Identity certificate application method and device

By combining near-field communication and biometrics to read information from external identity documents, generate distributed identity identifiers and apply for credentials, the problem of cumbersome and insecure existing identity recognition methods is solved, and efficient and secure identity credential application and verification is achieved.

CN121637469APending Publication Date: 2026-03-10THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-05
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing digital identity verification methods are cumbersome and insecure, requiring users to submit identity information frequently. Furthermore, the data formats vary greatly between different institutions, leading to complex business processes and low security.

Method used

Identity information is read from external identity documents via near-field communication, and then combined with biometric information for dual verification. A distributed identity identifier is generated and an identity credential is applied for. Verification is then performed using a distributed identity system and a credential permission chain.

Benefits of technology

It enables real-person and real-document verification, improves the reliability and efficiency of identity credentials, reduces repetitive operations, and ensures the security and interoperability of identity credentials.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121637469A_ABST
    Figure CN121637469A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an identity credential application method, which comprises the following steps that: an application party terminal sends a second identity verification request to an issuing party, and the issuing party generates a second identity verification result according to the second identity verification request; the applicant terminal judges that identity verification of the applicant is passed according to a second identity verification result sent by the issuing party, sends a distributed identity opening request to the distributed identity system, and receives a distributed identity identifier of the applicant from the distributed identity system; the applicant terminal sends an identity credential application request to the issuing party, and the issuing party generates an applicant identity credential and uploads verification data of the applicant identity credential to the credential permission chain; an applicant terminal receives an applicant identity credential from an issuer. On the basis of ensuring the security of the identity information, the operation of repeatedly submitting the identity information by the user is reduced, and the user experience is improved. The invention further provides a corresponding device, electronic equipment and a computer readable medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and computer-readable medium for applying for identity credentials. Background Technology

[0002] In the financial sector, identity verification and Know Your Customer (KYC) are crucial steps in ensuring transaction security and compliance.

[0003] Currently, the common method of digital identity verification is through SMS verification codes, inputting identity information, and facial recognition. However, with technological advancements, this method has become increasingly cumbersome and insecure. First, users need to frequently and repeatedly submit identity information in different scenarios and business situations, increasing their time costs and reducing overall service efficiency. Second, with the development of black market technologies, SMS verification codes, identity information, and facial recognition data are easily leaked, and the reliability of simple facial recognition verification is declining, leading to frequent cases of identity theft for business transactions. Furthermore, significant differences in technical architecture and data formats between different financial institutions and systems make the sharing and interoperability of digital identity information particularly difficult, hindering effective information exchange between departments or institutions. This not only increases the complexity of business processes but also restricts the overall advancement of digital services. Summary of the Invention

[0004] In view of this, a first aspect of the present invention provides an identity credential application method, applied to an applicant terminal, the method comprising:

[0005] A second authentication request is sent to the issuer so that the issuer can generate a second authentication result based on the second authentication request. The second authentication request includes the applicant's identity information and the applicant's biometric information. The applicant's identity information is obtained by the applicant's terminal from an external identity document through near-field communication.

[0006] Based on the second identity verification result sent by the issuer, the applicant's identity verification is deemed successful. A distributed identity activation request is sent to the distributed identity system, and the applicant's distributed identity identifier is received from the distributed identity system.

[0007] Send an identity credential request to the issuer so that the issuer can generate the applicant's identity credential and upload the verification data of the applicant's identity credential to the credential permission chain. The identity credential request includes the applicant's distributed identity identifier and the verification data includes the digest value of the applicant's identity credential.

[0008] The issuer receives the applicant's identity credentials, which include a statement portion containing the applicant's distributed identity identifier.

[0009] A second aspect of the present invention provides a method for applying for identity credentials, applied to an issuer, the method comprising:

[0010] The system receives a second authentication request from the applicant terminal, generates a second authentication result based on the second authentication request, and sends the second authentication result to the applicant terminal. After the applicant terminal determines that the applicant's authentication is successful based on the second authentication result, it sends a distributed identity activation request to the distributed identity system. The second authentication request includes the applicant's identity information and the applicant's biometric information. The applicant's identity information is obtained by the applicant terminal from an external identity document through near-field communication.

[0011] The system receives an identity credential application request sent by the applicant terminal, generates the applicant's identity credential, and uploads the verification data of the applicant's identity credential to the credential permission chain. The identity credential application request includes the applicant's distributed identity identifier, which is generated by the distributed identity system after receiving the distributed identity activation request sent by the applicant terminal. The verification data includes the digest value of the applicant's identity credential.

[0012] Send the applicant's identity credentials to the applicant's terminal. The applicant's identity credentials include a declaration part, which includes the applicant's distributed identity identifier.

[0013] A third aspect of the present invention provides an identity credential application device, applied to an applicant terminal. The device includes a second identity verification request module, a distributed identity activation request module, an identity credential request module, and an identity credential receiving module, wherein...

[0014] The second authentication request module is configured to send a second authentication request to the issuer so that the issuer can generate a second authentication result based on the second authentication request. The second authentication request includes the applicant's identity information and the applicant's biometric information. The applicant's identity information is read from an external identity document by the applicant's terminal through near-field communication.

[0015] The distributed identity activation request module is configured to determine that the applicant's identity has been verified based on the second identity verification result sent by the issuer, send a distributed identity activation request to the distributed identity system, and receive the applicant's distributed identity identifier from the distributed identity system.

[0016] The identity credential request module is configured to send an identity credential request to the issuer so that the issuer can generate the applicant's identity credential and upload the verification data of the applicant's identity credential to the credential permission chain. The identity credential request includes the applicant's distributed identity identifier, and the verification data includes the digest value of the applicant's identity credential.

[0017] The identity credential receiving module is configured to receive the applicant's identity credential from the issuer. The applicant's identity credential includes a declaration section, which includes the applicant's distributed identity identifier.

[0018] A fourth aspect of the present invention provides an identity credential application device, applied to an issuer. The device includes a second identity verification result generation module, an identity credential generation module, and a sending module, wherein...

[0019] The second authentication result generation module is configured to receive the second authentication request sent by the applicant terminal, generate the second authentication result according to the second authentication request, and send the second authentication result to the applicant terminal. This allows the applicant terminal to determine that the applicant's authentication is successful based on the second authentication result and then send a distributed identity activation request to the distributed identity system. The second authentication request includes the applicant's identity information and the applicant's biometric information. The applicant's identity information is obtained by the applicant terminal from an external identity document through near-field communication.

[0020] The identity credential generation module is configured to receive an identity credential application request sent by the applicant terminal, generate the applicant's identity credential, and upload the verification data of the applicant's identity credential to the credential permission chain. The identity credential application request includes the applicant's distributed identity identifier, which is generated by the distributed identity system after receiving the distributed identity activation request sent by the applicant terminal. The verification data includes the digest value of the applicant's identity credential.

[0021] The sending module is configured to send the applicant's identity credentials to the applicant's terminal. The applicant's identity credentials include a declaration part, which includes the applicant's distributed identity identifier.

[0022] A fifth aspect of the present invention provides an electronic device, comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method provided in the embodiments of the present invention.

[0023] A sixth aspect of the present invention provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the method provided in the embodiments of the present invention.

[0024] One embodiment of the above invention has the following advantages or beneficial effects:

[0025] In this embodiment of the invention, the user uses an applicant terminal to read the identity information stored in an external identity document via near-field communication (NFC). Combined with collected biometric information, the user initiates a second identity verification request. After successful verification by the issuing authority, the result is returned to the applicant terminal. The applicant terminal then activates a distributed identity with the distributed identity system. After obtaining the distributed identity identifier, the applicant terminal requests an identity credential from the issuing authority. Based on the previous verification result, the issuing authority issues the applicant's identity credential. This embodiment of the invention verifies the identity credential not only based on the user's biometric information but also on the identity information read from the physical document, achieving real-person, real-document verification and thus improving the reliability of the identity credential.

