CN118381663B - College alliance user identity management method based on blockchain and DID - Google Patents

College alliance user identity management method based on blockchain and DID Download PDF

Info

Publication number
CN118381663B
CN118381663B CN202410806278.1A CN202410806278A CN118381663B CN 118381663 B CN118381663 B CN 118381663B CN 202410806278 A CN202410806278 A CN 202410806278A CN 118381663 B CN118381663 B CN 118381663B
Authority
CN
China
Prior art keywords
university
verifiable certificate
verifiable
attribute
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202410806278.1A
Other languages
Chinese (zh)
Other versions
CN118381663A (en
Inventor
王峰
张烨
艾明瑞
罗昕怡
薛开平
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
University of Science and Technology of China USTC
Original Assignee
University of Science and Technology of China USTC
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by University of Science and Technology of China USTC filed Critical University of Science and Technology of China USTC
Priority to CN202410806278.1A priority Critical patent/CN118381663B/en
Publication of CN118381663A publication Critical patent/CN118381663A/en
Application granted granted Critical
Publication of CN118381663B publication Critical patent/CN118381663B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q50/00Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
    • G06Q50/10Services
    • G06Q50/20Education
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • H04L9/3268Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/50Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Business, Economics & Management (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Tourism & Hospitality (AREA)
  • Primary Health Care (AREA)
  • Theoretical Computer Science (AREA)
  • Human Resources & Organizations (AREA)
  • Marketing (AREA)
  • Economics (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Educational Technology (AREA)
  • Educational Administration (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The invention discloses a college alliance user identity management method based on a block chain and a DID, and belongs to the technical field of block chain application. The method comprises the steps that multiple universities form an identity alliance chain, and the identity alliance chain is used for maintaining DID identities of all users; universities prove that users possess certain attributes by issuing verifiable certificates to users; when the user needs to use the service of some service provider, the user can prove to have corresponding attribute by combining a plurality of verifiable certificates; wherein the user uses different derived DID when applying for different verifiable certificates. The method can effectively provide global identity management for college alliances established based on alliance chains, and realize identity authentication and fine-granularity service authorization based on verifiable certificates.

