A blockchain-based cross-domain identity authentication method, system and device
By generating and verifying identity parameters and digital certificates through blockchain technology, the problem of cross-domain mutual recognition of unmanned equipment is solved, and cross-domain identity authentication and data sharing are realized.
Patent Information
- Application Number
- CN202210985171.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-17
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2042-08-17
AI Technical Summary
In existing technologies, it is difficult to achieve efficient cross-domain mutual recognition between terminal devices such as unmanned devices, resulting in low efficiency in data sharing and interaction.
Through a blockchain-based cross-domain identity authentication method, edge servers and blockchain networks are used to generate identity parameters, issue and verify digital certificates, and achieve cross-domain identity authentication.
Ensure that identity information is authentic and reliable, achieve mutual recognition and trust among terminal devices across domains, activate data potential, enhance data value, and is suitable for cross-domain data sharing of unmanned devices.
Smart Images

Figure CN115378681B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a cross-domain identity authentication method and system based on a blockchain and a device. BACKGROUND
[0002] With the rapid development of the digital economy, more and more industries are beginning to transform digitally and intelligently. Blockchain, artificial intelligence, and the Internet of Things are widely used in city planning, city governance, and industry supervision. More and more unmanned devices such as unmanned aerial vehicles, unmanned ships, unmanned vehicles, automatic monitoring devices, unmanned inspection devices, and unmanned devices are widely used. The use of unmanned devices improves the overall efficiency of modern governance. SUMMARY
[0003] The present application relates to a cross-domain identity authentication method and system based on a blockchain and a device.
[0004] In a first aspect, the present application provides a cross-domain identity authentication method based on a blockchain, comprising:
[0005] The first terminal device sends an access request to the second terminal device to the first edge server;
[0006] The first edge server obtains the first identity authentication information of the first terminal device according to the request and sends it to the second edge server;
[0007] The second edge server obtains the second identity authentication information of the first terminal device from the blockchain network based on the first identity authentication information, and judges whether the identity is authenticated according to the first identity authentication information and the second identity authentication information;
[0008] If yes, send the identity confirmation information to the second terminal device.
[0009] In one or some embodiments, the second identity authentication information of the first terminal device obtained from the blockchain network is added to the blockchain network in the following way:
[0010] The edge server generates an identity parameter in response to the registration request of the terminal device, sends a digital certificate issuance request to the certificate authority server, receives the digital certificate returned by the certificate authority server, generates identity authentication information from the identity parameter and the digital certificate, and sends it to the blockchain network. The blockchain network generates a block from the identity authentication information and adds the block to the blockchain.
[0011] In a second aspect, an embodiment of the present application provides a blockchain-based edge distributed identity authentication system, comprising:
[0012] The edge server is configured to generate an identity parameter in response to a registration request from a terminal device, send a digital certificate issuance request to a certificate authority server, send a returned digital certificate to the terminal device, and send identity authentication information comprising the identity parameter and the digital certificate to a blockchain network.
[0013] The certificate authority server is configured to generate a corresponding digital certificate based on the identity parameter and send the digital certificate to the edge server.
[0014] The blockchain network is configured to generate a block based on the identity authentication information and add the block to a blockchain.
[0015] In one or some embodiments, the blockchain-based edge distributed identity authentication system further comprises a public maintenance database.
[0016] The public maintenance database is configured to receive the identity parameter sent by the edge server and the digital certificate sent by the certificate authority server, and update database data based on the identity parameter and the digital certificate.
[0017] In a third aspect, an embodiment of the present application provides a blockchain-based cross-domain identity authentication method, applied to a terminal device, comprising:
[0018] Sending an access request.
[0019] Obtaining first identity authentication information according to a received first identity authentication information request.
[0020] And,
[0021] According to the received identity confirmation information, interacting with a corresponding another terminal device.
[0022] In a fourth aspect, an embodiment of the present application provides a blockchain-based cross-domain identity authentication method, applied to an edge server, comprising:
[0023] Obtaining first identity authentication information of a first terminal device according to a received request for accessing the first terminal device, and sending the first identity authentication information to another edge server.
