An elevator digital identity authentication system empowered by a distributed identity platform
By using a distributed identity platform and blockchain technology, an elevator digital identity authentication system has been built, which solves the problems of security risks and low efficiency in traditional elevator identity authentication. It achieves efficient and secure entity identity management and access control, ensuring the security of the elevator system and user privacy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANDONG TIWANG INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2025-08-06
- Publication Date
- 2026-07-31
AI Technical Summary
In the traditional elevator maintenance and supervision model, poor management of physical identity information, security risks and inefficiency in identity authentication methods, and insufficient precision in access control lead to increased security vulnerabilities and accident risks during elevator operation and maintenance.
A distributed identity platform is adopted, and an elevator digital identity authentication system is built based on blockchain technology to realize entity identity registration, DID allocation, identity verification, access control and audit log recording. Unique DID and key pairs are generated using encryption algorithms, combined with a zero-knowledge proof identity verification protocol, and a smart contract module is set up for access management. Access logs are stored on an immutable blockchain.
It achieves decentralized management and tamper-proof storage of entity identities, prevents identity information leakage and forgery, ensures the underlying security of elevator system access, supports differentiated permission management, reduces the risk of unauthorized access, improves the efficiency and security of identity authentication, and ensures user privacy protection.
Smart Images

Figure CN120964546B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity authentication technology, and in particular to an elevator digital identity authentication system enabled by a distributed identity platform. Background Technology
[0002] With the acceleration of urbanization, the number of elevators has increased dramatically, and their safety has become a growing concern. Traditional elevator maintenance and supervision models have many drawbacks, such as poor management of elevator entity identity information, security risks and inefficiencies in the authentication methods for maintenance engineers and supervisors, insufficiently granular access control, and difficulties in auditing and tracing. These problems lead to security vulnerabilities in elevator operation and maintenance, increasing the risk of elevator malfunctions and safety accidents. Therefore, there is an urgent need for a more efficient, secure, and traceable elevator digital identity authentication system and method. Summary of the Invention
[0003] The purpose of this invention is to provide an elevator digital identity authentication system powered by a distributed identity platform, which aims to solve the above-mentioned problems.
[0004] This invention provides an elevator digital identity authentication system powered by a distributed identity platform, comprising:
[0005] The distributed identity platform is configured to implement entity identity registration, DID allocation, identity verification, access control, and audit log recording functions. The distributed identity platform is built on blockchain technology and consists of multiple nodes.
[0006] An entity identity registration module, located within the distributed platform, is configured to receive registration requests from entities and verify the registration information. These entities include elevators, maintenance engineers, and supervisors.
[0007] The DID allocation module, connected to the entity identity registration module, is configured to receive the verification pass signal from the entity identity registration module, generate a decentralized identifier for each entity according to the encryption algorithm and standard, and associate the decentralized identifier with the corresponding public key and the encrypted entity identity information.
[0008] An authentication module, located within the distributed platform, is configured to use a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions.
[0009] The smart contract module, set up within the distributed platform, is configured to set access permission rules for different entities regarding elevators and related data;
[0010] The audit log module, located within the distributed platform, is configured to generate access logs based on access requests and store them on an immutable blockchain, thus forming an audit trail.
[0011] Preferably, if the entity is an elevator, the registration information includes: elevator identification number, model, installation location, and property or management unit; wherein, the elevator identification number is unique and non-repeating;
[0012] If the entity is a maintenance engineer or supervisor, the registration information includes: personal identity information, professional qualification certificate number, and affiliated unit.
[0013] Preferably, the entity identity registration module receives the entity's registration request and verifies the registration information, including:
[0014] The distributed identity platform is connected to a management database, which includes basic information about all entities.
[0015] Upon receiving a registration request, the management database is filtered according to the type of entity, and the registration information is matched with the filtered data. If the match is successful, the registration information of the corresponding entity is verified.
[0016] If the match fails, it indicates that the registration information of the corresponding entity has failed verification.
