Identity authentication system, method, electronic device and computer program product

Through the coordinated operation of the client and the digital identity system and permission system, asymmetric encryption and biometric verification are used to generate distributed digital identity and verification credentials, solving the problems of poor privacy, low security and low efficiency in distributed digital identity authentication, and achieving efficient and secure user identity management.

CN120474761APending Publication Date: 2025-08-12CHINA TOWER CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510584370.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, distributed digital identity authentication has problems such as poor user privacy, low security and low application efficiency.

Method used

Through the coordinated operation of the client and the digital identity system and the permission system, asymmetric encryption public and private key mechanisms are used to generate distributed digital identity and verification credentials, combining biometrics and verification code verification to realize the authentication and permission management of distributed digital identity.

Benefits of technology

It improves user privacy protection capabilities, enhances security, and simplifies the permission application process and improves processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474761A_ABST
    Figure CN120474761A_ABST
Patent Text Reader

Abstract

The invention discloses an identity authentication system and method, electronic equipment and a computer program product. Relates to the technical field of privacy computing, and comprises a client used for sending a digital identity authentication request to a digital identity system, generating an access permission request according to a distributed digital identity and a verification certificate, and sending the access permission request to a permission system; the digital identity system is used for authenticating a target user, generating a distributed digital identity, calling a preset private key to generate a verification certificate associated with the distributed digital identity and sending the distributed digital identity and the verification certificate to the client under the condition that the digital identity authentication request is received; and the permission system is used for determining the role permission according to the verification certificate under the condition that the access permission request is received, and sending the role permission to the client. Through the application, the problems of poor user privacy, low security and low application efficiency during distributed digital identity application in related technologies are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of privacy computing technology, and more specifically, to an identity authentication system, method, electronic device, and computer program product. Background Art

[0002] Blockchain technology, as an emerging distributed data management technology, is gradually being integrated into various sectors, including finance, healthcare, the Internet of Things, electricity, energy, and transportation. In these areas, blockchain not only addresses the high trust costs, inefficient information transmission, and low data security issues inherent in traditional centralized technologies, but also improves data management efficiency, optimizes data usage processes, and enhances transaction and process transparency. However, the anonymity, immutability, and decentralization of blockchain technology also raise a series of issues regarding data security, privacy protection, and transaction transparency. Privacy computing platforms, particularly those utilizing a browser / server (B / S) architecture, aim to protect user privacy when processing sensitive data and prevent data leakage during computation. However, traditional authentication and permission management approaches have shortcomings in this context, such as the inability to ensure user anonymity and the opacity of permission allocation, which limits the platforms' ability to protect privacy when processing highly sensitive information.

[0003] While current privacy computing platforms' security mechanisms, such as two-factor authentication based on account and password verification, SMS verification codes, or hardware tokens, enhance security to a certain extent, these solutions rely on centralized identity service providers, increasing the risk of single points of failure and making it difficult to meet the stringent requirements of data protection and privacy regulations. This can easily lead to security vulnerabilities in the transmission and storage of user data, exposing sensitive user information and increasing privacy risks. Furthermore, in the traditional BS / CS architecture, each system requires independent development of identity authentication and permission management modules, resulting in wasted resources and increased development time and costs.

[0004] There is currently no effective solution to the problems of poor user privacy, low security, and low application efficiency when applying for distributed digital identities in related technologies. Summary of the Invention

[0005] The main purpose of this application is to provide an identity authentication system, method, electronic device and computer program product to solve the problems of poor user privacy, low security and low application efficiency when applying for distributed digital identities in related technologies.

[0006] In order to achieve the above-mentioned purpose, according to one aspect of the present application, an identity authentication system is provided. The system includes: a client, which is respectively connected to a digital identity system and a permission system, and is used to send a digital identity authentication request to the digital identity system, and is also used to generate an access permission request based on the distributed digital identity and verification certificate sent by the digital identity system, and send the access permission request to the permission system, wherein the digital identity authentication request refers to a request by the target user to apply for a digital identity, and the access permission request refers to a request by the target user to apply for role permissions; the digital identity system is used to authenticate the target user upon receiving the digital identity authentication request, generate a distributed digital identity, and send the distributed digital identity to the client, and is also used to call a preset private key to generate a verification certificate associated with the distributed digital identity, and send the verification certificate to the client; the permission system is used to determine the role permissions based on the verification certificate upon receiving the access permission request, and send the role permissions to the client.

[0007] Furthermore, the digital identity system is also used to authenticate the target user before the client sends a digital identity authentication request, and receive the digital identity authentication request if the target user's identity authentication is successful, wherein the identity authentication method includes at least one of the following: biometric verification and verification code verification.

[0008] Furthermore, the digital identity system is also used to generate an initial digital identity using the public key in the key when the client calls the key, and send the initial digital identity to the client. It is also used to verify the identity signature sent by the client. When the identity signature verification is correct, the initial digital identity is determined as a distributed digital identity, wherein the identity signature is obtained by signing the initial digital identity using the private key in the key when the client receives the initial digital identity.

[0009] Furthermore, the permission system is used to send the random number to the client after generating the random number, and when receiving the random number signature, call the public key in the key to verify the random number signature. If the random number signature verification is correct, the role permissions are filtered out from the permission list according to the verification certificate, and an access token is sent to the client based on the role permissions. When the client receives the random number, it uses the private key in the key to sign the random number, obtains the random number signature, and sends the random number signature to the permission system.

