A cross-domain business handling security verification method, system, device and storage medium

CN121396491BActive Publication Date: 2026-08-07DIGITAL GUANGDONG NETWORK CONSTR CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
DIGITAL GUANGDONG NETWORK CONSTR CO LTD
Filing Date
2025-10-29
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0004]跨区域业务办理需通过国家级平台多次协议转换与接口调用,涉及3-5个中间节点,导致业务办理耗时超5分钟,且跨省数据同步延迟普遍存在

Benefits of technology

[0043]本发明提供的跨域业务办理安全校验方法,业务终端获取用户提交的业务申请,业务申请包括用户的去中心化身份标识的多源凭证,业务终端将多源凭证发送至业务终端所在的目标区域的区域协作节点,区域协作节点判断是否需要跨域协同校验,若否,则区域协作节点将多源凭证分发给目标区域内相应的校验节点进行本地校验,并将校验节点返回的校验结果反馈给业务终端,若是,则区域协作节点将多源凭证发送至全局仲裁节点,全局仲裁节点将多源凭证分发给跨区域的校验节点进行本地校验,并将校验节点返回的校验结果通过区域协作节点反馈给业务终端,业务终端在校验结果为校验通过时,执行业务办理操作,采用分布式架构将业务处理压力分散至终端、区域、全局三级节点,缩短了跨域业务办理耗时,提高了业务办理效率,分布式架构无单点决策核心,即使单个区域节点故障,终端可自动切换至其他区域节点或使用本地缓存结果,避免全域业务瘫痪。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121396491B_ABST
    Figure CN121396491B_ABST
Patent Text Reader

Abstract

The application discloses a cross-domain business handling security verification method, system, device and storage medium. A business terminal acquires a business application submitted by a user, the business application comprising multi-source credentials of a decentralized identity of the user. The business terminal sends the multi-source credentials to a regional collaboration node of a target region where the business terminal is located. The regional collaboration node determines whether cross-domain collaborative verification is needed. If not, the regional collaboration node distributes the multi-source credentials to corresponding verification nodes in the target region for local verification, and feeds back verification results returned by the verification nodes to the business terminal. If yes, the regional collaboration node sends the multi-source credentials to a global arbitration node. The global arbitration node distributes the multi-source credentials to verification nodes across regions for local verification, and feeds back verification results returned by the verification nodes to the business terminal through the regional collaboration node. When the verification results are verified, the business terminal performs a business handling operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to security verification technology, and more particularly to a method, system, device, and storage medium for cross-domain business processing security verification. Background Technology

[0002] In scenarios requiring cross-regional business processing, individuals often need to handle related matters across different regions. For example, in the context of cross-regional tax business processing nationwide, taxpayers frequently need to handle complex transactions such as invoice application, tax refund application, and tax relocation across different regions. These transactions typically require verification of the applicant's identity information, qualifications, credit rating, and other multi-dimensional data.

[0003] Traditional business processing adopts a centralized architecture, the core characteristics of which are "single-center decision-making, full data upload, and centralized rule execution". Specifically, terminal devices (such as tax self-service machines and computer terminals) collect multi-source voucher information from applicants, encrypt the data and upload it to the provincial / national tax center server; the central server calls on multi-source authoritative data such as public security population database, tax database, and industrial and commercial credit database to verify the authenticity of identity and the validity of business qualifications, generate business processing results and return them to the terminal for execution.

[0004] Cross-regional business processing requires multiple protocol conversions and interface calls through the national platform, involving 3-5 intermediate nodes, resulting in processing times exceeding 5 minutes. Furthermore, cross-provincial data synchronization delays are common. Inconsistent data format standards between regions (such as differences in tax certificate coding rules) and poor interface protocol compatibility lead to a high rate of misjudgments in cross-regional business processing. Moreover, as the sole decision-making node, hardware failure of the central server can paralyze tax operations across the entire region. Summary of the Invention

[0005] This invention provides a method, system, device, and storage medium for cross-domain business processing security verification, so as to shorten the processing time of cross-domain business, improve the efficiency of business processing, and improve the stability of business systems.

