Cross-data-space distributed identity authentication system and method and electronic equipment

By generating decentralized identity identification and credentials in heterogeneous data spaces and using blockchain storage, the problem of inefficient identity authentication between heterogeneous data spaces is solved, and efficient and secure cross-data space identity recognition is achieved.

CN120834945APending Publication Date: 2025-10-24GRG BANKING EQUIPMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510953207.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

Existing identity authentication schemes are inefficient and have poor compatibility between heterogeneous data spaces, making it difficult to achieve efficient mutual recognition of user identities.

Method used

A distributed identity authentication system across data spaces is adopted to generate decentralized identity identification and identity proof credentials through the first data space, and blockchain technology is used for anchored storage to establish a decentralized trust mechanism to achieve identity authentication across data spaces.

Benefits of technology

It improves the efficiency of identity mutual recognition between user terminals in different data spaces, enhances the integrity and non-tamperability of identity information, provides security and reliability, and reduces dependence on centralized institutions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120834945A_ABST
    Figure CN120834945A_ABST
Patent Text Reader

Abstract

The invention discloses a cross-data-space distributed identity authentication system and method and electronic equipment, and belongs to the technical field of information security. The system comprises a first data space and a second data space; wherein the first data space is used for generating and decentralizing an identity label and an identity certificate; the first data space is also used for uploading authentication information corresponding to the user terminal to the block chain network for anchoring storage and returning the authentication information to the user terminal, and the authentication information at least comprises a decentralized identity identifier and an encrypted certificate obtained by performing encryption signature processing on the identity certificate; and the second data space is used for receiving the to-be-verified encryption certificate submitted by the user terminal, obtaining authentication information corresponding to the user terminal through the block chain network, and verifying the to-be-verified encryption certificate based on the authentication information so as to perform cross-data-space identity authentication. According to the invention, the efficiency of identity mutual recognition of the user terminal among different data spaces is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of information security, and particularly relates to a distributed identity authentication system, method and electronic device across data spaces. BACKGROUND

[0002] In the digital era, data has become an important asset, and various industries are actively seeking the sharing and circulation of data elements. However, with the continuous expansion of data spaces, identity authentication and data flow between heterogeneous data spaces have become increasingly prominent. Different data spaces often follow different standards, interfaces and architectures, making identity authentication and data circulation complex and difficult.

[0003] Currently, common identity authentication schemes rely on centralized institutions, such as traditional PKI (Public Key Infrastructure), OAuth (Open Authorization), etc. However, in the face of heterogeneous data spaces, these schemes have limitations. When users in data spaces perform identity authentication and data flow across data spaces, the efficiency is low and the compatibility is poor, making it difficult to achieve efficient mutual recognition of data space user identities. SUMMARY

[0004] The present application aims to at least solve one of the technical problems in the related art. To this end, the present application provides a distributed identity authentication system, method and electronic device across data spaces, which improves the efficiency of identity mutual recognition between user terminals in different data spaces.

[0005] In a first aspect, the present application provides a distributed identity authentication system across data spaces, the system comprising a first data space and a second data space; wherein:

[0006] The first data space is configured to generate a decentralized identity and an identity proof certificate corresponding to the user terminal, if the audit result of the application materials submitted by the user terminal is passed;

[0007] The first data space is further configured to upload the authentication information corresponding to the user terminal to the blockchain network for anchor storage, and return the authentication information to the user terminal, the authentication information at least including the decentralized identity corresponding to the user terminal and an encrypted certificate obtained by encrypting and signing the identity proof certificate;

[0008] The second data space is configured to receive the encrypted certificate to be verified submitted by the user terminal, and obtain the authentication information corresponding to the user terminal through the blockchain network, verify the encrypted certificate to be verified based on the authentication information, to perform identity authentication across data spaces.

[0009] In the above technical solution, the distributed identity authentication system across data spaces includes a first data space and a second data space, the first data space is configured to generate a decentralized identity corresponding to a user terminal according to application materials, and generate an identity proof certificate associated with the decentralized identity, the identity proof certificate is stored in a blockchain after encryption signature processing, and the authentication information is anchored, which enhances the integrity and tamper resistance of the identity information of the user terminal, and through the blockchain technology, a decentralized trust mechanism can be established among the data spaces in the system, so that the identity information of the user terminal can be shared and authenticated between different data spaces, by using the decentralized identity and the identity proof certificate, the data spaces with the established trust mechanism can independently issue and manage the identity certificates, and the user terminal can freely use these certificates for identity authentication in different data spaces, without the need for complex protocol conversion or data synchronization, realizing identity authentication across data spaces. The distributed identity authentication method effectively improves the data space protocol fragmentation problem in related technologies and improves the efficiency of identity mutual authentication between user terminals in different data spaces.

[0010] In a second aspect, the present application provides a distributed identity authentication method across data spaces, comprising:

[0011] In the case where the audit result of the application materials submitted by the user terminal is passed, a decentralized identity corresponding to the user terminal and an identity proof certificate are generated;

[0012] The authentication information corresponding to the user terminal is uploaded to the blockchain network for anchored storage, and the authentication information is returned to the user terminal, the authentication information at least includes the decentralized identity corresponding to the user terminal and the encrypted certificate obtained by encrypting and signing the identity proof certificate;

[0013] The encrypted certificate to be verified submitted by the user terminal is received, and the authentication information corresponding to the user terminal is obtained through the blockchain network, the encrypted certificate to be verified is verified based on the authentication information, so as to perform identity authentication across data spaces.

[0014] In the technical solution, the decentralized identity corresponding to the user terminal is generated according to the application materials, and the identity certificate associated with the decentralized identity is generated. After the identity certificate is processed by encryption signature, the authentication information is anchored and stored by using the blockchain technology, so that the integrity and tamper resistance of the identity information of the user terminal are enhanced. After receiving the to-be-verified encrypted certificate submitted by the user terminal, the authentication information corresponding to the user terminal is obtained from the blockchain network according to the decentralized identity corresponding to the user terminal, and the to-be-verified encrypted certificate is verified based on the authentication information, so that the verification result is obtained and the identity authentication result of the user terminal is determined. The distributed identity authentication across data spaces is realized. By using the tamper resistance and decentralization characteristics of the blockchain, the security and reliability of the identity authentication are improved, and technical support is provided for identity mutual authentication and data circulation between multiple data spaces with trust mechanisms, and the efficiency of identity mutual authentication between users in different data spaces is improved.

[0015] In a third aspect, the present application provides a distributed identity authentication device across data spaces, which comprises:

[0016] The generation unit is configured to generate a decentralized identity corresponding to the user terminal and an identity certificate in a case where the audit result of the application materials submitted by the user terminal is passed.

[0017] The storage unit is configured to upload the authentication information corresponding to the user terminal to the blockchain network for anchored storage, and return the authentication information to the user terminal. The authentication information at least includes the decentralized identity corresponding to the user terminal and the encrypted certificate obtained by processing the identity certificate by encryption signature.

[0018] The authentication unit is configured to receive the to-be-verified encrypted certificate submitted by the user terminal, and obtain the authentication information corresponding to the user terminal through the blockchain network. The to-be-verified encrypted certificate is verified based on the authentication information, so as to perform the identity authentication across data spaces.

[0019] In a fourth aspect, the present application provides an electronic device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the distributed identity authentication method across data spaces according to the second aspect is realized.

[0020] In a fifth aspect, the present application provides a non-transitory computer readable storage medium, which stores a computer program. When the computer program is executed by a processor, the distributed identity authentication method across data spaces according to the second aspect is realized.

[0021] In a sixth aspect, the present application provides a chip, comprising a processor and a communication interface, the communication interface and the processor are coupled, the processor is used to run programs or instructions to realize the distributed identity authentication method across data spaces according to the second aspect.

