Distributed identity opening method and device

By generating and managing distributed identity private and public key certificates in secure chips and wallet applications, the security and efficiency issues of online and offline identity verification are solved, and the interoperability of identity verification results between different systems is realized, thereby improving user experience and identity information security.

CN122048348APending Publication Date: 2026-05-15THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
Filing Date
2024-11-15
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In existing technologies, online identity verification lacks security, offline identity verification is inefficient, and the digital identity systems of different institutions are independent, which requires users to repeatedly submit identity information, reducing the efficiency and security of business processing.

Method used

By installing a distributed identity application in the security chip and wallet application of the applicant's terminal, the system generates and manages the user's distributed identity private key and public key certificate, uses the issuing authority to verify the user's identity and generate verifiable credentials, and achieves unified management and storage of identity identifiers.

Benefits of technology

It enables interoperability of identity verification results between different systems, reduces the need for users to repeatedly submit identity information, and improves the security of identity information and the efficiency of business processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122048348A_ABST
    Figure CN122048348A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a distributed identity opening method and device, electronic equipment and a computer readable medium, and the method comprises the steps: responding to the completion of the installation of a distributed identity application program in a security chip, and transmitting an installation result of the distributed identity application program to a wallet application, sending a verifiable certificate acquisition request to the issuing mechanism by the wallet application; acquiring a distributed identity opening instruction containing a verifiable certificate sent by the wallet application, and generating a user distributed identity private key, a user distributed identity public key and a user distributed identity public key certificate; and obtaining a user distributed identity identifier from the verifiable certificate, and sending the user distributed identity identifier and a user distributed identity public key certificate to the wallet application, so that the wallet application sends a user distributed identity identifier document and the verifiable certificate to a distributed identity chain for associative storage. The operation that the user submits the identity information for the second time is reduced, the user experience is improved, and the identity opening efficiency is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a distributed identity activation method, apparatus, electronic device, and computer-readable medium. Background Technology

[0002] In business processing scenarios, identity verification and customer knowledge (KYC) are key steps to ensure the effectiveness and compliance of business transactions.

[0003] Currently, online identity verification offers a convenient user experience, allowing users to quickly complete identity verification through websites or mobile applications. This method is sufficient for everyday business scenarios, but its security strength is limited and may not meet the requirements of higher-risk transactions. Offline identity verification, such as visiting a bank counter in person, typically involves reviewing identity documents and facial recognition, ensuring the security, accuracy, and strength of identity verification. However, it requires users to spend additional time and resources visiting physical branches. Especially when users need to conduct business with multiple financial institutions, such as upgrading their wallets at different operating institutions (banks), they must repeat the in-person verification process at each institution. This not only increases the user's time cost but also reduces the overall efficiency of the service.

[0004] Furthermore, the independent nature of digital identity systems across different departments or institutions, lacking unified standards and specifications, forces users or entities to repeatedly submit and verify identity information in cross-scenario services, significantly reducing service efficiency and convenience. In addition, the potentially significant differences in technical architecture and data formats between different systems make the sharing and interoperability of digital identity information particularly difficult, hindering effective information exchange between departments or institutions. This not only increases the complexity of business processes but also restricts the overall advancement of digital services. Summary of the Invention

[0005] In view of this, a first aspect of the present invention provides a distributed identity activation method, applied to a security chip installed in an applicant's terminal, the applicant's terminal also having a wallet application installed, the method comprising:

[0006] In response to the completion of the installation of the distributed identity application within the security chip, the installation result of the distributed identity application is sent to the wallet application, so that the wallet application sends a verifiable credential acquisition request to the issuing authority, wherein the verifiable credential acquisition request includes user identity information;

[0007] The system obtains the distributed identity activation instruction sent by the wallet application, generates the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate. The distributed identity activation instruction includes a verifiable credential, which includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier generated by the issuing authority after verifying the user's identity information.

[0008] The user's distributed identity identifier is obtained from the verifiable credentials. The user's distributed identity identifier and the user's distributed identity public key certificate are sent to the wallet application, so that the wallet application can generate a user's distributed identity identifier document based on the user's distributed identity identifier and the user's distributed identity public key certificate, and send the user's distributed identity identifier document and the verifiable credentials to the distributed identity chain for associated storage.

[0009] A second aspect of this invention also provides a distributed identity activation method, applied to a wallet application located within an applicant's terminal, the applicant's terminal also containing a security chip, the method comprising:

[0010] In response to the user's distributed identity activation operation, a distributed identity application is sent to the security chip so that the security chip can install the distributed identity application, and a distributed identity application installation result is generated after the installation is completed.

[0011] The system receives the installation result of the distributed identity application sent by the security chip, obtains the user's identity information, and sends a request to the issuing authority to obtain a verifiable credential containing the user's identity information, so that the issuing authority can generate a verifiable credential. The verifiable credential includes a declaration part and a signature part generated by signing the declaration part with the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier generated by the issuing authority after verifying the user's identity information.

[0012] The system receives verifiable credentials from the issuing authority and sends a distributed identity activation instruction containing the verifiable credentials to the security chip, so that the security chip generates the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate.

[0013] Receive the user distributed identity identifier and user distributed identity public key certificate sent by the security chip, and generate a user distributed identity identifier document based on the user distributed identity identifier and user distributed identity public key certificate;

[0014] Send the user's distributed identity document and verifiable credentials to the distributed identity chain for associated storage.

[0015] A third aspect of this invention also provides a distributed identity activation method, applied to an issuing authority, the method comprising:

[0016] Obtain the verifiable credential acquisition request sent by the wallet application within the applicant's terminal, wherein the verifiable credential acquisition request includes user identity information;

[0017] Verify the user's identity information, and generate a distributed identity identifier for the user after successful verification;

[0018] A verifiable credential is generated based on the user's distributed identity. The verifiable credential includes a declaration part and a signature part generated by signing the declaration part with the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity, and the user's distributed identity.

[0019] Send verifiable credentials to the wallet application.

[0020] A fourth aspect of the present invention also provides a distributed identity activation device, applied to a security chip installed in an applicant's terminal. The applicant's terminal also includes a wallet application. The device includes an application installation response module, a key generation module, and a credential processing module.

[0021] The application installation response module is configured to send the installation result of the distributed identity application to the wallet application in response to the completion of the installation of the distributed identity application in the security chip, so that the wallet application sends a verifiable credential acquisition request to the issuing authority, wherein the verifiable credential acquisition request includes user identity information;

[0022] The key generation module is configured to obtain the distributed identity activation instruction sent by the wallet application, generate the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate. The distributed identity activation instruction includes a verifiable credential, which includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier generated by the issuing authority after verifying the user's identity information.

[0023] The credential processing module is configured to obtain the user's distributed identity identifier from verifiable credentials, send the user's distributed identity identifier and the user's distributed identity public key certificate to the wallet application, so that the wallet application can generate a user's distributed identity identifier document based on the user's distributed identity identifier and the user's distributed identity public key certificate, and send the user's distributed identity identifier document and verifiable credentials to the distributed identity chain for associated storage.

[0024] A fifth aspect of the present invention also provides a distributed identity activation device applied to an applicant terminal. The applicant terminal further includes a security chip. The device comprises a personalization module, a verifiable credential acquisition module, a distributed identity activation module, a distributed identity receiving module, and an on-chain module.

[0025] The personalization module is configured to send a distributed identity application to the security chip in response to the user's distributed identity activation operation, so that the security chip can install the distributed identity application and generate the distributed identity application installation result after the installation is completed.

[0026] The verifiable credential acquisition module is configured to receive the installation result of the distributed identity application sent by the security chip, obtain the user identity information, and send a verifiable credential acquisition request containing the user identity information to the issuing authority so that the issuing authority can generate a verifiable credential. The verifiable credential includes a declaration part and a signature part generated by signing the declaration part with the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier generated by the issuing authority after verifying the user's identity information.

[0027] The distributed identity activation module is configured to receive verifiable credentials sent by the issuing authority and send a distributed identity activation instruction containing verifiable credentials to the security chip, so that the security chip generates the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate.

[0028] The distributed identity receiving module is configured to receive the user distributed identity identifier and user distributed identity public key certificate sent by the security chip, and generate a user distributed identity identifier document based on the user distributed identifier and user distributed identity public key certificate;

[0029] The on-chain module is configured to send the user's distributed identity document and verifiable credentials to the distributed identity chain for associated storage.

[0030] A sixth aspect of the present invention also provides a distributed identity activation device, applied to an issuing authority. The device includes a credential request acquisition module, a distributed identity generation module, a credential generation module, and a credential sending module, wherein...

[0031] The credential request acquisition module is configured to acquire verifiable credential acquisition requests sent by the wallet application within the applicant's terminal, wherein the verifiable credential acquisition request includes user identity information;

[0032] The distributed identity generation module is configured to verify user identity information, and generate a distributed identity identifier for the user after successful verification.

[0033] The credential generation module is configured to generate verifiable credentials based on the user's distributed identity identifier. The verifiable credentials include a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier.

[0034] The credential sending module is configured to send verifiable credentials to the wallet application.

[0035] A seventh aspect of the present invention provides an electronic device, comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method provided in the embodiments of the present invention.

[0036] An eighth aspect of the present invention provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the method provided in the embodiments of the present invention.

[0037] One embodiment of the above invention has the following advantages or beneficial effects:

[0038] In this embodiment of the invention, a user applies for a distributed identity through a wallet application. The wallet application retrieves the distributed identity application and the user's personalized data from the backend, and then sends them to a security chip. The security chip installs the distributed identity application, stores the user's personalized data, and notifies the wallet application. The wallet application then applies for a verifiable credential from the issuing authority based on the user's identity information. After verifying the user's identity information, the issuing authority generates a user distributed identity identifier and issues a verifiable credential based on the user's distributed identity identifier, returning the verifiable credential to the wallet application. The wallet application sends the verifiable credential to the security chip, which extracts the user's distributed identity identifier from the verifiable credential, generates the user's distributed identity private key and public key, and generates a user distributed identity public key certificate, returning it to the wallet application. The wallet application generates a user distributed identity identifier document based on the user's distributed identity identifier and the user's distributed identity public key certificate, and stores the user's distributed identity identifier document and the verifiable credential on the blockchain, thus realizing the activation of the user's distributed identity. In this embodiment of the invention, the wallet application does not need to repeatedly provide identity information to the issuing authority; it only needs to provide it once for the issuing authority to generate a distributed identity identifier and a verifiable credential, reducing the need for users to frequently provide identity information. In this embodiment of the invention, a distributed identity application is installed in the security chip, enabling the management of user distributed identities within the security chip. Subsequent key generation, certificate generation, parsing of verifiable credentials, and storage of verifiable credentials can all be achieved through the distributed identity application. This allows for the management of user distributed identities in a secure environment, enhancing the security of user identity information. The on-chain storage of user distributed identity identifiers, identifier documents, and verifiable credentials provides a foundation for subsequent credential verification to validate user identity.

