Article control right credential issuance method, article control right credential verification method, article control right credential transfer method, and electronic device

By generating item control certificates through distributed identity identifiers, the problems of high transaction costs and unclear item origins in the trading of high-value items are solved, enabling efficient and reliable verification and transfer of item control rights and reducing transaction costs.

WO2026026579A1PCT designated stage Publication Date: 2026-02-05THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/109412
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-31
Filing Date
2025-07-18
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Currently, in the trading of high-value goods, using third-party intermediary platforms increases transaction costs, and the origin of the goods is unclear, making it difficult to trace their authenticity, which increases the risk of purchasing.

Method used

A certificate of control over an item is generated through a distributed identity identifier, which includes item information and the identity identifier of the owner. The issuing authority generates and sends the certificate, the item owner user signs it using a private key, and the verification terminal verifies the signature and identifier of the certificate, thereby realizing reliable verification and transfer of control over the item.

Benefits of technology

It simplifies the transfer process for the resale of goods, reduces the cost of transferring goods between the two parties, improves the reliability and efficiency of transactions, and reduces reliance on third-party intermediary platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025109412_05022026_PF_FP_ABST
    Figure CN2025109412_05022026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in embodiments of the present disclosure are an article control right credential issuance method, an article control right credential verification method, and an article control right credential transfer method. The article control right credential issuance method is applied to an issuing authority, and comprises: in response to an access request for an article control right credential issuance link sent by an article owner application terminal, returning an article control right credential issuance response to the article owner application terminal; acquiring an acknowledgement operation sent by the article owner application terminal; generating an article control right credential of a target article; and sending the article control right credential to the article owner application terminal. Also provided are a corresponding electronic device and a computer-readable medium.
Need to check novelty before this filing date? Find Prior Art

Description

Methods for issuing, verifying, and transferring certificates of control over goods, and electronic devices.

[0001] This disclosure claims priority to Chinese Patent Application No. 202411048129X, filed on July 31, 2024, entitled "Method and Apparatus for Issuing Certificates of Control of Articles"; Chinese Patent Application No. 2024110467907, filed on July 31, 2024, entitled "Method and Apparatus for Verifying Certificates of Control of Articles"; and Chinese Patent Application No. 2024110467979, filed on July 31, 2024, entitled "Method and Apparatus for Transferring Certificates of Control of Articles". The contents of the above-mentioned Chinese patent applications are incorporated herein by reference in their entirety as part of this disclosure. Technical Field

[0002] This invention relates to the field of computer technology, and more particularly to a method, electronic device, and computer-readable medium for issuing, verifying, and transferring credentials of control over articles. Background Technology

[0003] Currently, transactions involving high-value items such as smart electronic devices, customized goods, luxury goods, and virtual digital assets typically involve the resale of these items through third-party intermediary platforms. These platforms charge transaction fees, increasing costs for both parties. Furthermore, the origins of high-value items sold through these platforms are often unclear, making it difficult to trace their origins and verify their authenticity, thus increasing the risk for buyers. Summary of the Invention

[0004] In view of this, embodiments of this disclosure provide a method and electronic device for issuing, verifying, and transferring credentials of control over goods, which can effectively reduce the transaction costs of verifying the authenticity of goods and facilitate the traceability of goods transactions. According to a first aspect of this disclosure, a method for issuing credentials of control over goods is provided, applied to an issuing institution, and the method includes the following steps:

[0005] In response to an access request for an item control certificate issuance link sent by the item owner's application terminal, an item control certificate issuance response is returned to the item owner's application terminal, wherein the item control certificate issuance link is associated with the target item.

[0006] The confirmation operation generated by the application terminal of the item owner based on the issuance response of the item control certificate is obtained. The confirmation operation includes the distributed identity of the item owner.

[0007] Generate an item control certificate for the target item, wherein the item control certificate for the target item includes information about the target item and a distributed identity identifier of the item owner;

[0008] Send the item control certificate to the application terminal of the item owner.

[0009] According to a second aspect of the present disclosure, an item control certificate issuing device is provided, applied to an issuing organization. The device includes an issuing response module, a confirmation operation acquisition module, a certificate generation module, and a sending module. The issuing response module is configured to respond to an access request for an item control certificate issuing link sent by an item owner application terminal and return an item control certificate issuing response to the item owner application terminal. The item control certificate issuing link is associated with the target item.

[0010] The confirmation operation acquisition module is configured to acquire the confirmation operation generated by the response issued based on the item control certificate sent by the application terminal of the item owner. The confirmation operation includes the distributed identity identifier of the item owner.

[0011] The certificate generation module is configured to generate an item control certificate for the target item, wherein the item control certificate for the target item includes information about the target item and a distributed identity identifier of the item owner;

[0012] The sending module is configured to send the item control certificate to the application terminal of the item owner.

[0013] According to a third aspect of the present disclosure, an electronic device is provided, including: one or more processors; and a storage device configured to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the methods provided in the embodiments of the present disclosure.

[0014] According to a fourth aspect of the present disclosure, a computer-readable medium is provided having a computer program stored thereon, which, when executed by a processor, implements the methods provided in the embodiments of the present disclosure.

[0015] One embodiment of the above invention has the following advantages or beneficial effects:

[0016] In this embodiment, the user who owns the item sends a grant link access request to the granting authority through their application terminal. The granting authority generates a grant response and returns it to the application terminal. After confirming the application credential, the granting authority generates an item control certificate for the target item based on the item's information and the owner's distributed identity identifier, and sends the certificate to the application terminal. By generating a verifiable certificate associated with the distributed identity identifier, control of the item can be verified in subsequent transactions, ensuring the item's reliable origin, improving the reliability of peer-to-peer transactions, simplifying the transfer process for resale, and reducing the item transfer costs between the transacting parties.

[0017] According to a fifth aspect of the present disclosure, a method for verifying an article control certificate is provided, applied to a verification party's application terminal, the method comprising:

[0018] The system obtains a verifiable expression of control over a target item sent by the application terminal of the item owner. This verifiable expression includes a control certificate for the target item stored on the application terminal of the item owner and a certificate signature generated by signing the control certificate with the item owner's private key. The control certificate includes a declaration portion and a signature portion generated by signing the declaration portion with the private key of the issuing authority. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item owner, and the distributed identity identifier of the issuing authority. The system then verifies the verifiable expression of control over the item to generate a control certificate verification result.

[0019] According to a sixth aspect of the present disclosure, an item control certificate verification device is provided, applied to a verification party application terminal. The device includes a verifiable expression acquisition module and a verification result generation module. The verifiable expression acquisition module is configured to acquire an item control certificate verification expression of a target item sent by the item owner application terminal. The item control certificate verification expression includes an item control certificate of the target item stored in the item owner application terminal and a certificate signature generated by signing the item control certificate with the item owner's private key. The item control certificate includes a declaration portion and a signature portion generated by signing the declaration portion with the private key of the issuing authority. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item owner, and the distributed identity identifier of the issuing authority.

[0020] The verification result generation module is configured to verify the verifiable expression of control over items and generate verification results for control rights certificates.

[0021] According to a seventh aspect of the present disclosure, an electronic device is provided, comprising: one or more processors; and a storage device configured to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the methods provided in the embodiments of the present disclosure.

[0022] According to an eighth aspect of the present disclosure, a computer-readable medium is provided having a computer program stored thereon, which, when executed by a processor, implements the methods provided in the embodiments of the present disclosure.

[0023] One embodiment of the above invention has the following advantages or beneficial effects:

[0024] In this embodiment, the owner of the item signs the item control certificate using their private key through their application terminal, generating a certificate signature. Based on the item control certificate and the certificate signature, a verifiable expression of item control is generated and sent to the verifying application terminal. The verifying application terminal verifies the verifiable expression of item control based on the owner's distributed identity identifier and the issuer's distributed identity identifier in the item control certificate, generating a verification result. Through distributed identity identifiers, an efficient and reliable method for verifying item control certificates is achieved, improving transaction efficiency in secondary item transactions. The buyer can quickly verify the control and origin of the item without relying on a third-party intermediary platform, simplifying the transfer procedure for secondary sales and reducing the item transfer costs between the transacting parties.

[0025] According to a ninth aspect of the present disclosure, a method for transferring an article control certificate is provided, applied to a verification application terminal, the method comprising:

[0026] The application terminal receiving the item receives an application request for transfer of control of the item. The application request for transfer of control of the item includes a verifiable expression for the transfer of control of the target item. The verifiable expression for the transfer of control of the item includes the item control certificate of the target item, the transfer request information, and the certificate signature generated by the application terminal of the item owner.

[0027] Validate the verifiable representation of the transfer of control over items and generate the verification result of the transfer verifiable representation.

[0028] The verification result of the transfer verifiable expression indicates that the verification has passed, and generates a post-transfer item control certificate for the item recipient.

[0029] Send the transferred item control certificate to the item recipient.

[0030] According to a tenth aspect of the present disclosure, a method for transferring a certificate of control over an item is provided, applied to an application terminal of an item recipient, the method comprising:

[0031] Send an application for transfer of control of an item to the issuing authority. The application for transfer of control of an item includes a verifiable expression for the transfer of control of the target item. The verifiable expression for the transfer of control of an item includes the item control certificate of the target item, the transfer request information, and the certificate signature generated by the application terminal of the item owner.

[0032] The recipient receives a transferred item control certificate from the issuing authority. This transferred item control certificate is generated by the issuing authority after verifying the verifiable expression of the transfer of item control.

[0033] According to the eleventh aspect of the present disclosure, an item control certificate transfer device is provided, applied to an issuing authority. The device includes a transfer application acquisition module, a verification module, a certificate generation module, and a sending module.

