Remote attestation method, device, electronic device and storage medium based on consortium blockchain
By generating and verifying attribute certificates in the alliance chain system, external nodes can legally join the network and become trusted nodes, solving the problem that alliance chain cannot be verified remotely, and achieving strict control of the alliance chain system and privacy protection of the computing environment.
Patent Information
- Application Number
- CN202211617501.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-15
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2042-12-15
AI Technical Summary
In the prior art, the alliance chain cannot realize remote proofing, especially in a decentralized distributed network environment, computing nodes cannot perform effective trusted verification and network access control.
Through external nodes, apply for attribute certificates to third-party trusted institutions, generate and verify the network access request, and the consensus node verifies the legitimacy of the network access request, ensure that the external node becomes a trusted node in the alliance chain system, and realizes network access by creating and verifying transaction blocks.
It realizes strict control of the alliance chain system and privacy protection of external node computing environments, while simplifying the computing environment integrity verification process to ensure the security of trusted network access and transactions of nodes.
Smart Images

Figure CN116112215B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a remote attestation method, device, electronic device, and storage medium based on an alliance chain. Background Art
[0002] With the promotion of blockchain application scenarios, more and more fields are adopting consortium chains that support smart contracts to implement various business scenarios. In addition, the new era and new situation have put forward new requirements for information system security level protection. For important information systems, trusted computing technology must be used to support them to ensure their security.
[0003] In order to strengthen the trustworthiness requirements of cybersecurity level protection levels 1 to 4, it is necessary to include trustworthiness verification at each level and raise trustworthiness verification requirements for each link step by step. As an important information system, the alliance chain must meet the trustworthiness verification requirements for important information systems.
[0004] Remote attestation is central to building a trusted network. However, current remote attestation models are only suitable for centralized networks and are not suitable for decentralized scenarios. Computing nodes in decentralized distributed network environments, such as consortium blockchains, are still unable to implement remote attestation. Summary of the Invention
[0005] The present invention provides a remote attestation method, device, electronic device and storage medium based on a consortium chain, which are used to solve the defect in the prior art that the consortium chain cannot realize remote attestation.
[0006] The present invention provides a remote certification method based on an alliance chain, comprising: an external node sends an attribute certificate application package to a third-party trusted organization; the external node receives the attribute certificate of the third-party trusted organization, wherein the attribute certificate is generated by the third-party trusted organization according to the attribute certificate application package; the external node sends a network access request to a consensus node in the alliance chain system, wherein the network access request includes the attribute certificate; if the consensus node verifies the network access request and the legitimacy is passed, the external node becomes a trusted node in the alliance chain system.
[0007] According to a remote attestation method based on alliance chain provided by the present invention, after an external node joins the alliance chain system, it also includes: any trusted node in the alliance chain system creates a transaction; the transaction includes the AIK certificate of the trusted node that creates the transaction, the measurement values of each component of the current computing environment of the trusted node that creates the transaction, and the transaction data; the trusted node that creates the transaction broadcasts the transaction in the alliance chain system; other nodes in the alliance chain system verify the format of the transaction and forward the transaction; the consensus node in the alliance chain system obtains the transaction and verifies the content of the transaction; if the verification passes, the transaction is approved.
[0008] According to a remote certification method based on alliance chain provided by the present invention, if the consensus node verifies the network access request and the legitimacy is passed, the external node becomes a trusted node in the alliance chain system, including: the consensus node verifies the validity of the attribute certificate provided by the external node, and determines the issuer and validity period of the attribute certificate; the consensus node verifies whether the attributes contained in the attribute certificate provided by the external node meet the network access requirements, wherein the attribute set required for network access must be a subset of the attribute set in the attribute certificate; the consensus node verifies whether the attribute values of each attribute provided in the attribute certificate provided by the external node are consistent with the measurement value provided by the external node.
[0009] According to a remote proof method based on alliance chain provided by the present invention, after an external node joins the alliance chain system, it also includes: any consensus node in the alliance chain system creates an entry transaction block; the entry transaction block includes the AIK certificate of the consensus node that creates the entry transaction block, and the measurement values of each component in the current computing environment of the consensus node that creates the entry transaction block; the consensus node that creates the entry transaction block broadcasts the entry transaction block in the alliance chain system; the trusted node in the alliance chain system verifies the entry transaction block; if the verification is successful, the entry transaction block is received, and the local account book is updated based on the entry transaction block.
