Method and system for processing credentials in distributed identity

By introducing proxy nodes in a distributed identity system and adopting vertically derived and horizontally aggregated credential presentation strategies, the problems of low communication efficiency and inflexible credential presentation in traditional systems are solved, and more efficient and secure credential circulation and verification are achieved.

CN120455027APending Publication Date: 2025-08-08TSINGHUA UNIVERSITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410176912.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-08
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The issuance, presentation and update of credentials in traditional distributed identity systems require the holder to communicate directly with the issuer, resulting in a bottleneck in communication with the communication efficiency, and the flexibility and accuracy of credentials are insufficient, affecting the security and efficiency of the system.

Method used

The proxy node role is introduced, and the identity of edge nodes is managed through the proxy nodes. The vertically derived and horizontally aggregated credential presentation strategy is adopted, so that identity holders can freely split and merge credentials for presentation, reducing direct communication with the issuer.

Benefits of technology

It improves the efficiency of credential circulation, the accuracy and security of verification, and at the same time improves communication efficiency and alleviates the communication pressure of issuing nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455027A_ABST
    Figure CN120455027A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for processing a voucher in a distributed identity. The method comprises the following steps: an agent node forwards an identity issuing request of an edge node to an issuing node; the issuing node issues and returns the main voucher to the proxy node; the edge node receives an identity verification request proposed by the other edge node as a verifier and sends the identity verification request to the proxy node; the agent node generates a presentation voucher according to a preset selective disclosure strategy and returns the presentation voucher to the verifier; the strategy comprises a longitudinally derived and transversely aggregated certificate presentation strategy, and the strategy is used for exposing and verifying one or more original attributes in the main certificate as derived presentation certificates, or re-aggregating the derived certificates to obtain an aggregated certificate. According to the invention, a flexible longitudinal and transverse voucher showing scheme is provided, so that an identity holder can freely split and merge vouchers for showing without communicating with an issuer, the voucher circulation efficiency and the verification accuracy and security are improved, and the communication efficiency is improved at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of distributed technology, and in particular to a method and system for processing credentials in a distributed identity. Background Art

[0002] This section is intended to provide a background or context to the embodiments of the invention that are recited in the claims. No statement herein is admitted to be prior art by virtue of its inclusion in this section.

[0003] A decentralized distributed identity system refers to a physical digital identity management model based on trusted technologies such as blockchain. The main participants are the holder (Holder), the issuer (Issuer), and the verifier (Verifier). From the perspective of application services, it mainly includes the anonymous issuance of physical identities, certificate maintenance, credential presentation, credential updates, etc.

[0004] Currently, distributed digital identity has been widely used in fields such as finance, e-commerce, and social networking. Distributed digital identity systems effectively protect user privacy and security in identity authentication, passwordless secure login, personal privacy protection, digital copyright protection, IoT, and edge computing applications. They also help combat false identification and fraud, contributing to a healthier, more transparent, and more efficient digital society. Regarding system implementation, uPort, Hyperledger Indy, and Sovrin are currently available. uPort, a distributed digital identity management service based on Ethereum, allows users to authenticate, log in without passwords, digitally sign, and interact with other applications on Ethereum. Hyperledger Indy is a distributed ledger application designed to decentralize identity information, with digital identities stored on blockchains or other distributed ledgers. Sovrin is a protocol for user-sovereign identity and decentralized trust, aiming to build a global distributed identity system based on blockchain technology, providing hardware, security, and network support for the creation of a digital identity network for users worldwide.

[0005] With the expansion of data volumes and the frequent flow of data elements in the digital age, secure, accurate, and efficient digital identity governance is a key challenge in promoting the development of industrial applications. In traditional distributed identity systems, the issuance, presentation, and update of credentials require direct communication between the holder and the issuer. As the total number of users in the system increases, the issuer's communication efficiency becomes a bottleneck for the entire digital identity system. As the circulation of various services increases, the presentation of credentials requires greater flexibility and accuracy. During the final settlement phase of user services, accurate certificate verification also becomes a security goal of the system. Summary of the Invention

[0006] An embodiment of the present invention provides a method for processing credentials in a distributed identity, which is used to propose a flexible vertical and horizontal credential presentation solution, allowing identity holders to freely split and combine credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation and the accuracy and security of verification, while also improving communication efficiency. The system for processing credentials in a distributed identity includes: an issuing node based on a distributed digital identity, at least one proxy node, and at least one edge node corresponding to each proxy node; the method for processing credentials in a distributed identity includes:

[0007] The proxy node forwards the identity issuance request of the edge node to the issuing node;

[0008] The issuing node issues the master certificate based on the identity issuance request and returns it to the proxy node;

[0009] The edge node receives an authentication request from another edge node as a verifier and sends the authentication request to the proxy node;

[0010] The proxy node generates a presentation credential and returns it to the verifier based on a preset selective disclosure strategy; the selective disclosure strategy includes: a credential presentation strategy of vertical derivation and horizontal aggregation, which is used to disclose and verify one or more original attributes in the master credential as a derived presentation credential, or to re-aggregate the derived credential to obtain an aggregated credential as the presentation credential.

