authentication of the back-end service of the authentication institution trusted by the business contract when the identity authentication contract supports multiple back-end services of the authentication institution, thus taking into account both the efficiency and accuracy of identity authentication.

[0179] In a possible implementation manner, the method further includes: upon receiving a query failure response sent by the identity authentication contract through the business contract, determining that the first user's identity authentication fails; the query failure response is sent by the identity authentication contract when the query of the first authentication identity information fails.

[0180] Among them, if the authentication contract fails to query the authentication identity information of the first user in the blockchain, at this time, the authentication contract can directly return a query failure response to the service contract. After receiving the query failure response, the service contract can determine that the first user has not passed the identity authentication by the background service of the authentication institution. At this time, it can directly determine that the identity authentication of the first user fails, thus ensuring that in the case where the first user has not passed the authentication of the background service of the authentication institution trusted by the service contract, the identity authentication can be accurately performed, ensuring the feasibility of the identity authentication and avoiding identity authentication errors.

[0181] Based on the above Figures 3 to 6 The solution shown, this application designs a blockchain-based decentralized application supervision solution. By deploying a unified supervision contract (i.e., the above-mentioned authentication contract) on the blockchain, recording the authentication status of user addresses in the supervision contract, and having the corresponding authoritative real-name authentication institution authenticate the user identity and uploading the signed real-name document information to the blockchain for storage. When a user uses a decentralized application that needs to be supervised, it will call the specified supervision contract to perform real-name verification on the address and verify the user identity document. Since the endorsed document is uploaded to the blockchain for public viewing, anyone can authenticate the specified user identity information on the blockchain. The above solution can achieve multi-party authentication of user identities on the blockchain and the effect of online verification.

[0182] The core part of this solution is as follows: storing the user's identity and verifiable identity document information through a unified user identity authentication smart contract on the blockchain; for the user identity authentication party, there can be multiple user identity authentication parties on the current blockchain, and each authentication party provides a proof signature for the user identity and then uploads the user identity document to the identity authentication contract on the blockchain.

[0183] Please refer to Figure 7 , which shows an architecture diagram of a decentralized application supervision involved in this application. As Figure 7 shown, the process of this decentralized application supervision can be as follows:

[0184] S71, Contract deployment. The business-side user deploys a service contract in the blockchain system through the management component.

[0185] S72, User identity authentication. The user requests identity authentication from the background service of one or more authentication institutions corresponding to the authentication institutions in the blockchain system through the management component.

[0186] S73, After the background service of the authentication institution successfully authenticates the user identity, it registers the authenticated user identity with the authentication contract.

[0187] S74, The user initiates a blockchain transaction by calling the service contract through the management component.

[0188] S75. The business contract calls isVerified of the identity authentication contract.

[0189] The function of isVerified is as follows:

[0190] Verify the validity of the address. If it is a valid address, return true; if it is an illegal address, return false. At the same time, the function of isVerified can also register the address in the contract and verify that the signature of the address declaration file corresponding to the address passes.

[0191] function isVerified(address_userAddress) external view returns (bool).

[0192] S76. The identity authentication contract verifies the user address and queries whether there is corresponding authenticated identity information in the blockchain.

[0193] S77. Return the verification status, that is, whether there is authenticated identity information in the blockchain. If so, the verification status also includes the queried authenticated identity information.

[0194] S78. The business contract executes or rejects the blockchain transaction initiated by the user according to the verification status.

[0195] Based on the above Figure 7 shown architecture, please refer to Figure 8 , which shows a flowchart of a decentralized application supervision involved in the present application. As Figure 8 shown, the decentralized application supervision mainly includes the following parts:

[0196] 1) First, the identity authenticator deploys the identity authentication contract through the management component. After the identity authenticator authenticates the user identity, it uploads the user authentication identity file containing the authenticator's signature to the identity authentication contract. In this solution, the identity authenticator is decentralized, and anyone can become an identity authenticator. However, generally, only the identity authentication of authoritative institutions can be recognized by the business parties of decentralized applications.