[0022] In a seventh aspect, the present application provides a computer program product, comprising a computer program, the computer program is executed by a processor to realize the distributed identity authentication method across data spaces according to the second aspect. BRIEF DESCRIPTION OF DRAWINGS

[0023] The above and / or additional aspects and advantages of the present application will become apparent and be readily understood from the following description, taken in conjunction with the following drawings, in which:

[0024] Figure 1 is a structural schematic diagram of a distributed identity authentication system across data spaces provided by some embodiments of the present application;

[0025] Figure 2 is a schematic diagram of identity authentication across data spaces provided by some embodiments of the present application;

[0026] Figure 3 is a flowchart of a distributed identity authentication method across data spaces provided by some embodiments of the present application;

[0027] Figure 4 is a structural schematic diagram of a distributed identity authentication apparatus across data spaces provided by some embodiments of the present application;

[0028] Figure 5 is a structural schematic diagram of an electronic device provided by some embodiments of the present application. DETAILED DESCRIPTION

[0029] The technical solutions in the embodiments of the present application will be clearly described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0030] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of a kind and do not limit the number of objects, for example, the first object can be one or more. In addition, "and / or" in the specification and claims indicates at least one of the connected objects, and the character " / ", generally indicates that the objects before and after are in a "or" relationship.

[0031] The cross-data-space distributed identity authentication system, method and electronic device provided by the embodiments of the present application will be described in detail below in conjunction with the drawings, specific embodiments and application scenarios.

[0032] It should be noted that in each specific embodiment of the present application, when relevant processing is required for data related to the identity or characteristics of the user (user terminal), such as application materials submitted by the user (user terminal), authentication information associated with the user (user terminal), and the corresponding decentralized identity of the user (user terminal), permission or consent of the user (user terminal) will be obtained first, and the collection, use and processing of these data will comply with relevant laws, regulations and standards. In addition, when the embodiments of the present application need to obtain sensitive personal information of the user (user terminal), the separate permission or separate consent of the user (user terminal) will be obtained through a pop-up window or a jump to a confirmation page, and after obtaining the separate permission or separate consent of the user (user terminal), the necessary data related to the user (user terminal) for the normal operation of the embodiments of the present application will be obtained.

[0033] Figure 1 is a structural schematic diagram of the cross-data-space distributed identity authentication system provided by some embodiments of the present application. As Figure 1 shown, the cross-data-space distributed identity authentication system includes a first data space 101 and a second data space 102.

[0034] As a centralized environment for storing, managing and processing data, data space realizes unified organization and management of multi-source heterogeneous data through data integration, virtualization, semantic modeling and metadata management, etc. Data space can be considered as a distributed system defined by a governance framework, which is used to create a secure and trusted data flow environment.

[0035] In some embodiments, a cross-domain trust mechanism is established between the first data space 101 and the second data space 102 through a consortium chain; the consortium chain is jointly maintained by a plurality of data spaces in the cross-data-space distributed identity authentication system, and each data space is a node of the consortium chain. Each data space automatically executes the cross-data-space identity authentication logic through the smart contract mechanism of the consortium chain, ensuring that the cross-data-space identity authentication process has the characteristics of verifiability, non-tamperability, and decentralization. In some embodiments, a cross-domain trust mechanism is also established between the first data space and the second data space through a trusted relay node.

[0036] It can be understood that each data space in the cross-data-space distributed identity authentication system can act as an issuing party (i.e., the first data space) of an identity proof credential (encrypted credential) and as a verifying party (i.e., the second data space) of the identity proof credential (encrypted credential). The embodiments of the present application do not limit the number of data spaces in the cross-data-space distributed identity authentication system, and support multiple data spaces participating in the identity authentication process at the same time, which makes the system have good scalability and flexibility and can adapt to various cross-domain identity authentication scenarios, such as government data sharing, cross-enterprise collaboration, cross-platform user authentication, etc.

[0037] The first data space 101 is configured to generate a decentralized identity corresponding to the user terminal and an identity proof credential in a case where the audit result of the application material submitted by the user terminal is passed.

[0038] In the embodiments of the present application, the first data space 101 audits the application material submitted by the user terminal after receiving the application material. The user terminal, i.e., the data space user terminal, such as a data demander, a data developer, etc., can be a personal user terminal or an organizational user terminal. For example, if the user terminal is an organizational (or institutional) terminal, the application material submitted by the user terminal can specifically include information such as the legal person of the corresponding organization, the contact number, the business income, and the unified credit code, etc.

[0039] In some embodiments, the decentralized identity is generated based on the decentralized identity (DID) standard proposed by the World Wide Web Consortium (W3C) or other related specifications or standards. The decentralized identity is a self-sovereign, distributed, verifiable, and persistent identity identifier, which can be used to identify various subjects, including persons or organizations, etc., and does not rely on a centralized entity, an authoritative organization, or a third party for verification.

[0040] In some embodiments, after determining the audit result of the application material submitted by the user terminal, the first data space 101 is further configured to:

[0041] returning an audit report containing the audit result to the user terminal.

[0042] The first data space 101 is further configured to upload authentication information corresponding to the user terminal to a blockchain network for anchor storage, and return the authentication information to the user terminal, wherein the authentication information at least includes a decentralized identity corresponding to the user terminal and an encrypted certificate obtained by performing encryption signature processing on the identity certificate.

[0043] The first data space 101 performs encryption processing on the identity certificate, so that only a legitimate (with decryption means) recipient can decrypt and use the identity certificate, which can effectively protect the confidentiality and integrity of the identity certificate and prevent it from being obtained or tampered with by unauthorized third parties during transmission and storage. The first data space 101 can perform encryption processing on the identity certificate using symmetric encryption or asymmetric encryption algorithms, and the present application does not make specific limitations on how the first data space performs encryption processing on the identity certificate.

[0044] After completing the encryption of the identity certificate, the first data space 101 further performs signature on the identity certificate. For example, the identity certificate can be digitally signed by using algorithms such as the national standard SM2 signature algorithm, the Elliptic Curve Digital Signature Algorithm (ECDSA), etc., to obtain a first data space signature, which can be used to verify the source of the identity certificate and the integrity of the identity certificate. In the embodiments of the present application, the first data space signature can be used to verify whether the identity certificate is issued by the first data space as claimed by the data signature, and whether the identity certificate is tampered with during the process of returning from the first data space to the user terminal, the user terminal sending to the second data space, etc.

[0045] It can be understood that the authentication information associated with the user terminal is uploaded to the blockchain network for anchor storage, i.e., the authentication information is written into the blockchain, so that it has tamper-proof and verifiable properties. For example, the anchor storage process involves converting the authentication information into a format suitable for blockchain storage, such as JSON format, etc., and it can be written into the blockchain through the smart contract of the blockchain or the related blockchain API. After the authentication information is uploaded to the blockchain for anchor storage, the information will be verified and stored by multiple nodes (in the embodiments of the present application, it can be multiple data spaces) in the blockchain network, thereby ensuring that it is tamper-proof.

[0046] The user corresponding decentralized identity and the encryption credential contained in the authentication information can be used to obtain the identity proof credential (i.e., the encryption credential) corresponding to the user terminal and associated with the decentralized identity from the blockchain network based on the user corresponding decentralized identity in the subsequent user identity authentication process, and the identity authentication is performed based on the encryption credential obtained from the blockchain network and the to-be-verified credential submitted by the user, thereby improving the security and reliability of the authentication process.

[0047] The second data space 102 is configured to receive the to-be-verified encryption credential submitted by the user terminal, obtain the authentication information corresponding to the user terminal through the blockchain network, and verify the to-be-verified encryption credential based on the authentication information, so as to perform the cross-data-space identity authentication.

[0048] The encryption credential is an identity proof credential encrypted and signed by the first data space 101. The encryption credential submitted by the user terminal can be issued by the current or other data space and has not been verified for authenticity, i.e., is a to-be-verified encryption credential. The authentication information is used to verify the validity and integrity of the encryption credential, is stored in the blockchain network, has the features of non-tamperability and verifiability, and generally includes the user terminal corresponding decentralized identity, the encryption credential, and the like. The identity authentication result is a conclusion drawn by the second data space according to the verification result, such as "authentication passed" or "authentication failed".

