Integrated business identity verification and payment method, and apparatus
By integrating business identity verification and payment through distributed identity identifiers and verifiable credentials, the system solves the problems of low efficiency and high privacy risks in traditional business processing, thereby improving user experience and security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2026-03-26
AI Technical Summary
In traditional business transactions, users need to carry physical ID cards and bank cards, and the process needs to be repeated every time a transaction is conducted, resulting in low efficiency and a high risk of privacy information leakage. Existing digital identity credential models have failed to effectively improve the user experience.
By using distributed identity identifiers and verifiable credentials, identity verification and payment are integrated. Users generate verifiable credentials using distributed identity identifiers, and the verifier verifies and confirms them before directly processing the payment, reducing redundant operations and information leakage.
It improved business processing efficiency, reduced the need for repeated verification and storage of user identity information, lowered the risk of privacy leaks, and optimized the user experience.
Smart Images

Figure CN2025121080_26032026_PF_FP_ABST
Abstract
Description
Integrated business identity verification and payment method and device
[0001] The present application claims priority to the Chinese patent application No. 202411320274.9, filed on September 20, 2024, and entitled "Integrated business identity verification and payment method and device", the whole content of which is incorporated herein by reference. TECHNICAL FIELD
[0002] The present application relates to the technical field of computer, and in particular to an integrated business identity verification and payment method and device, an electronic device and a computer readable medium. BACKGROUND
[0003] In a traditional business handling scenario, a user needs to provide a physical identity card and a bank card to a business service provider (verifier), and the business service provider verifies the user's identity and then deducts or freezes the corresponding prepayment by swiping the bank card. In this process, the user not only needs to carry an identity card, a bank card and other physical cards, but also needs to show real identity attribute information or biometric information to the business service provider, and the user needs to repeat the above operations every time he handles a business. This traditional business handling and payment method has the following problems: first, it is not suitable for the case where the user forgets to carry the identity card or the bank card; second, the business service provider needs to specially enter and recognize the information, which reduces the handling efficiency and affects the user experience; third, it causes the user's identity information to be repeatedly stored in multiple places, increasing the risk of user privacy information leakage. At present, although there are corresponding technical means to convert the user's physical identity credentials into digital identity credentials, and the user can realize online payment through online banking or third-party payment tools without carrying a bank card, in this combination mode, on the one hand, the business service provider still needs to collect biometric information such as facial features to ensure the consistency of the user himself and the digital identity credentials every time the user handles a business, and on the other hand, the user still needs to complete two independent operations (identity authentication + payment) to complete the business handling, and the user experience has not been substantially improved. SUMMARY
[0004] Therefore, in a first aspect, an integrated business identity verification and payment method is provided, which is applied to a verifier, and the method comprises:
[0005] receiving a business handling request sent by an applicant terminal, wherein the business handling request comprises a verifiable expression, and the verifiable expression comprises an applicant distributed identity, an applicant identity certificate issued by an identity issuing party, an applicant payment identity certificate issued by a payment service party, and a certificate signature generated by signing the applicant distributed identity, the applicant identity certificate and the applicant payment identity certificate with an applicant private key;
[0006] According to the application party distributed identity, the verifiable expression is verified, and a credential verification result is generated;
[0007] According to the credential verification result, it is judged that the verifiable expression is verified, and payment information is sent to the application party terminal, so that the application party confirms the payment information;
[0008] The payment confirmation response sent by the application party terminal is received, it is judged according to the payment confirmation response that the application party confirms the payment information, and the payment service party is sent a payment request according to the application party distributed identity and the payment information, so that the payment service party performs payment processing.
[0009] The second aspect of the embodiment of the application also provides an integrated business identity verification and payment method, which is applied to an application party terminal, and the method comprises the following steps:
[0010] An application party identity certificate issued by an identity issuing party and an application party payment identity certificate issued by a payment service party are obtained, and a verifiable expression is generated according to the application party identity certificate and the application party payment identity certificate, wherein the verifiable expression comprises an application party distributed identity, the application party identity certificate, the application party payment identity certificate, and a credential signature generated by signing the application party distributed identity, the application party identity certificate and the application party payment identity certificate by an application party private key;
[0011] A business handling request is sent to a verification party, wherein the business handling request comprises the verifiable expression;
[0012] Payment information sent by the verification party is received, wherein the payment information is generated after the verification party verifies the verifiable expression and the verification is passed;
[0013] A payment confirmation response is sent to the verification party, so that the verification party sends a payment request to the payment service party according to the application party distributed identity and the payment information, and the payment service party performs payment processing.
[0014] The third aspect of the embodiment of the application also provides an integrated business identity verification and payment device, which is applied to a verification party, and the device comprises a receiving module, a verification module, a payment information sending module and a payment processing module, wherein
[0015] The receiving module is configured to receive a business handling request sent by an application party terminal, wherein the business handling request comprises a verifiable expression, and the verifiable expression comprises an application party distributed identity, an application party identity certificate issued by an identity issuing party, an application party payment identity certificate issued by a payment service party, and a credential signature generated by signing the application party distributed identity, the application party identity certificate and the application party payment identity certificate by an application party private key;
[0016] The verification module is configured to verify the verifiable expression according to the distributed identity of the applicant, and generate a credential verification result.
[0017] The payment information sending module is configured to send payment information to the terminal of the applicant according to the credential verification result, so that the applicant confirms the payment information.
[0018] The payment processing module is configured to receive a payment confirmation response sent by the terminal of the applicant, judge whether the applicant confirms the payment information according to the payment confirmation response, and send a payment request to the payment service party according to the distributed identity of the applicant and the payment information, so that the payment service party performs payment processing.
[0019] The fourth aspect of the embodiment of the application further provides an integrated business identity verification and payment device applied to a terminal of an applicant, the device comprising a certificate obtaining module, a business processing module, a payment information receiving module and a payment confirmation module, wherein
[0020] The certificate obtaining module is configured to obtain an identity certificate of the applicant issued by an identity issuing party and a payment identity certificate of the applicant issued by a payment service party, and generate a verifiable expression according to the identity certificate of the applicant and the payment identity certificate of the applicant, wherein the verifiable expression comprises a distributed identity of the applicant, the identity certificate of the applicant, the payment identity certificate of the applicant and a certificate signature generated by signing the distributed identity of the applicant, the identity certificate of the applicant and the payment identity certificate of the applicant by a private key of the applicant.
[0021] The business processing module is configured to send a business processing request to a verification party, wherein the business processing request comprises the verifiable expression.
[0022] The payment information receiving module is configured to receive payment information sent by the verification party, wherein the payment information is generated after the verification party verifies the verifiable expression and the verification is passed.
[0023] The payment confirmation module is configured to send a payment confirmation response to the verification party, so that the verification party sends a payment request to the payment service party according to the distributed identity of the applicant and the payment information, and the payment service party performs payment processing.
[0024] The fifth aspect of the embodiment of the application provides an electronic device, comprising one or more processors, and a storage device configured to store one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method provided by the embodiment of the application.
[0025] The sixth aspect of the embodiment of the application provides a computer readable medium, which stores a computer program, when the program is executed by a processor, the method provided by the embodiment of the application is implemented.
[0026] One embodiment in the above application has the following advantages or beneficial effects:
[0027] In the embodiment of the application, the user (applicant) can apply for a proof certificate to the identity issuing party and the payment service party by using the distributed identity of the applicant, generate a verifiable expression by using the proof certificate and the private key of the user, submit a business handling request containing the verifiable expression to the verification party, and the verification party verifies the verifiable expression after obtaining the public key of the applicant from the distributed identity system by using the distributed identity of the applicant, and sends the payment information to the terminal of the applicant after determining that the verification is passed, so that the payment service party sends a payment request to the verification party after the applicant confirms the payment information, and the payment service party processes the payment, thereby realizing the effect of integrated business identity verification and payment, effectively improving the efficiency of the user in handling the business, and reducing the information leakage risk caused by repeated identity verification and repeated storage of the user's identity information in multiple places.
