ID-PKC information processing method, device, node and storage medium

By publishing and managing the public parameters and IRL of the ID-PKC system on the consortium chain, the certificate management complexity and multi-CA trust issues of the ID-PKC system in a cross-domain environment are solved, and cross-domain secure communication is achieved.

CN115225259BActive Publication Date: 2025-09-16CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111203497.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-04-19
Filing Date
2021-10-15
Publication Date
2025-09-16
Estimated Expiration
2041-10-15

AI Technical Summary

Technical Problem

The ID-PKC system relies on the PKI system during the boot process, which leads to complex certificate management and multi-CA trust issues. In addition, the establishment of the TLS secure channel requires certificates, which violates the original design intention of the ID-PKC system.

Method used

Through the consensus mechanism of the alliance chain, the public parameters and IRL of the ID-PKC system are written into the alliance chain to achieve cross-domain transmission and query, avoiding dependence on the PKI system.

Benefits of technology

It realizes cross-domain secure communication, simplifies certificate management, and solves the security and reliability issues of the ID-PKC system in a cross-domain environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115225259B_ABST
    Figure CN115225259B_ABST
Patent Text Reader

Abstract

This application discloses an identity-based public cryptography (ID-PKC) information processing method, device, node, and storage medium. The method includes: a first node obtains first ID-PKC system public parameters and / or an identity revocation list (IRL); the first ID-PKC system public parameters are valid; the first node is a bookkeeping node; and based on a consensus mechanism, the obtained first ID-PKC system public parameters and / or IRL are written into a consortium chain.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is based on the Chinese patent application with application number 202110419392.5 and application date of April 19, 2021, and claims the priority of the Chinese patent application. The entire content of the Chinese patent application is hereby introduced into this application as a reference. Technical Field

[0002] The present application relates to the field of network security technology, and in particular to an IDentity-based Public Key Cryptograph (ID-PKC) information processing method, device, node and storage medium. Background Art

[0003] In an ID-PKC system, public keys are not transmitted using certificates, eliminating the need for certificates and certificate management systems. Public parameters and / or identity revocation lists (IRLs) do not require encrypted transmission, but they cannot be altered during transmission. Therefore, in related technologies, the Transport Layer Security (TLS) protocol is used to securely transmit public parameters and IRLs.

[0004] However, when using the TLS protocol, the establishment of a TLS secure channel requires the use of certificates. In other words, the boot process of the ID-PKC system actually relies on the public key infrastructure (PKI)-based public cryptography (PKI-PKC) system, which will introduce the defects of the PKI-PKC system into the ID-PKC system. Summary of the Invention

[0005] To solve related technical problems, embodiments of the present application provide an ID-PKC information processing method, device, node, and storage medium.

[0006] The technical solution of the embodiment of the present application is implemented as follows:

[0007] This embodiment of the present application provides an ID-PKC information processing method, applied to a first node, including:

[0008] Obtaining a first ID-PKC system public parameter and / or IRL; the status of the first ID-PKC system public parameter is valid; the first node is a billing node;

[0009] Based on the consensus mechanism, the obtained first ID-PKC system public parameters and / or IRL are written into the alliance chain.

[0010] In the above solution, the first ID-PKC system public parameters are generated by the public parameter server (PPS) of the key generation center (KGC);

[0011] The first ID-PKC system public parameter includes at least one of the following:

[0012] Domain name;

[0013] Blockchain name;

[0014] System public parameter status;

[0015] The hashing algorithm used to hide the user's identity.

[0016] In the above solution, the domain name is a name defined according to a Uniform Resource Identifier (URI) or a Uniform Resource Locator (URL), or is a custom name.

[0017] In the above solution, the first ID-PKC system public parameters also include:

[0018] PPS name;

[0019] The name of the Identity Management Server (IMS).

[0020] In the above solution, the PPS name is a name defined according to URI or URL, or a custom name.

[0021] In the above scheme, the name is defined according to the URI or URL, or is a custom name.

[0022] In the above solution, the IRL is generated by the Identity Management Server (IMS) of KGC;

[0023] The IRL includes at least one of the following:

[0024] Domain name;

[0025] Blockchain name;

[0026] A collection of revocation identifiers.

[0027] In the above solution, the domain name is a name defined according to URI or URL, or a custom name.

[0028] In the above solution, the IRL further comprises:

[0029] IMS name.

[0030] In the above solution, the IMS name is a name defined according to a URI or URL, or a user-defined name.

[0031] In the above solution, the revocation identification set includes at least one of the following:

[0032] Whether the revocation identification is anonymous;

[0033] Revoke identification;

[0034] Reason for revocation.

[0035] In the above solution, the method further includes:

[0036] Acquire the second ID-PKC system public parameter; the status of the second ID-PKC system public parameter is invalid; the second ID-PKC system public parameter is the same as the first ID-PKC system public parameter except for the production time and status;

[0037] Based on the consensus mechanism, the acquired second ID-PKC system public parameters are written into the alliance chain;

[0038] Acquire a newly generated third ID-PKC system public parameter; the third ID-PKC system public parameter is updated by the first ID-PKC system public parameter; the status of the third ID-PKC system public parameter is valid;

[0039] Based on the consensus mechanism, the obtained third ID-PKC system public parameters are written into the alliance chain.

[0040] This embodiment of the present application further provides an ID-PKC information processing method, which is applied to a second node and includes:

[0041] Obtain a first request; the first request is used to request to obtain ID-PKC system public parameters;

[0042] Query the corresponding ID-PKC system public parameters from the consortium chain;

[0043] Returns a response based on the query results.

[0044] In the above solution, when querying the corresponding ID-PKC system public parameters from the consortium chain, the method includes:

[0045] Start querying from the latest block of the consortium chain.

[0046] In the above solution, the first request carries the domain name and the blockchain name;

[0047] Use the domain name carried in the first request to query the corresponding ID-PKC system public parameters from the alliance chain corresponding to the blockchain name.

[0048] In the above solution, the first request also carries the PPS name;

[0049] Use the domain name and / or PPS name carried in the first request to query the corresponding ID-PKC system public parameters from the alliance chain corresponding to the blockchain name.

[0050] In the above solution, returning a response based on the query result includes:

[0051] When the corresponding ID-PKC system public parameters are not found, an error message is returned;

[0052] or,

[0053] When the corresponding ID-PKC system common parameters are queried and the status of the queried ID-PKC system common parameters is invalid, an error message is returned;

[0054] or,

[0055] When the corresponding ID-PKC system common parameters are found and the status of the found ID-PKC system common parameters is valid, the found ID-PKC system common parameters are returned.

[0056] This embodiment of the present application further provides an ID-PKC information processing method, which is applied to a third node and includes:

[0057] Obtain a second request; the second request is used to request to query whether the first identification has been revoked;

[0058] querying from the alliance chain whether the first identification has been revoked; the alliance chain records the IRL;

[0059] Returns a response based on the query results.

[0060] In the above solution, the second request carries the first identifier and the blockchain name; and the first identifier is used to query the consortium chain corresponding to the blockchain name.

[0061] In the above solution, the second request carries the result of computing the first identifier using the hash function indicated by the public parameters of the ID-PKC system and the blockchain name;

[0062] The operation result is used to query the alliance chain corresponding to the blockchain name.

[0063] In the above solution, returning a response based on the query result includes:

[0064] When it is found that the first identification has been revoked, first information is returned; the first information indicates that the first identification has been revoked;

[0065] or,

[0066] When the first identifier is not found, second information is returned; the second information indicates that the first identifier is valid.

[0067] The embodiment of the present application further provides an ID-PKC information processing device, which is provided on a first node and includes:

[0068] A first acquiring unit is configured to acquire a first ID-PKC system public parameter and / or an IRL; the first ID-PKC system public parameter is in a valid state; and the first node is a bookkeeping node;

[0069] The first processing unit is configured to write the obtained first ID-PKC system public parameters and / or IRL into the alliance chain based on a consensus mechanism.

[0070] The present application also provides an ID-PKC information processing device, including:

[0071] A second acquiring unit is configured to acquire a first request, wherein the first request is used to request acquisition of public parameters of the ID-PKC system;

[0072] The second processing unit is used to query the corresponding ID-PKC system public parameters from the alliance chain and return a response based on the query result.

[0073] The present application also provides an ID-PKC information processing device, including:

[0074] A third acquiring unit is configured to acquire a second request, wherein the second request is configured to query whether the first identification has been revoked;

[0075] The third processing unit is used to query whether the first identification has been revoked from the alliance chain; the alliance chain records the IRL; and return a response according to the query result.

[0076] The embodiment of the present application further provides a first node, comprising: a first communication interface and a first processor; wherein,

[0077] The first communication interface is used to obtain a first ID-PKC system public parameter and / or an IRL; the status of the first ID-PKC system public parameter is valid; and the first node is a billing node;

[0078] The first processor is configured to write the acquired first ID-PKC system public parameters and / or IRL into the alliance chain based on a consensus mechanism.

[0079] The embodiment of the present application further provides a second node, comprising: a second communication interface and a second processor; wherein,

[0080] The second communication interface is used to obtain a first request; the first request is used to request to obtain public parameters of the ID-PKC system;

[0081] The second processor is used to query the corresponding ID-PKC system public parameters from the alliance chain; and return a response through the second communication interface according to the query result.

[0082] The embodiment of the present application further provides a third node, comprising: a third communication interface and a third processor; wherein,

[0083] The third communication interface is used to obtain a second request; the second request is used to request to query whether the first identification has been revoked;

[0084] The third processor is used to query from the alliance chain whether the first identification has been revoked; the alliance chain records the IRL; and return a response through the third communication interface according to the query result.

[0085] An embodiment of the present application further provides a first node, comprising: a first processor and a first memory for storing a computer program that can be run on the processor,

[0086] The first processor is configured to execute the steps of any method on the first node side when running the computer program.

[0087] The embodiment of the present application further provides a second node, comprising: a second processor and a second memory for storing a computer program that can be run on the processor,

[0088] The second processor is configured to execute the steps of any one of the above-mentioned second node side methods when running the computer program.

[0089] The embodiment of the present application further provides a third node, comprising: a third processor and a third memory for storing a computer program that can be run on the processor.

[0090] The third processor is configured to execute the steps of any one of the above-mentioned third node side methods when running the computer program.

[0091] An embodiment of the present application also provides a storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the above-mentioned methods on the first node side, or implements the steps of any of the above-mentioned methods on the second node side, or implements the steps of any of the above-mentioned methods on the third node side.

[0092] The ID-PKC information processing method, device, node, and storage medium provided in the embodiments of the present application include: a first node obtains a first ID-PKC system public parameter and / or IRL; the status of the first ID-PKC system public parameter is valid; the first node is a bookkeeping node; based on a consensus mechanism, the obtained first ID-PKC system public parameter and / or IRL is written into a consortium chain; a second node obtains a first request; the first request is used to request the acquisition of the ID-PKC system public parameter; the corresponding ID-PKC system public parameter is queried from the consortium chain; and a response is returned based on the query result; a third node obtains a second request; the second request is used to request whether the first identity has been revoked; the first identity is queried from the consortium chain; the consortium chain records the IRL; and a response is returned based on the query result. The solution provided in the embodiments of the present application is based on the consortium chain for the publication of ID-PKC system public parameters and the management of identity revocation. By using the consortium chain, ID-PKC system parameters and IRL can be transmitted across domains, and identity revocation can be queried across domains, thereby achieving cross-domain secure communication without relying on the PKI-PKC system and using the ID-PKC system. BRIEF DESCRIPTION OF THE DRAWINGS

[0093] Figure 1 This is a flowchart of a method for ID-PKC information processing according to an embodiment of the present application;

[0094] Figure 2 This is a flow chart of a second method for ID-PKC information processing according to an embodiment of the present application;

[0095] Figure 3 This is a flow chart of a second method for ID-PKC information processing according to an embodiment of the present application;

[0096] Figure 4 This is a schematic diagram of the structure of the first ID-PKC information processing device according to an embodiment of the present application;

[0097] Figure 5 This is a schematic structural diagram of the second ID-PKC information processing device according to an embodiment of the present application;

[0098] Figure 6 This is a schematic structural diagram of the third ID-PKC information processing device according to an embodiment of the present application;

[0099] Figure 7 This is a schematic diagram of the first node structure of an embodiment of the present application;

[0100] Figure 8 This is a schematic diagram of the second node structure of an embodiment of the present application;

[0101] Figure 9 This is a schematic diagram of the third node structure of an embodiment of this application. DETAILED DESCRIPTION

[0102] The present application will be described in further detail below with reference to the embodiments.

[0103] Before describing the embodiments of the present application, it is necessary to first understand the related technologies.

[0104] In traditional certificate-based key systems, the verifiability of user identities and public keys is achieved by binding public keys and identities in certificates and signing them with a trusted third-party certification authority (CA). Although certificate-based key systems have been widely used, they have some shortcomings:

[0105] (1) Certificates need to be exchanged in secure applications;

[0106] (2) The validity of the certificate needs to be verified when it is used;

[0107] (3) The issuance and management of certificates are very complicated.

[0108] To address these issues with certificate-based key systems, such as PKI-PKC, which rely on certificates and certificate management systems, Israeli cryptographer Shamir proposed the ID-PKC system in 1984, also known as the Identity-Based Cryptograph (ID-PKC) system. The key concept of the ID-PKC system is that public keys are no longer transmitted through certificates. Instead, user identifiers, such as name, Internet Protocol (IP) address, email address, or mobile phone number, are used as public keys. The private key is calculated by a key generation center (KGC) based on the system master key and user identifier. Consequently, this system no longer relies on certificates and certificate management systems (such as PKI-PKC systems), greatly simplifying the complexity of managing cryptographic systems. Simultaneously with the ID-PKC concept, Shamir proposed an identity-based signature algorithm (IBS) that uses the RSA algorithm. However, an effective solution for identity-based encryption (IBE) has long eluded the development of effective solutions. It wasn't until 2001 that D. Boneh and M. Franklin proposed pairing on elliptic curves to achieve a secure IBE system. Currently, the most efficient identity-based signature algorithm is the Elliptic Curve-based Certificateless Signatures for Identity-based Encryption (ECCSI) scheme.

[0109] The public parameters of the ID-PKC system do not require encrypted transmission, but must remain unchanged during transmission (i.e., integrity must be guaranteed). This is because the integrity of the public parameters is crucial to the correct use of the ID-PKC system. Initializing the ID-PKC system within a domain is relatively easier than across domains. Users within the domain can securely obtain their private keys and the public parameters of the ID-PKC system (e.g., through offline methods). The security of the transmission of user private keys and public parameters in the ID-PKC system can be achieved by using the Transport Layer Security (TLS) protocol. Specifically, a TLS secure channel is established between the user and the KGC, and the ID-PKC system public parameters are transmitted over the TLS secure channel.

[0110] On the other hand, ID-PKC systems require identity revocation to prevent the continued use of identities or credentials that are no longer valid or have security vulnerabilities, such as service termination or private key compromise. When revoking an identity, it should be set to a revoked state. The revoked identity constitutes the IRL, and a reliable channel is required to deliver the IRL to the user. This can be accomplished through a secure TLS channel established between the user and the KGC.

[0111] However, establishing a TLS secure channel requires the use of certificates, which means that the bootstrapping process of the ID-PKC system is actually dependent on PKI, which runs counter to the original design intent of the ID-PKC system. In addition, the multi-CA trust issue in certificate-based key systems is transferred to the ID-PKC system.

[0112] Based on this, in various embodiments of the present application, the publication of public parameters of the ID-PKC system and the management of identity revocation are performed based on the alliance chain.

[0113] In an embodiment of the present application, the public parameters and / or IRL of the ID-PKC system are written into the alliance chain through the consensus mechanism of the alliance chain. By using the alliance chain, the ID-PKC system parameters and IRL can be transmitted across domains, and identity revocation can be queried across domains, thereby achieving cross-domain secure communication without relying on the PKI system and using the ID-PKC system.

[0114] The embodiment of the present application provides an ID-PKC information processing method, which is applied to a first node, such as Figure 1 As shown, the method includes:

[0115] Step 101: Obtain first ID-PKC system public parameters and / or IRL; the status of the first ID-PKC system public parameters is valid; the first node is a billing node;

[0116] Step 102: Based on the consensus mechanism, the obtained first ID-PKC system public parameters and / or IRL are written into the alliance chain.

[0117] Here, in actual application, the ID-PKC system common parameters may also be referred to as ID-PKC system parameters or ID-PKC parameters. It should be noted that the ID-PKC system common parameters may also be named by other names, as long as they have the same function or effect as the ID-PKC system common parameters, and this embodiment of the application does not limit this. Correspondingly, IRL may also use other names, as long as they have the same function or effect as IRL, and this embodiment of the application does not limit this.

[0118] The alliance chain is a blockchain that is jointly managed by several organizations. The alliance chain specifies multiple pre-selected nodes as accounting nodes. The generation of each block is jointly determined by all pre-selected nodes using a consensus mechanism. Other access nodes can read the information on the chain but do not inquire about the accounting process. The alliance chain uses distributed ledgers and distributed consensus technology to form data immutable. A distributed database. As long as the information published on the chain is authentic and trustworthy.

[0119] In the embodiment of the present application, the organization may include a KGC of a domain. A KGC of a domain may correspond to one or more accounting nodes.

[0120] In actual application, the first ID-PKC system public parameter can be generated by KGC. Here, it should be noted that the embodiment of the present application does not limit the name of the organization that generates the ID-PKC system public parameter.

[0121] Among them, KGC usually includes the following three parts:

[0122] The Private Key Generator (PKG) generates a user's private key based on the master password and user identity securely stored in the ID-PKC system. The private key is distributed to the user over a secure channel, ensuring confidentiality and integrity. Therefore, only the user with the associated identity knows the private key.

[0123] The PPS is used to provide users with ID-PKC system public parameters and policy information describing PKC operations. Because the integrity of these public parameters and policy information is crucial to the proper functioning of the ID-PKC system, the communication channel between the user and the PPS must be trustworthy. In practice, the communication channel between the user and the PPS is not necessarily confidential, as these public parameters and policy information are publicly accessible. Therefore, the first ID-PKC system public parameters can be generated by the KGC's PPS.

[0124] The IMS manages user identities, including ensuring their uniqueness within the management domain, maintaining identity status (including validity and revocation), and publishing identity revocation lists (IRLs). The communication channel between users and the IMS should be trustworthy. In practice, the communication channel between users and the IMS is not necessarily confidential, as identity revocation lists are publicly accessible.

[0125] The ID-PKC system public parameters can include many parameters. In the embodiment of the present application, since the ID-PKC system public parameters are stored in the alliance chain, in addition to the general parameters, the ID-PKC system public parameters also need to include parameters associated with the alliance chain.

[0126] Based on this, in one embodiment, the first ID-PKC system public parameter includes at least one of the following:

[0127] Domain name (i.e. the name of the domain where KGC is located);

[0128] Blockchain name;

[0129] System public parameter status;

[0130] The hashing algorithm used to hide the user's identity.

[0131] Among them, the domain name indicates the name of the domain where the KGC that generates the first ID-PKC system public parameters is located; the blockchain name can also be called the alliance chain name, indicating the name of the alliance chain corresponding to the first ID-PKC system public parameters; the system public parameter status indicates the status of the first ID-PKC system public parameters, specifically valid; the hash algorithm used to hide the user identity is used to anonymize the identity in IRL.

[0132] Here, the ID-PKC system public parameter may further include at least one of the following:

[0133] PPS name;

[0134] IMS name.

[0135] The PPS name indicates the name of the PPS, and the IMS name indicates the name of the IMS.

[0136] In actual application, according to the encoding method, such as the ASN.1 method, the public parameters of the ID-PKC system can be described as follows:

[0137]

[0138] The meaning of each field is as follows:

[0139] version: is the version number of the ID-PKC system public parameters;

[0140] domainName: is the name of the domain where the KGC is located, used for KGC addressing. It can be a name defined by URI or URL, or a name defined by the user in his own way, that is, a custom name;

[0141] ppsName: is the name of the PPS, used for PPS addressing. It can be a name defined according to the URI or URL, or a name defined by the user in his own way, that is, a custom name.

[0142] imsName: is the name of the IMS, used for IMS addressing. It can be a name defined according to a URI or URL, or a name defined by the user in his own way, that is, a custom name.

[0143] domainSerial: This field is an integer representing a unique set of ID-PKC system public parameters that can be used on domainName, that is, a set of ID-PKC system public parameters that can be used on the domain where the KGC indicated by domainName is located;

[0144] Validity: This field defines the lifetime of the public parameters of the ID-PKC system and is defined as follows:

[0145]

[0146] id-pkcPublicParameters: is a structure that contains the public parameters corresponding to the ID-PKC algorithm supported by the ID-PKC system. The structure is defined as follows:

[0147]

[0148] Here, id-pkcAlgorithm: at least one ID-PKC algorithm supported by an ID-PKC system;

[0149] publicParameterData: This is a Distinguished Encoding Rules (DER)-encoded structure containing the actual cryptographic parameters. The specific structure of this field depends on the algorithm.

[0150] ID-PKCIdentityType: An identity used to define the type of identity used within a domain. The usage of this field depends on the application.

[0151] blockchainName: The public parameters of the ID-PKC system are published on the blockchain (i.e., consortium chain). This field is used to indicate the name of the blockchain.

[0152] hashAlgorithm: This field indicates the hash algorithm used to hide the user identity and is used to anonymize the user identity in IRL. The definition of this field is as follows:

[0153]

[0154]

[0155] id-pkcParamStatus: Indicates the status of the public parameters of the ID-PKC system. It can have two states: valid and invalid (also called revoked). The definition of this field is as follows:

[0156]

[0157] id-pkcParamExtensions: It is a set of extensions that can be used to define additional parameters that a specific implementation may require. The structure of this field is defined as follows:

[0158]

[0159] It should be noted that the embodiments of the present application do not limit the names of the above fields.

[0160] In actual application, in step 102, the first node can form a block based on the consensus mechanism using the first ID-PKC system public parameters, and then publish the formed block to the consortium chain. In the consortium chain, the blocks are linked into the consortium chain in chronological order (for example, the chronological order in which the ID-PKC system public parameters were generated).

[0161] For example, the specific steps of writing the public parameters of the ID-PKC system into the consortium chain include:

[0162] Step 1: The PPS of the KGC of a domain generates the ID-PKC system public parameters and marks their status as valid, that is, the ID-PKCParamStatus field is set to valid.

[0163] Step 2: One or several accounting nodes of the KGC's PPS on the alliance chain, together with the accounting nodes of the KGC's PPS in other domains on the alliance chain, that is, all accounting nodes on the alliance chain, use the consensus mechanism to write the ID-PKC system public parameters generated by the KGC's PPS into the alliance chain.

[0164] In actual application, KGC and accounting nodes may be set together, or KGC and accounting nodes may be set separately. In the case of separate settings, KGC and accounting nodes interact through a secure channel.

[0165] Here, after steps 1 and 2, the public parameters of the ID-PKC system are uploaded to the chain.

[0166] In actual applications, the ID-PKC system public parameters may need to be updated, such as when the cryptographic algorithm changes. Since messages on the consortium chain cannot be deleted, it is necessary to generate a new ID-PKC system public parameter that is identical to the original one, mark it as invalid, and write it to the consortium chain. Then, generate a new ID-PKC system public parameter with updated content, mark it as valid, and write it to the consortium chain, completing the update of the ID-PKC system public parameters.

[0167] Based on this, in one embodiment, the method may further include:

[0168] Acquire the second ID-PKC system public parameter; the status of the second ID-PKC system public parameter is invalid; the second ID-PKC system public parameter is the same as the first ID-PKC system public parameter except for the production time and status;

[0169] Based on the consensus mechanism, the acquired second ID-PKC system public parameters are written into the alliance chain;

[0170] Acquire newly generated third ID-PKC system public parameters; the third ID-PKC system public parameters are updated by the first ID-PKC system public parameters;

[0171] The status of the third ID-PKC system public parameter is valid;

[0172] Based on the consensus mechanism, the obtained third ID-PKC system public parameters are written into the alliance chain.

[0173] Exemplarily, the specific steps of updating the public parameters of the ID-PKC system include:

[0174] Step 1: PPS generates a second ID-PKC system public parameter with the same content as the ID-PKC system public parameter on the chain (except for the status item and generation time), that is, it generates a second ID-PKC system public parameter and marks its status as invalid.

[0175] Step 2: One or several accounting nodes of the PPS on the alliance chain, together with accounting nodes of other domains, use the consensus mechanism to write the ID-PKC system public parameters generated in step 1 into the alliance chain;

[0176] Step 3: The PPS generates another ID-PKC system public parameter with updated information content, i.e., generates a third ID-PKC system public parameter, and marks its status as valid;

[0177] Step 4: One or several accounting nodes of the PPS on the alliance chain, together with the accounting nodes of other domains, use the consensus mechanism to write the ID-PKC system parameters with updated information content into the alliance chain.

[0178] In actual application, the IRL may be generated by the KGC. Specifically, the IRL may be generated by the IMS of the KGC.

[0179] IRL can contain many parameters. In the embodiment of the present application, since IRL is stored in the alliance chain, in addition to general parameters, IRL also needs to include parameters associated with the alliance chain.

[0180] Based on this, in one embodiment, the IRL includes at least one of the following:

[0181] Domain name;

[0182] Blockchain name;

[0183] A collection of revocation identifiers.

[0184] The domain name indicates the name of the domain where the KGC that generates the IRL is located; the blockchain name can also be called the consortium chain name, indicating the name of the consortium chain corresponding to the IRL.

[0185] In one embodiment, the IRL may further include:

[0186] IMS name.

[0187] Here, the IMS name indicates the name of the MIS.

[0188] In one embodiment, the revocation identification set includes at least one of the following:

[0189] Whether the revocation identification is anonymous;

[0190] Revoke identification;

[0191] Reason for revocation.

[0192] In practical applications, depending on the encoding method, such as the ASN.1 method, IRL can be described as follows:

[0193]

[0194]

[0195] The meaning of each field is as follows:

[0196] Version: is the IRL version number;

[0197] Issuer: used to distinguish the issuer of IRL;

[0198] irlNumbe: is the issuer number of the current IRL; it starts at 0 and increases by 1 for each complete IRL release (i.e., the IRL released by KGC at a certain point in time includes all revocation flags). It is optional;

[0199] deltaList: Indicates whether the current IRL is an incremental IRL (i.e., a revoked identity at a certain point in time compared to the previous point in time). This list only contains identity information that has been revoked since the full IRL indexed by irlNumber was published;

[0200] domainName: is the name of the domain where the KGC that generates the IRL is located. It is used for KGC addressing. It can be a name defined by URI or URL, or a name defined by the user in his own way, that is, a custom name;

[0201] domainSerial: This field is an integer representing the set of unique IRLs that can be used on domainName, that is, the set of IRLs that can be used on the domain where the KGC indicated by domainName is located;

[0202] imsName: is the name of the IMS, used for IMS addressing. It can be a name defined according to a URI or URL, or a name defined by the user in his own way, that is, a custom name.

[0203] thisUpdate: indicates the time when this IRL table was generated;

[0204] nextUpdate: indicates the next IRL generation time, which is optional;

[0205] blockchainName: The IRL is published on a blockchain (i.e., a consortium chain). This field is used to indicate the name of the blockchain.

[0206] revokedIdentities: Used to indicate the revoked identity set, including the following fields: anonymity, identity, revokeReason, revocationDate, irlEntryExtensions. These fields are described as follows:

[0207] (1) anonymity: used to indicate whether the revocation identification needs to be anonymous, that is, whether the revocation identification is anonymous. The specific description of this field is as follows:

[0208]

[0209] (2) identity: used to indicate the revocation identity. The specific description of this field is as follows:

[0210] identity::=ID-PKCIdentityInfo

[0211] ID-PKCIdentityInfo::=CHOICE{

[0212] Hash(RovokedIdendity),

[0213] RovokedIdentity,

[0214] }

[0215] If anonymity is YES, the ID-PKCIdentityInfo field corresponds to the hash value of the revocation identifier; otherwise, the ID-PKCIdentityInfo field corresponds to the revocation identifier itself.

[0216] (3)revokeReason: Used to describe the reason for revoking the identity. This field is described as follows:

[0217]

[0218] irlEntryExtensions: This field defines possible revocation flag extensions.

[0219] It should be noted that the embodiments of the present application do not limit the names of the above fields.

[0220] In actual application, in step 102, the first node can form a block based on the consensus mechanism, and then publish the formed block to the alliance chain. In the alliance chain, the blocks are linked into the alliance chain in chronological order (for example, the chronological order of the generation of the IRL).

[0221] For example, the specific steps of writing the IRL number into the alliance chain (i.e., publishing (also understood as issuing) the IRL on the alliance) include:

[0222] Step 1: The IMS of the KGC of a domain generates an IRL;

[0223] Step 2: One or several accounting nodes of the IMS on the alliance chain, together with the accounting nodes of the KGC IMS in other domains on the alliance chain, that is, all accounting nodes on the alliance chain, use the consensus mechanism to write the IRL into the alliance chain.

[0224] After the ID-PKC system public parameters and IRL are written into the consortium chain, users can query the ID-PKC system public parameters and IRL.

[0225] Based on this, the embodiment of the present application also provides an ID-PKC information processing method, which is applied to the second node, such as Figure 2 As shown, the method includes:

[0226] Step 201: Obtain a first request; the first request is used to request to obtain public parameters of the ID-PKC system;

[0227] Step 202: Query the corresponding ID-PKC system public parameters from the consortium chain;

[0228] Step 203: Return a response based on the query result.

[0229] In actual application, the second node can be a billing node or a common access node.

[0230] In actual application, when the ID-PKC system public parameters are written into the consortium chain, the domain name can be used as the keyword (key); in addition, there are multiple consortium chains in the network. When querying, it is necessary to find the consortium chain where the ID-PKC system public parameters to be queried are located.

[0231] Based on this, in one embodiment, the first request carries the domain name and the blockchain name; accordingly, the second node uses the domain name carried in the first request to query the corresponding ID-PKC system public parameters from the consortium chain corresponding to the blockchain name.

[0232] In actual application, when the ID-PKC system public parameters include the PPS name, and when the ID-PKC system public parameters are written into the alliance chain, the domain name and / or PPS name can be used as the key.

[0233] Based on this, in one embodiment, the first request also carries a PPS name;

[0234] Use the domain name and / or PPS name carried in the first request to query the corresponding ID-PKC system public parameters from the alliance chain corresponding to the blockchain name.

[0235] On the consortium chain, blocks are linked in chronological order, so when querying, you can start from the latest block on the consortium chain.

[0236] When the domain name carried in the first request is not retrieved in the corresponding alliance chain, it means that the corresponding ID-PKC system public parameter is not queried, and the second node returns an error message. At this time, the error message may indicate that the ID-PKC system public parameter to be queried does not exist.

[0237] When the corresponding ID-PKC system public parameter is queried and the status of the queried ID-PKC system public parameter is invalid, an error message is returned. At this time, the error message may indicate that the status of the ID-PKC system public parameter to be queried is invalid.

[0238] When the corresponding ID-PKC system common parameters are found and the status of the found ID-PKC system common parameters is valid, the found ID-PKC system common parameters are returned.

[0239] Exemplarily, the step of querying the public parameters of the ID-PKC system may include:

[0240] Step 1: The user needs to obtain the public parameters of the ID-PKC system and first uses the domainName field and / or the ppsName field to query the consortium blockchain, that is, to initiate the first request. Here, the user initiates the first request through the application programming interface (API);

[0241] Step 2: The search starts from the latest block on the blockchain (i.e., the end of the entire link, search from back to front). If the domainName field and / or ppsName field to be queried is not retrieved on the blockchain, the query is terminated and an error message is returned to the user (i.e., the ID-PKC system parameters do not exist). If they are retrieved on the blockchain, the latest ID-PKC system public parameters obtained (i.e., the corresponding domainSerial is the largest) are checked. If their status is invalid, an error message is returned to the callee (i.e., the ID-PKC system parameters exist but the status is invalid); if the status of the latest ID-PKC system public parameters is valid, the ID-PKC system public parameters that the user wants to obtain are returned.

[0242] The embodiment of the present application also provides an ID-PKC information processing method, which is applied to a third node, such as Figure 3 As shown, the method includes:

[0243] Step 301: Obtain a second request; the second request is used to query whether the first identification has been revoked;

[0244] Step 302: Querying the alliance chain to determine whether the first identifier has been revoked; the alliance chain records the IRL;

[0245] Step 303: Return a response based on the query result.

[0246] In actual application, the third node can be a billing node or a common access node.

[0247] In step 302, the third node queries the IRL to determine whether the first identification has been revoked.

[0248] In actual application, when IRL is written into the consortium chain, the domain name and / or IMS name (when the IRL includes the IMS name) is used as the key; in addition, there are multiple consortium chains in the network. When querying, it is necessary to find the consortium chain where the IRL to be queried is located.

[0249] Based on this, in one embodiment, the second request carries the first identifier and the blockchain name; the third node uses the first identifier to query the consortium chain corresponding to the blockchain name.

[0250] In actual application, the first identifier may be an anonymous identifier, that is, the first identifier is a hidden user identifier. In order to query the anonymous identifier, the query can be performed using the result of a hash algorithm performed on the first identifier.

[0251] Based on this, in one embodiment, the second request carries the result of computing the first identifier using a hash function indicated by a public parameter of the ID-PKC system and the blockchain name;

[0252] The operation result is used to query the alliance chain corresponding to the blockchain name.

[0253] When it is found that the first identification has been revoked, first information is returned; the first information indicates that the first identification has been revoked;

[0254] When the first identifier is not found, second information is returned; the second information indicates that the first identifier is valid.

[0255] Exemplarily, the specific process of identifying the query may include:

[0256] Step 1: The user uses the ID to query the alliance chain. If it is found, it means that the ID has been abolished (i.e., it has been revoked), and a user message is returned to the user (i.e., the user ID has been abolished). If it is not found, then proceed to step 2; here, the user initiates a query request through the API;

[0257] Step 2: The user uses the hash function indicated in the public parameters of the ID-PKC system to operate on the identifier to be queried, obtains the operation result, and uses the operation result to query the alliance chain. If there is a value identical to the operation result, it means that the user identifier has been revoked, and a user message is returned to the user (i.e., the user identifier has been revoked); if no identical value is found, it means that the user identifier is valid, and a user message is returned to the user (i.e., the user identifier is valid). In this way, the validity of the anonymous identifier can also be queried on the alliance chain.

[0258] In actual application, in step 302, when the third node is an ordinary node, the third node can address the corresponding IMS according to the IMS name in the ID-PKC system public parameters (which can be an IMS belonging to the same domain as the third node or an IMS belonging to a different domain from the third node), and then initiate a query request to the corresponding IMS to inquire whether the first identification has been revoked.

[0259] When the third node is the accounting node of the alliance chain corresponding to the blockchain name, it can directly query whether the first identification has been revoked.

[0260] As can be seen from the above description, in the embodiments of this application, the KGC, which includes the PKG, PPS, and IMS, and the user terminal form a consortium chain. After a consensus process, a PPS writes the corresponding ID-PKC system public parameters to the consortium chain. After a consensus process, an IMS writes the IRL within the corresponding domain to the consortium chain. User terminals cannot write data to the consortium chain; they can only read data from it.

[0261] The ID-PKC information processing method provided by the embodiment of the present application comprises the following steps: a first node obtains a first ID-PKC system public parameter and / or IRL; the status of the first ID-PKC system public parameter is valid; the first node is a bookkeeping node; based on a consensus mechanism, the obtained first ID-PKC system public parameter and / or IRL is written into a consortium chain; a second node obtains a first request; the first request is used to request the acquisition of the ID-PKC system public parameter; the corresponding ID-PKC system public parameter is queried from the consortium chain; and a response is returned based on the query result; a third node obtains a second request; the second request is used to request whether the first identity has been revoked; the first identity is queried from the consortium chain; the consortium chain records the IRL; and a response is returned based on the query result. The solution provided by the embodiment of the present application is based on the consortium chain for the publication of the ID-PKC system public parameters and the management of identity revocation. By using the consortium chain, the ID-PKC system parameters and IRL can be transmitted across domains, and identity revocation can be queried across domains, thereby achieving cross-domain secure communication without relying on the PKI system and using the ID-PKC system.

[0262] In order to implement the method of the embodiment of the present application, the embodiment of the present application further provides an ID-PKC information processing device, which is set on the first node, such as Figure 4 As shown, the device includes:

[0263] The first acquisition unit 401 is configured to acquire a first ID-PKC system public parameter and / or an IRL; the first ID-PKC system public parameter is in a valid state; and the first node is a billing node.

[0264] The first processing unit 402 is configured to write the acquired first ID-PKC system public parameters and / or IRL into the alliance chain based on a consensus mechanism.

[0265] In one embodiment, the first acquisition unit 401 is further configured to acquire a second ID-PKC system public parameter; the status of the second ID-PKC system public parameter is invalid; the second ID-PKC system public parameter is identical to the first ID-PKC system public parameter except for the production time and status;

[0266] The first processing unit 402 is further configured to write the acquired second ID-PKC system public parameters into the alliance chain based on a consensus mechanism;

[0267] The first acquiring unit 401 is further configured to acquire a newly generated third ID-PKC system public parameter; the third ID-PKC system public parameter is updated from the first ID-PKC system public parameter; and the status of the third ID-PKC system public parameter is valid;

[0268] The first processing unit 402 is further configured to write the acquired third ID-PKC system public parameters into the alliance chain based on a consensus mechanism.

[0269] In actual application, the first acquisition unit 401 can be implemented by a communication interface in the ID-PKC information processing device; the first processing unit 402 can be implemented by a communication interface in the ID-PKC information processing device in combination with a processor.

[0270] In order to implement the method on the second node side of the embodiment of the present application, the embodiment of the present application also provides an ID-PKC information processing device, which is set on the second node, such as Figure 5 As shown, the device includes:

[0271] The second acquiring unit 501 is configured to acquire a first request, wherein the first request is used to request acquisition of public parameters of the ID-PKC system;

[0272] The second processing unit 502 is used to query the corresponding ID-PKC system public parameters from the alliance chain and return a response based on the query result.

[0273] In one embodiment, when the second processing unit 502 queries the corresponding ID-PKC system public parameters from the alliance chain, the query starts from the latest block of the alliance chain.

[0274] In one embodiment, the first request carries a domain name and a blockchain name;

[0275] The second processing unit 502 is specifically configured to use the domain name carried in the first request to query the corresponding ID-PKC system public parameters from the consortium chain corresponding to the blockchain name.

[0276] In one embodiment, the first request further carries a PPS name;

[0277] Use the domain name and / or PPS name carried in the first request to query the corresponding ID-PKC system public parameters from the alliance chain corresponding to the blockchain name.

[0278] In one embodiment, the second processing unit 502 is specifically configured to:

[0279] When the corresponding ID-PKC system public parameters are not found, an error message is returned;

[0280] or,

[0281] When the corresponding ID-PKC system common parameters are queried and the status of the queried ID-PKC system common parameters is invalid, an error message is returned;

[0282] or,

[0283] When the corresponding ID-PKC system common parameters are found and the status of the found ID-PKC system common parameters is valid, the found ID-PKC system common parameters are returned.

[0284] In actual application, the second acquisition unit 501 can be implemented by a communication interface in the ID-PKC information processing device; the second processing unit 502 can be implemented by a communication interface in the ID-PKC information processing device in combination with a processor.

[0285] In order to implement the method on the third node side of the embodiment of the present application, the embodiment of the present application also provides an ID-PKC information processing device, which is set on the third node, such as Figure 6 As shown, the device includes:

[0286] The third acquiring unit 601 is configured to acquire a second request, wherein the second request is configured to query whether the first identification has been revoked;

[0287] The third processing unit 602 is used to query whether the first identification has been revoked from the alliance chain; the alliance chain records the IRL; and return a response based on the query result.

[0288] In one embodiment, the second request carries the first identifier and the blockchain name; the third processing unit 602 uses the first identifier to query the consortium chain corresponding to the blockchain name.

[0289] In one embodiment, the second request carries a calculation result of calculating the first identifier using a hash function indicated by a public parameter of the ID-PKC system and the blockchain name;

[0290] The third processing unit 602 uses the calculation result to query the alliance chain corresponding to the blockchain name.

[0291] In one embodiment, the third processing unit 602 is specifically configured to:

[0292] When it is found that the first identification has been revoked, first information is returned; the first information indicates that the first identification has been revoked;

[0293] or,

[0294] When the first identifier is not found, second information is returned; the second information indicates that the first identifier is valid.

[0295] In actual application, the third acquisition unit 601 can be implemented by a communication interface in the ID-PKC information processing device; the third processing unit 602 can be implemented by a communication interface in the ID-PKC information processing device in combination with a processor.

[0296] It should be noted that the above-described embodiments of the ID-PKC information processing device, when performing ID-PKC information processing, illustrate the division of the aforementioned program modules only as an example. In actual applications, the aforementioned processing can be assigned to different program modules as needed, i.e., the internal structure of the device can be divided into different program modules to perform all or part of the aforementioned processing. Furthermore, the ID-PKC information processing device and the ID-PKC information processing method embodiments provided in the above-described embodiments are based on the same concept. The specific implementation process is detailed in the method embodiments and will not be further described here.

[0297] Based on the hardware implementation of the above program modules, and in order to implement the method of the control center side of the embodiment of the present application, the embodiment of the present application also provides a first node, such as Figure 7 As shown, the first node 700 includes:

[0298] The first communication interface 701 is capable of exchanging information with other nodes (such as other accounting nodes);

[0299] A first processor 702 is connected to the first communication interface 701 to implement information exchange with other nodes, and is used to execute the methods provided by one or more technical solutions on the first node side when running a computer program;

[0300] A first memory 703 , on which the computer program is stored.

[0301] Specifically, the first communication interface 701 is used to obtain the first ID-PKC system public parameters and / or IRL; the status of the first ID-PKC system public parameters is valid; the first node 700 is a billing node;

[0302] The first processor 702 is configured to write the acquired first ID-PKC system public parameters and / or IRL into the alliance chain based on a consensus mechanism.

[0303] In one embodiment, the first communication interface 701 is further used to obtain a second ID-PKC system public parameter; the status of the second ID-PKC system public parameter is invalid; the second ID-PKC system public parameter is the same as the first ID-PKC system public parameter except for the production time and status;

[0304] The first processor 702 is further configured to write the acquired second ID-PKC system public parameters into the consortium chain based on a consensus mechanism;

[0305] The first communication interface 701 is further used to obtain a newly generated third ID-PKC system public parameter; the third ID-PKC system public parameter is updated by the first ID-PKC system public parameter; the status of the third ID-PKC system public parameter is valid;

[0306] The first processor 702 is further configured to write the acquired third ID-PKC system public parameters into the alliance chain based on a consensus mechanism.

[0307] It should be noted that the specific processing process of the first processor 702 can be understood with reference to the above method.

[0308] Of course, in actual application, the various components in the first node 700 are coupled together through the bus system 704. It is understood that the bus system 704 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 704 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 7 Various buses are labeled as bus system 704 .

[0309] The first memory 703 in the embodiment of the present application is used to store various types of data to support the operation of the first node 700. Examples of such data include: any computer program used to operate on the first node 700.

[0310] The methods disclosed in the above embodiments of the present application can be applied to the first processor 702 or implemented by the first processor 702. The first processor 702 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the first processor 702 or by instructions in the form of software. The above first processor 702 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 702 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium located in the first memory 703. The first processor 702 reads the information in the first memory 703 and completes the steps of the above method in combination with its hardware.

[0311] In an exemplary embodiment, the first node 700 can be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to execute the aforementioned method.

[0312] Based on the hardware implementation of the above program modules, and in order to implement the method of the second node side of the embodiment of the present application, the embodiment of the present application also provides a second node, such as Figure 8 As shown, the second node 800 includes:

[0313] The second communication interface 801 is capable of exchanging information with other nodes and users;

[0314] A second processor 802 is connected to the second communication interface 801 to implement information exchange with other nodes and users, and is used to execute the methods provided by one or more technical solutions on the second node side when running a computer program;

[0315] The second memory 803 , on which the computer program is stored.

[0316] Specifically, the second communication interface 801 is used to obtain a first request; the first request is used to request to obtain ID-PKC system public parameters;

[0317] The second processor 802 is used to query the corresponding ID-PKC system public parameters from the alliance chain; and return a response through the second communication interface according to the query result.

[0318] In one embodiment, when the second processor 802 queries the corresponding ID-PKC system public parameters from the consortium chain, the query starts from the latest block of the consortium chain.

[0319] In one embodiment, the first request carries a domain name and a blockchain name;

[0320] The second processor 802 is specifically configured to use the domain name carried in the first request to query the corresponding ID-PKC system public parameters from the consortium chain corresponding to the blockchain name.

[0321] In one embodiment, the first request further carries a PPS name;

[0322] The second processor 802 is specifically configured to use the domain name and / or PPS name carried in the first request to query the corresponding ID-PKC system public parameters from the consortium chain corresponding to the blockchain name.

[0323] In one embodiment, the second processor 802 is specifically configured to:

[0324] When the corresponding ID-PKC system public parameters are not found, an error message is returned;

[0325] or,

[0326] When the corresponding ID-PKC system common parameters are queried and the status of the queried ID-PKC system common parameters is invalid, an error message is returned;

[0327] or,

[0328] When the corresponding ID-PKC system common parameters are found and the status of the found ID-PKC system common parameters is valid, the found ID-PKC system common parameters are returned.

[0329] It should be noted that the specific processing process of the second processor 802 can be understood with reference to the above method.

[0330] Of course, in actual application, the various components in the second node 800 are coupled together via the bus system 804. It is understood that the bus system 804 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 804 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 8 Various buses are labeled as bus system 804 .

[0331] The second memory 803 in the embodiment of the present application is used to store various types of data to support the operation of the second node 800. Examples of such data include: any computer program used to operate on the second node 800.

[0332] The methods disclosed in the above embodiments of the present application can be applied to or implemented by the second processor 802. The second processor 802 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits or software instructions in the second processor 802. The above second processor 802 may be a general-purpose processor, a DSP, or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The second processor 802 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium located in the second memory 803. The second processor 802 reads the information in the second memory 803 and, in conjunction with its hardware, completes the steps of the above method.

[0333] In an exemplary embodiment, the second node 800 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, Microprocessors, or other electronic components to perform the aforementioned method.

[0334] Based on the hardware implementation of the above program modules, and in order to implement the method of the third node side of the embodiment of the present application, the embodiment of the present application also provides a third node, such as Figure 9 As shown, the third node 900 includes:

[0335] The third communication interface 901 is capable of exchanging information with other nodes and users;

[0336] a third processor 902 connected to the third communication interface 901 to implement information exchange with other nodes and users, and configured to execute the methods provided by one or more technical solutions on the third node side when running a computer program;

[0337] A third memory 903 , on which the computer program is stored.

[0338] Specifically, the third communication interface 901 is used to obtain a second request; the second request is used to request to query whether the first identification has been revoked;

[0339] The third processor 902 is used to query whether the first identification has been revoked from the alliance chain; the alliance chain records the IRL; and return a response through the third communication interface based on the query result.

[0340] In one embodiment, the second request carries the first identifier and the blockchain name, and the third processor 902 uses the first identifier to query the consortium chain corresponding to the blockchain name.

[0341] In one embodiment, the second request carries a calculation result of calculating the first identifier using a hash function indicated by a public parameter of the ID-PKC system and the blockchain name;

[0342] The third processor 902 uses the calculation result to query the alliance chain corresponding to the blockchain name.

[0343] In one embodiment, the third processor 902 is specifically configured to:

[0344] When it is found that the first identification has been revoked, first information is returned; the first information indicates that the first identification has been revoked;

[0345] or,

[0346] When the first identifier is not found, second information is returned; the second information indicates that the first identifier is valid.

[0347] It should be noted that the specific processing process of the third processor 902 can be understood with reference to the above method.

[0348] Of course, in actual application, the various components in the third node 900 are coupled together via the bus system 904. It is understood that the bus system 904 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 904 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 9 Various buses are labeled as bus system 904.

[0349] The third memory 903 in the embodiment of the present application is used to store various types of data to support the operation of the third node 900. Examples of such data include: any computer program used to operate on the third node 900.

[0350] The methods disclosed in the above embodiments of the present application can be applied to or implemented by the third processor 902. The third processor 902 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits or software instructions in the third processor 902. The third processor 902 may be a general-purpose processor, a DSP, or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The third processor 902 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium located in the third memory 903. The third processor 902 reads the information in the third memory 903 and, in conjunction with its hardware, completes the steps of the above method.

[0351] In an exemplary embodiment, the third node 900 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, Microprocessors, or other electronic components to perform the aforementioned method.

[0352] It can be understood that the memory (first memory 703, second memory 803, third memory 903) of the embodiment of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.

[0353] In an exemplary embodiment, the present application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, which includes, for example, a first memory 703 storing a computer program, which can be executed by the first processor 702 of the first node 700 to complete the steps of the first node-side method described above. For another example, it includes a second memory 803 storing a computer program, which can be executed by the second processor 802 of the second node 800 to complete the steps of the second node-side method described above. For another example, it includes a third memory 903 storing a computer program, which can be executed by the third processor 902 of the third node 900 to complete the steps of the third node-side method described above. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.

[0354] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0355] In addition, the technical solutions described in the embodiments of the present application can be arbitrarily combined without conflict.

[0356] The above description is merely a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application.

Claims

1. A method for processing information based on an identification-based public key ID-PKC, characterized in that: Applied to the first node, including: Obtaining a first ID-PKC system public parameter and / or an identity revocation list (IRL); the status of the first ID-PKC system public parameter is valid; and the first node is a bookkeeping node; Based on the consensus mechanism, the acquired first ID-PKC system public parameters and / or IRL are written into the alliance chain; wherein, The method further comprises: Acquire the second ID-PKC system public parameter; the status of the second ID-PKC system public parameter is invalid; the second ID-PKC system public parameter is the same as the first ID-PKC system public parameter except for the production time and status; Based on the consensus mechanism, the acquired second ID-PKC system public parameters are written into the alliance chain; Acquire a newly generated third ID-PKC system public parameter; the third ID-PKC system public parameter is updated by the first ID-PKC system public parameter; the status of the third ID-PKC system public parameter is valid; Based on the consensus mechanism, the acquired third ID-PKC system public parameters are written into the alliance chain; the second ID-PKC system public parameters are used to invalidate the first ID-PKC system public parameters on the alliance chain, and the third ID-PKC system public parameters are used to update the first ID-PKC system public parameters in the alliance chain; wherein, the ID-PKC system public parameters include the system public parameter status, and the system public parameter status is valid or invalid.

2. The method according to claim 1, characterized in that The first ID-PKC system public parameters are generated by a public parameter server of a key generation center KGC; The first ID-PKC system public parameter includes at least one of the following: Domain name; Blockchain name; System public parameter status; The hashing algorithm used to hide the user's identity.

3. The method according to claim 2, characterized in that The domain name is a name defined according to a uniform resource identifier (URI) or a uniform resource locator (URL), or is a user-defined name.

4. The method according to claim 2, characterized in that The first ID-PKC system public parameters also include at least one of the following: Public parameter server name; Identifies the management server name.

5. The method according to claim 4, characterized in that The public parameter server name is a name defined according to a URI or URL, or a custom name.

6. The method according to claim 4, characterized in that The name of the identification management server is a name defined according to a URI or URL, or a user-defined name.

7. The method according to claim 1, characterized in that The IRL is generated by the identity management server of KGC; The IRL includes at least one of the following: Domain name; Blockchain name; A collection of revocation identifiers.

8. The method according to claim 7, characterized in that The domain name is a name defined according to a URI or URL, or a custom name.

9. The method according to claim 7, characterized in that The IRL also includes: Identifies the management server name.

10. The method according to claim 9, characterized in that The name of the identification management server is a name defined according to a URI or URL, or a user-defined name.

11. The method according to claim 7, characterized in that The revocation identification set includes at least one of the following: Whether the revocation identification is anonymous; Revoke identification; Reason for revocation.

12. A method for processing ID-PKC information, characterized in that: Applied to the second node, including: Obtain a first request; the first request is used to request to obtain ID-PKC system public parameters; Query the corresponding ID-PKC system public parameters from the consortium chain; Returns a response based on the query result; The ID-PKC system public parameters recorded in the alliance chain include the system public parameter status, and the system public parameter status is valid or invalid.

13. The method according to claim 12, characterized in that When querying the corresponding ID-PKC system public parameters from the alliance chain, the method includes: Start querying from the latest block of the consortium chain.

14. The method according to claim 12, characterized in that The first request carries a domain name and a blockchain name; Use the domain name carried in the first request to query the corresponding ID-PKC system public parameters from the alliance chain corresponding to the blockchain name.

15. The method according to claim 14, characterized in that The first request also carries a public parameter server name; Use the domain name and / or public parameter server name carried in the first request to query the corresponding ID-PKC system public parameters from the consortium chain corresponding to the blockchain name.

16. The method according to any one of claims 12 to 15, characterized in that The returning of a response according to the query result includes: When the corresponding ID-PKC system public parameters are not found, an error message is returned; or, When the corresponding ID-PKC system common parameters are queried and the status of the queried ID-PKC system common parameters is invalid, an error message is returned; or, When the corresponding ID-PKC system common parameters are found and the status of the found ID-PKC system common parameters is valid, the found ID-PKC system common parameters are returned.

17. An ID-PKC information processing device, characterized in that: Set on the first node, including: A first acquiring unit is configured to acquire a first ID-PKC system public parameter and / or an IRL; the first ID-PKC system public parameter is in a valid state; and the first node is a bookkeeping node; The first processing unit is configured to write the acquired first ID-PKC system public parameters and / or IRL into the alliance chain based on a consensus mechanism; wherein, The first acquisition unit is further used to acquire a second ID-PKC system public parameter; the status of the second ID-PKC system public parameter is invalid; the second ID-PKC system public parameter is the same as the first ID-PKC system public parameter except for the production time and status; The first processing unit is further configured to write the acquired second ID-PKC system public parameters into the alliance chain based on a consensus mechanism; The first acquisition unit is further configured to acquire a newly generated third ID-PKC system public parameter; the third ID-PKC system public parameter is updated from the first ID-PKC system public parameter; and the status of the third ID-PKC system public parameter is valid; The first processing unit is further used to write the acquired third ID-PKC system public parameters into the alliance chain based on a consensus mechanism; the second ID-PKC system public parameters are used to invalidate the first ID-PKC system public parameters on the alliance chain, and the third ID-PKC system public parameters are used to update the first ID-PKC system public parameters in the alliance chain; wherein the ID-PKC system public parameters include a system public parameter status, and the system public parameter status is valid or invalid.

18. An ID-PKC information processing device, characterized in that: include: A second acquiring unit, configured to acquire the first request; The first request is used to request to obtain ID-PKC system public parameters; The second processing unit is used to query the corresponding ID-PKC system public parameters from the alliance chain; return a response according to the query result; wherein, The ID-PKC system public parameters recorded in the alliance chain include the system public parameter status, and the system public parameter status is valid or invalid.

19. A first node, characterized in that: include: A first communication interface and a first processor; wherein, The first communication interface is used to obtain a first ID-PKC system public parameter and / or an IRL; the status of the first ID-PKC system public parameter is valid; and the first node is a billing node; The first processor is configured to write the obtained first ID-PKC system public parameters and / or IRL into the alliance chain based on a consensus mechanism; The first communication interface is further used to obtain a second ID-PKC system public parameter; the status of the second ID-PKC system public parameter is invalid; the second ID-PKC system public parameter is the same as the first ID-PKC system public parameter except for the production time and status; The first processor is further configured to write the acquired second ID-PKC system public parameters into the alliance chain based on a consensus mechanism; The first communication interface is further used to obtain a newly generated third ID-PKC system public parameter; the third ID-PKC system public parameter is updated by the first ID-PKC system public parameter; the status of the third ID-PKC system public parameter is valid; The first processor is further used to write the acquired third ID-PKC system public parameters into the alliance chain based on a consensus mechanism; the second ID-PKC system public parameters are used to invalidate the first ID-PKC system public parameters on the alliance chain, and the third ID-PKC system public parameters are used to update the first ID-PKC system public parameters in the alliance chain; wherein the ID-PKC system public parameters include a system public parameter status, and the system public parameter status is valid or invalid.

20. A second node, characterized in that: include: A second communication interface and a second processor; wherein, The second communication interface is used to obtain a first request; the first request is used to request to obtain public parameters of the ID-PKC system; The second processor is used to query the corresponding ID-PKC system public parameters from the alliance chain; return a response through the second communication interface according to the query result; wherein, The ID-PKC system public parameters recorded in the alliance chain include the system public parameter status, and the system public parameter status is valid or invalid.

21. A first node, characterized in that: include: a first processor and a first memory for storing a computer program capable of being executed on the processor, Wherein, when the first processor is used to run the computer program, it executes the steps of the method according to any one of claims 1 to 11.

22. A second node, characterized in that: include: a second processor and a second memory for storing a computer program capable of being executed on the processor, Wherein, when the second processor is used to run the computer program, it executes the steps of the method according to any one of claims 12 to 16.

23. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the computer program implements the steps of the method according to any one of claims 1 to 11, or the steps of the method according to any one of claims 12 to 16.

Citation Information

Patent Citations

  • Double-agent cross-domain authentication method based on identification password and alliance chain

    CN110138560A