[0011] An embodiment of the present invention further provides a system for processing credentials in a distributed identity, which is used to propose flexible vertical and horizontal credential presentation solutions, allowing identity holders to freely split and combine credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation and the accuracy and security of verification, while also improving communication efficiency. The system includes: an issuing node, at least one proxy node, and at least one edge node corresponding to each proxy node; wherein:

[0012] Proxy node, used to forward the identity issuance request of the edge node to the issuing node;

[0013] The issuing node is used to issue the primary certificate and return it to the proxy node based on the identity issuance request;

[0014] The edge node receives an authentication request from another edge node as a validator and sends the authentication request to the proxy node.

[0015] The proxy node is configured to generate a presentation credential and return it to the verifier based on a preset selective disclosure strategy; the selective disclosure strategy includes a vertical derivation and horizontal aggregation credential presentation strategy, wherein the strategy is configured to disclose and verify one or more original attributes of the master credential as a derived presentation credential, or to re-aggregate the derived credential to obtain an aggregated credential as the presentation credential.

[0016] An embodiment of the present invention further provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned method for processing credentials in a distributed identity when executing the computer program.

[0017] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the method for processing credentials in the distributed identity is implemented.

[0018] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the above-mentioned method for processing credentials in a distributed identity.

[0019] The solution for processing credentials in a distributed identity proposed in the present invention has the following beneficial technical effects:

[0020] First, the embodiments of the present invention propose flexible "vertical / derivative" and "horizontal / aggregate" credential presentation processes: the master credentials of all identities can be presented based on the statement issued by the verifier, and the proxy node can split all the original attributes in the master credential into credential fragments one by one to generate vertical / derivative credentials; the proxy node can also aggregate the selected multiple credential fragments according to the attribute key values required in the statement to generate horizontal / aggregate credentials; both types of generated credentials can be verified and presented. Therefore, the present invention proposes a flexible vertical and horizontal credential presentation scheme, which allows identity holders to freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation processing.

[0021] Secondly, the system for processing credentials in a distributed identity in an embodiment of the present invention includes: an issuing node based on a distributed digital identity, at least one proxy node and at least one edge node corresponding to each proxy node. The proxy node role is introduced in the embodiment of the present invention and deployed in the organizer who owns the edge node. As the real identity holder, it helps the edge node manage its identity, alleviates the communication pressure of the issuing node, improves the hardware processing speed, and improves the communication efficiency.

[0022] In summary, the present invention proposes a flexible vertical and horizontal credential presentation scheme, which allows identity holders to freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation and the accuracy and security of verification, while also improving communication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0024] Figure 1 This is a schematic diagram of the overall system architecture in an embodiment of the present invention;

[0025] Figure 2 This is a schematic diagram of the entire life cycle of an identity credential in an embodiment of the present invention;

[0026] Figure 3 A schematic diagram of the relationship between the three types of credentials, namely, "primary credential, derived credential, and aggregated credential," in an embodiment of the present invention;

[0027] Figure 4 Schematic diagram of a flow chart of a method for processing credentials in a distributed identity according to an embodiment of the present invention;

[0028] Figure 5 Schematic diagram of the structure of a system for processing credentials in a distributed identity according to an embodiment of the present invention. DETAILED DESCRIPTION

[0029] To make the purpose, technical solutions and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below with reference to the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.

[0030] The acquisition, storage, use, and processing of data in the technical solution of this application comply with relevant laws and regulations.

[0031] Taking into account the technical problems existing in the prior art, an embodiment of the present invention proposes a solution for processing credentials in a distributed identity. This solution is a system architecture solution that can flexibly manage anonymous credentials in a distributed identity. The solution for processing credentials in a distributed identity is introduced in detail below.

[0032] like Figure 1 and Figure 5As shown, the system for processing credentials in a distributed identity includes: an issuing node based on a distributed digital identity, at least one proxy node, and at least one edge node corresponding to each proxy node; Figure 4 FIG. 1 is a flow chart of a method for processing credentials in a distributed identity according to an embodiment of the present invention. Figure 4 As shown, the method includes the following steps:

[0033] Step 101: The proxy node forwards the identity issuance request of the edge node to the issuing node;

[0034] Step 102: The issuing node issues a master certificate based on the identity issuance request and returns it to the proxy node for management;

[0035] Step 103: The edge node receives an authentication request from another edge node as a verifier, and sends the authentication request to the proxy node;

[0036] Step 104: The proxy node generates a presentation credential based on a preset selective disclosure strategy and returns it to the verifier; the selective disclosure strategy includes: a vertical derivation and horizontal aggregation credential presentation strategy, which is used to disclose and verify one or more original attributes in the master credential as a derived presentation credential, or to re-aggregate the derived credential to obtain an aggregated credential as the presentation credential.

