Identity authentication method, device, equipment, medium and program product
By creating target task nodes in the blockchain network structure for identity authentication, the risk of single point of failure in centralized authentication is resolved, achieving efficient and reliable identity verification, and improving data flow efficiency and system scalability.
Patent Information
- Application Number
- CN202511146910.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-12-09
AI Technical Summary
Centralized identity authentication methods pose a single point of failure risk, which may lead to user data leakage or service interruption.
In the blockchain network structure, target task nodes are dynamically created, and a connection is established with the main chain of the source node where the user's identity information is located. Identity information is obtained through consensus verification, and authentication information is processed according to preset rules and stored in the target task node.
It achieves efficient and reliable identity authentication in a decentralized environment, avoids the single point of failure risk of centralized authentication, improves data flow efficiency and scalability, and ensures the security and consistency of identity verification.
Smart Images

Figure CN121098505A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of financial technology or big data, and in particular to an identity authentication method, device, equipment, medium, and program product. Background Technology
[0002] In the fintech field, identity authentication is a core line of defense for protecting user information security. By verifying a user's identity, it ensures that financial services can only be accessed by authorized users, effectively preventing unauthorized business transactions and information leaks, thereby enhancing user trust and maintaining the stability and security of the financial system.
[0003] In existing technologies, traditional identity authentication methods rely on centralized database systems to verify user identity by centrally storing and managing user authentication information, such as usernames, passwords, and personal identification information. In this model, when a user authenticates, the authentication credentials they provide must match the pre-stored information in the centralized database in order to be granted the corresponding access permissions.
[0004] However, centralized management carries the risk of a single point of failure. If the database is attacked or malfunctions, it may lead to the leakage of a large amount of user data or service interruption. Summary of the Invention
[0005] This application provides an identity authentication method, apparatus, device, medium, and program product to address the risk of single point of failure in centralized management methods, which could lead to the leakage of large amounts of user data or service interruption if the database is attacked or malfunctions.
[0006] Firstly, this application provides an identity authentication method applied to a blockchain network structure, wherein the blockchain network structure includes multiple source nodes and multiple business nodes corresponding to each source node, each source node stores the identity information of a corresponding user, and the identity information has passed pre-consensus verification; the method includes:
[0007] In response to a user's authentication request, a target task node is created in the blockchain network structure, and the user's consensus-verified identity information is obtained from the source node corresponding to the user; the target task node is connected to the main chain where the source node is located.
[0008] Based on the identity information, the identity identifier carried in the identity authentication request is verified to obtain the identity verification result.
[0009] When the identity verification result is successful, the information corresponding to the identity authentication request is processed based on the preset information processing rules, and the processed identity information is stored in the target task node.
[0010] Secondly, this application provides an identity authentication device, comprising:
[0011] The acquisition module is used to respond to the identity authentication request initiated by the user, create a target task node in the blockchain network structure, and obtain the user's consensus-verified identity information from the source node corresponding to the user; the target task node is connected to the main chain where the source node is located;
[0012] The acquisition module also verifies the identity identifier carried in the identity authentication request based on the identity information and obtains the identity verification result.
[0013] The processing module is used to process the information corresponding to the identity authentication request based on preset information processing rules when the identity verification result is successful, and to store the processed identity information to the target task node.
[0014] Thirdly, embodiments of this application provide an identity authentication device, including: a memory and a processor;
[0015] The memory stores computer-executed instructions;
[0016] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.
[0017] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.
[0018] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0019] The identity authentication method provided in this application achieves efficient and reliable identity authentication in a decentralized environment by dynamically creating target task nodes in the blockchain network structure and linking them with user source nodes. On the one hand, by adopting the distributed ledger characteristics and consensus mechanism of blockchain, the identity information obtained from the source node is tamper-proof and traceable, ensuring the security and consistency of identity verification. On the other hand, through the connection between the target task node and the main chain, the identity identifier is independently verified and the authentication information is processed according to preset rules. This achieves flexible and efficient data processing and storage while avoiding the single point of failure bottleneck of centralized authentication, improving the data flow efficiency and scalability of the system in large-scale application scenarios. This method constructs a reliable, efficient, and scalable decentralized identity authentication mechanism while ensuring privacy and security. Attached Figure Description
[0020] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0021] Figure 1 A flowchart illustrating the identity authentication method provided in this application;
[0022] Figure 2 A schematic diagram of the identity authentication device provided in this application;
[0023] Figure 3 A schematic diagram of the identity authentication device provided in this application.
