Blockchain-based Internet of Things Terminal Authentication Method, System, Device and Medium
By using blockchain technology to encrypt and store feature strings in IoT terminal authentication, the problem of data leakage in IoT terminal authentication is solved, and security is improved and the authentication process is simplified.
Patent Information
- Application Number
- CN202111652282.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-30
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-12-30
AI Technical Summary
There is a risk of data leakage during the authentication process of IoT terminals, especially the problem of displaying feature strings, which leads to insufficient security.
The blockchain-based IoT terminal authentication method is adopted to encrypt terminal information to form ciphertext and signatures, combine to form feature strings, and encrypt and store them in the blockchain. When the terminal requests registration, the encrypted string is obtained from the blockchain for decryption and authentication for terminal access.
It effectively avoids data leakage of feature strings, improves the security of terminal authentication, simplifies the terminal authentication process, and reduces the workload of terminal developers.
Smart Images

Figure CN114372245B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the Internet of Things, and in particular to an Internet of Things terminal authentication method, system, device, and storage medium based on a blockchain. Background Art
[0002] With the rise of smart hardware technology, in recent years, the Internet of Things market has shown an exponential growth trend. The Internet of Things platform is in the hub position of the combination of software and hardware in the era of all things connected and is becoming increasingly important in the Internet of Things industrial ecosystem. At the same time, Internet of Things security incidents have also shown an explosive growth trend. In particular, Internet of Things terminals have become the focus of attacks, and data leakage incidents occur frequently. Privacy data mainly exists in the cloud and Internet of Things terminal devices. On the one hand, the cloud service platform may be attacked externally or leaked internally, or due to reasons such as weak password authentication of cloud service users, sensitive data may be leaked; on the other hand, there is also a possibility of data leakage between devices. Summary of the Invention
[0003] In view of this, to at least partially solve one of the above technical problems, an object of an embodiment of the present invention is to provide an Internet of Things terminal authentication method based on a blockchain that can effectively avoid data leakage and has higher security; at the same time, the technical solution of the present application also provides a system, device, and computer-readable storage medium that can correspondingly implement this method.
[0004] On the one hand, the technical solution of the present application provides an Internet of Things terminal authentication method based on a blockchain, and the method includes the following steps:
[0005] Encrypt the terminal information of the Internet of Things terminal to be authenticated to form a ciphertext and a signature, and form a first feature string according to the combination of the ciphertext and the signature;
[0006] Encrypt the first feature string to obtain a first encrypted string, and store the first encrypted string in the blockchain;
[0007] Obtain a registration request, obtain a second encrypted string from the blockchain according to the registration request, and decrypt the second encrypted string to obtain a second feature string;
[0008] Match the first feature string with the second feature string, and authenticate the identity of the Internet of Things terminal to be authenticated according to the matching result.
[0009] In a feasible embodiment of the solution of the present application, before the step of encrypting the terminal information of the Internet of Things terminal to form a ciphertext and a signature, the authentication method includes:
[0010] Initialize the Internet of Things terminal to be authenticated, and generate a public key and a private key for the Internet of Things terminal to be authenticated;
[0011] Generate a root key based on the user information in the Internet of Things terminal to be authenticated;
[0012] The public key is used to encrypt the first feature string to obtain the first encrypted string; the private key is used to decrypt the second encrypted string to obtain the second feature string; the root key is used to encrypt the ciphertext to obtain the signature.
[0013] In a feasible embodiment of the solution of this application, the step of storing the first encrypted string in the blockchain includes:
[0014] Obtain a data uploading request;
[0015] Determine the main node of the blockchain service, and sort and package the first encrypted string according to the data uploading request through the main node to obtain a data packet;
[0016] Store the data packet in the blockchain to generate a data uploading certificate.
[0017] In a feasible embodiment of the solution of this application, the data uploading request includes first token information; after the step of obtaining the data uploading request, the authentication method includes:
[0018] Authenticate the first token information, determine that the authentication is passed, call the data storage and proof interface of the blockchain service, and upload the first encrypted string through the data storage and proof interface.
[0019] In a feasible embodiment of the solution of this application, the registration request includes second token information; after the step of obtaining the registration request, the authentication method includes:
[0020] Authenticate the second token information, determine that the authentication is passed, and call the data query interface of the blockchain service,
[0021] Obtain the second encrypted character through the data query interface.
