Block chain-based distributed digital identity management platform and construction method
By building a distributed digital identity management platform based on blockchain, the problem of low user identity verification participation in the alliance chain is solved, identity controllable and privacy protection is achieved, and a secure and trustworthy data interaction mechanism is provided.
Patent Information
- Application Number
- CN202310383101.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-11
- Publication Date
- 2025-07-25
AI Technical Summary
The existing alliance chains are not very involved in user identity authentication, and cannot achieve independent and controllable identity and minimize privacy disclosure.
Build a distributed digital identity management platform based on blockchain, including application side, DID SDK, blockchain gateway, blockchain underlying infrastructure and key management system, provide DID business-related functions and logical processing, support multiple DID registration, query and credential management, complete transactions through blockchain gateways, and build an independent key management system.
It realizes the independent control of user identities, reduces the privacy disclosure of identity information, supports on-chain credential verification and data storage, reduces the cost of identity information authentication, and establishes a safe and trustworthy data interaction mechanism.
Smart Images

Figure CN120378123A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and particularly relates to a distributed digital identity management platform based on blockchain and a construction method thereof. Background Art
[0002] In the past few years, the blockchain technology originating from the field of digital currency has gradually shown its application utility in fields such as finance and judicial evidence preservation after experiencing market bubbles and regulatory storms. After the wave of capital receded, industrial blockchain has become the consensus in the industry from proof of concept to large-scale promotion. Alliance blockchain has been designed to provide enterprise-level blockchain services since its inception. As a digital infrastructure for strengthening trust and multi-center data collaboration, it is currently weeding out the false and retaining the true from the ever-emerging market demands, exploring the application value of blockchain technology, constantly innovating industrial models, and leading industrial upgrading with technology.
[0003] At present, as a digital infrastructure for strengthening trust and multi-center data collaboration, the alliance blockchain can only verify the identity of organizations, and the user participation rate is not high. Considering that DID is beneficial to the identity verification of users or products, introducing DID technology can enrich the trust-enhancing ability of the blockchain. In recent years, multiple standard organizations and open-source communities have jointly promoted and developed a series of technical standards and protocols related to distributed digital identity, and the technology stack of distributed digital identity has been initially improved. The key to current research is to build a distributed digital identity management system for alliance blockchain data transactions, so as to eliminate the dependence on the identity center, achieve autonomous and controllable identity, and minimize the privacy disclosure of identity information. Summary of the Invention
[0004] The purpose of the present invention is to overcome the problems in the prior art and realize the autonomy of user identity ownership. The present invention proposes a distributed digital identity management platform based on blockchain and a construction method thereof.
[0005] A construction method for a distributed digital identity management platform based on blockchain includes the following steps:
[0006] Build a distributed digital identity management platform, including an application end and a DID SDK. Among them, the application end is an entry platform for users to visually use DID services, providing DID business-related functions, and the DID SDK integrates DID-related interfaces to provide DID business logic processing;
[0007] Set up a blockchain gateway to connect to the blockchain core service, and the distributed digital identity management platform completes transaction on-chain through the blockchain gateway;
[0008] Build a blockchain underlying infrastructure to provide blockchain core services, where the blockchain core services are provided by the blockchain underlying infrastructure;
[0009] Build a key management system to provide key escrow functionality for the distributed digital identity management platform.
[0010] As an implementable approach, the application side of the distributed digital identity management platform provides DID service-related functions including: key management, DID query, CPT management, credential management, credential presentation management, credential verification management, credential presentation verification management, authoritative credential issuer management, and account management;
[0011] The DID SDK of the distributed digital identity management platform provides business logic processing including: DID service, credential service, CPT service, and key service.
[0012] As an implementable approach, a user can have multiple DIDs. The registration process of the DID includes the following steps: Based on the DID document information submitted by the user on the distributed digital identity management platform, the DID SDK calls the DID service logic processing to perform information format verification and generate a DID number; The DID number and the DID document information are submitted to the blockchain, and the smart contract verifies whether the DID number is repeated. If the verification is successful, the DID registration is successful.
[0013] Furthermore, the DID query supports querying all DID information created in the current blockchain network. The DID information on the blockchain is public information and can be queried by any identity, including users without a DID identity. The specific steps include:
[0014] Call the query contract interface in the DID service business logic processing to obtain the DID information on the blockchain based on the DID number, role type, and account status. The DID information includes: DID number, role type, account status, creation time, update time, public key information, identity verification information, credential issuance information, and service information.
