League member authentication method, system, device, apparatus and storage medium
By introducing a dual verification mechanism of consortium verification and audit nodes into the consortium blockchain, combined with node re-election and random algorithm to update committee nodes, the problem of low accuracy under centralized management is solved, and the stability and accuracy of the consortium blockchain are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2022-09-22
- Publication Date
- 2026-07-31
AI Technical Summary
The centralized management approach used in existing consortium blockchains leads to significant errors in core nodes, which are difficult to detect and correct, resulting in low accuracy.
The verification information is sent from the alliance verification node to the alliance review node, and then sent to the alliance committee node after the alliance review node verifies it. This avoids the problem of low accuracy caused by the alliance committee node verifying it alone, and updates the alliance committee node through node re-election and random algorithm when necessary.
It improves the accuracy of node verification in consortium blockchains, avoids the spread of errors under centralized management, and ensures the stability and reliability of consortium blockchains.
Smart Images

Figure CN115694794B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of cybersecurity, and in particular to a method, system, apparatus, device, and storage medium for authenticating alliance members. Background Technology
[0002] As the information society deepens, the volume of business is gradually increasing. In order to process this large amount of business, multi-platform collaborative services have emerged.
[0003] To achieve multi-platform collaborative services, trust needs to be established between multiple platforms. Consortium blockchains are a commonly used solution for establishing consortium trust in untrusted networks. However, consortium blockchains still employ centralized management of nodes. This centralized management approach allows the central node to have excessive influence on the final result, thereby increasing the risk of errors. Summary of the Invention
[0004] This disclosure provides a method, system, device, equipment, and storage medium for authenticating consortium members, which at least to some extent overcomes the problem that centralized management in consortium blockchains increases the risk of errors.
[0005] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part by practice of this disclosure.
[0006] According to one aspect of this disclosure, a method for authenticating alliance members is provided, applied to an alliance verification node, the method comprising:
[0007] Receive verification information from the consortium's transceiver nodes for nodes awaiting verification;
[0008] The verification information is sent to the alliance review node so that the alliance review node can verify the verification information, and if the verification is successful, the verification success information is sent to the alliance review node.
[0009] The verification pass information is sent to the alliance committee node so that the alliance committee node can authorize the node to be verified;
[0010] Upon receiving an authorization message from a member node of the alliance, configuration information is sent to the alliance transceiver node, so that the transceiver node sends the configuration information to the node to be verified, and the node to be verified connects to the alliance according to the configuration information.
[0011] In one embodiment of this disclosure, the method further includes:
[0012] Upon receiving the access information sent by the node to be verified, the node information within the alliance is updated based on the node information of the node to be verified contained in the access information, and the number of nodes that have passed the verification of the alliance committee node is updated.
[0013] Send the message updating the node information within the alliance to all nodes within the alliance.
[0014] In one embodiment of this disclosure, after updating the number of nodes that have passed the verification of the alliance committee nodes, the method further includes:
[0015] Determine whether the number of nodes that have been verified by the updated alliance committee exceeds a preset threshold. If the number of nodes that have been authorized by the updated alliance committee exceeds the preset threshold, send a re-election signaling to the re-election node so that the re-election node can update the alliance committee node according to the re-election rules.
[0016] In one embodiment of this disclosure, the re-election node updates the alliance committee node according to the re-election rules, including:
[0017] The re-election node sends a re-election message to the alliance member nodes, so that the alliance member nodes generate a random number based on the time of receiving the re-election message and a random algorithm, and send the random number to the re-election node. The re-election node then re-determines the alliance member nodes based on the random number.
[0018] According to another aspect of this disclosure, an alliance member authentication system is provided, the system comprising: an alliance verification node, a transceiver node, an alliance committee node, and an alliance audit node;
[0019] The consortium transceiver node is used to receive verification information from the node to be verified and send the verification information from the node to be verified to the consortium verification node.
[0020] The alliance verification node is used to send verification information to the alliance review node. Upon receiving the verification pass information from the alliance review node, it sends the verification pass information to the alliance committee node.