[0039] In this embodiment of the invention, the distributed user identity activation and verification process enables the interoperability and mutual recognition of identity verification results across different systems, reducing the need for users to repeatedly provide identity information and lowering the risk of user identity information leakage.

[0040] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description

[0041] The accompanying drawings are provided to better understand the invention and are not intended to unduly limit the scope of the invention. Wherein:

[0042] Figure 1 This is a schematic diagram of the network system architecture in which the distributed identity activation method is operated according to some embodiments of the present invention;

[0043] Figure 2This is a flowchart illustrating a distributed identity activation method according to some embodiments of the present invention;

[0044] Figure 3 This is a schematic diagram of the process by which an issuing authority generates verifiable credentials according to some embodiments of the present invention;

[0045] Figure 4 This is a schematic diagram of the process by which an issuing authority generates the signature portion of a verifiable credential, according to other embodiments of the present invention.

[0046] Figure 5 This is a schematic diagram of the process by which a security chip generates a user's distributed identity public key certificate according to some embodiments of the present invention;

[0047] Figure 6 This is a schematic diagram of the storage structure of verifiable credentials within a security chip according to some embodiments of the present invention;

[0048] Figure 7 This is a flowchart illustrating a user authentication method according to some embodiments of the present invention;

[0049] Figure 8 This is a schematic diagram of the process of generating a credential signature using a security chip according to some embodiments of the present invention;

[0050] Figure 9 This is a schematic diagram illustrating the process by which a verification authority verifies a credential signature according to some embodiments of the present invention;

[0051] Figure 10 This is a flowchart illustrating the process by which a verification agency verifies the signature portion of a verifiable credential, according to some embodiments of the present invention.

[0052] Figure 11 This is a schematic diagram of the process by which a verification authority obtains the distributed identity public key of an issuing authority, according to some embodiments of the present invention;

[0053] Figure 12 This is a schematic diagram of the process by which a verification agency verifies the validity of a verifiable credential, according to other embodiments of the present invention.

[0054] Figure 13 This is a schematic diagram of the functional architecture of a distributed identity activation device according to some embodiments of the present invention;

[0055] Figure 14 This is a functional architecture diagram of a distributed identity activation device according to other embodiments of the present invention;

[0056] Figure 15 This is a functional architecture diagram of a distributed identity activation device according to other embodiments of the present invention;

[0057] Figure 16This is a functional architecture diagram of a user authentication device according to some embodiments of the present invention;

[0058] Figure 17 This is a functional architecture diagram of a user authentication device according to other embodiments of the present invention;

[0059] Figure 18 This is an exemplary system architecture diagram in which embodiments of the present invention can be applied;

[0060] Figure 19 This is a schematic diagram of the structure of a computer system suitable for implementing terminal devices or servers of the present invention. Detailed Implementation

[0061] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of the present invention, including various details to aid understanding. These details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0062] First, the abbreviations and related terms involved in the embodiments of the present invention are defined and explained.

[0063] "DID (Decentralized Identifiers)" refers to a distributed identity identifier, which is an identifier composed of strings to represent a digital identity. The DID is generated by the distributed identity chain based on the applicant's public key and other information. The distributed identity chain also stores the DID document corresponding to the DID, and the DID document stores the DID and the public key corresponding to the DID.

[0064] "VC (Verifiable Credential)" refers to a verifiable credential, typically a JSON string containing VC metadata, a declaration section, and a signature section. The VC metadata mainly includes information such as the issuer, issuance date, and type of declaration. The declaration section contains one or more specific descriptions about the entity. For example, if a VC is an ID card, the declaration section would contain the holder's name, gender, date of birth, ethnicity, address, and other personal information. The signature section is usually the issuer's digital signature, used to ensure the integrity and authenticity of the VC content, prevent tampering, and verify the issuer's identity.

[0065] A “VP (Verifiable Presentation)” is a verifiable representation associated with a user’s distributed identity. It consists of a verifiable proof document synthesized from one or more verifiable credentials (VCs) and digitally signed by the user.

[0066] In existing business processes, such as the digital wallet opening process, opening a wallet under different operating institutions requires repeatedly uploading ID documents and information to different operating institutions. This is cumbersome for users, and the need for users to upload identity information to different operating institutions multiple times can easily lead to the risk of identity information leakage. Furthermore, the identity authentication results of different operating institutions cannot be shared, which is not conducive to user risk control.

[0067] This invention provides a distributed identity activation method, which firstly digitizes various physical credentials of users and enables them to manage and authorize their own digital credentials, secondly enables the integrated and portable application of user digital credentials, thereby improving the efficiency of user business processing and optimizing user experience, and thirdly better protects the security of user privacy information.

[0068] The embodiments of this invention are based on distributed identity identification, which breaks down the current situation of independent identity authentication systems between different systems (e.g., between the certificate issuer and the verification authority), realizes identity commonality, and at the same time, by using the transmission of proof credentials, realizes the transmission of verification results between different systems, thereby improving the efficiency of business processing.

[0069] like Figure 1 As shown, a network system 100 is illustrated in an embodiment of the present invention. The distributed identity activation method in this embodiment of the present invention can be run in the network system 100. The network system 100 includes an applicant terminal 110, an issuing authority 120, a verification authority 130, a distributed identity chain 140, a trusted service management platform 150, and a trusted identity management platform 160.

[0070] In this embodiment of the invention, the applicant terminal 110 is a terminal containing a wallet application 111. The applicant can use the wallet application 111 to apply for distributed identity activation and identity verification. The applicant terminal 110 also includes a security chip 112, used to run the distributed identity application, generate the user's distributed identity public and private keys based on the distributed identity application, and store and verify the issued verifiable credentials. In this embodiment of the invention, the security chip 112 can be a chip embedded in the applicant terminal or a pluggable SIM card with a security module. In this embodiment of the invention, the distributed identity application can be an Applet application (a small application written in the Java programming language), and the security chip can run according to the Java Card specification.

[0071] In some embodiments of the present invention, the issuing authority 120 can be understood as an identity issuance system. The issuing authority 120 is equipped with a server cryptographic machine, which generates the issuer's public and private keys. The issuing authority 120 can provide identity credentials to users. In some embodiments of the present invention, the distributed identity chain 140 can associate and store distributed identity identifiers, distributed identity documents, and / or verifiable credentials. For example, through a user's distributed identity identifier, a user's distributed identity identifier document and / or verifiable credentials can be obtained from the distributed identity chain 140. In some embodiments of the present invention, the distributed identifier document stores the distributed identity identifier and the distributed identity public key certificate. In some embodiments of the present invention, the trusted identity management platform 160 can be an authoritative identity authentication institution that maintains and stores a database containing user identity information and biometric information, which can be accessed by other institutions or individuals to verify the user's identity.

[0072] In some embodiments of the present invention, the distributed identity activation process includes the processes of generating a distributed identity identifier, generating a verifiable credential, and storing distributed identity-related information on the blockchain.

[0073] like Figure 2 As shown, this embodiment of the invention provides a distributed identity activation method, including the following steps:

[0074] S201: In response to a user's distributed identity activation operation, wallet application 111 sends a distributed identity application and user personalized data to security chip 112. In some embodiments of the present invention, after receiving a user's distributed identity activation operation, wallet application 111 requests the distributed identity application and user personalized data from the backend. For example, wallet application 111 determines the issuing authority 120 from the user's operation, and then sends a distributed identity application activation request (including information about the issuing authority 120) to trusted service management platform 150. Trusted service management platform 150 identifies the issuing authority 120 information from the activation request, then obtains the user personalized data from the issuing authority 120, and sends the distributed identity application and user personalized data to wallet application 111. In embodiments of the present invention, when a user applies for distributed identity activation from different issuing authorities 120, they can obtain the distributed identity application from the same trusted service management platform 150. The trusted service management platform 150 manages the distributed identity application, saving management costs and reducing the manual costs of upgrading or deploying the distributed identity application.

[0075] In some embodiments of the present invention, user personalization data includes user wallet account information and issuing authority information (e.g., issuing authority distributed identity public key certificate, issuing authority name, etc.).

[0076] S202: Security chip 112 receives the distributed identity application and user-personalized data, installs the distributed identity application, and sends the installation result of the distributed identity application to wallet application 111 after installation. Security chip 112 initializes the distributed identity application using the user-personalized data, enabling the distributed identity application to function based on the user-personalized data. In this embodiment of the invention, the distributed identity application runs within security chip 112. Security chip 112 can use the distributed identity application to perform processes such as managing the user's distributed identity, generating the user's distributed identity private key and public key, generating public key certificates, verifying issued credentials, and issuing verifiable expressions based on the credentials.

[0077] S203: Wallet application 111 obtains user identity information and sends a verifiable credential acquisition request to issuing authority 120 based on the user identity information. The verifiable credential acquisition request includes the user identity information. In some embodiments of the present invention, user identity information may include the user's ID card information, mobile phone information, biometric information (e.g., facial information, fingerprint information), etc.

[0078] S204: After obtaining the request for verifiable credentials, the issuing authority 120 verifies the user's identity information. If the verification is successful, a distributed identity identifier for the user is generated.

[0079] In some embodiments of the present invention, the issuing authority 120 can verify the user's identity information using pre-stored user information, and can also send the user's identity information to the trusted identity management platform 160, which verifies the user's identity information and obtains the verification result from the trusted identity management platform 160.

