A Large-Scale Virtual Node Verification Method in a Cloud Environment
The method uses a certificate service log database with Merkle trees to securely and efficiently verify large-scale virtual nodes in cloud environments by assuming cloud providers maintain a reputation, addressing security and efficiency challenges.
Patent Information
- Application Number
- CN202211115815.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-14
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-09-14
AI Technical Summary
In a cloud computing environment, it is difficult for the prior art to efficiently verify large-scale virtual nodes while ensuring security, and existing methods are usually based on unpractical security assumptions, resulting in low efficiency or security risks.
By establishing a certificate service log database, using Merkle tree to manage the certificate database, combining CAP maintenance log extension certificate, encrypted verification between the user and CSP, ensuring certificate transparency and security, and using O(log n) complexity operations for certificate update and revocation.
It realizes an efficient and secure verification method in large-scale virtual node scenarios, prevents cloud service providers from cheating without leaving any evidence, and is suitable for large-scale application scenarios.
Smart Images

Figure CN115694825B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network nodes, and particularly relates to a method for verifying a large number of virtual nodes in a cloud environment. Background Art
[0002] With the rapid development of computer technology and the Internet, cloud computing, as a new computing model, has been widely applied in various fields. IT enterprises around the world have successively formulated and released their own cloud strategies. The further development of cloud computing has brought new impacts and challenges to the security field. A large number of users store their privacy data in the "cloud". Once the identity of a legitimate user is forged, the leakage of privacy data will occur. Therefore, it is urgent to propose a secure and reliable identity authentication scheme to enhance the security of the cloud computing environment. However, in the cloud computing environment, there are still many problems in terms of security and efficiency in verifying a large number of virtual nodes. Most of the existing verification methods are based on the assumption that the user cloud service provider is completely trustworthy, or on the assumption that the cloud service provider is completely malicious. The methods designed based on the first assumption are highly efficient but have security risks. Since the key information is stored in the cloud service provider, when problems occur, users cannot extract evidence to prove that the cloud service provider has done something wrong. The verification designed based on the second assumption will use cryptographic technologies such as fully homomorphic encryption. Although the security problem can be solved, due to the low algorithm efficiency, it is not applicable to large-scale application scenarios.
[0003] Therefore, it is necessary to develop a new method for verifying a large number of virtual nodes applicable to the cloud environment. Summary of the Invention
[0004] The present invention overcomes the deficiencies of the prior art and provides a method for verifying a large number of virtual nodes in a cloud environment to solve the above technical problems.
[0005] The present invention provides the following technical solutions:
[0006] A method for verifying a large number of virtual nodes in a cloud environment, which includes the following steps:
[0007] S101: Establish a service log database for certificates;
[0008] S102: The user registers an account in the application program on the system;
[0009] S103: The user requests services from the CSP;
[0010] S104: The CSP processes the user's request;
[0011] S105: Provide key and password management services in combination with the application environment of cloud computing.
[0012] Preferably, in the step S101, the public log of the certificate is maintained by the CAP, and the CAP can issue a log extension proof. The composition of the CAP's log is as follows:
[0013] db = [cert(user, pkuser), cert(CSP, pkCSP),...]
[0014] Where user represents the user, pkuser represents the public key of the user, and cert(user, pkuser) represents the certificate of the user user; CSP represents the cloud service provider, pkCSP represents the public key of the cloud service provider, and cert(CSP, pkCSP) represents the certificate of the cloud service provider CSP; define db′ as the extension proof of db, where db represents the database log, satisfying the relationship h(db) < h(db′), and h(x) represents the hash function; all the logs construct a certificate database, and the certificate database is managed in the form of a Merkle tree.
[0015] Preferably, in the step S102, the user registers the new or existing virtual node address owned in the CSP with the system client software; and creates an encryption key and a public key, and stores them in encrypted form using the CAP.
[0016] More preferably, the storing in encrypted form using the CAP includes that the system stores the user's encryption key together with the current snapshot of the CAP certificate and the log hash value in an encrypted package for verifying the correctness of the log operation and preventing the rollback attack of the CAP from sending an old version of the cached information to the user.
