Method, device and equipment for identification and authentication of distributed digital identity and medium
Patent Information
- Application Number
- CN202511968551.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-24
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2045-12-24
AI Technical Summary
[0004]现有技术存在一个核心问题:隐私保护能力不足
[0005] In order to solve the above-mentioned technical problems, or at least partially solve the above-mentioned technical problems, this disclosure provides a method, apparatus, device and medium for identifying and verifying distributed digital identities.
Smart Images

Figure CN121690818B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of computer technology, and in particular to a method, apparatus, device and medium for identifying and verifying distributed digital identities. Background Technology
[0002] With the rapid development of internet and blockchain technologies, distributed digital identity (DID), as a decentralized identity management solution, plays an increasingly important role in the field of computer technology. DID allows entities (such as individuals, organizations, or devices) to autonomously manage and control their digital identities without the need for a centralized authority, and is widely used in scenarios such as digital authentication, data privacy protection, the Internet of Things (IoT), and fintech. It combines cryptographic algorithms (such as hash functions and elliptic curve cryptography) with the immutability of blockchain, aiming to achieve uniqueness, verifiability, and security of identity, thereby providing fundamental support for digital transformation.
[0003] Currently, mainstream DID methods follow the syntax specifications set by the W3C consortium. Their basic structure is a combination of "did:", the method name (method-name), and the method-specific identifier (method-specific-id). For example, in some scenarios, the method-specific-id often uses a randomly generated string, hash value, or blockchain address as the identifier. This generation rule relies on the randomness of the algorithm to ensure uniqueness, but lacks semantic meaning.
[0004] A core problem with existing technologies is insufficient privacy protection. Because method-specific IDs are often based on plaintext or reversibly deducible elements (such as hash values or addresses), attackers may be able to infer the true identity of an entity by analyzing publicly available data on the blockchain, leading to identity leaks and misuse, thus resulting in low security. Summary of the Invention
[0005] In order to solve the above-mentioned technical problems, or at least partially solve the above-mentioned technical problems, this disclosure provides a method, apparatus, device and medium for identifying and verifying distributed digital identities.
[0006] This disclosure provides a method for identifying and authenticating distributed digital identities, the method comprising: After concatenating the entity's identity type and identity identifier, a hash identity identifier is generated by calculating a hash function to uniquely identify the entity, wherein a one-to-one correspondence is established between the hash identity identifier and the entity.
[0007] Using hash identity identifiers and public / private key pairs of entities, distributed digital identity identifiers are generated based on the base point parameters of elliptic curves through the Pedersen commitment algorithm. The generated distributed digital identity identifier documents are stored in the blockchain, where a one-to-many correspondence is established between distributed digital identity identifiers and hash identity identifiers.
[0008] During the authentication phase, the prover selects a random number and calculates its scalar product with the base point parameter as the commitment value. The prover then uses a hash function to calculate the challenge value using the base point parameter, the distributed digital identity identifier, the public key in the public-private key pair, the commitment value, and the message.
[0009] Determine the challenge value and the first product of the private key in the public-private key pair, calculate the first difference between the random number and the first product as the response value, and send the challenge value and the response value to the verifier.
[0010] After obtaining the public key from the blockchain, the verifier performs reconstruction calculations using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to obtain the reconstruction challenge value and verify the reconstruction challenge value.
[0011] This disclosure also provides a distributed digital identity identification and authentication device, the device comprising: The first generation unit is used to connect the identity type and identity identifier of an entity and then calculate a hash identity identifier that uniquely identifies the entity through a hash function, and establish a one-to-one correspondence between the hash identity identifier and the entity. The second generation unit is used to generate distributed digital identity identifiers based on the base point parameters of elliptic curves using the Pedersen commitment algorithm, using hash identity identifiers and public / private key pairs of entities. The generated distributed digital identity identifier documents are stored in the blockchain, and a one-to-many correspondence is established between distributed digital identity identifiers and hash identity identifiers. The third generation unit is used in the authentication phase, whereby the prover selects a random number and calculates a scalar product with the base point parameter as the commitment value, and generates a challenge value by using a hash function to calculate the base point parameter, the distributed digital identity identifier, the public key in the public-private key pair, the commitment value, and the message. The determining unit is used to determine the challenge value and the first product of the private key in the public-private key pair, calculate the first difference between the random number and the first product as the response value, and send the challenge value and the response value to the verifier. The verification unit is used by the verifier to obtain the public key from the blockchain, and then to perform reconstruction calculations by using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to obtain the reconstruction challenge value and verify the reconstruction challenge value.