[0197] 2) The business party logs in to the management component and deploys the business party smart contract through the management component. The business party smart contract verifies the user identity information by calling the address verification interface of the identity authentication contract according to the specified interface.

[0198] 3) The user logs in to the management component, then submits a file containing the user identity information to the background service of the identity authenticator. The identity authentication service verifies the user identity offline, signs the user identity file after authentication, and uploads the signed user identity file to the identity contract to publicly verify the user identity.

[0199] 4) The user logs in to the decentralized application of the service provider, initiates a call request to the service contract through the management component. The service contract first calls the authentication contract to verify the identity of the call address and verifies the user identity information through the public key of the user identity issuer.

[0200] 5) After the service contract passes the verification, it executes the business logic, modifies the storage space of the service contract, and completes the execution of the transaction.

[0201] Specifically, in Figure 8 the decentralized application supervision process may include the following steps.

[0202] S81, The certification authority deploys the authentication contract.

[0203] S82, The service provider logs in to the management component.

[0204] S83, The service provider deploys the service contract through the management component.

[0205] S84, The user logs in to the management component.

[0206] S85, The user applies for identity authentication to the background service of the certification authority through the management component. At this time, the blockchain address and identity information (such as name, mobile phone number, ID number, etc.) of the user can be sent to the background service of the certification authority.

[0207] S86, The background service of the certification authority conducts offline authentication of the user identity.

[0208] S87, After the background service of the certification authority passes the offline authentication of the user identity, it generates the authentication identity information of the user.

[0209] S88, The background service of the certification authority registers the user identity with the authentication contract. At this time, the blockchain address and authentication identity information of the user are sent to the authentication contract together.

[0210] S89, The authentication contract stores the authentication identity information in the blockchain, and stores the blockchain address and authentication identity information of the user correspondingly in the blockchain.

[0211] S810, The user triggers the call of the service contract through the management component.

[0212] S811, The management component calls the service contract.

[0213] S812, The service contract requests the authentication contract to verify the user identity, and the request contains the blockchain address of the user.

[0214] S813, The authentication contract queries the authentication identity information corresponding to the blockchain address of the user in the blockchain.

[0215] S814. The authentication contract returns a query result to the business contract. For example, it returns the authenticated identity information obtained from the query, or returns a query failure response.

[0216] S815. The business contract executes / denies a transaction based on the query result. For example, if the query result contains authenticated identity information and the signature verification of the authenticated identity information by the public key of a specific authentication institution's backend service is successful, the transaction is executed; if the signature verification of the authenticated identity information by the public key of a specific authentication institution's backend service fails, or the query result does not contain authenticated identity information, the transaction is denied.

[0217] Based on the solutions shown in the above various embodiments, please refer to Figure 9 , which shows a framework diagram of identity authentication in a blockchain system related to the present application. As Figure 9 shown, in a blockchain system that includes two authentication institution backend services (the authentication institution backend service 1 deployed by authentication institution 1 and the authentication institution backend service 2 deployed by authentication institution 2), a business party can log in to the management component to deploy business contract 1 and business contract 2. Business contract 1 trusts the authentication result of authentication institution backend service 1, and business contract 2 trusts the authentication result of authentication institution backend service 2. The process of identity authentication in this blockchain system can be as follows.

[0218] I. Identity Authentication + Registration Phase

[0219] S901. The user logs in to the management component and requests identity authentication from the authentication institution backend service through the management component. The request contains the user's address and identity information. Among them, each user can choose to request identity authentication from one or all of the authentication institution backend service 1 and the authentication institution backend service 2.

[0220] S902. The authentication institution backend service authenticates the user who requests authentication off-chain, and checks whether the user's identity information is correct through an off-chain identity authentication service.

[0221] S903. In the case where the user's identity information passes the off-chain authentication, the authentication institution backend service signs the hash value of the user's identity information with its own private key to obtain authenticated identity information, and registers the user's identity with the authentication contract, sending the user's address and the authenticated identity information to the authentication contract.