[0080] In some embodiments of the present invention, the issuing authority 120 generates a unique distributed identity identifier for each user. The issuing authority 120 can use the user's identity information to perform calculations to generate the distributed identity identifier. For example, the issuing authority 120 can use the identity document information in the user's identity information to perform a separate digest calculation, such as a hash calculation, or perform a digest calculation together with timestamp information to generate the user's distributed identity identifier. In some embodiments of the present invention, if the user's identity information is unique and does not belong to sensitive user information, the user's identity information can also be used as part or all of the user's distributed identity identifier. For example, if the user's identity information is a unique identity identifier of a credible platform, it can be used as part or all of the user's distributed identity identifier.

[0081] S205: Issuing authority 120 generates a verifiable credential based on the user's distributed identity identifier and sends the verifiable credential to wallet application 111. In embodiments of the present invention, the verifiable credential includes a declaration portion and a signature portion generated by signing the declaration portion using the issuing authority's distributed identity private key. The declaration portion includes credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier. In some embodiments of the present invention, issuing authority 120 may pre-generate an issuing authority's distributed identity identifier according to rules, and combine the issuing authority's distributed identity identifier with a public key certificate issued by a trusted central authority to form an issuing authority's distributed identity identifier document, which is then stored in the distributed identity chain 140.

[0082] In some embodiments of the present invention, the issuing authority distributed identity identifier and the issuing authority distributed identity public key certificate can be pre-created by a trusted central authority. After creation, the issuing authority 120 or the trusted central authority synchronously stores the issuing authority distributed identity identifier and the issuing authority distributed identity document on the distributed identity chain 140. The issuing authority distributed identity document contains the issuing authority distributed identity identifier, the issuing authority distributed identity public key certificate, and creator information: trusted central authority distributed identity identifier. The digital signature in the issuing authority distributed identity public key certificate is generated based on the trusted central authority distributed identity private key signature.

[0083] In some embodiments of the present invention, the issuing authority 120 generates a private key and a public key for its distributed identity, and sends the public key to a trusted central authority. The trusted central authority calculates and generates a distributed identity identifier based on the public key and the issuing authority's identity information, and signs the public key and other information using the private key to generate a distributed identity certificate. The trusted central authority then returns the distributed identity certificate and the distributed identity identifier to the issuing authority 120.

[0084] In this embodiment of the invention, the certificate content in the declaration section may include the verification result of the issuing authority 120, such as proving the user's legal identity information, proving the user's legal ownership of wallet account information, or proving the user's legal ownership of asset information. Different issuing authorities 120 can issue different certificates, and also require users to provide different information to the issuing authority 120. For example, when the certificate content is to prove that the user legally owns asset A, the wallet application 111 needs to send the identification information and description information of asset A to the issuing authority 120 so that the issuing authority can determine the information of asset A and verify it.

[0085] In an embodiment of the present invention, in order to improve the efficiency of issuing verifiable credentials by the issuing authority 120, the issuing authority 120 can also select a corresponding signature algorithm to sign the declaration part according to the amount of data in the declaration part, and generate a signature part.

[0086] like Figure 3 As shown, the process by which issuing authority 120 generates verifiable credentials can be as follows:

[0087] S2051: The issuing authority 120 generates a statement portion of a verifiable credential based on the user's distributed identity, wherein the statement portion includes the credential content, the issuing authority's distributed identity, and the user's distributed identity.

[0088] S2052: The issuing authority 120 selects the corresponding signature algorithm to sign the declaration part based on the amount of data in the declaration part, generating a signature part of the verifiable credential.

[0089] When the amount of data in the declaration section is too large, using a single signature algorithm for signing will result in reduced signing efficiency, longer processing time, and a poor user experience.

[0090] like Figure 4 As shown, in this embodiment of the invention, a corresponding signature algorithm can be selected based on the amount of data. Specifically, step S2052 includes:

[0091] S20521: Get the amount of data in the declaration section.

[0092] S20522: When the data volume of the declaration part exceeds a data volume threshold, perform a hash calculation on the declaration part to obtain a digest value of a preset data volume. Sign the digest value using the issuing authority's distributed identity private key to generate the signature part. In some embodiments of the present invention, if the data volume of the declaration part is greater than 512 bytes, use the national cryptographic algorithm SM3 to perform a hash algorithm on the data (ZA|Message, hash factor) to obtain a digest value of a preset data volume (e.g., 32 bytes). Then, use the national cryptographic algorithm ALG_SM2_SM3_256_INPUT_E to calculate the digest value and generate the signature part.

[0093] S20523: When the data size of the declaration portion is less than or equal to the data size threshold, the declaration portion is signed using the issuing authority's distributed identity private key to generate a signature portion. In some embodiments of the present invention, if the data size of the declaration portion is less than or equal to 512 bytes, the national cryptographic algorithm ALG_SM2_SM3_256 is used to sign the declaration portion to generate a signature portion.

[0094] In this embodiment of the invention, the preset data volume is less than a data volume threshold, or the preset data volume is much smaller than the data volume threshold. For example, the preset data volume can be 32 bytes or 64 bytes, and the data volume threshold can be 512 bytes or 544 bytes.

[0095] In embodiments of the present invention, the preset data volume is less than a data volume threshold, effectively reducing the amount of data required for signature calculation and thus improving signature efficiency. For declaration portions with large data volumes, hash calculation is performed first, followed by signing. The value of the generated signature portion is consistent with the value of the signature portion generated by direct signing. When verifying the signature portion, it is not necessary to focus on which signature algorithm was used to generate the signature portion; a single verification method can still be used to verify the signature portion. The verification organization does not need to be modified, reducing the modification cost of the verification organization.

[0096] S206: Wallet application 111 organizes a distributed identity activation instruction based on verifiable credentials and sends the distributed identity activation instruction to security chip 112. The distributed identity activation instruction includes verifiable credentials.

[0097] S207: Security chip 112 calls the distributed identity application to generate the user's distributed identity public key and private key, and generates the user's distributed identity public key certificate based on the public key and private key.

[0098] In an embodiment of the present invention, the security chip 112 has a built-in tool for generating public and private keys, and the generated private key is stored in the security chip 112.

[0099] In some embodiments of the present invention, the user distributed identity public key certificate includes creator identity information, public key subject, and digital signature, such as... Figure 5 As shown, the process by which the security chip 112 generates a user's distributed identity public key certificate is as follows:

[0100] S2071: Security chip 112 generates creator identity information based on user wallet account information.

[0101] S2072: Security chip 112 uses the user's distributed identity public key as the public key subject.

[0102] S2073: Security chip 112 generates a digital signature based on the user's distributed identity private key. Security chip 112 can use the user's distributed identity private key to sign information such as the creator's identity information and the public key subject, generating a digital signature. Subsequently, when using the user's distributed identity public key, the digital signature can be verified using the user's distributed identity public key.

[0103] S208: Security chip 112 obtains the user's distributed identity identifier from verifiable credentials and sends the user's distributed identity identifier and user's distributed identity public key certificate to wallet application 111.

[0104] In an embodiment of the present invention, the user-personalized data received by the security chip 112 includes issuing authority information, which includes the issuing authority name, the issuing authority's distributed identity public key certificate, and the issuing authority's distributed identity public key certificate, which includes the issuing authority's distributed identity public key. The process by which the security chip 112 obtains the user's distributed identity identifier from verifiable credentials is as follows:

[0105] The signature portion is verified using the issuing authority's distributed identity public key, generating a signature portion verification result. In response to the signature portion verification result indicating successful verification, the user's distributed identity identifier is obtained from the declaration portion of the verifiable credential, and the verifiable credential is stored.

[0106] In some embodiments of the present invention, to facilitate the reading of verifiable credentials, the security chip 112 performs chained storage of verifiable credentials. The security chip 112 can support storing multiple distributed identity identifiers and their corresponding verifiable credentials. For the same distributed identity identifier, the security chip 112 stores verifiable credentials with the same user distributed identity identifier in the same chained storage structure. During subsequent reading of verifiable credentials, after determining the corresponding chained storage structure based on the user distributed identity identifier, the target verifiable credential is determined by indexing chain by chain according to the chained storage structure, eliminating the need for cross-chain indexing and saving credential reading time. The chained storage structure in the embodiments of the present invention can be referred to... Figure 6 As shown, each node stores a verifiable credential VC and a next node address NEXT. For example, chain 1 stores the verifiable credential of user distributed identity DID1. Node 1-1 stores VC1-1, and the next node address NEXT1-1 of node 1-1 points to node 1-2. Node 1-2 stores VC1-2, and the next node address NEXT1-2 of node 1-2 points to node 1-3. Node 1-3 stores VC1-3, and the next node address NEXT1-3 of node 1-3 points to NULL. When a new verifiable credential VC1-4 corresponding to user distributed identity DID1 needs to be stored, node 1-4 is generated. Node 1-4 stores VC1-4, and the next node address NEXT1-3 of node 1-3 points to node 1-4. The next node address NEXT1-4 of node 1-4 points to NULL. Chain 2 stores the verifiable credential of user distributed identity DID2. Node 2-1 stores VC2-1, and the next node address NEXT2-1 of node 2-1 points to NULL. When it is necessary to read the verifiable credentials of the user's distributed identity identifier DID1, it is read from chain 1 instead of from chain 2, which reduces the index space and improves the reading efficiency.

[0107] In some embodiments of the present invention, when storing verifiable credentials, the security chip 112 also determines whether the amount of data of the verifiable credentials is greater than a storage threshold (e.g., 2048 bytes). If it is greater than the storage threshold, it reports storage failure to the wallet application 111, and the wallet application stores the verifiable credentials outside the security chip 112.

[0108] S209: Wallet application 111 generates a user distributed identity document based on the user's distributed identity identifier and user distributed identity public key certificate, and sends the user distributed identity document, verifiable credentials, and user distributed identity identifier to the distributed identity chain 140 for associated storage.

[0109] In some embodiments of the present invention, since the user distributed identity document contains a user distributed identity, the wallet application 111 can upload the user distributed identity document and verifiable credentials to the blockchain and send them to the distributed identity chain 140 for associated storage.

[0110] In some embodiments of the present invention, the security chip 112 can enable multiple user distributed identity identifiers, create different user distributed identity private keys, public keys and public key certificates, and create corresponding chain storage structures.