[0017] Preferably, in the step S103, the user's request for service from the CSP includes:
[0018] S103-1: Before verifying the user with the CAP, the user's application obtains the current h(db′) from the CAP;
[0019] S103-2: The application retrieves the h(dbs) stored locally by it, where dbs represents a log stored locally; optionally, it requests to prove that the database log hash value satisfies the relationship, that is, h(dbs) < h(db′), and verifies the correctness of the extension proof;
[0020] S103-3: The user requests and verifies that cert(user, pkuser) satisfies the relationship h(db) < h(db′) in the database log hash value in db′;
[0021] S103-4: The application verifies the correctness of the user operation and obtains the user name, log hash value, user public key, and user private key information from the CAP;
[0022] S103-5: The application requests and verifies that the proof verification log hash value satisfies the relationships, i.e., h(dbs) < h(db) and h(db) < h(db′). If the relationships are satisfied, the application replaces the locally stored h(dbs) with h(db′).
[0023] S103-6: The application finds the public key pkCSP of the CSP in db′ and requests to verify the correctness of the CSP log information proof.
[0024] S103-7: The application encrypts the message for the CSP with pkCSP and sends it to the CSP.
[0025] S103-8: The application randomly checks the log consistency.
[0026] Preferably, in the step S104, the CSP application retrieves its versions of h(dbs), h(db), and h(db) and performs the following checks:
[0027] S104-1: Check whether h(dbs) < h(db) < h(db′) is satisfied;
[0028] S104-2: Check whether the field information of the CSP and pkCSP is correct in db′;
[0029] S104-3: Obtain the public key pkuser of the user from db′ and request the correctness of its proof;
[0030] S104-4: Decrypt the user's message and check the user's signature;
[0031] If the above step S104 passes, it means that the CSP agrees to the user's request and generates virtual resources for the user.
[0032] Preferably, in the step S105, the key and password management scheme includes that the user's password is strongly random and the device key is used.
[0033] The beneficial effects of the present invention are:
[0034] 1. The present invention, considering that the cloud service provider is a large organization that needs to maintain its reputation and thus will not attack its users at all costs, and the cloud service provider will not initiate attacks leaving verifiable evidence, proposes a secure and efficient verification method applicable to large-scale virtual nodes in a cloud computing environment. In the present invention, the cloud service provider can simultaneously act as the certificate issuing authority and the maintainer of the CA log for its users.
[0035] 2. The present invention realizes certificate transparency by using a certificate log database, so that cloud service providers do not need to be trusted by users. Certificate transparency ensures that service providers cannot cheat without leaving evidence of their cheating. In the method provided by the present invention, the complexity of operations such as certificate update and revocation is O(log n), so the method provided by the present invention is applicable to large-scale application scenarios.
[0036] 3. The present invention reconsiders the security assumptions in the cloud environment. Considering that cloud service providers are large organizations that need to maintain their reputations and thus will not attack their users at all costs, and cloud service providers will not initiate attacks that leave verifiable evidence, it is a secure and efficient verification method applicable to large-scale virtual nodes in the cloud computing environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The present invention will be further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the following drawings.
[0038] Figure 1 It is a schematic flowchart of a method for verifying large-scale virtual nodes based on a cloud environment in an embodiment of the present invention;
[0039] Figure 2 It is a schematic structural diagram of a method for verifying large-scale virtual nodes based on a cloud environment provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] The following further describes in detail the method for verifying large-scale virtual nodes based on a cloud environment in combination with specific embodiments. These embodiments are only for comparison and explanation purposes, and the present invention is not limited to these embodiments.
[0041] Embodiment
[0042] Refer to the append Figure 1-2 In an embodiment of the present invention, in a certain system, there are many users. The method of the present invention supports the application environment of large-scale scenarios. A method for verifying large-scale virtual nodes in a cloud environment includes the following steps:
[0043] S101: Establish a service log database for certificates;
[0044] S102: The user registers an account with the application on the system;
[0045] S103: The user requests services from the CSP;
[0046] S104: The CSP processes the user's request;
[0047] S105: Provide key and password management services in combination with the application environment of cloud computing.
[0048] Preferably, in S101, the public log of the certificate is maintained by CAP, and CAP can issue a log extension proof. The composition of the CAP log is as follows:
[0049] db = [cert(user,pkuser),cert(CSP,pkCSP),...]
