Blockchain-based SDP Access Control Method and System

By introducing blockchain technology into the SDP system, verifying and recording the information and policies of the SDP connection acceptance host, the problem of SDP controller vulnerability and incorrect authorization is solved, and higher security and system stability are achieved.

CN114764492BActive Publication Date: 2025-05-30CHINA MOBILE COMM LTD RES INST +1

Patent Information

Application Number
CN202110001453.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-04
Publication Date
2025-05-30
Estimated Expiration
2041-01-04

AI Technical Summary

Technical Problem

SDP controllers are susceptible to DDoS attacks and incorrect implementation authorization, which causes the system to fail to function properly.

Method used

The blockchain-based SDP access control method is adopted to verify the host's host information and supported connection policies through the blockchain system nodes, and record it in the blockchain ledger to ensure the transparency and immutability of identity authentication and authorization.

Benefits of technology

It effectively avoids the problem of SDP controllers suffering from DDoS attacks and incorrect authorization, and improves the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114764492B_ABST
    Figure CN114764492B_ABST
Patent Text Reader

Abstract

The present invention provides a blockchain-based SDP access control method and system. The SDP connection acceptance host sends the SDP connection acceptance host information and supported connection policies to the blockchain system nodes, conducts blockchain node verification and consensus, and records them in the blockchain ledger. The SDP connection initiation host submits an identity authentication request to the blockchain system nodes. The blockchain system nodes verify the identity authentication request information, search for the list of SDP connection acceptance hosts that the SDP connection initiation host can access, and return it to the SDP connection initiation host. The SDP connection initiation host initiates a connection request, and the connection request includes the signature of the blockchain system nodes for the SDP connection acceptance host. The SDP connection acceptance host verifies the connection request initiated by the SDP connection initiation host, and provides access services after successful verification. The present invention can avoid the SDP controller from being attacked by DDoS and prevent the SDP controller from implementing incorrect authorization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a blockchain-based SDP access control method and system. Background Art

[0002] Software Defined Perimeter (SDP) aims to enable application owners to deploy perimeter security when needed to isolate services from insecure networks. SDP replaces physical devices with logical components controllable by application owners, and only after device authentication and identity authentication does SDP allow access to application infrastructure.

[0003] See Figure 1 , SDP consists of two parts: SDP hosts and SDP controllers. SDP hosts can create connections or accept connections. The SDP controller mainly performs host authentication and policy distribution. The SDP host and the SDP controller interact through a secure control channel. The SDP host is further divided into an SDP connection initiation host (IH) and an SDP connection acceptance host (AH).

[0004] SDP changes the traditional website connection method. In traditional connections, the client needs to establish a connection with the server, which exposes the server to the public network. If the server has vulnerabilities, it may be exploited; users enter usernames and passwords through the login page, and this method may cause the usernames and passwords to be stolen; in addition, multi-factor authentication can be used in addition to usernames and passwords. Through multi-factor authentication, the loss of usernames and passwords can be resisted, but multi-factor authentication is not very user-friendly for users.

[0005] At present, in the SDP system, the SDP controller controls the accessible service list of the IH, as well as information such as the IP address and connection parameters (such as port numbers, protocols, etc.) of the AH. Since the SDP controller is a centralized device and is exposed to the network, it is vulnerable to network attacks such as DDoS (Distributed Denial of Service). Once the controller is attacked by the network and stops serving, it may cause the entire system to malfunction, and the IH will be unable to access any data. Summary of the Invention

[0006] The present invention provides a blockchain-based SDP access control method and system, which provides SDP services to customers in a blockchain manner, and solves the problems of DDoS attacks on the SDP controller and incorrect authorization implemented by the SDP controller.

[0007] To solve the above technical problems, the present invention is implemented as follows:

[0008] In a first aspect, the present invention provides a blockchain-based SDP access control method, including:

[0009] The SDP connection accepting host sends the information to be verified to the blockchain system node, where the information to be verified includes: the host information of the SDP connection accepting host and the supported connection policies, so that the blockchain system node verifies the information to be verified and records it in the blockchain ledger after the verification passes;

[0010] The SDP connection accepting host receives a connection request sent by the SDP connection initiating host, where the connection request includes the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node;

[0011] If the SDP connection accepting host is in the SDP connection accepting host list, the SDP connection accepting host verifies the signature information according to the supported connection policies, and sends a request response to the SDP connection initiating host after the verification is successful.

[0012] Optionally, the SDP connection accepting host information includes at least one of the following: IP address, port, and protocol information; the supported connection policies include at least one of the following: the login ID of the accessing user, IP address, geographical location, and the blockchain node verification or endorsement policy.

[0013] Optionally, the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

[0014] Optionally, the information to be verified further includes: the signature of the host information and the supported connection policies of the SDP connection accepting host.

[0015] In a second aspect, the present invention provides a blockchain-based SDP access control method, including:

[0016] The blockchain system node receives the information to be verified sent by the SDP connection accepting host, where the information to be verified includes: the host information of the SDP connection accepting host and the supported connection policies;

[0017] The blockchain system node verifies the information to be verified and records it in the blockchain ledger after the verification passes;

[0018] The blockchain system node receives an identity authentication request submitted by the SDP connection initiating host;

[0019] The node of the blockchain system verifies the identity authentication request information. After successful verification, it searches in the blockchain for the list of SDP connection receiving hosts that the SDP connection initiating host can access, and returns the list of SDP connection receiving hosts to the SDP connection initiating host.

[0020] Optionally, the information to be verified further includes: the host information of the SDP connection receiving host and the signature of the supported connection policy.

[0021] Optionally, if the SDP connection initiating host in the identity authentication request signs the timestamp with its own private key;

[0022] The verification of the identity authentication request information by the node of the blockchain system includes:

[0023] The node of the blockchain system verifies the signature and timestamp submitted by the SDP connection initiating host.

[0024] Optionally, if the identity authentication request contains a KDF or the encrypted information of the KDF using the public key of the authentication node A1;

[0025] The verification of the identity authentication request information by the node of the blockchain system includes:

[0026] The node of the blockchain system verifies whether the KDF is correct.

[0027] Optionally, if the identity authentication request contains a token or the encrypted information of the token using the public key of the authentication node A2;

[0028] The verification of the identity authentication request information by the node of the blockchain system includes:

[0029] The node of the blockchain system verifies whether the token is correct.

[0030] In a third aspect, a method for SDP access control based on blockchain is provided, including:

[0031] The SDP connection initiating host sends an identity authentication request to the node of the blockchain system;

[0032] The SDP connection initiating host receives the list of SDP connection receiving hosts that can be accessed sent by the node of the blockchain system;

[0033] The SDP connection initiating host sends a connection request to the SDP connection receiving host, and the connection request includes the signature information of the SDP connection receiving host in the list of SDP connection receiving hosts by the node of the blockchain system;

[0034] The SDP connection initiation host receives the request response sent by the SDP connection acceptance host.

[0035] Optionally, in the identity authentication request, the SDP connection initiation host signs the timestamp with its own private key.

[0036] Optionally, if the SDP connection initiation host and the authentication node A1 have shared username and secret information, the identity authentication request includes KDF or the encrypted information of KDF using the public key of the authentication node A1.

[0037] Optionally, if the SDP connection initiation host has a token provided by the authentication node A2, the identity authentication request includes the token or the encrypted information of the token using the public key of the authentication node A2.

[0038] Optionally, the signature information of the SDP connection acceptance host in the SDP connection acceptance host list by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

[0039] In a fourth aspect, a blockchain-based SDP access control system is provided, including:

[0040] A first information verification module, configured to send the information to be verified to the blockchain system node, where the information to be verified includes: the host information of the SDP connection acceptance host and the supported connection policy, so that the blockchain system node verifies the information to be verified and records it in the blockchain ledger after the verification passes;

[0041] A first connection request module, configured to receive a connection request sent by the SDP connection initiation host, where the connection request includes the signature information of the SDP connection acceptance host in the SDP connection acceptance host list by the blockchain system node;

[0042] A first request response module, configured to, if the SDP connection acceptance host is in the SDP connection acceptance host list, verify the signature information according to the supported connection policy, and send a request response to the SDP connection initiation host after the verification is successful.

[0043] Optionally, the SDP connection acceptance host information includes at least one of the following: IP address, port, and protocol information; the supported connection policy includes at least one of the following: the login ID of the accessing user, IP address, geographical location, and the blockchain node verification or endorsement policy.

[0044] Optionally, the signature information of the SDP connection acceptance host in the SDP connection acceptance host list by the blockchain system node is the signature of one or more blockchain system nodes, which are determined according to the blockchain node verification or endorsement policy.

[0045] Optionally, the information to be verified further includes: the host information of the SDP connection acceptance host and the signature of the supported connection policy.

[0046] In a fifth aspect, a blockchain-based SDP access control system is provided, including:

[0047] A second information verification module, configured to receive the information to be verified sent by the SDP connection acceptance host, where the information to be verified includes: the host information of the SDP connection acceptance host and the supported connection policy; verify the information to be verified, and record it in the blockchain ledger after the verification passes;

[0048] A first identity authentication request module, configured to receive the identity authentication request submitted by the SDP connection initiating host;

[0049] A verification feedback module, configured to verify the identity authentication request information, and after the verification passes, search in the blockchain for the list of SDP connection acceptance hosts that the SDP connection initiating host can access, and return the list of SDP connection acceptance hosts to the SDP connection initiating host.

[0050] Optionally, the information to be verified further includes: the host information of the SDP connection acceptance host and the signature of the supported connection policy.

[0051] Optionally, if the SDP connection initiating host in the identity authentication request signs the timestamp with its own private key;

[0052] The verification of the identity authentication request information includes: verifying the signature and timestamp submitted by the SDP connection initiating host.

[0053] Optionally, if the identity authentication request contains a KDF or the encrypted information of the KDF using the public key of the authentication node A1;

[0054] The verification of the identity authentication request information includes: verifying whether the KDF is correct.

[0055] Optionally, if the identity authentication request contains a token or the encrypted information of the token using the public key of the authentication node A2;

[0056] The verification of the identity authentication request information includes: verifying whether the token is correct.