[0222] S904. The authentication contract stores the user's address and the authenticated identity information in the blockchain.

[0223] II. Business Invocation + Verification Phase

[0224] S905. The user logs in to the management component, and calls the business contract through the management component. The call request contains the user's address.

[0225] S906. The business contract sends an identity authentication request to the identity authentication contract, which contains the address of the user who calls the business contract.

[0226] S907. The identity authentication contract queries the authentication identity information corresponding to the user's address from the blockchain.

[0227] S908. The identity authentication contract returns the query result to the business contract, which contains the queried identity authentication information or a query failure response.

[0228] S909. In the case where the query result contains identity authentication information, the business contract can verify the signature of the identity authentication information through the public key of the authentication agency's background service.

[0229] For example, if business contract 1 trusts the background service 1 of the authentication agency, business contract 1 can verify the signature of the identity authentication information returned by the identity authentication contract through the public key of the background service 1 of the authentication agency; if business contract 2 trusts the background service 2 of the authentication agency, business contract 2 can verify the signature of the identity authentication information returned by the identity authentication contract through the public key of the background service 2 of the authentication agency.

[0230] If the query result contains a query failure response, the business contract can directly determine that the user's identity authentication fails.

[0231] The effects of this solution can be as follows:

[0232] 1) When the user calls the decentralized application, the user's identity is verified on the chain, without relying on the off-chain centralized business party;

[0233] 2) The user's verifiable identity documents are stored on the blockchain, and anyone can verify the verifiable identity documents;

[0234] 3) The identity systems of different decentralized applications on the chain can be connected, and different decentralized applications can use the same verifiable user identity documents for identity authentication.

[0235] Figure 10 The block diagram of the verification device in the blockchain system shown in an exemplary embodiment of the present application is shown. This device can be used to execute all or part of the steps performed by the blockchain node device running the identity authentication contract in any of the Figures 3 to 6 schemes shown; as Figure 10 shown, this device includes:

[0236] The authentication request receiving module 1001 is configured to receive, via the authentication contract, an authentication request sent by the service contract, where the authentication request is sent by the service contract when receiving a service invocation request sent by the management component; the authentication request is used to authenticate the first user, and the address of the first user is included in the authentication request.

[0237] The query module 1002 is configured to query, via the authentication contract, first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is information that the authentication agency background service requests the authentication contract to store in the blockchain after successfully authenticating the first user; the first authentication identity information is used to indicate the identity of the first user.

[0238] The authenticated identity information sending module 1003 is configured to, in response to the authentication contract querying the first authentication identity information, send the first authentication identity information to the service contract via the authentication contract, so that the service contract authenticates the first user based on the first authentication identity information.

[0239] In a possible implementation, the device further includes:

[0240] The query failure response sending module is configured to, in response to the authentication contract failing to query the first authentication identity information, send a query failure response to the service contract via the authentication contract.

[0241] Figure 11 The block diagram of the verification device in the blockchain system shown in an exemplary embodiment of the present application is shown. This device can be used to execute all or part of the steps performed by the blockchain node device running the authentication agency background service in any of the Figures 3 to 6 schemes shown; as Figure 11 shown, this device includes:

[0242] The identity authentication request receiving module 1101 is configured to receive, via the authentication agency background service, an identity authentication request sent by the management component, where the address of the first user and the identity information of the first user are included in the identity authentication request.

[0243] The offline verification module 1102 is configured to perform offline verification on the identity information of the first user via the authentication agency background service.

[0244] The authenticated identity information generating module 1103 is configured to, in response to the identity information of the first user passing the offline verification, generate first authentication identity information based on the identity information of the first user via the authentication agency background service.