[0037] The method for processing credentials in a distributed identity proposed in the present invention has the following beneficial technical effects:

[0038] First, the embodiments of the present invention propose flexible "vertical / derivative" and "horizontal / aggregate" credential presentation processes: the master credentials of all identities can be presented based on the statement (disclosure statement request, identity verification request) issued by the verifier, and the proxy node can split all the original attributes in the master credential into credential fragments one by one to generate vertical / derivative credentials; the proxy node can aggregate the selected multiple credential fragments according to the attribute key values required in the statement to generate horizontal / aggregate credentials; both generated credentials can be verified and presented. Therefore, the present invention proposes a flexible vertical and horizontal credential presentation scheme, which allows identity holders to freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation processing.

[0039] Secondly, the system for processing credentials in a distributed identity in an embodiment of the present invention includes: an issuing node based on a distributed digital identity, at least one proxy node and at least one edge node corresponding to each proxy node. In the embodiment of the present invention, a secondary proxy node role is introduced and deployed on an organizer with an edge node, as a real identity holder, to help the edge node manage its identity, thereby alleviating the communication pressure of the issuing node, improving the hardware processing speed, improving the hardware processing speed, and improving the communication efficiency. Therefore, the method for processing credentials in a distributed identity requested for protection in this application, its solution involves the improvement of artificial intelligence and big data algorithms, which have a specific technical connection with the internal structure of the computer system and can solve the technical problem of how to improve the hardware computing efficiency or execution effect, for example: introducing a secondary proxy node role and deploying it on an organizer with an edge node, as a real identity holder, to help the edge node manage its identity, thereby alleviating the communication pressure of the issuing node, improving the hardware system processing speed, and further improving the communication efficiency, thereby improving the internal performance of the computer system.

[0040] In summary, the present invention proposes a flexible vertical and horizontal credential presentation method, which allows identity holders to freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation and the accuracy and security of verification, while also improving communication efficiency.

[0041] The following combination Figures 1 to 3 A detailed introduction to the method of processing credentials in this distributed identity is given.

[0042] The method for processing credentials in a distributed identity proposed in an embodiment of the present invention: 1) In response to the security and efficiency issues of the entire life cycle of a distributed digital identity, the embodiment of the present invention introduces the concept of a blinding factor (blinded identity attribute) on the identity credential, so that the credentials can be operated in batches on an anonymous basis, and the efficiency is also improved on the basis of ensuring the privacy and security of the identity attributes; 2) In response to the problem that distributed digital identity operations are diverse and frequent, the embodiment of the present invention proposes a flexible vertical and horizontal credential presentation scheme, so that identity holders can freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of system credential circulation; 3) In order to improve the practicality and compatibility of the embodiment of the present invention, the embodiment of the present invention proposes the concept of a secondary proxy node, which is compatible with the existing industrial Internet identity resolution system. 4) In order to enhance the security and rationality of the system, all credential operations in the embodiment of the present invention can be proved by security regulations, while realizing member management of provable existence and non-existence of system users, further improving the practical security of identity credential management. A detailed introduction is given below.

[0043] The embodiment of the present invention adopts a three-tier architecture based on the issuing node, proxy node, and edge node of distributed digital identity. The overall system architecture is as follows: Figure 1shown.

[0044] The entire life cycle of the system identity credential is as follows Figure 2 (exist Figure 2 In the process, the proxy node acts as the real identity holder to help the edge node manage its identity credentials. Figure 2 The verifier in the example can be any edge node), and the detailed process is as follows:

[0045] 1) Initialize key generation

[0046] During the initialization phase, the system distributes public-private key pairs to all users, and the issuing node additionally allocates a public-private key pair for certificate revocation.

[0047] 2) Issuance of certificates

[0048] When entering the system, the edge node makes an identity registration request to the proxy node of its organization; the proxy node sends the blinded identity attributes after Pederson commitment to the issuing node; the issuing node generates the corresponding blinded certificate based on the attributes submitted by the proxy node and returns the certificate to the proxy node; after receiving the blinded certificate, the proxy node performs an unblinding operation to obtain the master certificate of the corresponding original attributes of the edge node.

