Distributed digital identity cross-domain mutual identification security activity probability consensus method
By constructing a distributed digital identity cross-domain mutual recognition security live probabilistic consensus method, and utilizing notary groups and memory consensus protocols, the security and reliability issues of cross-domain authentication in the context of distributed identity are solved, achieving efficient and flexible identity verification and data sharing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-21
- Publication Date
- 2026-04-14
AI Technical Summary
In the context of distributed digital identity, how can we achieve secure and reliable identity authentication and data sharing between different domains, and avoid data silos and single points of failure caused by the involvement of centralized third-party authentication authorities?
A distributed digital identity cross-domain mutual recognition security live probabilistic consensus method is constructed. Cross-domain trust is built through a notary group, a security liveness binary search method is used to select the minimum size of the notary group, Byzantine fault tolerance is used to improve the verification fault tolerance rate, and a memory consensus protocol is combined to verify the authenticity and reliability of user identity information.
It achieves highly secure, privacy-preserving, and efficient cross-domain identity authentication, reducing authentication overhead and computational costs, and meeting the flexibility requirements of different application scenarios.
Smart Images

Figure CN121864348A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a distributed digital identity cross-domain mutual recognition security live probabilistic consensus method, belonging to the field of cross-domain identity authentication and privacy protection technology, and applied to cross-domain identity verification and data sharing of the same user in blockchain. Background Technology
[0002] Digital identity is a crucial identifier of user identity on the internet, primarily used to provide social identity verification and related behavioral data to other entities, organizations, and individuals during network communications. The development of digital identity is generally considered to have gone through four stages: centralized identity, federated identity, user-centric identity, and decentralized identity. Centralized identity is managed and controlled by a single authoritative institution. This scheme offers advantages such as centralized information and convenient management, making it the most widely adopted identity information management solution on the internet. However, its data storage is overly centralized, preventing users from controlling their identities. If the central institution is attacked externally, privacy breaches and management failures may occur, posing a significant security threat to user identity data. Therefore, since the introduction of federated identity schemes, research on identity management methods has gradually shifted from centralized to decentralized identity management, and identity information has moved from centralized storage to distributed storage, managed by individual users. The value of digital information lies in its fluidity; data sharing and trading are key drivers of market development. The increasing demand for data from enterprises, society, and individuals further promotes information exchange and cross-domain access across various sectors. However, in multi-domain environments, the lack of accurate and reliable authentication increases the risk of identity forgery, unauthorized access, and privacy leaks when users access resources across domains and perform various operations. Therefore, how to securely and efficiently implement cross-domain user identity registration, management, authentication, and revocation has become an important research direction. Before providing digital resources, administrators must strictly verify the identities of new users to prevent unauthorized access and potential data loss and privacy leaks, ensuring the security and reliability of cross-domain authentication.
[0003] Decentralized Identity (DID) is a new type of decentralized identifier that enables verifiable decentralized digital identities. Control of a DID rests with the identity holder, who can be any entity, including but not limited to people, organizations, transactions, and data models. This control is separate from centralized registries, certificate authorities, and identity providers, meaning it doesn't rely on other institutions to prove the holder's identity. In short, while other institutions may be used to assist in the discovery of DID-related information, DID allows the holder to prove control over their identity without relying on permission from other parties. DID manages personal identities in a decentralized manner, avoiding the intervention of centralized third-party certification authorities and ensuring the privacy and security of personal data. DID establishes broad digital trust management of identities across systems in a decentralized manner. User identity information is distributed across multiple systems and controlled by the individual user, achieving decentralized identity authentication. However, as the requirements for data circulation and sharing increase, there is also a need for information exchange between systems. If user authentication relies solely on multiple organizations participating in the authentication process, it lacks credibility proof and presents security vulnerabilities. Traditional cross-domain identity authentication schemes mostly rely on third-party devices issuing digital certificates and other credentials to prove the trustworthiness of user identities. However, the involvement of untrusted third-party centralized institutions undermines the distributed requirements of decentralized identity, creating data silos and single points of failure. Therefore, how to achieve secure and reliable identity authentication across different domains and facilitate inter-domain data sharing within a distributed digital identity framework has become one of the main research challenges in this field.
