WO2020082886A1 - 认证方法及装置、电子设备 - Google Patents
认证方法及装置、电子设备 Download PDFInfo
- Publication number
- WO2020082886A1 WO2020082886A1 PCT/CN2019/102816 CN2019102816W WO2020082886A1 WO 2020082886 A1 WO2020082886 A1 WO 2020082886A1 CN 2019102816 W CN2019102816 W CN 2019102816W WO 2020082886 A1 WO2020082886 A1 WO 2020082886A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- transaction
- event
- server
- authenticated
- blockchain
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3825—Use of electronic signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4014—Identity check for transactions
Definitions
- One or more embodiments of this specification relate to the field of identity authentication technology, and in particular, to an authentication method and device, and electronic equipment.
- one or more embodiments of this specification provide an authentication method and apparatus, and electronic equipment.
- an authentication method including:
- the server receives an authentication request, which is initiated by the client for the event to be authenticated, and the event to be authenticated is declared to be related to the specified object;
- the server acquires a transaction event related to the event to be authenticated from the blockchain, and the transaction event is signed by the transaction-related object through a pre-registered digital identity;
- the server determines the entity identity of the transaction-related object based on the signature of the transaction event, the pre-recorded mapping relationship between the entity identity of each object and the digital identity, and is used to authenticate whether the specified object is Describe the transaction-related objects.
- an authentication method including:
- the client initiates an authentication request to the server for the event to be authenticated to instruct the server to obtain a transaction event related to the event to be authenticated from the blockchain, the transaction event is registered by the transaction-related object through a digital identity Sign
- the client receives the entity identity of the transaction-related object to verify whether the specified object is the transaction-related object, wherein the specified object is declared to be related to the event to be authenticated, and the transaction-related object
- entity identity of is determined by the server according to the signature of the transaction event, the mapping relationship between the pre-recorded entity identity of each object and the digital identity; or, the client receives the identity authentication returned by the server As a result, the identity authentication result is used to indicate whether the designated object is the transaction-related object.
- an authentication device including:
- the request receiving unit enables the server to receive the authentication request, which is initiated by the client for the event to be authenticated, and the event to be authenticated is declared to be related to the specified object;
- the event acquisition unit enables the server to acquire a transaction event related to the event to be authenticated from the blockchain, and the transaction event is signed by the transaction-related object through a pre-registered digital identity;
- the identity determination unit enables the server to determine the entity identity of the transaction-related object based on the mapping between the signature of the transaction event, the pre-recorded entity identity of each object and the digital identity, for use in authenticating the Specifies whether the object is the transaction-related object.
- an authentication device including:
- the request unit enables the client to initiate an authentication request to the server for the event to be authenticated, to instruct the server to obtain the transaction event related to the event to be authenticated from the blockchain, and the transaction event is passed by the transaction related object in advance Sign the registered digital identity;
- An identity receiving unit causing the client to receive the entity identity of the transaction-related object for use in verifying whether a specified object is the transaction-related object, wherein the specified object is declared to be related to the event to be authenticated, and The entity identity of the transaction-related object is determined by the server according to the signature of the transaction event, the mapping relationship between the pre-recorded entity identity and digital identity of each object; or, the client receives the service
- the identity authentication result returned by the terminal, the identity authentication result is used to indicate whether the specified object is the transaction-related object.
- an electronic device including:
- Memory for storing processor executable instructions
- the processor executes the executable instruction to implement the method according to the first aspect.
- an electronic device including:
- Memory for storing processor executable instructions
- the processor executes the executable instruction to implement the method according to the second aspect.
- FIG. 1 is a flowchart of an authentication method provided by an exemplary embodiment
- FIG. 2 is a flowchart of another authentication method provided by an exemplary embodiment
- FIG. 3 is a schematic diagram of a registered digital identity provided by an exemplary embodiment
- FIG. 4 is a schematic diagram of an information storage certificate provided by an exemplary embodiment
- FIG. 5 is a schematic diagram of an authentication and authorization situation provided by an exemplary embodiment
- FIG. 6 is a schematic structural diagram of a device provided by an exemplary embodiment
- FIG. 7 is a block diagram of an authentication device provided by an exemplary embodiment
- FIG. 8 is a schematic structural diagram of another device provided by an exemplary embodiment
- FIG. 9 is a block diagram of another authentication apparatus provided by an exemplary embodiment.
- the steps of the corresponding method are not necessarily performed in the order shown and described in this specification.
- the method may include more or fewer steps than described in this specification.
- the single step described in this specification may be decomposed into multiple steps for description in other embodiments; and the multiple steps described in this specification may also be combined into a single step in other embodiments description.
- FIG. 1 is a flowchart of an authentication method provided by an exemplary embodiment. As shown in Figure 1, this method is applied to the server and can include the following steps:
- Step 102 The server receives an authentication request.
- the authentication request is initiated by the client for the event to be authenticated, and the event to be authenticated is declared to be related to the specified object.
- the designated object is the object specified by the "declaration".
- the designated objects can be individuals, institutions (such as enterprises, etc.) or both.
- the number of designated objects can be one or more, and this specification does not limit this.
- the association relationship between the "event to be authenticated” and the "designated object” may be declared in any form, and this specification does not limit this.
- the content of the "to-be-certified event” and the information of the "designated object” can be presented in the same image, for example, the image can be a promotional poster, and the content of the "to-be-certified event” can be the promotional content of the poster, "designated object”
- the information is the photo of the celebrity in the poster, which is equivalent to declaring that the celebrity is the endorsement of the promotional content in the poster; for another example, the content of the "to be certified event” and the information of the "designated object” can be printed on the same paper, such as the paper
- the content of "event to be authenticated” is the position information in the business card
- the information of "designated object” is the name in the business card, which is equivalent to declaring that the issuer of the business card (that is, the user corresponding to the name) is in the corresponding
- Step 104 The server obtains a transaction event related to the event to be authenticated from the blockchain, and the transaction event is signed by the transaction-related object through a pre-registered digital identity.
- the transaction-related object may be registered in the above-mentioned server in advance to obtain the corresponding digital identity; or, the transaction-related object may be registered at another service provider to obtain the corresponding digital identity, and the other service provider
- the identity authentication service can be provided to the above-mentioned server, or the access right to the mapping relationship between the acquired entity identity and digital identity can be opened to the above-mentioned server, so that the server can implement identity authentication by itself.
- the transaction-related object may be an institution, which may use its own entity identity to register with the above-mentioned server or other service provider to obtain the corresponding digital identity.
- the transaction related object can be an individual, who can use his own entity identity to register with the above-mentioned server or other service providers to obtain the corresponding digital identity; or, when the individual is an employee of a certain structure or there is a certain
- the individual can first obtain the certification of an organization and obtain the signature implemented by the organization ’s registered digital identity, which is equivalent to the organization endorsement of the individual ’s identity, and then the individual can use the signature in the above services End or other service providers to register to obtain the corresponding digital identity.
- transaction-related objects can also obtain digital identities in other ways, and this specification does not limit this.
- the signature of the transaction event when there is a single transaction-related object, the signature of the transaction event is a single signature; when there are multiple transaction-related objects, the signature of the transaction event is a multi-signature.
- the transaction-related object may be the issuer of the transaction event, that is, the transaction-related object signs the transaction event and then publishes it to the blockchain (through its corresponding blockchain node, directly to the blockchain Or, submit to the server, and the server publishes the transaction event to the blockchain through its corresponding blockchain node.
- the transaction-related object is not the issuer of the transaction event, and the transaction-related object can sign the transaction event and then publish it to the blockchain by the issuer; wherein, the transaction-related object can be The issuer and the transaction event are authenticated separately, such as confirming that the identity of the issuer is true and reliable, confirming that the content of the transaction event is true and reliable, and signing the transaction event after the confirmation is passed, otherwise no signature will be implemented.
- authenticating the identity of the publisher you can restrict the publisher to have a preset association relationship with the transaction-related objects.
- the transaction-related object is an enterprise
- the publisher is an internal employee of the enterprise
- the transaction-related object is an individual
- the release The party is the address book friend of the transaction-related object, and when there is no preset association relationship, it is considered that the identity of the issuer has not been authenticated.
- the issuer can publish transaction events to the blockchain through its corresponding blockchain node.
- the publisher may submit the transaction event to the server, and the server publishes the transaction event to the blockchain through its corresponding blockchain node.
- the server can verify the identity of the publisher and the content of the transaction event: if the signature contained in the transaction event is the signature of the publisher, and the identity of the publisher has been registered with the server or other service providers, the server can It is believed that the identity of the publisher and the content of the transaction event are true and reliable, and can be posted to the blockchain; if the signature contained in the transaction event is a signature of a transaction-related object other than the publisher, the server can verify that the publisher and the transaction Whether there is the above-mentioned preset association relationship between transaction related objects, for example, the transaction related object is an enterprise, the publisher is an internal employee of the enterprise, and the transaction related object is an individual, and the publisher is the address book friend of the transaction related object, etc.
- the server can query the digital identity pre-registered by the publisher; when the digital identity of the publisher is registered based on the signature provided by the transaction-related object to the publisher, the server determines The preset association relationship exists.
- the issuer may request the transaction-related object to verify its entity identity in advance, and after the transaction-related object recognizes the entity identity of the issuer, it may provide the publisher with a digital signature (signed by the transaction-related object's private key), and The issuer may register its own digital identity based on the digital signature, so that the issuer's digital identity has already established an association relationship with the transaction related object's digital identity during registration. Then, after receiving the above-mentioned transaction event submitted by the publisher, the server can verify the identity of the publisher and the content of the transaction event based on the association relationship.
- the transfer described in this specification refers to a piece of data that a user creates through a client of the blockchain and needs to be finally released to the distributed database of the blockchain.
- a narrowly defined transaction refers to a value transfer issued by the user to the blockchain; for example, in the traditional Bitcoin blockchain network, the transaction can be a transfer initiated by the user in the blockchain.
- the generalized transaction refers to a piece of business data with business intent that users release to the blockchain; for example, the operator can build an alliance chain based on actual business needs, relying on the alliance chain to deploy some other types that have nothing to do with value transfer Online services (for example, authentication services, rental services, vehicle scheduling services, insurance claims services, credit services, medical services, etc.), and in this type of alliance chain, transactions can be a sum of business issued by users in the alliance chain Intent business message or business request.
- value transfer Online services for example, authentication services, rental services, vehicle scheduling services, insurance claims services, credit services, medical services, etc.
- the transaction event by storing the transaction event in the blockchain, it can ensure that the content of the transaction event is safe and reliable, will not be tampered with, and can be verified from the blockchain ledger at any time, with extremely high reliability Sex and trustworthiness.
- the server can obtain transaction anchor information, which is declared to be related to the event to be authenticated; then, the server obtains the transaction anchor information from the blockchain
- the corresponding transaction event is used as the transaction event related to the event to be authenticated.