[0010] Furthermore, the permission system is associated with a preset platform. When the client receives the access token, it accesses the preset platform based on the access token, wherein the preset platform performs security verification on the client according to the response policy.

[0011] To achieve the above-mentioned purpose, according to another aspect of the present application, an identity authentication method is provided. The method comprises: receiving a digital identity authentication request sent by a target user through a client, wherein the digital identity authentication request refers to a request by the target user to apply for a digital identity; when a key is called from the client, generating an initial digital identity using a public key in the key, and sending the initial digital identity to the client; when the client receives the initial digital identity, performing a signing operation using a private key in the key to obtain an identity signature; when the identity signature is received, verifying the identity signature, and when the identity signature verification is correct, determining the initial digital identity as a distributed digital identity, and sending the distributed digital identity to the client.

[0012] Furthermore, before receiving the digital identity authentication request sent by the target user through the client, the method also includes: authenticating the target user, wherein the authentication method includes at least one of the following: biometric verification and verification code verification; if the target user's identity authentication is successful, executing the step of receiving the digital identity authentication request sent by the target user through the client.

[0013] Furthermore, after sending the distributed digital identity to the client, the method also includes: calling a preset private key to generate a verification credential associated with the distributed digital identity, and sending the verification credential to the client, wherein, upon receiving the distributed digital identity and the verification credential, the client generates an access permission request and sends the access permission request to the permission system, and upon receiving the access permission request, the permission system determines the role permission based on the verification credential.

[0014] According to another aspect of an embodiment of the present invention, an electronic device is also provided, including one or more processors and a memory, wherein the memory stores an executable program, and the processor is used to run the program, wherein when the one or more programs are executed by one or more processors, the one or more processors implement any of the above-mentioned identity authentication methods.

[0015] According to another aspect of an embodiment of the present invention, a computer program product is provided. The computer program product includes a computer program, wherein when the computer program is executed by a processor, any one of the above-mentioned identity authentication methods is implemented.

[0016] In an embodiment of the present application, an identity authentication method is adopted, and the client is used to communicate with the digital identity system and the permission system respectively, and is used to send a digital identity authentication request to the digital identity system, and is also used to generate an access permission request based on the distributed digital identity and verification certificate sent by the digital identity system, and send the access permission request to the permission system, wherein the digital identity authentication request refers to the target user's request to apply for a digital identity, and the access permission request refers to the target user's request to apply for role permissions; the digital identity system is used to authenticate the target user upon receiving the digital identity authentication request, generate a distributed digital identity, and send the distributed digital identity to the client, and is also used to call a preset private key to generate a verification certificate associated with the distributed digital identity, and send the verification certificate to the client; the permission system is used to determine the role permission based on the verification certificate upon receiving the access permission request, and send the role permission to the client, thereby achieving the technical effect of improving processing efficiency and enhancing user privacy protection, thereby solving the problems of poor user privacy, low security and low application efficiency when applying for a distributed digital identity. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which constitute part of this application, are intended to provide a further understanding of this application. The exemplary embodiments and descriptions of this application are intended to explain this application and do not constitute an improper limitation on this application. In the accompanying drawings:

[0018] Figure 1 It is a hardware structure block diagram of a computer terminal (or mobile device) for implementing an identity authentication method;

[0019] Figure 2 This is a flowchart of an identity authentication method provided in accordance with an embodiment of the present application;

[0020] Figure 3 is a schematic diagram of an optional identity authentication method provided according to an embodiment of the present application;

[0021] Figure 4 is a schematic diagram of an identity authentication system provided according to an embodiment of the present application;

[0022] Figure 5 is a schematic diagram of an identity authentication device provided according to an embodiment of the present application;

[0023] Figure 6 This is a structural block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data for analysis, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set up between this system and the relevant user or organization. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information after receiving the consent information fed back by the aforementioned user or organization.

[0027] It should be noted that the collected information used in this application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse use.

[0028] Example 1

[0029] According to an embodiment of the present application, an embodiment of a method for identity authentication is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0030] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 It is a hardware structure diagram of a computer terminal (or mobile device) for implementing an identity authentication method, such as Figure 1 As shown, the computer terminal 10 (or mobile device) may include one or more ( Figure 1 The computer system includes a processor 102 (shown as 102a, 102b, ..., 102n) (the processor 102 may include but is not limited to a processing device such as a microcontroller unit (MCU) or a programmable logic device (FPGA)), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, the computer system may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS), a network interface, a keyboard, a cursor control device, a power supply, and / or a camera. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.

[0031] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry". The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuitry may be a single independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10 (or mobile device). As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0032] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the identity authentication method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implementing the above-mentioned identity authentication method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0033] The transmission device 106 is used to receive or send data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of the computer terminal 10. In one embodiment, the transmission device 106 includes a network interface controller (NIC) and a network interface, which can be connected to other network devices via a base station to enable communication with the Internet. In one embodiment, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0034] The display may be, for example, a touch screen liquid crystal display (LCD), which enables a user to interact with a user interface of the computer terminal 10 (or mobile device).

[0035] Under the above operating environment, this application provides Figure 2 The authentication method for the indicated identity. Figure 2 This is a flow chart of an identity authentication method according to an embodiment of the present application. Figure 2 As shown, the method includes the following steps:

[0036] Step S201: receiving a digital identity authentication request sent by a target user through a client, wherein the digital identity authentication request refers to a request from the target user to apply for a digital identity.