[0006] In a first aspect, the present invention provides a method for security verification of cross-domain business processing, comprising:

[0007] The business terminal obtains a business application submitted by the user, the business application including multi-source credentials of the user's decentralized identity identifier;

[0008] The service terminal sends the multi-source credentials to the regional cooperation node in the target area where the service terminal is located;

[0009] The regional collaboration node determines whether cross-domain collaborative verification is required.

[0010] If not, the regional collaboration node will distribute the multi-source credentials to the corresponding verification nodes within the target area for local verification, and feed back the verification results returned by the verification nodes to the business terminal.

[0011] If so, the regional cooperation node will send the multi-source certificate to the global arbitration node;

[0012] The global arbitration node distributes the multi-source credentials to cross-regional verification nodes for local verification, and feeds back the verification results returned by the verification nodes to the business terminal through the regional cooperation node;

[0013] When the verification result is successful, the service terminal performs the service processing operation.

[0014] Optionally, before the service terminal sends the multi-source credentials to the regional cooperation node in the target area where the service terminal is located, the method further includes:

[0015] The business terminal uses zero-knowledge proof to verify the validity of the multi-source credentials.

[0016] Optionally, the service terminal uses zero-knowledge proof to verify the validity of the multi-source credentials, including:

[0017] Extract the validity period of the multi-source certificate from the multi-source certificate;

[0018] Determine whether the multi-source certificate is within the validity period;

[0019] If so, then extract the proof from the multi-source credentials;

[0020] The verification key issued by the trusted digital identity platform, the public statement, and the proof input verification algorithm are used to calculate the validity of the multi-source credential.

[0021] Optionally, before the service terminal sends the multi-source credentials to the regional cooperation node in the target area where the service terminal is located, the method further includes:

[0022] The service terminal queries whether there is a reusable verification result required for the service application within a preset time period before the current time.

[0023] If so, the business processing operation will be performed when the reusable verification result is "verification passed".

[0024] Optionally, the regional cooperation node distributes the multi-source credentials to the corresponding verification nodes within the target area for local verification, including:

[0025] The regional cooperation node determines the target verification node with the lowest current load within the target area;

[0026] The multi-source credentials are distributed to the target verification node.

[0027] Optionally, the global arbitration node distributes the multi-source credentials to cross-regional verification nodes for local verification, including:

[0028] The multi-source credentials are decomposed into multiple encrypted fragments using federally secured multi-party computation.

[0029] The encrypted fragments are distributed to cross-regional verification nodes for local verification via an encrypted data collaboration channel.

[0030] Optional, cross-domain business processing security verification methods also include:

[0031] The service terminal caches the received verification result and retains it for a preset time.

[0032] When the business terminal performs a business processing operation, it sends an on-chain evidence storage notification to the regional cooperation node, the verification node, and the global arbitration node.

[0033] In response to the on-chain evidence storage notification, the regional collaboration node, the verification node, and the global arbitration node upload the verification result to the consortium blockchain for evidence storage.

[0034] Secondly, the present invention also provides a cross-domain business processing security verification system, comprising:

[0035] A business terminal is used to obtain business applications submitted by users, wherein the business applications include multi-source credentials of the user's decentralized identity identifier;

[0036] A regional collaboration node is used to receive the multi-source credentials sent by the business terminal in the target area, determine whether cross-domain collaborative verification is required, and when cross-domain collaborative verification is not required, distribute the multi-source credentials to the corresponding verification node in the target area for local verification and feed back the verification result returned by the verification node to the business terminal. When cross-domain collaborative verification is required, send the multi-source credentials to the global arbitration node.

[0037] A global arbitration node is used to distribute the multi-source credentials to cross-regional verification nodes for local verification, and to feed back the verification results returned by the verification nodes to the business terminal through the regional cooperation node; when the verification result is that the verification is successful, the business terminal performs the business processing operation.

[0038] Thirdly, the present invention also provides an electronic device, comprising:

[0039] One or more processors;

[0040] Storage device for storing one or more programs;

[0041] When the one or more programs are executed by the one or more processors, the one or more processors implement the cross-domain business processing security verification method as described in the first aspect of the present invention.

[0042] Fourthly, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the cross-domain business processing security verification method as described in the first aspect of the present invention.