[0010] According to a remote proof method based on a consortium chain provided by the present invention, a trusted node in the consortium chain system verifies the entry transaction block, including: the trusted node verifies the format of the entry transaction block; the trusted node verifies the identity of the consensus node that creates the entry transaction block; the trusted node verifies the integrity of the computing environment of the consensus node that creates the entry transaction block.
[0011] According to a remote certification method based on a consortium chain provided by the present invention, the attribute certificate application package includes the identity certification key of the TPCM of the external node, the AIK public key, the EK certificate, the configuration information of each component of the computing environment and its measurement value, and the measurement storage log.
[0012] According to a remote attestation method based on a consortium chain provided by the present invention, the network access request also includes an AIK certificate and measurement values of various components of the current computing environment of the external node.
[0013] The present invention also provides a remote certification device based on the alliance chain, including: an external node module, used to send an attribute certificate application package to a third-party trusted organization; receiving the attribute certificate of the third-party trusted organization, wherein the attribute certificate is generated by the third-party trusted organization according to the attribute certificate application package; sending a network access request to the consensus node in the alliance chain system, wherein the network access request includes the attribute certificate; a consensus node module, used to make the external node a trusted node in the alliance chain system when the network access request is verified and the legitimacy is passed.
[0014] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements any of the above-mentioned remote certification methods based on the alliance chain.
[0015] The present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements any of the above-mentioned remote certification methods based on the alliance chain.
[0016] The present invention provides a remote attestation method, device, electronic device, and storage medium based on a consortium chain, wherein the remote attestation method based on a consortium chain includes: an external node sends an attribute certificate application package to a third-party trusted institution; the external node receives the attribute certificate of the third-party trusted institution, wherein the attribute certificate is generated by the third-party trusted institution based on the attribute certificate application package; the external node sends a network access request to a consensus node in the consortium chain system, wherein the network access request includes an attribute certificate; if the consensus node verifies the network access request and its legitimacy, the external node becomes a trusted node in the consortium chain system. Through the above-mentioned method, the present invention provides a trusted network access method for a consortium chain, which strictly controls the access to the consortium chain system while protecting the privacy of the computing environment configuration of the external node. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is a flowchart of an embodiment of a remote attestation method based on a consortium chain according to the present invention;
[0019] Figure 2 This is a schematic diagram of the structure of an embodiment of the alliance chain system of the present invention;
[0020] Figure 3 This is a structural diagram of an embodiment of a remote certification device based on a consortium chain of the present invention.
[0021] Figure 4 It is a structural diagram of an embodiment of an electronic device of the present invention. DETAILED DESCRIPTION
[0022] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0023] This invention provides a remote certification method based on alliance chain, please refer to Figure 1-Figure 2 , Figure 1 It is a flow chart of an embodiment of a remote attestation method based on a consortium chain of the present invention. Figure 2 This is a schematic diagram of the structure of an embodiment of the alliance chain system of the present invention. In this embodiment, the remote attestation method based on the alliance chain includes steps S110 to S140, each of which is as follows:
[0024] S110: The external node sends an attribute certificate application package to a third-party trusted organization.
[0025] like Figure 2 As shown, the alliance chain system includes a consensus node and several trusted nodes. Several trusted nodes can be divided into multiple organizations. Each organization can include multiple interconnected nodes, and each organization is connected to the consensus node separately.
[0026] Among them, the consensus nodes in the alliance chain system can connect to a third-party trusted institution (Certification Authority, CA) outside the alliance chain system. After passing the network access verification, the external node can become a trusted node in the alliance chain system.
[0027] In the alliance chain system, in order to achieve active trusted control, the consensus node needs to have a trusted computing platform, in which the protection components include the Trusted Platform Control Module (TPCM), the Trusted Software Base (TSB), etc.
[0028] The consensus node is a trusted node with TPCM. The node has a built-in TSB for node network verification, transaction collection, transaction verification, block construction, block verification, etc.
[0029] Trusted nodes are located within an organization and possess attribute certificates issued by the TPCM and an external CA. Trusted nodes are used to locally store consortium chain ledger data, construct transactions, verify transactions, and validate blocks. Trusted nodes can also become consensus nodes.
[0030] External nodes need to submit an attribute certificate application package to a third-party trusted organization for verification. Optionally, this package includes the external node's TPCM identity authentication key, AIK public key, EK certificate (cryptographic module certificate), configuration information and measurement values for each component of the computing environment, and measurement storage logs. Measurement values include, but are not limited to, TPCM information, hardware information, BIOS, operating system kernel, operating system, and required application information.