[0245] A storage module 1104, configured to request, through the background service of the certification authority, the authentication contract to store the address of the first user and the first authenticated identity information in the blockchain in a corresponding manner, so that when the authentication contract receives an authentication request sent by the service contract, it queries the first authenticated identity information in the blockchain based on the address of the first user included in the authentication request, and sends the first authenticated identity information to the service contract, so that the service contract authenticates the first user based on the first authenticated identity information; the authentication request is sent by the service contract when receiving a service call request sent by the management component; the authentication request is used to authenticate the first user, and the address of the first user is included in the authentication request.

[0246] In a possible implementation manner, the authentication identity information generation module 1103 is configured to

[0247] In response to the identity information of the first user passing the offline verification, through the background service of the certification authority, perform a hash calculation on the identity information of the first user according to a hash algorithm to obtain a hash value of the identity information of the first user;

[0248] Through the background service of the certification authority, use the private key of the background service of the certification authority to sign the hash value of the identity information of the first user to obtain the first authenticated identity information.

[0249] Figure 12 The figure shows a block diagram of a verification device in a blockchain system shown in an exemplary embodiment of the present application. This device can be used to execute all or part of the steps performed by a blockchain node device running a service contract; as Figures 3 to 6 shown in any of the Figure 12 schemes, the device includes:

[0250] A service call request receiving module 1201, configured to receive, through the service contract, a service call request sent by the management component. The service call request includes the address of the first user and the identity information of the first user; the service call request is sent by the management component when the first user calls the service contract through the management component;

[0251] An authentication request sending module 1202, configured to send an authentication request to the authentication contract through the service contract, where the authentication request includes the address of the first user, so that the authentication contract queries first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is information that the authentication agency background service requests the authentication contract to store in the blockchain after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user.

[0252] An authentication module 1203, configured to, in response to receiving the first authentication identity information sent by the authentication contract through the service contract, authenticate the first user through the service contract based on the first authentication identity information.

[0253] In a possible implementation manner, the authentication module 1203 is configured to,

[0254] In response to receiving the first authentication identity information sent by the authentication contract through the service contract, verify the signature of the first authentication identity information through the service contract based on the public key of the authentication agency background service;

[0255] In response to successful signature verification of the first authentication identity information, determine that the first user passes the authentication.

[0256] In a possible implementation manner, the device further includes:

[0257] A verification failure determination module, configured to, in response to receiving a query failure response sent by the authentication contract through the service contract, determine that the first user fails the authentication; the query failure response is sent by the authentication contract when querying the first authentication identity information fails.

[0258] Figure 13 The block diagram of the verification device in the blockchain system shown in an exemplary embodiment of the present application is shown. This device can be used to execute all or part of the steps performed by the blockchain node device of the operation management component in any of the Figures 3 to 6 shown solutions; as Figure 13 shown, the device includes:

[0259] An instruction receiving module 1301, configured to receive an instruction for the first user to call the service contract through the management component;

[0260] The service call request sending module 1302 is configured to send a service call request to the service contract through the management component. The service call request includes the address of the first user and the identity information of the first user, so that the service contract sends an identity verification request including the address of the first user to the identity verification contract, enabling the identity verification contract to query the first authenticated identity information in the blockchain based on the address of the first user, and in response to querying the first authenticated identity information, sending the first authenticated identity information to the service contract, so that the service contract authenticates the identity of the first user based on the first authenticated identity information; the first authenticated identity information is information requested by the authentication agency background service to be stored in the blockchain by the identity verification contract after successfully authenticating the identity of the first user; the first authenticated identity information is used to indicate the identity of the first user.

[0261] In a possible implementation manner, the apparatus further includes:

[0262] The identity authentication request sending module is configured to send an identity authentication request to the authentication agency background service through the management component before the instruction receiving module 1301 receives an instruction for the first user to call the service contract through the management component. The identity authentication request includes the address of the first user and the identity information of the first user; the identity authentication request is used to trigger the authentication agency background service to perform offline verification on the identity information of the first user, and generate the first authenticated identity information based on the identity information of the first user in the case where the identity information of the first user passes the offline verification, and request the identity verification contract to store the address of the first user and the first authenticated identity information in the blockchain in a corresponding manner.

