Certificate authority based integration method for decentralized identity systems

CN122556056APending Publication Date: 2026-08-11BIT4ID LLC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0007]这种已知认证方法的主要限制在于,其要求该“第三方”改变其职责范围,承担通常由认证机构执行的任务

Benefits of technology

[0009]本发明的目的在于,通过提供一种用于去中心化身份系统的基于认证机构的集成方法来解决上述现有技术问题,该方法不需要“第三方/服务提供者”改变其行为和接口,使其继续仅处理认证证书,同时,由该认证机构构建集成了来自该认证证书的中心化信息和去中心化信息(VC和DID)的认证证书,该去中心化信息被转换为该认证证书的附加字段。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122556056A_ABST
    Figure CN122556056A_ABST
Patent Text Reader

Abstract

An authority-based integration method for a decentralized identity system is described, comprising: (101) obtaining input data related to an authentication certificate and a verifiable credential (VC); (102) verifying the validity of the certificate; (104) constructing a new certificate; (106) verifying that the verifiable credential (VC) and the authentication certificate point to the same subject; (107) verifying the validity of the verifiable credential (VC); (108) determining which information is relevant; (109) converting the relevant information into a series of fields for the authentication certificate; (110) adding the fields to the new authentication certificate; and (112) issuing the new authentication certificate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an authority-based integration method for decentralized identity systems that use verifiable credentials (VCs) and decentralized identifiers, particularly distributed identity files (DIDs).

[0002] In particular, the present invention relates to the preparation of new certification certificates by certification authorities, which begin with a certification certificate that integrates information stored in at least one verifiable credential (VC) and may be associated with at least one distributed identity file (DID) pointing to the same subject as the certification certificate.

[0003] In the integration method according to the invention, the certification authority constructs a new certification certificate that integrates centralized and decentralized information (VC and DID) of the certification certificate, the decentralized information being converted into additional fields of the new certification certificate. Background Technology

[0004] The known patent document GB2598096 involves the use of distributed identity files (DID) to authenticate users. These distributed identity files are also known as decentralized identity files, which are based on self-sovereign identity (SSI).

[0005] This known document describes a system and method for creating distributed identities for users, which can be used to authenticate with services and protect user data and data items.

[0006] Patent document GB2598096 describes an authentication method in which the analysis of the authenticity and validity of a DID is the responsibility of a "third party" (because it is the "third party" that parses the DID).

[0007] The main limitation of this known certification method is that it requires the "third party" to change its scope of responsibility and assume tasks that are normally performed by the certification body.

[0008] Document KR-A-2022 0112013 describes a prior art integration method. Summary of the Invention

[0009] The purpose of this invention is to solve the aforementioned problems of the prior art by providing an authority-based integration method for decentralized identity systems. This method does not require the "third party / service provider" to change its behavior and interface to continue processing only authentication certificates. At the same time, the authentication authority constructs an authentication certificate that integrates centralized and decentralized information (VC and DID) from the authentication certificate, and the decentralized information is converted into additional fields of the authentication certificate.

[0010] Another object of the present invention is to construct an authentication certificate that integrates information associated with multiple verifiable credentials and distributed identity files (VC and DID) into a single authentication certificate.

[0011] As will be apparent from the following description, the above and other objects and advantages of the invention are achieved through an authority-based integration method for a decentralized identity system, such as that described in the independent claims. Preferred embodiments and non-obvious variations of the invention constitute the subject matter of the dependent claims.

[0012] The method of the present invention can advantageously be implemented by a computer program including computer program encoding means, which, when executed on a computer, is used to implement one or more steps of the method. The scope of protection extends to such computer programs and to computer-readable media containing recorded messages, such computer-readable media including program encoding means, which, when executed on a computer, is used to implement one or more steps of the method.

[0013] It should be understood that the appended claims form part of this specification.

[0014] It will be apparent that numerous variations and modifications (e.g., relating to shape, size, arrangement, and components having equivalent functions) can be made to the described contents without departing from the scope of the invention as defined by the appended claims. Attached Figure Description

[0015] The present invention will now be better described with reference to the accompanying drawings and preferred embodiments, which are provided by way of example and not by way of limitation, wherein: Figure 1 A block diagram of an authority-based integration method for a decentralized identity system according to the present invention is shown. Detailed Implementation

