Identity authentication method, device, medium and program product

By introducing decentralized identifier (DID) information and consortium blockchain network into a distributed network, the problem of cross-subnet identity authentication for enterprise private network users is solved, achieving secure identity authentication and data privacy protection across subnets.

CN120880677APending Publication Date: 2025-10-31ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410537529.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-29
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In a distributed network, enterprise private network users cannot authenticate their identities across subnets, and external subnets lack user information, which makes it impossible to access authentication and subscription information across subnets, thus affecting cross-subnet user authentication.

Method used

By introducing decentralized identifier (DID) information into a distributed network, using a consortium blockchain network for identity authentication, generating and broadcasting DID information, and writing it into the blockchain after consensus is reached, cross-subnet identity authentication is achieved, avoiding reliance on a centralized authentication center.

Benefits of technology

It achieves security and privacy in cross-subnet identity authentication, ensures that data does not access sensitive data across subnets, and provides a security foundation between distributed subnets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880677A_ABST
    Figure CN120880677A_ABST
Patent Text Reader

Abstract

According to the identity authentication method and device, the medium and the program product provided by the embodiment of the invention, a first block chain function unit of a first subnet generates decentralized identifier (DID) information including a distributed identifier (DID) corresponding to a target object according to identity information corresponding to the target object, and initiates and broadcasts a first transaction according to the DID information, when the target object needs identity verification, the first block chain function unit performs consensus processing on the first transaction in cooperation with the second block chain function unit and the block chain function units of other subnets in the alliance chain network, and writes the first transaction into the respective corresponding block chain after the consensus is passed; cross-subnet service calling can be completed by directly sending the first service request carrying the DID corresponding to the target object to the second subnet. The method does not depend on a centralized authentication center, does not need to access sensitive data across subnets, effectively guarantees data privacy and data security, and provides a security basis for realizing interconnection and intercommunication of distributed subnets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to an identity authentication method, device, medium, and program product. Background Technology

[0002] The new generation of information service networks relies on the operator's large network. The centralized control method of traditional mobile communication networks is unsustainable, and the development of distributed networks is inevitable. With the development of distributed networks, independently operated subnets have emerged, such as enterprise private networks. The application of such subnets has become increasingly widespread in the context of the development of distributed networks.

[0003] However, enterprise private networks (IVNs) require independent management of enterprise users due to information security concerns. Users sign contracts within the IVN, and the contract information used for authentication is sensitive and cannot be exposed to external networks. When an IVN user accesses external network services, the external network needs to authenticate the IVN user. However, the external subnet does not possess the IVN user information; therefore, using the authentication contract information from the IVN to complete cross-subnet user authentication is not feasible. Summary of the Invention

[0004] This application provides an identity authentication method, device, medium, and program product for user cross-subnet identity authentication and distributed subnet inter-identity authentication, realizing mutual trust between subnets, providing a security foundation for inter-subnet interconnection, and ensuring that sensitive data does not leave the domain.

[0005] In a first aspect, embodiments of this application provide an identity authentication method applied to a first subnet, the first subnet including a first network control unit and a first blockchain functional unit, the first blockchain functional unit and blockchain functional units of at least one other subnet constructing a consortium blockchain network, the method including:

[0006] The first blockchain functional unit generates decentralized identifier (DID) information based on the identity information corresponding to the target object, wherein the DID information includes the DID corresponding to the target object;

[0007] The first blockchain functional unit initiates and broadcasts the first transaction to collaborate with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction. After the consensus is passed, the first transaction is written into their respective blockchains. The first transaction represents the storage of the DID information corresponding to the target object.

[0008] The first network control unit sends a first service request carrying the DID corresponding to the target object to the second subnet. The first service request is used to instruct the second subnet to determine the identity authentication result of the target object based on the DID. The second subnet is one of the other subnets.

[0009] Secondly, embodiments of this application provide an identity authentication method applied to a second subnet. The second subnet includes a second network control unit and a second blockchain functional unit. The second blockchain functional unit and blockchain functional units of at least one other subnet are used to construct a consortium blockchain network. The method includes:

[0010] The second blockchain functional unit receives a first transaction initiated by a first subnet, which is one of the other subnets. The first transaction carries DID information corresponding to the target object. The first transaction indicates that the DID information corresponding to the target object is stored. The DID information includes the DID corresponding to the target object.

[0011] The second blockchain functional unit collaborates with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction, and writes the first transaction into their respective blockchains after the consensus is passed;

[0012] The second network control unit receives a first service request from the first subnet, the first service request carrying the DID corresponding to the target object;

[0013] In response to the first service request, the second network control unit sends a verification request to the second blockchain functional unit, the verification request carrying the DID corresponding to the target object;

[0014] The second blockchain functional unit searches for the DID information corresponding to the target object in the blockchain corresponding to the local subnet based on the DID information of the target object in the verification request, and determines the identity authentication result of the target object based on the found DID information.

[0015] Thirdly, embodiments of this application provide an electronic device, including:

[0016] One or more processors;

[0017] A memory having stored one or more programs that, when executed by one or more processors, cause the one or more processors to implement: an authentication method as provided in the first aspect of the embodiments of this application, or an authentication method as provided in the second aspect of the embodiments of this application.

[0018] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements either the authentication method provided in the first aspect of embodiments of this application, or the authentication method provided in the second aspect of embodiments of this application.

[0019] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements: an authentication method as provided in the first aspect of embodiments of this application, or an authentication method as provided in the second aspect of embodiments of this application.

[0020] In this embodiment, the first blockchain functional unit of the first subnet generates decentralized identifier DID information, including the distributed identifier DID corresponding to the target object, based on the identity information corresponding to the target object. It then initiates and broadcasts a first transaction based on the DID information to collaborate with the second blockchain functional unit and the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction. After consensus is reached, the first transaction is written into their respective blockchains. Upon completion, the first network control unit sends a first service request carrying the DID corresponding to the target object to the second subnet, enabling the second subnet to determine the identity authentication result of the target object based on the DID. The second network control unit receives the first service request from the first subnet and responds by sending a verification request to the second blockchain functional unit, carrying the DID corresponding to the target object. The second blockchain functional unit searches for the DID corresponding to the target object in the blockchain corresponding to its local subnet based on the DID in the verification request, and determines the identity authentication result of the target object based on the found DID information, thus completing the identity authentication. The present application provides an identity authentication method, device, medium, and program product that completes identity information authentication by adding centralized identifier DID information. It does not rely on a centralized authentication center, effectively ensuring data privacy and data security. It does not require access to sensitive data across subnets, can meet the needs of various scenarios, and provides a secure foundation for realizing distributed subnet interconnection. Attached Figure Description

[0021] Figure 1 A schematic diagram of a block structure provided for related technologies;

[0022] Figure 2 A schematic diagram of a Merkle tree provided for related technologies;

[0023] Figure 3 A schematic diagram illustrating the process of service invocation between distributed network subnets for related technologies;

[0024] Figure 4This application provides a schematic diagram of the structure of a distributed network according to an embodiment of the present application.

