CN118381663B - College alliance user identity management method based on blockchain and DID - Google Patents
College alliance user identity management method based on blockchain and DID Download PDFInfo
- Publication number
- CN118381663B CN118381663B CN202410806278.1A CN202410806278A CN118381663B CN 118381663 B CN118381663 B CN 118381663B CN 202410806278 A CN202410806278 A CN 202410806278A CN 118381663 B CN118381663 B CN 118381663B
- Authority
- CN
- China
- Prior art keywords
- university
- verifiable certificate
- verifiable
- attribute
- user
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/10—Services
- G06Q50/20—Education
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3268—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/50—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Business, Economics & Management (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Tourism & Hospitality (AREA)
- Primary Health Care (AREA)
- Theoretical Computer Science (AREA)
- Human Resources & Organizations (AREA)
- Marketing (AREA)
- Economics (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Educational Technology (AREA)
- Educational Administration (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
The invention discloses a college alliance user identity management method based on a block chain and a DID, and belongs to the technical field of block chain application. The method comprises the steps that multiple universities form an identity alliance chain, and the identity alliance chain is used for maintaining DID identities of all users; universities prove that users possess certain attributes by issuing verifiable certificates to users; when the user needs to use the service of some service provider, the user can prove to have corresponding attribute by combining a plurality of verifiable certificates; wherein the user uses different derived DID when applying for different verifiable certificates. The method can effectively provide global identity management for college alliances established based on alliance chains, and realize identity authentication and fine-granularity service authorization based on verifiable certificates.
Description
Technical Field
The invention belongs to the technical field of block chain application, and particularly relates to a college alliance user identity management method based on block chains and DIDs.
Background
With the development of the Internet and digital technology, the role of the identity authentication technology becomes more important, so that the data security and privacy of individuals and organizations can be protected; meanwhile, resource intercommunication and information mutual recognition are important trends of development in the digital age, and can promote collaborative development and cooperation among industries. Under the scene of universities, identity authentication and resource intercommunication are more important, personal information and privacy of students and teachers can be protected, and collaborative development and resource sharing between universities are promoted. Therefore, the method has important practical value and strategic value for promoting college identity authentication and resource intercommunication.
The currently popular centralized identity authentication system has some defects, and the user has high dependence on an authentication mechanism or a service provider, which means that the user cannot control own identity information and cannot autonomously select the authentication mechanism or the service provider; the centralized architecture relies on a single authentication server or third party service provider, so that the entire system will be impacted once a single point of failure occurs; individuals build repeated but not identical identity data in different systems to form individual data islands; while the mechanism has the problem of opaque use of the data. One feasible method is to introduce a blockchain and decentralizing identity management method to realize identity authentication and information intercommunication in a college scene. The method can solve the problems of the dependency of the organization and the data island of the authentication of the central avatar, and the university can realize the inter-organization identity management and the data intercommunication, so that the complexity of resource service and the requirement of the organization intercommunication are improved, but the method has the risk of revealing the privacy information of the user, namely, a malicious attacker portrays the user through the public information on a alliance chain, and infringes the privacy of the user. The private information of the user can be protected by using the method of deriving the DID, but the related art lacks a corresponding solution.
Disclosure of Invention
In order to solve the technical problems, the invention provides a college alliance user identity management method based on block chains and DIDs, which can effectively provide global identity management for college alliances established based on the alliance chains, realize identity authentication and fine-granularity service authorization based on verifiable certificates, and provide privacy protection, user self-right and user-friendly decentralization avatar management schemes for users in the college alliances.
