Distributed identity platform enabled elevator digital identity authentication system
By using a distributed identity platform and blockchain technology, an elevator digital identity authentication system is built, which solves the problems of security risks and low efficiency in traditional elevator identity authentication. It achieves efficient and secure identity management and access control, ensuring the security and privacy protection of the elevator system.
Patent Information
- Application Number
- CN202511098344.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-08-06
AI Technical Summary
In the traditional elevator maintenance and supervision model, the identity authentication method has security risks and low efficiency. The access control is not precise enough and the audit traceability is difficult, which leads to an increase in security vulnerabilities in the elevator operation and maintenance process.
A distributed identity platform is adopted, and an elevator digital identity authentication system is built based on blockchain technology to realize entity identity registration, DID allocation, identity verification, access control and audit log recording. Unique DID and key pairs are generated using encryption algorithms, combined with a zero-knowledge proof identity verification protocol, and a smart contract module is set up for access management. Access logs are stored on an immutable blockchain.
It achieves decentralized management and tamper-proof storage of entity identities, prevents identity information leakage and forgery, ensures the underlying security of elevator system access, supports differentiated permission management, reduces the risk of unauthorized access, improves the efficiency and security of identity authentication, and ensures user privacy protection.
Smart Images

Figure CN120964546A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of identity authentication, in particular to an elevator digital identity authentication system empowered by a distributed identity platform. BACKGROUND
[0002] With the acceleration of urbanization, the number of elevators has increased dramatically, and their safety has attracted increasing attention. The traditional elevator maintenance and supervision mode has many drawbacks, such as poor management of elevator entity identity information, low efficiency and security risks in the identity authentication of maintenance engineers, supervisors and other personnel, insufficient fine-grained permission management, and difficulty in audit tracing. These problems lead to security vulnerabilities in the elevator operation and maintenance process, increasing the risk of elevator failure and safety accidents, so there is an urgent need for a more efficient, secure and traceable elevator digital identity authentication system and method. SUMMARY
[0003] The purpose of the present application is to provide an elevator digital identity authentication system empowered by a distributed identity platform to solve the above problems.
[0004] The present application provides an elevator digital identity authentication system empowered by a distributed identity platform, comprising:
[0005] A distributed identity platform configured to implement entity identity registration, DID allocation, identity verification, permission control and audit log recording functions, the distributed identity platform being constructed based on blockchain technology and composed of multiple nodes;
[0006] An entity identity registration module provided in the distributed platform and configured to receive entity registration requests and verify registration information, the entities including elevators, maintenance engineers and supervisors;
[0007] A DID allocation module connected to the entity identity registration module and configured to receive a verification pass signal from the entity identity registration module, generate a decentralized identifier for each entity according to an encryption algorithm and standard, and associate the decentralized identifier with the corresponding public key and encrypted entity identity information;
[0008] An identity verification module provided in the distributed platform and configured to perform identity verification on user access requests based on a zero-knowledge proof identity verification protocol and obtain elevator system access permissions;
[0009] An intelligent contract module provided in the distributed platform and configured to set access permission rules for elevators and related data for different entities;
[0010] An audit log module provided in the distributed platform and configured to generate access logs according to access requests and store them on a tamper-proof blockchain to form an audit trail.
[0011] Preferably, if the entity is an elevator, the registration information includes: elevator identification number, model, installation location, and property or management unit; wherein, the elevator identification number is unique and non-repeating;
[0012] If the entity is a maintenance engineer or supervisor, the registration information includes: personal identity information, professional qualification certificate number, and affiliated unit.
[0013] Preferably, the entity identity registration module receives the entity's registration request and verifies the registration information, including:
[0014] The distributed identity platform is connected to a management database, which includes basic information about all entities.
[0015] Upon receiving a registration request, the management database is filtered according to the type of entity, and the registration information is matched with the filtered data. If the match is successful, the registration information of the corresponding entity is verified.