[0034] The transfer request acquisition module is configured to receive the item control transfer request sent by the item recipient application terminal. The item control transfer request includes a verifiable expression for the transfer of item control of the target item. The verifiable expression for the transfer of item control includes the item control certificate of the target item, the transfer request information, and the certificate signature generated by the item owner application terminal.

[0035] The verification module is configured to verify verifiable expressions of item control transfer and generate verification results for the transfer verifiable expressions.

[0036] The voucher generation module is configured to respond to a transfer verifiable expression indicating that the verification has passed, and to generate a voucher for control of the transferred goods for the recipient of the goods.

[0037] The sending module is configured to send the transferred item control certificate to the item recipient.

[0038] According to a twelfth aspect of the present disclosure, an item control certificate transfer device is provided, applied to an item recipient's application terminal. The device includes a transfer application module and a certificate receiving module, wherein...

[0039] The transfer application module is configured to send an application for transfer of control of an item to the issuing authority. The application for transfer of control of an item includes a verifiable expression for the transfer of control of the target item. The verifiable expression for the transfer of control of an item includes the item control certificate of the target item, the transfer request information, and the certificate signature generated by the application terminal of the item owner.

[0040] The certificate receiving module is configured to receive transferred item control certificates sent by the issuing authority. The transferred item control certificate is generated by the issuing authority after verifying the verifiable expression of the transfer of item control.

[0041] According to a thirteenth aspect of the present disclosure, an electronic device is provided, comprising: one or more processors; and a storage device configured to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the methods provided in the embodiments of the present disclosure.

[0042] According to a fourteenth aspect of the present disclosure, a computer-readable medium is provided having a computer program stored thereon, which, when executed by a processor, implements the methods provided in the embodiments of the present disclosure.

[0043] One embodiment of the above invention has the following advantages or beneficial effects:

[0044] In this embodiment, the application terminal of the item owner generates a transfer verifiable expression based on the item control certificate and transfer request information, and sends the transfer verifiable expression to the application terminal of the item recipient. The application terminal of the item recipient organizes an item control transfer application based on the transfer verifiable expression and sends the application to the issuing authority. The issuing authority verifies various signatures in the transfer verifiable expression based on the distributed identity identifier. After successful verification, it generates a post-transfer item control certificate based on the item recipient's information and sends the post-transfer item control certificate to the item recipient, thus realizing the transfer of item control. During the item control transfer process, the distributed identity identifier enables fast and reliable control verification. After successful verification, a post-transfer item control certificate can also be generated based on the transaction request. This simplifies the transfer procedure for the resale of items and reduces the item transfer cost between the two parties.

[0045] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description

[0046] The accompanying drawings are provided to better understand this disclosure and do not constitute an undue limitation thereof. Wherein:

[0047] Figure 1 is a schematic diagram of the network system architecture of the article control certificate issuance method, article control certificate verification method and article control certificate transfer method according to some embodiments of this disclosure;

[0048] Figure 2 is a flowchart illustrating a method for issuing a certificate of control of an article according to some embodiments of this disclosure;

[0049] Figure 3 is a schematic diagram of credential verification data permission chain storage verification data according to some embodiments of the present disclosure;

[0050] Figure 4 is a flowchart illustrating the process of a user operating the application terminal of the owner of the item in the method for issuing an item control certificate according to some embodiments of this disclosure.

[0051] Figure 5 is a flowchart illustrating a method for verifying a certificate of control of an item according to some embodiments of this disclosure;

[0052] Figure 6 is a flowchart illustrating the process of generating a control certificate verification result in a method for verifying a control certificate according to some embodiments of the present disclosure;

[0053] Figure 7 is another flowchart illustrating the generation of control certificate verification results in the article control certificate verification method according to some embodiments of the present disclosure;

[0054] Figure 8 is another flowchart illustrating the generation of control certificate verification results in the article control certificate verification method according to some embodiments of the present disclosure;

[0055] Figure 9 is a flowchart illustrating the user's operation of the verification application terminal in the article control certificate verification method according to some embodiments of this disclosure;

[0056] Figure 10 is a flowchart illustrating a method for transferring a certificate of control of an article according to some embodiments of this disclosure;

[0057] Figure 11 is a flowchart illustrating the process of generating a verification result of a transfer verifiable expression in a method for transferring an article control certificate according to some embodiments of the present disclosure;

[0058] Figure 12 is another flowchart illustrating the generation of a transferable verifiable expression verification result in the article control certificate verification method according to some embodiments of the present disclosure;

[0059] Figure 13 is another flowchart illustrating the generation of a transferable verifiable expression verification result in the article control certificate verification method according to some embodiments of the present disclosure;

[0060] Figure 14 is a schematic flowchart of the process for generating a transferred document control certificate in a document control certificate verification method according to some embodiments of the present disclosure;

[0061] Figure 15 is a flowchart illustrating a method for transferring a certificate of control of an article according to other embodiments of this disclosure;

[0062] Figure 16 is a flowchart illustrating a method for transferring a certificate of control of an article according to other embodiments of this disclosure;

[0063] Figure 17 is a flowchart illustrating the user's operation of the application terminal of the item owner and the application terminal of the item recipient in the method for transferring the item control certificate according to some embodiments of this disclosure.

[0064] Figure 18 is a schematic diagram of the functional architecture of the article control certificate issuing device according to some embodiments of the present disclosure;

[0065] Figure 19 is a schematic diagram of the functional architecture of an article control certificate verification device according to some embodiments of the present disclosure;

[0066] Figure 20 is a schematic diagram of the functional architecture of the article control certificate transfer device according to some embodiments of the present disclosure;

[0067] Figure 21 is a schematic diagram of the functional architecture of the article control certificate transfer device according to some other embodiments of the present disclosure;

[0068] Figure 22 is an exemplary system architecture diagram in which embodiments of this disclosure can be applied;

[0069] Figure 23 is a schematic diagram of the structure of a computer system suitable for implementing terminal devices or servers of the present disclosure. Detailed Implementation

[0070] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0071] First, the abbreviations and related terms involved in the embodiments of this disclosure are defined and explained.

[0072] "DID (Decentralized Identifiers)" refers to a distributed identity identifier, which is an identifier composed of strings to represent a digital identity. The DID is generated by the distributed identity system based on the applicant's public key and other information. The distributed identity system also stores a DID document corresponding to the DID, which stores the DID and the public key corresponding to the DID.

[0073] "VC (Verifiable Credential)" refers to a verifiable credential that includes VC metadata, a declaration section, and a signature section. VC metadata mainly includes information such as the issuer, issuance date, and type of declaration. The declaration section is one or more specific descriptions about the subject. For example, if VC is an ID card, then the declaration section will include personal information such as the holder's name, gender, date of birth, ethnicity, and address. The signature section is usually the issuer's digital signature, used to ensure the integrity and authenticity of the VC content, prevent tampering, and verify the issuer's identity.

[0074] A “VP (Verifiable Presentation)” is a verifiable representation associated with a user’s distributed identity, which includes a verifiable proof document synthesized from one or more verifiable credentials (VCs) and a credential signature generated by the user’s digital signature of the proof document.

[0075] In existing goods trading processes, it is necessary to verify the origin of goods, which often requires the use of third-party intermediary platforms, resulting in reduced transaction efficiency and increased transaction costs.

[0076] This disclosure provides a method for issuing control rights of items based on distributed identity identification. It can generate corresponding credentials for control rights of items. In subsequent secondary transactions, the control rights credentials can be verified. Based on new transaction requests, after verifying the credentials, new control rights credentials can be generated to realize credential transfer. Credential transfer can be achieved without the need for a third-party intermediary platform, which effectively improves transaction efficiency and reduces transaction costs.

[0077] As shown in Figure 1, a network system 100 is illustrated in this embodiment of the present disclosure. The item control certificate issuance method, item control certificate verification method, and item control transfer method in this embodiment of the present disclosure can be run in the network system 100. The network system 100 includes an item owner application terminal 110, a verification application terminal 120, an item recipient application terminal 130, an issuing authority 140, a distributed identity system 150, and a certificate verification data permission chain 160.

[0078] In some embodiments of this disclosure, the issuing authority 140 can be understood as an issuing authority system. In some scenarios, it can be a system controlled by the article manufacturer, or a unified platform that can connect with the article manufacturer.

[0079] In some embodiments of this disclosure, the item owner application terminal 110, the verification application terminal 120, and the item recipient application terminal 130 can be digital wallet application terminals, and the functions related to managing the item control certificate can be set in the digital wallet application. In some embodiments of this disclosure, the item owner application terminal 110, the verification application terminal 120, and the item recipient application terminal 130 can also be equipped with a security unit. The security unit can generate a public-private key pair, store the private key, and transmit the public key to external users through the digital wallet application. In some embodiments of this disclosure, the item control certificate VC can be stored within the digital wallet application or in the security unit. In some embodiments of this disclosure, the verification application terminal 120 and the item recipient application terminal 130 can be the same application terminal, that is, the control certificate is transferred after verification by the item recipient.

[0080] This embodiment of the disclosure manages the item control certificate based on the network system 100, including functions such as item control certificate issuance, item control certificate verification, and item control certificate transfer.

[0081] As shown in Figure 2, this embodiment of the present disclosure provides a method for issuing a certificate of control over an item, including the following steps:

[0082] S210: After purchasing the target item online or offline, the item owner receives the target item and uses the item owner application terminal 110 to send an access request for the item control certificate issuance link to the issuing authority 140.

[0083] In some embodiments of this disclosure, during the production and packaging process of the target item, the manufacturer prints a QR code on the outer packaging of the target item that is associated with the issuance link of the item control certificate. The item owner application terminal 110 scans the QR code on the target item, parses the QR code, obtains the item control certificate issuance link of the target item, and sends an access request to the issuing authority. The issuance link contains the address or domain name of the server on which the issuing authority 140 receives the access request. The item owner application terminal 110 sends the access request to the issuing authority 140 according to the address or domain name of the server.