[0025] Figure 5 This application provides a schematic diagram of the structure of a consortium blockchain network.

[0026] Figure 6 A flowchart illustrating an identity authentication method provided in an embodiment of this application;

[0027] Figure 7 This application provides a schematic diagram of a process for locally storing the DID information of a target object.

[0028] Figure 8 This is a schematic diagram illustrating the process of deleting the DID information corresponding to a target object from the blockchain, provided in an embodiment of this application.

[0029] Figure 9 A flowchart illustrating another authentication method provided in this application embodiment;

[0030] Figure 10 A flowchart illustrating an identity authentication method provided in a specific embodiment of this application;

[0031] Figure 11 A flowchart illustrating an identity authentication method provided in another specific embodiment of this application;

[0032] Figure 12 A flowchart illustrating an identity authentication method provided in another specific embodiment of this application;

[0033] Figure 13 A flowchart illustrating an identity authentication method provided in another specific embodiment of this application;

[0034] Figure 14 A flowchart illustrating an identity authentication method provided in another specific embodiment of this application;

[0035] Figure 15 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0036] To enable those skilled in the art to better understand the technical solutions of this application, the technical solutions provided in this application will be described in detail below with reference to the accompanying drawings.

[0037] Exemplary embodiments will be described more fully below with reference to the accompanying drawings; however, the described exemplary embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this application will be thorough and complete, and will enable those skilled in the art to fully understand the scope of this application.

[0038] As used herein, the term “and / or” includes any and all combinations of one or more related enumerated entries.

[0039] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application. As used herein, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that when the terms “comprising” and / or “made of” are used in this specification, the presence of a feature, integral, step, operation, element, and / or component is specified, but the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof is not excluded.

[0040] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0041] Unless otherwise specified, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in common dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this application, and will not be interpreted as having an idealized or overly formal meaning, unless expressly so defined in the embodiments of this application.

[0042] To facilitate a better understanding of the solutions in the embodiments of this application, the relevant technologies will be introduced first below.

[0043] Blockchain is a new application model of computer technologies such as distributed data storage, consensus mechanisms, and cryptographic algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains one or more transaction records used to verify the validity of the information (anti-counterfeiting) and to generate the next block.

[0044] The functions of each node in a blockchain system include:

[0045] 1) Routing: A basic function of nodes used to support communication between nodes.

[0046] 2) Applications are deployed in the blockchain to implement specific business needs. They record data related to the implementation of functions to form record data, carry digital signatures in the record data to indicate the source of the task data, and send the record data to other nodes in the blockchain system. When other nodes successfully verify the source and integrity of the record data, they add the record data to the temporary block.

[0047] For example, the business logic implemented by the application includes:

[0048] 2.1) A wallet is used to provide the function of making payment transactions, including initiating a transaction (that is, sending the transaction record of the current transaction to other nodes in the blockchain system; after the other nodes verify the transaction successfully, they store the transaction record data in the temporary block of the blockchain as a response to acknowledge the validity of the transaction; of course, the wallet also supports querying the remaining amount in the payment address.

[0049] 2.2) Shared ledger, used to provide functions such as storage, query and modification of ledger data. It sends the record data of the operation on the ledger data to other nodes in the blockchain system. After the other nodes verify the validity, as a response to acknowledge the validity of the ledger data, they store the record data in a temporary block. It can also send confirmation to the node that initiated the operation.

[0050] 2.3) Smart contracts are computerized protocols that can execute the terms of a contract. They are implemented through code deployed on a shared ledger that executes when certain conditions are met. Based on actual business needs, the code is used to complete automated transactions, such as querying the logistics status of goods purchased by a buyer and transferring the buyer's payment to the merchant's address after the buyer signs for the goods. Of course, smart contracts are not limited to executing contracts for transactions; they can also execute contracts for processing received information.

[0051] 2.4) Consensus is used to solve and ensure the consistency and correctness of every transaction or data across all consensus nodes. The consensus mechanism of a blockchain determines how to reach and maintain that consensus. This mechanism enables blockchain to operate on a large scale and efficiently without relying on a centralized organization.

[0052] Consensus mechanism is an important feature of blockchain system. The so-called "consensus mechanism" is to complete the verification and confirmation of transaction data in the block data by some special nodes in the block system through voting, so that the corresponding transaction data block can be stored in the blockchain after the verification is successful.

[0053] In the blockchain field, a transaction refers to a task unit executed and recorded within the blockchain. A transaction typically includes a From field, a To field, and a Data field. In the case of a transfer transaction, the From field represents the account address initiating the transaction (i.e., initiating a transfer task to another account), the To field represents the account address receiving the transaction (i.e., receiving the transfer), and the Data field includes the transfer amount. In the case of a transaction calling a smart contract in the blockchain, the From field represents the account address initiating the transaction, the To field represents the account address of the contract called by the transaction, and the Data field includes the function name in the called contract and the parameters passed to that function, used to retrieve and execute the function's code from the blockchain during transaction execution. In practical applications, when blockchain is used in scenarios such as bill of exchange transactions or data storage for enterprises or regulatory agencies, not all nodes in the blockchain network have sufficient resources and the necessity to participate in blockchain consensus. Furthermore, due to data security considerations, the common data-peer blockchain deployment method is not suitable for data involving privacy and security in the blockchain system. To adapt to business needs (such as separation of internal and external networks, business networks, and office networks) and further improve data security and confidentiality, this application provides a two-layer chain. It forms a layered blockchain network architecture of "witness network + consensus network" through a P2P (Peer-to-Peer) network. The P2P network is a peer-to-peer connection network, where each node is called a peer node. Based on a specific network protocol, the P2P network eliminates the need for a central node to maintain the network state. Each node maintains the overall network state and its connection status with neighboring nodes through broadcast interactions with them.

[0054] A blockchain consists of a series of blocks linked together in chronological order of their creation. See also... Figure 1 This is a schematic diagram of the structure of a block provided in an embodiment of this application. Figure 1 The block shown includes a block header and a block body. The block header may include the hash value of the previous block, the hash value of the current block, the timestamp, the version number, and the Merkle root. The block body may include a series of transaction data generated by the blockchain system. The Merkle root in the block header is generated based on the transaction data in the block body.

[0055] To control block size, blockchain systems use hash functions to encode raw transaction data into hash values ​​of a specific length for storage. A hash function, also known as a hash map, maps a dataset in one space as evenly as possible to another space smaller than the original dataset. That is, for any input string x, it outputs a fixed-length H(x), and x cannot be derived from H(x). The hash values ​​of the raw transaction data are organized using a Merkle tree. See also... Figure 2 This is a schematic diagram of a Merkle tree provided in an embodiment of this application. The hash value of each transaction is a leaf node of the Merkle tree. Starting from the bottom up, the combined hash of two adjacent leaf nodes is used as a new hash value. This new hash value becomes a tree node and continues to be combined with adjacent tree nodes to form new hash values. This process is repeated a certain number of times until a unique root node of the Merkle tree is formed. The hash value of the final root node (i.e., the Merkle root) is stored in the block header so that the transaction can be simply verified using the block header (Simplified Payment Verification, SPV).

