Verification method and device for user attribute in data space, equipment and medium

By using a cryptographic accumulator to manage user attributes in the data space, the problems of high management costs and invalid computations of multiple VCs are solved, achieving efficient and privacy-preserving attribute verification.

CN121770830APending Publication Date: 2026-03-31CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-19
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing user attribute verification schemes in the data space suffer from high management costs of multiple VCs, heavy signing pressure on service providers, and invalid and redundant calculations, and also pose a high risk of leakage of complete VC information.

Method used

It adopts an attribute-based fragmented VC design, stores and manages user attributes through a cryptographic accumulator, and verifies only the accumulator and attribute evidence, reducing redundant calculations and providing stronger privacy protection.

Benefits of technology

It reduces user management costs, alleviates the signature burden on trusted service providers, improves privacy protection, reduces network bandwidth consumption, and achieves efficient attribute verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121770830A_ABST
    Figure CN121770830A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security, and provides a verification method and device for user attributes in a data space, equipment and a medium, and the method comprises the steps: receiving a service request sent by a participant; the service request comprises a user identity credential, a password accumulator, a target attribute and evidence of the target attribute in the password accumulator; the participant to which the password accumulator belongs is determined according to the user identity credential, and when it is determined that the target attribute is stored in the password accumulator according to the target attribute and the evidence of the target attribute in the password accumulator, the participant is allowed to access the service. According to the method, a complete semantic chain does not need to be verified, only the accumulator and the attribute evidence need to be verified, and privacy protection is higher.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and in particular to a method, apparatus, device, and medium for verifying user attributes in a data space. Background Technology

[0002] Data Space originated from solving the problems of data silos and value mining. In the digital economy era, data is a core production factor, and its circulation efficiency directly affects industrial innovation. Data Space aims to build a decentralized digital ecosystem, realize secure data sharing across organizations and fields through unified rules and trusted technologies, and ensure data sovereignty and compliant use.

[0003] Gaia-X is a representative data space project. As a European-led standardization project, it adopts a layered architecture. The trust plane establishes an underlying trust mechanism to ensure ecosystem security through technical compatibility specifications (such as identity authentication and verifiable credentials). The management plane provides directory services, data wallets, market tools, and other support for data discovery and transaction processes. The usage plane focuses on data exchange and business interaction, and relies on open standards (DCAT, ODRL) to achieve cross-system interoperability. Technically, it emphasizes decentralized trust, automated compliance verification, and open-source implementation. Through a federated model, it balances data control and sharing efficiency, laying the foundation for building an open and collaborative digital ecosystem.

[0004] In the data space, a key security and compliance process is that before a service requester and service provider begin interacting, the service provider verifies the requester's identity attributes. Service can only proceed if the verification is successful. The requester's identity attributes are represented by a verifiable credential (VC) signed by a trusted service provider. A VC typically contains multiple attributes. Existing solutions have the following problems: if a natural person's VC includes "name, role, and affiliated organization," the service provider only needs the "role" for authorization. However, current processes may require the complete VC, leading to the exposure of non-essential personal information such as "name" and "organization." One solution is as follows: Implement an attribute-based "fragmented VC" design, signing each attribute separately to construct attribute-level VCs, such as "Role VC," "Organization VC," and "Name VC." Participants can then only provide the fragments required by the service provider, avoiding the leakage of complete personal information. However, this solution has the following problems: 1. Multiple VCs will increase user management costs (requiring the storage of multiple VCs) and increase the signing pressure on trusted service providers (requiring separate signing for each attribute). 2. If the business service provider requires the client to support multiple attributes to access the service, the service provider needs to verify the VC of each attribute and check the signature of the entire VC. Different VCs may have multiple identical fields, resulting in invalid calculations and duplicate calculations. Summary of the Invention

[0005] In view of the problems existing in the prior art, the present invention provides a method, apparatus, device and medium for verifying user attributes in a data space.

[0006] This invention provides a method for verifying user attributes in a data space, applied to a service provider, comprising: Receive service requests sent by participating parties; the service requests include user identity credentials, a password accumulator, target attributes, and evidence of the target attributes in the password accumulator; Based on the user's identity credentials, the participant to which the password accumulator belongs is determined, and based on the target attribute and evidence of the target attribute in the password accumulator, the participant is allowed to access the service when it is determined that the target attribute is stored in the password accumulator.