[0024] And,
[0025] Receiving first identity authentication information of a second terminal device sent by another edge server, obtaining second identity authentication information of the second terminal device from a blockchain network based on the first identity authentication information, and judging whether the identity is authenticated based on the first identity authentication information and the second identity authentication information.
[0026] If yes, identity confirmation information is sent to the first terminal device.
[0027] In a fifth aspect, an embodiment of the present application provides a cross-domain identity authentication method based on a blockchain, applied to a blockchain network, comprising:
[0028] According to the received request for obtaining second identity authentication information sent by the edge server, the second identity authentication information is obtained and returned to the edge server.
[0029] In a sixth aspect, an embodiment of the present application provides a cross-domain identity authentication system based on a blockchain, comprising:
[0030] The first terminal device is configured to send an access request, send first identity authentication information to the first edge server according to a received request for obtaining first identity authentication information, and interact with a corresponding second terminal device according to received identity confirmation information.
[0031] The first edge server is configured to obtain first identity authentication information of the first terminal device according to a received request of the first terminal device for access, and send the first identity authentication information to the second edge server.
[0032] The second edge server is configured to receive first identity authentication information of the first terminal device sent by the first edge server, obtain second identity authentication information of the first terminal device from the blockchain network based on the first identity authentication information, judge whether the identity is authenticated according to the first identity authentication information and the second identity authentication information, and send identity confirmation information to the second terminal device.
[0033] The blockchain network is configured to obtain second identity authentication information according to a received request for obtaining second identity authentication information sent by the second edge server, and return the second identity authentication information to the second edge server.
[0034] The second terminal device is configured to interact with a corresponding first terminal device according to received identity confirmation information.
[0035] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the cross-domain identity authentication method based on a blockchain applied to a terminal device, or the cross-domain identity authentication method based on a blockchain applied to an edge server, or the cross-domain identity authentication method based on a blockchain applied to a blockchain network.
[0036] In an eighth aspect, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the blockchain-based cross-domain identity authentication method applied to a terminal device, the blockchain-based cross-domain identity authentication method applied to an edge server, or the blockchain-based cross-domain identity authentication method applied to a blockchain network when executing the program.
[0037] Based on the above technical solutions, the present application has the following beneficial effects compared with the prior art:
[0038] The blockchain-based cross-domain identity authentication method provided by the embodiments of the present application realizes cross-domain communication interaction of terminal devices in different domains through the first edge server and the second edge server, and when mutual authentication is required between terminal devices in different domains, the second identity authentication information is obtained from the blockchain network, and the second identity authentication information is compared and verified with the first identity authentication information possessed by the terminal device, so as to realize cross-domain identity authentication and mutual trust of the terminal device, ensure the authenticity and credibility of the identity information, and further realize sharing and interaction of cross-domain terminal device data after the terminal device completes cross-domain identity mutual authentication and mutual trust, so as to activate data potential and improve data value.
[0039] The blockchain-based edge distributed identity authentication system provided by the embodiments of the present application can realize unified identity authentication of the terminal device by the edge server responding to the registration request of the terminal device, generating identity parameters, and sending a digital certificate issuing request to the certificate authority server; the certificate authority server generates corresponding digital certificates according to the identity parameters, and sends the digital certificates to the edge server; and the edge server sends the identity parameters and the digital certificates to the terminal device. The identity parameter information of the terminal device is packaged into a block through the blockchain network, and then consensus is made on the chain and the block information is propagated on the blockchain, so as to ensure the safety and credibility of the data on the chain through the decentralization and consensus mechanism of the blockchain, and realize safe storage and management of the identity parameters and the digital certificates of the terminal device.
[0040] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be achieved and obtained by the structure particularly pointed out in the written description, claims, and drawings.