[0049] In some embodiments, the verification of the encryption credential further includes the user corresponding decentralized identity. In some embodiments, the user submits the corresponding decentralized identity at the same time of submitting the to-be-verified encryption credential.

[0050] After receiving the to-be-verified encryption credential submitted by the user, the second data space 102 obtains the authentication information associated with the user terminal from the blockchain network based on the user corresponding decentralized identity, and the authentication information is uploaded and anchored by the current data space or other data spaces that have established a trust mechanism.

[0051] Based on the authentication information, the second data space 102 can verify the to-be-verified encrypted credential of the user terminal. For example, the verification process can include verifying the digital signature of the to-be-verified encrypted credential, comparing the to-be-verified encrypted credential with the field data in the authentication information, and the like. According to the verification result, the second data space 102 determines whether the identity authentication of the user passes. If the to-be-verified encrypted credential passes the verification, the identity authentication result can be "authentication passed"; otherwise, the authentication fails. Wherein, the second data space 102 obtains the authentication information associated with the user from the blockchain network according to the decentralized identity of the user. The second data space 102 can construct a query request for the blockchain network according to the decentralized identity of the user, and send the constructed query request to the blockchain network. After the blockchain network receives the query request, it searches the distributed ledger for authentication information matching the decentralized identity, and returns the query result to the second data space 102. Due to the tamper-proof nature of the blockchain, obtaining authentication information from the blockchain network improves the credibility of the authentication information.

[0052] In related technologies, traditional identity identifiers are usually assigned and managed by centralized institutions, and the control of the user terminal over its own identity information is weak, and the data privacy risk is high in the case of failure of the centralized institution. The embodiments of the present application generate a corresponding decentralized identity for the user terminal, so that the user terminal can manage and use its own identity information between different data spaces (a trust mechanism has been established between the data spaces, for example, a consortium chain managed by multiple trusted data spaces). The user terminal does not need to rely on a centralized identity provider for identity authentication every time, which improves the flexibility and autonomy of the user terminal identity management, and helps to enhance the protection of the user's own data privacy.

[0053] In the embodiments of the present application, the first data space not only serves as a service provider for identity authentication, but also serves as a decentralized identity (DID) registration authority. Compared with the traditional Certificate Authority (CA), the distributed identity authentication system across data spaces has significant advantages in architecture, control, trust model, and the like. Specifically, the traditional CA authentication relies on a centralized certificate authority, and the issuance, verification, and revocation of all identity credentials need to be completed through the CA, which has a single point of failure risk. In the present application, the first data space serves as a DID registration authority, generates a decentralized identity based on the application materials submitted by the user terminal, and the user terminal has complete control over its own identity, without relying on a single central authority.

[0054] In the traditional CA system, the identity information of the user terminal is mastered by the CA institution, and the user is difficult to manage the identity data independently. In the present application, the user terminal can independently determine the disclosure range and use scenario of the identity information by holding the user terminal private key and the encryption certificate, thereby enhancing the privacy protection capability.

[0055] The traditional CA system is usually based on a "trust root" model, and all trust relationships are established on the basis of the authority of the CA institution. In the present application, the identity information is anchored and stored through a blockchain network, and multiple data spaces can establish a trust mechanism through a consortium chain to form a distributed trust network, thereby avoiding the systemic risk caused by centralized trust.

[0056] In addition, unlike the traditional CA which uses a fixed format (such as X.509 format) digital certificate, the verification process relies on the certificate chain and revocation list. In the present application, a verifiable certificate based on a Merkle tree is used in combination with the non-tamperable nature of the blockchain to realize field-level verification and minimal disclosure, thereby making the identity proofing certificate verification process more flexible and secure.

[0057] The distributed identity authentication system across data spaces provided by the present application includes a first data space and a second data space. The first data space is used to generate a decentralized identity corresponding to the user terminal according to the application materials, and to generate an identity proofing certificate associated with the decentralized identity. After the identity proofing certificate is encrypted and signed, the authentication information is anchored and stored using blockchain technology, thereby enhancing the integrity and non-tamperability of the user terminal identity information. Through the blockchain technology, a decentralized trust mechanism can be established among the data spaces in the system, so that the identity information of the user terminal can be shared and authenticated between different data spaces. By using the decentralized identity and the identity proofing certificate, each data space with a trust mechanism can independently issue and manage the identity certificate, and the user terminal can freely use these certificates for identity authentication in different data spaces without the need for complex protocol conversion or data synchronization. The cross-data-space identity authentication is realized. This distributed identity authentication method effectively improves the data space protocol fragmentation problem in the related art and improves the efficiency of identity mutual authentication between user terminals in different data spaces.

[0058] An example of uploading the authentication information corresponding to the user terminal to the blockchain network for anchored storage is given below, including:

[0059] The authentication information is formatted to generate a data structure that meets the storage requirements of the blockchain;

[0060] The data structure is submitted as transaction content to the blockchain network;

[0061] The transaction is consensus-verified by nodes of the blockchain network, and after verification, the data structure is written into the distributed ledger of the blockchain to achieve tamper-proof and verifiable storage of the authentication information.

[0062] In some embodiments of the present application, when the audit result of the application materials submitted by the user terminal is passed, a decentralized identity corresponding to the user terminal and an identity proof certificate are generated, including:

[0063] According to the application materials, a decentralized identity corresponding to the user terminal is generated;

[0064] Based on the application materials, the audit result, and the identity information of the user terminal in the first data space, field-level splitting is performed to obtain field data to construct a Merkle tree;

[0065] An identity proof certificate associated with the decentralized identity is generated; the identity proof certificate at least includes the field data, the root information of the Merkle tree, and a first data space signature generated by the first data space using a first data space private key.

[0066] When the application materials of the user terminal are passed, the first data space can generate a decentralized identity corresponding to the user terminal according to the application materials of the user terminal and in combination with cryptographic algorithms. For example, the first data space can generate a decentralized identity by using identity authentication software or development library, according to the decentralized identity generation standard and specification, by calling the corresponding Application Programming Interface (API), and the generated decentralized identity can be used as the unique identity of the user terminal in the first data space or different data spaces (such as the second data space) that have established a trust mechanism with the first data space.

[0067] The Merkle tree is a binary tree data structure, each leaf node of which contains a hash value of a data block, and a non-leaf node contains a combined hash of the hash values of its child nodes.

[0068] The audit result refers to the audit result of the application materials submitted by the user terminal. For example, it can be a field such as "whether authentication = yes", or a data structure including the audit result, audit time, and auditor information. The first data space field-level splits the application materials of the user terminal, the audit result, and the identity information of the user terminal in the data space, and splits these information into independent field data. For example, the application materials can be split into fields such as name, ID number, and contact information; the audit result can be split into fields such as audit pass status and audit time; and the identity information of the user terminal in the data space can be split into fields such as username and registration time. Then the first data space calculates the hash value of each field data, and takes these hash values as leaf nodes, calculates the hash value of the parent node step by step upwards according to the construction rule of the Merkle tree, and finally constructs a complete Merkle tree. The present application does not make specific limitation on how to construct the Merkle tree according to the field data.

[0069] The construction of the Merkle tree helps to efficiently verify the integrity and consistency of the identity information of the user terminal. Specifically, in the subsequent identity authentication process, the hash value of the data to be verified can be compared with the hash value of the corresponding node in the Merkle tree to quickly determine whether the identity information provided by the user terminal is tampered with. In addition, due to the structural characteristics of the Merkle tree, only a small number of hash values need to be verified to determine the integrity of the data, so even in the case of large data volume, the efficiency of the data verification process can be maintained. In the case of large data size of the application materials or identity information submitted by the user terminal or frequent authentication requests of the user terminal, identity authentication combined with the Merkle tree generated by the embodiments of the present application helps to improve the efficiency and reliability of identity authentication.

[0070] In some embodiments, the identity proof certificate is generated and modified based on the verifiable credential data model (VerifiableCredentials Data Model) proposed by W3C, or such a certificate generated according to other related specifications or standards. The identity proof certificate is a key protocol for realizing trusted digital identity authentication in the blockchain technology system, which improves the authenticity, privacy, and portability of the certificate through cryptography and other algorithms, and can establish a binding relationship with the decentralized identifier of the user terminal, and then be associated with a specific user terminal.