[0056] For Merkle trees, it's not necessary to know the value of every node in the entire Merkle tree. A node's value, the Merkle root value, and the relevant path can be used to quickly verify whether it belongs to the Merkle tree, thus quickly verifying whether a block contains a particular transaction. Furthermore, timestamps are used to mark block order.

[0057] The next-generation information service network relies on the operator's main network, making the centralized control method of traditional mobile communication networks unsustainable. The development of distributed networks is inevitable. Consortium blockchains, targeting only members of a specific group and a limited number of third parties, are well-suited for use in distributed communication network scenarios due to their high performance, flexibility, and high security. With the development of distributed networks, independently operated subnets have emerged, such as enterprise private networks, whose applications are becoming increasingly widespread in the context of distributed network development.

[0058] However, due to reasons such as enterprise information security, enterprise private networks require independent management of enterprise users. Users can only sign contracts within the enterprise private network, and the contract information used for authentication is sensitive information and cannot be exposed to external networks.

[0059] Please see Figure 3 This provides a flowchart illustrating a distributed network subnet service invocation process for related technologies, such as... Figure 3As shown, when a user in the first subnet of an enterprise private network accesses an external network service, after completing intra-subnet authentication through the first network control unit and the first network data unit, requests the service to the second subnet, the second subnet, being an external network, still needs to authenticate the enterprise user, i.e., it expects secondary authentication. However, the external second subnet does not have the user information of the first subnet user and cannot initiate an authentication request to the first subnet. Therefore, it is impossible to complete cross-subnet user authentication using access authentication subscription information in related technologies.

[0060] This application addresses the issue of users being unable to authenticate their identities across subnets by providing an identity authentication method, device, medium, and program product. It combines a consortium blockchain with a decentralized identifier (DID) and integrates it into standard communication protocol processes. A DID is a novel distributed digital identity with global uniqueness, high availability, and cryptographic verifiability, independent of any centralized registry, identity provider, or certificate authority. Identity authentication is achieved by adding decentralized identifier (DID) information, without relying on a centralized certification center, effectively ensuring data privacy and security. It eliminates the need for cross-subnet access to sensitive data, meeting the needs of various scenarios and providing a secure foundation for achieving distributed subnet interconnection.

[0061] To facilitate understanding of the technical solutions in the embodiments of this application, the implementation architecture of the identity authentication method provided in the embodiments of this application is described below. Please refer to... Figure 4 This is a schematic diagram of the architecture of a distributed network system provided in an embodiment of this application. The authentication method provided in this embodiment can be applied to... Figure 4 The distributed network system shown. For example... Figure 4 As shown, the distributed network system comprises multiple distributed subnets. Distributed subnet A serves as an enterprise private network, distributed subnet B as a carrier's main network, and other subnets include distributed subnets C and D, etc. Each distributed subnet includes a network control unit, a network data unit, and a blockchain functional unit, and each subnet maintains a corresponding blockchain.

[0062] In this embodiment of the application, the blockchain functional units of multiple subnets in a distributed network system can form a consortium blockchain network. Please refer to [link to relevant documentation]. Figure 5 This is a schematic diagram of a consortium blockchain network provided in an embodiment of this application. Figure 5 As shown, the consortium blockchain network includes blockchain functional units of multiple subnets, with each blockchain functional unit corresponding to a subnet.

[0063] In this embodiment, the network control unit is a unified and aggregated network control function entity. For example, it may be the logical processing part of the Access and Mobility Management Function (AMF), Session Management Function (SMF), Network Exposure Function (NEF), Policy Control Function (PCF), and Unified Data Management (UDM) in a 5G network.

[0064] In this embodiment, the network data unit is a unified aggregated data plane. Examples include static contract data from PCF and UDM in a 5G network, and a unified data repository (UDR).

[0065] In this embodiment, the blockchain functional unit is a blockchain functional entity with distributed ledger functionality, capable of performing multiple functions within the blockchain network, such as consensus mechanisms and ledger storage. The blockchain functional units of a subnet can operate independently, providing identity authentication for non-end-users, such as in a distributed subnet. Interconnection between distributed subnets and other subnets requires mutual trust as the first step. Distributed digital identities provide distributed subnet identity authentication, achieving mutual trust and ultimately interconnection. In this embodiment, the distributed subnet is a distributed network, serving as either a central network or an edge network providing network functionality to users.

[0066] In this embodiment of the application, the user can be a terminal, network node, group, etc. Any entity that can be identified can be defined as a user.

[0067] Please see Figure 6 This is a flowchart illustrating an identity authentication method provided in an embodiment of this application. The method can be applied to a first subnet, which includes a first network control unit and a first blockchain functional unit. The first blockchain functional unit and at least one blockchain functional unit from another subnet form a consortium blockchain network. Figure 6 As shown, the identity authentication method provided in this application embodiment includes, but is not limited to, steps S110 to S140:

[0068] Step S110: The first blockchain functional unit generates decentralized identifier (DID) information based on the identity information corresponding to the target object. The DID information includes the DID corresponding to the target object.

[0069] Step S120: The first blockchain functional unit initiates and broadcasts the first transaction, which indicates that the DID information corresponding to the target object is stored.

[0070] Step S130: The blockchain functional units of the first subnet and other subnets in the consortium blockchain network work together to process the consensus of the first transaction, and write the first transaction into their respective blockchains after the consensus is passed. The other subnets include the second subnet.

[0071] Step S140: The first network control unit sends a first service request carrying the DID corresponding to the target object to the second network control unit of the second subnet. The first service request is used to instruct the second subnet to determine the identity authentication result of the target object based on the DID.

[0072] For example, the first blockchain functional unit is pre-configured with a smart contract, and the first blockchain functional unit generates DID information based on the identity information corresponding to the target object through the smart contract.

[0073] The DID information corresponding to the target object can contain a digital signature, which the second subnet can directly verify during identity authentication; the second subnet can also initiate a challenge to perform secondary authentication on the target user. These two methods can be selected according to the application scenario.

[0074] The first subnet generates a decentralized representation of the DID for the target object through the first blockchain functional unit. This DID information is then written into the blockchain functional units of other subnets in the consortium blockchain network through the first transaction. When the first subnet needs to request services from the second subnet, the first network control unit carries the user's DID in the service request. The second subnet's network control unit then queries the blockchain for relevant DID information to complete identity authentication. The second subnet can perform identity authentication without relying on a centralized authentication center, effectively ensuring data privacy and security. It also eliminates the need for cross-subnet access to sensitive data, providing a secure foundation for distributed subnet interconnection.