[0024] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation
[0025] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0026] It should be noted that the identity authentication methods, devices, equipment, media, and program products provided in this application can be used in the fields of fintech or big data, or in any other field. This application does not limit the application fields of the identity authentication methods, devices, equipment, media, and program products.
[0027] In the fintech sector, identity verification is the first and most crucial line of defense for protecting user information security. By accurately verifying user identities, it ensures that only legitimate users can access their accounts, thereby effectively preventing unauthorized operations and the leakage of sensitive information.
[0028] Currently, traditional identity authentication technologies typically rely on centralized database architectures. User authentication information, such as username, password, and ID number, is centrally stored on a central server. When a user attempts to log in or perform business transactions, their submitted credentials are compared with the data stored in the database; only after a successful match is access to the relevant service granted.
[0029] However, centralized management carries the risk of a single point of failure. If the database is attacked or malfunctions, it may lead to the leakage of a large amount of user data or service interruption.
[0030] To address the aforementioned issues, the identity authentication method provided in this application dynamically creates a target task node in a chain network structure composed of multiple blockchains when a user initiates an identity authentication request. This node establishes a connection with the main chain of the source node containing the user's identity information. Subsequently, the target task node obtains the trusted identity information verified through the blockchain consensus mechanism from the source node and uses this information to verify the identity identifier carried in the authentication request. Once the verification is successful, the relevant data in the request is processed according to pre-set business rules, and the processed result is securely stored in the target task node. This method, by creating task nodes on demand in the chain network and linking them with the source chain for cross-chain identity verification, not only ensures the authenticity and consistency of identity data and avoids the single point of failure risk of centralized authentication, but also improves the efficiency of identity authentication through modular and distributed node collaboration.
[0031] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0032] Figure 1 This is a flowchart illustrating the identity authentication method provided in this application. The executing entity in this embodiment is, for example, an identity authentication system. The blockchain network structure includes multiple source nodes and multiple business nodes corresponding to each source node. Each source node stores the identity information of the corresponding user, and the identity information has passed pre-consensus verification. Figure 1 As shown, the method includes:
[0033] S101: In response to the user's identity authentication request, a target task node is created in the blockchain network structure, and the user's identity information that has been verified by consensus is obtained from the user's corresponding source node; the target task node is connected to the main chain where the source node is located.
[0034] Among them, identity authentication requests are a necessary prerequisite for user business processing. Users are allowed to process relevant business only after ensuring that their identity is authentic and valid, identity authentication is completed, and identity information is correct.
[0035] The identity information verified through consensus is confirmed by real-time verification with the associated authoritative identity source subchain, ensuring its authenticity and authority.
[0036] When a user initiates an identity authentication request, the identity authentication system dynamically creates a target task node within the blockchain network structure. This node is established to handle the identity authentication task and is responsible for coordinating the entire verification process. The target task node communicates with the source node, which stores the user's identity information that has been verified through consensus, to obtain the necessary identity authentication data. The source nodes are typically banks, which have already verified and stored the user's identity information on the main chain.
[0037] First, by creating a separate target task node within the blockchain network, the independence and security of each authentication process can be ensured, reducing potential security threats. Second, by utilizing the consensus-verified identity information already existing in the source node, the waste of resources and time delays caused by duplicate verification are avoided, improving the efficiency of the overall process. Finally, by connecting the target task node to the main chain, the transparency and traceability of all operations are guaranteed.
[0038] Specifically, upon receiving a user's authentication request, the system first generates a target task node in the blockchain network according to predefined rules and queries the main chain to determine the source node storing the user's identity information. Then, the target task node sends a request to the corresponding source node, requesting the user's authentication information. After confirming the request's validity and obtaining the user's authorization, the source node transmits the encrypted identity information or its verification credentials to the target task node. Finally, the target task node completes the authentication and records the relevant metadata (such as timestamps, participants, etc.) on the main chain.
[0039] S102: Verify the identity identifier carried in the identity authentication request based on the identity information, and obtain the identity verification result.