In order to achieve the above purpose, the technical scheme adopted by the invention is as follows:
step 1, initializing a system: establishing a coalition chain comprising college identities by a plurality of colleges and universities, and initializing DID identities on the college DID service manager coalition chain; the university DID service manager defines a verifiable certificate definition file list, and the verifiable certificate definition file list is stored on a alliance chain; the service provider generates a user downloadable attribute requirement list;
Step 2, initializing user identity: the user generates a main DID, and submits the identity verification information and the main DID to a college DID service manager of a college where the user is located; the university DID service manager checks the identity of the user, and stores the main DID on the alliance chain to enable the main DID to be effective;
Step 3, service required attribute requirement list and verifiable certificate definition file query: when a user needs to use the service of a service provider, downloading an attribute requirement list disclosed by the service provider, and screening all verifiable certificate definition files with part or all of the attribute requirement list from a verifiable certificate definition file list of a college on a alliance chain according to the type of the attribute in the attribute requirement list by the user;
Step 4, application and issuance of a verifiable certificate: the user generates derivative DIDs and submits the derivative DIDs to any university DID service manager, and the derivative DIDs of the user are stored on a alliance chain after the signature is verified by the any university DID service manager; the user sends the derivative DID and the identity verification information to a university DID service manager of the university to which the verifiable certificate definition file belongs; after the identity of the user is verified by a university DID service manager of the university to which the verifiable certificate definition file belongs, issuing a verifiable certificate to a derivative DID submitted by the user, and calculating and updating a hash value of a verifiable certificate accumulator stored on a alliance chain;
Step 5, generating a certification file and acquiring a service: the user processes the verifiable certificate into verifiable certificate claims, forms a certification file from the verifiable certificate claims, and sends the certification file to a service provider; the service provider verifies whether the attribute of the proof file meets the condition, verifies the validity of each verifiable certificate statement through a hash value of a verifiable certificate accumulator on a alliance chain, verifies the correctness of a private key signature of a college DID service manager and a private key signature of a derivative DID corresponding to each verifiable certificate statement through public key information on the alliance chain, and provides the service if the verification passes;
Step 6, the certificate revocation can be verified: when a verifiable certificate needs to be revoked, a university DID service administrator issuing the verifiable certificate revokes the verifiable certificate by modifying the verifiable certificate accumulator and updating the hash value of the verifiable certificate accumulator on the federation chain.
The invention has the beneficial effects that:
The method can effectively provide global identity management for college alliances established based on the alliance chain, and provide privacy protection for different users on the alliance chain, so that identity portraits of the users are prevented from being carried out through data on the alliance chain; meanwhile, mutual authentication among different universities is realized by using the verifiable certificates in a unified format, and the use of the privacy information in the minimum range is realized through selective disclosure.
Drawings
FIG. 1 is a flow chart of a college alliance user identity management method based on blockchain and DID.
Detailed Description
The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is apparent that the described embodiments are only some embodiments of the present invention, not all embodiments of the present invention, and this is not limiting to the present invention. All other embodiments, which can be made by those skilled in the art based on the embodiments of the invention without making any inventive effort, are intended to fall within the scope of the invention.
As shown in FIG. 1, the invention relates to a block chain and DID-based college alliance user identity management method flow chart, which comprises the following steps:
step 1, initializing a system: establishing a coalition chain comprising college identities by a plurality of colleges and universities, and initializing DID identities on the college DID service manager coalition chain; the university DID service manager defines a verifiable certificate definition file list, and the verifiable certificate definition file list is stored on a alliance chain; the service provider generates a user downloadable attribute requirement list;
Step 2, initializing user identity: the user generates a main DID, and submits the identification and the main DID to a college DID service manager of the college where the user is located; the university DID service manager checks the identity of the user, and stores the main DID on the alliance chain to enable the main DID to be effective;
Step 3, service required attribute requirement list and verifiable certificate definition file query: when a user needs to use the service of a service provider, downloading an attribute requirement list disclosed by the service provider, and screening all verifiable certificate definition files with part or all of the attribute requirement list from a verifiable certificate definition file list of a college on a alliance chain according to the type of the attribute in the attribute requirement list by the user;
step 4, application and issuance of a verifiable certificate: the user generates derivative DIDs, submits the derivative DIDs to any university DID service manager, and stores the derivative DIDs of the user on a alliance chain; the user sends the derivative DID and the identity verification information to a college DID service manager; after the identity of the user passes, issuing a verifiable certificate to the derivative DID submitted by the user, and calculating and updating a hash value of a verifiable certificate accumulator stored on a alliance chain;
Step 5, generating a certification file and acquiring a service: the user processes the verifiable certificate into verifiable certificate claims, forms a certification file from the verifiable certificate claims, and sends the certification file to a service provider; the service provider verifies whether the attribute of the certificate meets the condition, verifies the validity of each verifiable certificate statement through the hash value of the verifiable certificate accumulator, verifies the correctness of the signature through public key information on the alliance chain, and provides the service after the verification;
step 6, the certificate revocation can be verified: when a verifiable certificate needs to be revoked, a university DID service administrator issuing the verifiable certificate revokes the verifiable certificate by modifying a verifiable certificate accumulator and updating a verifiable certificate accumulator hash value on a federation chain.