[0015] Furthermore, the public key information includes: public key ID, algorithm type, public key holder, and public key content;
[0016] The identity verification information is used to create CPT signature verification and includes: identity verification public key ID, algorithm type, identity verification public key holder, and identity verification public key content;
[0017] The credential issuance information is used for VC and VP signature verification and includes: credential issuance public key ID, algorithm type, credential issuance public key holder, and credential issuance public key content;
[0018] The service information is used to describe the services related to the current DID and includes: service ID, service type, and service address.
[0019] As an implementable manner, the blockchain gateway is set up to connect to the core blockchain services through contract deployment services, on-chain identity identification, routing and forwarding, contract invocation, and event listening;
[0020] The blockchain underlying infrastructure provides core blockchain services, including at least ledger, transaction, event, smart contract, consensus, and MSP core modules. Among them, the distributed digital identity management platform updates the blockchain ledger by deploying smart contracts and invoking smart contract methods.
[0021] As an implementable manner, the key management system provides independent key management services, which are divided into three layers, specifically including:
[0022] Application layer, integrating data access components and public-private key parsing components;
[0023] Data layer, a relational database that provides services for the web, used to complete the storage of business data;
[0024] Infrastructure layer, the infrastructure layer is a container orchestration and management platform. The platform is based on virtualized servers and deploys and runs the virtual machine server system in a containerized and clustered manner.
[0025] Furthermore, the application layer selects Spring Boot as the development framework, and the data layer selects mysql as the relational database.
[0026] As an implementable manner, an interface is designed for the key management system to connect to the distributed digital identity management platform; the interface includes public-private key pair query, public-private key pair application, public key encryption, private key decryption, private key signature, public key verification signature, jws signature, and jws verification signature;
[0027] The encryption algorithms in the key management system include symmetric encryption algorithms and asymmetric encryption algorithms. Among them, the symmetric encryption algorithm is aes, which is used in the serialization and deserialization processes, and the asymmetric encryption algorithms are secp256ki and sm commercial encryption algorithms, which are used in other encryption and decryption processes.
[0028] As an implementable manner, the key management system provides a key escrow function for the distributed digital identity management platform. The key generation process includes the following steps: Based on the encryption algorithm type submitted by the user at the application end of the distributed digital identity management platform, a new key request is generated. The DID SDK calls the key service logic processing to create a public-private key pair. The key management system generates a unique key index based on the public-private key pair and returns it. The distributed digital identity management platform stores the unique key index.
[0029] A blockchain-based distributed digital identity management platform, including a distributed digital identity management platform, a blockchain underlying infrastructure, a blockchain gateway, and a key management system;
[0030] The distributed digital identity management platform includes an application end and a DID SDK. Among them, the application end is an entry platform for users to visually use DID services, providing DID service-related functions. The DID SDK integrates DID-related interfaces and provides DID service logic processing;
[0031] The blockchain gateway docks with the blockchain core service, and the distributed digital identity management platform completes transaction on-chain through the blockchain gateway;
[0032] The blockchain underlying infrastructure provides blockchain core services;
[0033] The key management system provides key escrow functions for the distributed digital identity management platform.
[0034] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of the above are implemented.
[0035] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method steps described in any one of the above are implemented.
[0036] For a better understanding of the present invention, the following explains the professional terms in the content of the invention book:
[0037] DID: A decentralized ID defined by the W3C DID specification;
[0038] DID document: A document describing how to use DID, including basic information of DID, holder public key information, verification information, DID revocation credential information, etc.;
[0039] CPT: The type of claim protocol (Claim Protocol Type). Specifically, for electronic credentials under the W3C VerifiableCredential specification, there need to be one or more claims about an entity to load the fields of the credential business data. For different credential issuers according to business scenario needs, different types of data structure claims are defined through different CPTs;
[0040] Jws: json web signature, a web signature algorithm in json format;
[0041] MSP: Membership Service Provider;
[0042] VC: Verifiable Credential;
[0043] VP: Verifiable Presentation.
