Identity credential application method and apparatus, and identity credential verification method and apparatus

By combining near-field communication and biometrics for identity verification, the problem of cumbersome and insecure existing identity recognition methods has been solved. This enables real-person, real-verification identity credential application and verification, improves the reliability of identity credentials and user convenience, and supports secure sharing among multiple institutions.

WO2026051866A1PCT designated stage Publication Date: 2026-03-12THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST +1
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing digital identity verification methods are cumbersome and insecure, requiring users to submit information frequently, making it easy for black market technologies to be leaked, and causing significant differences in data formats between institutions, making information sharing difficult and affecting business efficiency and security.

Method used

By reading external identity document information and collecting biometric features through near-field communication, a second identity verification is initiated. After the issuer verifies the identity, a distributed identity identifier is applied for and an identity credential is generated, which supports real-person and real-document verification and enables secure sharing of identity credentials among multiple institutions.

Benefits of technology

It improves the reliability and user convenience of identity credentials, reduces redundant identity verification, optimizes customer experience, and meets the identity authentication needs of multiple organizations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025117994_12032026_PF_FP_ABST
    Figure CN2025117994_12032026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in embodiments of the present invention are an identity credential application method and an identity credential verification method. The identity credential application method comprises: an applicant terminal sends a second identity verification request to an issuer, and the issuer generates a second identity verification result on the basis of the second identity verification request; the applicant terminal determines, on the basis of the second identity verification result sent by the issuer, that the identity verification of an applicant passes, sends a distributed identity activation request to a distributed identity system, and receives a distributed identity identifier of the applicant from the distributed identity system; the applicant terminal sends an identity credential application request to the issuer or the issuer generates an applicant identity credential and uploads verification data of the applicant identity credential to a credential permission chain, and the issuer generates the applicant identity credential; and the applicant terminal receives the applicant identity credential from the issuer. The identity credential verification method comprises: a verifier receives an identity verification request sent by the applicant terminal; the verifier verifies a verifiable presentation of the identity credential to generate a credential verification result; and the verifier sends the credential verification result to the applicant terminal. On the basis of ensuring the security of identity information, the operation of a user repeatedly submitting the identity information is reduced, thereby improving the user experience. Also provided are corresponding apparatuses, an electronic device, and a computer-readable medium.
Need to check novelty before this filing date? Find Prior Art

Description

Identity credential application, verification method and device

[0001] The present application claims priority to Chinese Patent Application No. 202411244522.6, filed on September 5, 2024, entitled "Identity credential application method and device", Chinese Patent Application No. 202411244592.1, filed on September 5, 2024, entitled "Identity credential verification method and device", Chinese Patent Application No. 202411246451.3, filed on September 5, 2024, entitled "Identity credential application method and device", and Chinese Patent Application No. 202411245192.2, filed on September 5, 2024, entitled "Identity credential verification method and device", all of which are incorporated herein by reference in their entirety. TECHNICAL FIELD

[0002] The present application relates to the technical field of computer, and in particular to an identity credential application method and device, an identity credential verification method and device, an electronic device and a computer readable medium. BACKGROUND

[0003] In the financial field, identity verification and customer identification (KYC) are key links to ensure transaction security and compliance.

[0004] The current common way of digital identity recognition is through SMS verification code, inputting identity information, and face verification. With the development of technology, this identity recognition method becomes increasingly cumbersome and insecure. First, users need to frequently and repeatedly submit identity information in different scenarios and businesses, which not only increases the time cost of users, but also reduces the overall efficiency of services. Second, with the development of black and gray production technology, SMS verification code, identity, and face information are vulnerable to leakage, and the reliability of simple face verification is also declining, and the situation of using stolen identities to handle business is common. In addition, there may be significant differences in technical architecture and data format between different financial institutions and systems, making the sharing and interconnection of digital identity information particularly difficult, so that information cannot be effectively connected between departments or institutions, which not only increases the complexity of business handling, but also restricts the overall promotion of digital services. SUMMARY

[0005] Therefore, in a first aspect, an identity credential application method is provided, applied to an applicant terminal, and the method comprises:

[0006] send a second identity authentication request to the issuing party to enable the issuing party to generate a second identity authentication result according to the second identity authentication request, wherein the second identity authentication request comprises the identity information of the applicant and the biometric information of the applicant, and the identity information of the applicant is read by the terminal of the applicant from an external identity document through near field communication;

[0007] determine that the identity authentication of the applicant is passed according to the second identity authentication result sent by the issuing party, send a distributed identity opening request to the distributed identity system, and receive the distributed identity identifier of the applicant from the distributed identity system;

[0008] send an identity credential application request to the issuing party to enable the issuing party to generate the identity credential of the applicant, wherein the identity credential application request comprises the distributed identity identifier of the applicant;

[0009] receive the identity credential of the applicant from the issuing party, wherein the identity credential of the applicant comprises a declaration part and a signature part generated by signing the declaration part with a private key of the issuing party, and the declaration part comprises the distributed identity identifier of the applicant and the distributed identity identifier of the issuing party.

[0010] In a second aspect, the embodiment of the present application provides an identity credential application method applied to an issuing party, and the method comprises the following steps:

[0011] receive a second identity authentication request sent by the terminal of the applicant, generate a second identity authentication result according to the second identity authentication request, and send the second identity authentication result to the terminal of the applicant, so that the terminal of the applicant sends a distributed identity opening request to the distributed identity system after determining that the identity authentication of the applicant is passed according to the second identity authentication result, wherein the second identity authentication request comprises the identity information of the applicant and the biometric information of the applicant, and the identity information of the applicant is read by the terminal of the applicant from an external identity document through near field communication;

[0012] receive an identity credential application request sent by the terminal of the applicant, and generate the identity credential of the applicant, wherein the identity credential application request comprises the distributed identity identifier of the applicant, and the distributed identity identifier of the applicant is generated by the distributed identity system after receiving the distributed identity opening request sent by the terminal of the applicant;

[0013] send the identity credential of the applicant to the terminal of the applicant, wherein the identity credential of the applicant comprises a declaration part and a signature part generated by signing the declaration part with a private key of the issuing party, and the declaration part comprises the distributed identity identifier of the applicant and the distributed identity identifier of the issuing party.

[0014] In a third aspect, the embodiment of the present application provides an identity credential application device applied to the terminal of the applicant, and the device comprises a second identity authentication request module, a distributed identity opening request module, an identity credential request module and an identity credential receiving module, wherein the second identity authentication request module is configured to send a second identity authentication request to the issuing party to enable the issuing party to generate a second identity authentication result according to the second identity authentication request, the distributed identity opening request module is configured to determine that the identity authentication of the applicant is passed according to the second identity authentication result sent by the issuing party, send a distributed identity opening request to the distributed identity system, and receive the distributed identity identifier of the applicant from the distributed identity system, the identity credential request module is configured to send an identity credential application request to the issuing party to enable the issuing party to generate the identity credential of the applicant, and the identity credential receiving module is configured to receive the identity credential of the applicant from the issuing party.

[0015] The second identity verification request module is configured to send a second identity verification request to the issuing party, so that the issuing party generates a second identity verification result according to the second identity verification request, wherein the second identity verification request comprises the identity information of the applicant, and the biometric information of the applicant, and the identity information of the applicant is read from an external identity certificate by the terminal of the applicant through a near field communication mode;

[0016] The distributed identity opening request module is configured to determine that the identity verification of the applicant is passed according to the second identity verification result sent by the issuing party, send a distributed identity opening request to the distributed identity system, and receive the distributed identity identifier of the applicant from the distributed identity system;

[0017] The identity credential request module is configured to send an identity credential application request to the issuing party, so that the issuing party generates the identity credential of the applicant, wherein the identity credential application request comprises the distributed identity identifier of the applicant;

[0018] The identity credential receiving module is configured to receive the identity credential of the applicant from the issuing party, wherein the identity credential of the applicant comprises a declaration part and a signature part generated by signing the declaration part by a private key of the issuing party, and the declaration part comprises the distributed identity identifier of the applicant and the distributed identity identifier of the issuing party.

[0019] In a fourth aspect, the embodiment of the present application provides an identity credential application device applied to an issuing party, and the device comprises a second identity verification result generation module, an identity credential generation module and a sending module, wherein,

[0020] The second identity verification result generation module is configured to receive a second identity verification request sent by the terminal of the applicant, generate a second identity verification result according to the second identity verification request, and send the second identity verification result to the terminal of the applicant, so that the terminal of the applicant sends a distributed identity opening request to the distributed identity system after determining that the identity verification of the applicant is passed according to the second identity verification result, wherein the second identity verification request comprises the identity information of the applicant and the biometric information of the applicant, and the identity information of the applicant is read from an external identity certificate by the terminal of the applicant through a near field communication mode;

[0021] The identity credential generation module is configured to receive an identity credential application request sent by the terminal of the applicant, and generate the identity credential of the applicant, wherein the identity credential application request comprises the distributed identity identifier of the applicant, and the distributed identity identifier of the applicant is generated by the distributed identity system after receiving the distributed identity opening request sent by the terminal of the applicant;

[0022] The sending module is configured to send the applicant identity credential to the applicant terminal, wherein the applicant identity credential comprises a statement part and a signature part generated by signing the statement part with a private key of the issuing party, and the statement part comprises the applicant distributed identity and the distributed identity of the issuing party.

[0023] In a fifth aspect, the present application provides an identity credential verification method, applied to a verification party, comprising:

[0024] receiving an identity verification request sent by the applicant terminal, wherein the identity verification request comprises an identity credential verifiable expression, the identity credential verifiable expression comprises identity credential related information and a credential signature generated by signing the identity credential related information with a private key of the applicant, and the identity credential related information comprises an applicant identity credential issued by the issuing party, the applicant identity credential comprises a statement part and a signature part generated by signing the statement part with a private key of the issuing party, and the statement part comprises the applicant distributed identity and the distributed identity of the issuing party, the applicant distributed identity is generated according to a public key of the applicant after the applicant identity information and the applicant biometric information are verified, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode;

[0025] verifying the identity credential verifiable expression to generate a credential verification result;

[0026] sending the credential verification result to the applicant terminal.

[0027] In a sixth aspect, the present application provides an identity credential verification method, applied to an applicant terminal, comprising:

[0028] obtaining identity credential related information stored locally, and generating an identity credential verifiable expression according to the identity credential related information, wherein the identity credential verifiable expression comprises the identity credential related information and a credential signature generated by signing the identity credential related information with a private key of the applicant, and the identity credential related information comprises an applicant identity credential issued by the issuing party, the applicant identity credential comprises a statement part and a signature part generated by signing the statement part with a private key of the issuing party, and the statement part comprises the applicant distributed identity and the distributed identity of the issuing party, the applicant distributed identity is generated according to a public key of the applicant after the applicant identity information and the applicant biometric information are verified, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode;

[0029] sending an identity verification request to the verification party, wherein the identity verification request comprises the identity credential verifiable expression;

[0030] receiving a credential verification result sent by the verification party, the credential verification result is generated by the verification party after verifying the identity credential verifiable expression.