[0028] The further effects of the above-mentioned non-conventional optional mode will be described in the following combined with the specific embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0029] The accompanying drawings are used to better understand the application and do not constitute an improper limitation on the application. Among them:
[0030] Fig. 1 is a schematic diagram of the architecture of a network system running an integrated business identity verification and payment method according to some embodiments of the application;
[0031] Fig. 2 is a schematic diagram of the flow of an integrated business identity verification and payment method according to some embodiments of the application;
[0032] Fig. 3a is a schematic diagram of the flow of the identity issuing party applying for a distributed identity according to some embodiments of the application;
[0033] Fig. 3b is a schematic diagram of the flow of the payment service party applying for a distributed identity according to some embodiments of the application;
[0034] Fig. 4 is a schematic diagram of the flow of the applicant applying for a distributed identity according to some embodiments of the application;
[0035] Fig. 5a is a schematic diagram of the flow of the applicant applying for an identity proof certificate according to some embodiments of the application;
[0036] Fig. 5b is a schematic diagram of the flow of the applicant applying for a payment identity certificate according to some embodiments of the application;
[0037] Fig. 6 is a schematic diagram of the flow of the verification party verifying the signature of the certificate according to some embodiments of the application;
[0038] FIG. 7 is a flow diagram illustrating a process of verifying a signature part of a proof credential by a verifier according to some embodiments of the present application;
[0039] FIG. 8 is a flow diagram illustrating a process of verifying the validity of a proof credential by a verifier according to some embodiments of the present application;
[0040] FIG. 9 is a functional architecture diagram of an integrated business identity verification and payment device according to some embodiments of the present application;
[0041] FIG. 10 is a functional architecture diagram of an integrated business identity verification and payment device according to some other embodiments of the present application;
[0042] FIG. 11 is an exemplary system architecture diagram in which embodiments of the present application can be applied;
[0043] FIG. 12 is a structural diagram of a computer system of a terminal device or a server suitable for implementing embodiments of the present application. DETAILED DESCRIPTION
[0044] Exemplary embodiments of the present application are described herein with reference to the accompanying drawings, which are meant to be exemplary and not limiting. Therefore, it should be recognized that many changes and modifications can be made to the embodiments described herein, without departing from the spirit and scope of the application. Also, for the purpose of clarity and a concise description, descriptions of well-known functions and constructions can be omitted in the following detailed description.
[0045] First, the abbreviations and related terms involved in embodiments of the present application are defined and explained.
[0046] “DID (Decentralized Identifiers)” refers to a distributed identity, an identifier composed of a string of characters to represent a digital identity, a DID is generated by a distributed identity system based on the public key and other information of an applicant, and the distributed identity system also stores a DID document corresponding to the DID, and the DID document stores the DID and the public key corresponding to the DID;
[0047] “VC (Verifiable Credential)” refers to a verifiable credential, usually a JSON string, containing VC metadata, a statement part and a proof part, the VC metadata mainly includes the issuer, the issuance date and the type of the statement, etc. Information, the statement part is one or more specific statements about the subject, for example, if the VC is an identity card, the statement part will contain the name, gender, date of birth, nationality, address and other personal information of the holder, the proof part is usually the digital signature of the issuer, which is used to ensure the integrity and authenticity of the VC content, prevent tampering, and verify the identity of the issuer of the VC;
[0048] A VP (Verifiable Presentation) is a verifiable presentation associated with a user's distributed identity, containing a verifiable proof file synthesized from one or more verifiable credentials VC, digitally signed by the user.
[0049] In the existing business handling process, for example, in the hotel check-in handling process, the user often needs to provide a physical identity certificate and a bank card to the hotel side when checking into the hotel. After the hotel verifies the user's identity, the corresponding prepayment is deducted or frozen by swiping the bank card. In this process, the user not only needs to carry an identity card, a bank card, and other entity cards, but also needs to show the real identity attribute information or biometric information to the hotel side, and the user needs to repeat the above operation every time he checks into the same or different hotel, which brings poor experience and the risk of information leakage.
[0050] The embodiment of the present application provides an integrated business identity verification and payment method, which realizes the digitization of user's various entity credentials, the self-management and authorization of the user's own digital credentials, the integrated application and migratable application of the user's digital credentials, improves the business handling efficiency of the user, optimizes the user experience, and better realizes the security protection of the user's private information.
[0051] The embodiment of the present application is based on a distributed identity, breaks through the independent status of the identity authentication system between different systems (for example, between the proof issuing party and the verification party), realizes the identity commonality, and realizes the transmission of the verification results between different systems by using the transmission of the proof credentials, thereby improving the efficiency of business handling.
[0052] As shown in FIG. 1, a network system 100 in the embodiment of the present application is shown, and the integrated business identity verification and payment method in the embodiment of the present application can be run into the network system 100. The network system 100 includes an applicant terminal 110, an identity issuing party 120a, a payment service party 120b, a verification party 130, a distributed identity system 140, a credential permission chain 150, and a trusted identity management institution 160.
[0053] In the embodiment of the present application, the applicant terminal 110 can be a terminal containing a digital wallet application. The applicant can use the digital wallet application to apply for a distributed identity, apply for a certificate, organize and send a service request (such as a hotel check-in service), and the like. The applicant terminal 110 can also be provided with a trusted environment for generating a public key and a private key of the applicant and storing the issued certificate. In the embodiment of the present application, the trusted environment is a secure area on the applicant terminal, which can ensure the security of the data loaded therein, including confidentiality, integrity, and availability. The trusted environment can be a trusted execution environment (TEE), a secure element (SE), a trusted cryptographic module (TCM), or other secure boundary protection areas. In some embodiments of the present application, the identity issuer 120a and the payment service provider 120b can be understood as systems controlled by identity issuing and payment service institutions. The identity issuer 120a and the payment service provider 120b are provided with a server cryptographic machine for generating an issuer public key and a private key. The identity issuer 120a can provide identity certificates for users, and the payment service provider 120b can provide payment services for users, such as a bank institution that can manage bank accounts, a running institution that runs digital currencies, or a third-party payment institution. In some embodiments of the present application, the distributed identity system 140 can generate a distributed identity after verification according to a distributed identity opening request, and generate a distributed identity document corresponding to the distributed identity. The distributed identity document stores the distributed identity and the public key corresponding to the distributed identity. The distributed identity system 140 stores and maintains the distributed identity document. In some embodiments of the present application, the trusted identity management institution 160 can be an institution with authoritative identity authentication, which maintains a database storing the identity information and biometric information of users, and can be called by other institutions or individuals to verify the identity of the user.
[0054] In some embodiments of the present application, the distributed identity application process and the certificate application process are the implementation basis of the integrated business identity verification and payment method. The integrated business identity verification and payment method can also include the distributed identity application process and the certificate application process. If the user has already applied for a distributed identity and a certificate in advance, the integrated business identity verification and payment method directly calls the existing certificate and distributed identity.
[0055] As shown in FIG. 2, the embodiment of the present application provides an integrated business identity verification and payment method, including the following steps:
[0056] S210: The applicant terminal 110, the identity issuer 120a, and the payment service provider 120b apply for a distributed identity, respectively.
[0057] In some embodiments of the present application, as shown in FIG. 3a, the identity issuer 120a applies for a distributed identity by the following steps.
[0058] S211a: The identity issuer 120a generates an identity issuer public key and a private key, and sends the identity issuer public key to the distributed identity system 140. In some embodiments of the present application, the identity issuer 120a generates the identity issuer public key and the private key by using a server cryptomachine, the identity issuer private key is stored in the server cryptomachine, the identity issuer public key is sent to the distributed identity system 140, and the identity issuer 120a can also send the global legal entity identification code (LEI), the name of the institution, and the like to the distributed identity system 140 when sending the identity issuer public key to the distributed identity system 140.
[0059] S212a: The distributed identity system 140 generates an identity issuer distributed identity and an identity issuer distributed identity document according to the identity issuer public key, stores the identity issuer public key in the identity issuer distributed identity document, and returns the identity issuer distributed identity to the identity issuer 120a. In some embodiments of the present application, the identity issuer public key can be obtained by indexing the identity issuer distributed identity to the identity issuer distributed identity document. In some embodiments of the present application, the identity issuer distributed identity can be parsed into a uniform resource identifier, and the name of the identity issuer distributed identity document can be named as the uniform resource identifier. In some embodiments of the present application, the distributed identity system 140 can obtain the identity issuer distributed identity by performing a hash calculation based on the identity issuer public key, or perform a hash calculation based on the identity issuer public key and a timestamp information to obtain the identity issuer distributed identity. In some embodiments of the present application, the distributed identity system 140 can also perform a hash calculation based on the identity issuer public key, the identity issuer LEI, and the name of the identity issuer to obtain the identity issuer distributed identity.
[0060] In some embodiments of the present application, as shown in FIG. 3b, the payment service provider 120b applies for a distributed identity by the following steps.
[0061] S211b: The payment service provider 120b generates a payment service provider public key and a private key, and sends the payment service provider public key to the distributed identity system 140. In some embodiments of the present application, the payment service provider 120b generates the payment service provider public key and the private key by using a server cryptomachine, the payment service provider private key is stored in the server cryptomachine, the payment service provider public key is sent to the distributed identity system 140, and the payment service provider 120b can also send the global legal entity identification code (LEI), the name of the institution, and the like to the distributed identity system 140 when sending the payment service provider public key to the distributed identity system 140.