[0007] According to the user attribute verification method in the data space provided by the present invention, the method further includes: Before determining the participant to which the password accumulator belongs based on the user's identity credentials, it is determined whether the password accumulator has preset signature information, and the legitimacy of the password accumulator is determined.

[0008] According to the user attribute verification method in the data space provided by the present invention, the method further includes: After determining that the cryptographic accumulator has preset signature information, a query request is sent to the trusted service provider; the query request includes the cryptographic accumulator and evidence of the target attribute in the cryptographic accumulator; Receive query results sent by a trusted service provider, and determine the validity of the cryptographic accumulator and evidence based on the query results.

[0009] According to the user attribute verification method in the data space provided by the present invention, the service request further includes a composite value of a target attribute and the validity period of the target attribute. Accordingly, the participant to which the password accumulator belongs is determined based on the user identity credentials, and the participant is allowed to access the service when the target attribute is stored in the password accumulator and the validity period of the target attribute has not expired, based on the composite value of the target attribute and the validity period of the target attribute, as well as evidence that the target attribute is in the password accumulator.

[0010] According to the method for verifying user attributes in the data space provided by the present invention, the password accumulator stores all user attributes or a composite value of all user attributes and the validity period of the corresponding user attributes.

[0011] This invention also provides a method for verifying user attributes in a data space, applied to participating parties, including: The system receives attribute requirements sent by the service provider, determines the target attribute based on the attribute requirements, and sends a service request back to the service provider. The service request includes user identity credentials, a password accumulator, the target attribute, and evidence of the target attribute in the password accumulator. The user receives verification information from the service provider and accesses the service provider's service. The verification information indicates that the service provider determines the participant to which the password accumulator belongs based on the user's identity credentials, and determines that the target attribute is stored in the password accumulator based on the target attribute and evidence of the target attribute in the password accumulator.

[0012] According to the user attribute verification method in the data space provided by the present invention, the method further includes: Send all user attributes and identity information to trusted service providers; Receive user identity credentials, password accumulator, and evidence of each user attribute in the password accumulator generated by the trusted server provider based on all user attributes and identity information.

[0013] According to the method for verifying user attributes in a data space provided by the present invention, the method further includes: receiving a composite value of user attributes and user attribute validity periods generated by a trusted server provider based on all user attributes and the validity period configured for each user attribute.

[0014] This invention also provides a method for verifying user attributes in a data space, applicable to trusted service providers, including... Receive all user attributes and identity information sent by the participants; User identity credentials, password accumulator, and evidence of each user attribute in the password accumulator are generated based on all user attributes and identity information. Send the user's identity credentials, password accumulator, and evidence of each user's attributes in the password accumulator to the participating party card.

[0015] According to the user attribute verification method in the data space provided by the present invention, the password accumulator stores all user attributes and user identity credentials.

[0016] The method for verifying user attributes in a data space according to the present invention further includes: Set an expiration date for each user attribute, and store the combined value of the user attribute and its expiration date into the password accumulator.

[0017] According to the method for verifying user attributes in a data space provided by the present invention, the method further includes: configuring preset signature information for the password accumulator; constructing a password accumulator list and storing valid password accumulators in the list.

[0018] The present invention also provides a user attribute verification device in a data space, applied to a service provider, comprising: The first receiving module is used to receive service requests sent by the participants; the service request includes user identity credentials, a password accumulator, a target attribute, and evidence of the target attribute in the password accumulator; The verification module is used to determine the participant to which the password accumulator belongs based on the user's identity credentials, and to allow the participant to access the service when the target attribute is stored in the password accumulator based on the target attribute and evidence of the target attribute in the password accumulator.

[0019] The present invention also provides a user attribute verification device in a data space, applied to participating parties, comprising: The second receiving module is used to receive attribute requirements sent by the service provider, determine the target attribute according to the attribute requirements, and send a service request back to the service provider; the service request includes user identity credentials, a password accumulator, the target attribute, and evidence of the target attribute in the password accumulator; The third receiving module is used to receive verification pass information from the service provider and access the service provider's service; the verification pass information indicates that the service provider determines the participant to which the password accumulator belongs based on the user's identity credentials, and determines that the target attribute is stored in the password accumulator based on the target attribute and evidence of the target attribute in the password accumulator.