[0026] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description

[0027] The accompanying drawings are provided to better understand the invention and are not intended to unduly limit the scope of the invention. Wherein:

[0028] Figure 1 This is a schematic diagram of the network system architecture in which the identity credential application method and the identity credential verification method operate according to some embodiments of the present invention;

[0029] Figure 2 This is a flowchart illustrating an identity credential application method according to some embodiments of the present invention;

[0030] Figure 3 This is a schematic diagram illustrating the process of reading identity information from an external identity document by the applicant's terminal in the identity credential application method according to some embodiments of the present invention;

[0031] Figure 4 This is a flowchart illustrating the process of verifying the identity of the applicant by the issuer in the identity credential application method according to some embodiments of the present invention;

[0032] Figure 5 This is a flowchart illustrating an identity credential application method according to other embodiments of the present invention;

[0033] Figure 6 This is a flowchart illustrating an identity credential verification method according to some embodiments of the present invention;

[0034] Figure 7 This is a flowchart illustrating the verification of verifiable representations in an identity credential verification method according to some embodiments of the present invention;

[0035] Figure 8 This is a schematic diagram of the process for verifying identity credentials in an identity credential verification method according to some embodiments of the present invention;

[0036] Figure 9 This is a flowchart illustrating the process of verifying the status of an identity credential in an identity credential verification method according to some embodiments of the present invention;

[0037] Figure 10 This is another flowchart illustrating the verification of identity credentials in the identity credential verification method according to some embodiments of the present invention;

[0038] Figure 11 This is a functional architecture diagram of an identity credential application device according to some embodiments of the present invention;

[0039] Figure 12 This is a functional architecture diagram of an identity credential application device according to other embodiments of the present invention;

[0040] Figure 13 This is a functional architecture diagram of an identity credential verification device according to some embodiments of the present invention;

[0041] Figure 14 This is a functional architecture diagram of an identity credential verification device according to other embodiments of the present invention;

[0042] Figure 15 This is an exemplary system architecture diagram in which embodiments of the present invention can be applied;

[0043] Figure 16 This is a schematic diagram of the structure of a computer system suitable for implementing terminal devices or servers of the present invention. Detailed Implementation

[0044] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of the present invention, including various details to aid understanding. These details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0045] First, the abbreviations and related terms involved in the embodiments of the present invention are defined and explained.

[0046] "DID (Decentralized Identifiers)" refers to a distributed identity identifier, which is an identifier composed of strings to represent a digital identity. The DID is generated by the distributed identity system based on the applicant's public key and other information. The distributed identity system also stores a DID document corresponding to the DID, which stores the DID and the public key corresponding to the DID.

[0047] A "Verifiable Credential" (VC) is a verifiable credential, typically a JSON string containing VC metadata and a declaration section. The VC metadata mainly includes information such as the issuer, issuance date, and type of declaration. The declaration section contains one or more specific details about the entity; for example, if the VC is an ID card, the declaration section would include the holder's name, gender, date of birth, ethnicity, address, and other personal information. In embodiments of this invention, the VC may not contain the issuer's digital signature; the integrity and authenticity of the VC can be verified through other methods.

[0048] A “VP (Verifiable Presentation)” is a verifiable representation associated with a user’s distributed identity. It contains a verifiable proof document synthesized from one or more verifiable credentials (VCs), and also contains a credential signature generated by digitally signing these proof documents with the user’s private key.

[0049] In existing identity verification services, certain business needs often require users to visit a branch in person for verification. If a user's transaction involves multiple banks, they need to visit multiple bank branches, making the process inefficient and inconvenient, and requiring multiple repetitive steps. While some identity verification services allow users to activate their identity through facial recognition, the security level of facial recognition alone is difficult to guarantee. Users still need to repeatedly submit their identity information for verification at different institutions, further reducing the efficiency of their transactions.

[0050] This invention provides an online method for applying for identity credentials with real-person verification, and correspondingly provides a method for verifying identity credentials online, making it convenient for users to verify their identity online and providing users with a convenient experience in handling business.

[0051] like Figure 1 As shown, a network system 100 is illustrated in an embodiment of the present invention. The credential application method and authentication method in the embodiment of the present invention can be run in the network system 100. The network system 100 includes an applicant terminal 110, an issuer 120, an authenticator 130, a distributed identity system 140, a credential permission chain 150, and a trusted identity management authority 160.

[0052] In embodiments of the present invention, the applicant terminal 110 can be a terminal containing a digital wallet application. The applicant can use the digital wallet application to apply for distributed identity identifiers, identity credentials, organize and send authentication requests, etc. The applicant terminal 110 can also be equipped with a trusted environment for generating the applicant's public and private keys and storing the issued proof credentials. In embodiments of the present invention, the trusted environment is a secure area on the applicant terminal that ensures the security of data loaded into it, including confidentiality, integrity, and availability. The trusted environment can be a Trusted Execution Environment (TEE), a Secure Element (SE), a Trusted Cryptographic Module (TCM), or other protected areas with security boundaries. In some embodiments of the present invention, the issuer 120 can be understood as a system controlled by an issuing authority. The issuer 120 is equipped with a server cryptographic machine, which generates the issuer's public and private keys. In some embodiments of the present invention, the distributed identity system 140 can generate a distributed identity identifier after verification based on a distributed identity activation request, and generate a distributed identity identifier document corresponding to the distributed identity identifier. The distributed identity identifier document stores the distributed identity identifier and the public key corresponding to the distributed identity identifier. The distributed identity system 140 stores and maintains the distributed identity identifier document. In some embodiments of the present invention, the trusted identity management authority 160 can be an authoritative identity authentication institution that maintains and stores a database containing user identity information and biometric information, which can be accessed by other institutions to verify the user's identity, etc.

[0053] like Figure 2 As shown, this embodiment of the invention provides a certificate application method, including the following steps:

[0054] S210: In response to the user's (applicant's) distributed identity activation request operation on the applicant terminal, the applicant terminal 110 reads the applicant's identity information from an external identity document via near-field communication and collects the applicant's biometric information. Based on the applicant's identity information and biometric information, it sends a first authentication request to a trusted identity management authority, wherein the first authentication request includes the applicant's identity information and biometric information.

[0055] like Figure 3 As shown, the external identification document 300 includes a near-field communication unit 310 and a storage unit 320. The applicant's identity information is stored in the storage unit 320. When the external identification document 300 is near the applicant's terminal 110, the applicant's terminal 110 communicates with the near-field communication unit 310 according to the near-field communication protocol. After obtaining the applicant's identity information from the storage unit 320, the near-field communication unit 310 transmits it to the applicant's terminal 110 through the near-field communication protocol. In some embodiments of the present invention, the applicant's identity information in the storage unit 320 may be encrypted.

[0056] In some embodiments of the present invention, the external identification document can be a physical document that supports NFC tag reading, such as an ID card, driver's license, passport, military officer's certificate, bank card, social security card, etc. The applicant's identity information can be name, ID card number, gender, date of birth, etc., and the applicant's biometric information can be facial information, fingerprint information, iris information, etc.

[0057] In some embodiments of the present invention, after obtaining the applicant's identity information from the external identity document 300, the applicant terminal 110 calls the camera to collect the applicant's facial information, and then initiates a first identity verification request to the trusted identity management agency 160.

[0058] In some embodiments of the present invention, the trusted identity management authority 160 provides an authentication interface so that other devices can call the authentication interface to transmit the identity information to be verified to the trusted identity management authority 160. In some embodiments of the present invention, the applicant terminal 110 calls the authentication interface to send a first authentication request to the trusted identity management authority 160.

[0059] In this embodiment of the invention, the applicant's identity information is obtained from an external identity document through a near-field communication protocol, ensuring that the user is currently using a physical identity document to conduct business, thereby improving the reliability of business processing. Subsequently, facial information is collected to ensure that the user is the applicant himself / herself, thus ensuring that the user conducts business under the condition of real person and real identity, thereby improving the reliability of verification business.

[0060] In some embodiments of the present invention, the applicant terminal 110 also generates a reading information record during the process of reading identity information. The reading information record includes the type of document read, the reading time, the identity information read, or a summary of the identity information read.

[0061] S220: The trusted identity management authority 160 generates and returns the first identity verification result based on the first identity verification request, and the applicant terminal 110 determines that the applicant's identity verification is successful based on the first identity verification result.

[0062] In an embodiment of the present invention, the trusted identity management institution 160 stores identity information from external identity documents and correspondingly stores the user's biometric information. The trusted identity management institution 160 compares and verifies the applicant's identity information and biometric information in the first identity verification request, generating a first identity verification result. If the applicant's identity information and biometric information are confirmed to match the information stored by the trusted identity management institution 160, the first identity verification result indicates successful verification. After determining that the applicant's identity verification is successful based on the first identity verification result, the applicant terminal 110 proceeds with the subsequent secondary verification process.