[0049] As can be seen from the above, in one embodiment, the method for processing credentials in the distributed identity further includes: issuing a master credential according to the following method:

[0050] When an edge node enters a system that can flexibly handle anonymous credentials, it initiates an identity registration request to the proxy node of its organization;

[0051] When receiving the identity registration request, the proxy node includes the blinded identity attribute in the identity issuance request and sends it to the issuing node;

[0052] The issuing node generates a blinded certificate containing the primary certificate based on the blinded identity attributes and returns the blinded certificate to the proxy node;

[0053] After receiving the blinded certificate, the proxy node performs an unblinding operation to obtain the master certificate of the corresponding original attribute of the edge node.

[0054] In specific implementation, the embodiment of the present invention aims at the security and efficiency issues of distributed digital identity throughout its entire life cycle. This architecture introduces the concept of blinding factors into identity credentials, allowing credentials to be operated in batches on an anonymous basis, thereby improving efficiency while ensuring the privacy and security of identity attributes.

[0055] 3) Presentation of credentials

[0056] When the edge node makes an authentication request as a verifier, the proxy node adopts a flexible selective disclosure strategy, which mainly includes vertical / derived and horizontal / aggregated credential presentation. It can not only reveal and verify one or more attributes in the main credential, but also re-aggregate the derived credentials to obtain new verifiable credentials and return the generated presentation credentials to the verifier.

[0057] As can be seen from the above, the method for processing credentials in a distributed identity provided by an embodiment of the present invention includes: the proxy node forwards the identity issuance request of the edge node to the issuing node; the issuing node issues a master credential and returns it to the proxy node based on the identity issuance request; the edge node receives the identity authentication request submitted by another edge node as a verifier and sends the identity authentication request to the proxy node; the proxy node generates a presentation credential and returns it to the verifier based on a preset selective disclosure strategy; the selective disclosure strategy includes: a vertical derivation and horizontal aggregation credential presentation strategy, which is used to disclose and verify one or more original attributes in the master credential as a derived presentation credential, or to re-aggregate the derived credential to obtain an aggregated credential as a presentation credential. The present invention proposes a flexible vertical and horizontal credential presentation method, which allows identity holders to freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation and the accuracy and security of verification, while also improving communication efficiency. To improve the practicality and compatibility of this system architecture, the embodiment of the present invention also considers credential formats that are compatible with existing standards. At the same time, the architecture also proposes the concept of proxy nodes, which is compatible with the existing industrial Internet identity resolution system.

[0058] 4) Verification of credentials

[0059] When the verifier receives the presented credential, it does not necessarily verify it immediately. When verification is required, the verifier needs to query the current public global state and membership proof of the edge node related to the presented credential; the verifier verifies the presented credential based on the query value and obtains the credential authentication result.

[0060] As can be seen from the above, in one embodiment, the method for processing credentials in the distributed identity further includes:

[0061] After receiving the presentation certificate returned by the proxy node, the other edge node, as a verifier, queries the current public global status and member proof of the edge node related to the certificate if it needs to verify the presentation certificate; based on the current public global status and member proof of the edge node related to the returned presentation certificate, it verifies the presentation certificate and obtains the authentication result of the certificate identity attribute.

[0062] In specific implementation, the above-mentioned credential verification method provided by the embodiment of the present invention improves the practical security of identity credential management.

[0063] 5) Credential Update

[0064] When an edge node actively or passively generates a revocation request, its proxy node will integrate the revocation request and send it to the issuing node. After the issuing node verifies the revocation request, it updates the global state of the edge node and returns the membership certificate to the proxy node.

[0065] As can be seen from the above, in one embodiment, the method for processing credentials in the distributed identity further includes:

[0066] When the current edge node actively or passively generates a revocation request, the proxy node of the current edge node integrates the revocation request and sends it to the issuing node;

[0067] After the issuing node verifies the revocation request, it updates the global status of the current edge node and returns the update result to the proxy node of the current edge node.

[0068] In specific implementation, the above-mentioned credential updating method provided by the embodiment of the present invention further improves the efficiency of credential circulation and the accuracy and security of verification.

[0069] 6) Other components

[0070] In addition, the embodiment of the present invention also maintains a set of edge entity public global states for managing the member states and corresponding witness certificates of each node in the system. In particular, in Algorithm 1 (Issuance of Credentials), the random prime number selected by the proxy node through HashToPrime() can represent the unique identity identifier of the edge entity, that is, in one embodiment, the random prime number selected by the proxy node through the HashToPrime() function represents the unique identity identifier of the edge node. Through this function, the issuing node does not need to perform trusted initialization to assign identifiers to each node, and the proxy node does not need to generate additional communication with the issuing node, thereby reducing the computational load and communication bandwidth of the issuing node and improving system efficiency. The prime number is also used to query and verify the witness certificate and global state of the corresponding member, that is, in one embodiment, the random prime number selected by the proxy node through HashToPrime() is used to generate the member certificate. The random prime number generated by this function is used as the unique identity identifier of the edge entity, thereby querying and verifying the member witness certificate and current global state of the entity. This function ensures the uniqueness of the random prime number under a certain space length.