[0021] The alliance verification node is used to verify the verification information. If the verification is successful, the verification information is sent to the alliance verification node.
[0022] The alliance committee node is used to authorize the verification information upon receiving it, and to send an authorization approval message to the alliance verification node if the authorization is successful.
[0023] In one embodiment of this disclosure, the system further includes:
[0024] The reselection node is used to receive the reselection signaling sent by the alliance validator when the number of nodes authorized by the updated alliance member node exceeds a preset threshold, and to update the alliance member node according to the reselection rules.
[0025] In one embodiment of this disclosure, the system further includes alliance member nodes;
[0026] Alliance member nodes are used to receive re-election messages sent by alliance validator nodes, generate random numbers based on the time of receiving the re-election message and a random algorithm, and send the random numbers to the re-election node.
[0027] According to another aspect of this disclosure, a consortium member authentication device is provided, applied to a consortium verification node, the device comprising:
[0028] The first receiving module is used to receive the verification information of the node to be verified sent by the consortium transceiver node;
[0029] The first sending module is used to send the verification information to the alliance review node so that the alliance review node can verify the verification information and send the verification pass information to the alliance review node if the verification is successful.
[0030] The second sending module is used to send the verification pass information to the alliance committee node so that the alliance committee node can authorize the node to be verified.
[0031] The third sending module is used to send configuration information to the alliance transceiver node when it receives an authorization pass message from the alliance committee node, so that the alliance transceiver node sends the configuration information to the node to be verified, and the node to be verified accesses the alliance according to the configuration information.
[0032] In one embodiment of this disclosure, the alliance member authentication device further includes:
[0033] The update module, upon receiving access information from the node to be verified, updates the node information within the alliance based on the node information of the node to be verified contained in the access information, and updates the number of nodes that have passed the verification of the alliance committee node.
[0034] The fourth sending module is used to send messages updating node information within the alliance to all nodes within the alliance.
[0035] In one embodiment of this disclosure, the alliance member authentication device further includes:
[0036] The fifth sending module determines whether the number of nodes that have passed the verification of the updated alliance committee node exceeds a preset threshold. If the number of nodes that have passed the authorization of the updated alliance committee node exceeds the preset threshold, it sends a re-selection signaling to the re-selection node so that the re-selection node updates the alliance committee node according to the re-selection rules.
[0037] In one embodiment of this disclosure, node reselection is further configured to:
[0038] A re-election message is sent to the alliance member nodes, so that the alliance member nodes generate random numbers based on the time of receiving the re-election message and a random algorithm, and send the random numbers to the re-election node. The re-election node then determines the alliance member nodes based on the random numbers.
[0039] According to another aspect of this disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the above-described alliance member authentication method by executing the executable instructions.
[0040] According to another aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the above-described alliance member authentication method.
[0041] The alliance member authentication method provided in this disclosure receives verification information from the alliance transceiver node of the node to be verified, and then sends the verification information to the alliance audit node so that the alliance audit node can verify the verification information. If the verification is successful, the verification success information is sent to the alliance verification node. Upon receiving an authorization approval message from the alliance committee node, configuration information is sent to the alliance transceiver node so that the alliance transceiver node can send the configuration information to the node to be verified. The node to be verified then joins the alliance according to the configuration information. Since the verification information is first sent from the alliance verification node to the alliance audit node, and then verified by the alliance audit node before being sent to the alliance committee node for further verification, the method avoids the problem of low accuracy caused by the limited number of verified nodes when verification is performed only by the alliance committee node.
[0042] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0043] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0044] Figure 1 This diagram illustrates the structure of an alliance member authentication system according to an embodiment of the present disclosure.
[0045] Figure 2 This diagram illustrates another alliance member authentication system architecture in an embodiment of this disclosure.
[0046] Figure 3 This diagram illustrates another alliance member authentication system architecture according to an embodiment of the present disclosure.
[0047] Figure 4 This diagram illustrates a flowchart of an alliance member authentication method according to an embodiment of the present disclosure;
[0048] Figure 5 This diagram illustrates another alliance member authentication method according to an embodiment of the present disclosure.
