Identity credential application method and apparatus, and wallet identity verification method and apparatus

By using distributed identity verification and encryption technology, the problems of insufficient security in online identity verification and low efficiency in offline verification are solved, realizing convenient and secure cross-institutional identity verification, and improving user experience and business efficiency.

WO2025261218A1PCT designated stage Publication Date: 2025-12-26THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Patent Information

Application Number
PCT/CN2025/100118
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-19
Filing Date
2025-06-10
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

In existing technologies, online identity verification is not secure enough to meet the requirements of high-risk transactions, while offline identity verification is inefficient and the digital identity systems of various financial institutions are not interoperable, which requires users to repeatedly submit identity information, increasing time costs and complexity.

Method used

By using distributed identity identifiers, wallet clients can apply for identity credentials from the primary operating institution, generate and store encrypted ciphertext, and transmit identity information using the encrypted method, reducing direct information transmission and achieving cross-institutional identity verification.

Benefits of technology

It has achieved convenience and security in online identity verification, reduced the risk of identity information leakage, improved user experience and business efficiency, and avoided the process of repeatedly submitting identity information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025100118_26122025_PF_FP_ABST
    Figure CN2025100118_26122025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the embodiments of the present application are an identity credential application method and apparatus, and an electronic device and a computer-readable medium. The method comprises: a wallet client sending an identity credential application request to a first operating organization; the first operating organization acquiring a public key of the corresponding wallet client from an identity chain on the basis of a user distributed identity identifier; after signature verification for signature information of the wallet client is successful, on the basis of a private key of the first operating organization, generating an identity credential; on the basis of first identity information of a user, generating first re-encryption ciphertext; and sending the identity credential and the first re-encryption ciphertext to the wallet client.
Need to check novelty before this filing date? Find Prior Art

Description

Identity credential application method and wallet identity verification method and device thereof

[0001] The present application claims priority to the Chinese Patent Application No. 202410796420.9, filed on June 19, 2024, entitled “Identity credential application method and device”, and the Chinese Patent Application No. 202410791166.3, filed on June 19, 2024, entitled “Wallet identity verification method and device”, the contents of which are incorporated herein by reference in their entirety. TECHNICAL FIELD

[0002] The present application relates to the technical field of computer technology, in particular to an identity credential application and wallet identity verification technology. BACKGROUND

[0003] In the financial field, identity verification and customer identification (KYC) are key links to ensure transaction security and compliance.

[0004] Currently, online identity verification provides a convenient user experience, allowing users to quickly complete identity verification through websites or mobile applications. This verification method can meet the needs of daily transaction scenarios, but its security strength is limited and may not meet the requirements of higher-risk transactions. Offline identity verification, such as personally going to a bank counter for verification, usually involves identity document review and facial recognition, ensuring the security, accuracy, and strength of identity verification, but requiring users to spend additional time and resources to visit physical locations. Especially when users need to handle business at multiple financial institutions, such as upgrading their wallets at different operating institutions (banks), they must repeat the in-person verification process at each institution, which not only increases the user's time cost but also reduces the overall efficiency of services.

[0005] Moreover, digital identity systems among different departments or institutions are independent of each other, lacking unified standards and specifications, resulting in users or entities having to repeatedly submit and verify identity information in cross-scenario services, greatly reducing service efficiency and convenience. In addition, there may be significant differences in technical architecture and data format between different systems, making the sharing and interconnection of digital identity information particularly difficult, so that information cannot be effectively connected between departments or institutions. This not only increases the complexity of business handling, but also restricts the overall advancement of digital services. SUMMARY

[0006] Therefore, according to an aspect of the present application, an identity credential application method is provided, applied to a wallet client, the method comprising: sending an identity credential application request to a first operating agency, the identity credential application request comprising a user distributed identity and signature information of the wallet client, so that the first operating agency acquires a public key of the wallet client corresponding to the user distributed identity from an identity chain according to the user distributed identity, and generates an identity credential according to a private key of the first operating agency after verifying the signature information of the wallet client by using the public key of the wallet client, and generates a first re-encryption ciphertext according to first identity information of the user, the identity credential comprising an abstract value of the first identity information, a distributed identity of the first operating agency, and signature information of the first operating agency; and receiving and storing the identity credential and the first re-encryption ciphertext sent by the first operating agency.

[0007] According to another aspect of the present application, an identity credential application method is provided, applied to a first operating agency, the method comprising: receiving an identity credential application request sent by a wallet client, the identity credential application request comprising a user distributed identity and signature information of the wallet client; acquiring a public key of the wallet client corresponding to the user distributed identity from an identity chain according to the user distributed identity, and verifying the signature information of the wallet client by using the public key of the wallet client, and in response to the verification being passed, generating an identity credential according to a private key of the first operating agency, and generating a first re-encryption ciphertext according to first identity information of the user, wherein the identity credential comprises an abstract value of the first identity information, a distributed identity of the first operating agency, and signature information of the first operating agency; and sending the identity credential and the first re-encryption ciphertext to the wallet client.

[0008] According to another aspect of the present application, an identity credential application device is provided, applied to a wallet client, the device comprising: an identity credential application module configured to send an identity credential application request to a first operating agency, the identity credential application request comprising a user distributed identity and signature information of the wallet client, so that the first operating agency acquires a public key of the wallet client corresponding to the user distributed identity from an identity chain according to the user distributed identity, and generates an identity credential according to a private key of the first operating agency after verifying the signature information of the wallet client by using the public key of the wallet client, and generates a first re-encryption ciphertext according to first identity information of the user, the identity credential comprising an abstract value of the first identity information, a distributed identity of the first operating agency, and signature information of the first operating agency; and a receiving module configured to receive and store the identity credential and the first re-encryption ciphertext of the first identity information sent by the first operating agency.

[0009] According to another aspect of the embodiments of the present application, there is provided an identity credential application device, applied to a first operating agency, the device comprising: a credential application receiving module configured to receive an identity credential application request sent by a wallet client, the identity credential application request comprising a user distributed identity and signature information of the wallet client; a credential generating module configured to obtain a public key of the wallet client corresponding to the user distributed identity from an identity chain according to the user distributed identity, and to verify the signature information of the wallet client using the public key of the wallet client, and in response to the verification being passed, to generate an identity credential according to a private key of the first operating agency, and to generate a first re-encryption ciphertext according to first identity information, wherein the identity credential comprises a digest value of the first identity information, a distributed identity of the first operating agency, and signature information of the first operating agency; and a sending module configured to send the identity credential and the first re-encryption ciphertext to the wallet client.

[0010] According to another aspect of the embodiments of the present application, there is provided a wallet identity verification method, applied to a wallet client, the method comprising: obtaining a locally stored identity credential and a first re-encryption ciphertext, wherein the identity credential is generated by a first operating agency, the identity credential comprising a digest value of first identity information, a distributed identity of the first operating agency, and signature information of the first operating agency, and the first re-encryption ciphertext comprising identity information ciphertext generated by the first operating agency according to the first identity information of the user and a symmetric key, and key ciphertext generated according to the symmetric key; generating a verifiable expression according to the identity credential, wherein the verifiable expression comprises the identity credential, a credential signature generated by signing the identity credential using a private key of the wallet client, and a user distributed identity; sending the key ciphertext and a second operating agency identifier to a distributed identity system, so that the distributed identity system re-encrypts the key ciphertext to generate a re-encrypted key ciphertext, and sends the re-encrypted key ciphertext to the wallet client; updating the first re-encryption ciphertext according to the re-encrypted key ciphertext to generate a second re-encryption ciphertext, and sending the verifiable expression and the second re-encryption ciphertext to a second operating agency, so that the second operating agency verifies the verifiable expression according to the user distributed identity and the second re-encryption ciphertext to generate a credential verification result; and receiving the credential verification result sent by the second operating agency.

[0011] According to another aspect of the embodiments of the present application, a wallet identity verification method is provided, applied to a second operating institution, the method comprising: receiving a verifiable representation and a second re-encryption ciphertext sent by a wallet client, wherein the verifiable representation comprises an identity credential, a credential signature generated by signing the identity credential with a private key of the wallet client, and a user distributed identity, the identity credential comprises a digest value of first identity information, a distributed identity of the first operating institution, and signature information of the first operating institution, the second re-encryption ciphertext comprises identity information ciphertext generated by the first operating institution according to the first identity information of the user and a symmetric key, and re-encrypted key ciphertext generated by the distributed identity system according to a second operating institution identifier and the key ciphertext, the key ciphertext is generated by the first operating institution according to the symmetric key; verifying the verifiable representation according to the user distributed identity and the second re-encryption ciphertext to generate a credential verification result; and sending the credential verification result to the wallet client.

[0012] According to another aspect of the embodiments of the present application, a wallet identity verification apparatus is provided, applied to a wallet client, the apparatus comprising: a credential obtaining module configured to obtain a locally stored identity credential and a first re-encryption ciphertext, wherein the identity credential is generated by a first operating institution, the identity credential comprises a digest value of first identity information, a distributed identity of the first operating institution, and signature information of the first operating institution, the first re-encryption ciphertext comprises identity information ciphertext generated by the first operating institution according to the first identity information and a symmetric key, and key ciphertext generated according to the symmetric key; a verifiable representation generating module configured to generate a verifiable representation according to the identity credential, wherein the verifiable representation comprises the identity credential, a credential signature generated by signing the identity credential with a private key of the wallet client, and a user distributed identity; a re-encryption application module configured to send the key ciphertext and a second operating institution identifier to a distributed identity system, so that the distributed identity system re-encrypts the key ciphertext to generate re-encrypted key ciphertext, and sends the re-encrypted key ciphertext to the wallet client; a verification application module configured to update the first re-encryption ciphertext according to the re-encrypted key ciphertext to generate a second re-encryption ciphertext, and send the verifiable representation and the second re-encryption ciphertext to a second operating institution, so that the second operating institution verifies the verifiable representation according to the user distributed identity and the second re-encryption ciphertext to generate a credential verification result; and a receiving module configured to receive the credential verification result sent by the second operating institution.