[0071] Through the verification parts of the above-mentioned algorithms, as well as the "credential update" and "other components" solutions, the system security and rationality are enhanced. That is, all credential operations in the embodiments of the present invention can be proved by security regulations, and at the same time, member management with provable existence and non-existence of system users is realized, further improving the practical security of identity credential management.

[0072] To further understand the entire lifecycle process of the above identity credentials, the following is an introduction combined with application scenarios.

[0073] The concept of the industrial value chain, or industrial supply chain, which integrates the various processes involved in production (and services) and is supported by the World Trade Organization (WTO), is rapidly evolving. In modern industrial society, concerns are growing about the environmental degradation caused by this industrial revolution. The Carbon2Chem project is dedicated to cross-industry collaboration to recycle top gases (such as CO2) from industrial production. To achieve carbon neutrality through further emission reduction measures, Carbon2Chem aims to record every emission information (such as the carbon footprint) associated with the production process, from the beginning to the end of the value chain.

[0074] In fact, many companies and organizations are exploring such use cases. For example, Ethereum has conducted some experiments and proposed the Ethereum Energy Consumption Index (EECI). According to the EECI, for example, the carbon footprint of an Ethereum transaction is 115.26 kg of CO2, which provides an up-to-date estimate of the total energy consumption of the Ethereum network. Obviously, this emission reduction information must be accurately identified and proven to third parties.

[0075] To achieve carbon traceability across industrial value chains, this application is a good candidate for identity management. A carbon emission allowance is the amount of carbon dioxide a company is allowed to emit by relevant authorities. When a company achieves emission reductions, the resulting allowance can be sold for additional profit. In this system, each unit of carbon emission allowance can be assigned an identity, and relevant authorities can monitor and archive emission information for all companies. Specifically, the issuance of carbon allowances can be abstracted into a certificate issuance process between a company (agent, such as a system agent node) and relevant authorities (issuer, such as a system issuing node). Based on energy usage in production, the company will disclose a proportional allowance to each entity through vertical / derived certificate presentation. Furthermore, carbon recycling can be considered a horizontal / aggregate presentation of allowance certificates. In the industrial supply chain, consumers (verifiers, such as system edge nodes) can also verify and validate the carbon footprint of products based on their flexible certificate presentation. Therefore, this application provides a flexible and scalable certificate process for industrial production, emission monitoring, emission reduction issuance, and emission reduction verification. It can even be extended to support other use cases such as emission subsidy / tax verification.

[0076] From the above, it can be seen that the method for processing credentials in distributed identity provided by an embodiment of the present invention can be applied to carbon traceability scenarios, and the specific steps may include: the proxy node forwards the identity issuance request of the edge node to the issuing node; the issuing node issues a master credential and returns it to the proxy node based on the identity issuance request; the edge node receives the carbon emission limit identity authentication request proposed by the verifier, and sends the carbon emission limit identity authentication request to the proxy node; the proxy node generates a vertically derived credential or a horizontally aggregated credential as a presentation credential and returns it to the verifier based on a preset selective disclosure strategy; the selective disclosure strategy includes: a vertically derived and horizontally aggregated carbon allowance issuance credential presentation strategy, which is used to disclose and verify one or more original attributes in the master credential as a derived presentation credential (disclosure ratio allowance derived credential), or to re-aggregate the derived credential to obtain a carbon allowance aggregate credential for carbon recovery as a presentation credential; the master credential is a credential pre-issued by the issuing node to the proxy node.

[0077] In specific implementation, the details of the anonymous credential algorithm involved in the above credential life cycle process are as follows:

[0078] 1) Issuance and verification of credentials

[0079] SETUP(1 λ )→pp: Make public parameters is an asymmetric bilinear group, where and is the cyclic group of λ-bit prime order p, g generates generate

[0080] is an efficiently computable bilinear map.