[0041] The technical solutions of the present application will be further described in detail below with the help of drawings and embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0042] The accompanying drawings are included to provide a further understanding of the present application, and are incorporated in and constitute a part of this specification, illustrate embodiments of the present application and are used to explain the present application, but are not intended to limit the present application. In the drawings:
[0043] Figure 1 Flowchart of the cross-domain identity authentication method based on a blockchain provided for an embodiment of the present application Figure 1 ;
[0044] Figure 2 Flowchart of the cross-domain identity authentication method based on a blockchain provided for an embodiment of the present application Figure 2 ;
[0045] Figure 3 Flowchart of adding the second identity authentication information into the blockchain network provided for an embodiment of the present application
[0046] Figure 4 Structural diagram of the edge distributed identity authentication system based on a blockchain provided for an embodiment of the present application
[0047] Figure 5 Flowchart of the cross-domain identity authentication method based on a blockchain applied to a terminal device provided for an embodiment of the present application
[0048] Figure 6 Flowchart of the cross-domain identity authentication method based on a blockchain applied to an edge server provided for an embodiment of the present application
[0049] Figure 7 Structural diagram of the cross-domain identity authentication system based on a blockchain provided for an embodiment of the present application
[0050] Figure 8 Cross-domain identity authentication architecture diagram provided for an embodiment of the present application
[0051] Figure 9 Structural diagram of an electronic device provided for an embodiment of the present application DETAILED DESCRIPTION
[0052] Exemplary embodiments of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings. While example embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the present disclosure to those skilled in the art.
[0053] Blockchain is a technology system that is jointly maintained by multiple parties, uses cryptographic algorithms to ensure transmission and access security, uses consensus algorithms, distributed storage, P2P, smart contracts and other technologies to achieve consistent storage of data, tamper-proofing and non-repudiation, and its essence is a decentralized evidence database, which is a distributed shared ledger technology (DLT).
[0054] Blockchain technology can be divided into public chain, alliance chain and private chain. The alliance chain is widely concerned due to its safety controllability and wide business scenarios. The alliance chain has a distributed identity authentication and node access mechanism, which can effectively protect the privacy of each party while confirming the identity of each party. The channel / group isolation technology can effectively isolate the data of different businesses to achieve business splitting and fine management. Based on the distributed storage technology, all the data on the chain in the blockchain has multiple copies, and each node stores a complete copy of the blockchain data, which solves the problem of single machine failure causing the entire blockchain network to malfunction or data loss due to hard disk failure, and enables more efficient and convenient business collaboration and data sharing among parties. The on-chain data is based on a cryptographic digital signature to ensure the integrity of the on-chain data (no tampering during the transaction process) and prevent transaction disputes (the signer cannot deny that the information was sent by himself). Based on the consensus algorithm of multiple parties, the single-sided malpractice is prevented, and the historical data on the chain is modified. When the blockchain technology performs accounting, multiple parties need to reach a consensus, and only the blocks that have reached a consensus will be accounted for. Regardless of which consensus algorithm is used, the malpractice of a single party or a small number of nodes cannot affect the data of the entire network, increasing the trust between the parties. The data structure of the blockchain is a chain structure, and each block header has the Merkle root hash of all transactions contained in the block and the hash value of the previous block. Once the data of a certain block is tampered with, the blockchain is destroyed, and other parties can easily detect that the data has been tampered with. The “blockchain+” modern governance architecture based on the alliance chain technology creates a new mode of establishing mutual trust and cooperation among multiple parties, which can achieve penetrating supervision and trust co-construction and transmission in many scenarios, and effectively protect data security, promote data sharing, activate data value, and promote the marketization of “data elements”.
[0055] Since the digital certificates of terminal devices in different domains are issued by different certificate systems, they cannot interact. Based on this, the embodiment of the present application provides a cross-domain identity authentication method based on a blockchain, as shown in Figure 1 , which comprises:
[0056] S101, the first terminal device sends an access request for the second terminal device to the first edge server;
[0057] S102, the first edge server acquires first identity authentication information of the first terminal device according to the request, and sends the first identity authentication information to the second edge server;
[0058] S103, the second edge server acquires second identity authentication information of the first terminal device from the blockchain network based on the first identity authentication information, judges whether the identity is authenticated according to the first identity authentication information and the second identity authentication information; if yes, step S104 is executed; if no, identity authentication failure information is sent to the second terminal device;
[0059] S104, identity confirmation information is sent to the second terminal device.