- the transaction anchor information can be information such as the transaction serial number; for another example, when the transaction event is generated as an intelligence in the blockchain In a contract, the transaction anchor information may be the name of the smart contract, the transaction serial number corresponding to the smart contract, and other information.
- the server can obtain the event content of the transaction event to verify the consistency between the transaction event and the above-mentioned event to be authenticated to ensure that the transaction event can be used to realize Authentication.
- the server acquires the transaction event through the above-mentioned transaction anchor information, it is possible to avoid wrongful guidance to the server after the criminal anchor changes the transaction anchor information.
- transaction anchor information can be presented in the poster in the form of a two-dimensional code, etc., and if the criminals anchor the two-dimensional code as the celebrity signs for other events Transaction event, then by checking the event content of the transaction event, you can accurately identify the wrongful act of the criminals and avoid misjudgment.
- the server can call a smart contract, and the smart contract is used to verify the consistency between the transaction event and the event to be authenticated; similar to the above embodiment, this embodiment can also ensure this Transaction events can be used to implement identity authentication related to the event to be authenticated, but the judgment of consistency can be automatically completed by the smart contract, not by the server, to reduce the processing pressure of the server, or based on the automatic smart contract Implementation characteristics to ensure the objectivity and fairness of certification results.
- the server can return the event content of the transaction event to the client, so that the client (or its user) can learn the details or verify the consistency between the transaction event and the event to be authenticated.
- Step 106 The server determines the entity identity of the transaction-related object according to the signature of the transaction event and the pre-recorded mapping relationship between the entity identity of each object and the digital identity, which is used to authenticate the specified object Whether it is the transaction related object.
- the transaction event related to the event to be authenticated by obtaining a transaction event related to the event to be authenticated and verifying the signature for the transaction event, it can be accurately determined whether the declared relationship between the event to be authenticated and the specified object is true and credible, such as when promoting When the poster contains a photo of a celebrity, you can determine whether the celebrity actually endorses the promotional content on the poster, for example, to determine whether the position included on the business card is true.
- the server may send the determined entity identity of the transaction-related object to the client, so that the client or its user compares the entity identity of the transaction-related object with the entity identity of the specified object to determine Are the two consistent?
- the server may actively compare the entity identity of the transaction-related object with the entity identity of the specified object, thereby verifying whether the specified object is the transaction-related object, and further return the authentication to the client result.
- the authentication result may include only the judgment result of "whether it is consistent", or may further include the entity identity of the transaction-related object, for the client (or its user) to understand the details, or for it to verify the aforementioned judgment result.
- FIG. 2 is a flowchart of another authentication method provided by an exemplary embodiment. As shown in FIG. 2, this method is applied to the client and may include the following steps:
- Step 202 The client initiates an authentication request to the server for the event to be authenticated to instruct the server to obtain a transaction event related to the event to be authenticated from the blockchain, the transaction event is pre-registered by the transaction-related object Digital identity.
- the transaction-related object may be registered in the above-mentioned server in advance to obtain the corresponding digital identity; or, the transaction-related object may be registered at another service provider to obtain the corresponding digital identity, and the other service provider
- the identity authentication service can be provided to the above-mentioned server, or the access right to the mapping relationship between the acquired entity identity and digital identity can be opened to the above-mentioned server, so that the server can implement identity authentication by itself.
- the transaction-related object may be an institution, which may use its own entity identity to register with the above-mentioned server or other service provider to obtain the corresponding digital identity.
- the transaction related object can be an individual, who can use his own entity identity to register with the above-mentioned server or other service providers to obtain the corresponding digital identity; or, when the individual is an employee of a certain structure or there is a certain
- the individual can first obtain the certification of an organization and obtain the signature implemented by the organization ’s registered digital identity, which is equivalent to the organization endorsement of the individual ’s identity, and then the individual can use the signature in the above services End or other service providers to register to obtain the corresponding digital identity.
- transaction-related objects can also obtain digital identities in other ways, and this specification does not limit this.
- the signature of the transaction event when there is a single transaction-related object, the signature of the transaction event is a single signature; when there are multiple transaction-related objects, the signature of the transaction event is a multi-signature.
- the transfer described in this specification refers to a piece of data that a user creates through a client of the blockchain and needs to be finally released to the distributed database of the blockchain.
- a narrowly defined transaction refers to a value transfer issued by the user to the blockchain; for example, in the traditional Bitcoin blockchain network, the transaction can be a transfer initiated by the user in the blockchain.
- the generalized transaction refers to a piece of business data with business intent that users release to the blockchain; for example, the operator can build an alliance chain based on actual business needs, relying on the alliance chain to deploy some other types that have nothing to do with value transfer Online services (for example, authentication services, rental services, vehicle scheduling services, insurance claims services, credit services, medical services, etc.), and in this type of alliance chain, transactions can be a sum of business issued by users in the alliance chain Intent business message or business request.
- value transfer Online services for example, authentication services, rental services, vehicle scheduling services, insurance claims services, credit services, medical services, etc.
- the client can identify the barcode pattern (such as bar code, two-dimensional code, etc.) associated with the event to be authenticated to obtain transaction anchor information; then, the client can transfer the transaction Anchor information is uploaded to the server to obtain the transaction event from the blockchain by the server.
- the transaction anchor information can be information such as the transaction serial number; for another example, when the transaction event is generated as an intelligence in the blockchain In a contract, the transaction anchor information may be the name of the smart contract, the transaction serial number corresponding to the smart contract, and other information.
- Step 204 The client receives the entity identity of the transaction-related object to verify whether the specified object is the transaction-related object, wherein the specified object is declared to be related to the event to be authenticated, and the The entity identity of the transaction-related object is determined by the server according to the mapping relationship between the signature of the transaction event and the pre-recorded entity identity and digital identity of each object; or, the client receives the return from the server The authentication result of the identity is used to indicate whether the specified object is the transaction-related object.
- the transaction event related to the event to be authenticated by obtaining a transaction event related to the event to be authenticated and verifying the signature for the transaction event, it can be accurately determined whether the declared relationship between the event to be authenticated and the specified object is true and credible, such as when promoting When the poster contains a photo of a celebrity, you can determine whether the celebrity actually endorses the promotional content on the poster, for example, to determine whether the position included on the business card is true.
- the designated object is the object specified by the "declaration".
- the designated objects can be individuals, institutions (such as enterprises, etc.) or both.
- the number of designated objects can be one or more, and this specification does not limit this.
- the association relationship between the "event to be authenticated” and the "designated object” may be declared in any form, and this specification does not limit this.
- the content of the "to-be-certified event” and the information of the "designated object” can be presented in the same image, for example, the image can be a promotional poster, and the content of the "to-be-certified event” can be the promotional content of the poster, "designated object”
- the information is the photo of the celebrity in the poster, which is equivalent to declaring that the celebrity is the endorsement of the promotional content in the poster; for another example, the content of the "to be certified event” and the information of the "designated object” can be printed on the same paper, such as It can be a business card, the content of "event to be authenticated” is the position information in the business card, and the information of "designated object” is the name in the business card, which is equivalent to declaring that the issuer of the business card (that is, the user corresponding to the name) is in the corresponding position
- the client may receive the event content of the transaction event returned by the server to verify the consistency between the transaction event and the event to be authenticated to ensure the transaction event It can be used to implement identity authentication related to the event to be authenticated.
- the server acquires the transaction event through the above-mentioned transaction anchor information, it is possible to avoid wrongful guidance to the server after the criminal anchor changes the transaction anchor information.
- transaction anchor information can be presented in the poster in the form of a two-dimensional code, etc., and if the criminals anchor the two-dimensional code as the celebrity signs for other events Transaction event, then by checking the event content of the transaction event, you can accurately identify the wrongful act of the criminals and avoid misjudgment.
- the transaction event is inconsistent with the event to be authenticated, it indicates that the transaction event is not a transaction event related to the event to be authenticated, so the client can determine that the specified object is not a transaction-related object of the transaction event related to the event to be authenticated.
- the client may receive the content authentication result returned by the server, and the content authentication result is used to indicate consistency between the transaction event and the event to be authenticated.
- the server can authenticate the consistency between the transaction event and the aforementioned event to be authenticated, and obtain the content authentication result described above to inform the client.
- the client can also receive the event content of the transaction event returned by the server, so that the client (or its user) can learn the details, or verify the consistency between the transaction event and the event to be authenticated.
- FIG. 3 is a schematic diagram of registering a digital identity provided by an exemplary embodiment.
- a certification authority specifically, a server-side application running on an electronic device corresponding to the certification authority
- the certification body can provide the materials and information required for registration, and the certification body can assign the corresponding digital identity to the enterprise AA after verification, such as enterprise digital identity 1; at the same time, the certification body can record the enterprise The mapping relationship between AA's corporate entity identity 1 and the enterprise's digital identity 1 to facilitate subsequent identity authentication.
- the certification body also issues a public and private key pair to the enterprise AA for the enterprise AA to generate a digital signature (or electronic signature) used to characterize its enterprise digital identity 1.
- enterprise BB can register with a certification authority and obtain a corresponding digital identity, such as enterprise digital identity 2.
- the certification authority can record the mapping relationship between the enterprise entity identity 2 of the enterprise BB and the enterprise digital identity 2, and issue the public and private key pair used to generate the digital signature to the enterprise BB.
- individuals can also register with certification bodies in a similar manner to obtain corresponding digital identities.
- user A can provide the certification authority with the materials and information required for registration, and the certification authority can assign a corresponding digital identity to user A after verification, such as user digital identity 1.
- the certification authority can record the mapping relationship between the user entity identity 1 of the user A and the user digital identity 1 to facilitate subsequent identity authentication.
- the certification authority also issues a public and private key pair to user A for user A to generate a digital signature used to characterize his user's digital identity 1.
- user B in addition to registering with a certification authority to obtain a digital identity in a similar manner to user A, if there is a certain relationship between user B and enterprise BB, for example, user B is an employee of enterprise BB, Then the user B can also complete the registration through the enterprise BB. For example, user B can submit an authentication to enterprise BB. This process is often easier than providing materials and information to register directly with the authentication structure, and enterprise BB confirms that user B can authenticate the user after passing the authentication.
- B provides a digital signature, such as an enterprise digital signature 2 generated by a private key; and user B can register with the certification authority based on the enterprise digital signature 2 to obtain a digital identity assigned by the certification authority, such as user digital identity 2.
- the certification authority can record the mapping relationship between the user entity identity 2 of the user B and the user digital identity 2, and issue a public and private key pair for generating a digital signature to the user B.
- any enterprise, individual, etc. can register with the certification body, so that the certification body can separately record the mapping relationship between the entity identity of each enterprise or individual and the assigned digital identity, and issued for generating digital signatures Of public and private key pairs.
- FIG. 4 is a schematic diagram of an information storage certificate provided by an exemplary embodiment. As shown in FIG. 4, assume that user A is a celebrity. When user A agrees to authorize xxx to make a poster, that is, user A agrees to endorse xxx, user A can deposit relevant information to the blockchain.
- the user equipment 1 used by user A may be any type such as a mobile phone, a tablet, or a personal computer, which is not limited in this specification.
