This invention discloses a cross-domain
authentication method for trusted data spaces based on digital certificates, belonging to the field of trusted
data space authentication technology. The method includes S1, constructing a trusted
data space cross-domain
authentication system; S2,
system initialization; S3, trusted
data space and user registration; S4, intra-domain two-way authentication between the trusted data space and the user; and S5, cross-domain authentication and key negotiation between the trusted data space and the user. This invention combines a lightweight
algorithm to achieve lightweight intra-domain authentication and secure cross-domain communication. Addressing the
single point of failure problem in traditional authentication, it designs a
blockchain distributed
verification mechanism to avoid the risk of
system paralysis by a centralized trusted party. During the authentication process, the identity information of the trusted data space and the user is anonymized through pseudo-identity and hash
processing. Simultaneously, location privacy and communication security are protected through timestamps and digital signatures. The
blockchain stores a permission table, simplifying the cross-domain
verification steps for authenticated entities and reducing system computation and communication costs.