[0020] This invention also provides a user attribute verification device in a data space, applied to a trusted service provider, comprising: The fourth receiving module is used to receive all user attributes and identity information sent by the participants; The generation module is used to generate user identity credentials, a password accumulator, and evidence of each user attribute in the password accumulator based on all user attributes and identity information. The sending module is used to send user identity credentials, password accumulator, and evidence of each user attribute in the password accumulator to the participants.

[0021] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement a method for verifying user attributes in any of the data spaces described above.

[0022] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a method for verifying user attributes in any of the data spaces described above.

[0023] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements a method for verifying user attributes in any of the data spaces described above.

[0024] This invention provides a method, apparatus, device, and medium for verifying user attributes in a data space. By receiving user identity credentials, a password accumulator, a target attribute, and evidence of the target attribute in the password accumulator sent by a participant, and determining the participant to whom the password accumulator belongs based on the user identity credentials, and determining that the target attribute is stored in the password accumulator based on the target attribute and the evidence of the target attribute in the password accumulator, the participant is allowed to access the service. This achieves stronger privacy protection by verifying only "accumulator + attribute evidence" without needing to verify the complete semantic chain. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0026] Figure 1 This is a flowchart illustrating the user attribute verification method in the data space provided by the present invention. Figure 1 .

[0027] Figure 2 This is a flowchart illustrating the user attribute verification method in the data space provided by the present invention. Figure 2 .

[0028] Figure 3 This is a flowchart illustrating the user attribute verification method in the data space provided by the present invention. Figure 3 .

[0029] Figure 4 This is a schematic diagram of the structure of the user attribute verification device in the data space provided by the present invention. Figure 1 .

[0030] Figure 5 This is a schematic diagram of the structure of the user attribute verification device in the data space provided by the present invention. Figure 2 .

[0031] Figure 6 This is a schematic diagram of the structure of the user attribute verification device in the data space provided by the present invention. Figure 3 .

[0032] Figure 7 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0033] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0034] Figure 1 This diagram illustrates a flowchart of a user attribute verification method in a data space provided by the present invention. (See attached diagram.) Figure 1 This method is applied to service provisioning methods and includes the following steps: Step 11: Receive the service request sent by the participant; the service request includes user identity credentials, password accumulator, target attributes, and evidence of the target attributes in the password accumulator.

[0035] Step 12: Determine the participant to which the password accumulator belongs based on the user's identity credentials, and when the target attribute is stored in the password accumulator based on the target attribute and evidence of the target attribute in the password accumulator, allow the participant to access the service.

[0036] Regarding steps 11 and 12, it should be noted that in this invention, the service provider is an individual, enterprise, or other organization that provides data services. The service requester is the user who needs to use the service, i.e., the participant. When a participant needs to access the data service provided by the service provider, they need to send a service request to the service provider. Upon receiving the service request, the service provider intends to verify the participant, that is, to verify the participant's user attributes to ensure secure access to the data service.

[0037] In this invention, for a participant to obtain a recognized identity, the trusted service provider (TSP) needs to verify the identity in order to generate reliable content that can be verified by the service provider. Therefore, the TSP verifies the participant's identity and identity attributes, and issues a cryptographic accumulator storing these attributes to the participant.

[0038] In this invention, the participant submits identity materials to the TSP, which verifies these materials. If verification is successful, a unique user identity credential (such as a DID) is issued to the participant, and a password accumulator storing user attributes is generated for them. Specifically: 1. Define mapping rules to map encoded values ​​(such as encoding user attributes) into values ​​that can be stored in a password accumulator. These mapping rules can be made public and shared with service providers. 2. To ensure the validity of each user attribute, i.e. the validity of the data stored in the password accumulator, the trusted service provider can also set the validity period of each attribute and bind the validity period of the attribute to the attribute value, such as forming a composite value of attribute plus validity period, like "attribute A+20250607". The composite value is mapped to the value that can be stored in the password accumulator and stored in the password accumulator until all attributes have been stored. 3. Map the user identity credentials of the participants to values ​​that can be stored in the password accumulator, store them in the password accumulator, bind the identity credentials to the password accumulator, and generate evidence for each attribute to prove that the attribute is in the password accumulator. 4. TSP is used to sign the cryptographic accumulator (the cryptographic accumulator is simply a string of numbers); 5. TSP constructs a list of password accumulators, storing valid password accumulators in the list. If a user's attributes are temporarily suspended due to violations or other reasons, the corresponding evidence for the attribute is stored in the list and marked as invalid. If a password accumulator is temporarily suspended, it is deleted from the list.

