Digital identity verification method and system based on block chain, and program product
Through a digital identity verification method combined with blockchain and knowledge graph, the user terminal's biological information and key password are used to generate public-private key pairs, solving the problem of users forgetting their ID documents, realizing financial services without documents, and improving user satisfaction and efficiency.
Patent Information
- Application Number
- CN202510811101.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-08-08
AI Technical Summary
Users are prone to forget to bring their ID documents and are unable to handle financial services, which affects user satisfaction.
Through the blockchain network and knowledge graph server, the biological information and key password of the user terminal are used to generate public and private key pairs and store them in the knowledge nodes to realize digital identity verification and replace traditional identity documents.
It realizes that financial services can be handled without bringing an ID card, improving users' financial service satisfaction and business processing efficiency.
Smart Images

Figure CN120454973A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology or other related fields, and in particular to a blockchain-based digital identity authentication method, system, and program product. Background Art
[0002] With the advancement of the digital age, the demand for personal identity verification is increasing. Traditional authentication methods, such as physical IDs, passwords, and security questions, face numerous challenges, including ease of forgetting, low security, high forgery potential, and an inability to adapt to trends in mobile payments and remote services. In the financial services sector, secure and efficient identity verification has become crucial, not only ensuring the security of user funds but also directly impacting user experience and service efficiency.
[0003] In real-world scenarios, many customers forget to bring their ID cards. Most transactions requiring an ID card can be completed with an electronic ID card or a photocopy. However, when retrieving a new card at a financial institution's offline branch, the original ID card must be used for activation at the terminal. This is a hardware requirement and cannot be processed without the original ID card.
[0004] In related technologies, electronic ID cards, driver's licenses and other documents are generally used to replace the original ID cards, or pre-set questions or emergency passwords are used to prove one's identity.
[0005] However, when proving the user's identity as described above, it is often necessary to set questions or emergency passwords in advance, and they can only prove the identity of the user. They cannot be used in scenarios where a photo of the ID card is required for record.
[0006] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0007] The embodiments of the present invention provide a blockchain-based digital identity authentication method, system, and program product to at least solve the technical problem in related technologies that users easily forget to carry their identity documents, are unable to handle financial transactions, and thus affect user satisfaction.
[0008] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a blockchain-based digital identity authentication method is provided, which is applied to a digital identity knowledge graph server, wherein the digital identity knowledge graph server is connected to a blockchain network, and N user-associated knowledge nodes are deployed in the digital identity knowledge graph server, where N is a positive integer, including: receiving an identity query request transmitted by any blockchain node in the blockchain network, wherein the identity query request includes at least: the identity information of the target user and the user identity digital signature, the blockchain node pre-establishing a network connection with financial business terminals distributed in various regions, the financial business terminal having pre-received an identity authentication request transmitted by the user terminal, wherein the identity authentication request includes at least: first biometric information and a first key password; querying the target knowledge node associated with the target user according to the identity information of the target user, Extract the public key stored in the target knowledge node, decrypt the user identity digital signature with the extracted public key to obtain a user identity information summary, wherein each knowledge node in the digital identity knowledge graph server pre-saves the user's identity information, biometric information, key password and public key; use a hash function to restore the electronic ID card encryption information in the user identity information summary, and transmit the electronic ID card encryption information, the second biometric information and the second key password to the financial business terminal through a secure channel, wherein, on the financial business terminal, the first biometric information and the second biometric information are compared and verified, and the first key password and the second key password are compared and verified; when the comparison and verification result indicates success, decrypt the electronic ID card encryption information to obtain the user digital identity of the target user.
[0009] Optionally, before receiving the identity query request transmitted by any blockchain node in the blockchain network, it also includes: receiving the decrypted ciphertext transmitted by the user terminal using the secure channel through the financial business terminal, and saving the decrypted ciphertext, wherein the user terminal uses the first proximal wireless communication module to pre-establish a network connection with the second proximal wireless communication module of the financial business terminal, and constructs the secure channel through the network connection; receiving the first biometric information and the first key password entered by the target user on the financial business terminal; responding to the identity authentication operation initiated by the user terminal through the financial business terminal, packaging the first biometric information and the first key password into an identity authentication request, and sending the identity authentication request to any blockchain node in the blockchain network using a secure channel.
[0010] Optionally, the step of decrypting the electronic ID card encrypted information to obtain the user digital identity of the target user includes: decrypting the electronic ID card encrypted information through the decrypted ciphertext transmitted by the user terminal to obtain the user digital identity of the target user.
[0011] Optionally, after comparing and verifying the first biometric information with the second biometric information, and comparing and verifying the first key password with the second key password, the method includes: if the comparison and verification result indicates a failure, generating an identity authentication failure prompt, and displaying the identity authentication failure prompt on the screen of the financial service terminal; if the number of consecutive failures of the comparison and verification results reaches a preset threshold, freezing the user digital identity of the target user.
[0012] Optionally, before receiving the identity query request transmitted by any blockchain node in the blockchain network, it also includes: responding to the identity registration operation initiated by the user terminal through the financial business terminal, and saving the electronic identity card encrypted information transmitted by the user terminal, wherein, after the user terminal opens the digital identity interface in the financial APP, the user terminal reads the user identity information through the first proximal wireless communication module of the user terminal, encrypts the user identity information using the financial APP, and generates electronic identity card encrypted information and decrypted ciphertext; collecting the user identity information and biometric information of the target user through the financial business terminal, wherein the biometric information includes at least one of the following: fingerprint, finger vein, 3D face, voiceprint or palmprint; receiving the digital password or gesture password set by the target user through the financial business terminal, and using the digital password or the gesture password as a key password; transmitting the user identity information, the biometric information and the key password to the digital identity knowledge graph server through the financial business terminal.
[0013] Optionally, after transmitting the user identity information, the biometric information and the key password to the digital identity knowledge graph server through the financial service terminal, it also includes: processing the biometric information and the key password according to a preset public-private key pair generation algorithm to generate a public-private key pair, and performing hash calculation on the electronic ID card encryption information to obtain a user identity information summary; using the private key in the public-private key pair to encrypt the user identity information summary to generate a user identity digital signature; entering the user identity information, the biometric information, the key password and the public key in the public-private key pair into the knowledge node associated with the target user; and transmitting the user identity information and the user identity digital signature to a blockchain node.
[0014] Optionally, after transmitting the user identity information and the user identity digital signature to the blockchain node, it also includes: encapsulating the user identity information and the user identity digital signature into transaction data through the blockchain node; uploading the transaction data carrying the transaction number to the blockchain network through the blockchain node using a preset consensus mechanism, and generating a digital identity registration success notification after the upload is successful; and sending the digital identity registration success notification to the financial business terminal through the blockchain node.
[0015] According to another aspect of an embodiment of the present invention, a blockchain-based digital identity authentication system is also provided, including: a user terminal, after opening the digital identity interface in a financial APP, an identity authentication request and a decrypted ciphertext are transmitted through the first proximal wireless communication module in the user terminal, wherein the identity authentication request includes at least: first biometric information and a first key password; a financial service terminal, establishing a secure channel with the first proximal wireless communication module of the user terminal through a second proximal wireless communication module, receiving the first biometric information and the first key password entered by the target user on the financial service terminal, responding to the identity authentication operation initiated by the user terminal, packaging the first biometric information and the first key password into an identity authentication request, and sending the identity authentication request to any blockchain node in the blockchain network using a secure channel; a blockchain network, including M blockchain nodes, wherein the blockchain node transmits the searched identity information of the target user and the user's digital identity signature to the digital identity knowledge graph server through a secure channel based on the identity authentication request, wherein each of the blockchain nodes pre-saves the user identity information and user identity digital signature, M is a positive integer; a digital identity information knowledge graph server receives an identity query request transmitted by any blockchain node in the blockchain network, queries the target knowledge node associated with the target user according to the identity information of the target user, extracts the public key stored in the target knowledge node, decrypts the user identity digital signature using the extracted public key to obtain a user identity information summary, uses a hash function to restore the electronic ID card encrypted information in the user identity information summary, and transmits the electronic ID card encrypted information, the second biometric information and the second key password to the financial service terminal through a secure channel, wherein N user-associated knowledge nodes are deployed in the digital identity knowledge graph server, N is a positive integer; wherein, on the financial service terminal, the first biometric information and the second biometric information are compared and verified, and the first key password and the second key password are compared and verified. When the comparison and verification result indicates success, the electronic ID card encrypted information is decrypted using the decrypted ciphertext to obtain the user digital identity of the target user.