[0037] Specifically, to securely obtain a user's distributed digital identity, the target user first sends a digital identity authentication request to the digital identity system through a client device. This request can be for a new distributed digital identity or for authenticating an existing distributed digital identity for subsequent access. It should be noted that before receiving this digital identity authentication request, the digital identity system must authenticate the target user sending the request to ensure the authenticity and security of the user's identity.

[0038] In step S202, when the key is called from the client, the public key in the key is used to generate an initial digital identity, and the initial digital identity is sent to the client. When the client receives the initial digital identity, it uses the private key in the key to perform a signing operation to obtain an identity signature.

[0039] Specifically, after the digital identity system receives a digital identity authentication request, in order to ensure the security and non-tamperability of the user's digital identity, the client can call the tools provided by the digital identity system to generate a pair of asymmetric encryption public and private keys locally after passing the identity authentication. At this time, when the digital identity system calls the key on the client, it can use the public key in the key to generate an initial digital identity and send the initial digital identity to the client. The initial digital identity can be generated based on the relevant identity information of the target user, such as a user-defined identifier, registration timestamp, etc.

[0040] Step S203: When the identity signature is received, the identity signature is verified. When the identity signature verification is correct, the initial digital identity is determined as a distributed digital identity, and the distributed digital identity is sent to the client.

[0041] Specifically, after the client receives the above-mentioned initial digital identity, it can use the previously generated private key to sign the initial digital identity and obtain an identity signature. At this time, the hash value of the identity (or specific information summary) can be combined with the private key to generate an identity signature through an asymmetric encryption algorithm. After the digital identity system receives the identity signature sent by the client, it can use the public key associated with the key to verify the correctness of the signature to ensure that the signature has not been tampered with and is indeed generated by the private key held by the user. If the identity signature verification is correct, the digital identity system can determine the initial digital identity as a distributed digital identity, and upload it to the blockchain network, and then send the confirmed distributed digital identity back to the client. At this time, the target user can use the privacy computing platform, access specific resources, or perform data transactions and other operations through the distributed digital identity.

[0042] The identity authentication method provided in the embodiment of the present application receives a digital identity authentication request sent by a target user through a client, wherein the digital identity authentication request refers to a request from the target user to apply for a digital identity; when a key is called from the client, an initial digital identity is generated using the public key in the key, and the initial digital identity is sent to the client, wherein, when the client receives the initial digital identity, a signing operation is performed using the private key in the key to obtain an identity signature; when the identity signature is received, the identity signature is verified, and when the identity signature verification is correct, the initial digital identity is determined as a distributed digital identity, and the distributed digital identity is sent to the client, thereby solving the problems of poor user privacy, low security and low application efficiency when applying for a distributed digital identity in the related art. When a digital identity authentication request is received, an initial digital identity is generated using the public key in the key, and the identity signature obtained by the client based on the initial digital identity is verified, and a distributed digital identity is obtained when the identity signature verification is correct, thereby achieving the technical effect of improving processing efficiency and enhancing user privacy protection.

[0043] Optionally, in the identity authentication method provided in the embodiment of the present application, before receiving the digital identity authentication request sent by the target user through the client, the method also includes: authenticating the target user, wherein the identity authentication method includes at least one of the following: biometric verification and verification code verification; if the target user identity authentication is successful, executing the step of receiving the digital identity authentication request sent by the target user through the client.

[0044] Specifically, before processing the digital identity authentication request sent by the client, the digital identity system first needs to authenticate the target user using the client. At this time, the user's biometric data, such as fingerprint, facial recognition, iris scan, etc., can be obtained, and then the biometric algorithm is used to compare it with the biometric template submitted by the user during registration to verify the user's identity; a verification code can also be sent to the user through the contact information provided by the user (such as mobile phone text messages, emails, or in-app messages). After receiving the verification code, the user enters it into the system within the validity period to verify the correctness and timeliness of the verification code. In order to further improve security, the digital identity system can also combine multiple verification methods, such as SMS verification codes combined with biometrics or passwords to form a multi-factor authentication system. Finally, if the target user's identity authentication is successful, the digital identity authentication request is processed accordingly. This embodiment uses biometric verification to enable the digital identity system to provide a higher level of identity confirmation, effectively prevent password-based attacks, simplify the login process, and improve efficiency.

[0045] Optionally, in the identity authentication method provided in the embodiment of the present application, after sending the distributed digital identity to the client, the method also includes: calling a preset private key to generate a verification credential associated with the distributed digital identity, and sending the verification credential to the client, wherein, upon receiving the distributed digital identity and the verification credential, the client generates an access permission request and sends the access permission request to the permission system, and upon receiving the access permission request, the permission system determines the role permission based on the verification credential.

[0046] It should be noted that after generating a distributed digital identity and sending it to the client, the preset private key can also be called to issue a verifiable declaration certificate that has passed real-name authentication for this distributed digital identity, that is, to obtain a verification certificate, and send the verification certificate to the client.