[0040] Identity verification based on identity information carried in an authentication request refers to the process by which the identity verification system, upon receiving a user's authentication request, uses identity information stored in the blockchain or verified in real-time through a secondary blockchain to verify the authenticity of the identity information provided by the user (such as ID number, name, etc.). This process confirms the validity of the user's identity by comparing the information submitted by the user with the information verified through consensus on the blockchain.
[0041] By using blockchain technology, particularly by combining secondary chains with real-time connections to authoritative identity sources, identity theft can be effectively prevented. This approach not only improves the accuracy of identity verification but also enhances the transparency and traceability of the verification system, making each verification process clearly visible and tamper-proof, thus significantly increasing trust between users and service providers.
[0042] Specifically, firstly, when a user initiates an identity authentication request, the identity verification system extracts the identity identifier to be verified from the request and searches for the corresponding verified identity information record in the blockchain network. If further confirmation of the real-time validity of the information is required, data synchronization checks are performed with the authoritative identity source via a secondary chain. Next, the identity verification system compares the user's submitted identity identifier with the data stored on the blockchain or the latest verification result fed back by the secondary chain. Finally, based on the comparison results, an identity verification report is generated, indicating whether the user's identity identifier is authentic and valid.
[0043] S103: When the identity verification result is successful, process the information corresponding to the identity authentication request based on the preset information processing rules, and store the processed identity information to the target task node.
[0044] If the identity verification result is successful, the identity verification system will further process the specific information related to the identity authentication request based on preset information processing rules. This includes, but is not limited to, updating user information, recording the operation log, or generating new verifiable credentials. After processing, this updated identity information will be stored in the previously created target task node, ensuring that all relevant information is accurately saved and can be used for subsequent queries.
[0045] Specifically, first, when the identity verification result shows that the verification is successful, the identity verification system begins to execute the corresponding operation according to the pre-set information processing logic (such as updating specific fields, adding new records, etc.). Next, smart contracts are used to automatically update the information or generate new data entries, ensuring that each operation conforms to the established rules and is tamper-proof. Finally, the processed identity information is encrypted and stored in the target task node, and relevant metadata (such as timestamps, operation types, etc.) is recorded synchronously.
[0046] The identity authentication method provided in this embodiment responds to an identity authentication request initiated by a user by creating a target task node in the blockchain network structure and obtaining the user's consensus-verified identity information from the corresponding source node. The target task node connects to the main chain where the source node is located, verifies the identity identifier carried in the identity authentication request based on the identity information, obtains the identity verification result, and processes the information corresponding to the identity authentication request based on preset information processing rules when the identity verification result is successful, and stores the processed identity information in the target task node. This method achieves trusted identity verification and information processing in a decentralized environment by creating a target task node in the blockchain network and linking it with the source node for consensus verification, avoiding the single point of failure risk of centralized authentication, and improving the efficiency of identity authentication through modular and distributed node collaboration.
[0047] In one possible implementation, the method further includes:
[0048] When there is no source node corresponding to the user in the blockchain network structure, the identity authentication request is parsed to obtain the user's identity information;
[0049] The identity information is decomposed, and the decomposed identity information is reordered and integrated to obtain the processed identity information.
[0050] The processed identity information is stored in the target task node for consensus verification; the target task node serves as the source node corresponding to the user.
[0051] When a user's corresponding source node does not exist in the blockchain network structure, the identity verification system first parses the user's authentication request to extract their identity information. Next, the system decomposes, reorders, and integrates the extracted identity information to generate processed identity information. Finally, this processed identity information is stored on the target task node and used as a new source node for consensus verification. This provides new users with a method to establish a trusted identity within the blockchain network.
[0052] By parsing, decomposing, and reassembling identity information, data formats can be standardized, facilitating subsequent automated processing and consensus verification. Furthermore, storing the processed identity information on the target task node and setting it as the user's source node enables rapid response to user authentication requests.
[0053] Specifically, firstly, when no existing source node corresponding to the user is detected in the blockchain network, the identity verification system automatically initiates a parsing process to extract the necessary identity information from the authentication request. Then, this information is analyzed, split, and reordered and integrated according to predefined standards to form formatted data that meets system requirements. Next, this processed identity information is encrypted and stored on the target task node, triggering a consensus verification process to confirm the authenticity and integrity of the information. Once verification is successful, the target task node becomes the user's first source node in the blockchain network, providing authoritative proof of identity for future related operations.