[0060] As a specific embodiment, the second edge server verifies the identity of the first terminal device by comparing the second digital certificate hash value acquired from the blockchain network with the first digital certificate hash value sent by the first edge server; the interaction between terminal devices in different domains is carried out through edge servers (ES), and the edge server stores the hash value and state information of the digital certificate on the blockchain. The hash value of the digital certificate owned by the terminal device is compared with the hash value of the digital certificate on the blockchain to realize cross-domain identity authentication of the terminal device, as shown in Figure 2 and Figure 7 The specific process is as follows:
[0061] S501, the first edge server ES1 corresponding to the first terminal device D1 sends an access request to the second edge server ES2 corresponding to the second terminal device D2;
[0062] S502, after the second edge server ES2 receives the access request sent by the first terminal device D1, the identity parameter and the first digital certificate hash value of the first terminal device D1 are acquired.
[0063] In the above step S502, after the second edge server ES2 receives the access request sent by the first terminal device D1, the second edge server ES2 sends a request for acquiring the identity parameter and the digital certificate to the first edge server ES1, the first edge server ES1 acquires the identity parameter and the digital certificate of the first terminal device D1, encrypts the content of the digital certificate to obtain the first digital certificate hash value, and sends the identity parameter and the first digital certificate hash value to the second edge server ES2; wherein the digital certificate of the first terminal device D1 is issued by the first certificate authority server CAS1, and the identity parameter and the digital certificate of the first terminal device D1 are also stored in the first public maintenance database PMD1; the digital certificate of the second terminal device D2 is issued by the second certificate authority server CAS2, and the identity parameter and the digital certificate of the second terminal device D2 are also stored in the second public maintenance database PMD2;
[0064] S503, the second terminal device D2 sends a request for obtaining a second digital certificate hash value to the blockchain network based on the identity parameter;
[0065] S504, the blockchain network receives the request for obtaining the second digital certificate hash value sent by the second edge server ES2, and obtains the second digital certificate hash value of the first terminal device D1 based on the identity parameter;
[0066] S505, the blockchain network sends the second digital certificate hash value of the first terminal device D1 to the second edge server ES2;
[0067] S506, the second edge server ES2 judges whether the second digital certificate hash value is consistent with the first digital certificate hash value; if yes, step S207 is executed; if not, identity authentication failure information is sent to the second terminal device;
[0068] S507, the second edge server ES2 sends identity confirmation information to the second terminal device D2.
[0069] In one embodiment, the second edge server ES2 obtains the identity parameter and the first digital certificate hash value of the first terminal device D1 in step S502, specifically comprising:
[0070] S601, the second edge server ES2 sends a request for obtaining identity authentication information to the first edge server ES1 in the first area;
[0071] S602, the first edge server ES1 obtains the identity parameter and the first digital certificate hash value of the first unmanned device D1, and sends them to the second edge server ES2 in the second area.
[0072] In the embodiment of the application, after the identity authentication of the first terminal device D1 by the second terminal device D2, cross-domain communication can be performed, and a key negotiation process in PKI (Public Key Infrastructure, public key infrastructure) can be performed. The optimized PKI mechanism provided in the embodiment of the application reduces the signature and verification process of the digital certificate compared with the existing PKI mechanism, and can improve the efficiency of cross-domain identity authentication.
