Combined service handling method and apparatus
By using distributed identity identifiers and verifiable credentials, verifiable representations are generated and sent to multiple business parties, solving the problems of identity authentication complexity and information leakage caused by the dispersion of user digital identities in the traditional Internet, and realizing efficient multi-party business processing.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2026-04-02
AI Technical Summary
In the traditional Internet, users' digital identities are scattered across different systems and platforms, resulting in complex identity authentication, high risk of information leakage, and waste of resources, making it impossible to achieve one-time multi-party business operations.
By using distributed identity identifiers and verifiable credentials, a verifiable representation is generated and sent to multiple business parties for verification, enabling the completion of business transactions for multiple parties with a single operation.
It improves the convenience of users managing their digital identities, reduces the number of identity authentications and the risk of information leakage, and improves the efficiency of business processing.
Smart Images

Figure CN2025123036_02042026_PF_FP_ABST
Abstract
Description
Combined business handling method and device
[0001] The present application claims priority to the Chinese patent application No. 202411388329.X, filed on September 30, 2024, and entitled "Combined business handling method and device", the whole content of which is incorporated herein by reference. TECHNICAL FIELD
[0002] The present application relates to the technical field of computer, and in particular to a combined business handling method and device, an electronic device and a computer readable medium. BACKGROUND
[0003] The traditional Internet development is characterized by centralized services, and each application is an island. The personal identity relies on different centralized service providers, and multiple systems and platforms need to be authenticated separately before operation. Users cannot perform multiple combined operations at a time. This way not only increases the risk of personal sensitive information leakage due to the collection and retention of the same identity information in multiple places, but also leads to the repeated construction of identity authentication infrastructure, resulting in waste of resources. In addition, for individuals, the management of their own digital identity becomes more and more complex and difficult to maintain. The digital identity of the same entity is often scattered in different systems and platforms in a fragmented way. With the explosive growth of Internet applications, it is repetitive and tedious to control, update and maintain this information. SUMMARY
[0004] Therefore, in a first aspect, the present application provides a combined business handling method applied to an applicant terminal or a distributed identity middle platform. The method comprises the following steps:
[0005] In response to the combined business handled by the user involving at least two business handling parties, obtaining the credential verification elements of the at least two business handling parties, and obtaining the verifiable credential corresponding to the credential verification elements from the local according to the credential verification elements, wherein the verifiable credential comprises a statement part and a signature part generated by signing the statement part with a private key of an issuing party, and the statement part comprises an applicant distributed identity and an issuing party distributed identity;
[0006] generating a verifiable expression according to the applicant distributed identity, the verifiable credential and the combined business, wherein the verifiable expression comprises the applicant distributed identity, the verifiable credential, the combined business and a credential signature generated by signing the applicant distributed identity, the verifiable credential and the combined business with a private key of the applicant;
[0007] sending the verifiable expression to the at least two business handling parties, so that each business handling party verifies the verifiable expression, and after verification, each business handling party performs the business operation related to itself in the combined business.
[0008] Receiving and aggregating the service handling results returned by the respective service handling parties.
[0009] In some embodiments of the present application, the credential verification element of the at least two service handling parties is acquired, including:
[0010] The credential verification element acquisition request is sent to the at least two service handling parties, and the credential verification element acquisition request includes the combined service.
[0011] The credential verification element sent by the at least two service handling parties is acquired.
[0012] In some embodiments of the present application, the verifiable expression is generated according to the verifiable credential and the combined service, including:
[0013] The identity authentication information of the user is acquired, and the identity authentication result is generated according to the identity authentication information;
[0014] The identity authentication of the user is determined to be passed according to the identity authentication result, and the verifiable expression is generated according to the applicant distributed identity, the verifiable credential, the combined service and the private key of the applicant.
[0015] In some embodiments of the present application, before the combined service handled by the user involves at least two service handling parties, the method further includes:
[0016] The credential application request is sent to the issuing party, so that the issuing party generates and returns the verifiable credential according to the credential application request, wherein the credential application request includes the distributed identity of the applicant;
[0017] The verifiable credential is received and stored locally.
[0018] In some embodiments of the present application, before the credential application request is sent to the issuing party, the method further includes:
[0019] The distributed identity opening request is sent to the distributed identity system, so that the distributed identity system generates the distributed identity of the applicant and the distributed identity document of the applicant, wherein the distributed identity opening request includes the public key of the applicant, and the public key of the applicant is stored in the distributed identity document of the applicant;
[0020] The distributed identity of the applicant returned by the distributed identity system is received.
[0021] In the second aspect of the embodiments of the present application, a combined service handling method is provided, which is applied to a service handling party, and the method includes the following steps:
[0022] receive a verifiable expression sent by the applicant terminal, wherein the verifiable expression comprises an applicant distributed identity, a verifiable credential, a combined business and a credential signature generated by signing the applicant distributed identity, the verifiable credential and the combined business with an applicant private key, the combined business involves at least two business handlers including a business handler, and the verifiable credential comprises a statement part and a signature part generated by signing the statement part with an issuer private key, the statement part comprises the applicant distributed identity and an issuer distributed identity;
[0023] verify the verifiable expression to generate a credential verification result;
[0024] if the verifiable expression is verified according to the credential verification result, perform a business operation related to the self in the combined business;
[0025] send a business handling result to the applicant terminal, so that the applicant terminal aggregates and displays the business handling results returned by the business handlers.
[0026] In some embodiments of the present application, before receiving the verifiable expression sent by the applicant terminal, the method further comprises:
[0027] receive a credential verification element acquisition request sent by the applicant terminal, wherein the credential verification element acquisition request comprises the combined business;
[0028] acquire the credential verification element according to the business operation related to the self in the combined business, and return the credential verification element to the applicant terminal.
[0029] In some embodiments of the present application, verifying the verifiable expression to generate a credential verification result comprises:
[0030] acquire an applicant public key from a distributed identity system according to the applicant distributed identity;
[0031] verify the credential signature according to the applicant public key to generate a credential signature verification result;
[0032] generate the credential verification result according to the credential signature verification result.
[0033] In some embodiments of the present application, generating the credential verification result according to the credential signature verification result comprises:
[0034] if the credential signature verification is passed according to the credential signature verification result, acquire the credential verification element according to the business operation related to the self in the combined business;
[0035] acquire a target verifiable credential from the verifiable credential according to the credential verification element;
[0036] According to the issuer distributed identity in the target verifiable credential, an issuer public key is obtained from a distributed identity system;
[0037] The signature part in the target verifiable credential is verified by using the issuer public key, and a signature part verification result is generated;
[0038] According to the signature part verification result, a credential verification result is generated.
[0039] In some embodiments of the present application, after the issuer generates the target verifiable credential, the issuer also synchronizes the verification data of the target verifiable credential to the credential permission chain, and the verification data includes a first credential digest value generated according to the target verifiable credential and a credential state;
[0040] According to the signature part verification result, a credential verification result is generated, including:
[0041] According to the signature part verification result, it is determined that the signature part verification is passed, and a second credential digest value is generated according to the target verifiable credential;
[0042] The second credential digest value is sent to the credential verification permission chain, so that the credential permission chain obtains the verification data according to the second credential digest value, and generates a credential state verification result according to the verification data;
[0043] According to the credential state verification result sent by the credential permission chain, it is determined that the state verification of the target verifiable credential is passed, and a credential verification result indicating that the verification is passed is generated.
[0044] In some embodiments of the present application, the business operation related to itself in the combined business is executed, including:
[0045] In response to the business operation related to itself in the combined business needing to rely on other business operations in the combined business, waiting is performed until the business operation result of the other business operation is received;
[0046] According to the business operation result of the other business operation, the business operation related to itself in the combined business is executed.
[0047] The third aspect of the embodiment of the present application also provides a combined business handling device, which is applied to an applicant terminal or a distributed identity middle platform, and the device includes a verifiable credential obtaining module, a verifiable expression generating module, a verifiable expression sending module and a business execution result summarizing module, wherein,
[0048] The verifiable credential obtaining module is configured to, in response to the combined service handled by the user involving at least two service handling parties, obtain credential verification elements of the at least two service handling parties, and obtain, from the local, a verifiable credential corresponding to the credential verification elements according to the credential verification elements, wherein the verifiable credential comprises a statement part and a signature part generated by signing the statement part with a private key of an issuing party, and the statement part comprises a distributed identity of the applicant and a distributed identity of the issuing party.
[0049] The verifiable expression generating module is configured to generate a verifiable expression according to the distributed identity of the applicant, the verifiable credential and the combined service, wherein the verifiable expression comprises the distributed identity of the applicant, the verifiable credential, the combined service and a credential signature generated by signing the distributed identity of the applicant, the verifiable credential and the combined service with a private key of the applicant.
[0050] The verifiable expression sending module is configured to send the verifiable expression to the at least two service handling parties, so that each service handling party verifies the verifiable expression, and after the verification is passed, each service handling party performs a service operation related to itself in the combined service.
[0051] The service execution result collecting module is configured to receive and collect service handling results returned by each service handling party.
[0052] In a fourth aspect, the embodiment of the present application provides a combined service handling device applied to a service handling party, and the device comprises a verifiable expression receiving module, a verification module, a service execution module and a sending module.
[0053] The verifiable expression receiving module is configured to receive the verifiable expression sent by the terminal of the applicant, wherein the verifiable expression comprises a distributed identity of the applicant, a verifiable credential, a combined service and a credential signature generated by signing the distributed identity of the applicant, the verifiable credential and the combined service with a private key of the applicant, the combined service involves at least two service handling parties including the service handling party, the verifiable credential comprises a statement part and a signature part generated by signing the statement part with a private key of an issuing party, and the statement part comprises a distributed identity of the applicant and a distributed identity of the issuing party.
[0054] The verification module is configured to verify the verifiable expression and generate a credential verification result.
[0055] The service execution module is configured to, after the credential verification result indicates that the verification of the verifiable expression is passed, perform a service operation related to itself in the combined service.
[0056] The sending module is configured to send a service handling result to the terminal of the applicant, so that the terminal of the applicant collects and displays service handling results returned by each service handling party.
[0057] In a fifth aspect, the present application provides an electronic device, comprising: one or more processors; and a storage device storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method provided by the present application.
[0058] In a sixth aspect, the present application provides a computer readable medium, having a computer program stored thereon, when the program is executed by a processor, the method provided by the present application is implemented.
[0059] The above-mentioned embodiment of the present application has the following advantages or beneficial effects:
[0060] In the embodiment of the present application, the applicant terminal detects that the service handled by the user belongs to a service involving multiple parties, the applicant terminal acquires the credential verification elements of the multi-party service, selects the corresponding verifiable credential according to the credential verification elements, generates a verifiable expression, and sends it to each multi-party service system. The multi-party service system verifies the verifiable expression and the verifiable credential according to its own needs, and after verification, handles the service involving itself and returns the handling result to the applicant terminal. The applicant terminal summarizes and displays it to the user. In the embodiment of the present application, through the distributed identity technology, a combined service handling can be realized by one operation, and operation instructions are sent to multiple service systems, thereby greatly improving the convenience of user management and maintenance of their own digital identity.
[0061] The further effects of the above-mentioned non-conventional optional mode will be described in the following combined with the specific embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0062] The accompanying drawings are used to better understand the present application and do not constitute an improper limitation on the present application. Among them:
[0063] Fig. 1 is a schematic diagram of the architecture of a network system running a combined service handling method according to some embodiments of the present application;
[0064] Fig. 2 is a schematic diagram of the flow of a combined service handling method according to some embodiments of the present application;
[0065] Fig. 3 is a schematic diagram of the flow of an issuer applying for a distributed identity according to some embodiments of the present application;
[0066] Fig. 4 is a schematic diagram of the flow of an applicant applying for a distributed identity according to some embodiments of the present application;
[0067] Fig. 5 is a schematic diagram of the flow of an applicant applying for a verifiable credential according to some embodiments of the present application;
[0068] Fig. 6 is a schematic diagram of the flow of an applicant terminal or a distributed identity intermediary acquiring credential verification elements according to some embodiments of the present application;
[0069] FIG. 7 is a flow diagram illustrating a process of a service requester verifying an expressible claim in a distributed identity according to some embodiments of the present application;
[0070] FIG. 8 is a flow diagram illustrating a process of a service provider verifying an expressible claim according to some embodiments of the present application;
[0071] FIG. 9 is a flow diagram illustrating a process of a service provider verifying a target expressible claim according to some embodiments of the present application;
[0072] FIG. 10 is a flow diagram illustrating a process of a service provider verifying the validity of a target expressible claim according to some embodiments of the present application;
[0073] FIG. 11 is a flow diagram illustrating a process of a service provider performing a service operation according to some embodiments of the present application;
[0074] FIG. 12 is a diagram illustrating a functional architecture of a combined service provider device according to some embodiments of the present application;
[0075] FIG. 13 is a diagram illustrating a functional architecture of a combined service provider device according to some embodiments of the present application;
[0076] FIG. 14 is a diagram illustrating an exemplary system architecture in which embodiments of the present application can be applied;
[0077] FIG. 15 is a diagram illustrating a computer system suitable for use as a terminal device or server for implementing embodiments of the present application. DETAILED DESCRIPTION
[0078] Exemplary embodiments of the present application are described herein with reference to the accompanying drawings, which are meant to be exemplary and not limiting. Therefore, it should be recognized that many modifications and variations of the disclosed embodiments can be made by those of ordinary skill in the art without departing from the spirit and scope of the application. Also, for the purpose of clarity and the brevity, the description below omits the description of well-known functions and structures.
[0079] First, the acronyms and related terms involved in the embodiments of the present application are defined and explained.
[0080] “DID (Decentralized Identifiers)” refers to a distributed identity, an identifier composed of a string of characters to represent a digital identity, which is generated by a distributed identity system based on the public key and other information of an applicant. The distributed identity system also stores a DID document corresponding to the DID, which stores the DID and the public key corresponding to the DID;
[0081] A "VC (Verifiable Credential)" refers to a verifiable credential, usually a JSON string, containing VC metadata, a statement part, and a proof part. The VC metadata mainly includes the issuer, the issuance date, and the type of the statement. The statement part is one or more specific statements about the subject, for example, if the VC is an identity card, the statement part will contain the holder's name, gender, date of birth, nationality, address, and other personal information. The proof part is usually the digital signature of the issuer, which is used to ensure the integrity and authenticity of the VC content, prevent tampering, and verify the identity of the issuer.
[0082] A "VP (Verifiable Presentation)" is a verifiable presentation associated with a user's distributed identity, containing a verifiable proof file synthesized from one or more verifiable credentials (VCs) and digitally signed by the user.
[0083] In the existing business handling process, if multiple business handling parties are involved, the user needs to submit an application to each business handling party, and each business handling party verifies the user's identity. The user needs to repeatedly submit identity information to each business handling party, resulting in a poor user experience and an increased risk of information leakage. The user needs to submit identity information multiple times, the business operation steps are complicated, the efficiency is low, and repeated verification wastes resources.
[0084] The embodiment of the present application is based on a distributed identity, which breaks through the independent status of identity authentication systems between different systems (e.g., between credential issuers and business handling parties), realizes identity sharing, and realizes the transmission of verification results between different systems by using the transmission of verifiable credentials, thereby improving the efficiency of business handling. At the same time, if the business involves multiple business handling parties, the verifiable credentials can be combined to generate a verifiable presentation according to the needs of each business handling party, and each business handling party verifies the same verifiable presentation, reducing the operation of generating a verifiable presentation and improving the operation efficiency.
[0085] As shown in FIG. 1, a network system 100 in the embodiment of the present application is shown. The combined business handling method in the embodiment of the present application can be run in the network system 100. The network system 100 includes an applicant terminal 110, an issuer 120, a business handling party 130, a distributed identity system 140, a credential permission chain 150, a trusted identity management organization 160, and a distributed identity platform 170.
[0086] In the embodiment of the present application, the applicant terminal 110 can be a terminal comprising a digital wallet application, and the applicant can apply for a distributed identity, apply for a verifiable credential, organize and send a verifiable representation, etc. using the digital wallet application. The applicant terminal 110 can also be provided with a trusted environment for generating the public key and the private key of the applicant and storing the issued verifiable credential. In the embodiment of the present application, the trusted environment is a secure area on the applicant terminal, which can ensure the security of the data loaded therein, including confidentiality, integrity and availability, etc. The trusted environment can be a trusted execution environment (TEE), a secure element (SE), a trusted cryptographic module (TCM) or other secure boundary protection area.
[0087] In some embodiments of the present application, the issuer 120 can be understood as a system controlled by an issuing agency, and the issuer 120 is provided with a server cryptographic machine for generating the public key and the private key of the issuer.