- the client-side application running on the user device 1 the user A can complete the operation of depositing relevant information in the blockchain.
- user A may generate certification information such as "I authorize xxx" on the user device 1, and sign the certification information by calling a private key issued by a certification authority, such as obtaining a corresponding digital signature as SIG_U1.
- the process of generating the certification information "I authorize xxx" and the digital signature SIG_U1 can actually be completed by the certification authority, and the user device 1 can only be used to provide an interactive interface to user A and authenticate the user A (especially It is based on the verification of physiological characteristics; of course, the password verification, input habit verification, etc. can also be completed by the certification authority), and the data transmission between the certification authority, so that the user A can instruct the certification authority to generate certification information and digital signature.
- the user equipment 1 may be configured as a blockchain node in the blockchain, then the user equipment 1 may submit a blockchain transaction [I authorize xxx; SIG_U1] to the blockchain, so that The blockchain transaction [I authorize xxx; SIG_U1] is recorded in the blockchain ledger maintained by each blockchain node.
- the user equipment 1 itself is not configured as a blockchain node, then the user equipment 1 can send the certification information "I authorize xxx" and the digital signature SIG_U1 to the blockchain node, so that the blockchain
- the node submits the above-mentioned blockchain transaction [I authorize xxx; SIG_U1] to the blockchain, which also enables the blockchain transaction [I authorize xxx; SIG_U1] to be recorded in the blockchain ledger maintained by each blockchain node in.
- the certification authority can be configured as a blockchain node, and through the client-side application running on the user equipment 1 and the server-side application running on the certification authority, the user equipment 1 can set the certification information "I authorize xxx "And the digital signature SIG_U1 is sent to the certification body, and the certification body submits the above-mentioned blockchain transaction [I authorize xxx; SIG_U1] to the blockchain.
- a corresponding access interface can be formed to facilitate access in the subsequent authentication process.
- the access interface can be presented in the form of a two-dimensional code, and the blockchain node can send the two-dimensional code to the production agency of the poster (such as enterprise AA), so that the enterprise AA can add the two-dimensional code to Propaganda poster.
- FIG. 5 is a schematic diagram of an authentication and authorization situation provided by an exemplary embodiment. As shown in FIG. 5, assuming that the application program on the client side is running on the electronic device 2 used by the user B, the camera module on the electronic device 2 can be called, and the QR code on the promotional poster shown in FIG. 4 Scan and upload the scanned content of the identified QR code to the certification body for certification by the certification body.
- the QR code scan content includes the access interface information generated in the embodiment shown in FIG. 4, and the certification authority can query the blockchain ledger based on the QR code scan content:
- the certification body may not be able to query any blockchain transactions, indicating that the QR code on the poster is useless information set by the criminals at random, and user A has not released and submitted xxx products to the blockchain Proof of authorization, then the certification body can determine that the authentication failed, that is, user A has not authorized.
- the certification authority can access the corresponding blockchain transaction, but the blockchain transaction does not contain a digital signature or the included digital signature is not the SIG_U1 corresponding to user A, indicating that the two on the poster
- the dimensional code is fake information set randomly by the criminals.
- User A did not publish the certification information on the blockchain and authorized the xxx product, then the certification body can determine that the authentication failed, that is, user A did not authorize.
- the certification authority can access the corresponding blockchain transaction, the digital signature included in the blockchain transaction is SIG_U1, and the certification authority can be based on the mapping relationship recorded in Figure 3 and the issuance record of the public and private key pair To determine that the digital signature SIG_U1 corresponds to user A. Then, the blockchain transaction has a certain probability to contain the certification information that user A authorizes the xxx product; however, under a certain probability, the blockchain transaction may contain the certification information that user A authorizes other products, not for xxx product authorization information, so the certification body can further verify the content contained in the blockchain exchange to ensure that the certification information it contains is "I authorize xxx" or similar description, not "I authorize yyy" content.
- the certification authority may return the certification information to the user device 2 so that the user device 2 can display related content to the user B.
- the authentication information can be as shown in Figure 5, including the certification information "I authorize xxx” and the digital signature SIG_U1 corresponding to Entity identity "User A" (Digital signature can reflect the digital identity, and further combined with the mapping relationship between the digital identity and the entity identity, the entity identity can be determined).
- the authentication information may further include an authentication conclusion, such as "passed authentication” or “authorized”, “not passed authentication” or “unauthorized".
- the authentication conclusion is not necessary; even if the authentication information only contains the content contained in the blockchain exchange, the entity information corresponding to the included digital signature, etc., user B can also view the authentication information and combine the content in the poster, Determine whether user A is authorized. For example, when the authentication information includes “authorization information not found”, “I authorize yyy”, “signature: user C", “unsigned”, etc., user B may determine that user A has not authorized the xxx product.
- user B wants to deposit his position on his business card to show the authenticity of the position. Assuming that user B is also a director of enterprise AA, chairman of enterprise BB and CEO of enterprise CC, then user B can put the position information that needs to be recorded on the business card "User B: enterprise AA-director, enterprise BB-chair, enterprise CC-CEO "It is handed over to each enterprise for authentication, and after passing the authentication, each enterprise can separately sign with the private key held by itself, so that user B can obtain a multiple digital signature SIG_M for the above position information.
- user B can submit a blockchain transaction to the blockchain ledger through user device 2, the blockchain transaction contains the above job information and multiple digital signatures SIG_M, and user B can gain access to the blockchain transaction Interface, and print the QR code corresponding to the access interface on User B's business card.
- the user X can request the authentication of the certification authority by scanning the QR code on the business card.
- the certification body can query the corresponding blockchain transaction from the blockchain through an embodiment such as shown in FIG. 5, the blockchain transaction contains job information "User B: Enterprise AA-Director, Enterprise BB-Chairman, "Enterprise CC-CEO", and the multiple digital signatures SIG_M corresponding to Enterprise AA, Enterprise BB and Enterprise CC, the certification body can assign the job information "User B: Enterprise AA-Director, Enterprise BB-Chairman, Enterprise CC-CEO" and The information of the enterprise AA, enterprise BB and enterprise CC corresponding to the multiple digital signature SIG_M is returned to the user X, so that the user X determines the authenticity of the post information actually marked on the business card.
- Blockchain transactions include the signatures of enterprise AA, enterprise BB and enterprise CC, and the positions marked on the business card are consistent with the position information contained in the blockchain transaction, then the position information marked on the business card can be considered to be true.
- the signature information is inconsistent or the position information is inconsistent, it indicates that the position information marked on the business card may be untrue.
- FIG. 6 is a schematic structural diagram of a device provided by an exemplary embodiment. Please refer to FIG. 6.
- the device includes a processor 602, an internal bus 604, a network interface 606, a memory 608, and a non-volatile memory 610. Of course, it may include hardware required for other services.
- the processor 602 reads the corresponding computer program from the non-volatile memory 610 into the memory 608 and then runs it to form an authentication device at a logical level.
- one or more embodiments of this specification do not exclude other implementations, such as logic devices or a combination of hardware and software, etc., that is to say, the execution body of the following processing flow is not limited to each
- the logic unit may also be a hardware or logic device.
- the authentication device may include:
- the request receiving unit 701 enables the server to receive the authentication request, which is initiated by the client for the event to be authenticated, and the event to be authenticated is declared to be related to the specified object;
- the event obtaining unit 702 enables the server to obtain a transaction event related to the event to be authenticated from the blockchain, and the transaction event is signed by a transaction-related object through a pre-registered digital identity;
- the identity determination unit 703 enables the server to determine the entity identity of the transaction-related object based on the mapping relationship between the signature of the transaction event, the pre-recorded entity identity of each object and the digital identity, and to be used for authentication Whether the specified object is the transaction-related object.
- the event acquisition unit 702 is specifically used to:
- a content acquisition unit 704 or a contract invocation unit 705 which:
- the content obtaining unit 704 is used to enable the server to obtain the event content of the transaction event, so as to verify the consistency between the transaction event and the event to be authenticated;
- the contract invoking unit 705 is used to cause the server to call a smart contract, and the smart contract is used to verify the consistency between the transaction event and the event to be authenticated.
- Optional also includes:
- the authentication unit 706 causes the server to authenticate whether the specified object is the transaction-related object, so as to return the authentication result to the client.
- Optional also includes:
- the return unit 707 causes the server to return the entity identity of the transaction-related object and / or the event content of the transaction event to the client.
- the transaction event is posted to the blockchain by the transaction-related object
- the transaction event is published to the blockchain by a publisher different from the transaction-related object.
- the transaction event is released to the blockchain by the publisher through its corresponding blockchain node
- the device further includes: a publishing unit 708, which causes the server to receive the transaction event submitted by the publisher and publish the transaction event to the blockchain through its corresponding blockchain node.
- a publishing unit 708 which causes the server to receive the transaction event submitted by the publisher and publish the transaction event to the blockchain through its corresponding blockchain node.
- Optional also includes:
- the verification unit 709 causes the server to verify whether there is a preset association relationship between the issuer and the transaction association object corresponding to the signature included in the transaction event;
- the publishing unit 708 causes the server to publish the transaction event to the blockchain.
- the verification unit 709 is specifically used to:
- the server When the digital identity of the issuer is registered based on the signature provided by the transaction association object to the issuer, the server is caused to determine that the preset association relationship exists.
- FIG. 8 is a schematic structural diagram of a device provided by an exemplary embodiment. Please refer to FIG. 8.
- the device includes a processor 802, an internal bus 804, a network interface 806, a memory 808, and a non-volatile memory 810.
- the processor 802 reads the corresponding computer program from the non-volatile memory 810 into the memory 808 and then runs it to form an authentication device at a logical level.
- one or more embodiments of this specification do not exclude other implementations, such as logic devices or a combination of hardware and software, etc., that is to say, the execution body of the following processing flow is not limited to each
- the logic unit may also be a hardware or logic device.
- the authentication device may include:
- the requesting unit 901 enables the client to initiate an authentication request to the server for the event to be authenticated, to instruct the server to obtain a transaction event related to the event to be authenticated from the blockchain, and the transaction event is passed by the transaction related object Pre-registered digital identity for signature;
- the identity receiving unit 902 enables the client to receive the entity identity of the transaction-related object for use in verifying whether the specified object is the transaction-related object, wherein the specified object is declared to be related to the event to be authenticated, And the entity identity of the transaction-associated object is determined by the server according to the mapping relationship between the signature of the transaction event, the pre-recorded entity identity of each object and the digital identity; or, the client receives the The identity authentication result returned by the server.
- the identity authentication result is used to indicate whether the specified object is the transaction-related object.
- Optional also includes:
- the identification unit 903 enables the client to identify the barcode pattern associated with the event to be authenticated to obtain transaction anchor information
- the uploading unit 904 enables the client to upload the transaction anchor information to the server, so that the server can obtain the transaction event from the blockchain.
- it also includes a content receiving unit 905 or a result receiving unit 906; where:
- the content receiving unit 905 is used to enable the client to receive the event content of the transaction event returned by the server, for verifying the consistency between the transaction event and the event to be authenticated;
- the result receiving unit 906 is used to enable the client to receive the content authentication result returned by the server, and the content authentication result is used to indicate the consistency between the transaction event and the event to be authenticated.
- the system, device, module or unit explained in the above embodiments may be specifically implemented by a computer chip or entity, or by a product having a certain function.
- a typical implementation device is a computer, and the specific form of the computer may be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email sending and receiving device, and a game control Desk, tablet computer, wearable device, or any combination of these devices.
- the computer includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
- processors CPUs
- input / output interfaces output interfaces
- network interfaces network interfaces
- memory volatile and non-volatile memory
- the memory may include non-permanent memory, random access memory (RAM) and / or non-volatile memory in computer-readable media, such as read only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
- RAM random access memory
- ROM read only memory
- flash RAM flash memory
- Computer-readable media including permanent and non-permanent, removable and non-removable media, can store information by any method or technology.
- the information may be computer readable instructions, data structures, modules of programs, or other data.
- Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, Magnetic cassette tapes, magnetic disk storage, quantum memory, graphene-based storage media or other magnetic storage devices or any other non-transmission media can be used to store information that can be accessed by computing devices.
- computer-readable media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.
- first, second, third, etc. may use the terms first, second, third, etc. to describe various information, the information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other.
- first information may also be referred to as second information, and similarly, the second information may also be referred to as first information.
- word "if” as used herein may be interpreted as "when” or “when” or “in response to a determination”.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Computer Security & Cryptography (AREA)
- Accounting & Taxation (AREA)
- General Business, Economics & Management (AREA)
- Finance (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
本说明书一个或多个实施例提供一种认证方法及装置、电子设备,该方法可以包括:服务端接收认证请求,所述认证请求由客户端针对待认证事件发起,所述待认证事件被声明为与指定对象相关;所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系,确定所述交易关联对象的实体身份,以用于认证所述指定对象是否为所述交易关联对象。
Description
本说明书一个或多个实施例涉及身份认证技术领域,尤其涉及一种认证方法及装置、电子设备。
在相关技术中,当某一事件被声明为与某一个人或组织相关联时,往往难以判断其真实性,甚至可能因此蒙受损失。同时,对于被声明为与该事件相关联的个人或组织,即便事实上并无关联,也可能被作为事后的维权对象,引发不必要的麻烦和纷争。
发明内容
有鉴于此,本说明书一个或多个实施例提供一种认证方法及装置、电子设备。
为实现上述目的,本说明书一个或多个实施例提供技术方案如下:
根据本说明书一个或多个实施例的第一方面,提出了一种认证方法,包括:
服务端接收认证请求,所述认证请求由客户端针对待认证事件发起,所述待认证事件被声明为与指定对象相关;
所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;
所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系,确定所述交易关联对象的实体身份,以用于认证所述指定对象是否为所述交易关联对象。
根据本说明书一个或多个实施例的第二方面,提出了一种认证方法,包括:
客户端针对待认证事件向服务端发起认证请求,以指示所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;
所述客户端接收所述交易关联对象的实体身份,以用于认证指定对象是否为所述交易关联对象,其中所述指定对象被声明为与所述待认证事件相关,且所述交易关联对象 的实体身份由所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系而确定;或者,所述客户端接收所述服务端返回的身份认证结果,所述身份认证结果用于表明所述指定对象是否为所述交易关联对象。
根据本说明书一个或多个实施例的第三方面,提出了一种认证装置,包括:
请求接收单元,使服务端接收认证请求,所述认证请求由客户端针对待认证事件发起,所述待认证事件被声明为与指定对象相关;
事件获取单元,使所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;
身份确定单元,使所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系,确定所述交易关联对象的实体身份,以用于认证所述指定对象是否为所述交易关联对象。
根据本说明书一个或多个实施例的第四方面,提出了一种认证装置,包括:
请求单元,使客户端针对待认证事件向服务端发起认证请求,以指示所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;
身份接收单元,使所述客户端接收所述交易关联对象的实体身份,以用于认证指定对象是否为所述交易关联对象,其中所述指定对象被声明为与所述待认证事件相关,且所述交易关联对象的实体身份由所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系而确定;或者,所述客户端接收所述服务端返回的身份认证结果,所述身份认证结果用于表明所述指定对象是否为所述交易关联对象。
根据本说明书一个或多个实施例的第五方面,提出了一种电子设备,包括:
处理器;
用于存储处理器可执行指令的存储器;
其中,所述处理器通过运行所述可执行指令以实现如第一方面所述的方法。
根据本说明书一个或多个实施例的第六方面,提出了一种电子设备,包括:
处理器;
用于存储处理器可执行指令的存储器;
其中,所述处理器通过运行所述可执行指令以实现如第二方面所述的方法。
图1是一示例性实施例提供的一种认证方法的流程图;
图2是一示例性实施例提供的另一种认证方法的流程图;
图3是一示例性实施例提供的一种注册数字身份的示意图;
图4是一示例性实施例提供的一种信息存证的示意图;
图5是一示例性实施例提供的一种认证授权情况的示意图;
图6是一示例性实施例提供的一种设备的结构示意图;
图7是一示例性实施例提供的一种认证装置的框图;
图8是一示例性实施例提供的另一种设备的结构示意图;
图9是一示例性实施例提供的另一种认证装置的框图。
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本说明书一个或多个实施例相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本说明书一个或多个实施例的一些方面相一致的装置和方法的例子。
需要说明的是:在其他实施例中并不一定按照本说明书示出和描述的顺序来执行相应方法的步骤。在一些其他实施例中,其方法所包括的步骤可以比本说明书所描述的更多或更少。此外,本说明书中所描述的单个步骤,在其他实施例中可能被分解为多个步骤进行描述;而本说明书中所描述的多个步骤,在其他实施例中也可能被合并为单个步骤进行描述。
图1是一示例性实施例提供的一种认证方法的流程图。如图1所示,该方法应用于服务端,可以包括以下步骤:
步骤102,服务端接收认证请求,所述认证请求由客户端针对待认证事件发起,所述待认证事件被声明为与指定对象相关。
在一实施例中,指定对象为“声明”所指明确定的对象。指定对象可以为个人、机构(如企业等)或两者均包含。指定对象的数量可以为一个或多个,本说明书并不对此进行限制。
在一实施例中,可以通过任意形式对“待认证事件”与“指定对象”之间的关联关系进行声明,本说明书并不对此进行限制。例如,可以将“待认证事件”的内容与“指定对象”的信息呈现于同一图像中,比如该图像可以为宣传海报,“待认证事件”的内容为海报中的宣传内容、“指定对象”的信息为海报中的名人照片,相当于声明该名人为海报中的宣传内容背书;再例如,可以将“待认证事件”的内容与“指定对象”的信息打印在同一纸张上,比如该纸张可以为名片,“待认证事件”的内容为名片中的职位信息、“指定对象”的信息为名片中的姓名,相当于声明该名片的发放者(即该姓名对应的用户)处于相应的职位。
步骤104,所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名。
在一实施例中,交易关联对象可以预先在上述的服务端处注册得到相应的数字身份;或者,该交易关联对象可以在其他服务提供方处注册得到相应的数字身份,而该其他服务提供方可以向上述的服务端提供身份认证服务,或者向上述的服务端开放对已获得的实体身份与数字身份之间的映射关系的访问权限、使得该服务端可以自行实施身份认证。