[0084] In some embodiments of this disclosure, the item control certificate issuance link is associated with the target item, and the issuing authority 140 maintains a mapping relationship between the two, so that the target item can be identified through the item control certificate issuance link.

[0085] In some embodiments of this disclosure, the purchase transaction process of the target item can be independent of the process of granting control of the item. The purchaser or payer of the target item can be the same as or different from the owner of the item. That is, the purchaser or payer can purchase the target item for themselves or for others.

[0086] In some embodiments of this disclosure, in order to adapt to scenarios where the end user needs to be limited, the issuing authority 140 can obtain information about the owner of the item during the purchase process (which can be collected during the purchase process) so as to verify the identity when applying for a certificate of control.

[0087] S220: The issuing authority 140 returns a certificate of control of the item to the item owner's application terminal 110. The certificate of control certificate is issued in the certificate of control of the item. The certificate of control certificate contains information on whether the link is valid and the item information of the target item, such as the item name, manufacturer, production time, shelf life, etc. The item owner's application terminal 110 displays a page based on the certificate of control certificate so that the item owner can confirm the information of the target item.

[0088] In some embodiments of this disclosure, when the issuing authority determines that the target item is one whose ownership needs to be restricted, the aforementioned issuance response also includes a channel for filling in the ownership information of the item, so that the item ownership application terminal 110 can transmit the ownership information of the item to the issuing authority 140.

[0089] S230: Based on the response to the issuance of the item control certificate and the operation of the item owner, the item owner's application terminal 110 sends a confirmation operation to the issuing authority 140. The confirmation operation may include the item owner's distributed identity identifier, the intention to confirm the application for the certificate, and may also include the item owner's identity information.

[0090] S240: The issuing authority 140 generates an item control certificate for the target item. The item control certificate for the target item includes information about the target item and a distributed identity identifier of the item's owner.

[0091] In some embodiments of this disclosure, the item control certificate includes a declaration portion and a signature portion generated by signing the declaration portion; the process of generating an item control certificate for a target item includes:

[0092] Issuing authority 140 uses its private key to sign the statement portion, generating a signed portion, wherein the statement portion includes the identifier of the target item, the distributed identity identifier of the item's owner, and the distributed identity identifier of the issuing authority.

[0093] In some embodiments of this disclosure, before generating the certificate, the issuing authority 140 also verifies the identity information of the owner of the item in the confirmation operation. If the identity information of the owner of the item is consistent with the identity information of the owner of the item stored by the issuing authority, the subsequent step of generating the item control certificate is carried out.

[0094] The identifier of the target item in this embodiment of the disclosure may be a distributed identity identifier of the target item, or other unique identifier.

[0095] In embodiments of this disclosure, the distributed identity of the target item, the distributed identity of the item owner, and the distributed identity of the issuing authority can be prepared before the issuance of the item control certificate.

[0096] In some embodiments of this disclosure, the distributed identity identifier of the target item is generated by a distributed identity system based on the unique identifier of the target item. The distributed identity system also generates a distributed identity identifier document corresponding to the distributed identity identifier of the target item based on the attribute data of the target item. The item manufacturer sends an item distributed identity identifier application to the distributed identity system 150. The item distributed identity identifier application includes the unique identifier of the item, as well as attribute data such as the item's manufacturer, production time, delivery time, and warranty period. The distributed identity system 150 can combine the item manufacturer information, the unique identifier of the target item, and random information to generate a unique distributed identity identifier (Obj-DID) for the target item, and simultaneously write the attribute data such as the target item's manufacturer, production time, delivery time, and warranty period into the distributed identity identifier document created for the target item.

[0097] In some embodiments of this disclosure, the distributed identity identifier of the item owner is generated by the distributed identity system 150 based on the owner's public key and sent to the item owner's application terminal 110. The distributed identity system 150 also generates a distributed identity identifier document corresponding to the item owner's distributed identity identifier based on the item owner's public key and the item owner's identifier. The item owner registers as a digital wallet user through the digital wallet APP in the application. During the registration process, the digital wallet calls the security unit SE in the application terminal to generate a public-private key pair User(sk, PK) for the user. The private key is stored in the security unit SE, and the public key is transmitted to the distributed identity system through the digital wallet. The distributed identity system 150 generates a globally unique distributed identity identifier User-DID for the user and simultaneously writes the user's public key User(PK) into the distributed identity identifier document created for the user.

[0098] In some embodiments of this disclosure, the product manufacturer interfaces with the distributed identity system 150 via an interface. During the interface process, the manufacturer generates a public-private key pair Org(sk, PK) based on its own secure cryptographic product. The private key Org(sk) is stored in its own secure cryptographic product. The manufacturer sends a distributed identity identifier generation request to the distributed identity system 150. The distributed identity identifier request includes information such as business license, legal person information, LEI (Legal Entity Identifier), and public key Org(PK). After reviewing the information in the request, the distributed identity system 150 generates a globally unique distributed identity identifier Org-DID for the manufacturer based on the LEI. At the same time, the manufacturer's public key Org(PK) and LEI are written into the distributed identity identifier document created for the manufacturer.

[0099] In the item control certificate of this embodiment, a distributed identity identifier of the issuing authority 140 is included. During subsequent certificate verification, the public key of the issuing authority can be obtained from the distributed identity system through the distributed identity identifier of the issuing authority 140, thereby verifying the correctness of the signature. The certificate includes a distributed identity identifier of the target item. After subsequent certificate verification, the attribute information of the target item can be obtained from the distributed identity system through the distributed identity identifier of the target item, thereby achieving the purpose of traceability.

[0100] In some embodiments of this disclosure, the declaration portion of the article control certificate further includes: maintenance data and / or transfer records of the target article. After certificate verification, accurate maintenance data and / or transfer records of the target article can be obtained, enriching the scope of traceability information.

[0101] S250: The issuing authority 140 sends the item control certificate to the item owner application terminal 110.

[0102] In some embodiments of this disclosure, the item owner application terminal 110 stores the item control certificate in a digital wallet application or a secure unit.

[0103] In some embodiments of this disclosure, to facilitate subsequent verification of the credential status by other parties, the issuing authority 140 also synchronizes the verification data of the credential of control to the credential verification data permission chain 160. The verification data includes the credential of control digest value and status information. After generating the credential of control VC, the issuing authority 140 calculates a digest value (e.g., a hash value) based on the credential of control VC and synchronizes the digest value, VC type, validity period, revocation status, and other information to the credential verification data permission chain 160. Subsequently, the credential verification data permission chain 160 can retrieve information such as the VC type, validity period, and revocation status from the credential verification data permission chain 160 based on the digest value. As shown in Figure 3, the credential verification data permission chain 160 can store the data synchronized by the issuing authority 140 in a key-value format, where the key is the digest value and the value is information such as the VC type, validity period, and revocation status.

[0104] In this embodiment of the disclosure, the user who owns the item applies for the issuance of an item control certificate through a digital wallet application on the item owner application terminal 110, as shown in Figure 4. The user clicks the "Item Control Certificate Application" button in the digital wallet application, the digital wallet application scans the QR code on the item, the item owner application terminal 110 sends an access request to the issuing authority 140, the issuing authority 140 returns an issuance response to the item owner application terminal 110, the user clicks the "Confirm Acquisition" button on the interface, the issuing authority 140 generates the item control certificate and returns the item control certificate to the item owner application terminal 110, the user clicks "Store Certificate" on the interface, and the item owner application terminal 110 stores the item control certificate in the digital wallet application or in the secure unit on the item owner application terminal 110.

[0105] The method for issuing item control certificates in this embodiment provides a foundation for subsequent certificate verification and transfer. The generated item control certificate can be verified after obtaining a public key based on a distributed identity identifier to determine control of the item. This simplifies the verification process using a third-party intermediary platform, improves transaction efficiency, and saves transaction costs. Compared to the disadvantages of traditional paper certificates, such as ease of forgery, alteration, and portability, the item control certificate issued in this embodiment better realizes the digital presentation and reliable transfer of item control certificates.

[0106] This disclosure also supports the function of verifying control credentials, which makes it convenient for counterparties to verify the identity of the person in charge of the goods and ensures the reliability of the transaction.

[0107] As shown in Figure 5, based on the network system 100 in Figure 1, this embodiment of the disclosure also provides a method for verifying credentials of control over goods, including:

[0108] S310: The application terminal 110 of the item owner obtains the item control certificate of the target item stored locally, and generates an item control verifiable expression based on the item control certificate. The item control verifiable expression includes the item control certificate and a certificate signature generated by signing the item control certificate with the item owner's private key. The item control certificate includes a declaration part and a signature part generated by signing the declaration part with the issuing authority's private key. The declaration part includes the identifier of the target item, the distributed identity identifier of the item owner, and the distributed identity identifier of the issuing authority.

[0109] S320: The item owner application terminal 110 sends an item control verification expression to the verification application terminal 120. In some embodiments of this disclosure, the verification application terminal 120 obtains the item control verification expression of the target item from the item owner application terminal 110 via a near-field communication protocol (e.g., NFC, UWB, Bluetooth, etc.); or, the verification application terminal 120 obtains the item control verification expression of the target item by scanning the QR code generated by the item owner application terminal 110 based on the item control verification expression of the target item.

[0110] S330: The verification party uses the terminal 120 to verify the control rights of the item and generates a control rights certificate verification result.