[0050] where user represents the user, pkuser represents the public key of the user, and cert(user,pkuser) represents the certificate of user user; CSP represents the cloud service provider, pkCSP represents the public key of the cloud service provider, and cert(CSP,pkCSP) represents the certificate of cloud service provider CSP; define db′ as the extension proof of db, db represents the database log, and satisfies the relationship h(db) < h(db′), where h(x) represents the hash function; all the logs construct a certificate database, and the certificate database is managed in the form of a Merkle tree.
[0051] Preferably, in S102, the user registers the new or existing virtual node address owned in the CSP with the CAP through the system client software; and creates an encryption key and a public key, and stores them in encrypted form using the CAP.
[0052] More preferably, the storing in encrypted form using the CAP includes that the system stores the user's encryption key together with the current snapshot of the CAP certificate and the log hash value in an encrypted package, which is used to verify the correctness of the log operation and prevent the rollback attack of the CAP from sending an old version of the cached information to the user.
[0053] Preferably, in S103, the user's request for services from the CSP includes:
[0054] S103-1: Before verifying the user with the CAP, the user's application obtains the current h(db′) from the CAP;
[0055] S103-2: The application retrieves the h(dbs) stored locally by it, where dbs represents a log stored locally; optionally, it requests to prove that the database log hash value satisfies the relationship, that is, h(dbs) < h(db′), and verifies the correctness of the extension proof;
[0056] S103-3: The user requests and verifies that cert(user,pkuser) satisfies the relationship h(db) < h(db′) in the database log hash value in db′;
[0057] S103-4: The application verifies the correctness of the user operation and obtains the user name, log hash value, user public key, and user private key information from the CAP;
[0058] S103-5: The application requests and verifies that the proof verification log hash value satisfies the relationship, that is, h(dbs) < h(db) and h(db) < h(db′). If the relationship is satisfied, the application replaces the locally stored h(dbs) with h(db′);
[0059] S103-6: The application finds the public key pkCSP of the CSP in db′ and requests to verify the correctness of the CSP log information proof;
[0060] S103-7: The application encrypts the message for the CSP with pkCSP and sends it to the CSP;
[0061] S103-8: The application randomly checks the log consistency.
[0062] Preferably, in S104, the CSP application retrieves its h(dbs), h(db), and h(db) versions and performs the following checks:
[0063] S104-1: Check whether h(dbs) < h(db) < h(db′) is satisfied;
[0064] S104-2: Check whether the field information of the CSP and pkCSP is correct in db′;
[0065] S104-3: Obtain the public key pkuser of the user from db′ and request the correctness of its proof;
[0066] S104-4: Decrypt the user's message and check the user's signature;
[0067] If the above S104 passes, it means that the CSP agrees to the user's request and generates virtual resources for the user.
[0068] Preferably, in S105, the key and password management scheme includes that the user's password is strongly random and the device key is used
[0069] In one embodiment, as Figure 1 and Figure 2 shown in the flow and structure diagram of the method for verifying large-scale virtual nodes based on the cloud environment, first establish a certificate log service system, where the public log of the certificates issued by the certificate authority is maintained by the CAP. The CAP can issue log extension proofs. The log of the CAP consists of many certificates:
[0070] db = [cert(user, pkuser), cert(CSP, pkCSP),...]
[0071] Among them, pkuser represents the public key of the user. There can be many users in the system, and this system supports the application environment of large-scale scenarios. In addition, define db′ as the extended proof of db, satisfying the relationship h(db) < h(db′). All logs are constructed into a certificate database, and this database is managed in the form of a Merkle tree. Items are stored in chronological order from left to right, and certificates are added in chronological order by extending the tree to the right. The revocation of a certificate is completed by adding a new key to the entry. Therefore, the key of an entry is considered current only when there are no subsequent items for that entry. By utilizing the characteristics of the Merkle tree, insertion, revocation, and extended proof are O(log n). Here, n represents the number of users. Thus, even when many users use virtual nodes, this method is efficient.
[0072] Assume that the user has already downloaded the appropriate application or installed an extension in his client. At registration, the user's client software registers the new or existing virtual node address he has in the CSP with the CAP; then creates his secret and public keys and stores them in encrypted form using the CAP. Specifically:
[0073] S102-1: The application obtains the current h(db) from the CAP and stores it.
[0074] S102-2: The user enters a username, such as "user@example.com", and selects a new password secret. The software selects an encryption key k and securely stores it on the user's device. (Alternatively, to avoid storing k on the device, the authentication password secret and the key k can be derived from a strong password selected by the user.)