[0062] S212b: The distributed identity system 140 generates a payment service party distributed identity identifier and a payment service party distributed identity document according to the payment service party public key, stores the payment service party public key in the payment service party distributed identity document, and returns the payment service party distributed identity identifier to the payment service party 120b. In some embodiments of the present application, the payment service party public key can be obtained by indexing the payment service party distributed identity document through the payment service party distributed identity. In some embodiments of the present application, the payment service party distributed identity can be parsed into a uniform resource identifier, and the name of the payment service party distributed identity document can be named as the uniform resource identifier. In some embodiments of the present application, the distributed identity system 140 can obtain the payment service party distributed identity identifier by performing hash calculation based on the payment service party public key, or obtain the payment service party distributed identity identifier by performing hash calculation based on the payment service party public key and timestamp information. In some embodiments of the present application, the distributed identity system 140 can also obtain the payment service party distributed identity identifier by performing hash calculation based on the payment service party public key, the payment service party LEI, and the payment service party name.
[0063] In some embodiments of the present application, as shown in FIG. 4, the applicant terminal 110 applies for and obtains a distributed identity identifier through the following steps.
[0064] S213: The applicant terminal 110 sends an identity verification request to the trusted identity management institution 160, the trusted identity management institution 160 verifies according to the identity verification request, generates an identity verification result, and returns the identity verification result to the applicant terminal 110, wherein the identity verification request includes applicant biometric information and applicant identity information; the applicant terminal 110 collects the applicant biometric information and the applicant identity information according to the operation of the applicant (for example, the operation of opening a distributed identity identifier), such as face pictures or face videos and other biometric information or name, identity card number, certificate type and other text identity information, generates an identity verification request, calls the interface of the trusted identity management institution 160, and sends the identity verification request to the trusted identity management institution 160. The trusted identity management institution 160 compares the received identity information with the information in its own database, and generates an identity verification result after comparison.
[0065] S214: The applicant terminal 110 judges that the identity verification is passed according to the identity verification result, generates an applicant private key and a public key, and sends the applicant public key to the distributed identity system 140; the applicant terminal 110 can generate an applicant private key and a public key by calling a trusted environment, and store the applicant private key in the trusted environment.
[0066] S215: The distributed identity system 140 generates an applicant distributed identity and an applicant distributed identity document according to the applicant public key, stores the applicant public key in the applicant distributed identity document, and returns the applicant distributed identity to the applicant terminal 110. In some embodiments of the present application, the applicant terminal 110 can also send the applicant distributed identity to the trusted identity management authority 160 for storage. The distributed identity system 140 can generate the applicant distributed identity according to the hash calculation of the applicant public key, or generate the applicant distributed identity based on the hash calculation of the applicant public key and the timestamp information. In some embodiments of the present application, the applicant public key can be obtained by indexing the applicant distributed identity to the applicant distributed identity document. In some embodiments of the present application, the applicant distributed identity can be parsed into a uniform resource identifier, and the name of the applicant distributed identity document can be named as the uniform resource identifier.
[0067] S220: The applicant terminal 110 applies for obtaining the applicant identity certificate and the applicant payment identity certificate by using the applicant distributed identity to the identity issuer 120a and the payment service provider 120b, respectively.
[0068] In some embodiments of the present application, as shown in FIG. 5a, the process of applying for the applicant identity certificate is as follows.
[0069] S221a: The applicant terminal 110 organizes an identity certificate application request and sends the identity certificate application request to the identity issuer 120a, wherein the identity certificate application request includes the applicant biometric information, the applicant identity information and the applicant distributed identity.
[0070] S222b: The identity issuer 120a receives the identity certificate application request sent by the applicant terminal 110.
[0071] S223a: The identity issuer 120 generates an identity authentication result according to the applicant identity certificate application request, judges that the applicant identity authentication is passed, generates the applicant identity certificate, and sends the applicant identity certificate to the applicant terminal 110, wherein the applicant identity certificate includes a statement part and a signature part generated by signing the statement part with the private key of the identity issuer, and the statement part includes the applicant distributed identity and the identity issuer distributed identity.
[0072] For example, the user can apply for an identity certificate through the applicant terminal 110, the applicant terminal 110 collects the biometric information (for example, face) of the user, and sends the applicant distributed identity identifier, biometric information, and identity information to the identity issuer 120a. After the identity verification of the identity issuer 120a is passed, the identity issuer 120a generates the applicant identity certificate.
[0073] In some embodiments of the application, the identity issuer 120a can verify the biometric information and identity information of the applicant itself, or send the biometric information and identity information of the applicant to the trusted identity management institution 160 for verification.
[0074] In some embodiments of the application, the identity issuer 120a can obtain the identity characteristic information and identity information of the applicant in an online manner, or obtain the identity characteristic information and identity information of the applicant in an offline manner.
[0075] In some embodiments of the application, as shown in FIG. 5b, the process of applying for an applicant payment identity certificate is as follows.
[0076] S221b: The applicant terminal 110 organizes a payment identity certificate application request and sends the payment identity certificate application request to the payment service party 120b, wherein the payment identity certificate application request includes the applicant distributed identity identifier, the applicant payment account, the payment password, and the verification information.
[0077] S222b: The payment service party 120b receives the payment identity certificate application request sent by the applicant terminal 110.
[0078] S223b: The payment service party 120b judges that the applicant payment account verification is passed according to the applicant payment account, the payment password, and the verification information, generates an applicant payment identity certificate, and sends the applicant payment identity certificate to the applicant terminal 110, wherein the applicant payment identity certificate includes a statement part and a signature part generated by signing the statement part with the private key of the payment service party, and the statement part includes the applicant distributed identity identifier and the payment service party distributed identity identifier.
[0079] For example, the user can apply for a payment identity certificate through the applicant terminal 110, the applicant terminal 110 sequentially obtains the applicant payment account, the payment password, and the verification information of the user, and sends the applicant payment account, the payment password, and the verification information to the payment service party 120b. After the identity verification of the payment service party 120b is passed, the payment service party 120b generates the applicant payment identity certificate.
[0080] In some embodiments of the present application, the verification information can be a mobile phone verification code or a dynamic password. The payment service 120b verifies the payment password and the verification information according to the payment account of the applicant.
[0081] In some embodiments of the present application, the payment service 120b can also verify the identity of the user. For example, before the applicant terminal 110 sends the payment identity credential application request to the payment service 120b, the applicant terminal 110 also sends the biometric information and the identity information of the applicant to the payment service 120b. The payment service 120b can verify the biometric information and the identity information of the applicant by itself, or send the biometric information and the identity information of the applicant to the trusted identity management institution 160. After the trusted identity management institution 160 verifies the biometric information and the identity information of the applicant, it returns the verification result to the payment service 120b, and the payment service 120b verifies the identity of the applicant according to the verification result.
[0082] In some embodiments of the present application, the applicant can send the biometric information and the identity information of the applicant to the payment service 120b through online network transmission, or send the biometric information and the identity information of the applicant to the payment service 120b through offline counter.
[0083] In some embodiments of the present application, the identity issuer 120a and the payment service 120b can also generate a proof credential through a zero-knowledge proof protocol. When a subsequent verifier verifies the proof credential, the zero-knowledge proof protocol can also be used for information verification, without the need to disclose sensitive information to the verifier. This can protect the privacy of the user, while ensuring the accuracy and security of the verification.
[0084] In some embodiments of the present application, after receiving the identity proof credential and the payment identity credential, the applicant terminal 110 stores the identity proof credential and the payment identity credential in a trusted environment in the applicant terminal 110, to ensure the security of the credential storage process.
[0085] In some embodiments of the present application, after generating the proof credential, the identity issuer 120a and the payment service 120b also synchronize the verification data of the proof credential to the credential permission chain 150. The verification data includes the digest value and the state of the proof credential. The state of the proof credential can be obtained from the credential permission chain 150 through the digest value of the proof credential. In some embodiments of the present application, the state of the proof credential includes valid and available, invalid, and transferred states.
[0086] In some embodiments of the present application, the verification data further comprises information such as the validity period of the credential. In some embodiments of the present application, after generating the applicant identity certificate credential, the identity issuer 120a further synchronizes the first digest value generated according to the applicant identity certificate credential and the state of the applicant identity certificate credential to the credential permission chain 150; after generating the applicant payment identity credential, the payment service provider 120b further synchronizes the second digest value generated according to the applicant payment identity credential and the state of the applicant payment identity credential to the credential permission chain 150.