[0111] In this embodiment of the disclosure, the verification application terminal 120 obtains the corresponding public key from the distributed identity system 150 based on the distributed identity identifier in the verifiable representation, thereby verifying the authenticity, validity, and integrity of the verifiable representation. Specifically, as shown in FIG6, step S330 includes:

[0112] S331: The verification application terminal 120 obtains the public key of the item owner from the distributed identity system 150 based on the distributed identity identifier of the item owner. In some embodiments of this disclosure, the distributed identity system 150 obtains the public key of the item owner from the distributed identity document based on the distributed identity identifier of the item owner, and sends the public key of the item owner to the verification application terminal 120.

[0113] S332: The verification application terminal 120 uses the public key of the item owner to verify the credential signature and generates a credential signature verification result; if the verification is successful, it proves that the item control certificate comes from the item owner application 110 and has not been changed during transmission.

[0114] S333: The verification terminal 120 generates a control credential verification result based on the credential signature verification result.

[0115] In this embodiment of the disclosure, the verification application terminal 120 performs further verification based on the credential signature verification result, as shown in Figure 7, generating a control credential verification result based on the credential signature verification result, including:

[0116] S3331: In response to the credential signature verification result indicating successful verification, the verification application terminal 120 obtains the public key of the issuing authority from the distributed identity system 150 based on the distributed identity identifier of the issuing authority. The distributed identity system 150 obtains the public key of the issuing authority from the distributed identity identifier document based on the distributed identity identifier of the issuing authority.

[0117] S3332: The verification application terminal 120 verifies the signature part based on the public key of the issuing authority and generates a certificate declaration verification result; if the verification is successful, it means that the declaration content in the certificate has not been changed, and the issuing authority has indeed confirmed the declaration content, proving its authenticity.

[0118] S3333: The verification terminal 120 generates a control credential verification result based on the credential signature verification result and the credential declaration verification result.

[0119] In this embodiment of the disclosure, the validity of the credential is further verified. Specifically, as shown in Figure 8, a control credential verification result is generated based on the credential signature verification result and the credential declaration verification result. The verification also includes:

[0120] S33331: The verification application terminal 120 responds to the credential signature verification result and credential declaration verification result indicating that the verification is successful, and generates an item control credential digest value based on the item control credential. For example, the item control credential hash value can be calculated as the digest value.

[0121] S33332: The verification application terminal 120 obtains status information from the credential verification data permission chain 160 based on the credential control certificate digest value; the credential verification data permission chain 160 queries and obtains the status information of the credential control certificate based on the credential control certificate digest value, and returns it to the verification application terminal 120.

[0122] S33333: If the verification application terminal 120 determines that the status of the item control certificate is normal based on the status information, then the verification certificate is valid, and a verification result indicating that the verification of the control certificate has passed is generated. If the verification application terminal 120 determines that the item control certificate has not been revoked, then the verification certificate is valid.

[0123] In some embodiments of this disclosure, the verification terminal 120 also displays the verification result of the control credential and prompts the verification party.

[0124] In some embodiments of this disclosure, the identifier of the target item is a distributed identity identifier of the target item, and the above verification method further includes:

[0125] S340: In response to the control credential verification result indicating successful verification, the verification application terminal 120 retrieves the attribute data of the target item from the distributed identity system 150 based on the distributed identity identifier of the target item, and displays the attribute data. For example, it displays information such as the manufacturer, production time, shipping time, and shelf life of the target item.

[0126] In some embodiments of this disclosure, the declaration portion of the item control certificate further includes transfer records of the target item and / or maintenance data of the target item, and the above method further includes:

[0127] S350: In response to the control credential verification result indicating successful verification, the verification application terminal 120 displays the transfer record and / or maintenance data of the target item. This allows the user to access the transfer record and maintenance data of the target item. The page displayed by the verification application terminal 120 is shown in Figure 9, which can display transfer records, maintenance data, and attribute information on the same page.

[0128] In this embodiment, the verification application terminal 120 may be equipped with a digital wallet application, through which the verification credential process is initiated. As shown in Figure 9, the digital wallet application has a "Verify Control Credential" button. The verification application terminal 120 scans the QR code generated by the item owner application terminal 110 or obtains the item control verifiable expression generated by the item owner application terminal 110 through near-field communication protocol. The user clicks the "Confirm Verification" button on the interface. The verification application terminal 120 obtains the corresponding public key based on the distributed identity identifier in the verifiable expression, verifies the content of the verifiable expression, and verifies the validity of the credential. After successful verification, the verification application terminal 120 obtains the attribute information of the target item based on the identifier of the target item, retrieves transfer records and maintenance data from the control credential, and displays the attribute information, transfer records, maintenance data, etc. on the interface. After verifying the status of the item control credential, the verification application terminal 120 can also display status information, such as the validity period, status, VC type, etc.

[0129] In this embodiment, a unified identification and distributed storage of digital identities for items can be achieved through DID Service Network Permissioned Chain technology. Each item manufacturer can join as a node in the DID Service Network Permissioned Chain after approval and authorization. Item manufacturers already in the distributed identity system assign digital identity identifiers (Obj-DIDs) to their manufactured items through the distributed identity system, and simultaneously write attribute data such as the item's manufacturer, production time, shipping time, and warranty period into a document indexed by this identifier. Interaction between the DID Service Network Permissioned Chain and the distributed identity system can be achieved using any secure online method. Item attribute data stored on the DID Service Network Permissioned Chain can be obtained by accessing the distributed identity system. Unlike the digital identity documents generated by the distributed identity platform for individuals and organizations, this document, including attribute data, stores metadata describing the item's attributes. Leveraging the multi-node distributed ledger in permissioned chain technology, and the immutable and tamper-proof characteristics of data, the identifiability, traceability, and tamper-proof nature of item identity attributes can be achieved.

[0130] In this embodiment of the disclosure, the method for verifying the certificate of control of an item can quickly verify control without relying on a third-party intermediary platform, providing a convenient basis for subsequent formal transactions, saving verification costs before the transaction, and enabling traceability of item information, thus ensuring the reliability of transaction information.

[0131] This embodiment of the disclosure can also realize the transfer of credentials based on the issued credentials of control of goods. Based on the network system 100 in Figure 1, as shown in Figure 10, this embodiment of the disclosure also provides a method for transferring credentials of control of goods, including the following steps:

[0132] S410: After the item owner and the item recipient confirm the intention to transfer the item, the item owner application terminal 110 retrieves the item control certificate of the target item from local storage, generates a transfer certificate signature based on the transfer request information and the item control certificate, generates an item control transfer verifiable expression based on the transfer certificate signature, the transfer request information and the item control certificate, and sends the item control transfer verifiable expression to the item recipient application terminal 130.

[0133] S420: The receiving application terminal 130 sends an application for transfer of control of the item to the issuing agency 140 based on the verifiable expression for the transfer of control of the item, wherein the application for transfer of control of the item includes the verifiable expression for the transfer of control of the target item.

[0134] S430: The issuing authority 140 verifies the verifiable representation of the transfer of control of the article and generates a verification result of the transfer verifiable representation.

[0135] In some embodiments of this disclosure, the authenticity, validity, and integrity of the verifiable expression for the transfer of control of an item can be verified. In embodiments of this disclosure, the item control certificate includes a declaration portion and a signature portion generated by signing the declaration portion with the private key of the issuing authority. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item's owner, and the distributed identity identifier of the issuing authority. As shown in Figure 11, step S430 includes:

[0136] S431: The issuing authority 140 obtains the public key of the item owner from the distributed identity system 150 based on the distributed identity identifier of the item owner; the issuing authority 140 obtains the distributed identity identifier of the item owner from the declaration portion of the item control certificate, and then obtains the public key of the item owner from the distributed identity system 150 based on the distributed identity identifier of the item owner.

[0137] S432: The issuing authority 140 uses the public key of the owner of the goods to verify the signature of the transfer certificate and generates a certificate signature verification result; when the verification is successful, it proves that the owner of the goods has a genuine intention to transfer the goods and that the intention to transfer has not been changed.

[0138] S433: The issuing authority 140 generates a transferable verifiable expression verification result based on the credential signature verification result.

[0139] In some embodiments of this disclosure, the issuing authority 140 performs further verification based on the credential signature verification result, as shown in FIG12. Step S433 includes:

[0140] S4331: In response to the credential signature verification result indicating successful verification, the issuing authority 140 verifies the signature portion based on its public key and generates a credential declaration verification result. In this embodiment, the public key of the issuing authority 140 can be obtained locally or from the distributed identity identifier of the issuing authority in the declaration portion of the credential of control of the item. The issuing authority's public key is then obtained from the distributed identity system 150 based on the distributed identity identifier of the issuing authority.

[0141] In this embodiment of the disclosure, the path to obtain the public key from the distributed identity system 150 ensures that the credentials can be verified even if the issuing authority's public key is updated.

[0142] In this embodiment of the disclosure, if the verification result of the credential declaration indicates that it has passed, it means that the credential of control of the goods was indeed generated by the issuing agency 140 and the content of the credential is true and complete.

[0143] S4332: Generate the verification result of the transfer verifiable expression based on the verification result of the voucher signature and the verification result of the voucher declaration.

[0144] In the embodiments of this disclosure, after both the credential signature verification result and the credential declaration verification result have passed verification, the validity of the credential is further verified, and finally a transferable verifiable expression verification result is generated. As shown in Figure 13, step S4332 includes:

[0145] S43321: In response to the verification results of the document signature verification and the document statement verification, indicating that the verification has passed, the issuing authority 140 generates a document control document digest value based on the document control document. The issuing authority 140 may perform a hash calculation on the content of the document control document to obtain the document digest value.

[0146] S43322: Issuing authority 140 obtains status information from credential verification data permission chain 160 based on the credential control certificate digest value. Issuing authority 140 sends the credential control certificate digest value to credential verification data permission chain 160, which queries based on the credential control certificate digest value to obtain the certificate's status information. The status information stored on credential verification data permission chain 160 includes normal status, revoked status, etc.