[0031] In a seventh aspect, the present application provides an identity credential verification device, applied to a verification party, comprising an identity verification request receiving module, a verification module and a sending module, wherein,

[0032] The identity verification request receiving module is configured to receive an identity verification request sent by an applicant terminal, wherein the identity verification request comprises an identity credential verifiable expression, the identity credential verifiable expression comprises identity credential related information and a credential signature generated by signing the identity credential related information with an applicant private key, and the identity credential related information comprises an applicant identity credential issued by an issuing party, the applicant identity credential comprises a statement part and a signature part generated by signing the statement part with an issuing party private key, and the statement part comprises an applicant distributed identity and an issuing party distributed identity, the applicant distributed identity is generated according to an applicant public key after the applicant identity information and the applicant biometric information are verified, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode;

[0033] The verification module is configured to verify the identity credential verifiable expression and generate a credential verification result;

[0034] The sending module is configured to send the credential verification result to the applicant terminal.

[0035] In an eighth aspect, the present application provides an identity credential verification device, applied to an applicant terminal, comprising a verifiable expression generating module, an identity verification request sending module and a receiving module, wherein,

[0036] The verifiable expression generating module is configured to obtain identity credential related information stored locally and generate an identity credential verifiable expression according to the identity credential related information, wherein the identity credential verifiable expression comprises the identity credential related information and a credential signature generated by signing the identity credential related information with an applicant private key, and the identity credential related information comprises an applicant identity credential issued by an issuing party, the applicant identity credential comprises a statement part and a signature part generated by signing the statement part with an issuing party private key, and the statement part comprises an applicant distributed identity and an issuing party distributed identity, the applicant distributed identity is generated according to an applicant public key after the applicant identity information and the applicant biometric information are verified, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode;

[0037] The identity verification request sending module is configured to send an identity verification request to a verification party, wherein the identity verification request comprises an identity credential verifiable expression;

[0038] The receiving module is configured to receive a credential verification result sent by the verifying party, the credential verification result being generated by the verifying party after verifying the identity credential verifiable expression.

[0039] In a ninth aspect, the present application provides an identity credential application method, applied to an applicant terminal, and the method comprises the following steps:

[0040] sending a second identity verification request to the issuing party, so that the issuing party generates a second identity verification result according to the second identity verification request, wherein the second identity verification request comprises the applicant identity information and the applicant biometric information, and the applicant identity information is read from an external identity document by the applicant terminal through a near field communication mode;

[0041] judging, according to the second identity verification result sent by the issuing party, that the applicant identity verification is passed, sending a distributed identity opening request to the distributed identity system, and receiving the distributed identity identifier of the applicant from the distributed identity system;

[0042] sending an identity credential application request to the issuing party, so that the issuing party generates the identity credential of the applicant and uploads verification data of the identity credential of the applicant to a credential permission chain, wherein the identity credential application request comprises the distributed identity identifier of the applicant, and the verification data comprises an abstract value of the identity credential of the applicant;

[0043] receiving the identity credential of the applicant from the issuing party, wherein the identity credential of the applicant comprises a declaration part, and the declaration part comprises the distributed identity identifier of the applicant.

[0044] In a tenth aspect, the present application provides an identity credential application method, applied to an issuing party, and the method comprises the following steps:

[0045] receiving a second identity verification request sent by an applicant terminal, generating a second identity verification result according to the second identity verification request, and sending the second identity verification result to the applicant terminal, so that the applicant terminal judges, according to the second identity verification result, that the applicant identity verification is passed, and then sends a distributed identity opening request to the distributed identity system, wherein the second identity verification request comprises the applicant identity information and the applicant biometric information, and the applicant identity information is read from an external identity document by the applicant terminal through a near field communication mode;

[0046] receiving an identity credential application request sent by an applicant terminal, generating the identity credential of the applicant and uploading verification data of the identity credential of the applicant to a credential permission chain, wherein the identity credential application request comprises the distributed identity identifier of the applicant, the distributed identity identifier of the applicant is generated by the distributed identity system after receiving a distributed identity opening request sent by the applicant terminal, and the verification data comprises an abstract value of the identity credential of the applicant;

[0047] The application identity credential is sent to the applicant terminal, wherein the application identity credential comprises a declaration part, and the declaration part comprises the application distributed identity.

[0048] In an eleventh aspect of the embodiment of the present application, an identity credential application device is provided, which is applied to an applicant terminal, and the device comprises a second identity verification request module, a distributed identity opening request module, an identity credential request module and an identity credential receiving module, wherein,

[0049] The second identity verification request module is configured to send a second identity verification request to the issuer, so that the issuer generates a second identity verification result according to the second identity verification request, wherein the second identity verification request comprises application identity information and application biological feature information, and the application identity information is read from an external identity certificate by the applicant terminal through a near field communication mode;

[0050] The distributed identity opening request module is configured to judge that the application identity verification is passed according to the second identity verification result sent by the issuer, send a distributed identity opening request to the distributed identity system, and receive the application distributed identity from the distributed identity system;

[0051] The identity credential request module is configured to send an identity credential application request to the issuer, so that the issuer generates an application identity credential and uploads verification data of the application identity credential to a credential permission chain, wherein the identity credential application request comprises the application distributed identity, and the verification data comprises an abstract value of the application identity credential;

[0052] The identity credential receiving module is configured to receive the application identity credential from the issuer, wherein the application identity credential comprises a declaration part, and the declaration part comprises the application distributed identity.

[0053] In a twelfth aspect of the embodiment of the present application, an identity credential application device is provided, which is applied to an issuer, and the device comprises a second identity verification result generation module, an identity credential generation module and a sending module, wherein,

[0054] The second identity verification result generation module is configured to receive a second identity verification request sent by the applicant terminal, generate a second identity verification result according to the second identity verification request, and send the second identity verification result to the applicant terminal, so that the applicant terminal sends a distributed identity opening request to the distributed identity system after judging that the application identity verification is passed according to the second identity verification result, wherein the second identity verification request comprises application identity information and application biological feature information, and the application identity information is read from an external identity certificate by the applicant terminal through a near field communication mode;

[0055] The identity credential generation module is configured to receive an identity credential application request sent by the applicant terminal, generate an applicant identity credential, and upload verification data of the applicant identity credential to a credential permission chain, wherein the identity credential application request comprises an applicant distributed identity, the applicant distributed identity is generated by the distributed identity system after receiving a distributed identity opening request sent by the applicant terminal, and the verification data comprises an abstract value of the applicant identity credential.

[0056] The sending module is configured to send the applicant identity credential to the applicant terminal, wherein the applicant identity credential comprises a declaration part, and the declaration part comprises the applicant distributed identity.

[0057] In a thirteenth aspect, an identity credential verification method is provided, which is applied to a verifier and comprises the following steps:

[0058] receiving an identity verification request sent by the applicant terminal, wherein the identity verification request comprises an identity credential verifiable expression, the identity credential verifiable expression comprises identity credential related information and a credential signature generated by signing the identity credential related information with an applicant private key, the identity credential related information comprises an applicant identity credential issued by an issuer, the applicant identity credential comprises a declaration part, the declaration part comprises an applicant distributed identity, the applicant distributed identity is generated according to an applicant public key after the applicant identity information and the applicant biometric information are verified, and the applicant identity information is read from an external identity certificate by the applicant terminal through near field communication.

[0059] verifying the identity credential verifiable expression to generate a credential verification result;

[0060] sending the credential verification result to the applicant terminal.

[0061] In a fourteenth aspect, an identity credential verification method is provided, which is applied to an applicant terminal and comprises the following steps:

[0062] obtaining identity credential related information stored locally, and generating an identity credential verifiable expression according to the identity credential related information, wherein the identity credential verifiable expression comprises the identity credential related information and a credential signature generated by signing the identity credential related information with an applicant private key, the identity credential related information comprises an applicant identity credential issued by an issuer, the applicant identity credential comprises a declaration part, the declaration part comprises an applicant distributed identity, the applicant distributed identity is generated according to an applicant public key after the applicant identity information and the applicant biometric information are verified, and the applicant identity information is read from an external identity certificate by the applicant terminal through near field communication.

[0063] send an identity authentication request to the verification party, wherein the identity authentication request comprises the identity credential verifiable expression;

[0064] receive a credential verification result sent by the verification party, the credential verification result being generated by the verification party after verifying the identity credential verifiable expression.

[0065] In a fifteenth aspect, the present application provides an identity credential verification device, applied to a verification party, comprising an identity authentication request receiving module, a verification module and a sending module, wherein,

[0066] The identity authentication request receiving module is configured to receive an identity authentication request sent by an application party terminal, wherein the identity authentication request comprises an identity credential verifiable expression, the identity credential verifiable expression comprises identity credential related information and a credential signature generated by signing the identity credential related information with an application party private key, the identity credential related information comprises an application party identity credential issued by an issuing party, the application party identity credential comprises a statement part, the statement part comprises an application party distributed identity, the application party distributed identity is generated according to an application party public key after the application party identity information and the application party biometric information are verified, and the application party identity information is read from an external identity certificate by the application party terminal through a near field communication mode.

[0067] The verification module is configured to verify the identity credential verifiable expression and generate a credential verification result.

[0068] The sending module is configured to send the credential verification result to the application party terminal.

[0069] In a sixteenth aspect, the present application provides an identity credential verification device, applied to an application party terminal, comprising a verifiable expression generating module, an identity authentication request sending module and a receiving module, wherein,

[0070] The verifiable expression generating module is configured to obtain identity credential related information stored locally and generate an identity credential verifiable expression according to the identity credential related information, wherein the identity credential verifiable expression comprises the identity credential related information and a credential signature generated by signing the identity credential related information with an application party private key, the identity credential related information comprises an application party identity credential issued by an issuing party, the application party identity credential comprises a statement part, the statement part comprises an application party distributed identity, the application party distributed identity is generated according to an application party public key after the application party identity information and the application party biometric information are verified, and the application party identity information is read from an external identity certificate by the application party terminal through a near field communication mode.

[0071] The identity authentication request sending module is configured to send an identity authentication request to the verification party, wherein the identity authentication request comprises the identity credential verifiable expression.

[0072] The receiving module is configured to receive a credential verification result sent by the verifying party, the credential verification result being generated after the verifying party verifies the identity credential verifiable expression.

[0073] In a seventeenth aspect, an electronic device is provided, including: one or more processors; and a storage device storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method provided by the embodiments of the present application.

[0074] In an eighteenth aspect, a computer readable medium is provided, and the computer readable medium stores a computer program, when the computer program is executed by a processor, the method provided by the embodiments of the present application is implemented.

[0075] The above-mentioned embodiment of the application has the following advantages or beneficial effects:

[0076] In the embodiment of the present application, the user uses the applicant terminal to read the identity information stored in the external identity certificate through the near field communication mode, combines the biological feature information, initiates a second identity verification request, and returns the result to the applicant terminal after the verifying party verifies and passes. The applicant terminal opens the distributed identity to the distributed identity system, and the applicant terminal applies for the identity credential after obtaining the distributed identity identifier. The applicant terminal issues the applicant identity credential based on the previous verification result. In the process of applying and issuing the identity credential, not only the biological feature information of the user is verified, but also the identity information read from the entity certificate is verified, the real person and real certificate verification is realized, and the reliability of the identity credential is improved.