Examples
The invention will be further illustrated with reference to specific examples.
The invention provides a college alliance user identity management method based on block chains and DIDs, which comprises the following steps:
step 1, initializing a system: establishing a coalition chain comprising college identities by a plurality of colleges and universities, and initializing DID identities on the college DID service manager coalition chain; the university DID service manager defines a verifiable certificate definition file list, and the verifiable certificate definition file list is stored on a alliance chain; the service provider generates a user downloadable attribute requirement list;
the step 1 system initialization specifically comprises the following steps:
In the step 1.1 of the method, The colleges and universities provide management nodes to form a college identity alliance chain, each college sets a respective college DID service manager, and records the colleges and universities on the alliance chainDID identity of college DID service managerPublic key,Representing the ith university;
In the specific implementation, the college alliance chain is a permitted blockchain, and each alliance member university maintains data in a mode of regularly carrying out consensus on the submitted contents by providing a management node to provide services; after passing the proportional authentication of all universities, the new universities can join the blockchain system by providing synchronous data of the management nodes, wherein the proportion is set by a specific implementation party;
Each university sets a DID service manager of the respective university, is responsible for managing the management node of the university where the university is located, and submits the data to be stored in a uplink mode to the management node.
Step 1.2, college of ithGenerating a first verifiable certificate definition file list by a university DID service manager,Indicating the ith collegeIs the 1 st verifiable certificate definition file,Indicating the ith collegeM verifiable certificate definition file, the ith universityThe j-th verifiable certificate definition fileIncluding the ith universityThe j-th verifiable certificate definition filePublic key of (a)And a hash value of the verifiable credential accumulatorFirst verifiable certificate attribute listThe verifiable certificate attribute list includes s elements,A first verifiable certificate attribute representing a first list of verifiable certificate attributes,The ith verifiable certificate attribute representing the first list of verifiable certificate attributes is used to define all files in the list of files using the ith university respectivelyPrivate key of (a)Storing the signature in a alliance chain;
The specific process of initializing the certificate definition file in the step 1.2 is as follows:
Colleges and universities of ith The DID service manager of the university defines a class of certificates, such as student certificates or achievement sheets, and the like in specific implementation;
Colleges and universities of ith The university DID service manager is the ith universityThe j-th verifiable certificate definition fileLocally maintaining verifiable certificate accumulatorAnd initialized to random large prime numbers=Thereafter, a hash value of the verifiable certificate accumulator is calculatedAnd stored on a coalition chain;
Wherein one of the certificate definition files may be verified The verifiable certificate definition files are respectively usedPrivate key of (a)And (5) after signing, storing the uplink.
Step 1.3, service providerGenerating a user downloadable attribute requirement listThere are h key-value pairs in the list,The 1 st attribute is indicated as such,Representing satisfaction attributesIs used for the attribute value space of (a),Representing the h-th attribute of the set,Representing satisfaction attributesIs a property value space of (a).