[0043] The cross-domain business processing security verification method provided by this invention involves a business terminal acquiring a business application submitted by a user. The application includes multi-source credentials representing the user's decentralized identity. The business terminal sends these credentials to a regional collaboration node in the target region where it is located. The regional collaboration node determines whether cross-domain collaborative verification is required. If not, the node distributes the credentials to the corresponding verification node within the target region for local verification and returns the verification result to the business terminal. If yes, the node sends the credentials to a global arbitration node, which distributes them to cross-regional verification nodes for local verification and returns the verification result to the business terminal via the regional collaboration node. When the verification result is successful, the business terminal executes the business processing operation. This distributed architecture distributes the business processing pressure across three levels: terminal, regional, and global nodes, shortening the cross-domain business processing time and improving efficiency. The distributed architecture eliminates single-point-of-failure decisions; even if a single regional node fails, the terminal can automatically switch to another regional node or use locally cached results, preventing a complete business paralysis.

[0044] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0045] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 A flowchart of a cross-domain business processing security verification method provided by the present invention;

[0047] Figure 2 A schematic diagram of the structure of a cross-domain business processing security verification system provided by the present invention;

[0048] Figure 3 This is a schematic diagram of the structure of an electronic device provided by the present invention.

[0049] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0050] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0051] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0052] Figure 1 This is a flowchart of a cross-domain business processing security verification method provided by the present invention. In this embodiment, a distributed security verification method is used to verify the user's multi-source credentials during the cross-domain business processing. Figure 1 As shown, the security verification method for cross-domain business processing includes the following steps:

[0053] S101. The business terminal obtains the business application submitted by the user. The business application includes multi-source credentials of the user's decentralized identity.

[0054] In this embodiment of the invention, taking cross-regional tax business processing as an example, the business terminal is typically a smart device such as a self-service tax terminal deployed in a tax hall, supporting the collection and pre-verification of multiple certificates such as electronic ID cards, tax payment certificates, and credit certificates. Taxpayers submit business applications (such as inter-provincial migration) on the business terminal, which can collect multi-source credentials of the user's decentralized identity (DID) through QR codes, NFC, etc., and package them into a multi-source credential package (containing identity, tax payment, credit, and other multi-source credentials). A decentralized identity is a new type of digital identity based on blockchain technology, fully owned, controlled, and managed by an individual or organization. It does not rely on any centralized institution (such as a government, company, or social media platform) for issuance or verification, allowing users to have complete control over their personal identity information.

[0055] For example, multi-source credentials are generated by a trusted digital identity platform, employing the zk-SNARKs zero-knowledge proof framework (optimized based on the Groth16 protocol). The trusted digital identity platform generates multi-source credentials for government users. Specifically, the trusted digital identity platform compiles the taxpayer's sensitive data into an R1CS constraint system. After compiling this sensitive data into an R1CS constraint system, it uses a predefined CRS (Common Reference String) to generate a fixed 288-byte ZKP proof π, and sets the validity period of this proof. This proof, after being signed by the user's DID private key, forms a verifiable multi-source credential. For example, the generation formula for the ZKP proof π is:

[0056] π = Prove(CRS, [sensitive information], R1CS constraint)

[0057] Here, CRS is the public reference string, Prove() is the function that generates the ZKP proof of π, and R1CS constraints define the data validity rules.

[0058] In some embodiments of the present invention, after obtaining a service application submitted by a user, the service terminal extracts the user's decentralized identity multi-source credential from the service application.

[0059] In some embodiments of the present invention, after receiving a service application submitted by a user, the service terminal extracts multi-source credentials representing the user's decentralized identity from the application and verifies the validity of the multi-source credentials. For example, in one embodiment of the present invention, the service terminal uses zero-knowledge proof (ZKP) to verify the validity of the multi-source credentials. Zero-knowledge proof is a verification method that allows one party (the prover) to prove a statement to another party (the verifier) ​​that it is true without revealing any additional information about the statement. This method is very important in cryptography, especially in protecting data privacy and authenticating identity.

[0060] For example, the process by which a business terminal verifies the validity of multi-source credentials using zero-knowledge proof is as follows:

[0061] 1. Extract the validity period of multi-source vouchers from multi-source vouchers.

[0062] The business terminal extracts the validity period of the multi-source vouchers from the multi-source vouchers.

[0063] 2. Determine whether the multi-source vouchers are within their validity period.

[0064] Determine whether the multi-source certificate is within its validity period.

[0065] 3. If so, extract the proof from the multi-source documents.