[0263] Figure 14 The structural block diagram of a computer device 1400 shown in an exemplary embodiment of the present application is shown. This computer device can be implemented as the server in the above solution of the present application. The computer device 1400 includes a central processing unit (CPU) 1401, a system memory 1404 including a random access memory (RAM) 1402 and a read-only memory (ROM) 1403, and a system bus 1405 connecting the system memory 1404 and the central processing unit 1401. The computer device 1400 further includes a mass storage device 1406 for storing an operating system 1409, application programs 1410, and other program modules 1411.

[0264] The mass storage device 1406 is connected to the central processing unit 1401 through a mass storage controller (not shown) connected to the system bus 1405. The mass storage device 1406 and its associated computer-readable medium provide non-volatile storage for the computer device 1400. That is to say, the mass storage device 1406 may include computer-readable media (not shown) such as a hard disk or a compact disc read-only memory (CD-ROM) drive.

[0265] Without loss of generality, the computer-readable medium may include computer storage media and communication media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes RAM, ROM, erasable programmable read-only registers (EPROM), electrically-erasable programmable read-only memory (EEPROM), flash memory or other solid-state storage technologies, CD-ROM, digital versatile disc (DVD) or other optical storage, magnetic tape cartridges, tapes, disk storage or other magnetic storage devices. Of course, those skilled in the art will know that the computer storage media is not limited to the above several types. The above system memory 1404 and mass storage device 1406 may be collectively referred to as memory.

[0266] According to various embodiments of the present disclosure, the computer device 1400 may also run by connecting to a remote computer on the network through a network such as the Internet. That is, the computer device 1400 may be connected to the network 1408 through the network interface unit 1407 connected to the system bus 1405. Or rather, the network interface unit 1407 may also be used to connect to other types of networks or remote computer systems (not shown).

[0267] The memory further includes at least one computer program. The at least one computer program is stored in the memory, and the central processing unit 1401 implements all or part of the steps in the methods shown in the above various embodiments by executing the at least one computer program.

[0268] In an exemplary embodiment, a computer-readable storage medium is further provided for storing at least one computer program, and the at least one computer program is loaded and executed by a processor to implement all or part of the steps in the methods shown in the above various embodiments. For example, the computer-readable storage medium may be a Read-Only Memory (ROM), a Random Access Memory (RAM), a Compact Disc Read-Only Memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.

[0269] In an exemplary embodiment, a computer program product or a computer program is further provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes all or part of the steps in the methods shown in the above various embodiments.

[0270] Before collecting the relevant data of the user and during the process of collecting the relevant data of the user, this application can display a prompt interface, a pop-up window or output a voice prompt message. The prompt interface, the pop-up window or the voice prompt message is used to prompt the user that their relevant data is being collected currently, so that this application only starts to execute the relevant steps of obtaining the relevant data of the user after obtaining the confirmation operation sent by the user for the prompt interface or the pop-up window. Otherwise (that is, when the confirmation operation sent by the user for the prompt interface or the pop-up window is not obtained), the relevant steps of obtaining the relevant data of the user are ended, that is, the relevant data of the user is not obtained. In other words, all the user data collected by this application is collected with the consent and authorization of the user, and the collection, use and processing of the relevant user data need to comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0271] The above relevant data of the user includes information (including but not limited to information of the user terminal, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals and other data. For example, the identity information involved in this application is obtained under full authorization.

[0272] Those skilled in the art will readily conceive of other embodiments of this application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application, which follow the general principles of this application and include known common knowledge or conventional technical means in the technical field not disclosed in this application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of this application are pointed out by the following claims.

[0273] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope.

Claims

1. A verification method in a blockchain system, characterized in that, The blockchain system includes a management component, an authentication contract, at least one business contract, and at least one certification authority back-end service. The method includes: In response to a first user invoking the business contract through the management component, the management component sends a business invocation request to the business contract, and the business invocation request includes the address of the first user; The business contract sends an authentication request to the authentication contract, and the authentication request includes the address of the first user; The authentication contract queries the first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is information that the certification authority back-end service requests the authentication contract to store in the blockchain after successfully authenticating the first user; the first authentication identity information is used to indicate the identity of the first user; In response to the authentication contract querying the first authentication identity information, the authentication contract sends the first authentication identity information to the business contract; The business contract authenticates the first user based on the first authentication identity information.