[0031] The EK certificate is also called the endorsement certificate. A TCM can only have one EK certificate in its lifetime. The EK certificate is the unique identifier of the TCM chip.
[0032] The AIK certificate, issued by the CA, certifies that the AIK key has been generated within the TCM and bound to the TCM's EK key. The AIK key is generated from the EK key. The AIK certificate can only be used for signing, not encryption and decryption, and can only be used to sign internal TCM information to prevent attackers from cracking the AIK.
[0033] S120: The external node receives the attribute certificate of the third-party trusted authority.
[0034] Attribute certificates are generated by a third-party trusted organization based on the attribute certificate application package.
[0035] Outside the consortium chain system, an external CA generates AIK certificates and attribute certificates for computing nodes. An attribute certificate contains an attribute set mapped from the node computing environment. The attribute set includes several computing environment attributes. Except for the trusted root attribute corresponding to the TPCM, the remaining attributes have attribute values. The attribute values are the measurement values obtained by the TPCM measuring the computing component corresponding to the attribute.
[0036] In the attribute certificate, different components are mapped to corresponding attributes according to the "component configuration information-attribute" mapping table. Attributes have dependencies based on the trust chain, specifically:
[0037] (TPCM attribute → BIOS attribute key-value pair);
[0038] (BIOS attributes → operating system kernel attributes key-value pair);
[0039] (OS kernel attribute → OS attribute key-value pair);
[0040] (OS Property → (Application Property 1 key-value pair, Application Property 2 key-value pair, ..., Application Property n key-value pair))
[0041] A key-value pair represents an attribute-attribute value. In each pair, the component corresponding to the previous attribute measures the component corresponding to the next attribute, resulting in the measurement value of the component corresponding to the next attribute. In the last pair, all applications are parallel and are measured by the operating system.
[0042] In this embodiment, attributes include attribute names and attribute values. Attribute names correspond to components in the computing environment, and attribute values correspond to the component's measurement values. The attribute values in the attribute certificate serve as a baseline for determining the integrity of the node's computing environment. The attribute values are obtained by the CA after performing a consistency check between the computing environment's measurement values and the stored measurement log.
[0043] Specifically, the steps for a third-party trusted authority to generate an attribute certificate may include:
[0044] (1) Verify the validity of the certificate information sent by the external node, and generate an AIK certificate if it is valid;
[0045] (2) The configuration information of each component of the computing environment sent by the external node is used to obtain the attribute set of the node computing environment according to the local "component configuration information-attribute" mapping table, and each attribute in the attribute set is assigned a value using the measurement value of the component.
[0046] (3) Construct an attribute certificate, sign the attribute certificate with the local private key, encrypt the AIK certificate and attribute certificate with the node's AIK public key, and send them together with the "component configuration information-attribute" mapping table to the node;
[0047] (4) The external node uses the AIK private key to decrypt and obtain the AIK certificate and attribute certificate.
[0048] Among them, the AIK certificate is used to verify the identity of the node TPCM, and the attribute certificate is used to verify the integrity of the node computing environment. The attribute value can be used as the benchmark value of the current node computing environment.
[0049] S130: The external node sends a network access request to the consensus node in the alliance chain system, where the network access request includes an attribute certificate.
[0050] Optionally, the network access request further includes an AIK certificate and measurement values of various components of the current computing environment of the external node.
[0051] External nodes will provide AIK certificates, attribute certificates, and measurement values of various components of the current computing environment for verification by the consortium chain system as required by the consortium chain system. If the external node does not have the attributes required by the consortium chain system, it can apply to the CA again to renew the attribute certificate.
[0052] When a consensus node in the consortium chain system receives a network access request from an outsourced node, it verifies the validity of the AIK certificate to determine whether the external node has a legitimate identity. If the verification fails, the node is denied network access.
[0053] S140: If the consensus node verifies the network access request and its legitimacy, the external node becomes a trusted node in the alliance chain system.
[0054] In some embodiments, the step of the consensus node verifying the network access request specifically includes:
[0055] (1) The consensus node verifies the validity of the attribute certificate provided by the external node and determines the issuer and validity period of the attribute certificate; the attribute certificate must be issued by the CA and must not have expired.
[0056] (2) The consensus node verifies whether the attributes contained in the attribute certificate provided by the external node meet the network access requirements, where the attribute set required for network access must be a subset of the attribute set in the attribute certificate;
[0057] (3) The consensus node verifies whether the attribute values of each attribute provided in the attribute certificate provided by the external node are consistent with the measurement value provided by the external node.