[0022] In a feasible embodiment of the solution of this application, the step of sorting and packaging the first encrypted string according to the data uploading request through the main node to obtain a data packet includes:
[0023] Sort and package the first encrypted string to obtain a data packet, and perform a first verification on the data packet to generate legal verification information;
[0024] Broadcast the legal verification information in the blockchain so that non-main nodes perform a second verification on the data packet to generate second verification information;
[0025] Compare the second verification information with the legal verification information, and write the data packet into the non-primary node according to the comparison result.
[0026] In a feasible embodiment of the solution of this application, before the step of sorting and packing the first encrypted string to obtain a data packet, the authentication method includes:
[0027] Determine the hash value of the data packet according to the Merkle tree.
[0028] On the other hand, the technical solution of this application also provides an Internet of Things terminal authentication system based on a blockchain, including:
[0029] A data encryption unit, configured to encrypt terminal information of an Internet of Things terminal to be authenticated to form a ciphertext and a signature, combine the ciphertext and the signature to form a first feature string; encrypt the first feature string to obtain a first encrypted string, and store the first encrypted string in the blockchain;
[0030] A terminal registration unit, configured to obtain a registration request;
[0031] A data decryption unit, configured to obtain a second encrypted string from the blockchain according to the registration request, and decrypt the second encrypted string to obtain a second feature string;
[0032] An identity authentication unit, configured to match the first feature string with the second feature string, and perform identity authentication on the Internet of Things terminal to be authenticated according to the matching result.
[0033] On the other hand, the technical solution of the present invention also provides an Internet of Things terminal authentication device based on a blockchain, which includes:
[0034] At least one processor;
[0035] At least one memory, configured to store at least one program;
[0036] When at least one program is executed by at least one processor, the at least one processor runs the Internet of Things terminal authentication method based on the blockchain as described above.
[0037] On the other hand, the technical solution of the present invention also provides a storage medium, in which a processor-executable program is stored, and the processor-executable program is used to run the Internet of Things terminal authentication method based on the blockchain as described above when executed by the processor.
[0038] The advantages and beneficial effects of the present invention will be partially given in the following description, and the other parts can be understood through the specific implementation manners of the present invention:
[0039] The technical solution of this application is based on the core technologies of blockchain distributed storage and consensus mechanism. It encrypts the terminal information to form ciphertext and signatures, combines the ciphertext and signatures to form a feature string, and further encrypts and stores it in the blockchain. When the terminal requests registration, it obtains the encrypted string from the blockchain, decrypts it to get the feature string, and conducts identity authentication for terminal access. The solution solves the problem of the plaintext display of the feature string during terminal authentication on existing platforms and realizes the secure storage of the feature string. In addition, the terminal in the solution does not need to pre-set the feature string, effectively avoiding the problem of re-burning when the terminal migrates to a different platform, thus promoting the diversified development of terminal services. The solution combines blockchain and the Internet of Things, and comprehensively considers the simplification of terminal implementation and the diversification of business requirements, which can effectively avoid data leakage of the feature string and improve the security of terminal authentication. Description of the Drawings
[0040] To more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0041] Figure 1 It is a flowchart of the steps of the Internet of Things terminal authentication method based on blockchain provided in the embodiments of the present invention;
[0042] Figure 2 It is an interaction flowchart between the terminal and the Internet of Things platform during terminal authentication in the embodiments of the present invention;
[0043] Figure 3 It is an interaction flowchart during the generation and uploading of the feature string in the embodiments of the present invention. Detailed Embodiments
[0044] The following details the embodiments of the present invention. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions from beginning to end. The embodiments described below with reference to the drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention. For the step numbers in the following embodiments, they are only set for the convenience of elaboration and explanation, and no limitation is placed on the order between the steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0045] Combined with the technical problems or defects clearly pointed out in the foregoing background art, it should be further supplemented that in relatively common application scenarios, the Internet of Things platform usually has to bear the access of a large number of Internet of Things terminals. To ensure the security of terminal access, the platform will authenticate the Internet of Things terminals accessing it. In the related art, the platform provides various authentication methods such as national cryptographic algorithm authentication, certificate authentication, and feature string authentication for devices with different protocols; taking feature string authentication as an example, the platform assigns a feature string to the terminal. Among them, the feature string can uniquely identify the terminal, and the terminal developer needs to import it into the terminal. When the terminal logs in to the platform, it needs to carry the terminal security authentication information to complete the terminal authentication. At present, the feature string authentication process of the Internet of Things platform in the related art is too simple. After the platform assigns a feature string to the terminal, the terminal developer needs to manually copy it from the platform portal and write it into the terminal. If the feature string changes, it needs to be re-burned, which not only brings inconvenience to the terminal developer, but also lacks privacy protection for the feature string data and has great security risks.
[0046] Based on the obvious defects existing in the above-mentioned related art, on the one hand, as Figure 1 shown, the embodiments of the present application provide an Internet of Things terminal authentication method based on blockchain. The method includes steps S100 - S400:
[0047] S100. Encrypt the terminal information of the Internet of Things terminal to be authenticated to form a ciphertext and a signature, and form a first feature string according to the combination of the ciphertext and the signature;
[0048] Among them, the Internet of Things terminal to be authenticated is initialized and needs to be connected to the Internet of Things platform in the embodiment. And in the solution of the present application, it is mainly aimed at Internet of Things terminals that communicate using a mobile cellular network. In the subsequent content of the specification, it is default that the communication protocol method is to communicate using a mobile cellular network. Specifically in this embodiment, the first feature string is a feature string formed by combining the ciphertext obtained by the first round of encryption of the terminal with legitimate authentication and the signature obtained by the second round of encryption of the ciphertext.
[0049] In some alternative embodiments, before the process of encrypting the terminal information of the Internet of Things terminal to form a ciphertext and a signature in step S100, the method may include step S001 and step S002:
[0050] S001. Initialize the Internet of Things terminal to be authenticated, and generate a public key and a private key of the Internet of Things terminal to be authenticated;
[0051] S002. Generate a root key according to the user information in the Internet of Things terminal to be authenticated;
[0052] In steps S001 - S002, the public key is used to encrypt the first feature string to obtain the first encrypted string; the private key is used to decrypt the second encrypted string to obtain the second feature string; the root key is used to encrypt the ciphertext to obtain the signature.
[0053] Specifically in the embodiment, as Figure 2 shown, first, the embodiment obtains the user's unique identification information, such as the platform account registered by the user and the mobile phone number bound to the platform account, etc. The embodiment first authenticates the user's unique identification information, and then the platform generates a root key RootKey for the user. After the authentication, the embodiment then performs device initialization operations on the cellular IoT terminal to be connected to the IoT platform, generating the independent public key PK_Device and private key SK_Device of the terminal.
[0054] In addition, in the embodiment, after logging in to the IoT platform, the platform can create an IoT blockchain product, which is a collection of the same type of terminals; in the user interaction window provided by the platform, the user can select or set the product classification. For example, the communication protocol selects the mobile cellular network, and the authentication method selects feature string authentication.
[0055] After creating the product in the IoT platform, the embodiment can add a terminal by inputting information such as the terminal name, terminal number, and terminal public key. Among them, the input terminal is the IoT terminal to be authenticated. In the embodiment, after the IoT platform receives the new device instruction, it first generates a device ID as the unique identifier of the terminal on the platform, then encrypts information such as the terminal ID using Base64 to generate the payload ciphertext, and then uses the root key obtained in step S002 to encrypt the payload ciphertext using HMAC - SHA256 to generate the signature. The payload ciphertext plus the signature are combined into the feature string token; for example, the token is: Dj9pt7s7fEbk9VOzicmQ8834Lp4IRDCwtWkva1yPQW8.
[0056] S200. Encrypt the first feature string to obtain the first encrypted string, and store the first encrypted string in the blockchain;
[0057] Among them, the first encrypted string refers to the string obtained by encrypting through the public key generated in step S001. Specifically in the embodiment, the terminal management unit in the IoT platform encrypts the feature string PK_Device(token) through the terminal public key, and then calls the data deposit interface of the blockchain service to save the feature string ciphertext to the IoT blockchain.
[0058] S300, obtaining a registration request, obtaining a second encrypted string from the blockchain according to the registration request, and decrypting the second encrypted string to obtain a second characteristic string;
[0059] Among them, the second encrypted string is a string obtained by querying the data block stored on the blockchain according to the ID identification of the terminal that initiates the registration request, and the second characteristic string refers to the string obtained by decrypting the second encrypted string using the private key in step S001.
[0060] In a specific embodiment, the IoT platform obtains the registration request initiated by the IoT terminal to be authenticated, obtains the registration message by parsing the registration request, calls the data query interface according to the device ID in the registration message to obtain the terminal's feature string ciphertext from the blockchain service module, and returns the ciphertext to the terminal. After receiving the feature string ciphertext, the terminal uses the private key to decrypt SK_Device (token) to obtain the feature string.
[0061] S400, matching the first characteristic character string with the second characteristic character string, and performing identity authentication on the IoT terminal to be authenticated according to the matching result;
[0062] Specifically in the embodiment, after the terminal decrypts and obtains the characteristic string, the login message carrying the characteristic string is sent to the IoT platform. After the IoT platform parses the message, it uses HMAC-SHA256 to generate a characteristic string token based on the terminal ID and the user root key, compares it with the token carried in the terminal login message, verifies the legitimacy of the characteristic string, completes the identity authentication of the terminal, and returns the login result to the terminal. If the terminal access authentication is successful, the platform will show that the terminal is online, and the terminal can communicate with the platform such as reporting data.
[0063] In some optional embodiments, in method step S200, the process of storing the first encrypted string in the blockchain may include steps S210-S230:
[0064] S210, obtaining a data upload request;
[0065] S220, determining a master node of the blockchain service, and using the master node to sort and package the first encrypted string according to the data on-chain request to obtain a data packet;
[0066] S230, storing the data packet in the blockchain and generating a data on-chain certificate;
[0067] Specifically in the embodiments, after the blockchain service receives a data upload request, the primary node Primary dynamically elected by the blockchain service is responsible for sorting and packing all messages of the IoT terminal. Among them, the message content includes, but is not limited to, data upload requests and registration requests, etc. In the embodiments, the blockchain service uses the RBFT consensus algorithm to incorporate the data into the blockchain storage. After the data is recorded, the blockchain service returns a data upload certificate.
[0068] In some alternative embodiments, during the deployment of the blockchain base chain, the underlying capabilities of the blockchain can be encapsulated, and the IoT platform terminal management module can uniformly interact with the blockchain service. Therefore, in the data upload request and the registration request in the embodiments, corresponding token information can be carried. Furthermore, before the process of obtaining the data upload request in step S210 of the embodiment method, the method may further include step S201:
[0069] S201. Authenticate the first token information, determine that the authentication is passed, call the data deposit interface of the blockchain service, and upload the first encrypted string through the data deposit interface.
[0070] In addition, after the process of obtaining the registration request in method step S300 of the embodiment, the method may further include step S301:
[0071] S301. Authenticate the second token information, determine that the authentication is passed, call the data query interface of the blockchain service, and obtain the second encrypted character through the data query interface.
[0072] Specifically in the embodiments, as Figure 3 shown, the blockchain service can allocate global tokens. The IoT platform needs to carry token information when calling the API for authentication to ensure the security of interface access. When uploading data, the terminal management module calls the data deposit API of the blockchain service; when authenticating the terminal, the terminal management module calls the data query API of the blockchain service to obtain the feature string data.
[0073] In some alternative embodiments, in the process of method step S220 of determining the primary node of the blockchain service and the primary node sorting and packing the first encrypted string according to the data upload request to obtain a data packet, it may include steps S221 - S223:
[0074] S221. Sort and pack the first encrypted string to obtain a data packet, and perform a first verification on the data packet to generate legal verification information;
[0075] S222. Broadcast the legal verification information in the blockchain so that non - primary nodes perform a second verification on the data packet to generate second verification information;
[0076] S223. Compare the second verification information with the legitimate verification information, and write the data packet into the non-primary node according to the comparison result.
[0077] In the embodiment, the blockchain service adopts the RBFT consensus algorithm; the embodiment of the robust Byzantine fault tolerance algorithm RBFT inserts a transaction verification link into the original PBFT algorithm, improving the stability of the solution. While retaining the original three-stage processing flow (PrePrepare, Prepare, Commit) of PBFT, RBFT consensus adds an important transaction verification (validate) link, ensuring consensus on both the transaction execution order and the block verification result. The RBFT consensus algorithm provides a mechanism for dynamic data automatic recovery, adding the function of dynamically adding and deleting nodes in the cluster without downtime, enhancing the availability of the consensus module.
[0078] Specifically in the embodiment, the primary node first verifies after packaging the transaction into a block, and includes the verification result in the PrePrepare message for global broadcast. In this way, the PrePrepare message contains both the sorted transaction information and the block verification result. After receiving the PrePrepare message from the primary node, the secondary node first checks the legality of the message. After passing the check, it broadcasts the Prepare message to indicate that this node agrees with the sorting result of the primary node; after receiving the number of nodes required to reach consensus (quorum-1) Prepare messages, the secondary node will start to verify the block, and compare the verification result with the verification result of the primary node. If the comparison result is consistent, it broadcasts Commit to indicate that this node agrees with the verification result of the primary node, otherwise it directly initiates ViewChange to indicate that this node believes that the primary node has abnormal behavior.
[0079] In some alternative embodiments, the method can determine the hash value of the data packet through a Merkle tree.
[0080] In the embodiment, a distributed storage such as a Merkle tree is adopted to record the hash value of the data block, optimizing the storage architecture of the blockchain and improving the storage efficiency of the blockchain. Exemplarily, when constructing a Merkle tree, first calculate the hash value of the data block. In the embodiment, hash algorithms such as SHA-256 are selected. However, if only preventing non-malicious damage or tampering of data, some checksum algorithms with low security but high efficiency, such as CRC, can be used instead. Then pair the hash values calculated from the data blocks in pairs (if there are an odd number of numbers, the last one pairs with itself), calculate the upper-layer hash, and repeat this step until the root hash value is calculated.
[0081] Combined with the attached Figure 2 , the complete implementation process of the solution of this application is described in detail as follows:
[0082] (1) The user registers for a platform account using a mobile phone number and undergoes real-name authentication. The platform generates a root key RootKey for this user.
[0083] (2) The user performs device initialization operations on the cellular Internet of Things terminal to generate a unique public key PK_Device and private key SK_Device for this terminal.
[0084] (3) The user logs in to the Internet of Things platform, creates an Internet of Things blockchain product (the product is a collection of the same type of terminals), selects the product classification, and note that the communication protocol is selected as "mobile cellular network" and the authentication method is selected as "feature string authentication".
[0085] (4) The user adds a terminal by entering information such as the terminal name, terminal number, and terminal public key under the created product. After the platform terminal management module receives the new device instruction, it first generates a device ID as the unique identifier of this terminal on the platform, then encrypts the information such as the terminal ID using Base64 to generate a payload ciphertext, and then uses the root key in step (1) to encrypt the payload ciphertext using HMAC-SHA256 to generate a signature. The payload ciphertext plus the signature are combined into a feature string token, for example: Dj9pt7s7fEbk9VOzicmQ8834Lp4IRDCwtWkva1yPQW8).
[0086] (5) The terminal management module encrypts the feature string PK_Device(token) using the terminal public key, and then calls the data deposit interface of the blockchain service to save the feature string ciphertext to the Internet of Things blockchain.
[0087] (6) After the blockchain service receives the data upload request, the primary node Primary dynamically elected by the blockchain service is responsible for sorting and packaging the client messages, and uses the RBFT consensus algorithm to incorporate the data into the blockchain storage. The blockchain service returns a data upload certificate.
[0088] (7) The terminal sends a registration request to the platform. The terminal access module parses the registration message and sends the request to the terminal management. According to the device ID identifier, the terminal management calls the data query interface to obtain the feature string ciphertext of this terminal from the blockchain service module and returns the ciphertext to the terminal.
[0089] (8) After the terminal receives the feature string ciphertext, it decrypts SK_Device(token) using the private key to obtain the feature string, and then sends the login message carrying the feature string to the platform. After the terminal access module parses the message, it forwards it to the terminal management module.
[0090] (9) The terminal management module generates a feature string token using HMAC-SHA256 based on the terminal ID and the user root key, compares it with the token carried in the terminal login message to verify the legality of the feature string, completes the authentication of the terminal's identity, and returns the login result to the terminal.
[0091] (10) If the terminal access authentication is successful, the platform will display the terminal as online, and the terminal can communicate with the platform for data reporting and so on.