[0077] In the embodiment of the present application, the applicant applies for the identity credential through the real person and real certificate verification mode, and applies for the identity verification to the verifying party according to the identity credential. The applicant terminal generates the identity credential verifiable expression according to the identity credential, sends the identity verification request to the verifying party, and the verifying party verifies the identity credential verifiable expression for authenticity, integrity and validity, thereby verifying the identity of the applicant. In the embodiment of the present application, the identity credential reflecting the verification result can be safely shared among multiple financial institutions, without the need to repeatedly collect the user identity information, not only meeting the requirements of various institutions for identity authentication strength, but also greatly improving the convenience of the user, reducing the repeated labor of identity verification among multiple institutions, and optimizing the customer experience.

[0078] The further effects of the above-mentioned non-conventional optional mode will be described in the following combined with the specific embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0079] The accompanying drawings are used to better understand the present application, and do not constitute undue limitations on the present application. Among them:

[0080] Figure 1 is a schematic diagram of an architecture of a network system in which the identity credential application method and the identity credential verification method according to some embodiments of the present application are implemented;

[0081] Figure 2 is a schematic diagram of a flow of the identity credential application method according to some embodiments of the present application;

[0082] Figure 3 is a schematic diagram of reading of identity information in an external identity document by a terminal of an applicant in the identity credential application method according to some embodiments of the present application;

[0083] Figure 4 is a schematic diagram of a flow of verification of an identity of an applicant by an issuer in the identity credential application method according to some embodiments of the present application;

[0084] Figure 5 is a schematic diagram of a flow of the identity credential application method according to some other embodiments of the present application;

[0085] Figure 6 is a schematic diagram of a flow of the identity credential verification method according to some embodiments of the present application;

[0086] Figure 7 is a schematic diagram of a flow of verification of a verifiable statement in the identity credential verification method according to some embodiments of the present application;

[0087] Figure 8 is a schematic diagram of a flow of verification of an identity credential in the identity credential verification method according to some embodiments of the present application;

[0088] Figure 9 is a schematic diagram of a flow of verification of a status of an identity credential in the identity credential verification method according to some embodiments of the present application;

[0089] Figure 10 is another schematic diagram of a flow of verification of an identity credential in the identity credential verification method according to some embodiments of the present application;

[0090] Figure 11 is a schematic diagram of a functional architecture of an identity credential application apparatus according to some embodiments of the present application;

[0091] Figure 12 is a schematic diagram of a functional architecture of an identity credential application apparatus according to some other embodiments of the present application;

[0092] Figure 13 is a schematic diagram of a functional architecture of an identity credential verification apparatus according to some embodiments of the present application;

[0093] Figure 14 is a schematic diagram of a functional architecture of an identity credential verification apparatus according to some other embodiments of the present application;

[0094] Figure 15 is an exemplary system architecture diagram in which embodiments of the present application can be applied;

[0095] Figure 16 is a schematic diagram of a structure of a computer system of a terminal device or a server suitable for implementing embodiments of the present application. DETAILED DESCRIPTION

[0096] Exemplary embodiments of the present application are described herein with reference to the accompanying drawings, which are meant to be exemplary in nature, and in which specific details are set forth to provide an understanding of the present application. Thus, it will be apparent to one of ordinary skill in the art that variations in these embodiments that do not have a material effect on the essential characteristics of the application can be made without departing from the spirit and scope of the application. Further, it is to be understood that the description of the present application is not meant to limit the application to the specific embodiments described. Accordingly, the following description is provided for illustrative purposes so as to enable others skilled in the art to best utilize the application and its equivalents.

[0097] First, the abbreviations and related terms involved in the embodiments of the present application are defined and explained.

[0098] “DID(Decentralized Identifiers)” refers to a distributed identity, an identifier composed of a string of characters to represent a digital identity, and the DID is generated by a distributed identity system based on the public key and other information of the applicant. The distributed identity system also stores a DID document corresponding to the DID, and the DID document stores the DID and the public key corresponding to the DID;

[0099] “VC(Verifiable Credential)” refers to a verifiable credential, usually a JSON string, containing VC metadata, a statement part, and a proof part. The VC metadata mainly includes the issuer, the issuance date, and the type of the statement, etc. The statement part is one or more specific statements about the subject, for example, if the VC is an identity card, the statement part will contain the holder's name, gender, date of birth, nationality, address, and other personal information. The proof part is usually the digital signature of the issuer, which is used to ensure the integrity and authenticity of the VC content, prevent tampering, and verify the identity of the issuer of the VC;

[0100] “VP(Verifiable Presentation)” is a verifiable presentation associated with a user's distributed identity, which contains verifiable proof files synthesized from one or more verifiable credentials VC, and also contains a credential signature generated by digitally signing these proof files with the user's private key.

[0101] In existing identity verification services, in some specific business needs, the user himself / herself often needs to go to a business site to perform identity verification. If the business handled by the user involves multiple banking institutions, the user needs to go to the business sites of multiple banks to handle the business, and the user is difficult to efficiently and conveniently handle the business, and needs to perform repeated operations multiple times. In some identity verification services, the user can open an identity through face recognition, but the security level is difficult to guarantee through pure face verification, and in identity verification services opened by different institutions, the user still needs to repeatedly submit identity information for verification, and the user's business handling efficiency is low.

[0102] The identity credential application method for online real person real evidence provided by the embodiments of the present application and the corresponding identity credential verification method that can be used online facilitate the user to perform identity verification online and provide the user with the experience of conveniently handling the business.

[0103] As shown in FIG. 1, a network system 100 in the embodiments of the present application is shown, and the credential application method and the identity verification method in the embodiments of the present application can be run into the network system 100. The network system 100 includes an applicant terminal 110, an issuer 120, a verifier 130, a distributed identity system 140, a credential permission chain 150, and a trusted identity management institution 160.

[0104] In the embodiments of the present application, the applicant terminal 110 can be a terminal containing a digital wallet application. The applicant can use the digital wallet application to apply for a distributed identity, apply for an identity credential, organize and send an identity verification request, and the like. A trusted environment can also be arranged in the applicant terminal 110, which is used to generate a public key and a private key of the applicant and can store an issued proof credential. In the embodiments of the present application, the trusted environment is a secure area on the applicant terminal, which can guarantee the security of the data loaded into it, including confidentiality, integrity, and availability, and the like. The trusted environment can be a trusted execution environment (TEE), a secure element (SE), a trusted cryptographic module (TCM), or other protection areas with a security boundary. In some embodiments of the present application, the issuer 120 can be understood as a system controlled by an issuing institution, and a server cryptographic machine is arranged in the issuer 120, which is used to generate an issuer public key and a private key. In some embodiments of the present application, the distributed identity system 140 can generate a distributed identity after verification according to a distributed identity opening request, and generate a distributed identity document corresponding to the distributed identity. The distributed identity document stores the distributed identity and the public key corresponding to the distributed identity, and the distributed identity system 140 stores and maintains the distributed identity document. In some embodiments of the present application, the trusted identity management institution 160 can be an institution with authoritative identity authentication, which maintains a database storing the identity information and the biometric information of the user, and calls the identity of the user for verification by other institutions, and the like.

[0105] As shown in FIG. 2, the embodiment of the present application provides a credential application method, comprising the following steps:

[0106] S210: In response to the distributed identity opening request operation of the user (the applicant) on the applicant terminal, the applicant terminal 110 reads the applicant identity information from the external identity certificate through the near field communication mode, and collects the applicant biometric information. According to the applicant identity information and the applicant biometric information, a first identity verification request is sent to the trusted identity management institution, wherein the first identity verification request comprises the applicant identity information and the applicant biometric information.

[0107] As shown in FIG. 3, the external identity certificate 300 is provided with a near field communication unit 310 and a storage unit 320, and the applicant identity information is stored in the storage unit 320. When the external identity certificate 300 is close to the applicant terminal 110, the applicant terminal 110 communicates with the near field communication unit 310 according to the near field communication protocol, and the near field communication unit 310 obtains the applicant identity information from the storage unit 320 and transmits it to the applicant terminal 110 through the near field communication protocol. In some embodiments of the present application, the applicant identity information in the storage unit 320 can be in an encrypted state.

[0108] In some embodiments of the present application, the external identity certificate can be an identity card, a driver's license, a passport certificate, an officer's certificate, a bank card, a social security card and other physical certificates supporting NFC certificate reading. The applicant identity information can be name, identity card number, gender, date of birth, etc., and the applicant biometric information can be face information, fingerprint information, iris information, etc.

[0109] In some embodiments of the present application, after the applicant terminal 110 obtains the applicant identity information from the external identity certificate 300, the camera is called to collect the face information of the applicant, and then the first identity verification request is initiated to the trusted identity management institution 160.

[0110] In some embodiments of the present application, the trusted identity management institution 160 provides an identity verification interface externally, so that other devices can call the identity verification interface to transmit the required identity information to the trusted identity management institution 160. In some embodiments of the present application, the applicant terminal 110 calls the identity verification interface to send the first identity verification request to the trusted identity management institution 160.

[0111] In the embodiment of the present application, the applicant identity information is obtained from the external identity certificate through the near field communication protocol, which ensures that the user is using the entity certificate to handle the business at this moment, and improves the reliability of the business handling. Then the face information is collected to ensure that the handling user is the applicant himself, so as to ensure that the user handles the business in the case of real person and real certificate, and improve the reliability of the verification business.

[0112] In some embodiments of the present application, the applicant terminal 110 also generates a reading information record in the reading identity information process, and the reading information record includes the read certificate type, reading time, read identity information, or an abstract of the read identity information, etc.

[0113] S220: The trusted identity management institution 160 generates and returns a first identity verification result according to the first identity verification request, and the applicant terminal 110 judges that the applicant identity verification is passed according to the first identity verification result.

[0114] In the embodiments of the present application, the trusted identity management institution 160 stores the identity information in the external identity certificate and the corresponding user biological feature information. The trusted identity management institution 160 performs comparison and verification according to the applicant identity information and biological feature information in the first identity verification request, and generates a first identity verification result. If the applicant identity information and biological feature information are compared and confirmed to be consistent with the information stored in the trusted identity management institution 160, the first identity verification result indicates that the verification is passed. After the applicant terminal 110 judges that the applicant identity verification is passed according to the first identity verification result, the subsequent secondary verification process is performed.

[0115] In some embodiments of the present application, after the applicant terminal 110 judges that the applicant identity verification is passed according to the first identity verification result, the applicant identity information and the applicant biological feature information are also stored in an encrypted manner.

[0116] S230: After the applicant terminal 110 judges that the applicant identity verification is passed according to the first identity verification result, the second identity verification request is sent to the issuer 120, wherein the second identity verification request includes the read applicant identity information and the collected applicant biological feature information.

[0117] S240: The issuer 120 generates a second identity verification result according to the second identity verification request, and returns the second identity verification result to the applicant terminal 110.

[0118] In some embodiments of the present application, the issuer 120 can call the interface of the trusted identity management institution 160 to send the applicant identity information and biological feature information in the second identity verification request to the trusted identity management institution 160 for verification, or can use the identity information and biological feature information stored in the self database for verification.