[0088] In some embodiments of the present application, the distributed identity system 140 can generate a distributed identity after verification according to a distributed identity opening request, and generate a distributed identity document corresponding to the distributed identity. The distributed identity document stores the distributed identity and the public key corresponding to the distributed identity, and the distributed identity system 140 stores and maintains the distributed identity document.
[0089] In some embodiments of the present application, the trusted identity management agency 160 can be an agency with authoritative identity authentication, which maintains a database storing the identity information and biometric information of users, and is called by other agencies to verify the identity of the user, etc.
[0090] In some embodiments of the present application, the functions performed by the applicant terminal 110 can also be performed by the distributed identity platform 170, for example, the processes of applying for a distributed identity, applying for a verifiable credential, organizing and generating a verifiable representation, and sending a verifiable representation, etc. can be performed by the distributed identity platform 170. At this time, the applicant terminal 110 is configured to collect the identity information of the user and send the identity information to the distributed identity platform 170, and the distributed identity platform 170 acts on behalf of the user to perform subsequent request operations. In this case, the hardware pressure of the applicant terminal 110 can be effectively reduced, for example, the trusted environment can not be provided on the applicant terminal 110, and the distributed identity related functions can also be used, so that the method in the embodiment of the present application can be widely used.
[0091] As shown in FIG. 2, the embodiment of the present application provides a combined service handling method, comprising the following steps:
[0092] S210: The applicant and the issuer apply for a distributed identity, respectively.
[0093] In some embodiments of the present application, as shown in FIG. 3, the issuer 120 applies for a distributed identity by the following steps.
[0094] S211: The issuer 120 generates an issuer public key and a private key, and sends the issuer public key to the distributed identity system 140. The issuer 120 generates the issuer public key and the private key by using a server cryptomachine, the issuer private key is stored in the server cryptomachine, the issuer public key is sent to the distributed identity system 140, and the issuer 120 can also send the LEI, the name of the institution, and other information to the distributed identity system 140 when sending the issuer public key to the distributed identity system 140.
[0095] S212: The distributed identity system 140 generates an issuer distributed identity and an issuer distributed identity document according to the issuer public key, stores the issuer public key in the issuer distributed identity document, and returns the issuer distributed identity to the issuer. In some embodiments of the present application, the issuer public key can be obtained by indexing the issuer distributed identity to the issuer distributed identity document. In some embodiments of the present application, the issuer distributed identity can be parsed into a uniform resource identifier, and the name of the issuer distributed identity document can be named as the uniform resource identifier. In some embodiments of the present application, the distributed identity system 140 can obtain the issuer distributed identity by hashing calculation based on the issuer public key, or obtain the issuer distributed identity by hashing calculation based on the issuer public key and the timestamp information. In some embodiments of the present application, the distributed identity system 140 can also obtain the issuer distributed identity by hashing calculation based on the issuer public key, the issuer LEI, and the name of the issuer.
[0096] In some embodiments of the present application, the application process of the applicant distributed identity can be initiated by the applicant terminal 110 or the distributed identity platform 170.
[0097] In some embodiments of the present application, as shown in FIG. 4, the applicant terminal 110 or the distributed identity platform 170 applies for a distributed identity by the following steps.
[0098] S213: The applicant terminal 110 or the distributed identity platform 170 sends an identity verification request to the trusted identity management institution 160, the trusted identity management institution 160 verifies according to the identity verification request, generates an identity verification result, and returns the identity verification result to the applicant terminal 110 or the distributed identity platform 170, wherein the identity verification request comprises the applicant's biological feature information; the applicant terminal 110 collects the identity information of the applicant, such as the applicant's biological feature information (for example, a face picture or a face video) or text identity information (name, ID number, certificate type), according to the operation of the applicant (for example, the operation of opening the distributed identity), generates an identity verification request, calls the interface of the trusted identity management institution 160 or forwards the identity verification request to the distributed identity platform 170, and the applicant terminal 110 or the distributed identity platform 170 sends the identity verification request to the trusted identity management institution 160. The trusted identity management institution 160 compares the received identity information with the information in its own database, and generates an identity verification result after comparison.
[0099] S214: The applicant terminal 110 or the distributed identity platform 170 judges that the identity verification is passed according to the identity verification result, generates the applicant's private key and public key, and sends the applicant's public key to the distributed identity system 140; the applicant terminal 110 can generate the applicant's private key and public key by calling the trusted environment, and store the applicant's private key in the trusted environment, and the distributed identity platform 170 stores the applicant's private key in the trusted storage after generating the applicant's private key and public key, and does not transmit the applicant's private key.
[0100] S215: The distributed identity system 140 generates the applicant's distributed identity and the applicant's distributed identity document according to the applicant's public key, stores the applicant's public key in the applicant's distributed identity document, and returns the applicant's distributed identity to the applicant terminal 110 or the distributed identity platform 170.
[0101] In some embodiments of the application, the applicant terminal 110 or the distributed identity platform 170 can also send the applicant's distributed identity to the trusted identity management institution 160 for storage. The distributed identity system 140 can perform hash calculation according to the applicant's public key to generate the applicant's distributed identity, or can perform hash calculation based on the applicant's public key and timestamp information to generate the applicant's distributed identity. In some embodiments of the application, the applicant's public key can be obtained by indexing the applicant's distributed identity to the applicant's distributed identity document. In some embodiments of the application, the applicant's distributed identity can parse a uniform resource identifier, and the name of the applicant's distributed identity document can be named as the above-mentioned uniform resource identifier.
[0102] S220: The applicant terminal 110 or the distributed identity platform 170 applies for obtaining a verifiable credential from the issuer 120 by using the distributed identity identifier of the applicant. In some embodiments of the present application, as shown in FIG. 5, the process of applying for obtaining a verifiable credential is as follows.
[0103] S221: The applicant terminal 110 or the distributed identity platform 170 organizes a verifiable credential application request and sends the verifiable credential application request to the issuer, wherein the verifiable credential application request includes the distributed identity identifier of the applicant, and can also include the biometric information of the applicant, the identity information of the applicant, and the proof request content.
[0104] For example, the user can apply for an identity verifiable credential, a work income verifiable credential, a work verifiable credential, etc. through the applicant terminal 110 or the distributed identity platform 170. The applicant terminal 110 collects the biometric information (such as face) and identity information of the user, and sends the distributed identity identifier of the applicant, the biometric information, the identity information, and the proof request content to the issuer 120. Alternatively, the applicant terminal 110 collects the biometric information and identity information of the user, and sends the biometric information, the identity information, and the proof request content to the distributed identity platform 170. The distributed identity platform 170 forwards the distributed identity identifier of the applicant, the biometric information, the identity information, and the proof request content to the issuer 120. The issuer 120 generates a verifiable credential. The proof request content can be identity information, work income in the past year, work unit information, etc. The issuer 120 can be a user's identity management agency, a bank that pays salaries, a system of a work unit, etc.
[0105] For another example, the user can apply for a housing ownership verifiable credential through the applicant terminal 110. The applicant terminal 110 collects the biometric information and identity information of the user, and sends the distributed identity identifier of the applicant, the biometric information, the identity information, and the proof request content to the issuer 120. The proof request content can be housing ownership related information, such as house number, address, area, owner, etc. The issuer 120 can be a system of a housing management or registration agency. In the above implementation example, the applicant terminal 110 can apply for a housing ownership verifiable credential from the issuer 120 through the distributed identity platform 170.
[0106] For another example, the user can apply for a vehicle ownership verifiable credential through the applicant terminal 110. The above process, and the proof request content corresponds to the vehicle frame number, vehicle brand, vehicle model, vehicle registration place, vehicle owner, etc. The issuer 120 can be a system of a vehicle management or registration agency. In the above implementation example, the applicant terminal 110 can apply for a vehicle ownership verifiable credential from the issuer 120 through the distributed identity platform 170.
[0107] In some embodiments of the present application, when a user applies for a credential through the distributed identity platform 170, the user operates the applicant terminal 110 to send relevant application information to the distributed identity platform 170, and the distributed identity platform 170 organizes the relevant information and applies for a credential to the issuer 120.
[0108] S222: The issuer 120 receives the verifiable credential application request sent by the applicant terminal 110 or the distributed identity platform 170.
[0109] In some embodiments of the present application, the issuer 120 can directly generate a verifiable credential according to the request, and in some embodiments, the identity of the applicant can also be verified, and a verifiable credential is generated after verification.