[0087] S230: The applicant terminal 110 generates a service handling request. The user uses the applicant terminal 110 to select the previously applied applicant identity certificate credential and the applicant payment identity credential, and the applicant terminal 110 generates a verifiable expression according to the selected certificate credential. In some embodiments of the present application, the service handling request comprises the verifiable expression described above, and the verifiable expression comprises the applicant distributed identity, the applicant identity certificate credential issued by the identity issuer, the applicant payment identity credential issued by the payment service provider, and the credential signature generated by signing the applicant distributed identity, the applicant identity certificate credential, and the applicant payment identity credential with the applicant private key.
[0088] S240: The applicant terminal 110 sends the generated service handling request to the verifier 130. In some embodiments of the present application, the applicant terminal 110 can send the service handling request to the verifier 130 through the near field communication protocol, or can generate a two-dimensional code or a bar code according to the service handling request and display it, and the verifier 130 can obtain the service handling request sent by the verifier 130 by scanning the two-dimensional code or the bar code.
[0089] In some embodiments of the present application, after the applicant terminal 110 sends the service handling request to the verifier 130, the verifier 130 can also require the identity of the applicant to be verified. At this time, the applicant terminal 110 sends the collected or stored applicant biometric information and identity information to the verifier 130, and the verifier 130 can perform self-verification on the applicant biometric information and identity information, or can send them to the trusted identity management institution 160 for verification. After verification, the subsequent step of verifying the verifiable expression is performed.
[0090] S250: The verifier 130 verifies the verifiable expression in the service handling request according to the applicant distributed identity, and generates a credential verification result.
[0091] In some embodiments of the present application, the applicant public key can be obtained through the applicant distributed identity, so as to verify the credential signature. Referring to FIG. 6, step S250 comprises the following steps:
[0092] S251: The verifier 130 obtains the applicant public key from the distributed identity system 140 according to the applicant distributed identity. The verifier 130 sends the applicant distributed identity to the distributed identity system 140, and the distributed identity system 140 obtains the applicant distributed identity document according to the applicant distributed identity, obtains the applicant public key from the applicant distributed identity document, and returns the applicant public key to the verifier 130.
[0093] S252: The verifier 130 verifies the signature of the certificate according to the applicant public key, and generates a certificate signature verification result.
[0094] S253: The verifier 130 judges whether the certificate signature verification passes according to the certificate signature verification result, verifies the applicant identity certificate and the applicant payment identity certificate, and generates a certificate verification result. In the embodiment of the application, through the verification of the certificate signature, the integrity of the verifiable expression is ensured, and the transmission from the applicant terminal 110 to the verifier 120 is not tampered.
[0095] In some embodiments of the application, in addition to the need to verify the certificate signature, the authenticity and integrity of the certificate can be further verified. Referring to FIG. 7, step S253 includes the following steps.
[0096] S2531: The verifier 130 obtains the identity issuer public key and the payment service provider public key from the distributed identity system 140 according to the identity issuer distributed identity and the payment service provider distributed identity. The distributed identity system 140 obtains the identity issuer distributed identity document and the payment service provider distributed identity document according to the identity issuer distributed identity and the payment service provider distributed identity, and obtains the identity issuer public key and the payment service provider public key from the identity issuer distributed identity document and the payment service provider distributed identity document.
[0097] S2532: The verifier 130 respectively verifies the signature part in the applicant identity certificate and the applicant payment identity certificate according to the identity issuer public key and the payment service provider public key, and generates a signature part verification result. The verifier 130 verifies the signature part by using a signature verification algorithm, and generates a signature part verification result.
[0098] S2533: The verifier 130 generates a certificate verification result according to the signature part verification result.
[0099] In some embodiments of the present application, when the distributed identity system 140 creates the distributed identity document for the applicant or the issuing party, it also writes a specific digital signature algorithm into the distributed identity document, and when the distributed identity system 140 receives the public key corresponding to the distributed identity of the applicant, it also returns the digital signature algorithm in the distributed identity document to the requesting party, so that the requesting party can verify the signature part according to the returned public key and the digital signature algorithm.
[0100] In some embodiments of the present application, in addition to being able to obtain the validity period of the proof credential from the issuing party to determine whether the proof credential is valid, the on-chain state of the proof credential can also be obtained from the credential permission chain 150 to verify the validity of the proof credential, ensuring that the state has not been tampered with.
[0101] In some embodiments of the present application, as described above, the identity issuing party 120a and the payment service party 120b respectively synchronize the verification data of the applicant identity proof credential and the applicant payment identity credential to the credential permission chain 150 after generating the applicant identity proof credential and the applicant payment identity credential, so that when the credential is verified subsequently, the validity of the credential can be verified. In some embodiments of the present application, the verification data of the applicant identity proof credential includes a first digest value and a state generated based on the applicant identity proof credential, and the verification data of the applicant payment identity credential includes a second digest value and a state generated based on the applicant payment identity credential; the state of the proof credential includes a valid credential, an invalid credential, a credential transfer, etc., and the first digest value or the second digest value can be obtained by performing a hash calculation on the proof credential. After the verification data of the proof credential is synchronized to the credential permission chain 150, the state of the proof credential can be obtained from the credential permission chain 150 by using the first digest value or the second digest value. Therefore, the verifier 130 can verify the state of the proof credential through the credential permission chain 150.
[0102] In some embodiments of the present application, when the proof credential is stored on the credential permission chain 150, the digest value and the state of the proof credential are also stored, and the state of the proof credential can be obtained from the credential permission chain to verify the validity of the proof credential.
[0103] In some embodiments of the present application, as shown in FIG. 8, the above step S2533 includes the following steps.
[0104] S25331: The verifier 130 determines that the signature part in the applicant identity proof credential and the applicant payment identity credential is verified according to the signature part verification result, generates a third digest value according to the identity proof credential, generates a fourth digest value according to the applicant payment identity credential, and sends the third digest value and the fourth digest value to the credential permission chain 150.
[0105] S25332: The credential permission chain 150 acquires the status of the identity certificate according to the third digest value, acquires the status of the payment service identity certificate according to the fourth digest value, and performs status verification on the applicant identity certificate and the applicant payment identity certificate according to the status of the identity certificate and the status of the payment service identity certificate respectively, and generates and returns a status verification result. In some embodiments of the present application, the credential permission chain 150 queries to find the first digest value according to the third digest value, thereby acquiring the status of the identity certificate, and similarly, queries to find the second digest value according to the fourth digest value, thereby acquiring the status of the payment service identity certificate. When the status of the identity certificate stored on the credential permission chain 150 is valid, the status verification result indicates that the status of the identity certificate is valid.
[0106] S25333: The verifier 130 determines that the status of the applicant identity certificate and the applicant payment identity certificate is valid according to the status verification result, and generates a credential verification result indicating that the verification is passed.
[0107] In some embodiments of the present application, when the credential signature verification is not passed, the signature part in the identity certificate is not verified, or the status of the identity certificate is invalid, a credential verification result indicating that the verification is not passed is generated.
[0108] S260: The verifier 130 determines that the verifiable expression is verified according to the credential verification result, and sends payment information to the applicant terminal 110 to enable the applicant to confirm the payment information. In some embodiments of the present application, after the verifier 130 determines that the verifiable expression is verified according to the credential verification result, the verifier receives an input payment amount, and the verifier 130 generates payment information according to the payment amount and its own transaction account information, and sends the payment information to the applicant terminal 110.
[0109] In some embodiments of the present application, the verifier 130 can send the payment information to the applicant terminal 110 through a near field communication protocol, or can send the payment information to the applicant terminal 110 through a background system. In some embodiments of the present application, the applicant terminal 110 runs a digital wallet application, and the applicant terminal 110 applies, manages and uses the identity certificate through the digital wallet application. A wallet background corresponding to the digital wallet application and a verification background corresponding to the verifier are set in the background system, the verifier 130 transmits the payment information to the verification background, the verification background forwards the payment information to the wallet background, and the wallet background sends the payment information to the digital wallet application (applicant terminal 110).
[0110] S270: After the application party terminal 110 receives the payment information, the application party terminal 110 displays the payment information to the user, and the user confirms the payment information. After the user confirms the payment information, the application party terminal generates a payment confirmation response and sends the payment confirmation response to the verification party 130. In an embodiment of the present application, the payment confirmation response represents that the application party confirms the payment information. The application party terminal 110 can send the payment confirmation response to the verification party 130 through a near field communication protocol, or send the payment confirmation response to the verification party 130 through a wallet background and a verification background.
[0111] S280: The verification party 130 receives the payment confirmation response sent by the application party terminal 110, judges whether the application party confirms the payment information according to the payment confirmation response, and sends a payment request to the payment service party according to the distributed identity of the application party and the payment information.
[0112] In some embodiments of the present application, the payment information includes payment amount information, a verification party account, and a distributed identity of a payment service party. The verification party 130 can confirm the payment service party receiving the payment request through the distributed identity of the payment service party. Specifically, sending the payment request to the payment service party includes sending the payment request to the payment service party 120b corresponding to the distributed identity of the payment service party.