[0017] Preferably, the DID allocation module generates a decentralized identifier for each entity based on the encryption algorithm and standard, and associates the decentralized identifier with the corresponding public key and the encrypted entity identity information, including:
[0018] Extract key metadata from registration information as the basic input for DID generation;
[0019] The key metadata is digested using SHA-256 to form a fixed-length basic vector. A high-intensity random salt value is generated, and a nanosecond-level timestamp is introduced as a variable factor to obtain a decentralized identifier, wherein the decentralized identifier is unique.
[0020] A key pair is generated using an encryption algorithm, and the entity's identity information is encrypted using the private key.
[0021] The public key is associated with the decentralized identifier and sent to the distributed identity platform, while the private key is sent to the entity.
[0022] Preferably, the authentication module uses a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions, including:
[0023] When a user needs to perform maintenance operations on the elevator, they send an access request to the elevator system. The access request includes the user's decentralized identifier and authentication information.
[0024] The public key is obtained from the distributed identity platform based on the user's decentralized identifier, and the verification information is verified using a zero-knowledge proof protocol to determine whether the user's decentralized identifier is valid.
[0025] If the verification is successful, the elevator system will grant the user the corresponding elevator system access permission, allowing the user to perform maintenance operations.
[0026] Preferably, the smart contract module sets access rules for different entities regarding elevators and related data, including:
[0027] Obtain the elevator system's operational requirements and safety policies, and generate access permission rules based on these requirements and policies. These access permission rules include: elevator information viewing, operational status monitoring, fault alarms, and maintenance operation requirements.
[0028] Access permission rules are assigned based on the type of entity.
[0029] Preferably, access permission rules are assigned based on the type of entity, including:
[0030] When the entity is a maintenance engineer, obtain the maintenance engineer's qualification level and assign different maintenance operation requirements according to the qualification level;
[0031] When the entity is a supervisor, obtain the supervisor's management scope and assign access permission rules for elevators within the management scope based on the management scope.
[0032] Preferably, the audit log module generates access logs based on access requests and stores them on an immutable blockchain to form an audit trail, including:
[0033] Receive access requests from the authentication module, generate access logs based on the access requests, and encrypt and store the generated access logs on the blockchain;
[0034] Based on preset audit rules, the stored access logs are analyzed and audited, and an audit report is generated.
[0035] Preferably, the access log includes: access request time, entity DID initiating access, target object accessed, access permission request content, and authorization result.
[0036] Compared with existing technologies, the advantages of this invention are as follows: This application constructs a distributed identity platform based on blockchain technology, realizing decentralized management and tamper-proof storage of entity identity information. Combined with encryption algorithms to generate unique DID and key pairs, it effectively prevents identity information leakage and forgery, ensuring the underlying security of elevator system access. Through a smart contract module, access permission rules for elevators and related data are set and assigned to different entities (elevator, maintenance engineer, supervisor), supporting differentiated permission management based on qualification level, management scope, and other dimensions, ensuring that each entity can only perform operations within its authorized scope, reducing the risk of unauthorized access. Employing a zero-knowledge proof authentication protocol, users can complete validity verification without exposing specific identity information, ensuring verification accuracy while maximizing the protection of user privacy data. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0038] Figure 1 This is a functional block diagram of an elevator digital identity authentication system powered by a distributed identity platform, as described in this invention. Detailed Implementation
[0039] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0040] like Figure 1 As shown, this invention provides an elevator digital identity authentication system powered by a distributed identity platform, comprising:
[0041] The distributed identity platform is configured to implement entity identity registration, DID allocation, identity verification, access control and audit log recording functions. The distributed identity platform is built on blockchain technology and consists of multiple nodes.
[0042] The entity identity registration module, located within the distributed platform, is configured to receive registration requests from entities and verify the registration information. These entities include elevators, maintenance engineers, and supervisors.
[0043] The DID allocation module, connected to the entity identity registration module, is configured to receive the verification pass signal from the entity identity registration module, generate a decentralized identifier for each entity according to the encryption algorithm and standard, and associate the decentralized identifier with the corresponding public key and the encrypted entity identity information.
[0044] An authentication module, located within the distributed platform, is configured to use a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions.
[0045] The smart contract module, located within the distributed platform, is configured to set access permission rules for different entities regarding elevators and related data.
[0046] The audit log module, located within the distributed platform, is configured to generate access logs based on access requests and store them on an immutable blockchain, thus forming an audit trail.