[0111] In this embodiment of the invention, the distributed identity document includes a user's distributed identity and a user's distributed identity public key certificate. When the wallet application 111 synchronizes data to the distributed identity chain 140, it can also synchronize the verification data of the verifiable credential to the distributed identity chain 140. In some embodiments of the invention, the verification data of the verifiable credential includes the digest value and the status of the verifiable credential. In this embodiment of the invention, the distributed identity chain 140 stores the user's distributed identity document, the verifiable credential, and the user's distributed identity in association, and can obtain the user's distributed identity document, the verifiable credential, or the verification data of the verifiable credential through the user's distributed identity.

[0112] In an embodiment of the present invention, after the wallet application 111 sends the user's distributed identity document, verifiable credential, and user's distributed identity to the distributed identity chain 140 for associated storage, it will also receive the storage result from the distributed identity chain 140. The wallet application 111 sends the storage success result to the issuing authority 120, and the issuing authority 120 sends the verification data of the verifiable credential to the distributed identity chain 140. The distributed identity chain 140 then associates and stores the verification data with the user's distributed identity.

[0113] In this embodiment of the invention, the issuing authority 120 may be the operator of the digital wallet. When generating a verifiable credential VC, the issuing authority 120 verifies the user based on the information submitted by the user when opening the wallet (name, age, date of birth, ID card number, specific address, etc.). The declaration part of the generated verifiable credential also includes the credential type, issuing authority, validity period, credential content, etc.

[0114] In this embodiment of the invention, wallet application 111 does not need to repeatedly provide identity information to issuing authority 120. Providing it only once allows the issuing authority to generate a distributed identity identifier and a verifiable credential based on that identifier, reducing the need for users to frequently provide identity information. In this embodiment, a distributed identity application is installed in the security chip, enabling the management of user distributed identities within the chip. Subsequent key generation, certificate generation, parsing of verifiable credentials, and storage of verifiable credentials can all be achieved through the distributed identity application. This allows for the management of user distributed identities in a secure environment, improving the security of managing user identity information. The user distributed identity identifier, identifier document, and verifiable credential are stored on the blockchain as verification credentials, thus providing a foundation for verifying the validity of user identities.

[0115] In this embodiment of the invention, after the issuing authority verifies the user's identity information, it activates a distributed identity for the user. The user's application terminal stores the user's distributed identity identifier and verifiable credentials. When the user needs to present verifiable credentials to the verification authority later, a verifiable representation can be generated based on the verifiable credentials. The verification authority verifies the verifiable credentials and the verifiable representation therein. After successful verification, the result of the issuing authority's verification of the user's identity is reused. The user does not need to repeatedly submit identity information to the verification authority during verification, thereby reducing repetitive operations for the user, improving the efficiency of the user's business processing, improving the user experience, and reducing the risk of leakage of user identity information.

[0116] like Figure 7 As shown, this embodiment of the invention also provides a user authentication method based on verifiable credentials in the applicant's terminal, including the following steps:

[0117] S301: Wallet application 111 receives the user's authentication request and sends a verifiable credential read instruction to security chip 112. The verifiable read instruction includes the distributed identity identifier selected by the user.

[0118] S302: The security chip 112 returns a verifiable credential related to the distributed identity identifier from the corresponding chained storage structure to the wallet application 111 based on the distributed identity identifier. The verifiable credential in this embodiment can be obtained based on the aforementioned distributed identity activation method, or it can be obtained from the issuing authority using other methods. For example, a user can apply for a verifiable credential from the issuing authority using the applied distributed identity identifier, collected identity information, and a proof request. After verifying the identity information and clarifying the proof request content, the issuing authority returns the verifiable credential to the user, and the verifiable credential is stored in the security chip 112.

[0119] It should be noted that, in this embodiment of the invention, the verifiable credentials in the security chip 112 can also be stored in a sequential manner. In this case, when reading the verifiable credentials, all verifiable credentials need to be read in full.

[0120] S303: Wallet application 111 displays verifiable credentials. The user selects a verifiable credential, and wallet application 111 sends a verifiable representation generation instruction to the security chip based on the user's selection. In some embodiments of the present invention, the verifiable representation generation instruction includes a user distributed identity identifier, an identifier of the verifiable credential, and may also include business request content, such as a wallet or account activation request, a wallet or account upgrade request, etc. In embodiments of the present invention, the user authentication method can be executed during the user's specific business processing. For example, if the user selects to activate their wallet under a certain operating institution from wallet application 111, then this operating institution is used as the verification institution, and wallet application 111 sends the corresponding business request content to security chip 112. Subsequently, security chip 112 generates a verifiable representation based on the business request content.

[0121] In some embodiments of the present invention, wallet application 111 may also send a random number acquisition request to verification authority 130, and verification authority 130 sends a random number to wallet application 111. The verifiable expression generation instruction includes the random number obtained from verification authority 130.

[0122] S304: Security chip 112 obtains locally stored verifiable credentials and user distributed identity identifiers according to verifiable representation generation instructions, and generates verifiable representations based on verifiable credentials and user distributed identity identifiers.

[0123] In embodiments of the present invention, the verifiable expression includes verifiable expression content and a credential signature. The security chip 112 uses the user's distributed identity private key to sign the verifiable expression content to generate a credential signature. The verifiable expression content includes a user-selected verifiable credential and a user distributed identity identifier. In some embodiments of the present invention, the verifiable expression content may also include business request content.

[0124] In some embodiments of the present invention, since the computing power of the security chip 112 is limited, in order to improve the signing efficiency (efficiency of generating credential signature) of the security chip 112, when generating credential signature, the security chip 112 selects the corresponding signature algorithm to sign the verifiable expression content in the verifiable expression according to the amount of data of the verifiable expression content, and generates the credential signature in the verifiable expression.

[0125] like Figure 8 As shown, the process of generating a credential signature using the security chip 112 can be as follows:

[0126] S3041: Security chip 112 acquires the amount of data that can verify the expressed content.

[0127] S3042: When the security chip 112 determines that the amount of data for verifiable content is greater than the data amount threshold, it performs hash calculation on the verifiable content to obtain a content digest value of a preset amount of data, and signs the content digest value using the user's distributed identity private key to generate a credential signature.

[0128] In some embodiments of the present invention, if the amount of data containing verifiable content is greater than 512 bytes, the national cryptographic algorithm SM3 is used to perform a hash algorithm on the data (ZA|Message, hash factor) to obtain a digest value of a preset amount of data (e.g., 32 bytes), and the national cryptographic algorithm ALG_SM2_SM3_256_INPUT_E is used to calculate and generate a credential signature.

[0129] S3043: When the security chip 112 determines that the amount of data in the verifiable expression is less than or equal to a data size threshold, it signs the verifiable expression using the user's distributed identity private key to generate a credential signature. In some embodiments of the present invention, if the amount of data in the verifiable expression is less than or equal to 512 bytes, the national cryptographic algorithm ALG_SM2_SM3_256 is used to sign the verifiable expression and generate a credential signature.

[0130] In some embodiments of the present invention, due to the limited storage capacity of the security chip 112, if the amount of verifiable credential data exceeds a storage threshold (e.g., 2048 bytes), the security chip 112 will not store the verifiable credential and will return a storage failure result to the wallet application 111. The wallet application 111 can store the verifiable credential outside the security chip, for example, in a TEE (Trusted Execution Environment). When the security chip 112 generates a credential signature, the wallet application 111 performs a digest calculation on the verifiable credential and other verifiable expressions to generate a credential digest, and sends the credential digest to the security chip 112. The security chip 112 signs the credential digest to generate a credential signature. Subsequent verification by the verification authority also first generates a credential digest and then uses the credential digest for signature verification. In some embodiments of the present invention, the wallet application 111 can also directly send the verifiable credential to the security chip 112 for signing.

[0131] In embodiments of the present invention, the preset data volume is less than a data volume threshold, or the preset data volume is much smaller than the data volume threshold. For example, the preset data volume can be 32 bytes or 64 bytes, and the data volume threshold can be 512 bytes or 544 bytes.

[0132] In some embodiments of the present invention, to ensure that each generated verifiable representation is different and to prevent hijackers from launching replay attacks after being intercepted, the verifiable representation content also includes timestamp information. Each time a verifiable representation is generated, the time and signature of the credential are different.

[0133] In some embodiments of the present invention, replay attacks can also be prevented using random numbers. In step S301 of this embodiment, after receiving a user authentication request, the wallet application 111 obtains a random number from the verification authority 130. In step S303, the wallet application 111 sets the random number into the verifiable representation generation instruction. When the security chip 112 generates a credential signature, the verifiable representation includes the random number, thus ensuring that the generated credential signature is different each time it is verified. Based on the changing credential signature, the verification authority 130 determines that the verifiable representation has not been hijacked and replayed. When subsequently verifying the credential signature, the verification authority 130 also compares whether the random number in the verifiable representation is consistent with the issued random number, thus verifying the user's consistency.

[0134] In embodiments of the present invention, to facilitate the verification of the credential signature in the verifiable representation by the verification authority 130, the security chip 112 may also set the user's distributed identity public key into the verifiable representation content when organizing it. Subsequently, when verifying the credential signature, the verification authority 130 can compare the user's distributed identity public key in the verifiable representation content with a public key obtained from other sources. Only after the comparison matches will the credential signature be verified, ensuring the security of public key transmission.

[0135] S305: The security chip 112 sends a verifiable representation to the wallet application 111. The wallet application 111 generates an authentication request based on the verifiable representation and sends the authentication request to the verification authority 130. The authentication request includes the verifiable representation.

[0136] In some embodiments of the present invention, when the security chip 112 sends the verifiable representation to the wallet application 111, it also sends the user's distributed identity public key certificate to the wallet application 111. The authentication request generated by the wallet application also includes the user's distributed identity public key certificate. Subsequently, when the verification authority 130 verifies the credential signature, it can use the public key in the user's distributed identity public key certificate to verify the credential signature, confirming that the credential signature was indeed generated by the user's distributed identity private key, and ensuring that the verifiable representation content in the verifiable representation has not been tampered with. The verification authority 130 directly obtains the user's distributed identity public key from the authentication request, saving time spent obtaining the user's distributed identity public key from other channels and improving verification efficiency.