[0075] This application embodiment is based on a consortium blockchain, using standard DID (Distributed Digital Identity) and integrating standard protocols to complete cross-subnet identity authentication for target objects. First, a consortium blockchain network is constructed through interconnected distributed subnet blockchain functional units to reach consensus on identity verification. Each subnet uses a pre-agreed verification method (such as through smart contracts) to authenticate the target object. Each subnet has a blockchain functional unit to complete the functional collaboration between the core network and the blockchain. After the target object completes authentication within its own subnet (such as the first subnet mentioned above), the local subnet's network control unit applies for a Distributed Digital Identity (DID) for the target object. Upon successful application, the DID and related documents are uploaded to the blockchain. The local subnet's network control unit carries the target object's DID to the service provider's (such as the second subnet mentioned above) network control unit to request service. The service provider's network control unit queries the blockchain for DID-related information based on the DID to complete identity authentication. The DID information may contain a digital signature, which the service provider can directly verify; alternatively, the service provider can initiate a challenge for secondary authentication of the target object. The choice between these two methods depends on the application scenario. In this embodiment, the generation of DID information and DID-based identity authentication can all be implemented using smart contracts to minimize the impact on network functions. For example, the target object can be a user, the first subnet can be an enterprise private network, and the second subnet can be a carrier's main network. Enterprise private network users can only authenticate within their own network; the carrier's main network cannot authenticate enterprise private network users. In this embodiment, the enterprise private network generates the user's DID information through its own blockchain functional unit and initiates a first transaction. This allows the blockchain functional units of other subnets in the consortium blockchain network to reach a consensus on the first transaction. After the consensus is passed, the first transaction is written into the corresponding blockchains to store the user's DID information. When an enterprise private network user needs to use the carrier's main network service, the enterprise private network sends a service request carrying the user's DID to the carrier's main network. The carrier's main network then searches for the corresponding DID information on the blockchain based on the user's DID and authenticates the enterprise private network user based on the found DID information. This eliminates the need for a centralized authentication center, effectively ensuring the data privacy and security of enterprise private network users. Once the enterprise private network user's authentication is successful, the carrier's main network provides services to that user.

[0076] It should be noted that the enterprise private network and the operator's large network mentioned above are only examples of distributed subnets. The embodiments of this application are applicable to any distributed subnet and are not limited to the two examples of distributed subnets mentioned above.

[0077] It should be noted that the first subnet in this embodiment further includes a first network data unit. After writing the first transaction information into the blockchain block corresponding to the local subnet, the DID information of the target object also needs to be saved to the first network data unit, such as... Figure 7 As shown, the steps for locally saving the DID information of the target object may include, but are not limited to, steps S210 to S230:

[0078] Step S210: The first blockchain functional unit sends a registration success message to the first network control unit, wherein the registration success message carries the DID information corresponding to the target object;

[0079] Step S220: The first network control unit obtains the DID information corresponding to the target object through the registration success message, and sends the DID information corresponding to the target object to the first network data unit;

[0080] Step S230: The first network data unit saves the DID information corresponding to the target object.

[0081] It is understandable that once the first network data unit saves the DID information corresponding to the target object, when the target object needs to call the service from the second subnet through the first subnet again, it can directly use the saved DID information for authentication without having to generate the DID again.

[0082] It should be noted that, in this embodiment of the application, before the first blockchain functional unit generates decentralized identifier (DID) information based on the target object's identity information, the target object needs to undergo local subnet identity authentication to access the first subnet. The local subnet identity authentication steps may include, but are not limited to, steps S310 to S330:

[0083] Step S310: The first network control unit receives the first access request of the target object, and the first access request carries the identity information of the target object.

[0084] Step S320: The first network control unit sends the identity information of the target object to the first network data unit to work together with the first network data unit to complete the local subnet identity authentication of the target object.

[0085] Step S330: After completing the local subnet identity authentication of the target object, the first network control unit sends the target object's identity information to the first blockchain functional unit.

[0086] By completing local subnet identity authentication, the target object for access is confirmed to be a local subnet user, ensuring data security and preventing identity theft and tampering.

[0087] It should be noted that, in this embodiment, when the target object completes local subnet identity authentication and needs to make a cross-subnet service call, a DID query needs to be performed on the first network data unit before sending the target object's identity information to the first blockchain functional unit to improve call efficiency. If the first network data unit has already stored the target object's DID, there is no need to generate the target user's DID again. For example, the DID query may include, but is not limited to, steps S410 to S430:

[0088] Step S410: The first network control unit sends a query request to the first network data unit. The query request is used to request the DID corresponding to the target object.

[0089] Step S420: The first network data unit searches for the corresponding DID locally according to the query request, and performs the following steps S430a or S430b according to the query result;

[0090] In step S430a, if the first network data unit does not find the corresponding DID, it returns a null value to the first network control unit so that the first network control unit responds to the null value and sends the identity information of the target object to the first blockchain function unit, so that the first blockchain function unit performs the operations as in steps S110-S140.

[0091] In step S430b, if the first network data unit finds the corresponding DID, it returns the found DID to the first network control unit; the first network control unit sends a second service request to the second subnet, and the second service request carries the DID returned by the first network data unit.

[0092] Understandably, when cross-subnet scheduling services are required, if the local subnet has already stored the target object's DID information, the corresponding DID stored locally can be directly obtained from the first network data unit. In this case, the found DID can be directly returned to the first network control unit, which then sends a second service request carrying the target user's DID to the second subnet to invoke the second subnet's service, improving calling efficiency without needing to regenerate the target object's corresponding DID information. If the corresponding DID cannot be found locally in the first network data unit, then the target object's identity information is sent to the first blockchain functional unit, which generates DID information based on the target object's identity information. The method for generating the target object's corresponding DID information is described in the preceding steps.

[0093] After the first network data unit saves the DID information corresponding to the target object, it needs to manage the saved DID information. When the DID information corresponding to the target object stored in the first network data unit exceeds the validity period, the first network data unit deletes the DID information corresponding to the target object.

[0094] Please see Figure 8 The diagram below illustrates the process of deleting the DID information corresponding to a target object from the blockchain, as provided in this application embodiment, including but not limited to steps S510 to S550:

[0095] Step S510: The DID information corresponding to the target object stored in the first network data unit has expired, and the first network data unit deletes the DID information corresponding to the target object.

[0096] Step S520: The first network control unit sends a query request to the first network data unit. The query request is used to request the DID corresponding to the target object.

[0097] Step S530: If the first network data unit cannot find the DID corresponding to the target object locally according to the query request, it returns a null value to the first network control unit.

[0098] Step S540: The first network control unit sends a deletion request to the first blockchain function unit based on the null value returned by the first network data unit. The deletion request is used to request the deletion of the DID information corresponding to the target object.

[0099] Step S550: The first blockchain functional unit initiates and broadcasts a second transaction based on the deletion request. The second transaction indicates the deletion of the DID information corresponding to the target object, so as to coordinate with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the second transaction.