[0012] This disclosure also provides a computing device, the computing device comprising: a processor; a memory for storing executable instructions of the processor; the processor being configured to read the executable instructions from the memory and execute the instructions to implement the distributed digital identity identification and authentication method provided in this disclosure.
[0013] This disclosure also provides a computer-readable storage medium storing a computer program for executing the identification and authentication method for distributed digital identity as provided in this disclosure. Attached Figure Description
[0014] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0015] Figure 1 A flowchart illustrating a distributed digital identity identification and authentication method provided in this embodiment of the disclosure; Figure 2 A schematic diagram of the structure of a distributed digital identity identification and authentication device provided in an embodiment of this disclosure; Figure 3 This is a schematic diagram of the structure of a computing device provided in an embodiment of the present disclosure. Detailed Implementation
[0016] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0017] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0018] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0019] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0020] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0021] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0022] With the rapid development of internet and blockchain technologies, distributed digital identity (DID), as a decentralized identity management solution, plays an increasingly important role in the field of computer technology. DID allows entities (such as individuals, organizations, or devices) to autonomously manage and control their digital identities without the need for a centralized authority, and is widely used in scenarios such as digital authentication, data privacy protection, the Internet of Things (IoT), and fintech. It combines cryptographic algorithms (such as hash functions and elliptic curve cryptography) with the immutability of blockchain, aiming to achieve uniqueness, verifiability, and security of identity, thereby providing fundamental support for digital transformation. However, with the expansion of application scenarios, the privacy protection and authentication mechanisms of DID face new challenges, urgently requiring more efficient technical solutions.
[0023] Currently, mainstream DID methods follow the syntax specifications set by the W3C consortium. Their basic structure is a combination of "did:", the method name, and a method-specific identifier (method-specific-id). For example, in some scenarios, the method-specific-id often uses a randomly generated string, hash value, or blockchain address as the identifier. This generation rule relies on the randomness of the algorithm to ensure uniqueness, but lacks semantic meaning.
[0024] Specifically, the W3C standard only specifies the syntactic framework of DIDs (such as ABNF rules), while the content of method-specific IDs is defined by each implementation. This leads to existing methods focusing primarily on the generation and storage of identifiers, without deeply integrating privacy enhancement mechanisms. This design causes DIDs to directly expose raw identity data during generation or use traceable addresses, making it difficult to hide sensitive information about the entity. In other words, existing technologies suffer from a core problem: insufficient privacy protection. Because method-specific IDs are often based on plaintext or reversibly deducible elements (such as hash values or addresses), attackers may analyze publicly available data on the blockchain to infer the entity's true identity, leading to identity leakage and abuse, thus resulting in low security for identity authentication.
[0025] This application achieves uniqueness by concatenating the entity's identity type and identifier to generate a hash identity (HID), thus hiding original sensitive information. This ensures the uniqueness of the generated HID for each entity and avoids directly exposing identity data. Secondly, it utilizes the Pedersen commitment algorithm based on elliptic curve base point parameters to generate a distributed digital identity (DID). The DID is stored as a commitment value on the blockchain. Leveraging the information-theoretic security properties of Pedersen commitments, the DID is public but cannot be used to deduce the HID or private key, effectively preventing identity leakage and reverse engineering attacks. Finally, in the authentication phase, zero-knowledge proofs are incorporated, using a challenge-response mechanism to verify identity ownership without disclosing private information, further strengthening privacy protection. The entire scheme, through the generation and commitment mechanisms of HID and DID, fundamentally solves the privacy vulnerability problem while ensuring authenticability, improving the security of identity authentication.
[0026] To address the aforementioned issues, this disclosure provides a method for identifying and verifying distributed digital identities. The method will be described below with reference to specific embodiments.
[0027] Figure 1 This is a flowchart illustrating a distributed digital identity identification and authentication method provided in an embodiment of this disclosure. The method can be executed by a distributed digital identity identification and authentication device, which can be implemented in software and / or hardware, and is generally integrated into a computing device. Figure 1 As shown, the method includes: S101, after concatenating the entity's identity type and identity identifier, a hash identity identifier that uniquely identifies the entity is generated by calculating a hash function.