[0113] S290: The payment service party 120b performs a payment process. In some embodiments of the present application, the payment service party 120b obtains an application party payment account according to the distributed identity of the application party, performs a payment process to the verification party account according to the account amount in the application party payment account and the payment amount information, and sends a payment process result to the verification party 130 and the application party terminal 110 after completing the payment process. The verification party 130 and the application party terminal 110 display or broadcast the payment process result. In some embodiments of the present application, the payment service party 120b confirms that the account amount meets the requirement of the payment amount information, and transfers the amount of the payment amount information to the verification party account. In some embodiments of the present application, the payment service party 120b can transfer digital currency corresponding to the payment amount information to the verification party account.
[0114] In some embodiments of the present application, the payment service party 120b can send a requirement for verification to the application party terminal 110 during the payment process, the application party terminal 110 sends the payment password and the verification information to the payment service party 120b, and the payment service party 120b performs a fund transfer operation after verification. In some embodiments of the present application, the application party payment account is set with a password-free quota. When the payment amount exceeds the password-free quota, the payment service party 120b sends a verification requirement to the application party terminal 110, the application party terminal 110 sends the payment password and the verification information to the payment service party 120b, and the payment service party 120b performs a fund transfer operation after verification.
[0115] In the embodiment of the present application, the user selects the identity certificate and the payment identity certificate to generate a verifiable expression VP, and after the subsequent verifier verifies the VP and the certificate VC therein, the integrated operation of business handling and payment can be realized, the operation steps of the user are saved, the user is prevented from repeatedly providing identity information, and the risk of identity information leakage is reduced. For example, in the hotel check-in scenario, the user only needs to complete the operation of presenting the VP and inputting the payment password once to realize the identity authentication and payment operation simultaneously, the integration of user identity authentication and payment is realized, and the hotel party can also realize the verification and tracing of the user identity without retaining any identity privacy information of the user.
[0116] The embodiment of the present application realizes the unified representation and expression of the digital certificate applied for in the digital wallet by using the verifiable certificate technology based on the digital signature, realizes the independent management and authorization of the user to the digital certificate of the user without changing the existing digital certificate format.
[0117] In the existing digital certificate technology, when the user needs to apply for multiple different digital certificates, the user needs to apply to the information system of each digital certificate issuing institution respectively, and the digital certificate formats issued by different digital certificate issuing institutions are different. In the hotel application scenario, the user needs to perform multiple operations when presenting and using multiple digital certificates, and due to the different digital certificate formats, it is difficult to realize the unified independent management and authorization application of the user to the digital certificate of the user. Although some third-party institutions have integrated the application and management of various digital certificates of the user to some extent, the user can apply for multiple different digital certificates in the same application system (for example, the user can apply for a network identity certificate, an electronic social security card, an electronic passport, etc. in an Internet application), but in fact, the user cannot realize the real association between the digital certificates, and the user still needs to operate and authorize one by one in the scene of presenting multiple digital certificates.
[0118] The embodiment of the application realizes unified representation of digital credentials and unified expression of multiple digital credentials based on the verifiable credential technology based on digital signature. In terms of unified representation of digital credentials, the user applies for the required digital credentials to each digital credential issuing agency through the digital wallet application. During the application process, each digital credential is assembled with the agency and the user's digital identity identifier through the digital wallet application, and is digitally signed by the private key of the corresponding issuing agency to form a verifiable credential (VC). The entire process does not change the format and application mode of the existing digital credentials. In terms of unified expression of multiple digital credentials, the user manages multiple verifiable credentials obtained through the digital wallet application. In the scenario where multiple verifiable credentials need to be presented for verification, the user selects the verifiable credentials to be presented, and then calls the verifiable credential technology based on digital signature again to assemble the selected verifiable credentials with the user's digital identity identifier, and digitally signs the assembled content with the user's private key to form a verifiable expression (VP), thereby realizing the user's self-management and authorization of the credentials, which can be used in hotel scenarios and other scenarios that require verification of one or more credentials.
[0119] The embodiment of the application realizes distributed storage and verification of verifiable credentials and verification data generated by digital identity credential issuing agencies and digital bank card issuing agencies based on distributed ledger technology in the credential permission chain.
[0120] In the traditional centralized digital credential management scenario, on the one hand, the digital credentials applied by the user can only be used in a local limited trust domain, and when the same digital credentials and corresponding verification data need to be used between different trust domains, they cannot be interconnected, on the other hand, during the application process of the digital credentials, there is often a situation of repeated submission and multi-site storage of the user's real identity information, thereby increasing the risk of leakage of the user's private identity information.
[0121] The application adopts a distributed ledger technology based on a credential permission chain to realize distributed storage and verification of verifiable credentials and verification data of a digital identity credential issuing agency and a digital bank card issuing agency, the permission chain is connected with a wallet background of a digital wallet application through a secure channel, when a user applies for or updates a digital identity verifiable credential (VC1, i.e. an applicant identity certificate) and a digital bank card verifiable credential (VC2, i.e. an applicant payment identity certificate) through the digital wallet application, the corresponding verifiable credentials and verification data will be synchronized to the permission chain, in this way, on the one hand, all the credential issuing agencies and verification agencies that join the credential permission chain can reuse the required verification data, thereby realizing the migratory application of the user credentials, on the other hand, only a few authoritative credential issuing agencies have the real identity information of the user, for most verification parties, only the verification data on the permission chain needs to be trusted, thereby greatly reducing the risk of user privacy identity information leakage.
[0122] The embodiment of the application realizes face-free identity verification of a user in a hotel scene based on the verification function of a digital wallet application, and the hotel party can realize integrated operation of user identity verification and payment without obtaining the user's private information.
[0123] In the current hotel check-in scene, the hotel party generally compares and identifies the real identity of the user by collecting the face photo and identity document information of the check-in user, and manually records the check-in, after the identity information verification is passed, the hotel party confirms the user's payment method and initiates a request for charging and deduction, and finally the user completes the payment by a payment tool or card swiping. In this process, the user identity authentication and the payment operation are two separate processes, the user and the hotel party need to cooperate to complete the process of multiple interactive operations and confirmations, and it is difficult to avoid the hotel party obtaining and storing the user's face feature information, identity document information and other sensitive data, thereby increasing the exposure of personal privacy data.
[0124] The embodiment of the application realizes face-free identity verification and authentication of a user in a hotel scene based on a digital wallet application. The hotel party can realize integrated operation of user identity authentication and payment deduction without obtaining user privacy information. A verifiable presentation (VP) presented by the user includes a digital identity verifiable credential (VC1) and a digital bank card verifiable credential (VC2). The public key information of the user and the public key information of a credential issuing authority are respectively parsed by obtaining the digital identity identifier of the user in the VP and the digital identity identifier of the credential issuing authority in the VC. The VP, the VC1 and the VC2 of the user are verified in sequence based on the corresponding public key information. A corresponding payment deduction request is initiated to the digital wallet application of the user at the same time of verification. The hotel check-in process is completed after the user confirms. In the whole process, the hotel staff can be excluded, the steps of user operation are simplified, and the check-in efficiency is improved. In addition, the hotel party can verify and trace the real identity of the user without obtaining the privacy information of the user, relying on the association of the anonymized digital identity identifier.
[0125] The embodiment of the application, as shown in FIG. 9, provides an integrated service identity verification and payment device 400 applied to a verification party. The device 400 includes a receiving module 410, a verification module 420, a payment information sending module 430 and a payment processing module 440, wherein,
[0126] The receiving module 410 is configured to receive a service handling request sent by an application party terminal. The service handling request includes a verifiable presentation. The verifiable presentation includes an application party distributed identity, an application party identity proof credential issued by an identity issuing party, an application party payment identity credential issued by a payment service party and a credential signature generated by signing the application party distributed identity, the application party identity proof credential and the application party payment identity credential by an application party private key.
[0127] The verification module 420 is configured to verify the verifiable presentation according to the application party distributed identity, and generate a credential verification result.
[0128] The payment information sending module 430 is configured to determine that the verifiable presentation is verified according to the credential verification result, and send payment information to the application party terminal, so that the application party confirms the payment information.
[0129] The payment processing module 440 is configured to receive a payment confirmation response sent by the application party terminal, determine that the application party confirms the payment information according to the payment confirmation response, and send a payment request to the payment service party according to the application party distributed identity and the payment information, so that the payment service party performs payment processing.