[0044] Compared with the prior art, the present invention divides the distributed digital identity management platform into two modules: business-related functions and business logic processing. Based on the self-developed blockchain underlying infrastructure, it provides core blockchain services, constructs a key management system, separates the key escrow function, provides key services for the distributed digital identity management platform, and ensures the privacy and security of on-chain operations. Through the distributed management of digital identities, the present invention returns the ownership and control of data flow of digital identities to the owners, and at the same time supports data holding institutions to verify credentials through on-chain smart contracts, realizes on-chain evidence storage for regulatory traceability. Description of the Drawings
[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0046] Figure 1 It is the overall architecture diagram in the specific embodiment of the method for constructing a distributed digital identity management platform based on blockchain of the present invention;
[0047] Figure 2 It is the business flow diagram in the specific embodiment of the method for constructing a distributed digital identity management platform based on blockchain of the present invention. Detailed Embodiments
[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions of the present invention with reference to the drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention fall within the scope of protection of the present invention.
[0049] In the description of this specification, the descriptions referring to terms such as "an embodiment", "a specific embodiment", "an implementation manner", and "for example" mean that the specific features, structures, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. The order of steps involved in each embodiment is used to schematically illustrate the implementation of this application, and the order of steps is not limited and can be adjusted appropriately as needed.
[0050] In a specific embodiment, as Figure 1 shows the overall architecture diagram of the present invention. This embodiment is based on Figure 1 and realizes a method for constructing a distributed digital identity management platform based on blockchain. The specific implementation steps include:
[0051] S1. Construct a distributed digital identity management platform, including an application end and a DID SDK. Among them, the application end is an entry platform for users to visually use DID services, provides DID service-related functions, and the DID SDK integrates DID-related interfaces and provides DID service logic processing;
[0052] S2. Set up a blockchain gateway to connect to the blockchain core service. The distributed digital identity management platform completes transaction on-chain through the blockchain gateway;
[0053] Construct the blockchain underlying infrastructure to provide blockchain core services;
[0054] S3. Construct a key management system to provide key escrow functions for the distributed digital identity management platform.
[0055] This embodiment helps customers quickly use distributed digital identity technology in combination with the actual business scenarios of customers, promotes business multi-party participating entities to reduce the cost of identity information authentication, and establishes a secure and trustworthy data interaction mechanism.
[0056] The functions provided by the application end of the distributed digital identity management platform related to DID include: key management, DID query, CPT management, credential management, credential presentation management, credential verification management, credential presentation verification management, authoritative credential issuer management, and account management;
[0057] The business logic processing provided by the DID SDK of the distributed digital identity management platform includes: DID service, credential service, CPT service, and key service.
[0058] Based on the construction method of a distributed digital identity management platform, this embodiment constructs a digital identity authentication system for privacy protection and data security based on distributed digital identity cryptography, returning the ownership and data transfer control rights of digital identities to the owners. The key function design of the DID business-related functions of the platform system includes:
[0059] On the one hand, a user can have multiple DIDs. The registration process of the DID includes the following steps: Based on the DID document information submitted by the user on the distributed digital identity management platform, the DID SDK calls the DID service logic processing to perform information format verification and generate a DID number; The DID number and the DID document information are submitted to the blockchain, and the smart contract verifies whether the DID number is repeated. If the verification is successful, the DID registration is successful.
[0060] On the one hand, the DID query supports querying all DID information created in the current blockchain network. The DID information on the blockchain is public information, and any identity can query it, and users without a DID identity can also query it. The specific steps include:
[0061] Call the query contract interface in the DID service business logic processing, and obtain the DID information on the blockchain based on the DID number, role type, and account status. The DID information includes: DID number, role type, account status, creation time, update time, public key information, identity authentication information, credential issuance information, service information;
[0062] Among them, the public key information includes: public key ID, algorithm type, public key holder, public key content;
[0063] The identity authentication information is used to create CPT signature verification, including: identity authentication public key ID, algorithm type, identity authentication public key holder, identity authentication public key content;
[0064] The credential issuance information is used for VC and VP signature verification, including: credential issuance public key ID, algorithm type, credential issuance public key holder, credential issuance public key content;
[0065] The service information is used to describe the services related to the current DID, including: service ID, service type, service address.
[0066] On the other hand, the CPT management includes the creation, update, revocation, query, and credential issuance of CPTs, specifically including:
[0067] Create a CPT for credential issuance. The CPT created by the authoritative credential issuer is an authoritative CPT, and the CPT created by an ordinary DID user is an ordinary CPT;
[0068] Update the CPT, edit the created CPT. After successful editing, the CPT version will be automatically incremented by 1;
[0069] Revoke the CPT, cancel the created CPT. After cancellation, the status of the CPT is modified to the invalid status, and then the CPT cannot be used;
[0070] Query the CPT, query the information of the created CPT;
[0071] Issue a credential, issue new credential information based on the current CPT, support issuing for other DIDs, and also support issuing for oneself.