[0047] After the client receives the distributed digital identity and verification credentials, if it accesses specific resources or performs specific operations, the client also needs to interact with the permission system. At this time, the client can generate an access permission request based on the distributed digital identity and verification credentials, and then send the access permission request to the permission system to apply for the corresponding role permissions. At this time, the permission system can obtain the verification credentials by parsing the access permission request, and then verify the credentials through the public key to confirm the authenticity of the credentials. When the verification credentials are verified, the permission system determines the role applied for by the user and its corresponding role permissions based on the above verification credentials according to the role definition and permission allocation rules in the smart contract. After the role permissions are determined, the permission system issues an access token containing the user role and permission information to the client for the user to use in the privacy computing platform.

[0048] It should be noted that after the client receives the access token, the user can use this token to access designated resources or perform specific operations on the privacy computing platform. The platform can provide users with corresponding levels of services based on the role and permission information in the access token, while recording access behavior to meet audit requirements. This embodiment ensures the reliability and security of user authentication by using verification credentials and private key signatures, reducing the risk of identity forgery and data tampering. Users do not need to reapply for roles and permissions, simplifying the process of cross-system permission application, allowing users to quickly apply for and obtain the required permissions, improving access efficiency and user experience.

[0049] This embodiment of the application also provides an identity authentication method, Figure 3 is a schematic diagram of an optional identity authentication method provided according to an embodiment of the present application, such as Figure 3 As shown, the method includes:

[0050] When a user applies for a distributed digital identity, they first register and log in to the distributed digital identity system using an account password or mobile phone verification code, and follow the system's instructions to complete identity authentication, either automatically or manually. After the user passes identity authentication, they invoke the tools provided by the distributed digital identity system to locally generate a pair of asymmetric public and private keys. The distributed digital identity system then generates an initial digital identity using the public key and sends it back to the client.

[0051] After receiving the initial digital identity, the client can sign it using the previously generated private key, obtaining an identity signature and sending it back to the distributed digital identity system. Upon receiving the identity signature sent by the client, the system can verify the signature's accuracy using the public key. If the identity signature verifies correctly, the initial digital identity is confirmed as a distributed digital identity and uploaded to the blockchain network. The distributed digital identity system then uses its own private key to issue a verifiable claim credential for this distributed digital identity, demonstrating real-name authentication, and returns the real-name authentication verifiable credential.

[0052] When a user needs to apply for permission to access the privacy computing platform, he or she can submit an application to use the privacy computing role to the permission system. The permission system verifies that this distributed digital identity belongs to the user through a challenge-response mechanism: the permission system generates a random number and returns it to the user. The user signs this random number with his or her own private key and then returns the signature to the permission system. The permission system uses the public key in the above distributed digital identity to verify the signature. If the verification is successful, it means that this distributed digital identity is held by this user and returns a verifiable declaration certificate of the privacy computing platform permission.

[0053] After the user's client receives the verifiable claim credential, it can apply for access to the privacy computing platform. At this time, the privacy computing platform can also use random number verification to determine the user's security and issue an access token (which can be a token) after verification. Finally, the user can use the token to access the privacy computing platform's related functions.

[0054] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0055] Example 2

[0056] The embodiment of the present application also provides an identity authentication system. It should be noted that the identity authentication system of the embodiment of the present application can be used to execute the identity authentication method provided in the embodiment of the present application. The identity authentication system provided in the embodiment of the present application is introduced below.

[0057] According to an embodiment of the present application, a system for implementing the above-mentioned identity authentication method is also provided. Figure 4 is a schematic diagram of an identity authentication system provided according to an embodiment of the present application, such as Figure 4 As shown, the system includes:

[0058] Client 401 is respectively connected to digital identity system 402 and permission system 403 for sending a digital identity authentication request to digital identity system 402, generating an access permission request based on the distributed digital identity and verification credentials sent by digital identity system 402, and sending an access permission request to permission system 403, wherein the digital identity authentication request refers to a request from the target user to apply for a digital identity, and the access permission request refers to a request from the target user to apply for role permissions.

[0059] Specifically, the client 401 acts as a bridge between the user and the distributed digital identity system 402 and the permission system 403, which can not only enhance the user experience, but also improve the security and privacy protection capabilities of the system. When the target user communicates with the digital identity system 402 and the permission system 403 through the client 401, the target user can first send a digital identity authentication request to the digital identity system 402 through the client 401, wherein the request may include user information for creating a user account. Based on the above request, the digital identity system 402 generates a distributed digital identity (DID: Decentralized Identifier) for the user, and sends it back to the client 401 together with information such as verification credentials. The distributed digital identity, as a globally unique, tamper-proof, and resolvable identifier, can provide users with an identity foundation for self-management.

[0060] It should be noted that when the digital identity system 402 generates a distributed digital identity, it can interact with the client 401 for private key signature, that is, the client 401 and the digital identity system 402 perform security verification through public and private keys, and then generate a distributed digital identity after the verification is passed. It can also generate a corresponding verification certificate and send it to the client 401 together.

[0061] After receiving this information, client 401 can securely store it on the user's device, such as a smartphone or computer. When a user needs to access specific resources or perform specific operations, client 401 interacts with permission system 403. At this point, client 401 can generate an access permission request based on the user's distributed digital identity and verification credentials to apply for the corresponding role permissions. This access permission request is then sent to permission system 403, which can process the permission request through a smart contract.

[0062] The digital identity system 402 is configured to, upon receiving a digital identity authentication request, authenticate the target user, generate a distributed digital identity, and send the distributed digital identity to the client 401. The system is also configured to use a preset private key to generate a verification credential associated with the distributed digital identity, and send the verification credential to the client 401.