Description

College alliance user identity management method based on blockchain and DID
Technical Field
The invention belongs to the technical field of block chain application, and particularly relates to a college alliance user identity management method based on block chains and DIDs.
Background
With the development of the Internet and digital technology, the role of the identity authentication technology becomes more important, so that the data security and privacy of individuals and organizations can be protected; meanwhile, resource intercommunication and information mutual recognition are important trends of development in the digital age, and can promote collaborative development and cooperation among industries. Under the scene of universities, identity authentication and resource intercommunication are more important, personal information and privacy of students and teachers can be protected, and collaborative development and resource sharing between universities are promoted. Therefore, the method has important practical value and strategic value for promoting college identity authentication and resource intercommunication.
The currently popular centralized identity authentication system has some defects, and the user has high dependence on an authentication mechanism or a service provider, which means that the user cannot control own identity information and cannot autonomously select the authentication mechanism or the service provider; the centralized architecture relies on a single authentication server or third party service provider, so that the entire system will be impacted once a single point of failure occurs; individuals build repeated but not identical identity data in different systems to form individual data islands; while the mechanism has the problem of opaque use of the data. One feasible method is to introduce a blockchain and decentralizing identity management method to realize identity authentication and information intercommunication in a college scene. The method can solve the problems of the dependency of the organization and the data island of the authentication of the central avatar, and the university can realize the inter-organization identity management and the data intercommunication, so that the complexity of resource service and the requirement of the organization intercommunication are improved, but the method has the risk of revealing the privacy information of the user, namely, a malicious attacker portrays the user through the public information on a alliance chain, and infringes the privacy of the user. The private information of the user can be protected by using the method of deriving the DID, but the related art lacks a corresponding solution.
Disclosure of Invention
In order to solve the technical problems, the invention provides a college alliance user identity management method based on block chains and DIDs, which can effectively provide global identity management for college alliances established based on the alliance chains, realize identity authentication and fine-granularity service authorization based on verifiable certificates, and provide privacy protection, user self-right and user-friendly decentralization avatar management schemes for users in the college alliances.
In order to achieve the above purpose, the technical scheme adopted by the invention is as follows:
step 1, initializing a system: establishing a coalition chain comprising college identities by a plurality of colleges and universities, and initializing DID identities on the college DID service manager coalition chain; the university DID service manager defines a verifiable certificate definition file list, and the verifiable certificate definition file list is stored on a alliance chain; the service provider generates a user downloadable attribute requirement list;
Step 2, initializing user identity: the user generates a main DID, and submits the identity verification information and the main DID to a college DID service manager of a college where the user is located; the university DID service manager checks the identity of the user, and stores the main DID on the alliance chain to enable the main DID to be effective;
Step 3, service required attribute requirement list and verifiable certificate definition file query: when a user needs to use the service of a service provider, downloading an attribute requirement list disclosed by the service provider, and screening all verifiable certificate definition files with part or all of the attribute requirement list from a verifiable certificate definition file list of a college on a alliance chain according to the type of the attribute in the attribute requirement list by the user;
Step 4, application and issuance of a verifiable certificate: the user generates derivative DIDs and submits the derivative DIDs to any university DID service manager, and the derivative DIDs of the user are stored on a alliance chain after the signature is verified by the any university DID service manager; the user sends the derivative DID and the identity verification information to a university DID service manager of the university to which the verifiable certificate definition file belongs; after the identity of the user is verified by a university DID service manager of the university to which the verifiable certificate definition file belongs, issuing a verifiable certificate to a derivative DID submitted by the user, and calculating and updating a hash value of a verifiable certificate accumulator stored on a alliance chain;
Step 5, generating a certification file and acquiring a service: the user processes the verifiable certificate into verifiable certificate claims, forms a certification file from the verifiable certificate claims, and sends the certification file to a service provider; the service provider verifies whether the attribute of the proof file meets the condition, verifies the validity of each verifiable certificate statement through a hash value of a verifiable certificate accumulator on a alliance chain, verifies the correctness of a private key signature of a college DID service manager and a private key signature of a derivative DID corresponding to each verifiable certificate statement through public key information on the alliance chain, and provides the service if the verification passes;
Step 6, the certificate revocation can be verified: when a verifiable certificate needs to be revoked, a university DID service administrator issuing the verifiable certificate revokes the verifiable certificate by modifying the verifiable certificate accumulator and updating the hash value of the verifiable certificate accumulator on the federation chain.
The invention has the beneficial effects that:
The method can effectively provide global identity management for college alliances established based on the alliance chain, and provide privacy protection for different users on the alliance chain, so that identity portraits of the users are prevented from being carried out through data on the alliance chain; meanwhile, mutual authentication among different universities is realized by using the verifiable certificates in a unified format, and the use of the privacy information in the minimum range is realized through selective disclosure.
Drawings
FIG. 1 is a flow chart of a college alliance user identity management method based on blockchain and DID.
Detailed Description
The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is apparent that the described embodiments are only some embodiments of the present invention, not all embodiments of the present invention, and this is not limiting to the present invention. All other embodiments, which can be made by those skilled in the art based on the embodiments of the invention without making any inventive effort, are intended to fall within the scope of the invention.
As shown in FIG. 1, the invention relates to a block chain and DID-based college alliance user identity management method flow chart, which comprises the following steps:
step 1, initializing a system: establishing a coalition chain comprising college identities by a plurality of colleges and universities, and initializing DID identities on the college DID service manager coalition chain; the university DID service manager defines a verifiable certificate definition file list, and the verifiable certificate definition file list is stored on a alliance chain; the service provider generates a user downloadable attribute requirement list;
Step 2, initializing user identity: the user generates a main DID, and submits the identification and the main DID to a college DID service manager of the college where the user is located; the university DID service manager checks the identity of the user, and stores the main DID on the alliance chain to enable the main DID to be effective;
Step 3, service required attribute requirement list and verifiable certificate definition file query: when a user needs to use the service of a service provider, downloading an attribute requirement list disclosed by the service provider, and screening all verifiable certificate definition files with part or all of the attribute requirement list from a verifiable certificate definition file list of a college on a alliance chain according to the type of the attribute in the attribute requirement list by the user;
step 4, application and issuance of a verifiable certificate: the user generates derivative DIDs, submits the derivative DIDs to any university DID service manager, and stores the derivative DIDs of the user on a alliance chain; the user sends the derivative DID and the identity verification information to a college DID service manager; after the identity of the user passes, issuing a verifiable certificate to the derivative DID submitted by the user, and calculating and updating a hash value of a verifiable certificate accumulator stored on a alliance chain;