[0130] In some embodiments of the application, the application party identity proof credential is generated according to the following steps:
[0131] The identity issuing party receives an identity certificate application request sent by the applicant terminal, wherein the identity certificate application request comprises applicant biological feature information, applicant identity information and applicant distributed identity;
[0132] The identity issuing party generates an identity verification result according to the applicant identity certificate application request, judges that the applicant identity verification is passed, and generates an applicant identity certificate, wherein the applicant identity certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the identity issuing party, and the statement part comprises the applicant distributed identity and the distributed identity of the identity issuing party.
[0133] In some embodiments of the present application, the applicant payment identity certificate is generated according to the following steps:
[0134] The payment service party receives a payment identity certificate application request sent by the applicant terminal, wherein the payment identity certificate application request comprises the applicant distributed identity, the applicant payment account, the payment password and the verification information;
[0135] The payment service party judges that the applicant payment account verification is passed according to the applicant payment account, the payment password and the verification information, and generates an applicant payment identity certificate, wherein the applicant payment identity certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the payment service party, and the statement part comprises the applicant distributed identity and the distributed identity of the payment service party.
[0136] In some embodiments of the present application, the distributed identity of the identity issuing party is generated according to the following steps:
[0137] The identity issuing party generates an identity issuing party public key and a private key, and sends the identity issuing party public key to the distributed identity system;
[0138] The distributed identity system generates an identity issuing party distributed identity and an identity issuing party distributed identity document according to the identity issuing party public key, stores the identity issuing party public key in the identity issuing party distributed identity document, and returns the identity issuing party distributed identity to the identity issuing party;
[0139] The distributed identity of the payment service party is generated according to the following steps:
[0140] The payment service party generates a payment service party public key and a private key, and sends the payment service party public key to the distributed identity system;
[0141] The distributed identity system generates a payment service party distributed identity and a payment service party distributed identity document according to the payment service party public key, stores the payment service party public key in the payment service party distributed identity document, and returns the payment service party distributed identity to the payment service party.
[0142] The application party distributed identity is generated according to the following steps:
[0143] The application party terminal sends an identity verification request to the trusted identity management institution, the trusted identity management institution verifies according to the identity verification request, generates an identity verification result, and returns the identity verification result to the application party terminal, wherein the identity verification request includes application party biological feature information and application party identity information;
[0144] The application party terminal judges that the identity verification is passed according to the identity verification result, generates an application party private key and a public key, and sends the application party public key to the distributed identity system;
[0145] The distributed identity system generates an application party distributed identity and an application party distributed identity document according to the application party public key, stores the application party public key in the application party distributed identity document, and returns the application party distributed identity to the application party terminal.
[0146] In some embodiments of the application, the verification module 420 is further configured to:
[0147] Obtain the application party public key from the distributed identity system according to the application party distributed identity;
[0148] According to the application party public key, the signature of the certificate is verified, and a certificate signature verification result is generated;
[0149] According to the certificate signature verification result, it is judged that the certificate signature verification is passed, the application party identity certificate and the application party payment identity certificate are verified, and a certificate verification result is generated.
[0150] In some embodiments of the application, the verification module 420 is further configured to:
[0151] According to the identity issuing party distributed identity and the payment service party distributed identity, the identity issuing party public key and the payment service party public key are obtained from the distributed identity system;
[0152] According to the identity issuing party public key and the payment service party public key, the signature part in the application party identity certificate and the application party payment identity certificate is verified respectively, and a signature part verification result is generated;
[0153] According to the signature part verification result, the certificate verification result is generated.
[0154] In some embodiments of the present application, the identity issuer and the payment service provider further synchronize the verification data of the applicant identity certification credential and the applicant payment identity credential to the credential permission chain after generating the applicant identity certification credential and the applicant payment identity credential, the verification data of the applicant identity certification credential includes a first digest value and a state generated based on the applicant identity certification credential, and the verification data of the applicant payment identity credential includes a second digest value and a state generated based on the applicant payment identity credential;
[0155] The verification module 420 is further configured to: determine that the signature part in the applicant identity certification credential and the applicant payment identity credential is verified according to the signature part verification result, generate a third digest value according to the identity certification credential, generate a fourth digest value according to the applicant payment identity credential, send the third digest value and the fourth digest value to the credential permission chain, so that the credential permission chain obtains the state of the identity certification credential according to the third digest value, obtains the state of the payment service identity credential according to the fourth digest value, and performs state verification on the applicant identity certification credential and the applicant payment identity credential according to the state of the identity certification credential and the state of the payment service identity credential respectively, generates and returns a state verification result;
[0156] According to the state verification result, it is determined that the states of the applicant identity certification credential and the applicant payment identity credential are valid, and a credential verification result indicating that the verification is passed is generated.
[0157] In some embodiments of the present application, the payment information includes: payment amount information, a verifier account and a payment service provider distributed identity;
[0158] The payment processing module 440 is further configured to: send a payment request to the payment service provider corresponding to the payment service provider distributed identity, so that the payment service provider obtains the applicant payment account according to the applicant distributed identity, performs payment processing on the verifier account according to the account amount in the applicant payment account and the payment amount information, and sends a payment processing result to the verifier and the applicant terminal after completing the payment processing.
[0159] As shown in FIG. 10, the embodiment of the present application further provides an integrated business identity verification and payment device 500 applied to an applicant terminal, the device 500 includes a certification credential obtaining module 510, a business handling module 520, a payment information receiving module 530 and a payment confirmation module 540, wherein,
[0160] The proof certificate obtaining module 510 is configured to obtain an applicant identity proof certificate issued by an identity issuer and an applicant payment identity certificate issued by a payment service provider, and generate a verifiable expression according to the applicant identity proof certificate and the applicant payment identity certificate, wherein the verifiable expression comprises an applicant distributed identity, the applicant identity proof certificate, the applicant payment identity certificate, and a certificate signature generated by signing the applicant distributed identity, the applicant identity proof certificate, and the applicant payment identity certificate with an applicant private key;
[0161] The business handling module 520 is configured to send a business handling request to the verifier, wherein the business handling request comprises the verifiable expression.
[0162] The payment information receiving module 530 is configured to receive payment information sent by the verifier, wherein the payment information is generated by the verifier after verifying and passing the verification of the verifiable expression.
[0163] The payment confirmation module 540 is configured to send a payment confirmation response to the verifier, so that the verifier sends a payment request to the payment service provider according to the applicant distributed identity and the payment information, and the payment service provider performs payment processing.
[0164] In some embodiments of the present application, the device 500 further comprises an identity proof certificate obtaining module 550, which is configured to:
[0165] send an identity proof certificate application request to the identity issuer, so that the identity issuer generates an identity verification result according to the applicant identity certificate application request, judges that the applicant identity verification is passed, and generates an applicant identity proof certificate, wherein the proof certificate application request comprises applicant biological feature information, applicant identity information, and an applicant distributed identity.
[0166] receive the identity proof certificate returned by the identity issuer, wherein the identity proof certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the identity issuer, and the statement part comprises the applicant distributed identity and an issuer distributed identity.
[0167] In some embodiments of the present application, the device 500 further comprises a payment identity certificate obtaining module 560, which is configured to:
[0168] send a payment identity certificate application request to the payment service provider, wherein the payment identity certificate application request comprises an applicant distributed identity, an applicant payment account, a payment password, and verification information, so that the payment service provider judges that the applicant payment account verification is passed according to the applicant payment account, the payment password, and the verification information, and generates an applicant payment identity certificate.
[0169] receiving the application party payment identity credential returned by the payment service party, wherein the application party payment identity credential comprises a statement part and a signature part generated by signing the statement part with a private key of the payment service party, and the statement part comprises an application party distributed identity and a payment service party distributed identity.
[0170] In some embodiments of the present application, the device 500 further comprises a distributed identity obtaining module 570, which is configured to:
[0171] sending an identity verification request to a trusted identity management authority, so that the trusted identity management authority verifies according to the identity verification request, generates an identity verification result, and returns the identity verification result to the application party terminal, wherein the identity verification request comprises application party biometric information and application party identity information;
[0172] judging that the identity verification is passed according to the identity verification result, generating an application party private key and public key, sending the application party public key to a distributed identity system, so that the distributed identity system generates an application party distributed identity and an application party distributed identity document according to the application party public key, stores the application party public key in the application party distributed identity document, and returns the application party distributed identity to the application party terminal;
[0173] receiving the application party distributed identity sent by the distributed identity system.
[0174] In some embodiments of the present application, the device 500 further comprises a payment result receiving module 580, which is configured to receive the payment processing result sent by the payment service party.
[0175] In some embodiments of the present application, the application party terminal is provided with a trusted environment, and the distributed identity obtaining module 570 is further configured to call the trusted environment to generate the application party private key and public key, and store the application party private key in the trusted environment.