In the specific implementation, the service provider can provide services similar to cross-school class selection, venue reservation, book and other resource sharing, and the services can be provided only after the identity of the user is authenticated; for required attributes, the service providerGenerating a user downloadable attribute requirement listIn a specific implementation, for example, in a cross-school selection class, the attribute requirement list may be { colleges } { school A student certificate, school B student certificate }, total score } { good }, pre-repair course { course C, course D }, and the service provider may be toPublished on self-built web pages.
Step 2, initializing user identity: the user generates a main DID, and submits the identity verification information and the main DID to a college DID service manager of a college where the user is located; the university DID service manager checks the identity of the user, and stores the main DID on the alliance chain to enable the main DID to be effective;
the step 2 specifically comprises the following steps:
Step 2.1, college of ith T th user of (2)Generating a primary DID identityPublic and private key pair for userThe user will master DID identityUser public keyThe identity verification information is sent to the ith universityA university DID service administrator of (a) requesting completion of main DID initialization;
Step 2.2, college of ith After receiving the main DID initialization request of the user, the university DID service manager of (1) verifies the ith universityT th user of (2)Will beStored on a alliance chain to enable the ith universityT th user of (2)Is validated by the primary DID of (a),Representative of use of the ith universityPrivate key of (a)For the first hash valueAnd signing.
In a specific implementation the authentication information of the user is defined by the respective university.
Step 3, service required attribute requirement list and verifiable certificate definition file query: when a user needs to use the service of a service provider, downloading an attribute requirement list disclosed by the service provider, and screening all verifiable certificate definition files with part or all of the attribute requirement list from a verifiable certificate definition file list of a college on a alliance chain according to the type of the attribute in the attribute requirement list by the user;
the step3 specifically comprises the following steps:
Step 3.1, ith university T th user of (2)Requiring use of service providersDownloading a list of published attribute requirements while providing a service;
Step 3.2, college of ithT th user of (2)Determining a second list in a verifiable certificate definition file list of a college according to the type of the attribute in the attribute requirement listMaking the second list satisfy,Representing the first verifiable certificate definition file stored in the federation chain at the nth university, containing a second list of verifiable certificate attributesThe list has q elements, and,Representing the first verifiable certificate attribute of the second list of verifiable certificate attributes,The q-th verifiable certificate attribute representing the second list of verifiable certificate attributes.
Step 4, application and issuance of a verifiable certificate: the user generates derivative DIDs and submits the derivative DIDs to any university DID service manager, and the derivative DIDs of the user are stored on a alliance chain after the signature is verified by the any university DID service manager; the user sends the derivative DID and the identity verification information to a university DID service manager of the university to which the verifiable certificate definition file belongs; after the identity of the user is verified by a university DID service manager of the university to which the verifiable certificate definition file belongs, issuing a verifiable certificate to a derivative DID submitted by the user, and calculating and updating a hash value of a verifiable certificate accumulator stored on a alliance chain;
step4 specifically comprises the following steps:
Step 4.1, college of ith T th user of (2)Generating the (u) th derivativePublic and private key pairWill derive DID registration requestSend to any universityIs a university DID service manager;
Step 4.2, any one of the universities Receiving the derived DID registration request by the DID service manager of the university of (A), and checking the signatureAfter being effective, use colleges and universitiesDID identity of a university DID service manager of (3)Corresponding private keyFor the second hash valueSigning and will beStoring in a alliance chain to enable the ith universityT th user of (2)Is the (u) th derivative of (2)Take effect;
Step 4.3, college of ith T th user of (2)Derivative the (u)Colleges and universities of iThe j-th verifiable certificate definition fileThe identity verification information is sent to the ith universityDID service manager of universities, apply for j-th verifiable certificate issued by i-th university;
The authentication information in the system needs to be accompanied with authentication information in the physical world at the initial stage of the system, and the user can prove the identity through the authentication certificates when the number of the authentication certificates owned by the user is enough.