[0119] In some embodiments of the present application, the second identity verification request also includes the reading information record generated by the applicant terminal 110, and the issuer 120 judges that the identity information in the second identity verification request is derived from the external entity certificate according to the reading information record.

[0120] In some embodiments of the present application, as shown in FIG. 4, step S240 includes the following steps.

[0121] S241: The issuer 120 judges whether the application party identity information matches the read information record, and sends the application party identity information and the application party biometric information to the trusted identity management institution 160, so that the trusted identity management institution 160 generates a third identity verification result according to the application party identity information and the application party biometric information.

[0122] In some embodiments of the present application, the manner in which the issuer 120 judges whether the application party identity information matches the read information record can adopt one or more of the following manners: judging whether the read certificate type in the read information record is within the trusted range according to the read certificate type; judging whether the read time is within the threshold range compared with the time of the second identity verification request; judging whether the read identity information or the digest of the read identity information is consistent with the application party identity information or the digest of the application party identity information in the second identity verification request, etc.

[0123] In the embodiments of the present application, the trusted identity management institution 160 processes the third identity verification request in a similar manner to the first identity verification request, which will not be described here.

[0124] S242: The issuer 120 receives the third identity verification result returned by the trusted identity management institution 160, and generates a second identity verification result according to the third identity verification result. In some embodiments of the present application, if the third identity verification result indicates that the verification is passed, the second identity verification result also indicates that the verification is passed.

[0125] In the embodiments of the present application, two identity verifications are adopted, which ensures the reliability of the identity verification.

[0126] S250: The application party terminal 110 judges that the application party identity verification is passed according to the second identity verification result sent by the issuer, sends a distributed identity opening request to the distributed identity system 140, and receives the application party distributed identity identifier from the distributed identity system 140.

[0127] In some embodiments of the present application, after the applicant terminal 110 judges that the applicant identity verification is passed according to the second identity verification result, the applicant terminal 110 generates an applicant public key and an applicant private key according to a trusted environment in the applicant terminal 110, saves the applicant private key in the trusted environment, and generates a distributed identity opening request according to the applicant public key. In some embodiments of the present application, the distributed identity opening request includes the applicant public key, the distributed identity system 140 generates an applicant distributed identity according to the applicant public key, and correspondingly generates an applicant distributed identity document, the applicant distributed identity document stores the applicant distributed identity and the applicant public key, and the applicant distributed identity document can be obtained by analyzing the applicant distributed identity, and the applicant public key can be obtained therefrom. In some embodiments of the present application, the distributed identity system 140 performs a hash calculation on the applicant public key or together with other random factors to obtain the applicant distributed identity.

[0128] In some embodiments of the present application, the trusted environment set in the applicant terminal 110 is a secure area on the applicant terminal 110, which can ensure the security of the data loaded therein, including confidentiality, integrity and availability, and can be a trusted execution environment (TEE), a secure element (SE), a trusted cryptographic module (TCM) or other protection areas with a security boundary. In some embodiments of the present application, the applicant identity information and the applicant biometric information can be stored in the trusted environment in an encrypted manner.

[0129] S260: The applicant terminal 110 sends an identity certificate application request to the issuer 120, wherein the identity certificate application request includes the applicant distributed identity. In embodiments of the present application, the applicant terminal 110 applies for an identity certificate from the issuer 120 based on the results of the previous two identity verifications.

[0130] S270: The issuer 120 generates an applicant identity certificate, wherein the applicant identity certificate includes a declaration part and a signature part generated by signing the declaration part with an issuer private key, and the declaration part includes the applicant distributed identity and the issuer distributed identity.

[0131] In some embodiments of the present application, the declaration part includes the issuer distributed identity, and in the subsequent identity certificate verification process, the issuer public key can be obtained from the distributed identity system 140, and the signature part is verified by using the issuer public key, so as to verify the integrity of the declaration part.

[0132] In some embodiments of the present application, the identity credential application request further includes an application party public key, and the issuing party 120 sets the application party public key in the declaration part during the generation of the application party identity credential. In the embodiments of the present application, the application party public key is generated by the trusted environment, and the uniqueness of the public key generated by each application party terminal ensures that the application party terminal 110 used by the user during the application of the distributed identity and the application of the identity credential is consistent, thereby ensuring the consistency of the verification.

[0133] In some embodiments of the present application, in order to support the verification requirements of the verification party in the verification of the identity credential, for example, to support the requirement of the verification party to recheck the application party identity information and the biometric information, the issuing party 120 further calculates the digest value of the application party identity information and / or the application party biometric information during the generation of the application party identity credential, obtains the identity information digest value, and sets the identity information digest value in the declaration part of the application party identity credential. In the subsequent verification process, after the application party terminal 110 sends the stored application party identity information and the application party biometric information to the verification party, the verification party can verify the application party identity information and the application party biometric information sent by the application party terminal 110 based on the identity information digest value in the declaration part. It should be noted that although the verification party verifies the application party identity information and the biometric information again at this time, the application party terminal 110 does not obtain the identity information again or collect the biometric information again, and the application party terminal 110 can obtain the above information from the trusted environment, thereby avoiding the repeated submission of the identity information by the user and reducing the repeated operation.

[0134] In some embodiments of the present application, the issuing party 120 further sets the validity time of the identity credential during the generation of the application party identity credential, and the credential issuing time can be set in the declaration part. In a specific scenario, the identity credential has a preset time length from the issuance to the expiration, and according to the issuing time and the preset time length, it can be known whether the identity credential is still within the validity period.

[0135] In some embodiments of the present application, in order to more accurately control the validity period of the identity credential, the issuing party 120 further sets the credential expiration time in the declaration part. In some embodiments of the present application, the identity information read by the application party terminal 110 from the external identity certificate further includes a certificate expiration time, and the application party public key also has an expiration time. The embodiments of the present application set the credential expiration time as the earlier time of the certificate expiration time and the expiration time of the application party public key. It is ensured that the corresponding public key and certificate are not expired when the identity credential is used.

[0136] In some embodiments of the present application, in order to distinguish different identity credentials, and facilitate the verifier to select different verification methods according to different types of identity credentials, the declaration part of the identity credential in the embodiments of the present application further includes a credential type. For example, the credential type of the identity credential generated by the real person real evidence method in the embodiments of the present application can be set as a sticker credential, and if the identity credential is generated according to the counter identity verification result, the credential type can be set as a counter verification credential.

[0137] Different credential types in the embodiments of the present application can be set with non-passing verification methods. For example, some credentials do not need to verify whether the public key in the verification declaration part is consistent with the public key in the distributed identity document, and for some identity credentials, in order to verify the device invariability, the public key of the applicant in the credential declaration and the public key of the applicant in the distributed identity document need to be verified.

[0138] In some embodiments of the present application, before receiving the second identity verification request sent by the applicant terminal, the issuer 120 sends an issuer distributed identity opening request containing the issuer public key to the distributed identity system 140; the issuer 120 receives the issuer distributed identity sent by the distributed identity system 140, wherein the issuer distributed identity is generated by the distributed identity system 140 according to the issuer distributed opening request, and after generating the issuer distributed identity, the distributed identity system 140 further generates an issuer distributed identity document according to the issuer distributed identity, and the issuer distributed identity document stores the issuer public key, and the issuer distributed identity document can be accessed through the issuer distributed identity to obtain the issuer public key.

[0139] S280: The applicant terminal 110 receives the applicant identity credential from the issuer 120.

[0140] In some embodiments of the present application, after generating the applicant identity credential, the issuer 120 issues a credential generation notification to the applicant terminal 120, and the user can receive the credential generation notification through the digital wallet application, or can receive the credential generation notification through the short message service. After receiving the credential generation notification, the user sends a download request to the issuer 120 through the applicant terminal 110, and the issuer 120 transmits the applicant identity credential to the applicant terminal 110 according to the credential download request.

[0141] In some embodiments of the present application, in order to facilitate other parties to verify the status of the identity credential, as shown in FIG. 5, the method in the embodiments of the present application further includes:

[0142] S290: The issuer 120 uploads the verification data of the applicant identity credential to the credential permission chain 150, and the verification data includes the digest value and the status of the applicant identity credential.

[0143] In the embodiment of the present application, the issuer 120 calculates the digest value according to the applicant identity credential, obtains the digest value of the applicant identity credential, synchronizes the digest value and the state to the credential permission chain 150, and in the subsequent identity credential verification process, the state of the identity credential can be obtained from the credential permission chain 150 according to the digest value, so as to verify the state of the identity credential. In the embodiment of the present application, the state of the identity credential can be valid, invalid, transfer, etc.

[0144] In the embodiment of the present application, the user uses the applicant terminal to read the identity information stored in the external identity certificate by the near field communication mode, combines the biological feature information, initiates a second identity verification request, and returns the result to the applicant terminal after the verification of the issuer. The applicant terminal opens the distributed identity to the distributed identity system, and the applicant terminal obtains the distributed identity identifier and applies for the identity credential to the issuer. The issuer issues the applicant identity credential to the applicant according to the previous verification result. In the process of applying and issuing the identity credential, the biological feature information of the user is verified, and the identity information read from the entity certificate is also verified, so as to realize the real person and real certificate verification, thereby improving the reliability of the identity credential.

[0145] According to the identity credential generated in the above embodiment of the present application, the applicant terminal 110 can also initiate a verification request of the identity credential to the verifier. Next, the identity credential verification process will be introduced, and in addition to the following embodiments, the above-mentioned identity credential application embodiments can also be referred to for the limitation of the identity credential.

[0146] As shown in FIG. 6, the embodiment of the present application also provides an identity credential verification method, which includes the following steps.

[0147] S410: The applicant terminal 110 obtains the locally stored identity credential related information, and generates an identity credential verifiable expression according to the identity credential related information, wherein the identity credential verifiable expression includes the identity credential related information and a credential signature generated by signing the identity credential related information by the applicant private key, and the identity credential related information includes the applicant identity credential issued by the issuer 120, the applicant identity credential includes a declaration part and a signature part generated by signing the declaration part by the issuer private key, and the declaration part includes the applicant distributed identity identifier and the issuer distributed identity identifier.

[0148] In some embodiments of the present application, referring to the above-mentioned identity credential embodiments, the applicant distributed identity identifier is generated by the distributed identity system 140 according to the applicant public key after the verification of the applicant identity information and the applicant biological feature information.

[0149] In some embodiments of the present application, the applicant identity information is read by the applicant terminal from an external identity certificate through near field communication.

[0150] In some embodiments of the present application, the applicant terminal 110 obtains identity certificate related information from the trusted environment, and signs the identity certificate related information using a private key in the trusted environment to generate a certificate signature.

[0151] S420: The applicant terminal 110 sends an identity verification request to the verifier 130, wherein the identity verification request includes an identity certificate verifiable expression.

[0152] In some embodiments of the present application, the applicant terminal 110 can send an identity verification request to the verifier 130 through a near field communication protocol, or can send an identity verification request to the verifier 130 by presenting a two-dimensional code. The applicant terminal 110 generates and displays a two-dimensional code according to the identity verification request, and the verifier 130 scans the two-dimensional code to obtain the identity verification request.

[0153] S430: The verifier 130 receives the identity verification request sent by the applicant terminal, verifies the identity certificate verifiable expression, and generates a certificate verification result.