[0176] The device features of the embodiments of the present application can refer to the method, step and other features of the embodiments of the present application, and the system embodiments can combine the features of the method embodiments to obtain new embodiments, and vice versa, which will not be described here again.
[0177] In the embodiments of the present application, an electronic device is provided, which comprises a processor and a memory storing a computer program, and the processor is configured to implement any method according to the embodiments of the present application when running the computer program. In addition, an apparatus according to the embodiments of the present application can also be provided.
[0178] FIG. 11 shows an exemplary system architecture 1100 of the identity credential application, integrated business identity verification and payment method, and integrated business identity verification and payment device to which the embodiments of the present application can be applied.
[0179] As shown in FIG. 11, the system architecture 1100 can include terminal devices 1101, 1102, 1103, a network 1104, and a server 1105. The network 1104 is a medium that provides a communication link between the terminal devices 1101, 1102, 1103 and the server 1105. The network 1104 can include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0180] A user can use the terminal devices 1101, 1102, 1103 to interact with the server 1105 through the network 1104 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 1101, 1102, 1103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0181] The terminal devices 1101, 1102, 1103 can be various electronic devices with display screens and support for web browsing, including but not limited to smartphones, tablet computers, laptop computers, desktop computers, etc.
[0182] The server 1105 can be a server that provides various services, such as a background management server that provides support for a user browsing a shopping website using the terminal devices 1101, 1102, 1103 (only as an example). The background management server can analyze and process received product information query requests and other data, and feed back the processing results (such as target push information, product information - only as examples) to the terminal devices.
[0183] It should be noted that the identity credential application, integrated business identity verification and payment method provided by the embodiments of the present application are generally executed by the server 1105, and correspondingly, the identity credential application, integrated business identity verification and payment implementation device is generally provided in the server 1105.
[0184] It should be understood that the number of terminal devices, networks, and servers in FIG. 11 is only illustrative. According to the needs of implementation, there can be any number of terminal devices, networks, and servers.
[0185] Reference is made below to FIG. 12, which shows a structural schematic diagram of a computer system 1200 suitable for implementing a terminal device or a server of the embodiments of the present application. The methods or device implementing methods in the embodiments of the present application can be implemented on the computer system 1200. The terminal device or server shown in FIG. 12 is only an example and should not bring any limitation to the functions and use range of the embodiments of the present application.
[0186] As shown in FIG. 12, the computer system 1200 includes a central processing unit (CPU) 1201 which can perform various appropriate actions and processes in accordance with a program stored in a read only memory (ROM) 1202 or a program loaded from the storage section 1208 into a random access memory (RAM) 1203. In the RAM 1203, various programs and data required for the operation of the system 1200 are also stored. The CPU 1201, the ROM 1202, and the RAM 1203 are connected to each other through a bus 1204. An input / output (I / O) interface 1205 is also connected to the bus 1204.
[0187] The following components are connected to the I / O interface 1205: an input section 1206 including a keyboard, a mouse, etc.; an output section 1207 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1208 including a hard disk, etc.; and a communication section 1209 including a network interface card such as a LAN card, a modem, etc. The communication section 1209 performs communication processing via a network such as the Internet. A drive 1210 is also connected to the I / O interface 1205 as necessary. A removable recording medium 1211 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 1210 as necessary, so that a computer program read therefrom is installed into the storage section 1208 as necessary.
[0188] In particular, the processes described above with reference to the flow charts can be implemented as a computer software program in accordance with the embodiments of the present disclosure. For example, the embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the methods shown in the flow charts. In such embodiments, the computer program can be downloaded and installed from a network by the communication section 1209, and / or installed from the removable recording medium 1211. When the computer program is executed by the central processing unit (CPU) 1201, the above-described functions defined in the system of the present disclosure are executed.
[0189] It should be noted that the computer-readable medium shown in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component. In the present application, the computer-readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or component. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0190] The flowcharts and block diagrams in the drawings illustrate the possible implementation architectures, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment or a part of code containing one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order than that shown in the drawings. For example, two blocks that are shown in succession can actually be executed substantially in parallel, and sometimes in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams or flowcharts, and the combination of blocks in the block diagrams or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0191] The units or modules described in the embodiments of the present application can be implemented by software or by hardware. The described units or modules can also be arranged in a processor, for example, a processor can be described as including a sending unit (or "module"), an obtaining unit, a determining unit, and a first processing unit. In some cases, the names of the units or modules do not limit the units or modules themselves, for example, the sending unit can also be described as "a unit that sends a picture obtaining request to a connected server".
[0192] As another aspect, the present application also provides a computer readable medium, which can be included in the device described in the above embodiments, or can exist independently without being assembled into the device. The computer readable medium carries one or more programs, which, when executed by the device, cause the device to perform the method in the above embodiments.
[0193] The above detailed description does not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made depending on design requirements and other factors. Any modification, equivalent replacement, and improvement made within the spirit and principles of the present application should be included in the protection scope of the present application. Industrial applicability
[0194] The scheme provided in the embodiments of the present application can be applied to the field of computer technology. In the embodiments of the present application, a service handling request sent by an applicant terminal is received, wherein the service handling request includes a verifiable expression; a verifier verifies the verifiable expression according to a distributed identity of the applicant, and generates a credential verification result; the verifier judges that the verification of the verifiable expression is passed according to the credential verification result, and sends payment information to the applicant terminal; the applicant confirms the payment information; the verifier receives a payment confirmation response sent by the applicant terminal, judges that the applicant confirms the payment information according to the payment confirmation response, and sends a payment request to a payment service party according to the distributed identity of the applicant and the payment information; and the payment service party performs payment processing. On the basis of ensuring the security of identity information, the integration of service handling and payment is realized, the operation of secondary verification of a user is reduced, and the user experience is improved.
Claims
1. An integrated business identity verification and payment method applied to a verification party, the method comprising: receiving a service handling request sent by an applicant terminal, wherein the service handling request comprises a verifiable representation, the verifiable representation comprising an applicant distributed identity, an applicant identity certificate issued by an identity issuer, an applicant payment identity certificate issued by a payment service party, and a certificate signature generated by signing the applicant distributed identity, the applicant identity certificate, and the applicant payment identity certificate with an applicant private key; verifying the verifiable representation according to the applicant distributed identity to generate a certificate verification result; judging that the verifiable representation is verified successfully according to the certificate verification result, sending payment information to the applicant terminal to enable the applicant to confirm the payment information; receiving a payment confirmation response sent by the applicant terminal, judging that the applicant confirms the payment information according to the payment confirmation response, and sending a payment request to the payment service party according to the applicant distributed identity and the payment information to enable the payment service party to perform payment processing.
2. The method of claim 1, wherein, the applicant identity certificate is generated according to the following steps: the identity issuer receives an identity certificate application request sent by an applicant terminal, wherein the identity certificate application request comprises applicant biometric information, applicant identity information, and an applicant distributed identity; the identity issuer generates an identity verification result according to the applicant identity certificate application request, judges that the applicant identity verification is successful, and generates the applicant identity certificate, wherein the applicant identity certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the identity issuer, and the statement part comprises the applicant distributed identity and an identity issuer distributed identity.
3. The method of claim 1, wherein, the applicant payment identity certificate is generated according to the following steps: the payment service party receives a payment identity certificate application request sent by an applicant terminal, wherein the payment identity certificate application request comprises an applicant distributed identity, an applicant payment account, a payment password, and verification information; the payment service party judges that the applicant payment account verification is successful according to the applicant payment account, the payment password, and the verification information, and generates the applicant payment identity certificate, wherein the applicant payment identity certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the payment service party, and the statement part comprises the applicant distributed identity and a payment service party distributed identity.
4. The method of claim 2 or 3, wherein, the identity issuer distributed identity is generated according to the following steps: the identity issuer generates an identity issuer public key and a private key, and sends the identity issuer public key to a distributed identity system; the distributed identity system generates an identity issuer distributed identity and an identity issuer distributed identity document according to the identity issuer public key, stores the identity issuer public key in the identity issuer distributed identity document, and returns the identity issuer distributed identity to the identity issuer; and the identity issuer distributed identity is generated according to the following steps: Alternatively, the payment service party distributed identity is generated according to the following steps: The payment service party generates a payment service party public key and a private key, and sends the payment service party public key to the distributed identity system; The distributed identity system generates a payment service party distributed identity and a payment service party distributed identity document according to the payment service party public key, stores the payment service party public key in the payment service party distributed identity document, and returns the payment service party distributed identity to the payment service party; Alternatively, the applicant distributed identity is generated according to the following steps: The applicant terminal sends an identity verification request to the trusted identity management institution, and the trusted identity management institution verifies the identity verification request, generates an identity verification result, and returns the identity verification result to the applicant terminal, wherein the identity verification request includes applicant biological feature information and applicant identity information; The applicant terminal judges that the identity verification is passed according to the identity verification result, generates the applicant private key and public key, and sends the applicant public key to the distributed identity system; The distributed identity system generates the applicant distributed identity and the applicant distributed identity document according to the applicant public key, stores the applicant public key in the applicant distributed identity document, and returns the applicant distributed identity to the applicant terminal.