2. A verification method in a blockchain system, characterized in that, The blockchain system includes a management component, an authentication contract, at least one business contract, and at least one certification authority back-end service. The method includes: The authentication contract receives the authentication request sent by the business contract. The authentication request is sent by the business contract when it receives the business invocation request sent by the management component; the authentication request is used to authenticate the first user, and the authentication request includes the address of the first user; The authentication contract queries the first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is information that the certification authority back-end service requests the authentication contract to store in the blockchain after successfully authenticating the first user; the first authentication identity information is used to indicate the identity of the first user; In response to the authentication contract querying the first authentication identity information, the authentication contract sends the first authentication identity information to the business contract so that the business contract authenticates the first user based on the first authentication identity information.

3. The method according to claim 2, wherein The method further includes: In response to the authentication contract failing to query the first authentication identity information, the authentication contract sends a query failure response to the business contract.

4. A verification method in a blockchain system, characterized in that, The blockchain system includes a management component, an authentication contract, at least one business contract, and at least one certification authority back-end service. The method includes: The certification authority back-end service receives the authentication request sent by the management component. The authentication request includes the address of the first user and the identity information of the first user; The certification authority back-end service offline-verifies the identity information of the first user; In response to the offline verification of the identity information of the first user, through the back-end service of the certification authority, generate first authentication identity information based on the identity information of the first user; Through the back-end service of the certification authority, request the identity verification contract to store the address of the first user and the first authentication identity information in the blockchain in a corresponding manner, so that when the identity verification contract receives the identity verification request sent by the service contract, query the first authentication identity information in the blockchain based on the address of the first user contained in the identity verification request, and send the first authentication identity information to the service contract, so that the service contract can authenticate the identity of the first user based on the first authentication identity information; the identity verification request is sent by the service contract when it receives the service call request sent by the management component; the identity verification request is used to authenticate the identity of the first user, and the address of the first user is included in the identity verification request.

5. The method according to claim 4, characterized in that, The step of, in response to the offline verification of the identity information of the first user, through the back-end service of the certification authority, generating first authentication identity information based on the identity information of the first user, includes: In response to the offline verification of the identity information of the first user, through the back-end service of the certification authority, perform a hash calculation on the identity information of the first user according to the hash algorithm to obtain the hash value of the identity information of the first user; Through the back-end service of the certification authority, use the private key of the back-end service of the certification authority to sign the hash value of the identity information of the first user to obtain the first authentication identity information.

6. A verification method in a blockchain system, characterized in that, The blockchain system includes a management component, an identity verification contract, at least one service contract, and at least one back-end service of the certification authority. The method includes: Through the service contract, receive the service call request sent by the management component, where the service call request includes the address of the first user and the identity information of the first user; the service call request is sent by the management component when the first user calls the service contract through the management component; Through the service contract, send an identity verification request to the identity verification contract, where the identity verification request includes the address of the first user, so that the identity verification contract can query the first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is the information stored in the blockchain by the identity verification contract at the request of the back-end service of the certification authority after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user; In response to receiving the first authentication identity information sent by the identity verification contract through the service contract, through the service contract, authenticate the identity of the first user based on the first authentication identity information.

7. The method according to claim 6, wherein The step of, in response to receiving the first authentication identity information sent by the identity verification contract through the service contract, through the service contract, verifying the identity information of the first user based on the first authentication identity information, includes: In response to receiving the first authenticated identity information sent by the authentication contract through the service contract, the service contract verifies the signature of the first authenticated identity information based on the public key of the authentication institution's background service; In response to successful verification of the signature of the first authenticated identity information, it is determined that the first user has passed the identity verification.