[0071] In the embodiments of the present application, the identity certificate is generated by the first data space and sent to the user terminal (and uploaded to the blockchain network for anchor storage), and the identity certificate includes field data, root information of the Merkle tree, a data signature generated by the first data space using a first data space private key, and other information given by the first data space to the user terminal. In some embodiments, the identity certificate also includes a decentralized identity corresponding to the user terminal and a decentralized identity corresponding to the data space.

[0072] The data in the identity certificate can be in plaintext form (such as the specific value of a field in the field data, such as “whether authenticated = yes”) or in encrypted ciphertext form (such as a sensitive field processed by an encryption algorithm). This way improves the flexibility of the identity certificate, making it able to adapt to the privacy protection and data verification needs in different scenarios. Specifically, when the data in the identity certificate is in plaintext form, the data can be directly used for verification and use without the need for additional decryption steps, and when the data is encrypted or converted into ciphertext (such as the hash value of the plaintext), the identity authentication needs can be met without exposing the original sensitive information. For example, if the hash value of the plaintext verification data is used as the ciphertext of the verification data, the verifier can confirm the consistency of the data by comparing the hash value of the verification data with the hash value of the current check data, without needing to obtain the verification data itself, thereby achieving identity authentication while minimizing disclosure. The representation form of the data in the identity certificate can be determined according to the specific application scenario and privacy protection needs. For sensitive data that requires high privacy protection, ciphertext form can effectively prevent information leakage; and for non-sensitive data that needs to be directly verified, plaintext form can be used.

[0073] In some embodiments, the root information of the Merkle tree includes a Merkle root of the Merkle tree and a hash path corresponding to each field data used to construct the Merkle tree.

[0074] For example, the process of generating the identity certificate by the first data space includes integrating the field data of the user terminal and the root information of the Merkle tree to form a structured data object, signing the data object using a data space private key through a signature algorithm to generate a data signature, and attaching the generated data signature to the identity certificate to form a complete identity certificate. The identity certificate, as a digital certificate of the user terminal identity, provides a basis for identity authentication between different data spaces.

[0075] In some embodiments, the first data space is also used for:

[0076] generating an updated identity certificate corresponding to the user terminal based on the re-submitted application materials of the user terminal;

[0077] uploading the updated authentication information to the blockchain network for anchor storage, and returning the updated authentication information to the user terminal, the updated authentication information at least including a decentralized identity corresponding to the user terminal and an encrypted credential obtained by performing signature processing on the updated identity certificate.

[0078] The uploading of the updated authentication information to the blockchain network for anchor storage includes:

[0079] According to the decentralized identity corresponding to the user terminal, the authentication information corresponding to the user terminal is marked as invalid in the blockchain network.

[0080] The updated authentication information is uploaded to the blockchain network for anchor storage through a dynamic updating mechanism of the blockchain network.

[0081] The distributed identity authentication system across data spaces provided by the embodiments of the present application generates a decentralized identity corresponding to the user terminal according to the application materials, and generates an identity certificate associated with the decentralized identity. The identity certificate includes field data, root information of a Merkle tree, and a first data space signature generated by the first data space using a first data space private key. Through field-level splitting and Merkle tree construction, identity information is managed in units of fields. In generating the identity certificate, the data in the certificate can be in plaintext form or in encrypted ciphertext form. The authentication information is anchor stored using blockchain technology, enhancing the integrity and tamper resistance of the identity information of the user terminal. Through the blockchain technology, a decentralized trust mechanism can be established among the data spaces, enabling the identity information of the user terminal to be shared and authenticated among different data spaces. When the user terminal performs identity authentication among different data spaces that have established a trust mechanism, the authenticity of the identity information of the user terminal can be verified by comparing hash values and the like without obtaining the original sensitive data of the user terminal, achieving identity authentication while meeting the minimization disclosure requirement. By using the decentralized identity and the identity certificate, the data spaces that have established a trust mechanism can independently issue and manage identity certificates, and the user terminal can freely use these certificates for identity authentication in different data spaces without the need for complex protocol conversion or data synchronization, realizing identity authentication across data spaces. This distributed identity authentication method effectively improves the data space protocol fragmentation problem in related technologies and improves the efficiency of identity mutual authentication of the user terminal among different data spaces.

[0082] In some embodiments of the present application, the authentication information is used to verify the to-be-verified encrypted credential to perform identity authentication across data spaces, including:

[0083] comparing the to-be-verified encrypted credential with the field data corresponding to the encrypted credential in the authentication information;

[0084] In the case of consistent comparison results, the to-be-verified root information of the Merkle tree is determined based on the field data contained in the to-be-verified encrypted credential and the corresponding root information in the Merkle tree;

[0085] In the case where the to-be-verified root information is consistent with the root information in the encrypted credential, it is determined that the to-be-verified encrypted credential passes the verification.

[0086] In the embodiments of the present application, after receiving the to-be-verified encrypted credential submitted by the user terminal, the second data space obtains the authentication information associated with the user terminal from the blockchain network according to the decentralized identity of the user terminal, and the authentication information includes the encrypted credential associated with the decentralized identity. Specifically, the second data space is specifically used for:

[0087] The field data is extracted from the to-be-verified encrypted credential and the encrypted credential obtained from the blockchain network, respectively. The field data from the two sources is compared item by item to verify whether the information recorded in the to-be-verified encrypted credential matches the information recorded on the blockchain.

[0088] If there is inconsistency in the field data during the comparison process, it can be confirmed that the to-be-verified encrypted credential submitted by the user terminal fails the verification. Even if the comparison result of the field data is consistent, it cannot be considered that the to-be-verified encrypted credential passes the verification, and it still needs to be further determined whether the data in the to-be-verified encrypted credential is tampered with during transmission.

[0089] For example, the second data space extracts the field data from the to-be-verified encrypted credential and calculates the hash values of the field data. The encrypted credential in the authentication information includes the Merkle root and the hash path of each field data. According to the calculated hash value of the field data and the corresponding hash path, the second data space re-calculates and derives the to-be-verified Merkle tree root information according to the construction rule of the Merkle tree. This process is based on the structural characteristics of the Merkle tree, and the hash value of the bottom node is calculated step by step to finally obtain the Merkle root hash value of the top layer.

[0090] The second data space compares the to-be-verified root information of the Merkle tree determined by the second data space with the original root information in the encrypted credential. If they are consistent, it means that the field data in the to-be-verified encrypted credential is not only consistent with the authentication information recorded on the blockchain, but also has not been tampered with during transmission, so it can be determined that the to-be-verified encrypted credential passes the verification.

[0091] The distributed identity authentication method across data spaces provided in the application, after receiving the encrypted credential to be verified submitted by the user terminal, acquires the associated authentication information from the blockchain network according to the decentralized identity of the user terminal, and ensures consistency by comparing the field data of the encrypted credential in the authentication information and the encrypted credential to be verified, and then recalculates the Merkle root based on the field data in the encrypted credential to be verified, and compares it with the Merkle root in the authentication information. If they are consistent, it is confirmed that the credential verification is passed. Through the blockchain and the Merkle tree, the effectiveness and authenticity of the encrypted credential to be verified are double-verified, effectively reducing the risk of tampering with the encrypted credential to be verified, and providing protection for the identity authentication of the user terminal between multiple data spaces with established trust mechanisms.

[0092] In some embodiments of the application, the first data space is further used for:

[0093] encrypting the root information and field data of the Merkle tree in the identity proof credential;

[0094] signing the encrypted root information and field data of the Merkle tree using the first data space private key to generate a first data space signature;

[0095] attaching the first data space signature to the identity proof credential to form an encrypted credential.