Step 4.4, college of ithThe university DID service manager is the ith universityT th user of (2)According to the ith universityThe j-th verifiable certificate definition fileList of verifiable certificate attributesFilling in corresponding attribute values to generate a large prime numberAs a serial number to a verifiable certificate accumulatorIn calculating and updating hash values of verifiable certificate accumulators on a federation chainCombining the attribute value and the serial number into a j-th verifiable certificate issued by the i-th universityAnd send to the ith universityT th user of (2)。
Colleges and universities of ithThe university DID service manager is the ith universityT th user of (2)Filling out plaintext attribute values and salt values according to a first verifiable certificate attribute list,First verifiable certificate attribute for first verifiable certificate attribute listIs used to determine the value of the plaintext attribute,Is the first verifiable certificate attribute for the first list of verifiable certificate attributesPlaintext attribute values of (2)The generated random number salt value is used for generating a random number,The s-th verifiable certificate attribute for the first list of verifiable certificate attributesIs used to determine the value of the plaintext attribute,Is the s-th verifiable certificate attribute for the first list of verifiable certificate attributesPlaintext attribute values of (2)The generated random number salt value and generate a hash value list for the plaintext attribute value of the first verifiable certificate attribute listWherein the first hash value in the hash value listThe s-th hash value in the hash value list; Generating a large prime numberAs a serial number to a verifiable certificate accumulatorIn calculating and updating hash values of verifiable certificate accumulators on a federation chainVerifiable certificate to be generatedSend to the ith universityT th user of (2)。
Updating the verifiable credential accumulator valueCalculating and updating hash values of verifiable certificate accumulators on a chain。
Step 5, generating a certification file and acquiring a service: the user processes the verifiable certificate into verifiable certificate claims, forms a certification file from the verifiable certificate claims, and sends the certification file to a service provider; the service provider verifies whether the attribute of the proof file meets the condition, verifies the validity of each verifiable certificate statement through a hash value of a verifiable certificate accumulator on a alliance chain, verifies the correctness of a private key signature of a college DID service manager and a private key signature of a derivative DID corresponding to each verifiable certificate statement through public key information on the alliance chain, and provides the service if the verification passes;
step5 specifically comprises the following steps:
Step 5.1, college of ith T th user of (2)Obtain and second listMatched verifiable certificate,Representing a first type verifiable certificate issued by an nth university, and after verifying that a signature is valid, including the verifiable certificate in an attribute requirement listThe attribute values of (2) are displayed in a plaintext, and the other attribute values are displayed in a plaintext hash value to become verifiable certificate declaration files, and the verifiable certificate declaration files are signed by using private keys corresponding to derived DIDs when the verifiable certificates are requested respectively, so that the verification files are combined to form the certification filesSent to the service provider;
The specific steps of the step 5.1 are as follows:
Colleges and universities of ith T th user of (2)Obtain and second listMatched verifiable certificate,Representing a first type verifiable certificate issued by an nth university, and after verifying that a signature is valid, including the verifiable certificate in an attribute requirement listThe attribute values of (2) are presented in plain text, and the other attribute values are presented in hash value, so that the list of verifiable certificate statement is formed,Represents the j-th verifiable certificate issued by the ith university after hash value processing,Express hashed value processed nth college issued type I verifiable certificateThe private key of the u-th derivative DID when requesting a verifiable certificate is used in turn… …, The e-th derivative private keySignature combination into a certificateThe certificate is subjected toSent to the service provider。
Step 5.2, service providerReceipt of a certificateThereafter, it is checked whether the attributes and attribute values satisfy the attribute requirement listFor each verifiable certificate statement file in the certificate file, checking the validity of the verifiable certificate statement through the verifiable certificate accumulator information, verifying the correctness of the private key signature of the university DID service manager and the private key signature of the derivative DID corresponding to each verifiable certificate statement through the public key information on the alliance chain, and providing service after the verification.