[0154] In some embodiments of the present application, the verifier 130 verifies the identity certificate verifiable expression and the applicant identity certificate, which can be verified for integrity, authenticity and validity.

[0155] Embodiments of the present application obtain the applicant public key from the distributed identity system 140 through the applicant distributed identity in the declaration, and verify the certificate signature using the applicant public key, and then further obtain the issuer public key from the distributed identity system 140 through the issuer distributed identity, and verify the signature part in the applicant identity certificate using the issuer public key.

[0156] As shown in FIG. 7, in some embodiments of the present application, the declaration part of the applicant identity certificate further includes a certificate issuance time and / or a certificate expiration time, which can be used to verify whether the identity certificate is still within the valid period. In some embodiments of the present application, step S430 includes:

[0157] S431: The verifier 120 verifies the validity period of the applicant identity certificate according to the current time, the certificate issuance time and / or the certificate expiration time.

[0158] In some embodiments of the present application, in the case of determining the validity period of a certain type of identity credential, it can be determined whether the current time is within the validity period according to the credential issuance time. For example, the validity period of a certain applicant identity credential is 1 year, the credential issuance time is September 1, 2023, and the applicant identity credential is within the validity period before August 31, 2024. The current time is August 12, 2024, and the applicant identity credential is within the validity period.

[0159] In some embodiments of the present application, the expiration time of the applicant identity credential is directly set in the statement part of the applicant identity credential. By comparing the current time with the expiration time of the credential, it can be determined whether the applicant identity credential is within the validity period. For example, the expiration time of a certain applicant identity credential is August 31, 2024. According to the current time August 12, 2024, it can be determined that the applicant identity credential is still within the validity period.

[0160] In some embodiments of the present application, the statement part of the applicant identity credential also includes the applicant public key. The device that applied for the credential, the device that applied for the identity, and the device that verified the identity credential can be determined to be the same device by verifying the applicant public key. The following will continue to refer to FIG. 7 to introduce step S430. As shown in FIG. 7, step S430 further includes:

[0161] S432: The verifier 130 obtains the applicant public key from the distributed identity system according to the applicant distributed identity. The verifier 130 obtains the applicant distributed identity from the statement part of the applicant identity credential, applies to the distributed identity system 140 to obtain the applicant public key, the distributed identity system 140 obtains the applicant distributed identity document according to the applicant distributed identity, obtains the applicant public key from the applicant distributed identity document, and returns the applicant public key to the verifier 130.

[0162] S433: The verifier 130 verifies whether the applicant public key in the applicant identity credential is consistent with the applicant public key obtained from the distributed identity system. In the case of consistency, the credential signature is verified using the applicant public key, and a credential signature verification result is generated.

[0163] S434: According to the credential signature verification result, a credential verification result is generated.

[0164] In the method of the embodiments of the present application, in the case of verifying that the two public keys are consistent, the credential signature is further verified, the public key is verified whether it is tampered with during the credential application process, the consistency of the applicant terminal during the verification of the identity credential and the applicant terminal during the application of the identity credential is further verified by verifying the consistent applicant public key, and the identity credential is verified whether it is transferred, and the security of the identity credential during the storage process is verified.

[0165] In some embodiments of the present application, the integrity of the declaration part of the identity credential can also be continuously detected, as shown in FIG. 8, step S434 further includes:

[0166] S4341: The verifier 130 judges that the signature verification of the credential passes according to the signature verification result, and obtains the public key of the issuing party from the distributed identity system 140 according to the distributed identity of the issuing party;

[0167] S4342: The verifier 130 verifies the signature part using the public key of the issuing party, and generates a signature part verification result;

[0168] S4343: The verifier 140 generates a credential verification result according to the signature part verification result.

[0169] In embodiments of the present application, the integrity of the declaration part is verified by verifying the signature part, ensuring that the content of the credential has not been tampered with.

[0170] In some embodiments of the present application, the validity status of the identity credential is also checked. According to the above description of the embodiments of the application for identity credentials, after the identity credential is generated, the verifier 130 will synchronize the verification data of the identity credential (including the status of the identity credential) to the credential permission chain 150, and in subsequent verification of the identity credential, the status of the identity credential can be obtained from the credential permission chain to determine the status of the identity credential. Specifically, referring to FIG. 9, in some embodiments of the present application, step S4343 includes the following steps.

[0171] S43431: The verifier 130 judges that the signature part verification passes according to the signature part verification result, and generates a credential digest value according to the identity credential of the applicant.

[0172] S43432: The verifier 130 sends the credential digest value to the credential permission chain, so that the credential permission chain 150 obtains the verification data according to the credential digest value, and generates a credential status verification result according to the verification data.

[0173] S43433: The verifier 130 judges that the status verification of the identity credential of the applicant passes according to the credential status verification result sent by the credential permission chain 150, and generates a credential verification result indicating that the verification passes.

[0174] Through status verification, the validity status of the identity credential is checked.

[0175] In some embodiments of the present application, in order to meet the business needs of different verification parties and meet the needs of the verification party to verify the identity information again, the declaration part of the applicant identity credential further includes an identity information digest value. The applicant terminal 110 generates the identity credential verifiable expression according to the locally stored applicant identity information and / or applicant biometric information when generating the identity credential verifiable expression, that is, the identity credential related information further includes the applicant identity information and / or the applicant biometric information. The process of verifying the identity credential verifiable expression further includes the process of verifying the applicant identity information and / or the applicant biometric information. Since the identity information and the applicant biometric information received by the issuing party 120 have been verified by the trusted identity management agency 160 when the identity credential is applied for, the identity information provided by the applicant terminal again when the identity credential is verified is consistent with the identity information and the applicant biometric information received by the issuing party 120, and the verification is passed. In some other embodiments of the present application, the credential state and the business identity information can be verified synchronously. Referring to FIG. 10, step S4343 includes:

[0176] S43431: The verification party 130 verifies the signature part according to the signature part verification result to determine that the signature part verification is passed, and generates a credential digest value according to the applicant identity credential.

[0177] S43432: The verification party 130 sends the credential digest value to the credential permission chain, so that the credential permission chain 150 obtains the verification data according to the credential digest value, and generates a credential state verification result according to the verification data.

[0178] S43434: The verification party 120 verifies the signature part according to the signature part verification result to determine that the signature part verification is passed, and generates a business identity information digest value according to the applicant identity information and / or the applicant biometric information.

[0179] S43435: The verification party 120 checks the business identity information digest value according to the identity information digest value to generate a business identity information verification result.

[0180] S43433': The verification party 120 determines that the state verification of the applicant identity credential is passed according to the credential state verification result sent by the credential permission chain 150, and determines that the business identity information verification is passed according to the business identity information verification result, and generates a credential verification result indicating that the verification is passed.

[0181] The execution order of the above steps S43431, S43432 and S43434, S43435 is not limited, which can be executed sequentially or in parallel.

[0182] In some embodiments of the application, the identity information digest value in the declaration part is generated by the applicant identity information, and the identity credential related information includes the applicant identity information.

[0183] In some embodiments of the application, the identity information digest value in the declaration part is generated by the applicant biological feature information, and the identity credential related information includes the applicant biological feature information.

[0184] In some embodiments of the application, the identity information digest value in the declaration part is generated by the applicant identity information and the applicant biological feature information, and the identity credential related information includes the applicant identity information and the applicant biological feature information.

[0185] Embodiments of the application take into account different types of identity credentials, whose verification methods are different. In order to quickly determine the verification method, in some embodiments of the application, the declaration part includes the credential type, and before the verifier 130 obtains the applicant public key from the distributed identity system according to the applicant distributed identity, the verifier 130 also obtains the credential type in the applicant identity credential, and after verifying that the credential type is a sticker credential, the verifier 130 continues the following credential signature verification process.

[0186] In some embodiments of the application, the identity information digest value is verified to pass and the status of the applicant identity credential is verified to pass, and the verifier 130 generates a credential verification result indicating that the verification passes.

[0187] S440: The verifier 130 sends the credential verification result to the applicant terminal 110.

[0188] S450: The applicant terminal 110 judges that the credential verification passes according to the credential verification result, and sends a business handling request to the verifier.

[0189] S460: The verifier 130 processes the business according to the business handling request.

[0190] In some embodiments of the application, the business handling request that the verifier 130 can handle includes a level upgrade request of a wallet account in a digital wallet application, a loan application request, a purchase insurance request, a purchase financial product request, etc.

[0191] In some embodiments of the identity credential application and identity credential verification of the present application, the interaction of the applicant terminal 120 with the trusted identity management authority 160, the distributed identity system 140, the issuer 120 and the verifier 130 can be carried out through the server corresponding to the applicant terminal, and the request is first sent from the applicant terminal to the server corresponding to the applicant terminal, and then sent by the server corresponding to the applicant terminal to the trusted identity management authority 160, the distributed identity system 140, the issuer 120 and the verifier 130. In turn, the corresponding results of the request are returned to the server corresponding to the applicant terminal first, and then sent by the server corresponding to the applicant terminal to the applicant terminal 110.

[0192] In the embodiment of the present application, after the applicant applies for an identity credential through real person and real evidence verification, the applicant applies for identity verification to the verifier according to the identity credential. The applicant terminal generates an identity credential verifiable expression according to the identity credential, and sends an identity verification request to the verifier. The verifier verifies the authenticity, integrity and validity of the identity credential verifiable expression, thereby realizing the verification of the identity of the applicant. In the embodiment of the present application, the identity credential reflecting the verification result can be safely shared among multiple financial institutions, without the need to repeatedly collect user identity information. Not only does it meet the requirements of various institutions for identity authentication strength, but also greatly improves the convenience of users, reduces the repetitive labor of identity verification among multiple institutions, and optimizes the customer experience.

[0193] The embodiment of the present application provides an identity credential application and verification method. On the one hand, the identity credential is bound to the applicant terminal through the DID identifier without revealing any sensitive personal information, which reflects the user's "real person + real evidence" verification, and takes the verification result as a reference index for whether the current operation device is trustworthy. On the other hand, compared with other general VC credentials, the identity credential can rely on the credential content itself (such as the client public key identifier, the credential time limit, etc.) and the user signature value added when presenting to realize the authenticity and validity verification of the credential.

[0194] In the embodiment of the present application, the distributed identity system and the certificate issuing party system belong to two responsible subjects respectively, and the trusted interaction of data is realized by constructing an online secure transmission channel. In the process of issuing the NFC certificate, the applicant terminal is connected with the trusted management institution to realize the first layer identity verification of the user. After the verification, the identity information obtained by the applicant terminal is transmitted to the certificate issuing party system to realize the second layer identity verification of the user. After the two identity verifications are passed, the user can open the digital identity, obtain the unified digital identity identifier DID, and obtain the NFC certificate. In this double-layer identity verification mode, the user only needs to submit an application to complete the two identity verifications, and at the same time, the distributed identity identifier and the identity certificate, and the key for controlling the distributed identity identifier and the identity certificate are obtained, so that the user operation is simplified, and the authentication strength and interoperability of the digital identity are improved.