[0073] The cross-domain identity authentication method based on the blockchain provided by the embodiment of the present application realizes cross-domain communication interaction of terminal devices in different domains through an edge server, and when cross-visit authentication is needed between terminal devices in different domains, second identity authentication information such as a second digital certificate hash value is obtained from a blockchain network, the second digital certificate hash value is compared with first identity authentication information such as a first digital certificate hash value possessed by the terminal device, identity authentication of terminal devices in different domains is performed through blockchain technology, cross-domain identity authentication and mutual trust of terminal devices in different domains are realized, identity information is ensured to be real and credible, and after cross-domain identity mutual authentication and mutual trust of terminal devices are completed, cross-domain terminal device data such as data collected by unmanned equipment can be further shared and interacted, so that data potential is activated and data value is improved. Moreover, the cross-domain identity authentication method can be widely applied to ecological link monitoring, emergency supervision, traffic management, meteorological supervision and other fields, and is suitable for cross-domain identity authentication of unmanned equipment such as unmanned aerial vehicles, unmanned vehicles, unmanned ships and other Internet of Things equipment.
[0074] In one embodiment, the second identity authentication information of the first terminal device obtained from the blockchain network is added to the blockchain network in the following manner, as shown in the following table: Figure 3
[0075] S201, the edge server generates an identity parameter in response to a registration request of a terminal device, sends a digital certificate issuing request to a certificate authority server, and receives a digital certificate returned by the certificate authority server;
[0076] S202, identity authentication information is generated by sending the identity parameter and the digital certificate to the blockchain network, the identity authentication information is generated into a block by the blockchain network, and the block is added to the blockchain.
[0077] In the embodiment of the present application, the edge server generates a distributed ID for the terminal device in the step S201, and the specific process of generating the identity parameter by the edge server is as follows: receiving a registration request sent by the terminal device, generating a unique distributed ID for the terminal device according to terminal device parameters contained in the request, including device number, device ownership, production date, device model and other parameters.
[0078] The specific process of generating the digital certificate by the certificate authority server in step S201 is as follows: after receiving the request for issuing the digital certificate sent by the edge server, the certificate authority server produces a public and private key for the terminal device, and packs the public key and the terminal device parameters to produce the digital certificate. The digital certificate includes certificate content, an encryption algorithm and encrypted ciphertext. The encryption algorithm includes a first encryption algorithm (such as SHA1 hash algorithm) and a second encryption algorithm (such as RSA encryption algorithm). The encrypted ciphertext is obtained by calculating the first digital certificate hash value of the certificate content by the first encryption algorithm, and then encrypting the first digital certificate hash value by the second encryption algorithm using the private key.
[0079] The identity authentication method provided by the embodiment of the application is mainly based on a public key infrastructure (PKI), and two semi-authoritative agencies, an edge server (ES) and a certificate authority server (CAS), are arranged to realize power decentralization, thereby restricting each other, and a public maintenance database (PMD) is combined to make the operation open, transparent and traceable, and prevent abuse of power. The identity parameters and the digital certificate and other information uploaded to the block chain in the ES are used as the reliability proof of the access of the devices in the region through pre-signature, and the trusted access of the terminal device in the block chain network is further ensured. The identity parameters and the digital certificate of the terminal device are stored in security through the block chain technology, and the unified identity authentication and management of a large number of terminal devices are solved.
[0080] At present, terminal devices such as unmanned devices are various and large in quantity, and it is difficult to achieve unified identity authentication management. Based on this, the embodiment of the application provides an edge distributed identity authentication system based on a block chain, as shown in Figure 4 , which comprises:
[0081] An edge server (Edge Severs, ES) is configured to respond to a registration request of a terminal device, generate identity parameters, and send a request for issuing a digital certificate to a certificate authority server; send the returned digital certificate to the terminal device; and send identity authentication information generated by the identity parameters and the digital certificate to a block chain network.
[0082] A certificate authority server (Certificate Authority Severs, CAS) is configured to generate a corresponding digital certificate according to the identity parameters, and send the digital certificate to the edge server.
[0083] A block chain network is configured to generate a block by the identity authentication information, and add the block to the block chain.
[0084] In the embodiment of the present application, the digital certificate issued by the certificate authority server provides a way to verify the identity information of the terminal device, and the digital certificate is used to verify the identity of the terminal device in other domains during the interaction between the terminal device and the terminal device in other domains. The terminal device described in the embodiment of the present application can be an unmanned device such as a drone, an unmanned ship, an unmanned vehicle, an automatic monitoring device, an unmanned inspection device, and an unmanned guard device, or other devices that need to be authenticated, which can realize unified identity authentication and management in the domain through the edge distributed identity authentication system based on the blockchain provided by the embodiment.
