Distributed digital identity identification method and device, distributed digital identity authentication method and device, equipment and medium
By generating hash identity identifiers through hash generation and distributed digital identity identifiers through the Pedersen commitment algorithm, combined with zero-knowledge proofs, the problem of insufficient privacy protection in the DID method is solved, achieving higher identity authentication security and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-24
- Publication Date
- 2026-03-17
AI Technical Summary
Existing distributed digital identity (DID) methods are insufficient in terms of privacy protection. Attackers can infer the true identity of an entity by analyzing publicly available data on the blockchain, leading to identity leakage and low security.
By concatenating the entity's identity type and identifier and then hashing to generate a hash identity (HID), and combining this with the Pedersen commitment algorithm based on the base point parameters of an elliptic curve to generate a distributed digital identity (DID), and using zero-knowledge proofs for authentication during the authentication phase, a secure correspondence between HID and DID is ensured.
It effectively hides the original identity information, prevents identity leakage and reverse attacks, and improves the security and privacy protection of identity authentication.
Smart Images

Figure CN121690818A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of computer technology, and particularly relates to a distributed digital identity identification and authentication method, device, equipment and medium. BACKGROUND
[0002] With the rapid development of the Internet and blockchain technology, as a decentralized identity management solution, Decentralized Identifier (DID) plays an increasingly important role in the field of computer technology. DID allows entities (such as individuals, organizations or devices) to autonomously manage and control their digital identities without the need for centralized authorities, and is widely used in digital authentication, data privacy protection, Internet of Things and financial technology scenarios. It combines cryptographic algorithms (such as hash functions and elliptic curve encryption) with the immutability of blockchain, aiming to achieve the uniqueness, verifiability and security of identity, thereby providing a foundation for digital transformation.
[0003] Currently, the mainstream DID method follows the syntax specification developed by the W3C consortium, and its basic structure is a combination of "did:", method name method-name and method-specific-id. For example, in some scenarios, method-specific-id usually directly uses a randomly generated string, hash value or blockchain address as an identifier. This generation rule relies on the randomness of the algorithm to ensure uniqueness, but lacks semantic meaning.
[0004] A core problem exists in the prior art: insufficient privacy protection capability. Since method-specific-id is often based on plaintext or reversibly derived elements (such as hash values or addresses), attackers may infer the real identity of the entity by analyzing the public data on the blockchain, leading to identity leakage and abuse, and thus the security is low. SUMMARY
[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a distributed digital identity identification and authentication method, device, equipment and medium.
[0006] The present disclosure provides a distributed digital identity identification and authentication method, which comprises: connecting the identity type and the identity identifier of the entity and then calculating a hash identity identifier that uniquely identifies the entity through a hash function, wherein a one-to-one correspondence is established between the hash identity identifier and the entity.
[0007] The distributed digital identity is generated based on a base point parameter of an elliptic curve by using a Pedersen commitment algorithm and a public-private key pair of the entity, and a document of the generated distributed digital identity is stored in a blockchain, wherein a one-to-many correspondence is established between the distributed digital identity and the hash identity.
[0008] In the authentication stage, the prover selects a random number and calculates a scalar product with the base point parameter as a commitment value, and a challenge value is generated by calculating the base point parameter, the distributed digital identity, the public key in the public-private key pair, the commitment value and a message by using a hash function.
[0009] A first product of the challenge value and a private key in the public-private key pair is determined, a first difference between the random number and the first product is calculated as a response value, and the challenge value and the response value are sent to the verifier.
[0010] After the verifier obtains the public key from the blockchain, a reconstructed challenge value is obtained by reconstructing calculation of the response value and the scalar product of the base point parameter, the challenge value and the scalar product of the distributed digital identity and the base point parameter, and the reconstructed challenge value is verified.