[0013] According to another aspect of the embodiments of the present application, a wallet identity verification apparatus is provided, applied to a second operating institution, and the apparatus comprises: a receiving module, configured to receive a verifiable expression and a second re-encryption ciphertext sent by a wallet client, wherein the verifiable expression comprises an identity credential, a credential signature generated by signing the identity credential by using a private key of the wallet client, and a user distributed identity, the identity credential comprises an abstract value of first identity information, a distributed identity of the first operating institution, and signature information of the first operating institution, the second re-encryption ciphertext comprises identity information ciphertext generated by the first operating institution according to the first identity information of the user and a symmetric key, and re-encrypted key ciphertext generated by a distributed identity system according to the second operating institution identifier and the key ciphertext, the key ciphertext is generated by the first operating institution according to the symmetric key; a verification module, configured to verify the verifiable expression according to the user distributed identity and the second re-encryption ciphertext, and generate a credential verification result; and a sending module, configured to send the credential verification result to the wallet client.

[0014] According to another aspect of the embodiments of the present application, an electronic device is provided, comprising: one or more processors; a storage device configured to store one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method provided by the embodiments of the present application.

[0015] According to another aspect of the embodiments of the present application, a computer readable medium is provided, and the computer readable medium stores a computer program, when the computer program is executed by a processor, the method provided by the embodiments of the present application is implemented.

[0016] The embodiments of the present application have the following advantages or beneficial effects:

[0017] In the embodiments of the present application, the user can apply for an identity credential to the first operating institution through the wallet client by using the distributed identity, and the wallet client stores the identity credential and the first re-encryption ciphertext issued by the first operating institution.

[0018] In the embodiments of the present application, the abstract value of the identity information is stored in the identity credential, and the specific identity information is transmitted by using the re-encryption mode, and the abstract value in the identity credential can be verified after the re-encrypted information is decrypted, so that the identity authentication is implemented.

[0019] In the identity information encryption process in the embodiments of the present application, the identity information is encrypted by using the re-encryption mode. In the subsequent identity verification process using the identity credential, different identity verification parties can re-encrypt the key ciphertext by using the public key of the different identity verification parties, to generate different re-encrypted key ciphertexts, so as to facilitate the identity verification parties to decrypt the re-encrypted ciphertexts and obtain the specific identity information. In the re-encryption process, the distributed identity system does not contact the ciphertext of the user's identity information, thereby reducing the number of identity information ciphertext transmissions and reducing the risk of information leakage.

[0020] When the subsequent identity verification is needed in the second operation mechanism, the wallet client obtains the re-encrypted key ciphertext generated by re-encrypting the key ciphertext in the first re-encrypted ciphertext from the distributed identity system, generates a second re-encrypted ciphertext, and sends the locally stored identity credential signature as a verifiable expression to the second operation mechanism together with the second re-encrypted ciphertext. The second operation mechanism verifies the verifiable expression according to the user's distributed identity and the second re-encrypted ciphertext. After the verification is passed, the wallet client can obtain the verification approval of the second operation mechanism, and the user can perform subsequent business processes through the wallet client, for example, can perform wallet upgrade, wallet opening and other business operations.

[0021] After the user obtains the identity credential from the first operation mechanism by using the distributed identity, when performing a business in the second operation mechanism, the identity verification is realized by transmitting the locally stored identity credential, without the need to repeatedly send and upload the identity information to the second operation mechanism. The user saves the operation, the identity credential and other information are transmitted by using the encryption mode, the risk of personal information leakage is reduced, and the business security is improved.

[0022] The further effects of the above-mentioned non-conventional optional mode will be described in the following combined with the specific embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0023] The accompanying drawings are used to better understand the present application and do not constitute an improper limitation on the present application. Among them:

[0024] FIG. 1 is a schematic diagram of the architecture of a network system running the identity credential application method and the wallet identity verification method according to some embodiments of the present application;

[0025] FIG. 2 is a flowchart of the identity credential application method according to some embodiments of the present application;

[0026] FIG. 3 is a flowchart of the identity credential application method according to some embodiments of the present application;

[0027] FIG. 4 is a flowchart of the wallet identity verification method according to some embodiments of the present application;

[0028] FIG. 5 is a flow diagram of verifying a credential in wallet identity verification according to some embodiments of the present application;

[0029] FIG. 6 is a flow diagram of a wallet identity verification method according to some other embodiments of the present application;

[0030] FIG. 7 is a functional architecture diagram of an identity credential application apparatus according to some embodiments of the present application;

[0031] FIG. 8 is a functional architecture diagram of an identity credential application apparatus according to some other embodiments of the present application;

[0032] FIG. 9 is a functional architecture diagram of a wallet identity verification apparatus according to some embodiments of the present application;

[0033] FIG. 10 is a functional architecture diagram of a wallet identity verification apparatus according to some other embodiments of the present application;

[0034] FIG. 11 is an exemplary system architecture diagram to which embodiments of the present application can be applied;

[0035] FIG. 12 is a structural diagram of a computer system of a terminal device or a server suitable for use in implementing embodiments of the present application. DETAILED DESCRIPTION

[0036] Exemplary embodiments of the present application are described below with reference to the accompanying drawings, which include various details of the embodiments of the present application to assist in understanding, which should be considered in the context of the present application. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present application. Also, descriptions of well-known functions and structures are omitted from the following description for the sake of clarity and conciseness.

[0037] First, the abbreviations and related terms involved in the embodiments of the present application are defined and explained.

[0038] “DID (Decentralized Identifiers)” refers to a distributed identity, an identifier composed of a string of characters to represent a digital identity, which is generated by a distributed identity system based on information such as a public key of an applicant, and the distributed identity system also stores a DID document corresponding to the DID, which stores the DID and the public key corresponding to the DID;

[0039] A "VC (Verifiable Credential)" refers to a verifiable credential, usually a JSON string, containing VC metadata, a statement part, and a proof part. The VC metadata mainly includes the issuer, the issuance date, and the type of the statement. The statement part is one or more specific statements about the subject, for example, if the VC is an identity card, the statement part will contain the holder's name, gender, date of birth, nationality, address, and other personal information. The proof part is usually the digital signature of the issuer, used to ensure the integrity and authenticity of the VC content, prevent tampering, and verify the identity of the issuer.

[0040] A "VP (Verifiable Presentation)" is a verifiable presentation associated with a user's distributed identity, containing verifiable proof documents synthesized from one or more verifiable credentials (VCs) and digitally signed by the user.

[0041] In some specific business needs, the existing wallet identity verification often requires the user to go to the business network point for identity verification. If the user's business involves multiple banking institutions, the user needs to go to multiple banking business network points for handling. In most cases, the business network points of various banks are often far apart, and the user has difficulty in efficiently and conveniently handling the business, and needs to perform multiple repetitive operations.

[0042] Embodiments of the present application provide an online identity credential application method and a corresponding online identity verification method, which facilitate online identity verification for users and provide a convenient business handling experience for users.

[0043] Figure 1 shows a network system 100 in embodiments of the present application. The credential application method and identity verification method in embodiments of the present application can be run into the network system 100. The network system 100 includes a wallet client 110, a first operating institution system 120, a second operating institution system 130, a distributed identity system 140, an identity chain 150, and a trusted identity authentication platform 160. In some embodiments of the present application, the wallet client 110 can be used for user digital currency transactions, management, etc., for example, for digital renminbi transactions and management.

[0044] As shown in Figure 2, embodiments of the present application provide a credential application method, including the following steps:

[0045] S210: The wallet client 110 acquires the first operator identity verification result identifier. The first operator identity verification result identifier is generated by the first operator 120 after verifying the first identity information submitted by the user in the identity verification service of the first operator 120, and the first identity information is partially or entirely included in the first operator identity verification result identifier. In some embodiments of the present application, the first identity information in the first operator identity verification result identifier includes the user's identity or the user's communication number or the photocopy of the user's identity document, etc. In some embodiments of the present application, the first operator identity verification result identifier includes the user's identity or the user's communication number, and the user's passing of the identity verification service can be quickly known through the first operator identity verification result identifier.

[0046] In the embodiments of the present application, the user can submit the user's first identity information in the identity verification service, and the first identity information includes one or more of the user's identity, the photocopy of the user's identity document, and the user's real-name communication number. The user can submit the above-mentioned first identity information in the over-the-counter service, for example, the user can submit the identity information such as the identity card number, the passport number, the photocopy of the identity card or the passport, and the mobile phone number in the process of opening a digital currency wallet or upgrading the wallet in the over-the-counter scenario.

[0047] In some embodiments of the present application, the first operator 120 sends the first identity information submitted by the user in the identity verification service to the trusted identity authentication platform 160, the trusted identity authentication platform 160 performs identity verification on the first identity information, and returns the identity verification result to the first operator 120. In some embodiments of the present application, the trusted identity authentication platform 160 can perform trusted authentication on the identity information, for example, trusted authentication on the identity card number. The first operator 120 generates the first operator identity verification result identifier and returns it to the wallet client 110 when the identity verification result is passed. In the embodiments of the present application, the first operator identity verification result identifier represents that the user has passed the identity verification service. In some embodiments of the present application, the first operator 120 can also verify the first identity information by using its own ability under the condition of having specific permissions.

[0048] In some embodiments of the present application, the first operator 120 generates and displays the two-dimensional code according to the first operator identity verification result identifier, and the user obtains the first operator identity verification result identifier by scanning and parsing the two-dimensional code through the wallet client 110. In some embodiments of the present application, the first operator 120 can display the two-dimensional code to the user through the counter in the counter service, and the user scans it. In addition, the first operator 120 can also send the first operator identity verification result identifier to the wallet client 110 of the user directly through NFC.

[0049] S220: The wallet client 110 sends the first operator identity verification result identifier and the second identity information of the currently logged-in user of the wallet client to the first operator 120, the first operator 120 verifies the second identity information according to the first operator identity verification result identifier, generates an identity verification result, and returns the identity verification result to the wallet client 110. The second identity information in the embodiments of the present application can be the user's ID card number or mobile phone number, which is verified to confirm that the identity of the current operator is consistent with that of the user in the previous identity verification business, and that the user has passed the identity verification business.

[0050] S230: The wallet client 110 sends a distributed identity identifier (hereinafter referred to as "DID") application request to the distributed identity system 140 in response to the identity verification result passing of the user, the distributed identity system 140 generates a user DID and a user DID document according to the DID application request, and stores the user DID document to the identity chain 150, wherein the DID application request includes the public key of the wallet client and the user identifier, and the user DID document includes the user identifier, the user DID and the public key of the wallet client. In the embodiments of the present application, the distributed identity system 140 can be maintained and operated by a central institution, for example, can be maintained and operated by the central bank.