[0096] In the embodiments of the application, the first data space can selectively encrypt the contents in the identity proof credential according to the application scenario or specific requirements during the encryption of the identity proof credential. For example, the high-privacy sensitive data in the identity proof credential such as the user terminal's ID number and contact information can be encrypted, and the fields used to verify whether the user terminal meets the access policy (such as "whether authentication = yes") are kept in plaintext form, so that the encrypted identity proof credential can meet the identity authentication requirements while protecting the user terminal data, i.e., to meet the minimization disclosure requirement as much as possible. The specific encryption method is not limited in the application.

[0097] The first data space private key is the private key in the key pair used by the first data space in the asymmetric encryption algorithm, which is used for digital signature or encryption of data. The corresponding public key can be public, which is used for signature verification or data decryption.

[0098] After the identity certificate is encrypted, the first data space uses the private key (first data space private key) held by the first data space to sign the Merkle tree root information and the field data in the identity certificate. For example, the encrypted Merkle tree root information and the field data can be hashed to generate a fixed-length hash value, and then the hash value can be signed using the first data space private key to generate a first data space signature.

[0099] The generated first data space signature is attached to the identity certificate, and the identity certificate containing the first data space signature forms an encrypted certificate. Since any modification of the certificate content will cause the signature verification to fail, signing the identity certificate using the private key of the first data space can ensure the integrity and authenticity of the data of the encrypted certificate.

[0100] In addition, since the data in the identity certificate can be in plaintext form or encrypted ciphertext form, which can be determined according to the application scenario and privacy protection requirements, for sensitive data that requires high privacy protection, even if the encrypted certificate is intercepted, unauthorized third parties cannot obtain sensitive information therein, protecting the privacy of the user terminal.

[0101] The distributed identity authentication method across data spaces provided in the present application uses the first data space private key to encrypt and sign the root information and field data of the Merkle tree of the identity certificate, generates a first data space signature, and attaches the first data space signature to the identity certificate to form an encrypted certificate. The encrypted certificate can be circulated and verified among different data spaces that have established a trust mechanism. Each data space can recognize the identity information of the user terminal by verifying the data space signature in the encrypted certificate, thereby realizing distributed identity authentication across data spaces and effectively improving the efficiency of identity mutual recognition of the user terminal between different data spaces.

[0102] In some embodiments of the present application, the encrypted certificate to be verified further includes a decentralized identity corresponding to the first data space, and the second data space is further configured to verify the first data space signature included in the encrypted certificate to be verified, including:

[0103] According to the decentralized identity corresponding to the first data space, a first data space public key is obtained, and the first data space signature included in the encrypted certificate to be verified is verified based on the first data space public key.

[0104] If the first data space signature verification is passed, the encrypted certificate to be verified is verified based on the authentication information to perform the step of cross-data-space identity authentication.

[0105] The to-be-verified encrypted credential includes a decentralized identity of a data space that issued the to-be-verified encrypted credential, which can be a current data space, another space that establishes a trust mechanism with the current space, or a fake data space that does not establish a trust mechanism. If the to-be-verified encrypted credential is a current data space or a data space that has established a trust mechanism, a public key of the data space can be obtained according to the decentralized identity of the data space.

[0106] In some embodiments, the first data space public key is stored in a blockchain network. A query request can be constructed according to the decentralized identity of the first data space and sent to the blockchain network. The blockchain network searches for a matching public key in its distributed ledger and returns a query result.

[0107] In some embodiments, different data spaces that establish a trust mechanism hold each other's public keys. For example, when a first data space generates a public-private key pair, the first data space sends (broadcasts) its own public key to other data spaces, which store the public key after receiving it.

[0108] In addition, the public keys of different data spaces can also be stored in other trusted storage. The present application does not limit how the public keys of data spaces are obtained.

[0109] The first data space public key obtained is used to verify the first data space signature in the received to-be-verified encrypted credential, to verify the validity of the signature, that is, to verify whether the credential is issued by the claimed first data space and has not been tampered with since being issued. If the signature verification is successful, it indicates that the first data space signature is valid, and subsequent steps of verifying the to-be-verified encrypted credential based on authentication information can be performed.

[0110] The method for distributed identity authentication across data spaces provided by the present application obtains a first data space public key according to a decentralized identity corresponding to the first data space, and verifies a first data space signature included in an encrypted credential based on the first data space public key, to confirm whether the to-be-verified encrypted credential is issued by the claimed first data space and has not been tampered with. In the case where the verification is passed, a step of verifying the to-be-verified encrypted credential based on authentication information is performed again, which effectively reduces the risk of credential forgery and tampering and improves the security of distributed identity mutual authentication between user terminals in different data spaces.

[0111] In some embodiments of the present application, the to-be-verified encrypted credential further includes a user terminal signature, and the second data space is further configured to:

[0112] obtain a user terminal public key according to a decentralized identity corresponding to the user terminal, and verify a user terminal signature included in the to-be-verified encrypted credential based on the user terminal public key;

[0113] In a case where the user terminal signature verification is passed, a step of verifying the first data space signature contained in the to-be-verified encrypted credential is performed.

[0114] Similar to the first data space public key described in the foregoing embodiments, the user terminal public key can be stored in the blockchain network, can be stored locally by each data space (when the user terminal public-private key pair is generated by the data space, the user terminal public key is sent (broadcasted) to other data spaces, and the other data spaces store the user terminal public key after receiving it), or can be stored in other trusted storage. The present application does not limit how the user terminal public key is obtained.

[0115] Verifying the user signature in the credential by using the user terminal public key can confirm whether the credential is generated by the user terminal private key, thereby ensuring that the credential source is reliable and has not been tampered with during transmission. After the user terminal signature verification is successful, the first data space signature in the to-be-verified encrypted credential can be further verified to verify whether the credential is issued by the claimed first data space and has not been tampered with. The double verification mechanism effectively reduces the risk of credential forgery and tampering, enhances the security of identity authentication, and effectively solves the problem of verifying the identity legality and data source credibility simultaneously in the data circulation in related technologies, such as manufacturing supply chains.

[0116] The distributed identity authentication method across data spaces provided by the present application determines the corresponding user terminal public key according to the decentralized identity of the user terminal, and verifies the to-be-verified encrypted credential based on the user terminal public key to verify whether the to-be-verified encrypted credential is submitted by the user terminal. In a case where the verification is passed, a step of verifying the first data space signature contained in the to-be-verified encrypted credential is performed to verify whether the credential is issued by the claimed data space and has not been tampered with. The double verification effectively reduces the risk of credential forgery and tampering, improves the reliability of identity authentication, and solves the problem of synchronously verifying the identity legality and data source credibility in data circulation in scenarios such as manufacturing supply chains, thereby providing protection for identity authentication of a user between multiple data spaces in which a trust mechanism is established.

[0117] In some embodiments of the present application, the first data space is further configured to:

[0118] generating a user terminal key pair for the user terminal based on an asymmetric encryption algorithm; the user terminal key pair includes a user terminal public key and a user terminal private key;

[0119] returning the user terminal private key to the user terminal, so that the user terminal uses the user terminal private key to sign the encrypted credential to obtain a user terminal signature.

[0120] In the embodiments of the present application, the first data space generates a pair of keys, i.e., a user terminal public key and a user terminal private key, for the user terminal by using an asymmetric encryption algorithm. The asymmetric encryption algorithm can be a national encryption SM2 signature algorithm, an elliptic curve digital signature algorithm (ECDSA), etc. The embodiments of the present application do not make a specific limitation in this regard. After generating the user terminal key pair, the first data space returns the user terminal private key to the user. Specifically, the return can be performed through an encrypted transmission channel, a secure message transmission mechanism, or a download link provided in a secure area of the user terminal, so that the user terminal private key is not disclosed in the transmission process.

[0121] Before using the identity proof certificate in the subsequent process, the user terminal can sign the certificate by using the user terminal private key. The receiver (such as another data space) can verify the signature by using the user terminal public key, and confirm that the certificate is sent by the legal user terminal.