[0047] This invention, through a distributed identity platform, achieves integrated management of identity registration, DID allocation, authentication, access control, and audit log recording for entities such as elevators, maintenance engineers, and supervisors. The system utilizes blockchain technology to construct a distributed identity platform, ensuring data security and immutability, effectively preventing the forgery and tampering of identity information. Simultaneously, the allocation of decentralized identifiers (DIDs) protects the uniqueness and anonymity of entity identities, improving the efficiency and security of identity authentication. Furthermore, the zero-knowledge proof-based authentication protocol enables user authentication without compromising user privacy, further enhancing system security. The smart contract module clarifies and automates access rules for different entities regarding elevators and related data, improving system management efficiency and convenience. The audit log module records all access requests, generating immutable access logs, providing strong support for system security auditing and traceability. In summary, this invention provides an efficient, secure, and convenient elevator digital identity authentication system with broad application prospects and significant social value.
[0048] In some embodiments of this application, if the entity is an elevator, the registration information includes: elevator identification number, model, installation location, and property or management unit; wherein the elevator identification number is unique and non-repeating; if the entity is a maintenance engineer or supervisor, the registration information includes: personal identity information, professional qualification certificate number, and affiliated unit.
[0049] In some embodiments of this application, the entity identity registration module receives a registration request from an entity and verifies the registration information, including: the distributed identity platform is connected to a management database, the management database including basic information of all entities; after receiving the registration request, the management database is filtered according to the type of entity, and the registration information is matched with the filtered data; if the match is successful, the registration information of the corresponding entity is determined to have passed verification; if the match is unsuccessful, the registration information of the corresponding entity is determined to have failed verification.
[0050] Specifically, the entity identity registration module is configured to receive identity registration requests from various entities and execute a rigorous verification process on the registration information submitted by the entities. This process includes the following detailed steps: First, the distributed identity platform establishes a stable and secure connection with the management database through a pre-defined data interface. This management database, as an authoritative information source, stores and maintains standardized basic information for all legitimate entities (covering individuals, organizations, devices, and other types). This information includes, but is not limited to, core data fields such as unique entity identifiers, identity attribute characteristics, and ownership proofs. When the entity identity registration module receives a registration request from an entity, the system will classify and filter the data in the management database based on the type declared by the entity in the registration request (e.g., elevator, maintenance engineer, and supervisor) to narrow the matching range and improve verification efficiency. The filtering process will strictly adhere to the pre-defined entity classification standards and corresponding database query rules. Subsequently, the system will perform multi-dimensional data matching and verification between the registration information submitted by the entity (such as identity identifiers, attribute information, and other key content) and the filtered subset of the management database. The matching logic includes precise field-level comparison and cross-validation of related information to ensure the authenticity and consistency of the registration information. If the registration information and the data record of a certain entity selected from the management database achieve a complete match across all key verification dimensions or comply with the preset fault-tolerant matching rules, the system automatically determines that the registration information of the corresponding entity has passed verification and generates a verification result feedback. Conversely, if during the matching process, it is found that there are key information mismatches, missing or conflicting information between the registration information and the data record selected from the management database, and this cannot be corrected through the fault-tolerant mechanism, the system determines that the registration information of the corresponding entity has failed verification and can further return the specific reason for the verification failure so that the entity can verify the information and resubmit.
[0051] Understandably, through its connection to and filtering of the management database, the system can automatically and accurately verify entity registration information, significantly improving registration efficiency and accuracy. This design not only reduces the tediousness of manual review but also avoids inaccurate registration information due to human error. Furthermore, for entities whose registration information fails verification, the system provides timely feedback, requiring resubmission or supplementation of relevant information, ensuring the completeness and authenticity of the registration information.
[0052] In some embodiments of this application, the DID allocation module generates a decentralized identifier for each entity according to encryption algorithms and standards, and associates the decentralized identifier with the corresponding public key and encrypted entity identity information, including: extracting key metadata from registration information as the basic input for DID generation; performing SHA-256 digest on the key metadata to form a fixed-length base vector, generating a high-strength random salt value, and introducing a nanosecond-level timestamp as a variable factor to obtain a decentralized identifier, wherein the decentralized identifier is unique; generating a key pair through an encryption algorithm, encrypting the entity identity information with the private key; associating the public key with the decentralized identifier and sending it to the distributed identity platform, and sending the private key to the entity.
[0053] Specifically, the DID allocation module, as a core component of the distributed identity system, is responsible for securely and uniquely generating a decentralized identifier (DID) for each independent entity accessing the system, based on preset encryption algorithm standards and procedures. Its core function is not only to generate this DID, but also to securely and reliably associate and distribute the DID with the corresponding entity's public key and encrypted entity identity information. The specific implementation process is as follows:
[0054] First, the module initiates the information extraction and preprocessing steps. It precisely filters and extracts key metadata for DID generation from the registration information submitted by the entity. This metadata typically covers the entity's unique characteristic information, registration context information, etc., which together constitute the basic input dataset for DID generation, ensuring the essential correlation between the DID and the entity's identity.
[0055] Next, the core generation stage of the DID begins. The module performs a SHA-256 cryptographic hash function operation on the extracted key metadata, generating a fixed-length (256-bit) hash digest. This digest serves as the base vector for generating the DID, ensuring the consistency and tamper resistance of the input data. To further enhance the uniqueness and security of the DID, the module generates a high-strength random salt value and combines it with the base vector. Simultaneously, to address potential metadata conflicts or replay attacks, the module introduces a nanosecond-precision current timestamp as a dynamically variable factor, incorporated into the DID generation process. Through the above multi-element hybrid calculations and specific algorithm processing, a globally unique decentralized identifier (DID) is finally generated, ensuring that there are no duplicates throughout the distributed network.
[0056] Next, key pair generation and entity identity information encryption are performed. The module uses a specified asymmetric encryption algorithm (such as RSA, ECDSA, or Ed25519) to generate a unique pair of keys for the entity, namely a public key and a private key. Subsequently, the generated private key is used to encrypt the entity's detailed identity information (which may contain more sensitive or detailed attributes in addition to key metadata), forming the encrypted entity identity information, thereby ensuring the confidentiality of the entity identity data during storage and transmission.
[0057] Finally, the module completes the distribution and storage of associated information. It binds the generated public key to the previously created decentralized identifier (DID), forming the core content of the DID document. This association information (typically including the DID, public key, and possibly other verification information) is then sent to a distributed identity platform (such as a blockchain network or distributed ledger) for registration and notarization, ensuring its public verifiability and immutability. Simultaneously, the private key used to decrypt the entity's identity information is sent securely and reliably to the entity for safekeeping, making it the entity's sole credential for controlling and proving its identity.
[0058] Understandably, by generating a unique decentralized identifier (DID) for each entity and associating it with a public key and encrypted entity identity information, the system achieves decentralized management and protection of entity identity information. This design not only enhances data security but also improves data processing efficiency. The uniqueness of the decentralized identifier ensures the accuracy of the entity's identity, avoiding the risk of identity confusion or impersonation. Simultaneously, the key pair generated through the encryption algorithm ensures the confidentiality and integrity of the entity's identity information during transmission and storage. Furthermore, the process of associating the public key with the decentralized identifier and sending it to the distributed identity platform, while sending the private key to the entity, guarantees both information traceability and the entity's privacy protection needs.
[0059] In some embodiments of this application, the authentication module authenticates user access requests and obtains elevator system access permissions based on a zero-knowledge proof authentication protocol. This includes: when a user needs to perform maintenance operations on the elevator, sending an access request to the elevator system, the access request including the user's decentralized identifier and authentication information; obtaining a public key from a distributed identity platform based on the user's decentralized identifier, and verifying the authentication information using a zero-knowledge proof protocol to determine whether the user's decentralized identifier is valid; if the verification passes, the elevator system grants the user the corresponding elevator system access permissions, allowing the user to perform maintenance operations.