[0072] This embodiment provides blockchain core services based on a self-developed blockchain underlying infrastructure, including:
[0073] Set up a blockchain gateway to connect to the blockchain core services, including setting up contract deployment services, on-chain identity identification, routing and forwarding, contract invocation, and event listening;
[0074] The blockchain underlying infrastructure provides blockchain core services, including at least ledger, transaction, event, smart contract, consensus, and MSP core modules. Among them, the distributed digital identity management platform updates the blockchain ledger by deploying smart contracts and invoking smart contract methods.
[0075] In this embodiment, the key management system provides independent key management services, which are divided into three layers, specifically including:
[0076] The application layer integrates data access components and public-private key parsing components;
[0077] The data layer is a relational database that provides services for the web and is used to store business data;
[0078] The infrastructure layer is a container orchestration and management platform. The platform is based on virtualized servers and deploys and runs the virtual machine server system in a containerized and clustered manner;
[0079] Specifically, the application layer selects SpringBoot as the development framework, and the data layer selects mysql as the relational database.
[0080] Preferably, design an interface for the key management system to connect to the distributed digital identity management platform; the interface includes public-private key pair query, public-private key pair application, public key encryption, private key decryption, private key signature, public key verification signature, jws signature, and jws verification signature;
[0081] The encryption algorithms in the key management system include symmetric encryption algorithms and asymmetric encryption algorithms. Among them, the symmetric encryption algorithm is AES, which is used in the serialization and deserialization processes, and the asymmetric encryption algorithms are secp256ki and SM commercial encryption algorithms, which are used in other encryption and decryption processes;
[0082] The process of key generation includes the following steps: Based on the type of encryption algorithm submitted by the user on the application side of the distributed digital identity management platform, a new key request is generated. The DID SDK calls the key service logic processing to create a public-private key pair. The key management system generates a unique key index based on the public-private key pair and returns it. The distributed digital identity management platform stores the unique key index.
[0083] In another embodiment, the present invention proposes an innovative solution in core technical issues such as how to eliminate the dependence on the identity center, achieve identity autonomy and control, and minimize the privacy disclosure of identity information; such as Figure 2 shows the business flow chart of the present invention. This embodiment is based on Figure 2 shown to implement the overall business process of the distributed digital identity management platform.
[0084] Among them, the user role division in this embodiment includes:
[0085] The user roles include ordinary users, authoritative credential issuers, and administrators;
[0086] The authoritative credential issuer has all the operation permissions of the ordinary user and can issue authoritative type CPTs, and manage the entire life cycle and disclosure policies of the authoritative type CPTs;
[0087] The administrator has all the operation permissions of the ordinary user and the authoritative credential issuer and can manage the authoritative credential issuer.
[0088] Specifically, according to specific business scenarios, the ordinary users are divided into holders, credential verifiers, and credential issuers;
[0089] The holder: manages the entire life cycle of its own DID, manages the entire life cycle and disclosure policies of the ordinary type CPTs created by itself, can query and use the held credentials, and create, query, and use credential presentations based on the held credentials;
[0090] The credential verifier: Any credential verifier is a holder, has all the functions available to the holder, and can use the functions of credential verification and credential presentation verification;
[0091] The said credential issuer: Any credential issuer is a credential verifier and has all the functions available to a credential verifier. The said credential issuer issues credentials and can perform operations such as updating and revoking the credentials it has issued.
[0092] Preferably, the credential verifier and the credential issuer perform credential verification and credential presentation verification through an on-chain smart contract to achieve the deposit of on-chain data for regulatory agencies to trace.
[0093] The disclosure policy management includes the creation, update, deletion, and query of policies. Among them, when creating a policy, select the corresponding CPT for creation, and each CPT can have multiple disclosure policies.
[0094] Those skilled in the art will readily conceive of other embodiments of the present specification after considering the specification and the invention disclosed herein. This specification is intended to cover any variations, uses, or adaptations of this specification, which follow the general principles of this specification and include the common general knowledge or conventional technical means in the technical field not disclosed in this specification. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of this specification are pointed out by the claims.
[0095] It should be understood that this specification is not limited to the exact structure already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this specification is only limited by the appended claims.