[0066] If yes, then extract proof π from the multi-source documents. If not, then the multi-source documents are deemed invalid, and the verification fails.

[0067] 4. Calculate the verification key issued by the trusted digital identity platform, the public statement, and the proof input into the verification algorithm, and determine the validity of the multi-source credentials based on the calculation results.

[0068] The verification algorithm is used to calculate the validity of multi-source credentials by inputting the verification key issued by the trusted digital identity platform, the public statement, and the proof. The validity of the multi-source credentials is determined based on the calculation result. For example, the verification equation is:

[0069] Verifier(vk,u,π)={0,1}

[0070] Where Verifier() is the verification function, vk is the verification key issued by the trusted digital identity platform, and u is the public statement, which is the "statement" or "fact" that the prover needs to prove to the verifier. This statement is known and agreed upon by both parties in advance and does not contain any secret information.

[0071] If the result of the verification equation is 0, it means that the multi-source voucher is invalid and the verification fails. If the result of the verification equation is 1, it means that the multi-source voucher is valid and the verification passes.

[0072] In a specific embodiment of the present invention, during the multi-source credential usage stage, after the business terminal obtains the multi-source credential package through QR code scanning or other means, it uses the zk-SNARKs verification algorithm to complete the local verification of the validity of the proof within 50ms. The verification process only needs to check whether the verification equation Verifier(vk, u, π) = 0 is true without touching the original sensitive data.

[0073] This embodiment deeply integrates decentralized identity (DID) with zero-knowledge proof (ZKP) technology. It generates encrypted credential packages that bind multi-dimensional data such as taxpayer identity characteristics and tax qualifications through a trusted digital identity platform. During the verification phase, zero-knowledge proof is used to verify the validity of multi-source credentials. This eliminates the need to access the original sensitive data, avoids the leakage of user sensitive data, and improves data security.

[0074] In some embodiments of the present invention, after the service terminal obtains the service application submitted by the user and extracts the user's decentralized identity multi-source credential from the service application, it further includes:

[0075] 1. The business terminal queries whether there is a reusable verification result required for the business application within a preset time period before the current time.

[0076] In this embodiment of the invention, the service terminal queries its local cache to see if there is a reusable verification result required for the service application within a preset time period (e.g., 5 minutes) prior to the current time. That is, it queries whether the user has processed the same service within the preset time period prior to the current time and retrieves the verification result from the previously processed service.

[0077] 2. If so, the business processing operation will be performed when the reusable verification result is "verification passed".

[0078] If the validation result exists, determine whether the reusable validation result is valid. If the reusable validation result is valid, execute the business processing operation. This eliminates the need for repeated validation, improving business processing efficiency. If the validation result does not exist, or if the previous validation result is invalid, proceed to step S102.

[0079] S102. The business terminal sends the multi-source credentials to the regional cooperation node in the target area where the business terminal is located.

[0080] For example, in this embodiment of the invention, the business terminal sends the ZKP proof π of the multi-source credentials to the regional collaboration node in the target area where the business terminal is located, thus preventing the leakage of sensitive user information in the multi-source credentials. For example, the regional collaboration node can be a city-level / district-level tax cloud node, responsible for the coordination and management of terminals within its jurisdiction and data collaboration within the region. The regional collaboration node is configured with a distributed ZVP gateway cluster.

[0081] S103. Regional collaboration nodes determine whether cross-domain collaboration verification is required.

[0082] For example, a regional collaboration node determines whether cross-domain collaborative verification is required. That is, the regional collaboration node determines whether the multi-source credentials requiring security verification for this business involve multiple verification nodes (or participants) across regions.

[0083] S104. The regional collaboration node distributes the multi-source credentials to the corresponding verification nodes within the target area for local verification, and feeds back the verification results returned by the verification nodes to the business terminal.

[0084] If the multi-source credentials required for security verification in this business do not involve multiple verification nodes across regions, and only verification nodes within this region (target region) are needed for verification, then the regional collaboration node will distribute the multi-source credentials to the corresponding verification nodes within the target region, where the verification nodes will perform local verification and feed back the verification results returned by the verification nodes to the business terminal.