[0122] The distributed identity authentication method across data spaces provided by the present application generates a pair of user terminal keys for the user terminal based on an asymmetric encryption algorithm, and returns the user terminal private key to the user terminal for signature operation in the subsequent certificate use. The user terminal can sign the certificate by using the user terminal private key, and the receiver can verify the signature by using the user terminal public key, so as to ensure that the certificate is sent by the user terminal and has not been tampered with in the transmission and use process. The certificate signed by the user terminal private key can be verified in multiple data spaces that establish a trust mechanism, so as to establish trust in the identity of the user terminal between different data spaces, which is helpful for the circulation of data between different data spaces.

[0123] In some embodiments, the distributed identity authentication system across data spaces provided by the present application is applied to the scenario of sharing government data across departments. For example, when a user handles a certain business, the user needs to submit personal information to multiple departments. In the traditional way, the user terminal submits materials to each department respectively, which is cumbersome and has problems such as repeated submission of information and leakage of privacy.

[0124] However, based on the distributed identity authentication system across data spaces provided by the present application, the user terminal can submit application materials to the first data space (such as a government service platform), and generate a decentralized identity and an encrypted certificate after the audit is passed. The certificate contains the user's personal information, such as name, certificate number, and household information, and is organized by a Merkle tree structure to ensure field-level verifiability.

[0125] When the subsidy application is submitted to other departments through the user terminal, the other departments can be a second data space, obtain the citizen's encrypted credential through the blockchain network, and verify the authenticity and integrity of the identity information based on the Merkle tree. If the verification is passed, the other departments can directly adopt the credential without requiring the user terminal to submit materials again. At the same time, since the sensitive fields in the encrypted credential can be stored in the form of ciphertext, the original data is not disclosed in the authentication process, meeting the privacy protection requirements in government data sharing.

[0126] The cross-data-space distributed identity authentication system provided in the application can improve government efficiency, reduce repeated authentication costs, and enhance data security in the scenario of government data sharing across departments.

[0127] Figure 2 is a schematic diagram of cross-data-space identity authentication provided by some embodiments of the application. As shown in Figure 2 The cross-data-space identity authentication process includes:

[0128] The A data space blockchain node generates an SM2 data space key pair, including a data space public key and a data space private key;

[0129] The A data space blockchain node generates an SM2 user key pair, including a user public key and a user private key;

[0130] The A data space blockchain node generates an identity certificate, encrypts the identity certificate, and signs it using the data space private key to form an encrypted credential;

[0131] The A data space blockchain node sends a decentralized identity, the encrypted credential, and the user private key to the user terminal;

[0132] The user terminal signs the encrypted credential using the user private key and generates a signature value, which is attached to the identity certificate;

[0133] The user terminal submits the encrypted credential to the B data space blockchain node;

[0134] The B data space blockchain node verifies the encrypted credential based on the user public key and verifies the credential signature in the encrypted credential based on the data space public key.

[0135] The cross-data-space distributed identity authentication method provided by the embodiments of the application can be executed by an electronic device or a functional module or functional entity in the electronic device that can implement the cross-data-space distributed identity authentication method, including but not limited to a data space server, a data space gateway device, etc. The cross-data-space distributed identity authentication method provided by the embodiments of the application will be described below with the electronic device as an example.

[0136] Figure 3 is a flowchart of a distributed identity authentication method across data spaces provided by some embodiments of the present application. As shown in the figure, the distributed identity authentication method across data spaces includes steps 310, 320 and 330. Figure 3

[0137] Step 310, in the case where the audit result of the application materials submitted by the user terminal is passed, a decentralized identity corresponding to the user terminal and an identity proof certificate are generated.

[0138] Step 320, the authentication information corresponding to the user terminal is uploaded to the blockchain network for anchored storage, and the authentication information is returned to the user terminal, the authentication information at least includes the decentralized identity corresponding to the user terminal and the encrypted certificate obtained by encrypting and signing the identity proof certificate.

[0139] Step 330, receiving the encrypted certificate to be verified submitted by the user terminal, and obtaining the authentication information corresponding to the user terminal through the blockchain network, verifying the encrypted certificate to be verified based on the authentication information, to perform identity authentication across data spaces.

[0140] In some embodiments, in the case where the audit result of the application materials submitted by the user terminal is passed, a decentralized identity corresponding to the user terminal and an identity proof certificate are generated, including:

[0141] Generating a decentralized identity corresponding to the user terminal according to the application materials;

[0142] Based on the application materials, the audit result and the identity information of the user terminal in the first data space, field-level splitting is performed to obtain field data to construct a Merkle tree;

[0143] Generating an identity proof certificate associated with the decentralized identity; the identity proof certificate at least includes: the field data, the root information of the Merkle tree and the first data space signature generated by the first data space using a first data space private key.

[0144] In some embodiments, the authentication information is verified based on the authentication information to perform identity authentication across data spaces, including:

[0145] Comparing the encrypted certificate to be verified and the field data corresponding to the encrypted certificate in the authentication information;

[0146] ​In a case where the comparison result is consistent, based on field data contained in the to-be-verified encrypted credential, corresponding root information of a Merkle tree is derived to determine the to-be-verified root information of the Merkle tree;

[0147] In a case where the to-be-verified root information is consistent with the root information in the encrypted credential, it is determined that the to-be-verified encrypted credential is verified.

[0148] In some embodiments, the method further comprises:

[0149] encrypting the root information and the field data of the Merkle tree in the identity proof credential;

[0150] signing the encrypted root information and the field data of the Merkle tree using a first data space private key to generate a first data space signature;

[0151] attaching the first data space signature to the identity proof credential to form an encrypted credential.

[0152] In some embodiments, the to-be-verified encrypted credential further comprises a decentralized identity corresponding to the first data space, and the method further comprises:

[0153] obtaining a first data space public key according to the decentralized identity corresponding to the first data space, and verifying the first data space signature contained in the to-be-verified encrypted credential based on the first data space public key;

[0154] In a case where the first data space signature is verified, performing the step of verifying the to-be-verified encrypted credential based on the authentication information to perform cross-data-space identity authentication.

[0155] In some embodiments, the to-be-verified encrypted credential further comprises a user terminal signature, and the method further comprises:

[0156] obtaining a user terminal public key according to the decentralized identity corresponding to the user terminal, and verifying the user terminal signature contained in the to-be-verified encrypted credential based on the user terminal public key;

[0157] In a case where the user terminal signature is verified, performing the step of verifying the first data space signature contained in the to-be-verified encrypted credential.

[0158] In some embodiments, the method further comprises:

[0159] generating a pair of user terminal key pairs for the user terminal based on an asymmetric encryption algorithm; the user terminal key pair comprises a user terminal public key and a user terminal private key;

[0160] returning the user terminal private key to the user terminal for the user terminal to sign the encrypted credential using the user terminal private key to obtain a user terminal signature.

[0161] The distributed identity authentication method across data spaces provided in the application generates a decentralized identity corresponding to the user terminal according to the application materials, and generates an identity proof certificate associated with the decentralized identity. After the identity proof certificate is processed by encryption and signature, the authentication information is anchored and stored by using the blockchain technology, which enhances the integrity and non-tamperability of the identity information of the user terminal. After receiving the encrypted credential to be verified submitted by the user terminal, the authentication information is obtained from the blockchain network according to the decentralized identity corresponding to the user terminal, and the encrypted credential to be verified is verified based on the authentication information, to obtain a verification result and then determine the identity authentication result of the user terminal. The distributed identity authentication across data spaces is realized. By using the non-tamperability and decentralization characteristics of the blockchain, the security and reliability of the identity authentication are improved, and technical support is provided for identity mutual authentication and data circulation between multiple data spaces with trust mechanisms, and the efficiency of identity mutual authentication between users in different data spaces is improved.

[0162] In combination with the related content of the above embodiments, in some embodiments of the application, the distributed identity protocol based on the W3C standard is selected instead of other traditional protocols, mainly due to the following core requirements and technical adaptability:

[0163] As a globally recognized open standard, the W3C distributed identity protocol provides a unified identity format (DID Document) and verification method (verifiable credential VC), supports multiple encryption algorithms (including national encryption algorithms), and provides a standardized unified framework. In comparison, protocols such as X.509 and Security Assertion Markup Language (SAML) are prone to cross-system protocol incompatibility and data island problems due to the dependence on a centralized certificate authority (CA) or a specific technology stack.