[0063] In some embodiments of the present invention, after the applicant terminal 110 determines that the applicant's identity verification is successful based on the first identity verification result, it also encrypts and stores the applicant's identity information and the applicant's biometric information.

[0064] S230: After determining that the applicant's identity verification is successful based on the first identity verification result, the applicant terminal 110 sends a second identity verification request to the issuer 120, wherein the second identity verification request includes the applicant's identity information read above and the applicant's biometric information collected above.

[0065] S240: The issuer 120 generates a second authentication result based on the second authentication request and returns the second authentication result to the applicant terminal 110.

[0066] In some embodiments of the present invention, the issuer 120 may call the interface of the trusted identity management authority 160 to send the applicant's identity information and biometric information in the second identity verification request to the trusted identity management authority 160 for verification, or may use the identity information and biometric information stored in its own database for verification.

[0067] In some embodiments of the present invention, the second authentication request also includes a read information record generated by the applicant terminal 110, and the issuer 120 determines from the read information record that the identity information in the second authentication request originates from an external entity certificate.

[0068] In some embodiments of the present invention, such as Figure 4 As shown, step S240 includes the following steps.

[0069] S241: The issuer 120 determines that the applicant's identity information matches the read information record and sends the applicant's identity information and biometric information to the trusted identity management agency 160 so that the trusted identity management agency 160 can generate a third-party authentication result based on the applicant's identity information and biometric information.

[0070] In some embodiments of the present invention, the issuing party 120 may determine whether the applicant's identity information matches the read information record by adopting one or more of the following methods: judging that the document type is within a reliable range based on the document type read in the read information record; the difference between the reading time and the time of the second identity verification request is within a threshold range; the read identity information or the digest of the read identity information is consistent with the applicant's identity information or the digest of the applicant's identity information in the second identity verification request, etc.

[0071] In this embodiment of the invention, the process of the trusted identity management authority 160 for the third identity verification request is similar to that in the first identity verification request, and will not be described in detail here.

[0072] S242: The issuer 120 receives the third authentication result returned by the trusted identity management authority 160 and generates a second authentication result based on the third authentication result. In some embodiments of the present invention, if the third authentication result indicates successful verification, the second authentication result also indicates successful verification.

[0073] In this embodiment of the invention, two authentication methods are used to ensure the reliability of authentication.

[0074] S250: The applicant terminal 110 determines that the applicant's identity verification is successful based on the second identity verification result sent by the issuer, sends a distributed identity activation request to the distributed identity system 140, and receives the applicant's distributed identity identifier from the distributed identity system 140.

[0075] In some embodiments of the present invention, after the applicant terminal 110 determines that the applicant's identity verification is successful based on the second identity verification result, it generates an applicant public key and an applicant private key based on the trusted environment within the applicant terminal 110, and stores the applicant private key in the trusted environment; it then generates a distributed identity activation request based on the applicant public key. In some embodiments of the present invention, the distributed identity activation request includes the applicant public key. The distributed identity system 140 generates an applicant distributed identity identifier based on the applicant public key and generates a corresponding applicant distributed identity identifier document. The applicant distributed identity identifier document stores the applicant distributed identity identifier and the applicant public key. By parsing the applicant distributed identity identifier, the applicant distributed identifier document can be obtained, and the applicant public key can be obtained from it. In some embodiments of the present invention, the distributed identity system 140 performs a hash calculation on the applicant public key or together with other random factors to obtain the applicant distributed identity identifier.

[0076] In some embodiments of the present invention, the trusted environment set in the applicant terminal 110 is a secure area on the applicant terminal 110, which can guarantee the security of data loaded into it, including confidentiality, integrity, and availability. Specifically, it can be a Trusted Execution Environment (TEE), a Secure Element (SE), a Trusted Cryptographic Module (TCM), or other protected areas with security boundaries. In some embodiments of the present invention, the applicant's identity information and the applicant's biometric information can be encrypted and stored in the trusted environment.

[0077] S260: The applicant terminal 110 sends an identity credential request to the issuer 120, wherein the identity credential request includes the applicant's distributed identity identifier. In this embodiment of the invention, the applicant terminal 110 requests an identity credential from the issuer 120 based on the results of two previous successful identity verifications.

[0078] S270: The issuer 120 generates the applicant's identity credential, wherein the applicant's identity credential includes a statement portion, which includes the applicant's distributed identity identifier.

[0079] In some embodiments of the present invention, the identity credential application request also includes the applicant's public key. The issuer 120 also sets the applicant's public key in the declaration section during the generation of the applicant's identity credential. In these embodiments, the applicant's public key is generated using a trusted environment. Since the public key generated by each applicant terminal is unique, setting the applicant's public key in the declaration section ensures that the applicant terminal 110 used by the user when applying for distributed identity and when applying for identity credential is consistent, thus guaranteeing the identity of the verification.

[0080] In some embodiments of the present invention, in order to support the verification needs of the verifier in the identity credential verification process, such as supporting the verifier's need to re-verify the applicant's identity information and biometric information, the issuer 120, during the generation of the applicant's identity credential, also calculates a digest value of the applicant's identity information and / or the applicant's biometric information, obtains the identity information digest value, and sets the identity information digest value in the declaration section of the applicant's identity credential. In subsequent verification processes, after the applicant terminal 110 sends the stored applicant's identity information and biometric information to the verifier, the verifier can verify the applicant's identity information and biometric information sent by the applicant terminal 110 based on the identity information digest value in the declaration section. It should be noted that although the verifier additionally verifies the applicant's identity information and biometric information at this time, the applicant terminal 110 does not obtain the identity information or collect the biometric information again. The applicant terminal 110 can obtain the above information from a trusted environment, avoiding the user from repeatedly submitting identity information and reducing repetitive operations.

[0081] In some embodiments of the present invention, the issuer 120 also sets the validity period of the identity certificate during the process of generating the applicant's identity certificate. The certificate issuance time can be set in the declaration section. In a specific scenario, the identity certificate has a preset duration from issuance to expiration. Based on the issuance time and the preset duration, it can be determined whether the identity certificate is still within its validity period.

[0082] In some embodiments of the present invention, to more accurately control the validity period of the identity credential, the issuing party 120 also sets a credential expiration time in the declaration section. In some embodiments of the present invention, the identity information read by the applicant terminal 110 from the external identity document also includes the document expiration time, and the applicant's public key is also set with an expiration time. In the embodiments of the present invention, the credential expiration time is set to the earlier of the document expiration time and the applicant's public key expiration time. This ensures that when the identity credential is used, the corresponding public key and the document have not expired.

[0083] In some embodiments of the present invention, in order to distinguish different identity credentials and facilitate the verification party in selecting different verification methods according to different types of identity credentials, the declaration part of the identity credentials in the embodiments of the present invention also includes a credential type. For example, for an identity credential generated through real person verification in the embodiments of the present invention, its credential type can be set as a sticker credential; if it is an identity credential generated based on the counter identity verification result, its credential type can be set as a counter verification credential.

[0084] Different credential types in the embodiments of the present invention can be configured with different verification methods. For example, some credentials do not require verification of whether the public key in the declaration part is consistent with the public key in the distributed identity document, while for some identity credentials, in order to verify the immutability of the device, it is also necessary to verify whether the applicant's public key in the credential declaration is consistent with the applicant's public key in the distributed identity document.

[0085] In some embodiments of the present invention, before receiving the second authentication request sent by the applicant terminal, the issuer 120 sends an issuer distributed identity activation request containing the issuer's public key to the distributed identity system 140; the issuer receives the issuer distributed identity identifier sent by the distributed identity system 140, wherein the issuer distributed identity identifier is generated by the distributed identity system 140 according to the issuer distributed activation request. After generating the issuer distributed identity identifier, the distributed identity system 140 also generates an issuer distributed identity identifier document based on the issuer distributed identity identifier. The issuer distributed identity identifier document stores the issuer's public key. The issuer distributed identity identifier document can be accessed through the issuer distributed identity identifier, thereby obtaining the issuer's public key.

[0086] S280: The applicant terminal 110 receives the applicant's identity certificate from the issuer 120.