[0147] S43323: The issuing agency 140 determines that the status of the item control certificate is normal based on the status information, and generates a verification expression indicating that the verification has been passed.

[0148] Multiple verifications ensure the reliability of the transfer verifiable expression verification, thus guaranteeing the reliability of the credential transfer.

[0149] S440: The issuing authority responds to the transfer verifiable expression verification result indicating that the verification has passed and generates a certificate of control of the transferred goods for the recipient of the goods.

[0150] In this embodiment of the disclosure, after the verification result of the transfer verifiable expression indicates that the verification has passed, a certificate of control of the transferred items can also be generated according to the user's wishes, as shown in Figure 14. Step S440 includes:

[0151] S441: The issuing agency 140 pushes a confirmation response of the transferred item control certificate to the item recipient application terminal 130;

[0152] S442: The item recipient application terminal 130 generates a confirmation operation based on the confirmation response of the transferred item control certificate and sends the confirmation operation to the issuing authority 140. The confirmation operation includes the item recipient's distributed identity identifier.

[0153] In the embodiments of this disclosure, the distributed identity identifier of the item recipient is generated by the distributed identity system 150 based on the item recipient's public key and sent to the item recipient. The distributed identity system 150 also generates a distributed identity identifier document corresponding to the item recipient's distributed identity identifier based on the item recipient's public key and the item recipient's identifier.

[0154] In some embodiments of this disclosure, the item recipient's application terminal is equipped with a digital wallet application and a security unit. The item recipient's public key and corresponding private key are generated by the security unit. The item recipient's public key is transmitted to the distributed identity system through the digital wallet application, and the item recipient's private key is kept by the security unit.

[0155] S443: The issuing authority 140 generates a post-transfer item control certificate based on the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority. The post-transfer item control certificate includes a declaration part and a signature part generated by signing the declaration part with the private key of the issuing authority. The declaration part includes the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority.

[0156] In some embodiments of this disclosure, transaction-by-transaction traceability is possible. The declaration portion of the item control certificate also includes a transfer record, and the declaration portion of the post-transfer item control certificate also includes a post-transfer transfer record. Step S443 further includes generating a post-transfer transfer record based on the transfer record and transfer request information. This achieves dynamic traceability, updating the transfer record in the certificate according to each transfer.

[0157] For example, if the transfer record is: A transfers to B on May 9, 2021, and the transfer request information is: B requests to transfer to C on July 19, 2024, then the transfer record after the transfer will be: A transfers to B on May 9, 2021; B transfers to C on July 19, 2024.

[0158] In some embodiments of this disclosure, the declaration portion of the article control certificate also includes maintenance data, and the declaration portion of the transferred article control certificate also includes post-transfer maintenance data; step S443 further includes: generating post-transfer maintenance data based on the maintenance data. Since the transfer of the certificate does not involve updating the maintenance data, the post-transfer maintenance data is consistent with the pre-transfer maintenance data.

[0159] S450: The issuing authority 140 sends the transferred item control certificate to the item recipient application terminal 130.

[0160] S460: The receiving party's application terminal 130 stores the certificate of control of the transferred items.

[0161] In some embodiments of this disclosure, the item recipient's application terminal 130 stores the transferred item control certificate in a digital wallet application or secure unit, ensuring secure storage of the certificate.

[0162] In some embodiments of this disclosure, after verifying the authenticity, completeness, and validity of the credentials, the credentials can be revoked to prevent multiple transfers of control and limit fraudulent transactions. As shown in Figure 15, the transfer method in this disclosure further includes:

[0163] S470: In response to the transfer of the verifiable expression indicating successful verification, the issuing authority 140 sets the status of the credential of control of the goods to revoked; based on the credential of control of the goods digest value and the status, it updates the status information on the credential verification data permission chain. Subsequent verification of this credential will display the credential as revoked.

[0164] In some embodiments of this disclosure, to allow other parties to verify the validity of the certificate of control over the transferred goods, as shown in Figure 16, the transfer method further includes:

[0165] S480: The issuing authority 140 synchronizes the verification data of the transferred item control certificate to the certificate verification data permission chain 160, wherein the verification data includes the digest value and status information of the transferred item control certificate. The certificate verification data permission chain 160 stores the hash value, type, validity period, revocation status, etc. of the transferred item control certificate.

[0166] As shown in Figure 17, the item owner application terminal 110 generates a verifiable expression for the transfer of item control rights based on the locally stored item control rights certificate and the transfer request information filled in by the user. After the item recipient application terminal 130 obtains the verifiable expression for the transfer of item control rights, the user clicks the "Item Control Rights Transfer Request" button on the digital wallet page, which sends the item control rights transfer request to the issuing authority 140. After the issuing authority 140 verifies the verifiable expression for the transfer of item control rights, it pushes a confirmation response for the transferred item control rights certificate to the item recipient application terminal 130. The user clicks the "Confirm to Obtain Transferred Certificate" button on the page, and the item recipient application terminal 130 sends the confirmation operation to the issuing authority 140. After the issuing authority 140 generates the transferred item control rights certificate, it sends the transferred item control rights certificate to the item recipient application terminal 130. The user clicks "Store Certificate" on the interface, and the item recipient application terminal 130 stores the transferred item control rights certificate in the digital wallet application or in the secure unit on the item recipient application terminal 130.

[0167] In this embodiment of the disclosure, the transfer process of the item control certificate is separate from the payment process. That is, the two users can use any online or offline payment method to pay for the item and then transfer the item control certificate, or directly transfer the item control certificate through a gift.

[0168] In this embodiment of the disclosure, the issuing authority can connect with the digital wallet through an SDK interface or a mini-program to realize the issuance and transfer functions of credentials.

[0169] In this embodiment of the disclosure, the registration method for digital wallets includes, but is not limited to, one or more combinations of methods such as name / ID number verification, mobile phone number SMS verification code, face verification, and fingerprint verification. The registration process may or may not include the issuance of a CA certificate.

[0170] In this embodiment of the disclosure, the security unit for implementing digital wallet-side key management can be a security element (SE), or it can be implemented through a front-end and back-end key collaborative signature technology, or by adopting other cryptographic white-box schemes that meet security requirements.

[0171] In this embodiment of the disclosure, when the issuing authority issues a credential for control of an item (VC) to a user, the issuing authority can directly obtain the user's distributed identity identifier from the application terminal of the item owner or the application terminal of the item recipient, or indirectly query the distributed identity system to obtain the user's distributed identity identifier through the user's mobile phone number or wallet ID returned by the application terminal of the item owner or the application terminal of the item recipient.

[0172] The method for transferring control of goods in this embodiment verifies the authenticity, completeness, and validity of the voucher before transferring it, ensuring the reliability of the voucher transfer and preventing the voucher from being tampered with or forged. It achieves fast and efficient voucher transfer verification without relying on a third-party intermediary platform, improving the efficiency of control transfer and saving transaction costs.

[0173] This disclosure provides a digital wallet-based mechanism for transferring control of goods. Under this mechanism, both parties to a transaction use a distributed identity system and blockchain technology to store, verify, and transfer control certificates based on their respective digital wallet applications. The issuing authority issues control certificates that can bind the digital identity of the goods to both parties and uploads the certificate status data to a permissioned blockchain based on distributed ledger technology. This enables the traceability of goods and the verification of control certificates based on digital wallet devices, while also simplifying the transfer process for the resale of goods and reducing the cost of transferring goods between the two parties.

[0174] In this embodiment, a secure unit integrated with a digital wallet application enables the trusted transfer of control of items. When a user registers with the digital wallet, a unique digital signature key pair is generated through the secure unit, with the private key stored within the unit. When a user holding an item control certificate (VC) transfers the VC through the digital wallet, the digital wallet uses the private key in the secure module to digitally sign the VC, forming a corresponding item control certificate (VP) and item control transfer certificate (VP'). The verifying user and the issuing authority obtain public keys through a distributed identity system. The verifying user performs trusted verification of the VP to confirm the authenticity, validity, and integrity of the VC certificate, as well as the ownership and maintenance status of the item. The issuing authority performs trusted verification of the VP' to confirm the authenticity, validity, and integrity of the VC certificate, as well as the user's intention to transfer the item, thereby executing subsequent certificate transfer operations. The secure module integrated with the digital wallet ensures the exclusivity and control of the user's signature private key, ensuring that any alteration to the signature data can be detected. Compared to the shortcomings of traditional paper certificates, such as ease of forgery, alteration, and portability, this provides a better digital representation and trusted transfer of item control certificates.

[0175] As shown in FIG18, this embodiment of the present disclosure provides an item control right certificate issuing device 500, applied to an issuing agency 140. The device 500 includes an issuing response module 510, a confirmation operation acquisition module 520, a certificate generation module 530, and a sending module 540.

[0176] The issuance response module 510 is configured to respond to an access request for the issuance link of the item control certificate sent by the item owner application terminal, and return an item control certificate issuance response to the item owner application terminal, wherein the item control certificate issuance link is associated with the target item.

[0177] The confirmation operation acquisition module 520 is configured to acquire the confirmation operation generated by the response issued based on the item control certificate sent by the application terminal of the item owner. The confirmation operation includes the distributed identity identifier of the item owner.

[0178] The credential generation module 530 is configured to generate an item control certificate for the target item, wherein the item control certificate for the target item includes information about the target item and a distributed identity identifier of the item owner.

[0179] The sending module 540 is configured to send the item control certificate to the application terminal of the item owner.