[0016] Optionally, each knowledge node in the digital identity information knowledge graph server includes: a main node for storing the user's identity information; and multiple child nodes for storing the user's biometric information, key password, and public key.
[0017] Optionally, the financial service terminal also includes: an identity registration response unit, used to respond to the identity registration operation initiated by the user terminal, and save the electronic ID card encrypted information transmitted by the user terminal, wherein, after the user terminal opens the digital identity interface in the financial APP, the user terminal reads the user identity information through the first proximal wireless communication module of the user terminal, and uses the financial APP to encrypt the user identity information to generate electronic ID card encrypted information and decrypted ciphertext; a biometric information collection unit, used to collect the user identity information and biometric information of the target user, wherein the biometric information includes at least one of the following: fingerprint, finger vein, 3D face, voiceprint or palmprint; a password receiving unit, used to receive the digital password or gesture password set by the target user, and use the digital password or the gesture password as a key password; an identity information transmission unit, used to transmit the user identity information, the biometric information and the key password to the digital identity knowledge graph server.
[0018] Optionally, the digital identity information knowledge graph server also includes: a key pair generation unit, used to process the biometric information and the key password according to a preset public-private key pair generation algorithm to generate a public-private key pair, and perform hash calculation on the electronic ID card encryption information to obtain a user identity information summary; an identity information summary encryption unit, used to use the private key in the public-private key pair to encrypt the user identity information summary to generate a user identity digital signature; a knowledge node information entry unit, used to enter the user identity information, the biometric information, the key password and the public key in the public-private key pair into the knowledge node associated with the target user; a signature transmission unit, used to transmit the user identity information and the user identity digital signature to the blockchain node.
[0019] Optionally, each blockchain node in the blockchain network further includes: a signature encapsulation unit, used to encapsulate the user identity information and the user identity digital signature into transaction data; an information uploading unit, used to upload the transaction data carrying the transaction number to the blockchain network using a preset consensus mechanism, and after the upload is successful, generate a digital identity registration success notification; a notification sending unit, used to send the digital identity registration success notification to the financial service terminal.
[0020] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned blockchain-based digital identity authentication methods.
[0021] According to another aspect of an embodiment of the present invention, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the above-mentioned blockchain-based digital identity authentication methods.
[0022] According to another aspect of an embodiment of the present invention, a computer program product is also provided, including a computer program, which, when executed by a processor, implements the steps of any one of the above-mentioned blockchain-based digital identity authentication methods.
[0023] Based on the above-mentioned public content, the user's identity information can be read in advance by the proximal wireless communication module deployed in the financial business terminal, the user's identity information and user identity digital signature can be saved by the blockchain node, and the knowledge node in the knowledge graph can be used as a carrier of the digital identity information. In the subsequent use process, the knowledge graph server can be used to query the target knowledge node associated with the target user according to the identity information of the target user, and the user's electronic ID card encrypted information is obtained through the target knowledge node. Combined with the second biometric information and the second key password pre-stored in the knowledge node, it is transmitted to the financial business terminal through a secure channel. The electronic ID card encrypted information is decrypted using the decryption ciphertext on the financial business terminal to obtain the user's digital identity, so that the user's digital identity can be extracted only through the financial APP deployed on the user terminal. Using digital identity as an alternative to the ID card meets the customer needs of the financial industry, meets the user's financial business processing needs, and improves the user's financial service satisfaction, thereby solving the technical problem in the related technology that users easily forget to carry their identity documents, cannot handle financial business, and affect user satisfaction. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0025] Figure 1 is a schematic diagram of an optional blockchain-based digital identity authentication system according to an embodiment of the present invention;
[0026] Figure 2is a flowchart of an optional blockchain-based digital identity authentication method according to an embodiment of the present invention;
[0027] Figure 3 This is a structural block diagram of an electronic device for executing a blockchain-based digital identity authentication method according to an embodiment of the present application. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0029] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0030] To facilitate those skilled in the art to understand the present invention, some of the terms or nouns involved in the embodiments of the present invention are explained below:
[0031] Near Field Communication (NFC) is a short-range wireless communication technology that allows electronic devices to exchange data within a few centimeters. In this application, NFC is used to securely transmit user identity information and decrypted ciphertext between financial institution clients (such as mobile banking apps) and financial service terminals, ensuring that data cannot be intercepted or tampered with during transmission.
[0032] Publicly Switched Access (PSA) refers to a public-private key algorithm. In public-key cryptography, a public-private key pair is a set of keys generated by an algorithm, one of which is public (the public key) and the other must be kept secret (the private key). The algorithm used to generate the public-private key pair ensures the secure transmission and decryption of data. In the present invention, the public-private key pair is used to encrypt and decrypt a user's biometric information and key passwords, as well as to generate and verify a user's digital signature, thereby protecting the user's identity information from unauthorized access.
[0033] A hash function converts data of arbitrary length into a fixed-length output, called a hash value or digest. This conversion is typically one-way, meaning it's difficult to derive the original data from the hash value. In this invention, hash functions are used to protect the encrypted information in a user's electronic ID card. By calculating a digest of the encrypted information and then comparing this digest during the subsequent verification process, the integrity and consistency of the information can be confirmed without directly exposing the sensitive information itself.
[0034] A knowledge graph, or KG, is a structured data model used to represent entities and their relationships. It organizes and stores complex data in a graphical format, with nodes representing entities and edges representing relationships between them. In the context of the present invention, a knowledge graph server is used to store user identity information, biometric information, key passwords, and the public key of a public-private key pair. This enables the system to quickly retrieve and process relevant information about a user's identity while maintaining data integrity and consistency.
[0035] Blockchain is a distributed ledger technology that records and stores transaction data in a decentralized manner through a series of cryptographically linked data blocks (i.e., blocks). Each block contains the hash value of the previous block, forming a chain. This ensures that once data is written, it cannot be modified or deleted, improving data transparency, security, and tamper-resistance. In this invention, the blockchain network is used to store and verify user digital identity information, ensuring the security and credibility of this information while achieving decentralized data management and distributed identity authentication.
[0036] It should be noted that the blockchain-based digital identity authentication method and device thereof in the present disclosure can be used in the field of blockchain technology. When the registration, verification and update of digital identity are realized based on blockchain and knowledge graph, it can also be used in any field other than the field of blockchain technology. When the registration, verification and update of digital identity are realized based on blockchain and knowledge graph, the present disclosure does not limit the application field of the blockchain-based digital identity authentication method and device thereof.
[0037] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) collected by this disclosure are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of the relevant regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation portals for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or institution through the interface, and obtain relevant information after receiving the consent information fed back by the aforementioned user or institution.
[0038] It should be noted that in this disclosure, when collecting and analyzing customer information, the corresponding operation entrance is provided for users to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered.
[0039] The following embodiments of the present invention can be applied to various blockchain-based digital identity authentication systems / applications / devices. The present invention can be applied in the field of financial technology, particularly in scenarios requiring highly secure identity authentication, such as banking, payment systems, credit services, and insurance processing (e.g., banking, mobile payment, and cross-border financial services). For example, in banking, when opening an account, withdrawing money, transferring money, applying for a loan, and other services at a bank branch or through a bank self-service terminal, the knowledge graph-based and blockchain-based digital identity authentication system provided by the present invention can replace the use of traditional identity documents, thereby improving the security and efficiency of business processing.
[0040] This invention combines knowledge graphs and blockchain technology to encrypt, store, and verify user biometrics, effectively preventing identity tampering or misuse, and enhancing the security of financial services. It leverages NFC technology to rapidly read and transmit user identity information, combined with the efficient query capabilities of knowledge graphs, to shorten authentication and service processing wait times and enhance the user experience.
[0041] At the same time, this invention leverages the decentralized nature of blockchain to eliminate reliance on a single point of trust, reducing the risk of single points of failure and making identity management more transparent and reliable. The knowledge graph's real-time update capability ensures that changes to user identity information are promptly reflected in the system, eliminating the need for repeated entry. This simplifies the identity update process and improves the system's flexibility and responsiveness.
[0042] The present invention will be described in detail below with reference to various embodiments.
[0043] Example 1
[0044] This embodiment can construct a user's digital identity in the financial institution system, which includes ID card chip information, electronic ID card, user account related information, user biometric information, private key and public key, and use digital identity as an alternative to ID card.
[0045] First, combining knowledge graph and blockchain technology, a schematic illustration of the blockchain-based digital identity authentication system is given.