[0081] KEYGEN(pp)→(sk,pk): The generation of a public-private key pair consists of two algorithms:

[0082] -ISSUERKEYGEN(pp)→(sk i ,pk i ):The algorithm selects Where n is the total number of edge node identity features, choose X←g x , And i∈[1,n], Z i,j ←g yi·yj And i∈[1,n],i / =j, set sk i For (x,y1,...,y n ), pk i for -HOLDERKEYGEN(pp)→(sk b ,pkb ): As the above algorithm assumes, the algorithm sets sk b for (b,w1,...,w n ), where B←g b , And set pk b for

[0083] · The algorithm selects a random large integer Calculate features Commitment value And prove π1, where π1 is defined as:

[0084]

[0085] · The algorithm verification must first prove π1. If π1 satisfies, this algorithm selects a random large integer return in

[0086] · The algorithm analyzes for The output signed master certificate σ is:

[0087]

[0088] · The algorithm determines the equation

[0089] Is it true? If they are equal, output 1, otherwise output 0.

[0090] 2) Presentation and verification of credentials

[0091] CREDDISCLOSE(σ,S,Cred)→σ′: Credential disclosure consists of two algorithms (derivation and aggregation):

[0092] -CREDDERIVE(σ,S)→σ D :The algorithm inputs the public key pk, The signature σ=(h,s) on Where S is a disclosure statement, output in {m i} i∈S Derived certificate σ on D And the corresponding proof is π2. The algorithm generates 2 random scalars Generate derived credentials σ D As output σ′:

[0093]

[0094] in if but and

[0095] The proof is that π2 is defined as:

[0096]

[0097] - The algorithm inputs the key sk b for (b,w1,...,w n ) and initial signature As the starting point of the aggregate signature. Secondly, verify The effectiveness of this algorithm is to select Generate aggregated credentials σ A As output σ′:

[0098]

[0099] The first algorithm mentioned above CREDDERIVE(σ,S)→σ D For the derived certificate algorithm, the second algorithm mentioned above It is the aggregated credential algorithm.

[0100] As can be seen from the above, in one embodiment, the proxy node generates a presentation credential and returns it to the verifier according to the preset selective disclosure strategy, which may include: using the above σ D Formula (derived certificate algorithm) and σ A The presentation credential (derived credential or aggregated credential) generated by the formula (aggregate credential algorithm) is returned to the verifier.

[0101] · The verification of presented credentials is divided into two algorithms (the algorithm for verifying derived credentials and the algorithm for verifying aggregated credentials):

[0102] - The algorithm checks two equalities and Are they both true? If they are equal, output 1, otherwise output 0. In particular, if the operation does not require the identity to be hidden, C and D in the π2 formula can also be verified by the verifier through {m i} i∈S calculate.

[0103] - The algorithm determines the equation Is it true? If they are equal, output 1, otherwise output 0.

[0104] The first algorithm mentioned above To verify the derived credential algorithm, the second algorithm mentioned above An algorithm for verifying aggregated credentials.

[0105] From the above, it can be seen that in one embodiment, after receiving the presentation credential returned by the proxy node, another edge node as a verifier, if it needs to verify the presentation credential, queries the current public global status and member proof of the edge node related to the credential; based on the current public global status and member proof of the edge node related to the returned presentation credential, verifies the presentation credential (derived credential or aggregated credential), and obtains the authentication result of the credential identity attribute, which may include: using the above-mentioned first algorithm VERIFYDERIVE to verify the derived credential, and the above-mentioned second algorithm VERIFYAGGREGATE to verify the aggregated credential.

[0106] 3) Credential Update and Verification

[0107] SETUP(1 λ )→pp: Input a security parameter λ, the algorithm outputs public parameters pp=(n,g), where the modulus n=pq, p=2p'+1, q=2q'+1, and p, p', q, q' are all random prime numbers; is a group of unknown order, and g generates

[0108] MEMEVAL(x,pp)→z: The calculation of the accumulated value is divided into three algorithms:

[0109] -CREATEEVAL(pp)→z: This algorithm selects Output an initialized accumulator value z=g.

[0110] - This algorithm adds an element x into the accumulator z, sets

[0111] The output The new accumulator value after the addition operation.

[0112] - This algorithm removes an element x from the accumulator z and sets where y = x -1 modφ(n), output The new accumulator value after the deletion operation.

[0113] UPDATEWIT(x,z,pp)→ω: Witness update is divided into three algorithms:

[0114] -CREωATEMEMWIT(x,pp)→ω: Input an element x to be accumulated, and output a witness certificate ω=g for element x y , where y = Π s∈S,s≠x s.

[0115] - When the accumulator has added element x, the algorithm updates the other elements Eyewitness testimony, including Output in is the new witness proof value after the addition operation.

[0116] - When the accumulator has deleted element x, the algorithm updates the other elements Eyewitness testimony, including Output the new witness proof value after the deletion operation Where a and b satisfy The new accumulator value after the deletion operation.

[0117] · The algorithm determines the equation (ω) x =z is true, if they are equal, output 1, otherwise output 0.