[0060] Specifically, the authentication module is configured to use a zero-knowledge proof (ZKP) authentication protocol. It performs a multi-step authentication process on user-initiated access requests and grants the corresponding elevator system access permissions upon successful authentication. The implementation involves the following steps: When a user needs to perform planned maintenance, troubleshooting, parameter adjustment, or emergency repairs on the target elevator equipment, the user first sends a structured access request to the elevator system's access control unit through an authorized client (such as a dedicated maintenance terminal, mobile application, or smart device with an integrated identity module). This access request encapsulates the user's unique decentralized identifier (DID). The identifier is pre-registered on the distributed identity management platform and bound to the user's real identity and maintenance qualification information, as well as identity verification information generated by the user's client according to preset rules. This verification information typically includes dynamic data such as the timestamp of the user's private key signature, the request operation type identifier, and a random challenge value to ensure the timeliness of the request and the ability to prevent replay attacks. After receiving the access request, the elevator system's identity verification module first parses out the user's decentralized identifier and, based on this identifier, initiates a query request to the trusted distributed identity platform through a secure communication channel (such as an HTTPS encrypted connection or a blockchain node communication protocol) to obtain the public key certificate corresponding to the user's DID and related identity metadata (such as certificate certificate, DID ... The system verifies the validity period of the document, the issuing authority, etc.; subsequently, the identity verification module calls a zero-knowledge proof verification algorithm, using the public key obtained from the distributed identity platform as the verification basis, to perform a zero-knowledge proof verification process on the identity verification information provided by the user. During this process, the verifier (elevator system) does not need to know the user's specific private key information or other sensitive identity details. It only needs to verify whether the user can correctly prove that they have the private key bound to the DID and that their identity meets the preset access control policy (such as having maintenance qualifications for a specific elevator model, authorization within the validity period, etc.) to determine the validity of the decentralized identifier provided by the user and the authenticity and legality of the user's identity; if the zero-knowledge proof protocol is used... Once the user's decentralized identifier is verified to be genuine and valid, and the user's identity meets the authorization requirements for elevator maintenance operations, the elevator system's access control unit will dynamically grant the user elevator system access permissions that match the type of maintenance operation and the user's qualifications based on a preset permission matrix. These permissions may include, but are not limited to, reading elevator operation logs, modifying specific maintenance parameters, controlling the elevator to enter inspection mode, and operating function buttons inside the car. The permission token will be sent to the user's client through a secure session mechanism, allowing the user to perform the corresponding maintenance operations within the specified permission scope and valid time. At the same time, the elevator system will log the entire authorization process and subsequent operations for auditing and traceability.
[0061] Understandably, by introducing a zero-knowledge proof-based authentication protocol, the system can verify the validity of a user's decentralized identifier without disclosing the user's specific identity information. This mechanism not only protects user privacy but also ensures that only legitimate users can gain access to the elevator system. Furthermore, the efficiency and security of the zero-knowledge proof protocol make the authentication process faster and more reliable, improving the overall system performance and user experience.
[0062] In some embodiments of this application, the smart contract module sets access permission rules for different entities regarding elevators and related data, including: obtaining the elevator system's operational requirements and security policies; generating access permission rules based on the operational requirements and security policies; the access permission rules including: elevator information viewing, operational status monitoring, fault alarms, and maintenance operation requirements; and allocating access permission rules according to the type of entity.
[0063] Specifically, the smart contract module undertakes the core function of access control, its key role being to establish a refined, dynamic, and secure access permission rule system for different entities within the elevator system ecosystem. This process encompasses the following key steps: First, the smart contract module proactively acquires and deeply analyzes the inherent operational requirements of the elevator system itself, such as elevator usage frequency, load capacity, scheduling priority, and service hours. Simultaneously, it comprehensively considers and incorporates relevant security policies, which may involve data encryption standards, operational audit requirements, emergency response mechanisms, personnel qualification certification standards, and security threshold settings that comply with industry regulations. Based on this, the smart contract module utilizes preset algorithms and logic to automatically generate a structured set of access permission rules, integrating the various parameters of operational requirements and security policies. The access permission rules can be further refined into multiple dimensions of operation authorization, including at least: viewing permissions for basic elevator information (such as model, manufacturing date, technical parameters, etc.); monitoring permissions for real-time elevator operation status (such as current floor, direction of travel, speed, load, and operating conditions of various components); receiving and viewing permissions for fault alarm information when the elevator malfunctions or experiences abnormal conditions (such as entrapment, unusual noises, component failure warnings, etc.); and execution permissions and corresponding operational specifications for maintenance operations such as planned maintenance, troubleshooting, component replacement, and firmware upgrades. Subsequently, the smart contract module will accurately and differentiate the generated access permission rules based on the specific types or preset roles of entities within the system (e.g., elevator manufacturers, property management companies, maintenance service providers, regulatory agencies, ordinary passengers, system administrators, etc.), according to their responsibilities, required functions, and corresponding security levels throughout the elevator's lifecycle. This ensures that each entity can only access and operate the elevator and related data within its authorized scope, thereby achieving minimal and controllable permission management and effectively guaranteeing the safe and stable operation of the elevator system and data privacy protection.