[0085] For example, in this embodiment of the invention, the verification node uses the zk-STARKs engine to batch verify ZKP proofs π (typically taking less than 100ms), and performs collaborative computation with other data sources within the region through the SPDZ-MPC (Secure Multi-Party Computation) protocol. For example, the ZVP gateway cluster adopts a dynamic sharding architecture, automatically allocating verification tasks based on terminal geographic location and real-time load (gateway response timeout), determining the target verification node with the lowest current load within the target region, and distributing multi-source credentials to the target verification node. Each gateway node integrates an optimized zk-STARKs verification engine, using FFT (Fast Fourier Transform) acceleration and recursive proof technology to keep single verification latency below 100ms. The verification process introduces an aggregate signature mechanism, merging multiple ZKP proofs to generate a fixed 192-byte BLS aggregate signature σ_agg, reducing cross-node data transmission by 70%. The gateway has a built-in intelligent caching module that implements differentiated caching strategies based on risk level (low-risk credentials TTL=10 minutes, high-risk credentials TTL=1 minute), and builds a credential index tree using a Merkle tree structure, supporting second-level retrieval of millions of credentials. When a single gateway fails, the primary / backup switchover mechanism based on the Raft protocol can synchronize traffic cache data to the backup node within 200ms (based on Merkle tree differential synchronization), ensuring system availability of 99.99%.

[0086] S105, The regional collaboration node sends the multi-source credentials to the global arbitration node.

[0087] If the multi-source credentials required for security verification in this business involve multiple verification nodes across regions, and verification by these multiple verification nodes is necessary, then the regional collaboration nodes will send the multi-source credentials to the global arbitration node. The global arbitration node can be a national / provincial tax platform, responsible for cross-regional data collaboration, business rule management, and anomaly arbitration. The global arbitration node compiles dynamic tax policies into verifiable arithmetic circuits using the Marlin protocol and implements an M-of-N threshold signature verification mechanism using the BLS12-381 curve. When a regional node requests cross-domain collaborative verification, it automatically loads the multi-source rule engine.

[0088] S106. The global arbitration node distributes multi-source credentials to cross-regional verification nodes for local verification, and feeds back the verification results returned by the verification nodes to the business terminal through regional cooperation nodes.

[0089] For example, in an embodiment of the present invention, the global arbitration node distributes the ZKP proof of the multi-source credentials to the cross-regional verification nodes for local verification, and feeds back the verification results returned by the verification nodes to the business terminal through the regional cooperation nodes.

[0090] For example, in some embodiments of the present invention, the global arbitration node uses federated secure multi-party computation to decompose multi-source credentials into multiple encrypted fragments, and distributes the encrypted fragments to cross-regional verification nodes (participants) for local verification through an encrypted data collaboration channel. Specifically, the global arbitration node establishes an encrypted collaboration channel with external regional nodes through a federated computing engine in a TEE environment, decomposes the computation task into encrypted fragments, and distributes them to the verification nodes (participants). Each verification node (participant) returns the verification result after calculating the fragment results locally. The global arbitration node aggregates the results and generates a verifiable proof VC_Proof, which is then fed back to the business terminal through regional collaboration nodes. The global arbitration node signs the arbitration result (pass / reject / requires supplementary materials) and returns it to the regional collaboration node, with the time consumption controlled within 800ms. After receiving the global arbitration result (i.e., the verification result), the regional collaboration node updates its local cache (setting the TTL to be dynamically adjusted according to the risk level) and encrypts the result to return it to the business terminal.

[0091] S107. When the verification result is "verification passed", the business terminal performs the business processing operation.

[0092] For example, the business terminal receives the verification result returned by the regional cooperation node, and performs the business processing operation when the verification result is successful, and issues a prompt message to the user when the verification result is unsuccessful, indicating the reason for the failure, such as missing materials.

[0093] In some embodiments of the present invention, after the service terminal receives the verification result returned by the regional cooperation node, the service terminal caches the received verification result and retains it for a preset time (e.g., 5 minutes).