[0028] The computing device concatenates the entity's identity type and identity identifier, and then uses a hash function to generate a hash identity identifier that uniquely identifies the entity.
[0029] This requires clearly defining the entity's identity type (IDType) and identity identifier (ID). The identity type distinguishes the entity's category, such as a resident ID card, while the identity identifier is a string that uniquely identifies the entity within that type, such as a resident's ID card number. Next, a hash function (HASH) is used to concatenate these two elements into a longer, composite string containing complete identity semantics. This composite string is then used as input and processed by a cryptographically secure hash function. This hash function irreversibly maps an input of arbitrary length to a fixed-length, seemingly random digest value. The output of this calculation process is called the Hash Identity Identifier (HID).
[0030] The specific formula can be as follows: ; Through this design, HID can not only uniquely correspond to the original entity, ensuring the determinacy of the identifier, but more importantly, it can effectively hide sensitive information such as the original identity type and identifier, laying a solid foundation for the subsequent construction of a distributed digital identity with privacy protection features, and realizing a one-to-one correspondence between entities and HID.
[0031] S102, using the hash identity identifier and the entity's public / private key pair, a distributed digital identity identifier is generated based on the base point parameters of an elliptic curve using the Pedersen commitment algorithm, and the generated distributed digital identity identifier document is stored in the blockchain.
[0032] Computing devices can use hash identity identifiers and public / private key pairs of entities to generate distributed digital identity identifiers based on the base point parameters of elliptic curves using the Pedersen commitment algorithm, and store the generated distributed digital identity identifier documents in the blockchain.
[0033] For example, the computing device can compute the first scalar product sk of the private key sk in the public-private key pair and the first elliptic curve base point H. H, calculate hash identity identifier HID The second scalar product with the base point G of the second elliptic curve HID G A distributed digital identity is generated based on the sum of the first scalar product and the second scalar product, wherein the base points of the first and second elliptic curves are preset parameters of the elliptic curves.
[0034] The specific formula is as follows:
[0035] in, This refers to the result generated after making a cryptographic commitment to a hash identity using the Pedersen commitment algorithm.
[0036] This structure makes the DID a commitment to the HID and private key: it is presented externally as a random point on an elliptic curve, effectively hiding the original HID and private key information, providing information-theoretic security for privacy. Simultaneously, an entity possessing the correct private key and HID can prove to a verifier that it knows the secret hidden by this commitment, thus completing authentication. After generating the DID, it can be encapsulated along with the corresponding public key and other metadata into a distributed digital identity document, stored on the blockchain for notarization and public verification. This establishes a crucial one-to-many correspondence between entities, HIDs, and DIDs: one entity corresponds to one HID, but this HID can be combined with different private keys (key rotation) to generate multiple different DIDs, enhancing privacy and flexibility while ensuring authenticability.
[0037] S103, during the authentication phase, the proving party selects a random number and calculates its scalar product with the base point parameter as the commitment value. It then uses a hash function to calculate a challenge value based on the base point parameter, the distributed digital identity, the public key in the public-private key pair, the commitment value, and the message. The proving party determines the first product of the challenge value and the private key in the public-private key pair, calculates the first difference between the random number and the first product as the response value, and sends the challenge value and the response value to the verifying party.
[0038] For example, the core of this step is for the proving party to prove to the verifying party that it does indeed possess the secret corresponding to the distributed digital identity without revealing its private key and hash identity. Its technical essence is a non-interactive zero-knowledge proof constructed based on the Schnorr protocol and the Fiat-Shamir heuristic.
[0039] First, the proving party needs to initiate an authentication session. For this, it can randomly select a secure random number r. Then, it can use this random number to perform scalar product operations with the two publicly known elliptic curve base point parameters (i.e., the first elliptic curve base point H and the second elliptic curve base point G), generating two commitment values: the first commitment value Q1 = r is determined based on the third scalar product of the random number r and the first elliptic curve base point. H, and the second commitment value Q2=r is determined based on the fourth scalar product of the random number and the base point of the second elliptic curve. G.