[0164] The distributed identity protocol realizes the decentralized control of identity ownership by means of the blockchain or distributed ledger technology, and does not need to rely on a single CA or identity provider (IdP), which is more suitable for the architecture requirements of equal participation and self-governance in a trusted data space, and realizes a decentralized trust mechanism. For example, SAML2.0 needs to rely on metadata synchronization between IdP and SP, which is difficult to meet the dynamic identity mutual authentication requirements across multiple data spaces.

[0165] DID protocol allows users to disclose only necessary attributes (such as "age ≥ 10") rather than complete identity data through verifiable credentials (VC) and zero-knowledge proof (ZKP) technologies, meeting the privacy compliance requirements of "available but invisible" in trusted data space, and helping to achieve selective disclosure and zero-knowledge verification. Compared with the advantages of selective disclosure and zero-knowledge verification, dynamic permission management of DID protocol, OAuth tokens and X.509 certificates usually need to transmit complete identity statements or sensitive metadata, which has the risk of overexposure.

[0166] Based on the W3C protocol, the credential can embed fine-grained access policies (such as time limit, usage scenario constraint), support real-time update of permission state in cross-domain scenarios, avoid security risks caused by permission revocation delay in traditional protocols (such as static JWT token), and help to achieve dynamic permission management.

[0167] W3C standard supports flexible replacement of underlying encryption algorithms (such as national encryption SM2 / SM3 / SM9), meets domestic password compliance requirements while realizing protocol unification, realizes algorithm neutrality and national encryption compatibility. In contrast, OpenID Connect, SAML and other protocols are usually bound to specific encryption algorithms, making it difficult to seamlessly integrate national encryption systems.

[0168] DID protocol reduces the computational and communication overhead of cross-data space identity verification through DID resolver and light node verification mechanism, and is more suitable for real-time mutual recognition scenarios between large-scale heterogeneous systems, and realizes lightweight verification and cross-chain mutual recognition. X.509 certificate based on PKI system needs to rely on complex certificate chain verification, which is difficult to meet the needs of high concurrency and low delay.

[0169] DID protocol anchors DID and verifiable credentials to the blockchain to ensure the integrity and non-tamperability of identity data, and complements the "data trust management" capability of trusted data space. In manufacturing supply chain scenarios, data sharing between enterprises needs to verify the legality of identity and the credibility of data source, and DID protocol can meet this dual demand at one station, supporting the trusted circulation of data elements.

[0170] By standardizing identity protocols, it reduces the threshold for multi-party cooperation and accelerates the interaction and value flow of resources in the data space. For example, in the public data authorization operation scenario, DID protocol can ensure the identity verification and permission traceability of data users, avoiding the compliance risks caused by the fragmentation of traditional protocol permission management.

[0171] An attribute obfuscated assertion generation method is proposed, which combines zero-knowledge proof and homomorphic encryption technology to make the target data space verify whether the user meets the access policy (such as "whether authentication = yes") without obtaining the original sensitive data (such as the legal contact number), and meet the minimum disclosure requirement of General Data Protection Regulation (GDPR) / California Consumer Privacy Act (CCPA) and other regulations. The user identity information is processed by a Merkel tree structure hash to generate a unique root hash value anchored to the blockchain. When verifying, only the hash path of the specific information needs to be provided without exposing all the data. The user-held certificate contains a complete set of information, which is encrypted or hashed to achieve the "partially visible" effect, and the verifier can only access the fields authorized by the user to disclose, which helps to realize cross-domain attribute verification of privacy compliance.

[0172] For example, the attribute Merkel tree construction process includes:

[0173] Attribute partitioning: the institutional attributes (such as legal person, contact number, business income, and whether the authentication is passed) are split into independent data blocks according to the fields, and each field is taken as a leaf node of the Merkel tree. For example, in the data space scenario, the leaf node can include the fields of legal person = Zhang San, contact number = 15888888888, business income = 999999, and whether the authentication is passed = yes.

[0174] Attribute verification process: after the institution passes the authentication in the data space, the issued certificate is carried to the B data space for verification. The B data space only needs to generate a HASH for the attribute to be verified (such as whether the authentication is passed), and simultaneously verify whether there is a node with the same HASH value in the Merkel attribute node.

[0175] The application embodiment provides a cross-data-space distributed identity authentication method applied to a data space. The execution subject can be a cross-data-space distributed identity authentication device. In the application embodiment, the cross-data-space distributed identity authentication device is taken as an example to execute the cross-data-space distributed identity authentication method applied to the data space, and the cross-data-space distributed identity authentication device provided by the application embodiment is described.

[0176] Figure 4 FIG. 1 is a structural schematic diagram of a cross-data-space distributed identity authentication device provided by some embodiments of the application. As shown in FIG. 1, the cross-data-space distributed identity authentication device 400 includes a generation unit 401, a storage unit 402, and an authentication unit 403. Figure 4

[0177] ​The generation unit 401 is configured to generate a decentralized identity corresponding to the user terminal and an identity certificate in a case where the review result of the application material submitted by the user terminal is passed.

[0178] The storage unit 402 is configured to upload the authentication information corresponding to the user terminal to a block chain network for anchor storage, and return the authentication information to the user terminal, wherein the authentication information at least includes the decentralized identity corresponding to the user terminal and an encrypted certificate obtained by encrypting and signing the identity certificate.

[0179] The authentication unit 403 is configured to receive the encrypted certificate to be verified submitted by the user terminal, and obtain the authentication information corresponding to the user terminal through the block chain network, and verify the encrypted certificate to be verified based on the authentication information, so as to perform identity authentication across data spaces.

[0180] In some embodiments, the generation unit 401 is configured to:

[0181] generate the decentralized identity corresponding to the user terminal according to the application material;

[0182] perform field-level splitting based on the application material, the review result and the identity information of the user terminal in the first data space to obtain field data, so as to construct a Merkle tree;

[0183] generate an identity certificate associated with the decentralized identity; the identity certificate at least includes the field data, root information of the Merkle tree and a first data space signature generated by the first data space using a first data space private key.

[0184] In some embodiments, the authentication unit 403 is configured to:

[0185] compare the encrypted certificate to be verified with the field data corresponding to the encrypted certificate in the authentication information;

[0186] in a case where the comparison result represents consistency, determine the to-be-verified root information of the Merkle tree based on the root information respectively corresponding to the field data contained in the encrypted certificate to be verified in the Merkle tree;

[0187] in a case where the to-be-verified root information is consistent with the root information in the encrypted certificate, determine that the encrypted certificate to be verified is verified.

[0188] In some embodiments, the generation unit 401 is further configured to:

[0189] encrypt the root information and the field data of the Merkle tree in the identity certificate;

[0190] sign the encrypted root information of the Merkle tree and the field data using the first data space private key to generate a first data space signature;

[0191] attach the first data space signature to the identity certificate to form an encrypted certificate.

[0192] In some embodiments, the encrypted certificate to be verified further includes a decentralized identity corresponding to the first data space, and the authentication unit 403 is further configured to:

[0193] obtain a first data space public key according to the decentralized identity corresponding to the first data space, and verify the first data space signature included in the encrypted certificate to be verified based on the first data space public key;

[0194] if the first data space signature is verified, perform the step of verifying the encrypted certificate to be verified based on the authentication information to perform cross-data-space identity authentication.

[0195] In some embodiments, the encrypted certificate to be verified further includes a user terminal signature, and the authentication unit 403 is further configured to:

[0196] obtain a user terminal public key according to the decentralized identity corresponding to the user terminal, and verify the user terminal signature included in the encrypted certificate to be verified based on the user terminal public key;

[0197] if the user terminal signature is verified, perform the step of verifying the first data space signature included in the encrypted certificate to be verified.