[0195] In the embodiment of the present application, the user identity information obtained by the certificate is securely stored in the user terminal device by the public key encryption mode, and any institution or individual cannot obtain the locally stored information. The user can independently extract and use the information from the terminal device according to the business needs, and can present the NFC certificate together. In the presentation process, the "encrypted identity information + NFC certificate" is digitally signed by the user private key and then transmitted to the authorized institution (verification party) for verification, so that the self-management and authorization of the identity information are realized under the premise of ensuring the security of the user privacy.

[0196] The embodiment of the present application provides an NFC certificate identity certificate application and verification method, which allows the identity verification result of a user completed in one financial institution to be recognized and reused by other financial institutions. The user only needs to open the NFC certificate by using the physical identity certificate (such as the second-generation identity card) held by the user through the mobile phone with NFC function, and the verification result can be safely shared between multiple financial institutions without repeated collection of user identity information. This not only meets the requirements of the financial institutions for the identity authentication strength, but also greatly improves the convenience of the user, reduces the repeated labor of identity verification between multiple institutions, and optimizes the customer experience. The financial institutions can provide more flexible and user-friendly services while ensuring business safety. The main problems solved are as follows, first, the security of identity verification is improved, the embodiment of the present application introduces the "real person + real certificate" identity verification capability, and at the same time, the digital identity opened is bound to the trusted device through the double-layer identity verification mode, so that the security and effectiveness of the online identity verification are improved; second, the user identity autonomy is improved, the real identity information and related certificates of the user are encrypted and stored locally in the user device, and the control right of the digital identity is returned to the user; third, the interoperability and convenience are improved, the user can realize the one-time application of the identity certificate in multiple places.

[0197] The embodiment of the present application, as shown in Figure 11, provides an identity credential application device 500 applied to an applicant terminal, wherein the device 500 comprises a second identity verification request module 510, a distributed identity opening request module 520, an identity credential request module 530 and an identity credential receiving module 540, wherein

[0198] The second identity verification request module 510 is configured to send a second identity verification request to an issuing party, so that the issuing party generates a second identity verification result according to the second identity verification request, wherein the second identity verification request comprises applicant identity information and applicant biological feature information, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode;

[0199] The distributed identity opening request module 520 is configured to judge that the applicant identity verification is passed according to the second identity verification result sent by the issuing party, send a distributed identity opening request to a distributed identity system, and receive an applicant distributed identity identifier from the distributed identity system;

[0200] The identity credential request module 530 is configured to send an identity credential application request to the issuing party, so that the issuing party generates an applicant identity credential, wherein the identity credential application request comprises the applicant distributed identity identifier;

[0201] The identity credential receiving module 540 is configured to receive the applicant identity credential from the issuing party, wherein the applicant identity credential comprises a declaration part and a signature part generated by signing the declaration part by a private key of the issuing party, and the declaration part comprises the applicant distributed identity identifier and an issuing party distributed identity identifier.

[0202] In some embodiments of the present application, the device 500 further comprises a distributed identity opening request module 550, which is configured to read the applicant identity information from the external identity certificate through the near field communication mode and collect the applicant biological feature information in response to the distributed identity opening request operation of the applicant, and send a first identity verification request to a trusted identity management institution according to the applicant identity information and the applicant biological feature information, so that the trusted identity management institution generates and returns a first identity verification result according to the first identity verification request, and judges that the applicant identity verification is passed according to the first identity verification result.

[0203] In some embodiments of the present application, the distributed identity opening request module 550 is configured to:

[0204] generate an applicant public key and an applicant private key according to a trusted environment in the applicant terminal, and save the applicant private key in the trusted environment;

[0205] generate the distributed identity opening request according to the applicant public key.

[0206] In some embodiments of the present application, the identity credential application request further comprises an application party public key, and the declaration part comprises the application party public key.

[0207] In some embodiments of the present application, the distributed identity opening request module 550 is further configured to generate a reading information record after obtaining the application party identity information from the external identity certificate through the near field communication mode; and the second identity verification request comprises the reading information record.

[0208] In some embodiments of the present application, the second identity verification result is generated according to the following steps,

[0209] The issuer determines that the application party identity information matches the reading information record, and sends the application party identity information and the application party biometric information to the trusted identity management institution;

[0210] The trusted identity management institution generates a third identity verification result according to the application party identity information and the application party biometric information, and returns the third identity verification result to the issuer;

[0211] The issuer generates the second identity verification result according to the third identity verification result.

[0212] In some embodiments of the present application, the distributed identity opening request module 550 is further configured to encrypt and store the application party identity information and the application party biometric information.

[0213] In some embodiments of the present application, the identity credential receiving module 540 is configured to:

[0214] receive the credential generation notification sent by the issuer;

[0215] download the application party identity credential from the issuer.

[0216] In the embodiments of the present application, as shown in FIG. 12, the embodiments of the present application provide an identity credential application device 600 applied to an issuer, the device 600 comprising a second identity verification result generation module 610, an identity credential generation module 620 and a sending module 630, wherein,

[0217] The second identity verification result generation module 610 is configured to receive a second identity verification request sent by an application party terminal, generate a second identity verification result according to the second identity verification request, and send the second identity verification result to the application party terminal, so that the application party terminal sends a distributed identity opening request to a distributed identity system after determining that the application party identity verification is passed according to the second identity verification result, wherein the second identity verification request comprises application party identity information and application party biometric information, and the application party identity information is obtained by the application party terminal from an external identity certificate through a near field communication mode;

[0218] The identity credential generation module 620 is configured to generate an applicant identity credential in response to an identity credential application request sent by an applicant terminal, wherein the identity credential application request comprises an applicant distributed identity, and the applicant distributed identity is generated by the distributed identity system in response to a distributed identity opening request sent by the applicant terminal;

[0219] The sending module 630 is configured to send the applicant identity credential to the applicant terminal, wherein the applicant identity credential comprises a statement part and a signature part generated by signing the statement part with an issuer private key, and the statement part comprises the applicant distributed identity and the issuer distributed identity.

[0220] In some embodiments of the present application, the apparatus 600 further comprises a verification data uploading module 640 configured to upload verification data of the applicant identity credential to a credential permission chain, wherein the verification data comprises an abstract value and a state of the applicant identity credential.

[0221] In some embodiments of the present application, the second identity verification request is generated according to the following steps,

[0222] In response to a distributed identity opening request of the applicant, the applicant terminal reads the applicant identity information from an external identity certificate through near field communication, collects the applicant biometric information, and sends a first identity verification request to the trusted identity management institution according to the applicant identity information and the applicant biometric information, wherein the first identity verification request comprises the applicant identity information and the applicant biometric information.

[0223] The trusted identity management institution generates a first identity verification result according to the first identity verification request and returns the first identity verification result to the applicant terminal.

[0224] The applicant terminal generates a second identity verification request according to the first identity verification result.

[0225] In some embodiments of the present application, the second identity verification request further comprises a read information record, and the read information record is generated by the applicant terminal after obtaining the applicant identity information from the external identity certificate through near field communication; the second identity verification result generation module 610 is further configured to:

[0226] determine whether the applicant identity information matches the read information record, and send the applicant identity information and the applicant biometric information to the trusted identity management institution to enable the trusted identity management institution to generate a third identity verification result according to the applicant identity information and the applicant biometric information;

[0227] receive the third identity verification result returned by the trusted identity management institution, and generate the second identity verification result according to the third identity verification result.

[0228] In some embodiments of the present application, the identity credential application request further comprises an application party public key, and the statement part further comprises the application party public key.

[0229] In some embodiments of the present application, the statement part further comprises an identity information digest value, and the identity credential generation module 620 is configured to calculate a digest value of the application party identity information and / or the application party biometric information, and obtain the identity information digest value.

[0230] In some embodiments of the present application, the statement part further comprises a credential issuance time and / or a credential expiration time, and the identity credential generation module 620 is configured to:

[0231] set the credential issuance time according to a current time, and / or

[0232] set the credential expiration time as an earlier time of a certificate expiration time and an expiration time of the application party public key, wherein the application party identity information comprises the certificate expiration time.

[0233] In some embodiments of the present application, the statement part further comprises a credential type.

[0234] In some embodiments of the present application, the sending module is configured to:

[0235] send a credential generation notification to the application party terminal, so that the application party terminal sends a credential download request to the issuing party according to the credential generation notification;

[0236] transmit the application party identity credential to the application party terminal according to the credential download request.

[0237] In some embodiments of the present application, the apparatus 600 further comprises a distributed identity opening request module 650 configured to:

[0238] send an issuing party distributed identity opening request containing an issuing party public key to a distributed identity system;

[0239] receive an issuing party distributed identity identifier sent by the distributed identity system, wherein the issuing party distributed identity identifier is generated by the distributed identity system according to the issuing party distributed opening request.

[0240] As shown in FIG. 13, the embodiments of the present application provide an identity credential verification apparatus 700 applied to a verification party, the apparatus 700 comprises an identity verification request receiving module 710, a verification module 720 and a sending module 730, wherein:

[0241] The identity authentication request receiving module 710 is configured to receive an identity authentication request sent by the applicant terminal, wherein the identity authentication request comprises an identity credential verifiable expression, the identity credential verifiable expression comprises identity credential related information and a credential signature generated by signing the identity credential related information by the applicant private key, the identity credential related information comprises an applicant identity credential issued by an issuer, the applicant identity credential comprises a statement part and a signature part generated by signing the statement part by an issuer private key, the statement part comprises an applicant distributed identity and an issuer distributed identity, the applicant distributed identity is generated according to an applicant public key after the applicant identity information and the applicant biometric information are verified to be correct, and the applicant identity information is read from an external identity certificate by the applicant terminal through near field communication;

[0242] The verification module 720 is configured to verify the identity credential verifiable expression and generate a credential verification result.

[0243] The sending module 730 is configured to send the credential verification result to the applicant terminal.

[0244] In some embodiments of the present application, the applicant identity credential further comprises a credential issuance time and / or a credential expiration time, and the verification module 720 is further configured to:

[0245] verify the validity period of the applicant identity credential according to the current time, the credential issuance time and / or the credential expiration time.

[0246] In some embodiments of the present application, the statement part comprises an applicant public key, and the verification module 720 is further configured to:

[0247] obtain the applicant public key from the distributed identity system according to the applicant distributed identity;

[0248] check whether the applicant public key in the applicant identity credential is consistent with the applicant public key obtained from the distributed identity system, and in the case of consistency, verify the credential signature by using the applicant public key to generate a credential signature verification result;

[0249] generate the credential verification result according to the credential signature verification result.

[0250] In some embodiments of the present application, the verification module 720 is further configured to:

[0251] determine that the credential signature verification is passed according to the credential signature verification result, obtain an issuer public key from the distributed identity system according to the issuer distributed identity;

[0252] verify the signature part by using the issuer public key to generate a signature part verification result;

[0253] According to the signature part verification result, a credential verification result is generated.

[0254] In some embodiments of the present application, the verification module 720 is further configured to:

[0255] According to the signature part verification result, it is determined that the signature part verification is passed, and a credential digest value is generated according to the applicant identity credential.

[0256] The credential digest value is sent to the credential permission chain, so that the credential permission chain obtains verification data according to the credential digest value, and generates a credential status verification result according to the verification data.