[0011] The disclosure also provides a distributed digital identity identification and authentication device, which comprises: A first generation unit is configured to connect the identity type and the identity identifier of the entity and generate a hash identity of the entity by using a hash function, and a one-to-one correspondence is established between the hash identity and the entity; A second generation unit is configured to generate a distributed digital identity by using a Pedersen commitment algorithm based on a base point parameter of an elliptic curve and a public-private key pair of the entity, and store a document of the generated distributed digital identity in a blockchain, wherein a one-to-many correspondence is established between the distributed digital identity and the hash identity; A third generation unit is configured to select a random number and calculate a scalar product with the base point parameter as a commitment value in the authentication stage, and generate a challenge value by calculating the base point parameter, the distributed digital identity, the public key in the public-private key pair, the commitment value and a message by using a hash function; A determination unit is configured to determine a first product of the challenge value and a private key in the public-private key pair, calculate a first difference between the random number and the first product as a response value, and send the challenge value and the response value to the verifier; A verification unit is configured to obtain a reconstructed challenge value by reconstructing calculation of the response value and the scalar product of the base point parameter, the challenge value and the scalar product of the distributed digital identity and the base point parameter after the verifier obtains the public key from the blockchain, and verify the reconstructed challenge value.
[0012] The embodiment of the present disclosure further provides a computing device, comprising: a processor; a memory for storing executable instructions of the processor; the processor is used for reading the executable instructions from the memory and executing the instructions to realize the identification and authentication method of distributed digital identity provided by the embodiment of the present disclosure.
[0013] The embodiment of the present disclosure further provides a computer readable storage medium, which stores a computer program, and the computer program is used for executing the identification and authentication method of distributed digital identity provided by the embodiment of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0014] The above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent upon consideration of the following detailed description, taken in conjunction with the accompanying drawings. Throughout the drawings, like or similar reference numerals are used to refer to like or similar elements. It should be understood that the drawings are schematic and elements depicted are not necessarily shown to scale.
[0015] Figure 1 A flowchart of the identification and authentication method of distributed digital identity provided by the embodiment of the present disclosure; Figure 2 A structure diagram of the identification and authentication device of distributed digital identity provided by the embodiment of the present disclosure; Figure 3 A structure diagram of the computing device provided by the embodiment of the present disclosure. DETAILED DESCRIPTION
[0016] Embodiments of the present disclosure will be described in greater detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms, and should not be interpreted as being limited to the embodiments set forth herein, but rather these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes, and are not intended to limit the scope of protection of the present disclosure.
[0017] It should be understood that each step recorded in the method embodiment of the present disclosure can be executed in different order and / or in parallel. In addition, the method embodiment can include additional steps and / or omit the execution of the steps shown. The scope of the present disclosure is not limited in this respect.
[0018] As used herein, the term "includes" and its variants are to be read to be analogous to "comprises," "comprising," "includes," "including," and "has," "having," "contains" or "containing." The term "based on" is to be interpreted as "based, at least in part, on." The term "one embodiment" means "at least one embodiment." The term "another embodiment" means "at least one additional embodiment." The term "some embodiments" means "at least some embodiments." Related definitions are given throughout the description below.
[0019] It should be noted that the terms "first", "second", and the like in the present disclosure are merely intended to distinguish different devices, modules or units, and do not imply the sequence of execution of the functions of these devices, modules or units or the mutual dependency of these devices, modules or units.
[0020] It should be noted that the terms "one", "multiple" in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that "one" or "multiple" should be understood as "one or more" unless otherwise explicitly indicated in the context.
[0021] The names of the messages or information exchanged between the plurality of devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.
[0022] With the rapid development of the Internet and blockchain technology, Decentralized Identifier (DID) as a decentralized identity management solution plays an increasingly important role in the field of computer technology. DID allows entities such as individuals, organizations or devices to autonomously manage and control their digital identities without the need for centralized authorities, and is widely used in digital authentication, data privacy protection, Internet of Things and financial technology scenarios. It combines cryptographic algorithms such as hash functions and elliptic curve encryption with the immutability of blockchain, aiming to achieve the uniqueness, verifiability and security of identity, thereby providing a foundation for digital transformation. However, as the application scenarios expand, the privacy protection and authentication mechanism of DID face new challenges, and more efficient technical solutions are urgently needed.