[0198] In some embodiments, the generation unit 401 is further configured to:

[0199] generate a pair of user terminal key pairs for the user terminal using an asymmetric encryption algorithm; the user terminal key pair includes a user terminal public key and a user terminal private key;

[0200] return the user terminal private key to the user terminal, so that the user terminal uses the user terminal private key to sign the encrypted certificate to obtain a user terminal signature.

[0201] The distributed identity authentication apparatus across data spaces in the embodiments of the present application can be an electronic device, or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, or other devices other than the terminal. For example, the electronic device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle-mounted electronic device, a Mobile Internet Device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), and can also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, and the like, and the embodiments of the present application are not limited in this regard.

[0202] The distributed identity authentication apparatus across data spaces in the embodiments of the present application can be an apparatus with an operating system. The operating system can be a Windows operating system, an Android operating system, an IOS operating system, or other possible operating systems, and the embodiments of the present application are not limited in this regard.

[0203] Figure 5 FIG. 1 is a structural schematic diagram of an electronic device according to some embodiments of the present application. In some embodiments, as shown in FIG. 1, the electronic device 100 can include a processor 101, a memory 102, and a computer program stored in the memory 102 and executable on the processor 101. The computer program is executed by the processor 101 to implement each process of the above-mentioned distributed identity authentication method across data spaces, and the same technical effects can be achieved. To avoid repetition, details are not described herein. Figure 5

[0204] It should be noted that the electronic device in the embodiments of the present application includes the mobile electronic device and the non-mobile electronic device described above.

[0205] The embodiments of the present application further provide a non-transitory computer readable storage medium having a computer program stored thereon. The computer program is executed by a processor to implement each process of the above-mentioned distributed identity authentication method across data spaces, and the same technical effects can be achieved. To avoid repetition, details are not described herein. ​

[0206] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes a computer readable storage medium, such as a computer readable only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0207] The present application also provides a computer program product, which includes a computer program, and the computer program is executed by a processor to implement the above-mentioned distributed identity authentication method across data spaces.

[0208] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes a computer readable storage medium, such as a computer readable only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0209] The present application also provides a computer program product, which includes a computer program, and the computer program is executed by a processor to implement the above-mentioned distributed identity authentication method across data spaces.

[0210] It should be understood that the chip mentioned in the present application can also be referred to as a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0211] It should be understood that the chip mentioned in the present application can also be referred to as a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0212] Those skilled in the art can clearly understand the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a plurality of instructions to make a terminal (which can be a mobile phone, computer, server, or network equipment, etc.) execute the method described in each embodiment of the present application.

[0213] The embodiments of the present application are described above in conjunction with the drawings, but the present application is not limited to the above-mentioned specific embodiments, and the above-mentioned specific embodiments are only illustrative, not restrictive, and those skilled in the art can make many forms under the inspiration of the present application without departing from the purpose of the present application and the scope protected by the claims, which all belong to the protection of the present application.

[0214] In the description of the present application, the description of the terms "one embodiment", "some embodiments", "illustrative embodiment", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are contained in at least one embodiment or example of the present application. In the present application, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0215] Although the embodiments of the present application have been shown and described, those skilled in the art can understand that various changes, modifications, replacements and variations can be made to the embodiments without departing from the principles and purposes of the present application, and the scope of the present application is defined by the claims and their equivalents.

Claims

1. A distributed identity authentication system across data spaces, characterized in that, The system comprises a first data space and a second data space; wherein: The first data space is configured to generate a decentralized identity corresponding to the user terminal and an identity certificate in the case that the audit result of the application materials submitted by the user terminal is passed; The first data space is further configured to upload the authentication information corresponding to the user terminal to the blockchain network for anchor storage, and return the authentication information to the user terminal, wherein the authentication information at least comprises the decentralized identity corresponding to the user terminal and an encrypted certificate obtained by encrypting and signing the identity certificate; The second data space is configured to receive the encrypted certificate to be verified submitted by the user terminal, and obtain the authentication information corresponding to the user terminal through the blockchain network, and verify the encrypted certificate to be verified based on the authentication information, so as to perform cross-data-space identity authentication.

2. The distributed identity authentication system across data spaces of claim 1, wherein, The generation of the decentralized identity corresponding to the user terminal and the identity certificate in the case that the audit result of the application materials submitted by the user terminal is passed comprises: Generating the decentralized identity corresponding to the user terminal according to the application materials; Performing field-level splitting to obtain field data based on the application materials, the audit result and the identity information of the user terminal in the first data space, so as to construct a Merkle tree; Generating the identity certificate associated with the decentralized identity, wherein the identity certificate at least comprises the field data, the root information of the Merkle tree and a first data space signature generated by the first data space using a first data space private key. 3.The distributed identity authentication system across data spaces of claim 1 or 2, characterized in that, The verification of the encrypted certificate to be verified based on the authentication information for cross-data-space identity authentication comprises: Comparing the field data corresponding to the encrypted certificate in the authentication information and the encrypted certificate to be verified; In the case that the comparison result represents consistency, determining the to-be-verified root information of the Merkle tree based on the root information corresponding to the field data contained in the encrypted certificate to be verified in the Merkle tree; In the case that the to-be-verified root information is consistent with the root information in the encrypted certificate, determining that the encrypted certificate to be verified is verified.

4. The distributed identity authentication system across data spaces according to claim 1 or 2, characterized in that, The first data space is further configured to: Encrypt the root information and the field data of the Merkle tree in the identity certificate; Sign the encrypted root information and the field data of the Merkle tree using a first data space private key to generate a first data space signature; Attach the first data space signature to the identity certificate to form an encrypted certificate.

5. The distributed identity authentication system across data spaces of claim 4, wherein, The encrypted certificate to be verified further comprises the decentralized identity corresponding to the first data space, and the second data space is further configured to verify the first data space signature contained in the encrypted certificate to be verified, comprising: Obtaining a first data space public key according to the decentralized identity corresponding to the first data space, and verifying the first data space signature contained in the encrypted certificate to be verified based on the first data space public key; In a case where the first data space signature verification is passed, the step of verifying the to-be-verified encrypted credential based on the authentication information is performed to perform cross-data-space identity authentication.

6. The distributed identity authentication system across data spaces of claim 5, wherein, The to-be-verified encrypted credential further includes a user terminal signature, and the second data space is further configured to: obtain a user terminal public key according to the decentralized identity corresponding to the user terminal, and verify the user terminal signature included in the to-be-verified encrypted credential based on the user terminal public key; In a case where the user terminal signature verification is passed, the step of verifying the first data space signature included in the to-be-verified encrypted credential is performed.

7. The distributed identity authentication system across data spaces of claim 6, wherein, The first data space is further configured to: generate a pair of user terminal key pairs for the user terminal based on an asymmetric encryption algorithm; the user terminal key pair includes a user terminal public key and a user terminal private key; return the user terminal private key to the user terminal, so that the user terminal uses the user terminal private key to sign the encrypted credential to obtain a user terminal signature.

8. A method for distributed identity authentication across data spaces, characterized in that, comprise: In a case where the audit result of the application materials submitted by the user terminal is passed, a decentralized identity corresponding to the user terminal and an identity proof credential are generated; upload the authentication information corresponding to the user terminal to a blockchain network for anchor storage, and return the authentication information to the user terminal; the authentication information at least includes the decentralized identity corresponding to the user terminal and an encrypted credential obtained by encrypting and signing the identity proof credential; receive the to-be-verified encrypted credential submitted by the user terminal, and obtain the authentication information corresponding to the user terminal through the blockchain network, and verify the to-be-verified encrypted credential based on the authentication information to perform cross-data-space identity authentication.

9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the cross-data-space distributed identity authentication method of claim 8 when executing the program. 10.A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the cross-data-space distributed identity authentication method of claim 8.

Citation Information

Patent Citations

  • Block chain digital identity processing method, device and system

    CN116346355A

  • Mobile platform distributed digital identity authentication method and device and medium

    CN116886357A

  • Decentralized identity authentication method, system, device and medium

    CN119939547A

  • Data processing method, system, blockchain platform, and readable storage medium

    WO2019233345A1