[0092] In a second aspect, the technical solution of the present application also provides an Internet of Things terminal authentication system based on blockchain. This system includes two main objects: a cellular terminal and an Internet of Things platform; in the Internet of Things platform, it mainly includes:
[0093] A data encryption unit, which is used to encrypt the terminal information of the Internet of Things terminal to be authenticated to form a ciphertext and a signature, and form a first feature string according to the combination of the ciphertext and the signature; encrypt the first feature string to obtain a first encrypted string, and store the first encrypted string in the blockchain;
[0094] A terminal registration unit, which is used to obtain a registration request;
[0095] A data decryption unit, which is used to obtain a second encrypted string from the blockchain according to the registration request, and decrypt the second encrypted string to obtain a second feature string;
[0096] An identity authentication unit, which is used to match the first feature string with the second feature string, and authenticate the identity of the Internet of Things terminal to be authenticated according to the matching result.
[0097] In some alternative embodiments, the functional units in the Internet of Things can be further divided. For example, in some Internet of Things platforms of some embodiments, it also includes:
[0098] A terminal access unit: used to process the reception and response of the terminal login message, and the verification of the feature string;
[0099] A terminal management unit: used to generate and save the feature string, encrypt the feature string with a public key, and interact with the blockchain service;
[0100] A blockchain service unit: used to store terminal feature string information on the chain, and provide data deposit and query interfaces externally.
[0101] In a third aspect, the technical solution of the present application also provides an Internet of Things terminal authentication device based on blockchain, which includes:
[0102] At least one processor; at least one memory for storing at least one program; when the at least one program is executed by the at least one processor, the at least one processor runs the blockchain-based Internet of Things terminal authentication method as in the first aspect.
[0103] An embodiment of the present invention also provides a storage medium storing a program, and the program is executed by a processor to implement the above-mentioned blockchain-based Internet of Things terminal authentication method.
[0104] From the above specific implementation process, it can be summarized that the technical solution provided by the present invention has the following advantages or advantages compared with the prior art:
[0105] 1. Data storage security. When the current mainstream Internet of Things platforms authenticate the access of cellular Internet of Things devices, they generally use feature string authentication. The feature strings are displayed in plain text on the platform portal, and the privacy of the feature strings cannot be guaranteed. The method of the present invention encrypts the feature strings and stores them in the blockchain service, and the data is secure and reliable.
[0106] 2. Simple authentication process. The technical solution of this application uses the public key / private key of the device to encrypt / decrypt the feature string, simplifies the authentication process on the premise of improving the security of terminal authentication, and reduces the development workload on the terminal side. The terminal does not directly interact with the blockchain service, reducing the terminal interaction process.
[0107] In some alternative embodiments, the functions / operations mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the functions / operations involved, two consecutive blocks shown may actually be executed substantially simultaneously or the blocks can sometimes be executed in the reverse order. In addition, the embodiments presented and described in the flowcharts of the present invention are provided by way of example for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operations and logical flows presented herein. Alternative embodiments are contemplated, where the order of various operations is changed and the sub-operations described as part of a larger operation are executed independently.
[0108] In addition, although the present invention has been described in the context of functional modules, it should be understood that, unless otherwise stated to the contrary, one or more of the functions and / or features may be integrated in a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It should also be understood that a detailed discussion of the actual implementation of each module is not necessary for an understanding of the present invention. Rather, given the attributes, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the modules will be understood within the ordinary skill of an engineer. Thus, those of ordinary skill in the art can implement the present invention as set forth in the claims without undue experimentation. It should also be understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.
[0109] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definitional sequence of executable instructions for implementing logical functions, which can be embodied in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device.
[0110] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0111] Although embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the claims and their equivalents.
[0112] The above is a specific description of the preferred embodiments of the present invention, but the present invention is not limited to the above embodiments. Those skilled in the art can also make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included in the scope defined by the claims of this application.
Claims
1. Internet of Things terminal authentication method based on blockchain, characterized in that, The method includes the following steps: Encrypt the terminal information of the Internet of Things terminal to be authenticated to form a ciphertext and a signature, and combine the ciphertext and the signature to form a first feature string; Encrypt the first feature string to obtain a first encrypted string, and store the first encrypted string in the blockchain; Obtain a registration request, obtain a second encrypted string from the blockchain according to the registration request, and decrypt the second encrypted string to obtain a second feature string; Match the first feature string with the second feature string, and authenticate the identity of the Internet of Things terminal to be authenticated according to the matching result; Among them, the step of storing the first encrypted string in the blockchain includes: Obtain a data upload request to the blockchain; Determine the main node of the blockchain service, and sort and package the first encrypted string according to the data upload request through the main node to obtain a data packet; Store the data packet in the blockchain and generate a data upload certificate; The data upload request to the blockchain includes first token information; after the step of obtaining the data upload request to the blockchain, the authentication method includes: Authenticate the first token information, determine that the authentication is passed, call the data storage interface of the blockchain service, and upload the first encrypted string through the data storage interface; The registration request includes second token information; after the step of obtaining the registration request, the authentication method includes: authenticate the second token information, determine that the authentication is passed, call the data query interface of the blockchain service, and obtain the second encrypted string through the data query interface; The step of sorting and packaging the first encrypted string according to the data upload request through the main node includes: Sort and package the first encrypted string to obtain a data packet, and perform a first verification on the data packet to generate legal verification information; Broadcast the legal verification information in the blockchain so that non-main nodes perform a second verification on the data packet to generate second verification information; Compare the second verification information with the legal verification information, and write the data packet into the non-main nodes according to the comparison result.
2. The Internet of Things terminal authentication method based on blockchain according to claim 1, characterized in that, Before the step of encrypting the terminal information of the Internet of Things terminal to form a ciphertext and a signature, the authentication method includes: Initialize the Internet of Things terminal to be authenticated, and generate a public key and a private key for the Internet of Things terminal to be authenticated; Generate a root key according to the user information in the Internet of Things terminal to be authenticated; The public key is used to encrypt the first feature string to obtain the first encrypted string; the private key is used to decrypt the second encrypted string to obtain the second feature string; the root key is used to encrypt the ciphertext to obtain the signature.
3. The Internet of Things terminal authentication method based on blockchain according to claim 1, characterized in that, Before the step of sorting and packaging the first encrypted string to obtain a data packet, the authentication method includes: Determine the hash value of the data packet according to the Merkle tree.
4. Internet of Things terminal authentication system based on blockchain, characterized in that, Includes: A data encryption unit, configured to encrypt according to the terminal information of the Internet of Things terminal to be authenticated to form a ciphertext and a signature, and combine the ciphertext and the signature to form a first feature string; Encrypt the first feature string to obtain a first encrypted string, and store the first encrypted string in the blockchain; A terminal registration unit, configured to obtain a registration request; A data decryption unit, configured to obtain a second encrypted string from the blockchain according to the registration request, and decrypt the second encrypted string to obtain a second feature string; An identity authentication unit, configured to match the first feature string with the second feature string, and perform identity authentication on the Internet of Things terminal to be authenticated according to the matching result; Wherein, the step of storing the first encrypted string in the blockchain includes: Obtain a data uploading request to the blockchain; Determine the main node of the blockchain service, and sort and package the first encrypted string according to the data uploading request through the main node to obtain a data packet; Store the data packet in the blockchain and generate a data uploading certificate; The data uploading request includes first token information; after the step of obtaining the data uploading request, the authentication method includes: Authenticate the first token information, determine that the authentication is passed, call the data storage interface of the blockchain service, and upload the first encrypted string through the data storage interface; The registration request includes second token information; after the step of obtaining the registration request, the authentication method includes: authenticate the second token information, determine that the authentication is passed, call the data query interface of the blockchain service, and obtain the second encrypted string through the data query interface; The step of sorting and packaging the first encrypted string according to the data uploading request through the main node includes: Sort and package the first encrypted string to obtain a data packet, and perform a first verification on the data packet to generate legal verification information; Broadcast the legal verification information in the blockchain so that non-main nodes perform a second verification on the data packet to generate second verification information; Compare the second verification information with the legal verification information, and write the data packet into the non-main nodes according to the comparison result.
5. The Internet of Things terminal authentication device based on blockchain, characterized in that, Includes: At least one processor; At least one memory, configured to store at least one program; When the at least one program is executed by the at least one processor, the at least one processor runs the blockchain-based Internet of Things terminal authentication method according to any one of claims 1-3.
6. A storage medium storing a program executable by a processor, characterized in that, The program executable by the processor, when executed by the processor, is used to run the blockchain-based Internet of Things terminal authentication method according to any one of claims 1-3.
Citation Information
Patent Citations
Internet of Things cloud access method and device
CN110113355A