[0085] The edge distributed identity authentication system based on the blockchain provided by the embodiment of the present application can generate identity parameters in response to the registration request of the terminal device through the edge server, and send a request for issuing a digital certificate to the certificate authority server; the certificate authority server generates a corresponding digital certificate according to the identity parameters, and sends the digital certificate to the edge server; the edge server sends the digital certificate to the terminal device, so that the unified identity authentication of the terminal device can be realized; the identity parameters and the digital certificate of the terminal device are packaged into a block by the blockchain network, and then consensus is chained, and the block information is propagated on the blockchain, so that the security and reliability of the data on the chain are ensured by the decentralization and consensus mechanism of the blockchain, and the security storage and management of the identity parameters and the digital certificate of the terminal device are realized. The identity parameters and the digital certificate and other information uploaded to the blockchain network in the edge server are used as the reliability proof of the access of the devices in the region through pre-signing, so that the reliable access of the terminal device to the blockchain network is further ensured.
[0086] In one embodiment, the edge distributed identity authentication system based on the blockchain further includes a public maintenance database (PMD) as shown in Figure 4
[0087] The public maintenance database is used to receive the identity parameters sent by the edge server and the digital certificate sent by the certificate authority server, and update the database data based on the identity parameters and the digital certificate.
[0088] In the embodiment of the present application, the edge server uploads the generated identity parameters to the public maintenance database, and the certificate authority server uploads the digital certificate to the public maintenance database, and the public maintenance database is maintained by the edge server and the certificate authority server, so that the power is dispersed, and only the double verification of the edge server and the certificate authority server can modify the public maintenance database, so that the tampering of the digital certificate and the identity parameters caused by malicious attacks is avoided.
[0089] Based on the same inventive concept, the embodiment of the present application provides a cross-domain identity authentication method based on a blockchain, which is applied to a terminal device, as shown in the accompanying drawings, and comprises the following steps: Figure 5
[0090] S301, sending an access request;
[0091] In the above step S301, since the interaction between terminal devices in different domains is carried out through an edge server, the terminal device sends an access request by sending an access request to another terminal device to the edge server corresponding to the terminal device, and the edge server sends the access request to the edge server corresponding to another terminal device;
[0092] S302, obtaining first identity authentication information according to the received first identity authentication information request;
[0093] and
[0094] S303, interacting with the corresponding another terminal device according to the received identity confirmation information.
[0095] The embodiment of the present application provides a cross-domain identity authentication method based on a blockchain, which is applied to an edge server, as shown in the accompanying drawings, and comprises the following steps: Figure 6
[0096] S401, obtaining first identity authentication information of a first terminal device according to a request received by the first terminal device, and sending the first identity authentication information to another edge server;
[0097] In the above step S401, taking obtaining the first digital certificate hash value of the first terminal device as an example, the edge server calculates the first digital certificate hash value (i.e. the first digital certificate hash value in step S201) of the certificate content of the digital certificate as described in step S201 through a first encryption algorithm, and sends the first digital certificate hash value to another edge server;
[0098] and
[0099] S402, receiving the first identity authentication information of a second terminal device sent by another edge server, obtaining second identity authentication information of the second terminal device from a blockchain network based on the first identity authentication information, and judging whether the identity is authenticated through the first identity authentication information and the second identity authentication information; if yes, executing step S403; if no, identity authentication fails, and sending identity authentication failure information to the first terminal device;
[0100] S403, sending identity confirmation information to the first terminal device.
[0101] The embodiment of the present application provides a cross-domain identity authentication method based on a blockchain, applied to a blockchain network, and comprising the following steps:
[0102] S701, acquiring second identity authentication information according to the received request for acquiring the second identity authentication information sent by the edge server and returning the second identity authentication information to the edge server.