[0016] If the match fails, it indicates that the registration information of the corresponding entity has failed verification.
[0017] Preferably, the DID allocation module generates a decentralized identifier for each entity based on the encryption algorithm and standard, and associates the decentralized identifier with the corresponding public key and the encrypted entity identity information, including:
[0018] Extract key metadata from registration information as the basic input for DID generation;
[0019] The key metadata is digested using SHA-256 to form a fixed-length basic vector. A high-intensity random salt value is generated, and a nanosecond-level timestamp is introduced as a variable factor to obtain a decentralized identifier, wherein the decentralized identifier is unique.
[0020] A key pair is generated using an encryption algorithm, and the entity's identity information is encrypted using the private key.
[0021] The public key is associated with the decentralized identifier and sent to the distributed identity platform, while the private key is sent to the entity.
[0022] Preferably, the authentication module uses a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions, including:
[0023] When a user needs to perform maintenance operations on the elevator, they send an access request to the elevator system. The access request includes the user's decentralized identifier and authentication information.
[0024] According to the user's decentralized identifier, a public key is obtained from the distributed identity platform, and the verification information is verified using a zero-knowledge proof protocol to determine whether the user's decentralized identifier is valid.
[0025] If the verification is passed, the elevator system grants the user corresponding elevator system access permission, allowing the user to perform maintenance operations.
[0026] Preferably, the smart contract module sets access permission rules for different entities for elevators and related data, including:
[0027] Obtain the operation requirements and safety policies of the elevator system, and generate access permission rules according to the operation requirements and safety policies, including elevator information viewing, operation state monitoring, fault alarm and maintenance operation requirements;
[0028] According to the type of entity, the access permission rules are distributed.
[0029] Preferably, the access permission rules are distributed according to the type of entity, including:
[0030] When the entity is a maintenance engineer, the qualification level of the maintenance engineer is obtained, and different maintenance operation requirements are distributed according to the qualification level;
[0031] When the entity is a supervisor, the management range of the supervisor is obtained, and the access permission rules of the elevators within the management range are distributed based on the management range.
[0032] Preferably, the audit log module generates access logs according to access requests and stores them on a tamper-proof blockchain to form an audit trail, including:
[0033] Receive access requests from the identity verification module, generate access logs according to the access requests, and store the generated access logs on the blockchain after encryption;
[0034] According to the preset audit rules, the stored access logs are analyzed and audited to generate an audit report.
[0035] Preferably, the access log includes: access request time, entity DID initiating access, access target object, access permission application content and authorization result.
[0036] Compared with the prior art, the application has the beneficial effects that the application constructs a distributed identity platform based on blockchain technology, realizes the decentralized management and tamper-proof storage of entity identity information, generates a unique DID and a key pair in combination with an encryption algorithm, effectively prevents identity information leakage and forgery, and guarantees the underlying security of elevator system access. The intelligent contract module sets and allocates the access permission rules of different entities (elevators, maintenance engineers and supervisors) for elevators and related data, supports differentiated permission management based on qualification levels, management ranges and other dimensions, ensures that each entity can only perform operations within the authorized range, and reduces the risk of exceeding authority. The identity verification protocol using zero-knowledge proof can complete the validity proof without exposing specific identity information when the user performs identity verification, thereby guaranteeing the accuracy of verification and protecting user privacy data to the greatest extent. BRIEF DESCRIPTION OF DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of the provided drawings.
[0038] Figure 1 is a functional block diagram of an elevator digital identity authentication system enabled by a distributed identity platform of the present application. DETAILED DESCRIPTION
[0039] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0040] As shown in Figure 1 , the present application provides an elevator digital identity authentication system enabled by a distributed identity platform, comprising:
[0041] The distributed identity platform is configured to realize entity identity registration, DID allocation, identity verification, permission control and audit log recording functions. The distributed identity platform is constructed based on blockchain technology and composed of multiple nodes.