[0054] In one possible implementation, the identity verification is performed on the identity identifier carried in the identity authentication request based on the identity information, and the identity verification result is obtained, including:
[0055] Parse the identity information to obtain the identity identifier;
[0056] The identity information is matched with the identity identifier carried in the identity authentication request to obtain the identity verification result.
[0057] After a user initiates a business request, the identity authentication system parses the user's identity information that has been verified by consensus on the blockchain, extracts its identity identifier (such as ID number, name, etc.), and compares it with the identity identifier submitted by the user in this request to determine whether the two are consistent and generate the identity verification result.
[0058] Traditional identity verification relies on manual comparison or centralized databases, which suffers from low efficiency, data silos, and difficulty in effectively preventing identity theft. Automated verification using blockchain combined with authoritative data sources not only improves accuracy and efficiency but also prevents data tampering and duplicate submissions, enhancing the transparency of the identity authentication system and user trust.
[0059] First, the identity authentication system retrieves the user's identity information, which has been verified through consensus, from the blockchain and parses out the identity identifier. Second, it performs feature matching (such as field comparison, hash value verification, or multi-dimensional verification combined with biometrics) on the identity identifier carried in the user's current authentication request. Finally, it generates a verification conclusion of "pass" or "fail" based on the matching result and records the metadata such as the time, participants, and result of this verification action on the blockchain to ensure that the entire process is traceable and tamper-proof.
[0060] Optionally, the identity identifier in the identity information is matched with the identity identifier carried in the identity authentication request to obtain the identity verification result, including:
[0061] Feature extraction is performed on the identity identifier of the identity information and the identity identifier carried in the identity authentication request to obtain the first identity feature corresponding to the identity information and the second identity feature corresponding to the identity authentication request.
[0062] If the feature matching degree of the first identity feature and the second identity feature is greater than the preset threshold, the identity verification result is that the verification is successful.
[0063] If the feature matching degree between the first identity feature and the second identity feature is not greater than the preset threshold, the identity verification result is verification failure.
[0064] During the identity verification process, the identity authentication system not only compares textual information (such as name and ID number), but also extracts digital features from biometric identifiers (such as facial recognition images and fingerprint templates) to generate quantifiable feature vectors. By comparing the similarity between the biometric features already authenticated in the blockchain (first identity feature) and the biometric features submitted by the user in real time (second identity feature), it determines whether they come from the same person, thus arriving at a conclusion of verification success or failure.
[0065] Biometric matching, such as facial recognition and fingerprint recognition, can be introduced to achieve strong identity binding of "person and document," significantly improving the security and anti-counterfeiting capabilities of identity verification. Biometric features are unique and difficult to replicate; combined with feature matching algorithms and threshold judgments, they can effectively identify risks such as impersonation.
[0066] Specifically, firstly, the identity authentication system extracts features from the verified biometric data stored on the blockchain (such as the facial feature vector during user registration) and the real-time biometric features collected in this authentication request (such as a facial image or fingerprint taken on-site), generating standardized first and second identity features. Then, it calculates the feature matching degree between the two (such as the similarity score of facial comparison and the number of matching points in fingerprint comparison). Finally, it compares the matching degree with a preset security threshold (such as facial similarity ≥ 90%): if it is higher than the threshold, it is determined as "verification passed"; if it is equal to or lower than the threshold, it is determined as "verification failed" and the business is rejected, triggering a risk warning mechanism if necessary.
[0067] In one possible implementation, the preset information processing rules include: information encryption; processing the information corresponding to the identity authentication request based on the preset information processing rules; and storing the processed identity information to the target task node, including:
[0068] The information corresponding to the identity authentication request is encrypted using the encryption algorithm corresponding to the information encryption, and the encrypted identity information is stored in the target task node.
[0069] During the identity verification process, the identity authentication system uses a specific encryption algorithm to encrypt and transform the user's identity data (such as ID number, name, biometrics, etc.) according to preset encryption standards, generating ciphertext information, and then stores this encrypted data in the target task node. This mechanism ensures that sensitive identity information remains protected during transmission and temporary storage, preventing data leakage or unauthorized access.
[0070] In the identity authentication process, raw identity information is highly vulnerable to attack. If stored or transmitted in plaintext at intermediate nodes, it poses a serious risk of privacy breaches. Implementing mandatory encryption effectively protects the confidentiality and integrity of data. Especially in temporary processing units such as target task nodes, encrypted storage prevents data exposure due to node intrusion, thus enhancing the security perimeter of the entire blockchain identity verification system.