[0103] As a specific embodiment, the second identity authentication information is a second digital certificate hash value, and in the step S701, the blockchain network acquires the second digital certificate hash value according to the received request for acquiring the second digital certificate hash value sent by the edge server and returns the second digital certificate hash value to the edge server. The process of generating the second digital certificate hash value by the blockchain network is as follows: after receiving the request for acquiring the digital certificate of the terminal device sent by the edge server, the blockchain network decrypts the encrypted ciphertext in the digital certificate in the step S201 to obtain the second digital certificate hash value through the public key in the digital certificate.
[0104] Based on the same inventive concept, the embodiment of the present application also provides a cross-domain identity authentication system based on a blockchain, as shown in the accompanying drawings, comprising a first terminal device, a second terminal device, a first edge server, a second edge server and a blockchain network; the first terminal device is located in a first region, and the second terminal device is located in a second region; Figure 8
[0105] The first terminal device is configured to send an access request, send first identity authentication information to the first edge server ES1 according to a received request for acquiring the first identity authentication information, and interact with the corresponding second terminal device according to received identity confirmation information.
[0106] The first edge server ES1 is configured to acquire first identity authentication information of the first terminal device according to a received request for accessing the first terminal device and send the first identity authentication information to the second edge server ES2.
[0107] The second edge server ES2 is configured to receive the first identity authentication information of the first terminal device sent by the first edge server ES1, acquire second identity authentication information of the first terminal device from the blockchain network based on the first identity authentication information, judge whether the identity is authenticated according to the first identity authentication information and the second identity authentication information, and send identity confirmation information to the second terminal device.
[0108] The blockchain network is configured to acquire second identity authentication information according to a received request for acquiring the second identity authentication information sent by the second edge server ES2 and return the second identity authentication information to the second edge server ES2.
[0109] The second terminal device is configured to interact with the corresponding first terminal device according to received identity confirmation information.
[0110] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the blockchain-based cross-domain identity authentication method applied to a terminal device, the blockchain-based cross-domain identity authentication method applied to an edge server, or the blockchain-based cross-domain identity authentication method applied to a blockchain network.
[0111] The embodiment of the present application also provides an electronic device 800, as shown in the figure, comprising a memory 82, a processor 81, and a computer program stored in the memory 82 and capable of running on the processor 81, and the processor 81 executes the program to implement the blockchain-based cross-domain identity authentication method applied to a terminal device, the blockchain-based cross-domain identity authentication method applied to an edge server, or the blockchain-based cross-domain identity authentication method applied to a blockchain network. Figure 9
[0112] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt a computer program product in the form of being implemented on one or more computer usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer usable program codes.
[0113] The present application is described with reference to flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks Figure 1 The functions specified in one or more flows and / or blocks
[0114] These computer program instructions can also be stored in a computer readable storage medium capable of guiding a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer readable storage medium produce a product including instruction means, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks Figure 1 The functions specified in one or more flows and / or blocks
[0115] These computer program instructions can also be loaded into computer or other programmable data processing devices, so that a series of operation steps are performed on the computer or other programmable data processing devices to generate computer-implemented processes, thus the instructions executed on the computer or other programmable data processing devices provide a process for implementing the functions specified in the flowchart Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0116] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.