[0075] S102-3: The CAP creates an account for the user with the username and password the same as in S102-2, that is, the username is "user@example.com" and the password is secret.
[0076] S102-4: The application creates a public key pair pkuser, skuser.
[0077] S102-5: The application uses the CAP to store (user, pkuser, {h(db), skuser,...}, k).
[0078] S102-6: The application randomly checks the log consistency.
[0079] The user's application stores his encryption key together with the current snapshot of the CAP and the log hash value in an encrypted package, which is used to verify the correctness of log operations and prevent rollback attacks where the CAP sends an old version of his cached information to the user.
[0080] Subsequently, a service is requested from the CSP. S103-1: Before verifying the user with the CAP, the user's application obtains the current h(db′) from the CAP.
[0081] S103-2: The application retrieves its locally stored h(dbs). Optionally, it requests a proof that h(dbs) < h(db′) and verifies the correctness of the extended proof. (This verification is not necessary because if it fails, subsequent verifications will also fail; but if the verification is performed, any illegal behavior of the CAP will be detected earlier.)
[0082] S103-3: The user requests and verifies the proof that cert(user,pkuser) is current in db′.
[0083] S103-4: The application verifies the correctness of the user operation and obtains (user,{h(db),pkuser,skuser,...},k) from the CAP.
[0084] S103-5: The application requests and verifies the proofs that h(dbs) < h(db) and h(db) < h(db′). The application replaces its locally stored h(dbs) with h(db′).
[0085] S103-6: The application finds the public key pkCSP of the CSP in db′ and requests to verify the correctness of the proof.
[0086] S103-7: The application encrypts the message for the CSP with pkCSP and sends it to the CSP.
[0087] S103-8: The application performs a random check on log consistency.
[0088] Among them, step S103-1 and step S103-2 ensure that the CAP still maintains the log in an append-only manner. In step S103-3, the user's application verifies whether the CAP correctly maintains his certificate. S103-5 ensures that the locally stored snapshot dbs is not later than the db stored in the user account; and the db stored in the account takes precedence over the current db′. These two checks can prevent rollback attacks and attacks based on improper log maintenance by the CAP.
[0089] Subsequently, the CSP processes the user's request. The CSP application retrieves its versions of h(dbs), h(db), and h(db), and then performs the following checks.
[0090] S104-1: Check that h(dbs) < h(db) < h(db′);
[0091] S104-2: Check whether the field information of CSP and pkCSP is correct in db′;
[0092] S104-3: Obtain the public key pkuser of the user from db′ and request the correctness of its proof;
[0093] S104-4: Decrypt the user's message and check the user's signature;
[0094] If the above S104 passes, it means that the CSP agrees to the user's request and generates virtual resources for the user.
[0095] Finally, this issuance provides a choice between two key and password management schemes.
[0096] (1) The user's password is strongly random. In this option, the user's password secret is a sufficiently random password and is not disclosed to the CSP. The user authenticates with the CSP using kdf(secret, 1) to obtain a suitable key derivation function kdf, and uses k = kdf(secret, 2) as the key wallet encryption key. In this case, the password must be strongly random to prevent the CSP (or anyone else) from performing a guessing attack to obtain the key k.
[0097] (2) Device key. In this option, the key wallet encryption key k is stored on the user's device. The password does not have to be strongly random because the CSP can prevent online guessing attacks.
[0098] Each of the two methods has its own advantages. The strong random password is the most flexible because users can access the service from any device without providing them with the key wallet encryption key k. However, the main drawback is that the server can attempt an offline guessing attack on the secret to derive k. If a user wants to change their password, the client application only needs to decrypt and re-encrypt the key wallet using the keys derived from the old password and the new password respectively. If a user loses their password, the user can prove ownership of the account out-of-band, which allows her public key to be revoked and the account to be reinitialized. The device key option is more secure but requires a way to migrate the key k to a new device. A user's request to change their password is handled in a conventional manner; a request to change k is handled by decrypting the key package with the old k and encrypting it with the new k. In the event of a lost password, the usual recovery mechanism can be used. If the key k is lost, the user will not be able to access their historical data but can use password knowledge to prove ownership of the account; as described above, this will allow the user to revoke their public key and reinitialize the account. However, since users typically have k on multiple devices, it is unlikely that she will lose it completely. These two options are essential for any cloud computing application where users have encryption keys that are secret from the cloud provider, thus ensuring the security of authentication.