[0257] According to the credential status verification result sent by the credential permission chain, it is determined that the status verification of the applicant identity credential is passed, and a credential verification result indicating that the verification is passed is generated.

[0258] In some embodiments of the present application, the identity credential related information further includes applicant identity information and / or applicant biological feature information, and the declaration part further includes an identity information digest value; the verification module 720 is further configured to:

[0259] According to the signature part verification result, it is determined that the signature part verification is passed, and a business identity information digest value is generated according to the applicant identity information and / or the applicant biological feature information.

[0260] According to the identity information digest value, the business identity information digest value is checked, and a business identity information verification result is generated.

[0261] In some embodiments of the present application, the declaration part includes a credential type, and the verification module 720 is further configured to:

[0262] The credential type in the applicant identity credential is obtained, and it is checked that the credential type is a sticker credential.

[0263] In some embodiments of the present application, the device 700 further includes a business processing module 740, which is configured to:

[0264] The business processing module 740 receives a business handling request sent by the applicant terminal, wherein the business handling request is generated by the applicant terminal according to the indication of the credential verification result that the verification is passed.

[0265] The business processing module 740 processes the business according to the business handling request.

[0266] As shown in FIG. 14, the embodiment of the present application provides an identity credential verification device 800 applied to an applicant terminal, wherein the device 800 includes a verifiable expression generation module 810, an identity verification request sending module 820 and a receiving module 830, wherein:

[0267] The verifiable expression generation module 810 is configured to obtain the locally stored identity credential related information, and generate an identity credential verifiable expression according to the identity credential related information, wherein the identity credential verifiable expression comprises the identity credential related information and a credential signature generated by signing the identity credential related information with the application party private key, and the identity credential related information comprises an application party identity credential issued by an issuing party, the application party identity credential comprising a statement part and a signature part generated by signing the statement part with the issuing party private key, and the statement part comprising an application party distributed identity and an issuing party distributed identity, the application party distributed identity being generated according to the application party public key after the application party identity information and the application party biometric information are verified to be correct, and the application party identity information being read from an external identity certificate by the application party terminal through near field communication;

[0268] The identity authentication request sending module 820 is configured to send an identity authentication request to the verification party, wherein the identity authentication request comprises the identity credential verifiable expression.

[0269] The receiving module 830 is configured to receive a credential verification result sent by the verification party, the credential verification result being generated by the verification party after verifying the identity credential verifiable expression.

[0270] In some embodiments of the present application, the statement part further comprises an application party identity information digest value, and the identity credential related information further comprises the application party identity information and / or the application party biometric information.

[0271] In some embodiments of the present application, the statement part further comprises an application party public key.

[0272] In some embodiments of the present application, the device 800 further comprises a service handling request module 840 configured to:

[0273] According to the credential verification result, it is determined that the credential verification is passed, and a service handling request is sent to the verification party, so that the verification party performs service processing according to the service handling request.

[0274] The device features of the embodiments of the present application can refer to the method features and the like of the embodiments of the present application, and the system embodiments can combine the features of the method embodiments to obtain new embodiments, and vice versa, which will not be described here again.

[0275] In the embodiments of the present application, an electronic device is provided, which comprises a processor and a memory storing a computer program, the processor being configured to implement any method according to the embodiments of the present application when running the computer program. In addition, an apparatus according to the embodiments of the present application can also be provided.

[0276] FIG. 15 shows an exemplary system architecture 1500 to which embodiments of the present application can apply an identity credential application, a wallet identity verification method or an identity credential application, a wallet identity verification apparatus.

[0277] As shown in FIG. 15, the system architecture 1500 can include terminal devices 1501, 1502, 1503, a network 1504 and a server 1505. The network 1504 is a medium for providing a communication link between the terminal devices 1501, 1502, 1503 and the server 1505. The network 1504 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0278] A user can use the terminal devices 1501, 1502, 1503 to interact with the server 1505 through the network 1504 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 1501, 1502, 1503, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0279] The terminal devices 1501, 1502, 1503 can be various electronic devices with display screens and support for web browsing, including but not limited to smartphones, tablet computers, laptop computers and desktop computers, etc.

[0280] The server 1505 can be a server that provides various services, such as a background management server that provides support for shopping websites browsed by users using the terminal devices 1501, 1502, 1503 (only as an example). The background management server can analyze and process received product information query requests and other data, and feed back the processing results (such as target push information, product information - only as examples) to the terminal devices.

[0281] It should be noted that the identity credential application, the wallet identity verification method provided by the embodiments of the present application is generally executed by the server 1505, and accordingly, the identity credential application, the wallet identity verification implementation apparatus is generally provided in the server 1505.

[0282] It should be understood that the number of terminal devices, networks and servers in FIG. 15 is only illustrative. According to the needs of implementation, there can be any number of terminal devices, networks and servers.

[0283] Reference will now be made to FIG. 16, which shows a structural diagram of a computer system 1600 suitable for use in implementing the terminal device or server of embodiments of the present application. The method or apparatus for implementing the method of embodiments of the present application can be implemented on the computer system 1600. The terminal device or server shown in FIG. 16 is merely an example and should not impose any limitation on the functions and use range of embodiments of the present application.

[0284] As shown in FIG. 16, the computer system 1600 includes a central processing unit (CPU) 1601, which can perform various appropriate actions and processes according to programs stored in a read only memory (ROM) 1602 or programs loaded from a storage section 1608 into a random access memory (RAM) 1603. Various programs and data required for the operation of the system 1600 are also stored in the RAM 1603. The CPU 1601, the ROM 1602, and the RAM 1603 are connected to each other through a bus 1604. An input / output (I / O) interface 1605 is also connected to the bus 1604.

[0285] The following components are connected to the I / O interface 1605: an input section 1606 including a keyboard, a mouse, etc.; an output section 1607 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1608 including a hard disk, etc.; and a communication section 1609 including a network interface card such as a LAN card, a modem, etc. The communication section 1609 performs communication processing via a network such as the Internet. A drive 1610 is also connected to the I / O interface 1605 as necessary. A removable recording medium 1611 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 1610 as necessary, so that a computer program read therefrom is installed into the storage section 1608 as necessary.

[0286] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to embodiments of the present application. For example, embodiments of the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program code for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network by the communication section 1609 and / or installed from the removable recording medium 1611. When the computer program is executed by the central processing unit (CPU) 1601, the above-described functions defined in the system of the present application are executed.

[0287] It should be noted that the computer-readable medium shown in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component. In the present application, the computer-readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or component. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0288] The flowcharts and block diagrams in the drawings illustrate the possible implementation architectures, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment or a part of code containing one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order than that shown in the drawings. For example, two blocks that are shown in succession can actually be executed substantially in parallel, and sometimes in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams or flowcharts, and the combination of blocks in the block diagrams or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0289] The units or modules described in the embodiments of the present application can be implemented by software or by hardware. The described units or modules can also be arranged in a processor, for example, a processor can be described as including a sending unit (or a module), an obtaining unit, a determining unit and a first processing unit. In some cases, the names of the units or modules do not constitute a limitation on the units or modules themselves, for example, the sending unit can also be described as a unit that sends a picture obtaining request to a connected server.

[0290] As another aspect, the present application also provides a computer readable medium, which can be included in the device described in the above embodiments, or can exist independently without being assembled into the device. The computer readable medium carries one or more programs, which, when executed by the device, cause the device to perform the identity credential application and wallet identity verification method in the above embodiments.

[0291] The specific embodiments described above do not constitute a limitation on the scope of protection of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made depending on design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application should be included in the scope of protection of the present application. Industrial applicability

[0292] The scheme provided by the embodiments of the present application can be applied to the field of computer technology. In the embodiments of the present application, the applicant terminal sends a second identity verification request to the issuing party, the issuing party generates a second identity verification result according to the second identity verification request; the applicant terminal judges that the applicant identity verification is passed according to the second identity verification result sent by the issuing party, sends a distributed identity opening request to the distributed identity system, and receives an applicant distributed identity identifier from the distributed identity system; the applicant terminal sends an identity credential application request to the issuing party or the issuing party generates an applicant identity credential and uploads verification data of the applicant identity credential to a credential permission chain, and the issuing party generates an applicant identity credential; the applicant terminal receives the applicant identity credential from the issuing party. The verification party receives the identity verification request sent by the applicant terminal; the verification party verifies the identity credential verifiable expression and generates a credential verification result; and the verification party sends the credential verification result to the applicant terminal. On the basis of ensuring the security of identity information, the operation of repeatedly submitting identity information by the user is reduced, and the user experience is improved.

Claims

1. An identity credential application method applied to an applicant terminal, the method comprising: sending a second identity verification request to an issuer to enable the issuer to generate a second identity verification result according to the second identity verification request, wherein the second identity verification request comprises applicant identity information and applicant biometric information, the applicant identity information being read from an external identity document by the applicant terminal through near field communication; judging that the applicant identity verification is passed according to the second identity verification result sent by the issuer, sending a distributed identity opening request to a distributed identity system, and receiving an applicant distributed identity identifier from the distributed identity system; sending an identity credential application request to the issuer to enable the issuer to generate an applicant identity credential, wherein the identity credential application request comprises the applicant distributed identity identifier; receiving the applicant identity credential from the issuer, wherein the applicant identity credential comprises a statement part, and the statement part comprises the applicant distributed identity identifier.

2. The method of claim 1, wherein, The applicant identity credential further comprises a signature part generated by signing the statement part with an issuer private key, and the statement part further comprises the issuer distributed identity identifier.

3. The method of claim 1, wherein, The sending of the identity credential application request to the issuer to enable the issuer to generate the applicant identity credential comprises: sending the identity credential application request to the issuer to enable the issuer to generate the applicant identity credential and upload verification data of the applicant identity credential to a credential permission chain, wherein the verification data comprises a digest value of the applicant identity credential.

4. The method of claim 1, wherein, Before the sending of the second identity verification request to the issuer, the method further comprises: in response to the distributed identity opening request operation of the applicant, reading the applicant identity information from the external identity document through near field communication and collecting the applicant biometric information, sending a first identity verification request to a trusted identity management institution according to the applicant identity information and the applicant biometric information to enable the trusted identity management institution to generate and return a first identity verification result according to the first identity verification request, and judging that the applicant identity verification is passed according to the first identity verification result.

5. The method of claim 1, wherein, The sending of the distributed identity opening request to the distributed identity system comprises: generating an applicant public key and an applicant private key according to a trusted environment in the applicant terminal, and saving the applicant private key in the trusted environment; generating the distributed identity opening request according to the applicant public key.

6. The method of claim 5, wherein, The identity credential application request further comprises the applicant public key, and the statement part comprises the applicant public key.

7. The method of claim 4, wherein, The method further comprises: generating a reading information record after the applicant identity information is obtained from the external identity document through near field communication; and the second identity verification request comprises the reading information record.

8. The method of claim 7, wherein, The second identity verification result is generated according to the following steps, the issuer judges that the applicant identity information matches the reading information record, and sends the applicant identity information and the applicant biometric information to the trusted identity management institution; The trusted identity management institution generates a third identity verification result according to the applicant identity information and the applicant biometric information, and returns the third identity verification result to the issuing party; The issuing party generates the second identity verification result according to the third identity verification result.