[0094] In some embodiments of the present invention, the business terminal receives the verification result returned by the regional cooperation node, and when the verification result is successful, it executes the business processing operation and triggers the existence process to send an on-chain evidence storage notification to the regional cooperation node, the verification node, and the global arbitration node. The regional cooperation node, the verification node, and the global arbitration node respond to the on-chain evidence storage notification by uploading the verification result to the consortium blockchain for evidence storage. For example, each node uses a hybrid PBFT-ZKP notarization mechanism to achieve traceability and tamper-proof verification through triple protection: In the notarization construction phase, Merkle tree aggregation technology is used to process zero-knowledge proofs in batches (100,000 records / block), and the notarized content only includes non-sensitive fields such as anonymized DID hashes and decision result codes; at the consensus layer, the PBFT algorithm is optimized, and a view switching mechanism and dynamic node weights are introduced to achieve transaction confirmation within 3 seconds while tolerating 1 / 3 of malicious nodes; at the audit verification layer, a zero-knowledge audit interface is provided, and regulators can prove the authenticity of verification logs through ZK-SNARK (e.g., Proof_Audit = ZKProof(Log ∈ ValidSet)) without obtaining specific business data; at the same time, a cross-chain interoperability channel (based on the ICCC protocol) is established to achieve data anchoring with existing systems of various participants. This technology enables the notarization tamper-proof capability to reach 99.999% reliability (average annual downtime <5 minutes). In the certificate management process, the blockchain-based certificate storage system synchronizes the certificate revocation status in real time. When verifying the certificate, the business terminal queries the CRL (Certificate Revocation List) through a light node to ensure the validity of the certificate. This technology reduces the exposure of sensitive data by more than 96% (compared to traditional plaintext transmission schemes).

[0095] The cross-domain business processing security verification method provided by this invention involves a business terminal acquiring a business application submitted by a user. The application includes multi-source credentials representing the user's decentralized identity. The business terminal sends these credentials to a regional collaboration node in the target region where it is located. The regional collaboration node determines whether cross-domain collaborative verification is required. If not, the node distributes the credentials to the corresponding verification node within the target region for local verification and returns the verification result to the business terminal. If yes, the node sends the credentials to a global arbitration node, which distributes them to cross-regional verification nodes for local verification and returns the verification result to the business terminal via the regional collaboration node. When the verification result is successful, the business terminal executes the business processing operation. This distributed architecture distributes the business processing pressure across three levels: terminal, regional, and global nodes, shortening the cross-domain business processing time and improving efficiency. The distributed architecture eliminates single-point-of-failure decisions; even if a single regional node fails, the terminal can automatically switch to another regional node or use locally cached results, preventing a complete business paralysis.

[0096] Figure 2 This invention provides a structural schematic diagram of a cross-domain business processing security verification system, as shown below. Figure 2 As shown, the cross-domain business processing security verification system includes:

[0097] Business terminal 201 is used to obtain business applications submitted by users. The business applications include multi-source credentials for the user's decentralized identity.

[0098] The regional collaboration node 202 is used to receive multi-source credentials sent by the business terminal 201 within the target area, determine whether cross-domain collaborative verification is required, and distribute the multi-source credentials to the corresponding verification node within the target area for local verification when cross-domain collaborative verification is not required, and feed back the verification result returned by the verification node to the business terminal 201. When cross-domain collaborative verification is required, the multi-source credentials are sent to the global arbitration node 203.

[0099] The global arbitration node 203 is used to distribute multi-source credentials to cross-regional verification nodes for local verification, and to feed back the verification results returned by the verification nodes to the business terminal 201 through the regional cooperation node 202; when the verification result is that the verification is successful, the business terminal 201 performs the business processing operation.

[0100] Specifically, the verification process of the cross-domain business processing security verification system has been described in detail in the aforementioned embodiments, and will not be repeated here in the embodiments of the present invention.

[0101] The aforementioned cross-domain business processing security verification system can execute the cross-domain business processing security verification method provided in the foregoing embodiments of the present invention, and has the corresponding functional modules and beneficial effects for executing the cross-domain business processing security verification method.

[0102] Figure 3 This is a schematic diagram of an electronic device provided by the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0103] like Figure 3As shown, the electronic device includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer programs stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0104] Multiple components in the electronic device are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, optical disk, etc.; and a communication unit 19, such as a network card, modem, wireless transceiver, etc. The communication unit 19 allows the electronic device to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0105] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as cross-domain business processing security verification methods.

[0106] In some embodiments, the cross-domain business processing security verification method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on an electronic device via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the cross-domain business processing security verification method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the cross-domain business processing security verification method by any other suitable means (e.g., by means of firmware).

[0107] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0108] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0109] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0110] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0111] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0112] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0113] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the cross-domain business processing security verification method provided in any embodiment of this application.

[0114] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0115] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0116] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for security verification in cross-domain business processing, characterized in that, include: The business terminal obtains a business application submitted by the user, the business application including multi-source credentials of the user's decentralized identity identifier; The service terminal sends the multi-source credentials to the regional cooperation node in the target area where the service terminal is located; The regional collaboration node determines whether cross-domain collaborative verification is required. If not, the regional collaboration node will distribute the multi-source credentials to the corresponding verification nodes within the target area for local verification, and feed back the verification results returned by the verification nodes to the business terminal. If so, the regional cooperation node will send the multi-source certificate to the global arbitration node; The global arbitration node distributes the multi-source credentials to cross-regional verification nodes for local verification, and feeds back the verification results returned by the verification nodes to the business terminal through the regional cooperation node; When the verification result is successful, the service terminal performs the service processing operation.

2. The cross-domain business processing security verification method according to claim 1, characterized in that, Before the service terminal sends the multi-source credentials to the regional cooperation node in the target area where the service terminal is located, the method further includes: The business terminal uses zero-knowledge proof to verify the validity of the multi-source credentials.

3. The cross-domain business processing security verification method according to claim 2, characterized in that, The business terminal uses zero-knowledge proof to verify the validity of the multi-source credentials, including: Extract the validity period of the multi-source certificate from the multi-source certificate; Determine whether the multi-source certificate is within the validity period; If so, then extract the proof from the multi-source credentials; The verification key issued by the trusted digital identity platform, the public statement, and the proof input verification algorithm are used to calculate the validity of the multi-source credential.

4. The cross-domain business processing security verification method according to any one of claims 1-3, characterized in that, Before the service terminal sends the multi-source credentials to the regional cooperation node in the target area where the service terminal is located, the method further includes: The service terminal queries whether there is a reusable verification result required for the service application within a preset time period before the current time. If so, the business processing operation will be performed when the reusable verification result is "verification passed".

5. The cross-domain business processing security verification method according to any one of claims 1-3, characterized in that, The regional cooperation node distributes the multi-source credentials to the corresponding verification nodes within the target area for local verification, including: The regional cooperation node determines the target verification node with the lowest current load within the target area; The multi-source credentials are distributed to the target verification node.

6. The cross-domain business processing security verification method according to any one of claims 1-3, characterized in that, The global arbitration node distributes the multi-source credentials to cross-regional verification nodes for local verification, including: The multi-source credentials are decomposed into multiple encrypted fragments using federally secured multi-party computation. The encrypted fragments are distributed to cross-regional verification nodes for local verification via an encrypted data collaboration channel.

7. The cross-domain business processing security verification method according to any one of claims 1-3, characterized in that, Also includes: The service terminal caches the received verification result and retains it for a preset time. When the business terminal performs a business processing operation, it sends an on-chain evidence storage notification to the regional cooperation node, the verification node, and the global arbitration node. In response to the on-chain evidence storage notification, the regional collaboration node, the verification node, and the global arbitration node upload the verification result to the consortium blockchain for evidence storage.

8. A cross-domain business processing security verification system, characterized in that, include: A business terminal is used to obtain business applications submitted by users, wherein the business applications include multi-source credentials of the user's decentralized identity identifier; A regional collaboration node is used to receive the multi-source credentials sent by the business terminal in the target area, determine whether cross-domain collaborative verification is required, and when cross-domain collaborative verification is not required, distribute the multi-source credentials to the corresponding verification node in the target area for local verification and feed back the verification result returned by the verification node to the business terminal. When cross-domain collaborative verification is required, send the multi-source credentials to the global arbitration node. A global arbitration node is used to distribute the multi-source credentials to cross-regional verification nodes for local verification, and to feed back the verification results returned by the verification nodes to the business terminal through the regional cooperation node; when the verification result is that the verification is successful, the business terminal performs the business processing operation.

9. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the cross-domain business processing security verification method as described in any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the cross-domain business processing security verification method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Method and system for verifying cross-regional authentication credential of power system network

    CN119496644A

  • Systems and methods for credentialing of non-local requestors in decoupled systems utilizing a domain local authenticator

    US20160119306A1