[0137] S306: Verification authority 120 receives the authentication request sent by wallet application 111, verifies the verifiable representation, and generates a credential verification result.

[0138] In this embodiment of the invention, the authentication request includes a verifiable representation, which comprises verifiable representation content and a credential signature. The verifiable representation content includes a user distributed identity identifier and a verifiable credential. The declaration portion of the verifiable credential includes an issuing authority distributed identity identifier, and the signature portion is generated by signing with the issuing authority's distributed identity private key. In this embodiment of the invention, the verification authority 130 can verify the credential signature to obtain a preliminary verification result, and can further verify the signature portion of the verifiable credential to verify that the verifiable credential has not been tampered with.

[0139] In this embodiment of the invention, to prevent replay attacks after the verifiable representation is hijacked, the verification agency 130 checks whether the received verifiable representation is a replay attack before verifying the signature in the verifiable representation. In some embodiments of the invention, the verification agency 130 determines whether the value of the credential signature is consistent with the value of the credential signature sent from the wallet application before a preset time period. If they are consistent, the verification fails. For example, the preset time period can be 5 minutes or 10 minutes. After each successful verification of the verifiable representation, the verification agency 130 stores the credential signature in the verifiable representation. When the next verifiable representation is received, it determines whether the credential signature is the same as the credential signature in a previously sent verifiable representation. If it is consistent with the previously received credential signature value, the verification fails.

[0140] To avoid replay attacks, in some embodiments of the present invention, the security chip 112 also obtains a random number from the verification agency 130. The verifiable expression includes a random number, causing the credential signature value to change, thus avoiding replay attacks. When the verification agency 130 verifies the verifiable expression, in addition to verifying the change in the credential signature value, it also verifies the random number in the verifiable expression to determine whether it is consistent with the issued random number. If they are inconsistent, the verification fails, thereby verifying the consistency of the identity of the security chip 112 when applying for the random number and when verifying the verifiable expression.

[0141] In this embodiment of the invention, the verification agency 130 verifies the verifiable expression, which can verify the correctness of the credential signature and / or the correctness of the signature portion in the verifiable expression. Specifically, as... Figure 9 As shown, the verifiable expression is validated to generate a credential validation result, including:

[0142] S3061: Verification authority 130 obtains the user's distributed identity public key. In this embodiment of the invention, verification authority 130 may obtain the user's distributed identity public key in different ways depending on the authentication request and the settings in the verifiable content.

[0143] In some embodiments of the present invention, the verification authority 130 can obtain the user's distributed identity public key from the distributed identity chain 140 based on the user's distributed identity identifier. In this embodiment, when distributed identity is activated, the wallet application 111 stores the user's distributed identity identifier document and the user's distributed identity identifier together on the distributed identity chain 140, obtains the user's distributed identity identifier document from the distributed identity chain 140 using the user's distributed identity identifier, obtains the user's distributed identity public key certificate from the distributed identity identifier document, and obtains the user's distributed identity public key from the certificate.

[0144] In some embodiments of the present invention, to save the process of obtaining the public key from the distributed identity chain, the verification authority 130 can also obtain the user's distributed identity public key from the applicant terminal 110. Specifically, the authentication request also includes a user's distributed identity public key certificate. The verification authority 130 obtains the public key body from the user's distributed identity public key certificate, verifies the digital signature in the user's distributed identity public key certificate using the public key body, and obtains the user's distributed identity public key based on the public key body after successful verification. In these embodiments of the present invention, obtaining the user's distributed identity public key through the public key certificate in the authentication request saves the step of querying and obtaining the public key from the distributed identity chain, saves verification time, and improves verification efficiency.

[0145] In an embodiment of the present invention, if the consensus process on the blockchain takes a long time and the user's distributed identity public key certificate is updated but the public key certificate on the distributed identity chain 140 is not updated, the verification of the credential signature will fail. The latest user distributed public key certificate is obtained through the applicant terminal 110 to ensure that the credential signature can be verified according to the actual situation, thereby improving the user experience.

[0146] In some embodiments of the present invention, to ensure the consistency of public key certificates stored by multiple parties, the verification authority 130 also compares the public key obtained from the user's distributed identity public key certificate in the authentication request with the public key obtained from the distributed identity chain 140. Specifically, obtaining the user's distributed identity public key based on the public key subject includes:

[0147] Verification authority 130 obtains the user's distributed identity public key from the distributed identity chain 140 based on the user's distributed identity identifier; it compares whether the public key subject is consistent with the user's distributed identity public key. If they are consistent, the public key subject is used as the user's distributed identity public key.

[0148] In other embodiments of the present invention, in order to ensure that the user distributed identity public key used by the security chip 112 in generating the credential signature is consistent with the public key in the user distributed identity public key certificate, the verification authority 130 may also require that the verifiable expression content include the user distributed identity public key, and then perform a consistency check. Specifically, obtaining the user distributed identity public key based on the public key body includes:

[0149] Verification agency 130 compares whether the user's distributed identity public key in the verifiable expression content is consistent with the public key subject. If they are consistent, the public key subject is used as the user's distributed identity public key.

[0150] In this embodiment of the invention, multiple public key verifications are performed to ensure that the user distributed identity public key used is authentic and reliable.

[0151] S3062: Verification authority 130 verifies the credential signature using the user's distributed identity public key and generates a credential signature verification result. In this embodiment of the invention, the signature verification algorithm can adopt a national cryptographic algorithm for signature verification.

[0152] S3063: Verification agency 130 verifies verifiable vouchers based on the voucher signature verification result and generates voucher verification result.

[0153] In this embodiment of the invention, the verifiable credential includes a signature portion issued by the issuing authority's distributed identity private key. The issuing authority's distributed identity public key is required to verify the signature portion. In this embodiment of the invention, the issuing authority's distributed identity public key is obtained through the issuing authority's distributed identity identifier in the declaration portion.

[0154] like Figure 10 As shown, step S3063 above includes the following steps:

[0155] S30631: In response to the credential signature verification result indicating that the credential signature verification is successful, the verification authority 130 obtains the issuing authority's distributed identity public key from the distributed identity chain 140 based on the issuing authority's distributed identity identifier. In some embodiments of the present invention, the distributed identity chain 140 stores an issuing authority's distributed identity identifier document, which can be obtained from the distributed identity chain 140 through the issuing authority's distributed identity identifier, and the issuing authority's distributed identity public key can be obtained from the distributed identity identifier document.

[0156] In some embodiments of the present invention, the issuing authority's distributed identity document stores the issuing authority's distributed identity public key certificate, and the validity of the public key can be verified before use. Specifically, such as Figure 11 As shown, the public key for the issued authority's distributed identity is obtained from the distributed identity chain 140, including:

[0157] S306311: Verification authority 130 obtains the issuing authority distributed identity identifier document from the distributed identity chain 140, wherein the issuing authority distributed identity identifier document includes the issuing authority distributed identity public key certificate and the trusted central authority distributed identity identifier (creator), and the digital signature in the issuing authority distributed identity public key certificate is generated by signing the trusted central authority distributed identity private key.

[0158] S306312: Verification authority 130 obtains a trusted central authority distributed identity public key from distributed identity chain 140 based on the trusted central authority distributed identity identifier. Distributed identity chain 140 stores a trusted central authority distributed identity identifier document, which contains the trusted central authority distributed identity identifier and a trusted central authority distributed identity public key certificate. The trusted central authority distributed identity identifier document can be indexed through the trusted central authority distributed identity identifier, thereby obtaining the trusted central authority distributed identity public key certificate, and then obtaining the trusted central authority distributed identity public key from the trusted central authority distributed identity public key certificate. In some embodiments of the present invention, the digital signature in the trusted central authority distributed identity public key certificate is generated by the trusted central authority distributed identity private key. After obtaining the trusted central authority distributed identity public key certificate, verification authority 130 can use the trusted central authority distributed identity public key therein to verify the digital signature in the trusted central authority distributed identity public key certificate. After successful verification, it is determined that the trusted central authority distributed identity public key stored on the chain has not been tampered with, and the trusted central authority distributed identity public key is used to verify the digital signature in the issuing authority distributed identity public key certificate.

[0159] S306313: Verification authority 130 uses the trusted central authority's distributed identity public key to verify the digital signature in the issuing authority's distributed identity public key certificate. After successful verification, the public key subject in the issuing authority's distributed identity public key certificate is used as the issuing authority's distributed identity public key.

[0160] In this embodiment of the invention, the trusted central authority creates a distributed identity for the issuing authority. The trusted central authority sets the distributed identity identifier of the trusted central authority as the creator in the distributed identity identifier document of the issuing authority, and uses the private key of the trusted central authority's distributed identity to generate a digital signature in the distributed identity document of the issuing authority.

[0161] In this embodiment of the invention, the digital signature in the issuing authority's distributed identity public key certificate is verified by the distributed identity public key of a trusted central authority, thereby determining the legitimacy of the issuing authority's distributed identity public key.

[0162] In this embodiment of the invention, the verification authority 130 performs at least three signature verifications. First, it verifies that the verifiable representation was submitted by the user (verification through credential signature); second, it verifies that the verifiable representation was submitted by the user and issued by the issuing authority (verification of the signature portion of the verifiable representation); third, it verifies that the distributed identity of the issuing authority was created by a trusted central authority (verification through the digital signature of the issuing authority's distributed public key certificate), and the trusted central authority is in the trusted list of verification authorities, forming a verification closed loop.

[0163] S30632: Verification authority 130 verifies the signature portion based on the issuing authority's distributed identity public key. After successful verification, it generates a credential verification result indicating that the verification has been successful.

[0164] In an embodiment of the present invention, the authenticity of the verifiable credential is determined by verifying the signature portion, and the content of the credential has not been tampered with.

[0165] In other embodiments of the present invention, in step S30632 above, after the verification agency 130 verifies the signature portion, it does not directly generate a credential verification result indicating that the verification has passed. Instead, it also verifies the status of the verifiable credential, such as... Figure 12 As shown, the specific steps include the following:

[0166] S306321': After the verification agency 130 determines that the signature part has been verified based on the verification result of the signature part, it generates a query digest value based on the verifiable credential.