[0118] Through the above embodiments, the key points of the embodiments of the present invention are emphasized again below:

[0119] 1) This embodiment of the present invention provides a three-tier architecture of "issuing node-proxy node-edge node." Edge nodes typically lack capacity and computing power, making it difficult to deploy complex cryptographic algorithms. The system architecture introduces proxy nodes, typically deployed by the organization that owns the edge node. These proxy nodes act as true identity holders, helping edge nodes manage their identities. This enables the system to support functions such as blinding, batch processing, and proof of membership, while also alleviating communication pressure on issuing nodes.

[0120] 2) The embodiment of the present invention provides three types of anonymous credentials: "primary credential - derived credential - aggregated credential": through the signature operation of the issuing node, the proxy node receives the identity credential of its edge node, namely the primary credential. The primary credential can be subsequently divided into derived credentials, or multiple derived credentials can be integrated into an aggregated credential. The three definitions of credentials structure the credential presentation process, which can help the development of subsequent system functions. The relationship between the three credentials is as follows: Figure 3 shown.

[0121] 3) The embodiment of the present invention provides a flexible "vertical / derivative" and "horizontal / aggregate" credential presentation process: the master credentials of all identities in the system can be presented according to the statement issued by the verifier. The proxy node can split all the attributes in the master credential into credential fragments one by one to generate vertical / derivative credentials; the proxy node can also aggregate the selected multiple credential fragments according to the attribute key values required in the statement to generate horizontal / aggregate credentials; both types of generated credentials can be verified and presented.

[0122] 4) The embodiment of the present invention provides full life cycle management that meets the requirements of anonymous credentials: The embodiment of the present invention supports the functions of single issuance, multiple disclosures, flexible presentation, verifiable credentials, revocation and membership certification. These functions cover all forms of anonymous credentials in all periods, including the management of the entire life cycle of credentials.

[0123] The present invention also provides a system for processing credentials in a distributed identity, as described in the following embodiments. Because the principles of this system are similar to those of the method for processing credentials in a distributed identity, the implementation of this system can be referenced to the implementation of the method for processing credentials in a distributed identity, and any repetitions will not be repeated.

[0124] Figure 5 FIG. 1 is a schematic diagram of a system for processing credentials in a distributed identity according to an embodiment of the present invention. Figure 5 As shown, the system includes: an issuing node 01, at least one proxy node 02, and at least one edge node 03 corresponding to each proxy node; wherein:

[0125] Issuing node 01 is used to issue a primary certificate and return it to the proxy node based on the identity issuance request;

[0126] Edge node 03 is used to receive an authentication request from another edge node as a verifier and send the authentication request to the proxy node;

[0127] Proxy node 02 is used to forward the identity issuance request of the edge node to the issuing node; based on the preset selective disclosure strategy, it generates a presentation credential and returns it to the verifier; the selective disclosure strategy includes: a credential presentation strategy of vertical derivation and horizontal aggregation, which is used to disclose and verify one or more original attributes in the master credential as a derived presentation credential, or to re-aggregate the derived credential to obtain an aggregated credential as the presentation credential.

[0128] When implementing it specifically, Figure 5 There can be M proxy nodes in the network, and each proxy node can correspond to N edge nodes, where M and N are positive integers greater than or equal to 1.

[0129] In one embodiment, when a master credential is issued:

[0130] The edge node is also used to: initiate identity registration requests to its organization's proxy node when entering a system that can flexibly handle anonymous credentials;

[0131] The proxy node is specifically configured to, upon receiving an identity registration request, include the blinded identity attributes in the identity issuance request and send it to the issuing node; after receiving the blinded credential, perform an unblinding operation to obtain a master credential with the corresponding original attributes of the edge node;

[0132] The issuing node is specifically used to generate a blinded credential containing the primary credential based on the blinded identity attributes, and return the blinded credential to the proxy node.

[0133] In one embodiment, the random prime number selected by the proxy node through HashToPrime() represents the unique identifier of the edge node.

[0134] In one embodiment, after receiving the presentation credential returned by the proxy node, another edge node as a verifier queries the current public global status and member proof of the edge node related to the credential if verification of the presentation credential is required; based on the current public global status and member proof of the edge node related to the returned presentation credential, the presentation credential is verified to obtain the authentication result of the credential identity attribute.

[0135] In one embodiment, the random prime number selected by the proxy node through HashToPrime() is used to generate the membership certificate.

[0136] In one embodiment, when the current edge node actively or passively generates a revocation request, the proxy node of the current edge node is further used to integrate the revocation request and send it to the issuing node;

[0137] The issuing node is also used to verify that the revocation request is passed, update the global status of the current edge node, and return the update result to the proxy node of the current edge node.

[0138] An embodiment of the present invention further provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned method for processing credentials in a distributed identity when executing the computer program.