[0046] Figure 1 is a schematic diagram of an optional blockchain-based digital identity authentication system according to an embodiment of the present invention. Figure 1 As shown, the blockchain-based digital identity authentication system includes: multiple user terminals ( Figure 1 The financial service terminals deployed at each branch ( Figure 1 China-Israel business terminal 1, business terminal 2... business terminal N schematic), blockchain network ( Figure 1 including multiple blockchain network nodes), digital identity information knowledge graph server ( Figure 1 Including server 1, server 2 ... server N schematically). Next, Figure 1 Provide detailed description of each part.
[0047] After opening the digital identity interface in the financial APP, the user terminal transmits an identity authentication request and a decrypted ciphertext through the first proximal wireless communication module in the user terminal, where the identity authentication request includes at least: the first biometric information and the first key password.
[0048] In this embodiment, when a user terminal (such as a smartphone equipped with a bank financial APP) opens the digital identity interface in the financial APP, the interface will guide the user to touch the corresponding module on the financial service terminal through the built-in first proximal wireless communication module (such as an NFC module), thereby triggering the transmission of an identity authentication request. The identity authentication request is constructed through a secure near-field communication protocol and contains the first biometric information provided by the user (such as fingerprint, facial recognition, etc.) and the first key password (a password or gesture set by the user). This information will be encrypted before transmission to ensure that it is not stolen or tampered with during air transmission. The decrypted ciphertext is the decrypted part of the encrypted information generated by the user terminal after reading the information on the identity document chip. It is only stored in the user terminal and used for the subsequent identity information decryption process.
[0049] The financial service terminal establishes a secure channel with the first proximal wireless communication module of the user terminal through the second proximal wireless communication module, receives the first biometric information and the first key password input by the target user on the financial service terminal, responds to the identity authentication operation initiated by the user terminal, packages the first biometric information and the first key password into an identity authentication request, and sends the identity authentication request to any blockchain node in the blockchain network using the secure channel.
[0050] It should be noted that the financial service terminal in this embodiment is equipped with a second near-end wireless communication module (such as an NFC card reader) for establishing a secure channel with the user terminal. This secure channel is established based on near-field communication protocols and encryption technology to ensure the secure transmission of user information between the terminal and the user terminal. When a user enters their first biometric information and first key password into the financial service terminal, the terminal responds to the identity authentication operation initiated by the user terminal and sends the input information to the blockchain network via an identity authentication request.
[0051] Furthermore, encryption technology is used in both the packaging and sending of the identity authentication request in this embodiment to ensure the confidentiality and integrity of the data. After receiving the response, the financial service terminal can perform corresponding business operations based on the identity authentication result, such as account query and transaction execution.
[0052] The blockchain network includes M blockchain nodes. Based on the identity authentication request, the blockchain node transmits the searched target user's identity information and user's digital identity signature to the digital identity knowledge graph server through a secure channel. Among them, each blockchain node pre-stores the user's identity information and user's digital identity signature, and M is a positive integer.
[0053] The blockchain network in this embodiment consists of M distributed blockchain nodes, where M is a positive integer representing the network's scale and distribution characteristics. The blockchain network is designed to provide a decentralized, secure, and transparent environment for storing and verifying users' digital identity information. When a financial service terminal sends an identity authentication request, any blockchain node searches for the user data stored on it based on the user identity information in the request. Once a matching target user information, including identity information and the user's digital identity signature, is found, the node encapsulates and encrypts this data and sends it via a secure channel to the digital identity knowledge graph server for further authentication. The user's digital identity signature is generated by a private key and is used to verify the integrity and authenticity of the user's identity information.
[0054] The digital identity information knowledge graph server receives an identity query request transmitted by any blockchain node in the blockchain network, queries the target knowledge node associated with the target user according to the identity information of the target user, extracts the public key stored in the target knowledge node, decrypts the user identity digital signature by using the extracted public key to obtain the user identity information summary, uses the hash function to restore the electronic ID card encrypted information in the user identity information summary, and transmits the electronic ID card encrypted information, the second biometric information and the second key password to the financial business terminal through a secure channel, wherein N user-associated knowledge nodes are deployed in the digital identity knowledge graph server, and N is a positive integer; wherein, on the financial business terminal, the first biometric information and the second biometric information are compared and verified, and the first key password and the second key password are compared and verified. When the comparison and verification result indicates success, the electronic ID card encrypted information is decrypted using the decrypted ciphertext to obtain the user digital identity of the target user.
[0055] The digital identity information knowledge graph server in this embodiment is a component that stores and queries user information. It deploys N user-associated knowledge nodes, where N is a positive integer representing the server's storage capacity and the breadth of its user base. Optionally, each knowledge node in the digital identity information knowledge graph server includes a master node, which stores the user's identity information; and multiple child nodes, which store the user's biometric information, key passwords, and public keys. In this embodiment, the core design of the digital identity information knowledge graph server revolves around individual nodes for each user, which are subdivided into two categories: master nodes and child nodes. The master node is primarily responsible for storing user identity information, including but not limited to static identity attributes such as the user's name and ID number, which serve as the foundation of the user's digital identity. The multiple child nodes are used to store more detailed and personalized data, such as the user's biometric information (fingerprints, finger veins, 3D facial recognition, voiceprints, palmprints), key passwords (digital passwords or gesture passwords), and public keys. This structural design ensures centralized management of static user identity information while enabling decentralized storage of biometrics, keys, and public keys, improving data security and system scalability.
[0056] When the knowledge graph server receives an identity query request transmitted by a blockchain node, it searches for the target knowledge node in the knowledge graph based on the target user identity information in the request. After finding the target knowledge node, the knowledge graph server extracts the public key from it and uses it to decrypt the user identity digital signature and restore the user identity information summary. Subsequently, the server uses a hash function to decode the electronic ID card encrypted information from the summary and sends it together with the second biometric information and the second key password to the financial service terminal. The second biometric information and the second key password are user authentication information stored in the knowledge graph and are used to compare and verify with the first biometric information and the first key password entered by the user on the financial service terminal. After successful verification, the financial service terminal uses the received decrypted ciphertext to decrypt the electronic ID card encrypted information, ultimately obtaining the target user's complete user digital identity information, and then performs corresponding operations according to business needs.
[0057] The blockchain-based digital identity authentication system can pre-read a user's identity information using a near-end wireless communication module deployed in a financial service terminal, store the user's identity information and digital signature using a blockchain node, and use knowledge nodes in a knowledge graph as carriers of the digital identity information. In subsequent use, the knowledge graph server can query a target knowledge node associated with the target user based on the target user's identity information. The target knowledge node can then be used to obtain the user's encrypted electronic ID card information. This information, combined with the second biometric information and the second key password pre-stored in the knowledge node, is transmitted to the financial service terminal via a secure channel. The encrypted electronic ID card information is then decrypted on the financial service terminal using a decryption ciphertext to obtain the user's digital identity. This allows the user's digital identity to be extracted solely through a financial application (APP) deployed on the user terminal. Using digital identity as an alternative to ID cards satisfies the customer needs of the financial industry, meets the financial service processing needs of users, and improves user satisfaction with financial services. This addresses the technical issue in related technologies where users easily forget to carry their ID documents, are unable to conduct financial services, and thus suffer from low user satisfaction.
[0058] Optionally, the financial service terminal also includes: an identity registration response unit, used to respond to the identity registration operation initiated by the user terminal, and save the electronic ID card encrypted information transmitted by the user terminal, wherein, after the user terminal opens the digital identity interface in the financial APP, the user terminal reads the user identity information through the first proximal wireless communication module of the user terminal, and uses the financial APP to encrypt the user identity information to generate electronic ID card encrypted information and decrypted ciphertext; a biometric information collection unit, used to collect user identity information and biometric information of the target user, wherein the biometric information includes at least one of the following: fingerprint, finger vein, 3D face, voiceprint or palmprint; a password receiving unit, used to receive the digital password or gesture password set by the target user, and use the digital password or gesture password as a key password; an identity information transmission unit, used to transmit the user identity information, biometric information and key password to the digital identity knowledge graph server.
[0059] It should be noted that the financial service terminal in this embodiment integrates a series of functional units to support comprehensive digital identity management. First, the identity registration response unit is used to respond to identity registration operations initiated by the user terminal (the device running the mobile banking app). When the user initiates the identity registration process through the digital identity interface in the financial app and uses the first near-end wireless communication module (such as NFC) to read and transmit ID information, the terminal's identity registration response unit is responsible for receiving and storing the generated electronic ID card encryption information and decrypted ciphertext. The latter is only stored locally on the user terminal for subsequent decryption. The biometric information collection unit is used to collect the user's biometric information, which constitutes an important component of the user's digital identity and increases the complexity and security of identity authentication. The password receiving unit is responsible for receiving the user's customized key password, which can be a numeric password or a unique gesture password, to protect the user's biometric information and identity information. Finally, the identity information transmission unit is responsible for transmitting all collected information, including user identity information, biometric information, and key password, to the digital identity information knowledge graph server for further processing and storage.