[0180] In some embodiments of this disclosure, the credential for control of an item includes a declaration portion and a signature portion generated by signing the declaration portion; the credential generation module 530 is further configured to:

[0181] The declaration portion is signed using the private key of the issuing authority to generate the signature portion, which includes the identifier of the target item, the distributed identity identifier of the item's owner, and the distributed identity identifier of the issuing authority.

[0182] In some embodiments of this disclosure, the declaration section also includes: maintenance data and / or transfer records of the target item.

[0183] In some embodiments of this disclosure, the identifier of the target item is a distributed identity identifier, which is generated by a distributed identity system based on the unique identifier of the target item. The distributed identity system also generates a distributed identity identifier document corresponding to the distributed identity identifier of the target item based on the attribute data of the target item.

[0184] In some embodiments of this disclosure, the distributed identity identifier of the item owner is generated by the distributed identity system based on the owner's public key and sent to the item owner's application terminal. The distributed identity system also generates a distributed identity identifier document corresponding to the item owner's distributed identity identifier based on the item owner's public key and the item owner's identifier.

[0185] In some embodiments of this disclosure, the application terminal of the item owner is equipped with a digital wallet application and a security unit. The public key and the corresponding private key of the item owner are generated by the security unit. The public key of the item owner is transmitted to the distributed identity system through the digital wallet application, and the private key of the item owner is kept by the security unit.

[0186] In some embodiments of this disclosure, the item control certificate is stored within a digital wallet application or a secure unit.

[0187] In some embodiments of this disclosure, the apparatus further includes a verification data synchronization module 550 configured to synchronize the verification data of the item control certificate to the certificate verification data permission chain, wherein the verification data includes an item control certificate digest value and status information.

[0188] As shown in FIG19, this embodiment of the present disclosure provides an item control credential verification device 600, applied to a verification party application terminal. The device 600 includes a verifiable expression acquisition module 610 and a verification result generation module 620. The verifiable expression acquisition module 610 is configured to acquire an item control credential verification expression of a target item sent by the item owner application terminal. The item control credential verification expression includes an item control credential of the target item stored in the item owner application terminal and a credential signature generated by signing the item control credential with the item owner's private key. The item control credential includes a declaration portion and a signature portion generated by signing the declaration portion with the issuing authority's private key. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item owner, and the distributed identity identifier of the issuing authority. The verification result generation module 620 is configured to verify the item control credential verification expression and generate a control credential verification result.

[0189] In some embodiments of this disclosure, the verification result generation module 620 is configured as follows:

[0190] The public key of the item owner is obtained from the distributed identity system based on the distributed identity identifier of the item owner;

[0191] The public key of the item owner is used to verify the credential signature, and a credential signature verification result is generated.

[0192] Generate control credential verification results based on credential signature verification results.

[0193] In some embodiments of this disclosure, the verification result generation module 620 is further configured to:

[0194] In response to the credential signature verification result indicating successful verification, the public key of the issuing authority is obtained from the distributed identity system based on the distributed identity identifier of the issuing authority;

[0195] The signature is verified using the public key of the issuing authority, and a credential statement verification result is generated.

[0196] The control document verification result is generated based on the document signature verification result and the document declaration verification result.

[0197] In some embodiments of this disclosure, the verification result generation module 620 is further configured to:

[0198] In response to the verification results of the document signature verification and the document statement verification, indicating that the verification is successful, generate a document control document digest value based on the document control document;

[0199] Retrieve status information from the credential verification data permission chain based on the credential control document digest value;

[0200] Based on the status information, if the status of the item control certificate is determined to be normal, a control certificate verification result indicating that the verification has passed is generated.

[0201] In some embodiments of this disclosure, the identifier of the target item is a distributed identity identifier of the target item, and the device 600 further includes a display module 630 configured as follows:

[0202] In response to the control credential verification result indicating successful verification, the system retrieves the target item's attribute data from the distributed identity system based on the target item's distributed identity identifier and displays the attribute data.

[0203] In some embodiments of this disclosure, the declaration section also includes transfer records of the target item and / or maintenance data of the target item, and the display module 630 is further configured to:

[0204] In response to the verification result of the control certificate indicating that the verification is successful, the transfer record of the target item and / or the maintenance data of the target item are displayed.

[0205] In some embodiments of this disclosure, the verification application terminal obtains the verifiable expression of control of the target item from the item owner application terminal via a near-field communication protocol; or, the verification application terminal obtains the verifiable expression of control of the target item by scanning the QR code generated by the item owner application terminal based on the verifiable expression of control of the target item.

[0206] As shown in FIG20, this embodiment of the present disclosure provides an item control certificate transfer device 700, which is applied to an issuing authority. The device 700 includes a transfer application acquisition module 710, a verification module 720, a certificate generation module 730, and a sending module 740. The transfer application acquisition module 710 is configured to receive an item control transfer application sent by the item recipient's application terminal. The item control transfer application includes a verifiable expression for the transfer of item control of the target item. The verifiable expression for the transfer of item control includes the item control certificate of the target item, transfer request information, and a transfer certificate signature generated by the item owner's application terminal.

[0207] The verification module 720 is configured to verify the verifiable representation of the transfer of control of an item and generate a verification result of the transfer verifiable representation.

[0208] The voucher generation module 730 is configured to respond to a transfer verifiable expression indicating that the verification has passed and to generate a post-transfer item control voucher for the item recipient.

[0209] The sending module 740 is configured to send the transferred item control certificate to the item recipient.

[0210] In some embodiments of this disclosure, the item control transfer verifiable expression is generated by the item owner's application terminal based on the item control certificate and transfer request information and sent to the item recipient's application terminal.

[0211] In some embodiments of this disclosure, the item control certificate includes a declaration portion and a signature portion generated by signing the declaration portion with the private key of the issuing authority. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item owner, and the distributed identity identifier of the issuing authority; the verification module 720 is configured as follows:

[0212] The public key of the item owner is obtained from the distributed identity system based on the distributed identity identifier of the item owner;

[0213] The public key of the owner of the item is used to verify the signature of the transfer certificate, and a certificate signature verification result is generated;

[0214] Generate a transfer verifiable expression verification result based on the credential signature verification result.

[0215] In some embodiments of this disclosure, the verification module 720 is further configured to:

[0216] In response to the credential signature verification result indicating that the verification has passed, the signature portion is verified based on the issuing authority's public key, and a credential statement verification result is generated;

[0217] The verification result of the transfer verifiable expression is generated based on the verification result of the credential signature and the verification result of the credential statement.

[0218] In some embodiments of this disclosure, the verification module 720 is further configured to:

[0219] In response to the verification results of the document signature verification and the document statement verification, indicating that the verification is successful, generate a document control document digest value based on the document control document;

[0220] Retrieve status information from the credential verification data permission chain based on the credential control document digest value;

[0221] Based on the status information, if the status of the item control certificate is determined to be normal, a transfer verifiable expression indicating that the verification has passed is generated to verify the result.

[0222] In some embodiments of this disclosure, the apparatus 700 further includes a credential revocation module 750, configured as follows:

[0223] In response to the transfer of the verifiable expression verification result indicating that the verification has passed, the status of the item control certificate is set to the revoked status; based on the item control certificate digest value and status, the status information on the certificate verification data permission chain is updated.

[0224] In some embodiments of this disclosure, the credential for control of an item includes a declaration portion and a signature portion generated by signing the declaration portion with the private key of the issuing authority. The declaration portion includes an identifier of the target item, a distributed identity identifier of the item's owner, and a distributed identity identifier of the issuing authority. The credential generation module 730 is configured as follows:

[0225] After the transfer is pushed, the confirmation of the item control certificate is sent to the item recipient's application terminal.

[0226] The receiving party's application terminal generates a confirmation operation based on the confirmation response of the transferred item control certificate. The confirmation operation includes the item recipient's distributed identity identifier.

[0227] Based on the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority, a post-transfer item control certificate is generated. The post-transfer item control certificate includes a declaration part and a signature part generated by signing the declaration part with the private key of the issuing authority. The declaration part includes the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority.

[0228] In some embodiments of this disclosure, the declaration portion of the article control certificate further includes a transfer record, and the declaration portion of the transferred article control certificate further includes a transfer record after the transfer; the certificate generation module 730 is also configured to:

[0229] Based on the transfer record and transfer request information, generate a post-transfer record.

[0230] In some embodiments of this disclosure, the declaration portion of the article control certificate further includes maintenance data, and the declaration portion of the transferred article control certificate further includes post-transfer maintenance data; the certificate generation module 730 is also configured to:

[0231] Post-transfer maintenance data is generated based on the maintenance data.

[0232] In some embodiments of this disclosure, the apparatus 700 further includes a verification data synchronization module 760, configured to synchronize the verification data of the transferred item control certificate to the certificate verification data permission chain, wherein the verification data includes the transferred item control certificate summary value and status information.

[0233] As shown in FIG21, this embodiment of the present disclosure provides an item control certificate transfer device 800, which is applied to the item recipient's application terminal. The device 800 includes a transfer application module 810 and a certificate receiving module 820. The transfer application module 810 is configured to send an item control transfer application to the issuing authority. The item control transfer application includes an item control transfer verifiable expression for the target item. The item control transfer verifiable expression includes the item control certificate of the target item, transfer request information, and a transfer certificate signature generated by the item owner's application terminal.

[0234] The credential receiving module 820 is configured to receive the transferred item control certificate sent by the issuing authority. The transferred item control certificate is generated by the issuing authority after verifying the verifiable expression of the transfer of item control and obtaining the verification result after the verification is successful.

[0235] In some embodiments of this disclosure, the apparatus 800 further includes an acquisition module 830 configured to acquire, before sending an application for transfer of control of the item to the issuing authority, a verifiable expression for the transfer of control of the item generated by the application terminal of the item owner based on the item control certificate and the transfer request information.