[0004] Current cross-domain authentication schemes are gradually shifting from relying on untrusted third-party platforms for centralized user identity management to using distributed digital identity as the infrastructure to build data transmission, information management, and user authentication mechanisms between different participating domains. This improves the scalability of the entire system and securely and efficiently enables trusted access and data sharing for users across multiple domains, thereby protecting user identity information and privacy. In this process, the transmission, verification, and storage of user information are encrypted and reliably authenticated, laying a solid foundation for promoting the efficient sharing and widespread circulation of data assets. Cross-domain authentication schemes designed based on distributed digital identity not only help build an open and shared digital information environment but also promote data flow and transactions across various industries, maximizing the utilization value of digital resources.
[0005] Cross-domain authentication consensus schemes for distributed digital identity serve as trusted identity authentication tools, providing a new method for verifying the reliability and legitimacy of user identity information. Specifically, an effective cross-domain authentication scheme needs to meet three requirements: reliable user authentication, secure information storage, and protection of personal privacy.
[0006] Therefore, achieving cross-domain mutual recognition in user digital identity authentication under a distributed architecture, with the premise of improving security and reliability, has become an urgent problem to be solved. Summary of the Invention
[0007] The purpose of this invention is to address the technical problem of cross-domain mutual recognition in user digital identity authentication under a distributed architecture, with the premise of improving security and reliability, and to propose a distributed digital identity cross-domain mutual recognition security liveness probability consensus method.
[0008] The objective of this invention is achieved through the following technical solution:
[0009] This invention discloses a distributed digital identity cross-domain mutual recognition security liveness probability consensus method, comprising the following steps:
[0010] Step 1: Construct a cross-domain distributed digital identity verification model, dividing the model into a base layer, a consensus layer, and an application layer according to hierarchical functions; further, the base layer is used to build cross-domain trust through a group of notaries, the consensus layer is used for cross-domain authentication of users through the trust of notaries, and the application layer is used for users' cross-domain service interaction.
[0011] Step 1.1: The base layer is used to build cross-domain trust through notary groups. It consists of the current domain A and the target domain B of blockchains with the same functions. Both the current domain A and the target domain B have a node management module for storing node identity information, a notary group management module for storing notary group identity information, and a storage module for storing user identity information, which includes decentralized identifiers, user information, and verifiable credentials. This will provide data storage interaction for the consensus layer.
[0012] Step 1.2: The consensus layer is used for cross-domain authentication through the trust of notaries to verify users, and will provide cross-domain trust interaction for user authentication to the application layer;
[0013] Step 1.2.1: Select the smallest group of notaries using the security-active dichotomy method;
[0014] Step 1.2.2: Authenticate user identity information using a minimum-sized group of notaries;
[0015] Step 1.2.3: Utilize Byzantine fault tolerance to improve the fault tolerance of verification by the smallest notary group;
[0016] Step 1.3: The application layer is used for cross-domain service interaction between users. The member nodes of this layer consist of issuers, users, and verifiers. Issuers provide identity credentials to users, and users, as service users and verifiers, obtain user applications and return verification results.
[0017] Step 2: The user obtains a verifiable credential issued by the issuer within the current domain A;
[0018] Step 2.1: The user sends a valid identity registration request to the current domain A;
[0019] Step 2.2: The current domain A verifies the user's identity using a decentralized identifier and stores the decentralized identifier in the storage module;
[0020] Step 2.3: The user sends the decentralized identifier to the issuer of the current domain A and requests a verifiable credential from the issuer;
[0021] Step 2.4: After verifying the authenticity and legitimacy of the user, the issuer of the current domain A issues a verifiable credential to the user and stores the verifiable credential in the storage module;
[0022] Step 3: The user makes a cross-domain access from the current domain A to the target domain B;
[0023] Step 3.1: When a user makes a cross-domain access request, the user sends verifiable credentials to the verifier of the target domain B;
[0024] Step 3.2: The verifier of target domain B packages the user's verifiable credentials and access request and sends them to the trusted notary group for user identity verification;
[0025] Step 3.3: In the current domain A and the target domain B, use the security liveness dichotomy method to obtain the minimum notary group size and select the notary group, and return the verification results of the authenticity and reliability of the user identity information through the memory consensus protocol to the verifier in the target domain B.