[0060] Optionally, the digital identity information knowledge graph server also includes: a key pair generation unit, which is used to process the biometric information and key password according to a preset public-private key pair generation algorithm to generate a public-private key pair, and perform hash calculation on the electronic ID card encrypted information to obtain a user identity information summary; an identity information summary encryption unit, which is used to encrypt the user identity information summary using the private key in the public-private key pair to generate a user identity digital signature; a knowledge node information entry unit, which is used to enter the user identity information, biometric information, key password and the public key in the public-private key pair into the knowledge node associated with the target user; a signature transmission unit, which is used to transmit the user identity information and the user identity digital signature to the blockchain node.
[0061] It should be noted that the digital identity information knowledge graph server in this embodiment also has several key processing function units. Among them, the key pair generation unit adopts a preset public-private key pair generation algorithm to generate a public-private key pair for encryption and decryption based on the user's biometric information and key password, thereby strengthening the security of user information and ensuring that unauthorized third parties cannot access or tamper with user data. The identity information summary encryption unit converts the electronic ID card encrypted information into a user identity information summary through hash calculation, and then encrypts this summary using the private key to generate a user identity digital signature, further verifying the authenticity and integrity of the user identity information. Furthermore, all user information is entered into the knowledge node associated with the user through the knowledge node information entry unit to ensure centralized storage and convenient query of information. Finally, this embodiment transmits the encapsulated user identity information and its corresponding digital signature to the blockchain node through the signature transmission unit to complete the chain process and create a blockchain record of the digital identity.
[0062] Optionally, each blockchain node in the blockchain network also includes: a signature encapsulation unit, used to encapsulate user identity information and user identity digital signature into transaction data; an information uploading unit, used to upload the transaction data carrying the transaction number to the blockchain network using a preset consensus mechanism, and after the upload is successful, generate a digital identity registration success notification; a notification sending unit, used to send the digital identity registration success notification to the financial business terminal.
[0063] It should be noted that in the blockchain network of this embodiment, each blockchain node is equipped with a corresponding functional unit to process identity registration transactions. Specifically, the signature encapsulation unit is responsible for combining user identity information and the user's digital signature to encapsulate transaction data, which is the basic unit of blockchain network transactions. The information upload unit, using a pre-defined consensus mechanism such as proof-of-work, proof-of-stake, or other variants, uploads the transaction data along with a unique transaction number to the blockchain network. This upload process is encrypted and verified, ensuring the irreversibility and security of the transaction. Upon successful upload, the node generates a digital identity registration success notification, indicating that the user's digital identity has been officially registered on the blockchain network. Finally, the notification sending unit transmits the registration success notification back to the financial service terminal, informing the user that their digital identity has been successfully created and can be used for subsequent business operations and identity authentication.
[0064] This embodiment of the present invention combines knowledge graphs with blockchain technology. Leveraging the flexibility and query efficiency of knowledge graphs, it provides users with fast and accurate identity verification services. Furthermore, leveraging the immutability and distributed nature of blockchain, it builds a decentralized and secure digital identity management system, effectively mitigating the risks of data leakage and identity theft. The use of public-private key pairs and hashing techniques ensures the security of user biometric information, identity information, and transaction data, making it difficult to decrypt or tamper with even if the data is intercepted during transmission.
[0065] Furthermore, this embodiment can also simplify the steps of user identity registration and verification through the integration of NFC and financial APP, reduce the user's operation time in front of the terminal, and improve service efficiency.
[0066] This embodiment uses ID card chip information as the main digital identity information, supplementing various user information to enrich the digital identity. Using knowledge graphs and blockchain technology as the technical foundation, it creates a three-dimensional, secure, and convenient financial digital identity. In the current environment of widespread internet access and the pursuit of convenience and efficiency, and where permitted by laws and regulations, digital identity can provide customers with a convenient and efficient way to handle daily transactions, greatly improving the customer experience.
[0067] This embodiment uses a knowledge graph as a carrier for digital identity information, leveraging its vast knowledge storage capacity, real-time updates, and support for multilingual, multimodal, and complex queries to fully meet the customer needs of the financial industry. Most importantly, the knowledge graph's knowledge data supports complex data with high latitude, multiple languages, and heterogeneous structures. This allows for the storage of various types of user biometric information without the worry of data type unsupported. Furthermore, the dynamic extensibility of knowledge will also support richer and more advanced authentication methods in the future.
[0068] Example 2
[0069] According to an embodiment of the present invention, an embodiment of a blockchain-based digital identity authentication method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in an order different from that shown here.
[0070] It should be noted that the blockchain-based digital identity authentication method provided in this embodiment can be applied to the blockchain-based digital identity authentication system in Example 1. The blockchain-based digital identity authentication method is described in detail below in conjunction with the blockchain-based digital identity authentication system in Example 1.
[0071] According to one aspect of the present application, a blockchain-based digital identity authentication method is provided, which is applied to a digital identity knowledge graph server, the digital identity knowledge graph server is connected to a blockchain network, and N user-associated knowledge nodes are deployed in the digital identity knowledge graph server, where N is a positive integer.
[0072] Figure 2 is a flowchart of an optional blockchain-based digital identity authentication method according to an embodiment of the present invention. Figure 2 As shown, the blockchain-based digital identity authentication method includes the following steps:
[0073] Optionally, before receiving an identity query request transmitted by any blockchain node in the blockchain network, the decrypted ciphertext transmitted by the user terminal using a secure channel is received through the financial business terminal, and the decrypted ciphertext is saved, wherein the user terminal uses a first proximal wireless communication module to pre-establish a network connection with a second proximal wireless communication module of the financial business terminal, and builds a secure channel through the network connection; receives the first biometric information and the first key password entered by the target user on the financial business terminal; responds to the identity authentication operation initiated by the user terminal through the financial business terminal, packages the first biometric information and the first key password into an identity authentication request, and sends the identity authentication request to any blockchain node in the blockchain network using a secure channel.
[0074] In this embodiment, the initial stage of the digital identity verification process involves establishing a secure channel between the user terminal and the financial service terminal. Here, the digital identity interface of a pre-installed financial app on the user terminal can be opened. Subsequently, the user terminal's first proximal wireless communication module (e.g., NFC) makes physical contact with the financial service terminal's second proximal wireless communication module, triggering the establishment of a network connection. The secure channel is based on near-field communication technology, ensuring the privacy and integrity of information transmission through encryption and authentication mechanisms. The user terminal first transmits decrypted ciphertext over this secure channel. This ciphertext, generated after reading and encrypting the user's ID card information, serves as the key for subsequently decrypting the encrypted information on the electronic ID card. Upon receiving the decrypted ciphertext, the financial service terminal securely stores it for use in subsequent identity verification.
[0075] Once a stable secure channel is established, the financial service terminal provides a user interface for entering the primary biometric information (such as fingerprint or facial recognition) and the primary key password (a user-defined numeric or gesture password) required for identity verification. This information is then combined with the previously received decrypted ciphertext to form an authentication request. The authentication request comprises multiple dimensions of user-provided information, which is encrypted and encapsulated to protect user privacy and prevent data interception or tampering during transmission. Once encapsulation is complete, the financial service terminal utilizes the previously established secure channel to send the authentication request to any blockchain node in the blockchain network, initiating the authentication process. The establishment and use of the secure channel in this embodiment combines the physical proximity requirements of near-field communication with the data protection of encryption technology, providing an additional layer of security for the creation and verification of user digital identities.
[0076] This embodiment integrates financial apps and NFC technology to seamlessly connect user terminals to financial service terminals, simplifying the authentication process. Instead of manually entering complex information, users can quickly authenticate using biometrics and ciphertext, improving the user experience.
[0077] Step S201: Receive an identity query request transmitted by any blockchain node in the blockchain network, wherein the identity query request includes at least: identity information of the target user and the user's identity digital signature; the blockchain node has pre-established a network connection with financial service terminals distributed in various regions; the financial service terminal has pre-received an identity authentication request transmitted by the user terminal, wherein the identity authentication request includes at least: first biometric information and a first key password.