[0051] In some embodiments of the present application, a security component can be installed in the wallet client 110, and the wallet client 110 generates the public key and the private key of the wallet client by calling the locally installed security component in response to the identity verification result indicating that the verification is passed. In the embodiments of the present application, the security component can be a security unit SE, a trusted execution environment TEE, a secure SIM card and the like.

[0052] In some embodiments of the present application, the distributed identity system 140 generates the DID of the user through the public key of the wallet client and the user identifier. For example, the public key of the wallet client and the user identifier can be calculated by HASH algorithm to generate the DID of the user.

[0053] In an embodiment of the present application, after the distributed identity system 140 generates the DID of the user, the distributed identity system 140 also generates a DID document of the user, and the DID document includes the generated DID of the user, the user identifier, and the public key of the wallet client. Then the distributed identity system 140 transmits the DID document to the identity chain 150 for storage. Subsequently, the identity chain 150 can query the public key of the corresponding wallet client according to the DID of the user.

[0054] S240: The wallet client 110 acquires the user DID and the user DID document sent by the distributed identity system 150. The wallet client 110 stores the user distributed identity and the user distributed identity document.

[0055] S250: The wallet client 110 sends an identity credential application request to the first operating institution 120, and the identity credential application request includes the user DID and the signature information of the wallet client 110.

[0056] In some embodiments of the present application, before the wallet client 110 sends the credential request to the first operating institution 120, the wallet client 110 also sends the payment password input by the user to the first operating institution 120, the first operating institution 120 verifies the payment password, and sends the password verification result to the wallet client 110. The wallet client 110 sends the identity credential application request to the first operating institution 120 after confirming that the password verification is passed.

[0057] S260: The first operating institution 120 acquires the public key of the wallet client 110 corresponding to the user DID from the identity chain 150 according to the user distributed identity, and verifies the signature information of the wallet client by using the public key. In response to the verification passing, the first operating institution 120 generates an identity credential VC according to the private key of the first operating institution 120, generates a first re-encryption ciphertext according to the first identity information of the user, and sends the identity credential VC and the first re-encryption ciphertext to the wallet client 110. The identity credential includes the digest value of the first identity information, the DID of the first operating institution, and the signature information of the first operating institution.

[0058] In some embodiments of the present application, the first operating institution 120 signs the digest value (for example, the HASH value) of the first identity information according to the private key of the first operating institution 120 to generate the identity credential.

[0059] In some embodiments of the present application, the identity credential application request further comprises a first operator identity verification result identifier and second identity information, and before generating the identity credential according to the private key of the first operator, the first operator verifies the second identity information according to the first operator identity verification result identifier, and after verification, it is confirmed that the user currently applying for the credential has passed the verification in the identity verification business. In some embodiments of the present application, the first operator identity verification result identifier comprises part or all of the first identity information, and the identity information verification confirms that the user currently applying for the credential has passed the verification in the identity verification business.

[0060] In some embodiments of the present application, the first operator 120 generates the first re-encryption ciphertext according to the first identity information, comprising: encrypting the first identity information by using a symmetric key to generate an identity information ciphertext; and encrypting the symmetric key by using the public key of the distributed identity system to generate a key ciphertext, wherein the first re-encryption ciphertext comprises the identity information ciphertext and the key ciphertext.

[0061] In the embodiments of the present application, the symmetric key is encrypted by using the public key of the distributed identity system to generate the key ciphertext, and the subsequent distributed identity system 150 only decrypts the key ciphertext without directly decrypting the identity information ciphertext, thereby ensuring the confidentiality of the ciphertext. In the subsequent identity verification application to other operators, the wallet client 110 can send the key ciphertext to the distributed identity system 150, the distributed identity system 150 first decrypts the key ciphertext to obtain the symmetric key, and then encrypts the symmetric key by using the public key of the other operator to update the key ciphertext, generates a re-encrypted key ciphertext, and returns it to the wallet client 110. The wallet client 110 updates and generates a second re-encryption ciphertext according to the re-encrypted key ciphertext, and the wallet client 150 sends the second re-encryption ciphertext to the other operator, and the other operator can decrypt the symmetric key according to its own private key, decrypt the identity information ciphertext to obtain the first identity information for subsequent verification.

[0062] In the embodiments of the present application, the re-encryption method is adopted, which can generate the initial first re-encryption ciphertext in an uncertain other operator scenario, and then update and generate the second re-encryption ciphertext by using the public key of the other operator in the use, so that the first identity information can be decrypted and obtained by the other operator in the future in the uncertain other operator scenario. In the embodiments of the present application, only the key is re-encrypted in the re-encryption process, which reduces the transmission of the identity information ciphertext and reduces the risk of leakage.

[0063] The identity credential in the embodiment of the present application includes a digest value of the first identity information instead of the plaintext of the first identity information, ensuring that the first identity information in the credential is not disclosed, and the first identity information needs to be obtained by decrypting the second re-encryption ciphertext and compared to determine the user identity. The digest value of the first identity information can be obtained by hashing the first identity information, or can be obtained by other digest calculation methods.

[0064] In some embodiments of the present application, after generating the identity credential according to the private key of the first operating institution, the method further includes generating a credential hash value according to the identity credential, and sending the credential hash value to the identity chain for storage. In the embodiment of the present application, the first operating institution can send the credential status to the identity chain, and the identity chain can store the credential hash value as the key and the status of the credential as the value. The status of the credential can include information such as whether it is valid and the validity period. In the embodiment of the present application, the credential hash value is stored in the identity chain, and the credential hash can be obtained from the identity chain for comparison in the future to determine whether the credential exists. The status of the credential can also be obtained through the credential hash value.

[0065] The identity credential in the embodiment of the present application includes the DID of the first operating institution and the signature information of the first operating institution. In the subsequent identity credential verification process, the public key of the first operating institution can be obtained from the identity chain through the DID of the first operating institution, and the signature information of the first operating institution is verified by using the public key of the first operating institution.

[0066] S270: The wallet client 110 receives and stores the identity credential and the first re-encryption ciphertext sent by the first operating institution 120. The wallet client 110 can store the identity credential and the first re-encryption ciphertext in a secure component in the wallet client to improve security. The identity credential and the first re-encryption ciphertext are taken out from the secure component when the credential is used later.

[0067] The identity credential application method in the embodiment of the present application solves the problem that the user systems of various financial institutions are not interconnected and the users of the financial institutions are not mutually recognized. In the embodiment of the present application, the central bank end (distributed identity system) uniformly allocates unique DID identifiers to enterprise and natural person users and binds digital renminbi wallets as financial accounts while maintaining the existing financial institution user system. The financial identity DID forms a unified user identifier under the decentralized identity system, realizes unified identity authentication, and connects the financial business ecosystem to integrate various services for the financial industry with a unified user identity, and provides solid support for the digital economy. The credential applied in the embodiment of the present application can assist the user in identity verification later, avoiding the user from presenting or submitting identity information again, avoiding the repeated verification process, and improving the user experience.

[0068] The identity credential application method in the embodiments of the present application can be applied to a scenario of applying for a credential after performing temporary counter verification of an identity, as shown in FIG. 3, the embodiments of the present application provide a user identity credential application method. The specific steps are as follows:

[0069] S301: The bank counter of the first operating institution determines that the user has completed a temporary counter service and has opened a wallet of the first operating institution. After the temporary counter service is completed, the first operating institution has collected necessary identity information of the user, such as a name, a mobile phone number, an ID card number, and an ID card photocopy, and has opened a digital currency wallet of the first operating institution for the user.

[0070] S302: The bank counter requests service two-dimensional code information (including a first operating institution identity verification result identifier) from a bank back-end system of the first operating institution.

[0071] S303: The bank back-end system sends the identity information of the user to a trusted identity authentication platform for verification through a service interface of the trusted identity authentication platform.

[0072] S304: After the trusted identity authentication platform verifies the identity information of the user, the trusted identity authentication platform returns a verification result to the bank back-end system.

[0073] S305: After the bank back-end system determines that the verification is passed, the bank back-end system generates service two-dimensional code information according to the identity information of the user, and sends the service two-dimensional code information to the bank counter, and the bank counter displays the two-dimensional code.

[0074] S306: The user scans the two-dimensional code information displayed by the bank counter through a wallet client.

[0075] S307: The wallet client parses the two-dimensional code information to obtain the first operating institution identity verification result identifier in the two-dimensional code information.

[0076] S308: The wallet client submits the two-dimensional code information and the information of the currently logged-in user to the bank back-end system of the first operating institution.

[0077] S309: The bank back-end system verifies whether the identity information in the two-dimensional code information and the information of the currently logged-in user are consistent. The purpose of the verification by the bank back-end system here is to determine that the currently logged-in user is consistent with the user in the previous temporary counter service.

[0078] S310: The bank back-end system determines that the verification is consistent, returns a result of passing the verification to the wallet client, adds the opened wallet to the wallet client, and binds the wallet to an account in the wallet client.

[0079] S311: After the wallet client determines that the verifications are consistent, the wallet client sends the wallet payment password of the first operation agency to the bank back-end system for verification. After determining that the verifications are consistent, the wallet client also checks whether a secure chip (SE) is installed in the local hardware environment of the wallet client, ensures that the wallet client has the condition of opening a distributed identity, and then the wallet client completes the initialization of the SE, generates a public-private key pair, and returns the public key as the public key of the wallet client.

[0080] S312: After the bank back-end system verifies the wallet payment password, the bank back-end system returns a verification pass message to the wallet client.

[0081] S313: After the wallet client determines that the payment password verification is passed, the wallet client sends a distributed identity application request to the distributed identity system, and the request includes the user's identity, the public key of the wallet client, and the like.

[0082] S314: The distributed identity system creates a user DID and a user DID document according to the application request, wherein the user DID document includes the user DID identity and the public key of the wallet client. In the embodiments of the present application, the distributed identity system can generate the user DID according to the user's identity and the wallet client, for example, by hash calculation.

[0083] S315: The distributed identity system sends the user DID document to the identity chain for on-chain storage.

[0084] S316: The identity chain returns the on-chain result to the distributed identity system, and the on-chain result includes the on-chain address of the user DID document.