[0026] Step 3.3.1: Within the current domain A and the target domain B, select the minimum notary group size Q from the candidate notary group sizes using the security activity dichotomy method shown in equation (1). min Perform the screening;
[0027]
[0028] Where n is the number of nodes in the current domain A and the target domain B, t is the percentage of malicious nodes in the current domain A and the target domain B, q is the total number of nodes, m is the number of malicious nodes, and m / q is the percentage of malicious nodes; K is a security parameter used to limit the probability of failure in selecting events.
[0029] Step 3.3.2: Based on the minimum notary group size Q min Selecting the notary public;
[0030] Step 3.3.3: Select a group of notaries to verify the authenticity and reliability of user identity information using a consensus protocol;
[0031] Step 3.3.4: Select a notary group to return the verification result to the verifier in the target domain B, and store the verification result in the storage module;
[0032] Step 4: The verifier in target domain B allows users to access the domain across domains and notifies the user of the verification result;
[0033] Beneficial effects:
[0034] Compared with existing technologies, it has the following beneficial effects:
[0035] 1. The designed identity authentication method has high security and privacy protection. This invention uses internal notary group technology to ensure the security and privacy of user identity information during the authentication process, prevent information leakage threats, and achieve secure and reliable authentication while protecting privacy.
[0036] 2. The method is highly efficient. By selecting the smallest feasible notary group, the present invention reduces the number of nodes participating in the certification, thereby reducing the model certification overhead and computational cost, and thus achieving high-efficiency model operation.
[0037] 3. The method has good flexibility. The notary group selection algorithm and memory consensus protocol in this solution have modular characteristics and can adjust parameters according to the security requirements of actual application scenarios, thereby meeting the different needs of solution users. Attached Figure Description
[0038] Figure 1 This is a diagram of the cross-domain identity authentication model of the present invention;
[0039] Figure 2 This is a schematic diagram of the workflow of the present invention. Detailed Implementation
[0040] To better illustrate the purpose and advantages of this invention, the invention will be further described below with reference to the accompanying drawings and examples. It should be noted that the implementation of this invention is not limited to the following embodiments, and any modifications or alterations made to this invention will fall within the scope of protection of this invention.
[0041] This example illustrates a scenario of cross-domain authentication using distributed digital identities. For instance, in a job-seeking scenario after graduation, the user is a student at a university with a secure and trusted distributed digital identity. This identity includes transcripts, certificates of honor, degree certificates, and other identity verification materials. When applying for a job, the graduate sends their resume and academic records to company B. However, company B cannot independently verify the accuracy and authenticity of this information, while university A cannot trust the company to provide access to its internal database for authentication.
[0042] Example
[0043] like Figure 1 As shown in the figure, the specific implementation steps of the distributed digital identity cross-domain mutual recognition security liveness probability consensus method in this embodiment are as follows:
[0044] Step 1: Construct a cross-domain distributed digital identity verification model, dividing the model into a base layer, a consensus layer, and an application layer according to hierarchical functions; further, the base layer is used to build cross-domain trust through a group of notaries, the consensus layer is used for cross-domain authentication of users through the trust of notaries, and the application layer is used for users' cross-domain service interaction.
[0045] Step 1.1: The base layer is used to build cross-domain trust through notary groups. It consists of the current domain A and the target domain B of blockchains with the same functions. Both the current domain A and the target domain B have a node management module for storing node identity information, a notary group management module for storing notary group identity information, and a storage module for storing user identity information, which includes decentralized identifiers, user information, and verifiable credentials. This will provide data storage interaction for the consensus layer.
[0046] Step 1.2: The consensus layer is used for cross-domain authentication through the trust of notaries to verify users, and will provide cross-domain trust interaction for user authentication to the application layer;
[0047] Step 1.2.1: Select the smallest group of notaries using the security-active dichotomy method;
[0048] Step 1.2.2: Authenticate user identity information using a minimum-sized group of notaries;
[0049] Step 1.2.3: Utilize Byzantine fault tolerance to improve the fault tolerance of verification by the smallest notary group;
[0050] Step 1.3: The application layer is used for cross-domain service interaction between users. The member nodes of this layer consist of issuers, users, and verifiers. Issuers provide identity credentials to users, and users, as service users and verifiers, obtain user applications and return verification results.
