Security authentication method, system and device for distributed network and medium
By generating device public and private keys in a distributed network to construct public key certificates and authentication ciphertexts, the problem of cumbersome device authentication process is solved and the efficiency of device authentication is improved.
Patent Information
- Application Number
- CN202510689307.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-05
AI Technical Summary
In a distributed network, the device authentication process is cumbersome and the authentication efficiency is low.
The device to be authenticated generates a device public key and private key in a trusted execution environment, constructs a public key certificate and authentication ciphertext, and transmits them to distributed connected devices through a distributed network bus for authentication, thereby simplifying the device authentication process.
While ensuring the security of device authentication, the process of server searching for peripheral devices is simplified, and the efficiency of device authentication is improved.
Smart Images

Figure CN120602094A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security authentication technology, and in particular to a distributed network security authentication method, system, equipment and medium. Background Art
[0002] A distributed network is a network architecture formed by multiple independent nodes (such as servers, computers or IoT devices) interconnected through communication protocols. Among them, device security authentication is a crucial link in the distributed network.
[0003] At present, the relevant technology usually uses the server's search interface to discover surrounding devices in a distributed network, and after discovering untrusted devices in the surrounding area, it authenticates the untrusted devices by calling the authentication device interface. This method is more cumbersome in the device authentication process between the discovery end and the discovered end during the authentication process, and the device authentication efficiency is low.
[0004] Therefore, the problems existing in related technologies still need to be solved and optimized urgently. Summary of the Invention
[0005] The purpose of the present invention is to solve one of the technical problems existing in the related art to at least a certain extent.
[0006] To this end, an object of an embodiment of the present invention is to provide a distributed network security authentication method, system, device and medium, wherein the method can effectively improve the security authentication efficiency of distributed devices.
[0007] In order to achieve the above technical objectives, the technical solutions adopted in the embodiments of the present application include:
[0008] In a first aspect, an embodiment of the present application provides a distributed network security authentication method, applied to a device to be authenticated, the method comprising:
[0009] Obtain authentication communication data and generate a device public key and a device private key using a random number generator in a trusted execution environment;
[0010] Performing certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate;
[0011] Performing ciphertext generation processing on the authentication communication data according to the device private key to obtain authentication ciphertext;
[0012] The public key certificate and the authentication ciphertext are sent to at least one distributed connection device via a bus of a distributed network, so that at least one distributed connection device performs device authentication on the authentication ciphertext according to the public key certificate, and obtains a device authentication result returned by the distributed connection device.
[0013] In addition, the method according to the above embodiment of the present application may also have the following additional technical features:
[0014] Furthermore, in one embodiment of the present application, performing certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate includes:
[0015] Obtain device identity information based on authentication communication data;
[0016] Performing a signature request construction process on the device identity information according to the device public key and the device private key to obtain a certificate signature request file;
[0017] The certificate signing request file is sent to a trusted certificate authority device, so that the trusted certificate authority device performs authorized signature on the certificate signing request file, and obtains a public key certificate returned by the trusted certificate authority device.
[0018] Furthermore, in one embodiment of the present application, performing ciphertext generation processing on the authentication communication data according to the device private key to obtain the authentication ciphertext includes:
[0019] Dividing the authentication communication data into data intervals to obtain a plurality of interval data;
[0020] Randomly sorting all the interval data to obtain messy data corresponding to each of the interval data;
[0021] All the messy data are encrypted with a key according to the device private key to obtain the authentication ciphertext.
[0022] In a second aspect, an embodiment of the present application provides a distributed network security authentication method, which is applied to a distributed connection device, and the method includes:
[0023] Receiving a public key certificate and authentication ciphertext sent by the device to be authenticated via a bus of a distributed network;
[0024] Performing device authentication on the authentication ciphertext according to the public key certificate to obtain a device authentication result;
[0025] The public key certificate and the authentication ciphertext are obtained by the following steps:
[0026] The device to be authenticated obtains authentication communication data and generates a device public key and a device private key using a random number generator in a trusted execution environment;
[0027] The device to be authenticated performs certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain the public key certificate;
[0028] The device to be authenticated performs ciphertext generation processing on the authentication communication data according to the device private key to obtain the authentication ciphertext.
[0029] Furthermore, in one embodiment of the present application, performing device authentication on the authentication ciphertext according to the public key certificate to obtain a device authentication result includes:
[0030] Obtaining a device public key according to the public key certificate;
[0031] Decrypting the authentication ciphertext according to the device public key to obtain authentication plaintext;
[0032] Performing plaintext analysis on the authentication plaintext to obtain plaintext data;
[0033] According to the plaintext data, the messy data in the authentication ciphertext is compared and authenticated to obtain the device authentication result.
[0034] Furthermore, in one embodiment of the present application, performing plaintext analysis on the authentication plaintext to obtain plaintext data includes:
[0035] Performing image generation processing on the authentication plaintext to obtain a plaintext image;
[0036] Inputting the plaintext image into a trained code line detection model to perform code line detection, obtaining a plurality of line region coordinates output by the trained code line detection model, wherein the line region coordinates are used to represent region coordinates of code lines in the plaintext image;
[0037] performing region segmentation processing on the plaintext image according to all the row region coordinates to obtain a plaintext region block corresponding to each row region coordinate;
[0038] All the plaintext area blocks are input into a trained text recognition model for recognition, and the plaintext data output by the trained text recognition model are obtained.
[0039] Furthermore, in one embodiment of the present application, comparing and authenticating the messy data in the authentication ciphertext based on the plaintext data to obtain the device authentication result includes:
[0040] Comparing the code text in the messy data with the code text in the plaintext data to obtain a code text comparison result;
[0041] If the code text comparison result is a successful comparison, the device to be authenticated is authenticated to obtain the device authentication result; or, if the code text comparison result is a failed comparison, the process returns to the step of receiving the public key certificate and authentication ciphertext sent by the device to be authenticated through the bus of the distributed network.
[0042] In a third aspect, an embodiment of the present application provides a distributed network security authentication system, which is applied to a device to be authenticated. The system includes:
[0043] a first processing unit, configured to obtain authentication communication data and generate a device public key and a device private key using a random number generator in a trusted execution environment;
[0044] a second processing unit, configured to perform certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate;
[0045] a third processing unit, configured to perform ciphertext generation processing on the authentication communication data according to the device private key to obtain an authentication ciphertext;
[0046] The fourth processing unit is used to send the public key certificate and the authentication ciphertext to at least one distributed connection device through the bus of the distributed network, so that at least one of the distributed connection devices performs device authentication on the authentication ciphertext according to the public key certificate, and obtains the device authentication result returned by the distributed connection device.
[0047] In a fourth aspect, an embodiment of the present application further provides an electronic device, including:
[0048] at least one processor;
[0049] at least one memory for storing at least one program;
[0050] When the at least one program is executed by the at least one processor, the at least one processor implements the above method.
[0051] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores a program executable by a processor, and the program executable by the processor is used to implement the above method when executed by the processor.
[0052] The advantages and benefits of this application will be partially given in the following description, and partially become apparent from the following description, or learned through practice of this application:
[0053] The embodiments of the present application disclose a method, system, device and medium for secure authentication of a distributed network, wherein the method obtains authentication communication data and uses a random number generator to generate a device public key and a device private key in a trusted execution environment; performs certificate generation processing on the authentication communication data based on the device public key and the device private key to obtain a public key certificate; performs ciphertext generation processing on the authentication communication data based on the device private key to obtain an authentication ciphertext; and sends the public key certificate and the authentication ciphertext to at least one distributed connection device via a bus of a distributed network, so that at least one distributed connection device performs device authentication on the authentication ciphertext based on the public key certificate, and obtains a device authentication result returned by the distributed connection device. The method generates a device public key and a device private key using a random number generator in a trusted execution environment by the device to be authenticated, and transmits the public key certificate and the authentication ciphertext constructed based on the device public key and the device private key to the distributed connection device via a distributed bus for device authentication. While ensuring the security of device authentication, the method simplifies the process of the server searching for peripheral devices during device authentication, effectively improving the efficiency of device authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following introduction is made to the drawings of the embodiments of the present application or the related technical solutions in the prior art. It should be understood that the drawings introduced below are only for the convenience of clearly expressing some embodiments of the technical solutions of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without any creative work.
[0055] Figure 1 A schematic diagram of a distributed network security authentication method provided in an embodiment of the present application;
[0056] Figure 2 A schematic diagram of the structural framework of a distributed network security authentication system provided in an embodiment of the present application;
[0057] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0058] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application and are not to be construed as limiting the present application. For the step numbers in the following embodiments, they are provided only for the convenience of explanation and are not intended to limit the order of the steps. The order of execution of the steps in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0059] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0060] At present, the relevant technology usually uses the server's search interface to discover surrounding devices in a distributed network, and after discovering untrusted devices in the surrounding area, it authenticates the untrusted devices by calling the authentication device interface. This method is more cumbersome in the device authentication process between the discovery end and the discovered end during the authentication process, and the device authentication efficiency is low.
[0061] In view of this, an embodiment of the present invention provides a distributed network security authentication method, system, device and medium, wherein the method uses a random number generator to generate a device public key and a device private key in a trusted execution environment by the device to be authenticated, and transmits the public key certificate and authentication ciphertext constructed based on the device public key and the device private key to the distributed connection device through a distributed bus for device authentication. While ensuring the security of device authentication, this method simplifies the server's search for peripheral devices and the device authentication process in which the server calls the authentication device interface to authenticate untrusted devices, thereby effectively improving the efficiency of device authentication.
[0062] In addition, the method uses distributed devices connected to a distributed network to authenticate the device to be authenticated. Specifically, the distributed connection device uses the code text in the plaintext data to compare the code text in the authentication ciphertext messy data, and provides authentication services for the device to be authenticated based on the code text comparison results. It can simplify the device authentication process of the server calling the authentication device interface to authenticate the identity of an untrusted device, and further improve the efficiency of device authentication.
[0063] Reference Figure 1 In an embodiment of the present application, a distributed network security authentication method is applied to a device to be authenticated, and the method includes:
[0064] Step 110: Obtain authentication communication data and generate a device public key and a device private key using a random number generator in a trusted execution environment;
[0065] In an embodiment of the present application, the authentication communication data may be the communication data used by the device to be authenticated for device security authentication, which may specifically include the device identity information of the device to be authenticated and the user name, password and other information entered by the user on the device to be authenticated, wherein the device identity information includes the device ID, serial number, organization name, etc. of the device to be authenticated.
[0066] It is understandable that the device to be authenticated can start the key generation process in a trusted execution environment (such as ARM TrustZone, Intel SGX), specifically by using a hardware random number generator or a true random number generator in the trusted execution environment to collect physical noise (such as thermal noise, circuit jitter noise) as a key seed, and then generate two large prime numbers based on the large number decomposition problem, and calculate the device public key and device private key of the device to be authenticated based on modulus calculation and / or Euler function.
[0067] Step 120: Perform certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate;
[0068] In an embodiment of the present application, before the device to be authenticated performs device authentication with the distributed connection device, the device can use the device public key and the device private key to generate a public key certificate corresponding to the authentication communication data.
[0069] In some embodiments, performing certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate includes:
[0070] Obtain device identity information based on authentication communication data;
[0071] Performing a signature request construction process on the device identity information according to the device public key and the device private key to obtain a certificate signature request file;
[0072] The certificate signing request file is sent to a trusted certificate authority device, so that the trusted certificate authority device performs authorized signature on the certificate signing request file, and obtains a public key certificate returned by the trusted certificate authority device.
[0073] In an embodiment of the present application, the device to be authenticated can first obtain the device identity information in the authentication communication data and bind the device identity information with the device public key; then use the device private key to sign the bound device identity information and device public key to obtain the original signature data of the device to be authenticated, and encapsulate the original signature data, device identity information and device public key into a certificate request file (CSR) format, thereby completing the signature request construction process and obtaining a certificate signature request file.
[0074] It can be understood that after obtaining the certificate signing request file, the device to be authenticated can send the certificate signing request file to a trusted certificate authorization device through an encrypted HTTP secure channel. The trusted certificate authorization device can specifically be an authorized device of a certificate issuing agency (Certificate Authority, CA); then, the trusted certificate authorization device uses its private key to sign the certificate signing request file to generate a public key certificate, and returns the public key certificate to the device to be authenticated through the MQTT protocol.
[0075] Step 130: Perform ciphertext generation processing on the authentication communication data according to the device private key to obtain authentication ciphertext;
[0076] In an embodiment of the present application, before the device to be authenticated performs device authentication with the distributed connection device, the device can use the device private key to encrypt the authentication communication data to generate an authentication ciphertext.
[0077] In some embodiments, the ciphertext generation processing of the authentication communication data according to the device private key to obtain the authentication ciphertext includes:
[0078] Dividing the authentication communication data into data intervals to obtain a plurality of interval data;
[0079] Randomly sorting all the interval data to obtain messy data corresponding to each of the interval data;
[0080] All the messy data are encrypted with a key according to the device private key to obtain the authentication ciphertext.
[0081] In an embodiment of the present application, the data to be authenticated can divide the authentication communication data into several interval data. Specifically, in the first embodiment, the authentication communication data can be divided based on a preset data interval size to obtain several interval data; or, in the second embodiment, the authentication communication data can be evenly divided according to the required number of interval data to obtain several interval data.
[0082] It is understood that for any interval of data, random bit sorting can be performed by generating a random operator based on a random algorithm, which has the same number of bits as the data interval. The bits in the data interval are then sorted based on the random operator to obtain the randomly sorted interval data, which is recorded as the scrambled data. The device to be authenticated then encrypts the scrambled data using the device's private key to generate the authentication ciphertext.
[0083] Step 140: Send the public key certificate and the authentication ciphertext to at least one distributed connection device through the bus of the distributed network, so that at least one distributed connection device performs device authentication on the authentication ciphertext according to the public key certificate, and obtains the device authentication result returned by the distributed connection device.
[0084] In an embodiment of the present application, a distributed connection is established between a distributed connection device and a device to be authenticated via a distributed soft bus. Specifically, after generating an authentication ciphertext and a public key certificate, the device to be authenticated can send the public key certificate and authentication ciphertext via the distributed bus to at least one distributed connection device connected to the device to be authenticated. The at least one distributed connection device then compares the authentication ciphertext with the public key certificate. If the comparison passes, authentication services are provided to the device to be authenticated, and the generated device authentication result is returned to the device to be authenticated via the bus of the distributed network.
[0085] The device authentication result is returned to the device to be authenticated through the bus of the distributed network.
[0086] A distributed network security authentication method proposed in an embodiment of the present application is applied to a distributed connection device, the method comprising:
[0087] Step 150: Receive the public key certificate and authentication ciphertext sent by the device to be authenticated via the bus of the distributed network;
[0088] Step 160: Perform device authentication on the authentication ciphertext according to the public key certificate to obtain a device authentication result;
[0089] In the embodiment of the present application, the contents of steps 150 to 160 are similar to the contents of the aforementioned step 140 and can be simply deduced by analogy, so the present application will not elaborate on them here.
[0090] In some embodiments, performing device authentication on the authentication ciphertext according to the public key certificate to obtain a device authentication result includes:
[0091] Obtaining a device public key according to the public key certificate;
[0092] Decrypting the authentication ciphertext according to the device public key to obtain authentication plaintext;
[0093] In an embodiment of the present application, after receiving the public key certificate of the device to be authenticated, the distributed connection device can parse the public key certificate to extract the device public key of the device to be authenticated in the public key certificate, and then use the device public key to decrypt the authentication ciphertext to obtain the authentication ciphertext after public key decryption, which is recorded as authentication plaintext.
[0094] Performing plaintext analysis on the authentication plaintext to obtain plaintext data;
[0095] Furthermore, the performing plaintext analysis on the authentication plaintext to obtain plaintext data includes:
[0096] Performing image generation processing on the authentication plaintext to obtain a plaintext image;
[0097] Inputting the plaintext image into a trained code line detection model to perform code line detection, obtaining a plurality of line region coordinates output by the trained code line detection model, wherein the line region coordinates are used to represent region coordinates of code lines in the plaintext image;
[0098] performing region segmentation processing on the plaintext image according to all the row region coordinates to obtain a plaintext region block corresponding to each row region coordinate;
[0099] All the plaintext area blocks are input into a trained text recognition model for recognition, and the plaintext data output by the trained text recognition model are obtained.
[0100] In an embodiment of the present application, the image generation process can be a distributed connection device calling an automation structure to take a screenshot of the authentication plaintext to generate an image of the authentication plaintext, which is recorded as a plaintext image; then the code line area in the plaintext image is subjected to target detection through a trained code line detection model to obtain the line area coordinates of each code line area in the plaintext image, wherein the trained code line detection model can be any one of the yolo series models, CNN models, etc., which will not be repeated in this application.
[0101] It is understandable that for any row region coordinate, the region corresponding to the plaintext image can be cropped and segmented based on the row region coordinate to obtain the plaintext image block under the row region coordinate, which is recorded as the plaintext region block. The plaintext region blocks under the remaining row region coordinates are similarly derived by analogy. The trained text recognition model can be a hybrid model based on deep learning, which can specifically be composed of a convolutional neural network (CNN) and a long short-term memory (LSTM) network. The trained text recognition model is used to recognize the code text within each plaintext region block to obtain plaintext data consisting of the code text within all plaintext region blocks, that is, the plaintext data records all the code text of the authentication plaintext.
[0102] According to the plaintext data, the messy data in the authentication ciphertext is compared and authenticated to obtain the device authentication result.
[0103] Furthermore, comparing and authenticating the messy data in the authentication ciphertext based on the plaintext data to obtain the device authentication result includes:
[0104] Comparing the code text in the messy data with the code text in the plaintext data to obtain a code text comparison result;
[0105] If the code text comparison result is a successful comparison, the device to be authenticated is authenticated to obtain the device authentication result; or, if the code text comparison result is a failed comparison, the process returns to the step of receiving the public key certificate and authentication ciphertext sent by the device to be authenticated through the bus of the distributed network.
[0106] In an embodiment of the present application, the distributed connection device can first obtain the messy data and compare each code text in the plaintext data with each code text in the messy data. Specifically, if each code text in the plaintext data has a corresponding code text in the messy data, and the number of code texts in the messy data is the same as the number of code texts in the plaintext data, a code text comparison result representing a successful comparison can be generated, and the distributed device provides authentication services for the device to be authenticated, thereby obtaining a device authentication result for the device to be authenticated; or, if at least one code text in the plaintext data does not have a corresponding code text in the messy data, and / or, at least one code text in the messy data does not have a corresponding code text in the plaintext data, a device authentication result representing a failed comparison can be generated, and at this time, step 150 can be returned to wait for the next device authentication process of the device to be authenticated.
[0107] The public key certificate and the authentication ciphertext are obtained by the following steps:
[0108] Step 170: The device to be authenticated obtains authentication communication data and generates a device public key and a device private key using a random number generator in a trusted execution environment.
[0109] Step 180: The device to be authenticated performs certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain the public key certificate;
[0110] Step 190: The device to be authenticated performs ciphertext generation processing on the authentication communication data according to the device private key to obtain the authentication ciphertext.
[0111] In the embodiment of the present application, the contents of steps 170 to 190 are similar to the contents of the aforementioned steps 110 to 130 and can be simply deduced by analogy, so the present application will not elaborate on them here.
[0112] A distributed network security authentication system proposed according to an embodiment of the present application is described in detail below with reference to the accompanying drawings.
[0113] Reference Figure 2A distributed network security authentication system proposed in an embodiment of the present application is applied to a device to be authenticated, and the system includes:
[0114] The first processing unit 101 is configured to obtain authentication communication data and generate a device public key and a device private key using a random number generator in a trusted execution environment;
[0115] The second processing unit 102 is configured to perform certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate;
[0116] The third processing unit 103 is configured to perform ciphertext generation processing on the authentication communication data according to the device private key to obtain an authentication ciphertext;
[0117] The fourth processing unit 104 is used to send the public key certificate and the authentication ciphertext to at least one distributed connection device through the bus of the distributed network, so that at least one of the distributed connection devices performs device authentication on the authentication ciphertext according to the public key certificate, and obtains the device authentication result returned by the distributed connection device.
[0118] It can be understood that the contents of the above method embodiments are all applicable to the present system embodiments, the functions specifically implemented by the present system embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0119] Reference Figure 3 , an embodiment of the present application further provides an electronic device, including:
[0120] at least one processor 201;
[0121] At least one memory 202, configured to store at least one program;
[0122] When the at least one program is executed by the at least one processor 201 , the at least one processor 201 implements the above method embodiment.
[0123] Similarly, it can be understood that the contents of the above method embodiments are applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0124] An embodiment of the present application further provides a computer-readable storage medium, in which a program executable by the processor 201 is stored. The program executable by the processor 201 is used to implement the above-mentioned method embodiment when executed by the processor 201.
[0125] Similarly, the contents of the above method embodiments are applicable to the computer-readable storage medium embodiments. The functions specifically implemented by the computer-readable storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0126] In some optional embodiments, the functions / operations mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the functions / operations involved, the two boxes shown in succession may actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiments presented and described in the flow chart of the present application are provided in an exemplary manner for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operations and logic flows presented herein. Optional embodiments are contemplated in which the order of the various operations is changed and the sub-operations described as a part of a larger operation are performed independently.
[0127] In addition, although the present application is described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is not necessary for understanding the present application. More specifically, given the properties, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the module will be understood within the routine skills of an engineer. Therefore, a person skilled in the art can implement the present application as set forth in the claims using ordinary techniques without undue experimentation. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present application, which is determined by the full scope of the appended claims and their equivalents.
[0128] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the embodiment method of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0129] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0130] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.
[0131] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0132] In the above description of this specification, reference to the terms "one embodiment / example," "another embodiment / example," or "certain embodiments / examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples.
[0133] Although the embodiments of the present application have been shown and described, those skilled in the art will appreciate that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and intent of the present application, and that the scope of the present application is defined by the claims and their equivalents.
[0134] The above is a specific description of the preferred implementation of the present application, but the present application is not limited to the embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present application, and these equivalent modifications or substitutions are all included in the scope defined by the claims of the present application.
Claims
1. A distributed network security authentication method, characterized in that: Applied to a device to be authenticated, the method includes: Obtain authentication communication data and generate a device public key and a device private key using a random number generator in a trusted execution environment; Performing certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate; Performing ciphertext generation processing on the authentication communication data according to the device private key to obtain authentication ciphertext; The public key certificate and the authentication ciphertext are sent to at least one distributed connection device via a bus of a distributed network, so that at least one distributed connection device performs device authentication on the authentication ciphertext according to the public key certificate, and obtains a device authentication result returned by the distributed connection device.
2. The method according to claim 1, characterized in that The step of performing certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate includes: Obtain device identity information based on authentication communication data; Performing a signature request construction process on the device identity information according to the device public key and the device private key to obtain a certificate signature request file; The certificate signing request file is sent to a trusted certificate authority device, so that the trusted certificate authority device performs authorized signature on the certificate signing request file, and obtains a public key certificate returned by the trusted certificate authority device.
3. The method according to claim 1, characterized in that The step of performing ciphertext generation processing on the authentication communication data according to the device private key to obtain the authentication ciphertext includes: Dividing the authentication communication data into data intervals to obtain a plurality of interval data; Randomly sorting all the interval data to obtain messy data corresponding to each of the interval data; All the messy data are encrypted with a key according to the device private key to obtain the authentication ciphertext.
4. A distributed network security authentication method, characterized in that: Applied to a distributed connection device, the method includes: Receiving a public key certificate and authentication ciphertext sent by the device to be authenticated via a bus of a distributed network; Performing device authentication on the authentication ciphertext according to the public key certificate to obtain a device authentication result; The public key certificate and the authentication ciphertext are obtained by the following steps: The device to be authenticated obtains authentication communication data and generates a device public key and a device private key using a random number generator in a trusted execution environment; The device to be authenticated performs certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain the public key certificate; The device to be authenticated performs ciphertext generation processing on the authentication communication data according to the device private key to obtain the authentication ciphertext.
5. The method according to claim 4, characterized in that The performing device authentication on the authentication ciphertext according to the public key certificate to obtain a device authentication result includes: Obtaining a device public key according to the public key certificate; Decrypting the authentication ciphertext according to the device public key to obtain authentication plaintext; Performing plaintext analysis on the authentication plaintext to obtain plaintext data; According to the plaintext data, the messy data in the authentication ciphertext is compared and authenticated to obtain the device authentication result.
6. The method according to claim 5, characterized in that The performing plaintext analysis on the authentication plaintext to obtain plaintext data includes: Performing image generation processing on the authentication plaintext to obtain a plaintext image; Inputting the plaintext image into a trained code line detection model to perform code line detection, obtaining a plurality of line region coordinates output by the trained code line detection model, wherein the line region coordinates are used to represent region coordinates of code lines in the plaintext image; performing region segmentation processing on the plaintext image according to all the row region coordinates to obtain a plaintext region block corresponding to each row region coordinate; All the plaintext area blocks are input into a trained text recognition model for recognition, and the plaintext data output by the trained text recognition model are obtained.
7. The method according to claim 5, characterized in that The comparing and authenticating the messy data in the authentication ciphertext according to the plaintext data to obtain the device authentication result includes: Comparing the code text in the messy data with the code text in the plaintext data to obtain a code text comparison result; If the code text comparison result is a successful comparison, the device to be authenticated is authenticated to obtain the device authentication result; or, if the code text comparison result is a failed comparison, the process returns to the step of receiving the public key certificate and authentication ciphertext sent by the device to be authenticated through the bus of the distributed network.
8. A distributed network security authentication system, characterized in that: Applied to a device to be authenticated, the system includes: a first processing unit, configured to obtain authentication communication data and generate a device public key and a device private key using a random number generator in a trusted execution environment; a second processing unit, configured to perform certificate generation processing on the authentication communication data according to the device public key and the device private key to obtain a public key certificate; a third processing unit, configured to perform ciphertext generation processing on the authentication communication data according to the device private key to obtain an authentication ciphertext; The fourth processing unit is used to send the public key certificate and the authentication ciphertext to at least one distributed connection device through the bus of the distributed network, so that at least one of the distributed connection devices performs device authentication on the authentication ciphertext according to the public key certificate, and obtains the device authentication result returned by the distributed connection device.
9. An electronic device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the method according to any one of claims 1 to 3 or the method according to any one of claims 4 to 7.
10. A computer-readable storage medium storing a program executable by a processor, characterized in that: The program executable by the processor is used to implement the method according to any one of claims 1 to 3 or the method according to any one of claims 4 to 7 when executed by the processor.