[0039] In this invention, the Trusted Service Provider supports dynamic addition / deletion, reducing costs for TSPs and users. When adding an attribute, only the prime factors of the attribute need to be added to the accumulator and a new evidence needs to be generated. When deleting an attribute, only the evidence of the attribute needs to be marked as invalid (without updating the entire accumulator), without requiring the TSP to reissue, thus reducing the issuance pressure on the TSP.

[0040] Finally, the trusted service provider sends the user's identity credentials, the password accumulator, and evidence of each user attribute in the password accumulator to the participating parties. The participating parties store the user's identity credentials, the password accumulator, and evidence of each user attribute in the password accumulator. Both the accumulator value and attribute evidence are of fixed size (e.g., 256 bits), eliminating the need to transmit the complete verifiable credential (VC) and its credentialSubject and proof fields (which may contain multiple attributes and a long signature chain), thus reducing network bandwidth consumption.

[0041] In this invention, the service provider returns the attribute requirements necessary for using the service to the participants, i.e., the attribute type. This attribute type informs the participants to determine the target attribute based on the attribute type.

[0042] In response, the participants send a service request to the service provider. The service request includes user identity credentials, a password accumulator, target attributes, and evidence of the target attributes in the password accumulator.

[0043] The service provider authenticates the participants' identities and verifies their unique identity credentials.

[0044] The user's identity credentials are used to determine whether the password accumulator belongs to a participating party. Specifically, this involves determining whether the user's identity credentials are stored in the password accumulator. If they are, the password accumulator belongs to a participating party; otherwise, it does not.

[0045] Then, based on the target attribute and evidence of the target attribute in the cryptographic accumulator, if it is determined that the target attribute is stored in the cryptographic accumulator, the participant is allowed to access the service. If it is determined that the target attribute is not stored in the cryptographic accumulator, the participant is not allowed to access the service.

[0046] It should also be noted that before determining the participant to whom the password accumulator belongs based on the user's identity credentials, it is necessary to determine whether the password accumulator has preset signature information and to verify its legitimacy. Specifically, the service provider verifies whether the password accumulator is signed by a legitimate TSP. After verification, the service provider checks the TSP's list of legitimate accumulators to see if the accumulator and its evidence are valid, ensuring that the accumulator and its identity attributes have not been temporarily revoked.

[0047] Furthermore, when the service request includes a composite value of the target attribute and the target attribute validity period, rather than just the target attribute, the participant to which the password accumulator belongs is determined based on the user's identity credentials. Based on the composite value of the target attribute and the target attribute validity period, as well as the evidence that the target attribute is in the password accumulator, if it is determined that the target attribute is stored in the password accumulator and has not expired according to the target attribute validity period, the participant is allowed to access the service.

[0048] It needs to be further explained that the process by which the aforementioned trusted service provider generates the cryptographic accumulator is more specifically as follows: 1) Set mapping rules for TSP. Used to map encoded values ​​to prime numbers ; 2) The TSP generates an RSA key pair (large prime number p / q, modulus N) for the participants, selects a generator g, and initializes the accumulator value to 1 (indicating an empty attribute set), where (p, q) are private parameters, which are stored secretly by the TSP; 3) TSP encodes the attribute values ​​of the participants into numerical values ​​(such as using UTF8), and then maps them to prime numbers using mapping rules, such as mapping "nationality China + 20250607" to "101"; 4) TSP sets the prime number mapping of all attributes of the participants plus the validity period composite value and the participant's unique certificate as pi (0<=i<=n), and uses the product of pi as the exponent to update the accumulator value (A = g). p0p1p2...pn mod N); 5) TSP calculates evidence for each attribute (w = g) (总素数乘积 / 当前属性素数)(mod N), the evidence can only prove that "this attribute belongs to the accumulator", and cannot be used to infer other attributes; 6) After signing the accumulator value, TSP sends the accumulator value A and the evidence to the participating parties; Therefore, in this invention, when a participant requests a service, and the service provider confirms the legitimacy of the accumulator, the verification method for verifying the participant's attributes is as follows: For attribute pi, the formula wi pi ≡ A mod N checks whether the attribute is in the accumulator. If the equation is true, it proves that the attribute is indeed in the user's password accumulator.