[0063] Specifically, digital identity system 402, as a core component of the distributed digital identity ecosystem, ensures the security, privacy, and interoperability of user identities. Upon receiving a digital identity authentication request from client 401, digital identity system 402 initiates a multi-layered authentication process, including verification of basic identity information, biometric authentication, and real-name verification, to ensure the authenticity and legitimacy of the user's identity.

[0064] After the user passes the identity authentication, the system can generate a unique distributed digital identity, and through the interaction with the client 401, it can return it to the client 401 through TLS / SSL encryption and a secure API interface. In addition, the digital identity system 402 can also use the preset private key to issue a verifiable credential for the distributed digital identity as evidence that the user has passed the authentication, and send the credential to the client 401. The client 401 can then generate an access permission request based on the credential to be sent to the permission system 403. The permission system 403 uses the credential to verify the user's role and permissions to determine the user's access level on the privacy computing platform.

[0065] The permission system 403 is used to determine the role permission according to the verification credential when receiving the access permission request, and send the role permission to the client 401.

[0066] Specifically, before receiving access rights, the permission system 403 can use smart contracts to manage the roles of the privacy computing platform and assign different permissions to the roles, thereby obtaining multiple role permissions. After receiving the access rights request, the permission system 403 determines the user's role permissions by deeply analyzing and processing the verification credentials, and then securely communicates with the client 401 to complete the permission allocation and confirmation. At this time, the permission system 403 will first parse the access rights request to obtain the verification credentials, and then verify the credentials. Once the verification credentials are verified, the permission system 403 determines the user's requested role and its corresponding role permissions based on the role definition and permission allocation rules in the smart contract. The smart contract can check whether the user's verification credentials are associated with the preset roles and whether these roles have the permissions specified in the access request. The communication between the permission system 403 and the client 401 is carried out through an encrypted channel to ensure the secure transmission of user role and permission information. Once the user's role permissions are determined, the permission system 403 can return a response containing the role permissions to the client 401 through a secure interface. After receiving the response, the client 401 can generate the required request for the privacy computing platform associated with the access rights system 403 based on the permission information, thereby achieving platform access.

[0067] It should be noted that when a user's responsibilities or needs change, the permission system 403 can reflect these changes in real time by updating the permission allocation in the smart contract without manual intervention, thereby greatly improving the efficiency and response speed of permission management.

[0068] The identity authentication system provided in the embodiment of the present application is connected to the digital identity system 402 and the authority system 403 through the client 401, and is used to send a digital identity authentication request to the digital identity system 402, and is also used to generate an access permission request based on the distributed digital identity and verification credentials sent by the digital identity system 402, and send the access permission request to the authority system 403, wherein the digital identity authentication request refers to the target user's request to apply for a digital identity, and the access permission request refers to the target user's request to apply for role permissions; the digital identity system 402 is used to authenticate the target user, generate a distributed digital identity, and The distributed digital identity is sent to the client 401, and is also used to call the preset private key to generate a verification certificate associated with the distributed digital identity, and send the verification certificate to the client 401; the permission system 403 is used to determine the role authority based on the verification certificate when receiving an access permission request, and send the role authority to the client 401, which solves the problems of poor user privacy, low security and low application efficiency when applying for a distributed digital identity in the related technology. Through the coordinated operation of the client 401, the digital identity system 402 and the permission system 403, the generation of digital identity and role authority is realized, thereby achieving the technical effect of improving processing efficiency and enhancing user privacy protection.

[0069] Optionally, in the identity authentication system provided in the embodiment of the present application, the digital identity system 402 is also used to authenticate the target user before the client 401 sends a digital identity authentication request, and receive the digital identity authentication request if the target user's identity authentication is successful, wherein the identity authentication method includes at least one of the following: biometric verification and verification code verification.

[0070] Specifically, before processing the digital identity authentication request sent by the client 401, the digital identity system 402 first needs to authenticate the target user using the client 401 to ensure the authenticity and security of the user's identity. At this time, the user's biometric data, such as fingerprint, facial recognition, iris scan, etc., can be obtained, and then a biometric algorithm is used to compare it with the biometric template submitted by the user during registration to verify the user's identity; a verification code can also be sent to the user through the contact information provided by the user (such as mobile phone text message, email or in-app message). After receiving the verification code, the user enters it into the system within the validity period to verify the correctness and timeliness of the verification code.

[0071] It should be noted that to further enhance security, digital identity system 402 can also combine multiple verification methods, such as SMS verification codes combined with biometrics or passwords, to form a multi-factor authentication system. This embodiment utilizes biometric verification to enable digital identity system 402 to provide a higher level of identity confirmation, increase the difficulty of attacks, effectively prevent password-based attacks, simplify the login process, and improve efficiency.

[0072] Optionally, in the identity authentication system provided in the embodiment of the present application, the digital identity system 402 is also used to generate an initial digital identity using the public key in the key when the client 401 calls the key, and send the initial digital identity to the client 401. It is also used to verify the identity signature sent by the client 401. When the identity signature verification is correct, the initial digital identity is determined as a distributed digital identity, wherein the identity signature is obtained by signing the initial digital identity using the private key in the key when the client 401 receives the initial digital identity.