[0087] In some embodiments of the present invention, after generating the applicant's identity credential, the issuer 120 sends a credential generation notification to the applicant terminal 120. The user can receive the credential generation notification through a digital wallet application or via SMS. After receiving the credential generation notification, the user sends a download request to the issuer 120 through the applicant terminal 110. The issuer 120 then transmits the applicant's identity credential to the applicant terminal 110 according to the credential download request.

[0088] In some embodiments of the present invention, to facilitate verification of the status and integrity of identity credentials by other parties, such as... Figure 5 As shown, the method in this embodiment of the invention further includes:

[0089] S290: Issuer 120 uploads the verification data of the applicant's identity credential to the credential permission chain 150. The verification data includes the digest value and status of the applicant's identity credential.

[0090] In an embodiment of the present invention, the issuer 120 calculates a digest value based on the applicant's identity credential, obtains the digest value of the applicant's identity credential, and synchronizes the digest value and status to the credential permission chain 150. During subsequent identity credential verification, the digest value of the received identity credential can be compared with the digest value stored on the credential permission chain 150. If they match, the received identity credential is considered complete and authentic. Furthermore, the status of the identity credential can be obtained from the credential permission chain 150 based on the digest value, thereby verifying the status of the identity credential. In this embodiment of the present invention, the status of the identity credential can be valid, invalid, transferred, etc.

[0091] In this embodiment of the invention, the user uses an applicant terminal to read the identity information stored in an external identity document via near-field communication (NFC). Combined with collected biometric information, the user initiates a second identity verification request. After successful verification by the issuing authority, the result is returned to the applicant terminal. The applicant terminal then activates a distributed identity with the distributed identity system. After obtaining the distributed identity identifier, the applicant terminal requests an identity credential from the issuing authority. The issuing authority issues the applicant's identity credential based on the previous verification result. This embodiment of the invention verifies identity credentials not only based on the user's biometric information but also on the identity information read from the physical document, achieving real-person, real-document verification and thus improving the reliability of the identity credential.

[0092] According to the identity credential generated in the above embodiments of the present invention, the applicant terminal 110 can also initiate an identity credential verification request to the verifier. The identity credential verification process will be described below. In addition to referring to the following embodiments, the above-described embodiments of identity credential application can also be referred to regarding the limitations of the identity credential.

[0093] like Figure 6 As shown in the figure, the present invention also provides an identity credential verification method, which includes the following steps.

[0094] S410: The applicant terminal 110 obtains the identity credential information stored locally and generates an identity credential verifiable representation based on the identity credential information. The identity credential verifiable representation includes the identity credential information and a credential signature generated by signing the identity credential information with the applicant's private key. The identity credential information includes the applicant's identity credential issued by the issuer 120. The applicant's identity credential includes a declaration part, which includes the applicant's distributed identity identifier.

[0095] In some embodiments of the present invention, referring to the above-described embodiments of identity credentials, after the applicant's identity information and biometric information have been verified, the distributed identity system 140 generates the applicant's distributed identity identifier based on the applicant's public key.

[0096] In some embodiments of the present invention, the applicant's identity information is obtained by the applicant's terminal from an external identity document via near-field communication.

[0097] In some embodiments of the present invention, the applicant terminal 110 obtains identity credential information from a trusted environment and uses the private key in the trusted environment to sign the identity credential information to generate a credential signature.

[0098] S420: The applicant terminal 110 sends an authentication request to the verifier 130, wherein the authentication request includes a verifiable expression of identity credentials.

[0099] In some embodiments of the present invention, the applicant terminal 110 may send an authentication request to the verifier 130 via a near-field communication protocol or by presenting a QR code. The applicant terminal 110 generates and displays a QR code based on the authentication request, and the verifier 130 scans the QR code to obtain the authentication request.

[0100] S430: Verifier 130 receives the identity verification request sent by the applicant terminal, verifies the verifiable identity credential, and generates a credential verification result.

[0101] In some embodiments of the present invention, the verifier 130 verifies the verifiable representation of the identity credential and the applicant's identity credential, and can verify its completeness, authenticity and validity.

[0102] In embodiments of the present invention, the applicant's public key is obtained from the distributed identity system 140 through the applicant's distributed identity identifier in the declaration, and the applicant's public key is used to verify the credential signature. Then, the authenticity and integrity of the applicant's identity credential are further verified using the verification data on the credential permission chain.

[0103] like Figure 7 As shown, in some embodiments of the present invention, the declaration portion of the applicant's identity credential also includes the credential issuance time and / or credential expiration time. The credential issuance time and / or credential expiration time can be used to verify whether the identity credential is still valid. In some embodiments of the present invention, step S430 includes:

[0104] S431: Verifier 120 verifies the validity period of the applicant's identity credential based on the current time and the credential issuance time / or credential expiration time.

[0105] In some embodiments of the present invention, when determining the lifespan of a certain type of identity credential, the validity period can be determined based on the credential issuance date. For example, if the lifespan of an applicant's identity credential is one year and the issuance date is September 1, 2023, then the applicant's identity credential is valid until August 31, 2024. Since the current date is August 12, 2024, the applicant's identity credential is valid.

[0106] In some embodiments of the present invention, the declaration section of the applicant's identity credential directly includes the credential expiration date. By comparing the current time with the credential expiration date, it can be determined whether the applicant's identity credential is still valid. For example, if the credential expiration date of an applicant's identity credential is August 31, 2024, then based on the current time August 12, 2024, it can be determined that the applicant's identity credential is still valid.

[0107] In some embodiments of the present invention, the declaration portion of the applicant's identity credential also includes the applicant's public key. By verifying the applicant's public key, it can be determined that the device for the application credential, the device for the application identifier, and the device for verifying the identity credential are the same device. (Continued below) Figure 7 Step S430 will be described as follows: Figure 7 As shown, step S430 further includes:

[0108] S432: Verifier 130 obtains the applicant's public key from the distributed identity system based on the applicant's distributed identity identifier; Verifier 130 obtains the applicant's distributed identity identifier from the declaration section of the applicant's identity credential, requests the applicant's public key from the distributed identity system 140, the distributed identity system 140 obtains the applicant's distributed identity identifier document based on the applicant's distributed identity identifier, obtains the applicant's public key from the applicant's distributed identity identifier document, and returns the applicant's public key to Verifier 130.

[0109] S433: Verifier 130 verifies whether the applicant's public key in the applicant's identity credential is consistent with the applicant's public key obtained from the distributed identity system. If they are consistent, the credential signature is verified using the applicant's public key, and a credential signature verification result is generated.

[0110] S434: Generate voucher verification result based on voucher signature verification result.

[0111] In this embodiment of the invention, the method verifies the credential signature after verifying that the two public keys are consistent. This verifies whether the public key has been tampered with during the credential application process. Furthermore, the method uses the consistent applicant's public key to verify the credential signature, thus verifying the consistency between the applicant terminal when verifying the identity credential and the applicant terminal when applying for the identity credential. This verifies whether the identity credential has been transferred and the security of the identity credential during storage.

[0112] In some embodiments of the present invention, the integrity of the declaration portion of the identity credential can also be further detected, such as... Figure 8 As shown, step S434 further includes:

[0113] S4341: Verifier 130 determines that the credential signature verification is successful based on the credential signature verification result, and generates a credential digest value based on the applicant's identity credential.

[0114] S4342: Verifier 130 sends a credential digest value to credential permission chain 150, enabling credential permission chain 150 to obtain verification data based on the credential digest value and generate a credential integrity verification result based on the verification data. The verification data is generated by the issuer after generating the applicant's identity credential, and includes a digest value of the applicant's identity credential. In some embodiments of the present invention, credential permission chain 150 stores the verification data sent by issuer 120. Credential permission chain 130 compares the digest value sent by verifier 130 with the digest value in the stored verification data. If they match, the integrity of the applicant's identity credential is verified.

[0115] S4343: Verifier 140 generates a credential verification result based on the credential integrity verification result sent by credential permission chain 150.

[0116] In embodiments of the present invention, the integrity of the declaration portion is verified by verifying the on-chain verification data and the digest value, thereby ensuring that the content of the credential has not been tampered with.

[0117] In some embodiments of the present invention, the validity status of the identity credential is also verified. As described in the embodiments for applying for an identity credential above, after the identity credential is generated, the issuer 120 will synchronize the verification data of the identity credential (including the status of the identity credential) to the credential permission chain 150. Subsequently, when verifying the identity credential, the status of the identity credential can be obtained from the credential permission chain to determine the status of the identity credential. Specifically, refer to... Figure 9 In some embodiments of the present invention, step S4343 includes the following steps.