[0058] If all the above verifications are passed, the subsequent steps will be carried out; otherwise, the network access will be denied.
[0059] Alternatively, the consensus node in the consortium chain system creates a network entry transaction that includes the external node's AIK certificate, attribute certificate, and measurement values for each component in the current computing environment. Alternatively, the consensus node in the consortium chain system creates a block containing the aforementioned network entry transaction. The block includes the consensus node's AIK certificate and measurement values for each component in the current computing environment. The consensus node broadcasts the block within the consortium chain system.
[0060] According to a remote attestation method based on a consortium chain provided by the present invention, the steps after an external node joins the consortium chain system further include:
[0061] Any trusted node in the consortium chain system creates a transaction; the transaction includes the AIK certificate of the trusted node that creates the transaction, the measurement values of the various components of the current computing environment of the trusted node that creates the transaction, and the transaction data; the trusted node that creates the transaction broadcasts the transaction in the consortium chain system; other nodes in the consortium chain system verify the format of the transaction and forward the transaction; the consensus node in the consortium chain system obtains the transaction and verifies the content of the transaction; if the verification passes, the transaction is approved.
[0062] Computing nodes join the consortium blockchain system and interact with other nodes by constructing transactions. A node undergoes an identity verification process when conducting transactions. However, identity verification no longer requires the involvement of a CA. Consensus nodes collect the transaction and perform the following verification:
[0063] (1) Verify that the transaction format is correct.
[0064] (2) Verify the node identity, obtain the AIK certificate from the ledger, and compare it with the AIK certificate in the transaction. If they are consistent, the identity is valid.
[0065] (3) Verify the integrity of the node computing environment, obtain the attribute certificate from the ledger, and compare it with the measurement values of each component of the node computing environment in the transaction. If they are consistent, it means that the node computing environment is valid.
[0066] If all the above verifications are passed, the subsequent process will be carried out; otherwise, the transaction will be rejected.
[0067] According to a remote attestation method based on a consortium chain provided by the present invention, the steps after an external node joins the consortium chain system further include:
[0068] Any consensus node in the alliance chain system creates an entry transaction block; the entry transaction block includes the AIK certificate of the consensus node that creates the entry transaction block and the measurement values of each component in the current computing environment of the consensus node that creates the entry transaction block; the consensus node that creates the entry transaction block broadcasts the entry transaction block in the alliance chain system; the trusted node in the alliance chain system verifies the entry transaction block; if the verification is successful, the entry transaction block is received and the local ledger is updated based on the entry transaction block.
[0069] The steps for trusted nodes in the alliance chain system to verify the incoming transaction blocks specifically include:
[0070] (1) Trusted nodes verify the format of incoming transaction blocks.
[0071] (2) The trusted node verifies the identity of the consensus node that created the transaction block; obtains the AIK certificate of the consensus node from the alliance chain ledger and compares it with the AIK certificate of the consensus node in the block. If they are consistent, it means that the identity of the consensus node is valid.
[0072] (3) The trusted node verifies the integrity of the computing environment of the consensus node that created the transaction block. The trusted node obtains the attribute certificate of the consensus node from the alliance chain ledger and determines whether the attribute values of the components of the computing environment of the consensus node in the attribute certificate are consistent with the measurement values of the components of the computing environment of the consensus node in the block. If they are consistent, it means that the computing environment of the consensus node is trustworthy.
[0073] (4) Verify each transaction.
[0074] If all the above verifications are passed, the block is accepted and the local ledger is updated; otherwise, the block is rejected.
[0075] In summary, this embodiment provides a remote attestation method based on the alliance chain, including: an external node sends an attribute certificate application package to a third-party trusted institution; the external node receives the attribute certificate of the third-party trusted institution, wherein the attribute certificate is generated by the third-party trusted institution based on the attribute certificate application package; the external node sends a network access request to the consensus node in the alliance chain system, wherein the network access request includes the attribute certificate; if the consensus node verifies the network access request and the legitimacy is passed, the external node becomes a trusted node in the alliance chain system. Through the above method, the present invention provides a trusted network access method for alliance chains, which strictly controls the access to the alliance chain system while ensuring the privacy of the external node computing environment configuration; and simplifies the computing environment integrity verification process, which only needs to be compared with the attribute value in the attribute certificate.
[0076] The following describes the remote attestation device based on the alliance chain provided by the present invention. The remote attestation device based on the alliance chain described below and the remote attestation method based on the alliance chain described above can refer to each other.