[0071] Specifically, first, the identity authentication system selects an encryption algorithm based on preset information processing rules; then, it encrypts sensitive information in the identity authentication request to generate ciphertext data; finally, it securely stores the encrypted identity information in the target task node dynamically created for this authentication. This node is only valid during the verification process, and all data access requires authorization and decryption verification to ensure that the information is "usable but not visible," achieving full-process privacy protection and security control.
[0072] Optionally, the encryption algorithm is a hash algorithm. Based on the encryption algorithm corresponding to the information encryption, the information corresponding to the identity authentication request is encrypted, and the encrypted identity information is stored in the target task node, including:
[0073] The hash value corresponding to the identity authentication request is determined by performing a hash calculation on the information corresponding to the encrypted identity information based on the hash algorithm.
[0074] The encrypted identity information and hash value are concatenated, and the concatenated identity information is stored in the target task node.
[0075] During the identity verification process, the authentication system uses a hash algorithm (such as SHA-256 (Secure HashAlgorithm 256-bit)) to perform an irreversible hash calculation on the user-submitted identity information (such as ID number, name, etc.), generating a fixed-length hash value. This hash value serves as a unique fingerprint of the original information, used for subsequent data comparison and integrity verification. Then, the hashed identity information is concatenated with the corresponding hash value and stored in the target task node created for this authentication.
[0076] Using hash algorithms to process identity information ensures data integrity and consistency because even minute changes in input will result in entirely different hash outputs, making any tampering easily detectable. Furthermore, hash values are one-way, meaning the original data cannot be deduced from the hash value, thus protecting user privacy. This approach not only prevents data tampering during transmission or storage but also ensures the authenticity and reliability of identity information, enhancing the security of the entire identity authentication system.
[0077] First, the authentication system selects a suitable hash algorithm (such as SHA-256) and performs hash calculations on the sensitive information in the authentication request to obtain a unique hash value. Next, the original encrypted identity information is concatenated with this hash value to form a new data structure. Finally, this concatenated identity information is stored in a dynamically created target task node. This approach not only ensures data security, but also allows verification of data integrity by simply recalculating the hash and comparing it with the stored hash value.
[0078] In one possible implementation, the method further includes:
[0079] Set access permissions for users whose identity information is stored in the source node;
[0080] Based on the user's identity identifier, the concatenated identity information corresponding to the identity identifier in the source node can be obtained in real time.
[0081] In a blockchain-based identity management system, fine-grained access control policies are set for each user's identity data to ensure that only authorized institutions or business scenarios can access their identity information. Simultaneously, real-time retrieval of concatenated identity information based on the user's identity identifier means that, after obtaining legitimate authorization, the identity authentication system can quickly locate and read the data stored in the source node—data composed of encrypted identity information and hash values—for subsequent verification or business processing.
[0082] Access control allows users to decide who can access their data, when, and for what purpose. Support for real-time identity-based queries ensures that, with proper authorization, banks and other institutions can efficiently obtain the necessary information, improving business processing speed and achieving a balance between security and efficiency.
[0083] In one possible implementation, the method further includes:
[0084] If the identity information result is that the verification fails, repeat the steps of obtaining the identity identifier carried in the user's identity authentication request and verifying the identity based on the identity information until the verification is successful or the number of verifications reaches the preset number.
[0085] When the identity authentication system fails to verify the user's submitted identity information on the first attempt (e.g., due to inconsistencies or insufficient feature matching), it does not immediately terminate the process. Instead, it initiates a retry mechanism: the identity authentication system receives the user's resubmitted identity authentication request, extracts the identity identifier carried by the request, and re-executes the verification process based on the verified identity information stored on the blockchain. This process continues until identity verification is successful or the number of retries reaches a preset limit.
[0086] Initial verification failures may be caused by non-malicious factors, such as data distortion due to network transmission, user input errors, or poor posture during biometric recognition (e.g., insufficient lighting for facial recognition). Directly refusing service would impact the efficiency of legitimate users' business transactions. By limiting the number of retries, users are given the opportunity to correct their mistakes, improving service availability, while the limited number of attempts prevents malicious attackers from making unlimited attempts (e.g., brute-force attacks), achieving a reasonable balance between security and convenience.