[0078] In this embodiment, step S201 describes the process by which the digital identity knowledge graph server receives an identity query request from any node in the blockchain network. The identity query request carries the target user's identity information and the user's digital signature, which serves as the core basis for verifying the authenticity and integrity of the user's digital identity. This request is initiated by the blockchain node's pre-established network connection with financial service terminals distributed across the country. This means that the blockchain network can instantly respond to requests from financial service terminals and provide the necessary user authentication services, regardless of the user's location.
[0079] Optionally, before receiving an identity query request transmitted by any blockchain node in the blockchain network, it also includes: responding to the identity registration operation initiated by the user terminal through the financial business terminal, and saving the electronic identity card encrypted information transmitted by the user terminal, wherein, after the user terminal opens the digital identity interface in the financial APP, the user identity information is read through the first proximal wireless communication module of the user terminal, and the user identity information is encrypting the user identity information using the financial APP to generate electronic identity card encrypted information and decrypted ciphertext; collecting user identity information and biometric information of the target user through the financial business terminal, wherein the biometric information includes at least one of the following: fingerprint, finger vein, 3D face, voiceprint or palmprint; receiving the digital password or gesture password set by the target user through the financial business terminal, and using the digital password or gesture password as the key password; transmitting the user identity information, biometric information and key password to the digital identity knowledge graph server through the financial business terminal.
[0080] In this embodiment, the interaction between a user terminal and a financial service terminal begins with an identity registration operation initiated by the user through the digital identity interface within a financial app. The user terminal utilizes a built-in first proximal wireless communication module (e.g., NFC) to establish a connection with the second proximal wireless communication module of the financial service terminal, thereby establishing a secure channel. Within this secure channel, the user terminal reads the user's identity information and encrypts it using the app's built-in encryption algorithm to generate encrypted electronic ID information. To ensure decryption feasibility, a decrypted ciphertext is generated. This ciphertext is stored only on the user terminal and serves as the key for subsequent decryption processes. The financial service terminal acts as an information collector in this process, not only receiving the decrypted ciphertext from the user terminal but also collecting the target user's first biometric information and first key password. Biometric information can include, but is not limited to, fingerprints, finger veins, 3D facial features, voiceprints, or palmprints. These biometric features provide multiple layers of authentication. The key password is a user-defined numeric password or gesture password that encrypts and encapsulates the biometric and identity information, further enhancing security. Finally, the financial service terminal integrates all collected information into an identity authentication request and forwards it to the digital identity knowledge graph server.
[0081] In this embodiment, digital identity operations are divided into two phases: identity registration and identity verification. During the user-initiated identity registration phase, a secure channel is established between the financial app and the financial service terminal, transmitting encrypted personal information and the generated decrypted ciphertext. The financial service terminal further collects the user's biometric information and a pre-set key password to form an identity authentication request, which is ultimately sent to the digital identity knowledge graph server for information storage and key pair generation. During the identity verification phase, when user identity verification is required, the financial service terminal receives the user's input biometric information and key password, forms an identity query request, and submits it to the digital identity knowledge graph server through any node in the blockchain network. The server uses the stored public key to decrypt the user's digital signature, recovering the user's identity information digest to confirm the legitimacy of the user's identity.
[0082] By combining NFC technology, public-private key encryption, and the immutable nature of blockchain, this embodiment provides a multi-layered security system that effectively prevents the leakage and tampering of user identity information while protecting user privacy. Any node in the blockchain network can respond to authentication requests, demonstrating the decentralized nature of the system. This reduces reliance on single points of failure, ensures data authenticity and consistency, and enhances system stability and efficiency.
[0083] Optionally, after transmitting the user identity information, biometric information and key password to the digital identity knowledge graph server through the financial business terminal, it also includes: processing the biometric information and key password according to a preset public-private key pair generation algorithm to generate a public-private key pair, and performing hash calculation on the electronic ID card encryption information to obtain a user identity information summary; using the private key in the public-private key pair to encrypt the user identity information summary to generate a user identity digital signature; entering the user identity information, biometric information, key password and the public key in the public-private key pair into the knowledge node associated with the target user; and transmitting the user identity information and the user identity digital signature to the blockchain node.
[0084] In this embodiment, after identity information, biometric information, and key passwords are transmitted to the digital identity knowledge graph server, the server processes this sensitive information using a pre-defined public-private key pair generation algorithm to generate a public-private key pair. The private key in this key pair is kept strictly confidential, while the public key is used for subsequent transaction verification. Simultaneously, the server performs a hash calculation on the encrypted information in the electronic ID card to generate a user identity information digest. This digest is an irreversible conversion of the original data, protecting sensitive information while ensuring data uniqueness and integrity. The server then uses the generated private key to encrypt the user identity information digest to generate the user's digital signature. Digital signatures are created based on the principles of public key cryptography to verify the source and integrity of information and are a critical step in ensuring data authenticity in digital identity systems.
[0085] After the digital signature is generated, the digital identity knowledge graph server in this embodiment executes the process of entering the execution information into the knowledge node. Optionally, after transmitting the user identity information and the user identity digital signature to the blockchain node, the process further includes: encapsulating the user identity information and the user identity digital signature into transaction data via the blockchain node; uploading the transaction data, including the transaction number, to the blockchain network via the blockchain node using a preset consensus mechanism, and generating a digital identity registration success notification upon successful upload; and sending the digital identity registration success notification to the financial service terminal via the blockchain node. This embodiment enters the user's identity information, biometric information, key password, and the public key of the public-private key pair into the knowledge node associated with the target user, ensuring centralized storage and rapid retrieval of user information. Furthermore, the association with the public key enhances information security verification.
[0086] Next, the blockchain node takes over data processing, encapsulating the user's identity information and digital signature into transaction data. This encapsulation process includes formatting and encrypting the data to ensure the security and privacy of the transaction data during transmission on the blockchain network. Transaction data upload is achieved through a pre-defined consensus mechanism. Consensus mechanisms such as proof-of-work and proof-of-stake control data entry within the blockchain network, ensuring data reliability and immutability. Upon successful upload, the blockchain node generates a digital identity registration success notification, confirming that the user's digital identity has been officially registered on the blockchain network, ensuring traceability and trustworthiness.
[0087] After transaction data is successfully uploaded to the blockchain network, the blockchain node is responsible for sending a notification of successful digital identity registration to the financial service terminal. This not only ensures a two-way flow of information but also forms a closed-loop business process, enhancing the transparency and reliability of the system. Upon receiving the notification, the financial service terminal can inform the user of the completion of digital identity registration, allowing the user to use the digital identity to participate in subsequent financial services and transactions.
[0088] By generating public-private key pairs and creating digital signatures, this embodiment ensures the accuracy and immutability of user identity information, improving the overall security of the system. Furthermore, the hash algorithm-based information summary mechanism provides additional assurance of data integrity and consistency. The entry and management of knowledge nodes leverages the structured storage advantages of the knowledge graph, enabling efficient retrieval of user information and rapid response to authentication requests. This is crucial for improving the efficiency of financial services and user satisfaction.
[0089] Step S202: query the target knowledge node associated with the target user based on the target user's identity information, extract the public key stored in the target knowledge node, decrypt the user identity digital signature using the extracted public key, and obtain the user identity information summary, wherein each knowledge node in the digital identity knowledge graph server pre-stores the user's identity information, biometric information, key password, and public key.
[0090] In this embodiment, step S202 describes how the digital identity knowledge graph server processes identity query requests from blockchain nodes. Upon receiving a request containing the target user's identity information and the user's digital signature, the server immediately initiates a query mechanism to search for the associated target knowledge node. The knowledge graph server already has multiple knowledge nodes, each storing key user information, including identity information, biometric information, key passwords, and public keys. This information constitutes the complete picture of the user's digital identity.
[0091] After finding the corresponding target knowledge node, the server extracts the stored public key from the node. This public key is used to decrypt the user's digital signature. This signature is created during the registration phase by encrypting the user's identity information summary with the private key. It is used to verify the authenticity and integrity of the user's identity information. By decrypting this signature with the public key, the server can recover the user's identity information summary. This is a crucial step in the authentication process, ensuring the correct transmission and interpretation of information.
[0092] In step S203, a hash function is used to restore the electronic ID card encrypted information in the user identity information summary, and the electronic ID card encrypted information, the second biometric information, and the second key password are transmitted to the financial service terminal through a secure channel. At the financial service terminal, the first biometric information and the second biometric information are compared and verified, and the first key password and the second key password are compared and verified.
[0093] After decryption is complete, step S203 involves using a hash function to restore the encrypted electronic ID information within the user identity information digest. In this embodiment, the hash function is used to extract the encrypted ID information from the digest. This process reversely verifies the original state of the encrypted information and further confirms the accuracy of the user identity information. The restored encrypted electronic ID information, along with the second biometric information and second key password extracted from the target knowledge node, is transmitted to the financial service terminal via a pre-established secure channel.