[0049] The method for verifying user attributes in a data space provided by this invention receives user identity credentials, a password accumulator, a target attribute, and evidence of the target attribute in the password accumulator sent by a participant. Based on the user identity credentials, the method determines the participant to whom the password accumulator belongs. Based on the target attribute and the evidence of the target attribute in the password accumulator, the method determines that when the target attribute is stored in the password accumulator, the participant is allowed to access the service. This achieves stronger privacy protection by verifying only "accumulator + attribute evidence" without needing to verify the complete semantic chain.

[0050] The following describes the method for verifying user attributes in the data space provided by the present invention. The method for verifying user attributes in the data space described below is applied to the participating parties and can be referred to in correspondence with the method for verifying user attributes in the data space described above.

[0051] Figure 2 This diagram illustrates a flowchart of a user attribute verification method in a data space provided by the present invention. (See attached diagram.) Figure 2 The method includes the following steps: Step 21: Receive the attribute requirements sent by the service provider, determine the target attribute according to the attribute requirements, and send a service request back to the service provider; the service request includes user identity credentials, password accumulator, target attribute, and evidence of the target attribute in the password accumulator; Step 22: Receive the verification pass information from the service provider and access the service provider's service; the verification pass information indicates that the service provider has determined the participant to which the password accumulator belongs based on the user's identity credentials, and has determined that the target attribute is stored in the password accumulator based on the target attribute and the evidence of the target attribute in the password accumulator.

[0052] In a further method of the above method, the method further includes: Send all user attributes and identity information to trusted service providers; Receive user identity credentials, password accumulator, and evidence of each user attribute in the password accumulator generated by the trusted server provider based on all user attributes and identity information.

[0053] In a further step of the above method, the method further includes: receiving a composite value of user attributes and user attribute validity periods generated by a trusted server provider based on all user attributes and the validity period configured for each user attribute.

[0054] Since the method in this embodiment of the invention is based on the same principle as the method in the above embodiments, more detailed explanations will not be repeated here.

[0055] Figure 3 This diagram illustrates a flowchart of a user attribute verification method in a data space provided by the present invention. (See attached diagram.) Figure 3 This method, applied to trusted service providers, includes the following steps: Step 31: Receive all user attributes and identity information sent by the participants.

[0056] Step 32: Generate user identity credentials, a password accumulator, and evidence of each user attribute in the password accumulator based on all user attributes and identity information.

[0057] Step 33: Send the user identity credentials, password accumulator, and evidence of each user attribute in the password accumulator to the participating parties.

[0058] In a further step of the above method, the password accumulator stores all user attributes and user identity credentials.

[0059] In a further method of the above method, the method further includes: Set an expiration date for each user attribute, and store the combined value of the user attribute and its expiration date into the password accumulator.

[0060] In a further step of the above method, the method further includes: configuring preset signature information for the cryptographic accumulator; constructing a cryptographic accumulator list and storing valid cryptographic accumulators in the list.

[0061] Since the method in this embodiment of the invention is based on the same principle as the method in the above embodiments, more detailed explanations will not be repeated here.

[0062] The following describes the user attribute verification device in the data space provided by the present invention. The user attribute verification device in the data space described below and the user attribute verification method in the data space described above can be referred to in correspondence.

[0063] Figure 4 This diagram illustrates the structure of a user attribute verification device in a data space provided by the present invention. (See attached diagram.) Figure 4 The device is used by a service provider and includes a first receiving module 41 and a verification module 42, wherein: The first receiving module is used to receive service requests sent by the participants; the service request includes user identity credentials, a password accumulator, target attributes, and evidence of the target attributes in the password accumulator; The verification module is used to determine the participant to which the password accumulator belongs based on the user's identity credentials, and to allow the participant to access the service when the target attribute is stored in the password accumulator based on the target attribute and evidence of the target attribute in the password accumulator.

[0064] Figure 5 This diagram illustrates the structure of a user attribute verification device in a data space provided by the present invention. (See attached diagram.) Figure 5 The device is applied to the participating parties and includes a second receiving module 51 and a third receiving module 52, wherein: The second receiving module is used to receive attribute requirements sent by the service provider, determine the target attribute based on the attribute requirements, and send a service request back to the service provider. The service request includes user identity credentials, a password accumulator, the target attribute, and evidence of the target attribute in the password accumulator. The third receiving module is used to receive the verification pass information fed back by the service provider and access the service provider's service; the verification pass information indicates that the service provider determines the participant to which the password accumulator belongs based on the user's identity credentials, and determines that the target attribute is stored in the password accumulator based on the target attribute and the evidence of the target attribute in the password accumulator.