The specific steps of the step 5.2 are as follows:
Service provider Receiving the saidVerify whether or not to meetAll the required attributes of the attributes, wherein the attribute values of the attributes belong to an attribute value space of the attributes;
service provider verifies j-th type verifiable certificate issued by i-th university In the validity, from colleges and universitiesObtaining verifiable certificate accumulator values at a university DID service managerCalculating and comparing the hash value with the hash value stored on the federation chain, and verifying the certificate accumulator if the hash value is consistentClass j verifiable certificate issued by the university of modulo iWhether the value of the serial number Q in the colleges is 0, if 0, the colleges and universities of the ithThe j-th verifiable certificateThe effect is achieved;
And verifying whether the private key signature of the college DID service manager and the private key signature of the derivative DID corresponding to each verifiable certificate statement are correct or not through public key information on a alliance chain, and providing service if the verification passes.
Step 6, the certificate revocation can be verified: when a verifiable certificate needs to be revoked, a university DID service administrator issuing the verifiable certificate revokes the verifiable certificate by modifying the verifiable certificate accumulator and updating the hash value of the verifiable certificate accumulator on the federation chain.
The specific steps of the step6 are as follows:
Verifiable certificate Beyond the validity period or due to failure, it is necessary for the university to be issued by a certificateDID service manager of universities to perform verifiable certificate accumulator updatesThereafter, a hash value of a verifiable certificate accumulator stored on the federation chain is calculated and updated。
It is noted that what is not described in detail in the embodiments of the present invention belongs to the prior art known to those skilled in the art.
In summary, the method provided by the embodiment of the invention has the following advantages:
1) Trusted and non-tamperable storage of identity information: the college alliance user identity system is realized by means of the block chain technology, so that the resource intercommunication and information mutual recognition between colleges and universities can be effectively promoted, and the credibility and safety of information sharing between the colleges and universities are ensured by means of the characteristic that the block chain is not tamperable;
2) Across-facility global identity management: the DID and verifiable certificate technologies are adopted, so that identity management across different institutions is realized, and the decentralization and the high efficiency of identity verification and information sharing are realized; the user can realize identity verification and information sharing in different institutions and application scenes only by possessing a DID identifier and some verifiable certificates;
3) Information association protection on federation chain: adopting a derived DID technology to resist malicious users from portraying the users through the identities on the alliance chains, so that the identities on the alliance chains of the users are not associated with the identities on other alliance chains;
4) Privacy protection in certificate usage: using a hash function based attribute processing method ensures that a minimum range of certificate contents is used when generating a certificate.
In addition, it will be understood by those skilled in the art that all or part of the steps in implementing the methods of the above embodiments may be implemented by a program to instruct related hardware, and the corresponding program may be stored in a computer readable storage medium, where the storage medium may be a read only memory, a magnetic disk or an optical disk, etc.
The foregoing is only a preferred embodiment of the present invention, but the scope of the present invention is not limited thereto, and any changes or substitutions easily contemplated by those skilled in the art within the scope of the present invention should be included in the scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims. The information disclosed in the background section herein is only for enhancement of understanding of the general background of the invention and is not to be taken as an admission or any form of suggestion that this information forms the prior art already known to those of ordinary skill in the art.