[0049] Figure 6 This invention discloses a flowchart of another alliance member authentication method in an embodiment of the present invention.
[0050] Figure 7 This diagram illustrates a schematic of an alliance member authentication device according to an embodiment of the present disclosure;
[0051] Figure 8 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation
[0052] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0053] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0054] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0055] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0056] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0057] With technological advancements, the demand for multi-platform collaborative services is growing stronger, and the foundation of multi-platform collaboration lies in building trust among the entities managing these platforms. A consortium blockchain is a solution for establishing consortium trust in an untrusted network. A consortium blockchain is jointly initiated and maintained by participating platforms and is only open to the participating platforms.
[0058] However, current consortium blockchains still use a centralized approach for management and maintenance. This centralized management approach makes it difficult to detect and correct errors when core nodes in the consortium blockchain make mistakes.
[0059] Consortium blockchains are accessible only to members of a specific group and a limited number of third parties. Internally, multiple pre-selected nodes are designated as ledger keepers. The generation of each block is jointly determined by all pre-selected nodes. Other access nodes can participate in transactions but do not interfere with the ledger process. Third parties can perform limited queries through the blockchain's open API. To achieve better performance, consortium blockchains have certain requirements regarding the configuration of consensus or verification nodes and the network environment. The admission mechanism makes it easier to improve transaction performance and avoids problems caused by participants of varying levels of competence.
[0060] To address the aforementioned issues, this disclosure provides an alliance member authentication method, system, apparatus, device, and storage medium.
[0061] Figure 1 A structural diagram of an alliance member authentication system according to an embodiment of this disclosure is shown.
[0062] like Figure 1 As shown, the alliance member authentication system 10 may include:
[0063] Alliance Verification Node 102, Alliance Transceiver Node 104, Alliance Committee Node 106, and Alliance Audit Node 108;
[0064] Alliance transceiver node 104 is used to receive the verification information of the node to be verified and send the verification information of the node to be verified to alliance verification node 102.
[0065] Alliance verification node 102 is used to send verification information to alliance audit node 108, and upon receiving verification pass information from alliance audit node 108, it sends the verification pass information to alliance committee node 106.
[0066] Alliance verification node 108 is used to verify the verification information. If the verification is successful, the verification success information is sent to alliance verification node 102.
[0067] Alliance committee node 106 is used to authorize the verification information upon receiving it, and send an authorization approval message to alliance verification node 102 if the authorization is successful.
[0068] It should be noted that Alliance Verification Node 102, Alliance Sending and Receiving Node 104, Alliance Committee Node 106, and Alliance Audit Node 108 are all nodes within the consortium blockchain.
[0069] Any node within the alliance can be configured as one of the aforementioned nodes in a user-defined manner.
[0070] In some implementations, the aforementioned nodes can all be configured on servers or terminal devices.
[0071] Terminal devices can be various electronic devices, including but not limited to smartphones, tablets, laptops, desktop computers, wearable devices, augmented reality devices, virtual reality devices, etc.
[0072] Optionally, the client for the application installed on different terminal devices can be the same, or the client for the same type of application based on different operating systems. Depending on the terminal platform, the specific form of the application client can also differ; for example, the application client can be a mobile client, a PC client, etc.
[0073] A server can be a server that provides various services, such as a backend management server that supports the devices operated by users through terminal devices. The backend management server can analyze and process received requests and other data, and then feed the processing results back to the terminal device.
[0074] Optionally, the server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, etc., but is not limited to these. The terminal and server can be directly or indirectly connected via wired or wireless communication, which is not limited herein.
[0075] Optionally, the aforementioned wireless or wired networks use standard communication technologies and / or protocols. The network is typically the Internet, but can also be any network, including but not limited to Local Area Networks (LANs), Metropolitan Area Networks (MANs), Wide Area Networks (WANs), mobile, wired or wireless networks, private networks, or any combination of virtual private networks. In some embodiments, technologies and / or formats including Hyper Text Markup Language (HTML), Extensible Markup Language (XML), etc., are used to represent data exchanged over the network. Furthermore, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Networks (VPNs), and Internet Protocol Security (IPsec) can be used to encrypt all or some links. In other embodiments, custom and / or dedicated data communication technologies can be used to replace or supplement the aforementioned data communication technologies.