[0065] Figure 6 This diagram illustrates the structure of a user attribute verification device in a data space provided by the present invention. (See attached diagram.) Figure 6 The device is used by a trusted service provider and includes a fourth receiving module 61, a generating module 62, and a sending module 63, wherein: The fourth receiving module is used to receive all user attributes and identity information sent by the participants; The generation module is used to generate user identity credentials, a password accumulator, and evidence of each user attribute in the password accumulator based on all user attributes and identity information. The sending module is used to send user identity credentials, password accumulator, and evidence of each user attribute in the password accumulator to the participants.

[0066] Since the apparatus of this embodiment is based on the same principle as the method of the above embodiment, more detailed explanations will not be repeated here.

[0067] It should be noted that, in the embodiments of the present invention, the relevant functional modules can be implemented by a hardware processor.

[0068] The user attribute verification device in the data space provided by this invention receives user identity credentials, a password accumulator, a target attribute, and evidence of the target attribute in the password accumulator sent by the participants. It determines the participant to which the password accumulator belongs based on the user identity credentials, and allows the participants to access the service when the target attribute is stored in the password accumulator based on the target attribute and the evidence of the target attribute in the password accumulator. This achieves stronger privacy protection by verifying only "accumulator + attribute evidence" without needing to verify the complete semantic chain.

[0069] Figure 7 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 7 As shown, the electronic device may include: a processor 71, a communication interface 72, a memory 73, and a communication bus 74, wherein the processor 71, the communication interface 72, and the memory 73 communicate with each other via the communication bus 74. The processor 71 can call logical instructions in the memory 73 to execute a method for verifying user attributes in the data space, the method including: Receive service requests sent by participating parties; the service request includes user identity credentials, password accumulator, target attributes, and evidence of the target attributes in the password accumulator; The participant to which the password accumulator belongs is determined based on the user's identity credentials, and when the target attribute is stored in the password accumulator based on the target attribute and evidence of the target attribute in the password accumulator, the participant is allowed to access the service.

[0070] Or, Receive attribute requirements sent by the service provider, determine the target attribute based on the attribute requirements, and send a service request back to the service provider; the service request includes user identity credentials, password accumulator, target attribute, and evidence of the target attribute in the password accumulator; The user receives a verification pass message from the service provider and accesses the service provider's service. The verification pass message indicates that the service provider determines the participant to which the password accumulator belongs based on the user's identity credentials, and determines that the target attribute is stored in the password accumulator based on the target attribute and evidence of the target attribute in the password accumulator.

[0071] Or, Receive all user attributes and identity information sent by the participants; User identity credentials, password accumulator, and evidence of each user attribute in the password accumulator are generated based on all user attributes and identity information. Send the user's identity credentials, password accumulator, and evidence of each user's attributes in the password accumulator to the participating parties.

[0072] Furthermore, the logical instructions in the aforementioned memory 73 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0073] On the other hand, the present invention also provides a computer program product, the computer program product including a computer program, the computer program being stored on a non-transitory computer-readable storage medium, and when the computer program is executed by a processor, the computer is able to execute the above-mentioned method for verifying user attributes in the data space.

[0074] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the aforementioned method for verifying user attributes in the data space.

[0075] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0076] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for verifying user attributes in a data space, characterized in that, The application is applied to a service provider, comprising: receiving a service request sent by a participant; the service request comprises a user identity credential, a password accumulator, a target attribute, and evidence of the target attribute in the password accumulator; determining the participant to which the password accumulator belongs according to the user identity credential, and determining that the target attribute is stored in the password accumulator according to the target attribute and the evidence of the target attribute in the password accumulator, and allowing the participant to access the service.

2. The method of claim 1, wherein, The method further comprises: determining whether the password accumulator has preset signature information before determining the participant to which the password accumulator belongs according to the user identity credential, and determining the legitimacy of the password accumulator.

3. The method of claim 2, wherein, The method further comprises: sending a query request to a trusted service provider after determining that the password accumulator has the preset signature information; the query request comprises the password accumulator and the evidence of the target attribute in the password accumulator; receiving a query result sent by the trusted service provider, and determining the validity of the password accumulator and the evidence according to the query result.

4. The method of claim 1, wherein, The service request further comprises a composite value of the target attribute and a validity period of the target attribute, and correspondingly, the participant is allowed to access the service according to the target attribute and the composite value of the validity period of the target attribute, and the evidence of the target attribute in the password accumulator, and the target attribute is stored in the password accumulator and has not expired according to the validity period of the target attribute.