[0016] Referring to the accompanying drawings, a preferred embodiment of an authority-based integration method for a decentralized identity system is illustrated and described; the method includes the following steps: - Step 101, in which the certification authority obtains input data, wherein data related to the certification certificate (preferably of type X.509) and data related to at least one verifiable credential (VC), each VC being able to point to at least one distributed identity file (DID). - Step 102: Verify the validity of the certification certificate (preferably of type X.509): If the verification is negative, the execution ends with an error message 103; - If the verification is positive, consider all relevant information present in the input authentication certificate (preferably of type X.509) and proceed to step 104 of constructing a new authentication certificate (preferably of type X.509); - Consider step 105, which involves one of the input verifiable credentials (VCs); - Step 106: Verifying that the verifiable credential (VC) and the authentication certificate (preferably of type X.509) point to the same subject; preferably, the verification step 106 includes a first sub-step, verifying the identity of the subject pointed to by the verifiable credential (VC), the verification being performed by considering any distributed identity files (DIDs) contained therein; and a second sub-step, verifying that the identity of the subject pointed to by the verifiable credential (VC) is the same as the identity present in the authentication certificate (preferably of type X.509); - If step 106, which verifies that the verifiable credential (VC) and the authentication certificate (preferably of type X.509) point to the same subject, is affirmative, the process continues to step 107, which verifies the validity of the verifiable credential (VC) based on the internal content of the verifiable credential (VC) and any distributed identity files (DIDs) contained within the verifiable credential itself. Step 107 includes: a first sub-step verifying the validity of the VC and the DID relative to their expiration dates; a second sub-step verifying that the same issuing authority has not issued an updated DID pointing to the same subject; and a third sub-step verifying that the key used to sign the VC or DID has not been revoked or expired. If step 106, which verifies that the VC and the DID and the authentication certificate point to the same subject, is negative, and / or if step 107, which verifies the validity of the verifiable credential (VC) or the distributed identity file (DID), the process continues to step 111, which verifies the existence of other pending verifiable credentials (VCs). - If the result of step 107, which verifies the validity of the verifiable credential (VC) and any associated distributed identity file (DID), is positive, there is a determination step 108, which determines which information contained in the verifiable credential (VC) and the distributed identity file (DID) is relevant to identifying the role, attributes, qualifications, and permissions of the subject indicated by the authentication certificate (preferably of type X.509); - Step 109: Converting the information recorded in the verifiable credential (VC) and its associated distributed identity file (DID) into a series of fields of the authentication certificate (preferably of type X.509); - Step 110: Add the fields involved in step 109 before the new certification certificate (preferably of type X.509); - Step 111 for verifying the existence of other pending verifiable credentials (VCs): If the result of this verification step 111 is positive, return to step 105, where one of the input verifiable credentials (VCs) is considered, and the subsequent steps described above are continued. - If the result of step 111, which verifies the existence of other pending verifiable credentials (VCs), is negative, there is an output step 112 to issue the new authentication certificate (preferably of type X.509), which includes at least one piece of information recorded in the input verifiable credential (VC), which is inserted into a series of fields of the new authentication certificate (preferably of type X.509).

[0017] The following describes examples of use cases for the authority-based integration method of the present invention for decentralized identity systems: a) A person wants to sign a contract; b) For this purpose, he / she uses his / her electronic identity card (CIE) to electronically identify himself / herself, which contains an X.509 authentication certificate (centralized). c) In order to sign, the person must prove, for example, that he / she is registered with a medical association; d) The person possesses the certificate, but in the form of a verifiable credential (VC) he / she received from the Medical Association; the verifiable credential points to a distributed identity document (DID) which contains further information relating to determining the validity of the certificate; e) The person obtains certification from a certification body (and presents the CIE to the body), along with the VC; f) The certification body verifies that the VC points to the same person as the certified person and that he / she is valid, and this verification is also performed by verifying the information recorded in the DID associated with the VC; g) In this case, the certification authority creates a new X.509 certification certificate, which contains, in addition to the information from the electronic ID, further information proving that the person is a doctor; h) The person uses the certificate to sign documents as a doctor (e.g., reports or legal reports); i) In order to perform this signature, the signing system manages the X.509 certification certificate generated by the certification authority, maintains its existing functional interface (and does not need to know or discover any information about VC or DID). j) The generated X.509 certification may include information with a limited length, can only be used once, or similar usage restrictions (to continue this example, since the person may lose that role in the future, even though he is a doctor). k) In any event that the certifying authority becomes aware that the person is no longer a doctor, it may revoke the X.509 generated containing that additional information.

[0018] Advantageously, the authority-based integration method for decentralized identity systems according to the invention does not require the "third party / service provider" to change its behavior and interface to continue processing only authentication certificates, but leaves the task of building an authentication certificate that integrates centralized information and decentralized information (DID) from that authentication certificate to the authentication authority.

[0019] Another advantage of this invention is that it allows the creation of an authentication certificate that integrates information associated with multiple verifiable credentials (VCs) into the same authentication certificate.