[0064] Understandably, the automatic setting and allocation of access permission rules through smart contract modules greatly simplifies the complexity of access control and improves management efficiency. Furthermore, generating access permission rules based on the actual operational needs and security policies of the elevator system ensures the rationality and relevance of permissions.
[0065] In some embodiments of this application, access permission rules are assigned according to the type of entity, including: when the entity is a maintenance engineer, obtaining the qualification level of the maintenance engineer and assigning different maintenance operation requirements according to the qualification level; when the entity is a supervisor, obtaining the supervisor's management scope and assigning access permission rules for elevators within the management scope based on the management scope.
[0066] In some embodiments of this application, the audit log module generates access logs based on access requests and stores them on an immutable blockchain to form an audit trail. This includes: receiving access requests from the authentication module; generating access logs based on the access requests; encrypting the generated access logs and storing them on the blockchain; and analyzing and auditing the stored access logs according to preset audit rules to generate an audit report. The access logs include: access request time, the DID of the entity initiating the access, the target object being accessed, the access permission request content, and the authorization result.
[0067] Specifically, the audit log module is configured to automatically generate detailed access logs based on various access requests generated within the system, and reliably store them in a blockchain distributed ledger system with immutable characteristics, thereby constructing a complete, traceable, and non-repudiable audit trail. The specific implementation process includes the following steps: First, the audit log module receives access requests forwarded by the authentication module after verifying the identity of the accessing entity. This request contains the authenticated entity's information and its intended operation. Next, the audit log module extracts key information from the received access requests according to preset log generation specifications, supplements necessary contextual data, and generates structured access log records. To ensure the confidentiality and integrity of log data during storage and transmission, the generated access logs are first encrypted using an encryption algorithm (such as asymmetric encryption or symmetric encryption combined with a hash algorithm), then packaged into blockchain transactions, and submitted to the blockchain network through a consensus mechanism, ultimately being permanently recorded on the blockchain for immutable storage. Furthermore, the audit log module automatically retrieves, filters, performs correlation analysis, and conducts in-depth audits of historical and real-time access logs stored on the blockchain, periodically or in real-time, based on diverse audit rules pre-configured by the system administrator (such as rules for identifying abnormal access behavior, detecting abuse of privileges, and verifying operational compliance). Through comparison of access behavior patterns, marking of sensitive operations, and tracking of permission changes, the audit log module can identify potential security risks, violations, or suspicious behaviors. Based on the analysis results, it automatically generates a comprehensive audit report including an audit summary, details of abnormal events, compliance assessment, risk level, and recommended actions, facilitating administrator review and subsequent processing. The access log specifically includes the following core elements: a timestamp of the access request accurate to the millisecond level to record the exact moment the access behavior occurred; a decentralized identifier (DID) corresponding to the entity initiating the access, which uniquely identifies the access subject and ensures the verifiability and decentralized management of the identity; a clearly defined target object for access, such as a specific file path, database table name, API interface name, or specific system resource identifier; detailed access permission request content, including the type of operation requested (such as read, write, modify, delete, execute, etc.) and the specific scope of permissions requested; and the authorization result returned by the authorization decision module, which clearly indicates whether the access request is allowed, denied, or requires further multi-factor verification.
[0068] Understandably, storing access logs on an immutable blockchain ensures the authenticity and integrity of the logs, providing a reliable data foundation for the safety audit of the elevator system. This approach not only enhances the system's transparency and traceability but also helps to promptly detect and trace any unauthorized access, thereby further strengthening the system's security.