[0042] The entity identity registration module is arranged in the distributed platform and configured to receive the registration request of the entity and verify the registration information. The entity includes elevators, maintenance engineers and supervisors.
[0043] The DID distribution module is connected with the entity identity registration module, configured to receive the verification pass signal of the entity identity registration module, generate a decentralized identifier for each entity according to an encryption algorithm and a standard, and associate the decentralized identifier with the corresponding public key and the encrypted entity identity information.
[0044] The identity verification module is arranged in the distributed platform and is configured to perform identity verification on the access request of the user based on a zero-knowledge proof identity verification protocol and obtain the access permission of the elevator system.
[0045] The smart contract module is arranged in the distributed platform and is configured to set the access permission rules of different entities for the elevator and related data.
[0046] The audit log module is arranged in the distributed platform and is configured to generate an access log according to the access request and store the access log on a tamper-proof blockchain to form an audit trail.
[0047] The elevator digital identity authentication system provided by the application realizes the integrated management of identity registration, DID distribution, identity verification, permission control and audit log recording of entities such as elevators, maintenance engineers and supervisors through the distributed identity platform. The system uses blockchain technology to build a distributed identity platform, ensuring the security and tamper resistance of data, effectively preventing the forgery and tampering of identity information. At the same time, through the distribution of decentralized identifiers (DID), the uniqueness and anonymity protection of entity identity are realized, improving the efficiency and security of identity authentication. In addition, the identity verification protocol based on zero-knowledge proof can verify the identity of the user without revealing the user's privacy, further enhancing the security of the system. The setting of the smart contract module makes the access permission rules of different entities for the elevator and related data more explicit and automated, improving the management efficiency and convenience of the system. The audit log module can record all access requests and generate tamper-proof access logs, providing strong support for the security audit and traceability of the system. In summary, the application provides an efficient, secure and convenient elevator digital identity authentication system, which has wide application prospect and important social value.
[0048] In some embodiments of the application, if the entity is an elevator, the registration information is: elevator identification number, model, installation location, property or management unit; wherein the elevator identification number is unique and not repeated; if the entity is a maintenance engineer or supervisor, the registration information is: personal identity information, professional qualification certificate number and affiliated unit.
[0049] In some embodiments of the present application, the entity identity registration module receives the registration request of the entity and verifies the registration information, including: the distributed identity platform is connected with a management database, and the management database includes basic information of all entities; after receiving the registration request, the management database is filtered according to the type of the entity, and the registration information is matched with the filtered data, if the matching is successful, it is determined that the registration information verification of the corresponding entity is passed; if the matching is not successful, it is determined that the registration information verification of the corresponding entity is not passed.
[0050] Specifically, the entity identity registration module is configured to receive identity registration requests from various entities and perform strict verification procedures on the registration information submitted by the entities, including the following detailed steps: first, the distributed identity platform establishes a stable and secure connection with a management database through a preset data interface, and the management database serves as an authoritative information source, storing and maintaining the standardized basic information of all legal entities (including individuals, organizations, devices and other types of entities), including but not limited to entity unique identifier, identity attribute characteristics, ownership relationship proof and other core data fields. When the entity identity registration module receives the registration request initiated by the entity, the system will classify and filter the data in the management database based on the type declared by the entity in the registration request (such as elevator, maintenance engineer and supervisor), to narrow the matching range and improve the verification efficiency, and the filtering process will be strictly performed according to the preset entity classification standard and the corresponding database query rule. Subsequently, the system will perform multi-dimensional data matching and verification on the registration information (such as identity identifier, attribute information and other key contents) submitted by the entity and the subset of the management database obtained after filtering, and the matching logic includes field-level accurate comparison, cross-verification of associated information and other methods, to ensure the authenticity and consistency of the registration information. If the registration information and the data record of a certain entity in the management database after filtering are completely matched or meet the preset fault-tolerant matching rule in all key verification dimensions, the system automatically determines that the registration information verification of the corresponding entity is passed, and generates a feedback of the verification passed result; otherwise, if the registration information and the data record after filtering are found to be mismatched, missing or conflicted in key information during the matching process, and cannot be corrected by the fault-tolerant mechanism, the system determines that the registration information verification of the corresponding entity is not passed, and can further return the specific verification failure reason, so that the entity can check and resubmit the information.