[0100] Step S560: After consensus is reached, each subnet will write the second transaction into its corresponding blockchain.

[0101] In this embodiment, after the storage time of the DID information corresponding to the target object exceeds its validity period, all blockchain functional units of the consortium blockchain need to reach a consensus to delete the DID information corresponding to the target object stored in the blockchains of each subnet. The first network data unit in the first subnet triggers the first network control unit to return a null value, confirming that the DID information corresponding to the target object has expired. The first network control unit then sends a deletion request to the first blockchain functional unit, causing the first blockchain functional unit to broadcast a second transaction. After other subnets of the consortium blockchain receive the second transaction and reach a consensus, they write the second transaction into the blockchains of their respective subnets, ensuring that the expired DID information corresponding to the target object is deleted in a timely manner.

[0102] It is understood that, in this embodiment of the application, the DID information also includes the DID document corresponding to the target object and the permission information corresponding to the target object. After the first network control unit generates the DID information (which may include the DID, DID document, and permission information) corresponding to the target object based on the identity information corresponding to the target object through a smart contract, it puts the DID and the DID document corresponding to the target object on the blockchain. If the consensus part between subnets includes the permission information corresponding to the target object, the subnets of the consortium blockchain will negotiate the permissions of the target object and put the negotiated permission information corresponding to the target object on the blockchain.

[0103] Please see Figure 9 This is a flowchart illustrating another identity authentication method provided in an embodiment of this application. This method can be applied to a second subnet, which includes a second network control unit and a second blockchain functional unit. The second blockchain functional unit and at least one blockchain functional unit from another subnet form a consortium blockchain network. Figure 9 As shown, the method includes, but is not limited to, steps S610 to S650:

[0104] Step S610: The second blockchain functional unit receives the first transaction initiated by the first subnet. The first transaction carries the DID information corresponding to the target object. The first transaction indicates that the DID information corresponding to the target object is stored. The DID information includes the DID corresponding to the target object.

[0105] In step S620, the second blockchain functional unit collaborates with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction, and writes the first transaction into their respective blockchains after the consensus is passed.

[0106] Step S630: The second network control unit receives a first service request from the first subnet, the first service request carrying the DID corresponding to the target object.

[0107] In step S640, the second network control unit responds to the first service request by sending a verification request to the second blockchain functional unit, the verification request carrying the DID corresponding to the target object.

[0108] Step S650: The second blockchain functional unit searches for the DID information corresponding to the target object in the blockchain corresponding to the local subnet based on the DID information of the target object in the verification request, and determines the identity authentication result of the target object based on the found DID information.

[0109] It should be noted that the second blockchain functional unit and at least one other subnet's blockchain functional unit constitute a consortium blockchain network, with the first subnet being one of the other subnets.

[0110] By adding a second blockchain functional unit to the second subnet, the second blockchain functional unit collaborates with the blockchain functional units of other subnets in the consortium blockchain network to process the consensus of the first transaction. After the consensus is passed, the first transaction is written into their respective blockchains, so that the DID information corresponding to the target object is stored in the blockchain of the second subnet. When the target object needs to call the service of the second subnet, the second subnet can look up the corresponding DID information (which may include DID, DID document and permission information) in the blockchain of its local subnet according to the DID, and then verify the identity of the target object by using the found DID information. This does not require access to sensitive data across subnets, effectively ensuring data privacy and data security.

[0111] For example, the second blockchain functional unit may be pre-configured with a smart contract, which verifies the DID information of the target object.

[0112] For example, the DID information can contain a digital signature, which the second subnet can directly verify to obtain the authentication result. Service providers can also use the DID information to initiate a challenge for secondary authentication of the target object. These two methods can be chosen based on the application scenario. It should be understood that using smart contracts to implement DID-based authentication can reduce the impact on network functions.

[0113] In this embodiment of the application, the DID information corresponding to the target object is generated through the first subnet. The first subnet initiates and broadcasts a first transaction that stores the DID information corresponding to the target object, so as to cooperate with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction. After the consensus is passed, the first transaction is written into their respective blockchains. For the specific method and process, please refer to the identity authentication method applied to the first subnet described above, which will not be repeated here.

[0114] For example, to obtain services from the second subnet, the first subnet first sends a service request carrying a DID to the second network control unit of the second subnet. In response to the service request, the second network control unit sends the DID carried in the service request to the second blockchain functional unit of its local subnet. The second blockchain functional unit then searches for the corresponding DID information in the blockchain of its local subnet and verifies the DID information using a smart contract to determine the identity authentication result of the target object. The second blockchain functional unit sends a verification response message to the second network control unit, carrying the identity authentication result of the target object. If the identity authentication result is successful, the second network control unit establishes a service connection with the first subnet, enabling cross-subnet service calls in the distributed network while ensuring data security.

[0115] In this embodiment, the DID information also includes the DID document corresponding to the target object and the permission information corresponding to the target object. If the authentication result is successful, the second network control unit establishes a service connection with the first subnet based on the permission information corresponding to the target object. Based on the permission information of the target object, corresponding permission services are provided to the target object.

[0116] It is understandable that after the DID information corresponding to the target object expires, the second subnet needs to work with the first subnet to delete the expired DID information to avoid resource consumption. The deletion of DID information may include, but is not limited to, steps S710 and S720:

[0117] Step S710: The second blockchain functional unit receives a second transaction initiated by the first subnet. The second transaction indicates that the DID information corresponding to the target object is deleted.

[0118] In step S720, the second blockchain functional unit collaborates with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the second transaction, and writes the second transaction into their respective blockchains after the consensus is passed.

[0119] For the second transaction initiated by the first subnet, please refer to the method described above, which will not be repeated here.

[0120] After receiving the second transaction and reaching a consensus, other sub-networks of the consortium blockchain, including the second sub-network, will write the second transaction into the corresponding blockchain of the other sub-network to ensure that the DID information of the target object that has expired is deleted in a timely manner.

[0121] It should be noted that, on the other hand, the blockchain functional unit provided in this application embodiment can work independently to provide identity authentication for non-end-users, such as in a distributed subnet. Before a distributed subnet interconnects with other subnets, mutual trust is the first step. This can be achieved through distributed digital identity, providing distributed subnet identity authentication, thus enabling mutual trust and ultimately interconnection.

[0122] The embodiments of this application will be further described in detail below with reference to specific examples.

[0123] Example 1:

[0124] Please see Figure 10 The above is a flowchart illustrating an identity authentication method provided in a specific embodiment of this application. Figure 10 As shown, the enterprise private network is the first subnet, the carrier network is the second subnet, and the enterprise user is the target. After accessing the enterprise private network, the enterprise user expects to call services from the carrier network. At this time, the carrier network needs to authenticate the enterprise user. The authentication method includes the following steps:

[0125] Step S801: The first network control unit receives the first access request from the enterprise user, and the enterprise user accesses the first network control unit in the enterprise private network;

[0126] Step S802: The first network control unit and the first network data unit in the enterprise private network complete the enterprise user subnet authentication, which is the authorization authentication.