[0069] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program goods. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program goods embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0070] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program goods according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0071] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0072] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0073] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. An elevator digital identity authentication system powered by a distributed identity platform, characterized in that, include: The distributed identity platform is configured to implement entity identity registration, DID allocation, identity verification, access control, and audit log recording functions. The distributed identity platform is built on blockchain technology and consists of multiple nodes. The entity identity registration module, located within the distributed identity platform, is configured to receive registration requests from entities and verify the registration information. The entities include elevators, maintenance engineers, and supervisors. The DID allocation module, connected to the entity identity registration module, is configured to receive the verification pass signal from the entity identity registration module, generate a decentralized identifier for each entity according to the encryption algorithm and standard, and associate the decentralized identifier with the corresponding public key and the encrypted entity identity information. The authentication module, located within the distributed identity platform, is configured with a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions. The smart contract module, located within the distributed identity platform, is configured to set access permission rules for different entities regarding elevators and related data. The audit log module, located within the distributed identity platform, is configured to generate access logs based on access requests and store them on an immutable blockchain, thus forming an audit trail. The DID allocation module generates a decentralized identifier for each entity based on encryption algorithms and standards, and associates the decentralized identifier with the corresponding public key and encrypted entity identity information, including: Extract key metadata from registration information as the basic input for DID generation; The key metadata is digested using SHA-256 to form a fixed-length basic vector. A high-intensity random salt value is generated, and a nanosecond-level timestamp is introduced as a variable factor to obtain a decentralized identifier, wherein the decentralized identifier is unique. A key pair is generated using an encryption algorithm, and the entity's identity information is encrypted using the private key. The public key is associated with the decentralized identifier and sent to the distributed identity platform, while the private key is sent to the entity. The authentication module uses a zero-knowledge proof-based authentication protocol to authenticate user access requests and obtain elevator system access permissions, including: When a user needs to perform maintenance operations on the elevator, they send an access request to the elevator system. The access request includes the user's decentralized identifier and authentication information. The public key is obtained from the distributed identity platform based on the user's decentralized identifier, and the verification information is verified using a zero-knowledge proof protocol to determine whether the user's decentralized identifier is valid. If the verification is successful, the elevator system will grant the user the corresponding elevator system access permission, allowing the user to perform maintenance operations; The smart contract module sets access rules for different entities regarding elevators and related data, including: Obtain the elevator system's operational requirements and safety policies, and generate access permission rules based on these requirements and policies. These access permission rules include: elevator information viewing, operational status monitoring, and maintenance operation requirements. Access permission rules are assigned based on the type of entity.
2. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, If the entity is an elevator, the registration information includes: elevator identification number, model, installation location, and property or management unit; wherein, the elevator identification number is unique and non-repeating; If the entity is a maintenance engineer or supervisor, the registration information includes: personal identity information, professional qualification certificate number, and affiliated unit.
3. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, The entity identity registration module receives registration requests from entities and verifies the registration information, including: The distributed identity platform is connected to a management database, which includes basic information about all entities. Upon receiving a registration request, the management database is filtered according to the type of entity, and the registration information is matched with the filtered data. If the match is successful, the registration information of the corresponding entity is verified. If the match fails, it indicates that the registration information of the corresponding entity has failed verification.
4. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, Access permission rules are assigned based on the type of entity, including: When the entity is a maintenance engineer, obtain the maintenance engineer's qualification level and assign different maintenance operation permissions according to the qualification level; When the entity is a supervisor, obtain the supervisor's management scope and assign access permission rules for elevators within the management scope based on the management scope.
5. The elevator digital identity authentication system powered by the distributed identity platform according to claim 1, characterized in that, The audit log module generates access logs based on access requests and stores them on an immutable blockchain, forming an audit trail, including: Receive access requests from the authentication module, generate access logs based on the access requests, and encrypt and store the generated access logs on the blockchain; Based on preset audit rules, the stored access logs are analyzed and audited, and an audit report is generated.
6. The elevator digital identity authentication system powered by the distributed identity platform according to claim 5, characterized in that, The access log includes: access request time, entity DID that initiated the access, target object, access permission request content, and authorization result.