[0051] It can be understood that through the connection with the management database and the screening matching process, the system can automatically and accurately verify the registration information of the entity, greatly improving the registration efficiency and accuracy. This design not only reduces the cumbersome manual review, but also avoids the problem of inaccurate registration information caused by human error. At the same time, for entities whose registration information verification fails, the system can give feedback in time, requiring resubmission or supplement of relevant information, ensuring the completeness and authenticity of the registration information.
[0052] In some embodiments of the present application, the DID allocation module generates a decentralized identifier for each entity according to an encryption algorithm and standard, and associates the decentralized identifier with the corresponding public key and the encrypted entity identity information, including: extracting key metadata from the registration information as the basis for DID generation; SHA-256 digest of key metadata to form a fixed-length base vector, generate a high-strength random salt value, and introduce a nanosecond timestamp as a variable factor to obtain a decentralized identifier, wherein the decentralized identifier has uniqueness; generate a key pair through an encryption algorithm, encrypt the entity identity information through the private key; associate the public key with the decentralized identifier and send it to the distributed identity platform, and send the private key to the entity.
[0053] Specifically, the DID allocation module, as the core component of the distributed identity system, is responsible for generating a decentralized identifier (DID) for each independent entity accessing the system in a secure and unique manner according to the preset encryption algorithm standard and specification process. Its core function is not only to generate this DID, but also to securely and reliably associate and distribute the DID with the corresponding entity's public key and the encrypted entity identity information. The specific implementation process is as follows:
[0054] First, the module starts the information extraction and preprocessing step. It will accurately screen and extract key metadata for DID generation from the registration information submitted by the entity. These metadata usually cover the unique feature information of the entity, registration context information, etc., which together constitute the basic input data set for DID generation, ensuring the essential association between DID and entity identity.
[0055] Secondly, the core generation phase of DID is entered. The module performs SHA-256 cryptographic hash function operation on the key metadata extracted above to generate a fixed-length (256-bit) hash digest. This digest serves as the basis vector for generating DID, ensuring the consistency and tamper resistance of the input data. To further enhance the uniqueness and security of DID, the module generates a high-strength random salt value (Salt) and combines it with the basis vector. At the same time, to deal with potential metadata conflicts or replay attacks, the module introduces a nanosecond-precision current timestamp as a dynamic variable factor into the DID generation process. Through the above multi-element mixed calculation and specific algorithm processing, a globally unique decentralized identifier (DID) is finally generated, ensuring that there is no duplication in the entire distributed network.
[0056] Next, key pair generation and entity identity information encryption are performed. The module generates a pair of unique corresponding keys, i.e., public key and private key, for the entity using a specified asymmetric encryption algorithm (such as RSA, ECDSA, or Ed25519, etc.). Then, the generated private key is used to encrypt the entity's detailed identity information (which may include more sensitive or detailed attributes in addition to key metadata), forming encrypted entity identity information, thereby ensuring the confidentiality of entity identity data during storage and transmission.
[0057] Finally, the association information distribution and storage are completed. The module binds the generated public key to the previously created decentralized identifier (DID) to form the core content of the DID document, and sends this association information (usually including DID, public key, and possibly other verification information) to the distributed identity platform (such as a blockchain network or distributed ledger) for registration and notarization, ensuring its public availability and tamper resistance. At the same time, the private key used to decrypt the entity's identity information is sent to the entity itself through a secure and trusted channel for proper storage, making it the only credential for the entity to control and prove its identity.
[0058] It can be understood that by generating a unique decentralized identifier (DID) for each entity and associating it with the public key and encrypted entity identity information, the system realizes the decentralized management and protection of entity identity information. This design not only enhances data security, but also improves data processing efficiency. The uniqueness of the decentralized identifier ensures the accuracy of the entity's identity, avoiding the risk of identity confusion or impersonation. At the same time, through the generation of key pairs by encryption algorithms, the system can ensure the confidentiality and integrity of entity identity information during transmission and storage. In addition, the association of public keys with decentralized identifiers and the sending of private keys to entities ensures the traceability of information while taking into account the privacy protection needs of entities.
[0059] In some embodiments of the present application, the identity verification module verifies the access request of the user based on the identity verification protocol of zero-knowledge proof, and obtains the access permission of the elevator system, comprising: when the user needs to perform maintenance operation on the elevator, an access request is sent to the elevator system, the access request comprising a decentralized identifier and identity verification information of the user; the public key is obtained from the distributed identity platform according to the decentralized identifier of the user, and the identity verification information is verified using the zero-knowledge proof protocol to determine whether the decentralized identifier of the user is valid; if the verification is passed, the elevator system grants the user corresponding access permission of the elevator system, allowing the user to perform maintenance operation.
[0060] Specifically, the identity authentication module is specifically configured to perform a multi-step identity authentication process on the access request initiated by the user based on a zero-knowledge proof (ZKP) identity authentication protocol, and to grant the user corresponding elevator system access rights after verification, and the specific implementation includes: when the user needs to perform a planned maintenance, troubleshooting, parameter debugging or emergency repair on the target elevator equipment, the user first sends a structured access request to the access control unit of the elevator system through an authorized client (such as a dedicated maintenance terminal, a mobile application or a smart device integrated with an identity module), which encapsulates a unique decentralized identifier (DID) of the user in the access request - this identifier is pre-registered on a distributed identity management platform and is bound to the user's real identity and maintenance qualification information, and identity authentication information generated by the user end according to the preset rules, which usually includes user private key signed timestamp, request operation type identification and random challenge value, etc. Dynamic data to ensure the timeliness of the request and anti-replay attack capability; the identity authentication module of the elevator system first parses the user's decentralized identifier after receiving the access request, and initiates a query request to the trusted distributed identity platform based on the identifier through a secure communication channel (such as HTTPS encrypted connection or blockchain node communication protocol) to obtain the public key certificate and related identity metadata (such as certificate validity period, issuing authority, etc.) corresponding to the user DID; then, the identity authentication module calls the zero-knowledge proof verification algorithm to verify the identity authentication information provided by the user based on the public key obtained from the distributed identity platform, and performs a zero-knowledge proof verification process, in which the verifier (elevator system) does not need to know the specific private key information or other sensitive identity details of the user, but only needs to verify whether the user can correctly prove that it owns the private key bound to the DID and its identity meets the preset access control strategy (such as having maintenance qualification for a specific elevator model, being authorized within the validity period, etc.), to determine the validity of the decentralized identifier provided by the user and the authenticity and authorization legality of the user's identity; if the zero-knowledge proof protocol verification confirms that the user's decentralized identifier is real and effective and the user's identity meets the authorization requirements of the elevator maintenance operation, the access control unit of the elevator system will dynamically grant the user the elevator system access rights matching the type of this maintenance operation and the user's qualification according to the preset permission matrix, which may include but is not limited to reading elevator operation logs, modifying specific maintenance parameters, controlling elevator to enter maintenance mode, operating in-car function buttons, etc., and the permission token is issued to the user client through a secure session mechanism, allowing the user to perform corresponding maintenance operations within the specified permission range and within the effective time, while the elevator system logs the entire authorization process and subsequent operation behavior for audit and traceability.
[0061] It can be understood that by introducing the identity authentication protocol of zero-knowledge proof, the system can verify the validity of the decentralized identifier of the user without revealing the specific identity information of the user. This mechanism not only protects the privacy of the user, but also ensures that only legitimate users can obtain access to the elevator system. In addition, the efficiency and security of the zero-knowledge proof protocol make the identity authentication process more rapid and reliable, improving the overall performance and user experience of the system.
[0062] In some embodiments of the present application, the smart contract module sets access permission rules for different entities for the elevator and related data, including: obtaining the operation requirements and safety policies of the elevator system, generating access permission rules according to the operation requirements and safety policies, the access permission rules including: elevator information viewing, operation state monitoring, fault alarm and maintenance operation requirements; and distributing the access permission rules according to the types of entities.
[0063] In particular, the smart contract module assumes the core function of permission management, and its key role is to set a set of refined, dynamic and safe and reliable access permission rule system for different entities in the elevator system ecosystem. The process covers the following key links: first, the smart contract module actively acquires and deeply analyzes the inherent operation requirements of the elevator system itself, such as the use frequency, load capacity, scheduling priority, service period of the elevator, and comprehensively considers and incorporates relevant safety strategies, which may involve data encryption standards, operation audit requirements, emergency response mechanisms, personnel qualification certification specifications, and safety threshold settings in line with industry regulations. On this basis, the smart contract module uses pre-set algorithms and logic to automatically generate a structured access permission rule by integrating the parameters of operation requirements and safety strategies. The access permission rule can be refined into multiple dimensions of operation authorization, at least including: viewing permission of elevator basic information (such as model, date of manufacture, technical parameters, etc.), monitoring permission of real-time operation status of the elevator (such as current floor, running direction, speed, load, working condition of each component, etc.), fault alarm information receiving and viewing permission when the elevator fails or abnormally (such as being trapped, abnormal noise, component failure warning, etc.), and execution permission and corresponding operation specification requirements for planned maintenance, fault elimination, component replacement, firmware upgrade, and other maintenance operations on the elevator. Subsequently, the smart contract module will allocate the access permission rule generated above accurately and differently according to the specific types or pre-set role division of entities in the system (for example, elevator manufacturers, property management companies, maintenance service providers, regulatory agencies, ordinary passengers, system administrators, etc.), according to their responsibilities in the elevator life cycle, the functions they need to complete, and the corresponding safety levels, to ensure that each entity can only access and operate the elevator and related data within the scope of its authorization, thereby realizing the minimum and controllable management of permissions, effectively protecting the safe and stable operation of the elevator system and data privacy protection.
[0064] It can be understood that by automatically setting and allocating access permission rules through the smart contract module, the complexity of permission management is greatly simplified, and the management efficiency is improved. At the same time, the access permission rule is generated according to the actual operation requirements and safety strategies of the elevator system, ensuring the rationality and pertinence of the permission.
[0065] In some embodiments of the present application, the allocation of access permission rules according to the types of entities includes: when the entity is a maintenance engineer, the qualification level of the maintenance engineer is acquired, and different maintenance operation requirements are allocated according to the qualification level; when the entity is a supervisor, the management range of the supervisor is acquired, and the access permission rules of the elevators within the management range are allocated based on the management range.
[0066] In some embodiments of the present application, the audit log module generates an access log according to an access request and stores it on a tamper-proof blockchain to form an audit trail, including: receiving an access request from an identity verification module, generating an access log according to the access request, and storing the generated access log on the blockchain after encryption; according to a preset audit rule, analyzing and auditing the stored access log to generate an audit report. The access log includes: access request time, entity DID initiating access, access target object, access permission application content and authorization result.
[0067] In particular, the audit log module is configured to automatically generate detailed access logs based on various types of access requests generated within the system, and reliably store them in a blockchain distributed ledger system with tamper-proof characteristics, thereby building a complete, traceable and irrefutable audit trail. The specific implementation process includes the following steps: first, the audit log module receives the access request forwarded by the identity verification module after completing the identity verification of the access subject, which contains the authenticated subject information and the intended operation. Then, the audit log module extracts key information from the received access request according to the preset log generation specification, and supplements the necessary context data to generate structured access log records. To ensure the confidentiality and integrity of log data during storage and transmission, the generated access log will first be encrypted by an encryption algorithm (such as asymmetric encryption or symmetric encryption combined with a hash algorithm), then packaged into a blockchain transaction, submitted to the blockchain network through a consensus mechanism, and finally permanently recorded on the blockchain, achieving tamper-proof storage. In addition, the audit log module will also regularly or in real-time search, filter, correlate, analyze and deeply audit the historical and real-time access logs stored on the blockchain according to the diversified audit rules pre-configured by the system administrator (such as abnormal access behavior identification rules, permission abuse detection rules, operation compliance verification rules, etc.). By comparing access behavior patterns, marking sensitive operations, and tracking permission changes, the audit log module can identify potential security risks, violations or suspicious behavior, and based on the analysis results, automatically generate comprehensive audit reports containing audit summaries, abnormal event details, compliance assessments, risk levels and recommended measures, etc. for administrators to review and follow-up. Among them, the access log specifically includes the following core elements: an access request timestamp accurate to the millisecond, which records the exact time of the access behavior; a decentralized identifier (DID) corresponding to the entity initiating the access, which uniquely identifies the identity of the access subject, ensuring the verifiability and decentralized management of the identity; a clear access target object, such as a specific file path, database table name, API interface name or specific system resource identifier; detailed access permission application content, including the requested operation type (such as read, write, modify, delete, execute, etc.) and the specific permission range applied; and the authorization result returned by the authorization decision module, which clearly indicates whether this access request is allowed, denied, or requires further multi-factor authentication.
[0068] It can be understood that by storing access logs on a tamper-proof blockchain, the authenticity and integrity of the logs are ensured, providing a reliable data foundation for the security audit of the elevator system. This approach not only enhances the transparency and traceability of the system, but also helps to timely detect and trace any unauthorized access behavior, thereby further consolidating the security of the system.
[0069] Those skilled in the art will appreciate that embodiments of the application can be supplied as a method, a system or a computer program product. Accordingly, the application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the application can be embodied in the form of a computer program product on one or more computer readable storage media (including, but not limited to, disk memory, CD-ROMs, optical storage media, etc.) embodying computer readable program code.
[0070] The present application is described in reference to the flowchart and / or block diagrams of the method, apparatus (system) and computer program product according to embodiments of the application. It should be understood that each flow and / or block in the flowchart and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, a special purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions, which are executed via the processor of the computer or other programmable data processing device, generate a means for implementing the functions specified in the flowchart and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for functionally implementing the
[0071] These computer program instructions can also be stored in a computer readable storage medium that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable storage medium produce a product including an instruction means, which implements the functions specified in the flowchart and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for functionally implementing the
[0072] These computer program instructions can also be loaded into a computer or other programmable data processing device, so that a series of operational steps are performed on the computer or other programmable data processing device to generate a computer implemented process, so that the instructions executed on the computer or other programmable device provide a process for implementing the functions specified in the flowchart and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 means for functionally implementing the
[0073] Finally, it should be noted that the above embodiments are merely intended to illustrate the technical solutions of the present application, but not to limit it. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that the specific embodiments of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.