[0127] Step S803: The first network unit sends the enterprise user's identity information to the first blockchain functional unit;

[0128] Step S804: The first blockchain functional unit generates decentralized identifier (DID) information based on the identity information of the enterprise user through a smart contract. The DID information includes the DID corresponding to the enterprise user.

[0129] Step S805: The first blockchain functional unit initiates and broadcasts the first transaction to collaborate with the blockchain functional units of other subnets in the consortium blockchain network to process the first transaction in a consensus manner. The first transaction represents the storage of the DID information corresponding to the enterprise user.

[0130] Step S806: After consensus is reached, the blockchain functional units of the enterprise private network and other subnets in the consortium blockchain network will write the first transaction into their respective blockchains.

[0131] Step S807: The first blockchain functional unit sends a registration success message to the first network control unit, wherein the registration success message carries the DID information corresponding to the enterprise user;

[0132] Step S808: The first network control unit obtains the DID information corresponding to the enterprise user through the registration success message, and sends the DID information corresponding to the enterprise user to the first network data unit;

[0133] Step S809: The first network data unit stores the DID information corresponding to the enterprise user;

[0134] Step S810: The first network control unit sends a first service request carrying the DID corresponding to the enterprise user to the second network control unit of the operator's network.

[0135] Step S811: In response to the first service request, the second network control unit sends a verification request to the second blockchain functional unit, the verification request carrying the DID corresponding to the enterprise user;

[0136] Step S812: The second blockchain functional unit searches for the DID information corresponding to the enterprise user in the blockchain corresponding to the local subnet based on the DID information of the enterprise user in the verification request, and determines the identity authentication result of the enterprise user based on the found DID information.

[0137] Step S813: The second blockchain functional unit sends a verification response message to the second network control unit. The verification response message carries the identity authentication result of the enterprise user.

[0138] Step S814: If the identity authentication result is successful, the second network control unit establishes a service connection with the enterprise private network, allowing enterprise users to access the services of the operator's main network.

[0139] By adding decentralized identifier (DID) information to complete identity authentication, enterprise users can access services from the operator's main network without relying on a centralized authentication center, effectively ensuring data privacy and security. It also eliminates the need to access sensitive data across subnets, meeting the needs of various scenarios and providing a secure foundation for achieving distributed subnet interconnection.

[0140] Example 2:

[0141] Please refer to Figure 11 The above is a flowchart illustrating an identity authentication method provided in another specific embodiment of this application, as shown below. Figure 11 As shown, the enterprise private network is the first subnet, the operator's main network is the second subnet, and the enterprise user is the target. After accessing the enterprise private network, the enterprise user expects to call services from the operator's main network. In Example 2, the enterprise user's DID information has been recorded in the first network data unit. At this time, the identity authentication method includes the following steps:

[0142] Step S901: The first network control unit receives the first access request from the enterprise user, and the enterprise user accesses the first network control unit in the enterprise private network;

[0143] Step S902: The first network control unit and the first network data unit in the enterprise private network complete the enterprise user subnet authentication, which is the authorization authentication.

[0144] Step S903: The first network control unit sends a query request to the first network data unit. The query request is used to request the DID corresponding to the target object.

[0145] Step S904: The first network data unit searches for the corresponding DID locally according to the query request;

[0146] Step S905: If the first network data unit finds the corresponding DID, it returns the found corresponding DID to the first network control unit.

[0147] Step S906: The first network control unit sends a second service request to the operator's main network. The second service request carries the DID returned by the first network data unit.

[0148] Step S907: In response to the second service request, the second network control unit sends a verification request to the second blockchain functional unit, the verification request carrying the DID corresponding to the target object;

[0149] Step S908: The second blockchain functional unit searches for the DID information corresponding to the enterprise user in the blockchain corresponding to the local subnet based on the DID information of the target enterprise user in the verification request, and determines the identity authentication result of the enterprise user based on the found DID information.

[0150] Step S909: The second blockchain functional unit sends a verification response message to the second network control unit. The verification response message carries the identity authentication result of the enterprise user.

[0151] Step S910: If the identity authentication result is successful, the second network control unit establishes a service connection with the enterprise private network, allowing enterprise users to access the services of the operator's main network.

[0152] In Embodiment 2, the enterprise user has already obtained its corresponding DID information when it last accessed and requested the operator's network service. After the DID information is saved into the first network data unit of the enterprise private network, it can be directly called. When the enterprise user accesses the enterprise private network again, it can request the service call from the operator's network through the method of Embodiment 2, thereby reducing the consumption of system resources.

[0153] Example 3:

[0154] Please refer to Figure 12 The above is a flowchart illustrating an identity authentication method provided in another specific embodiment of this application, as shown below. Figure 12 As shown, the enterprise private network is the first subnet, the operator's main network is the second subnet, and the enterprise user is the target. After accessing the enterprise private network, the enterprise user expects to call services from the operator's main network. In Example 3, the enterprise user's DID information has been recorded in the first network data unit. The recorded DID information has a validity period. At this time, the identity authentication method includes the following steps:

[0155] Step S1001: The first network control unit sends the DID information corresponding to the successfully registered enterprise user to the first network data unit. The DID information corresponding to the enterprise user carries the validity period.

[0156] Step S1002: The first network data unit saves the DID information corresponding to the enterprise user and starts the timer;

[0157] Step S1003: When the DID information corresponding to the enterprise user stored in the first network data unit exceeds the validity period, the first network data unit deletes the corresponding DID information.

[0158] Step S1004: The first network control unit sends a query request to the first network data unit. The query request is used to query the DID corresponding to the enterprise user.

[0159] Step S1005: If the first network data unit cannot find the DID corresponding to the enterprise user locally according to the query request, it returns a null value to the first network control unit.

[0160] Step S1006: The first network control unit sends a deletion request to the first blockchain function unit based on the null value returned by the first network data unit. The deletion request is used to request the deletion of the DID information corresponding to the enterprise user.

[0161] Step S1007: The first blockchain functional unit initiates and broadcasts a second transaction based on the deletion request. The second transaction indicates the deletion of the DID information corresponding to the enterprise user.

[0162] Step S1008: The blockchain functional units of the enterprise private network and other subnets in the consortium blockchain network work together to process the consensus of the second transaction, and write the second transaction into their respective blockchains after the consensus is passed. The operator's main network is included in other subnets in the consortium blockchain network.

[0163] Step S1009: When an enterprise user reconnects to the enterprise private network, the first network control unit sends the enterprise user information to the first blockchain functional unit to re-register the DID. The specific registration method is described above and will not be repeated here.

[0164] In Example 3, the DID information corresponding to enterprise users carries an expiration date. When the expiration date is exceeded, the first network data unit deletes it and then reapplies, saving system overhead and ensuring the periodic updating of user identity, thus improving security.

[0165] Example 4:

[0166] Please refer to Figure 13 The above is a flowchart illustrating an identity authentication method provided in another specific embodiment of this application, as shown below. Figure 13 As shown, the UE is the user (i.e., the target object), the AMF, Authentication Server Function (AUSF) / UDM, and I-SMF in the first subnet are the first network control unit, the RAN in the first subnet is the first network data unit, and the A-SMF in the second subnet is the second network control unit. The user subscribes in the first subnet and expects to call the services of the second subnet. At this time, the authentication method includes the following steps:

[0167] Step S1101: User UE goes online and accesses the AMF in the first subnet;

[0168] Step S1102: The AMF of the first subnet initiates a UE authentication request to the AUSF / UDM of the first subnet to perform intranet authentication;

[0169] Step S1103: The UE, the AMF of the first subnet, and the AUSF / UDM of the first subnet work together to complete the subnet authentication.

[0170] Step S1104: AUSF / UDM sends the UE's identity information to the first blockchain functional unit;

[0171] Step S1105: The first blockchain functional unit generates decentralized identifier (DID) information based on the user's corresponding identity information through a smart contract. The DID information includes the user's corresponding DID.

[0172] Step S1106: The first blockchain functional unit initiates and broadcasts the first transaction to collaborate with the blockchain functional units of other subnets in the consortium blockchain network to process the first transaction in a consensus manner. The first transaction represents storing the DID information corresponding to the target object.

[0173] Step S1107: After consensus is reached, the blockchain functional units of the first subnet and other subnets in the consortium blockchain network will write the first transaction into their respective blockchains. Other subnets in the consortium blockchain network include the second subnet.

[0174] Step S1108: The first blockchain functional unit sends a registration success message to AUSF / UDM, wherein the registration success message carries the DID information corresponding to the UE;

[0175] Step S1109: AUSF / UDM informs AMF that user authentication is complete;

[0176] Step S1110: The AMF sends a first service request carrying the DID corresponding to the UE to the A-SMF of the second subnet;

[0177] Step S1111: In response to the first service request, A-SMF sends a verification request to the second blockchain functional unit, the verification request carrying the user's corresponding DID;

[0178] Step S1112: The second blockchain functional unit searches for the user's corresponding DID information in the blockchain corresponding to the local subnet based on the DID information of the user in the verification request, and determines the user's identity authentication result based on the found DID information.

[0179] Step S1113: The second blockchain functional unit sends a verification response message to A-SMF, and the verification response message carries the user's identity authentication result;

[0180] Step S1114: If the authentication result is successful, A-SMF establishes a service connection with the first subnet, allowing the user UE to access the services of the second subnet.

[0181] When user UE performs cross-subnet identity authentication, it does not rely on a centralized authentication center, effectively ensuring data privacy and data security. It does not require cross-subnet access to sensitive data, which can meet the needs of various scenarios and provide a secure foundation for realizing distributed subnet interconnection.

[0182] Example 5:

[0183] In addition to the embodiments described above, this application also provides an embodiment in which blockchain functional units operate independently. Before interconnection between distributed subnets, the identity and permissions of the distributed subnets must be verified. Only after successful verification can interconnection occur, thereby providing services to subnet users. This embodiment is the basis of the above embodiments and is also an embodiment in which blockchain functional units operate independently.

[0184] Please see Figure 14 The above is a flowchart illustrating an identity authentication method provided in another specific embodiment of this application, as shown below. Figure 14 As shown, when the blockchain functional units operate independently, the first subnet contains a first network management unit and a first blockchain functional unit, and the second subnet contains a second network management unit and a second blockchain functional unit. Distributed network A, which is the first subnet, and distributed network B, which is the second subnet, authenticate each other through the first blockchain functional unit in the first subnet and the second blockchain functional unit in the second subnet, so as to provide services to subnet users in the future. The authentication steps are as follows:

[0185] Step S1201: The first network management unit of the first subnet sends the identity information corresponding to subnet A to the first blockchain functional unit;

[0186] Step S1202: The first blockchain functional unit generates decentralized identifier (DID) information based on the identity information corresponding to subnet A. The DID information includes the DID corresponding to subnet A.

[0187] Step S1203: The first blockchain functional unit initiates and broadcasts the first transaction, which represents storing the DID information corresponding to subnet A;

[0188] Step S1204: The blockchain functional units of the first subnet and other subnets in the consortium blockchain network work together to process the consensus of the first transaction, and write the first transaction into their respective blockchains after the consensus is passed. The second subnet is included in other subnets in the consortium blockchain network.

[0189] Step S1205: The first blockchain functional unit sends a registration success message to the first network management unit, wherein the registration success message carries the DID information corresponding to subnet A;

[0190] Step S1206: The first network management unit sends a connection request carrying the DID corresponding to subnet A to the second network management unit;

[0191] Step S1207: After receiving the connection request, the second network management unit sends a verification request to the second blockchain functional unit. The verification request carries the DID corresponding to the target object.

[0192] Step S1208: The second blockchain functional unit searches for the DID information corresponding to the target object in the blockchain corresponding to the local subnet based on the DID information of the target object in the verification request, and determines the identity authentication result of the target object based on the found DID information.

[0193] Step S1209: The second blockchain functional unit sends a verification response message to the second network management unit. The verification response message carries the identity authentication result of subnet A.

[0194] Step S1210: If the identity authentication result is successful, the second subnet and the first subnet shall be interconnected.

[0195] The blockchain functional unit verifies the identity and permissions of the distributed subnet, thereby providing services to subnet users.

[0196] This application also provides an electronic device, such as... Figure 15 As shown, the electronic device 1400 includes:

[0197] One or more processors 1410;

[0198] The memory 1420 stores one or more programs that, when executed by one or more processors 1410, cause the one or more processors 1410 to implement the authentication method described in any of the above embodiments.

[0199] Memory 1420, as a non-transitory network system, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory 1420 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory 1420 may optionally include remotely located memories 1420 relative to processor 1410, which can be connected to processor 1410 via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0200] The memory 1420 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1420 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1420 and is called and executed by the processor 1410.

[0201] The processor 1410 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0202] In some embodiments, the electronic device further includes:

[0203] Input / output interfaces are used to implement information input and output;

[0204] The communication interface is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0205] The bus transmits information between various components of the device (e.g., processor 1410, memory 1420, input / output interface, and communication interface);

[0206] The processor 1410, memory 1420, input / output interface, and communication interface can communicate with each other within the device via a bus.

[0207] One embodiment of this application also provides a computer-readable storage medium storing computer-executable instructions for performing the authentication method described in any of the embodiments above.

[0208] An embodiment of this application also provides a computer program product, including a computer program or computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform an authentication method as described in any of the above embodiments.

[0209] The system architecture and application scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. Those skilled in the art will know that as the system architecture evolves and new application scenarios emerge, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0210] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.

