Distributed two-way authentication method, device and storage medium based on blockchain

By using blockchain technology and smart contracts to achieve two-way authentication between devices, it solves the problems of insufficient flexibility and high cost in IoT devices, and provides a highly secure, low-cost lightweight access authentication solution suitable for multi-point access scenarios in homes and small businesses.

CN114462015BActive Publication Date: 2025-10-03DIGITAL WORLD (SHENZHEN) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210114556.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-30
Publication Date
2025-10-03
Estimated Expiration
2042-01-30

AI Technical Summary

Technical Problem

Existing two-way authentication technology has problems with insufficient flexibility and high user cost in IoT devices, especially in small devices, where it is difficult to achieve highly secure lightweight access authentication.

Method used

A distributed two-way authentication method based on blockchain is adopted, blockchain technology and smart contracts are used to perform two-way authentication between devices, the non-repudiation and integrity of information are ensured through blockchain account addresses and transaction signature mechanisms, and a flexible authentication process is established.

Benefits of technology

It realizes high-security, low-cost two-way authentication in IoT devices, which is suitable for the security authentication needs of homes or small businesses, simplifies the deployment process, and is applicable to multi-point and multi-service access security authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114462015B_ABST
    Figure CN114462015B_ABST
Patent Text Reader

Abstract

This application provides a distributed two-way authentication method, device, and storage medium based on blockchain. The method includes: an authenticated device requests access to a controlled resource; the authenticated device performs two-way authentication with an authentication device through a smart contract in the blockchain; after the two-way authentication is successful, the authenticated device accesses the controlled resource through a controller device. When accessing the controlled resource, two-way authentication is performed between the authenticated device and the controller device; wherein the controller device is a device used to control the controlled resource. This application can achieve secure access control at a low cost through blockchain technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and in particular to a distributed two-way authentication method, device, and storage medium based on blockchain. Background Art

[0002] Wide-area multi-point access for small and micro enterprises, wide-area cross-network multi-point access for home devices, and even wide-area access for enterprise-level devices usually reflect network heterogeneity and large cross-domain access. A single enterprise or family cannot use an existing authentication access system to cover these diverse access authentications, or the deployment cost is too high. Especially in the era of the Internet of Things explosion, Internet of Things sensors also involve privacy and security, and also require two-way authentication access with high security guarantees. However, since the performance of Internet of Things devices is often relatively small, there is an urgent need for a lightweight but highly secure two-way access authentication method. At present, the two-way authentication technology in related technologies is mostly based on the CA system of electronic certificates. Under the existing technical conditions, it is not flexible enough and the cost for users to use is too high. Summary of the Invention

[0003] This application provides a distributed two-way authentication method, device and storage medium based on blockchain, which can complete secure access control at a low cost through blockchain technology.

[0004] On the one hand, this application provides a distributed two-way authentication method based on blockchain, including:

[0005] The authenticated device requests access to controlled resources;

[0006] The authenticated device performs two-way authentication with the authentication device through the smart contract in the blockchain;

[0007] After the two-way authentication is passed, the authenticated device accesses the controlled resource through the controller device. When accessing the controlled resource, two-way authentication is performed between the authenticated device and the controller device; wherein the controller device is a device used to control the controlled resource.

[0008] On the other hand, the present application also provides a distributed two-way authentication method based on blockchain, comprising: when an authentication device is triggered by a smart contract in the blockchain, the authentication device performs two-way authentication with the authenticated device requesting access to a controlled resource and the controller device related to the controlled resource requested to be accessed, respectively, through the smart contract;

[0009] After the two-way authentication between the authentication device and the authenticated device and the controller device is passed, the authentication device sends the authentication result to the authenticated device and the controller device through the smart contract or directly in the form of a blockchain transaction.

[0010] On the other hand, the present application also provides a distributed two-way authentication method based on blockchain, comprising: after a controller device receives a controlled resource access application message, initiating an authentication and authorization application to a smart contract based on the controlled resource access application message; receiving an authentication result from the smart contract to determine whether to open a secure resource, and forwarding the authentication result to the authenticated device according to the needs of the authenticated device; or, the controller device receives the authentication result to determine whether to open a secure resource;

[0011] When the authenticated device requests access to a controlled resource, and both the authenticated device and the authenticating device have passed bidirectional authentication, the controller device provides the authenticated device with access to the controlled resource;

[0012] The controller device performs two-way authentication with the authenticated device when the authenticated device accesses the device.

[0013] In yet another aspect, the present application further provides a distributed two-way authentication method based on blockchain, comprising: a smart contract receiving a request from an authenticated device to access a controlled resource;

[0014] The smart contract triggers two-way authentication between the authenticated device and the authentication device, and triggers two-way authentication between the controller device and the authentication device, so that when all authentications pass, the authenticated device accesses the controlled resources controlled by the controller device.

[0015] On the other hand, the present application also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any one of the above methods when executing the program.

[0016] On the other hand, the present application also provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to implement any of the above methods.

[0017] Compared with related technologies, the embodiment of the present application uses smart contracts for two-way authentication to ensure the security of access. By adopting blockchain technology, there is no need to establish complex authentication center certificate system delivery center and other entities. It has the characteristics of high security, low cost, and simple deployment. It is particularly suitable for security authentication of homes or small businesses, or decentralized multi-point and multi-service access security authentication.

[0018] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. Other advantages of the present application can be realized and obtained by the solutions described in the description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings are used to provide an understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.

[0020] Figure 1 This is a schematic diagram of the architecture of the access system according to an embodiment of the present application;

[0021] Figure 2 This is a flowchart of a distributed two-way authentication method based on blockchain according to an embodiment of the present application;

[0022] Figure 3 This is a flowchart of the authentication scheme A of the embodiment of the present application;

[0023] Figure 4 This is a flowchart of the authentication scheme B of the embodiment of the present application;

[0024] Figure 5 This is a flowchart of a distributed two-way authentication method based on blockchain (operations on the authentication device side) according to an embodiment of the present application.

[0025] Figure 6 This is a flowchart of a distributed two-way authentication method based on blockchain according to an embodiment of the present application (applied to the operation of the authenticated device);

[0026] Figure 7 This is a schematic diagram of authentication scheme A in the application example of this application;

[0027] Figure 8 This is a schematic diagram of authentication scheme B in the application example of this application. DETAILED DESCRIPTION

[0028] This application describes multiple embodiments, but this description is exemplary rather than restrictive, and it will be apparent to those skilled in the art that there may be more embodiments and implementations within the scope of the embodiments described herein. Although many possible feature combinations are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with any other feature or element in any other embodiment, or may replace any other feature or element in any other embodiment.

[0029] This application includes and contemplates combinations of features and elements known to those of ordinary skill in the art. The embodiments, features, and elements disclosed in this application may also be combined with any conventional features or elements to form a unique inventive solution defined by the claims. Any features or elements of any embodiment may also be combined with features or elements from other inventive solutions to form another unique inventive solution defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this application may be implemented individually or in any appropriate combination. Therefore, except for the limitations made according to the appended claims and their equivalents, the embodiments are not subject to other limitations. In addition, various modifications and changes may be made within the scope of protection of the appended claims.

[0030] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not rely on the specific order of the steps described in the application, the method or process should not be limited to the steps in the specific order. As will be understood by those skilled in the art, other sequences of steps are also possible. Therefore, the specific sequence of the steps set forth in the specification should not be interpreted as a limitation to the claims. In addition, the claims for the method and / or process should not be limited to the steps performed in the order written, and those skilled in the art can easily understand that these sequences can change and still remain within the spirit and scope of the embodiments of the application.

[0031] In the embodiment of this application, blockchain technology is applied to the access field to ensure the security of end-to-end access.

[0032] The blockchain's account address and transaction signature mechanism ensures that signed transaction information is irrefutably and uniquely sourced from the account address to which the signature belongs. This feature is ideal for information exchange between multiple roles during authentication. Each role can use this mechanism to sign information sent to other roles, ensuring that the information originates from that role and that the content cannot be altered.

[0033] Blockchain's smart contract technology ensures the reliable operation of distributed nodes, and the logic of smart contracts can perform various identity verification and signature verification. Smart contracts can be created using blockchain account addresses and establish corresponding relationships. These relationships are tamper-proof and non-repudiable, allowing authentication systems to create flexible authentication processes and authentication objects through smart contracts.

[0034] The architecture of the access system in the embodiment of the present application is as follows Figure 1 As shown, it includes an authentication device, an authenticated device, a security resource control point (or controller device), and a smart contract created by the authentication device through the blockchain.

[0035] The authentication device is also called the authenticator, and the authenticated device is also called the authenticatee or authenticated object. The security resource control point is used to control security resources (or controlled resources). The authenticator, the security resource control point, and the authenticated device perform two-way authentication via smart contracts, allowing the authenticated device to access a designated area and use the controlled resources provided by the designated area. The designated area includes a designated network or a controlled security domain. The controlled security domain is the security domain controlled by the security resource control point.