Claims
1.A blockchain-based cross-domain identity authentication method, characterized in that, Comprising: The first terminal device sends an access request to the second terminal device to the first edge server; The first edge server obtains the identity parameter and the digital certificate of the first terminal device according to the request, generates a first digital certificate hash value of the digital certificate through a preset first encryption algorithm, synthesizes the identity parameter and the first digital certificate hash value into first identity authentication information, and sends it to the second edge server; wherein the identity parameter of the first terminal device is generated by the first edge server according to the registration request of the first terminal device and uploaded to the first public maintenance database; the digital certificate of the first terminal device is issued by the first certificate authority server according to the request of the first edge server and uploaded to the first public maintenance database; The second edge server sends a request to obtain a second digital certificate hash value to the blockchain network based on the identity parameter in the first identity authentication information; The blockchain network obtains the second identity authentication information of the first terminal device based on the identity parameter in the first identity authentication information according to the request; the second identity authentication information includes identity parameter and digital certificate; the digital certificate includes public key and encrypted ciphertext; the encrypted ciphertext is obtained through a preset second encryption algorithm; the second identity authentication information is generated by the first edge server according to the identity parameter and the digital certificate and uploaded to the blockchain network; The blockchain network decrypts the encrypted ciphertext according to the public key to obtain the second digital certificate hash value and sends it to the second edge server; The second edge server judges whether the identity is authenticated according to the first digital certificate hash value in the first identity authentication information and the second digital certificate hash value; If yes, send identity confirmation information to the second terminal device. 2.The blockchain-based cross-domain identity authentication method of claim 1, characterized in that, The second identity authentication information of the first terminal device obtained from the blockchain network is added to the blockchain network in the following way: The edge server generates an identity parameter in response to the registration request of the terminal device, and sends a request for issuing a digital certificate to the certificate authority server; The certificate authority server generates a public key and a private key according to the identity parameter after receiving the request, and merges the public key and the identity parameter into certificate content based on the public key and the identity parameter, generates a first digital certificate hash value of the certificate content through a preset first encryption algorithm, and encrypts the first digital certificate hash value through the private key using a preset second encryption algorithm to obtain an encrypted ciphertext, merges the certificate content, public key, identity parameter, first encryption algorithm, second encryption algorithm and encrypted ciphertext into a digital certificate, and sends the digital certificate to the edge server; The edge server receives the digital certificate returned by the certificate authority server, generates identity authentication information of the identity parameter and the digital certificate, and sends it to the blockchain network, and the blockchain network generates a block of the identity authentication information and adds the block to the blockchain. 3.A blockchain-based cross-domain identity authentication system, characterized in that, Comprising: The first terminal device, for sending an access request; According to the received request for obtaining the first identity authentication information, the identity parameter and the first digital certificate hash value are obtained; and interacting with the corresponding second terminal device according to the received identity confirmation information; The first edge server is configured to generate a digital certificate, obtain identity parameters of the first terminal device and the digital certificate according to a received request for accessing the first terminal device, generate a first digital certificate hash value of the digital certificate through a preset first encryption algorithm, synthesize the identity parameters and the first digital certificate hash value into first identity authentication information, and send the first identity authentication information to the second edge server; The second edge server is configured to receive the identity parameters in the first identity authentication information of the first terminal device sent by the first edge server, send a request for obtaining a second digital certificate hash value to a blockchain network, and receive the second digital certificate hash value sent by the blockchain network. The second edge server is configured to receive the identity parameters in the first identity authentication information of the first terminal device sent by the first edge server, send a request for obtaining a second digital certificate hash value to a blockchain network, and receive the second digital certificate hash value sent by the blockchain network. The second edge server is configured to receive the identity parameters in the first identity authentication information of the first terminal device sent by the first edge server, send a request for obtaining a second digital certificate hash value to a blockchain network, and receive the second digital certificate hash value sent by the blockchain network. The second edge server is configured to receive the identity parameters in the first identity authentication information of the first terminal device sent by the first edge server, send a request for obtaining a second digital certificate hash value to a blockchain network, and receive the second digital certificate hash value sent by the blockchain network. The second edge server is configured to receive the identity parameters in the first identity authentication information of the first terminal device sent by the first edge server, send a request for obtaining a second digital certificate hash value to a blockchain network, and receive the second digital certificate hash value sent by the blockchain network. The second terminal device is configured to interact with the corresponding first terminal device according to the received identity confirmation information. The certificate authority server is configured to issue the digital certificate according to a request of the first edge server. The public maintenance database is configured to receive the identity parameters sent by the edge server and the digital certificate sent by the certificate authority server, and update database data based on the identity parameters and the digital certificate.
Citation Information
Patent Citations
Cross-domain access system, method and device
CN112995097A
Identity authentication method and device based on block chain, and storage medium
CN114710317A
Identity authentication method, system and device based on trusted storage in distributed environment and storage medium
CN114844700A