9. The method of claim 4, wherein, The method further comprises: encrypting and storing the applicant identity information and the applicant biometric information.

10. The method of claim 1, wherein, The receiving of the applicant identity credential from the issuing party comprises: Receiving a credential generation notification sent by the issuing party; Downloading the applicant identity credential from the issuing party.

11. An identity credential application method applied to an issuing party, the method comprising: Receiving a second identity verification request sent by an applicant terminal, generating a second identity verification result according to the second identity verification request, and sending the second identity verification result to the applicant terminal, so that the applicant terminal judges that the applicant identity verification is passed according to the second identity verification result, and sends a distributed identity opening request to a distributed identity system, wherein the second identity verification request comprises applicant identity information and applicant biometric information, and the applicant identity information is read from an external identity certificate by the applicant terminal through a near field communication mode; Receiving an identity credential application request sent by the applicant terminal, and generating an applicant identity credential, wherein the identity credential application request comprises an applicant distributed identity identifier, and the applicant distributed identity identifier is generated by the distributed identity system after receiving the distributed identity opening request sent by the applicant terminal; Sending the applicant identity credential to the applicant terminal, wherein the applicant identity credential comprises a declaration part, and the declaration part comprises the applicant distributed identity identifier.

12. The method of claim 11, wherein, The applicant identity credential further comprises a signature part generated by signing the declaration part with an issuing party private key, and the declaration part further comprises an issuing party distributed identity identifier.

13. The method of claim 11, wherein, After generating the applicant identity credential, the method further comprises: uploading verification data of the applicant identity credential to a credential permission chain, and the verification data comprises a digest value of the applicant identity credential.

14. The method of claim 13, wherein, The verification data further comprises a state of the applicant identity credential.

15. The method of claim 11, wherein, The second identity verification request is generated according to the following steps, The applicant terminal reads the applicant identity information from an external identity certificate through a near field communication mode in response to a distributed identity opening request operation of the applicant, collects the applicant biometric information, and sends a first identity verification request to a trusted identity management institution according to the applicant identity information and the applicant biometric information, wherein the first identity verification request comprises the applicant identity information and the applicant biometric information; The trusted identity management institution generates a first identity verification result according to the first identity verification request, and returns the first identity verification result to the applicant terminal; The applicant terminal generates the second identity verification request after judging that the applicant identity verification is passed according to the first identity verification result.

16. The method of claim 15, wherein, The second identity authentication request further comprises a reading information record, which is generated by the applicant terminal after obtaining the applicant identity information from the external identity certificate through near field communication; The second identity authentication result is generated according to the second identity authentication request, comprising: determining whether the applicant identity information matches the reading information record, and sending the applicant identity information and the applicant biometric information to a trusted identity management institution if the applicant identity information matches the reading information record, so that the trusted identity management institution generates a third identity authentication result according to the applicant identity information and the applicant biometric information; receiving the third identity authentication result returned by the trusted identity management institution, and generating the second identity authentication result according to the third identity authentication result.

17. The method of claim 11, wherein, The identity certificate application request further comprises an applicant public key, and the statement part further comprises the applicant public key.

18. The method of claim 11, wherein, The statement part further comprises an identity information digest value, and the applicant identity certificate is generated, comprising: calculating a digest value of the applicant identity information and / or the applicant biometric information to obtain the identity information digest value.

19. The method of claim 11, wherein, The statement part further comprises a certificate issuance time and / or a certificate expiration time, and the applicant identity certificate is generated, further comprising: setting the certificate issuance time according to the current time, and / or setting the certificate expiration time as the earlier time of the certificate expiration time and the expiration time of the applicant public key, wherein the applicant identity information comprises the certificate expiration time.

20. The method of claim 11, wherein, The statement part further comprises a certificate type.

21. The method of claim 11, wherein, The applicant identity certificate is sent to the applicant terminal, comprising: sending a certificate generation notification to the applicant terminal, so that the applicant terminal sends a certificate download request to the issuer according to the certificate generation notification; transmitting the applicant identity certificate to the applicant terminal according to the certificate download request.

22. The method of claim 11, wherein, Before receiving the second identity authentication request sent by the applicant terminal, the method further comprises: sending an issuer distributed identity opening request containing an issuer public key to a distributed identity system; receiving an issuer distributed identity identifier sent by the distributed identity system, wherein the issuer distributed identity identifier is generated by the distributed identity system according to the issuer distributed opening request.

23. An identity certificate verification method applied to a verifier, the method comprising: receiving an identity authentication request sent by an applicant terminal, wherein the identity authentication request comprises an identity certificate verifiable expression, the identity certificate verifiable expression comprises identity certificate related information and a certificate signature generated by signing the identity certificate related information with an applicant private key, and the identity certificate related information comprises an applicant identity certificate issued by an issuer, the applicant identity certificate comprises a statement part, and the statement part comprises an applicant distributed identity identifier, which is generated according to an applicant public key after the applicant identity information and the applicant biometric information are verified, and the applicant identity information is read from an external identity certificate by the applicant terminal through near field communication; verifying the identity credential verifiable expression, to generate a credential verification result; sending the credential verification result to the applicant terminal.

24. The method of claim 23, wherein, The applicant identity credential further comprises a signature part generated by signing the statement part with an issuer private key, and the statement part further comprises an issuer distributed identity.

25. The method of claim 23, wherein, The applicant identity credential further comprises a credential issuance time and / or a credential expiration time, and the verifying the identity credential verifiable expression, to generate a credential verification result, comprises: verifying a validity period of the applicant identity credential according to a current time, the credential issuance time and / or the credential expiration time.

26. The method of claim 23 or 24, wherein, The statement part comprises an applicant public key, and the verifying the identity credential verifiable expression, to generate a credential verification result, further comprises: obtaining an applicant public key from a distributed identity system according to the applicant distributed identity; verifying whether the applicant public key in the applicant identity credential is consistent with the applicant public key obtained from the distributed identity system, and in the case of consistency, verifying the credential signature with the applicant public key to generate a credential signature verification result; generating the credential verification result according to the credential signature verification result.

27. The method of claim 26, wherein, The generating the credential verification result according to the credential signature verification result comprises: judging that the credential signature verification passes according to the credential signature verification result, obtaining an issuer public key from a distributed identity system according to the issuer distributed identity; verifying the signature part with the issuer public key to generate a signature part verification result; generating the credential verification result according to the signature part verification result.

28. The method of claim 27, wherein, The generating the credential verification result according to the signature part verification result comprises: judging that the signature part verification passes according to the signature part verification result, generating a credential digest value according to the applicant identity credential; sending the credential digest value to a credential permission chain, so that the credential permission chain obtains verification data according to the credential digest value, and generates a credential status verification result according to the verification data; judging that the status verification of the applicant identity credential passes according to the credential status verification result sent by the credential permission chain, to generate a credential verification result indicating that the verification passes.

29. The method of claim 27, wherein, The identity credential related information further comprises applicant identity information and / or applicant biometric information, and the statement part further comprises an identity information digest value; the generating the credential verification result according to the signature part verification result further comprises: judging that the signature part verification passes according to the signature part verification result, generating a business identity information digest value according to the applicant identity information and / or the applicant biometric information; verifying the business identity information digest value according to the identity information digest value, to generate a business identity information verification result.

30. The method of claim 26, wherein, The generating the credential verification result according to the credential signature verification result comprises: judging that the credential signature verification passes according to the credential signature verification result, generating a credential digest value according to the applicant identity credential; sending the credential digest value to a credential permission chain, so that the credential permission chain acquires verification data according to the credential digest value, and generates a credential integrity verification result according to the verification data, wherein the verification data is generated by an issuing party according to the applicant identity credential after the applicant identity credential is generated, and the verification data includes a digest value of the applicant identity credential; generating the credential verification result according to the credential integrity verification result sent by the credential permission chain.

31. The method of claim 30, wherein, The verification data further includes a state of the applicant identity credential, and the generating of the credential verification result according to the credential integrity verification result sent by the credential permission chain includes: receiving a credential state verification result returned by the credential permission chain, wherein the credential state verification result is generated by the credential permission chain according to the state of the applicant identity credential; generating a credential verification result indicating that the verification is passed, according to the judgment that the state verification of the applicant identity credential is passed according to the credential state verification result.

32. The method of claim 30, wherein, The identity credential related information further includes applicant identity information and / or applicant biometric information, and the declaration part further includes an identity information digest value; and the generating of the credential verification result according to the credential integrity verification result sent by the credential permission chain further includes: judging that the integrity verification of the applicant identity credential is passed according to the credential integrity verification result, generating a business identity information digest value according to the applicant identity information and / or the applicant biometric information; generating a business identity information verification result according to the verification of the business identity information digest value on the business identity information digest value.

33. The method of claim 26, wherein, The declaration part includes a credential type, and before the acquiring of the applicant public key from the distributed identity system according to the applicant distributed identity, the verifying of the identity credential verifiable expression to generate a credential verification result further includes: acquiring the credential type in the applicant identity credential, and verifying that the credential type is a credential.

34. The method of claim 23, wherein, The method further includes: receiving a business handling request sent by an applicant terminal, wherein the business handling request is generated by the applicant terminal according to the case that the credential verification result indicates that the verification is passed; performing business processing according to the business handling request.

35. An identity credential verification method applied to an applicant terminal, the method comprising: acquiring locally stored identity credential related information, and generating an identity credential verifiable expression according to the identity credential related information, wherein the identity credential verifiable expression includes the identity credential related information and a credential signature generated by signing the identity credential related information by a private key of the applicant, the identity credential related information includes an applicant identity credential issued by an issuing party, the applicant identity credential includes a declaration part, the declaration part includes an applicant distributed identity, the applicant distributed identity is generated according to an applicant public key after the verification of applicant identity information and applicant biometric information is passed, and the applicant identity information is read from an external identity certificate by the applicant terminal through near field communication. sending an identity authentication request to a verifier, wherein the identity authentication request comprises the identity credential verifiable expression; receiving a credential verification result sent by the verifier, the credential verification result being generated by the verifier after verifying the identity credential verifiable expression.

36. The method of claim 35, wherein, The applicant identity credential further comprises a signature part generated by signing the claim part with a private key of an issuing party, and the claim part further comprises a distributed identity of the issuing party.

37. The method of claim 35, wherein, The claim part further comprises an applicant identity information digest value, and the identity credential related information further comprises applicant identity information and / or applicant biometric information.

38. The method of claim 35, wherein, The claim part further comprises an applicant public key.

39. The method of claim 35, further comprising: judging, according to the credential verification result, that the credential verification is passed, and sending a service handling request to the verifier to make the verifier handle a service according to the service handling request.

40. An electronic device, comprising: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1-39.

41. A computer readable medium having stored thereon a computer program, the program being executed by a processor to implement the method of any one of claims 1-39.

Citation Information

Patent Citations

  • Identity authorization method and device, storage medium and equipment

    CN112291245A

  • Distributed power transaction credible identity management method and system, and computer equipment

    CN113761497A

  • Identity authentication method, certificate holding system and verification system

    CN113918899A

  • Digital identity registration method and digital identity registration system

    CN116108411A

  • Mobile platform distributed digital identity authentication method and device and medium

    CN116886357A