[0167] S306322': Verification agency 130 obtains verifiable credential status information from distributed identity chain 140 based on the query digest value. In some embodiments of the present invention, when a user activates distributed identity or applies for a verifiable credential, the applicant terminal 110 or issuing agency 120 stores the verifiable credential digest value and verifiable credential status information together on distributed identity chain 140, and the corresponding verifiable credential status information can be queried through the digest value. In embodiments of the present invention, verifiable credential status information includes valid, invalid, etc. When a verifiable credential becomes invalid, the status information on distributed identity chain 140 is synchronously changed, which can be synchronized from the applicant terminal 110 or issuing agency 120 to the distributed identity chain 140.

[0168] In this embodiment of the invention, the verification agency 130 sends the query digest value to the distributed identity chain 140, the distributed identity chain 140 obtains the credential status information based on the query digest value, and sends the credential status information to the verification agency 130.

[0169] S306323': After the verification agency 130 responds to the status information indicating that the credential is valid, it generates a credential verification result indicating that the verification has passed.

[0170] In this embodiment of the invention, when the verifiable credential is generated, the issuing authority 120 sets a validity period, that is, the declaration part includes credential validity period information. Verifying the verifiable credential also includes verifying the validity period based on the current time. For example, if the declaration part specifies that the validity period expires on January 1, 2025, at 00:00:00, and the current time is November 1, 2024, at 12:05:56, then the validity period has not expired, and the verification passes.

[0171] In some embodiments of the present invention, the declaration portion of the verifiable credential also includes the credential type. When verifying the verifiable credential, the credential type can also be verified. For example, the verification agency only accepts verifiable credentials of type A and B, and considers type C verifiable credentials to be untrustworthy. Therefore, when the user presents a type C verifiable credential, the verification agency 130 fails to verify it.

[0172] In some embodiments of the present invention, the verification authority 130 also verifies the identity of the issuing authority. The verification authority 130 pre-stores a whitelist of trusted issuing authorities. When the issuing authority is not in the whitelist, the verification authority 130 fails to verify. The verification authority 130 can determine whether the issuing authority is in the pre-stored whitelist of trusted issuing authorities based on the distributed identity identifier of the issuing authority, or based on the issuing authority information in the verifiable credential declaration section.

[0173] In the above-described verification of credential signature, verification of signature portion, and verification of verifiable credential validity period and status in this embodiment of the invention, if verification fails, the verification agency 130 returns the verification failure result to the applicant terminal 110 or wallet application 111.

[0174] In some embodiments of the present invention, the verifiable content may include business processing request related content. After verifying the credential signature and the verifiable credential signature portion, the verification agency 130 can process the business based on the business processing request related content. For example, after the verification agency 130 verifies the request, it can perform operations such as wallet opening or wallet upgrade.

[0175] S307: Verification agency 130 sends the credential verification result to wallet application 111. In some embodiments of the present invention, verification agency 130 may also send the business processing result to wallet application 111 synchronously or asynchronously. In some embodiments of the present invention, verification agency 130 may first send the credential verification result to wallet application 111, and after wallet application 111 confirms it, verification agency continues to process the business request, and after processing is completed, sends the business processing result to wallet application 111.

[0176] S308: Wallet application 111 displays the credential verification result and / or the transaction processing result. In some embodiments of the present invention, wallet application 111 may first display the credential verification result, and then display the transaction processing result after receiving it.

[0177] This invention provides a distributed identity activation method and a user authentication method based on a security chip. It realizes functions such as distributed identity creation and maintenance, credential issuance, credential presentation and verification, and authorization management. It constructs a financial distributed identity chain, realizes distributed storage and verification of credentials, and stores and manages nodes for access institution registration services.

[0178] Some embodiments of this invention are based on security chips and use domestically developed cryptographic algorithms to authenticate the legitimacy of visitors, preventing keys from being illegally stolen or tampered with, thus improving data transmission security and providing cryptographic hardware support. The security chip is responsible for key creation, use, and management. In these embodiments, authentication results can be shared and reused across operating institutions and business processes, simplifying user authentication within the digital wallet system, thereby improving user convenience and establishing a mechanism for multi-party mutual trust and efficient collaboration among banking institutions, markets, government agencies, and other stakeholders, ultimately enhancing the efficiency of financial services.

[0179] According to embodiments of the present invention, a corresponding apparatus is also provided based on the above method flow, such as... Figure 13 As shown, this embodiment of the invention provides a distributed identity activation device 400, which is applied to a security chip installed in the applicant's terminal. The applicant's terminal also has a wallet application installed. The device 400 includes an application installation response module 410, a key generation module 420, and a credential processing module 430. The functions of each module are described below:

[0180] The application installation response module 410 is configured to send the installation result of the distributed identity application to the wallet application in response to the completion of the installation of the distributed identity application in the security chip, so that the wallet application sends a verifiable credential acquisition request to the issuing authority, wherein the verifiable credential acquisition request includes user identity information;

[0181] The key generation module 420 is configured to obtain the distributed identity activation instruction sent by the wallet application, generate the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate. The distributed identity activation instruction includes a verifiable credential, which includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier generated by the issuing authority after verifying the user's identity information.

[0182] The credential processing module 430 is configured to obtain the user's distributed identity identifier from the verifiable credentials, send the user's distributed identity identifier and the user's distributed identity public key certificate to the wallet application, so that the wallet application can generate a user's distributed identity identifier document based on the user's distributed identity identifier and the user's distributed identity public key certificate, and send the user's distributed identity identifier document, verifiable credentials and user's distributed identity identifier to the distributed identity chain for associated storage.

[0183] In some embodiments of the present invention, the application installation response module 410 is further configured to obtain the distributed identity application and user personalization data sent by the wallet application, and install the distributed identity application, wherein the user personalization data includes user wallet account information.

[0184] In some embodiments of the present invention, the user distributed identity public key certificate includes creator identity information, public key subject, and digital signature, and the key generation module 420 is further configured to:

[0185] Generate creator identity information based on user wallet account information;

[0186] Use the user's distributed identity public key as the public key subject;

[0187] A digital signature is generated based on the user's distributed identity private key.

[0188] In some embodiments of the present invention, the user's personalized data further includes issuing authority information, which includes the issuing authority name, the issuing authority's distributed identity public key certificate, and the issuing authority's distributed identity public key certificate including the issuing authority's distributed identity public key; the credential processing module 430 is also configured to:

[0189] The signature portion is verified using the issuing authority's distributed identity public key, and a signature verification result is generated.

[0190] In response to the signature verification result indicating successful verification, the user's distributed identity identifier is obtained from the claim section of the verifiable credentials, and the verifiable credentials are stored.

[0191] In some embodiments of the present invention, the credential processing module 430 is further configured to store verifiable credentials with the same user distributed identity into the same chained storage structure.

[0192] like Figure 14 As shown, this embodiment of the invention also provides a distributed identity activation device 500, applied to the applicant terminal. The applicant terminal is also equipped with a security chip. The device 500 includes a personalization module 510, a verifiable credential acquisition module 520, a distributed identity activation module 530, a distributed identity receiving module 540, and an on-chain module 550. The functions of each module are described below:

[0193] The personalization module 510 is configured to send a distributed identity application and user personalization data to the security chip in response to the user's distributed identity activation operation, so that the security chip can install the distributed identity application and generate the distributed identity application installation result after the installation is completed.

[0194] The verifiable credential acquisition module 520 is configured to receive the installation result of the distributed identity application sent by the security chip, obtain the user identity information, and send a verifiable credential acquisition request containing the user identity information to the issuing authority so that the issuing authority can generate a verifiable credential. The verifiable credential includes a declaration part and a signature part generated by signing the declaration part with the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier generated by the issuing authority after verifying the user's identity information.

[0195] The distributed identity activation module 530 is configured to receive verifiable credentials sent by the issuing authority and send a distributed identity activation instruction containing verifiable credentials to the security chip, so that the security chip generates the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate.

[0196] The distributed identity receiving module 540 is configured to receive the user distributed identity identifier and user distributed identity public key certificate sent by the security chip, and generate a user distributed identity identifier document based on the user distributed identifier and user distributed identity public key certificate;

[0197] The on-chain module 550 is configured to send the user's distributed identity identifier, the user's distributed identity identifier document, and verifiable credentials to the distributed identity chain for associated storage.

[0198] In some embodiments of the present invention, the personalization module 510 is further configured to: send a distributed identity application activation request to the trusted service management platform, so that the trusted service management platform obtains user personalization data from the issuing authority and sends the user personalization data and the distributed identity application to the wallet application; and receive user personalization data and the distributed identity application sent by the trusted service management platform.

[0199] like Figure 15 As shown in the figure, this embodiment of the invention also provides a distributed identity activation device 600, applied to an issuing authority. The device 600 includes a credential request acquisition module 610, a distributed identity generation module 620, a credential generation module 630, and a credential sending module 640. The functions of each module are described below:

[0200] The credential request acquisition module 610 is configured to acquire a verifiable credential acquisition request sent by the wallet application in the applicant's terminal, wherein the verifiable credential acquisition request includes user identity information.

[0201] The distributed identity generation module 620 is configured to verify user identity information and generate a distributed identity identifier for the user after successful verification.

[0202] In some embodiments of the present invention, the distributed identity generation module 620 is further configured to perform digest calculation using user identity information and timestamp information to generate a user distributed identity identifier.

[0203] In some embodiments of the present invention, the distributed identity generation module 620 is further configured as follows:

[0204] Send user identity information to a trusted identity management authority so that the trusted identity management authority can verify the user identity information and generate an identity verification result; receive the identity verification result returned by the trusted identity management authority.

[0205] The credential generation module 630 is configured to generate verifiable credentials based on the user's distributed identity identifier. The verifiable credentials include a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes the credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier.

[0206] In some embodiments of the present invention, the credential generation module 630 is further configured to: generate a declaration portion of a verifiable credential based on the user's distributed identity identifier, select a corresponding signature algorithm to sign the declaration portion based on the data volume of the declaration portion, and generate a signature portion of the verifiable credential.

[0207] In some embodiments of the present invention, the voucher generation module 630 is further configured as follows:

[0208] When the amount of data in the declaration part exceeds the data amount threshold, a hash calculation is performed on the declaration part to obtain a digest value of the preset data amount. The digest value is then signed using the issuing authority's distributed identity private key to generate the signature part.