5. The method of claim 1, wherein, All user attributes or a composite value of all user attributes and corresponding user attribute validity periods are stored in the password accumulator.

6. A method for verifying user attributes in a data space, characterized in that, The application is applied to a participant, comprising: receiving an attribute requirement sent by a service provider, determining a target attribute according to the attribute requirement, and feeding back a service request to the service provider; the service request comprises a user identity credential, a password accumulator, the target attribute, and evidence of the target attribute in the password accumulator; receiving verification pass information fed back by the service provider, and accessing the service of the service provider; the verification pass information indicates that the service provider determines the participant to which the password accumulator belongs according to the user identity credential, and determines that the target attribute is stored in the password accumulator according to the target attribute and the evidence of the target attribute in the password accumulator.

7. The method of claim 6, wherein, The method further comprises: sending all user attributes and identity information to a trusted service provider; receiving a user identity credential, a password accumulator, and evidence of each user attribute in the password accumulator generated by the trusted service provider according to all user attributes and identity information.

8. The method of claim 6, wherein, The method further comprises: receiving a composite value of a user attribute and a user attribute validity period generated by the trusted service provider according to all user attributes and a validity period configured for each user attribute.

9. A method for verifying a user attribute in a data space, characterized by, The application is applied to a trusted service provider, comprising: receiving all user attributes and identity information sent by a participant; generating a user identity credential, a password accumulator, and evidence of each user attribute in the password accumulator according to all user attributes and identity information; sending the user identity credential, the password accumulator, and the evidence of each user attribute in the password accumulator to the participant.

10. The method of claim 9, wherein, The password accumulator stores all user attributes and user identity credentials.

11. The method of claim 9 or 10, wherein, The method further comprises: Setting a validity period for each user attribute, and storing the composite value of the user attribute and the user attribute validity period in the password accumulator.

12. The method of claim 9, wherein, The method further comprises: configuring preset signature information for the password accumulator; and constructing a password accumulator list to store valid password accumulators in the list.

13. A device for verifying user attributes in a data space, characterized in that, Applied to a service provider, comprising: A first receiving module configured to receive a service request sent by a participant; the service request comprising user identity credentials, a password accumulator, a target attribute, and evidence of the target attribute in the password accumulator; A verification module configured to determine, according to the user identity credentials, that the password accumulator belongs to the participant, and to determine, according to the target attribute and the evidence of the target attribute in the password accumulator, that the target attribute is stored in the password accumulator, thereby allowing the participant to access the service.

14. A device for verifying user attributes in a data space, characterized in that, Applied to a participant, comprising: A second receiving module configured to receive an attribute requirement sent by a service provider, to determine a target attribute according to the attribute requirement, and to feed back a service request to the service provider; the service request comprising user identity credentials, a password accumulator, a target attribute, and evidence of the target attribute in the password accumulator; A third receiving module configured to receive verification pass information fed back by the service provider, and to access the service of the service provider; the verification pass information indicating that the service provider determines, according to the user identity credentials, that the password accumulator belongs to the participant, and determines, according to the target attribute and the evidence of the target attribute in the password accumulator, that the target attribute is stored in the password accumulator.

15. A device for verifying user attributes in a data space, characterized in that, Applied to a trusted service provider, comprising: A fourth receiving module configured to receive all user attributes and identity information sent by a participant; A generating module configured to generate, according to all user attributes and identity information, user identity credentials, a password accumulator, and evidence of each user attribute in the password accumulator; A sending module configured to send the user identity credentials, the password accumulator, and the evidence of each user attribute in the password accumulator to the participant.

16. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, The processor executes the program to implement the method for verifying user attributes in a data space according to any one of claims 1-5, or to implement the method for verifying user attributes in a data space according to any one of claims 6-8, or to implement the method for verifying user attributes in a data space according to any one of claims 9-12.

17. A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method for verifying user attributes in a data space according to any one of claims 1-5, or to implement the method for verifying user attributes in a data space according to any one of claims 6-8, or to implement the method for verifying user attributes in a data space according to any one of claims 9-12.

18. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the method for verifying user attributes in a data space according to any one of claims 1-5, or to implement the method for verifying user attributes in a data space according to any one of claims 6-8, or to implement the method for verifying user attributes in a data space according to any one of claims 9-12.