Identity Authentication Using Merkle Tree Verification Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital identity authentication methods are vulnerable to privacy information leakage, as they require the disclosure of all identity attributes, which can lead to severe losses of property and related interests.
Innovation Solution
A method for identity authentication that involves acquiring an identity proof with a Merkel root verification path, deducing the Merkel root verification path based on the disclosed identity attribute, and authenticating the identity proof using both paths, thereby allowing only partial identity attributes to be disclosed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all identity attributes are disclosed for authentication, then authentication reliability is improved, but privacy information security deteriorates
Solution Approach 1:
The patent segments identity attributes into multiple independent components and uses a Merkle tree structure to organize them. Each identity attribute is represented as a leaf node in the Merkle tree, and only the specific attribute needed for authentication is disclosed through its hash value and verification path, rather than all attributes. This segmentation allows authentication to proceed while keeping other identity information hidden.
Solution Approach 2:
The patent extracts only the necessary identity attribute for authentication from the complete set of identity attributes. By using cryptographic hash functions and Merkle tree verification paths, the system extracts and discloses minimal information (specific attribute hash and verification path) while keeping the rest of the identity information private, thus solving the contradiction between authentication reliability and privacy protection.
2Object-affected harmful factors
If partial identity attributes are disclosed for privacy protection, then privacy information security is improved, but authentication reliability deteriorates
Solution Approach 1:
The patent introduces cryptographic hash functions and Merkle tree verification paths as intermediaries between the identity attributes and the authentication process. These intermediaries enable the system to verify identity attributes without directly exposing them. The hash values and verification paths serve as mediators that prove the authenticity of identity attributes while maintaining privacy, thus resolving the contradiction between partial disclosure and authentication reliability.
3Ease of operation
If traditional identity authentication methods are used, then ease of operation is maintained, but security against privacy leakage deteriorates
Solution Approach 1:
The patent uses cryptographic hash copies of identity attributes instead of the actual identity attributes themselves. The Merkle tree structure creates hash copies at each level, and the verification path provides a cryptographic copy that proves the authenticity of the disclosed attribute without revealing the original information. This copying approach maintains operational simplicity while enhancing security against privacy leakage.
Data Source
AI summary
The present disclosure provides a method for identity authentication, an electronic device and a computer readable storage medium. The method for identity authentication may include: acquiring an identity proof of a user, wherein the identity proof comprises an identity attribute of the user and a Merkel root verification path, and the Merkel root verification path in the identity proof is a verification path obtained when the identity proof is generated and based on the identity attribute selected by the user to be disclosed; deducing the Merkel root verification path according to the identity attribute disclosed in the identity proof; and authenticating the identity proof of the user according to the deduced verification path and a verification path in the identity proof.