[0087] For example, after the initial verification fails, the identity authentication system automatically records the current number of verification attempts (initially 1) and provides the user with the reason for the failure (such as "insufficient face matching" or "incorrect ID number input"). The user is then prompted to resubmit their identity information. Each time the system retryes, it updates the counter and re-executes the verification steps, including identity extraction, feature matching, and threshold comparison. When verification passes, the process proceeds to the next stage; if the number of verification attempts reaches a preset threshold (e.g., 3 times), the system terminates the authentication process, rejects the application, and generates a risk event log for on-chain storage, triggering manual review or anti-fraud warning mechanisms if necessary.
[0088] Figure 2 A schematic diagram of the identity authentication device provided in this application is shown below. Figure 2 As shown, the identity authentication device 200 provided in this embodiment includes:
[0089] The acquisition module 201 is used to respond to the identity authentication request initiated by the user, create a target task node in the blockchain network structure, and obtain the user's identity information that has passed consensus verification from the corresponding source node; the target task node is connected to the main chain where the source node is located;
[0090] The acquisition module 201 also verifies the identity identifier carried in the identity authentication request based on the identity information and obtains the identity verification result.
[0091] The processing module 202 is used to process the information corresponding to the identity authentication request based on preset information processing rules when the identity verification result is successful, and to store the processed identity information to the target task node.
[0092] In one possible implementation, the processing module 202 is further configured to parse the identity authentication request and obtain the user's identity information when there is no source node corresponding to the user in the blockchain network structure.
[0093] The processing module 202 is also used to decompose the identity information and reorder and integrate the decomposed identity information to obtain the processed identity information;
[0094] The processing module 202 is also used to store the processed identity information to the target task node for consensus verification; the target task node serves as the source node corresponding to the user.
[0095] In one possible implementation, the processing module 202 is further configured to parse the identity information to obtain the identity identifier of the identity information;
[0096] The acquisition module 201 is also used to perform feature matching between the identity identifier of the identity information and the identity identifier carried in the identity authentication request to obtain the identity verification result.
[0097] In one possible implementation, the identity authentication device further includes: a determination module 203;
[0098] The processing module 202 is also used to extract features from the identity identifier of the identity information and the identity identifier carried in the identity authentication request, respectively, to obtain the first identity feature corresponding to the identity information and the second identity feature corresponding to the identity authentication request;
[0099] The determination module 203 is used to determine the identity verification result as successful if the feature matching degree of the first identity feature and the second identity feature is greater than a preset threshold.
[0100] The determination module 203 is used to determine the identity verification result as "verification failed" if the feature matching degree of the first identity feature and the second identity feature is not greater than a preset threshold.
[0101] In one possible implementation, the processing module 202 further encrypts the information corresponding to the identity authentication request based on the encryption algorithm corresponding to the information encryption, and stores the encrypted identity information to the target task node.
[0102] In one possible implementation, the determining module 203 further performs hash calculation on the information corresponding to the identity authentication request based on a hash algorithm to determine the hash value corresponding to the encrypted identity information.
[0103] The processing module 201 is also used to concatenate the encrypted identity information and hash value, and store the concatenated identity information to the target task node.
[0104] In one possible implementation, the determining module 203 is further configured to set access permissions for users who store identity information in the source node;
[0105] The acquisition module 201 is also used to obtain the concatenated identity information corresponding to the identity identifier in the source node in real time based on the user's identity identifier.
[0106] In one possible implementation, the determining module 203 is further configured to repeatedly execute the steps of obtaining the identity identifier carried in the user's identity authentication request and verifying the identity identifier carried in the identity authentication request based on the identity information when the identity information result is verification failure, until the verification is successful or the number of verifications reaches a preset number.
[0107] The identity authentication device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0108] Figure 3 A schematic diagram of the identity authentication device provided in this application. Figure 3 As shown, the electronic device of this embodiment may include: at least one processor 301; and a memory 302 communicatively connected to at least one processor; wherein the memory 302 stores instructions that can be executed by at least one processor 301, and the instructions are executed by at least one processor 301 to cause the electronic device to perform the method as described in any of the above embodiments.
[0109] Optionally, the memory 302 can be either standalone or integrated with the processor 301. When the memory 302 is set up independently, the device also includes a bus for connecting the memory 302 and the processor 301.