Claims
1. An elevator digital identity authentication system powered by a distributed identity platform, characterized in that, include: The distributed identity platform is configured to implement entity identity registration, DID allocation, identity verification, access control, and audit log recording functions. The distributed identity platform is built on blockchain technology and consists of multiple nodes. An entity identity registration module, located within the distributed platform, is configured to receive registration requests from entities and verify the registration information. These entities include elevators, maintenance engineers, and supervisors. The DID allocation module, connected to the entity identity registration module, is configured to receive the verification pass signal from the entity identity registration module, generate a decentralized identifier for each entity according to the encryption algorithm and standard, and associate the decentralized identifier with the corresponding public key and the encrypted entity identity information. An authentication module, located within the distributed platform, is configured to use a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions. The smart contract module, set up within the distributed platform, is configured to set access permission rules for different entities regarding elevators and related data; The audit log module, located within the distributed platform, is configured to generate access logs based on access requests and store them on an immutable blockchain, thus forming an audit trail.
2. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, If the entity is an elevator, the registration information includes: elevator identification number, model, installation location, and property or management unit; wherein, the elevator identification number is unique and non-repeating; If the entity is a maintenance engineer or supervisor, the registration information includes: personal identity information, professional qualification certificate number, and affiliated unit.
3. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, The entity identity registration module receives registration requests from entities and verifies the registration information, including: The distributed identity platform is connected to a management database, which includes basic information about all entities. Upon receiving a registration request, the management database is filtered according to the type of entity, and the registration information is matched with the filtered data. If the match is successful, the registration information of the corresponding entity is verified. If the match fails, it indicates that the registration information of the corresponding entity has failed verification.
4. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, The DID allocation module generates a decentralized identifier for each entity based on encryption algorithms and standards, and associates the decentralized identifier with the corresponding public key and encrypted entity identity information, including: Extract key metadata from registration information as the basic input for DID generation; The key metadata is digested using SHA-256 to form a fixed-length basic vector. A high-intensity random salt value is generated, and a nanosecond-level timestamp is introduced as a variable factor to obtain a decentralized identifier, wherein the decentralized identifier is unique. A key pair is generated using an encryption algorithm, and the entity's identity information is encrypted using the private key. The public key is associated with the decentralized identifier and sent to the distributed identity platform, while the private key is sent to the entity.
5. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, The authentication module uses a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions, including: When a user needs to perform maintenance operations on the elevator, they send an access request to the elevator system. The access request includes the user's decentralized identifier and authentication information. The public key is obtained from the distributed identity platform based on the user's decentralized identifier, and the verification information is verified using a zero-knowledge proof protocol to determine whether the user's decentralized identifier is valid. If the verification is successful, the elevator system will grant the user the corresponding elevator system access permission, allowing the user to perform maintenance operations.
6. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, The smart contract module sets access rules for different entities regarding elevators and related data, including: Obtain the elevator system's operational requirements and safety policies, and generate access permission rules based on these requirements and policies. These access permission rules include: elevator information viewing, operational status monitoring, fault alarms, and maintenance operation requirements. Access permission rules are assigned based on the type of entity.
7. The elevator digital identity authentication system powered by the distributed identity platform according to claim 6, characterized in that, Access permission rules are assigned based on the type of entity, including: When the entity is a maintenance engineer, obtain the maintenance engineer's qualification level and assign different maintenance operation requirements according to the qualification level; When the entity is a supervisor, obtain the supervisor's management scope and assign access permission rules for elevators within the management scope based on the management scope.
8. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, The audit log module generates access logs based on access requests and stores them on an immutable blockchain, forming an audit trail, including: Receive access requests from the authentication module, generate access logs based on the access requests, and encrypt and store the generated access logs on the blockchain; Based on preset audit rules, the stored access logs are analyzed and audited, and an audit report is generated.
9. The elevator digital identity authentication system powered by the distributed identity platform according to claim 8, characterized in that, The access log includes: access request time, entity DID that initiated the access, target object, access permission request content, and authorization result.
Citation Information
Patent Citations
Elevator data management method
CN106276457A
Elevator permission safety control system
CN109809262A
Elevator equipment monitoring method and system based on block chain, terminal and medium
CN119117845A
Effective supervision dimension can be realized and intelligent elevator of elevator is protected and use in violation of rules and regulations
CN206940146U