5. The method of claim 4, wherein, The verification of the verifiable expression according to the applicant distributed identity generates a credential verification result, which includes: Obtain the applicant public key from the distributed identity system according to the applicant distributed identity; According to the applicant public key, the signature of the credential is verified, and a credential signature verification result is generated; According to the credential signature verification result, it is judged that the signature verification of the credential is passed, and the applicant identity certificate and the applicant payment identity certificate are verified, and the credential verification result is generated.
6. The method of claim 5, wherein, The verification of the applicant identity certificate and the applicant payment identity certificate generates the credential verification result, which includes: Obtain the identity issuing party public key and the payment service party public key from the distributed identity system according to the identity issuing party distributed identity and the payment service party distributed identity; According to the identity issuing party public key and the payment service party public key, the signature part in the applicant identity certificate and the applicant payment identity certificate is verified respectively, and a signature part verification result is generated; According to the signature part verification result, the credential verification result is generated.
7. The method of claim 6, wherein, The identity issuing party and the payment service party also respectively synchronize the verification data of the applicant identity certificate and the applicant payment identity certificate to the credential permission chain after generating the applicant identity certificate and the applicant payment identity certificate, the verification data of the applicant identity certificate includes a first digest value and a state generated based on the applicant identity certificate, and the verification data of the applicant payment identity certificate includes a second digest value and a state generated based on the applicant payment identity certificate; The generation of the credential verification result according to the signature part verification result includes: According to the signature part verification result, it is judged that the signature part verification of the applicant identity certificate and the applicant payment identity certificate is passed, a third digest value is generated according to the identity certificate, a fourth digest value is generated according to the applicant payment identity certificate, the third digest value and the fourth digest value are sent to the certificate permission chain, so that the certificate permission chain acquires the state of the identity certificate according to the third digest value, acquires the state of the payment service identity certificate according to the fourth digest value, and performs state verification on the applicant identity certificate and the applicant payment identity certificate according to the state of the identity certificate and the state of the payment service identity certificate respectively, and generates and returns a state verification result; According to the state verification result, it is judged that the state of the applicant identity certificate and the applicant payment identity certificate is valid, and a certificate verification result indicating that the verification is passed is generated.
8. The method of claim 1, wherein, The payment information includes: payment amount information, verifier account and payment service party distributed identity; The payment request sent to the payment service party includes: The payment request is sent to the payment service party corresponding to the payment service party distributed identity, so that the payment service party acquires the applicant payment account according to the applicant distributed identity, performs payment processing on the verifier account according to the account amount in the applicant payment account and the payment amount information, and sends a payment processing result to the verifier and the applicant terminal after completing the payment processing.
9. An integrated business identity verification and payment method applied to an applicant terminal, the method comprising: obtaining an applicant identity certificate issued by an identity issuing party and an applicant payment identity certificate issued by a payment service party, and generating a verifiable expression according to the applicant identity certificate and the applicant payment identity certificate, wherein the verifiable expression includes an applicant distributed identity, the applicant identity certificate, the applicant payment identity certificate, and a certificate signature generated by signing the applicant distributed identity, the applicant identity certificate and the applicant payment identity certificate with an applicant private key; sending a business handling request to a verifier, wherein the business handling request includes the verifiable expression; receiving payment information sent by the verifier, wherein the payment information is generated after the verifier verifies the verifiable expression and the verification is passed; sending a payment confirmation response to the verifier, so that the verifier sends a payment request to the payment service party according to the applicant distributed identity and the payment information, and the payment service party performs payment processing.
10. The method of claim 9, wherein, Before the applicant identity certificate issued by the identity issuing party and the applicant payment identity certificate issued by the payment service party are obtained, the method further comprises: sending an identity certificate application request to an identity issuer to make the identity issuer generate an identity authentication result according to the application party identity certificate application request, judge that the application party identity authentication is passed, and generate the application party identity certificate, wherein the identity certificate application request comprises the application party biological feature information, the application party identity information, and the application party distributed identity; receiving the identity certificate returned by the identity issuer, wherein the identity certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the identity issuer, and the statement part comprises the application party distributed identity and the identity issuer distributed identity.
11. The method of claim 9, wherein, Before the application party identity certificate issued by the identity issuer and the application party payment identity certificate issued by the payment service party are obtained, the method further comprises: sending a payment identity certificate application request to the payment service party, wherein the payment identity certificate application request comprises the application party distributed identity, the application party payment account, the payment password, and the verification information, to make the payment service party judge that the application party payment account verification is passed according to the application party payment account, the payment password, and the verification information, and generate the application party payment identity certificate; receiving the application party payment identity certificate returned by the payment service party, wherein the application party payment identity certificate comprises a statement part and a signature part generated by signing the statement part with a private key of the payment service party, and the statement part comprises the application party distributed identity and the payment service party distributed identity.
12. The method of claim 10 or 11, wherein, Before the payment identity certificate application request is sent to the payment service party or the identity certificate application request is sent to the identity issuer, the method further comprises: sending an identity authentication request to a trusted identity management organization to make the trusted identity management organization generate an identity authentication result according to the identity authentication request and return the identity authentication result to the application party terminal, wherein the identity authentication request comprises the application party biological feature information and the application party identity information; judging that the identity authentication is passed according to the identity authentication result, generating the application party private key and public key, and sending the application party public key to a distributed identity system to make the distributed identity system generate the application party distributed identity and the application party distributed identity document according to the application party public key, store the application party public key in the application party distributed identity document, and return the application party distributed identity to the application party terminal; receiving the application party distributed identity sent by the distributed identity system.
13. The method of claim 9, wherein, The method further comprises: receiving the payment processing result sent by the payment service party.
14. The method of claim 12, wherein, The application party terminal is provided with a trusted environment, and the generation of the application party private key and public key comprises: generating the application party private key and public key by calling the trusted environment and storing the application party private key in the trusted environment.
15. An integrated business identity verification and payment device applied to a verification party, the device comprising a receiving module, a verification module, a payment information sending module, and a payment processing module, wherein, The receiving module is configured to receive a service handling request sent by the applicant terminal, wherein the service handling request comprises a verifiable expression, and the verifiable expression comprises an applicant distributed identity, an applicant identity certificate issued by an identity issuing party, an applicant payment identity certificate issued by a payment service party, and a certificate signature generated by signing the applicant distributed identity, the applicant identity certificate, and the applicant payment identity certificate with an applicant private key. The verifying module is configured to verify the verifiable expression according to the applicant distributed identity, and generate a certificate verification result. The payment information sending module is configured to determine, according to the certificate verification result, that the verifiable expression is verified, send payment information to the applicant terminal, and enable the applicant to confirm the payment information. The payment processing module is configured to receive a payment confirmation response sent by the applicant terminal, determine, according to the payment confirmation response, that the applicant confirms the payment information, and send a payment request to the payment service party according to the applicant distributed identity and the payment information, so that the payment service party performs payment processing. 16.An integrated service identity verification and payment device applied to an applicant terminal, comprising a certificate obtaining module, a service handling module, a payment information receiving module, and a payment confirmation module, wherein The certificate obtaining module is configured to obtain an applicant identity certificate issued by an identity issuing party and an applicant payment identity certificate issued by a payment service party, and generate a verifiable expression according to the applicant identity certificate and the applicant payment identity certificate, wherein the verifiable expression comprises an applicant distributed identity, the applicant identity certificate, the applicant payment identity certificate, and a certificate signature generated by signing the applicant distributed identity, the applicant identity certificate, and the applicant payment identity certificate with an applicant private key. The service handling module is configured to send a service handling request to a verifying party, wherein the service handling request comprises the verifiable expression. The payment information receiving module is configured to receive payment information sent by the verifying party, wherein the payment information is generated after the verifying party verifies the verifiable expression and the verification is passed. The payment confirmation module is configured to send a payment confirmation response to the verifying party, so that the verifying party sends a payment request to the payment service party according to the applicant distributed identity and the payment information, and the payment service party performs payment processing. 17.An electronic device comprising: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1-14. 18.A computer readable medium having stored thereon a computer program, the program being executed by a processor to implement the method of any one of claims 1-14.
Citation Information
Patent Citations
Security authentication method and system
CN102891842A
Identity authentication method, certificate holding system and verification system
CN113918899A
Identity validation system and method
US20210342842A1