[0236] In some embodiments of this disclosure, the credential receiving module 820 is configured as follows:

[0237] Obtain the confirmation response of the transferred item control certificate pushed by the issuing authority. The confirmation response of the transferred item control certificate is generated by the issuing authority after verifying the verifiable expression of the transfer of item control.

[0238] Send a confirmation operation generated based on the confirmation response of the transferred item control certificate to the issuing authority, wherein the confirmation operation includes the distributed identity of the item recipient;

[0239] The recipient receives a transferred item control certificate sent by the issuing authority. The transferred item control certificate includes a declaration portion and a signature portion generated by signing the declaration portion with the issuing authority's private key. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority.

[0240] In some embodiments of this disclosure, the declaration portion of the article control certificate also includes a transfer record, and the declaration portion of the article control certificate after transfer also includes a post-transfer transfer record, which is generated by the issuing authority based on the transfer record and transfer request information.

[0241] In some embodiments of this disclosure, the distributed identity identifier of the item recipient is generated by the distributed identity system based on the item recipient's public key and sent to the item recipient. The distributed identity system also generates a distributed identity identifier document corresponding to the item recipient's distributed identity identifier based on the item recipient's public key and the item recipient's identifier.

[0242] In some embodiments of this disclosure, the item recipient's application terminal is equipped with a digital wallet application and a security unit. The item recipient's public key and corresponding private key are generated by the security unit. The item recipient's public key is transmitted to the distributed identity system through the digital wallet application, and the item recipient's private key is kept by the security unit.

[0243] In some embodiments of this disclosure, the device 800 further includes a credential storage module 840 configured to store transferred item control credentials in a digital wallet application or a secure unit.

[0244] The device features of the embodiments of this disclosure can be referenced to the features of the methods and steps of the embodiments of this disclosure, and the system embodiments can be combined with the features of the method embodiments to obtain new embodiments, and vice versa, and will not be repeated here.

[0245] An embodiment of this disclosure provides an electronic device including a processor and a memory storing a computer program, the processor being configured to implement a method for issuing, verifying, and transferring article control credentials according to any embodiment of this disclosure when running the computer program. Additionally, apparatus for implementing the issuance, verification, and transfer of article control credentials according to embodiments of this disclosure may also be provided.

[0246] Figure 22 illustrates an exemplary system architecture 1100 for the article control certificate issuance, verification, and transfer method or apparatus that can be applied to embodiments of this disclosure.

[0247] As shown in Figure 22, the system architecture 1100 may include terminal devices 1101, 1102, and 1103, a network 1104, and a server 1105. The network 1104 serves as the medium for providing communication links between the terminal devices 1101, 1102, and 1103 and the server 1105. The network 1104 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0248] Users can use terminal devices 1101, 1102, and 1103 to interact with server 1105 via network 1104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 1101, 1102, and 1103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0249] Terminal devices 1101, 1102, and 1103 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0250] Server 1105 can be a server that provides various services, such as a backend management server that supports shopping websites browsed by users using terminal devices 1101, 1102, and 1103 (for example only). The backend management server can analyze and process data such as received product information query requests, and feed back the processing results (such as target push information and product information - for example only) to the terminal devices.

[0251] It should be noted that the methods for applying for identity credentials and issuing property control credentials provided in this embodiment are generally executed by server 1105, and correspondingly, the implementation device for applying for identity credentials and issuing property control credentials is generally located in server 1105.

[0252] It should be understood that the number of terminal devices, networks, and servers shown in Figure 22 is merely illustrative. Any number of terminal devices, networks, and servers can be used depending on implementation needs.

[0253] Referring now to FIG23, a schematic diagram of the structure of a computer system 1200 suitable for implementing a terminal device or server in the embodiments of the present disclosure is shown. The methods or apparatus for implementing the methods in the embodiments of the present disclosure can be implemented on the computer system 1200. The terminal device or server shown in FIG23 is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present disclosure.

[0254] As shown in Figure 23, the computer system 1200 includes a central processing unit (CPU) 1201, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 1202 or programs loaded from storage section 1208 into random access memory (RAM) 1203. The RAM 1203 also stores various programs and data required for the operation of the system 1200. The CPU 1201, ROM 1202, and RAM 1203 are interconnected via bus 1204. An input / output (I / O) interface 1205 is also connected to bus 1204.

[0255] The following components are connected to I / O interface 1205: an input section 1206 including a keyboard, mouse, etc.; an output section 1207 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1208 including a hard disk, etc.; and a communication section 1209 including a network interface card such as a LAN card, modem, etc. The communication section 1209 performs communication processing via a network such as the Internet. A drive 1210 is also connected to I / O interface 1205 as needed. Removable media 1211, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 1210 as needed so that computer programs read from them can be installed into storage section 1208 as needed.

[0256] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1209, and / or installed from removable medium 1211. When the computer program is executed by central processing unit (CPU) 1201, it performs the functions defined above in the system of this disclosure.

[0257] It should be noted that the computer-readable medium disclosed herein may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0258] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0259] The units or modules described in the embodiments of this disclosure can be implemented in software or hardware. The described units or modules can also be housed in a processor; for example, a processor can be described as including a sending unit (or "module"), an acquisition unit, a determining unit, and a first processing unit. The names of these units or modules do not necessarily limit the specific unit or module itself; for example, a sending unit can also be described as "a unit that sends an image acquisition request to a connected server."

[0260] In another aspect, this disclosure also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to perform the identity credential application and item control credential issuance methods described in the above embodiments.

[0261] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure. Industrial applicability

[0262] The solution provided in this disclosure can be applied to the field of computer technology. In this disclosure, the user who owns the item sends a grant link access request to the granting authority through the item owner's application terminal. The granting authority generates a grant response and returns it to the item owner's application terminal. After the item owner's application terminal confirms the application credential, the granting authority generates an item control certificate for the target item based on the information of the target item and the distributed identity identifier of the owner, and sends the certificate to the item owner's application terminal. By generating a verifiable certificate associated with the distributed identity identifier, it is easier to verify the control of the item in subsequent transactions, ensuring the reliability of the item's origin and improving the reliability of peer-to-peer transactions. The user who owns the item signs the item control certificate using their private key through the item owner's application terminal, generating a certificate signature. Based on the item control certificate and certificate signature, a verifiable expression of item control is generated and sent to the verification application terminal. The verification application terminal verifies the verifiable expression of item control based on the distributed identity identifier of the owner and the distributed identity identifier of the granting authority in the item control certificate, generating a verification result. By employing distributed identity identifiers, an efficient and reliable method for verifying the ownership of goods is achieved, improving transaction efficiency in the secondary sale of goods. The buyer can quickly verify the ownership and origin of the goods without relying on a third-party intermediary platform. In this embodiment, the application terminal of the goods owner generates a transfer verifiable expression based on the ownership certificate and transfer request information, and sends the transfer verifiable expression to the application terminal of the goods recipient. The application terminal of the goods recipient organizes a transfer application based on the transfer verifiable expression and sends it to the issuing authority. The issuing authority verifies various signatures in the transfer verifiable expression based on the distributed identity identifier. After successful verification, it generates a post-transfer ownership certificate for the target goods based on the information of the goods recipient and sends the post-transfer ownership certificate to the goods recipient, thus realizing the transfer of ownership. During the transfer of ownership, the distributed identity identifier enables fast and reliable verification of ownership. After successful verification, a post-transfer ownership certificate can be generated based on the transaction request. This simplifies the transfer procedure for the secondary sale of goods and reduces the cost of goods transfer between the two parties.

Claims

1. An item control right certificate issuing method applied to an issuing party, the method comprising the steps of: in response to an access request of an item control right credential issuance link transmitted by the item owner application terminal, returning an item control right credential issuance response to the item owner application terminal, wherein associating the item control right certificate issuing link with a target item; acquiring a confirmation operation sent by an application terminal of an item owner according to a response to the item control right certificate issuing, wherein the confirmation operation comprises a distributed identity of the item owner; generating an item control right certificate of the target item, wherein the item control right certificate of the target item comprises an identity of the target item and the distributed identity of the item owner; sending the item control right certificate to the application terminal of the item owner.

2. The method of claim 1, wherein, The item control right certificate comprises a statement part and a signature part generated by signing the statement part, and the step of generating the item control right certificate of the target item comprises: signing the statement part with a private key of the issuing party to generate the signature part, wherein the statement part comprises the identity of the target item, the distributed identity of the item owner, and a distributed identity of the issuing party.

3. The method of claim 2, wherein, The statement part further comprises maintenance data of the target item and / or transfer records.

4. The method of claim 2, wherein, The identity of the target item is a distributed identity, and the distributed identity of the target item is generated by a distributed identity system according to a unique identity of the target item, wherein the distributed identity system further generates a distributed identity document corresponding to the distributed identity of the target item according to attribute data of the target item.

5. The method of claim 1, wherein, The distributed identity of the item owner is generated by the distributed identity system according to a public key of the item owner and sent to the application terminal of the item owner, wherein the distributed identity system further generates a distributed identity document corresponding to the distributed identity of the item owner according to the public key of the item owner and an identity of the item owner.

6. The method of claim 5, wherein, The application terminal of the item owner is provided with a digital wallet application and a security unit, the public key of the item owner and a corresponding private key are generated by the security unit, the public key of the item owner is transmitted to the distributed identity system through the digital wallet application, and the private key of the item owner is kept by the security unit.

7. The method of claim 6, wherein, The item control right certificate is stored in the digital wallet application or the security unit.

8. The method of claim 1, wherein, The method further comprises: synchronizing verification data of the item control right certificate to a certificate verification data permission chain, wherein the verification data comprises an item control right certificate digest value and state information.