[0076] The alliance member authentication system provided in this disclosure receives verification information from the alliance transceiver node of the node to be verified, and then sends the verification information to the alliance audit node. The alliance audit node verifies the verification information and, if successful, sends verification approval information to the alliance verification node. Upon receiving an authorization approval message from the alliance committee node, the system sends configuration information to the alliance transceiver node, which then sends the configuration information to the node to be verified. The node to be verified then joins the alliance based on the configuration information. Because the verification information is first sent from the alliance verification node to the alliance audit node, and then verified by the alliance audit node before being sent to the alliance committee node for further verification, the system avoids the low accuracy problem caused by verification by only the alliance committee node, which involves a limited number of verified nodes.
[0077] Based on the same inventive concept, another alliance member authentication system is also provided in this disclosure.
[0078] Figure 2 A structural diagram of another alliance member authentication system is shown in an embodiment of this disclosure.
[0079] like Figure 2As shown, the difference between this alliance member authentication system and the alliance member authentication system in the above embodiments is that the alliance member authentication system 20 may further include:
[0080] The reselection node 202 is used to receive the reselection signaling sent by the alliance verification node 102 when the number of nodes authorized by the updated alliance committee node 106 exceeds a preset threshold, and to update the alliance committee node 106 according to the reselection rules.
[0081] It should be noted that node 202, which is a node within the consortium blockchain, can also be configured on terminal devices or servers.
[0082] The alliance member authentication system provided in the embodiments of this disclosure updates the alliance member nodes by setting a reselection node. Thus, in the event of an anomaly in the alliance member node, the alliance member node is replaced, which can prevent the failure of the alliance member node from worsening.
[0083] Based on the same inventive concept, another alliance member authentication system is also provided in this disclosure.
[0084] Figure 3 A structural diagram of another alliance member authentication system according to an embodiment of this disclosure is shown.
[0085] like Figure 3 As shown, the difference between this alliance member authentication system 30 and the alliance member authentication system in the above embodiments is that the alliance member authentication system may further include:
[0086] Alliance member node 302;
[0087] Alliance member node 302 is used to receive reselection messages sent by reselection node 202, generate random numbers based on the time of receiving the reselection message and a random algorithm, and send the random numbers to reselection node 202.
[0088] It should be noted that alliance member node 302 is also a node within the alliance chain and can also be configured on terminal devices and servers.
[0089] In the alliance member authentication system provided by the embodiments of this disclosure, an alliance member node is randomly selected from the alliance member nodes by using a random algorithm. This makes the selection process random and avoids the problem that the probability of an alliance member node being selected as an alliance member node is too high due to the excessive weight of a certain alliance member node when other algorithms are used.
[0090] Furthermore, this avoids the problem of faulty nodes being identified as alliance committee nodes with an excessively high probability when there are faulty nodes among the alliance member nodes.
[0091] Based on the same inventive concept, this disclosure also provides a method for authenticating alliance members, as shown in the following embodiments. Since the principle by which this method solves the problem is similar to that of the system embodiments described above, the implementation of this method can refer to the implementation of the system embodiments described above, and repeated details will not be elaborated further.
[0092] Figure 4 A flowchart of a consortium member authentication method according to an embodiment of this disclosure is shown.
[0093] like Figure 4 As shown, this method is applied to consortium validator nodes, and the method may include:
[0094] S402, Receive verification information from the consortium transceiver node for the node to be verified.
[0095] It should be noted that consortium transceiver nodes can be nodes within a consortium blockchain used to connect to external networks. The addresses of these consortium transceiver nodes can be public addresses.
[0096] The verification information may include verification materials, which may be verification materials determined by external users according to access rules.