[0085] S317: The distributed identity system returns the DID opening result to the wallet client, and the opening result includes the user DID document and the user DID.

[0086] S318: The wallet client prompts the user that the DID function is successfully opened.

[0087] S319: The user clicks to create a temporary cabinet credential and inputs a payment password.

[0088] S320: The wallet client sends the payment password input by the user to the bank back-end system for verification.

[0089] S321: After the bank back-end system verifies the payment password, the bank back-end system returns the result to the wallet client.

[0090] S322: After the wallet client determines that the password verification is passed, the identity certificate application request is sent to the bank back-end system of the first operating agency to obtain the temporary counter certificate, wherein the identity certificate application request includes the two-dimensional code information, the user DID, and the signature information generated by signing the above information with the private key (the private key generated by the secure chip) of the wallet client. In some embodiments of the present application, the identity certificate application request also includes the identity information of the currently logged-in user.

[0091] S323: The bank back-end system requests the identity chain to obtain the corresponding user DID document according to the user DID.

[0092] S324: The identity chain returns the user DID document to the bank back-end system.

[0093] S325: The bank back-end system verifies the signature information in the identity certificate application request according to the wallet client public key in the user DID document, and determines that the verification is passed. In some embodiments of the present application, the bank back-end system also verifies the identity information of the currently logged-in user according to the identity information in the two-dimensional code information, and if they are consistent, the subsequent steps such as generating the certificate are continued.

[0094] S326: The bank back-end system generates the temporary counter certificate according to the necessary identity information of the user collected, and generates the first re-encryption ciphertext according to the necessary identity information of the user collected.

[0095] In some embodiments of the present application, the temporary counter certificate includes the temporary counter factoring element, the necessary identity information (name, ID number, mobile phone number) of the user, and the digest information of the photocopy. In some embodiments of the present application, the temporary counter certificate also includes the DID of the first operating agency and the private key signature information of the first operating agency.

[0096] In some embodiments of the present application, the bank back-end system can encrypt the necessary identity information of the user to generate the identity information ciphertext using the symmetric key, and encrypt the symmetric key to generate the key ciphertext using the public key of the distributed identity system. The identity information ciphertext and the key ciphertext constitute the first re-encryption ciphertext.

[0097] S327: The bank back-end system generates a certificate hash value according to the temporary counter certificate, and uploads the certificate hash value to the identity chain for storage. Subsequent other verification subjects can obtain the certificate hash value from the identity chain to verify the existence of the certificate. In some embodiments of the present application, the bank back-end system can also transmit the state of the temporary counter certificate to the identity chain, and the identity chain stores the certificate hash value as the key value and the certificate state as the value. The certificate state is obtained according to the certificate hash value. The certificate state includes whether it is valid, the valid time, and other information.

[0098] S328: The identity chain returns the storage result to the bank background system, and the storage result can include the voucher hash value storage address.

[0099] S329: The bank background system returns the temporary counter voucher and the first re-encryption ciphertext to the wallet client.

[0100] S330: The wallet client stores the temporary counter voucher and the first re-encryption ciphertext locally.

[0101] S331: The wallet client displays that the temporary counter voucher has been opened.

[0102] The identity voucher application method in the embodiment of the application opens the DID for the user after determining that the user has performed the temporary counter verification service, and the user applies for the temporary counter voucher based on the DID, so as to facilitate the user to use the temporary counter voucher for identity verification in subsequent services. Moreover, the temporary counter voucher includes the digest value of the identity information, avoiding direct inclusion of the identity information and bringing the risk of information leakage, and the information verification is performed through cooperation between the first re-encryption ciphertext and the temporary counter voucher. In the embodiment of the application, the re-encryption method is used to generate the ciphertext, and the important information can be encrypted and transmitted without determining the decryption party, and then the re-encryption processing is performed after the decryption party is determined, so that the decryption party can decrypt, and the ciphertext is generated conveniently and flexibly.

[0103] In the embodiment of the application, according to the foregoing network system 100, as shown in FIG. 4, an identity verification method is further provided, including the following steps:

[0104] S410: The wallet client 110 obtains the locally stored identity voucher and the first re-encryption ciphertext, wherein the identity voucher is generated by the first operating institution, the identity voucher includes the digest value of the first identity information, the distributed identity of the first operating institution, and the signature information of the first operating institution, the first re-encryption ciphertext includes the identity information ciphertext generated by the first operating institution according to the first identity information of the user and the symmetric key, and the key ciphertext generated according to the symmetric key. The process of generating the identity voucher and the first re-encryption ciphertext by the first operating institution in the embodiment of the application can refer to the identity voucher application method in the embodiment of the application.

[0105] In the embodiment of the application, before the wallet client obtains the local identity voucher and the first re-encryption ciphertext, the wallet client 110 obtains the payment password input by the user and sends it to the second operating institution 130, the second operating institution 130 verifies the payment password, and returns the result to the wallet client 110 after verification. Through the verification of the payment password, the legality of the user operation is confirmed.

[0106] In some embodiments of the present application, before obtaining the identity credential and the first re-encryption ciphertext, the wallet client 110 further obtains a user DID document and a first identity of a local security component from the local, wherein the user DID document includes a user identity, a user DID, a public key of the wallet client, and a second identity of a security component generating the public key of the wallet client; and the first identity is verified according to the second identity. By verifying the first identity according to the second identity, it is checked whether the security component in the current device is the security component used by the user to apply for the DID before, and if not, the verification fails.

[0107] S420: The wallet client 110 generates a verifiable presentation (hereinafter referred to as VP) according to the identity credential, wherein the VP includes the identity credential VC, a credential signature generated by signing the identity credential VC using a private key of the wallet client, and a user DID. In the embodiments of the present application, the wallet client 110 signs the identity credential using the private key in the wallet client to generate the credential signature, and subsequently verifies the credential signature to confirm that the VP is determined from the wallet client 110.

[0108] S430: The wallet client 110 sends the key ciphertext and the second operating agency identity to the distributed identity system 140.

[0109] S440: The distributed identity system 140 re-encrypts the key ciphertext to generate a re-encrypted key ciphertext, and sends the re-encrypted key ciphertext to the wallet client 110.

[0110] In the embodiments of the present application, the first re-encryption ciphertext includes identity information ciphertext generated by encrypting the first identity information using a symmetric key and key ciphertext generated by encrypting the symmetric key using a public key of the distributed identity system; the distributed identity system decrypts the key ciphertext using a private key of itself to obtain the symmetric key, and encrypts the symmetric key using a public key of the second operating agency to update the key ciphertext.

[0111] S450: The wallet client 110 replaces the key ciphertext in the first re-encryption ciphertext with the re-encrypted key ciphertext to generate a second re-encryption ciphertext, and sends the verifiable presentation and the second re-encryption ciphertext to the second operating agency 130.

[0112] S460: The second operating agency 130 verifies the VP according to the user DID and the second re-encryption ciphertext to generate a credential verification result.

[0113] As shown in FIG. 5, the verification step performed by the second operating agency 130 in the embodiments of the present application can include the following:

[0114] S461: The second operating agency 130 sends the user DID to the identity chain 150, and the identity chain 150 acquires the public key of the wallet client according to the user DID and sends the public key of the wallet client to the second operating agency 130;

[0115] S462: The second operating agency 130 verifies the credential signature according to the public key of the wallet client, and after the verification is passed, acquires the identity credential;

[0116] S463: The second operating agency 130 sends the DID of the first operating agency to the identity chain 150, and the identity chain 150 acquires the public key of the first operating agency according to the DID of the first operating agency.

[0117] S464: The second operating agency 130 verifies the signature information of the first operating agency according to the public key of the first operating agency, and after the verification is passed, decrypts the second re-encryption ciphertext by using the private key of the second operating agency to acquire the first identity information. Specifically, in the embodiments of the present application, the second operating agency first decrypts the re-encrypted key ciphertext according to the private key of the second operating agency to acquire the symmetric key, and then decrypts the identity information ciphertext by using the symmetric key to acquire the first identity information.

[0118] S465: The second operating agency 130 calculates the digest value of the first identity information, acquires the calculation digest value, and verifies the digest value of the first identity information in the identity credential according to the calculation digest value.

[0119] In some embodiments of the present application, the existence of the credential is also verified, and the step of the second operating agency performing the credential verification can further include:

[0120] S466: The second operating agency 130 generates an identity credential hash value according to the identity credential;

[0121] S467: The second operating agency 130 sends the identity credential hash value to the identity chain 150, and the identity chain 150 acquires the identity credential state according to the identity credential hash value and returns the identity credential state to the second operating agency;

[0122] S468: The second operating agency 130 receives the identity credential state sent by the identity chain and verifies the existence of the identity credential according to the identity credential state.

[0123] In the embodiments of the present application, by performing multiple verifications, the safety and reliability of the verification information can be ensured. Specifically, the existence proof of the identity credential, the legality of the issuing party and the user identity, the integrity (digest comparison) of the attachment, etc. are verified first, and then the correctness of the credential is verified, so that the business elements can be better ensured to meet the expectations.

[0124] S470: The wallet client 110 receives the credential verification result sent by the second operating agency 130.

[0125] In some embodiments of the present application, after identity verification, business operations can also be carried out, for example, wallet level upgrade can be carried out, in some embodiments of the present application, the method in the embodiments of the present application further comprises:

[0126] S480: When the verification result of the credential indicates that the verification is passed, the wallet client 110 sends a wallet upgrade request to the second operating institution 130, and the second operating institution 130 upgrades the wallet level. For example, the wallet level is upgraded to level two or level one. In some embodiments of the present application, the wallet upgrade request further includes the bank card number of the user to be verified, and the second operating institution binds the bank card and the digital currency wallet after verifying the bank card number, and upgrades the registration of the digital currency wallet.

[0127] The identity verification method in the embodiments of the present application does not require the user to submit identity information to the second operating institution again, and the wallet client only needs to generate a VP by signing the identity credential stored this time, and send the VP and the locally stored first encryption ciphertext to the second operating institution for verification, to achieve the purpose of identity verification. In this way, the pressure on the user to upload identity information again is reduced, and the user's use experience is improved.