Step 5, generating a certification file and acquiring a service: the user processes the verifiable certificate into verifiable certificate claims, forms a certification file from the verifiable certificate claims, and sends the certification file to a service provider; the service provider verifies whether the attribute of the certificate meets the condition, verifies the validity of each verifiable certificate statement through the hash value of the verifiable certificate accumulator, verifies the correctness of the signature through public key information on the alliance chain, and provides the service after the verification;
step 6, the certificate revocation can be verified: when a verifiable certificate needs to be revoked, a university DID service administrator issuing the verifiable certificate revokes the verifiable certificate by modifying a verifiable certificate accumulator and updating a verifiable certificate accumulator hash value on a federation chain.
Examples
The invention will be further illustrated with reference to specific examples.
The invention provides a college alliance user identity management method based on block chains and DIDs, which comprises the following steps:
step 1, initializing a system: establishing a coalition chain comprising college identities by a plurality of colleges and universities, and initializing DID identities on the college DID service manager coalition chain; the university DID service manager defines a verifiable certificate definition file list, and the verifiable certificate definition file list is stored on a alliance chain; the service provider generates a user downloadable attribute requirement list;
the step 1 system initialization specifically comprises the following steps:
In the step 1.1 of the method, The colleges and universities provide management nodes to form a college identity alliance chain, each college sets a respective college DID service manager, and records the colleges and universities on the alliance chainDID identity of college DID service managerPublic keyRepresenting the ith university;
In the specific implementation, the college alliance chain is a permitted blockchain, and each alliance member university maintains data in a mode of regularly carrying out consensus on the submitted contents by providing a management node to provide services; after passing the proportional authentication of all universities, the new universities can join the blockchain system by providing synchronous data of the management nodes, wherein the proportion is set by a specific implementation party;
Each university sets a DID service manager of the respective university, is responsible for managing the management node of the university where the university is located, and submits the data to be stored in a uplink mode to the management node.
Step 1.2, college of ithGenerating a first verifiable certificate definition file list by a university DID service managerIndicating the ith collegeIs the 1 st verifiable certificate definition file,Indicating the ith collegeM verifiable certificate definition file, the ith universityThe j-th verifiable certificate definition fileIncluding the ith universityThe j-th verifiable certificate definition filePublic key of (a)And a hash value of the verifiable credential accumulatorFirst verifiable certificate attribute listThe verifiable certificate attribute list includes s elements,A first verifiable certificate attribute representing a first list of verifiable certificate attributes,The ith verifiable certificate attribute representing the first list of verifiable certificate attributes is used to define all files in the list of files using the ith university respectivelyPrivate key of (a)Storing the signature in a alliance chain;
The specific process of initializing the certificate definition file in the step 1.2 is as follows:
Colleges and universities of ith The DID service manager of the university defines a class of certificates, such as student certificates or achievement sheets, and the like in specific implementation;
Colleges and universities of ith The university DID service manager is the ith universityThe j-th verifiable certificate definition fileLocally maintaining verifiable certificate accumulatorAnd initialized to random large prime numbers=Thereafter, a hash value of the verifiable certificate accumulator is calculatedAnd stored on a coalition chain;
Wherein one of the certificate definition files may be verified The verifiable certificate definition files are respectively usedPrivate key of (a)And (5) after signing, storing the uplink.
Step 1.3, service providerGenerating a user downloadable attribute requirement listThere are h key-value pairs in the list,The 1 st attribute is indicated as such,Representing satisfaction attributesIs used for the attribute value space of (a),Representing the h-th attribute of the set,Representing satisfaction attributesIs a property value space of (a).
In the specific implementation, the service provider can provide services similar to cross-school class selection, venue reservation, book and other resource sharing, and the services can be provided only after the identity of the user is authenticated; for required attributes, the service providerGenerating a user downloadable attribute requirement listIn a specific implementation, for example, in a cross-school selection class, the attribute requirement list may be { colleges } { school A student certificate, school B student certificate }, total score } { good }, pre-repair course { course C, course D }, and the service provider may be toPublished on self-built web pages.
Step 2, initializing user identity: the user generates a main DID, and submits the identity verification information and the main DID to a college DID service manager of a college where the user is located; the university DID service manager checks the identity of the user, and stores the main DID on the alliance chain to enable the main DID to be effective;
the step 2 specifically comprises the following steps:
Step 2.1, college of ith T th user of (2)Generating a primary DID identityPublic and private key pair for userThe user will master DID identityUser public keyThe identity verification information is sent to the ith universityA university DID service administrator of (a) requesting completion of main DID initialization;
Step 2.2, college of ith After receiving the main DID initialization request of the user, the university DID service manager of (1) verifies the ith universityT th user of (2)Will beStored on a alliance chain to enable the ith universityT th user of (2)Is validated by the primary DID of (a),Representative of use of the ith universityPrivate key of (a)For the first hash valueAnd signing.
In a specific implementation the authentication information of the user is defined by the respective university.
Step 3, service required attribute requirement list and verifiable certificate definition file query: when a user needs to use the service of a service provider, downloading an attribute requirement list disclosed by the service provider, and screening all verifiable certificate definition files with part or all of the attribute requirement list from a verifiable certificate definition file list of a college on a alliance chain according to the type of the attribute in the attribute requirement list by the user;
the step3 specifically comprises the following steps:
Step 3.1, ith university T th user of (2)Requiring use of service providersDownloading a list of published attribute requirements while providing a service
Step 3.2, college of ithT th user of (2)Determining a second list in a verifiable certificate definition file list of a college according to the type of the attribute in the attribute requirement listMaking the second list satisfyRepresenting the first verifiable certificate definition file stored in the federation chain at the nth university, containing a second list of verifiable certificate attributesThe list has q elements, and,Representing the first verifiable certificate attribute of the second list of verifiable certificate attributes,The q-th verifiable certificate attribute representing the second list of verifiable certificate attributes.
Step 4, application and issuance of a verifiable certificate: the user generates derivative DIDs and submits the derivative DIDs to any university DID service manager, and the derivative DIDs of the user are stored on a alliance chain after the signature is verified by the any university DID service manager; the user sends the derivative DID and the identity verification information to a university DID service manager of the university to which the verifiable certificate definition file belongs; after the identity of the user is verified by a university DID service manager of the university to which the verifiable certificate definition file belongs, issuing a verifiable certificate to a derivative DID submitted by the user, and calculating and updating a hash value of a verifiable certificate accumulator stored on a alliance chain;
step4 specifically comprises the following steps:
Step 4.1, college of ith T th user of (2)Generating the (u) th derivativePublic and private key pairWill derive DID registration requestSend to any universityIs a university DID service manager;
Step 4.2, any one of the universities Receiving the derived DID registration request by the DID service manager of the university of (A), and checking the signatureAfter being effective, use colleges and universitiesDID identity of a university DID service manager of (3)Corresponding private keyFor the second hash valueSigning and will beStoring in a alliance chain to enable the ith universityT th user of (2)Is the (u) th derivative of (2)Take effect;
Step 4.3, college of ith T th user of (2)Derivative the (u)Colleges and universities of iThe j-th verifiable certificate definition fileThe identity verification information is sent to the ith universityDID service manager of universities, apply for j-th verifiable certificate issued by i-th university
The authentication information in the system needs to be accompanied with authentication information in the physical world at the initial stage of the system, and the user can prove the identity through the authentication certificates when the number of the authentication certificates owned by the user is enough.
Step 4.4, college of ithThe university DID service manager is the ith universityT th user of (2)According to the ith universityThe j-th verifiable certificate definition fileList of verifiable certificate attributesFilling in corresponding attribute values to generate a large prime numberAs a serial number to a verifiable certificate accumulatorIn calculating and updating hash values of verifiable certificate accumulators on a federation chainCombining the attribute value and the serial number into a j-th verifiable certificate issued by the i-th universityAnd send to the ith universityT th user of (2)
Colleges and universities of ithThe university DID service manager is the ith universityT th user of (2)Filling out plaintext attribute values and salt values according to a first verifiable certificate attribute listFirst verifiable certificate attribute for first verifiable certificate attribute listIs used to determine the value of the plaintext attribute,Is the first verifiable certificate attribute for the first list of verifiable certificate attributesPlaintext attribute values of (2)The generated random number salt value is used for generating a random number,The s-th verifiable certificate attribute for the first list of verifiable certificate attributesIs used to determine the value of the plaintext attribute,Is the s-th verifiable certificate attribute for the first list of verifiable certificate attributesPlaintext attribute values of (2)The generated random number salt value and generate a hash value list for the plaintext attribute value of the first verifiable certificate attribute listWherein the first hash value in the hash value listThe s-th hash value in the hash value list; Generating a large prime numberAs a serial number to a verifiable certificate accumulatorIn calculating and updating hash values of verifiable certificate accumulators on a federation chainVerifiable certificate to be generatedSend to the ith universityT th user of (2)
Updating the verifiable credential accumulator valueCalculating and updating hash values of verifiable certificate accumulators on a chain
Step 5, generating a certification file and acquiring a service: the user processes the verifiable certificate into verifiable certificate claims, forms a certification file from the verifiable certificate claims, and sends the certification file to a service provider; the service provider verifies whether the attribute of the proof file meets the condition, verifies the validity of each verifiable certificate statement through a hash value of a verifiable certificate accumulator on a alliance chain, verifies the correctness of a private key signature of a college DID service manager and a private key signature of a derivative DID corresponding to each verifiable certificate statement through public key information on the alliance chain, and provides the service if the verification passes;
step5 specifically comprises the following steps:
Step 5.1, college of ith T th user of (2)Obtain and second listMatched verifiable certificateRepresenting a first type verifiable certificate issued by an nth university, and after verifying that a signature is valid, including the verifiable certificate in an attribute requirement listThe attribute values of (2) are displayed in a plaintext, and the other attribute values are displayed in a plaintext hash value to become verifiable certificate declaration files, and the verifiable certificate declaration files are signed by using private keys corresponding to derived DIDs when the verifiable certificates are requested respectively, so that the verification files are combined to form the certification filesSent to the service provider
The specific steps of the step 5.1 are as follows:
Colleges and universities of ith T th user of (2)Obtain and second listMatched verifiable certificateRepresenting a first type verifiable certificate issued by an nth university, and after verifying that a signature is valid, including the verifiable certificate in an attribute requirement listThe attribute values of (2) are presented in plain text, and the other attribute values are presented in hash value, so that the list of verifiable certificate statement is formedRepresents the j-th verifiable certificate issued by the ith university after hash value processingExpress hashed value processed nth college issued type I verifiable certificateThe private key of the u-th derivative DID when requesting a verifiable certificate is used in turn… …, The e-th derivative private keySignature combination into a certificateThe certificate is subjected toSent to the service provider
Step 5.2, service providerReceipt of a certificateThereafter, it is checked whether the attributes and attribute values satisfy the attribute requirement listFor each verifiable certificate statement file in the certificate file, checking the validity of the verifiable certificate statement through the verifiable certificate accumulator information, verifying the correctness of the private key signature of the university DID service manager and the private key signature of the derivative DID corresponding to each verifiable certificate statement through the public key information on the alliance chain, and providing service after the verification.
The specific steps of the step 5.2 are as follows:
Service provider Receiving the saidVerify whether or not to meetAll the required attributes of the attributes, wherein the attribute values of the attributes belong to an attribute value space of the attributes;
service provider verifies j-th type verifiable certificate issued by i-th university In the validity, from colleges and universitiesObtaining verifiable certificate accumulator values at a university DID service managerCalculating and comparing the hash value with the hash value stored on the federation chain, and verifying the certificate accumulator if the hash value is consistentClass j verifiable certificate issued by the university of modulo iWhether the value of the serial number Q in the colleges is 0, if 0, the colleges and universities of the ithThe j-th verifiable certificateThe effect is achieved;
And verifying whether the private key signature of the college DID service manager and the private key signature of the derivative DID corresponding to each verifiable certificate statement are correct or not through public key information on a alliance chain, and providing service if the verification passes.
Step 6, the certificate revocation can be verified: when a verifiable certificate needs to be revoked, a university DID service administrator issuing the verifiable certificate revokes the verifiable certificate by modifying the verifiable certificate accumulator and updating the hash value of the verifiable certificate accumulator on the federation chain.
The specific steps of the step6 are as follows:
Verifiable certificate Beyond the validity period or due to failure, it is necessary for the university to be issued by a certificateDID service manager of universities to perform verifiable certificate accumulator updatesThereafter, a hash value of a verifiable certificate accumulator stored on the federation chain is calculated and updated
It is noted that what is not described in detail in the embodiments of the present invention belongs to the prior art known to those skilled in the art.
In summary, the method provided by the embodiment of the invention has the following advantages:
1) Trusted and non-tamperable storage of identity information: the college alliance user identity system is realized by means of the block chain technology, so that the resource intercommunication and information mutual recognition between colleges and universities can be effectively promoted, and the credibility and safety of information sharing between the colleges and universities are ensured by means of the characteristic that the block chain is not tamperable;
2) Across-facility global identity management: the DID and verifiable certificate technologies are adopted, so that identity management across different institutions is realized, and the decentralization and the high efficiency of identity verification and information sharing are realized; the user can realize identity verification and information sharing in different institutions and application scenes only by possessing a DID identifier and some verifiable certificates;
3) Information association protection on federation chain: adopting a derived DID technology to resist malicious users from portraying the users through the identities on the alliance chains, so that the identities on the alliance chains of the users are not associated with the identities on other alliance chains;
4) Privacy protection in certificate usage: using a hash function based attribute processing method ensures that a minimum range of certificate contents is used when generating a certificate.
In addition, it will be understood by those skilled in the art that all or part of the steps in implementing the methods of the above embodiments may be implemented by a program to instruct related hardware, and the corresponding program may be stored in a computer readable storage medium, where the storage medium may be a read only memory, a magnetic disk or an optical disk, etc.
The foregoing is only a preferred embodiment of the present invention, but the scope of the present invention is not limited thereto, and any changes or substitutions easily contemplated by those skilled in the art within the scope of the present invention should be included in the scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims. The information disclosed in the background section herein is only for enhancement of understanding of the general background of the invention and is not to be taken as an admission or any form of suggestion that this information forms the prior art already known to those of ordinary skill in the art.

Claims (9)

1.一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述方法包括如下步骤:1. A method for managing university alliance user identities based on blockchain and DID, characterized in that the method comprises the following steps: 步骤1、系统初始化:多所高校建立包括高校身份的联盟链,初始化高校DID服务管理员联盟链上DID身份;高校DID服务管理员定义可验证证书定义文件列表,将可验证证书定义文件列表存储在联盟链上;服务提供方生成用户可下载的属性需求列表;Step 1: System initialization: Multiple universities establish a consortium chain including university identities, and initialize the DID identity of the university DID service administrator on the consortium chain; the university DID service administrator defines a list of verifiable certificate definition files and stores the list of verifiable certificate definition files on the consortium chain; the service provider generates a list of attribute requirements that users can download; 步骤2、用户身份初始化:用户生成主DID,将身份验证信息和主DID提交给用户所在高校的高校DID服务管理员;高校DID服务管理员审核用户身份,将主DID存储在联盟链上,使主DID生效;Step 2: User identity initialization: The user generates a primary DID and submits the identity authentication information and primary DID to the university DID service administrator of the user’s university. The university DID service administrator reviews the user’s identity and stores the primary DID on the consortium chain, making the primary DID effective. 步骤3、服务所需属性需求列表及可验证证书定义文件查询:用户需要使用服务提供方的服务时,下载服务提供方公开的属性需求列表,用户依据所述属性需求列表中属性的类型在联盟链上高校的可验证证书定义文件列表中筛选具有属性需求列表部分或全部属性的所有可验证证书定义文件;Step 3. Query the attribute requirement list and verifiable certificate definition file required for the service: When the user needs to use the service of the service provider, the user downloads the attribute requirement list published by the service provider. The user selects all verifiable certificate definition files with some or all attributes in the attribute requirement list from the verifiable certificate definition file list of universities on the alliance chain according to the type of attributes in the attribute requirement list; 步骤4、可验证证书申请和颁发:用户生成派生DID,将其提交给任意高校DID服务管理员,所述任意高校DID服务管理员验证签名后将用户的派生DID存储在联盟链上;用户将该派生DID和身份验证信息发送给所述可验证证书定义文件所属高校的高校DID服务管理员;所述可验证证书定义文件所属高校的高校DID服务管理员对用户的身份验证通过后,向用户提交的派生DID颁发可验证证书,计算并更新存储在联盟链上的可验证证书累加器的散列值;Step 4, application and issuance of verifiable certificates: the user generates a derived DID and submits it to any university DID service administrator, who verifies the signature and stores the derived DID of the user on the alliance chain; the user sends the derived DID and identity authentication information to the university DID service administrator of the university to which the verifiable certificate definition file belongs; after the university DID service administrator of the university to which the verifiable certificate definition file belongs passes the user's identity authentication, the verifiable certificate is issued to the derived DID submitted by the user, and the hash value of the verifiable certificate accumulator stored on the alliance chain is calculated and updated; 步骤5、证明文件生成和服务获取:用户将可验证证书处理为可验证证书声明,将所述可验证证书声明组成证明文件,并发送给服务提供方;服务提供方验证证明文件属性是否满足条件,通过联盟链上可验证证书累加器的散列值验证每个可验证证书声明的有效性,通过联盟链上公钥信息验证每个可验证证书声明对应的高校DID服务管理员的私钥签名和派生DID的私钥签名的正确性,均验证通过则提供服务;Step 5, certification document generation and service acquisition: the user processes the verifiable certificate into a verifiable certificate statement, forms the verifiable certificate statement into a certification document, and sends it to the service provider; the service provider verifies whether the certification document attributes meet the conditions, verifies the validity of each verifiable certificate statement through the hash value of the verifiable certificate accumulator on the alliance chain, and verifies the correctness of the private key signature of the university DID service administrator and the derived DID private key signature corresponding to each verifiable certificate statement through the public key information on the alliance chain. If all are verified, the service is provided; 步骤6、可验证证书撤销:可验证证书需要被撤销时,颁发所述可验证证书的高校DID服务管理员通过修改可验证证书累加器并更新联盟链上可验证证书累加器的散列值来撤销可验证证书。Step 6, revocation of verifiable certificate: When the verifiable certificate needs to be revoked, the DID service administrator of the university that issued the verifiable certificate revokes the verifiable certificate by modifying the verifiable certificate accumulator and updating the hash value of the verifiable certificate accumulator on the alliance chain. 2.根据权利要求1所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述步骤1包括:2. According to a method for managing university alliance user identity based on blockchain and DID according to claim 1, it is characterized in that step 1 comprises: 步骤1.1,所高校提供管理节点共同构成高校身份联盟链,每所高校设置各自的高校DID服务管理员,联盟链上记录所述所高校DID服务管理员的DID身份及公钥代表第i所高校;Step 1.1, The universities provide management nodes to form a university identity alliance chain. Each university sets up its own university DID service administrator. The alliance chain records the DID identity of the university's DID service administrator and public key , represents the i-th university; 步骤1.2,第i所高校的高校DID服务管理员生成第一可验证证书定义文件列表表示第i所高校的第1张可验证证书定义文件,表示第i所高校的第m张可验证证书定义文件,第i所高校的第j张可验证证书定义文件包含第i所高校的第j张可验证证书定义文件的公钥和可验证证书累加器的散列值,第一可验证证书属性列表,该可验证证书属性列表包括s个元素,代表第一可验证证书属性列表的第一个可验证证书属性,代表第一可验证证书属性列表的第s个可验证证书属性,将所述可验证证书定义文件列表中的所有文件分别使用第i所高校的私钥签名后上联盟链存储;Step 1.2, the i-th university The university DID service administrator generates the first verifiable certificate definition file list , represents the i-th university The first verifiable certificate definition file, represents the i-th university The mth verifiable certificate definition file, the i-th university The j-th verifiable certificate definition file Includes the i-th university The j-th verifiable certificate definition file The public key and the hash value of the verifiable certificate accumulator , the first verifiable certificate attribute list , the verifiable certificate attribute list includes s elements, represents the first verifiable credential attribute of the first verifiable credential attribute list, Represents the sth verifiable certificate attribute in the first verifiable certificate attribute list, and uses the i-th university Private key After signing, it is stored on the alliance chain; 步骤1.3,服务提供方生成用户可下载的属性需求列表,该属性需求列表中有h个键值对,表示第1个属性,表示满足属性的属性值空间,表示第h个属性,表示满足属性的属性值空间。Step 1.3, Service Provider Generate a user-downloadable list of property requirements , this attribute requires that there are h key-value pairs in the list, Indicates the first attribute, Indicates that the property is satisfied The attribute value space of represents the hth attribute, Indicates that the property is satisfied The attribute value space. 3.根据权利要求1所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述步骤2包括:3. According to a method for managing university alliance user identity based on blockchain and DID according to claim 1, it is characterized in that step 2 comprises: 步骤2.1,第i所高校的第t个用户生成主DID身份、用户公私钥对,用户将主DID身份,用户公钥,身份验证信息发送给第i所高校的高校DID服务管理员,请求完成主DID初始化;Step 2.1, the i-th university The tth user Generate a primary DID identity 、User public and private key pair , the user will use the primary DID identity , user public key , the identity verification information is sent to the i-th university The university DID service administrator requests to complete the primary DID initialization; 步骤2.2,第i所高校的高校DID服务管理员接收用户的主DID初始化请求后,验证第i所高校的第t个用户的身份验证信息,将存储在联盟链上,使第i所高校的第t个用户的主DID生效,代表使用第i所高校的私钥对第一散列值进行签名。Step 2.2, the i-th university After receiving the user's primary DID initialization request, the university DID service administrator verifies the i-th university The tth user The authentication information will be Stored on the alliance chain, the i-th university The tth user The primary DID takes effect. Represents the use of the i-th university Private key For the first hash value Sign. 4.根据权利要求1所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述步骤3包括:4. According to a method for managing university alliance user identity based on blockchain and DID according to claim 1, it is characterized in that step 3 comprises: 步骤3.1,第i所高校的第t个用户需要使用服务提供方提供的服务时,下载公开的属性需求列表Step 3.1, the i-th university The tth user Need to use a service provider When providing services, download the public property requirement list ; 步骤3.2,第i所高校的第t个用户依据所述属性需求列表中属性的类型在高校的可验证证书定义文件列表中确定第二列表,使所述第二列表满足表示第n个高校上联盟链存储的第l张可验证证书定义文件,含有第二可验证证书属性列表,该列表有q个元素,代表第二可验证证书属性列表的第一个可验证证书属性,代表第二可验证证书属性列表的第q个可验证证书属性。Step 3.2, the i-th university The tth user Determine a second list in the university's verifiable certificate definition file list based on the type of attribute in the attribute requirement list , so that the second list satisfies , Indicates the definition file of the first verifiable certificate stored on the alliance chain of the nth university, which contains the attribute list of the second verifiable certificate , the list has q elements, a first verifiable credential attribute representing a second list of verifiable credential attributes, Represents the qth verifiable credential attribute of the second verifiable credential attribute list. 5.根据权利要求1所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述步骤4包括:5. According to a method for managing university alliance user identity based on blockchain and DID according to claim 1, it is characterized in that step 4 comprises: 步骤4.1,第i所高校的第t个用户生成第u个派生DID、公私钥对,将派生DID注册请求发送给任意一所高校的高校DID服务管理员;Step 4.1, the i-th university The tth user Generate the uth derived DID , public and private key pairs , will derive the DID registration request Send to any university DID service administrators of colleges and universities; 步骤4.2,任意一所高校的高校DID服务管理员收到派生DID注册请求,校验签名有效后,使用第p所高校的高校DID服务管理员的DID身份对应的私钥对第二散列值进行签名,将上联盟链存储,使第i所高校的第t个用户的第u个派生DID生效;Step 4.2, any university The university DID service administrator receives the derived DID registration request and verifies the signature After it is effective, use the pth college DID identity of the university DID service administrator The corresponding private key For the second hash value Sign it and On the alliance chain storage, the i-th university The tth user The u-th derived DID come into force; 步骤4.3,第i所高校的第t个用户将第u个派生DID,第i所高校的第j张可验证证书定义文件,身份验证信息,发送给第i所高校的高校DID服务管理员,申请第i所高校颁发的第j类可验证证书Step 4.3, the i-th university The tth user The u-th derived DID , the i-th university The j-th verifiable certificate definition file , identity verification information, sent to the i-th university The university DID service administrator applies for the jth type of verifiable certificate issued by the i-th university ; 步骤4.4,第i所高校的高校DID服务管理员为第i所高校的第t个用户按照第i所高校的第j张可验证证书定义文件中第一可验证证书属性列表填写对应属性值,生成一个大素数作为序列号,添加到可验证证书累加器中,计算并更新联盟链上可验证证书累加器的散列值,将属性值和序列号组合成为第i所高校颁发的第j类可验证证书并发送给第i所高校的第t个用户Step 4.4, the i-th university The college DID service administrator is the i-th college The tth user According to the i-th university The j-th verifiable certificate definition file First Verifiable Certificate Attribute List Fill in the corresponding attribute value to generate a large prime number As a serial number, added to the verifiable certificate accumulator Calculate and update the hash value of the verifiable certificate accumulator on the consortium chain , combining the attribute value and the serial number into the jth type of verifiable certificate issued by the i-th university And send it to the i-th university The tth user . 6.根据权利要求1所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述步骤5包括:6. According to a method for managing university alliance user identity based on blockchain and DID according to claim 1, it is characterized in that step 5 comprises: 步骤5.1,第i所高校的第t个用户获得与第二列表匹配的可验证证书表示第n所高校颁发的第l类可验证证书,校验签名有效后,将可验证证书中包含于属性需求列表的属性值以明文展示,其他以明文的散列值展示,成为可验证证书声明文件,分别使用请求可验证证书时的派生DID所对应的私钥对可验证证书声明文件签名,组合成为证明文件发送给服务提供方Step 5.1, the i-th university The tth user Get the second list with Matching verifiable certificates , Indicates the lth type of verifiable certificate issued by the nth university. After verifying the validity of the signature, the verifiable certificate is included in the attribute requirement list The attribute values of the DID are displayed in plain text, and the others are displayed in plain text hash values, which become a verifiable certificate declaration file. The verifiable certificate declaration file is signed using the private key corresponding to the derived DID when requesting the verifiable certificate, and the combination becomes a certification file. Send to service provider ; 步骤5.2,服务提供方接收到证明文件后,检查属性和属性值是否满足属性需求列表,对于证明文件中的每张可验证证书声明文件,分别通过可验证证书累加器信息检查可验证证书声明的有效性,通过联盟链上公钥信息验证每个可验证证书声明对应的高校DID服务管理员的私钥签名和派生DID的私钥签名的正确性,均验证通过则提供服务。Step 5.2, Service Provider Receive supporting documents Finally, check whether the attributes and attribute values meet the attribute requirement list For each verifiable certificate declaration file in the certification document, the validity of the verifiable certificate declaration is checked through the verifiable certificate accumulator information, and the correctness of the private key signature of the university DID service administrator and the derived DID corresponding to each verifiable certificate declaration is verified through the public key information on the alliance chain. If all are verified, the service is provided. 7.根据权利要求2所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述可验证证书累加器工作的具体步骤为:7. According to a method for managing university alliance user identity based on blockchain and DID in claim 2, it is characterized in that the specific steps of the verifiable certificate accumulator are: 第i所高校的高校DID服务管理员为第i所高校的第j张可验证证书定义文件在本地维护可验证证书累加器,并初始化为随机的大素数=,之后计算可验证证书累加器的散列值,并存储在联盟链上;The i-th university The college DID service administrator is the i-th college The j-th verifiable certificate definition file Maintaining a local accumulator of verifiable certificates , and initialized to a random large prime number = , then calculate the hash value of the verifiable certificate accumulator , and stored on the alliance chain; 第i所高校的高校DID服务管理员生成第j类可验证证书后,随机生成一个大素数作为序列号,可验证证书累加器值更新=,之后计算并更新联盟链上存储的可验证证书累加器的散列值The i-th university The university DID service administrator generates a class j verifiable certificate Then, randomly generate a large prime number As a serial number, it can verify the certificate accumulator value update = , then calculate and update the hash value of the verifiable certificate accumulator stored on the consortium chain ; 当第i所高校颁发的第j类可验证证书被撤销时,执行可验证证书累加器更新=,之后计算并更新联盟链上存储的可验证证书累加器的散列值When the jth type of verifiable certificate issued by the i-th university When revoked, perform a verifiable certificate accumulator update = , then calculate and update the hash value of the verifiable certificate accumulator stored on the consortium chain ; 系统中任意实体验证第i所高校颁发的第j类可验证证书有效性时,从高校的高校DID服务管理员处获取可验证证书累加器值,计算散列值并和存储在联盟链上的散列值进行对比,一致则验证可验证证书累加器模第i所高校颁发的第j类可验证证书中的序列号Q的值是否为0,若为0,则该第i所高校颁发的第j类可验证证书有效。Any entity in the system verifies the jth type of verifiable certificate issued by the i-th university Validity, from colleges and universities Get the verifiable certificate accumulator value from the university DID service administrator , calculate the hash value and compare it with the hash value stored on the consortium chain, and verify the verifiable certificate accumulator if they are consistent Model: Verifiable certificate of type j issued by the i-th university Is the value of the serial number Q in 0? If it is 0, then the i-th university Issued a verifiable certificate of type j efficient. 8.根据权利要求5所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述可验证证书生成的具体步骤为:8. According to a method for managing university alliance user identity based on blockchain and DID according to claim 5, it is characterized in that the specific steps of generating the verifiable certificate are: 第i所高校的高校DID服务管理员为第i所高校的第t个用户按照第一可验证证书属性列表填写明文属性值和盐值为第一可验证证书属性列表第一个可验证证书属性的明文属性值,是为第一可验证证书属性列表第一个可验证证书属性的明文属性值生成的随机数盐值,为第一可验证证书属性列表第s个可验证证书属性的明文属性值,是为第一可验证证书属性列表第s个可验证证书属性的明文属性值生成的随机数盐值,并为该第一可验证证书属性列表的明文属性值生成散列值列表,其中,散列值列表中的第一个散列值,散列值列表中的第s个散列值;生成一个大素数作为序列号,添加到可验证证书累加器中,计算并更新联盟链上的可验证证书累加器的散列值,将生成的可验证证书发送给第i所高校的第t个用户The i-th university The college DID service administrator is the i-th college The tth user Fill in the plaintext attribute value and salt value according to the first verifiable certificate attribute list , The first verifiable certificate attribute in the first verifiable certificate attribute list The plaintext attribute value of Is the first verifiable certificate attribute in the first verifiable certificate attribute list The plaintext attribute value of The generated random salt value, The sth verifiable certificate attribute in the first verifiable certificate attribute list The plaintext attribute value of is the sth verifiable certificate attribute in the first verifiable certificate attribute list The plaintext attribute value of The generated random salt value is used to generate a hash value list for the plaintext attribute value of the first verifiable certificate attribute list. , where the first hash value in the hash value list , the sth hash value in the hash value list ; Generate a large prime number As a serial number, added to the verifiable certificate accumulator Calculate and update the hash value of the verifiable certificate accumulator on the consortium chain , the generated verifiable certificate Send to the i-th university The tth user . 9.根据权利要求6所述的一种基于区块链和DID的高校联盟用户身份管理方法,其特征在于,所述证明文件形成的具体步骤为:9. According to a method for managing university alliance user identities based on blockchain and DID according to claim 6, it is characterized in that the certification document The specific steps of formation are: 第i所高校的第t个用户获得与第二列表匹配的可验证证书,并校验签名有效后,将可验证证书中包含于属性需求列表的属性值以明文展示,其他以明文的散列值展示,成为可验证证书声明列表表示散列值处理后的第i所高校颁发的第j类可验证证书表述散列值处理后的第n所高校颁发的第l类可验证证书,依次使用请求可验证证书时的第u个派生DID的私钥,……,第e个派生的私钥签名组合成证明文件,将所述证明文件发送给服务提供方The i-th university The tth user Get the second list with Matching verifiable certificates , and after verifying that the signature is valid, the verifiable certificate is included in the attribute requirement list The attribute values of are displayed in plain text, and the others are displayed as hash values of plain text, forming a list of verifiable certificate declarations. , Represents the jth type of verifiable certificate issued by the i-th university after hash value processing , Describes the lth type of verifiable certificate issued by the nth university after hash value processing , using the private key of the u-th derived DID when requesting a verifiable certificate , ..., the e-th derived private key Signatures combined into a certification document , the certification documents Send to service provider .
CN202410806278.1A 2024-06-21 2024-06-21 College alliance user identity management method based on blockchain and DID Active CN118381663B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202410806278.1A CN118381663B (en) 2024-06-21 2024-06-21 College alliance user identity management method based on blockchain and DID

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202410806278.1A CN118381663B (en) 2024-06-21 2024-06-21 College alliance user identity management method based on blockchain and DID

Publications (2)

Publication Number Publication Date
CN118381663A CN118381663A (en) 2024-07-23
CN118381663B true CN118381663B (en) 2024-08-23

Family

ID=91902137

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202410806278.1A Active CN118381663B (en) 2024-06-21 2024-06-21 College alliance user identity management method based on blockchain and DID

Country Status (1)

Country Link
CN (1) CN118381663B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN119402198B (en) * 2024-08-28 2025-12-16 北京理工大学 Distributed identity hierarchical storage and trusted authentication method based on verifiable computation

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112073479A (en) * 2020-08-26 2020-12-11 重庆邮电大学 Method and system for controlling de-centering data access based on block chain
CN115485682A (en) * 2020-04-28 2022-12-16 微软技术许可有限责任公司 Derived child verifiable certificate with optional claims

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11769577B1 (en) * 2020-01-15 2023-09-26 Ledgerdomain Inc. Decentralized identity authentication framework for distributed data
CN116391378A (en) * 2020-11-06 2023-07-04 联想(新加坡)私人有限公司 Subscription Onboarding Using Verified Digital IDs
KR20230064354A (en) * 2021-11-03 2023-05-10 펜타시큐리티시스템 주식회사 Blockchain-based authentication audit data sharing and integrity verification system, device and method thereof
WO2023095967A1 (en) * 2021-11-29 2023-06-01 주식회사 블록체인기술연구소 Remote-interaction large document access system in which blockchain-based did service, ipfs-based data sharing technology and private key distributed storage technology are combined
CN116566705A (en) * 2023-05-24 2023-08-08 北京泰尔英福科技有限公司 Authentication method, system, client and server based on key derivation function

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115485682A (en) * 2020-04-28 2022-12-16 微软技术许可有限责任公司 Derived child verifiable certificate with optional claims
CN112073479A (en) * 2020-08-26 2020-12-11 重庆邮电大学 Method and system for controlling de-centering data access based on block chain

Also Published As

Publication number Publication date
CN118381663A (en) 2024-07-23

Similar Documents

Publication Publication Date Title
Das et al. A secure blockchain-enabled vehicle identity management framework for intelligent transportation systems
Abraham et al. Revocable and offline-verifiable self-sovereign identities
AU2017225928A1 (en) Systems and methods for distributed data sharing with asynchronous third-party attestation
CN111881483B (en) Resource account binding methods, devices, equipment and media based on blockchain
Brunner et al. SPROOF: A Platform for Issuing and Verifying Documents in a Public Blockchain.
CN106992988B (en) A cross-domain anonymous resource sharing platform and its implementation method
Chandra et al. Novel blockchain-based framework to publish, verify, and store digital academic credentials of universities
KR102460299B1 (en) Anonymous credential authentication system and method thereof
CN110855445B (en) Block chain-based certificate management method and device and storage equipment
Abraham et al. Privacy-preserving eID derivation for self-sovereign identity systems
CN114930770B (en) Voucher authentication method and system based on distributed ledger
CN114944937B (en) Distributed digital identity verification method, system, electronic equipment and storage medium
CN115688191A (en) Block chain-based electronic signature system and method
US12463822B2 (en) Sharing security settings between entities using verifiable credentials
CN117280346A (en) Methods and apparatus for generating, providing and forwarding trusted electronic data sets or certificates based on electronic files associated with users
Mukta et al. Credtrust: Credential based issuer management for trust in self-sovereign identity
CN115412253B (en) Digital certificate preparation method based on blockchain technology
Abraham et al. Privacy-preserving eID derivation to self-sovereign identity systems with offline revocation
Garg Blockchain ecosystem for education and employment verification
Cheng et al. A permissioned blockchain-based platform for education certificate verification
CN118381663B (en) College alliance user identity management method based on blockchain and DID
Lohar et al. A Self-Sovereign Identity Framework for Context-Aware De-Centralized Identifier Creation and Credential Verification
Chiliveri et al. ProveDoc: A blockchain based proof of existence with proof of storage
CN119561696B (en) A trusted identity authentication method for academic participants based on blockchain-verifiable credentials
Namazi et al. zkFaith: Soonami's Zero-Knowledge Identity Protocol

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant