节点文献
按需披露的区块链数字身份认证机制DCIdentity
DCIdentity: on-demand disclosure blockchain digital identity authentication mechanism
【摘要】 针对现有分布式数字身份(DID)认证方案中,可验证声明(VC)在链下客户端明文存储导致的用户与客户端强耦合和隐私安全易受威胁的问题,提出一种按需披露的区块链数字身份认证机制DCIdentity。首先,基于万维网联盟去中心化标识标准(W3C DID),将用户身份的VC在链上加密存储,降低用户对客户端的依赖,实现认证过程与客户端的松耦合;然后,设计VC分层加密机制支持用户信息的按需披露,提升多主体认证效率并降低相关开销。实验结果表明,与链下存储方案相比,所提机制有效降低了客户端与用户身份认证过程的耦合程度,同时实现了用户身份信息的按需披露;与密文策略属性基加密(CP-ABE)方案相比,所提机制的加密处理时延与链上存储开销分别降低了91.5%和84.1%。可见,所提机制为多领域、多应用场景下的身份统一认证提供了高效解决方案,在保障用户信息隐私的同时,显著提高了认证效率,可有力支撑DID在实际场景中的落地应用。
【Abstract】 To solve the problems of strong coupling between users and clients and the vulnerability of privacy security due to the plaintext storage of Verifiable Credentials(VCs) in the off-chain clients in the existing Decentralized IDentity(DID) authentication schemes, an on-demand disclosure blockchain digital identity authentication mechanism was proposed, namely DCIdentity. Firstly, based on the World Wide Web Consortium Decentralized IDentifier(W3C DID), user identities’ VCs were encrypted and stored on the blockchain, which reduced users’ dependency on clients and realized loose coupling between the authentication process and the clients. Secondly, a hierarchical encryption mechanism for VCs was designed to support on-demand disclosure of user information, which enhanced efficiency in multi-party authentication and reduced the associated overhead. Experimental results show that compared with the off-chain storage scheme, the proposed mechanism reduces the degree of coupling between the clients and the user authentication process effectively, and achieves the on-demand disclosure of user identity information; compared with the Ciphertext-Policy Attribute-Based Encryption(CP-ABE) scheme, the proposed mechanism has the encryption processing delay and the on-chain storage overhead decreased by 91. 5% and 84. 1%, respectively. It can be seen that the proposed mechanism provides an efficient solution for unified identity authentication in multi-domain multi-application scenarios, which improves the authentication efficiency significantly while ensuring the privacy of user information, and can support the landing application of DID in actual scenarios strongly.
【Key words】 Decentralized IDentity (DID); client-side loose coupling; on-demand disclosure; Ciphertext-Policy Attribute-Based Encryption(CP-ABE); identity authentication;
- 【文献出处】 计算机应用 ,Journal of Computer Applications , 编辑部邮箱 ,2026年04期
- 【分类号】TP311.13;TP309
- 【下载频次】265