在一实施例中,交易关联对象可以为机构,该机构可以使用自身的实体身份在上述的服务端或其他服务提供方处进行注册,得到相应的数字身份。交易关联对象可以为个人,该个人可以使用自身的实体身份在上述的服务端或其他服务提供方处进行注册,得到相应的数字身份;或者,当该个人为某一结构的员工或存在某种关联时,该个人可以首先获得某一机构的认证,得到该机构已注册的数字身份所实施的签名,相当于该机构为该个人的身份进行背书,然后该个人可以通过该签名在上述的服务端或其他服务提供方处注册得到相应的数字身份。当然,交易关联对象还可以通过其他方式获得数字身份,本说明书并不对此进行限制。
在一实施例中,当存在单个交易关联对象时,对交易事件的签名为单个签名;当存在多个交易关联对象时,对交易事件的签名为多重签名。
在一实施例中,交易关联对象可以为交易事件的发布方,即该交易关联对象对交易事件进行签名后,向区块链发布(通过自身对应的区块链节点,直接发布至区块链;或者,提交至服务端,由服务端通过自身对应的区块链节点发布至区块链)了该交易事件。
在一实施例中,交易关联对象并非交易事件的发布方,该交易关联对象可以对该交易事件进行签名后,交由发布方将其发布至区块链中;其中,交易关联对象可以对该发布方和交易事件分别进行认证,比如确认该发布方的身份真实、可靠,确认交易事件的内容真实、可靠,并在确认通过认证后针对交易事件进行签名,否则不实施签名。在针对发布方的身份进行认证时,可以限制该发布方与交易关联对象存在预设关联关系,比如交易关联对象为企业、发布方为该企业的内部员工,再比如交易关联对象为个人、发布方为该交易关联对象的通讯录好友等,而当不存在该预设关联关系时,则认为发布方的身份未通过认证。
在一实施例中,发布方可以通过自身对应的区块链节点,向区块链中发布交易事件。
在一实施例中,发布方可以将交易事件提交至服务端,并由服务端通过自身对应的区块链节点向区块链中发布交易事件。服务端可以对发布方的身份、交易事件的内容进行验证:如果交易事件包含的签名为该发布方的签名,且该发布方的身份已注册至服务端或其他服务提供方,则服务端可以认为发布方的身份、交易事件的内容均真实可靠,可以发布至区块链;如果交易事件包含的签名为该发布方之外的交易关联对象的签名,那么服务端可以验证该发布方与该交易关联对象之间是否存在上述的预设关联关系,比如交易关联对象为企业、发布方为该企业的内部员工,再比如交易关联对象为个人、发布方为该交易关联对象的通讯录好友等,当存在该预设关联关系时可以认为发布方的身份、交易事件的内容均真实可靠,可以发布至区块链,否则认为发布方的身份未通过认证、拒绝发布至区块链。
其中,所述服务端可以查询所述发布方预先注册的数字身份;当所述发布方的数字身份是基于所述交易关联对象向所述发布方提供的签名而注册时,所述服务端判定存在所述预设关联关系。例如,发布方可以预先请求交易关联对象认证其实体身份,而交易关联对象在认可发布方的实体身份后,可以向该发布方提供数字签名(由交易关联对象的私钥进行签名得到),而发布方可以基于该数字签名注册自身的数字身份,使得该发布方的数字身份在注册时就已经与交易关联对象的数字身份建立了关联关系。那么,服务端在收到发布方提交的上述交易事件后,可以基于该关联关系对该发布方的身份、交易事件的内容进行验证。
在一实施例中,本说明书中所描述的交易(transfer),是指用户通过区块链的客户端创建,并需要最终发布至区块链的分布式数据库中的一笔数据。其中,区块链中的交易,存在狭义的交易以及广义的交易之分。狭义的交易是指用户向区块链发布的一笔价值转移;例如,在传统的比特币区块链网络中,交易可以是用户在区块链中发起的一笔转账。而广义的交易是指用户向区块链发布的一笔具有业务意图的业务数据;例如,运营方可以基于实际的业务需求搭建一个联盟链,依托于联盟链部署一些与价值转移无关的其它类型的在线业务(比如,认证业务、租房业务、车辆调度业务、保险理赔业务、信用服务、医疗服务等),而在这类联盟链中,交易可以是用户在联盟链中发布的一笔具有业务意图的业务消息或者业务请求。
在一实施例中,通过将交易事件存证于区块链中,可以确保该交易事件的内容安全可靠、不会被篡改,并且随时可以从区块链账本中予以查证,具有极高的可靠性和可信任度。
在一实施例中,服务端可以获取交易锚定信息,所述交易锚定信息被声明为与所述待认证事件相关;然后,所述服务端从区块链中获取所述交易锚定信息对应的交易事件,以作为与所述待认证事件相关的交易事件。比如,当交易事件被基于某一交易而被发布至区块链时,该交易锚定信息可以为交易流水号等信息;再比如,当该交易事件被生成为区块链中的某一智能合约时,该交易锚定信息可以为该智能合约的名称、该智能合约对应的交易流水号等信息。
在一实施例中,服务端可以获取交易事件的事件内容,以用于认证该交易事件与上述的待认证事件之间的一致性,确保该交易事件可以用于实现与该待认证事件相关的身份认证。尤其是,当服务端通过上述的交易锚定信息获取交易事件时,可以避免不法分子对交易锚定信息进行改动后,向服务端做出错误引导。例如,对于包含名人照片的宣传海报,可以将交易锚定信息以诸如二维码等形式呈现于该宣传海报中,而如果不法分子将该二维码锚定为该名人针对其他事件进行签名得到的交易事件,那么通过对该交易事件的事件内容进行核对,即可准确识别出不法分子的不法行为,避免发生误判。
在一实施例中,服务端可以调用智能合约,所述智能合约用于认证所述交易事件与所述待认证事件之间的一致性;与上述实施例相类似,本实施例同样可以确保该交易事件可以用于实现与该待认证事件相关的身份认证,只是对于一致性的判断操作可以由智能合约自动完成、并非由服务端完成,以减轻服务端的处理压力,也可以基于智能合约的自动执行特性而保障认证结果的客观性和公平性。
在一实施例中,服务端可以向客户端返回交易事件的事件内容,以供客户端(或其使用者)了解详情,或供其验证交易事件与待认证事件之间的一致性。
步骤106,所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系,确定所述交易关联对象的实体身份,以用于认证所述指定对象是否为所述交易关联对象。
在一实施例中,通过获取与待认证事件相关的交易事件,以及验证针对该交易事件的签名,可以准确判断出待认证事件与指定对象之间被声明的关系是否真实可信,比如当宣传海报上包含名人照片时,可以确定该名人是否确实为海报上的宣传内容背书,再比如确定名片上包含的职位是否真实等。
在一实施例中,服务端可以将确定出的交易关联对象的实体身份发送至客户端,使得客户端或其使用者将该交易关联对象的实体身份与指定对象的实体身份进行比较,以确定两者是否一致。
在一实施例中,服务端可以主动将该交易关联对象的实体身份与指定对象的实体身份进行比较,从而认证所述指定对象是否为所述交易关联对象,并进一步向所述客户端返回认证结果。其中,认证结果中可以仅包含“是否一致”的判断结果,或者还可以进一步包含交易关联对象的实体身份,以供客户端(或其使用者)了解详情,或供其验证上述的判断结果。
图2是一示例性实施例提供的另一种认证方法的流程图。如图2所示,该方法应用于客户端,可以包括以下步骤:
步骤202,客户端针对待认证事件向服务端发起认证请求,以指示所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名。
在一实施例中,交易关联对象可以预先在上述的服务端处注册得到相应的数字身份;或者,该交易关联对象可以在其他服务提供方处注册得到相应的数字身份,而该其他服务提供方可以向上述的服务端提供身份认证服务,或者向上述的服务端开放对已获得的实体身份与数字身份之间的映射关系的访问权限、使得该服务端可以自行实施身份认证。
在一实施例中,交易关联对象可以为机构,该机构可以使用自身的实体身份在上述的服务端或其他服务提供方处进行注册,得到相应的数字身份。交易关联对象可以为个人,该个人可以使用自身的实体身份在上述的服务端或其他服务提供方处进行注册,得 到相应的数字身份;或者,当该个人为某一结构的员工或存在某种关联时,该个人可以首先获得某一机构的认证,得到该机构已注册的数字身份所实施的签名,相当于该机构为该个人的身份进行背书,然后该个人可以通过该签名在上述的服务端或其他服务提供方处注册得到相应的数字身份。当然,交易关联对象还可以通过其他方式获得数字身份,本说明书并不对此进行限制。
在一实施例中,当存在单个交易关联对象时,对交易事件的签名为单个签名;当存在多个交易关联对象时,对交易事件的签名为多重签名。
在一实施例中,本说明书中所描述的交易(transfer),是指用户通过区块链的客户端创建,并需要最终发布至区块链的分布式数据库中的一笔数据。其中,区块链中的交易,存在狭义的交易以及广义的交易之分。狭义的交易是指用户向区块链发布的一笔价值转移;例如,在传统的比特币区块链网络中,交易可以是用户在区块链中发起的一笔转账。而广义的交易是指用户向区块链发布的一笔具有业务意图的业务数据;例如,运营方可以基于实际的业务需求搭建一个联盟链,依托于联盟链部署一些与价值转移无关的其它类型的在线业务(比如,认证业务、租房业务、车辆调度业务、保险理赔业务、信用服务、医疗服务等),而在这类联盟链中,交易可以是用户在联盟链中发布的一笔具有业务意图的业务消息或者业务请求。
在一实施例中,所述客户端可以识别与所述待认证事件相关联的条码图案(如条形码、二维码等),得到交易锚定信息;然后,所述客户端可以将所述交易锚定信息上传至所述服务端,以由所述服务端从区块链中获取所述交易事件。比如,当交易事件被基于某一交易而被发布至区块链时,该交易锚定信息可以为交易流水号等信息;再比如,当该交易事件被生成为区块链中的某一智能合约时,该交易锚定信息可以为该智能合约的名称、该智能合约对应的交易流水号等信息。
步骤204,所述客户端接收所述交易关联对象的实体身份,以用于认证指定对象是否为所述交易关联对象,其中所述指定对象被声明为与所述待认证事件相关,且所述交易关联对象的实体身份由所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系而确定;或者,所述客户端接收所述服务端返回的身份认证结果,所述身份认证结果用于表明所述指定对象是否为所述交易关联对象。
在一实施例中,通过获取与待认证事件相关的交易事件,以及验证针对该交易事件的签名,可以准确判断出待认证事件与指定对象之间被声明的关系是否真实可信,比如当宣传海报上包含名人照片时,可以确定该名人是否确实为海报上的宣传内容背书,再 比如确定名片上包含的职位是否真实等。
在一实施例中,指定对象为“声明”所指明确定的对象。指定对象可以为个人、机构(如企业等)或两者均包含。指定对象的数量可以为一个或多个,本说明书并不对此进行限制。
在一实施例中,可以通过任意形式对“待认证事件”与“指定对象”之间的关联关系进行声明,本说明书并不对此进行限制。例如,可以将“待认证事件”的内容与“指定对象”的信息呈现于同一图像中,比如该图像可以为宣传海报,“待认证事件”的内容为海报中的宣传内容、“指定对象”的信息为海报中的名人照片,相当于声明该名人为海报中的宣传内容背书;再例如,可以将“待认证事件”的内容与“指定对象”的信息打印在同一纸张上,比如该纸张可以为名片,“待认证事件”的内容为名片中的职位信息、“指定对象”的信息为名片中的姓名,相当于声明该名片的发放者(即该姓名对应的用户)处于相应的职位。
在一实施例中,所述客户端可以接收所述服务端返回的所述交易事件的事件内容,以用于认证所述交易事件与所述待认证事件之间的一致性,确保该交易事件可以用于实现与该待认证事件相关的身份认证。尤其是,当服务端通过上述的交易锚定信息获取交易事件时,可以避免不法分子对交易锚定信息进行改动后,向服务端做出错误引导。例如,对于包含名人照片的宣传海报,可以将交易锚定信息以诸如二维码等形式呈现于该宣传海报中,而如果不法分子将该二维码锚定为该名人针对其他事件进行签名得到的交易事件,那么通过对该交易事件的事件内容进行核对,即可准确识别出不法分子的不法行为,避免发生误判。例如,当交易事件与待认证事件不一致时,表明该交易事件并非与待认证事件相关的交易事件,因此客户端可以判定指定对象并非与待认证事件相关的交易事件的交易关联对象。
在一实施例中,所述客户端可以接收所述服务端返回的内容认证结果,所述内容认证结果用于表明所述交易事件与所述待认证事件之间的一致性。换言之,可以由服务端对交易事件与上述的待认证事件之间的一致性进行认证,并得到上述的内容认证结果,以告知客户端。进一步地,客户端还可以接收服务端返回的交易事件的事件内容,使得客户端(或其使用者)可以了解详情,或者验证交易事件与待认证事件之间的一致性。
图3是一示例性实施例提供的一种注册数字身份的示意图。如图3所示,认证机构(具体可以为认证机构对应的电子设备上运行的服务端侧应用程序)可以通过实体认证、数据分析、间接认证等手段,提供数字身份的注册功能。
以企业AA为例,可以向认证机构提供注册所需的材料和信息,而认证机构在验证通过后即可向企业AA分配相应的数字身份,比如企业数字身份1;同时,认证机构可以记录企业AA的企业实体身份1与该企业数字身份1之间的映射关系,以便于后续实施身份认证。认证机构还向企业AA颁发公私钥对,以供企业AA生成用于表征其企业数字身份1的数字签名(或称,电子签名)。
类似地,企业BB可以向认证机构进行注册并得到相应的数字身份,比如企业数字身份2。同时,认证机构可以记录企业BB的企业实体身份2与该企业数字身份2之间的映射关系,并向企业BB颁发用于生成数字签名的公私钥对。