[0110] S223: The issuer 120 generates an identity verification result according to the identity information and biometric information of the applicant, judges that the identity verification of the applicant is passed, generates a verifiable credential according to the proof request content, and sends the verifiable credential to the applicant terminal 110 or the distributed identity platform 170, wherein the verifiable credential includes a statement part and a signature part generated by signing the statement part with the private key of the issuer, the statement part includes the distributed identity identifier of the applicant, the distributed identity identifier of the issuer, and the proof content, the proof content is generated by the issuer after verifying the proof request content, and the proof content includes identity proof, income proof, asset ownership proof, and work proof.
[0111] In some embodiments of the present application, the issuer 120 can send the biometric information and identity information of the applicant to the trusted identity management institution 160, the trusted identity management institution 160 performs identity verification according to the biometric information of the applicant, and sends the verification result to the issuer 120 after verification, and the issuer 120 generates an identity verification result according to the verification result, and generates a credential after judging that the identity of the user is passed.
[0112] In some embodiments of the present application, the verifiable credential includes a statement part and a signature part generated by signing the statement part with the private key of the issuer 120. The statement part includes the distributed identity identifier of the applicant, the distributed identity identifier of the issuer, and the proof content, which is generated by the issuer after verifying the proof request content. For example, the applicant applies for an income verifiable credential, and the proof content includes income proof, which can be the annual income of the applicant, including pre-tax annual income, after-tax annual income, etc. For another example, the applicant applies for a housing ownership verifiable credential, and the proof content is an asset ownership proof, which is the information of house number, address, and house area.
[0113] S224: The applicant terminal 110 or the distributed identity platform 170 receives and stores the verifiable credential, and in some embodiments of the present application, the applicant terminal 110 stores the verifiable credential into the trusted environment of the applicant terminal 110. The distributed identity platform 170 stores the verifiable credential in the trusted encryption area.
[0114] In some embodiments of the present application, the applicant uses the applicant terminal 110 to send a verifiable credential application request to different issuers 120 for different verifiable credentials, and different issuers 120 generate corresponding verifiable credentials after identity verification.
[0115] In some embodiments of the present application, the issuer 120 also synchronizes the verification data of the verifiable credential to the credential permission chain 150 after generating the verifiable credential, and the verification data includes a first digest value generated according to the verifiable credential and a state. The state of the verifiable credential can be obtained from the credential permission chain 150 through the first digest value of the verifiable credential. In some embodiments of the present application, the state of the verifiable credential includes valid, invalid, and transferred states. In some embodiments of the present application, the verification data also includes the validity period of the credential and other information.
[0116] S230: The applicant terminal 110 or the distributed identity platform 170 obtains a user's combined business handling request, and obtains the credential verification elements of at least two business handling parties in response to the user's combined business involving at least two business handling parties.
[0117] In embodiments of the present application, the user performs a business handling operation through the applicant terminal 110, and the applicant terminal 110 can determine whether multiple business handling parties are involved. The applicant terminal 110 can also transmit the user's business handling operation to the distributed identity platform 170, which can determine whether multiple business handling parties are involved to obtain the credential verification elements.
[0118] In embodiments of the present application, the combined business refers to the combination of multiple businesses. For example, the combined business can be transferring 50 yuan from the user UA's UA-BK1 account to the other party's UB-BK1 account, and transferring 50 yuan from the user's UA-BK2 account to the other party's UB-BK1 account. Since the UA-BK1 account is opened under BK1 bank and the UA-BK2 account is opened under BK2 bank, the combined business involves two business handling parties, BK1 bank and BK2 bank.
[0119] For another example, the combined business can be upgrading the user UA's UA-BK1 account to level two and upgrading the user UA's UA-BK2 account to level three. Since the UA-BK1 account is opened under BK1 bank and the UA-BK2 account is opened under BK2 bank, the combined business involves two business handling parties, BK1 bank and BK2 bank.
[0120] In some embodiments of the present application, if the combined service involves two or more service agents, the corresponding verifiable credentials are selected for combination according to the credential verification elements of the two service agents, a single verifiable expression is generated, and the single verifiable expression is transmitted to the service agents involved for verification, and then the service is handled.
[0121] In some embodiments of the present application, the credential verification element refers to the credential verification requirement associated with the service type and the service agent, for example, for the payment service handled by the service agent BK1, the required credentials of the service agent BK1 include the identity certificate and the BK1 bank card certificate; for the payment service handled by the service agent BK2, the required credentials of the service agent BK2 include the identity certificate and the BK2 bank card certificate. In the embodiments of the present application, each service agent has different credential verification requirements for the same service or different services, and these credential verification requirements are the credential verification elements.
[0122] In some embodiments of the present application, the applicant terminal 110 or the distributed identity platform 170 can prestore the credential verification elements required for different services, or obtain the credential verification elements from the relevant service agents according to the service handling requirements.
[0123] In some embodiments of the present application, as shown in FIG. 6, the credential verification elements of at least two service agents are obtained, including:
[0124] S231: The applicant terminal 110 or the distributed identity platform 170 sends a credential verification element acquisition request to at least two service agents 130, and the credential verification element acquisition request includes a combined service.
[0125] S232: The service agent 130 determines the credential verification element according to the type of the service involving itself in the combined service.
[0126] For example, the combined service is to transfer 50 yuan from the user UA-BK1 account of the user UA to the UB-BK1 account of the other party, and to transfer 50 yuan from the user UA-BK2 account of the user UA to the UB-BK1 account of the other party; the service agent BK1 feeds back the credential verification elements as: the identity certificate and the BK1 bank card certificate, and the service agent BK2 feeds back the credential verification elements as: the identity certificate and the BK2 bank card certificate.
[0127] S233: The applicant terminal 110 or the distributed identity platform 170 obtains the credential verification elements sent by at least two service agents.
[0128] S240: The applicant terminal 110 or the distributed identity platform 170 obtains the verifiable credential corresponding to the credential verification element from the local according to the credential verification element, wherein the verifiable credential includes a statement part and a signature part signed by the private key of the issuing party 120 on the statement part, and the statement part includes the distributed identity identifier of the applicant and the distributed identity identifier of the issuing party.
[0129] According to the above example, the applicant terminal 110 or the distributed identity platform 170 obtains the identity certificate, the BK1 bank card credential and the BK2 bank card credential from the local according to the credential verification element, and then the applicant terminal 110 or the distributed identity platform 170 generates the verifiable expression according to the obtained credentials.
[0130] S250: The applicant terminal 110 or the distributed identity platform 170 generates the verifiable expression. The applicant terminal 110 or the distributed identity platform 170 generates the verifiable expression according to the distributed identity identifier of the applicant, the verifiable credential and the combined business, wherein the verifiable expression includes the distributed identity identifier of the applicant, the verifiable credential, the combined business and the credential signature signed by the private key of the applicant on the distributed identity identifier of the applicant, the verifiable credential and the combined business.
[0131] In some embodiments of the present application, the applicant terminal 110 or the distributed identity platform 170 can generate the verifiable expression after selecting the corresponding verifiable credential according to the credential verification element, and then send the business handler for verification. In some embodiments of the present application, in order to verify the control right of the user on the verifiable credential, the identity of the user is also verified. In some embodiments of the present application, as shown in FIG. 7, step S250 includes the following steps:
[0132] S251: The application terminal 110 or the distributed identity platform 170 obtains the identity authentication information of the user, and generates an identity authentication result according to the identity authentication information; in some embodiments of the present application, the identity authentication information of the user can include identity information, biometric information, and the like of the user. In some embodiments of the present application, the application terminal 110 or the distributed identity platform 170 can call the interface of the trusted identity management institution 160, send the identity authentication information of the user to the trusted identity management institution 160, and verify the identity authentication information of the user by the trusted identity management institution 160, return the verification result to the application terminal 110 or the distributed identity platform 170, and generate the identity authentication result according to the verification result. In some embodiments of the present application, the distributed identity platform 170 can collect the identity information and biometric information of the user through the application terminal 110, the application terminal 110 transmits the collected identity information and biometric information of the user to the distributed identity platform 170, and the distributed identity platform 170 itself verifies or calls the interface of the trusted identity management institution 160 to perform identity authentication.
[0133] In some embodiments of the present application, the trusted environment of the application terminal 110 can prestore the identity authentication information of the user, and the application terminal 110 can verify the identity authentication information submitted by the user locally to generate the identity authentication result.
[0134] S252: The application terminal 110 or the distributed identity platform 170 determines that the user identity authentication is passed according to the identity authentication result, and generates a verifiable expression according to the application distributed identity identifier, the verifiable credential, the combined business, and the application private key.