[0020] Preferred embodiments of the invention have been described, but naturally, they can be subject to further modifications and variations within the same inventive concept. In particular, numerous variations and modifications that fall within the scope of the invention as emphasized in the appended claims and are functionally equivalent to the foregoing embodiments will be apparent to those skilled in the art.

Claims

1. A certificate authority-based integration method for decentralized identity systems, comprising the following steps: - Step (101) of obtaining input data by the certification body, wherein data related to the certification certificate and data related to at least one verifiable credential (VC) are obtained; - Step (102) to verify the validity of the authentication certificate: If the verification is negative, the execution ends with an error message (103). - If the verification is positive, consider all relevant information present in the input authentication certificate and proceed to the step of building a new authentication certificate (104). - Among them, one of the input verifiable credentials (VC) is considered in step (105); - Step (106) to verify that the input verifiable credential (VC) and the authentication certificate point to the same subject. - If the result of the verification step (106) is positive, proceed to the step (107) of verifying the validity of the verifiable credential (VC). - If the result of step (107) in verifying the validity of the verifiable credential (VC) is positive, there is a step (108) to determine which information recorded in the verifiable credential (VC) is relevant to identifying the role, attributes, qualifications and permissions of the person indicated by the authentication certificate; - Step (109) to convert the relevant information recorded in the verifiable credential (VC) into a series of fields of the authentication certificate. - Step (110) to add the fields involved in step (109) before the new certification certificate; - Step (111) to verify the existence of other pending verifiable credentials (VCs). - If the result of step (111) verifying the existence of other pending verifiable credentials (VCs) is negative, there is an output step (112) of issuing the new authentication certificate, which includes the relevant information recorded in the verifiable credentials (VCs) and the relevant information is inserted into a series of fields of the new authentication certificate.

2. The authority-based integration method for decentralized identity systems according to claim 1, characterized in that, If the result of the verification step (106) in verifying that the verifiable credential (VC) points to the same subject as the authentication certificate is negative, and / or if the result of the step (107) in verifying the validity of the verifiable credential (VC) is negative, the method includes continuing to the step (111) in verifying that there are other verifiable credentials (VC) pending processing.

3. The authority-based integration method for decentralized identity systems according to claim 1 or 2, characterized in that, If the result of the verification step (111) is positive, return to step (105), in which one of the input verifiable credentials (VC) is considered, and continue with the subsequent steps described in the preceding claims.

4. The authority-based integration method for a decentralized identity system according to any one of the preceding claims, characterized in that, The step (106) of verifying that the input verifiable credential (VC) and the authentication certificate point to the same subject includes: a first sub-step of verifying the identity of the subject pointed to by the verifiable credential (VC); and a second sub-step of verifying that the identity of the subject pointed to by the verifiable credential (VC) is the same as the identity present in the authentication certificate.

5. The authority-based integration method for a decentralized identity system according to any one of the preceding claims, characterized in that, In step (101) where the authentication authority obtains the input data, each verifiable credential (VC) points to at least one distributed identity file (DID), and is characterized in that step (107) for verifying the validity of the verifiable credential (VC) is performed based on both the internal content of the verifiable credential (VC) and the distributed identity file (DID) recorded in the verifiable credential itself, wherein in step (108) it is determined which information recorded in the verifiable credential (VC) and the distributed identity file (DID) is related, and in step (109) the relevant information recorded in the verifiable credential (VC) and the at least one distributed identity file (DID) associated with it is converted.

6. The authority-based integration method for decentralized identity systems according to claim 5, characterized in that, The step (107) of verifying the validity of the verifiable credential (VC) includes: a first sub-step, verifying the validity of the verifiable credential (VC) based on its expiry date; a second sub-step, verifying that the same issuing authority has not issued an updated distributed identity file (DID) pointing to the same subject; and a third sub-step, verifying that the key used to sign the verifiable credential (VC) and / or the distributed identity file (DID) associated with it has not been revoked or expired.

7. The authority-based integration method for decentralized identity systems according to claim 5 or 6, characterized in that, The verification step (106) includes a first sub-step, verifying the identity of the subject pointed to by the verifiable credential (VC), and performing the verification by considering the distributed identity file (DID) contained in the verifiable credential (VC).

8. The authority-based integration method for a decentralized identity system according to any one of the preceding claims, characterized in that, The authentication certificate is an X.509 type certificate.

9. A computer program comprising a computer program encoding means, wherein when the program is executed on a computer, the computer program encoding means is adapted to perform all the steps of the method of claims 1 to 8.

10. A computer-readable medium having a program recorded thereon, the computer-readable medium including a computer program encoding means, which, when the program is executed on a computer, is adapted to perform all the steps of the method of claims 1 to 8.

Citation Information

Patent Citations

  • Method for authenticating using distributed identities

    GB2598096A