[0094] After receiving this information, the financial service terminal performs a two-step verification process. First, the terminal compares the first biometric information entered by the user on-site with the second biometric information received from the digital identity knowledge graph server to confirm the consistency of the biometric features. Second, the terminal also compares the first key password entered by the user with the second key password to ensure that the keys and passwords match. Only after both verifications pass is the user considered successfully authenticated. The terminal then uses the decryption ciphertext to decrypt the encrypted information on the electronic ID card, obtaining the user's complete digital identity and completing subsequent financial service operations.
[0095] By combining two-factor authentication of biometric information and key passwords, this embodiment greatly improves the accuracy of identity authentication and effectively reduces the occurrence of identity impersonation and fraud incidents.
[0096] Optionally, after comparing and verifying the first biometric information with the second biometric information, and comparing and verifying the first key password with the second key password, the method includes: if the comparison and verification result indicates a failure, generating an identity authentication failure prompt, and displaying the identity authentication failure prompt on the screen of the financial service terminal; if the number of consecutive failures of the comparison and verification results reaches a preset threshold, freezing the user digital identity of the target user.
[0097] In this embodiment, when a financial service terminal performs a biometric and key password comparison verification, if it detects that the entered first biometric information does not match the second biometric information stored in the knowledge graph, or if the first key password does not match the second key password, the system triggers specific security measures. If the comparison verification result indicates a failure, the financial service terminal's software system generates an authentication failure notification. This notification is designed to be clear and concise to prevent potential attackers from accessing sensitive information. The financial service terminal then displays the authentication failure notification on the screen, prompting the user to try again or to verify that the entered biometric information and key password are correct.
[0098] To further enhance security, this embodiment introduces a monitoring mechanism for the number of consecutive failures. Once a user enters incorrect biometric information and / or key passwords during the identity authentication process for a preset number of times, the system will take more stringent measures, namely freezing the target user's digital identity. The threshold is set based on security policies, aiming to balance user experience with security requirements. For example, if the preset failure threshold is three, and the user fails to successfully verify their identity in three attempts, the financial service terminal will send a freeze request to the digital identity knowledge graph server. Upon receiving the request, the server will immediately freeze all knowledge nodes associated with the user, preventing further use of the user's digital identity until the unfreezing process is completed. This mechanism effectively prevents malicious attempts and unauthorized use of identity information, protecting the security of user assets and personal information.
[0099] It should be noted that in this embodiment, when identity verification fails, the prompt message displayed on the financial service terminal screen is not only a simple warning, but also an educational tool to encourage users to properly use and protect their digital identity. For example, the user can be prompted to "make sure your hands are dry and try fingerprint recognition again" or "be aware of ambient noise and re-record your voiceprint sample," thereby reducing the number of verification failures caused by improper operation.
[0100] Once a user's digital identity is frozen, it can be restored through the customer service hotline, online customer service, or manual verification at a bank branch. In these channels, the user needs to provide additional identity proof, such as the original ID card, answers to reserved security questions, or further biometric verification to ensure that the unfreezing operation will not be exploited by unauthorized parties.
[0101] Step S204: If the comparison and verification result indicates success, decrypt the encrypted information of the electronic ID card to obtain the user digital identity of the target user.
[0102] In this embodiment, step S204 details the key operation after successful identity verification: decrypting the encrypted electronic ID information to obtain the target user's complete digital identity. This process restores the digital identity from an encrypted state to a readable state, allowing the financial service terminal to use this information to perform subsequent business processing.
[0103] The user's digital identity, obtained by the financial service terminal after successful decryption, is formed through multi-step data processing and verification. From the initial ID card reading and information encryption at the user terminal, to the collection of biometric information and key passwords by the financial service terminal, to the public and private key processing and information storage on the digital identity knowledge graph server, and finally to the packaging and recording of transaction data on the blockchain network, each step provides the necessary data support and security guarantees for the creation and acquisition of the user's digital identity. The acquisition of a user's digital identity is the final result of this process, representing the completion of user identity verification and the starting point for conducting financial business.
[0104] Optionally, the step of decrypting the electronic ID card encrypted information to obtain the user digital identity of the target user includes: decrypting the electronic ID card encrypted information through the decryption ciphertext transmitted by the user terminal to obtain the user digital identity of the target user.
[0105] When the verification result indicates success, the financial service terminal prepares to decrypt the encrypted information on the electronic ID card. The decryption process relies on the decrypted ciphertext generated and securely stored by the user terminal during the registration process. The user terminal transmits the decrypted ciphertext to the financial service terminal via a secure channel through the digital identity interface of the financial app. This transmission process adheres to strict encryption and authentication protocols, ensuring the security of the decrypted ciphertext during transmission and preventing it from being intercepted by third parties.
[0106] After receiving the decrypted ciphertext, the financial service terminal applies it to the decryption process of the electronic ID card's encrypted information. This matching of the decrypted ciphertext with the electronic ID card's encrypted information is based on secure interaction between the user terminal and the financial service terminal using NFC technology. The decryption process is performed by the terminal's built-in security module, ensuring that the decryption operation is performed in a highly secure environment and protecting user information from being leaked.
[0107] After successful decryption, the financial service terminal will be able to obtain the target user's digital identity. This digital identity, which includes the user's basic identity information, biometric information, key password, and public key, serves as the user's unique identifier and pass in the digital financial ecosystem. After obtaining the user's digital identity, the terminal can further perform various financial business operations related to the user, such as account inquiries, transaction authorizations, and loan applications, without the need for the user's physical ID card to be physically present.
[0108] The above-mentioned blockchain-based digital identity authentication method receives an identity query request transmitted by any blockchain node in the blockchain network, wherein the identity query request includes at least: the identity information of the target user and the user's identity digital signature. The blockchain node pre-establishes a network connection with the financial service terminals distributed in various regions. The financial service terminals have pre-received the identity authentication request transmitted by the user terminal, and the identity authentication request includes at least: the first biometric information and the first key password. According to the identity information of the target user, the target knowledge node associated with the target user is queried, the public key stored in the target knowledge node is extracted, and the user's identity digital signature is decrypted by the extracted public key to obtain A user identity information summary, wherein each knowledge node in the digital identity knowledge graph server pre-saves the user's identity information, biometric information, key password and public key, uses a hash function to restore the electronic ID card encryption information in the user identity information summary, and transmits the electronic ID card encryption information, the second biometric information and the second key password to the financial business terminal through a secure channel, wherein, on the financial business terminal, the first biometric information and the second biometric information are compared and verified, and the first key password and the second key password are compared and verified. When the comparison and verification result indicates success, the electronic ID card encryption information is decrypted to obtain the user digital identity of the target user.
[0109] In this embodiment, the user's identity information can be read in advance by using the proximal wireless communication module deployed in the financial business terminal, the user's identity information and user identity digital signature can be stored by using the blockchain node, and the knowledge node in the knowledge graph can be used as a carrier of the digital identity information. In the subsequent use process, the knowledge graph server can be used to query the target knowledge node associated with the target user according to the identity information of the target user, and the user's electronic ID card encrypted information can be obtained through the target knowledge node. Combined with the second biometric information and the second key password pre-stored in the knowledge node, the encrypted information is transmitted to the financial business terminal through a secure channel. The electronic ID card encrypted information is decrypted using the decryption ciphertext on the financial business terminal to obtain the user's digital identity, so that the user's digital identity can be extracted only through the financial APP deployed on the user terminal. The digital identity is used as an alternative to the ID card, which meets the customer needs of the financial industry and the user's financial business processing needs, and improves the user's financial service satisfaction, thereby solving the technical problem in the related technology that users easily forget to carry their identity documents, cannot handle financial business, and affect user satisfaction.
[0110] In this embodiment, through efficient data interaction between the user terminal and the financial service terminal, this embodiment can quickly complete identity authentication and digital identity acquisition, avoiding the tedious steps of traditional identity document verification, and greatly improving the efficiency of financial service processing and user experience.
[0111] The acquisition of user digital identity provides the basis for the development of financial services. Whether it is ATM self-service, online banking operations, or counter services, users only need to complete identity authentication through their devices (such as smartphones), adapting to the financial industry's growing demand for efficient, convenient and secure digital services.
[0112] The embodiment of the present invention is described below in conjunction with another specific implementation manner.