[0118] S43431: The credential permission chain 150 generates a credential status verification result based on the status of the applicant's identity credential. After receiving the digest value sent by the verifier 130, the credential permission chain 150 obtains the verification data stored on the chain, retrieves the status of the applicant's identity credential from the verification data, and generates a credential status verification result based on the status. When the status is valid, the credential status verification result indicates that the status verification has passed.

[0119] S43432: Verifier 130 receives the credential status verification result returned by credential permission chain 150.

[0120] S43433: Verifier 130 determines that the applicant's identity credential status verification has passed based on the credential status verification result, and generates a credential verification result indicating that the verification has passed.

[0121] The validity status of the identity credential was verified through status verification.

[0122] In some embodiments of the present invention, to meet the business needs of different verification parties and to satisfy the verification party's need to re-verify identity information, the declaration portion of the applicant's identity credential also includes an identity information digest value. When generating a verifiable identity credential representation, the applicant terminal 110 also generates the verifiable identity credential representation based on locally stored applicant identity information and / or applicant biometric information; that is, the identity credential related information also includes applicant identity information and / or applicant biometric information. The process of verifying the verifiable identity credential representation also includes the process of verifying the applicant identity information and / or applicant biometric information. Since the issuer 120 has already sent the received applicant identity information and applicant biometric information to the trusted identity management agency 160 for verification when applying for the identity credential, if the identity information provided by the applicant terminal again is consistent with the applicant identity information and applicant biometric information received by the issuer 120, the verification passes. In other embodiments of the present invention, the credential status and business identity information can be verified synchronously, as described above. Figure 10 Step S4343 further includes:

[0123] S43431: The credential permission chain 150 generates a credential status verification result based on the status of the applicant's identity credential. After receiving the digest value sent by the verifier 130, the credential permission chain 150 obtains the verification data stored on the chain, retrieves the status of the applicant's identity credential from the verification data, and generates a credential status verification result based on the status. When the status is valid, the credential status verification result indicates that the status verification has passed.

[0124] S43432: Verifier 130 receives the credential status verification result returned by credential permission chain 150.

[0125] S43434: Verifier 120 determines that the identity credential integrity verification is successful based on the credential integrity verification result, and generates a business identity information digest value based on the applicant's identity information and / or the applicant's biometric information.

[0126] S43435: Verifier 120 verifies the business identity information digest value based on the identity information digest value and generates a business identity information verification result.

[0127] S43433': Verifier 120 determines that the applicant's identity credential status verification is successful based on the credential status verification result and determines that the business identity information verification is successful based on the business identity information verification result, and generates a credential verification result indicating that the verification is successful.

[0128] The execution order of the above steps S43431, S43432 and S43434, S43435 is not restricted; they can be executed sequentially or in parallel.

[0129] In some embodiments of the present invention, the identity information digest value in the declaration section is generated from the applicant's identity information, and the identity credential information includes the applicant's identity information.

[0130] In some embodiments of the present invention, the identity information digest value in the declaration section is generated from the applicant's biometric information, and the identity credential information includes the applicant's biometric information.

[0131] In some embodiments of the present invention, the identity information digest value in the declaration section is generated from the applicant's identity information and the applicant's biometric information, then the identity credential related information includes the applicant's identity information and the applicant's biometric information.

[0132] In this embodiment of the invention, different verification methods are used for different types of identity credentials. In order to quickly determine the verification method, in some embodiments of the invention, the declaration part includes the credential type. Before the verifier 130 obtains the applicant's public key from the distributed identity system based on the applicant's distributed identity identifier, the verifier 130 also obtains the credential type in the applicant's identity credential. After verifying that the credential type is a sticker credential, the subsequent credential signature verification process continues.

[0133] In some embodiments of the present invention, after the identity information digest value is verified and the status of the applicant's identity credential is verified, the verifier 130 generates a credential verification result indicating that the verification has been successful.

[0134] S440: Verifier 130 sends the credential verification result to applicant terminal 110.

[0135] S450: The applicant terminal 110 determines that the credential verification is successful based on the credential verification result and sends a business processing request to the verifier.

[0136] S460: Verifier 130 processes the business based on the business processing request.

[0137] In some embodiments of the present invention, the business processing requests that the verification party 130 can handle include wallet account level upgrade requests, loan application requests, insurance purchase requests, wealth management purchase requests, etc. in digital wallet applications.

[0138] In some embodiments of the identity credential application and identity credential verification of the present invention, the interaction between the applicant terminal 120 and the trusted identity management authority 160, the distributed identity system 140, the issuer 120, and the verifier 130 can be carried out through the server corresponding to the applicant terminal. The request first arrives at the server corresponding to the applicant terminal from the applicant terminal, and then the server corresponding to the applicant terminal sends it to the trusted identity management authority 160, the distributed identity system 140, the issuer 120, and the verifier 130. Conversely, the result of the request is first returned from the trusted identity management authority 160, the distributed identity system 140, the issuer 120, and the verifier 130 to the server corresponding to the applicant terminal, and then the server corresponding to the applicant terminal sends it to the applicant terminal 110.

[0139] In this embodiment of the invention, after obtaining an identity credential through real-person and identity verification, the applicant requests identity verification from the verifier based on the obtained identity credential. The applicant's terminal generates a verifiable representation of the identity credential based on the identity credential and sends an identity verification request to the verifier. The verifier verifies the authenticity, completeness, and validity of the verifiable representation of the identity credential, thereby verifying the applicant's identity. In this embodiment of the invention, the identity credential reflecting the verification result can be securely shared among multiple financial institutions without repeatedly collecting user identity information. This not only meets the requirements of various institutions for the strength of identity authentication but also significantly improves user convenience, reduces the repetitive work of identity verification among multiple institutions, and optimizes the customer experience.

[0140] The embodiments of this invention provide a method for applying for and verifying identity credentials. On the one hand, this identity credential, without disclosing any sensitive personal information, binds to the applicant's terminal through a DID identifier, embodying the user's "real person + real certificate" verification, and using the verification result as a reference indicator of the trustworthiness of the currently operating device. On the other hand, compared with other general VC credentials, this identity credential does not contain the signature of the credential issuer. The authenticity and validity of the credential can be verified using the credential content itself (such as the client's public key identifier, credential validity period, etc.), on-chain verification data, and the user signature value added upon presentation.

[0141] In this embodiment of the invention, the distributed identity system and the credential issuer system are two separate responsible entities. They achieve trusted data interaction through a secure online transmission channel. During the NFC sticker credential issuance process, the applicant terminal interfaces with a trusted management agency to perform the first layer of user identity verification. After successful verification, the applicant terminal transmits the acquired identity information to the credential issuer system for the second layer of user identity verification. Only after both identity verifications are successful can the user activate their digital identity, obtain a unified digital identity identifier (DID), and receive an NFC sticker credential. In this two-layer identity verification mode, users only need to submit one application to complete both identity verifications, simultaneously obtaining a distributed identity identifier and identity credential, as well as a user-specific key to control the distributed identity identifier and identity credential. This simplifies user operations and enhances the authentication strength and interoperability of the digital identity.

[0142] In this embodiment of the invention, the user identity information obtained through NFC stickers is securely stored in the user's terminal device using public key encryption, preventing any organization or individual from accessing the locally stored information. Users can independently retrieve and use the information from their terminal device according to business needs, and it can be presented in conjunction with the NFC sticker certificate. During the presentation process, the user's private key is used to digitally sign the "encrypted identity information + NFC sticker certificate" before transmitting it to the authorized institution (verifier) ​​for verification. This ensures user privacy and security while enabling autonomous management and authorization of identity information.

[0143] This invention provides a method for applying for and verifying NFC-enabled identity credentials, allowing users to have their identity verification results, completed at one financial institution, recognized and reused by other financial institutions. Users only need to activate the NFC-enabled identity credential using their physical identity credential (such as a second-generation ID card) on an NFC-enabled mobile phone. The verification result can then be securely shared among multiple financial institutions without repeatedly collecting user identity information. This not only meets the requirements of financial institutions for strong identity authentication but also significantly improves user convenience, reduces repetitive work in identity verification across multiple institutions, and optimizes customer experience. Financial institutions can provide more flexible and user-friendly services while ensuring business security. The main problems addressed are as follows: First, it enhances the security of identity verification. This invention introduces "real person + real certificate" identity verification capabilities and binds the activated digital identity to a trusted device through a two-layer identity verification method, improving the security and effectiveness of online identity verification. Second, it enhances user autonomy. The user's real identity information and related credentials are encrypted and stored locally on the user's device, returning control of the digital identity to the user. Third, it improves interoperability and convenience, allowing users to apply for identity credentials once and use them in multiple locations.