[0211] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0212] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0213] The above description, with reference to the accompanying drawings, illustrates some embodiments of this application, but does not limit the scope of this application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and spirit of this application shall be within the scope of this application.

Claims

1. An identity authentication method applied to a first subnet, the first subnet including a first network control unit and a first blockchain functional unit, the first blockchain functional unit and blockchain functional units of at least one other subnet forming a consortium blockchain network, the method comprising: The first blockchain functional unit generates decentralized identifier (DID) information based on the identity information corresponding to the target object, wherein the DID information includes the DID corresponding to the target object; The first blockchain functional unit initiates and broadcasts the first transaction to collaborate with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction. After the consensus is passed, the first transaction is written into their respective blockchains. The first transaction represents the storage of the DID information corresponding to the target object. The first network control unit sends a first service request carrying the DID corresponding to the target object to the second subnet. The first service request is used to instruct the second subnet to determine the identity authentication result of the target object based on the DID. The second subnet is one of the other subnets.

2. The method according to claim 1, characterized in that, The first subnet further includes a first network data unit. After writing the first transaction information into the blockchain block corresponding to the local subnet, the method further includes: The first blockchain functional unit sends a registration success message to the first network control unit, wherein the registration success message carries the DID information corresponding to the target object; The first network control unit obtains the DID information corresponding to the target object through the registration success message, and sends the DID information corresponding to the target object to the first network data unit; The first network data unit stores the DID information corresponding to the target object.

3. The method according to claim 1, characterized in that, The first subnet further includes a first network data unit. Before the first blockchain functional unit generates decentralized identifier (DID) information based on the identity information of the target object, the method further includes: The first network control unit receives a first access request from the target object, the first access request carrying the identity information of the target object; The first network control unit sends the identity information of the target object to the first network data unit to work with the first network data unit to complete the local subnet identity authentication of the target object; After completing the local subnet identity authentication of the target object, the first network control unit sends the identity information of the target object to the first blockchain functional unit.

4. The method according to claim 3, characterized in that, Before sending the identity information of the target object to the first blockchain functional unit, the method further includes: The first network control unit sends a query request to the first network data unit, the query request being used to request the query of the DID corresponding to the target object; The first network data unit searches for the corresponding DID locally based on the query request; If the first network data unit does not find the corresponding DID, it returns a null value to the first network control unit, so that the first network control unit responds to the null value and sends the identity information of the target object to the first blockchain function unit.

5. The method according to claim 4, characterized in that, After the first network data unit searches for the corresponding DID locally according to the query request, the method further includes: If the first network data unit finds the corresponding DID, it returns the found DID to the first network control unit. The first network control unit sends a second service request to the second subnet, the second service request carrying the DID returned by the first network data unit.

6. The method according to claim 2, characterized in that, After the first network data unit saves the DID information corresponding to the target object, the method further includes: When the DID information corresponding to the target object stored in the first network data unit exceeds its validity period, the first network data unit deletes the DID information corresponding to the target object.

7. The method according to claim 6, characterized in that, After the first network data unit deletes the DID information corresponding to the target object, the method further includes: The first network control unit sends a query request to the first network data unit, the query request being used to request the query of the DID corresponding to the target object; If the first network data unit cannot find the DID corresponding to the target object locally based on the query request, it returns a null value to the first network control unit. The first network control unit sends a deletion request to the first blockchain function unit based on the null value returned by the first network data unit. The deletion request is used to request the deletion of the DID information corresponding to the target object. The first blockchain functional unit initiates and broadcasts a second transaction based on the deletion request, so as to cooperate with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the second transaction, and write the second transaction into their respective blockchains after the consensus is passed. The second transaction indicates the deletion of the DID information corresponding to the target object.

8. The method according to any one of claims 1-7, characterized in that, The DID information also includes the DID document corresponding to the target object.

9. The method according to any one of claims 1-7, characterized in that, The DID information also includes the permission information corresponding to the target object.

10. The method according to any one of claims 1-7, characterized in that, The first blockchain functional unit generates the DID information based on the identity information corresponding to the target object through a smart contract.

11. An identity authentication method applied to a second subnet, the second subnet including a second network control unit and a second blockchain functional unit, the second blockchain functional unit and blockchain functional units of at least one other subnet forming a consortium blockchain network, the method comprising: The second blockchain functional unit receives a first transaction initiated by a first subnet, which is one of the other subnets. The first transaction carries DID information corresponding to the target object. The first transaction indicates that the DID information corresponding to the target object is stored. The DID information includes the DID corresponding to the target object. The second blockchain functional unit collaborates with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction, and writes the first transaction into their respective blockchains after the consensus is passed; The second network control unit receives a first service request from the first subnet, the first service request carrying the DID corresponding to the target object; In response to the first service request, the second network control unit sends a verification request to the second blockchain functional unit, the verification request carrying the DID corresponding to the target object; The second blockchain functional unit searches for the DID information corresponding to the target object in the blockchain corresponding to the local subnet based on the DID information of the target object in the verification request, and determines the identity authentication result of the target object based on the found DID information.

12. The method according to claim 11, characterized in that, After determining the identity authentication result of the target object based on the found DID information, the method further includes: The second blockchain functional unit sends a verification response message to the second network control unit, the verification response message carrying the identity authentication result of the target object; If the authentication result is successful, the second network control unit establishes a service connection with the first subnet.

13. The method according to claim 12, characterized in that, The DID information also includes permission information corresponding to the target object, and the verification response message also carries the permission information corresponding to the target object; If the authentication result is successful, the second network control unit establishes a service connection with the first subnet, including: If the identity authentication result is successful, the second network control unit establishes a service connection with the first subnet based on the permission information corresponding to the target object.

14. The method according to claim 13, characterized in that, The DID information also includes the DID document corresponding to the target object.

15. The method according to claim 14, characterized in that, After the second blockchain functional unit collaborates with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the first transaction, and writes the first transaction into their respective blockchains after consensus is achieved, the method further includes: The second blockchain functional unit receives a second transaction initiated by the first subnet, the second transaction indicating the deletion of the DID information corresponding to the target object; The second blockchain functional unit collaborates with the blockchain functional units of other subnets in the consortium blockchain network to perform consensus processing on the second transaction, and writes the second transaction into their respective blockchains after the consensus is passed.

16. The method according to claim 11, characterized in that, The second blockchain functional unit determines the identity authentication result of the target object based on the found DID information through a smart contract.

17. An electronic device, characterized in that, include: One or more processors; A memory having stored one or more programs that, when executed by one or more processors, cause the one or more processors to implement: the authentication method as described in any one of claims 1-10, or the authentication method as described in any one of claims 11-16.

18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements: the authentication method as described in any one of claims 1-10, or the authentication method as described in any one of claims 11-16.

19. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements: the authentication method as described in any one of claims 1-10, or the authentication method as described in any one of claims 11-16.