与企业AA、企业BB注册数字身份的过程相类似地,个人也可以通过相似的方式向认证机构注册得到相应的数字身份。例如,用户A可以向认证机构提供注册所需的材料和信息,而认证机构在验证通过后即可向用户A分配相应的数字身份,比如用户数字身份1。同时,认证机构可以记录用户A的用户实体身份1与该用户数字身份1之间的映射关系,以便于后续实施身份认证。认证机构还向用户A颁发公私钥对,以供用户A生成用于表征其用户数字身份1的数字签名。
而对于用户B而言,除了采用与用户A相类似的方式向认证机构注册得到数字身份之外,如果该用户B与企业BB之间存在某种关联,比如该用户B为企业BB的员工,那么该用户B还可以借由企业BB完成注册。例如,用户B可以向企业BB提出认证,该过程相比于向认证结构直接注册而言,所需提供的材料和信息等往往更为简化,而企业BB确认用户B通过认证后可以向该用户B提供数字签名,比如通过私钥生成的企业数字签名2;而用户B可以基于该企业数字签名2向认证机构进行注册,从而得到认证机构分配的数字身份,比如用户数字身份2。同时,认证机构可以记录用户B的用户实体身份2与该用户数字身份2之间的映射关系,并向用户B颁发用于生成数字签名的公私钥对。
基于上述描述,任一企业、个人等均可以向认证机构进行注册,使得认证机构可以分别记录每一企业或个人的实体身份与分配的数字身份之间的映射关系,并颁发用于生成数字签名的公私钥对。
下面结合图4-5,以宣传海报上的名人背书信息为例,对本说明书的认证方案进行详细描述。
图4是一示例性实施例提供的一种信息存证的示意图。如图4所示,假定用户A为 某一名人,当该用户A同意向xxx予以授权制作宣传海报,即该用户A同意为该xxx背书时,用户A可以向区块链存证相关信息。
在一实施例中,用户A使用的用户设备1可以为手机、平板、个人电脑等任意类型,本说明书并不对此进行限制。通过该用户设备1上运行的客户端侧应用程序,使得用户A能够完成向区块链存证相关信息的操作。比如,用户A可以在该用户设备1上生成诸如“我授权xxx”的证明信息,并通过调用认证机构颁发的私钥对该证明信息进行签名,比如得到相应的数字签名为SIG_U1。在调用私钥生成签名之前,可以对用户A进行身份验证,比如密码验证、输入习惯验证或基于指纹、声纹、人脸、虹膜等形式的生理特征验证等,并在验证通过后允许生成签名,否则不允许生成签名。
当然,对于证明信息“我授权xxx”和数字签名SIG_U1的生成过程,实际上也可以由认证机构完成,而用户设备1可以仅用于向用户A提供交互界面、向用户A进行身份验证(尤其是基于生理特征的验证;当然,对于密码验证、输入习惯验证等,也可以由认证机构完成)、与认证机构之间实现数据传输,以使得用户A可以指示认证机构生成证明信息和数字签名。
在一实施例中,用户设备1可以被配置为区块链中的一区块链节点,那么该用户设备1可以向区块链提交一笔区块链交易[我授权xxx;SIG_U1],使得该区块链交易[我授权xxx;SIG_U1]被记录至各个区块链节点统一维护的区块链账本中。
在一实施例中,用户设备1本身并未配置为区块链节点,那么该用户设备1可以通过将证明信息“我授权xxx”和数字签名SIG_U1发送至区块链节点,以由区块链节点向区块链提交上述的区块链交易[我授权xxx;SIG_U1],同样可以使得该区块链交易[我授权xxx;SIG_U1]被记录至各个区块链节点统一维护的区块链账本中。例如,认证机构可以被配置为一区块链节点,而通过用户设备1上运行的客户端侧应用程序、认证机构处运行的服务端侧应用程序,用户设备1可以将证明信息“我授权xxx”和数字签名SIG_U1发送至认证机构,并由认证机构向区块链提交上述的区块链交易[我授权xxx;SIG_U1]。
在一实施例中,针对被发布的区块链交易[我授权xxx;SIG_U1],可以形成相应的访问接口,以便于在后续认证的过程中进行访问。例如,该访问接口可以采用二维码形式进行呈现,而区块链节点可以将该二维码发送至宣传海报的制作机构(比如企业AA),以使得企业AA可以将该二维码添加至宣传海报中。
当用户B查看到如图4所示的宣传海报后,根据该宣传海报所宣传的xxx产品以及用户A的照片,会自然地联想到用户A可能在为该xxx产品进行背书,但也可能是不法分子随意使用了用户A的照片,则用户B可以通过该宣传海报上的二维码进行认证,以确定用户A是否确实授权了对该xxx产品进行背书。
图5是一示例性实施例提供的一种认证授权情况的示意图。如图5所示,假定用户B使用的电子设备2上运行有客户端侧的应用程序,可以调用该电子设备2上的摄像头模组,对如图4所示的宣传海报上的二维码进行扫描,并将识别出的二维码扫描内容上传至认证机构,以由认证机构予以认证处理。
在一实施例中,二维码扫描内容包括图4所示实施例中生成的访问接口信息,认证机构可以基于该二维码扫描内容对区块链账本进行查询:
在第一种情况下,认证机构可能无法查询到任何区块链交易,表明宣传海报上的二维码是不法分子随意设置的无用信息,用户A并未向区块链中发布与向xxx产品进行授权的证明信息,那么认证机构可以判定为认证失败,即用户A并未授权。
在第二种情况下,认证机构可以访问到相应的区块链交易,但该区块链交易中并未包含数字签名或者包含的数字签名并非用户A所对应的SIG_U1,表明宣传海报上的二维码是不法分子随意设置的假冒信息,用户A并未向区块链中发布与向xxx产品进行授权的证明信息,那么认证机构可以判定为认证失败,即用户A并未授权。
在第三种情况下,认证机构可以访问到相应的区块链交易,该区块链交易中包含的数字签名为SIG_U1,认证机构可以基于图3中记录的映射关系和公私钥对的颁发记录,确定该数字签名SIG_U1对应于用户A。那么,该区块链交易具有一定概率包含用户A向xxx产品进行授权的证明信息;但是,在一定概率下,该区块链交易可能包含用户A向其他产品进行授权的证明信息,而并非针对xxx产品的授权信息,因而认证机构可以进一步对该区块链交易所包含的内容进行认证,以确保其包含的证明信息为“我授权xxx”或类似描述,而并非“我授权yyy”等无关内容。
在一实施例中,认证机构可以将认证信息返回至用户设备2,以使得用户设备2可以将相关内容向用户B进行展示。例如,当认证结构访问到的区块链交易确实包含证明信息“我授权xxx”和数字签名SIG_U1时,认证信息可以如图5所示,包括证明信息“我授权xxx”以及数字签名SIG_U1对应的实体身份“用户A”(数字签名可以反映出数字身份,进一步结合数字身份与实体身份的映射关系,可以确定出实体身份)。
在一实施例中,认证信息中还可以包含认证结论,比如“通过认证”或“已授权”、“未通过认证”或“未授权”等。当然,认证结论并非必须;即便认证信息中仅包含区块链交易所包含的内容、所包含的数字签名对应的实体信息等,用户B同样能够通过查看该认证信息并结合宣传海报中的内容,确定用户A是否授权。例如,当认证信息包含“未查询到授权信息”、“我授权yyy”、“签名:用户C”、“未签名”等内容时,用户B可以确定用户A并未对xxx产品进行授权。
类似于上述“宣传海报”的实施例,本说明书的技术方案显然还可以应用于诸多其他场景下,均可以用于实现快速、准确的认证操作。
例如,用户B希望对自己名片上的职位进行存证,以表明该职位的真实性。假定用户B同时属于企业AA的董事、企业BB的主席和企业CC的CEO,那么用户B可以将名片上需要记载的职位信息“用户B:企业AA-董事、企业BB-主席、企业CC-CEO”分别交由各个企业进行认证,而各个企业在认证通过后可以分别通过自身持有的私钥进行签名,使得用户B可以获得对上述职位信息的多重数字签名SIG_M。然后,用户B可以通过用户设备2向区块链账本中提交区块链交易,该区块链交易中包含上述职位信息和多重数字签名SIG_M,而用户B可以获得针对该区块链交易的访问接口,并将对应于该访问接口的二维码印刷在用户B的名片上。
那么,当用户B将名片分发给用户X时,该用户X可以通过扫描该名片上的二维码,请求认证机构进行认证。而认证机构可以通过诸如图5所示的实施例,从区块链中查询到相应的区块链交易,该区块链交易包含职位信息“用户B:企业AA-董事、企业BB-主席、企业CC-CEO”,以及对应于企业AA、企业BB和企业CC的多重数字签名SIG_M,认证机构可以将该职位信息“用户B:企业AA-董事、企业BB-主席、企业CC-CEO”与多重数字签名SIG_M对应的企业AA、企业BB和企业CC的信息返回至用户X,使得用户X确定名片上实际标注的职位信息的真实性。
譬如,当名片上标注了用户B为企业AA的董事、企业BB的主席和企业CC的CEO时,即名片内容被声明为与企业AA、企业BB、企业CC和企业DD相关;那么,如果区块链交易中包含企业AA、企业BB和企业CC的签名,并且名片上标注的职位与区块链交易中包含的职位信息一致,那么可以认为名片上标注的职位信息是真实的。但是,如果签名信息不一致或者职位信息不一致,那么表明名片上标注的职位信息可能是不真实的。
图6是一示例性实施例提供的一种设备的示意结构图。请参考图6,在硬件层面, 该设备包括处理器602、内部总线604、网络接口606、内存608以及非易失性存储器610,当然还可能包括其他业务所需要的硬件。处理器602从非易失性存储器610中读取对应的计算机程序到内存608中然后运行,在逻辑层面上形成认证装置。当然,除了软件实现方式之外,本说明书一个或多个实施例并不排除其他实现方式,比如逻辑器件抑或软硬件结合的方式等等,也就是说以下处理流程的执行主体并不限定于各个逻辑单元,也可以是硬件或逻辑器件。
请参考图7,在软件实施方式中,该认证装置可以包括:
请求接收单元701,使服务端接收认证请求,所述认证请求由客户端针对待认证事件发起,所述待认证事件被声明为与指定对象相关;
事件获取单元702,使所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;
身份确定单元703,使所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系,确定所述交易关联对象的实体身份,以用于认证所述指定对象是否为所述交易关联对象。
可选的,所述事件获取单元702具体用于:
使所述服务端获取交易锚定信息,所述交易锚定信息被声明为与所述待认证事件相关;
使所述服务端从区块链中获取所述交易锚定信息对应的交易事件,以作为与所述待认证事件相关的交易事件。
可选的,还包括内容获取单元704或合约调用单元705;其中:
所述内容获取单元704用于使所述服务端获取所述交易事件的事件内容,以用于认证所述交易事件与所述待认证事件之间的一致性;
所述合约调用单元705用于使所述服务端调用智能合约,所述智能合约用于认证所述交易事件与所述待认证事件之间的一致性。
可选的,还包括:
认证单元706,使所述服务端认证所述指定对象是否为所述交易关联对象,以向所述客户端返回认证结果。
可选的,还包括:
返回单元707,使所述服务端向所述客户端返回所述交易关联对象的实体身份和/或所述交易事件的事件内容。
可选的,
所述交易事件被所述交易关联对象发布至区块链;
或者,在所述交易关联对象对所述交易事件签名后,所述交易事件被区别于所述交易关联对象的发布方发布至区块链。
可选的,
所述交易事件被所述发布方通过自身对应的区块链节点发布至区块链;
或者,所述装置还包括:发布单元708,使所述服务端接收所述发布方提交的所述交易事件,并通过自身对应的区块链节点将所述交易事件发布至区块链。
可选的,还包括:
验证单元709,使所述服务端验证所述发布方与所述交易事件所包含的签名对应的交易关联对象之间是否存在预设关联关系;
当存在所述预设关联关系时,所述发布单元708使所述服务端将所述交易事件发布至区块链。
可选的,所述验证单元709具体用于:
使所述服务端查询所述发布方预先注册的数字身份;
当所述发布方的数字身份是基于所述交易关联对象向所述发布方提供的签名而注册时,使所述服务端判定存在所述预设关联关系。
图8是一示例性实施例提供的一种设备的示意结构图。请参考图8,在硬件层面,该设备包括处理器802、内部总线804、网络接口806、内存808以及非易失性存储器810,当然还可能包括其他业务所需要的硬件。处理器802从非易失性存储器810中读取对应的计算机程序到内存808中然后运行,在逻辑层面上形成认证装置。当然,除了软件实现方式之外,本说明书一个或多个实施例并不排除其他实现方式,比如逻辑器件抑或软硬件结合的方式等等,也就是说以下处理流程的执行主体并不限定于各个逻辑单元,也可以是硬件或逻辑器件。
请参考图9,在软件实施方式中,该认证装置可以包括:
请求单元901,使客户端针对待认证事件向服务端发起认证请求,以指示所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;
身份接收单元902,使所述客户端接收所述交易关联对象的实体身份,以用于认证指定对象是否为所述交易关联对象,其中所述指定对象被声明为与所述待认证事件相关,且所述交易关联对象的实体身份由所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系而确定;或者,所述客户端接收所述服务端返回的身份认证结果,所述身份认证结果用于表明所述指定对象是否为所述交易关联对象。
可选的,还包括:
识别单元903,使所述客户端识别与所述待认证事件相关联的条码图案,得到交易锚定信息;
上传单元904,使所述客户端将所述交易锚定信息上传至所述服务端,以由所述服务端从区块链中获取所述交易事件。
可选的,还包括内容接收单元905或结果接收单元906;其中:
所述内容接收单元905用于使所述客户端接收所述服务端返回的所述交易事件的事件内容,以用于认证所述交易事件与所述待认证事件之间的一致性;
所述结果接收单元906用于使所述客户端接收所述服务端返回的内容认证结果,所述内容认证结果用于表明所述交易事件与所述待认证事件之间的一致性。
上述实施例阐明的系统、装置、模块或单元,具体可以由计算机芯片或实体实现,或者由具有某种功能的产品来实现。一种典型的实现设备为计算机,计算机的具体形式可以是个人计算机、膝上型计算机、蜂窝电话、相机电话、智能电话、个人数字助理、媒体播放器、导航设备、电子邮件收发设备、游戏控制台、平板计算机、可穿戴设备或者这些设备中的任意几种设备的组合。
在一个典型的配置中,计算机包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。
内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机 可读介质的示例。
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带、磁盘存储、量子存储器、基于石墨烯的存储介质或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。
还需要说明的是,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、商品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、商品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、商品或者设备中还存在另外的相同要素。
上述对本说明书特定实施例进行了描述。其它实施例在所附权利要求书的范围内。在一些情况下,在权利要求书中记载的动作或步骤可以按照不同于实施例中的顺序来执行并且仍然可以实现期望的结果。另外,在附图中描绘的过程不一定要求示出的特定顺序或者连续顺序才能实现期望的结果。在某些实施方式中,多任务处理和并行处理也是可以的或者可能是有利的。
在本说明书一个或多个实施例使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本说明书一个或多个实施例。在本说明书一个或多个实施例和所附权利要求书中所使用的单数形式的“一种”、“所述”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本说明书一个或多个实施例可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本说明书一个或多个实施例范围的情况下,第一信息也可以被称为第二信息,类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”可以被解释成为“在……时”或“当……时”或“响应于确定”。
以上所述仅为本说明书一个或多个实施例的较佳实施例而已,并不用以限制本说明书一个或多个实施例,凡在本说明书一个或多个实施例的精神和原则之内,所做的任何修改、等同替换、改进等,均应包含在本说明书一个或多个实施例保护的范围之内。
Claims (26)
- 一种认证方法,包括:服务端接收认证请求,所述认证请求由客户端针对待认证事件发起,所述待认证事件被声明为与指定对象相关;所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系,确定所述交易关联对象的实体身份,以用于认证所述指定对象是否为所述交易关联对象。
- 根据权利要求1所述的方法,所述服务端从区块链中获取与所述待认证事件相关的交易事件,包括:所述服务端获取交易锚定信息,所述交易锚定信息被声明为与所述待认证事件相关;所述服务端从区块链中获取所述交易锚定信息对应的交易事件,以作为与所述待认证事件相关的交易事件。
- 根据权利要求1或2所述的方法,还包括:所述服务端获取所述交易事件的事件内容,以用于认证所述交易事件与所述待认证事件之间的一致性;或者,所述服务端调用智能合约,所述智能合约用于认证所述交易事件与所述待认证事件之间的一致性。
- 根据权利要求1所述的方法,还包括:所述服务端认证所述指定对象是否为所述交易关联对象,以向所述客户端返回认证结果。
- 根据权利要求1所述的方法,还包括:所述服务端向所述客户端返回所述交易关联对象的实体身份和/或所述交易事件的事件内容。
- 根据权利要求1所述的方法,所述交易事件被所述交易关联对象发布至区块链;或者,在所述交易关联对象对所述交易事件签名后,所述交易事件被区别于所述交易关联对象的发布方发布至区块链。
- 根据权利要求6所述的方法,所述交易事件被所述发布方通过自身对应的区块链节点发布至区块链;或者,所述方法还包括:所述服务端接收所述发布方提交的所述交易事件,并通过自身对应的区块链节点将所述交易事件发布至区块链。
- 根据权利要求7所述的方法,还包括:所述服务端验证所述发布方与所述交易事件所包含的签名对应的交易关联对象之间是否存在预设关联关系;当存在所述预设关联关系时,所述服务端将所述交易事件发布至区块链。
- 根据权利要求8所述的方法,所述服务端验证所述发布方与所述交易事件所包含的签名对应的交易关联对象之间是否存在预设关联关系,包括:所述服务端查询所述发布方预先注册的数字身份;当所述发布方的数字身份是基于所述交易关联对象向所述发布方提供的签名而注册时,所述服务端判定存在所述预设关联关系。
- 一种认证方法,包括:客户端针对待认证事件向服务端发起认证请求,以指示所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;所述客户端接收所述交易关联对象的实体身份,以用于认证指定对象是否为所述交易关联对象,其中所述指定对象被声明为与所述待认证事件相关,且所述交易关联对象的实体身份由所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系而确定;或者,所述客户端接收所述服务端返回的身份认证结果,所述身份认证结果用于表明所述指定对象是否为所述交易关联对象。
- 根据权利要求10所述的方法,还包括:所述客户端识别与所述待认证事件相关联的条码图案,得到交易锚定信息;所述客户端将所述交易锚定信息上传至所述服务端,以由所述服务端从区块链中获取所述交易事件。
- 根据权利要求10所述的方法,还包括:所述客户端接收所述服务端返回的所述交易事件的事件内容,以用于认证所述交易事件与所述待认证事件之间的一致性;或者,所述客户端接收所述服务端返回的内容认证结果,所述内容认证结果用于表明所述交易事件与所述待认证事件之间的一致性。
- 一种认证装置,包括:请求接收单元,使服务端接收认证请求,所述认证请求由客户端针对待认证事件发 起,所述待认证事件被声明为与指定对象相关;事件获取单元,使所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;身份确定单元,使所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系,确定所述交易关联对象的实体身份,以用于认证所述指定对象是否为所述交易关联对象。
- 根据权利要求13所述的装置,所述事件获取单元具体用于:使所述服务端获取交易锚定信息,所述交易锚定信息被声明为与所述待认证事件相关;使所述服务端从区块链中获取所述交易锚定信息对应的交易事件,以作为与所述待认证事件相关的交易事件。
- 根据权利要求13或14所述的装置,还包括内容获取单元或合约调用单元;其中:所述内容获取单元用于使所述服务端获取所述交易事件的事件内容,以用于认证所述交易事件与所述待认证事件之间的一致性;所述合约调用单元用于使所述服务端调用智能合约,所述智能合约用于认证所述交易事件与所述待认证事件之间的一致性。
- 根据权利要求13所述的装置,还包括:认证单元,使所述服务端认证所述指定对象是否为所述交易关联对象,以向所述客户端返回认证结果。
- 根据权利要求13所述的装置,还包括:返回单元,使所述服务端向所述客户端返回所述交易关联对象的实体身份和/或所述交易事件的事件内容。
- 根据权利要求13所述的装置,所述交易事件被所述交易关联对象发布至区块链;或者,在所述交易关联对象对所述交易事件签名后,所述交易事件被区别于所述交易关联对象的发布方发布至区块链。
- 根据权利要求18所述的装置,所述交易事件被所述发布方通过自身对应的区块链节点发布至区块链;或者,所述装置还包括:发布单元,使所述服务端接收所述发布方提交的所述交易事件,并通过自身对应的区块链节点将所述交易事件发布至区块链。
- 根据权利要求19所述的装置,还包括:验证单元,使所述服务端验证所述发布方与所述交易事件所包含的签名对应的交易关联对象之间是否存在预设关联关系;当存在所述预设关联关系时,所述发布单元使所述服务端将所述交易事件发布至区块链。
- 根据权利要求20所述的装置,所述验证单元具体用于:使所述服务端查询所述发布方预先注册的数字身份;当所述发布方的数字身份是基于所述交易关联对象向所述发布方提供的签名而注册时,使所述服务端判定存在所述预设关联关系。
- 一种认证装置,包括:请求单元,使客户端针对待认证事件向服务端发起认证请求,以指示所述服务端从区块链中获取与所述待认证事件相关的交易事件,所述交易事件由交易关联对象通过预先注册的数字身份进行签名;身份接收单元,使所述客户端接收所述交易关联对象的实体身份,以用于认证指定对象是否为所述交易关联对象,其中所述指定对象被声明为与所述待认证事件相关,且所述交易关联对象的实体身份由所述服务端根据所述交易事件的签名、预先记录的各个对象的实体身份与数字身份之间的映射关系而确定;或者,所述客户端接收所述服务端返回的身份认证结果,所述身份认证结果用于表明所述指定对象是否为所述交易关联对象。
- 根据权利要求22所述的装置,还包括:识别单元,使所述客户端识别与所述待认证事件相关联的条码图案,得到交易锚定信息;上传单元,使所述客户端将所述交易锚定信息上传至所述服务端,以由所述服务端从区块链中获取所述交易事件。
- 根据权利要求22所述的装置,还包括内容接收单元或结果接收单元;其中:所述内容接收单元用于使所述客户端接收所述服务端返回的所述交易事件的事件内容,以用于认证所述交易事件与所述待认证事件之间的一致性;所述结果接收单元用于使所述客户端接收所述服务端返回的内容认证结果,所述内容认证结果用于表明所述交易事件与所述待认证事件之间的一致性。
- 一种电子设备,包括:处理器;用于存储处理器可执行指令的存储器;其中,所述处理器通过运行所述可执行指令以实现如权利要求1-9中任一项所述的方法。
- 一种电子设备,包括:处理器;用于存储处理器可执行指令的存储器;其中,所述处理器通过运行所述可执行指令以实现如权利要求10-12中任一项所述的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201811258195.4 | 2018-10-26 | ||
| CN201811258195.4A CN109327312B (zh) | 2018-10-26 | 2018-10-26 | 认证方法及装置、电子设备 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020082886A1 true WO2020082886A1 (zh) | 2020-04-30 |
Family
ID=65261732
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2019/102816 Ceased WO2020082886A1 (zh) | 2018-10-26 | 2019-08-27 | 认证方法及装置、电子设备 |
Country Status (3)
| Country | Link |
|---|---|
| CN (2) | CN109327312B (zh) |
| TW (1) | TW202016833A (zh) |
| WO (1) | WO2020082886A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113656497A (zh) * | 2021-08-06 | 2021-11-16 | 支付宝(杭州)信息技术有限公司 | 一种基于区块链的数据验证方法和装置 |
Families Citing this family (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109327312B (zh) * | 2018-10-26 | 2020-03-24 | 阿里巴巴集团控股有限公司 | 认证方法及装置、电子设备 |
| CN109978551A (zh) * | 2019-03-29 | 2019-07-05 | 北京投肯科技有限公司 | 一种基于区块链的账户信息确认及找回方法以及装置 |
| CN110086626B (zh) * | 2019-04-22 | 2023-05-05 | 如般量子科技有限公司 | 基于非对称密钥池对的量子保密通信联盟链交易方法和系统 |
| CN110599190B (zh) * | 2019-09-27 | 2022-10-21 | 支付宝(杭州)信息技术有限公司 | 基于区块链的身份认证方法以及装置 |
| CN113542288B (zh) * | 2019-10-11 | 2023-06-30 | 支付宝(杭州)信息技术有限公司 | 业务授权方法、装置、设备及系统 |
| CN111010395B (zh) * | 2019-12-17 | 2021-09-24 | 支付宝(杭州)信息技术有限公司 | 基于信用的信息标识生成方法及装置 |