Claims
1. A method for constructing a distributed digital identity management platform based on blockchain, characterized in that, It includes the following steps: Build a distributed digital identity management platform, including an application side and a DID SDK. Among them, the application side is an entry platform for users to visually use DID services, providing DID business-related functions, and the DID SDK integrates DID-related interfaces to provide DID business logic processing; Set up a blockchain gateway to connect to the blockchain core service, and the distributed digital identity management platform completes transaction on-chain through the blockchain gateway; Build a blockchain underlying infrastructure to provide blockchain core services, where the blockchain core services are provided by the blockchain underlying infrastructure; Build a key management system to provide key escrow functions for the distributed digital identity management platform.
2. The method for constructing a blockchain-based distributed digital identity management platform according to claim 1, wherein The DID business-related functions provided by the application side include: key management, DID query, CPT management, credential management, credential presentation management, credential verification management, credential presentation verification management, authoritative credential issuer management, and account management; The DID business logic processing provided by the DID SDK includes: DID service, credential service, CPT service, and key service.
3. The method for constructing a blockchain-based distributed digital identity management platform according to claim 2, wherein A user can have multiple DIDs, and the registration process of the DID includes the following steps: Based on the DID document information submitted by the user on the distributed digital identity management platform, the DID SDK calls the DID service logic processing to perform information format verification and generate a DID number; submit the DID number and the DID document information on-chain, and the smart contract verifies whether the DID number is repeated. If the verification is successful, the DID registration is successful.
4. The method for constructing a blockchain-based distributed digital identity management platform according to claim 1, wherein The setting of the blockchain gateway connects to the blockchain core service through contract deployment service, on-chain identity recognition, routing forwarding, contract call, and event listening; The blockchain underlying infrastructure provides blockchain core services, including at least ledger, transaction, event, smart contract, consensus, and MSP core modules. Among them, the distributed digital identity management platform updates the blockchain ledger by deploying smart contracts and calling smart contract methods.
5. The method for constructing a blockchain-based distributed digital identity management platform according to claim 1, wherein, The construction of the key management system includes building an application layer, a data layer, and an infrastructure layer, including the following steps: The application layer integrates a data access component and a public-private key parsing component; The data layer is a relational database that provides services for the web and is used to complete the storage of business data; The infrastructure layer is a container orchestration management platform, and the container orchestration management platform is based on a virtualized server and deploys and runs the virtual machine server system in a containerized and clustered manner.
6. The method for constructing a blockchain-based distributed digital identity management platform according to claim 5, wherein, It also includes the following steps: Design an interface for the key management system and connect it to the distributed digital identity management platform. Among them, the interface includes public-private key pair query, public-private key pair application, public key encryption, private key decryption, private key signature, public key verification signature, jws signature, and jws verification signature; The encryption algorithms in the key management system include symmetric encryption algorithms and asymmetric encryption algorithms. Among them, the symmetric encryption algorithm is AES, which is used in the serialization and deserialization processes, and the asymmetric encryption algorithms are secp256ki and SM commercial encryption algorithms, which are used in other encryption and decryption processes.
7. The method for constructing a blockchain-based distributed digital identity management platform according to claims 1 and 6, characterized in that, The key management system provides a key escrow function for the distributed digital identity management platform. The key generation process includes the following steps: Based on the encryption algorithm type submitted by the user at the application end of the distributed digital identity management platform, a new key request is generated. The DIDSDK calls the key service logic processing to create a public-private key pair. The key management system generates a unique key index based on the public-private key pair and returns it. The distributed digital identity management platform stores the unique key index.
8. A blockchain-based distributed digital identity management platform, characterized in that, It includes a distributed digital identity management platform, a blockchain underlying infrastructure, a blockchain gateway, and a key management system; The distributed digital identity management platform includes an application end and a DIDSDK. Among them, the application end is the entry platform for users to visually use DID services, providing DID business-related functions. The DIDSDK integrates DID-related interfaces and provides DID business logic processing; The blockchain gateway docks with the blockchain core service, and the distributed digital identity management platform completes transaction on-chain through the blockchain gateway; The blockchain underlying infrastructure provides blockchain core services; The key management system provides a key escrow function for the distributed digital identity management platform.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1-7.
10. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the computer program, it implements the method described in any one of claims 1-7.
Citation Information
Cited By
Container data safe use method and system based on decentralized identity
CN121664487A