[0113] 1) Registration process:
[0114] Step 1: The user uses a personal mobile phone (with NFC functionality) to open the financial institution's app. After entering the digital identity interface, they place their original ID card near the phone's NFC module. The NFC module reads the ID card's chip. The financial institution's app verifies and encrypts the ID card chip information, generating encrypted electronic ID information and decrypted ciphertext. The phone's NFC module then interacts with the terminal's NFC module, transmitting the encrypted electronic ID card information to the terminal via a secure channel. After the transfer is complete, the encrypted electronic ID card information is deleted, leaving only the decrypted ciphertext stored on the user's personal phone, accessible only to the financial institution's app.
[0115] Step 2: Confirm the transmission results from Step 1 on the business terminal and collect the user's identity information and biometric information, including but not limited to fingerprints, finger veins, 3D facial recognition, voiceprints, and palm prints. Finally, set a 6-digit password or a 3x3 gesture password as a key password. The information collected in Steps 1 and 2 is transmitted together through a secure channel to the digital identity knowledge graph server.
[0116] Step 3: On the digital identity knowledge graph server, the user's biometric information and key password are processed according to the PSA public-private key pair generation algorithm to generate a public-private key pair. The encrypted information from the electronic ID card is then hashed to obtain the user's identity information digest. The user's identity information digest is encrypted using the private key to generate the user's identity digital signature. The user's identity information, biometric information, key password, and public key serve as knowledge nodes to form a knowledge graph. If the knowledge graph is generated successfully, the user's identity information and digital signature are transmitted to the blockchain network node via a secure channel. If generation fails, a failure result is returned to the terminal, and step 2 is repeated.
[0117] Step 4: After receiving the user's identity information and digital signature, the blockchain network node encapsulates the transaction data and attaches the transaction number to upload to the entire blockchain network. The transaction is recorded in a new block through the relevant consensus mechanism, ultimately forming a new blockchain. If the upload is successful, a success result is returned to the terminal, notifying the user that their digital identity registration was successful. If the upload fails, step 3 is repeated.
[0118] 2) Certification process:
[0119] Step 1: The user uses a personal mobile phone (with NFC function) to open the financial institution's app and enter the digital identity interface. After unlocking the digital identity function, the user brings the mobile phone's NFC module close to the terminal's NFC module to interact, and the decrypted ciphertext is transmitted to the business terminal through a secure channel.
[0120] Step 2: After confirming the transmission result from Step 1 on the business terminal, the user enters their biometric information and key password on the business terminal to initiate an identity authentication request. This user's identity information is then sent to any blockchain network node via a secure channel. The user's identity information is then retrieved from the blockchain network node, where it was stored during registration. If the user's identity information is found, the next step is executed; otherwise, Step 1 is repeated.
[0121] Step 3: The blockchain network node transmits the user identity information and the user identity digital signature to the digital identity knowledge graph server via a secure channel. If found, the next step is executed; otherwise, step 1 is repeated.
[0122] Step 4: The digital identity knowledge graph server queries the user's relevant knowledge nodes based on the user's identity information. It extracts the public key stored in the knowledge node and decrypts the user's digital signature to obtain the user's identity information digest. A hash function is then used to recover the encrypted electronic ID information. The encrypted electronic ID information, user biometric information, and key password are then transmitted to the service terminal via a secure channel. If the transmission is successful, the next step is executed; otherwise, step 1 is repeated.
[0123] Step 5: On the business terminal, the user's biometric information and key password are compared and verified with the biometric information and key password returned by the digital identity knowledge graph server. If verification fails, the user is prompted to re-enter their biometric information and key password. After three failures, the user's digital identity is frozen. If verification succeeds, the decrypted ciphertext transmitted in Step 1 is used to decrypt the encrypted electronic ID card information transmitted in Step 4. If decryption is successful, the business process begins using the digital identity. If it fails, repeat Step 1.
[0124] 3) Update process:
[0125] The update process is basically the same as the registration process. You only need to collect the updated information in step 1 and step 2. You don’t need to enter the unchanged information again.
[0126] However, since the blockchain system is a decentralized distributed environment, in order to ensure data reliability and security, the block data information on the blockchain cannot be modified or adjusted. Therefore, in this embodiment, the user identity information is updated by adding new block information.
[0127] The technical effects that can be achieved through the above implementation include:
[0128] 1. Use the ID card chip information as the main information of the digital identity, supplement various types of user information to enrich the digital identity, and use knowledge graph and blockchain technology as the technical foundation to create a three-dimensional, secure and convenient financial digital identity. Through digital identity, it provides customers with a convenient and fast processing method in the process of daily financial business, which can greatly improve the customer's user experience.
[0129] 2. By using the knowledge graph as a carrier for digital identity information, leveraging its vast knowledge storage capacity, real-time updates, and support for multilingual, multimodal, and complex queries, it fully meets the customer needs of the financial industry. Crucially, the knowledge graph supports complex data with high dimensionality, multiple languages, and heterogeneous structures. This allows for the storage of a wide range of user biometric information without the challenges of unsupported data types. Furthermore, the dynamic extensibility of knowledge will support even richer and more advanced authentication methods in the future.
[0130] 3. By using biometric information such as fingerprints, finger veins, 3D facial features, voiceprints, and palm prints as a means of entity identification and authentication, the user's entity identity information can be more accurately reflected, effectively ensuring the accuracy and reliability of user identity recognition. In addition, to protect the security of biometric information such as fingerprints and facial features, it is also possible to consider fusing multiple biometric information of the user as a unique authentication identifier for the entity's identity.
[0131] 4. By adopting blockchain technology, user identity information and digital signatures are securely stored in the form of blocks on the blockchain network. This information is then shared across the blockchain network, allowing each blockchain node to access the identity information of each entity in the network, thereby achieving decentralized management of identity information. This also enables local identification of user entities, improving authentication efficiency and effectively supporting remote login and authentication needs.
[0132] Example 3
[0133] An embodiment of the present application may provide an electronic device, Figure 3 This is a structural block diagram of an electronic device for executing a blockchain-based digital identity authentication method according to an embodiment of the present application. Figure 3As shown, the electronic device may include: one or more ( Figure 3 Only one is shown) processor 302, memory 304, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.
[0134] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the blockchain-based digital identity authentication method and device in the embodiments of this application. The processor executes the software programs and modules stored in the memory to perform various functional applications and data processing, thereby implementing the aforementioned blockchain-based digital identity authentication method. The memory can include high-speed random access memory (RAM) and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory may further include memory located remotely from the processor, which can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0135] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: receiving an identity query request transmitted by any blockchain node in the blockchain network, wherein the identity query request at least includes: the identity information of the target user and the user's identity digital signature, the blockchain node pre-establishes a network connection with the financial business terminals distributed in various regions, and the financial business terminal has pre-received an identity authentication request transmitted by the user terminal, and the identity authentication request at least includes: the first biometric information and the first key password; querying the target knowledge node associated with the target user according to the identity information of the target user, extracting the public key stored in the target knowledge node, and verifying the user's identity digital signature through the extracted public key. The first biometric information and the second biometric information are compared and verified on the financial service terminal, and the first key password and the second key password are compared and verified on the financial service terminal; when the comparison and verification result indicates success, the electronic ID card encrypted information is decrypted to obtain the user digital identity of the target user.
[0136] It can be understood by those skilled in the art that Figure 3The structure shown is for illustration only, and the electronic device may also be a smart phone, a tablet computer, a PDA, a mobile Internet device (MID), a PAD or other terminal device. Figure 3 It does not limit the structure of the above electronic device. For example, the electronic device may also include Figure 3 More or fewer components (such as network interfaces, display devices, etc.) shown in, or with Figure 3 Different configurations shown.
[0137] Those skilled in the art will understand that all or part of the steps in the various blockchain-based digital identity authentication methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0138] Example 4
[0139] The embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the blockchain-based digital identity authentication method provided in the first embodiment.
[0140] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is further provided, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the blockchain-based digital identity authentication methods in the above-mentioned embodiment 1.
[0141] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0142] The present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the blockchain-based digital identity authentication method described in each embodiment of the present application.
[0143] The present application also provides a computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the blockchain-based digital identity authentication method described in each embodiment of the present application are implemented.
[0144] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0145] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0146] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0147] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0148] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0149] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.