[0036] The bidirectional nature of this application refers to mutual authentication between the authenticated party and the authenticator, between the authenticated party and the controller device, and between the controller device and the authenticator. The authenticator authenticates the authenticated party, and the authenticated party also authenticates the authenticator; the controller device authenticates the authenticated party, and the authenticated party also authenticates the controller device; and the authenticator authenticates the controller device, and the controller device also authenticates the authenticator. This application leverages blockchain infrastructure, specifically the intelligent processing of account transaction attributes and smart contracts, to design a corresponding process to achieve mutual authentication between these three parties.

[0037] The embodiments of the present application can be widely applied in environments with blockchain facilities, where there are authenticator and authenticatee roles, as well as controlled resources and control points for controlling access to controlled resources. For example, they can be applied to secure multi-point access, such as home device access / multi-home device secure access, enterprise device access / enterprise device remote access, etc. They can also be applied to shared network access, such as shared WiFi access.

[0038] In the embodiment of the present application, the accessed network may be the Internet of Things, a wireless network, etc.

[0039] like Figure 2 As shown, the distributed two-way authentication method based on blockchain in the embodiment of the present application includes:

[0040] Step 201: The authentication device creates a smart contract on the blockchain.

[0041] In an exemplary embodiment, the authentication device applies for a blockchain account as the authentication device account, and creates a blockchain smart contract using the authentication device account. The authentication device account may be referred to as a primary account.

[0042] The key information in the smart contract may include: authenticated device data, authentication function, security resource control point data, and owner information and interactive interface information of the smart contract.

[0043] The authenticated device data may include authenticated object data, including the account number, authentication protocol, permission scope, device type, and other information identifying the authenticated device itself and corresponding permissions.

[0044] The interaction interface information is a list of interaction methods supported by this object and the corresponding interaction addresses. These methods indicate which interaction semantics the object supports; the corresponding address is the interaction address used for the method, which can be a blockchain address, a smart contract address, or an interaction communication protocol and address information outside the blockchain, such as the HTTPS protocol and URL or other remote call protocols and addresses.

[0045] The authentication function implements the processing logic of authentication and authorization, and is used to determine or match the access rights of the authenticated device to a certain security resource and provide the corresponding assigned security resource control point data. The input parameters may include (authenticated device information, security resource information, access request operation information, optional security resource control point information), and the output is the processing results of whether access is allowed or not, as well as the authentication information of each participating authentication role and the optional corresponding assigned security resource control point data details, including the details of the security resources that can be accessed and used. The "optional" here means that the security resource control point information is not necessarily an input parameter, and the corresponding assigned security resource control point data details are not necessarily in the output; because in some schemes (such as the authentication scheme B mentioned later), the security resource control point information may not be provided directly, but the assigned security resource control point and the accessible security resources can be found through the function.

[0046] Security resource control point data includes the security resource control point account, device type, security resource type, security resource detailed information, interactive interface information, etc.

[0047] Owner information and interaction interface information: The creator of a smart contract is typically the owner of the smart contract, unless another account is set as the owner in the smart contract. The owner can be a single account or multiple accounts, and can even set up a multi-account joint signature to exercise the right to modify the smart contract. The owner's interaction interface information is used to identify the interaction interface when the owner / authentication device needs to confirm certain information, guiding the interaction between the smart contract or other authentication entity and the owner. These interfaces can be multiple, allowing the system to communicate through one or more interfaces based on business selection and reliability considerations.

[0048] Accordingly, smart contracts can choose to include the following interface logic:

[0049] Authenticated device data addition and deletion interface: This interface is used to add and delete authenticated device data. This interface has security level restrictions and requires the owner or an account designated by the owner to have permission to operate.

[0050] Authentication function interface: There can be multiple interfaces of this type, which are smart contract functions and are allowed to be called.

[0051] Owner and interaction interface configuration interfaces: This interface is used to configure owner and interaction interface information. Multiple interaction interface information can be provided, allowing the system to select one or more interfaces for communication based on business needs and reliability. These configuration interfaces are typically only accessible to the owner.

[0052] Note: In a specific blockchain smart contract, not only can the owner be set, but different blockchain accounts can also be subdivided to authorize different levels of smart contract management roles. For example, in addition to the owner account, a certain account can be given the ability to add or delete authenticated person information. This application does not limit the use of smart contracts in this way, but for the sake of clarity, these management roles are logically grouped under the owner. Usually, the authentication device is the owner's device. Therefore, this application does not subdivide the specific blockchain account distinction between the owner and the authentication device. In practice, you can simply choose an appropriate account mechanism, but this does not affect the method described in this application. For the sake of simplicity, the two are equivalent.

[0053] Security Resource Control Point Data Add / Delete Interface: This interface is used to add or delete security resource control point data. This interface can only be called by the owner or a specified account.

[0054] In this embodiment, after step 201, the following steps may also be included:

[0055] The authentication device sets the owner information and interaction interface information of the smart contract.

[0056] Among them, the owner's account and the owner's interactive information interface are set through the setting interface of the smart contract's owner information and interactive interface information.

[0057] The security resource control point device applies for a blockchain account as the account of the security resource control point device in the smart contract, and sets the authentication device account and the smart contract account in the security resource control point device.

[0058] The authentication device adds or modifies the security resource control point data in the smart contract.

[0059] Among them, the smart contract interface, namely the security resource control point data addition and deletion interface, is used to add or modify resource control points and security resource detailed information.

[0060] The authenticated device applies for a blockchain account as the account of the authenticated device. The authenticated device account can be called a sub-account. The authentication device account and the smart contract account are set in the authenticated device.

[0061] The authentication device adds the authenticated device data, such as the authenticated device account information, etc., to the smart contract or the authentication device interaction interface information address specified by the smart contract, such as the URL address, and sets the security resource access permissions corresponding to each authenticated device. One or a class of security resources corresponds to one authentication function.

[0062] Among them, if the authenticated device information is recorded in the smart contract, the authentication device uses the master account to add the authenticated device data to the smart contract through the authenticated device data addition and deletion interface, specifies specific security resource access permissions, specifies specific authentication functions, and optionally specifies the access security resource control point information.

[0063] If the authenticated device information is recorded at the authentication device interaction interface information address specified by the smart contract, then the authentication device data is added to the corresponding authentication device interaction interface information address for subsequent interaction between the smart contract and the authentication device regarding this data. This application is not limited to these interaction technologies outside of the blockchain as long as the identities of the two interacting parties are authentic and verifiable.

[0064] In step 202, the authenticated device requests to access a designated area, and the authenticating device, the authenticated device, and the controller device perform two-way authentication.

[0065] Specifically, through the smart contract, the authentication device authenticates the authenticated device and the relevant controller device; after the authentication is passed, the authentication device gives a verifiable authentication result, and the authenticated device and the controller device can verify the identity and information integrity of the authentication result based on this result, that is, the authentication device and the controller device authenticate the authentication device, that is, the two-way authentication between the authentication device and the authenticated device and between the authentication device and the controller device. The authenticated device accesses the controlled resource through the controller device. When accessing, the authenticated device and the controller device perform two-way authentication. The authenticated device verifies the controller device based on the controller device identity information (such as the blockchain address) contained in the aforementioned authentication result. The controller device can also verify the authenticated device based on the authenticated device information (such as the blockchain address) in the authentication result, that is, two-way authentication between the authenticated device and the controller device.

[0066] Step 203: After the two-way authentication is passed, the authenticated device accesses the designated area and uses the security resources (ie, controlled resources) of the designated area.

[0067] In step 202, two-way authentication can be performed using a variety of schemes. Two examples are used below to illustrate two two-way authentication schemes. In these two examples, the security resource control point is used as the controller device, and the security resources in the designated area are used as the controlled resources.

[0068] Authentication scheme A: The authenticated device interacts with the security resource control point as the controller device to perform authentication, such as Figure 3 As shown, the following steps are included:

[0069] In step 301, the authenticated device sends a controlled resource access application message (transaction) to the secure resource control point, that is, sends the controlled resource access application message to the smart contract indirectly.

[0070] Among them, the authenticated device can initiate a controlled resource access application message to the security resource control point in the form of a blockchain transaction through a blockchain network or a non-blockchain network (out-of-band message).

[0071] For example, when a user sends an access request message via a non-blockchain network, the method described in this application is used when accessing Wi-Fi on a mobile phone. The phone (the WiFi station entity in Wi-Fi) acts as the authenticated device, and the wireless access point (the WiFi AP entity in Wi-Fi) acts as the controller. The phone sends a network access request message to the AP, which logically forwards the message after adding its own identity verification according to this application process. Because the message sent from the phone to the AP is not sent over the blockchain network, it is considered an out-of-band message.

[0072] Sending a message in blockchain format means that the message conforms to the transaction format requirements of the target blockchain and the original sender of the transaction signs the transaction message. This allows the target blockchain or blockchain smart contract to identify and verify the original sender.

[0073] The controlled resource access application message carries the identity information and signature information of the authenticated device, as well as the information of the controlled resources (such as IP address, URL, blockchain address, etc., representing the information of the controlled resources); it may also include an application serial number. The application serial number is used to track the processing of the application by all relevant roles and smart contracts associated with each application and the corresponding messages sent. All processing corresponding to an application is called an application transaction. The application serial number can be used to prevent replay attacks and solve the problem of information tracking for different roles in the same application in a distributed environment to avoid the problem that the same application and its related information cannot be associated or the association is inaccurate. For example, if the same access application message is received repeatedly, if there is no application serial number, to determine whether it is the same access message, it is necessary to keep the original message (transaction) or the hash value of the message (transaction). With the application serial number, it can be determined by saving the application serial number. In addition, subsequent applications with the same serial number can be modified, invalidated, or used to design more flexible access application messages and mechanisms for the same access application. Each application is assigned a unique serial number by the applicant, such as a strictly monotonically increasing sequence of positive integers starting from 0 with a step size of 1. In the subsequent process, all associated roles, including smart contracts, perform a validity check on the application serial number, primarily to determine whether it is legally obtained according to the serial number rules and whether it is a message assembled from a replayed message or a partial message with an existing serial number. Because it is common to all processes, this check can be uniformly included in the following processing steps, so this check step and content will not be listed in each processing step. The signature information is a signature of the entire access application information, which can serve as both the integrity protection signature of the controlled resource access application message and the identity signature of the authenticated device. That is, the identity signature and integrity protection signature can be combined into one. If the "Controlled Resource Access Request" is sent in the form of a blockchain transaction (note that the out-of-band message format can also be the information format of the blockchain transaction, but it is not sent through the blockchain network), then when the blockchain account is used as the identity of the authentication device, the optimization method is: the identity signature and integrity signature can be replaced by the signature of the blockchain transaction's sender account on the transaction.

[0074] The recipient can determine the identity of the message generator and whether the message has been tampered with during transmission based on the identity signature and integrity protection signature.

[0075] In step 302, after receiving the controlled resource access application message, the secure resource control point detects whether the application message is legal. If it is legal, it initiates an authentication and authorization application to the smart contract based on the controlled resource access application message.

[0076] The authentication and authorization application includes the received controlled resource access application message, the identity information added by the security resource control point, and the signature of the entire "authentication and authorization application message", that is, the access application of the authenticated device (including the identity signature and information integrity signature), the identity signature and integrity protection signature of the authentication and authorization application by the security resource control point. Similarly, the identity signature and integrity protection signature can usually be combined into one. If the authentication and authorization application is issued in the form of a blockchain transaction, then when the blockchain account is used as the identity of the security resource control point, the identity signature and integrity signature can be directly replaced by the signature of the blockchain transaction sender account on the transaction.

[0077] In step 303, the smart contract processes the authentication and authorization request. Specifically, it authenticates the request through the smart contract's authentication function, verifies the sender's identity and signature of the "Authentication and Authorization Request Message" is a permitted control point, decrypts the contained "Controlled Resource Access Request" and verifies the original sender's identity and signature is a permitted subject, then unpacks the instructions and parameters contained in the "Controlled Resource Access Request" and performs calculations and logical processing according to the matching authentication function within the smart contract, returning the authentication result to the secure resource control point. In the context of blockchain smart contract technology, transactions sent to a smart contract for processing by a designated smart contract internal function are generally referred to as calls to that smart contract function. This means that the secure resource control point calls the smart contract function, and the caller receives a result returned after consensus on the blockchain.

[0078] Among them, when the smart contract performs identity authentication, control point allocation, and resource allocation, if the information supporting function calculation and judgment is stored at a designated interface address outside the smart contract, the smart contract needs to use the methods and addresses in the corresponding interactive interface information to interact, which will not be repeated below.

[0079] The smart contract processes the application according to the parameters and the applicant's identity, following the smart contract processing flow, and returns the authentication result to the secure resource control point. Furthermore, the smart contract can interact with the authentication device as needed to verify and confirm the smart contract's authentication result, and apply identity and integrity signature protection to the authentication result. This ensures that the authentication result returned by the smart contract carries the authentication device's identity information, identity signature, and information integrity signature, ensuring that the authentication result information has been approved by the authentication device.

[0080] In addition to including whether the access application is approved, the authentication result may also include the identity information of the security resource control point, the authentication result information of the security resource control point, the identity information and authentication result information of the authenticated device and the security resource usage information, as well as the identity and identity signature of the authentication device, and the integrity protection signature of the authentication device for the authentication result. Similarly, the identity signature and integrity protection signature of the authentication device can be combined into one.

[0081] Step 304: The security resource control point determines whether to open security resources according to the authentication result, and forwards the authentication result to the authenticated device according to the needs of the authenticated device.

[0082] Among them, the security resource control point determines whether the identity of the authentication device is legal based on the identity signature of the authentication device in the authentication result, and verifies the authenticity of the authentication result by the authentication device's information integrity signature on the authentication result, and then verifies the legality of the identity of the authenticated device and the legality of the application based on whether the identity of the authenticated device in the authentication result is passed and whether the application is passed. Only after confirming the legality of the identity of the authentication device and the legality of the identity and application of the authenticated device, can it decide to open the security resources and forward the authentication result to the authenticated device.

[0083] Step 305: the authenticated device authenticates the security resource control point and the authentication device respectively according to the authentication result, and accepts the authentication result after the authentication is successful.

[0084] The authenticated device determines the authenticity of the authentication device and whether the authentication result has been impersonated or tampered with based on the authentication device's identity, signature, and integrity protection signature in the authentication result. Furthermore, the authenticated device can also determine the identity and legitimacy of the security resource control point based on the security resource control point's identity information and the security resource control point's authentication result information in the authentication result. Furthermore, this also includes the authenticated device using the respective identities in the authentication result to perform bidirectional authentication with the security control point when subsequently accessing security resources based on the security resource usage information, i.e., by sending information with the identity signature to prove its identity to the other party.

[0085] Authentication solution B: The authenticated device interacts with the smart contract for authentication. It can be applied to situations where the communication address and / or blockchain address information of the security resource control point does not need to be known in advance or cannot be known, such as Figure 4 As shown, the following steps are included:

[0086] In step 401, the authenticated device directly sends a controlled resource access application message (transaction) to the address of the smart contract in the form of a blockchain transaction.

[0087] The controlled resource access request message can carry the identity information and signature information of the authenticated device, as well as information about the controlled resources; it can also carry the request serial number. The signature information, which is a signature of the entire access request message, can serve as both the integrity protection signature of the controlled resource access request message and the identity signature of the authenticated device. This means the identity signature and integrity protection signature can be combined into one. Because this information is sent to the smart contract via a blockchain transaction, these two signatures can typically be replaced by the signature of the original sender, the authentication device account, on the entire transaction. The blockchain can then verify the sender's identity and the integrity of the transaction information.

[0088] In step 402, the authentication function in the smart contract determines the legitimacy of the controlled resource access application message. If the message is legitimate, authentication and authorization are performed, the authentication result is notified to the security resource control point, and the authentication result is returned to the authenticated device.

[0089] The smart contract matches the security resources within the contract with the authentication level processing flow and configuration data, notifies the security resource control point of the authentication results, and returns the results to the authenticated device. Furthermore, the smart contract can interact with the authentication device as needed to verify and confirm the smart contract's authentication results and perform identity and integrity signature protection on the authentication results. The authentication results returned by the smart contract carry the authentication device's identity information, identity signature, and information integrity signature to ensure that the authentication results are recognized by the authentication device.

[0090] The authentication result includes not only whether the access application is approved, but also the identity information of the assigned security resource control point, the authentication result information of the assigned security resource control point, the identity information and authentication result information of the authenticated device and the allocated security resource usage information, as well as the identity and identity signature of the authentication device, and the integrity protection signature of the authentication device for the authentication result. Usually, the identity signature and the integrity protection signature can be combined into one.

[0091] Step 403: The security resource control point determines whether to open the security resource according to the authentication result.

[0092] The assigned security resource control point determines whether to grant access to secure resources based on the authentication result, judging the identity of the authenticated device and the legitimacy of the application. Furthermore, the authenticity of the authentication device can be determined based on the authentication device's identity and signature in the authentication result, and the authenticity of the authentication result can be verified by the authentication device's information integrity signature. This prevents malicious behavior on the blockchain, which could render smart contract processing results unreliable. Because the authentication device reviews and signs the authentication result for integrity protection, it cannot be tampered with by others, including the smart contract.

[0093] In step 404, the authenticated device authenticates the authenticating device and the security resource control point based on the authentication result. Specifically, the authenticated device can determine the authenticity of the authenticating device and whether the authentication result has been impersonated or tampered with based on the authenticating device's identity signature and the integrity protection signature of the authentication result. Furthermore, the authenticated device can also determine the identity and legitimacy of the security resource control point based on the security resource control point's identity information and the security resource control point's authentication result information in the authentication result. After all of these authentications are successful, the authenticated device accepts the authentication result.

[0094] In step 405, a two-way authentication is performed between the authenticated device and the security resource control point. Specifically, the authenticated device initiates an application for the use of controlled resources to the security resource control point based on the security resource usage information and security resource control point information in the authentication result. The authenticated device uses the authenticated device identity in the authentication result, the security resource control point obtained in the authentication result, and the corresponding allocated security resource information to initiate an application (message) for the use of the security resource and signs the message. The security resource control point responds to the message using the identity information in the authentication result, which includes further usage instructions and other information, and signs the message. The authenticated device and the security resource control point each use the information in the authentication result to sign and compare the identity of the other party. The security resource control point also compares the use application information based on the controlled resource information in the authentication result. If the comparison results are consistent, the security resource control point allows the authenticated device to access / use the controlled resources.

[0095] In an optimized solution for the authentication scheme (A or B or other authentication schemes), if the authenticated device, the authenticating device, and the security resource control point device are running in a trusted smart contract runtime environment, that is, these devices are confident that the called smart contract address and the call function results, including the return result, the generated contract data, and the notification message, are credible and will not be tampered with maliciously or unintentionally due to the called node not following the chain consensus or the specific running node of the called smart contract (tampering with such call results is often the behavior of consensus isolated nodes or malicious nodes), then the authenticating device can authorize the smart contract to provide the authentication results of the identity authentication and access application, and the authenticating device does not need to judge the application and sign the result. The authenticated device and the security resource control point device each make a judgment based on the authentication result given by the smart contract.

[0096] In an exemplary embodiment, the method further comprises:

[0097] The authentication device deletes the information of the authenticated device account in the smart contract.

[0098] Among them, the authentication object account and other information can be deleted in the smart contract through the authenticated device data addition and deletion interface, so that the authenticated device cannot access the network.

[0099] This embodiment of the present application utilizes blockchain addresses and digital signatures for bidirectional authentication when an authenticated device accesses a controlled resource. The authenticating device can determine whether the authenticated device, the controller device, and the resource access request are permitted; the authenticated device can also determine whether the authenticating device and the controller device are legitimate, and the controller device can also determine whether the authenticating device, the authenticated device, and the resource access are permitted. Leveraging the characteristics of blockchain and smart contracts, blockchain applications are empowered with intelligent operational processes, facilitating the development of new features. In particular, leveraging blockchain's unique characteristics, each blockchain address can become the access control management core for a single network at minimal cost, eliminating the need for complex authentication centers, certificate delivery centers, and other entities. An authentication system built around account addresses is more suitable for decentralized, small-scale, or household end-to-end security authentication deployments with high security requirements.

[0100] like Figure 5 As shown, in the distributed two-way authentication method based on blockchain in the embodiment of the present application, the operations on the authentication device side include:

[0101] Step 501: The authentication device receives a notification from the smart contract and reviews and confirms the authentication result. This notification can be sent through a blockchain event, a transaction notification, or a communication channel outside the blockchain (the smart contract can set the authentication device interaction interface information to indicate these supported interaction methods and specific communication methods). Then, the authentication device performs a two-way authentication process on the relevant device requesting access to the controlled resource and the controlled resource access application. That is, the authenticated device requesting access to the controlled resource, the security resource control point device designated by the authenticated device or the security resource control point device matched by the smart contract, and the access control resource permission designated by the authenticated device are authenticated through the smart contract.

[0102] Step 502: After the authentication device authenticates the above-mentioned device and application, the authentication device can directly send the authentication result to the blockchain account corresponding to other authentication-related devices in the form of a blockchain transaction or through the smart contract. The authentication result uses the authentication device account to perform identity signature and information integrity protection signature to prove that the authentication result is the result given by the authentication device and has not been tampered with during the transmission process.

[0103] Before step 501, the method may further include: the authentication device creates a smart contract on the blockchain.

[0104] In an exemplary embodiment, the authentication device applies for a blockchain account, and uses the account of the authentication device to create a blockchain smart contract. The account of the authentication device can be called a primary account.

[0105] The smart contract may include: authenticated device data, authentication function, security resource control point data, and owner information / authentication device and interaction interface information.

[0106] Accordingly, smart contracts can choose to include the following interface logic:

[0107] Authenticated device data addition and deletion interface, authentication function interface, owner information / authentication device and interaction interface information setting interface, security resource control point data addition and deletion interface.

[0108] In an exemplary embodiment, before step 501, the method further includes:

[0109] The authentication device sets the owner / authentication device information and interaction interface information of the smart contract.

[0110] Among them, the owner's account is set through the smart contract interface (usually smart contract technology provides the owner setting function of the smart contract) and the owner / authentication device interaction interface information is set.

[0111] The authentication device adds or modifies the security resource control point data in the smart contract, including detailed security resource information.

[0112] Among them, the resource control point information can be added or modified using the smart contract interface.

[0113] The authentication device adds information of the authenticated device account, and sets security resource access authority and authentication function corresponding to each or each type of authenticated device account.

[0114] Among them, the authentication device uses the master account to add the authenticated device account and other information in the smart contract through the "authenticated device data addition and deletion interface", specifies specific security resource access permissions, specifies specific authentication functions, and optionally specifies access control point information.

[0115] In step 501, when the authenticated device requests access to controlled resources, the smart contract may trigger the process of two-way authentication between the authentication device and related devices and the application, that is, the authenticated device requesting access to the controlled resources, the security resource control point device designated by the authenticated device or the security resource control point device matched by the smart contract, and the access controlled resource authority designated by the authenticated device are authenticated through the smart contract; in step 502, after the authentication device authenticates the above-mentioned devices and applications, the authentication device may directly send the corresponding authentication result to the blockchain account corresponding to the other authentication-related devices in the form of a blockchain transaction, or the authentication device may trigger the smart contract process to send the authentication result to other authentication-related devices by sending an authentication result message to the smart contract, or authorize the smart contract to send the authentication result to other authentication-related devices according to the contract function process, which is used to indicate the identity information and legitimacy of the devices participating in the authentication and whether the authenticated device is allowed to access the designated area and access the controlled resources, wherein the controlled resources may refer to the security resources in the designated area, and the designated area may include a designated network or a controlled security domain.

[0116] Steps 501 and 502 illustrate the interaction between the authentication device and the smart contract, where the smart contract performs a two-way authentication with the authenticated device and the secure resource control point. After the two-way authentication passes, the secure resource control point allows the authenticated device to access the controlled resources.

[0117] The interaction technology between blockchain smart contracts and accounts should be determined by the specific blockchain technology used. Generally, the interaction can be achieved as follows: Account notification / calling contracts can be achieved by sending smart contract transactions to the contract; in addition to directly sending transactions to the other party, the contract notification account can also notify the other party through several state variable change events within the smart contract (usually, blockchain smart contracts are designed with event message mechanisms, and state variable changes can trigger event events). Alternatively, the smart contract sets specific state variables, and the other party's account can obtain information by monitoring changes in these state variables to achieve the purpose of "being notified." An example of monitoring variable changes in this application is: the smart contract uses the following variable information: authentication state variable, authentication result information variable, interface variable, and application pointer variable. For a new access request, if the smart contract still requires confirmation from the authenticator after passing authentication, the "Authentication Status Variable" is set to "Contract authentication passed, but the authenticator still needs to confirm and sign the access request result information." The "Authentication Result Information Variable" is set to "the original authentication and authorization request sent and the security resource details allocated to it." The "Application Pointer Variable" is set to the original hash value of the access request message (the hash value of the blockchain transaction corresponding to the authentication and authorization request). The "Interface Variable" is set to "the specified authenticator interaction interface information and a pointer to the corresponding authentication result information variable." The authenticator determines whether to perform any action on the new access request by monitoring the "Interface Variable" and "Authentication Status Variable" associated with the smart contract on the blockchain. If necessary, the authenticator verifies that the identities of the authenticated party B and the security resource control point C, as well as the address of contract A, are correct. After confirming the authentication result is correct, Authenticator A sends a transaction to Contract A. The purpose is to modify the "Authentication Status Variable" to "Authenticator Confirmed Passed", add A's identity information and authentication pass information to the "Authentication Result Information Variable", and sign the entire "Authentication Result Information Variable" to replace the original information in the "Authentication Result Information Variable". (This transaction triggers the smart contract to subsequently send the authentication result to other authentication-related devices)

[0118] It should be understood that there are many ways to interact with smart contracts, depending on the specific blockchain smart contract technology and interface design. This method only demonstrates one possible implementation. The following description of smart contract interactions and returning messages to other roles will also be analogous and will not be repeated here.

[0119] In an exemplary embodiment, the method further comprises:

[0120] The authentication device deletes the information of the authenticated device account in the smart contract.

[0121] Among them, the authentication object account and other information can be deleted in the smart contract through the authenticated device data addition and deletion interface, so that the authenticated device cannot access the designated area.

[0122] In an exemplary embodiment, a distributed two-way authentication method based on blockchain includes:

[0123] When the authentication device is triggered by the smart contract in the blockchain, it performs two-way authentication with the authenticated device requesting access to the controlled resource and the controller device related to the controlled resource requested for access through the smart contract.

[0124] After the two-way authentication with the authenticated device is passed, the authentication device directly sends the authentication result to the authenticated device in the form of a blockchain transaction based on the information of the authenticated device or the interactive interface information of the authenticated device recorded in the smart contract, or sends the authentication result to the authenticated device through the smart contract; after the two-way authentication with the controller device is passed, the authentication device directly sends the authentication result to the controller device in the form of a blockchain transaction based on the information of the controller device or the interactive interface information of the controller device recorded in the smart contract, or sends the authentication result to the controller device through the smart contract.

[0125] In an exemplary embodiment, directly sending the authentication result in the form of a blockchain transaction or sending the authentication result to the authenticated device and the controller device through the smart contract includes:

[0126] The authentication device generates an authentication result indicating whether the authentication device's application for the authenticated device is approved, which carries the identity information and identity authentication information of the authenticated device and the controller device, the access authorization token of the authenticated device, the access information and authorization information of the controlled resource, and the identity information and signature information of the authentication device; the signature information is the integrity protection signature of the authentication device on the authentication result, and / or the identity signature information of the authentication device; the authentication result is sent to the authenticated device and the controller device via the smart contract or directly in the form of a blockchain transaction;

[0127] Alternatively, the authentication device authorizes the smart contract to generate an authentication result and send it to the authenticated device and the controller device, which carries the identity information and identity authentication information of the authenticated device and the controller device, the access authorization token of the authenticated device, and the access information and authorization information of the controlled resource.

[0128] like Figure 6 As shown, in the distributed two-way authentication method based on blockchain in the embodiment of the present application, the operation of the authenticated device includes:

[0129] 601. The authenticated device requests access to controlled resources;

[0130] 602. The authenticated device performs bidirectional authentication with the authentication device through a smart contract in the blockchain;

[0131] 603. After the two-way authentication is passed, the authenticated device accesses the controlled resource through the controller device. When accessing the controlled resource, two-way authentication is performed between the authenticated device and the controller device; wherein the controller device is a device for controlling the controlled resource.

[0132] In step 601, the authenticated device can directly or indirectly send a controlled resource access request message to the smart contract. Correspondingly, in step 602, two-way authentication can be performed using a variety of schemes, such as:

[0133] Authentication scheme A: The authenticated device interacts with the security resource control point for authentication, refer to Figure 3 ;

[0134] Authentication Scheme B: The authenticated device interacts with the smart contract for authentication. This can be applied to situations where the controller’s device address information is not required or cannot be known. Figure 4 .

[0135] If the controlled resource is a security resource in a designated area and the controller device is a security resource control point, then when the two-way authentication is passed, the authenticated device is allowed to use the security resource controlled by the security resource control point.

[0136] In an exemplary embodiment, the authenticated device requesting access to a controlled resource may include:

[0137] The authenticated device uses a direct method (i.e., the authentication scheme B method) or an indirect method (i.e., the authentication scheme A method) to send a controlled resource access application message to the address of the smart contract in the form of a blockchain transaction. The controlled resource access application message carries the information of the controlled resource, the identity information of the authenticated device, and the signature information of the authenticated device; the signature information is an integrity protection signature for the application message, and can also be used as the identity signature of the authenticated device.

[0138] In an exemplary embodiment, the authenticated device directly sends a controlled resource access request message to the address of the smart contract in the form of a blockchain transaction, which may include:

[0139] The authenticated device directly sends the controlled resource access application message to the address of the smart contract in the form of a blockchain transaction.

[0140] In an exemplary embodiment, the authenticated device uses an indirect method to send a controlled resource access request message to the address of the smart contract in the form of a blockchain transaction, which may include:

[0141] The authenticated device sends the controlled resource access application message to the address of the smart contract through the controller device in the form of a blockchain transaction.

[0142] In an exemplary embodiment, the authenticated device performs two-way authentication with the authentication device through a smart contract in the blockchain, which may include:

[0143] The authenticated device obtains an authentication result through the smart contract. The authentication result indicates whether the authentication device has authenticated the identity and access application of the authenticated device and detailed information. The authentication result carries the identity information and identity authentication information of the authenticated device and the controller device, the access authorization token of the authenticated device, the access information and authorization information of the controlled resource, and the signature information of the authentication device. The signature information is the integrity protection signature of the authentication device on the authentication result, and can also serve as the identity signature information of the authentication device.

[0144] The authenticated device performs identity authentication on the authenticating device according to the identity signature information of the authenticating device.

[0145] In another exemplary embodiment, when the authenticated device and / or controller device obtains an authentication result in a trusted smart contract execution environment and can confirm that the address of the invoked smart contract is trustworthy, the authentication result can be generated by the authentication device authorizing the smart contract to generate the authentication result, which contains the identity information and authentication information of the authenticated device and controller device, the access authorization token of the authenticated device, and the access information and authorization information of the controlled resource. In other words, the authentication device does not need to sign the authentication result.

[0146] In an exemplary embodiment, the authenticated device accesses the controlled resource through the controller device, and performing bidirectional authentication between the authenticated device and the controller device when accessing the controlled resource includes:

[0147] The authenticated device accesses the controlled resource through the controller device according to the access information of the controlled resource in the authentication result;

[0148] If the authenticated device uses a direct method when sending the controlled resource access application message, then when accessing the controlled resource, the authenticated device and the controller device each perform a two-way authentication based on the identity information in the authentication result message;

[0149] If the authenticated device sends the controlled resource access request message out-of-band, indirectly, to the controller device via a secure channel, and if that channel is used for controlled resource access authentication, upon receiving the authentication result message, the authenticated device and the controller device complete bidirectional authentication with the controller device. If these requirements are not met, subsequent access to controlled resources may require bidirectional authentication based on the identity information in the authentication result message.

[0150] The authenticated device uses an indirect method when sending a controlled resource access application message. When the authenticated device B and the controller device C initiate the above-mentioned authentication process through a secure channel, the authentication result carries the identity signature and information integrity signature of the message sent by B and C, as well as the identity authentication information of B and C by the authentication device A. Therefore, it can be considered that half of the two-way authentication between B and C has been completed. Subsequently, as long as C proves to B that its identity is C in the authentication result, if C uses C's identity in the authentication result to sign and integrity protect the message when forwarding the authentication result, B can authenticate C by comparing this signature with C's identity information in the authentication result to complete the two-way authentication between B and C. That is, in the indirect method, only when a reliable secure channel exists can the authentication result be considered as two-way authentication. In other cases, because the message is forwarded from an unknown third party, the device and identity cannot be bound, so separate two-way authentication is required between B and C.

[0151] The distributed two-way authentication method based on blockchain in an embodiment of the present application is applied to a controller device, including:

[0152] After receiving the controlled resource access request message, the controller device initiates an authentication authorization request to the smart contract based on the controlled resource access request message; receives the authentication result of the smart contract to determine whether to open the secure resource, and forwards the authentication result to the authenticated device according to the needs of the authenticated device (that is, forwarding the authentication result to the authenticated device is an optional operation); or, the controller device receives the authentication result to determine whether to open the secure resource. Specifically, there are two methods: indirect and direct:

[0153] When the indirect method, i.e., authentication scheme A, is adopted, the security resource control point, upon receiving the controlled resource access request message, initiates an authentication authorization request to the smart contract based on the controlled resource access request message; upon receiving the authentication result from the smart contract, determines whether to open the security resource, and forwards the authentication result to the authenticated device according to the needs of the authenticated device;

[0154] When the direct method, i.e., authentication scheme B, is adopted, the security resource control point receives the authentication result and determines whether to open the security resource;

[0155] When the authenticated device requests access to a controlled resource, and both the authenticated device and the authenticating device have passed bidirectional authentication, and the controller device and the authenticating device have passed bidirectional authentication, the controller device provides the authenticated device with access to the controlled resource;

[0156] The controller device performs two-way authentication with the authenticated device when the authenticated device accesses the device.

[0157] The distributed two-way authentication method based on blockchain in the embodiment of the present application is applied to smart contracts, including:

[0158] The smart contract receives a request from the authenticated device to access controlled resources;

[0159] The smart contract triggers two-way authentication between the authenticated device and the authentication device, and triggers two-way authentication between the controller device and the authentication device, so that when all authentications pass, the authenticated device accesses the controlled resources controlled by the controller device.

[0160] The trigger can be a direct notification, such as sending a transaction or event, or by changing a predetermined state variable. The authentication device monitors the changes in the state variable and, upon detecting a change to a predetermined state, performs a two-way authentication between the triggering device and the authenticating device or the authenticated device. The specific triggering method depends on the blockchain technology used and is not limited by this application.

[0161] In an exemplary embodiment, the smart contract receives a request from an authenticated device to access a controlled resource, including:

[0162] The smart contract receives a controlled resource access application message sent by the authenticated device to the address of this smart contract directly or indirectly through a blockchain transaction. The controlled resource access application message carries the identity information and signature information of the authenticated device and the information of the controlled resource; the signature information is an integrity protection signature for the application message and / or the identity signature of the authenticated device.

[0163] In an exemplary embodiment, the smart contract receives a controlled resource access request message sent by the authenticated device to the address of the smart contract directly in the form of a blockchain transaction, including:

[0164] The smart contract receives the controlled resource access application message sent by the authenticated device directly to the address of the smart contract in the form of a blockchain transaction.

[0165] In an exemplary embodiment, the smart contract receives a controlled resource access request message sent by the authenticated device to the address of the smart contract indirectly through a blockchain transaction, including:

[0166] The smart contract receives a controlled resource access application message sent by the authenticated device to the address of the smart contract through the controller device in the form of a blockchain transaction.

[0167] In an exemplary embodiment, triggering bidirectional authentication between the authenticated device and the authenticating device, and triggering bidirectional authentication between the controller device and the authenticating device, includes:

[0168] Sending an authentication request for the authenticated device and an authorization request for the controlled resource to the authentication device through blockchain transactions or other blockchain interaction methods (e.g., changing state variables, sending blockchain events, etc.);

[0169] Send the identity authentication of the controller device related to the application to the authentication device through a blockchain transaction or other blockchain interaction method;

[0170] Upon receiving the authentication result, the authentication result is sent directly or indirectly to the authenticated device through a blockchain transaction, or other blockchain interaction methods, and the authentication result carries the identity authentication result and access authorization token of the authenticated device, the access information of the controlled resource, the identity information and identity authentication result of the controller device, and the identity information of the authentication device and a signature on the authentication result information, which is also the identity signature information of the authentication device, so that the authenticated device can determine the authentication result and perform identity authentication on the authentication device and the controller device; and

[0171] The authentication result is sent to the controller device through blockchain transactions or other blockchain interaction methods, which carries the identity information and identity authentication result of the authenticated device and the access authorization token, the access information of the controlled resource, the identity information and identity authentication result of the controller device, and the identity information of the authentication device and the signature of the authentication result information, which is also the identity signature information of the authentication device, so that the controller device can determine the access information and perform identity authentication on the authentication device and the authenticated device.

[0172] In summary, the embodiments of the present application offer high security, low cost, and simple deployment, making them particularly suitable for security authentication in homes or small businesses, or decentralized multi-point, multi-service access security authentication. These applications are similar to unified access authentication for multiple IoT devices in a home, enterprise remote access authentication, secure resource usage authentication, and shared WiFi access authentication. The embodiments of the present application leverage the high availability of blockchain smart contracts, ensuring reliable operation even when some nodes fail. Blockchain smart contracts offer rich logical processing support, enabling the development of a wide variety of AAA (Authentication, Authorization, Accounting) processes.

[0173] The above embodiment is described below with reference to an application example.

[0174] 1) Initialization process:

[0175] 1) Generate a blockchain account according to the blockchain requirements. For convenience, this account is called the primary account.

[0176] Use this account to create a smart contract on the blockchain. The contract can optionally include the following interface logic:

[0177] a. The authenticated device data add / delete interface, also known as the authenticated object data add / delete interface, is used to add and delete authenticated device data. Authenticated device data includes the authenticated device account, authentication protocol, permission scope, device type, and other information identifying the device and corresponding permissions. This interface is subject to security level restrictions and requires the primary account or an account designated by the primary account to operate.

[0178] b. Authentication Function: This function determines / matches the access level of an account / device to a specific security resource. Its input parameters include (authenticated object information, security resource information, access request information, and optional security resource control point information). Its output is authentication status and authentication result information. This information is stateful and recorded on the blockchain (for example, the storage variable type in the Solidity language, commonly used in smart contracts). Multiple interfaces of this type can be configured. The authentication status records the current status of the access request, which can be categorized as: application, authentication device confirmation required, approved, or rejected. When the authentication status is "approved," the authentication result information is called an authentication pass message. The authentication result information includes, in addition to the authentication status, the identity information of the security resource control point, the authentication result information of the security resource control point, the identity and authentication result information of the authenticated device, the security resource usage information, the identity and identity signature of the authentication device, and the integrity protection signature of the authentication result information. The identity signature and integrity protection signature can often be combined into one.

[0179] c. Authentication device information and interactive interface information: The master account can set the authentication device details. Each authentication device or each type of authentication device corresponds to one or a type of authentication. This information includes: authentication device account, authentication protocol, authentication scope, device type, interactive interface information, and other information that identifies the device itself and the corresponding management authority. Usually the master account is the owner of the smart contract and is consistent with the authentication device account. Of course, a more complex account system can be set within the scope allowed by the specific blockchain smart contract to distinguish these roles. Practitioners can easily understand the authentication logic of this application, and it will not change the implementation method of this application, so it will not be listed or explained in detail here. Set this account in the authenticated device and the security access control point as the basis for the identity of the authentication device; you can also set one or more other accounts as the authentication device account, but the authenticated device and the security resource control point device that use the authentication device for two-way authentication need to set the corresponding authentication device account as the basis for verifying the identity of the authentication device for two-way authentication.

[0180] d. Security Resource Control Point Data Add / Delete Interface: This interface specifies the addition and deletion of security resource objects, including the security resource control point account (equivalent to an ID), device type, security resource information (including ID, type, access information, etc.), and interaction interface information. This interface can only be called by the owner or their designated account. The interaction interface information of the security resource control point is used by smart contracts, authenticators, or authenticatees to interact with the security resource control point when necessary.

[0181] 2) Set smart contract owner information interface. Blockchain smart contract technology typically provides an interface for setting the owner of a smart contract. The owner has the highest authority to create, destroy, and modify smart contracts. Once a smart contract is created, an owner is specified or the default creation account is the owner. When creating a smart contract, this interface can be called to set the smart contract owner's account and the operation permissions of various functions. The owner of a smart contract is usually the account that created the contract. In this application, the primary account is usually the owner role. Of course, the primary account can also grant one or more other accounts as owners to subsequently modify or revoke the smart contract.

[0182] 3) Use the security resource control point data addition and deletion interface to add or modify security resource objects including resource control point information.

[0183] 2) Increase equipment process

[0184] 1) The authenticated device applies for a blockchain account. For convenience, these accounts are called sub-accounts.

[0185] 2) The master account adds the authenticated device account and other information to the smart contract through the "Authenticated Device Data Add / Delete Interface," specifies specific security resource access permissions, specifies a specific authentication function, and optionally specifies access control point information. This information, combined with the security resource control point information, can be used for intelligent logic control and judgment of the authentication function.

[0186] 3) Set the smart contract address and optional authentication device account in the authenticated device and security resource control point device respectively (this information can be read from the smart contract in a secure smart contract environment).

[0187] 4) The authenticated device can now be used. To access secure resources, a two-way authentication process must be initiated, such as using authentication scheme A or authentication scheme B.

[0188] Authentication Scheme A, where the authenticated device indirectly sends a request for access to controlled resources to the smart contract, includes:

[0189] like Figure 7 As shown, Peer (node) A is the authentication device, also known as the authenticator; Peer B is the authenticated device, also known as the authenticated entity or authenticated object; Peer C is the security resource control point, also known as the controller device; and Contract a is the smart contract a deployed by Peer A. These are referred to as A, B, C, and Contract a below. When B wants to access a secure resource, B initiates an access request to Contract a through C. C is designated by B by directly forwarding the message, or assigned by Contract a to handle the original request. Typically, A is notified of the validity of the request. A authenticates the identities and signatures of B and C through contract a to ensure that B and C are not impersonating each other, and authenticates B's application for access rights to ensure that it is within the scope of the application rights; secondly, B must obtain access permission to secure resources through A's authentication and ensure that A is not impersonated and that A's authentication result is not impersonated. Therefore, it also needs to verify that A and the authentication result information are not impersonated through its own identity information of A and A's identity signature in the authentication result; in addition, B can also ensure that C's identity is legitimate through C's identity information carried in the authentication result information, and verify that C's device identity is not impersonated by performing two-way authentication with C using the identity information in the authentication result when accessing and using secure resources; similarly, C verifies that A and A's authentication result information are not impersonated through A's identity information set by itself and A's identity signature in the authentication result, and verifies that B's device is not impersonated by performing two-way authentication with B through B's identity signature carried in the authentication result information.

[0190] First, A achieves this goal by deploying contract a and setting authentication methods (authentication functions) and specific authenticated objects through the aforementioned initialization and device addition processes. Contract a's information and / or its address information are pre-installed in B and C. When B seeks access to or uses secure resources, it must identify itself to C. B initiates a request for controlled resource access to C via the blockchain network or an out-of-band channel in the form of a blockchain transaction. This request carries information about the secure resources B is requesting, along with B's identity and an integrity signature for the request. This signature also serves as B's identity signature. All subsequent steps require the sender to include their identity and signature in the message—the sender's identity information and the sender's integrity signature for the entire message. This signature also serves as the sender's identity signature. The recipient can use this signature to determine the message's originator's identity and whether the message has been tampered with during transmission. Upon receiving the request, C initiates an authentication and authorization request to contract a based on the secure resource request. This request is typically completed through a function call within a smart contract. C sends a blockchain smart contract transaction to the smart contract based on B's application type to call the smart contract function, which specifies the calling function and parameters and includes B's original application information.

[0191] Because it's a blockchain transaction, the transaction itself requires that C sign the message for integrity and identity. Contract A "receives the message" (typically, this refers to a blockchain account sending a transaction to invoke a smart contract function to invoke a specific function. The specific method and requirements for sending the message depend on the specific blockchain's smart contract methods and interfaces and are not detailed here). It then executes the processing steps according to the contract function. This includes verifying C's and B's identities, matching different security authentication levels within the contract, and interacting with account A as needed. The interaction technology between blockchain smart contracts and accounts depends on the specific blockchain technology used. Typically, this can be achieved as follows: Accounts can notify / call contracts by sending smart contract transactions to the contract. Contracts can notify their counterparts by sending blockchain transactions or state variable change events within the smart contract (blockchain smart contracts typically have an event messaging mechanism, with state variable changes triggering events). Accounts can also actively monitor changes in these state variables to obtain information and "be notified." A specific example of this application is that the smart contract uses the following variable information: authentication status variable, authentication result information variable, interface variable, and application pointer variable. For a new access application, if the smart contract authentication is passed and confirmation by the authenticator is required, the status of the "authentication status variable" is set to "the contract authentication is passed and the authenticator is required to confirm and sign the access application result information"; the "authentication result information variable" is set to "the original authentication and authorization application sent and the detailed information of the security resources allocated to the application"; the "application pointer variable" is set to the original hash value of the access application message (the hash value of the blockchain transaction corresponding to the authentication and authorization application); and the "interface variable" is set to "the specified authenticator interaction interface information and the pointer to the corresponding authentication result information variable". The authenticator can determine whether it is necessary to operate on the status of the new access application by monitoring the "interface variable" and "authentication status variable" related to itself on the smart contract on the blockchain. If necessary, verify the identities of B and C and the correctness of the contract a address. After confirming the authentication result is correct, A sends a transaction to contract a. The purpose is to modify the "Authentication Status Variable" to "Authenticator Confirmed Passed", add A's identity information and authentication pass information to the "Authentication Result Information Variable", and sign the entire "Authentication Result Information Variable" to replace the original information in the "Authentication Result Information Variable". (This transaction triggers the smart contract to subsequently send the authentication result to other authentication-related devices)

[0192] It should be understood that there are many ways to interact with smart contracts, depending on the specific blockchain smart contract technology and interface design. This method only demonstrates one possible implementation. The following description of smart contract interactions and returning messages to other roles will also be analogous and will not be repeated here.

[0193] The authentication result or authentication result information includes "authentication state variable" and "authentication result information variable" information.

[0194] Contract a returns the authentication result to C (for example, C monitors the transaction processing results sent and obtains the authentication result through the above state variables and authentication result information variables of contract A. Alternatively, contract a directly sends a blockchain transaction carrying the authentication result information to C.). The authentication result carries the identity information of B and C, the identity authentication results of B and C, detailed information on the security resources allocated to the application, including B's access authorization token (used to limit access to the authenticated device by time or time period), and other security resource access and authorization information, as well as A's identity information and signature on the information, i.e., A's integrity signature for the above information. When C receives the return result from contract a, it determines A's identity and verifies the integrity of the authentication result information and that the identity signature belongs to A, and then trusts the authentication result. C can confirm the legitimacy of B's ​​application through the authentication result. If B and C communicate using a non-blockchain network, C forwards the result to B. If B and C use a blockchain network as a means of communication, C sends a transaction to B via the blockchain network carrying the obtained authentication result. When B receives the return result of contract a, it determines whether A is impersonating and whether the authentication result has been tampered with based on A's signature. B can also determine C's identity as needed. If the authentication is successful, B can initiate subsequent access to the corresponding resources based on the security resource information allocated in the authentication result and C's information. In subsequent use, B and C use the identities in the authentication result to perform two-way authentication on the secure channel when accessing and using.

[0195] Note that in the indirect authentication process, B and C initiate the aforementioned authentication process over a secure channel. The message B sends to C carries B's identity information and signature. Furthermore, the authentication result contains the identity signatures and message integrity signatures of both B and C, as well as the authentication device's authentication information for both B and C. Therefore, half of the mutual authentication between B and C can be considered complete: C can confirm B's identity. Subsequently, C only needs to prove its identity to B, as evidenced by C's identity in the authentication result. If C signs and integrity-protects the message using C's identity in the authentication result before forwarding it, B can authenticate C by comparing this signature with C's identity in the authentication result, completing mutual authentication between B and C. For example, when a WiFi STA connects to a WiFi AP, the STA performs the aforementioned authentication interaction with the AP over an authenticated secure channel. Upon receiving the authentication result, C signs the message using its own identity information in the authentication result and sends it to B. B verifies that the signature matches C's identity in the authentication result, thus completing mutual authentication between B and C.

[0196] Authentication scheme B: The authenticated device directly sends a request for access to controlled resources to the smart contract.

[0197] Authentication scheme B is used in situations where it is not necessary or impossible to know the address information of the security resource control point C. Figure 8 shown.

[0198] In this authentication scheme, B does not need to know C's address. B initiates a secure resource access request to Contract A, which matches the request to the secure resource's control point, C. Contract A then generates an authentication result based on the matching function and the identity and resource information contained in the request. Contract A can also interact with Contract A based on the authentication type, as described in Authentication Scheme A and will not be repeated here. Contract A sends the authentication result to Contract C and Contract B (i.e., by setting the "authentication state variable" and "authentication result information variable," or directly sending a blockchain transaction with the authentication result). The information carried is the same as in Authentication Scheme A. Based on the result information, Contract A and Contract C can both determine the authenticity of the identities of Contract A, Contract B, Contract C, and Contract A, and that the information transmitted has not been tampered with, and accept the result of the request.

[0199] We know that parties conducting blockchain transactions typically don't own a blockchain node, but rather a wallet. These wallets rely on third-party nodes for blockchain interaction services. When roles A, B, and C simply use their own blockchain wallets, the results provided by the third-party node's smart contract are not necessarily trustworthy. Therefore, the final confirmation step by A in the above solution is necessary. If A, B, and C utilize their own nodes or trusted third-party nodes, improve the confidentiality of communication channels, and employ other technical measures to ensure full-chain consensus and prevent malicious nodes from influencing the smart contract's execution, the following optimization solution can be adopted.

[0200] One optimization solution is to use a trusted smart contract environment, such as one with trusted blockchain nodes and smart contract execution nodes, for A, B, and C to conduct smart contract-related blockchain transactions and obtain return results through these nodes. In other words, if the smart contract execution and results are trustworthy, A can authorize the smart contract to determine the access request, eliminating the need for A to confirm or sign the access request result. Because the smart contract execution result is trustworthy, the request result will contain A's identity information and the signature of A authorizing contract A, but not A's signature on the request result. All other information is consistent with authentication scheme A, meaning contract A can directly provide the result. A, B, and C can all use the "authentication status variable" and "authentication result information variable" to determine A's, B's, and C's identities, as well as the authentication result status.

[0201] Another optimization solution: In the smart contract, the identity information of the authenticated device can be verified by other methods besides the blockchain account that can perform identity verification and message signing; wherein, other authentication entities record the public key of the authenticated device, and the authenticated device retains its own private key. The authenticated device sends identity information signed with this private key for identity verification, so that other authentication entities can verify the identity of the authenticated device based on this identity information and private key signature; wherein, other authentication entities include one or more of the following: smart contracts, authentication devices, and controller devices.

[0202] For example, in A and contract a, the identity information of B and C can be recorded to verify their identities, rather than recording their blockchain addresses as identity information. Each B and C can have its own identity information, or a class of B or C can have a single identity information. For example, a public key (PK) can be recorded for a class of B. All devices that can prove possession of this public key can access the designated secure resource. If B1 and B2 possess the private key (Sk) corresponding to the PK, B1 and B2 can use Sk to sign and integrity-protect messages in the above process. Other devices or roles can verify that the messages sent by B1 and B2 correspond to this PK based on the identity and integrity signatures of the messages. This optimization eliminates the need to wait until each new device obtains a blockchain address before adding the blockchain address to the smart contract and A. Instead, this identity information can be added first, facilitating flexible system deployment. Similarly, A can be an identity information set in B and C, such as A's public key information PKA. In this case, A's identity signature and message integrity-protection signature in the above process are replaced with signatures using the private key corresponding to A's PKA.

[0203] 3) Deleting device process

[0204] Delete the authenticated device account and other information in the smart contract through the authenticated device data addition and deletion interface.

[0205] An embodiment of the present application also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the distributed two-way authentication method based on blockchain of any of the above embodiments is implemented.

[0206] An embodiment of the present application also provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the distributed two-way authentication method based on blockchain of any of the above embodiments.

[0207] In this embodiment, the above-mentioned storage medium may include but is not limited to: a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and other media that can store program codes.

[0208] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media generally embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

Claims

1. A distributed two-way authentication method based on blockchain, characterized in that: include: The authenticated device sends a controlled resource access application message to the address of the smart contract in the blockchain in the form of a blockchain transaction, or initiates a controlled resource access application message to the controller device through a secure channel, so that the controller device initiates an authentication authorization application to the smart contract based on the controlled resource access application message; The authenticated device performs two-way authentication with the authentication device through the smart contract to obtain an authentication result; After the two-way authentication is passed, the authenticated device accesses the controlled resource through the controller device. When accessing the controlled resource, if the controlled resource access application message is sent to the address of the smart contract, the authenticated device and the controller device perform two-way authentication based on the authentication result; if the controlled resource access application message is initiated to the controller device through a secure channel and the secure channel can be used for access authentication of the controlled resource, the authenticated device and the controller device complete two-way authentication when they obtain the authentication result; wherein, the controller device is a device used to control the controlled resource.

2. The method according to claim 1, wherein: The controlled resource access application message carries the information of the controlled resource, the identity information of the authenticated device, and the signature information of the authenticated device; the signature information is an integrity protection signature of the application message and / or the identity signature of the authenticated device.

3. The method according to claim 2, characterized in that The authenticated device performs two-way authentication with the authentication device through the smart contract in the blockchain to obtain the authentication result, including: The authenticated device performs two-way authentication with the authentication device through the smart contract to obtain an authentication result, wherein the authentication result indicates whether the authentication device has authenticated the identity and access application of the authenticated device. The authentication result carries the identity information and identity authentication information of the authenticated device and the controller device, the access authorization token of the authenticated device, the access information and authorization information of the controlled resource, and the signature information of the authentication device; the signature information is the integrity protection signature of the authentication device on the authentication result, and / or the identity signature information of the authentication device; The authenticated device performs identity authentication on the authenticating device according to the identity signature information of the authenticating device.

4. The method according to claim 2, wherein: When the authenticated device and / or controller device obtains an authentication result in a trusted smart contract operating environment and can confirm that the address of the called smart contract is credible, the authentication result is generated by the authentication device authorizing the smart contract, which carries the identity information and identity authentication information of the authenticated device and controller device, the access authorization token of the authenticated device, and the access information and authorization information of the controlled resource.

5. The method according to claim 3, characterized in that The authenticated device accessing the controlled resource through the controller device includes: The authenticated device accesses the controlled resource through the controller device according to the access information of the controlled resource in the authentication result.

6. A distributed two-way authentication method based on blockchain, characterized in that: include: When the authentication device is triggered by a smart contract in the blockchain, the authentication device performs two-way authentication with the authenticated device requesting access to the controlled resource and the controller device associated with the controlled resource requested for access through the smart contract. The smart contract is triggered upon receipt of a controlled resource access request message sent by the authenticated device in the form of a blockchain transaction, or upon receipt of an authentication and authorization request initiated by the controller device. The authentication and authorization request is initiated by the controller device based on the controlled resource access request message sent by the authenticated device in the form of a blockchain transaction via a secure channel. After the two-way authentication between the authentication device and the authenticated device and the controller device is passed, the authentication device sends the authentication result to the authenticated device and the controller device through the smart contract or directly sends the authentication result to the authenticated device and the controller device in the form of a blockchain transaction; wherein, when the smart contract receives the controlled resource access application message, the authenticated device and the controller device perform two-way authentication based on the authentication result; when the smart contract receives the controlled resource access application message and the secure channel can be used for access authentication of the controlled resource, the authenticated device and the controller device complete the two-way authentication when they obtain the authentication result.

7. The method according to claim 6, wherein The sending of the authentication result message to the authenticated device and the controller device through the smart contract or directly in the form of a blockchain transaction includes: The authentication device generates an authentication result indicating whether the authentication device's application for the authenticated device is passed, which carries the identity information and identity authentication information of the authenticated device and the controller device, the access authorization token of the authenticated device, the access information and authorization information of the controlled resource, and the identity information and signature information of the authentication device; the signature information is the integrity protection signature of the authentication device on the authentication result message, and / or the identity signature information of the authentication device; the authentication result is sent to the authenticated device and the controller device through the smart contract or directly in the form of a blockchain transaction; Alternatively, the authentication device authorizes the smart contract to generate an authentication result message and send it to the authenticated device and the controller device, which carries the identity information and identity authentication information of the authenticated device and the controller device, the access authorization token of the authenticated device, and the access information and authorization information of the controlled resources.

8. A distributed two-way authentication method based on blockchain, characterized in that: include: After receiving the controlled resource access request message sent by the authenticated device in the form of a blockchain transaction, the controller device initiates an authentication and authorization request to the smart contract based on the controlled resource access request message; Receive the authentication result of the smart contract to determine whether to open the security resource, and forward the authentication result to the authenticated device according to the needs of the authenticated device; or, the controller device receives the authentication result to determine whether to open the security resource; When the authenticated device requests access to a controlled resource, and both the authenticated device and the authenticating device pass bidirectional authentication, the controller device provides the controlled resource for the authenticated device to access; The controller device performs two-way authentication with the authenticated device when the authenticated device accesses the device; wherein, if the controller device has not received the controlled resource access application message, the controller device and the authenticated device perform two-way authentication based on the authentication result; if the controller device receives the controlled resource access application message through a secure channel and the secure channel can be used for access authentication of the controlled resource, the controller device and the authenticated device complete the two-way authentication when they obtain the authentication result.

9. A distributed two-way authentication method based on blockchain, characterized in that: include: The smart contract receives a controlled resource access application message sent by the authenticated device in the form of a blockchain transaction, or receives an authentication and authorization application initiated by the controller device; the authentication and authorization application is initiated by the controller device based on the controlled resource access application message after receiving the controlled resource access application message sent by the authenticated device in the form of a blockchain transaction through a secure channel; The smart contract triggers two-way authentication between the authenticated device and the authentication device, and triggers two-way authentication between the controller device and the authentication device, so that when all authentications pass, an authentication result is obtained, and the authenticated device accesses the controlled resource controlled by the controller device; wherein, when the authenticated device accesses the controlled resource, if the smart contract receives the controlled resource access request message, the authenticated device and the controller device perform two-way authentication based on the authentication result; When the smart contract receives the authentication authorization application and the secure channel can be used for access authentication of controlled resources, the authenticated device and the controller device complete the two-way authentication when they obtain the authentication result.

10. The method according to claim 9, characterized in that: The controlled resource access application message carries the identity information and signature information of the authenticated device and the information of the controlled resource; the signature information is an integrity protection signature of the application message and / or the identity signature of the authenticated device.

11. The method according to claim 10, characterized in that The triggering of bidirectional authentication between the authenticated device and the authenticating device, and the triggering of bidirectional authentication between the controller device and the authenticating device, include: Send the authentication application of the authenticated device and the authorization application of the controlled resources to the authentication device in the form of blockchain transactions; Sending the identity authentication of the controller device related to the authorization application to the authentication device in the form of a blockchain transaction; Upon receiving the authentication result, the authentication result is sent directly or indirectly to the authenticated device in the form of a blockchain transaction, which carries the identity authentication result and access authorization token of the authenticated device, the access information of the controlled resource, the identity information of the authenticating device and the signature of the authentication result information, which is also the identity signature information of the authenticating device, the identity information of the controller device and the identity authentication result, so that the authenticated device determines the authentication result and performs identity authentication on the authenticating device and the controller device; and The authentication result is sent to the controller device through a blockchain transaction, which carries the identity information of the authenticated device, the identity authentication result and the access authorization token, the access information of the controlled resource, the identity information of the authentication device and the signature of the authentication result information. The signature is also the identity signature information of the authentication device, so that the controller device can determine the access information and perform identity authentication on the authentication device and the authenticated device.

12. The method according to claim 10, wherein: The key information in the smart contract includes: authenticated device data, authentication function, security resource control point data, and smart contract owner information and interactive interface information; The authenticated device data includes authenticated object data, which includes one or more of the following: the authenticated device account, authentication protocol, permission scope, device type, and other information identifying the authenticated device itself and corresponding permissions; The authentication function is a function that implements the processing logic of authentication and authorization, and is used to determine or match the access rights of the authenticated device to a certain security resource and provide the corresponding allocated security resource control point data; The security resource control point data includes the security resource control point account, device type, security resource type, security resource detailed information, and interactive interface information; The owner is the creator of the smart contract or another account set as the owner of the smart contract in the smart contract; the owner can be a single account or multiple accounts; The owner's interaction interface information is used to identify the interaction interface when the owner / authentication device needs to confirm certain information, guiding the interaction between the smart contract or other authentication entity and the owner. The interaction interface may be one or more; if there are multiple interaction interfaces, the system selects one or more interaction interfaces for communication based on business or reliability.

13. The method according to claim 10, wherein: In a smart contract, the identity information of the authenticated device is verified by other methods other than the blockchain account that can be used for identity verification and message signing; other authentication entities record the public key of the authenticated device, while the authenticated device retains its own private key. The authenticated device sends identity information signed with this private key for identity verification, so that other authentication entities can verify the identity of the authenticated device based on this identity information and private key signature; other authentication entities include one or more of the following: smart contracts, authentication devices, and controller devices.

14. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method according to any one of claims 1 to 5 is implemented, or the method according to any one of claims 6 to 7 is implemented, or the method according to claim 8 is implemented, or the method according to any one of claims 9 to 13 is implemented.

15. A computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to implement the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 7, or the method according to claim 8, or the method according to any one of claims 9 to 13.

Citation Information

Patent Citations

  • industrial Internet of Things equipment identity authentication and security interaction method based on a block chain

    CN109918878A

  • Precise access control method, device and system based on block chain

    CN111327618A