8. The method according to claim 6, wherein The method further includes: In response to receiving a query failure response sent by the authentication contract through the service contract, it is determined that the first user's identity verification fails; the query failure response is sent by the authentication contract when the query of the first authenticated identity information fails.

9. A verification method in a blockchain system, characterized in that, The blockchain system includes a management component, an authentication contract, at least one service contract, and at least one authentication institution's background service. The method includes: Receiving, by the management component, an instruction from a first user to invoke the service contract; Sending a service invocation request to the service contract by the management component. The service invocation request includes the address of the first user and the identity information of the first user, so that the service contract sends an identity verification request including the address of the first user to the authentication contract, enabling the authentication contract to query the first authenticated identity information in the blockchain based on the address of the first user, and in response to querying the first authenticated identity information, sending the first authenticated identity information to the service contract, so that the service contract authenticates the first user based on the first authenticated identity information; the first authenticated identity information is information requested by the authentication institution's background service to be stored in the blockchain by the authentication contract after successfully authenticating the first user; the first authenticated identity information is used to indicate the identity of the first user.

10. The method according to claim 9, characterized in that, Before receiving, by the management component, an instruction from a first user to invoke the service contract, it further includes: Sending an identity authentication request to the authentication institution's background service by the management component. The identity authentication request includes the address of the first user and the identity information of the first user; the identity authentication request is used to trigger the authentication institution's background service to perform offline verification on the identity information of the first user, and based on the identity information of the first user to generate the first authenticated identity information in the case where the identity information of the first user passes the offline verification, and requesting the authentication contract to store the address of the first user and the first authenticated identity information in the blockchain in a corresponding manner.

11. A verification device in a blockchain system, characterized in that, The blockchain system includes a management component, an authentication contract, at least one service contract, and at least one authentication institution's background service. The device includes: An identity verification request receiving module, configured to receive, by the authentication contract, an identity verification request sent by the service contract. The identity verification request is sent by the service contract when receiving a service invocation request sent by the management component; the identity verification request is used to authenticate the first user, and the identity verification request includes the address of the first user; A query module, configured to query first authentication identity information in the blockchain based on the address of the first user through the authentication contract; the first authentication identity information is information that the authentication agency background service requests the authentication contract to store in the blockchain after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user. An authentication identity information sending module, configured to, in response to the authentication contract querying the first authentication identity information, send the first authentication identity information to the service contract through the authentication contract, so that the service contract authenticates the identity of the first user based on the first authentication identity information.

12. A verification device in a blockchain system, characterized in that, The blockchain system includes a management component, an authentication contract, at least one service contract, and at least one authentication agency background service, and the device includes: A service call request receiving module, configured to receive a service call request sent by the management component through the service contract, where the service call request includes the address of the first user and the identity information of the first user; the service call request is sent by the management component when the first user calls the service contract through the management component. An authentication request sending module, configured to send an authentication request to the authentication contract through the service contract, where the authentication request includes the address of the first user, so that the authentication contract queries first authentication identity information in the blockchain based on the address of the first user; the first authentication identity information is information that the authentication agency background service requests the authentication contract to store in the blockchain after successfully authenticating the identity of the first user; the first authentication identity information is used to indicate the identity of the first user. An authentication module, configured to, in response to receiving the first authentication identity information sent by the authentication contract through the service contract, authenticate the identity of the first user through the service contract based on the first authentication identity information.

13. A computer device, characterized in that, The computer device includes a processor and a memory, and the memory stores at least one computer program, and the at least one computer program is loaded and executed by the processor to implement the verification method in the blockchain system according to any one of claims 2 to 10.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, and the computer program is loaded and executed by the processor to implement the verification method in the blockchain system according to any one of claims 2 to 10.

15. A computer program product, characterized in that, The computer program product includes computer instructions, and the computer instructions are stored in a computer-readable storage medium; the computer instructions are read and executed by the processor of the computer device to implement the verification method in the blockchain system according to any one of claims 2 to 10.