[0128] In some embodiments of the present application, based on the above identity credential application method, the above identity verification method can also be applied to wallet upgrade business, for example, the wallet level is upgraded from a four-class wallet to a two-class wallet. As shown in FIG. 6, the embodiments of the present application provide a method for upgrading a wallet after identity verification, comprising the following steps:

[0129] S501: The user operates the wallet client 110 to request to upgrade the wallet to be upgraded.

[0130] S502: The wallet client 110 obtains the payment password of the wallet to be upgraded from the user, and sends the payment password to the second operating institution 130.

[0131] S503: The second operating institution 130 verifies the payment password and returns the verification result to the wallet client 110.

[0132] S504: After the wallet client 110 determines that the payment password verification is passed, the local stored user DID document is obtained, the identifier of the security component is taken out, and the identifier of the local security component is obtained from the local security component. Compare the two identifiers to determine that the current local security component is the security component used before applying for the user DID.

[0133] S505: The wallet client 110 obtains the identity credential and the first re-encryption ciphertext from the local, calls the security component, signs the identity credential by using the private key of the wallet client, and generates a VP.

[0134] In an embodiment of the present application, the VP includes the identity credential, the credential signature generated by signing the identity credential by using the private key of the wallet client, and the DID of the user. The identity credential is generated by the first operating institution, the first re-encryption ciphertext includes the identity information ciphertext generated by the first operating institution according to the first identity information of the user and the symmetric key and the key ciphertext generated according to the symmetric key, and the identity credential includes the digest value of the first identity information, the distributed identity of the first operating institution, and the signature information of the first operating institution.

[0135] S506: The wallet client 110 sends the identity of the second operating institution 130 and the key ciphertext to the distributed identity system 140.

[0136] S507: The distributed identity system 140 decrypts the key ciphertext by using the private key thereof to obtain the symmetric key. The distributed identity system 140 obtains the public key of the second operating institution according to the identity of the second operating institution, encrypts the symmetric key by using the public key of the second operating institution, updates the key ciphertext, and generates the re-encrypted key ciphertext. In some embodiments of the present application, the distributed identity system 140 can call the cryptographic service platform to perform the re-encryption processing and generate the second re-encryption ciphertext. In an embodiment of the present application, the distributed identity system 140 pre-stores the public keys of various operating institutions and can obtain the corresponding public key according to the identity of the operating institution. In an embodiment of the present application, the distributed identity system 140 does not contact the ciphertext of the identity information in the re-encryption process, reduces the number of transmission times of the ciphertext of the identity information, and reduces the risk of leakage.

[0137] S508: The distributed identity system 140 sends the re-encrypted key ciphertext to the wallet client 110.

[0138] S509: The wallet client 110 updates the second re-encryption ciphertext according to the re-encrypted key ciphertext, sends the verifiable representation and the second re-encryption ciphertext to the second operating institution 130.

[0139] S510: The second operating institution 130 requests the existence proof of the credential and the distributed identity document of the user and the first operating institution from the identity chain 150. The second operating institution 130 calculates the hash value of the identity credential, sends the hash value to the identity chain 150, and the identity chain 150 returns the read credential state as the existence proof.

[0140] S511: The identity chain 150 returns the existence proof of the credential and the DID document of the user and the first operating institution.

[0141] S512: The second operation agency 130 obtains the public key of the wallet client and the public key of the first operation agency according to the DID document of the user and the first operation agency, and verifies the VP by using the public key of the wallet client and the public key of the first operation agency. When verifying, the signature of the user is verified first to determine that the VP is signed by the user, and then the identity certificate is verified by using the public key of the first operation agency to verify that the identity certificate is issued by the first operation agency.

[0142] S513: The second operation agency 130 decrypts the second re-encryption ciphertext by using the public key of the second operation agency, obtains the first identity information, and calculates the digest value of the first identity information. The calculated digest value is compared with the digest value in the identity certificate, and if the comparison is consistent, it is verified that the content of the certificate is consistent with the expectation. The second operation agency 130 decrypts the key ciphertext by using the public key to obtain the symmetric key, and decrypts the identity information ciphertext by using the symmetric key to obtain the first identity information.

[0143] S514: The second operation agency 130 returns the certificate verification result to the wallet client 110.

[0144] S515: The wallet client 110 sends a wallet upgrade request to the second operation agency 130 after determining that the certificate verification is passed. In some embodiments of the present application, the upgrade request can also include information such as a bank card that needs to be bound.

[0145] S516: The second operation agency 130 upgrades the wallet according to the application request, for example, upgrades the wallet from a four-class wallet to a two-class wallet.

[0146] S517: The second operation agency 130 returns the wallet upgrade request to the wallet client 110.

[0147] S518: The wallet client shows the user the upgrade result.

[0148] The wallet level upgrade method in the embodiments of the present application can realize fast identity verification in business handling by calling the locally stored identity certificate and the first re-encryption ciphertext without the user inputting the identity information again, and can also improve the user experience while breaking through the user information mutual recognition between independent agencies. In the identity information storage and transmission process, a reliable encryption method is used to avoid information leakage. The second operation agency performs multiple verifications in the identity verification process to improve the credibility of identity verification.

[0149] In the embodiments of the present application, identity information transmission and storage is implemented by using re-encryption technology. The identity credential issuing agency (for example, the first operation agency mentioned above) encrypts the key information using the public key of the central bank end (for example, the distributed identity system mentioned above), and sends the encrypted data to the client. When the client is used in other agencies, the central bank end is called to re-encrypt the encryption key, and then the re-encrypted encryption key and the encrypted data are sent to the target agency (for example, the second operation agency mentioned above). It is ensured that the central bank end does not process sensitive information such as user real name information, and the wallet client cannot decrypt the sensitive information saved locally. At the same time, the credential issuing agency end does not send sensitive information to other agencies, but only sends sensitive information to the user himself.

[0150] The identity credential application method and the identity verification method in the embodiments of the present application have the following advantages:

[0151] Advantage one: double-layer identity mode

[0152] The identity authentication in the financial field has the highest strength, and the bank is particularly strict in verifying the identity of the user. However, the user systems of various financial institutions are not interconnected, and it is always difficult to form an interconnected user ecosystem, and different financial institutions are fighting separately. The embodiments of the present application provide a financial identity DID, which adopts a double-layer identity mode, and uniformly allocates a unique DID identifier to enterprise and natural person users by the central bank end under the existing user system of the financial institution, and binds a digital renminbi wallet as a financial account. The financial identity DID forms a unified user identifier in a decentralized identity system, realizes unified identity authentication, and breaks through the financial business ecosystem to connect various services for the financial industry with a unified user identity, and provides a solid support for the digital economy.

[0153] Advantage two: secondary credential mode

[0154] An important problem in DID ecological construction is how to include unverifiable credentials (Unverifiable Confidential, UVC) into the DID system. UVC comes from the non-DID world, such as systems that do not support DID, overseas credentials, paper documents, etc. The compatibility of UVC determines the business scope of DID application. The financial identity DID cleverly solves this problem through the secondary credential mode. Under the witness of the trusted agency (for example, the trusted authentication platform mentioned above), the credential issuing agency verifies the UVC, so as to issue the verification result as a VC, and convert the UVC into a VC that can be used in the DID system. In this mode, the trusted agency only endorses the verification result witnessed by it, and the credential issuing agency endorses the credential itself, which constitutes a complete legal chain.

[0155] Advantage three: re-encryption mode based on domestic cryptography

[0156] The legal digital currency system strictly complies with data security laws and regulations and design principles. In the design of the financial identity DID, the central bank end does not process user real-name information and other sensitive information, and the client end cannot decrypt and save the sensitive information stored locally. At the same time, the institution end will not send sensitive information to other institutions, but only send sensitive information to the user himself. Under this design constraint, the financial identity DID uses an encrypted key and encrypted data separated digital envelope encryption mode. The certificate issuing agency (such as the first operating agency mentioned above) uses the central bank end public key to encrypt the sensitive information, and sends the encrypted data to the client end. When the client end is used by other agencies, the central bank re-encrypts the encryption key, and then sends the re-encrypted encryption key and the encrypted data to the target agency.

[0157] As shown in FIG. 7, the embodiments of the present application provide an identity credential application device 600 applied to a wallet client, the device 600 comprises an identity credential application module 610 and a receiving module 620, wherein,

[0158] The identity credential application module 610 is configured to send an identity credential application request to the first operating agency, the identity credential application request comprising a user distributed identity and signature information of the wallet client, so that the first operating agency acquires the public key of the wallet client corresponding to the user distributed identity from the identity chain according to the user distributed identity, and generates an identity credential according to the private key of the first operating agency after verifying and passing the signature information of the wallet client by using the public key of the wallet client, generates a first re-encryption ciphertext of the first identity information of the user, and sends the identity credential and the first re-encryption ciphertext of the first identity information to the wallet client, the identity credential comprising an abstract value of the first identity information, a distributed identity of the first operating agency, and signature information of the first operating agency;

[0159] The receiving module 620 is configured to receive and store the identity credential and the first re-encryption ciphertext of the first identity information sent by the first operating agency.

[0160] In some embodiments of the present application, the device 600 further comprises a distributed identity application module 630, the distributed identity application module 630 is configured to, in response to the identity verification result of the user being passed, send a distributed identity application request to the distributed identity system, so that the distributed identity system generates a user distributed identity and a user distributed identity document according to the distributed identity application request, and stores the user distributed identity document to the identity chain, wherein the distributed identity application request comprises a public key of the wallet client and a user identifier, and the user distributed identity document comprises the user identifier, the user distributed identity, and the public key of the wallet client; and acquire the user distributed identity and the user distributed identity document sent by the distributed identity system.

[0161] In some embodiments of the present application, the apparatus 600 further comprises an identity verification result obtaining module 640, configured to obtain a first operator identity verification result identifier, the first operator identity verification result identifier being generated by the first operator after verifying the first identity information submitted by the user in the identity verification service of the first operator, and the first operator identity verification result identifier comprising part or all of the first identity information; and send the first operator identity verification result identifier and the second identity information of the currently logged-in user of the wallet client to the first operator, so that the first operator verifies the second identity information according to the first operator identity verification result identifier, generates an identity verification result, and returns the identity verification result to the wallet client.

[0162] In some embodiments of the present application, the apparatus 600 further comprises a key generation module 650, configured to, in response to the identity verification result indicating that the verification is passed, the wallet client calling a locally installed security component to generate a public key and a private key of the wallet client.

[0163] In some embodiments of the present application, the apparatus 600 further comprises a payment password verification module 660, configured to send the payment password input by the user to the first operator, so that the first operator verifies the payment password.

[0164] In some embodiments of the present application, the identity verification result obtaining module 640 is further configured to scan a two-dimensional code generated by the first operator, and parse the two-dimensional code to obtain the first operator identity verification result identifier.

[0165] In some embodiments of the present application, the identity credential application request further comprises the first operator identity verification result identifier and the second identity information, so that the first operator further verifies the second identity information according to the first operator identity verification result identifier before generating the identity credential.

[0166] In some embodiments of the present application, the first identity information comprises one or more of a user identity identifier, a user identity certificate photocopy file, and a user real-name communication number.

[0167] As shown in FIG. 8, the embodiments of the present application further provide an identity credential application apparatus 700 applied to a first operator, the apparatus 700 comprising a credential application receiving module 710, a credential generation module 720, and a sending module 730.

[0168] The credential application receiving module 710 is configured to receive an identity credential application request sent by a wallet client, the identity credential application request comprising a user distributed identity identifier and signature information of the wallet client.

[0169] The credential generation module 720 is configured to obtain, from the identity chain, a public key of the wallet client corresponding to the distributed identity of the user according to the distributed identity of the user, and generate an identity credential according to the private key of the first operation institution after verifying the signature information of the wallet client by using the public key of the wallet client, and generate a first re-encryption ciphertext according to the first identity information, wherein the identity credential comprises an abstract value of the first identity information, the distributed identity of the first operation institution, and the signature information of the first operation institution.

[0170] The sending module 730 is configured to send the identity credential and the first re-encryption ciphertext to the wallet client.

[0171] In some embodiments of the present application, the apparatus 700 further comprises a result identity generation module 740 configured to generate a first operation institution identity verification result identity in response to a result of verifying the first identity information submitted by the user in the identity verification service of the first operation institution, so that the wallet client obtains the first operation institution identity verification result identity, and the first operation institution identity verification result identity comprises the first identity information; receive the first operation institution identity verification result identity and second identity information of the currently logged-in user of the wallet client sent by the wallet client, and generate an identity verification result after verifying the second identity information according to the first operation institution identity verification result identity, and send the identity verification result to the wallet client, so that the wallet client applies for the distributed identity of the user and the distributed identity document of the user from the distributed identity system, and obtains the distributed identity of the user and the distributed identity document of the user from the distributed identity system, wherein the distributed identity document is also sent to the identity chain for storage by the distributed identity system, and the distributed identity document comprises the distributed identity of the user and the public key of the wallet client.

[0172] In some embodiments of the present application, the identity credential application request further comprises the first operation institution identity verification result identity and the second identity information, and the apparatus 700 further comprises an identity information verification module configured to verify the second identity information according to the first operation institution identity verification result identity before generating the identity credential according to the private key of the first operation institution.

[0173] In some embodiments of the present application, the apparatus 700 further comprises a payment password verification module 750 configured to receive the payment password input by the user sent by the wallet client before receiving the identity credential application request sent by the wallet client, verify the payment password, and send the password verification result to the wallet client.

[0174] In some embodiments of the present application, the apparatus 700 further comprises a credential hash generation module 760 configured to generate a credential hash value according to the identity credential after generating the identity credential according to the private key of the first operation institution, and send the credential hash value to the identity chain for storage.

[0175] In some embodiments of the present application, the apparatus 700 further comprises a trusted identity authentication module 770 configured to send the first identity information to the trusted identity authentication platform to enable the trusted identity authentication platform to perform identity verification according to the first identity information and return an identity verification result to the first operating agency, in response to the first identity information submitted by the user in the identity verification service of the first operating agency passing the verification.

[0176] In some embodiments of the present application, the credential generation module 720 is further configured to:

[0177] encrypt the first identity information using the symmetric key to generate identity information ciphertext;

[0178] encrypt the symmetric key using the public key of the distributed identity system to generate key ciphertext, wherein the first re-encryption ciphertext comprises the identity information ciphertext and the key ciphertext.

[0179] As shown in FIG. 9, the embodiments of the present application further provide a wallet identity verification apparatus 800 applied to a wallet client, the apparatus 800 comprising a credential acquisition module 810, a verifiable expression generation module 820, a re-encryption application module 830, a verification application module 840 and a receiving module 850.

[0180] The credential acquisition module 810 is configured to acquire a locally stored identity credential and a first re-encryption ciphertext, wherein the identity credential is generated by the first operating agency, the first re-encryption ciphertext comprises symmetric key ciphertext generated by the first operating agency according to the first identity information of the user and the symmetric key and key ciphertext generated according to the symmetric key, and the identity credential comprises a digest value of the first identity information, a distributed identity of the first operating agency and signature information of the first operating agency.

[0181] The verifiable expression generation module 820 is configured to generate a verifiable expression according to the identity credential, wherein the verifiable expression comprises the identity credential, a credential signature generated by signing the identity credential using the private key of the wallet client and a distributed identity of the user.

[0182] The re-encryption application module 830 is configured to send the key ciphertext and a second operating agency identifier to the distributed identity system to enable the distributed identity system to re-encrypt the key ciphertext to generate re-encrypted key ciphertext and send the re-encrypted key ciphertext to the wallet client.

[0183] The verification application module 840 is configured to update the first re-encryption ciphertext according to the re-encrypted key ciphertext to generate second re-encryption ciphertext, and send the verifiable expression and the second re-encryption ciphertext to the second operating agency to enable the second operating agency to verify the verifiable expression according to the distributed identity of the wallet client and the second re-encryption ciphertext to generate a credential verification result.

[0184] The receiving module 850 is configured to receive the credential verification result sent by the second operating institution.

[0185] In some embodiments of the present application, the apparatus 800 further comprises a wallet level upgrade request module 860 configured to send a wallet level upgrade request to the second operating institution to make the second operating institution upgrade the wallet level when the credential verification result indicates that the verification is passed.

[0186] In some embodiments of the present application, the identity information ciphertext is generated by encrypting the first identity information with a symmetric key, and the key ciphertext is generated by encrypting the symmetric key with a public key of the distributed identity system; the re-encrypted key ciphertext is generated by the distributed identity system according to the following steps:

[0187] The re-encrypted key ciphertext is generated by the distributed identity system according to the following steps:

[0188] In some embodiments of the present application, the apparatus 800 comprises a payment password verification module 870 configured to obtain a payment password input by the user before obtaining the locally stored identity credential and the first re-encrypted ciphertext, and send the payment password to the second operating institution to make the second operating institution verify the payment password.

[0189] In some embodiments of the present application, the apparatus 800 further comprises a security component verification module 880 configured to obtain a user distributed identity identification document and a first identification of a local security component from the local before obtaining the locally stored identity credential and the first re-encrypted ciphertext, wherein the user distributed identity identification document comprises a user identification, a user distributed identity identification, a public key of the wallet client, and a second identification of a security component generating the public key of the wallet client; and verify the first identification and the second identification.

[0190] As shown in FIG. 10, the embodiments of the present application further provide a wallet identity verification apparatus 900 applied to the second operating institution, wherein the apparatus 900 comprises a receiving module 910, a verification module 920, and a sending module 930.

[0191] The receiving module 910 is configured to receive the verifiable representation and the second re-encryption ciphertext sent by the wallet client, where the verifiable representation includes an identity credential, a credential signature generated by signing the identity credential with a private key of the wallet client, and a user distributed identity, the identity credential includes an abstract value of first identity information, a distributed identity of the first operating institution, and signature information of the first operating institution, the second re-encryption ciphertext includes identity information ciphertext generated by the first operating institution according to the first identity information of the user and a symmetric key, and re-encrypted key ciphertext generated by re-encrypting the key ciphertext according to the second operating institution identifier by the distributed identity system, the key ciphertext is generated by the first operating institution according to the symmetric key.

[0192] The verification module 920 is configured to verify the verifiable representation according to the user distributed identity and the second re-encryption ciphertext, and generate a credential verification result.

[0193] The sending module 930 is configured to send the credential verification result to the wallet client.

[0194] In some embodiments of the present application, the apparatus 900 further includes a wallet upgrade module 940 configured to receive a wallet upgrade request sent by the wallet client after determining that the credential verification result indicates that the verification is passed, and upgrade the wallet level according to the wallet upgrade request.

[0195] In some embodiments of the present application, the verification module 920 is specifically configured to:

[0196] send the user distributed identity to the identity chain, so that the identity chain obtains the public key of the wallet client according to the user distributed identity, and sends the public key of the wallet client to the second operating institution;

[0197] verify the credential signature according to the public key of the wallet client, and after the verification is passed, obtain the identity credential;

[0198] send the distributed identity of the first operating institution to the identity chain, so that the identity chain obtains the public key of the first operating institution according to the distributed identity of the first operating institution;

[0199] verify the signature information of the first operating institution according to the public key of the first operating institution, and after the verification is passed, decrypt the second re-encryption ciphertext by using the private key of the second operating institution, and obtain the first identity information;

[0200] calculate the abstract value of the first identity information, obtain the calculation abstract value, and verify the abstract value of the first identity information in the identity credential according to the calculation abstract value.

[0201] In some embodiments of the present application, the verification module 920 is further specifically configured to:

[0202] generate an identity credential hash value according to the identity credential;

[0203] sending the identity credential hash value to the identity chain, so that the identity chain acquires an identity credential state according to the identity credential hash value, and returns the identity credential state to the second operation agency;

[0204] receiving the identity credential state sent by the identity chain, and performing existence verification on the identity credential according to the identity credential state.

[0205] In some embodiments of the present application, the verification module 920 is further specifically configured to:

[0206] decrypting the re-encrypted key ciphertext according to the private key of the second operation agency, to obtain the symmetric key;

[0207] decrypting the identity information ciphertext by using the symmetric key, to obtain the first identity information.

[0208] In some embodiments of the present application, the apparatus 900 further comprises a payment password verification module 950, configured to receive the payment password sent by the wallet client, verify the payment password, and return the password verification result to the wallet client.

[0209] The apparatus features of the embodiments of the present application can refer to the method, step and other features of the embodiments of the present application, and the system embodiments can obtain new embodiments in combination with the features of the method embodiments, and vice versa, which will not be described herein again.

[0210] In the embodiments of the present application, an electronic device is provided, which comprises a processor and a memory storing a computer program, the processor being configured to implement the identity credential application and wallet identity verification method according to any of the embodiments of the present application when running the computer program. In addition, an apparatus for implementing the identity credential application and wallet identity verification according to the embodiments of the present application can also be provided.

[0211] FIG. 11 shows an exemplary system architecture 1100 to which the identity credential application and wallet identity verification method or identity credential application and wallet identity verification apparatus of the embodiments of the present application can be applied.

[0212] As shown in FIG. 11, the system architecture 1100 can include terminal devices 1101, 1102, 1103, a network 1104 and a server 1105. The network 1104 is a medium for providing a communication link between the terminal devices 1101, 1102, 1103 and the server 1105. The network 1104 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0213] The user can use the terminal devices 1101, 1102, and 1103 to interact with the server 1105 through the network 1104 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 1101, 1102, and 1103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0214] The terminal devices 1101, 1102, and 1103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, etc.

[0215] The server 1105 can be a server providing various services, such as a background management server supporting a shopping website browsed by the user using the terminal devices 1101, 1102, and 1103 (only as an example). The background management server can analyze and process received product information query requests, etc., and feed back the processing results (such as target push information, product information--only as examples) to the terminal devices.

[0216] It should be noted that the identity credential application and wallet identity verification method provided by the embodiments of the present application are generally executed by the server 1105, and accordingly, the identity credential application and wallet identity verification implementation device is generally provided in the server 1105.

[0217] It should be understood that the number of terminal devices, networks, and servers in FIG. 11 is merely illustrative. According to the needs of implementation, there can be any number of terminal devices, networks, and servers.

[0218] Reference is made below to FIG. 12, which shows a structural schematic diagram of a computer system 1200 suitable for implementing the terminal device or server of the embodiments of the present application. The methods in the embodiments of the present application or the devices implementing the methods can be implemented on the computer system 1200. The terminal device or server shown in FIG. 12 is merely an example and should not bring any limitation to the functions and use range of the embodiments of the present application.

[0219] As shown in FIG. 12, the computer system 1200 includes a central processing unit (CPU) 1201, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1202 or loaded from a storage portion 1208 to a random access memory (RAM) 1203. Various programs and data required for the operation of the system 1200 are also stored in the RAM 1203. The CPU 1201, the ROM 1202, and the RAM 1203 are connected to each other through a bus 1204. An input / output (I / O) interface 1205 is also connected to the bus 1204.

[0220] The following components are connected to the I / O interface 1205: an input part 1206 including a keyboard, a mouse, etc.; an output part 1207 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage part 1208 including a hard disk, etc.; and a communication part 1209 including a network interface card such as a LAN card, a modem, etc. The communication part 1209 performs communication processing via a network such as the Internet. A drive 1210 is also connected to the I / O interface 1205 as necessary. A removable media 1211 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 1210 as necessary, so that a computer program read out therefrom is installed in the storage part 1208 as necessary.

[0221] In particular, according to the embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, the embodiments of the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program codes for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network by the communication part 1209, and / or installed from the removable media 1211. When the computer program is executed by the central processing unit (CPU) 1201, the above-described functions defined in the system of the present application are executed.

[0222] It should be noted that computer-readable media in this disclosure can be computer-readable storage media, or computer-readable signal media, or any combination thereof. Computer-readable storage media can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specific examples of computer-readable storage media can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this disclosure, computer-readable storage media can be any tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a computer-readable storage medium, or any computer-readable medium that can transmit or propagate code in the form of computer-readable instructions or program code, or any combination of the above. The computer-readable medium can be transmitted in baseband or as part of a carrier wave over a transmission medium, including a wired medium, or a wireless medium, or any suitable combination of the above. Computer-readable media can also be any medium that can be used to store or transfer a program for use by or in connection with an instruction execution system, apparatus, or device.

[0223] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functional processes, and operations that can be implemented in systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code that comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the block can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flow diagrams, and combinations thereof, can be implemented by special purpose hardware-based systems that perform the specified functions or operations, or combinations of special purpose hardware and computer instructions.

[0224] The units or modules described in the embodiments of the present application can be implemented by software or hardware. The described units or modules can also be arranged in a processor, for example, a processor can be described as including a sending unit (or "module"), an obtaining unit, a determining unit and a first processing unit. In some cases, the names of the units or modules do not constitute a limitation on the units or modules themselves, for example, the sending unit can also be described as "a unit for sending a picture obtaining request to a connected server".

[0225] As another aspect, the present application also provides a computer readable medium, which can be included in the device described in the above embodiments, or can exist independently without being assembled into the device. The computer readable medium carries one or more programs, which, when executed by the device, enable the device to perform the identity credential application and wallet identity verification method described in the above embodiments.

[0226] The specific embodiments described above do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made depending on design requirements and other factors. Any modification, equivalent replacement and improvement made within the principles of the present application should be included in the protection scope of the present application.

Claims

1. A method for applying for identity credentials, applied to a wallet client, the method comprising: An identity credential request is sent to the first operating institution. The identity credential request includes a user's distributed identity identifier and the signature information of the wallet client. This enables the first operating institution to obtain the public key of the wallet client corresponding to the user's distributed identity identifier from the identity chain. After verifying the signature information of the wallet client using the public key of the wallet client, the first operating institution generates an identity credential based on its private key and generates a first encrypted ciphertext based on the user's first identity information. The identity credential includes a digest value of the first identity information, the distributed identity identifier of the first operating institution, and the signature information of the first operating institution. Receive and store the identity credential and the first encrypted ciphertext sent by the first operating institution.

2. The method according to claim 1, wherein, Before sending the identity credential application request to the first operating institution, the method further includes: In response to the successful identity verification of the user, a distributed identity identifier request is sent to the distributed identity system. The distributed identity system then generates the user's distributed identity identifier and user distributed identity document based on the request, and stores the user's distributed identity document in the identity chain. The distributed identity identifier request includes the wallet client's public key and the user identifier, and the user distributed identity document includes the user identifier, the user's distributed identity identifier, and the wallet client's public key. Obtain the user distributed identity identifier and the user distributed identity document sent by the distributed identity system.

3. The method according to claim 2, wherein, Before sending the distributed identity request to the distributed identity system, the method further includes: Obtain the identity verification result identifier of the first operating institution. The first operating institution identity verification result identifier is generated by the first operating institution after verifying the first identity information submitted by the user in the identity verification business of the first operating institution. The first operating institution identity verification result identifier includes part or all of the first identity information. The first operator sends the identity verification result identifier of the first operator and the second identity information of the currently logged-in user of the wallet client to the first operator, so that the first operator verifies the second identity information according to the identity verification result identifier of the first operator, generates the identity verification result, and returns the identity verification result to the wallet client.

4. The method according to claim 2 or 3, wherein, The method further includes: In response to the identity verification result indicating that the verification is successful, the wallet client calls the locally installed security component to generate the wallet client's public and private keys.

5. The method according to any one of claims 1-3, wherein, Before sending the identity credential application request to the first operating institution, the method further includes: Send the user's input payment password to the first operating institution; and Receive the verification result of the payment password from the first operating institution.

6. The method according to claim 3, wherein, The step of obtaining the identity verification result identifier of the first operating institution includes: Scan the QR code generated by the first operator and parse the QR code to obtain the identity verification result identifier of the first operator.

7. The method according to claim 3 or 6, wherein, The identity credential application request also includes the first operator's identity verification result identifier and the second identity information, so that the first operator verifies the second identity information based on the first operator's identity verification result identifier before generating the identity credential.

8. The method according to any one of claims 1-3, wherein, The first identity information includes one or more of the following: user identity identifier, photocopy of user identity certificate, and user real-name communication number.

9. A method for applying for an identity credential, applied to a first operating institution, the method comprising: Receive an identity credential request sent by a wallet client, the identity credential request including the user's distributed identity identifier and the wallet client's signature information; The public key of the wallet client corresponding to the user's distributed identity is obtained from the identity chain based on the user's distributed identity. The signature information of the wallet client is verified using the public key of the wallet client. In response to the successful verification, an identity credential is generated based on the private key of the first operating institution, and a first encrypted ciphertext is generated based on the user's first identity information. The identity credential includes the digest value of the first identity information, the distributed identity of the first operating institution, and the signature information of the first operating institution. The identity credential and the first encrypted ciphertext are sent to the wallet client.

10. The method according to claim 9, wherein, Before receiving the identity credential request sent by the wallet client, the method further includes: In response to the user's successful verification of the first identity information submitted in the first operator's identity verification service, a first operator's identity verification result identifier is generated so that the wallet client can obtain the first operator's identity verification result identifier, which includes part or all of the first identity information; The system receives the first operator authentication result identifier and the second identity information of the currently logged-in user of the wallet client from the wallet client. It verifies the second identity information according to the first operator authentication result identifier. In response to the successful verification of the second identity information, it generates an identity verification result and sends the identity verification result to the wallet client, so that the wallet client can apply for and obtain the user distributed identity identifier and the user distributed identity document from the distributed identity system. The distributed identity document is also sent by the distributed identity system to the identity chain for storage. The distributed identity document includes the user distributed identity identifier and the public key of the wallet client.

11. The method according to claim 10, wherein, The identity credential application request also includes the identity verification result identifier of the first operating institution and the second identity information, and before generating the identity credential based on the private key of the first operating institution, the method further includes: The second identity information is verified based on the identity verification result identifier of the first operating institution.

12. The method according to any one of claims 9 to 11, wherein, Before receiving the identity credential request sent by the wallet client, the method further includes: Receive the payment password entered by the user from the wallet client; The payment password is verified to generate a password verification result; and The password verification result is sent to the wallet client.

13. The method according to any one of claims 9 to 11, wherein, After generating the identity credential based on the private key of the first operating institution, the method further includes: Generate a credential hash value based on the identity credential, and send the credential hash value to the identity chain for storage.

14. The method according to claim 10 or 11, wherein, Before the verification of the first identity information submitted by the user in the identity verification service of the first operating institution is passed, the method further includes: The first identity information is sent to a trusted identity authentication platform so that the trusted identity authentication platform can perform identity verification based on the first identity information to generate an identity verification result and return the identity verification result to the first operating organization.