9. An item control right certificate verification method applied to a verification party application terminal, the method comprising the steps of: Obtaining an item control right verifiable expression of a target item sent by an item ownership application terminal, wherein the item control right verifiable expression comprises an item control right certificate of the target item stored by the item ownership application terminal and a certificate signature generated by signing the item control right certificate with a private key of the item ownership, and the item control right certificate comprises a statement part and a signature part generated by signing the statement part with a private key of an issuing party institution, and the statement part comprises an identification of the target item, a distributed identity of the item ownership and a distributed identity of the issuing party institution; Verifying the item control right verifiable expression to generate a control right certificate verification result.

10. The method of claim 9, wherein, The verifying the item control right verifiable expression to generate a control right certificate verification result comprises: Obtaining a public key of the item ownership from a distributed identity system according to the distributed identity of the item ownership; Verifying the certificate signature with the public key of the item ownership to generate a certificate signature verification result; Generating the control right certificate verification result according to the certificate signature verification result.

11. The method of claim 10, wherein, The generating the control right certificate verification result according to the certificate signature verification result comprises: In response to the certificate signature verification result indicating that the verification is passed, obtaining a public key of the issuing party institution from a distributed identity system according to the distributed identity of the issuing party institution; Verifying the signature part with the public key of the issuing party institution to generate a certificate statement verification result; Generating the control right certificate verification result according to the certificate signature verification result and the certificate statement verification result.

12. The method of claim 11, wherein, The generating the control right certificate verification result according to the certificate signature verification result and the certificate statement verification result further comprises: In response to the certificate signature verification result and the certificate statement verification result indicating that the verification is passed, generating an item control right certificate digest value according to the item control right certificate; Obtaining state information from a certificate verification data permission chain according to the item control right certificate digest value; Determining that the item control right certificate state is normal according to the state information, and generating a control right certificate verification result indicating that the verification is passed.

13. The method of claim 10, wherein, The identification of the target item is a distributed identity of the target item, and the method further comprises: In response to the control right certificate verification result indicating that the verification is passed, obtaining attribute data of the target item from a distributed identity system according to the distributed identity of the target item, and displaying the attribute data.

14. The method of claim 10, wherein, The statement part further comprises transfer records of the target item and / or maintenance data of the target item, and the method further comprises: In response to the control right certificate verification result indicating that the verification is passed, displaying the transfer records of the target item and / or the maintenance data of the target item.

15. The method of claim 9, wherein, The verification party application terminal obtains the item control right verifiable expression of the target item from the item ownership party application terminal through a near field communication protocol; or the verification party application terminal obtains the item control right verifiable expression of the target item by scanning a two-dimensional code generated by the item ownership party application terminal according to the item control right verifiable expression of the target item.

16. An item control right certificate transfer method applied to an issuing party institution, the method comprising: receiving an item control right transfer application sent by an item acceptor application terminal, wherein the item control right transfer application comprises an item control right transfer verifiable expression of a target item, and the item control right transfer verifiable expression comprises an item control right certificate of the target item, transfer request information, and a transfer certificate signature generated by an item ownership party application terminal; verifying the item control right transfer verifiable expression to generate a transfer verifiable expression verification result; in response to the transfer verifiable expression verification result indicating that the verification is passed, generating a post-transfer item control right certificate for the item acceptor; sending the post-transfer item control right certificate to the item acceptor application terminal.

17. The method of claim 16, wherein, The item control right transfer verifiable expression is generated by the item ownership party application terminal according to the item control right certificate and the transfer request information and is sent to the item acceptor application terminal.

18. The transfer method according to claim 16, wherein, The item control right certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the issuing party institution, the statement part comprises an identity of the target item, a distributed identity of the item ownership party, and a distributed identity of the issuing party institution; and the verifying the item control right transfer verifiable expression to generate a transfer verifiable expression verification result comprises: obtaining a public key of the item ownership party from a distributed identity system according to the distributed identity of the item ownership party; verifying the transfer certificate signature with the public key of the item ownership party to generate a certificate signature verification result; generating the transfer verifiable expression verification result according to the certificate signature verification result.

19. The method of claim 18, wherein, The generating the transfer verifiable expression verification result according to the certificate signature verification result comprises: in response to the certificate signature verification result indicating that the verification is passed, verifying the signature part with a public key of the issuing party institution to generate a certificate statement verification result; generating the transfer verifiable expression verification result according to the certificate signature verification result and the certificate statement verification result.

20. The method of claim 19, wherein, The generating the transfer verifiable expression verification result according to the certificate signature verification result and the certificate statement verification result further comprises: in response to the certificate signature verification result and the certificate statement verification result indicating that the verification is passed, generating an item control right certificate digest value according to the item control right certificate; obtaining state information from a certificate verification data permission chain according to the item control right certificate digest value; determining that the item control right certificate state is normal according to the state information to generate a transfer verifiable expression verification result indicating that the verification is passed.

21. The method of claim 20, wherein, The method further comprises: In response to the verification result indicating that the transfer is successful, the status of the item control certificate is set to revocation; the status information on the certificate verification data permission chain is updated according to the item control certificate digest value and status.

22. The method of claim 16, wherein, The item control certificate includes a declaration portion and a signature portion generated by signing the declaration portion with the private key of the issuing authority. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item owner, and the distributed identity identifier of the issuing authority. The process of generating a certificate of control over the transferred goods for the recipient includes: After the transfer is pushed, a confirmation response of the item control certificate is sent to the application terminal of the item recipient. The application terminal of the recipient of the item receives a confirmation operation generated based on the confirmation response of the transferred item control certificate, wherein the confirmation operation includes the distributed identity identifier of the recipient of the item; Based on the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority, a post-transfer item control certificate is generated. The post-transfer item control certificate includes a declaration portion and a signature portion generated by signing the declaration portion with the private key of the issuing authority. The declaration portion includes the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority.

23. The method of claim 22, wherein, The declaration portion of the item control certificate also includes a transfer record, and the declaration portion of the transferred item control certificate also includes a post-transfer transfer record; the generation of the transferred item control certificate based on the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority includes: The post-transfer record is generated based on the transfer record and the transfer request information.

24. The method of claim 22 or 23, wherein, The declaration portion of the item control certificate also includes maintenance data, and the declaration portion of the transferred item control certificate also includes post-transfer maintenance data; the generation of the transferred item control certificate based on the identifier of the target item, the distributed identity identifier of the item recipient, and the distributed identity identifier of the issuing authority includes: The post-transfer maintenance data is generated based on the maintenance data.

25. The method of claim 16, wherein, The method further includes: The verification data of the transferred item control certificate is synchronized to the certificate verification data permission chain, wherein the verification data includes the summary value and status information of the transferred item control certificate.

26. An article of control right certificate transfer method, wherein, The method, applied to an application terminal of a recipient of goods, includes: Send an application for transfer of control of an item to the issuing authority, wherein the application for transfer of control of an item includes a verifiable expression for the transfer of control of the target item, and the verifiable expression for the transfer of control of an item includes an item control certificate of the target item, transfer request information, and a signature of the transfer certificate generated by the application terminal of the item owner; receiving a post-transfer item control right credential sent by the issuing authority, wherein the post-transfer item control right credential is generated by the issuing authority after verifying the item control right transfer verifiable expression and passing the verification.

27. The method of claim 26, wherein, Before sending the item control right transfer application to the issuing authority, the method further comprises: obtaining the item control right transfer verifiable expression generated by the item owner application terminal according to the item control right credential and the transfer request information.

28. The method of claim 26, wherein, The receiving of the post-transfer item control right credential sent by the issuing authority comprises: obtaining a post-transfer item control right credential confirmation response pushed by the issuing authority, wherein the post-transfer item control right credential confirmation response is generated by the issuing authority after verifying the item control right transfer verifiable expression and passing the verification; sending a confirmation operation generated according to the post-transfer item control right credential confirmation response to the issuing authority, wherein the confirmation operation comprises a distributed identity of the item receiver; receiving the post-transfer item control right credential sent by the issuing authority, wherein the post-transfer item control right credential comprises a statement part and a signature part generated by signing the statement part with a private key of the issuing authority, and the statement part comprises an identity of the target item, a distributed identity of the item receiver, and a distributed identity of the issuing authority.

29. The method of claim 28, wherein, The statement part of the item control right credential further comprises a transfer record, and the statement part of the post-transfer item control right credential further comprises a post-transfer transfer record, which is generated by the issuing authority according to the transfer record and the transfer request information.

30. The method of claim 26, wherein, The distributed identity of the item receiver is sent to the item receiver by the distributed identity system according to the public key of the item receiver, and the distributed identity system further generates a distributed identity document corresponding to the distributed identity of the item receiver according to the public key of the item receiver and the identity of the item receiver.

31. The method of claim 30, wherein the item receiver application terminal is provided with a digital wallet application and a security unit, the public key of the item receiver and the corresponding private key are generated by the security unit, the public key of the item receiver is transmitted to the distributed identity system through the digital wallet application, and the private key of the item receiver is kept by the security unit.

32. The method of claim 31, wherein, The method further comprises: storing the post-transfer item control right credential in the digital wallet application or the security unit.

33. An electronic device, comprising: one or more processors; a storage device configured to store one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1-32.

34. A computer readable medium having stored thereon a computer program, which program, when executed by a processor, implements the method of any one of claims 1-32.

Citation Information

Patent Citations

  • Identity authentication method, certificate holding system and verification system

    CN113918899A

  • Method and device for performing certificate management in block chain, terminal and storage medium

    CN114282270A

  • Block chain-based information interaction method and device, storage medium and electronic equipment

    CN117521148A

  • Generation method and device of digital creditor's right certificate, computer equipment and storage medium

    CN117557360A

  • Identity verification method and system, storage medium, and chip

    WO2024140274A1