[0023] Currently, the mainstream DID method follows the syntax specification developed by the W3C consortium, and its basic structure is a combination of "did:", method name and method-specific-id. For example, in some scenarios, the method-specific-id usually directly uses a randomly generated string, hash value or blockchain address as an identifier, and this generation rule relies on the randomness of the algorithm to ensure uniqueness, but lacks semantic meaning.
[0024] Specifically, the W3C standard only specifies the syntactic framework of DIDs (such as ABNF rules), while the content of method-specific IDs is defined by each implementation. This leads to existing methods focusing primarily on the generation and storage of identifiers, without deeply integrating privacy enhancement mechanisms. This design causes DIDs to directly expose raw identity data during generation or use traceable addresses, making it difficult to hide sensitive information about the entity. In other words, existing technologies suffer from a core problem: insufficient privacy protection. Because method-specific IDs are often based on plaintext or reversibly deducible elements (such as hash values or addresses), attackers may analyze publicly available data on the blockchain to infer the entity's true identity, leading to identity leakage and abuse, thus resulting in low security for identity authentication.
[0025] This application achieves uniqueness by concatenating the entity's identity type and identifier to generate a hash identity (HID), thus hiding original sensitive information. This ensures the uniqueness of the generated HID for each entity and avoids directly exposing identity data. Secondly, it utilizes the Pedersen commitment algorithm based on elliptic curve base point parameters to generate a distributed digital identity (DID). The DID is stored as a commitment value on the blockchain. Leveraging the information-theoretic security properties of Pedersen commitments, the DID is public but cannot be used to deduce the HID or private key, effectively preventing identity leakage and reverse engineering attacks. Finally, in the authentication phase, zero-knowledge proofs are incorporated, using a challenge-response mechanism to verify identity ownership without disclosing private information, further strengthening privacy protection. The entire scheme, through the generation and commitment mechanisms of HID and DID, fundamentally solves the privacy vulnerability problem while ensuring authenticability, improving the security of identity authentication.
[0026] To address the aforementioned issues, this disclosure provides a method for identifying and verifying distributed digital identities. The method will be described below with reference to specific embodiments.
[0027] Figure 1 This is a flowchart illustrating a distributed digital identity identification and authentication method provided in an embodiment of this disclosure. The method can be executed by a distributed digital identity identification and authentication device, which can be implemented in software and / or hardware, and is generally integrated into a computing device. Figure 1 As shown, the method includes: S101, after concatenating the entity's identity type and identity identifier, a hash identity identifier that uniquely identifies the entity is generated by calculating a hash function.
[0028] The computing device concatenates the entity's identity type and identity identifier, and then uses a hash function to generate a hash identity identifier that uniquely identifies the entity.
[0029] This requires clearly defining the entity's identity type (IDType) and identity identifier (ID). The identity type distinguishes the entity's category, such as a resident ID card, while the identity identifier is a string that uniquely identifies the entity within that type, such as a resident's ID card number. Next, a hash function (HASH) is used to concatenate these two elements into a longer, composite string containing complete identity semantics. This composite string is then used as input and processed by a cryptographically secure hash function. This hash function irreversibly maps an input of arbitrary length to a fixed-length, seemingly random digest value. The output of this calculation process is called the Hash Identity Identifier (HID).
[0030] The specific formula can be as follows: ; Through this design, HID can not only uniquely correspond to the original entity, ensuring the determinacy of the identifier, but more importantly, it can effectively hide sensitive information such as the original identity type and identifier, laying a solid foundation for the subsequent construction of a distributed digital identity with privacy protection features, and realizing a one-to-one correspondence between entities and HID.
[0031] S102, using the hash identity identifier and the entity's public / private key pair, a distributed digital identity identifier is generated based on the base point parameters of an elliptic curve using the Pedersen commitment algorithm, and the generated distributed digital identity identifier document is stored in the blockchain.
[0032] Computing devices can use hash identity identifiers and public / private key pairs of entities to generate distributed digital identity identifiers based on the base point parameters of elliptic curves using the Pedersen commitment algorithm, and store the generated distributed digital identity identifier documents in the blockchain.
[0033] For example, the computing device can compute the first scalar product sk of the private key sk in the public-private key pair and the first elliptic curve base point H. H, calculate hash identity identifier HID The second scalar product with the base point G of the second elliptic curve HID G A distributed digital identity is generated based on the sum of the first scalar product and the second scalar product, wherein the base points of the first and second elliptic curves are preset parameters of the elliptic curves.
[0034] The specific formula is as follows:
[0035] in, This refers to the result generated after making a cryptographic commitment to a hash identity using the Pedersen commitment algorithm.
[0036] This structure makes the DID a commitment to the HID and private key: it is presented externally as a random point on an elliptic curve, effectively hiding the original HID and private key information, providing information-theoretic security for privacy. Simultaneously, an entity possessing the correct private key and HID can prove to a verifier that it knows the secret hidden by this commitment, thus completing authentication. After generating the DID, it can be encapsulated along with the corresponding public key and other metadata into a distributed digital identity document, stored on the blockchain for notarization and public verification. This establishes a crucial one-to-many correspondence between entities, HIDs, and DIDs: one entity corresponds to one HID, but this HID can be combined with different private keys (key rotation) to generate multiple different DIDs, enhancing privacy and flexibility while ensuring authenticability.
[0037] S103, during the authentication phase, the proving party selects a random number and calculates its scalar product with the base point parameter as the commitment value. It then uses a hash function to calculate a challenge value based on the base point parameter, the distributed digital identity, the public key in the public-private key pair, the commitment value, and the message. The proving party determines the first product of the challenge value and the private key in the public-private key pair, calculates the first difference between the random number and the first product as the response value, and sends the challenge value and the response value to the verifying party.
[0038] For example, the core of this step is for the proving party to prove to the verifying party that it does indeed possess the secret corresponding to the distributed digital identity without revealing its private key and hash identity. Its technical essence is a non-interactive zero-knowledge proof constructed based on the Schnorr protocol and the Fiat-Shamir heuristic.
[0039] First, the proving party needs to initiate an authentication session. For this, it can randomly select a secure random number r. Then, it can use this random number to perform scalar product operations with the two publicly known elliptic curve base point parameters (i.e., the first elliptic curve base point H and the second elliptic curve base point G), generating two commitment values: the first commitment value Q1 = r is determined based on the third scalar product of the random number r and the first elliptic curve base point. H, and the second commitment value Q2=r is determined based on the fourth scalar product of the random number and the base point of the second elliptic curve. G.
[0040] These two commitment values pledge to this specific proof session; their randomness ensures the freshness of each proof and prevents replay attacks. Following this, the crucial challenge value generation phase can begin. To transform the interactive protocol into a non-interactive one, the proving party can use a hash function to simulate the verifying party's challenge generation behavior. It concatenates all publicly available parameters involved in this proof, along with an optional message (which may include a timestamp), as input to the hash function. These inputs include the base points H and G, the distributed digital identity (DID) to be proven, the public key PK verifiable on the blockchain, the two commitment values Q1 and Q2 just calculated, and the message m. By hashing this combination, a fixed-length challenge value c is generated.
[0041] The specific formula can be as follows: ; in, This represents a hash function.
[0042] The prover can then compute the response value. This process involves two key operations: First, the product of the challenge value c and the prover's private key PK is calculated; this is the first product c. sk. Next, calculate the difference between the previously selected random number and this first product, i.e., the first difference s=r. c sk, this result is the response value. Finally, the proving party sends the core parameter challenge value and response value generated from this proof to the validating party.
[0043] S104 After obtaining the public key from the blockchain, the verifier performs a reconstruction calculation using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to obtain the reconstruction challenge value and verify the reconstruction challenge value.
[0044] This step is crucial for the verifier to reconstruct the proof and ultimately confirm the legitimacy of the verifier's identity. The verifier can use the parameters disclosed by the verifier and publicly available data on the blockchain to recalculate the challenge value and verify its validity through comparison.
[0045] For example, the verifier can first obtain the public key PK claimed by the prover in connection with the authentication from the blockchain. The verifier can then perform a reconstruction computation, a process designed to reproduce the computations performed by the prover when generating the commitment value.
[0046] Specifically, the verifier performs the following operations: Determine the second product HID of the hash identity identifier and the base point of the second elliptic curve. G, determine the second difference between the distributed digital identity and the second product, DID-HID. G, determine the third product c of the challenge value and the second difference. (DID-HID) G).
[0047] Calculate the scalar product s of the response value and the base point of the first elliptic curve. H, the first verification value is determined by the sum of the fifth scalar product and the third product. .
[0048] The specific formula is as follows: ; Determine the fourth product c of the challenge value and the public key. PK determines the sixth scalar product s of the response value and the base point of the second elliptic curve. G, calculate the second verification value based on the sum of the sixth scalar product and the fourth product. .
[0049] The specific formula is as follows:
[0050] Based on the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity, the public key, the first verification value, the second verification value, and the message m, the reconstruction challenge value is calculated using a hash function. ; ; After completing the above reconstruction, the verifier performs the most crucial step: obtaining the reconstruction challenge value. It uses the exact same hash function as the prover, concatenating the same public parameters (base point parameters, distributed digital identity, and public key, etc.), the reconstructed commitment values (here called the first and second verification values), and the same message in the same order, and then calculates the hash value. Finally, the verifier performs verification: comparing the calculated reconstruction challenge value with the original challenge value received from the prover. If they are exactly equal, authentication passes. This is because all parameters can only match if the prover actually possesses the private key corresponding to the DID and public key, and the correct HID, ensuring that the reconstructed challenge value matches the original challenge value. This ultimately proves the prover's ownership of the distributed digital identity.
[0051] In some possible implementations, this application can also verify the validity of timestamps; If the timestamp is valid, the reconstruction calculation operation can be performed.
[0052] For example, when generating a knowledge signature, the proving party embeds a timestamp containing the current moment into the message used as input to the hash function. When the verifying party receives the proof parameters, it first parses the message and extracts the timestamp, checking whether it is within a reasonable and valid time window (e.g., whether it deviates too much from the verifying party's current time or has expired). If the timestamp is invalid (e.g., expired or future time), the verification process terminates immediately, and authentication fails. This measure aims to effectively defend against replay attacks and ensure the freshness and uniqueness of each proof session. Only when the timestamp is valid, confirming that the proof request was recently generated and not reused, will the verifying party continue with subsequent key operations: using the scalar product of the response value and the base point parameter received from the proving party, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to perform reconstruction calculations, and finally, by comparing the reconstructed challenge value with the original challenge value, to complete the final determination of identity authentication.
[0053] This application achieves uniqueness by concatenating the entity's identity type and identifier to generate a hash identity (HID), thus hiding original sensitive information. This ensures the uniqueness of the generated HID for each entity and avoids directly exposing identity data. Secondly, it utilizes the Pedersen commitment algorithm based on elliptic curve base point parameters to generate a distributed digital identity (DID). The DID is stored as a commitment value on the blockchain. Leveraging the information-theoretic security properties of Pedersen commitments, the DID is public but cannot be used to deduce the HID or private key, effectively preventing identity leakage and reverse engineering attacks. Finally, in the authentication phase, zero-knowledge proofs are incorporated, using a challenge-response mechanism to verify identity ownership without disclosing private information, further strengthening privacy protection. The entire scheme, through the generation and commitment mechanisms of HID and DID, fundamentally solves the privacy vulnerability problem while ensuring authenticability, improving the security of identity authentication.
[0054] To implement the above embodiments, this disclosure also proposes a distributed digital identity identification and authentication device.
[0055] Figure 2 This is a schematic diagram of a distributed digital identity identification and authentication device provided in an embodiment of this disclosure. The device can be implemented by software and / or hardware, and is generally integrated into a computing device. Figure 2 As shown, the device includes: a first generation unit 210, a second generation unit 220, a third generation unit 230, a determination unit 240, and a verification unit 250, wherein, The first generation unit is used to concatenate the identity type and identity identifier of an entity and then calculate a hash identity identifier that uniquely identifies the entity through a hash function. The hash identity identifier establishes a one-to-one correspondence with the entity. The second generation unit is used to generate a distributed digital identity based on the base point parameters of an elliptic curve using the public-private key pair of the hash identity and the entity through the Pedersen commitment algorithm, and to store the generated distributed digital identity document in the blockchain. A one-to-many correspondence is established between the distributed digital identity and the hash identity. The third generation unit is used in the authentication phase, whereby the prover selects a random number and calculates a scalar product with the base point parameter as the commitment value, and generates a challenge value by using a hash function to calculate the base point parameter, the distributed digital identity identifier, the public key in the public-private key pair, the commitment value, and the message. The determining unit is used to determine the challenge value and the first product of the private key in the public-private key pair, calculate the first difference between the random number and the first product as the response value, and send the challenge value and the response value to the verifier. The verification unit is used to verify the reconstruction challenge value by performing a reconstruction calculation on the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter after the verifier obtains the public key from the blockchain, and then verifies the reconstruction challenge value.
[0056] Optionally, the first generating unit is specifically used for: Calculate the first scalar product between the private key in the public-private key pair and the first elliptic curve base point, calculate the second scalar product between the hash identity and the second elliptic curve base point, and generate a distributed digital identity based on the sum of the first and second scalar products. The first and second elliptic curve base points are preset parameters of the elliptic curve.
[0057] Optionally, the third generation unit is specifically used for: A random number is determined; a first commitment value is determined based on the third scalar product of the random number and the base point of the first elliptic curve; and a second commitment value is determined based on the fourth scalar product of the random number and the base point of the second elliptic curve. The challenge value is calculated by using the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity identifier, the public key in the public-private key pair, the first commitment value, the second commitment value, and the message as inputs to the hash function.
[0058] Optional, verification unit, specifically used for: Obtain the public key corresponding to the distributed digital identity from the blockchain; Determine the second product of the hash identity identifier and the base point of the second elliptic curve, determine the second difference between the distributed digital identity identifier and the second product, and determine the third product of the challenge value and the second difference; Calculate the fifth scalar product between the response value and the base point of the first elliptic curve, and use the sum of the fifth scalar product and the third product to determine the first verification value; Determine the fourth product of the challenge value and the public key, determine the sixth scalar product of the response value and the base point of the second elliptic curve, and calculate the second verification value based on the sum of the sixth scalar product and the fourth product; Based on the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity identifier, the public key, the first verification value, the second verification value, and the message, the reconstruction challenge value is calculated using a hash function; Verify whether the reconstruction challenge value is consistent with the challenge value sent by the prover; if they are consistent, the authentication is successful.
[0059] Optional, verification unit, specifically used for: Verify the validity of the timestamp; If the timestamp is valid, then the reconstruction calculation is performed using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter.
[0060] The distributed digital identity identification and authentication device provided in this disclosure can execute the distributed digital identity identification and authentication method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of the method execution.
[0061] To implement the above embodiments, this disclosure also proposes a computer program product, including a computer program / instruction, which, when executed by a processor, implements the distributed digital identity identification and authentication method in the above embodiments.
[0062] Figure 3 This is a schematic diagram of the structure of a computing device provided in an embodiment of the present disclosure.
[0063] The following is a detailed reference. Figure 3 The diagram illustrates a structural schematic suitable for implementing the computing device 300 in the embodiments of this disclosure. The computing device 300 in the embodiments of this disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 3 The computing device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0064] like Figure 3As shown, the computing device 300 may include a processor (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 302 or a program loaded from memory 308 into random access memory (RAM) 303. The RAM 303 also stores various programs and data required for the operation of the computing device 300. The processor 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0065] Typically, the following devices can be connected to I / O interface 305: input devices 306 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 307 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 308 including, for example, magnetic tapes, hard disks, etc.; and communication devices 309. Communication device 309 allows computing device 300 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 3 A computing device 300 with various devices is shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.
[0066] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 309, or installed from memory 308, or installed from ROM 302. When the computer program is executed by processor 301, it performs the functions defined in the distributed digital identity identification and authentication method of embodiments of this disclosure.
[0067] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0068] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0069] The aforementioned computer-readable medium may be included in the aforementioned computing device; or it may exist independently and not assembled into the computing device.
[0070] The aforementioned computer-readable medium carries one or more programs, which, when executed by the computing device, cause the computing device to perform the aforementioned distributed digital identity identification and authentication method.
[0071] The computing device can be programmed with computer program code in one or more programming languages or a combination thereof to perform the operations of this disclosure. These programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0072] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0073] The units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units are not, in some cases, intended to limit the specific unit.
[0074] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0075] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0076] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0077] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0078] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A method for identification and authentication of distributed digital identity, characterized in that, The application comprises: connecting the identity type and the identity identifier of an entity to generate a hash identity identifier of the entity through a hash function, and establishing a one-to-one correspondence between the hash identity identifier and the entity; using the hash identity identifier and a public-private key pair of the entity, generating a distributed digital identity identifier based on a base point parameter of an elliptic curve through a Pedersen commitment algorithm, and storing the generated distributed digital identity identifier document in a blockchain, and establishing a one-to-many correspondence between the distributed digital identity identifier and the hash identity identifier; in the authentication stage, a prover selects a random number and calculates a scalar product of the base point parameter as a commitment value, and calculates a challenge value through a hash function based on the base point parameter, the distributed digital identity identifier, a public key in the public-private key pair, the commitment value and a message; determining a first product of the challenge value and a private key in the public-private key pair, calculating a first difference value between the random number and the first product as a response value, and sending the challenge value and the response value to a verifier; after the verifier obtains the public key from the blockchain, the verifier reconstructs and calculates the response value and the scalar product of the base point parameter, the challenge value and the scalar product of the distributed digital identity identifier and the base point parameter to obtain a reconstructed challenge value, and verifies the reconstructed challenge value.
2. The method of claim 1, wherein, The distributed digital identity identifier is generated through the Pedersen commitment algorithm, comprising: calculating a first scalar product of a private key in the public-private key pair and a first elliptic curve base point, calculating a second scalar product of the hash identity identifier and a second elliptic curve base point, and generating a distributed digital identity identifier according to the sum of the first scalar product and the second scalar product, wherein the first elliptic curve base point and the second elliptic curve base point are preset parameters of the elliptic curve.
3. The method of claim 1, wherein, The prover selects a random number and calculates a scalar product of the base point parameter as a commitment value, and calculates a challenge value through a hash function based on the base point parameter, the distributed digital identity identifier, a public key in the public-private key pair, the commitment value and a message, comprising: determining a random number, determining a first commitment value according to a third scalar product of the random number and a first elliptic curve base point, and determining a second commitment value according to a fourth scalar product of the random number and a second elliptic curve base point; calculating the challenge value by taking the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity identifier, the public key in the public-private key pair, the first commitment value, the second commitment value and the message as inputs of the hash function.
4. The method of claim 3, wherein, After the verifier obtains the public key from the blockchain, the verifier reconstructs and calculates the response value and the scalar product of the base point parameter, the challenge value and the scalar product of the distributed digital identity identifier and the base point parameter to obtain a reconstructed challenge value, and verifies the reconstructed challenge value, comprising: obtaining the public key corresponding to the distributed digital identity identifier from the blockchain; determining a second product of the hash identity identifier and the second elliptic curve base point, determining a second difference value between the distributed digital identity identifier and the second product, and determining a third product of the challenge value and the second difference value; calculating a fifth scalar product of the response value and a first elliptic curve base point, determining a first verification value according to a sum of the fifth scalar product and the third product; calculating a fourth product of the challenge value and the public key, calculating a sixth scalar product of the response value and a second elliptic curve base point, and calculating a second verification value according to a sum of the sixth scalar product and the fourth product; reconstructing the challenge value based on the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity, the public key, the first verification value, the second verification value and the message by using a hash function; verifying whether the reconstructed challenge value is consistent with the challenge value sent by the prover, and if so, the authentication is passed.
5. The method of claim 1, wherein, The message includes a timestamp, and the reconstruction calculation is performed by using the scalar product of the response value and a base point parameter, the challenge value and the scalar product of the distributed digital identity and the base point parameter, including: verifying the validity of the timestamp; if the timestamp is valid, the reconstruction calculation is performed by using the scalar product of the response value and a base point parameter, the challenge value and the scalar product of the distributed digital identity and the base point parameter.
6. An identification and authentication apparatus of distributed digital identity, characterized in that, including: a first generating unit configured to connect an identity type and an identity identifier of an entity, and generate a hash identity identifier of the entity by using a hash function, and establish a one-to-one correspondence between the hash identity identifier and the entity; a second generating unit configured to generate a distributed digital identity based on a base point parameter of an elliptic curve by using the hash identity identifier and a public-private key pair of the entity through a Pedersen commitment algorithm, and store a distributed digital identity document into a block chain, and establish a one-to-many correspondence between the distributed digital identity and the hash identity identifier; a third generating unit configured to select a random number and calculate a scalar product of the random number and the base point parameter as a commitment value in an authentication stage, and generate a challenge value by performing calculation on the base point parameter, the distributed digital identity, a public key in the public-private key pair, the commitment value and a message by using a hash function; a determining unit configured to determine a first product of the challenge value and a private key in the public-private key pair, calculate a first difference value between the random number and the first product as a response value, and send the challenge value and the response value to a verifier; a verifying unit configured to obtain a reconstructed challenge value by performing reconstruction calculation on the response value and the base point parameter, the challenge value and the scalar product of the distributed digital identity and the base point parameter by the verifier after obtaining the public key from the block chain, and verify the reconstructed challenge value.
7. The apparatus of claim 6, wherein, The first generating unit has functions of: calculating a first scalar product of a private key in the public-private key pair and a first elliptic curve base point, calculating a second scalar product of the hash identity identifier and a second elliptic curve base point, and generating the distributed digital identity according to a sum of the first scalar product and the second scalar product, the first elliptic curve base point and the second elliptic curve base point being preset parameters of the elliptic curve.
8. The apparatus of claim 6, wherein, The third generating unit is specifically configured to: determining a random number, determining a first commitment value based on a third scalar multiplication of the random number and a first elliptic curve base point, and determining a second commitment value based on a fourth scalar multiplication of the random number and a second elliptic curve base point; computing a challenge value as an input of a hash function with the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity, a public key of the public-private key pair, the first commitment value, the second commitment value, and a message.
9. A computing device, comprising: comprising: a memory; a processor; and a computer program; wherein the computer program is stored in the memory and configured to be executed by the processor to implement the method of any one of claims 1-5. The computer program, when executed by the processor, implements the method of any one of claims 1-5.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that,
Citation Information
Patent Citations
Trusted distributed identity authentication method and system, storage medium and application
CN113098838A
Anti-quantum signature method and system used between two terminals, and electronic equipment
CN120128321A
Distributed digital identity data processing method
CN121098476A
Chinese national cryptographic algorithm-based identity authentication and data encryption method for coap
WO2025000590A1