Claims (9)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202410806278.1A CN118381663B (en) | 2024-06-21 | 2024-06-21 | College alliance user identity management method based on blockchain and DID |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202410806278.1A CN118381663B (en) | 2024-06-21 | 2024-06-21 | College alliance user identity management method based on blockchain and DID |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN118381663A CN118381663A (en) | 2024-07-23 |
| CN118381663B true CN118381663B (en) | 2024-08-23 |
Family
ID=91902137
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN202410806278.1A Active CN118381663B (en) | 2024-06-21 | 2024-06-21 | College alliance user identity management method based on blockchain and DID |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN118381663B (en) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN119402198B (en) * | 2024-08-28 | 2025-12-16 | 北京理工大学 | Distributed identity hierarchical storage and trusted authentication method based on verifiable computation |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112073479A (en) * | 2020-08-26 | 2020-12-11 | 重庆邮电大学 | Method and system for controlling de-centering data access based on block chain |
| CN115485682A (en) * | 2020-04-28 | 2022-12-16 | 微软技术许可有限责任公司 | Derived child verifiable certificate with optional claims |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11769577B1 (en) * | 2020-01-15 | 2023-09-26 | Ledgerdomain Inc. | Decentralized identity authentication framework for distributed data |
| CN116391378A (en) * | 2020-11-06 | 2023-07-04 | 联想(新加坡)私人有限公司 | Subscription Onboarding Using Verified Digital IDs |
| KR20230064354A (en) * | 2021-11-03 | 2023-05-10 | 펜타시큐리티시스템 주식회사 | Blockchain-based authentication audit data sharing and integrity verification system, device and method thereof |
| WO2023095967A1 (en) * | 2021-11-29 | 2023-06-01 | 주식회사 블록체인기술연구소 | Remote-interaction large document access system in which blockchain-based did service, ipfs-based data sharing technology and private key distributed storage technology are combined |
| CN116566705A (en) * | 2023-05-24 | 2023-08-08 | 北京泰尔英福科技有限公司 | Authentication method, system, client and server based on key derivation function |
-
2024
- 2024-06-21 CN CN202410806278.1A patent/CN118381663B/en active Active
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115485682A (en) * | 2020-04-28 | 2022-12-16 | 微软技术许可有限责任公司 | Derived child verifiable certificate with optional claims |
| CN112073479A (en) * | 2020-08-26 | 2020-12-11 | 重庆邮电大学 | Method and system for controlling de-centering data access based on block chain |
Also Published As
| Publication number | Publication date |
|---|---|
| CN118381663A (en) | 2024-07-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Das et al. | A secure blockchain-enabled vehicle identity management framework for intelligent transportation systems | |
| Abraham et al. | Revocable and offline-verifiable self-sovereign identities | |
| AU2017225928A1 (en) | Systems and methods for distributed data sharing with asynchronous third-party attestation | |
| CN111881483B (en) | Resource account binding methods, devices, equipment and media based on blockchain | |
| Brunner et al. | SPROOF: A Platform for Issuing and Verifying Documents in a Public Blockchain. | |
| CN106992988B (en) | A cross-domain anonymous resource sharing platform and its implementation method | |
| Chandra et al. | Novel blockchain-based framework to publish, verify, and store digital academic credentials of universities | |
| KR102460299B1 (en) | Anonymous credential authentication system and method thereof | |
| CN110855445B (en) | Block chain-based certificate management method and device and storage equipment | |
| Abraham et al. | Privacy-preserving eID derivation for self-sovereign identity systems | |
| CN114930770B (en) | Voucher authentication method and system based on distributed ledger | |
| CN114944937B (en) | Distributed digital identity verification method, system, electronic equipment and storage medium | |
| CN115688191A (en) | Block chain-based electronic signature system and method | |
| US12463822B2 (en) | Sharing security settings between entities using verifiable credentials | |
| CN117280346A (en) | Methods and apparatus for generating, providing and forwarding trusted electronic data sets or certificates based on electronic files associated with users | |
| Mukta et al. | Credtrust: Credential based issuer management for trust in self-sovereign identity | |
| CN115412253B (en) | Digital certificate preparation method based on blockchain technology | |
| Abraham et al. | Privacy-preserving eID derivation to self-sovereign identity systems with offline revocation | |
| Garg | Blockchain ecosystem for education and employment verification | |
| Cheng et al. | A permissioned blockchain-based platform for education certificate verification | |
| CN118381663B (en) | College alliance user identity management method based on blockchain and DID | |
| Lohar et al. | A Self-Sovereign Identity Framework for Context-Aware De-Centralized Identifier Creation and Credential Verification | |
| Chiliveri et al. | ProveDoc: A blockchain based proof of existence with proof of storage | |
| CN119561696B (en) | A trusted identity authentication method for academic participants based on blockchain-verifiable credentials | |
| Namazi et al. | zkFaith: Soonami's Zero-Knowledge Identity Protocol |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant |