Remote attestation method, apparatus, system, electronic device, and readable storage medium

By querying validator and policy blocks in consortium chains and blockchains within the RATS framework, target validators and policies are identified, thus solving the problem of validator unreliability and improving the reliability and efficiency of verification results.

CN114764661BActive Publication Date: 2026-01-20CHINA MOBILE COMM LTD RES INST +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202110001468.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-04
Publication Date
2026-01-20
Estimated Expiration
2041-01-04

AI Technical Summary

Technical Problem

In the RATS framework, the unreliability of the verifier leads to unreliable verification results, and the trust relationship between the dependent and the verifier cannot be guaranteed.

Method used

By querying the validator block and verification strategy block in the consortium blockchain, the target validator and strategy that match the information to be verified are determined. The validator information is stored using blockchain technology to ensure its immutability and achieve the reliability of the validator's identity.

Benefits of technology

This ensures the reliability of the verification results, improves the efficiency of verifiers, and promotes communication between provers and dependents by disclosing verifier information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114764661B_ABST
    Figure CN114764661B_ABST
Patent Text Reader

Abstract

The application discloses a remote attestation method, device and system, electronic equipment and readable storage medium, and belongs to the network security field. The method comprises the following steps: querying a verifier block of a consortium chain that provides a verification service, and determining information of at least one verifier that matches parameters of to-be-verified information; querying a verification strategy block of a block chain that provides a verification service, and determining information of a target verification strategy that matches the parameters of the to-be-verified information in the information of the verification strategy of the at least one verifier, and determining a verifier with the target verification strategy as a target verifier; obtaining an address of the target verifier from the information of the verifier of the target verifier, and obtaining an identifier of the target verification strategy from the information of the target verification strategy; and sending the to-be-verified information and the identifier of the target verification strategy to the address of the target verifier, so that the target verifier obtains the target verification strategy according to the identifier of the target verification strategy, and verifies the to-be-verified information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the field of network security, and particularly relates to a remote attestation method, a remote attestation device, a remote attestation system, an electronic device and a computer readable storage medium. BACKGROUND

[0002] Remote ATtestation ProcedureS (RATS) provided by International Engineer Task Force (IETF) is proposed for solving remote attestation, and generally, when network protocol is exchanged, an entity, i.e. a dependant, requests an entity or program at a remote end, i.e. an attester, to provide evidence, the evidence is used to evaluate the reliability of the remote entity, and through remote attestation, the dependant can trust the remote system or component.

[0003] The attester provides the evidence to a third party, also called a verifier, instead of directly providing the evidence to the dependant, the verifier verifies the evidence by using a corresponding strategy, and then provides a verification result to the dependant, and the dependant can determine the degree of trust for the attester according to the verification result, and based on the degree of trust, the dependant can determine whether to open certain permissions or resources for the attester.

[0004] In the RATS framework, the verifier is a very important role. If the reliability of the verifier cannot be guaranteed, the reliability of the verification result cannot be guaranteed. SUMMARY

[0005] Embodiments of the present application provide a remote attestation method, a remote attestation device, a remote attestation system, an electronic device and a computer readable storage medium, so as to solve the problem of verifying the identity of the verifier.

[0006] In order to solve the above technical problems, the present application is implemented as follows:

[0007] In a first aspect, the embodiments of the present application provide a remote attestation method applied to an electronic device, and the method comprises the following steps:

[0008] Querying a verifier block in an alliance chain providing a verification service, and determining information of at least one verifier matched with parameters of to-be-verified information;

[0009] Querying a verification strategy block in a block chain providing a verification service, and determining information of a target verification strategy matched with the parameters of the to-be-verified information in the information of the verification strategy of the at least one verifier, and determining a verifier with the target verification strategy as a target verifier;

[0010] obtain an address of the target verifier from the information of the verifier of the target verifier, and obtain an identification of the target verification policy from the information of the target verification policy;

[0011] send the to-be-verified information and the identification of the target verification policy to the address of the target verifier, and enable the target verifier to obtain the target verification policy according to the identification of the target verification policy and verify the to-be-verified information.

[0012] In a second aspect, an embodiment of the present application provides a remote attestation device applied to an attester, and the device comprises:

[0013] a query module, configured to query a verifier block in a consortium chain that provides a verification service, determine information of at least one verifier that matches a parameter of to-be-verified information, and query a verification policy block in a blockchain that provides a verification service, determine information of a target verification policy that matches the parameter of the to-be-verified information from information of a verification policy of the at least one verifier, and determine a verifier with the target verification policy as a target verifier;

[0014] a first communication module, configured to obtain an address of the target verifier from the information of the verifier of the target verifier, and obtain an identification of the target verification policy from the information of the target verification policy; send the to-be-verified information and the identification of the target verification policy to the address of the target verifier, and enable the target verifier to obtain the target verification policy according to the identification of the target verification policy and verify the to-be-verified information.

[0015] In a third aspect, an embodiment of the present application provides a remote attestation device applied to a verifier, and the device comprises:

[0016] a second communication module, configured to receive to-be-verified information and an identification of a target verification policy;

[0017] a first processing module, configured to obtain a target verification policy according to the identification of the target verification policy, verify the to-be-verified information, and obtain a verification result;

[0018] the second communication module is further configured to feed back the obtained verification result to an attester who provides the to-be-verified information and a corresponding dependee.

[0019] In a fourth aspect, an embodiment of the present application provides a remote attestation device applied to a dependee, and the device comprises:

[0020] a third communication module, configured to receive a verification result obtained by a target verifier according to a target verification policy by verifying to-be-verified information;

[0021] The second processing module is configured to determine, according to the verification result, a corresponding right of a certificate provider providing the information to be verified.

[0022] In a fifth aspect, an embodiment of the present application provides a remote certification system, which comprises:

[0023] The certificate provider comprises the remote certification device according to the second aspect;

[0024] The verifier comprises the remote certification device according to the third aspect;

[0025] The dependee comprises the remote certification device according to the fourth aspect.

[0026] In a sixth aspect, an embodiment of the present application provides an electronic device, which comprises a processor, a memory, and a program or instruction stored in the memory and executable on the processor, and the program or instruction is executed by the processor to implement the steps of the remote certification method according to the first aspect.

[0027] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium, which stores a program or instruction, and the program or instruction is executed by a processor to implement the steps of the remote certification method according to the first aspect.

[0028] In the embodiment of the present application, the information of at least one verifier matched with the parameter of the information to be verified is determined by querying the verifier block in the alliance chain providing the verification service, the information of the target verification strategy matched with the parameter of the information to be verified is determined in the information of the verification strategy of the at least one verifier by querying the verification strategy block in the blockchain providing the verification service, the verifier with the target verification strategy is determined as the target verifier, the address of the target verifier is obtained from the information of the verifier of the target verifier, the identification of the target verification strategy is obtained from the information of the target verification strategy, the information to be verified and the identification of the target verification strategy are sent to the address of the target verifier, the target verifier obtains the target verification strategy according to the identification of the target verification strategy, and the information to be verified is verified; the information of the verifier is stored in the alliance chain by introducing the blockchain technology, so that the information of the verifier cannot be tampered with, the problem that the remote certification process performed by the verifier cannot be normally executed due to the attack on the single point of the verifier or the communication failure of the verifier is overcome, the reliability of the verifier identity is ensured, and thus the reliability of the verification result is ensured, the address of the verifier can be disclosed by the information of the verifier in the alliance chain, the communication between the certificate provider and the verifier and the dependee and the verifier is facilitated, and meanwhile the information of the verifier can be shared in the blockchain, and the use efficiency of the verifier is improved. BRIEF DESCRIPTION OF DRAWINGS

[0029] Figure 1 is a flowchart of a remote attestation method provided by an embodiment of the present application;

[0030] Figure 2 is a flowchart of an implementation of a method for determining a target verifier and a target attestation policy provided by an embodiment of the present application;

[0031] Figure 3 is a flowchart of an implementation of a method for determining a target verifier by evaluation information of an attestation policy provided by an embodiment of the present application;

[0032] Figure 4 is a flowchart of an implementation of a method for scoring a target attestation policy according to an attestation result provided by an embodiment of the present application;

[0033] Figure 5 is a flowchart of an implementation of a method for adjusting evaluation information of a target attestation policy according to a score of the target attestation policy provided by an embodiment of the present application;

[0034] Figure 6 is a flowchart of an implementation of a method for determining a right limit of an attestation authority according to an attestation result provided by an embodiment of the present application;

[0035] Figure 7 is a schematic diagram of conceptual data flow of a remote attestation method provided by an embodiment of the present application;

[0036] Figure 8 is a schematic diagram of a consortium chain and data recorded therein provided by an embodiment of the present application;

[0037] Figure 9 is a schematic diagram of a blockchain and data recorded therein provided by an embodiment of the present application;

[0038] Figure 10 is a structural schematic diagram of a remote attestation apparatus provided by an embodiment of the present application;

[0039] Figure 11 is a structural schematic diagram of another structure of a remote attestation apparatus of Figure 10 ;

[0040] Figure 12 is a structural schematic diagram of another remote attestation apparatus provided by an embodiment of the present application;

[0041] Figure 13 is a structural schematic diagram of another structure of a remote attestation apparatus of Figure 12 ;

[0042] Figure 14 is a structural schematic diagram of yet another remote attestation apparatus provided by an embodiment of the present application;

[0043] Figure 15 is Figure 14 a schematic diagram of another structure of the remote attestation device of

[0044] Figure 16 is a structural schematic diagram of an electronic device also provided by the embodiment of the present application. DETAILED DESCRIPTION

[0045] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0046] The terms "first", "second", and the like in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be exchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than that illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally a category, and are not limited to the number of objects, for example, the first object can be one or more. In addition, "and / or" in the specification and claims indicates at least one of the connected objects, and the character " / ", generally indicates that the front and rear associated objects are in an "or" relationship.

[0047] The remote attestation method, remote attestation device, remote attestation system, electronic device and computer readable storage medium provided by the embodiments of the present application will be described in detail below in combination with the drawings, through specific embodiments and application scenarios.

[0048] Please refer to Figure 1 , Figure 1 is a flowchart of a remote attestation method provided by the embodiments of the present application, which is applied to an electronic device, as shown in Figure 1 The method comprises the following steps:

[0049] Step 101, querying a verifier block in a consortium chain providing a verification service to determine information of at least one verifier matched with parameters of to-be-verified information.

[0050] In the embodiments of the present application, the alliance chain is a distributed database that is tamper-proof and uses distributed ledger and distributed consensus technology. The alliance chain is a blockchain managed by a plurality of verifiers. A plurality of verifiers are designated as ledger nodes in the alliance chain, and verifier blocks are generated. Each verifier block in the alliance chain is determined by all verifier nodes through a consensus mechanism. Other access nodes can read the information of the verifier blocks in the alliance chain, but do not participate in the ledger process. The information of the verifier provided by each verifier block in the alliance chain can include: basic information of the verifier and verification information of the verifier. The embodiments of the present application do not limit the content of the basic information of the verifier and the verification information of the verifier provided by the verifier block.

[0051] Optionally, the basic information of the verifier can include: an identifier of the verifier, an address of the verifier, institution information of the verifier, an authorized party of the verifier, an acceptable evidence format of the verifier, a validity period of the verifier, and a supported communication protocol of the verifier. The identifier of the verifier is used to uniquely identify the identity of the verifier. The address of the verifier refers to an IP address that is reachable in network communication. The institution information of the verifier refers to an institution that provides verification services, such as a device manufacturer or a third-party evaluation institution. The authorized party of the verifier refers to an institution that grants verification qualifications, such as an institution similar to CA. The acceptable evidence format of the verifier refers to the evidence format accepted by the verifier in the verification process, such as CWT or JWT format. The validity period of the verifier refers to the validity period of the verification service. If the validity period is exceeded, the verifier cannot provide verification services, or a user prompt needs to be given, and the user decides whether to continue to use the verification service of the verifier. The verifier can usually provide different types of verification services, and the supported communication protocols are diversified. The verifier selects the communication protocol used for each verification.

[0052] Optionally, the verification information of the verifier can include: a verifiable type, a trusted standard to be followed, and a verification policy to be adopted. The verifiable type can include: software platform security, hardware platform security, computing security, virtualization security, and health information. The trusted standard to be followed can be, for example, TPM1.2, TPM2.0, etc. The verification policy to be adopted can include a plurality of policy types. The identifier of the verification policy can be stored. A list type data structure is used to store the verification policy, and the identifier of the verification policy is used to index to find the specific verification policy.

[0053] In the embodiment of the present application, the to-be-verified information can be the evidence provided by the prover, and the evidence provided by the prover can include identity information of a system component, a constituent list of the system component, a root of trust, a declaration of software source, a declaration of hardware manufacturing, an integrity description of the system component, a configuration description of the system component, a status of a job of the system component, and the like. The embodiment of the present application does not limit the form of the evidence provided by the prover. The parameters of the to-be-verified information can be determined according to the verifier information provided by the verifier block, for example, the parameters of the to-be-verified information can include a verification type and an evidence format, so as to ensure that the parameters of the to-be-verified information can match the verifier information provided by the verifier block. The embodiment of the present application does not limit the type of the parameters of the to-be-verified information.

[0054] In the embodiment of the present application, when the prover needs the verifier to provide evidence verification, one or more verifier information matching the parameters of the evidence can be determined by querying the verifier block in the alliance chain providing the verification service.

[0055] In step 102, the verification strategy block in the block chain providing the verification service is queried, and the information of the target verification strategy matching the parameters of the to-be-verified information is determined in the information of the verification strategy of at least one verifier, and the verifier with the target verification strategy is determined as the target verifier.

[0056] In the embodiment of the present application, each verification strategy block in the block chain stores the information of all verification strategies of a verifier, which can specifically include an identifier of the verifier, an identifier of the verification strategy, a verification type of the verification strategy, and the like. The identifier of each verifier corresponds to the identifier of the verifier in a verifier block in the alliance chain. The identifiers of the multiple verification strategies of each verifier correspond to the identifiers of the verification strategies in the linked list type data structure storing the verification strategies in the corresponding verifier block. The verification type of the verification strategy refers to the verification type applicable to the verification strategy, and the verification type of the verification strategy is consistent with the verification type that can be provided by the verifier in the corresponding verifier block in the alliance chain. The embodiment of the present application does not limit the type of the information of the verification strategy included in each verification strategy block in the block chain.

[0057] In the embodiment of the present application, if the prover determines the information of a verifier by querying the alliance chain, the information of a verification strategy matching the parameters of the evidence can be determined in the verification strategy provided by the verifier by querying the verification strategy block in the block chain providing verification services, the information of the target verification strategy is determined as the information of the target verification strategy, and the verifier with the target verification strategy is determined as the target verifier; if the prover determines the information of multiple verifiers by querying the alliance chain, each verifier in the multiple verifiers can be selected respectively, the information of a verification strategy matching the parameters of the evidence can be determined in the verification strategy provided by the corresponding verifier by querying the verification strategy block in the block chain providing verification services, one of the information of the multiple verification strategies is selected as the information of the target verification strategy, and the verifier with the target verification strategy is determined as the target verifier.

[0058] In step 103, the address of the target verifier is obtained from the information of the verifier of the target verifier, and the identification of the target verification strategy is obtained from the information of the target verification strategy.

[0059] In the embodiment of the present application, after the prover determines the target verification strategy and the target verifier, the address of the target verifier can be obtained from the information of the verifier of the target verifier corresponding to the target verifier in the alliance chain, and the identification of the target verification strategy can be obtained from the information of the target verification strategy corresponding to the target verification strategy in the block chain.

[0060] In step 104, the to-be-verified information and the identification of the target verification strategy are sent to the address of the target verifier, so that the target verifier obtains the target verification strategy according to the identification of the target verification strategy and verifies the to-be-verified information.

[0061] In the embodiment of the present application, after the prover obtains the address of the target verifier and the identification of the target verification strategy, the evidence to be verified and the identification of the target verification strategy are sent to the address of the target verifier, the target verification strategy is obtained from the chain table storing the verification strategy by the target verifier according to the identification of the target verification strategy, and the evidence is verified by the target verification strategy.

[0062] In the embodiment of the present application, by querying the verifier block in the alliance chain providing verification service, the information of at least one verifier matched with the parameters of the information to be verified is determined, the verification strategy block in the blockchain providing verification service is queried, in the information of the verification strategy of the at least one verifier, the information of the target verification strategy matched with the parameters of the information to be verified is determined, and the verifier with the target verification strategy is determined as the target verifier, the address of the target verifier is obtained from the information of the verifier of the target verifier, the identification of the target verification strategy is obtained from the information of the target verification strategy, the information to be verified and the identification of the target verification strategy are sent to the address of the target verifier, so that the target verifier obtains the target verification strategy according to the identification of the target verification strategy, and verifies the information to be verified; the blockchain technology is introduced, the information of the verifier is stored in the alliance chain, so that the information of the verifier cannot be tampered with, the problem that the single point of the verifier is attacked or communication failure occurs, and the remote proof process which needs to be performed by the verifier cannot be normally executed is overcome, the reliability of the verifier identity can be guaranteed, so that the reliability of the verification result is guaranteed, the address of the verifier can be disclosed through the information of the verifier in the alliance chain, the communication between the prover and the relying party and the verifier is facilitated, and meanwhile the information of the verifier can be shared in the blockchain, and the use efficiency of the verifier is improved.

[0063] Please refer to Figure 2 , Figure 2 is a flowchart of an implementation manner of determining the target verification strategy and the target verifier provided by the embodiment of the present application, as shown in Figure 2 , the verification strategy block in the blockchain providing verification service is queried, in the information of the verification strategy of the at least one verifier, the information of the target verification strategy matched with the parameters of the information to be verified is determined, and the verifier with the target verification strategy is determined as the target verifier, including the following steps:

[0064] Step 201, for each verifier in the at least one verifier, the verification strategy block in the blockchain providing verification service is queried, and the information of the verification strategy matched with the parameters of the information to be verified is determined.

[0065] In the embodiment of the present application, the prover determines the information of a plurality of verifiers by querying the alliance chain, and can respectively determine, for each verifier in the plurality of verifiers, the information of a verification strategy matched with the parameters of the evidence to be verified by querying the verification strategy block in the blockchain providing verification service.

[0066] Step 202, according to the evaluation information in the information of the verification strategy, the information of the target verification strategy is determined in the information of the verification strategy of the at least one verifier matched with the parameters of the information to be verified.

[0067] In the embodiment of the present application, after the prover determines the information of the plurality of verification strategies matching the parameters of the evidence to be verified by querying the blockchain, the information of a verification strategy can be selected as the information of the target verification strategy from the information of the plurality of verification strategies matching the parameters of the evidence to be verified according to the evaluation information of the verification strategy in the information of each determined verification strategy. Optionally, the evaluation information of the verification strategy can be the evaluation of the verification strategy made by the prover and the dependents according to the experience, for example, the evaluation information of the verification strategy can include the score of the verification strategy, and the information of the verification strategy with the highest score can be selected as the information of the target verification strategy. The embodiment of the present application does not limit the implementation form of the evaluation information of the verification strategy.

[0068] Step 203, determining the verifier having the target verification strategy as the target verifier from the at least one verifier.

[0069] In the embodiment of the present application, after the prover determines the information of the target verification strategy according to the evaluation information of the verification strategy, the verifier having the target verification strategy can be determined as the target verifier.

[0070] The embodiment can realize the public transparency of the evaluation of the verification strategy by setting the evaluation information of the verification strategy in the information of the verification strategy in the blockchain, and the accuracy of the obtained verification result can be ensured by selecting the verification strategy for verification by using the evaluation information of the verification strategy.

[0071] Please refer to Figure 3 , Figure 3 is an implementation flowchart of the embodiment of the present application for determining the target verifier by using the evaluation information of the verification strategy, as shown in Figure 3 The information of the target verification strategy is determined from the information of the at least one verifier matching the parameters of the to-be-verified information according to the evaluation information in the information of the verification strategy, and includes the following steps:

[0072] Step 301, determining the information of the verification strategy in the effective state from the information of the at least one verifier matching the parameters of the to-be-verified information according to the verification strategy state information in the evaluation information.

[0073] Optionally, the verification strategy state information can include the effective state and the invalid state.

[0074] Step 302, determining the information of the target verification strategy from the information of the verification strategy in the effective state according to the verification strategy score information in the evaluation information.

[0075] Optionally, the verification strategy score information can be a score made by the prover and the dependents on the verification strategy according to experience.

[0076] In the embodiment of the present application, the evaluation information of the verification strategy stored in the blockchain can include verification strategy state information and verification strategy score information. When the prover determines the information of the target verification strategy according to the evaluation information of the verification strategy, the prover can first determine whether the information of the corresponding verification strategy is in an effective state according to the verification strategy state information in the information of each verification strategy, and then determine the information of the verification strategy with the highest score from the information of the verification strategy in the effective state as the information of the target verification strategy.

[0077] The embodiment sets the verification strategy state information and the verification strategy score information in the information of the verification strategy in the blockchain to perform two-level evaluation on the verification strategy, and can improve the efficiency of selecting the verification strategy when selecting the verification strategy for verification.

[0078] Please refer to Figure 4 , Figure 4 is a flowchart of an implementation manner of scoring the target verification strategy according to the verification result provided by the embodiment of the present application, as shown in Figure 4 After the identification of the target verification strategy and the to-be-verified information are sent to the address of the target verifier, the following steps can be further included:

[0079] Step 401, receiving a verification result obtained by the target verifier according to the target verification strategy for verifying the to-be-verified information.

[0080] In the embodiment of the present application, after the prover sends the evidence to be verified and the identification of the target verification strategy to the address of the target verifier, the prover can further receive the verification result obtained by the target verifier according to the target verification strategy for verifying the evidence to be verified.

[0081] Step 402, scoring the target verification strategy according to the verification result, and feeding back the score to the target verifier, so that the target verifier adjusts the evaluation information of the target verification strategy according to the score of the target verification strategy.

[0082] In the embodiment of the present application, after receiving the verification result fed back by the target verifier, the prover can score the corresponding target verification strategy according to the verification result, and feed back the score to the target verifier, so that the target verifier can adjust the evaluation information of the target verification strategy according to the score of the target verification strategy, for example, can adjust the verification strategy score information in the evaluation information of the target verification strategy, or can adjust the verification strategy score information and the verification strategy state information in the evaluation information of the target verification strategy at the same time.

[0083] In the embodiment of the present application, after receiving the verification result fed back by the target verifier, the prover can score the corresponding target verification strategy according to the verification result, and feed back the score to the target verifier, so that the target verifier can adjust the evaluation information of the target verification strategy according to the score of the target verification strategy, for example, can adjust the verification strategy score information in the evaluation information of the target verification strategy, or can adjust the verification strategy score information and the verification strategy state information in the evaluation information of the target verification strategy at the same time.

[0084] Please refer to Figure 5 , Figure 5 is a flowchart of an implementation manner of adjusting the evaluation information of the target verification strategy according to the score of the target verification strategy provided by the embodiment of the present application, as shown in Figure 5 The target verifier adjusts the evaluation information of the target verification strategy according to the score of the target verification strategy, and includes the following steps:

[0085] Step 501, receiving the score of the target verification strategy fed back by the prover who provides the to-be-verified information.

[0086] Optionally, in addition to receiving the score of the target verification strategy fed back by the prover, the target verifier can also receive the score of the target verification strategy fed back by the dependent person according to the verification result, wherein the dependent person can determine the corresponding authority granted to the prover according to the verification result.

[0087] Step 502, adjusting the score of the verification strategy score information in the information of the target verification strategy according to the received score of the target verification strategy.

[0088] In the embodiment of the present application, the score of the target verification strategy can include the score of the target verification strategy fed back by the prover and the score of the target verification strategy fed back by the dependent person, and the prover can adjust the score of the verification strategy score information in the information of the target verification strategy according to all the received scores of the target verification strategy.

[0089] Step 503, judging whether the score of the verification strategy score information of the target verification strategy is less than a preset threshold value.

[0090] If the score of the verification policy score information of the target verification policy is less than the preset threshold value, step 504 is performed; otherwise, if the score of the verification policy score information of the target verification policy is greater than or equal to the preset threshold value, step 505 is performed.

[0091] In step 504, the verification policy state information in the information of the target verification policy is adjusted to an invalid state, and the target verification policy is adjusted to generate a new target verification policy.

[0092] In step 505, a new verification policy block is generated according to the adjusted verification policy information, and the generated new verification policy block is connected to the block chain.

[0093] In the embodiment of the present application, after the score of the verification policy score information of the target verification policy is adjusted according to the received score of the target verification policy, the verifier can further compare the score of the adjusted verification policy score information of the target verification policy with the preset threshold value of the score, and determine whether the score of the verification policy score information of the target verification policy is less than the preset threshold value of the score.

[0094] If the score of the verification policy score information of the target verification policy is greater than or equal to the preset threshold value of the score, the verification policy score information can be updated according to the adjustment result of the verification policy score information, and a new verification policy block can be generated according to the information of the verification policy containing the updated verification policy score information, and the generated new verification policy block is connected to the block chain.

[0095] If the score of the verification policy score information of the target verification policy is less than the preset threshold value of the score, the verification policy state information in the information of the target verification policy can be further adjusted to an invalid state, and then the verification policy score information and the verification policy state information can be updated according to the adjustment results of the verification policy score information and the verification policy state information. The verifier can generate a new verification policy by configuring and adjusting the target verification policy, and generate a new verification policy block according to the information of the verification policy containing the updated verification policy score information and the verification policy state information, and the generated new verification policy block is connected to the block chain.

[0096] The embodiment receives the score of the target verification strategy fed back by the prover and the dependent according to the verification result, adjusts the target verification strategy according to the received evaluation information of the target verification strategy, and adjusts the target verification strategy according to the adjusted evaluation information of the target verification strategy, so as to overcome the problem that the existing verification strategy is usually formulated by the verifier and is usually set in the form of configuration, and lacks flexible evaluation mechanism and adjustment mode, and to achieve the purpose of evaluating the verification strategy and the purpose of adjusting the verification strategy through the evaluation mechanism without leaking the specific content of the verification strategy.

[0097] Please refer to Figure 6 , Figure 6 is a flowchart of an implementation mode for determining the authority of the prover by the dependent according to the verification result, as shown in Figure 6 , the dependent determines the corresponding authority of the prover according to the verification result, including the following steps:

[0098] Step 601, receiving the verification result obtained by the target verifier according to the target verification strategy for verifying the to-be-verified information.

[0099] In the embodiment of the application, after the target verifier verifies the evidence to be verified according to the target verification strategy, the obtained verification result is sent to the prover who provides the evidence for verification and the corresponding dependent.

[0100] Step 602, identifying the verification result according to the preset identification strategy of the verification result to obtain an identification result.

[0101] In the embodiment of the application, after the dependent receives the verification result obtained by the target verifier according to the target verification strategy for verifying the evidence to be verified, the dependent can identify the verification result according to the preset identification strategy of the verification result to obtain an identification result.

[0102] Step 603, determining the authority of the prover who provides the to-be-verified information according to the obtained identification result.

[0103] In the embodiment of the application, the dependent can determine the trust degree of the prover according to the obtained identification result, for example, the identification result can include distrust, complete trust or partial trust, and the dependent can determine to open the authority or resources of the prover based on the trust degree of the prover.

[0104] The embodiment determines the trust degree of the prover by authenticating the verification result according to the authentication strategy of the dependents, so as to determine the authority granted to the prover, and the security of the system can be ensured by reasonably setting the authentication strategy, accurately determining the trust degree of the prover, and granting the prover corresponding authority.

[0105] Please refer to Figure 7 , Figure 7 is a schematic diagram of a conceptual data flow of a remote attestation method provided by the embodiment of the application, as shown in Figure 6 The RATS framework includes the following roles:

[0106] Prover (Attester): refers to an attribute of an entity, which must be evaluated to determine whether to trust the entity, for example, whether to authorize some platform operation permissions of the entity.

[0107] Verifier (Verifier): verifies the validity of the evidence provided by the prover, and provides the verification result to the relying party, which uses the verification result.

[0108] Verifier owner (Verifier Owner): an entity, for example, an administrator, authorized to be able to configure the verification strategy.

[0109] Relying party (Relying Party): an entity that relies on the validity of the prover information for reliable use of specific operations of hardware or software.

[0110] Relying party owner (Relying Party Owner): an entity, for example, an administrator, authorized to configure the authentication strategy for authentication of the verification result.

[0111] Endorser (Endorser): an entity, usually a manufacturer, whose endorsement can help the verifier to evaluate the authenticity of the prover.

[0112] The process is as follows:

[0113] 1. The prover provides the evidence owned by the prover to the verifier;

[0114] 2. The verifier verifies the evidence provided by the prover using a verification strategy, which is configured by the verifier owner, and the verification strategy can also be an endorsement from the endorser;

[0115] 3. The verifier provides the verification result to the relying party through a secure channel after verification using the verification strategy;

[0116] 4. The owner of the dependent party has formulated an identification strategy in advance, and the dependent party uses the identification strategy to complete the identification of the verification result; according to the identification result, the dependent party decides the trust degree of the certifier, and accordingly completes the use authorization or resource opening of the certifier.

[0117] Please refer to Figure 8 , Figure 8 is a schematic diagram of a consortium chain and data recorded therein provided by an embodiment of the present application. As shown in Figure 8 , each verifier block in the consortium chain includes a block header and a block body, wherein the block body records information of verifiers such as Verifier 1…Verifier i, Verifier N, and the information of the verifiers includes: basic information (Basic Info) of the verifiers and verification information (Verify Info) of the verifiers.

[0118] Please refer to Figure 9 , Figure 9 is a schematic diagram of a blockchain and data recorded therein provided by an embodiment of the present application, as shown in Figure 9 , each verification policy block in the blockchain includes a block header and a block body, wherein the block body records information of a verifier ID and a verification policy, such as a policy ID, a policy state Policystate, a policy score Policy score, and a verification type Verifier Type.

[0119] Please refer to Figure 10 , Figure 10 is a structural schematic diagram of a remote certification device provided by an embodiment of the present application, which is applied to an electronic device, which can be an electronic device of a certifier, as shown in Figure 10 , the remote certification device 100 can include:

[0120] The query module 110 is configured to query a verifier block in the consortium chain that provides a verification service, determine information of at least one verifier matched with a parameter of to-be-verified information, and query a verification policy block in the blockchain that provides a verification service, determine information of a target verification policy matched with the parameter of the to-be-verified information in the information of the verification policy of the at least one verifier, and determine a verifier having the target verification policy as a target verifier.

[0121] The first communication module 120 is configured to obtain an address of the target verifier from the information of the verifier of the target verifier, and obtain an identifier of the target verification policy from the information of the target verification policy; send the to-be-verified information and the identifier of the target verification policy to the address of the target verifier, so that the target verifier obtains the target verification policy according to the identifier of the target verification policy and verifies the to-be-verified information.

[0122] Optionally, the query module 110 comprises: a query unit configured to query, for each verifier in the at least one verifier, a verification policy block providing a verification service in the block chain, and determine information of a verification policy matching a parameter of the to-be-verified information; and a processing unit configured to determine, according to evaluation information in the information of the verification policy, information of a target verification policy from the determined information of the verification policy of the at least one verifier matching the parameter of the to-be-verified information, and determine, as the target verifier, the verifier having the target verification policy in the at least one verifier.

[0123] Optionally, the processing unit comprises: a state processing subunit configured to determine, according to verification policy state information in the evaluation information, information of a verification policy in an active state from the information of the verification policy of the at least one verifier matching the parameter of the to-be-verified information; and a score processing subunit configured to determine, according to verification policy score information in the evaluation information, information of a verification policy having the highest score from the determined information of the verification policy in the active state as the information of the target verification policy.

[0124] Optionally, the first communication module 120 is further configured to receive a verification result obtained by the target verifier by verifying the to-be-verified information according to the target verification policy.

[0125] As shown in Figure 11 , the remote proof device 100 further comprises an evaluation module 130 configured to score the target verification policy according to the verification result,

[0126] The first communication module 120 is further configured to feed back the score to the target verifier, so that the target verifier adjusts the evaluation information of the target verification policy according to the score of the target verification policy.

[0127] It can be understood that the remote proof device 100 of the embodiment of the present application can implement each process of the method embodiment shown in Figures 1 to 4 and achieve the same technical effects. To avoid repetition, details are not described here.

[0128] Please refer to Figure 12 , Figure 12is a structural diagram of another remote attestation device provided by the embodiment of the present application, which is applied to an electronic device, and the electronic device can be an electronic device of a verifier, as shown in FIG. 12, the remote attestation device 200 can include:

[0129] The second communication module 210 is configured to receive the to-be-verified information and the identification of the target verification policy.

[0130] The first processing module 220 is configured to acquire the target verification policy according to the identification of the target verification policy, and verify the to-be-verified information to obtain a verification result.

[0131] The second communication module 210 is further configured to feed back the obtained verification result to a prover providing the to-be-verified information and a corresponding dependee.

[0132] Optionally, the second communication module 210 is further configured to receive a score of the target verification policy fed back by the prover providing the to-be-verified information.

[0133] As shown in FIG. 12, the remote attestation device 200 further includes an adjustment module 230 configured to adjust a score of verification policy score information in information of the target verification policy according to the received score of the target verification policy, judge whether the score of the verification policy score information of the target verification policy is less than a preset threshold, and if the score of the verification policy score information of the target verification policy is less than the preset threshold, adjust verification policy state information in the information of the target verification policy to an invalid state, and adjust the target verification policy to generate a new target verification policy. Figure 13

[0134] The first processing module 220 is further configured to generate a new verification policy block according to the adjusted information of the verification policy, and connect the generated new verification policy block to a block chain.

[0135] Optionally, the first processing module 220 is further configured to, if the score of the verification policy score information of the target verification policy is greater than or equal to the preset threshold, generate a new verification policy block according to the adjusted information of the verification policy, and connect the generated new verification policy block to the block chain.

[0136] Optionally, the second communication module 210 is further configured to receive a score of the target verification policy fed back by a dependee according to the verification result, wherein the dependee determines a corresponding right of the prover according to the verification result.

[0137] It can be understood that the remote attestation device 200 of the embodiment of the present application can implement each process of the method embodiment shown in FIG. 12 and achieve the same technical effects, and thus details are not repeated here. Figure 5

[0138] ​​Please refer to Figure 14 , Figure 14 is another structure diagram of a remote attestation device provided by the embodiment of the present application, which is applied to an electronic device, which can be a dependent electronic device, as shown in FIG. 14, the remote attestation device 300 can include:

[0139] a third communication module 310, configured to receive a verification result obtained by a target verifier according to a target verification policy on the to-be-verified information.

[0140] a second processing module 320, configured to determine a permission to be granted to a prover providing the to-be-verified information according to the verification result.

[0141] Optionally, as shown in Figure 15 , the remote attestation device 300 further includes an identification module 330, configured to identify the verification result according to a preset identification policy of the verification result, to obtain an identification result.

[0142] The second processing module 320 is configured to determine the permission to be granted to the prover providing the to-be-verified information according to the obtained identification result.

[0143] Optionally, as shown in Figure 15 , the remote attestation device 300 further includes an evaluation module 340, configured to score the target verification policy according to the verification result.

[0144] The third communication module 310 is further configured to feed back the score to the target verifier, so that the target verifier adjusts the evaluation information of the target verification policy according to the score of the target verification policy.

[0145] It can be understood that the remote attestation device 300 of the embodiment of the present application can implement each process of the method embodiment shown in Figure 6 , and achieve the same technical effects. To avoid repetition, details are not repeated here.

[0146] In addition, the embodiment of the present application further provides a remote attestation system including a prover, a verifier and a dependent. The prover includes the remote attestation device 100 shown in Figure 10 or Figure 11 ; the verifier includes the remote attestation device 200 shown in Figure 12 or Figure 13 ; and the dependent includes the remote attestation device 300 shown in Figure 14 or Figure 15 .

[0147] Further, the embodiment of the present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program can realize the above-mentioned method when executed by the processor. Figures 1 to 6 The processes of the method embodiment shown and the same technical effects can be achieved, and thus details are not repeated here.

[0148] Please refer to Figure 16 The embodiment of the present application also provides an electronic device 400, comprising a bus 410, a transceiver 420, an antenna 430, a bus interface 440, a processor 450 and a memory 460.

[0149] In the embodiment of the present application, the electronic device 400 further comprises a program or instructions stored in the memory 460 and executable on the processor 450. Optionally, the program or instructions can realize the following steps when executed by the processor 450:

[0150] Query a verifier block in the alliance chain providing verification services, and determine information of at least one verifier matched with parameters of the information to be verified;

[0151] Query a verification strategy block in the blockchain providing verification services, and in the information of the verification strategy of the at least one verifier, determine information of a target verification strategy matched with parameters of the information to be verified, and determine a verifier with the target verification strategy as a target verifier;

[0152] Obtain an address of the target verifier from the information of the verifier of the target verifier, and obtain an identification of the target verification strategy from the information of the target verification strategy;

[0153] Send the information to be verified and the identification of the target verification strategy to the address of the target verifier, so that the target verifier obtains a target verification strategy according to the identification of the target verification strategy, and verifies the information to be verified.

[0154] It can be understood that the computer program can realize the above-mentioned method when executed by the processor 450. Figures 1 to 6 The processes of the method embodiment shown and the same technical effects can be achieved, and thus details are not repeated here.

[0155] In Figure 16In particular embodiments, bus architecture (represented by bus 410) can include any number of interconnecting buses and bridges, allowing for example, data to be passed between various components of the device, including for example, the processor 450 and the memory 460. The bus 410 can also link various other circuits such as peripheral devices, voltage regulators and power management circuits, which are well known in the art and thus, will not be described further. Bus interface 440 provides an interface between the bus 410 and the transceiver 420. The transceiver 420 can be a single element or multiple elements, such as a plurality of receivers and transmitters, providing a means for communicating with various other apparatus over a transmission medium. Data processed by the processor 450 is transmitted over a wireless medium via the antenna 430, which further receives data and communicates the data to the processor 450.

[0156] The processor 450 is responsible for managing the bus 410 and general processing, and can also provide various functions including timing, peripheral interfaces, voltage regulation, power management, and other control functions. The memory 460 can be used to store data used by the processor 450 during execution of operations.

[0157] Optionally, the processor 450 can be a CPU, ASIC, FPGA, or CPLD.

[0158] The embodiments of the present application also provide a computer readable storage medium, which stores programs or instructions, and the programs or instructions are executed by a processor to implement various processes of the method embodiments shown above and achieve the same technical effects. To avoid repetition, details will not be described here. Figures 1 to 6

[0159] ​Computer-readable media includes permanent and non-permanent, removable and non-removable media, which can be implemented by any method or technology to store information. Information can be computer-readable instructions, data structures, modules of programs or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carriers.

[0160] It should be noted that in this paper, the term "including", "containing" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.

[0161] The above-mentioned embodiment numbers of the present application are only for description, not representing the advantages and disadvantages of the embodiments.

[0162] Through the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be realized by software and necessary general hardware platform, of course, also can be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical scheme of the present application or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for making a service classification device (which can be a mobile phone, computer, server, air conditioner or network device, etc.) execute the method described in each embodiment of the present application.

[0163] The above-mentioned only is the preferred embodiment of the present application, it should be pointed out that, for those skilled in the art, without departing from the principle of the present application, can make a number of improvements and refinements, these improvements and refinements should be regarded as the protection scope of the present application.

Claims

1. A remote attestation method applied to an electronic device, comprising: The method comprises the following steps: querying a block of a verifier in an alliance chain providing a verification service to determine information of at least one verifier matching parameters of information to be verified; querying a block of a verification strategy in a blockchain providing a verification service to determine information of a target verification strategy matching the parameters of the information to be verified in the information of the verification strategy of the at least one verifier, and determining a verifier with the target verification strategy as a target verifier; obtaining an address of the target verifier from the information of the verifier of the target verifier, and obtaining an identifier of the target verification strategy from the information of the target verification strategy; sending the information to be verified and the identifier of the target verification strategy to the address of the target verifier, so that the target verifier obtains a target verification strategy according to the identifier of the target verification strategy, and verifies the information to be verified.

2. The method of claim 1, wherein, The method of querying a block of a verification strategy in a blockchain providing a verification service to determine information of a target verification strategy matching the parameters of information to be verified in the information of the verification strategy of the at least one verifier, and determining a verifier with the target verification strategy as a target verifier, comprises the following steps: for each of the at least one verifier, querying a block of a verification strategy in a blockchain providing a verification service to determine information of a verification strategy matching the parameters of the information to be verified; determining the information of the target verification strategy from the determined information of the verification strategy of the at least one verifier matching the parameters of the information to be verified according to evaluation information in the information of the verification strategy; determining the verifier with the target verification strategy in the at least one verifier as the target verifier.

3. The method of claim 2, wherein, The method of determining the information of the target verification strategy from the determined information of the verification strategy of the at least one verifier matching the parameters of the information to be verified according to evaluation information in the information of the verification strategy, comprises the following steps: determining information of a verification strategy in a valid state from the information of the verification strategy of the at least one verifier matching the parameters of the information to be verified according to verification strategy state information in the evaluation information; determining information of a verification strategy with the highest score from the determined information of the verification strategy in a valid state as the information of the target verification strategy according to verification strategy score information in the evaluation information.

4. The method of claim 3, wherein, After sending the information to be verified and the identifier of the target verification strategy to the address of the target verifier, the method further comprises the following steps: receiving a verification result obtained by the target verifier according to the target verification strategy on the information to be verified; scoring the target verification strategy according to the verification result, and feeding back the score to the target verifier, so that the target verifier adjusts evaluation information of the target verification strategy according to the score of the target verification strategy.

5. The method of claim 4, wherein, The method of adjusting the evaluation information of the target verification strategy by the target verifier according to the score of the target verification strategy, comprises the following steps: receiving a score of the target verification strategy fed back by a witness providing the information to be verified; According to the score of the target verification strategy received, the score of the verification strategy score information in the information of the target verification strategy is adjusted; It is judged whether the score of the verification strategy score information of the target verification strategy is less than a preset threshold value; If the score of the verification strategy score information of the target verification strategy is less than a preset threshold value, the verification strategy state information in the information of the target verification strategy is adjusted to an invalid state, and the target verification strategy is adjusted to generate a new target verification strategy; According to the adjusted verification strategy information, a new verification strategy block is generated, and the generated new verification strategy block is connected to the block chain.

6. The method of claim 5, wherein, The target verifier adjusts the evaluation information of the target verification strategy according to the score of the target verification strategy, and further comprises: If the score of the verification strategy score information of the target verification strategy is greater than or equal to a preset threshold value, a new verification strategy block is generated according to the adjusted verification strategy information, and the generated new verification strategy block is connected to the block chain.

7. The method according to claim 5 or 6, characterized in that, The target verifier adjusts the evaluation information of the target verification strategy according to the score of the target verification strategy, and further comprises: The dependent receives the score of the target verification strategy according to the verification result feedback, wherein the dependent determines to grant the corresponding authority to the prover according to the verification result.

8. The method of claim 7, wherein, The dependent determines to grant the authority to the prover according to the verification result, comprising: The target verifier receives the verification result obtained by verifying the to-be-verified information according to the target verification strategy; According to the preset verification result identification strategy, the verification result is identified to obtain an identification result; According to the obtained identification result, it is determined to grant the authority to the prover who provides the to-be-verified information.

9. A remote verification device, applied to a verifier, characterized in that, Comprising: The query module is used to query the verifier block in the alliance chain which provides verification service, determine the information of at least one verifier matched with the parameters of the to-be-verified information, and query the verification strategy block in the block chain which provides verification service, determine the information of the target verification strategy matched with the parameters of the to-be-verified information in the verification strategy information of the at least one verifier, and determine the verifier with the target verification strategy as the target verifier; The first communication module is used to obtain the address of the target verifier from the verifier information of the target verifier, and obtain the identification of the target verification strategy from the information of the target verification strategy; The to-be-verified information and the identification of the target verification strategy are sent to the address of the target verifier, so that the target verifier obtains the target verification strategy according to the identification of the target verification strategy, and verifies the to-be-verified information. The query module comprises:

10. The apparatus of claim 9, wherein, The query unit is used to query the verification strategy block in the block chain which provides verification service for each verifier in the at least one verifier, and determine the information of the verification strategy matched with the parameters of the to-be-verified information; ​ The processing unit is configured to determine, according to evaluation information in the information of the verification policy, the information of the target verification policy from the information of the verification policy of the at least one verifier that matches the parameter of the information to be verified; and determine the verifier having the target verification policy in the at least one verifier as the target verifier.

11. The apparatus of claim 10, wherein, The processing unit comprises: A state processing subunit configured to determine, according to verification policy state information in the evaluation information, the information of the verification policy in an active state from the information of the verification policy of the at least one verifier that matches the parameter of the information to be verified; A score processing subunit configured to determine, according to verification policy score information in the evaluation information, the information of the verification policy with the highest score from the information of the verification policy in the active state as the information of the target verification policy.

12. The apparatus of claim 11, wherein, The communication module is further configured to receive a verification result obtained by the target verifier from verifying the information to be verified according to the target verification policy. The device further comprises: An evaluation module configured to score the target verification policy according to the verification result; The first communication module is further configured to feed back the score to the target verifier, so that the target verifier adjusts the evaluation information of the target verification policy according to the score of the target verification policy.

13. A remote attestation apparatus applied to a verifier, comprising: The device comprises: A second communication module configured to receive information to be verified and an identifier of a target verification policy; wherein the identifier of the target verification policy is obtained from information of the target verification policy; the information of the target verification policy is information that matches the parameter of the information to be verified and is determined from the information of the at least one verifier by querying a verification policy block in a block chain that provides verification services; and the information of the at least one verifier is information of the verifier that matches the parameter of the information to be verified and is determined by querying a verifier block in a consortium chain that provides verification services; A first processing module configured to obtain a target verification policy according to the identifier of the target verification policy, and verify the information to be verified to obtain a verification result; The second communication module is further configured to feed back the obtained verification result to a prover of the information to be verified and a corresponding dependee.

14. The apparatus of claim 13, wherein, The second communication module is further configured to receive a score of the target verification policy fed back by the prover of the information to be verified; The device further comprises: An adjustment module configured to adjust a score of the verification policy score information in the information of the target verification policy according to the received score of the target verification policy; determine whether the score of the verification policy score information of the target verification policy is less than a preset threshold value; if the score of the verification policy score information of the target verification policy is less than the preset threshold value, adjust the verification policy state information in the information of the target verification policy to an invalid state, and adjust the target verification policy to generate a new target verification policy; The first processing module is further configured to generate a new verification policy block according to the adjusted information of the verification policy, and connect the generated new verification policy block to the block chain.

15. The apparatus of claim 14, wherein, The first processing module is further configured to, if the score of the verification policy score information of the target verification policy is greater than or equal to a preset threshold, generate a new verification policy block according to the adjusted information of the verification policy, and connect the generated new verification policy block to the block chain.

16. The apparatus of claim 14 or 15, wherein, The second communication module is further configured to receive a score of the target verification policy fed back by a dependee according to the verification result, wherein the dependee determines to grant the prover corresponding authority according to the verification result.

17. A remote attestation device applied to a dependee, characterized in that, The method comprises: The third communication module is configured to receive a verification result obtained by a target verifier by verifying the to-be-verified information according to a target verification policy; wherein the target verification policy is obtained according to an identifier of the target verification policy; the identifier of the target verification policy is obtained from information of the target verification policy; the information of the target verification policy is determined by querying a block chain for a verification policy block providing a verification service, and searching for information of at least one verifier matching a parameter of the to-be-verified information from information of the at least one verifier; the information of the at least one verifier is determined by querying a consortium chain for a verifier block providing a verification service, and searching for information of a verifier matching the parameter of the to-be-verified information from the information of the at least one verifier; The second processing module is configured to determine to grant a prover providing the to-be-verified information corresponding authority according to the verification result.

18. The apparatus of claim 17, wherein, The device further comprises: The identification module is configured to identify the verification result according to a preset verification result identification strategy, and obtain an identification result; The second processing module is configured to determine to grant the prover providing the to-be-verified information corresponding authority according to the obtained identification result.

19. The apparatus of claim 17 or 18, wherein, The device further comprises: The evaluation module is configured to score the target verification policy according to the verification result; The third communication module is further configured to feed back the score to the target verifier, so that the target verifier adjusts evaluation information of the target verification policy according to the score of the target verification policy.

20. A remote attestation system, comprising: The method comprises: The prover comprises the remote attestation device according to any one of claims 9 to 12; The verifier comprises the remote attestation device according to any one of claims 13 to 16; The dependee comprises the remote attestation device according to any one of claims 17 to 19.

21. An electronic device, comprising: The computer readable storage medium stores a program or instructions, and the program or instructions are executed by the processor to implement the steps of the remote attestation method according to any one of claims 1 to 8.

22. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a program or instructions, and the program or instructions are executed by the processor to implement the steps of the remote attestation method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Badge authentication

    CN105229682A

  • System and method for binding verifiable claims

    CN111602116A

  • Identity label sharing method and device, electronic equipment and readable storage medium

    CN114722429A

  • Offline verification method and system, verification terminal, readable storage medium and product

    CN118803030A

  • Attestation token sharing in edge computing environments

    US20200084202A1