[0073] Specifically, in order to ensure the security and non-tamperability of the user's digital identity, the client 401 can call the tool provided by the digital identity system 402 after passing the identity authentication to generate a pair of asymmetric encryption public and private keys locally. At this time, when the digital identity system 402 calls the key on the client 401, it can use the public key in the key to generate an initial digital identity and send the initial digital identity to the client 401.

[0074] After receiving the initial digital identity, client 401 can sign the initial digital identity using the previously generated private key to obtain an identity signature. This signature operation ensures the integrity of the digital identity and proves the user's ownership of the digital identity. By signing with the private key, the user can prove their control over the digital identity without revealing the private key itself.

[0075] After receiving the identity signature sent by client 401, digital identity system 402 can use the public key provided by the target user to verify the correctness of the signature, ensuring that the signature has not been tampered with and is indeed generated by the user's private key. If the identity signature verification is correct, digital identity system 402 can determine the initial digital identity as a distributed digital identity and chain it to the blockchain network.

[0076] It should be noted that while generating a distributed digital identity, a preset private key can also be used to issue a verifiable declaration credential for this distributed digital identity that has passed real-name authentication, that is, to obtain a verification credential, and send the verification credential to the client 401. This embodiment, by generating a distributed digital identity through the digital identity system 402, can help users use the same set of identity information across multiple systems and platforms without the need for repeated registration or verification, greatly simplifying the identity management process and promoting the practical application of blockchain technology in the field of identity authentication.

[0077] Optionally, in the identity authentication system provided in the embodiment of the present application, the permission system 403 is used to send the random number to the client 401 after generating the random number, and when the random number signature is received, call the public key in the key to verify the random number signature. If the random number signature verification is correct, the role permissions are filtered out from the permission list according to the verification certificate, and an access token is sent to the client 401 based on the role permissions. When the random number is received, the client 401 uses the private key in the key to sign the random number, obtains the random number signature, and sends the random number signature to the permission system 403.

[0078] Specifically, when a user submits an access permission request to the permission system 403, the permission system 403 can verify that the distributed digital identity belongs to the user through a challenge-response mechanism. At this time, when the permission system 403 receives the access permission request initiated by the client 401, it first generates a random number and then sends the generated random number to the client 401. After receiving the random number, the client 401 performs a signing operation. That is, the user signs the received random number using the private key in the key held by the user to generate a random number signature that is bound to the original random number.

[0079] Furthermore, after receiving the random number signature returned by client 401, permission system 403 can verify the correctness of the random number signature using the public key associated with the user of client 401. If the random number signature is verified to be correct, it indicates that the user holds a key pair that matches their digital identity. At this time, permission system 403 can filter out the corresponding role permissions from the permission list based on the verification credentials. The permission list includes the permission types of each role in the system. Permission system 403 can then assign corresponding access rights based on the user's corresponding role.

[0080] Furthermore, permission system 403 can also generate an access token (which can be a JSON Web Token, JWT) based on the selected role permissions. This token contains key information such as the user's identity, permission details, and expiration date. The generated access token is then sent to client 401 via a communication channel. After receiving the token, client 401 can use it to subsequently access the privacy computing platform or perform corresponding operations. Permission system 403 in this embodiment uses random numbers for security verification, ensuring that it protects the user's personal privacy while meeting the platform's audit requirements, while also improving the system's maintainability and efficiency.

[0081] Optionally, in the identity authentication system provided in the embodiment of the present application, the permission system 403 is associated with a preset platform. When the client 401 receives an access token, it accesses the preset platform based on the access token, wherein the preset platform performs security verification on the client 401 according to the response strategy.

[0082] It should be noted that the preset platform can be a privacy computing platform, and the permission system 403 is associated with the platform. If the target user needs to access the preset platform, he can first submit a verification credential to apply for access. At this time, the privacy computing platform can also use a challenge-response mechanism to confirm that the credential belongs to this user, that is, the privacy computing platform generates a random number and sends the random number to the client 401; the target user signs the random number using the private key corresponding to the distributed digital identity, and returns it to the privacy computing platform through the client 401. After the privacy computing platform verifies the signature, the client 401 can use the received access token to access the platform, and can also use the relevant functions of the privacy computing platform. This embodiment reduces the risk of unauthorized access and data leakage by means of access tokens and random number verification, thereby realizing refined management of permissions, meeting security requirements in different scenarios, simplifying the access process, and improving user experience.

[0083] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0084] Example 3

[0085] The embodiment of the present application also provides an identity authentication device. It should be noted that the identity authentication device of the embodiment of the present application can be used to execute the identity authentication method provided in the embodiment of the present application. The identity authentication device provided in the embodiment of the present application is introduced below.

[0086] According to an embodiment of the present application, a device for implementing the above-mentioned identity authentication method is also provided. Figure 5 Schematic diagram of an identity authentication device according to an embodiment of the present application. Figure 5 As shown, the device includes: a receiving unit 50, a generating unit 51, and a checking unit 52.

[0087] The receiving unit 50 is configured to receive a digital identity authentication request sent by a target user through a client, wherein the digital identity authentication request refers to a request from the target user to apply for a digital identity;

[0088] The generating unit 51 is configured to generate an initial digital identity using the public key in the key when the key is called from the client, and send the initial digital identity to the client. When the client receives the initial digital identity, it uses the private key in the key to perform a signing operation to obtain an identity signature.