15. The method according to any one of claims 9 to 11, wherein, The step of generating the first encrypted ciphertext based on the first identity information includes: The first identity information is encrypted using a symmetric key to generate ciphertext identity information; The symmetric key is encrypted using the public key of the distributed identity system to generate key ciphertext, wherein the first encrypted ciphertext includes the identity information ciphertext and the key ciphertext.

16. An identity credential application device, applied to a wallet client, the device comprising: An identity credential application module is configured to send an identity credential application request to a first operating institution. The identity credential application request includes a user's distributed identity identifier and the signature information of the wallet client. This allows the first operating institution to obtain the public key of the wallet client corresponding to the user's distributed identity identifier from the identity chain, verify the signature information of the wallet client using the public key, generate an identity credential based on the first operating institution's private key, and generate a first encrypted ciphertext based on the user's first identity information. The identity credential includes a digest value of the first identity information, the distributed identity identifier of the first operating institution, and the signature information of the first operating institution. The receiving module is configured to receive and store the identity credential and the first encrypted ciphertext sent by the first operating institution.

17. An identity credential application device, applied to a first operating institution, the device comprising: A credential request receiving module is configured to receive identity credential request requests sent by a wallet client, wherein the identity credential request requests include a user's distributed identity identifier and the wallet client's signature information; The credential generation module is configured to obtain the public key of the wallet client corresponding to the user's distributed identity identifier from the identity chain, and verify the signature information of the wallet client using the public key of the wallet client. In response to the successful verification, the module generates an identity credential based on the private key of the first operating institution, and generates a first encrypted ciphertext based on the first identity information. The identity credential includes a digest value of the first identity information, the distributed identity identifier of the first operating institution, and the signature information of the first operating institution. as well as The sending module is configured to send the identity credential and the first encrypted ciphertext to the wallet client.

18. A wallet authentication method, applied to a wallet client, the method comprising: Obtain locally stored identity credentials and first encrypted ciphertext, wherein the identity credentials are generated by the first operating institution, and the identity credentials include a digest value of the user's first identity information, a distributed identity identifier of the first operating institution, and signature information of the first operating institution; the first encrypted ciphertext includes identity information ciphertext generated by the first operating institution based on the first identity information and a symmetric key, and key ciphertext generated based on the symmetric key. A verifiable representation is generated based on the identity credential, wherein the verifiable representation includes the identity credential, a credential signature generated by signing the identity credential using the private key of the wallet client, and a user distributed identity identifier; The key ciphertext and the second operator identifier are sent to the distributed identity system, so that the distributed identity system can re-encrypt the key ciphertext, generate a re-encrypted key ciphertext, and send the re-encrypted key ciphertext to the wallet client; Based on the encrypted key ciphertext, the key ciphertext in the first encrypted ciphertext is replaced to generate the second encrypted ciphertext. The verifiable representation and the second encrypted ciphertext are then sent to the second operating institution, so that the second operating institution can verify the verifiable representation based on the user's distributed identity and the second encrypted ciphertext, and generate a credential verification result. Receive the credential verification result sent by the second operating institution.

19. The method according to claim 18, wherein, The method further includes: When the credential verification result indicates that the verification is successful, a wallet upgrade request is sent to the second operating institution so that the second operating institution can upgrade the wallet level.

20. The method according to claim 18 or 19, wherein, The encrypted identity information is generated by encrypting the first identity information with the symmetric key, and the encrypted key is generated by encrypting the symmetric key with the public key of the distributed identity system; the encrypted key is generated by the distributed identity system according to the following steps: The ciphertext of the key is decrypted using the private key of the distributed identity system to obtain the symmetric key, and the symmetric key is then encrypted using the public key of the second operating institution to generate the encrypted ciphertext of the key.

21. The method according to claim 18 or 19, wherein, Before obtaining the locally stored identity credentials and the first encrypted ciphertext, the method further includes: Obtain the user's input payment password; and The payment password is sent to the second operating institution so that the second operating institution can verify the payment password.

22. The method according to claim 18 or 19, wherein, Before obtaining the locally stored identity credentials and the first encrypted ciphertext, the method further includes: The system retrieves a user distributed identity document and a first identifier of a local security component from the local database. The user distributed identity document includes a user identifier, the user distributed identity, the public key of the wallet client, and a second identifier of the security component that generated the public key of the wallet client. The first identifier is verified using the second identifier.

23. A wallet authentication method applied to a second operating institution, the method comprising: The system receives a verifiable representation and a second-encrypted ciphertext sent by a wallet client. The verifiable representation includes an identity credential, a credential signature generated by signing the identity credential using the wallet client's private key, and a user distributed identity identifier. The identity credential includes a digest value of first identity information, a distributed identity identifier of a first operating institution, and signature information of the first operating institution. The second-encrypted ciphertext includes an identity information ciphertext generated by the first operating institution based on the user's first identity information and a symmetric key, and a re-encrypted key ciphertext generated by the distributed identity system by re-encrypting the key ciphertext based on the second operating institution's identifier. The key ciphertext is generated by the first operating institution based on the symmetric key. The verifiable representation is verified based on the user's distributed identity identifier and the second encrypted ciphertext to generate a credential verification result; The credential verification result is sent to the wallet client.

24. The method according to claim 23, wherein, The method further includes: Receive the wallet upgrade request sent by the wallet client after determining that the credential verification result indicates that the verification is successful, and upgrade the wallet level according to the wallet upgrade request.

25. The method according to claim 23 or 24, wherein, The verification of the verifiable representation based on the user's distributed identity and the second encrypted ciphertext includes: Send the user's distributed identity identifier to the identity chain, so that the identity chain can obtain the wallet client's public key based on the user's distributed identity identifier, and send the wallet client's public key to the second operating institution; The signature of the credential is verified using the public key of the wallet client. Once the verification is successful, the identity credential is obtained. Send the distributed identity identifier of the first operating institution to the identity chain, so that the identity chain can obtain the public key of the first operating institution based on the distributed identity identifier of the first operating institution; The signature information of the first operating institution is verified using the public key of the first operating institution. After successful verification, the second encrypted ciphertext is decrypted using the private key of the second operating institution to obtain the first identity information. Calculate the digest value of the first identity information, obtain the calculated digest value, and verify the digest value of the first identity information in the identity credential based on the calculated digest value.

26. The method of claim 25, wherein, The step of verifying the verifiable representation based on the user's distributed identity and the second encrypted ciphertext further includes: Generate an identity credential hash value based on the aforementioned identity credential; Sending the identity credential hash value to the identity chain, so that the identity chain obtains the identity credential status based on the identity credential hash value and returns the identity credential status to the second operating institution; and Receive the identity credential status sent by the identity chain, and verify the existence of the identity credential based on the identity credential status.

27. The method according to claim 25, wherein, The first encrypted ciphertext includes key ciphertext and identity information ciphertext. The step of decrypting the second encrypted ciphertext using the private key of the second operating institution to obtain the first identity information includes: The symmetric key is obtained by decrypting the encrypted key ciphertext using the private key of the second operating institution. The ciphertext of the identity information is decrypted using the symmetric key to obtain the first identity information.

28. The method according to claim 23 or 24, wherein, The method further includes: Receive the payment password sent by the wallet client; The payment password is verified to generate a password verification result; and The password verification result is returned to the wallet client.

29. A wallet authentication device, applied to a wallet client, the device comprising: The credential acquisition module is configured to acquire locally stored identity credentials and first encrypted ciphertext, wherein the identity credentials are generated by a first operating institution and include a digest value of the user's first identity information, a distributed identity identifier of the first operating institution, and signature information of the first operating institution; the first encrypted ciphertext includes identity information ciphertext generated by the first operating institution based on the first identity information and a symmetric key, and key ciphertext generated based on the symmetric key. A verifiable representation generation module is configured to generate a verifiable representation based on the identity credential, wherein the verifiable representation includes the identity credential, a credential signature generated by signing the identity credential using the private key of the wallet client, and a user distributed identity identifier; The encryption request module is configured to send the key ciphertext and the second operator identifier to the distributed identity system, so that the distributed identity system can encrypt the key ciphertext, generate a ciphertext after encryption, and send the ciphertext after encryption to the wallet client. The verification application module is configured to replace the key ciphertext in the first trans-encrypted ciphertext with the trans-encrypted key ciphertext to generate a second trans-encrypted ciphertext, and send the verifiable expression and the second trans-encrypted ciphertext to the second operating institution, so that the second operating institution can verify the verifiable expression based on the user distributed identity identifier and the second trans-encrypted ciphertext and generate a credential verification result; as well as A receiving module, configured to receive the credential verification result sent by the second operating institution.

30. A wallet authentication device, applied to a second operating institution, the device comprising: The receiving module is configured to receive a verifiable representation and a second-encrypted ciphertext sent by a wallet client. The verifiable representation includes an identity credential, a credential signature generated by signing the identity credential using the wallet client's private key, and a user distributed identity identifier. The identity credential includes a digest value of first identity information, a distributed identity identifier of a first operating institution, and signature information of the first operating institution. The second-encrypted ciphertext includes an identity information ciphertext generated by the first operating institution based on the user's first identity information and a symmetric key, and a re-encrypted key ciphertext generated by the distributed identity system by re-encrypting the key ciphertext based on the second operating institution identifier. The key ciphertext is generated by the first operating institution based on the symmetric key. The verification module is configured to verify the verifiable representation based on the user's distributed identity identifier and the second encrypted ciphertext, and generate a credential verification result. A sending module is configured to send the credential verification result to the wallet client.

31. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-15 or the method as described in any one of claims 18-28.

32. A computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the method as claimed in any one of claims 1-15 or the method as claimed in any one of claims 18-28.

Citation Information

Patent Citations

  • Identity certificate generation method, verification method and system related to digital currency

    CN114157414A

  • Distributed digital identity identifier management method

    CN115134091A

  • Communication method and device based on distributed identity

    CN115174146A

  • Identity verification method and system using distributed network identity

    CN116760597A

  • Web wallet

    US20230025320A1

Cited By

  • Data security transmission method and device realized based on national cryptographic algorithm

    CN121664573A

  • A data security transmission method and device based on a national secret algorithm

    CN121664573B