A Certificate Management Method and Device for Blockchain
By encapsulating the certificate into a plug-in and adapting it according to the plug-in status, the problem that the alliance chain certificate management model is difficult to adapt to the application needs of microservices, and the flexibility and efficiency of certificate management are achieved, reducing the time cost of blockchain.
Patent Information
- Application Number
- CN202011455265.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-10
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2040-12-10
AI Technical Summary
The existing alliance chain certificate management model is difficult to adapt to the flexible application needs of the alliance chain and microservices. The traditional method of update configuration is cumbersome and cannot flexibly adapt to certificates from different institutions.
By encapsulating the certificate into a plug-in form and adapting different certificates according to the plug-in status of the certificate plug-in, it is possible to adapt different certificates without updating the blockchain configuration file, improving the efficiency of certificate management.
It realizes the flexibility to adapt different certificates without updating the blockchain configuration file, which improves the efficiency of certificate management and reduces the time cost of blockchain.
Smart Images

Figure CN114626847B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of blockchain, and particularly to a method and device for managing certificates of a blockchain. Background Art
[0002] In recent years, with the increasing maturity of blockchain technology, more and more blockchain applications have emerged in people's vision. According to specific application scenarios and business requirements, enterprises or organizations will select private chains, consortium chains, or public chains as the underlying technical architecture of the application. Among them, consortium chains have been widely used due to their technical characteristics of fast transaction speed, high scalability, and easy operation and maintenance. Consortium chains are usually participated in by specific consortiums or organizational members, so the authentication of participating nodes, clients, and users is particularly important, and the main way of authentication is to rely on various certificates to achieve.
[0003] Currently, the combination mode of consortium chains and microservices has become the main technical development direction, and its distributed characteristics can achieve functions such as rapid iteration of the underlying technical architecture, convenient fault tolerance, and agile development. However, the current consortium chain certificate management mode cannot well adapt to this flexible application demand. The traditional consortium chain certificate management method is to store relevant certificates in a specified path, and when the entire chain runs, read the certificates in this path through a configuration file or other means. When there is a need to adapt to certificates of different institutions, it can only be achieved by updating the relevant configuration of the chain, and the whole process is very cumbersome. Summary of the Invention
[0004] Embodiments of the present invention provide a method and device for managing certificates of a blockchain, so as to improve the efficiency of certificate management and reduce the time cost of the blockchain.
[0005] In a first aspect, embodiments of the present invention provide a method for managing certificates of a blockchain, including:
[0006] Obtain a transaction request sent by a client; the transaction request includes a transaction to be processed;
[0007] Judge whether the plug-in state of the certificate plug-in corresponding to the transaction to be processed is available. If not, put the transaction request into a preset message queue until it is determined that the plug-in state of the certificate plug-in corresponding to the transaction to be processed is available, and then send the transaction request to a sorting node for processing.
[0008] In the above technical solution, by encapsulating the certificate in the form of a plug-in and adapting different certificates according to the plug-in state of the certificate plug-in, it is possible to flexibly adapt different certificates without updating the configuration file of the blockchain, thereby improving the efficiency of certificate management.
[0009] Optionally, before obtaining the transaction request sent by the client, it further includes:
[0010] Obtain the certificates of each institution in the blockchain;
[0011] According to the configured scenarios and services, encapsulate the certificates into certificate plugins;
[0012] Store the certificate plugins in the blockchain in the form of dynamic libraries.
[0013] Optionally, the method further includes:
[0014] Listen for operations on the certificate plugins in the dynamic library through the certificate plugin management interface;
[0015] Convert the protocol of the monitored operations into the same protocol as the certificate authority party of the certificate plugin.
[0016] Optionally, the method further includes:
[0017] When it is monitored that the scenario and / or service changes, set the plugin status of the certificate plugin corresponding to the changed scenario and / or service to available.
[0018] Optionally, the method further includes:
[0019] When initializing the consensus module of the blockchain, load the certificate plugins required for the current scenario and / or service.
[0020] In a second aspect, an embodiment of the present invention provides a certificate management device for a blockchain, including:
[0021] An obtaining unit, configured to obtain a transaction request sent by a client; the transaction request includes a transaction to be processed;
[0022] A processing unit, configured to determine whether the plugin status of the certificate plugin corresponding to the transaction to be processed is available. If not, put the transaction request into a preset message queue until it is determined that the plugin status of the certificate plugin corresponding to the transaction to be processed is available, and then send the transaction request to the sorting node for processing.
[0023] Optionally, the processing unit is further configured to:
[0024] Before obtaining the transaction request sent by the client, obtain the certificates of each institution in the blockchain;
[0025] According to the configured scenarios and services, encapsulate the certificates into certificate plugins;
[0026] Store the certificate plugins in the blockchain in the form of dynamic libraries.
[0027] Optionally, the processing unit is further configured to:
[0028] Monitor operations on the certificate plugin in the dynamic library through the certificate plugin management interface;
[0029] Convert the protocol of the monitored operation into the same protocol as the certificate authority party of the certificate plugin.
[0030] Optionally, the processing unit is further configured to:
[0031] When it is monitored that the scenario and / or business has changed, set the plugin status of the certificate plugin corresponding to the changed scenario and / or business to available.
[0032] Optionally, the processing unit is further configured to:
[0033] When initializing the consensus module of the blockchain, load the certificate plugins required for the current scenario and / or business.
[0034] In a third aspect, an embodiment of the present invention further provides a computing device, including:
[0035] A memory for storing program instructions;
[0036] A processor for calling the program instructions stored in the memory and executing the above-mentioned blockchain certificate management method according to the obtained program.
[0037] In a fourth aspect, an embodiment of the present invention further provides a computer-readable non-volatile storage medium, including computer-readable instructions, when a computer reads and executes the computer-readable instructions, the computer is caused to execute the above-mentioned blockchain certificate management method. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0039] Figure 1 A schematic diagram of a system architecture provided by an embodiment of the present invention;
[0040] Figure 2 A flowchart of a blockchain certificate management method provided by an embodiment of the present invention;
[0041] Figure 3 A schematic diagram of blockchain transaction processing provided by an embodiment of the present invention;
[0042] Figure 4Schematic diagram of a certificate management device for a blockchain provided by an embodiment of the present invention. Detailed implementation manners
[0043] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0044] Figure 1 A system architecture provided by an embodiment of the present invention. As Figure 1 shown, the system architecture may include upper-layer applications, member management, certificate services, chain code services, consensus services, ledger storage and other unit modules;
[0045] Among them, the upper-layer applications can provide functions such as APIs, operation interfaces, and log management.
[0046] The member management can implement the functions of registering members in the consortium blockchain and interacting with certificate services.
[0047] The certificate services can implement certificate management and certificate status management, and the certificate status can also be referred to as the plug-in status.
[0048] The chain code services are used to provide a secure container execution environment and a secure mirror file repository.
[0049] The consensus services mainly provide services such as P2P protocols, distributed ledgers, sorting services, and endorsement verification.
[0050] The ledger storage can provide storage functions such as distributed storage, relational databases, KV databases, and IPFS.
[0051] It should be noted that the structure shown above Figure 1 is only an example, and the embodiments of the present invention are not limited thereto.
[0052] Based on the above description, Figure 2 the flow of a certificate management method for a blockchain provided by an embodiment of the present invention is shown in detail, and this flow can be executed by a certificate management device of the blockchain.
[0053] As Figure 2 shown, the flow specifically includes:
[0054] Step 201, obtain a transaction request sent by a client.
[0055] In an embodiment of the present invention, the transaction request includes a transaction to be processed. Before obtaining the transaction request sent by the client, it is necessary to first encapsulate the certificate. Specifically, the certificates of each institution in the blockchain can be obtained, and then, according to the configured scenarios and services, the certificates are encapsulated into certificate plugins, and finally the certificate plugins are stored in the blockchain in the form of dynamic libraries.
[0056] When the consensus module in the blockchain is initialized, the certificate plugins required for the current scenario and / or service can be loaded simultaneously. Each certificate plugin is equipped with the scenarios and service types it uses. When a transaction request corresponding to the corresponding scenario and service arrives, the certificate plugin can be called automatically.
[0057] In order to be able to flexibly adapt to the certificate plugins used in different scenarios and services, when it is monitored that the scenario and / or service has changed, the plugin status of the certificate plugin corresponding to the changed scenario and / or service can be set to available, and at the same time, the plugin status of the certificate plugin corresponding to the scenario and / or service before the change is set to unavailable.
[0058] That is to say, when the CA service or application certificate requirements change, there is no need to modify the chain configuration file. Only the relevant certificate plugins need to be added, deleted, or modified. The system can dynamically update the plugin status when it monitors the changes of the plugins.
[0059] In order to facilitate different entities to uniformly operate on the certificates, the certificate plugin management interface can monitor the operations on the certificate plugins in the dynamic library, and then convert the protocol corresponding to the monitored operations into the same protocol as the certificate authority party of the certificate plugin, that is, the common certificate methods (certificate application, certificate update, certificate revocation) can be abstracted to adapt to the protocols of different certificate authority parties.
[0060] Step 202, determine whether the plugin status of the certificate plugin corresponding to the transaction to be processed is available. If not, put the transaction request into a preset message queue until it is determined that the plugin status of the certificate plugin corresponding to the transaction to be processed is available, and then send the transaction request to the sorting node for processing.
[0061] After obtaining the transaction request, it is necessary to first determine whether the certificate plugin corresponding to the transaction to be processed in the transaction request is available. If available, the transaction request can be directly sent to the sorting node for subsequent processing. If not, the transaction request needs to be put into a preset message queue first, and at the same time, continue to monitor the plugin status until it is determined that the plugin status of the certificate plugin corresponding to the transaction to be processed is available, and then send the transaction request to the sorting node for processing, that is, sorting the transactions and generating blocks.
[0062] In the specific implementation process, when the status of a plugin changes, the system generates a middleware for this plugin. When the operation in the transaction request received by the blockchain involves the certificate method in this plugin, it will be intercepted by this middleware, and the transaction request will be stored in a preset message queue (in the embodiments of the present invention, redis can be used). When the status update of the certificate plugin is completed, the requests are taken out from redis in sequence and subsequent operations are executed.
[0063] To better adapt to the pluggable consensus framework characteristics of the blockchain, the system binds the certificate plugin module to the consensus framework. By modifying the code in the controller package under the consensus module (consensus) path of the blockchain, the supporting certificate plugin is loaded in the consensus module initialization method, thereby realizing the dynamic association between the certificate module and the consensus algorithm.
[0064] The certificate management method provided in the embodiments of the present invention can integrate the certificates required during the operation of the consortium chain into the plugin, realize dynamic management of various certificates during the operation of the chain system, and at the same time provide a unified management interface for relevant technical personnel for development and maintenance. Dynamically binding the certificate plugin to the formula framework can meet the high scalability requirements for the development of the consortium chain towards the pluggable microservice direction.
[0065] To better explain the embodiments of the present invention, the process of the above-mentioned blockchain certificate management will be described below in a specific implementation scenario.
[0066] As Figure 3 shown, the specific steps include:
[0067] Step 1, submit a transaction proposal.
[0068] Step 2, return the endorsement result.
[0069] The application program and the endorsement node interact with each other to achieve transaction endorsement.
[0070] Step 3, submit the signed endorsement and the transaction.
[0071] The application program submits the signed endorsement and the transaction request to the blockchain.
[0072] The blockchain determines whether the plugin status of the certificate corresponding to the transaction in the transaction request is available. If it is available, it proceeds to Step 4. Otherwise, it asks whether to continue the transaction. If not, the transaction ends. If it continues, the transaction request is put into the message queue. At the same time, the blockchain system monitors the plugin status. When it is determined that the plugin status is available, the transaction is released and sent to the sorting node.
[0073] Step 4, sort the transactions and generate a block.
[0074] The sorting node sorts the transactions and generates a block.
[0075] Step 5, broadcast the block.
[0076] The sorting node broadcasts the block.
[0077] Step 6, synchronize the block.
[0078] Each node in the blockchain synchronizes the block.
[0079] In an embodiment of the present invention, a transaction request sent by a client is obtained. The transaction request includes a transaction to be processed. It is determined whether the plugin status of the certificate plugin corresponding to the transaction to be processed is available. If not, the transaction request is placed in a preset message queue until it is determined that the plugin status of the certificate plugin corresponding to the transaction to be processed is available, and then the transaction request is sent to the sorting node for processing. By encapsulating the certificate in the form of a plugin and adapting different certificates according to the plugin status of the certificate plugin, it is possible to flexibly adapt different certificates without updating the configuration file of the blockchain, thereby improving the certificate management efficiency.
[0080] Based on the same technical concept, Figure 4 Exemplarily shows the structure of a certificate management device of a blockchain provided by an embodiment of the present invention. The device can execute the certificate management process of the blockchain.
[0081] As Figure 4 shown, the device specifically includes:
[0082] An obtaining unit 401, configured to obtain a transaction request sent by a client; the transaction request includes a transaction to be processed;
[0083] A processing unit 402, configured to determine whether the plugin status of the certificate plugin corresponding to the transaction to be processed is available. If not, the transaction request is placed in a preset message queue until it is determined that the plugin status of the certificate plugin corresponding to the transaction to be processed is available, and then the transaction request is sent to the sorting node for processing.
[0084] Optionally, the processing unit 402 is further configured to:
[0085] Before obtaining the transaction request sent by the client, obtain the certificates of each institution in the blockchain;
[0086] According to the configured scenario and business, encapsulate the certificate as a certificate plugin;
[0087] Store the certificate plugin in the blockchain in the form of a dynamic library.
[0088] Optionally, the processing unit 402 is further configured to:
[0089] Monitor operations on the certificate plug-in in the dynamic library through the certificate plug-in management interface;
[0090] Convert the protocol of the monitored operation into the same protocol as the certificate authority party of the certificate plug-in.
[0091] Optionally, the processing unit 402 is further configured to:
[0092] When it is monitored that the scenario and / or business has changed, set the plug-in status of the certificate plug-in corresponding to the changed scenario and / or business to available.
[0093] Optionally, the processing unit 402 is further configured to:
[0094] When the consensus module of the blockchain is initialized, load the certificate plug-ins required for the current scenario and / or business.
[0095] Based on the same technical concept, an embodiment of the present invention further provides a computing device, including:
[0096] A memory for storing program instructions;
[0097] A processor for calling the program instructions stored in the memory and executing the above-mentioned certificate management method of the blockchain according to the obtained program.
[0098] Based on the same technical concept, an embodiment of the present invention further provides a computer-readable non-volatile storage medium, including computer-readable instructions, which when read and executed by a computer, cause the computer to execute the above-mentioned certificate management method of the blockchain.
[0099] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks to specify the function of the device.
[0100] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements in the process Figure 1one or more processes and / or blocks Figure 1 functions specified in one or more blocks.
[0101] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 one or more processes and / or blocks Figure 1 or more processes and / or blocks.
[0102] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to cover the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.
[0103] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. A method for managing certificates in a blockchain, characterized in that, including: Obtain the certificates of each institution in the blockchain; Encapsulate the certificates into certificate plugins according to the configured scenarios and services; Store the certificate plugins in the blockchain in the form of dynamic libraries; Obtain a transaction request sent by a client; the transaction request includes a transaction to be processed; Determine whether the plugin status of the certificate plugin corresponding to the transaction to be processed is available. If not, put the transaction request into a preset message queue until it is determined that the plugin status of the certificate plugin corresponding to the transaction to be processed is available, and then send the transaction request to the sorting node for processing; Wherein, when it is monitored that the scenario and / or service has changed, set the plugin status of the certificate plugin corresponding to the changed scenario and / or service to available.
2. The method according to claim 1, characterized in that, The method further includes: Monitor the operations on the certificate plugins in the dynamic library through a certificate plugin management interface; Convert the protocol of the monitored operations into the same protocol as the certificate authority party of the certificate plugin.
3. The method according to any one of claims 1 to 2, characterized in that, The method further includes: When initializing the consensus module of the blockchain, load the certificate plugins required for the current scenario and / or service.
4. A device for managing certificates in a blockchain, characterized in that, including: An obtaining unit, configured to obtain the certificates of each institution in the blockchain; Encapsulate the certificates into certificate plugins according to the configured scenarios and services; Store the certificate plugins in the blockchain in the form of dynamic libraries; Obtain a transaction request sent by a client; the transaction request includes a transaction to be processed; A processing unit, configured to determine whether the plugin status of the certificate plugin corresponding to the transaction to be processed is available. If not, put the transaction request into a preset message queue until it is determined that the plugin status of the certificate plugin corresponding to the transaction to be processed is available, and then send the transaction request to the sorting node for processing; Wherein, when it is monitored that the scenario and / or service has changed, set the plugin status of the certificate plugin corresponding to the changed scenario and / or service to available.
5. The device according to claim 4, characterized in that, The processing unit is further configured to: Monitor the operations on the certificate plugins in the dynamic library through a certificate plugin management interface; Convert the protocol of the monitored operations into the same protocol as the certificate authority party of the certificate plugin.
6. A computing device, characterized in that, including: A memory, configured to store program instructions; A processor, configured to call the program instructions stored in the memory and execute the method according to any one of claims 1 to 3 according to the obtained program.
7. A computer-readable non-volatile storage medium, characterized in that, including computer-readable instructions, when a computer reads and executes the computer-readable instructions, causing the computer to execute the method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Multi-CA application authentication method based on block chain
CN107273760A
Certificate processing method and device for blockchain network, electronic equipment and storage medium
CN110597911A