[0089] The verification unit 52 is configured to verify the identity signature upon receipt, and if the identity signature is verified to be correct, determine the initial digital identity as a distributed digital identity, and send the distributed digital identity to the client.

[0090] The identity authentication device provided by the embodiment of the present application receives a digital identity authentication request sent by a target user through a client through a receiving unit 50, wherein the digital identity authentication request refers to a request for application for a digital identity by the target user; when the generation unit 51 calls the key from the client, it uses the public key in the key to generate an initial digital identity and sends the initial digital identity to the client, wherein, when the client receives the initial digital identity, it uses the private key in the key to perform a signing operation to obtain an identity signature; when the identity signature is received, the verification unit 52 verifies the identity signature, and when the identity signature verification is correct, the initial digital identity is determined as a distributed digital identity, and the distributed digital identity is sent to the client, thereby solving the problems of poor user privacy, low security and low application efficiency when applying for a distributed digital identity in the related art. By generating the initial digital identity using the public key in the key when receiving the digital identity authentication request, and verifying the identity signature obtained by the client based on the initial digital identity, a distributed digital identity is obtained when the identity signature verification is correct, thereby achieving the technical effect of improving processing efficiency and enhancing user privacy protection.

[0091] Optionally, in the identity authentication device provided in the embodiment of the present application, the device also includes: an authentication unit, used to authenticate the target user before receiving the digital identity authentication request sent by the target user through the client, wherein the identity authentication method includes at least one of the following: biometric verification and verification code verification; an execution unit, used to execute the step of receiving the digital identity authentication request sent by the target user through the client when the target user identity authentication is successful.

[0092] Optionally, in the identity authentication device provided in the embodiment of the present application, the device also includes: a calling unit, which is used to call a preset private key to generate a verification credential associated with the distributed digital identity after sending the distributed digital identity to the client, and send the verification credential to the client, wherein the client generates an access permission request when receiving the distributed digital identity and the verification credential, and sends the access permission request to the permission system, and the permission system determines the role permission based on the verification credential when receiving the access permission request.

[0093] It should be noted that the receiving unit 50, generating unit 51, and verifying unit 52 described above correspond to steps S201 to S203 in Example 1. The examples and application scenarios implemented by the above units and corresponding steps are the same, but are not limited to the contents disclosed in the above Example 1. It should be noted that the above modules or units can be hardware components or software components stored in a memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above units can also be part of a device and can be run in the computer terminal 10 provided in Example 1.

[0094] Example 4

[0095] The embodiment of the present application can provide a computer terminal, which can be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the computer terminal can also be replaced by a terminal device such as a mobile terminal or an electronic device.

[0096] Optionally, in this embodiment, the computer terminal may be located in at least one network device among a plurality of network devices of a computer network.

[0097] In this embodiment, the above-mentioned computer terminal can execute the program code of the following steps in the identity authentication method: receiving a digital identity authentication request sent by the target user through the client, wherein the digital identity authentication request refers to the target user's request to apply for a digital identity; when calling the key from the client, using the public key in the key to generate an initial digital identity, and sending the initial digital identity to the client, wherein, when the client receives the initial digital identity, using the private key in the key to perform a signing operation to obtain an identity signature; when receiving the identity signature, verifying the identity signature, and when the identity signature verification is correct, determining the initial digital identity as a distributed digital identity, and sending the distributed digital identity to the client.

[0098] Optionally, the above-mentioned computer terminal can execute the program code of the following steps in the identity authentication method: before receiving the digital identity authentication request sent by the target user through the client, the method also includes: authenticating the target user, wherein the identity authentication method includes at least one of the following: biometric verification and verification code verification; if the target user identity authentication is successful, execute the step of receiving the digital identity authentication request sent by the target user through the client.

[0099] Optionally, the above-mentioned computer terminal can execute the program code of the following steps in the identity authentication method: after sending the distributed digital identity to the client, the method also includes: calling a preset private key to generate a verification credential associated with the distributed digital identity, and sending the verification credential to the client, wherein, upon receiving the distributed digital identity and the verification credential, the client generates an access permission request and sends the access permission request to the permission system, and upon receiving the access permission request, the permission system determines the role permission based on the verification credential.

[0100] Optionally, Figure 6 This is a structural block diagram of an electronic device according to an embodiment of the present application. Figure 6 As shown, the electronic device may include: one or more ( Figure 6 Only one is shown) processor 602, memory 604, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.

[0101] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the identity authentication method and device in the embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned identity authentication method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include but are not limited to the Internet, corporate intranet, local area network, mobile communication network and combinations thereof.

[0102] The processor can call the information and application stored in the memory through the transmission device to execute the above steps in the above identity authentication method.

[0103] According to an embodiment of the present application, a scheme for identity authentication is provided. By receiving a digital identity authentication request sent by a target user through a client, wherein the digital identity authentication request refers to a request by the target user to apply for a digital identity; when a key is called from the client, an initial digital identity is generated using the public key in the key, and the initial digital identity is sent to the client, wherein, when the client receives the initial digital identity, a signing operation is performed using the private key in the key to obtain an identity signature; when the identity signature is received, the identity signature is verified, and when the identity signature verification is correct, the initial digital identity is determined as a distributed digital identity, and the distributed digital identity is sent to the client, thereby achieving the technical effect of improving processing efficiency and enhancing user privacy protection, thereby solving the problems of poor user privacy, low security and low application efficiency when applying for a distributed digital identity.

[0104] It can be understood by those skilled in the art that Figure 6 The structure shown is for illustration only, and the electronic device may also be a terminal device such as a smart phone, a tablet computer, a PDA, a mobile Internet device (MID), or a PAD. Figure 6 It does not limit the structure of the above electronic device. For example, the electronic device may also include Figure 6 More or fewer components (such as network interfaces, display devices, etc.) shown in, or with Figure 6 Different configurations shown.

[0105] A person skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0106] Example 5

[0107] The embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the identity authentication method provided in the first embodiment.

[0108] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.

[0109] Optionally, in this embodiment, the storage medium is configured to store program code for executing the following steps: receiving a digital identity authentication request sent by a target user through a client, wherein the digital identity authentication request refers to a request from the target user to apply for a digital identity; in the case of calling a key from the client, generating an initial digital identity using a public key in the key, and sending the initial digital identity to the client, wherein, in the case of receiving the initial digital identity, performing a signing operation using a private key in the key to obtain an identity signature; in the case of receiving the identity signature, verifying the identity signature, and if the identity signature verification is correct, determining the initial digital identity as a distributed digital identity, and sending the distributed digital identity to the client.

[0110] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing the steps of the identity authentication method.

[0111] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0112] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0113] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0114] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0115] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0116] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program code.

[0117] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. An identity authentication system, characterized in that: include: The client is in communication with the digital identity system and the permission system, and is used to send a digital identity authentication request to the digital identity system, generate an access permission request based on the distributed digital identity and verification credentials sent by the digital identity system, and send the access permission request to the permission system, wherein the digital identity authentication request is a request by the target user to apply for a digital identity, and the access permission request is a request by the target user to apply for role permissions; The digital identity system is configured to, upon receiving the digital identity authentication request, authenticate the target user, generate the distributed digital identity, and send the distributed digital identity to the client; and further configured to invoke a preset private key to generate the verification credential associated with the distributed digital identity, and send the verification credential to the client; The permission system is configured to, upon receiving the access permission request, determine the role permission according to the verification credential and send the role permission to the client.

2. The system according to claim 1, wherein: The digital identity system is further configured to authenticate the target user before the client sends the digital identity authentication request, and receive the digital identity authentication request if the target user authentication is successful, wherein the authentication method includes at least one of the following: biometric verification and verification code verification.

3. The system according to claim 1, wherein: The digital identity system is also used to generate an initial digital identity using the public key in the key when the client calls the key, and send the initial digital identity to the client. It is also used to verify the identity signature sent by the client. If the identity signature verification is correct, the initial digital identity is determined as the distributed digital identity, wherein the identity signature is obtained by signing the initial digital identity using the private key in the key when the client receives the initial digital identity.

4. The system according to claim 1, wherein: The permission system is used to send a random number to the client after generating the random number, and upon receiving the random number signature, call the public key in the key to verify the random number signature. If the random number signature verification is correct, filter out the role permission from the permission list according to the verification credential, and send an access token to the client based on the role permission. When the client receives the random number, it uses the private key in the key to sign the random number to obtain the random number signature, and sends the random number signature to the permission system.

5. The system according to claim 4, characterized in that The permission system is associated with a preset platform. When the client receives the access token, the client accesses the preset platform based on the access token, wherein the preset platform performs security verification on the client according to a response policy.

6. A method for identity authentication, characterized in that: Applications in digital identity systems, including: Receiving a digital identity authentication request sent by a target user through a client, wherein the digital identity authentication request refers to a request by the target user to apply for a digital identity; When the key is called from the client, an initial digital identity is generated using the public key in the key, and the initial digital identity is sent to the client. When the client receives the initial digital identity, it uses the private key in the key to perform a signing operation to obtain an identity signature; When the identity signature is received, the identity signature is verified. If the identity signature is verified to be correct, the initial digital identity is determined as a distributed digital identity, and the distributed digital identity is sent to the client.

7. The method according to claim 6, characterized in that Before receiving the digital identity authentication request sent by the target user through the client, the method further includes: Performing identity authentication on the target user, wherein the identity authentication method includes at least one of the following: biometric verification and verification code verification; In the case where the target user identity authentication is successful, the step of receiving a digital identity authentication request sent by the target user through the client is performed.

8. The method according to claim 6, characterized in that After sending the distributed digital identity to the client, the method further includes: Calling a preset private key to generate a verification credential associated with the distributed digital identity, and sending the verification credential to the client, wherein the client, upon receiving the distributed digital identity and the verification credential, generates an access permission request and sends the access permission request to the permission system, and the permission system, upon receiving the access permission request, determines the role permission based on the verification credential.

9. An electronic device, characterized in that: include: a memory storing an executable program; A processor, configured to run the program, wherein the program, when running, executes the identity authentication method described in any one of claims 6 to 8.

10. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by a processor, the steps of the identity authentication method described in any one of claims 6 to 8 are implemented.

Citation Information

Patent Citations

  • Network identity authentication system and method

    CN101674304A

  • Method, device and system for distributed identity authentication

    CN102143134A

  • Identity authentication server and identity authentication token

    CN108092776A

  • Digital identity verification system and method, electronic equipment and storage medium

    CN113271211A

  • Zero-knowledge proof verifiable certificate digital identity management system and method based on block chain smart contract

    CN114186248A