[0135] In some embodiments of the present application, the application private key is stored in the trusted environment of the application terminal 110, and the process of generating the verifiable expression is also executed in the trusted environment. The application private key is used to sign the application distributed identity identifier, the verifiable credential, and the combined business to generate a credential signature, and the credential signature is combined with the application distributed identity identifier, the verifiable credential, and the combined business to generate the verifiable expression.
[0136] In another embodiment of the present application, the application private key is stored in the trusted encryption area of the distributed identity platform 170, and the process of generating the verifiable expression is also executed in the trusted encryption area.
[0137] In some embodiments of the present application, the declaration part of the verifiable credential further includes a credential name or a credential type id, so that the business handler can determine the target credential required for verification through the credential name or the credential type id in the subsequent verification process.
[0138] In the embodiment of the present application, the user can only need to generate a verifiable expression and perform identity authentication once in the process of handling the combined service, without the need to perform identity authentication for different service handling parties, thereby reducing the number of identity authentications, improving the service handling efficiency, and reducing the risk of leakage caused by information transmission.
[0139] In the embodiment of the present application, the applicant terminal 110 or the distributed identity platform 170 combines the verifiable credentials according to the credential verification elements fed back by the respective service handling parties, and generates a verifiable expression.
[0140] For example, the combined service is to transfer 50 yuan from the user's UA-BK1 account to the counterpart's UB-BK1 account and to transfer 50 yuan from the user's UA-BK2 account to the counterpart's UB-BK1 account; the service handling party BK1 feeds back the credential verification elements as: identity proof credentials and BK1 bank card credentials, and the service handling party BK2 feeds back the credential verification elements as: identity proof credentials and BK2 bank card credentials. The verifiable credentials used to generate the verifiable expression include: identity proof credentials, BK1 bank card credentials and BK2 bank card credentials.
[0141] S260: The applicant terminal 110 or the distributed identity platform 170 sends the verifiable expression to at least two service handling parties 130.
[0142] In the embodiment of the present application, the applicant terminal 110 or the distributed identity platform 170 transmits the same verifiable expression to different service handling parties, and different service handling parties perform verification according to the same verifiable expression, without the need to generate respective verifiable expressions corresponding to respective service handling parties, thereby improving the efficiency of generating verifiable expressions.
[0143] S270: Each service handling party 130 generates a credential verification result according to the verification of the verifiable expression.
[0144] In some embodiments of the present application, each service handling party 130 can obtain the applicant public key from the applicant distributed identity identifier, so as to verify the credential signature in the verifiable expression. Referring to FIG. 8, step S270 includes the following steps:
[0145] S271: The service handling party 130 obtains the applicant public key from the distributed identity system 140 according to the applicant distributed identity identifier. The service handling party 130 sends the applicant distributed identity identifier to the distributed identity system 140, the distributed identity system 140 obtains the applicant distributed identity identifier document according to the applicant distributed identity identifier, obtains the applicant public key from the applicant distributed identity identifier document, and returns the applicant public key to the service handling party 120.
[0146] S272: The business handling party 130 verifies the signature of the credential according to the public key of the applicant party, to generate a credential signature verification result.
[0147] S273: The business handling party 130 generates a credential verification result according to the credential signature verification result. In the embodiments of the present application, through the verification of the credential signature, the integrity of the verifiable expression is ensured, and the transmission from the applicant terminal 110 or the distributed identity platform 170 to the business handling party 120 is not tampered.
[0148] In some embodiments of the present application, before verifying the signature part of the verifiable credential, the identity information of the verifiable credential holder is also verified, for example, real person real evidence verification is performed, specifically, before verifying the verifiable credential, the method in the embodiments of the present application further includes: the business handling party 130 collects the biological feature information of the applicant, and creates an identity verification request (containing the biological feature information of the applicant and the distributed identity of the applicant) according to the distributed identity of the applicant, and sends the identity verification request to the trusted identity management institution 160, the trusted identity management institution 160 verifies the biological feature information of the applicant, generates an identity verification result, and returns the identity verification result to the business handling party 130; the business handling party 130 judges the identity verification of the applicant to be passed according to the identity verification result, and verifies the verifiable credential.
[0149] In some embodiments of the present application, after the business handling party 120 verifies the credential signature using the distributed identity of the applicant and the verification is passed, an identity verification request link is generated and sent to the applicant terminal, the applicant terminal 110 sends the biological feature information of the applicant to the business handling party according to the identity verification request link, the business handling party 130 sends an identity verification request containing the biological feature information of the applicant to the trusted identity management institution 160, the trusted identity management institution 160 verifies the biological feature information of the applicant, generates an identity verification result, and returns the identity verification result to the business handling party 130, the business handling party 130 judges the identity verification of the applicant to be passed according to the identity verification result, and verifies the verifiable credential.
[0150] In some embodiments of the present application, in addition to the need to verify the credential signature, the authenticity and integrity of the verifiable credential can be further verified, referring to FIG. 9, step S273 includes the following steps.
[0151] S2731: The business handling party 130 judges the credential signature verification to be passed according to the credential signature verification result, and obtains the credential verification elements according to the business operation related to itself in the combined business.
[0152] For example, the combined business is to transfer 50 yuan from the UA-BK1 account of the user UA to the UB-BK1 account of the other party, and to transfer 50 yuan from the UA-BK2 account of the user to the UB-BK1 account of the other party; the business handling party BK1 determines the business operation involving itself as: transferring 50 yuan from the UA-BK1 account of the user UA to the UB-BK1 account of the other party, and the credential verification elements obtained are: identity proof credentials and BK1 bank card credentials.
[0153] S2732: The business handling party 130 obtains target verifiable credentials from the verifiable credentials according to the credential verification elements.
[0154] In the above example, the verifiable credentials in the verifiable expression include: identity proof credentials, BK1 bank card credentials and BK2 bank card credentials, and the business handling party BK1 obtains target verifiable credentials: identity proof credentials and BK1 bank card credentials from the verifiable credentials in the verifiable expression.
[0155] S2733: The business handling party 130 obtains the issuer public key from the distributed identity system 140 according to the issuer distributed identity in the target verifiable credentials. The business handling party 130 obtains the issuer public key corresponding to each target verifiable credential for subsequent signature part verification.
[0156] For example, the business handling party BK1 obtains the issuer distributed identity of the identity proof credentials from the identity proof credentials, and obtains the issuer public key of the identity proof credentials from the distributed identity system 140 according to the issuer distributed identity of the identity proof credentials. The business handling party BK1 obtains the issuer distributed identity of the BK1 bank card credentials from the BK1 bank card credentials, and obtains the issuer public key of the BK1 bank card credentials from the distributed identity system 140 according to the issuer distributed identity of the BK1 bank card credentials.
[0157] S2734: The business handling party 130 verifies the signature part in the target verifiable credentials by using the issuer public key, and generates a signature part verification result; the business handling party 130 verifies the signature part for each target verifiable credential, and generates a signature part verification result after the signature part verification of each target verifiable credential is completed. When the signature part verification of each target verifiable credential is passed, the generated signature part verification directly indicates that the signature part verification is passed, otherwise it indicates that it is not passed.
[0158] S2735: The business handling party 130 generates a credential verification result according to the signature part verification result.
[0159] In some embodiments of the present application, when the distributed identity system 140 creates a distributed identity document for an applicant or an issuer, it also writes a specific digital signature algorithm into the distributed identity document, and when the distributed identity system 140 receives a public key corresponding to the application for a distributed identity, it also returns the digital signature algorithm in the distributed identity document to the requestor, so that the requestor can verify the signature according to the returned public key and the digital signature algorithm.
[0160] In some embodiments of the present application, it can be further determined whether the verifiable credential is valid, and the on-chain status of the verifiable credential can be obtained from the credential permission chain 150 to verify the validity of the verifiable credential, thereby ensuring that the status has not been tampered with.
[0161] In some embodiments of the present application, after the issuer 120 generates the verifiable credential, it also synchronizes the verification data of the verifiable credential to the credential permission chain 150, the verification data including a first credential digest value generated according to the verifiable credential and a status, the status of the verifiable credential including a valid credential, an invalid credential, a credential transfer, etc., and the first credential digest value can be obtained by performing a hash calculation on the verifiable credential. After the verification data of the verifiable credential is synchronized to the credential permission chain 150, the business handler 130 can generate a second credential digest value according to the verifiable credential when verifying the status of the verifiable credential, and then can query the status of the verifiable credential from the credential permission chain 150 through the second credential digest value.