[0099] In the above embodiments of the present invention, by re-considering the security assumptions in the cloud environment, taking into account that cloud service providers are large organizations that need to maintain their reputation and thus will not attack their users at all costs, and that cloud service providers will not initiate attacks that leave verifiable evidence, it is a secure and efficient authentication method applicable to large-scale virtual nodes in the cloud computing environment.
[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the protection scope of the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the essence and scope of the technical solutions of the present invention.
Claims
1. A method for validating large-scale virtual nodes in a cloud environment, characterized in that, It includes the following steps: S101: Establish a service log database for certificates; S102: The user registers an account in the application on the system; the user registers the new or existing virtual node address owned in the CSP with the CAP in the system client software; And create an encryption key and a public key, and store them in encrypted form using the CAP; wherein, the storing in encrypted form using the CAP includes: the system stores the user's encryption key together with the current snapshot of the CAP certificate and the log hash value in an encrypted package for verifying the correctness of the log operation and preventing a rollback attack where the CAP sends an old version of the cached information to the user; S104: The user requests a service from the CSP; S105: Process the user's request by the CSP; S106: Provide a management solution for keys and passwords in combination with the application environment of cloud computing.
2. The large-scale virtual node verification method in a cloud environment according to claim 1, wherein In step S101, the public log of the certificate is maintained by the CAP, and the CAP can issue a log extension proof. The composition of the CAP's log is as follows: db = [cert(user, pkuser), cert(CSP, pkCSP),...] Where user represents the user, pkuser represents the public key of the user, and cert(user, pkuser) represents the certificate of user user; CSP represents the cloud service provider, pkCSP represents the public key of the cloud service provider, and cert(CSP, pkCSP) represents the certificate of the cloud service provider CSP; define db' as the extended proof of db, db represents the database log, and it satisfies the relationship h(db) < h(db'), where h(x) represents the hash function; all the logs construct a certificate database, and the certificate database is managed in the form of a Merkle tree.
3. The large-scale virtual node verification method in a cloud environment according to claim 2, wherein In step S103, the user's request for a service from the CSP includes: S103-1: Before verifying the user with the CAP, the user's application obtains the current h(db') from the CAP; S103-2: The application retrieves h(dbs) stored locally by it, where dbs represents a log stored locally; h(dbs) requests a proof that the database log hash value satisfies the relationship, that is, h(dbs) < h(db'), and verifies the correctness of the extended proof; S103-3: The user requests and verifies that cert(user, pkuser) in db' satisfies the relationship h(db) < h(db') for the database log hash value; S103-4: The application verifies the correctness of the user's operation and obtains the user name, log hash value, user public key, and user private key information from the CAP; S103-5: The application requests and verifies whether the proof verifies that the log hash value satisfies h(dbs) < h(db) and h(db) < h(db'). If it is satisfied, the application replaces the locally stored h(dbs) with h(db'); S103-6: The application finds the public key pkCSP of the CSP in db' and requests to verify the correctness of the CSP log information proof; S103-7: The application uses pkCSP to encrypt the message for CSP and sends it to CSP; S103-8: The application randomly checks the log consistency.
4. The large-scale virtual node verification method in a cloud environment according to claim 3, wherein In step S104, the CSP application retrieves its h(dbs), h(db) and h(db) versions and performs the following checks: S104-1: Check whether h(dbs) < h(db) < h(db′) is satisfied; S104-2: Check whether the field information of CSP and pkCSP is correct in db′; S104-3: Obtain the public key pkuser of the user from db′ and request the correctness of its proof; S104-4: Decrypt the user's message and check the user's signature; If the above checks pass, it means that CSP agrees to the user's request and generates virtual resources for the user.
5. The large-scale virtual node verification method in a cloud environment according to claim 1, characterized in that In the step S105, the management scheme of the key and the password includes that the user's password is strongly random and the device key is used.
Citation Information
Patent Citations
A cross-domain authentication and fair audit deduplication cloud storage system based on a block chain
CN109829326A
Heterogeneous cross-domain authentication method based on trusted agent in cloud environment
CN110166444A