[0040] These two commitment values pledge to this specific proof session; their randomness ensures the freshness of each proof and prevents replay attacks. Following this, the crucial challenge value generation phase can begin. To transform the interactive protocol into a non-interactive one, the proving party can use a hash function to simulate the verifying party's challenge generation behavior. It concatenates all publicly available parameters involved in this proof, along with an optional message (which may include a timestamp), as input to the hash function. These inputs include the base points H and G, the distributed digital identity (DID) to be proven, the public key PK verifiable on the blockchain, the two commitment values Q1 and Q2 just calculated, and the message m. By hashing this combination, a fixed-length challenge value c is generated.
[0041] The specific formula can be as follows: ; in, This represents a hash function.
[0042] The prover can then compute the response value. This process involves two key operations: First, the product of the challenge value c and the prover's private key PK is calculated; this is the first product c. sk. Next, calculate the difference between the previously selected random number and this first product, i.e., the first difference s=r. c sk, this result is the response value. Finally, the proving party sends the core parameter challenge value and response value generated from this proof to the validating party.
[0043] S104 After obtaining the public key from the blockchain, the verifier performs a reconstruction calculation using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to obtain the reconstruction challenge value and verify the reconstruction challenge value.
[0044] This step is crucial for the verifier to reconstruct the proof and ultimately confirm the legitimacy of the verifier's identity. The verifier can use the parameters disclosed by the verifier and publicly available data on the blockchain to recalculate the challenge value and verify its validity through comparison.
[0045] For example, the verifier can first obtain the public key PK claimed by the prover in connection with the authentication from the blockchain. The verifier can then perform a reconstruction computation, a process designed to reproduce the computations performed by the prover when generating the commitment value.
[0046] Specifically, the verifier performs the following operations: Determine the second product HID of the hash identity identifier and the base point of the second elliptic curve. G, determine the second difference between the distributed digital identity and the second product, DID-HID. G, determine the third product c of the challenge value and the second difference. (DID-HID) G).
[0047] Calculate the scalar product s of the response value and the base point of the first elliptic curve. H, the first verification value is determined by the sum of the fifth scalar product and the third product. .
[0048] The specific formula is as follows: ; Determine the fourth product c of the challenge value and the public key. PK determines the sixth scalar product s of the response value and the base point of the second elliptic curve. G, calculate the second verification value based on the sum of the sixth scalar product and the fourth product. .
[0049] The specific formula is as follows:
[0050] Based on the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity, the public key, the first verification value, the second verification value, and the message m, the reconstruction challenge value is calculated using a hash function. ; ; After completing the above reconstruction, the verifier performs the most crucial step: obtaining the reconstruction challenge value. It uses the exact same hash function as the prover, concatenating the same public parameters (base point parameters, distributed digital identity, and public key, etc.), the reconstructed commitment values (here called the first and second verification values), and the same message in the same order, and then calculates the hash value. Finally, the verifier performs verification: comparing the calculated reconstruction challenge value with the original challenge value received from the prover. If they are exactly equal, authentication passes. This is because all parameters can only match if the prover actually possesses the private key corresponding to the DID and public key, and the correct HID, ensuring that the reconstructed challenge value matches the original challenge value. This ultimately proves the prover's ownership of the distributed digital identity.
[0051] In some possible implementations, this application can also verify the validity of timestamps; If the timestamp is valid, the reconstruction calculation operation can be performed.
[0052] For example, when generating a knowledge signature, the proving party embeds a timestamp containing the current moment into the message used as input to the hash function. When the verifying party receives the proof parameters, it first parses the message and extracts the timestamp, checking whether it is within a reasonable and valid time window (e.g., whether it deviates too much from the verifying party's current time or has expired). If the timestamp is invalid (e.g., expired or future time), the verification process terminates immediately, and authentication fails. This measure aims to effectively defend against replay attacks and ensure the freshness and uniqueness of each proof session. Only when the timestamp is valid, confirming that the proof request was recently generated and not reused, will the verifying party continue with subsequent key operations: using the scalar product of the response value and the base point parameter received from the proving party, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to perform reconstruction calculations, and finally, by comparing the reconstructed challenge value with the original challenge value, to complete the final determination of identity authentication.