[0162] In some embodiments of the present application, when storing the verifiable credential on the credential permission chain 150, the digest value and the status of the verifiable credential are also stored, and the status of the verifiable credential can be obtained from the chain to verify the validity of the verifiable credential.
[0163] In some embodiments of the present application, as shown in FIG. 10, the above step S2735 includes the following steps.
[0164] S27351: The business handler 130 determines that the signature part is verified according to the result of the credential signature verification, and generates a second credential digest value according to the target verifiable credential.
[0165] S27352: The business handler 130 sends the second credential digest value to the credential permission chain.
[0166] S27353: The credential permission chain 150 acquires the verification data according to the second credential digest value, and generates a credential status verification result according to the verification data, and returns the credential status verification result to the service handling party 130. The credential permission chain 150 queries the corresponding first credential digest value according to the second credential digest value, thereby acquiring the status information in the verification data, and generates the credential status verification result according to the status information. When the status is valid, the credential status verification result indicates that the status verification is passed.
[0167] S27354: The service handling party 130 judges that the status verification of the target verifiable credential is passed according to the credential status verification result sent by the credential permission chain, and generates a credential verification result indicating that the verification is passed.
[0168] In some embodiments of the present application, when the credential signature verification is not passed, the signature part verification in the verifiable credential is not passed, or the status of the verifiable credential is invalid, the service handling party 130 generates a credential verification result indicating that the verification is not passed.
[0169] S280: After the service handling party 130 judges that the verifiable expression verification is passed according to the credential verification result, the service handling party 130 performs the business operation related to itself in the combined business, and sends a service handling result to the applicant terminal 110 or the distributed identity platform 170.
[0170] In the embodiments of the present application, when the combined business involves multiple service handling parties, the service handling parties can perform the business handling in parallel, that is, they do not need to depend on the handling results of other service handling parties. In some embodiments of the combined business handling process, when part of the business operation needs to depend on the results of other business operations, the service handling party 130 needs to wait for the business handling results fed back by other service handling parties, and then performs the business handling according to the business handling results of other service handling parties. As shown in FIG. 11, in some embodiments of the present application, step S280 includes the following steps.
[0171] S281: The service handling party 130 waits until the business operation result of other business operation is received in response to the business operation related to itself in the combined business needing to depend on other business operations in the combined business. In some embodiments of the present application, the business operation result of other business operation is generated by other service handling party 130 after verifying the verifiable expression and handling the business operation. The business operation result of other business operation can be directly sent to the current service handling party by other service handling party, or can be sent to the applicant terminal 110 or the distributed identity platform 170 by other service handling party, and then forwarded to the current service handling party by the applicant terminal 110 or the distributed identity platform 170.
[0172] S282: The business handling party 130 performs the business operation related to itself in the combined business according to the business operation result of the other business operation, and sends the business handling result to the applicant terminal 110 or the distributed identity platform 170. When the business operation result of the other business operation indicates that the operation is successful, the current business handling party handles the business related to itself; when the business operation result of the other business operation indicates that the operation fails, the current business handling party does not handle the business related to itself.
[0173] In the embodiment of the application, the dependency relationship between each business operation in the combined business can be specified by the user, for example, for operation A, operation B, operation C, and operation D in the combined business, the user can specify that operation A is completed, operation B is executed, operation C is executed after operation B is completed, and operation D is executed.
[0174] S290: The applicant terminal 110 or the distributed identity platform 170 aggregates the business handling results returned by each business handling party 130, and the applicant terminal 110 displays the aggregated business handling result.
[0175] For example, the combined business is to transfer 50 yuan from the UA-BK1 account of the user UA to the UB-BK1 account of the other party and to transfer 50 yuan from the UA-BK2 account of the user to the UB-BK1 account of the other party; after the business handling party BK1 completes the business of transferring 50 yuan from the UA-BK1 account of the user UA to the UB-BK1 account of the other party, the business handling party BK1 feeds back the business handling result to the applicant terminal 110 or the distributed identity platform 170: the UA-BK1 account successfully transfers 50 yuan to the UB-BK1 account; after the business handling party BK2 completes the business of transferring 50 yuan from the UA-BK2 account of the user to the UB-BK1 account of the other party, the business handling party BK2 feeds back the business handling result to the applicant terminal 110 or the distributed identity platform 170: the UA-BK2 account successfully transfers 50 yuan to the UB-BK1 account. The applicant terminal 110 or the distributed identity platform 170 aggregates the business handling results as: the UA-BK1 account successfully transfers 50 yuan to the UB-BK1 account, and the UA-BK2 account successfully transfers 50 yuan to the UB-BK1 account. In some embodiments of the application, when the aggregation step is performed by the applicant terminal 110, the applicant terminal 110 displays the aggregated result; when the aggregation step is performed by the distributed identity platform 170, the distributed identity terminal 170 sends the aggregated business execution result to the applicant terminal 110, and the applicant terminal 110 displays the aggregated business handling result.
[0176] The embodiment of the present application is applied to a combined service, and only one application needs to be submitted. The user does not need to repeatedly submit identity information and certificate information to each service handling party. According to the certificate verification elements of each service handling party, a verifiable expression that can be verified by each service handling party is generated. The user does not need to independently generate a verifiable expression for each service handling party, thereby reducing the operation of the user, improving the service handling efficiency, and improving the user experience. Meanwhile, the embodiment of the present application uses a distributed identity to replace a plaintext identity. Under the premise of ensuring reliable verification, the privacy of the user is protected, the step of repeatedly verifying the plaintext identity information of the user is reduced, and the information leakage risk caused by identity information transmission is reduced.
[0177] The embodiment of the present application is shown in FIG. 12. The embodiment of the present application provides a combined service handling device 400 applied to an application party terminal or a distributed identity middle platform. The device 400 includes a verifiable certificate acquisition module 410, a verifiable expression generation module 420, a verifiable expression sending module 430, and a service execution result summarizing module 440. The verifiable certificate acquisition module 410 is configured to acquire certificate verification elements of at least two service handling parties in response to a combined service handled by the user involving the at least two service handling parties. The certificate verification elements are acquired from the local according to the certificate verification elements. The verifiable certificate corresponding to the certificate verification elements is acquired from the local according to the certificate verification elements. The verifiable certificate includes a declaration part and a signature part generated by signing the declaration part by a private key of an issuing party. The declaration part includes an application party distributed identity and an issuing party distributed identity.
[0178] The verifiable certificate acquisition module 410 is configured to acquire certificate verification elements of at least two service handling parties in response to a combined service handled by the user involving the at least two service handling parties. The certificate verification elements are acquired from the local according to the certificate verification elements. The verifiable certificate corresponding to the certificate verification elements is acquired from the local according to the certificate verification elements. The verifiable certificate includes a declaration part and a signature part generated by signing the declaration part by a private key of an issuing party. The declaration part includes an application party distributed identity and an issuing party distributed identity.
[0179] The verifiable expression generation module 420 is configured to generate a verifiable expression according to the application party distributed identity, the verifiable certificate, and the combined service. The verifiable expression includes the application party distributed identity, the verifiable certificate, the combined service, and a certificate signature generated by signing the application party distributed identity, the verifiable certificate, and the combined service by a private key of the application party.
[0180] The verifiable expression sending module 430 is configured to send the verifiable expression to the at least two service handling parties, so that each service handling party verifies the verifiable expression, and each service handling party performs a service operation related to itself in the combined service after the verification is passed.
[0181] The service execution result summarizing module 440 is configured to receive and summarize the service handling results returned by each service handling party, and display the summarized service handling results.
[0182] In some embodiments of the present application, the verifiable certificate acquisition module 410 is further configured to:
[0183] send a certificate verification element acquisition request to the at least two service handling parties. The certificate verification element acquisition request includes the combined service.
[0184] obtaining the credential verification element sent by the at least two service providers.
[0185] In some embodiments of the present application, the verifiable expression generation module 420 is further configured to:
[0186] obtain the identity authentication information of the user, and generate an identity authentication result according to the identity authentication information;
[0187] determine that the user identity authentication is passed according to the identity authentication result, and generate a verifiable expression according to the applicant distributed identity, the verifiable credential, the combined service and the applicant private key.
[0188] In some embodiments of the present application, the device 400 further comprises a credential application module 450, and the credential application module 450 is configured to:
[0189] send a credential application request to the issuing party, so that the issuing party generates and returns a verifiable credential according to the credential application request, wherein the credential application request comprises the applicant distributed identity;
[0190] receive and locally store the verifiable credential.