[0110] The implementation principle and technical effects of the electronic device provided in this embodiment can be found in the foregoing embodiments, and will not be repeated here.
[0111] This application also provides a computer-readable storage medium storing computer-executable instructions. When the computer-executable instructions are executed by a processor, the methods provided in any of the foregoing embodiments can be implemented.
[0112] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the method provided in any of the foregoing embodiments.
[0113] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0114] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0115] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0116] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0117] Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.
[0118] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0119] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0120] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0121] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. An identity authentication method, characterized in that, The method is applied to a blockchain network structure, which includes multiple source nodes and multiple business nodes corresponding to each source node. Each source node stores the identity information of a corresponding user, and this identity information has been pre-verified through consensus. In response to a user's authentication request, a target task node is created in the blockchain network structure, and the user's consensus-verified identity information is obtained from the source node corresponding to the user; the target task node is connected to the main chain where the source node is located. Based on the identity information, the identity identifier carried in the identity authentication request is verified to obtain the identity verification result. When the identity verification result is successful, the information corresponding to the identity authentication request is processed based on the preset information processing rules, and the processed identity information is stored in the target task node.
2. The method according to claim 1, characterized in that, The method further includes: When the source node corresponding to the user does not exist in the blockchain network structure, the identity authentication request is parsed to obtain the user's identity information; The identity information is decomposed, and the decomposed identity information is reordered and integrated to obtain the processed identity information; The processed identity information is stored in the target task node for consensus verification; the target task node serves as the source node corresponding to the user.
3. The method according to claim 1, characterized in that, The step of verifying the identity identifier carried in the identity authentication request based on the identity information and obtaining the identity verification result includes: Parse the identity information to obtain the identity identifier of the identity information; The identity identifier in the identity information is matched with the identity identifier carried in the identity authentication request to obtain the identity verification result.
4. The method according to claim 3, characterized in that, The step of performing feature matching between the identity identifier of the identity information and the identity identifier carried in the identity authentication request to obtain the identity verification result includes: Feature extraction is performed on the identity identifier of the identity information and the identity identifier carried in the identity authentication request to obtain the first identity feature corresponding to the identity information and the second identity feature corresponding to the identity authentication request. If the feature matching degree between the first identity feature and the second identity feature is greater than a preset threshold, then the identity verification result is that the verification is successful. If the feature matching degree between the first identity feature and the second identity feature is not greater than a preset threshold, the identity verification result is verification failure.
5. The method according to claim 1, characterized in that, The preset information processing rules include: information encryption; the step of processing the information corresponding to the identity authentication request based on the preset information processing rules, and storing the processed identity information in the target task node, includes: The information corresponding to the identity authentication request is encrypted using the encryption algorithm corresponding to the information encryption, and the encrypted identity information is stored in the target task node.
6. The method according to claim 5, characterized in that, The encryption algorithm is a hash algorithm. The encryption of the identity authentication request information based on the encryption algorithm corresponding to the information encryption, and the storage of the encrypted identity information in the target task node, includes: The hash value corresponding to the identity authentication request is determined by performing a hash calculation on the information corresponding to the encrypted identity information based on the hash algorithm. The encrypted identity information and the hash value are concatenated, and the concatenated identity information is stored in the target task node.
7. The method according to claim 6, characterized in that, The method further includes: Set access permissions for users whose identity information is stored in the source node; Based on the user's identity identifier, the concatenated identity information corresponding to the identity identifier in the source node can be obtained in real time.
8. The method according to claim 4, characterized in that, The method further includes: If the identity information result is that the verification fails, the steps of obtaining the identity identifier carried in the user identity authentication request and verifying the identity based on the identity information are repeated until the verification is successful or the number of verifications reaches the preset number.
9. An identity authentication device, characterized in that, include: The acquisition module is used to respond to the identity authentication request initiated by the user, create a target task node in the blockchain network structure, and obtain the user's consensus-verified identity information from the source node corresponding to the user; the target task node is connected to the main chain where the source node is located; The acquisition module also verifies the identity identifier carried in the identity authentication request based on the identity information and obtains the identity verification result. The processing module is used to process the information corresponding to the identity authentication request based on preset information processing rules when the identity verification result is successful, and to store the processed identity information to the target task node.
10. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-8.
12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-8.