[0053] This application achieves uniqueness by concatenating the entity's identity type and identifier to generate a hash identity (HID), thus hiding original sensitive information. This ensures the uniqueness of the generated HID for each entity and avoids directly exposing identity data. Secondly, it utilizes the Pedersen commitment algorithm based on elliptic curve base point parameters to generate a distributed digital identity (DID). The DID is stored as a commitment value on the blockchain. Leveraging the information-theoretic security properties of Pedersen commitments, the DID is public but cannot be used to deduce the HID or private key, effectively preventing identity leakage and reverse engineering attacks. Finally, in the authentication phase, zero-knowledge proofs are incorporated, using a challenge-response mechanism to verify identity ownership without disclosing private information, further strengthening privacy protection. The entire scheme, through the generation and commitment mechanisms of HID and DID, fundamentally solves the privacy vulnerability problem while ensuring authenticability, improving the security of identity authentication.
[0054] To implement the above embodiments, this disclosure also proposes a distributed digital identity identification and authentication device.
[0055] Figure 2 This is a schematic diagram of a distributed digital identity identification and authentication device provided in an embodiment of this disclosure. The device can be implemented by software and / or hardware, and is generally integrated into a computing device. Figure 2 As shown, the device includes: a first generation unit 210, a second generation unit 220, a third generation unit 230, a determination unit 240, and a verification unit 250, wherein, The first generation unit is used to concatenate the identity type and identity identifier of an entity and then calculate a hash identity identifier that uniquely identifies the entity through a hash function. The hash identity identifier establishes a one-to-one correspondence with the entity. The second generation unit is used to generate a distributed digital identity based on the base point parameters of an elliptic curve using the public-private key pair of the hash identity and the entity through the Pedersen commitment algorithm, and to store the generated distributed digital identity document in the blockchain. A one-to-many correspondence is established between the distributed digital identity and the hash identity. The third generation unit is used in the authentication phase, whereby the prover selects a random number and calculates a scalar product with the base point parameter as the commitment value, and generates a challenge value by using a hash function to calculate the base point parameter, the distributed digital identity identifier, the public key in the public-private key pair, the commitment value, and the message. The determining unit is used to determine the challenge value and the first product of the private key in the public-private key pair, calculate the first difference between the random number and the first product as the response value, and send the challenge value and the response value to the verifier. The verification unit is used to verify the reconstruction challenge value by performing a reconstruction calculation on the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter after the verifier obtains the public key from the blockchain, and then verifies the reconstruction challenge value.
[0056] Optionally, the first generating unit is specifically used for: Calculate the first scalar product between the private key in the public-private key pair and the first elliptic curve base point, calculate the second scalar product between the hash identity and the second elliptic curve base point, and generate a distributed digital identity based on the sum of the first and second scalar products. The first and second elliptic curve base points are preset parameters of the elliptic curve.
[0057] Optionally, the third generation unit is specifically used for: A random number is determined; a first commitment value is determined based on the third scalar product of the random number and the base point of the first elliptic curve; and a second commitment value is determined based on the fourth scalar product of the random number and the base point of the second elliptic curve. The challenge value is calculated by using the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity identifier, the public key in the public-private key pair, the first commitment value, the second commitment value, and the message as inputs to the hash function.
[0058] Optional, verification unit, specifically used for: Obtain the public key corresponding to the distributed digital identity from the blockchain; Determine the second product of the hash identity identifier and the base point of the second elliptic curve, determine the second difference between the distributed digital identity identifier and the second product, and determine the third product of the challenge value and the second difference; Calculate the fifth scalar product between the response value and the base point of the first elliptic curve, and use the sum of the fifth scalar product and the third product to determine the first verification value; Determine the fourth product of the challenge value and the public key, determine the sixth scalar product of the response value and the base point of the second elliptic curve, and calculate the second verification value based on the sum of the sixth scalar product and the fourth product; Based on the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity identifier, the public key, the first verification value, the second verification value, and the message, the reconstruction challenge value is calculated using a hash function; Verify whether the reconstruction challenge value is consistent with the challenge value sent by the prover; if they are consistent, the authentication is successful.
[0059] Optional, verification unit, specifically used for: Verify the validity of the timestamp; If the timestamp is valid, then the reconstruction calculation is performed using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter.