[0097] Admission rules can include rules determined by nodes within multiple consortium blockchains.
[0098] Admission rules can be publicly disclosed rules.
[0099] In a specific example, after obtaining the address of the consortium transceiver node and the admission rules, the external platform or device determines the verification information according to the admission rules, then merges the verification information and the request into verification information, and then sends the above verification information to the consortium transceiver node.
[0100] By setting up sender and receiver nodes, nodes within the consortium blockchain can avoid contact with external networks, reducing the risk of attacks on nodes within the consortium blockchain.
[0101] S404 sends the verification information to the alliance audit node so that the alliance audit node can verify the verification information, and if the verification is successful, sends the verification success information to the alliance audit node.
[0102] It should be noted that the consortium validator node can receive verification information sent by the consortium sender and receiver nodes. The consortium validator node can store the verification information and the time of sending and receiving the verification information.
[0103] It should be noted that the consortium audit nodes can verify the verification information according to the pre-determined audit rules. The audit rules can be jointly determined by multiple nodes in the consortium chain, and the audit rules can be pre-stored in any node in the consortium chain.
[0104] After receiving the verification approval information from the alliance review node, the alliance committee node can review the verification approval information. If the review is successful, the node can authorize the verification approval information and send an authorization approval message to the alliance verification node.
[0105] S406 sends the verification pass information to the alliance committee node so that the alliance committee node can authorize the node to be verified.
[0106] S408, upon receiving an authorization pass message from a member node of the alliance, sends configuration information to the alliance transceiver node, so that the transceiver node sends the configuration information to the node to be verified, and the node to be verified connects to the alliance according to the configuration information.
[0107] It should be noted that the configuration information may include the role and rights of the node to be verified within the consortium blockchain, as well as the parameters for connecting to the consortium blockchain.
[0108] In some implementations, after connecting to the consortium blockchain, the node to be verified can send a connection success message to the consortium verification node.
[0109] In some implementations, the consortium verification node can store node information of the nodes within the consortium blockchain. This node information may include the node ID, node role, node authorizer information, public key of the consortium blockchain, number of authorizations of consortium committee nodes, audit records, audit time, etc.
[0110] By storing the above information, it becomes easier to retrieve and verify it.
[0111] The alliance member authentication method provided in this disclosure receives verification information from the alliance transceiver node of the node to be verified, and then sends the verification information to the alliance audit node so that the alliance audit node can verify the verification information. If the verification is successful, the verification success information is sent to the alliance verification node. Upon receiving an authorization approval message from the alliance committee node, configuration information is sent to the alliance transceiver node so that the alliance transceiver node can send the configuration information to the node to be verified. The node to be verified then joins the alliance according to the configuration information. Since the verification information is first sent from the alliance verification node to the alliance audit node, and then verified by the alliance audit node before being sent to the alliance committee node for further verification, the method avoids the problem of low accuracy caused by the limited number of verified nodes when verification is performed only by the alliance committee node.
[0112] Based on the same inventive concept, this disclosure provides another method for authenticating alliance members.
[0113] Figure 5 A flowchart of another alliance member authentication method according to an embodiment of this disclosure is shown.
[0114] like Figure 5 As shown, the method may include:
[0115] S502, upon receiving access information sent by the node to be verified, updates the node information within the alliance based on the node information of the node to be verified contained in the access information and updates the number of nodes that have passed the verification of the alliance committee node.
[0116] It should be noted that the alliance validator nodes pre-store the number of nodes that have been verified by the alliance committee nodes. After the current alliance committee node verifies and approves the node to be verified, the stored number is updated.
[0117] The node information within the alliance includes the node information of the node to be verified and the node information of the other nodes. The node information has already been described in the above embodiments and will not be repeated here.
[0118] S504 sends a message updating node information within the alliance to all nodes within the alliance.
[0119] In this embodiment of the disclosure, by storing the updated node information of the node to be verified and the number of nodes verified by the alliance committee node, it is convenient to query changes in node information.
[0120] Based on the same inventive concept, this disclosure provides another method for authenticating alliance members.
[0121] Figure 6A flowchart of another alliance member authentication method according to an embodiment of this disclosure is shown.
[0122] like Figure 6 As shown, the method may include:
[0123] S602, determine whether the number of nodes that have passed the verification of the updated alliance committee node exceeds a preset threshold. If the number of nodes that have passed the authorization of the updated alliance committee node exceeds the preset threshold, send a re-election signaling to the re-election node so that the re-election node updates the alliance committee node according to the re-election rules.
[0124] It should be noted that, in order to avoid the alliance committee node being difficult to detect in the event of a failure, the embodiment of this disclosure replaces the alliance committee node after the number of verified nodes that have passed the verification after the update reaches a preset threshold.
[0125] In this embodiment of the disclosure, by replacing the alliance committee node, it is possible to avoid the difficulty in detecting the failure of the alliance committee node, thereby ensuring that the failure of the alliance committee node continues to affect the alliance chain.
[0126] In some embodiments, updating the alliance committee nodes according to the re-election rules at the re-election node includes:
[0127] The re-election node sends a re-election message to the alliance member nodes, enabling the member nodes to generate random numbers based on the time they receive the message and a random algorithm. These random numbers are then sent to the re-election node, which uses the random numbers to re-determine the alliance committee members.
[0128] It should be noted that alliance member nodes can be nodes other than alliance committee nodes within the alliance chain.
[0129] When a member node receives a reselection message, it can obtain the time point at which the reselection message was received, then determine a random number based on the aforementioned time point and a random algorithm, and then send the determined random number to the reselection node.
[0130] If the reselection node receives random numbers from multiple alliance member nodes, it can determine the alliance member node corresponding to any one of the random numbers as the new alliance committee node.
[0131] In this embodiment of the disclosure, by setting a random method to determine a new alliance committee node from multiple alliance member nodes, the probability of each alliance member node being determined as an alliance committee node can be made equal.
[0132] Based on the same inventive concept, this disclosure also provides an alliance member authentication device, as shown in the following embodiment. Since the principle by which this device embodiment solves the problem is similar to that of the above-described method embodiment, the implementation of this device embodiment can refer to the implementation of the above-described method embodiment, and repeated details will not be described again.
[0133] Figure 7 A schematic diagram of an alliance member authentication device is shown in an embodiment of this disclosure.
[0134] like Figure 7 As shown, the device 700 is applied to a consortium validator node, and the device includes:
[0135] The first receiving module 702 is used to receive the verification information of the node to be verified sent by the consortium transceiver node;
[0136] The first sending module 704 is used to send the verification information to the alliance review node so that the alliance review node can verify the verification information and send the verification pass information to the alliance review node if the verification is successful.
[0137] The second sending module 706 is used to send the verification pass information to the alliance committee node so that the alliance committee node can authorize the node to be verified.
[0138] The third sending module 708 is used to send configuration information to the alliance transceiver node when it receives an authorization pass message sent by the alliance committee node, so that the alliance transceiver node sends the configuration information to the node to be verified, and the node to be verified accesses the alliance according to the configuration information.
[0139] The alliance member authentication device provided in this disclosure receives verification information from the alliance transceiver node of the node to be verified, and then sends the verification information to the alliance audit node so that the alliance audit node can verify the verification information. If the verification is successful, the audit node sends the verification success information to the alliance verification node. Upon receiving an authorization approval message from the alliance committee node, the device sends configuration information to the alliance transceiver node so that the alliance transceiver node can send the configuration information to the node to be verified. The node to be verified then joins the alliance according to the configuration information. Because the verification information is first sent from the alliance verification node to the alliance audit node, and then verified by the alliance audit node before being sent to the alliance committee node for further verification, the device avoids the problem of low accuracy caused by the limited number of nodes verified by only the alliance committee node.
[0140] In one embodiment of this disclosure, the alliance member authentication device 700 further includes:
[0141] The update module 710, upon receiving access information sent by the node to be verified, is used to update the node information within the alliance based on the node information of the node to be verified contained in the access information and update the number of nodes that have passed the verification of the alliance committee node.
[0142] The fourth sending module 712 is used to send the message of updating the node information within the alliance to all nodes within the alliance.
[0143] In this embodiment of the disclosure, by storing the updated node information of the node to be verified and the number of nodes verified by the alliance committee node, it is convenient to query changes in node information.
[0144] In one embodiment of this disclosure, the alliance member authentication device 700 further includes:
[0145] The fifth sending module 714 determines whether the number of nodes that have passed the verification of the updated alliance committee node exceeds a preset threshold. If the number of nodes that have passed the authorization of the updated alliance committee node exceeds the preset threshold, it sends a re-selection signaling to the re-selection node so that the re-selection node updates the alliance committee node according to the re-selection rules.
[0146] In one embodiment of this disclosure, the reselection of the node further includes:
[0147] A re-election message is sent to the alliance member nodes, so that the alliance member nodes generate random numbers based on the time of receiving the re-election message and a random algorithm, and send the random numbers to the re-election node. The re-election node then determines the alliance member nodes based on the random numbers.
[0148] In this embodiment of the disclosure, by setting a random method to determine a new alliance committee node from multiple alliance member nodes, the probability of each alliance member node being determined as an alliance committee node can be made equal.
[0149] Those skilled in the art will understand that various aspects of this disclosure can be implemented as a system, method, or program product. Therefore, various aspects of this disclosure can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, collectively referred to herein as a "circuit," "module," or "system."
[0150] The following reference Figure 8 To describe an electronic device 800 according to such an embodiment of the present disclosure. Figure 8 The electronic device 800 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.
[0151] like Figure 8As shown, the electronic device 800 is manifested in the form of a general-purpose computing device. The components of the electronic device 800 may include, but are not limited to: at least one processing unit 810, at least one storage unit 820, and a bus 830 connecting different system components (including storage unit 820 and processing unit 810).
[0152] The storage unit stores program code, which can be executed by the processing unit 810, causing the processing unit 810 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure. For example, the processing unit 810 can perform the following steps of the above method embodiments:
[0153] Receive verification information from the nodes to be verified sent by the consortium's transceiver nodes;
[0154] The verification information is sent to the alliance review node so that the alliance review node can verify the verification information, and if the verification is successful, the verification success information is sent to the alliance review node.
[0155] The verification pass information is sent to the alliance committee node so that the alliance committee node can authorize the node to be verified;
[0156] Upon receiving an authorization message from a member node of the alliance, configuration information is sent to the alliance transceiver node, so that the transceiver node sends the configuration information to the node to be verified, and the node to be verified connects to the alliance according to the configuration information.
[0157] Storage unit 820 may include a readable medium in the form of a volatile storage unit, such as random access memory (RAM) 8201 and / or cache memory 8202, and may further include a read-only memory (ROM) 8203.
[0158] The storage unit 820 may also include a program / utility 8204 having a set (at least one) of program modules 8205, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.
[0159] Bus 830 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.
[0160] Electronic device 800 can also communicate with one or more external devices 840 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 800, and / or with any device that enables electronic device 800 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 850. Furthermore, electronic device 800 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 860. As shown, network adapter 860 communicates with other modules of electronic device 800 via bus 830. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0161] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0162] In exemplary embodiments of this disclosure, a computer-readable storage medium is also provided, which may be a readable signal medium or a readable storage medium. A program product capable of implementing the methods described above is stored thereon. In some possible implementations, various aspects of this disclosure may also be implemented as a program product including program code, which, when run on a terminal device, causes the terminal device to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure.
[0163] More specific examples of computer-readable storage media in this disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0164] In this disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device.
[0165] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0166] In practical implementation, program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0167] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0168] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.
[0169] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0170] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.
Claims
1. A method for authenticating alliance members, characterized in that, Applied to consortium validator nodes, the method includes: Receive verification information from the consortium transceiver node, which includes verification data. The verification data is determined by external users based on admission rules, which include rules determined by nodes within multiple consortium chains. The verification information is sent to the alliance review node so that the alliance review node can verify the verification information, and if the verification is successful, the verification success information is sent to the alliance review node. The verification pass information is sent to the alliance committee node so that the alliance committee node can authorize the node to be verified; Upon receiving an authorization pass message from a member node of the alliance, configuration information is sent to the alliance transceiver node, so that the alliance transceiver node sends the configuration information to the node to be verified, and the node to be verified accesses the alliance according to the configuration information.
2. The alliance member authentication method according to claim 1, characterized in that, The method further includes: Upon receiving the access information sent by the node to be verified, the node information within the alliance is updated based on the node information of the node to be verified contained in the access information, and the number of nodes that have passed the verification of the alliance committee node is updated. Send the message updating the node information within the alliance to all nodes within the alliance.
3. The alliance member authentication method according to claim 2, characterized in that, After updating the number of nodes that have passed the alliance committee node verification, the method further includes: Determine whether the number of nodes that have passed the verification of the updated alliance committee node exceeds a preset threshold. If the number of nodes that have passed the authorization of the updated alliance committee node exceeds the preset threshold, send a re-election signaling to the re-election node so that the re-election node updates the alliance committee node according to the re-election rules.
4. The alliance member authentication method according to claim 3, characterized in that, The re-election node updates the alliance committee nodes according to the re-election rules, including: The re-election node sends a re-election message to the alliance member nodes, so that the alliance member nodes generate a random number based on the time of receiving the re-election message and a random algorithm, and send the random number to the re-election node. The re-election node then re-determines the alliance member nodes based on the random number.
5. A consortium member authentication system, characterized in that, This includes alliance verification nodes, alliance sending and receiving nodes, alliance committee nodes, and alliance audit nodes; The consortium transceiver node is used to receive the verification information of the node to be verified and send the verification information of the node to be verified to the consortium verification node. The verification information includes verification data, which is determined by external users based on admission rules. The admission rules include rules determined by nodes within multiple consortium chains. The alliance verification node is used to send the verification information to the alliance review node, and upon receiving the verification pass information from the alliance review node, to send the verification pass information to the alliance committee node. The alliance verification node is used to verify the verification information, and if the verification is successful, the verification success information is sent to the alliance verification node. The alliance committee node is used to authorize the verification information upon receiving it, and to send an authorization approval message to the alliance verification node if the authorization is successful.
6. The alliance member authentication system according to claim 5, characterized in that, The system also includes: The reselection node is used to receive a reselection signaling sent by the alliance verification node when the alliance verification node determines that the number of nodes authorized by the updated alliance committee node exceeds a preset threshold, and to update the alliance committee node according to the reselection rules.
7. The alliance member authentication system according to claim 5, characterized in that, The system also includes alliance member nodes; The alliance member node is used to receive the re-election message sent by the re-election node, generate a random number based on the time point of receiving the re-election message and a random algorithm, and send the random number to the re-election node so that the re-election node can re-determine the alliance member node based on the random number.
8. A device for authenticating alliance members, characterized in that, The device, applied to a consortium validator node, includes: The first receiving module is used to receive verification information of the node to be verified sent by the consortium transceiver node. The verification information includes verification data, which is determined by external users based on admission rules. The admission rules include rules determined by nodes within multiple consortium chains. The first sending module is used to send the verification information to the alliance review node, so that the alliance review node can verify the verification information, and if the verification is successful, send the verification success information to the alliance review node. The second sending module is used to send the verification pass information to the alliance committee node so that the alliance committee node can authorize the node to be verified; The third sending module is used to send configuration information to the alliance transceiver node when it receives an authorization pass message from the alliance committee node, so that the alliance transceiver node sends the configuration information to the node to be verified, and the node to be verified accesses the alliance according to the configuration information.
9. An electronic device, characterized in that, include: processor; as well as Memory for storing the executable instructions of the processor; The processor is configured to execute the alliance member authentication method according to any one of claims 1 to 4 by executing the executable instructions.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the alliance member authentication method according to any one of claims 1 to 4.