[0139] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the method for processing credentials in the distributed identity is implemented.

[0140] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the above-mentioned method for processing credentials in a distributed identity.

[0141] The solution for processing credentials in a distributed identity proposed in the present invention has the following beneficial technical effects:

[0142] First, the embodiments of the present invention propose flexible "vertical / derivative" and "horizontal / aggregate" credential presentation processes: the master credentials of all identities can be presented based on the statement issued by the verifier, and the proxy node can split all the original attributes in the master credential into credential fragments one by one to generate vertical / derivative credentials; the proxy node can also aggregate the selected multiple credential fragments according to the attribute key values required in the statement to generate horizontal / aggregate credentials; both types of generated credentials can be verified and presented. Therefore, the present invention proposes a flexible vertical and horizontal credential presentation scheme, which allows identity holders to freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation processing.

[0143] Secondly, the system for processing credentials in a distributed identity in an embodiment of the present invention includes: an issuing node based on a distributed digital identity, at least one proxy node and at least one edge node corresponding to each proxy node. The proxy node role is introduced in the embodiment of the present invention, which is usually deployed in the organizer who owns the edge node. As the real identity holder, it helps the edge node manage its identity, alleviates the communication pressure of the issuing node, improves the hardware processing speed, and improves the communication efficiency.

[0144] In summary, the present invention proposes a flexible vertical and horizontal credential presentation scheme, which allows identity holders to freely split and merge credentials for presentation without having to communicate with the issuer, thereby improving the efficiency of credential circulation and the accuracy and security of verification, while also improving communication efficiency.

[0145] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0146] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0147] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0148] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0149] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for processing credentials in a distributed identity, characterized in that: A system for processing credentials in a distributed identity includes: an issuing node based on a distributed digital identity, at least one proxy node, and at least one edge node corresponding to each proxy node; a method for processing credentials in the distributed identity includes: The proxy node forwards the identity issuance request of the edge node to the issuing node; The issuing node issues the master certificate based on the identity issuance request and returns it to the proxy node; The edge node receives an authentication request from another edge node as a verifier and sends the authentication request to the proxy node; The proxy node generates a presentation credential and returns it to the verifier based on a preset selective disclosure strategy; the selective disclosure strategy includes: a credential presentation strategy of vertical derivation and horizontal aggregation, which is used to disclose and verify one or more original attributes in the master credential as a derived presentation credential, or to re-aggregate the derived credential to obtain an aggregated credential as the presentation credential.

2. The method according to claim 1, wherein Also included is issuing a master certificate in the following manner: When an edge node enters a system that can flexibly handle anonymous credentials, it initiates an identity registration request to the proxy node of its organization; When receiving the identity registration request, the proxy node includes the blinded identity attribute in the identity issuance request and sends it to the issuing node; The issuing node generates a blinded certificate containing the primary certificate based on the blinded identity attributes and returns the blinded certificate to the proxy node; After receiving the blinded certificate, the proxy node performs an unblinding operation to obtain the master certificate of the corresponding original attribute of the edge node.

3. The method according to claim 2, wherein The random prime number selected by the proxy node through HashToPrime() represents the unique identifier of the edge node.

4. The method according to claim 1, wherein Also includes: After receiving the presentation certificate returned by the proxy node, the other edge node, as a verifier, queries the current public global status and member proof of the edge node related to the certificate if it needs to verify the presentation certificate; based on the current public global status and member proof of the edge node related to the returned presentation certificate, it verifies the presentation certificate and obtains the authentication result of the certificate identity attribute.

5. The method according to claim 4, wherein The random prime number selected by the proxy node through HashToPrime() is used to generate the membership certificate.

6. The method according to claim 1, wherein Also includes: When the current edge node actively or passively generates a revocation request, the proxy node of the current edge node integrates the revocation request and sends it to the issuing node; After the issuing node verifies the revocation request, it updates the global status of the current edge node and returns the update result to the proxy node of the current edge node.

7. A system for processing credentials in a distributed identity, characterized in that include: An issuing node, at least one proxy node, and at least one edge node corresponding to each proxy node; wherein: The issuing node is used to issue the primary certificate and return it to the proxy node based on the identity issuance request; The edge node receives an authentication request from another edge node as a validator and sends the authentication request to the proxy node. The proxy node is used to forward the identity issuance request of the edge node to the issuing node; according to a preset selective disclosure policy, it generates a presentation credential and returns it to the verifier; the selective disclosure policy includes: a vertical derivation and horizontal aggregation credential presentation policy, which is used to disclose and verify one or more original attributes in the master credential as a derived presentation credential, or to re-aggregate the derived credential to obtain an aggregated credential as the presentation credential.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.