[0057] Sixth aspect, a blockchain-based SDP access control system is provided, including:

[0058] A second identity authentication request module, configured to send an identity authentication request to a blockchain system node; and receive a list of SDP connection acceptance hosts that can be accessed sent by the blockchain system node;

[0059] A second connection request module, configured to send a connection request to an SDP connection acceptance host, where the connection request includes signature information of the blockchain system node for the SDP connection acceptance host in the list of SDP connection acceptance hosts;

[0060] A second request response module, configured to receive a request response sent by the SDP connection acceptance host.

[0061] Optionally, in the identity authentication request, the SDP connection initiating host signs the timestamp with its own private key.

[0062] Optionally, if the SDP connection initiating host and the authentication node A1 have shared username and secret information, the identity authentication request includes KDF or encrypted information of KDF using the public key of the authentication node A1.

[0063] Optionally, if the SDP connection initiating host has a token provided by the authentication node A2, the identity authentication request includes the token or encrypted information of the token using the public key of the authentication node A2.

[0064] Optionally, the signature information of the blockchain system node for the SDP connection acceptance host in the list of SDP connection acceptance hosts is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

[0065] Seventh aspect, an SDP connection acceptance host is provided, including: a processor, a memory, and a program stored on the memory and executable on the processor, where when the program is executed by the processor, it implements the steps of the blockchain-based SDP access control method according to the first aspect or any possible implementation manner thereof.

[0066] Eighth aspect, a blockchain system node is provided, including: a processor, a memory, and a program stored on the memory and executable on the processor, where when the program is executed by the processor, it implements the steps of the blockchain-based SDP access control method according to the second aspect or any possible implementation manner thereof.

[0067] In a ninth aspect, an SDP connection initiating host is provided, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the steps of the blockchain-based SDP access control method of the third aspect or any possible implementation thereof are implemented.

[0068] In a tenth aspect, a computer-readable storage medium is characterized in that a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the blockchain-based SDP access control method of the first aspect or any possible implementation thereof are implemented;

[0069] Alternatively, when the computer program is executed by a processor, the steps of the blockchain-based SDP access control method of the second aspect or any possible implementation thereof are implemented;

[0070] Alternatively, when the computer program is executed by a processor, it implements the steps of the blockchain-based SDP access control method of the third aspect or any possible implementation thereof.

[0071] In the present invention, the SDP connection accepting host sends the SDP connection accepting host information and the supported connection strategies to the blockchain system node; the SDP connection accepting host information and the supported connection strategies are verified and agreed upon by the blockchain node, and the SDP connection accepting host information and the supported connection strategies after the blockchain node verification and consensus are recorded in the blockchain account book; the SDP connection initiating host submits an identity authentication request to the blockchain system node; the blockchain system node verifies the identity authentication request information submitted by the SDP connection initiating host, and the verification of the identity authentication information includes searching the blockchain for a list of SDP connection accepting hosts that the SDP connection initiating host can access, and returning the list of SDP connection accepting hosts to the SDP connection initiating host; the SDP connection initiating host initiates a connection request to the SDP connection accepting hosts in the SDP connection accepting host list, and the connection request includes the signature of the blockchain system node on the SDP connection accepting hosts in the SDP connection accepting host list; the SDP connection accepting host verifies the connection request initiated by the SDP connection initiating host, and provides access services to the SDP connection initiating host after successful verification. The present invention provides SDP services to customers in a blockchain manner, and authentication and requests are verified. On the one hand, it can protect the SDP controller from DDoS attacks, and on the other hand, it can prevent the SDP controller from implementing incorrect authorization. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of illustrating the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to denote the same components. In the drawings:

[0073] Figure 1 is a schematic diagram of SDP control in the prior art;

[0074] Figure 2 is the blockchain system architecture provided in the embodiment of the present invention;

[0075] Figure 3 is the thread diagram of SDP access control based on blockchain provided in the embodiment of the present invention;

[0076] Figure 4 is the flowchart of the SDP access control method based on blockchain provided in Embodiment 1 of the present invention;

[0077] Figure 5 is the flowchart of the SDP access control method based on blockchain provided in Embodiment 2 of the present invention;

[0078] Figure 6 is the flowchart of the SDP access control method based on blockchain provided in Embodiment 3 of the present invention;

[0079] Figure 7 is the schematic diagram of the SDP access control system based on blockchain provided in Embodiment 4 of the present invention;

[0080] Figure 8 is the schematic diagram of the SDP access control system based on blockchain provided in Embodiment 5 of the present invention;

[0081] Figure 9 is the schematic diagram of the SDP access control system based on blockchain provided in Embodiment 6 of the present invention. Detailed Embodiments

[0082] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0083] Embodiment 1

[0084] Auxiliary Figure 1 、 Figure 2 、 Figure 3 See Figure 4, a blockchain-based SDP access control method is provided, including the following steps:

[0085] S11: The SDP connection accepting host sends the information to be verified to the blockchain system node. The information to be verified includes: the host information of the SDP connection accepting host and the supported connection policies, so that the blockchain system node verifies the information to be verified and records it in the blockchain ledger after passing the verification;

[0086] S12: The SDP connection accepting host receives the connection request sent by the SDP connection initiating host. The connection request includes the signature information of the blockchain system node for the SDP connection accepting host in the SDP connection accepting host list;

[0087] S13: If the SDP connection accepting host is in the SDP connection accepting host list, the SDP connection accepting host verifies the signature information according to the supported connection policies. After successful verification, a request response is sent to the SDP connection initiating host.

[0088] In this embodiment, the SDP connection accepting host information includes IP address, port and protocol information; the supported connection policies include the login ID, IP address, geographical location of the accessing user, and blockchain node verification and endorsement policies. The SDP connection accepting host sends the SDP connection accepting host information (such as IP address, port and protocol information, etc.) and the supported connection policies (such as the user login ID, IP address, geographical location supported for access, and information such as blockchain node verification / endorsement policies, etc.) to the blockchain system node.

[0089] Optionally, the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policies.

[0090] Optionally, the signature of the SDP connection accepting host for the SDP connection accepting host information and the supported connection policies can also be sent to the blockchain system node, and the blockchain node verifies the information and its signature submitted by the SDP connection accepting host. After passing the verification, the blockchain node records the SDP connection accepting host information and the supported connection policies submitted by the SDP connection accepting host in the blockchain ledger.

[0091] Auxiliary Figure 2 , the blockchain system node is composed of an SDP controller and an authentication node connected to each other. Both the SDP controller and the authentication node are blockchain nodes. Both the SDP connection accepting host and the SDP connection initiating host can submit transactions to the blockchain and can read ledger data from the blockchain.

[0092] Specifically, the way for the SDP connection initiating host to submit an identity authentication request to the blockchain system node is as follows: The SDP connection initiating host signs the timestamp with its own private key;

[0093] Specifically, the blockchain system node verifies the signature and timestamp of the identity authentication request information submitted by the SDP connection initiating host. The SDP connection initiating host signs the timestamp with its own private key. If the SDP connection initiating host signs the timestamp with its own private key, then verify the signature and timestamp.

[0094] In this embodiment, when the SDP connection initiating host and the authentication node A1 have shared username and secret information, the identity authentication request includes KDF(timestamp, username, password), and encrypts KDF(timestamp, username, password) with the public key of the authentication node A1. In step S4, the blockchain system node verifies whether KDF(timestamp, username, password) is correct for the identity authentication request information submitted by the SDP connection initiating host.

[0095] Specifically, if the SDP connection initiating host and the authentication node A1 have shared username and secret information such as a user password, then the authentication request contains KDF(timestamp, username, password), and encrypts it with the public key of the authentication node A1. For example, E pk_A1 (KDF(timestamp, username, password)).

[0096] KDF is a method to implement key stretching. Specifically, it derives one or more keys from a master key, password, or passphrase. In the derivation process, a PRF (Pseudo Random Function, a pseudo-random function) can be a certain hash algorithm.

[0097] For example, PBKDF2 is an algorithm for deriving keys based on passwords and requires a lot of computing power to prevent brute-force cracking of encryption. Scrypt is a KDF algorithm based on passwords and consumes more resources than PBKDF2, effectively preventing brute-force cracking by proprietary hardware ASIC / FPGA. Scrypt uses the PBKDF2 algorithm internally, but internally maintains a set of bit data for a long time, and these data are repeatedly encrypted (Salsa20, a stream cipher) during the process of generating a complex salt.

[0098] Specifically, when the SDP connection initiating host has the token provided by the authentication node A2, the identity authentication request contains the token Token, and the token Token is encrypted using the public key of the authentication node A2. The blockchain system node verifies whether the token Token in the identity authentication request information submitted by the SDP connection initiating host is correct. After successful identity authentication, the blockchain node searches for the SDP connection accepting host and policy information in the ledger, and returns the list of SDP connection accepting hosts that the SDP connection initiating host can access as the response result to the SDP connection initiating host, including the signature of the blockchain node on the response result, which can be the signature of one node or multiple nodes. If the SDP connection accepting host specifies a verification / endorsement node in the policy, then the node specified by the SDP connection accepting host needs to sign the response result.

[0099] Specifically, Token means a flag or a mark, and is also called a token in the IT field. In computer identity authentication, it means a token (temporary), and is generally used for invitation and logging in to the system. Before some data transmissions, the verification of the secret signal needs to be carried out first, and different secret signals are authorized for different data operations. For example, in the USB1.1 protocol, 4 types of data packets are defined: Token packet, data packet, handshake packet, and special packet. The continuous data exchange between the host and the USB device can be divided into three stages. In the first stage, the host sends a Token packet. Different Token packet contents (different secret signals) can tell the device to do different jobs. In the second stage, a data packet is sent, and in the third stage, the device returns a handshake packet.

[0100] In this embodiment, the SDP connection initiating host submits an access request to the SDP connection accepting host, including the list of SDP connection accepting hosts that the SDP connection initiating host can access and the signature information of the blockchain node. If the SDP connection accepting host is in the list of SDP connection accepting hosts that the SDP connection initiating host can access, the SDP connection accepting host verifies the signature information according to the policy published in the blockchain ledger, such as whether the signature is generated by the node specified in the policy. If the verification is successful, the connection is established; otherwise, no response is given.

[0101] In this embodiment, the SDP connection acceptance host sends the SDP connection acceptance host information and the supported connection policies to the blockchain system node; the SDP connection acceptance host information and the supported connection policies are verified and consensus reached by the blockchain nodes, and the SDP connection acceptance host information and the supported connection policies after the verification and consensus by the blockchain nodes are recorded in the blockchain ledger; the SDP connection initiation host submits an identity authentication request to the blockchain system node; the blockchain system node verifies the identity authentication request information submitted by the SDP connection initiation host, and the verification of the identity authentication information includes finding a list of SDP connection acceptance hosts that the SDP connection initiation host can access in the blockchain, and returning the list of SDP connection acceptance hosts to the SDP connection initiation host; the SDP connection initiation host initiates a connection request to the SDP connection acceptance hosts in the list of SDP connection acceptance hosts, and the connection request includes the signature of the blockchain system node for the SDP connection acceptance hosts in the list of SDP connection acceptance hosts; the SDP connection acceptance host verifies the connection request initiated by the SDP connection initiation host, and provides access services to the SDP connection initiation host after successful verification. The present invention provides the SDP service to customers in a blockchain manner, and verifies authentication, requests, etc. On the one hand, it can avoid the SDP controller from being attacked by DDoS, and on the other hand, it can prevent the SDP controller from implementing incorrect authorizations.

[0102] Embodiment 2

[0103] Auxiliary Figure 1 、 Figure 2 、 Figure 3 , see Figure 5 , provide a blockchain-based SDP access control method, including:

[0104] S21: The blockchain system node receives the information to be verified sent by the SDP connection acceptance host, and the information to be verified includes: the host information of the SDP connection acceptance host and the supported connection policies;

[0105] S22: The blockchain system node verifies the information to be verified and records it in the blockchain ledger after the verification passes;

[0106] S23: The blockchain system node receives the identity authentication request submitted by the SDP connection initiation host;

[0107] S24: The blockchain system node verifies the identity authentication request information, and after the verification passes, finds a list of SDP connection acceptance hosts that the SDP connection initiation host can access in the blockchain, and returns the list of SDP connection acceptance hosts to the SDP connection initiation host.

[0108] In this embodiment, the information to be verified further includes: the host information of the SDP connection accepting host and the signature of the supported connection policy.

[0109] Specifically, if the SDP connection initiating host in the identity authentication request signs the timestamp with its own private key;

[0110] The verification of the identity authentication request information by the blockchain system node includes:

[0111] The blockchain system node verifies the signature and timestamp submitted by the SDP connection initiating host.

[0112] Specifically, if the identity authentication request contains a KDF or the encrypted information of the KDF using the public key of the authentication node A1;

[0113] The verification of the identity authentication request information by the blockchain system node includes:

[0114] The blockchain system node verifies whether the KDF is correct.

[0115] Specifically, if the identity authentication request contains a token or the encrypted information of the token using the public key of the authentication node A2;

[0116] The verification of the identity authentication request information by the blockchain system node includes:

[0117] The blockchain system node verifies whether the token is correct.

[0118] The SDP access control method based on blockchain in Embodiment 2 is an implementation scheme on the side of the blockchain system node corresponding to Embodiment 1. The specific implementation details are the same as those in Embodiment 1 and will not be elaborated here.

[0119] Embodiment 3

[0120] Auxiliary Figure 1 、 Figure 2 、 Figure 3 See Figure 6 , and provide a blockchain-based SDP access control method, including:

[0121] S31: The SDP connection initiating host sends an identity authentication request to the blockchain system node;

[0122] S32: The SDP connection initiating host receives the list of SDP connection accepting hosts that can be accessed sent by the blockchain system node;

[0123] S32: The SDP connection initiating host sends a connection request to the SDP connection accepting host, and the connection request includes the signature information of the blockchain system nodes for the SDP connection accepting hosts in the SDP connection accepting host list;

[0124] S34: The SDP connection initiating host receives the request response sent by the SDP connection accepting host.

[0125] Specifically, in the identity authentication request, the SDP connection initiating host signs the timestamp with its own private key.

[0126] Specifically, if the SDP connection initiating host and the authentication node A1 have shared username and secret information, the identity authentication request includes KDF or the encrypted information of KDF using the public key of the authentication node A1. If the SDP connection initiating host has a token provided by the authentication node A2, the identity authentication request includes the token or the encrypted information of the token using the public key of the authentication node A2.

[0127] Optionally, the signature information of the blockchain system nodes for the SDP connection accepting hosts in the SDP connection accepting host list is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

[0128] The SDP access control method based on blockchain in this Embodiment 3 is the implementation scheme on the SDP connection initiating host side corresponding to Embodiment 1. The specific implementation details are the same as those in Embodiment 1 and will not be elaborated here.

[0129] Embodiment 4

[0130] Auxiliary Figure 1 、 Figure 2 、 Figure 3 See Figure 7 To provide a blockchain-based SDP access control system, including:

[0131] The first information verification module 41 is used for the SDP connection accepting host to send the information to be verified to the blockchain system nodes. The information to be verified includes the host information of the SDP connection accepting host and the supported connection policies, so that the blockchain system nodes verify the information to be verified and record it in the blockchain ledger after the verification passes;

[0132] The first connection request module 42 is used for the SDP connection accepting host to receive the connection request sent by the SDP connection initiating host, and the connection request includes the signature information of the blockchain system nodes for the SDP connection accepting hosts in the SDP connection accepting host list;

[0133] The first request response module 43 is used to, if the SDP connection accepting host is in the SDP connection accepting host list, the SDP connection accepting host verifies the signature information according to the supported connection policy, and after successful verification, sends a request response to the SDP connection initiating host.

[0134] Specifically, the SDP connection accepting host information includes at least one of the following: IP address, port, and protocol information; the supported connection policies include at least one of the following: the login ID of the accessing user, IP address, geographical location, and blockchain node verification or endorsement policy.

[0135] Optionally, the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

[0136] Specifically, the information to be verified further includes: the host information of the SDP connection accepting host and the signature of the supported connection policy.

[0137] The SDP access control system based on blockchain in Embodiment 4 of the present invention is a product implementation corresponding to Embodiment 1, and the specific implementation details are the same as those in Embodiment 1 and will not be elaborated here.

[0138] Embodiment 5

[0139] Auxiliary Figure 1 、 Figure 2 、 Figure 3 See Figure 8 , a SDP access control system based on blockchain is provided, including:

[0140] The second information verification module 51 is used to receive the information to be verified sent by the SDP connection accepting host, and the information to be verified includes: the host information of the SDP connection accepting host and the supported connection policy; verify the information to be verified, and record it in the blockchain ledger after successful verification;

[0141] The first identity authentication request module 52 is used to receive the identity authentication request submitted by the SDP connection initiating host;

[0142] The verification feedback module 53 is used to verify the identity authentication request information, and after successful verification, find the SDP connection accepting host list that the SDP connection initiating host can access in the blockchain, and return the SDP connection accepting host list to the SDP connection initiating host.

[0143] Specifically, the information to be verified further includes: the host information of the SDP connection accepting host and the signature of the supported connection policy.

[0144] Specifically, if the SDP connection initiating host in the identity authentication request signs the timestamp with its own private key;

[0145] Verifying the identity authentication request information includes: verifying the signature and timestamp submitted by the SDP connection initiating host.

[0146] Specifically, if the identity authentication request contains a KDF or the encrypted information of the KDF using the public key of the authentication node A1;

[0147] Verifying the identity authentication request information includes: verifying whether the KDF is correct.

[0148] Specifically, if the identity authentication request contains a token or the encrypted information of the token using the public key of the authentication node A2;

[0149] Verifying the identity authentication request information includes: verifying whether the token is correct.

[0150] The SDP access control system based on blockchain in Embodiment 5 of the present invention is a product implementation corresponding to Embodiment 2. The specific implementation details are the same as those in Embodiment 2 and will not be elaborated here.

[0151] Embodiment 6

[0152] Auxiliary Figure 1 、 Figure 2 、 Figure 3 See Figure 9 , provide a blockchain-based SDP access control system, including:

[0153] The second identity authentication request module 61 is used to send an identity authentication request to the blockchain system node; the SDP connection initiating host receives the list of SDP connection accepting hosts that can be accessed sent by the blockchain system node;

[0154] The second connection request module 62 is used to send a connection request to the SDP connection accepting host, and the connection request includes the signature information of the SDP connection accepting host in the list of SDP connection accepting hosts by the blockchain system node;

[0155] The second request response module 63 is used to receive the request response sent by the SDP connection accepting host.

[0156] Specifically, in the identity authentication request, the SDP connection initiating host signs the timestamp with its own private key.

[0157] Specifically, if the SDP connection initiating host and the authentication node A1 have shared username and secret information, the identity authentication request contains KDF or the encrypted information of KDF using the public key of the authentication node A1.

[0158] Specifically, if the SDP connection initiating host has a token provided by the authentication node A2, the identity authentication request contains the token or the encrypted information of the token using the public key of the authentication node A2.

[0159] The SDP access control system based on blockchain in Embodiment 6 of the present invention is a product implementation corresponding to Embodiment 3, and the specific implementation details are the same as those in Embodiment 3 and will not be elaborated here.

[0160] Embodiment 7

[0161] Provided is an SDP connection accepting host, including: a processor, a memory, and a program stored on the memory and executable on the processor, where when the program is executed by the processor, the steps of the SDP access control method based on blockchain in Embodiment 1 or any possible implementation manner thereof are implemented.

[0162] Embodiment 8

[0163] Provided is a blockchain system node, including: a processor, a memory, and a program stored on the memory and executable on the processor, where when the program is executed by the processor, the steps of the SDP access control method based on blockchain in Embodiment 2 or any possible implementation manner thereof are implemented.

[0164] Embodiment 9

[0165] Provided is an SDP connection initiating host, including: a processor, a memory, and a program stored on the memory and executable on the processor, where when the program is executed by the processor, the steps of the SDP access control method based on blockchain in Embodiment 3 or any possible implementation manner thereof are implemented.

[0166] Embodiment 10

[0167] Provided is a computer-readable storage medium, on which a computer program is stored, where when the computer program is executed by a processor, the steps of the SDP access control method based on blockchain in Embodiment 1 or any possible implementation manner thereof are implemented;

[0168] or, when the computer program is executed by a processor, the steps of the SDP access control method based on blockchain in Embodiment 2 or any possible implementation manner thereof are implemented;

[0169] Alternatively, when the computer program is executed by a processor, it implements the steps of the blockchain-based SDP access control method according to Embodiment 3 or any possible implementation thereof.

[0170] Specifically, the computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state disk (SSD)).

[0171] Specifically, the processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor that implements by reading software code stored in a memory, and the memory can be integrated in the processor or can exist independently outside the processor.

[0172] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (e.g., infrared, wireless, microwave, etc.).

[0173] Specifically, the central processing unit (CPU) executes various processes according to the program stored in the read-only memory (ROM) or the program loaded from the storage section into the random access memory (RAM). In the RAM, data required when the CPU executes various processes, etc. is also stored as needed. The CPU, ROM, and RAM are connected to each other via a bus. The input / output interface is also connected to the bus.

[0174] The following components are connected to the input / output interface: an input section (including a keyboard, a mouse, etc.), an output section (including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.), a storage section (including a hard disk, etc.), and a communication section (including a network interface card such as a LAN card, a modem, etc.). The communication section performs communication processing via a network such as the Internet. If necessary, a drive may also be connected to the input / output interface. A removable medium such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. may be mounted on the drive as needed, so that a computer program read therefrom is installed in the storage section as needed.

[0175] In the case where the above-described series of processes are implemented by software, a program constituting the software is installed from a network such as the Internet or a storage medium such as a removable medium.

[0176] Those skilled in the art should understand that such a storage medium is not limited to a removable medium that stores a program and is distributed separately from the device to provide the program to the user. Examples of the removable medium include a magnetic disk (including a floppy disk (registered trademark)), an optical disk (including a compact disc read-only memory (CD-ROM) and a digital versatile disc (DVD)), a magneto-optical disk (including a mini disc (MD) (registered trademark)), and a semiconductor memory. Alternatively, the storage medium may be a ROM, a hard disk included in the storage section, etc., in which a program is stored and which is distributed to the user together with the device containing them.

[0177] Obviously, those skilled in the art should understand that the above-described modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Optionally, they can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.

[0178] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above-described specific embodiments. The above-described specific embodiments are merely illustrative and not restrictive. Those of ordinary skill in the art, under the inspiration of the present invention and without departing from the spirit and scope protected by the present invention and the claims, can also make many forms, all of which fall within the protection scope of the present invention.

Claims

1. A blockchain-based SDP access control method, characterized in that, it includes: The SDP connection accepting host sends the information to be verified to the blockchain system node, and the information to be verified includes: the host information of the SDP connection accepting host and the supported connection policies, so that the blockchain system node verifies the information to be verified and records it in the blockchain ledger after passing the verification; The SDP connection accepting host receives the connection request sent by the SDP connection initiating host, and the connection request includes the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node; If the SDP connection accepting host is in the SDP connection accepting host list, the SDP connection accepting host verifies the signature information according to the supported connection policies, and sends a request response to the SDP connection initiating host after successful verification; Among them, the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

2. The blockchain-based SDP access control method according to claim 1, characterized in that, The SDP connection accepting host information includes at least one of the following: IP address, port and protocol information; the supported connection policies include at least one of the following: the login ID of the accessing user, IP address, geographical location, and the blockchain node verification or endorsement policy.

3. The blockchain-based SDP access control method according to claim 1, characterized in that, The information to be verified further includes: the signature of the host information and the supported connection policies of the SDP connection accepting host.

4. A blockchain-based SDP access control method, characterized in that, it includes: The blockchain system node receives the information to be verified sent by the SDP connection accepting host, and the information to be verified includes: the host information of the SDP connection accepting host and the supported connection policies; The blockchain system node verifies the information to be verified and records it in the blockchain ledger after passing the verification; The blockchain system node receives the identity authentication request submitted by the SDP connection initiating host; The blockchain system node verifies the identity authentication request information, and after passing the verification, searches in the blockchain for the SDP connection accepting host list that the SDP connection initiating host can access, and returns the SDP connection accepting host list to the SDP connection initiating host; Among them, the SDP connection accepting host is further configured to receive the connection request sent by the SDP connection initiating host, and the connection request includes the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node; the signature information is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

5. The blockchain-based SDP access control method according to claim 4, characterized in that, The information to be verified further includes: the signature of the host information of the SDP connection accepting host and the supported connection policy by the host.

6. The blockchain-based SDP access control method according to claim 4, wherein, if in the identity authentication request, the SDP connection initiating host signs the timestamp with its own private key; the verification of the identity authentication request information by the blockchain system node includes: the blockchain system node verifies the signature and timestamp submitted by the SDP connection initiating host.

7. The blockchain-based SDP access control method according to claim 4, wherein, if the identity authentication request contains a KDF or the encrypted information of the KDF using the public key of the authentication node A1; the verification of the identity authentication request information by the blockchain system node includes: the blockchain system node verifies whether the KDF is correct.

8. The blockchain-based SDP access control method according to claim 4, wherein, if the identity authentication request contains a token or the encrypted information of the token using the public key of the authentication node A2; the verification of the identity authentication request information by the blockchain system node includes: the blockchain system node verifies whether the token is correct.

9. A blockchain-based SDP access control method, wherein, it includes: The SDP connection initiating host sends an identity authentication request to the blockchain system node; The SDP connection initiating host receives the list of SDP connection accepting hosts that can be accessed sent by the blockchain system node; The SDP connection initiating host sends a connection request to the SDP connection accepting host, and the connection request includes the signature information of the SDP connection accepting host in the list of SDP connection accepting hosts by the blockchain system node; The SDP connection initiating host receives the request response sent by the SDP connection accepting host; The signature information of the SDP connection accepting host in the list of SDP connection accepting hosts by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

10. The blockchain-based SDP access control method according to claim 9, wherein, in the identity authentication request, the SDP connection initiating host signs the timestamp with its own private key.

11. The blockchain-based SDP access control method according to claim 9, wherein, if the SDP connection initiating host and the authentication node A1 have shared username and secret information, the identity authentication request contains a KDF or the encrypted information of the KDF using the public key of the authentication node A1.

12. The blockchain-based SDP access control method according to claim 9, wherein, if the SDP connection initiating host has a token provided by the authentication node A2, the identity authentication request contains a token or the encrypted information of the token using the public key of the authentication node A2.

13. A blockchain-based SDP access control system, wherein, it includes: The first information verification module is used to send the information to be verified to the blockchain system node. The information to be verified includes the host information of the SDP connection accepting host and the supported connection policy, so that the blockchain system node verifies the information to be verified and records it in the blockchain ledger after the verification passes; The first connection request module is used to receive the connection request sent by the SDP connection initiating host. The connection request includes the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node; The first request response module is used to, if the SDP connection accepting host is in the SDP connection accepting host list, verify the signature information according to the supported connection policy, and send a request response to the SDP connection initiating host after the verification is successful; Wherein, the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

14. A blockchain-based SDP access control system Characterized in that It includes: The second information verification module is used to receive the information to be verified sent by the SDP connection accepting host. The information to be verified includes the host information of the SDP connection accepting host and the supported connection policy; verify the information to be verified and record it in the blockchain ledger after the verification passes; The first identity authentication request module is used to receive the identity authentication request submitted by the SDP connection initiating host; The verification feedback module is used to verify the identity authentication request information. After the verification passes, search in the blockchain for the SDP connection accepting host list that the SDP connection initiating host can access, and return the SDP connection accepting host list to the SDP connection initiating host; Wherein, the SDP connection accepting host is further used to receive the connection request sent by the SDP connection initiating host. The connection request includes the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node; the signature information is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

15. A blockchain-based SDP access control system Characterized in that It includes: The second identity authentication request module is used to send an identity authentication request to the blockchain system node; Receive the SDP connection accepting host list that can be accessed sent by the blockchain system node; The second connection request module is used to send a connection request to the SDP connection accepting host. The connection request includes the signature information of the SDP connection accepting host in the SDP connection accepting host list by the blockchain system node; The second request response module is used to receive the request response sent by the SDP connection accepting host; The signature information of the SDP connection acceptance host in the SDP connection acceptance host list by the blockchain system node is the signature of one or more blockchain system nodes, and the one or more blockchain system nodes are determined according to the blockchain node verification or endorsement policy.

16. An SDP connection acceptance host, characterized in that, it includes: a processor, a memory, and a program stored on the memory and executable on the processor, and when the program is executed by the processor, it implements the steps of the blockchain-based SDP access control method according to any one of claims 1 to 3.

17. A blockchain system node, characterized in that, it includes: a processor, a memory, and a program stored on the memory and executable on the processor, and when the program is executed by the processor, it implements the steps of the blockchain-based SDP access control method according to any one of claims 4 to 8.

18. An SDP connection initiation host, characterized in that, it includes: a processor, a memory, and a program stored on the memory and executable on the processor, and when the program is executed by the processor, it implements the steps of the blockchain-based SDP access control method according to any one of claims 9 to 12.

19. A computer-readable storage medium, characterized in that, a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, it implements the steps of the blockchain-based SDP access control method according to any one of claims 1 to 3; or, when the computer program is executed by a processor, it implements the steps of the blockchain-based SDP access control method according to any one of claims 4 to 8; or, when the computer program is executed by a processor, it implements the steps of the blockchain-based SDP access control method according to any one of claims 9 to 12.

Citation Information

Patent Citations

  • Communication method, device, system, electronic equipment and computer readable storage medium

    CN107980216A

Cited By

  • Blockchain-based method and system for SDP access control

    EP4261716B1