[0144] Embodiments of the present invention, such as Figure 11As shown, this embodiment of the invention provides an identity credential application device 500, applied to an applicant terminal. The device 500 includes a second identity verification request module 510, a distributed identity activation request module 520, an identity credential request module 530, and an identity credential receiving module 540.

[0145] The second authentication request module 510 is configured to send a second authentication request to the issuer so that the issuer can generate a second authentication result based on the second authentication request. The second authentication request includes the applicant's identity information and the applicant's biometric information. The applicant's identity information is obtained by the applicant's terminal from an external identity document through near-field communication.

[0146] The distributed identity activation request module 520 is configured to determine that the applicant's identity has been verified based on the second identity verification result sent by the issuer, send a distributed identity activation request to the distributed identity system, and receive the applicant's distributed identity identifier from the distributed identity system.

[0147] The identity credential request module 530 is configured to send an identity credential request to the issuer so that the issuer can generate the applicant's identity credential and upload the verification data of the applicant's identity credential to the credential permission chain. The identity credential request includes the applicant's distributed identity identifier, and the verification data includes the digest value of the applicant's identity credential.

[0148] The identity credential receiving module 540 is configured to receive the applicant's identity credential from the issuer, wherein the applicant's identity credential includes a declaration portion, which includes the applicant's distributed identity identifier.

[0149] In some embodiments of the present invention, the device 500 further includes a distributed identity activation request module 550. The distributed identity activation request module 550 is configured to respond to the applicant's distributed identity activation request operation, read the applicant's identity information from an external identity document via near-field communication, collect the applicant's biometric information, and send a first identity verification request to a trusted identity management agency based on the applicant's identity information and biometric information, so that the trusted identity management agency generates and returns a first identity verification result based on the first identity verification request, and determines that the applicant's identity verification is successful based on the first identity verification result.

[0150] In some embodiments of the present invention, the distributed identity activation request module 550 is configured as follows:

[0151] Generate the applicant's public key and private key based on the trusted environment within the applicant's terminal, and store the applicant's private key in the trusted environment;

[0152] A distributed identity activation request is generated based on the applicant's public key.

[0153] In some embodiments of the present invention, the identity credential application request also includes the applicant's public key, and the declaration section includes the applicant's public key.

[0154] In some embodiments of the present invention, the distributed identity activation request module 550 is further configured to generate a read information record after obtaining the applicant's identity information from an external identity document via near-field communication; the second identity verification request includes the read information record.

[0155] In some embodiments of the present invention, the second authentication result is generated according to the following steps:

[0156] Once the issuing authority determines that the applicant's identity information matches the information record, it will send the applicant's identity information and biometric information to a trusted identity management agency.

[0157] The trusted identity management authority generates a third-party authentication result based on the applicant's identity information and biometric information, and returns the third-party authentication result to the issuer.

[0158] The issuer generates a second authentication result based on the third authentication result.

[0159] In some embodiments of the present invention, the distributed identity activation request module 550 is further configured to encrypt and store the applicant's identity information and the applicant's biometric information.

[0160] In some embodiments of the present invention, the identity credential receiving module 540 is configured as follows:

[0161] Receive the credential generation notification sent by the issuer;

[0162] Download the applicant's identity credentials from the issuing authority.

[0163] In embodiments of the present invention, such as Figure 12 As shown, this embodiment of the invention provides an identity credential application device 600, applied to an issuer. The device 600 includes a second identity verification result generation module 610, an identity credential generation module 620, and a sending module 630, wherein...

[0164] The second authentication result generation module 610 is configured to receive a second authentication request sent by the applicant terminal, generate a second authentication result based on the second authentication request, and send the second authentication result to the applicant terminal. This allows the applicant terminal to determine that the applicant's authentication has been successful based on the second authentication result and then send a distributed identity activation request to the distributed identity system. The second authentication request includes the applicant's identity information and the applicant's biometric information. The applicant's identity information is obtained by the applicant terminal from an external identity document via near-field communication.

[0165] The identity credential generation module 620 is configured to receive the identity credential application request sent by the applicant terminal, generate the applicant's identity credential, and upload the verification data of the applicant's identity credential to the credential permission chain. The identity credential application request includes the applicant's distributed identity identifier, which is generated by the distributed identity system after receiving the distributed identity activation request sent by the applicant terminal. The verification data includes the digest value of the applicant's identity credential.

[0166] The sending module 630 is configured to send the applicant's identity credential to the applicant's terminal. The applicant's identity credential includes a declaration part, which includes the applicant's distributed identity identifier.

[0167] In some embodiments of the present invention, the verification data also includes the status of the applicant's identity credentials.

[0168] In some embodiments of the present invention, the second authentication request is generated according to the following steps:

[0169] In response to the applicant's distributed identity activation request, the applicant terminal reads the applicant's identity information from the external identity document via near-field communication and collects the applicant's biometric information. Based on the applicant's identity information and biometric information, it sends a first identity verification request to the trusted identity management authority, wherein the first identity verification request includes the applicant's identity information and the applicant's biometric information.

[0170] The trusted identity management authority generates a first authentication result based on the first authentication request and returns the first authentication result to the applicant terminal;

[0171] After determining that the applicant's identity verification is successful based on the first identity verification result, the applicant's terminal generates a second identity verification request.

[0172] In some embodiments of the present invention, the second authentication request further includes reading an information record, which is generated by the applicant terminal after obtaining the applicant's identity information from an external identity document via near-field communication; the second authentication result generation module 610 is further configured to:

[0173] If the applicant's identity information matches the information record, the applicant's identity information and biometric information are sent to a trusted identity management agency so that the trusted identity management agency can generate a third-party identity verification result based on the applicant's identity information and biometric information.

[0174] Receive the third authentication result returned by the trusted identity management authority, and generate the second authentication result based on the third authentication result.

[0175] In some embodiments of the present invention, the identity credential application request also includes the applicant's public key, and the declaration section also includes the applicant's public key.

[0176] In some embodiments of the present invention, the declaration portion further includes an identity information digest value, and the identity credential generation module 620 is configured to calculate the digest value of the applicant's identity information and / or the applicant's biometric information, and obtain the identity information digest value.

[0177] In some embodiments of the present invention, the declaration section further includes the credential issuance time and / or credential expiration time, and the identity credential generation module 620 is configured as follows:

[0178] Set the voucher issuance time based on the current time, and / or,

[0179] The credential expiration time is set to the earlier of the document expiration time and the applicant's public key expiration time, where the applicant's identity information includes the document expiration time.

[0180] In some embodiments of the present invention, the declaration section also includes a credential type.

[0181] In some embodiments of the present invention, the sending module 630 is configured as follows:

[0182] Send a certificate generation notification to the applicant terminal so that the applicant terminal can send a certificate download request to the issuer based on the certificate generation notification;

[0183] Based on the credential download request, the applicant's identity credential is transmitted to the applicant's terminal.

[0184] Embodiments of the present invention, such as Figure 13 As shown, this embodiment of the invention provides an identity credential verification device 700, applied to the verification party. The device 700 includes an identity verification request receiving module 710, a verification module 720, and a sending module 730, wherein...

[0185] The authentication request receiving module 710 is configured to receive authentication requests sent by the applicant terminal. The authentication request includes a verifiable identity credential representation, which includes identity credential related information and a credential signature generated by signing the identity credential related information with the applicant's private key. The identity credential related information includes the applicant's identity credential issued by the issuer. The applicant's identity credential includes a declaration part, which includes the applicant's distributed identity identifier. The applicant's distributed identity identifier is generated based on the applicant's public key after the applicant's identity information and biometric information have been verified. The applicant's identity information is read by the applicant terminal from an external identity document via near-field communication.

[0186] The verification module 720 is configured to verify verifiable representations of identity credentials and generate credential verification results.

[0187] The sending module 730 is configured to send the credential verification result to the applicant's terminal.

[0188] In some embodiments of the present invention, the applicant's identity credential also includes the credential issuance time and / or credential expiration time, and the verification module 720 is further configured as follows:

[0189] The validity period of the applicant's identity certificate is verified based on the current time, the certificate issuance time, and / or the certificate expiration time.

[0190] In some embodiments of the present invention, the declaration portion includes the applicant's public key, and the verification module 720 is further configured as follows:

[0191] The applicant's public key is obtained from the distributed identity system based on the applicant's distributed identity identifier;

[0192] Verify whether the applicant's public key in the applicant's identity credential matches the applicant's public key obtained from the distributed identity system. If they match, use the applicant's public key to verify the credential signature and generate a credential signature verification result.

[0193] Generate a voucher verification result based on the voucher signature verification result.

[0194] In some embodiments of the present invention, the verification module 720 is further configured as follows:

[0195] Based on the signature verification result, the signature verification is deemed successful, and a document digest value is generated based on the applicant's identity document.

[0196] Send the credential digest value to the credential permission chain so that the credential permission chain can obtain verification data based on the credential digest value and generate a credential integrity verification result based on the verification data. The verification data is generated by the issuer based on the applicant's identity credential after generating the applicant's identity credential, and the verification data includes the digest value of the applicant's identity credential.

[0197] Generate a credential verification result based on the credential integrity verification result sent by the credential permission chain.

[0198] In some embodiments of the present invention, the verification data also includes the status of the applicant's identity credentials, and the verification module 720 is further configured as follows:

[0199] Receive the credential status verification result returned by the credential permission chain, wherein the credential status verification result is generated by the credential permission chain based on the status of the applicant's identity credential;

[0200] Based on the credential status verification result, it is determined that the applicant's identity credential status verification has passed, and a credential verification result indicating that the verification has passed is generated.

[0201] In some embodiments of the present invention, the identity credential information further includes the applicant's identity information and / or the applicant's biometric information, and the declaration portion further includes an identity information digest value; the verification module 720 is also configured to,

[0202] Based on the credential integrity verification result, the identity credential integrity verification is deemed successful, and a business identity information digest value is generated based on the applicant's identity information and / or the applicant's biometric information.

[0203] The business identity information digest value is validated based on the identity information digest value, and a business identity information verification result is generated.

[0204] In some embodiments of the present invention, the declaration section includes a credential type, and the verification module 720 is further configured to:

[0205] Obtain the certificate type from the applicant's identity certificate and verify that the certificate type is a sticker certificate.

[0206] In some embodiments of the present invention, the apparatus 700 further includes a service processing module 740, configured as follows:

[0207] Receive a service processing request sent by the applicant terminal, wherein the service processing request is generated by the applicant terminal when the verification is successful based on the credential verification result;

[0208] Process business requests based on their requirements.

[0209] Embodiments of the present invention, such as Figure 14 As shown, this embodiment of the invention provides an identity credential verification device 800, applied to an applicant terminal. The device 800 includes a verifiable representation generation module 810, an identity verification request sending module 820, and a receiving module 830.

[0210] The verifiable representation generation module 810 is configured to obtain locally stored identity credential information and generate an identity credential verifiable representation based on the identity credential information. The identity credential verifiable representation includes identity credential information and a credential signature generated by signing the identity credential information with the applicant's private key. The identity credential information includes the applicant's identity credential issued by the issuer. The applicant's identity credential includes a declaration part, which includes the applicant's distributed identity identifier. The applicant's distributed identity identifier is generated based on the applicant's public key after the applicant's identity information and biometric information have been verified. The applicant's identity information is read from an external identity document by the applicant's terminal through near-field communication.

[0211] The authentication request sending module 820 is configured to send an authentication request to the authenticator, wherein the authentication request includes a verifiable representation of identity credentials;

[0212] The receiving module 830 is configured to receive the credential verification result sent by the verifier. The credential verification result is generated by the verifier after verifying the verifiable representation of the identity credential.

[0213] In some embodiments of the present invention, the declaration portion also includes a digest value of the applicant's identity information, and the identity credential information includes the applicant's identity information and / or the applicant's biometric information.

[0214] In some embodiments of the present invention, the declaration section also includes the applicant's public key.

[0215] In some embodiments of the present invention, the device 800 further includes a service processing request module 840, configured as follows:

[0216] If the verification result of the credential is deemed successful, a business processing request is sent to the verifier so that the verifier can process the business according to the request.

[0217] The device features of the embodiments of the present invention can be referred to the features of the methods and steps of the embodiments of the present invention, and the system embodiments can be combined with the features of the method embodiments to obtain new embodiments, and vice versa, and will not be repeated here.

[0218] An embodiment of the present invention provides an electronic device comprising: a processor and a memory storing a computer program, the processor being configured to implement any method according to an embodiment of the present invention when running the computer program. Additionally, means for implementing an embodiment of the present invention may also be provided.

[0219] Figure 15 An exemplary system architecture 1500 is shown that can be applied to the identity credential application, wallet authentication method or identity credential application, wallet authentication device of the present invention embodiments.

[0220] like Figure 15 As shown, system architecture 1500 may include terminal devices 1501, 1502, and 1503, network 1504, and server 1505. Network 1504 is used as a medium to provide a communication link between terminal devices 1501, 1502, and 1503 and server 1505. Network 1504 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0221] Users can use terminal devices 1501, 1502, and 1503 to interact with server 1505 via network 1504 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 1501, 1502, and 1503, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0222] Terminal devices 1501, 1502, and 1503 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0223] Server 1505 can be a server that provides various services, such as a backend management server that supports shopping websites browsed by users using terminal devices 1501, 1502, and 1503 (for example only). The backend management server can analyze and process data such as received product information query requests, and feed back the processing results (such as target push information and product information - for example only) to the terminal devices.

[0224] It should be noted that the identity credential application and wallet authentication methods provided in the embodiments of the present invention are generally executed by the server 1505, and correspondingly, the identity credential application and wallet authentication implementation device is generally set in the server 1505.

[0225] It should be understood that Figure 15 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0226] The following is for reference. Figure 16 It shows a schematic diagram of the structure of a computer system 1600 suitable for implementing terminal devices or servers of the present invention. The methods or apparatus for implementing the methods in the embodiments of the present invention can be implemented on the computer system 1600. Figure 16 The terminal device or server shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.

[0227] like Figure 16As shown, the computer system 1600 includes a central processing unit (CPU) 1601, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 1602 or programs loaded from storage portion 1608 into random access memory (RAM) 1603. The RAM 1603 also stores various programs and data required for the operation of the system 1600. The CPU 1601, ROM 1602, and RAM 1603 are interconnected via a bus 1604. An input / output (I / O) interface 1605 is also connected to the bus 1604.

[0228] The following components are connected to I / O interface 1605: an input section 1606 including a keyboard, mouse, etc.; an output section 1607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1608 including a hard disk, etc.; and a communication section 1609 including a network interface card such as a LAN card, modem, etc. The communication section 1609 performs communication processing via a network such as the Internet. A drive 1610 is also connected to I / O interface 1605 as needed. Removable media 1611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 1610 as needed so that computer programs read from them can be installed into storage section 1608 as needed.

[0229] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1609, and / or installed from removable medium 1611. When the computer program is executed by central processing unit (CPU) 1601, it performs the functions defined above in the system of this invention.

[0230] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0231] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0232] The units or modules described in the embodiments of the present invention can be implemented in software or hardware. The described units or modules can also be housed in a processor; for example, a processor can be described as including a sending unit (or "module"), an acquisition unit, a determining unit, and a first processing unit. The names of these units or modules do not necessarily limit the specific unit or module itself; for example, a sending unit can also be described as "a unit that sends an image acquisition request to a connected server."

[0233] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to perform the identity credential application and wallet authentication methods described in the above embodiments.

[0234] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. An identity credential application method characterized by, Applied to an applicant terminal, the method comprises: sending a second identity authentication request to an issuing party to enable the issuing party to generate a second identity authentication result according to the second identity authentication request, wherein the second identity authentication request comprises applicant identity information and applicant biometric information, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode; judging that the applicant identity authentication is passed according to the second identity authentication result sent by the issuing party, sending a distributed identity opening request to a distributed identity system, and receiving an applicant distributed identity identifier from the distributed identity system; sending an identity credential application request to the issuing party to enable the issuing party to generate an applicant identity credential and upload verification data of the applicant identity credential to a credential permission chain, wherein the identity credential application request comprises the applicant distributed identity identifier, and the verification data comprises a digest value of the applicant identity credential; receiving the applicant identity credential from the issuing party, wherein the applicant identity credential comprises a declaration part, and the declaration part comprises the applicant distributed identity identifier.

2. The method of claim 1, wherein, Before sending the second identity authentication request to the issuing party, the method further comprises: in response to the distributed identity opening request operation of the applicant, reading the applicant identity information from the external identity certificate through the near field communication mode and collecting the applicant biometric information, sending a first identity authentication request to a trusted identity management institution according to the applicant identity information and the applicant biometric information to enable the trusted identity management institution to generate and return a first identity authentication result according to the first identity authentication request, and judging that the applicant identity authentication is passed according to the first identity authentication result.

3. The method of claim 1, wherein, The sending of the distributed identity opening request to the distributed identity system comprises: generating an applicant public key and an applicant private key according to a trusted environment in the applicant terminal, and saving the applicant private key in the trusted environment; generating the distributed identity opening request according to the applicant public key.

4. The method of claim 3, wherein, The identity credential application request further comprises the applicant public key, and the declaration part comprises the applicant public key.

5. The method of claim 2, wherein, The method further comprises: after obtaining the applicant identity information from the external identity certificate through the near field communication mode, generating a reading information record; and the second identity authentication request comprises the reading information record.

6. The method of claim 5, wherein, The second identity authentication result is generated according to the following steps, the issuing party judges that the applicant identity information matches the reading information record, and sends the applicant identity information and the applicant biometric information to a trusted identity management institution; the trusted identity management institution generates a third identity authentication result according to the applicant identity information and the applicant biometric information, and returns the third identity authentication result to the issuing party; the issuing party generates the second identity authentication result according to the third identity authentication result.

7. The method of claim 2, wherein, The method further comprises: encrypting and storing the applicant identity information and the applicant biometric information.

8. The method of claim 1, wherein, The receiving of the applicant identity credential from the issuing party comprises: receiving a credential generation notification sent by the issuing party; download the applicant identity credential from the issuing party.

9. An identity credential application method characterized by, The method applied to the issuing party comprises: receiving a second identity authentication request sent by the applicant terminal, generating a second identity authentication result according to the second identity authentication request, and sending the second identity authentication result to the applicant terminal, so that the applicant terminal sends a distributed identity opening request to the distributed identity system after judging that the applicant identity authentication is passed according to the second identity authentication result, wherein the second identity authentication request comprises applicant identity information and applicant biological feature information, and the applicant identity information is read from an external identity certificate by the applicant terminal through near field communication; receiving an identity credential application request sent by the applicant terminal, generating an applicant identity credential, and uploading verification data of the applicant identity credential to a credential permission chain, wherein the identity credential application request comprises the applicant distributed identity, the applicant distributed identity is generated by the distributed identity system after receiving the distributed identity opening request sent by the applicant terminal, and the verification data comprises a digest value of the applicant identity credential; sending the applicant identity credential to the applicant terminal, wherein the applicant identity credential comprises a declaration part, and the declaration part comprises the applicant distributed identity.

10. The method of claim 9, wherein, The verification data further comprises a state of the applicant identity credential.

11. The method of claim 9, wherein, The second identity authentication request is generated according to the following steps, the applicant terminal reads the applicant identity information from the external identity certificate through near field communication in response to the distributed identity opening request operation of the applicant, collects the applicant biological feature information, and sends a first identity authentication request to the trusted identity management institution according to the applicant identity information and the applicant biological feature information, wherein the first identity authentication request comprises the applicant identity information and the applicant biological feature information; the trusted identity management institution generates a first identity authentication result according to the first identity authentication request, and returns the first identity authentication result to the applicant terminal; the applicant terminal generates the second identity authentication request after judging that the applicant identity authentication is passed according to the first identity authentication result.

12. The method of claim 11, wherein, The second identity authentication request further comprises read information record, which is generated by the applicant terminal after obtaining the applicant identity information from the external identity certificate through near field communication; The second identity authentication result is generated according to the second identity authentication request, comprising: judging that the applicant identity information matches the read information record, sending the applicant identity information and the applicant biological feature information to the trusted identity management institution, so that the trusted identity management institution generates a third identity authentication result according to the applicant identity information and the applicant biological feature information; receiving the third identity authentication result returned by the trusted identity management institution, and generating the second identity authentication result according to the third identity authentication result.

13. The method of claim 9, wherein, The identity credential application request further comprises an applicant public key, and the declaration part further comprises the applicant public key.

14. The method of claim 9, wherein, The statement part further includes an identity information digest value, the generating the applicant identity credential includes: calculating a digest value of the applicant identity information and / or the applicant biometric information, and obtaining the identity information digest value.

15. The method of claim 9, wherein, The statement part further includes a credential issuance time and / or a credential expiration time, and the generating the applicant identity credential further includes: setting the credential issuance time according to a current time, and / or setting the credential expiration time as an earlier time of the certificate expiration time and an expiration time of the applicant public key, wherein the applicant identity information includes the certificate expiration time.

16. The method of claim 9, wherein, The statement part further includes a credential type.

17. The method of claim 9, wherein, The sending the applicant identity credential to the applicant terminal includes: sending a credential generation notification to the applicant terminal, so that the applicant terminal sends a credential download request to the issuing party according to the credential generation notification; transmitting the applicant identity credential to the applicant terminal according to the credential download request.

18. An identity credential application apparatus, comprising: Applied to an applicant terminal, the device includes a second identity verification request module, a distributed identity opening request module, an identity credential request module, and an identity credential receiving module, wherein The second identity verification request module is configured to send a second identity verification request to the issuing party, so that the issuing party generates a second identity verification result according to the second identity verification request, wherein the second identity verification request includes applicant identity information and applicant biometric information, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode; The distributed identity opening request module is configured to determine that the applicant identity verification is passed according to the second identity verification result sent by the issuing party, send a distributed identity opening request to a distributed identity system, and receive an applicant distributed identity identifier from the distributed identity system; The identity credential request module is configured to send an identity credential application request to the issuing party, so that the issuing party generates an applicant identity credential and uploads verification data of the applicant identity credential to a credential permission chain, wherein the identity credential application request includes the applicant distributed identity identifier, and the verification data includes a digest value of the applicant identity credential; The identity credential receiving module is configured to receive an applicant identity credential from the issuing party, wherein the applicant identity credential includes a statement part, and the statement part includes an applicant distributed identity identifier.

19. An identity credential application apparatus, comprising: Applied to an issuing party, the device includes a second identity verification result generation module, an identity credential generation module, and a sending module, wherein The second identity verification result generation module is configured to generate a second identity verification result according to a second identity verification request, wherein the second identity verification request includes applicant identity information and applicant biometric information, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode; The identity credential generation module is configured to generate an applicant identity credential according to the second identity verification result, and upload verification data of the applicant identity credential to a credential permission chain, wherein the verification data includes a digest value of the applicant identity credential; The sending module is configured to send the applicant identity credential to the applicant terminal. The second identity authentication result generation module is configured to receive a second identity authentication request sent by the applicant terminal, generate a second identity authentication result according to the second identity authentication request, and send the second identity authentication result to the applicant terminal, so that the applicant terminal sends a distributed identity opening request to the distributed identity system after judging that the identity authentication of the applicant is passed according to the second identity authentication result, wherein the second identity authentication request comprises applicant identity information and applicant biological feature information, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode. The identity credential generation module is configured to receive an identity credential application request sent by the applicant terminal, generate an applicant identity credential, and upload verification data of the applicant identity credential to a credential permission chain, wherein the identity credential application request comprises the applicant distributed identity identifier, the applicant distributed identity identifier is generated by the distributed identity system after receiving the distributed identity opening request sent by the applicant terminal, and the verification data comprises a digest value of the applicant identity credential. The sending module is configured to send the applicant identity credential to the applicant terminal, wherein the applicant identity credential comprises a declaration part, and the declaration part comprises the applicant distributed identity identifier.

20. An electronic device, comprising: comprise: one or more processors; a memory device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1-17.

21. A computer readable medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the method of any one of claims 1-17.