[0051] In this example, the school and the company are designated as the current domain A and the target domain B, respectively. The graduate has a legally registered identity and genuine student information in the school's database, while the job application resume sent by the graduate to the company serves as the access request and is the credential for passing the screening process and proceeding to the interview.
[0052] Step 2: The user obtains a verifiable credential issued by the issuer within the current domain A;
[0053] Step 2.1: The user sends a valid identity registration request to the current domain A;
[0054] Step 2.2: The current domain A verifies the user's identity using a decentralized identifier and stores the decentralized identifier in the storage module;
[0055] Step 2.3: The user sends the decentralized identifier to the issuer of the current domain A and requests a verifiable credential from the issuer;
[0056] Step 2.4: After verifying the authenticity and legitimacy of the user, the issuer of the current domain A issues a verifiable credential to the user and stores the verifiable credential in the storage module;
[0057] In the embodiments, such as Figure 2 As shown, the student identity information and student ID number obtained by graduates during their enrollment serve as their legal identity, while their academic records, graduation certificates, and other documents obtained during their time at the university serve as verifiable credentials. The university's database stores graduates' identity information for verification purposes.
[0058] Step 3: The user makes a cross-domain access from the current domain A to the target domain B;
[0059] Step 3.1: When a user makes a cross-domain access request, the user sends verifiable credentials to the verifier of the target domain B;
[0060] Step 3.2: The verifier of target domain B packages the user's verifiable credentials and access request and sends them to the trusted notary group for user identity verification;
[0061] Step 3.3: In the current domain A and the target domain B, use the security liveness dichotomy method to obtain the minimum notary group size and select the notary group, and return the verification results of the authenticity and reliability of the user identity information through the memory consensus protocol to the verifier in the target domain B.
[0062] Step 3.3.1: Within the current domain A and the target domain B, select the minimum notary group size Q from the candidate notary group sizes using the security activity dichotomy method shown in equation (1). min Perform the screening;
[0063]
[0064] Where n is the number of nodes in the current domain A and the target domain B, t is the percentage of malicious nodes in the current domain A and the target domain B, q is the total number of nodes, m is the number of malicious nodes, and m / q is the percentage of malicious nodes; K is a security parameter used to limit the probability of failure in selecting events.
[0065] Step 3.3.2: Based on the minimum notary group size Q min Selecting the notary public;
[0066] Step 3.3.3: Select a group of notaries to verify the authenticity and reliability of user identity information using a consensus protocol;
[0067] Step 3.3.4: Select a notary group to return the verification result to the verifier in the target domain B, and store the verification result in the storage module;
[0068] Step 4: The verifier in target domain B allows users to access the domain across domains and notifies the user of the verification result;
[0069] In this embodiment, the graduate sends a resume containing personal information and job application details to the target company as an access request. When the human resources department of company B receives the resume, it verifies it. The school's academic affairs system acts as the trusted notary group for the current domain, and the company's human resources department acts as the trusted notary group for the target domain; the two trust each other's review authority and capabilities. A minimum-sized notary group, calculated from the two departments' systems, jointly reviews the graduate's resume. If any falsified or false personal information is found in the graduate's resume, such as awards, research experience, etc., the request is rejected; if the graduate's resume is authentic and credible, the file is authenticated and allowed to proceed to the next access stage.
[0070] To further demonstrate the superiority of this invention, simulation experiments were conducted to verify its effectiveness. As shown in Table 1, the minimum notary group size obtained in the experiment is as follows under different total number of nodes, malicious node rate, and security threshold. Using the total number of nodes as the input to the consensus scheme, we set the number of simulated nodes in the experiment to [4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16], and conducted experiments using clique and cycle network structures to obtain the consensus time delay and throughput under different numbers of nodes.
[0071] Table 1 Minimum size of notary group under different parameters
[0072]
[0073] Table 2. Consensus protocol performance under different parameters
[0074]
[0075] Table 2 shows the operating performance, latency, and throughput changes of the consensus scheme under different numbers of nodes. As the number of nodes increases from 4 to 16, the latency and throughput show an upward trend, but remain within a relatively stable range. The overall efficiency is still high, and lightweight and efficient authentication can be achieved while maintaining system security.