[0209] When the amount of data in the declaration section is less than or equal to the data volume threshold, the declaration section is signed using the issuing authority's distributed identity private key to generate the signature section.

[0210] In some embodiments of the present invention, the preset data volume is less than the data volume threshold.

[0211] The credential sending module 640 is configured to send verifiable credentials to the wallet application.

[0212] In some embodiments of the present invention, the device 600 further includes a personalized data sending module 650, which is configured to: obtain a distributed identity application activation request forwarded by a trusted service management platform, send user personalized data to the trusted service management platform, so that the trusted service management platform sends the user personalized data and the distributed identity application to the wallet application, the wallet application sends the user personalized data and the distributed identity application to the security chip, and the security chip installs the distributed application.

[0213] In some embodiments of the present invention, user personalization data also includes an authority-issued distributed identity public key certificate.

[0214] like Figure 16 As shown, this embodiment of the invention also provides a user authentication device 700, which is applied to a security chip installed in the applicant's terminal. The applicant's terminal also has a wallet application installed. The device 700 includes a credential reading module 710, a verifiable expression generation module 720, and a verifiable expression sending module 730. The functions of each module are described below:

[0215] The credential reading module 710 is configured to receive a verifiable credential generation instruction sent by the wallet application, and obtain the locally stored verifiable credential and user distributed identity identifier. The verifiable credential includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes credential content, issuing authority distributed identity identifier, and user distributed identity identifier.

[0216] The verifiable representation generation module 720 is configured to generate verifiable representations based on verifiable credentials and user distributed identity identifiers.

[0217] In embodiments of the present invention, a verifiable expression includes verifiable expression content and a credential signature. A credential signature is generated by signing the verifiable expression content using the user's distributed identity private key. The verifiable expression content includes a user-selected verifiable credential and a user distributed identity identifier. In some embodiments of the present invention, the verifiable expression content may further include business request content.

[0218] In some embodiments of the present invention, the verifiable expression generation module 720 is further configured to: select a corresponding signature algorithm to sign the verifiable expression content in the verifiable expression according to the amount of data in the verifiable expression content, and generate a credential signature in the verifiable expression.

[0219] In some embodiments of the present invention, the verifiable expression generation module 720 is further configured as follows:

[0220] When the amount of verifiable content exceeds the data volume threshold, a hash calculation is performed on the verifiable content to obtain a content digest value of a preset data volume. The content digest value is then signed using the user's distributed identity private key to generate a credential signature.

[0221] When the amount of verifiable content is less than or equal to the data volume threshold, the verifiable content is signed using the user's distributed identity private key to generate a credential signature.

[0222] In some embodiments of the present invention, the preset data volume is less than the data volume threshold.

[0223] In some embodiments of the present invention, the verifiable content also includes timestamp information.

[0224] In some embodiments of the present invention, the verifiable expression generation instruction also includes a random number, which is obtained by the wallet application from the verification authority after receiving the authentication request operation, and the verifiable expression content also includes a random number.

[0225] In some embodiments of the present invention, the verifiable expression content also includes the user's distributed identity public key.

[0226] The verifiable expression sending module 730 is configured to send a verifiable expression to the wallet application, so that the wallet application sends an authentication request containing the verifiable expression to the verification authority for verification.

[0227] In some embodiments of the present invention, the verifiable expression sending module 730 is further configured to send the user's distributed identity public key certificate to the wallet application, and the authentication request also includes the user's distributed identity public key certificate.

[0228] like Figure 17 As shown, this embodiment of the invention also provides an identity verification device 800, applied to a verification organization. The device 800 includes an identity verification request acquisition module 810, a verification module 820, and a verification result sending module 830. The functional modules are described below:

[0229] The authentication request acquisition module 810 is configured to acquire the authentication request sent by the wallet application of the applicant terminal. The authentication request includes a verifiable expression, which includes the content of the verifiable expression and the credential signature.

[0230] In some embodiments of the present invention, the credential signature is generated by the security chip of the applicant terminal after selecting the corresponding algorithm for signing based on the amount of data of the verifiable express content. The verifiable express content includes verifiable credentials and user distributed identity identifiers.

[0231] The verification module 820 is configured to verify verifiable expressions and generate credential verification results.

[0232] In some embodiments of the present invention, the verification module 820 is further configured as follows:

[0233] The system checks whether the value of the credential signature matches the value of the credential signature sent from the wallet application before a preset time period. If they match, the verification fails.

[0234] In some embodiments of the present invention, the device 800 further includes a random number distribution module 840, which is configured to: acquire a random number acquisition request sent by a wallet application, generate a random number, and send the random number to the wallet application, so that the wallet application sends a random number to the security chip. The wallet application generates the random number acquisition request after receiving an authentication request operation; the verifiable expression content includes the random number. Correspondingly, in some embodiments of the present invention, the verification module 820 is further configured to: verify whether the random number in the verifiable expression content is consistent with the distributed random number; if they are inconsistent, the verification fails.

[0235] In some embodiments of the present invention, the verification module 820 is further configured as follows:

[0236] Obtain the user's distributed identity public key;

[0237] The credential signature is verified using the user's distributed identity public key, and a credential signature verification result is generated.

[0238] Based on the voucher signature verification result, the verifiable voucher is verified, and a voucher verification result is generated.

[0239] In some embodiments of the present invention, the verification module 820 is further configured as follows:

[0240] Based on the user's distributed identity identifier, obtain the user's distributed identity public key from the distributed identity chain.

[0241] In some embodiments of the present invention, the authentication request includes a user's distributed identity public key certificate, and the verification module 820 is further configured to obtain the user's distributed identity public key based on the user's distributed identity public key certificate. Specifically, the verification module 820 is further configured to:

[0242] Obtain the public key body from the user's distributed identity public key certificate, use the public key body to verify the digital signature in the user's distributed identity public key certificate, and after successful verification, obtain the user's distributed identity public key based on the public key body.

[0243] In some embodiments of the present invention, the verification module 820 is further configured as follows:

[0244] Based on the user's distributed identity identifier, obtain the user's distributed identity public key from the distributed identity chain;

[0245] The system compares the public key subject with the user's distributed identity public key. If they match, the public key subject is used as the user's distributed identity public key.

[0246] In some embodiments of the present invention, the verification module 820 is further configured as follows:

[0247] The system compares the user's distributed identity public key in the verifiable expression content with the public key body. If they match, the public key body is used as the user's distributed identity public key.

[0248] In some embodiments of the present invention, the verifiable credential includes a declaration portion and a signature portion generated by signing the declaration portion with the issuing authority's distributed identity private key, wherein the declaration portion includes the issuing authority's distributed identity identifier. In some embodiments of the present invention, the verification module 820 is further configured to:

[0249] In response to the credential signature verification result indicating that the credential signature verification is successful, the issuing authority's distributed identity public key is obtained from the distributed identity chain based on the issuing authority's distributed identity identifier;

[0250] The signature is verified using the issuing authority's distributed identity public key. Once the verification is successful, a credential verification result indicating successful verification is generated.

[0251] In some embodiments of the present invention, the verification module 820 is further configured as follows:

[0252] Obtain the issuing authority's distributed identity document from the distributed identity chain. The distributed identity document includes the issuing authority's distributed identity public key certificate and the trusted central authority's distributed identity. The digital signature in the issuing authority's distributed identity public key certificate is generated by signing the trusted central authority's distributed identity private key.

[0253] Obtain the trusted central authority's distributed identity public key from the distributed identity chain based on the trusted central authority's distributed identity identifier;

[0254] The digital signature in the issuing authority's distributed identity public key certificate is verified using the trusted central authority's distributed identity public key. Once the verification is successful, the public key subject in the issuing authority's distributed identity public key certificate is used as the issuing authority's distributed identity public key.

[0255] In some embodiments of the present invention, the verification module 820 further verifies the status of the verifiable credential, and the verification module 820 is further configured to:

[0256] After determining that the signature verification is successful based on the signature verification result, a query digest value is generated based on the verifiable credentials.

[0257] Retrieve verifiable credential status information from the distributed identity chain based on the query digest value;

[0258] In response to a status information indicating that the credential is valid, a credential verification result indicating that the verification has passed is generated.

[0259] In some embodiments of the present invention, the declaration section also includes a certificate validity period, and the verification module 820 is further configured to verify the certificate validity period based on the current time.

[0260] The verification result sending module 830 is configured to send the credential verification result to the wallet application.

[0261] The device features of the embodiments of the present invention can be referred to the features of the methods and steps of the embodiments of the present invention, and the system embodiments can be combined with the features of the method embodiments to obtain new embodiments, and vice versa, and will not be repeated here.

[0262] An embodiment of the present invention provides an electronic device comprising: a processor and a memory storing a computer program, the processor being configured to implement any method according to an embodiment of the present invention when running the computer program. Additionally, means for implementing an embodiment of the present invention may also be provided.

[0263] Figure 18 An exemplary system architecture 1800 is shown, in which the identity credential application, distributed identity activation method, and distributed identity activation device of embodiments of the present invention can be applied.

[0264] like Figure 18 As shown, system architecture 1800 may include terminal devices 1801, 1802, and 1803, network 1804, and server 1805. Network 1804 is used as a medium to provide communication links between terminal devices 1801, 1802, and 1803 and server 1805. Network 1804 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0265] Users can use terminal devices 1801, 1802, and 1803 to interact with server 1805 via network 1804 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 1801, 1802, and 1803, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0266] Terminal devices 1801, 1802, and 1803 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0267] Server 1805 can be a server providing various services, such as a backend management server supporting shopping websites browsed by users using terminal devices 1801, 1802, and 1803 (for example only). The backend management server can analyze and process data such as received product information query requests, and feed back the processing results (such as target push information and product information - for example only) to the terminal devices.

[0268] It should be noted that the identity credential application and distributed identity activation method provided in the embodiments of the present invention is generally executed by the server 1805, and correspondingly, the identity credential application and distributed identity activation implementation device is generally set in the server 1805.

[0269] It should be understood that Figure 18 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0270] The following is for reference. Figure 19 It shows a schematic diagram of the structure of a computer system 1900 suitable for implementing terminal devices or servers of the present invention, and the methods or apparatus for implementing the methods in the embodiments of the present invention can be implemented on the computer system 1900. Figure 19 The terminal device or server shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.