[0191] In some embodiments of the present application, the device 400 further comprises a distributed identity application module 460, and the distributed identity application module 460 is configured to:
[0192] send a distributed identity opening request to the distributed identity system, so that the distributed identity system generates the applicant distributed identity and an applicant distributed identity document, wherein the distributed identity opening request comprises the applicant public key, and the applicant public key is stored in the applicant distributed identity document;
[0193] receive the applicant distributed identity returned by the distributed identity system.
[0194] As shown in FIG. 13, the embodiment of the present application provides a combined service handling device 500 applied to a service provider, and the device 500 comprises a verifiable expression receiving module 510, a verification module 520, a service execution module 530 and a sending module 540, wherein,
[0195] The verifiable expression receiving module 510 is configured to receive the verifiable expression sent by the applicant terminal or the distributed identity platform, wherein the verifiable expression comprises an applicant distributed identity, a verifiable credential, a combined service, and a credential signature generated by signing the applicant distributed identity, the verifiable credential, and the combined service with an applicant private key, and the combined service involves at least two service providers including a service provider, and the verifiable credential comprises a statement part and a signature part generated by signing the statement part with an issuer private key, and the statement part comprises the applicant distributed identity and an issuer distributed identity;
[0196] The verification module 520 is configured to verify the verifiable expression and generate a credential verification result.
[0197] The service execution module 530 is configured to, after determining that the verifiable expression passes the verification according to the credential verification result, execute a service operation related to itself in the combined service.
[0198] The sending module 540 is configured to send a service handling result to the applicant terminal or the distributed identity platform, so that the applicant terminal or the distributed identity platform aggregates the service handling results returned by the service providers and displays the service handling results on the applicant terminal.
[0199] In some embodiments of the present application, the device 500 further comprises a credential element sending module 550, which is configured to:
[0200] receive a credential verification element obtaining request sent by the applicant terminal or the distributed identity platform, wherein the credential verification element obtaining request comprises a combined service;
[0201] obtain a credential verification element according to a service operation related to itself in the combined service, and return the credential verification element to the applicant terminal or the distributed identity platform.
[0202] In some embodiments of the present application, the verification module 520 is further configured to:
[0203] obtain an applicant public key from a distributed identity system according to the applicant distributed identity;
[0204] verify the credential signature according to the applicant public key and generate a credential signature verification result;
[0205] generate the credential verification result according to the credential signature verification result.
[0206] In some embodiments of the present application, the verification module 520 is further configured to:
[0207] determine that the credential signature passes the verification according to the credential signature verification result, and obtain a credential verification element according to a service operation related to itself in the combined service;
[0208] obtain a target verifiable credential from the verifiable credential according to the credential verification element;
[0209] obtain an issuer public key from the distributed identity system according to the issuer distributed identity in the target verifiable credential;
[0210] verify the signature part in the target verifiable credential by using the issuer public key, and generate a signature part verification result;
[0211] generate a credential verification result according to the signature part verification result.
[0212] In some embodiments of the present application, after generating the target verifiable credential, the issuer also synchronizes the verification data of the target verifiable credential to the credential permission chain, and the verification data includes a first credential digest value generated according to the target verifiable credential and a credential state;
[0213] The verification module 520 is further configured to: determine that the signature part verification is passed according to the signature part verification result, and generate a second credential digest value according to the target verifiable credential;
[0214] send the second credential digest value to the credential verification permission chain, so that the credential verification permission chain obtains the verification data according to the second credential digest value, and generates a credential state verification result according to the verification data;
[0215] determine that the state verification of the target verifiable credential is passed according to the credential state verification result sent by the credential verification permission chain, and generate a credential verification result indicating that the verification is passed.
[0216] In some embodiments of the present application, the business execution module 530 is configured to:
[0217] In response to the business operation related to itself in the combined business needing to rely on other business operations in the combined business, wait until the business operation result of the other business operation is received;
[0218] execute the business operation related to itself in the combined business according to the business operation result of the other business operation.
[0219] The device features of the embodiments of the present application can refer to the method, steps and other features of the embodiments of the present application, and the system embodiments can combine the features of the method embodiments to obtain new embodiments, and vice versa, which will not be described here.
[0220] In the embodiments of the present application, an electronic device is provided, which includes a processor and a memory storing a computer program, the processor is configured to implement any method according to the embodiments of the present application when running the computer program. In addition, an apparatus according to the embodiments of the present application can also be provided.
[0221] FIG. 14 shows an exemplary system architecture 1400 to which the identity credential application, combined service handling method or identity credential application, combined service handling apparatus of embodiments of the present application can be applied.
[0222] As shown in FIG. 14, the system architecture 1400 can include terminal devices 1401, 1402, 1403, a network 1404 and a server 1405. The network 1404 is a medium for providing a communication link between the terminal devices 1401, 1402, 1403 and the server 1405. The network 1404 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0223] A user can use the terminal devices 1401, 1402, 1403 to interact with the server 1405 through the network 1404 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 1401, 1402, 1403, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0224] The terminal devices 1401, 1402, 1403 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers and desktop computers, etc.
[0225] The server 1405 can be a server providing various services, such as a background management server supporting a shopping website browsed by a user using the terminal devices 1401, 1402, 1403 (only as an example). The background management server can analyze and process received product information query requests and other data, and feed back the processing results (such as target push information, product information - only as examples) to the terminal devices.
[0226] It should be noted that the identity credential application, combined service handling method provided by embodiments of the present application is generally executed by the server 1405, and accordingly, the identity credential application, combined service handling apparatus is generally provided in the server 1405.
[0227] It should be understood that the number of terminal devices, networks and servers in FIG. 14 is only illustrative. According to the needs of implementation, there can be any number of terminal devices, networks and servers.
[0228] Reference will now be made to FIG. 15, which shows a structural diagram of a computer system 1500 suitable for use in implementing the terminal device or server of an embodiment of the present application. The method or the apparatus for implementing the method of an embodiment of the present application can be implemented on the computer system 1500. The terminal device or server shown in FIG. 15 is merely an example and should not impose any limitation on the functions and the use range of an embodiment of the present application.
[0229] As shown in FIG. 15, the computer system 1500 includes a central processing unit (CPU) 1501, which can perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 1502 or a program loaded from a storage section 1508 into a random access memory (RAM) 1503. Various programs and data required for the operation of the system 1500 are also stored in the RAM 1503. The CPU 1501, the ROM 1502, and the RAM 1503 are connected to each other through a bus 1504. An input / output (I / O) interface 1505 is also connected to the bus 1504.
[0230] The following components are connected to the I / O interface 1505: an input section 1506 including a keyboard, a mouse, etc.; an output section 1507 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1508 including a hard disk, etc.; and a communication section 1509 including a network interface card such as a LAN card, a modem, etc. The communication section 1509 performs communication processing via a network such as the Internet. A drive 1510 is also connected to the I / O interface 1505 as necessary. A removable media 1511 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 1510 as necessary, so that a computer program read therefrom is installed into the storage section 1508 as necessary.
[0231] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to an embodiment of the present application. For example, an embodiment of the present application includes a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the method shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network by the communication section 1509 and / or from the removable media 1511. When the computer program is executed by the central processing unit (CPU) 1501, the above-described functions defined in the system of the present application are performed.
[0232] It should be noted that the computer-readable medium shown in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component. In the present application, the computer-readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or component. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0233] The flowcharts and block diagrams in the drawings illustrate the possible implementation architectures, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment or a part of code containing one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order than that shown in the drawings. For example, two blocks that are shown in succession can actually be executed substantially in parallel, and sometimes in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams or flowcharts, and the combination of blocks in the block diagrams or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0234] The units or modules described in the embodiments of the present application can be implemented by software or by hardware. The described units or modules can also be arranged in a processor, for example, a processor can be described as including a sending unit (or "module"), an obtaining unit, a determining unit, and a first processing unit. In some cases, the names of the units or modules do not constitute a limitation on the units or modules themselves, for example, the sending unit can also be described as "a unit for sending a picture obtaining request to a connected server".
[0235] As another aspect, the present application also provides a computer readable medium, which can be included in the device described in the above embodiments, or can exist independently without being assembled into the device. The computer readable medium carries one or more programs, which, when executed by the device, cause the device to perform the identity credential application and combined service handling method described in the above embodiments.