[0076] The above detailed description further illustrates the purpose, technical solution, and beneficial effects of the invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A distributed digital identity cross-domain mutual recognition security liveness probabilistic consensus method, characterized in that: Includes the following steps, Step 1: Construct a cross-domain distributed digital identity verification model, dividing the model into a base layer, a consensus layer, and an application layer according to hierarchical functions; further, the base layer is used to build cross-domain trust through a group of notaries, the consensus layer is used for cross-domain authentication of users through the trust of notaries, and the application layer is used for users' cross-domain service interaction. Step 2: The user obtains a verifiable credential issued by the issuer within the current domain A; Step 3: The user makes a cross-domain access from the current domain A to the target domain B; Step 3.1: When a user makes a cross-domain access request, the user sends verifiable credentials to the verifier of the target domain B; Step 3.2: The verifier of target domain B packages the user's verifiable credentials and access request and sends them to the trusted notary group for user identity verification; Step 3.3: In the current domain A and the target domain B, use the security liveness dichotomy method to obtain the minimum notary group size and select the notary group, and return the verification results of the authenticity and reliability of the user identity information through the memory consensus protocol to the verifier in the target domain B. Step 3.3.1: Within the current domain A and the target domain B, select the minimum notary group size Q from the candidate notary group sizes using the security activity dichotomy method shown in equation (1). min Perform the screening; Where n is the number of nodes in the current domain A and the target domain B, t is the percentage of malicious nodes in the current domain A and the target domain B, q is the total number of nodes, m is the number of malicious nodes, and m / q is the percentage of malicious nodes; K is a security parameter used to limit the probability of failure in selecting events. Step 3.3.2: Based on the minimum notary group size Q min Selecting the notary public; Step 3.3.3: Select a group of notaries to verify the authenticity and reliability of user identity information using a consensus protocol; Step 3.3.4: Select a notary group to return the verification result to the verifier in the target domain B, and store the verification result in the storage module; Step 4: The verifier in target domain B allows users to access the domain across domains and notifies the user of the verification result.
2. The distributed digital identity cross-domain mutual recognition security liveness probabilistic consensus method as described in claim 1, characterized in that: Step 1 is implemented as follows: Step 1.1: The base layer is used to build cross-domain trust through notary groups. It consists of the current domain A and the target domain B of blockchains with the same functions. Both the current domain A and the target domain B have a node management module for storing node identity information, a notary group management module for storing notary group identity information, and a storage module for storing user identity information, which includes decentralized identifiers, user information, and verifiable credentials. This will provide data storage interaction for the consensus layer. Step 1.2: The consensus layer is used for cross-domain authentication through the trust of notaries to verify users, and will provide cross-domain trust interaction for user authentication to the application layer; Step 1.3: The application layer is used for cross-domain service interaction between users. The member nodes of this layer consist of issuers, users, and verifiers. Issuers provide identity credentials to users, and users, as service users and verifiers, obtain user applications and return verification results.
3. The distributed digital identity cross-domain mutual recognition security liveness probabilistic consensus method as described in claim 2, characterized in that: Step 1.2 is implemented as follows: Step 1.2.1: Select the smallest group of notaries using the security-active dichotomy method; Step 1.2.2: Authenticate user identity information using a minimum-sized group of notaries; Step 1.2.3: Utilize Byzantine fault tolerance to improve the fault tolerance of verification by the smallest notary group.
4. The distributed digital identity cross-domain mutual recognition security liveness probabilistic consensus method as described in claim 1, characterized in that: Step 2 is implemented as follows: Step 2.1: The user sends a valid identity registration request to the current domain A; Step 2.2: The current domain A verifies the user's identity using a decentralized identifier and stores the decentralized identifier in the storage module; Step 2.3: The user sends the decentralized identifier to the issuer of the current domain A and requests a verifiable credential from the issuer; Step 2.4: After verifying the authenticity and legitimacy of the user, the issuer of the current domain A issues a verifiable credential to the user and stores the verifiable credential in the storage module.