[0150] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A digital identity authentication method based on blockchain, characterized in that: Applied to a digital identity knowledge graph server, the digital identity knowledge graph server is connected to a blockchain network, and the digital identity knowledge graph server deploys N user-associated knowledge nodes, where N is a positive integer, including: Receiving an identity query request transmitted by any blockchain node in the blockchain network, wherein the identity query request includes at least: identity information of a target user and a digital signature of the user's identity, the blockchain node pre-establishing a network connection with financial service terminals distributed in various regions, the financial service terminals having pre-received an identity authentication request transmitted by a user terminal, wherein the identity authentication request includes at least: first biometric information and a first key password; Querying the target knowledge node associated with the target user based on the target user's identity information, extracting the public key stored in the target knowledge node, and decrypting the user identity digital signature using the extracted public key to obtain a user identity information summary, wherein each knowledge node in the digital identity knowledge graph server pre-stores the user's identity information, biometric information, key password, and public key; Using a hash function to restore the electronic ID card encrypted information in the user identity information digest, and transmitting the electronic ID card encrypted information, the second biometric information, and the second key password to the financial service terminal via a secure channel, wherein the first biometric information and the second biometric information are compared and verified on the financial service terminal, and the first key password and the second key password are compared and verified; If the comparison and verification result indicates success, the electronic ID card encrypted information is decrypted to obtain the user digital identity of the target user.
2. The digital identity authentication method according to claim 1, characterized in that: Before receiving an identity query request transmitted by any blockchain node in the blockchain network, the method further includes: receiving, by the financial service terminal, a decrypted ciphertext transmitted by a user terminal via a secure channel, and storing the decrypted ciphertext, wherein the user terminal pre-establishes a network connection with a second proximal wireless communication module of the financial service terminal via a first proximal wireless communication module, and constructs the secure channel via the network connection; receiving the first biometric information and the first key password input by the target user on the financial service terminal; The financial service terminal responds to the identity authentication operation initiated by the user terminal, packages the first biometric information and the first key password into an identity authentication request, and sends the identity authentication request to any blockchain node in the blockchain network using a secure channel.
3. The digital identity authentication method according to claim 2, characterized in that: The step of decrypting the encrypted information of the electronic ID card to obtain the user digital identity of the target user includes: The electronic identity card encrypted information is decrypted by the decrypted ciphertext transmitted by the user terminal to obtain the user digital identity of the target user.
4. The digital identity authentication method according to claim 1, wherein: After comparing and verifying the first biometric information with the second biometric information and comparing and verifying the first key password with the second key password, the method includes: If the comparison verification result indicates a failure, generating an identity authentication failure prompt, and displaying the identity authentication failure prompt on the screen of the financial service terminal; When the number of failures in the continuous comparison and verification results reaches a preset threshold, the user digital identity of the target user is frozen.
5. The digital identity authentication method according to claim 1, characterized in that: Before receiving an identity query request transmitted by any blockchain node in the blockchain network, the method further includes: The financial service terminal responds to an identity registration operation initiated by a user terminal and saves the encrypted electronic ID card information transmitted by the user terminal. After the user terminal opens the digital identity interface in the financial app, the user terminal reads the user identity information through the first proximal wireless communication module of the user terminal, encrypts the user identity information using the financial app, and generates encrypted electronic ID card information and decrypted ciphertext. collecting user identity information and biometric information of the target user through the financial service terminal, wherein the biometric information includes at least one of the following: fingerprint, finger vein, 3D face, voiceprint or palmprint; receiving, through the financial service terminal, a numeric password or a gesture password set by the target user, and using the numeric password or the gesture password as a key password; The user identity information, the biometric information and the key password are transmitted to the digital identity knowledge graph server through the financial service terminal.
6. The digital identity authentication method according to claim 5, characterized in that: After transmitting the user identity information, the biometric information, and the key password to the digital identity knowledge graph server through the financial service terminal, the method further includes: Processing the biometric information and the key password according to a preset public-private key pair generation algorithm to generate a public-private key pair, and performing a hash calculation on the electronic ID card encrypted information to obtain a user identity information summary; Encrypting the user identity information summary using the private key in the public-private key pair to generate a user identity digital signature; Entering the user identity information, the biometric information, the key password, and the public key of the public-private key pair into a knowledge node associated with the target user; The user identity information and the user identity digital signature are transmitted to the blockchain node.
7. The digital identity authentication method according to claim 6, characterized in that: After transmitting the user identity information and the user identity digital signature to the blockchain node, the method further includes: Encapsulating the user identity information and the user identity digital signature into transaction data through the blockchain node; The transaction data and the transaction number are uploaded to the blockchain network by the blockchain node using a preset consensus mechanism, and a digital identity registration success notification is generated after the upload is successful; The blockchain node sends a notification of successful digital identity registration to the financial service terminal.
8. A digital identity authentication system based on blockchain, characterized in that: include: The user terminal, after opening the digital identity interface in the financial app, transmits an identity authentication request and a decrypted ciphertext through the first proximal wireless communication module in the user terminal, wherein the identity authentication request includes at least: first biometric information and a first key password; The financial service terminal establishes a secure channel with the first proximal wireless communication module of the user terminal via the second proximal wireless communication module, receives the first biometric information and the first key password input by the target user on the financial service terminal, responds to the identity authentication operation initiated by the user terminal, packages the first biometric information and the first key password into an identity authentication request, and sends the identity authentication request to any blockchain node in the blockchain network via the secure channel; A blockchain network, comprising M blockchain nodes, wherein the blockchain nodes transmit the searched identity information and user digital identity signature of the target user to the digital identity knowledge graph server through a secure channel based on the identity authentication request, wherein each blockchain node pre-stores the user's identity information and user digital identity signature, and M is a positive integer; The digital identity information knowledge graph server receives an identity query request transmitted by any blockchain node in the blockchain network, queries a target knowledge node associated with the target user based on the identity information of the target user, extracts a public key stored in the target knowledge node, decrypts the user identity digital signature using the extracted public key to obtain a user identity information summary, uses a hash function to restore the electronic ID card encrypted information in the user identity information summary, and transmits the electronic ID card encrypted information, the second biometric information, and the second key password to the financial service terminal via a secure channel, wherein N user-associated knowledge nodes are deployed in the digital identity knowledge graph server, where N is a positive integer; Among them, on the financial service terminal, the first biometric information and the second biometric information are compared and verified, and the first key password and the second key password are compared and verified. When the comparison and verification result indicates success, the decryption ciphertext is used to decrypt the electronic ID card encrypted information to obtain the user digital identity of the target user.
9. The digital identity verification system according to claim 8, characterized in that: Each knowledge node in the digital identity information knowledge graph server includes: Master node, used to store user identity information; Multiple child nodes are used to store the user's biometric information, key password, and public key.
10. The digital identity verification system according to claim 8, characterized in that: The financial service terminal further includes: an identity registration response unit, configured to respond to an identity registration operation initiated by the user terminal and save the encrypted electronic ID card information transmitted by the user terminal, wherein, after the user terminal opens the digital identity interface in the financial app, the user terminal reads the user identity information through the first proximal wireless communication module of the user terminal, encrypts the user identity information using the financial app, and generates encrypted electronic ID card information and decrypted ciphertext; A biometric information collection unit, configured to collect user identity information and biometric information of the target user, wherein the biometric information includes at least one of the following: fingerprint, finger vein, 3D face, voiceprint, or palmprint; A password receiving unit, configured to receive a numeric password or a gesture password set by the target user, and use the numeric password or the gesture password as a key password; An identity information transmission unit is used to transmit the user identity information, the biometric information and the key password to the digital identity knowledge graph server.
11. The digital identity verification system according to claim 8, wherein: The digital identity information knowledge graph server also includes: a key pair generation unit, configured to process the biometric information and the key password according to a preset public-private key pair generation algorithm to generate a public-private key pair, and perform a hash calculation on the electronic ID card encrypted information to obtain a user identity information digest; An identity information summary encryption unit, configured to encrypt the user identity information summary using the private key in the public-private key pair to generate a user identity digital signature; A knowledge node information entry unit, configured to enter the user identity information, the biometric information, the key password, and the public key of the public-private key pair into the knowledge node associated with the target user; The signature transmission unit is used to transmit the user identity information and the user identity digital signature to the blockchain node.
12. The digital identity verification system according to claim 8, characterized in that: Each blockchain node in the blockchain network also includes: A signature encapsulation unit, configured to encapsulate the user identity information and the user identity digital signature into transaction data; An information uploading unit, configured to upload the transaction data and the transaction number to the blockchain network using a preset consensus mechanism, and generate a notification of successful digital identity registration after successful upload; A notification sending unit is used to send the digital identity registration success notification to the financial service terminal.
13. An electronic device, characterized in that: The system comprises one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the blockchain-based digital identity authentication method according to any one of claims 1 to 7.
14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the blockchain-based digital identity authentication method described in any one of claims 1 to 7 are implemented.