[0236] The above detailed description does not constitute a limitation on the scope of protection of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present application should be included in the scope of protection of the present application. Industrial applicability
[0237] The scheme provided by the embodiments of the present application can be applied to the field of computer technology. In the embodiments of the present application, the credential verification elements of at least two service handling parties are obtained, and the corresponding verifiable credentials are obtained from the local according to the credential verification elements; a verifiable expression is generated according to the application party distributed identity, the verifiable credentials, and the combined service; the verifiable expression is sent to the at least two service handling parties; the service handling results returned by each service handling party are received and summarized, and the summarized service handling results are displayed, thereby ensuring the security of identity information, reducing the operation of secondary verification of the user, and improving the efficiency of combined service handling.
Claims
1. A method for handling a combined service, applied to an applicant terminal or a distributed identity platform, the method comprising the following steps: In response to the combined service handled by the user involving at least two service handling parties, the credential verification elements of the at least two service handling parties are acquired, and the verifiable credential corresponding to the credential verification elements is acquired locally according to the credential verification elements, wherein the verifiable credential comprises a statement part and a signature part signed by a private key of an issuer, the statement part comprising an applicant distributed identity and an issuer distributed identity; generating a verifiable representation according to the applicant distributed identity, the verifiable credential and the combined service, wherein the verifiable representation comprises the applicant distributed identity, the verifiable credential, the combined service and a credential signature signed by a private key of the applicant on the applicant distributed identity, the verifiable credential and the combined service; sending the verifiable representation to the at least two service handling parties, so that each service handling party verifies the verifiable representation, and after verification, each service handling party performs a service operation related to itself in the combined service; receiving and aggregating service handling results returned by each service handling party.
2. The method of claim 1, wherein, the obtaining of the credential verification elements of the at least two service handling parties comprises: sending a credential verification element obtaining request to the at least two service handling parties, the credential verification element obtaining request comprising the combined service; obtaining the credential verification elements sent by the at least two service handling parties.
3. The method of claim 1, wherein, the generating of the verifiable representation according to the verifiable credential and the combined service comprises: obtaining identity authentication information of a user, and generating an identity authentication result according to the identity authentication information; judging that the identity authentication of the user is passed according to the identity authentication result, and generating the verifiable representation according to the applicant distributed identity, the verifiable credential, the combined service and the private key of the applicant.
4. The method of claim 1, wherein, In response to the combined service handled by the user involving at least two service handling parties, the method further comprises: sending a credential application request to the issuer, so that the issuer generates and returns a verifiable credential according to the credential application request, wherein the credential application request comprises the applicant distributed identity; receiving and locally storing the verifiable credential.
5. The method of claim 4, wherein, Before sending the credential application request to the issuer, the method further comprises: sending a distributed identity opening request to a distributed identity system, so that the distributed identity system generates the applicant distributed identity and an applicant distributed identity document, wherein the distributed identity opening request comprises an applicant public key, and the applicant public key is stored in the applicant distributed identity document; receiving the applicant distributed identity returned by the distributed identity system. 6.A method for handling a combined service, applied to a service handling party, the method comprising the following steps: receiving a verifiable representation sent by the application terminal or the distributed identity platform, wherein, The verifiable expression includes an applicant distributed identity, a verifiable credential, a combined business, and a credential signature signed by the applicant private key on the applicant distributed identity, the verifiable credential, and the combined business, the combined business involving at least two business handlers including the business handler, and the verifiable credential including a statement part and a signature part signed by an issuer private key on the statement part, the statement part including the applicant distributed identity and an issuer distributed identity; verifying the verifiable expression to generate a credential verification result; after determining that the verifiable expression is verified according to the credential verification result, performing a business operation related to itself in the combined business; sending a business handling result to the applicant terminal or the distributed identity middle station to enable the applicant terminal or the distributed identity middle station to aggregate the business handling results returned by the business handlers and display the business handling results on the applicant terminal.
7. The method of claim 6, wherein, Before receiving the verifiable expression sent by the applicant terminal or the distributed identity middle station, the method further includes: receiving a credential verification element acquisition request sent by the applicant terminal or the distributed identity middle station, the credential verification element acquisition request including the combined business; acquiring a credential verification element according to the business operation related to itself in the combined business, and returning the credential verification element to the applicant terminal or the distributed identity middle station.
8. The method of claim 7, wherein, verifying the verifiable expression to generate a credential verification result, including: acquiring an applicant public key from a distributed identity system according to the applicant distributed identity; verifying the credential signature according to the applicant public key to generate a credential signature verification result; generating the credential verification result according to the credential signature verification result.
9. The method of claim 8, wherein, The generating of the credential verification result according to the credential signature verification result includes: determining that the credential signature verification is passed according to the credential signature verification result, and acquiring a credential verification element according to the business operation related to itself in the combined business; acquiring a target verifiable credential from the verifiable credential according to the credential verification element; acquiring an issuer public key from a distributed identity system according to an issuer distributed identity in the target verifiable credential; verifying a signature part in the target verifiable credential according to the issuer public key to generate a signature part verification result; generating the credential verification result according to the signature part verification result.
10. The method of claim 9, wherein, After the issuer generates the target verifiable credential, the issuer also synchronizes verification data of the target verifiable credential to a credential permission chain, the verification data including a first credential digest value generated according to the target verifiable credential and a credential state, The generating of the credential verification result according to the signature part verification result includes: determining that the signature part verification is passed according to the signature part verification result, and generating a second credential digest value according to the target verifiable credential; sending the second credential digest value to a credential verification permission chain to enable the credential verification permission chain to acquire verification data according to the second credential digest value, and generate a credential state verification result according to the verification data; The credential status verification result sent according to the credential permission chain is used to determine whether the target verifiable credential passes the status verification, and a credential verification result indicating that the verification passes is generated.
11. The method of claim 6, wherein, The performing of the business operation related to itself in the combined business includes: In response to the business operation related to itself in the combined business needing to rely on other business operations in the combined business, waiting is performed until a business operation result of the other business operation is received; The business operation related to itself in the combined business is performed according to the business operation result of the other business operation.
12. A combined business handling device, applied to an applicant terminal or a distributed identity platform, the device comprising a verifiable credential acquisition module, a verifiable expression generation module, a verifiable expression sending module, and a business execution result aggregation module, wherein The verifiable credential acquisition module is configured to, in response to a combined business handled by a user involving at least two business handling parties, acquire credential verification elements of the at least two business handling parties, and acquire a verifiable credential corresponding to the credential verification elements from a local according to the credential verification elements, wherein the verifiable credential comprises a statement part and a signature part generated by signing the statement part with a private key of an issuing party, and the statement part comprises an applicant distributed identity and an issuing party distributed identity; The verifiable expression generation module is configured to generate a verifiable expression according to the applicant distributed identity, the verifiable credential, and the combined business, wherein the verifiable expression comprises the applicant distributed identity, the verifiable credential, the combined business, and a credential signature generated by signing the applicant distributed identity, the verifiable credential, and the combined business with a private key of the applicant; The verifiable expression sending module is configured to send the verifiable expression to the at least two business handling parties, so that each business handling party verifies the verifiable expression, and after the verification passes, each business handling party performs a business operation related to itself in the combined business; The business execution result aggregation module is configured to receive and aggregate business handling results returned by each business handling party.
13. A combined business handling device, applied to a business handling party, the device comprising a verifiable expression receiving module, a verification module, a business execution module, and a sending module, wherein The verifiable expression receiving module is configured to receive a verifiable expression sent by an applicant terminal or a distributed identity platform, wherein the verifiable expression comprises an applicant distributed identity, a verifiable credential, a combined business, and a credential signature generated by signing the applicant distributed identity, the verifiable credential, and the combined business with a private key of the applicant, the combined business involves at least two business handling parties including the business handling party, the verifiable credential comprises a statement part and a signature part generated by signing the statement part with a private key of an issuing party, and the statement part comprises the applicant distributed identity and an issuing party distributed identity; The verification module is configured to verify the verifiable expression, and generate a credential verification result; The business execution module is configured to execute a business operation related to the business execution module itself in the combined business according to a result of judging that the verifiable expression is verified successfully. The sending module is configured to send a business handling result to the applicant terminal or the distributed identity intermediary, so that the applicant terminal or the distributed identity intermediary collects the business handling results returned by the business handling parties and displays the business handling results on the applicant terminal.
14. An electronic device, comprising: one or more processors; storage configured to store one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1-11.
15. A computer readable medium having stored thereon a computer program which, when executed by a processor, implements the method of any one of claims 1-11.
Citation Information
Patent Citations
A distributed digital identity-based service processing method and a related device
CN113704775A
Identity authentication method, certificate holding system and verification system
CN113918899A
Identity verification method and device, electronic equipment and computer readable storage medium
CN116975810A
Personal identity system
US20210385216A1