[0060] The distributed digital identity identification and authentication device provided in this disclosure can execute the distributed digital identity identification and authentication method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of the method execution.
[0061] To implement the above embodiments, this disclosure also proposes a computer program product, including a computer program / instruction, which, when executed by a processor, implements the distributed digital identity identification and authentication method in the above embodiments.
[0062] Figure 3 This is a schematic diagram of the structure of a computing device provided in an embodiment of the present disclosure.
[0063] The following is a detailed reference. Figure 3 The diagram illustrates a structural schematic suitable for implementing the computing device 300 in the embodiments of this disclosure. The computing device 300 in the embodiments of this disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 3 The computing device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0064] like Figure 3As shown, the computing device 300 may include a processor (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 302 or a program loaded from memory 308 into random access memory (RAM) 303. The RAM 303 also stores various programs and data required for the operation of the computing device 300. The processor 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0065] Typically, the following devices can be connected to I / O interface 305: input devices 306 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 307 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 308 including, for example, magnetic tapes, hard disks, etc.; and communication devices 309. Communication device 309 allows computing device 300 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 3 A computing device 300 with various devices is shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.
[0066] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 309, or installed from memory 308, or installed from ROM 302. When the computer program is executed by processor 301, it performs the functions defined in the distributed digital identity identification and authentication method of embodiments of this disclosure.
[0067] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0068] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0069] The aforementioned computer-readable medium may be included in the aforementioned computing device; or it may exist independently and not assembled into the computing device.
[0070] The aforementioned computer-readable medium carries one or more programs, which, when executed by the computing device, cause the computing device to perform the aforementioned distributed digital identity identification and authentication method.
[0071] The computing device can be programmed with computer program code in one or more programming languages or a combination thereof to perform the operations of this disclosure. These programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0072] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0073] The units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units are not, in some cases, intended to limit the specific unit.
[0074] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0075] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0076] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0077] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0078] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A method for identifying and verifying distributed digital identities, characterized in that, include: The identity type and identity identifier of an entity are concatenated and then a hash identity identifier is generated by calculating a hash function to uniquely identify the entity. A one-to-one correspondence is established between the hash identity identifier and the entity. Using the hash identity identifier and the entity's public / private key pair, a distributed digital identity identifier is generated based on the base point parameters of an elliptic curve using the Pedersen commitment algorithm. The generated distributed digital identity identifier document is stored in the blockchain, and a one-to-many correspondence is established between the distributed digital identity identifier and the hash identity identifier. During the authentication phase, the proving party selects a random number and calculates its scalar product with the base point parameter as the commitment value. The proving party then uses a hash function to calculate and generate a challenge value from the base point parameter, the distributed digital identity identifier, the public key in the public-private key pair, the commitment value, and the message. Determine the first product of the challenge value and the private key in the public-private key pair, calculate the first difference between the random number and the first product as the response value, and send the challenge value and the response value to the verifier; After obtaining the public key from the blockchain, the verifier performs a reconstruction calculation using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to obtain the reconstruction challenge value and verify the reconstruction challenge value. The proving party selects a random number and calculates its scalar product with the base point parameter as the commitment value. It then uses a hash function to calculate a challenge value based on the base point parameter, the distributed digital identity, the public key in the public-private key pair, the commitment value, and the message. A random number is determined; a first commitment value is determined based on the third scalar product of the random number and the base point of the first elliptic curve; and a second commitment value is determined based on the fourth scalar product of the random number and the base point of the second elliptic curve. The challenge value is calculated by using the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity, the public key in the public-private key pair, the first commitment value, the second commitment value, and the message as inputs to the hash function. After obtaining the public key from the blockchain, the verifier performs a reconstruction calculation using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter to obtain the reconstruction challenge value. Verification of the reconstruction challenge value includes: Obtain the public key corresponding to the distributed digital identity from the blockchain; Determine the second product of the hash identity identifier and the base point of the second elliptic curve, determine the second difference between the distributed digital identity identifier and the second product, and determine the third product of the challenge value and the second difference; Calculate the fifth scalar product between the response value and the base point of the first elliptic curve, and use the sum of the fifth scalar product and the third product to determine the first verification value; Determine the fourth product of the challenge value and the public key, determine the sixth scalar product of the response value and the base point of the second elliptic curve, and calculate the second verification value based on the sum of the sixth scalar product and the fourth product; Based on the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity identifier, the public key, the first verification value, the second verification value, and the message, the reconstruction challenge value is calculated using a hash function; Verify whether the reconstruction challenge value is consistent with the challenge value sent by the prover; if they are consistent, the authentication is successful.