| CN113704712B (zh) * | 2020-05-21 | 2024-11-19 | 北京金山云网络技术有限公司 | 身份认证方法、装置、系统和电子设备 |
| CN113807700B (zh) * | 2021-09-18 | 2023-10-27 | 厦门大学 | 基于区块链的飞机在翼指挥调度发布、接收方法及系统 |
| CN116264691A (zh) * | 2021-12-14 | 2023-06-16 | 中国移动通信有限公司研究院 | 认证方法、装置、认证平台和存储介质 |
| CN114925341B (zh) * | 2022-03-18 | 2025-10-31 | 度小满科技(北京)有限公司 | 实体身份管理和信用评估方法、装置、设备及存储介质 |
| TWI875371B (zh) * | 2023-12-12 | 2025-03-01 | 事必得科技有限公司 | 電子名片驗證系統 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106384236A (zh) * | 2016-08-31 | 2017-02-08 | 江苏通付盾科技有限公司 | 基于区块链的ca认证管理方法、装置及系统 |
| WO2017051250A1 (en) * | 2015-09-25 | 2017-03-30 | Assa Abloy Ab | Virtual credentials and licenses |
| CN107079037A (zh) * | 2016-09-18 | 2017-08-18 | 深圳前海达闼云端智能科技有限公司 | 基于区块链的身份认证方法、装置、节点及系统 |
| CN107086909A (zh) * | 2017-03-07 | 2017-08-22 | 阿里巴巴集团控股有限公司 | 身份信息的生成方法和装置、身份审核的方法和装置 |
| CN108416588A (zh) * | 2018-02-14 | 2018-08-17 | 北京三六五八网络科技有限公司 | 用于电子交易认证的数据处理方法及装置 |
| CN109327312A (zh) * | 2018-10-26 | 2019-02-12 | 阿里巴巴集团控股有限公司 | 认证方法及装置、电子设备 |
Family Cites Families (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9858569B2 (en) * | 2014-03-21 | 2018-01-02 | Ramanan Navaratnam | Systems and methods in support of authentication of an item |
| WO2017218986A1 (en) * | 2016-06-16 | 2017-12-21 | The Bank Of New York Mellon | Managing verifiable, cryptographically strong transactions |
| CN106845210A (zh) * | 2017-01-19 | 2017-06-13 | 布比(北京)网络技术有限公司 | 事件认证方法和装置 |
| CN111880746A (zh) * | 2017-05-25 | 2020-11-03 | 创新先进技术有限公司 | 一种向区块链系统中写入业务数据的方法和装置 |
| CN107257340B (zh) * | 2017-06-19 | 2019-10-01 | 阿里巴巴集团控股有限公司 | 一种认证方法、基于区块链的认证数据处理方法及设备 |
| CN107742212B (zh) * | 2017-10-13 | 2021-01-01 | 深圳怡化电脑股份有限公司 | 基于区块链的资产验证方法、装置及系统 |
| CN108123936B (zh) * | 2017-12-13 | 2021-04-13 | 北京科技大学 | 一种基于区块链技术的访问控制方法及系统 |
| CN108573741A (zh) * | 2017-12-25 | 2018-09-25 | 北京金山云网络技术有限公司 | 业务数据记录方法、装置、设备和存储介质 |
| CN108183801B (zh) * | 2017-12-29 | 2023-04-25 | 苏州朗润创新知识产权运营有限公司 | 一种业务认证方法、系统和计算机可读存储介质 |
| CN108234135B (zh) * | 2017-12-29 | 2021-02-26 | 苏州朗润创新知识产权运营有限公司 | 一种业务认证方法、系统和计算机可读存储介质 |
| CN108111543B (zh) * | 2018-02-06 | 2020-08-04 | 上海冲量网络科技有限公司 | 一种区块链上的数字身份识别系统 |
| CN108520462B (zh) * | 2018-03-30 | 2020-07-24 | 阿里巴巴集团控股有限公司 | 基于区块链的业务执行方法及装置、电子设备 |
| CN108667618B (zh) * | 2018-05-10 | 2020-07-03 | 阿里巴巴集团控股有限公司 | 区块链成员管理的数据处理方法、装置、服务器及系统 |
-
2018
- 2018-10-26 CN CN201811258195.4A patent/CN109327312B/zh active Active
- 2018-10-26 CN CN202010393386.2A patent/CN111600716B/zh active Active
-
2019
- 2019-03-20 TW TW108109552A patent/TW202016833A/zh unknown
- 2019-08-27 WO PCT/CN2019/102816 patent/WO2020082886A1/zh not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2017051250A1 (en) * | 2015-09-25 | 2017-03-30 | Assa Abloy Ab | Virtual credentials and licenses |
| CN106384236A (zh) * | 2016-08-31 | 2017-02-08 | 江苏通付盾科技有限公司 | 基于区块链的ca认证管理方法、装置及系统 |
| CN107079037A (zh) * | 2016-09-18 | 2017-08-18 | 深圳前海达闼云端智能科技有限公司 | 基于区块链的身份认证方法、装置、节点及系统 |
| CN107086909A (zh) * | 2017-03-07 | 2017-08-22 | 阿里巴巴集团控股有限公司 | 身份信息的生成方法和装置、身份审核的方法和装置 |
| CN108416588A (zh) * | 2018-02-14 | 2018-08-17 | 北京三六五八网络科技有限公司 | 用于电子交易认证的数据处理方法及装置 |
| CN109327312A (zh) * | 2018-10-26 | 2019-02-12 | 阿里巴巴集团控股有限公司 | 认证方法及装置、电子设备 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113656497A (zh) * | 2021-08-06 | 2021-11-16 | 支付宝(杭州)信息技术有限公司 | 一种基于区块链的数据验证方法和装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN111600716A (zh) | 2020-08-28 |
| TW202016833A (zh) | 2020-05-01 |
| CN111600716B (zh) | 2023-09-29 |
| CN109327312B (zh) | 2020-03-24 |
| CN109327312A (zh) | 2019-02-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020082886A1 (zh) | 认证方法及装置、电子设备 | |
| CN108665946B (zh) | 一种业务数据的访问方法和装置 | |
| US11139976B2 (en) | System and method, which using blockchain and mobile devices, provides the validated and authenticated identity of an individual to a valid and authenticated requestor | |
| US11645632B2 (en) | System and method for a decentralized portable information container supporting privacy protected digital information credentialing, remote administration, local validation, access control and remote instruction signaling utilizing blockchain distributed ledger and container wallet technologies | |
| JP7187532B2 (ja) | 電子文書を締結して配送するためのシステム及び方法 | |
| TWI728678B (zh) | 基於區塊鏈的企業認證、認證追溯方法、裝置及設備 | |
| US10902425B2 (en) | System and method for biometric credit based on blockchain | |
| US20210327008A1 (en) | Systems and methods for automated will creation, verification of beneficiaries, and passing assets through a borderless fintech ecosystem | |
| WO2020119286A1 (zh) | 基于区块链的发票创建方法及装置、电子设备 | |
| US20200092102A1 (en) | Secure biometric authentication using electronic identity | |
| US11171781B2 (en) | System and method which using blockchain protects the privacy of access code and the identity of an individual seeking online access | |
| CN114884674B (zh) | 一种基于区块链的用户数据流转方法、装置及设备 | |
| CN107636662A (zh) | 网络内容认证 | |
| CN113434849B (zh) | 一种基于可信硬件的数据管理方法、装置及设备 | |
| US12373533B2 (en) | Method and system for digital identity and transaction verification | |
| Boonkrong | Design of an academic document forgery detection system | |
| CN110969531A (zh) | 借款存证、在线查证方法及其系统 | |
| CN112287311A (zh) | 一种基于区块链的业务实现方法和装置 | |
| CN114240399A (zh) | 基于区块链平台的政务数据处理方法及系统 | |
| CN112507370A (zh) | 一种基于区块链网络的电子证照核验方法 | |
| CN112052434A (zh) | 电子文件的验证方法、装置、电子设备及可读存储介质 | |
| US20250139611A1 (en) | System and Methods for Implementing Blockchain Based Zero Knowledge Protocol | |
| CN112766755A (zh) | 一种业务处理方法、装置、设备及介质 | |
| HK40035929B (zh) | 认证方法及装置、电子设备 | |
| NL2038183B1 (en) | Method, system, and device for property transaction management involving distributed ledger technologies |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19876449 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 19876449 Country of ref document: EP Kind code of ref document: A1 |