[0271] like Figure 19 As shown, the computer system 1900 includes a central processing unit (CPU) 1901, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 1902 or programs loaded from storage section 1908 into random access memory (RAM) 1903. The RAM 1903 also stores various programs and data required for the operation of the system 1900. The CPU 1901, ROM 1902, and RAM 1903 are interconnected via bus 1904. An input / output (I / O) interface 1905 is also connected to bus 1904.

[0272] The following components are connected to I / O interface 1905: input section 1906 including keyboard, mouse, etc.; output section 1907 including cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; storage section 1908 including hard disk, etc.; and communication section 1909 including network interface card, such as LAN card, modem, etc. Communication section 1909 performs communication processing via a network such as the Internet. Drive 1910 is also connected to I / O interface 1905 as needed. Removable media 1911, such as disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 1910 as needed so that computer programs read from them can be installed into storage section 1908 as needed.

[0273] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1909, and / or installed from removable medium 1911. When the computer program is executed by central processing unit (CPU) 1901, it performs the functions defined above in the system of this invention.

[0274] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0275] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0276] The units or modules described in the embodiments of the present invention can be implemented in software or hardware. The described units or modules can also be housed in a processor; for example, a processor can be described as including a sending unit (or "module"), an acquisition unit, a determining unit, and a first processing unit. The names of these units or modules do not necessarily limit the specific unit or module itself; for example, a sending unit can also be described as "a unit that sends an image acquisition request to a connected server."

[0277] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to perform the methods described in the above embodiments.

[0278] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A distributed identity activation method, characterized in that, The method, which applies to a security chip installed in a requester's terminal, and the requester's terminal also includes a wallet application, comprises: In response to the completion of the installation of the distributed identity application within the security chip, the installation result of the distributed identity application is sent to the wallet application, so that the wallet application sends a verifiable credential acquisition request to the issuing authority, wherein the verifiable credential acquisition request includes user identity information; The system obtains the distributed identity activation instruction sent by the wallet application, generates a user distributed identity private key and public key, as well as a user distributed identity public key certificate. The distributed identity activation instruction includes a verifiable credential, which includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes credential content, an issuing authority's distributed identity identifier, and a user distributed identity identifier generated by the issuing authority after verifying the user's identity information. The user distributed identity identifier is obtained from the verifiable credentials, and the user distributed identity identifier and the user distributed identity public key certificate are sent to the wallet application, so that the wallet application generates a user distributed identity identifier document based on the user distributed identity identifier and the user distributed identity public key certificate, and sends the user distributed identity identifier document and the verifiable credentials to the distributed identity chain for associated storage.

2. The method according to claim 1, characterized in that, The method further includes: Obtain the distributed identity application and user personalization data sent by the wallet application, and install the distributed identity application, wherein the user personalization data includes user wallet account information.

3. The method according to claim 2, characterized in that, The user distributed identity public key certificate includes creator identity information, public key subject, and digital signature. Generating the user distributed identity public key certificate includes: The creator's identity information is generated based on the user's wallet account information; Use the user's distributed identity public key as the public key subject; The digital signature is generated based on the user's distributed identity private key.

4. The method according to claim 2, characterized in that, The user's personalized data also includes issuing authority information, which includes the issuing authority's name and a distributed identity public key certificate, wherein the distributed identity public key certificate includes the issuing authority's distributed identity public key; obtaining the user's distributed identity identifier from the verifiable credential includes: The signature portion is verified using the issued authority's distributed identity public key, and a signature portion verification result is generated. In response to the signature verification result indicating successful verification, the user's distributed identity identifier is obtained from the declaration portion of the verifiable credential, and the verifiable credential is stored.

5. The method according to claim 4, characterized in that, The storage of the verifiable credentials includes: If the amount of data of the verifiable credential exceeds the storage threshold, a storage failure result is sent to the wallet application so that the wallet application stores the verifiable credential outside the security chip.

6. The method according to claim 2, characterized in that, The method further includes: Verifiable credentials with the same distributed identity of a user are stored in the same chained storage structure.

7. A distributed identity activation method, characterized in that, The method, applied to a wallet application installed within a requester's terminal, wherein the requester's terminal also contains a security chip, includes: In response to a user's distributed identity activation operation, a distributed identity application is sent to the security chip so that the security chip can install the distributed identity application, and a distributed identity application installation result is generated after the installation is completed. The system receives the installation result of the distributed identity application sent by the security chip, obtains the user identity information, and sends a request to the issuing authority to obtain a verifiable credential containing the user identity information, so that the issuing authority can generate a verifiable credential. The verifiable credential includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes credential content, the issuing authority's distributed identity identifier, and a user distributed identity identifier generated by the issuing authority after verifying the user identity information. The system receives the verifiable credential sent by the issuing authority and sends a distributed identity activation instruction containing the verifiable credential to the security chip, so that the security chip generates the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate. Receive the user distributed identity identifier and the user distributed identity public key certificate sent by the security chip, and generate a user distributed identity identifier document based on the user distributed identifier and the user distributed identity public key certificate; The user's distributed identity document and the verifiable credentials are sent to the distributed identity chain for associated storage.

8. The method according to claim 7, characterized in that, Before sending the distributed identity application to the security chip, the method further includes: Send a distributed identity application activation request to the trusted service management platform so that the trusted service management platform can obtain the user's personalized data from the issuing authority and send the user's personalized data and the distributed identity application to the wallet application; Receive user-personalized data and distributed identity applications sent by the trusted service management platform; When the security chip sends the distributed identity application, it also sends the user's personalized data.

9. The method according to claim 7, characterized in that, The method further includes: in response to a failure to store verifiable credentials sent by the security chip, storing the verifiable credentials outside the security chip.

10. A distributed identity activation method, characterized in that, Applied to an issuing authority, the method includes: Obtain a verifiable credential acquisition request sent by the wallet application within the applicant's terminal, wherein the verifiable credential acquisition request includes user identity information; The user's identity information is verified, and a distributed user identity identifier is generated upon successful verification. A verifiable credential is generated based on the user's distributed identity identifier. The verifiable credential includes a declaration portion and a signature portion generated by signing the declaration portion using the issuing authority's distributed identity private key. The declaration portion includes credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier. Send the verifiable credentials to the wallet application.

11. The method according to claim 10, characterized in that, Before obtaining the verifiable credential acquisition request, the method further includes: The system obtains a distributed identity application activation request forwarded by the trusted service management platform, sends user-personalized data to the trusted service management platform, so that the trusted service management platform sends the user-personalized data and the distributed identity application to the wallet application, the wallet application sends the user-personalized data and the distributed identity application to the security chip, and the security chip installs the distributed application.

12. A distributed identity activation device, characterized in that, The device is applied to a security chip installed in the applicant's terminal, which also contains a wallet application. The device includes an application installation response module, a key generation module, and a credential processing module. The application installation response module is configured to send the installation result of the distributed identity application to the wallet application in response to the completion of the installation of the distributed identity application in the security chip, so that the wallet application sends a verifiable credential acquisition request to the issuing authority, wherein the verifiable credential acquisition request includes user identity information; The key generation module is configured to obtain the distributed identity activation instruction sent by the wallet application, generate a user distributed identity private key and public key, and a user distributed identity public key certificate. The distributed identity activation instruction includes a verifiable credential, which includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes credential content, an issuing authority's distributed identity identifier, and a user distributed identity identifier generated by the issuing authority after verifying the user's identity information. The credential processing module is configured to obtain the user's distributed identity identifier from the verifiable credentials, send the user's distributed identity identifier and the user's distributed identity public key certificate to the wallet application, so that the wallet application generates a user's distributed identity identifier document based on the user's distributed identity identifier and the user's distributed identity public key certificate, and sends the user's distributed identity identifier document and the verifiable credentials to the distributed identity chain for associated storage.

13. A distributed identity activation device, characterized in that, The device is applied to the applicant's terminal, which also contains a security chip. The device includes a personalization module, a verifiable credential acquisition module, a distributed identity activation module, a distributed identity receiving module, and an on-chain module. The personalization module is configured to send a distributed identity application and user personalization data to the security chip in response to the user's distributed identity activation operation, so that the security chip can install the distributed identity application and generate a distributed identity application installation result after the installation is completed. The verifiable credential acquisition module is configured to receive the distributed identity application installation result sent by the security chip, obtain user identity information, and send a verifiable credential acquisition request containing the user identity information to the issuing authority, so that the issuing authority generates a verifiable credential. The verifiable credential includes a declaration part and a signature part generated by signing the declaration part using the issuing authority's distributed identity private key. The declaration part includes credential content, the issuing authority's distributed identity identifier, and a user distributed identity identifier generated by the issuing authority after verifying the user identity information. The distributed identity activation module is configured to receive the verifiable credential sent by the issuing authority and send a distributed identity activation instruction containing the verifiable credential to the security chip, so that the security chip generates the user's distributed identity private key and public key, as well as the user's distributed identity public key certificate. The distributed identity receiving module is configured to receive the user distributed identity identifier and the user distributed identity public key certificate sent by the security chip, and generate a user distributed identity identifier document based on the user distributed identifier and the user distributed identity public key certificate; The on-chain module is configured to send the user's distributed identity document and the verifiable credential to the distributed identity chain for associated storage.

14. A distributed identity activation device, characterized in that, Applied to issuing authorities, the device includes a credential request acquisition module, a distributed identity generation module, a credential generation module, and a credential sending module, wherein... The credential request acquisition module is configured to acquire a verifiable credential acquisition request sent by the wallet application in the applicant's terminal, wherein the verifiable credential acquisition request includes user identity information; The distributed identity generation module is configured to verify the user's identity information, and generate a distributed identity identifier for the user after successful verification. The credential generation module is configured to generate verifiable credentials based on the user's distributed identity identifier. The verifiable credentials include a declaration portion and a signature portion generated by signing the declaration portion using the issuing authority's distributed identity private key. The declaration portion includes credential content, the issuing authority's distributed identity identifier, and the user's distributed identity identifier. The credential sending module is configured to send the verifiable credential to the wallet application.

15. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-11.

16. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-11.