2. The method according to claim 1, characterized in that, Distributed digital identities are generated using the Pedersen commitment algorithm, including: Calculate the first scalar product between the private key in the public-private key pair and the first elliptic curve base point, calculate the second scalar product between the hash identity and the second elliptic curve base point, and generate a distributed digital identity based on the sum of the first and second scalar products. The first and second elliptic curve base points are preset parameters of the elliptic curve.
3. The method according to claim 1, characterized in that, The message includes a timestamp, and is reconstructed using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter, including: Verify the validity of the timestamp; If the timestamp is valid, then the reconstruction calculation is performed using the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter.
4. A distributed digital identity identification and authentication device, characterized in that, include: The first generation unit is used to concatenate the identity type and identity identifier of an entity and then calculate a hash identity identifier that uniquely identifies the entity through a hash function. The hash identity identifier establishes a one-to-one correspondence with the entity. The second generation unit is used to generate a distributed digital identity based on the base point parameters of an elliptic curve using the public-private key pair of the hash identity and the entity through the Pedersen commitment algorithm, and to store the generated distributed digital identity document in the blockchain. A one-to-many correspondence is established between the distributed digital identity and the hash identity. The third generation unit is used in the authentication phase, whereby the prover selects a random number and calculates a scalar product with the base point parameter as the commitment value, and generates a challenge value by using a hash function to calculate the base point parameter, the distributed digital identity identifier, the public key in the public-private key pair, the commitment value, and the message. The determining unit is used to determine the first product of the challenge value and the private key in the public-private key pair, calculate the first difference between the random number and the first product as the response value, and send the challenge value and the response value to the verifier. The verification unit is used to verify the reconstruction challenge value by performing a reconstruction calculation on the scalar product of the response value and the base point parameter, the challenge value, and the scalar product of the distributed digital identity and the base point parameter after the verifier obtains the public key from the blockchain, and then verifies the reconstruction challenge value. The third generation unit is specifically used for: A random number is determined; a first commitment value is determined based on the third scalar product of the random number and the base point of the first elliptic curve; and a second commitment value is determined based on the fourth scalar product of the random number and the base point of the second elliptic curve. The challenge value is calculated by using the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity, the public key in the public-private key pair, the first commitment value, the second commitment value, and the message as inputs to the hash function. The verification unit is specifically used for: Obtain the public key corresponding to the distributed digital identity from the blockchain; Determine the second product of the hash identity identifier and the base point of the second elliptic curve, determine the second difference between the distributed digital identity identifier and the second product, and determine the third product of the challenge value and the second difference; Calculate the fifth scalar product between the response value and the base point of the first elliptic curve, and use the sum of the fifth scalar product and the third product to determine the first verification value; Determine the fourth product of the challenge value and the public key, determine the sixth scalar product of the response value and the base point of the second elliptic curve, and calculate the second verification value based on the sum of the sixth scalar product and the fourth product; Based on the first elliptic curve base point, the second elliptic curve base point, the distributed digital identity identifier, the public key, the first verification value, the second verification value, and the message, the reconstruction challenge value is calculated using a hash function; Verify whether the reconstruction challenge value is consistent with the challenge value sent by the prover; if they are consistent, the authentication is successful.
5. The apparatus according to claim 4, characterized in that, The first generating unit has the following functions: Calculate the first scalar product between the private key in the public-private key pair and the first elliptic curve base point, calculate the second scalar product between the hash identity and the second elliptic curve base point, and generate a distributed digital identity based on the sum of the first and second scalar products. The first and second elliptic curve base points are preset parameters of the elliptic curve.
6. A computing device, characterized in that, include: Memory; processor; as well as Computer programs; The computer program is stored in the memory and configured to be executed by the processor to implement the method as described in any one of claims 1-3.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-3.
Citation Information
Patent Citations
Trusted distributed identity authentication method and system, storage medium and application
CN113098838A
Anti-quantum signature method and system used between two terminals, and electronic equipment
CN120128321A