[0077] See also Figure 3 , Figure 3 It is a structural diagram of an embodiment of a remote certification device based on a consortium chain of the present invention. In this embodiment, the remote certification device based on the consortium chain includes: an external node module 310 and a consensus node module 320.
[0078] The external node module 310 is used to send an attribute certificate application package to a third-party trusted agency; receive the attribute certificate of the third-party trusted agency, where the attribute certificate is generated by the third-party trusted agency based on the attribute certificate application package; and send a network access request to the consensus node in the alliance chain system, where the network access request includes the attribute certificate.
[0079] The consensus node module 320 is used to make the external node a trusted node in the alliance chain system when the network access request is verified and the legitimacy is passed.
[0080] In some embodiments, the remote attestation device based on the alliance chain also includes a trusted node module, and the trusted node module includes a trusted node in the alliance chain system.
[0081] Among them, any trusted node in the alliance chain system creates a transaction; the transaction includes the AIK certificate of the trusted node that creates the transaction, the measurement values of each component of the current computing environment of the trusted node that creates the transaction, and the transaction data; the trusted node that creates the transaction broadcasts the transaction in the alliance chain system; other nodes in the alliance chain system verify the format of the transaction and forward the transaction; the consensus node in the alliance chain system obtains the transaction and verifies the content of the transaction; if the verification passes, the transaction is approved.
[0082] In some embodiments, the consensus node module 320 includes a consensus node in a consortium chain system.
[0083] Among them, the consensus node verifies the validity of the attribute certificate provided by the external node, determines the issuer and validity period of the attribute certificate; the consensus node verifies whether the attributes contained in the attribute certificate provided by the external node meet the network access requirements, where the attribute set required for network access must be a subset of the attribute set in the attribute certificate; the consensus node verifies whether the attribute values of each attribute provided in the attribute certificate provided by the external node are consistent with the measurement value provided by the external node.
[0084] Optionally, any consensus node in the alliance chain system creates an entry transaction block; the entry transaction block includes the AIK certificate of the consensus node that creates the entry transaction block, and the measurement values of each component in the current computing environment of the consensus node that creates the entry transaction block; the consensus node that creates the entry transaction block broadcasts the entry transaction block in the alliance chain system; the trusted node in the alliance chain system verifies the entry transaction block; if the verification is successful, the entry transaction block is received, and the local ledger is updated based on the entry transaction block.
[0085] Optionally, the trusted node module is also used to: verify the format of the on-line transaction block; verify the identity of the consensus node that created the on-line transaction block; and verify the integrity of the computing environment of the consensus node that created the on-line transaction block.
[0086] In some embodiments, the attribute certificate application package includes the identity authentication key of the TPCM of the external node, the AIK public key, the EK certificate, the configuration information of each component of the computing environment and its measurement values, and the measurement storage log.
[0087] In some embodiments, the network access request further includes an AIK certificate and measurement values of various components of the current computing environment of the external node.
[0088] The present invention also provides an electronic device, see Figure 4 , Figure 4This is a schematic diagram of the structure of an embodiment of an electronic device according to the present invention. In this embodiment, the electronic device may include a memory 420, a processor 410, and a computer program stored in the memory 420 and executable on the processor 410. When the computer program is executed by the processor 410, the remote attestation method based on the consortium chain provided by the aforementioned methods is implemented.
[0089] Optionally, the electronic device may further include a communication bus 430 and a communication interface (CommunicationsInterface) 440, wherein the processor 410, the communication interface 440, and the memory 420 communicate with each other via the communication bus 430. The processor 410 may call the logic instructions in the memory 420 to execute a remote attestation method based on the alliance chain, which includes:
[0090] The external node sends an attribute certificate application package to a third-party trusted agency; the external node receives the attribute certificate from the third-party trusted agency, where the attribute certificate is generated by the third-party trusted agency based on the attribute certificate application package; the external node sends a network access request to the consensus node in the alliance chain system, where the network access request includes the attribute certificate; if the consensus node verifies the network access request and its legitimacy is passed, the external node becomes a trusted node in the alliance chain system.
[0091] In addition, the logic instructions in the above-mentioned memory 420 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0092] On the other hand, the present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the remote proof method based on the alliance chain provided by the above methods. Its steps and principles have been introduced in detail in the above methods and will not be repeated here.
[0093] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0094] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.
[0095] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A remote attestation method based on alliance chain, characterized in that: include: The external node sends an attribute certificate application package to a third-party trusted organization; The external node receives the attribute certificate of the third-party trusted institution, wherein the attribute certificate is generated by the third-party trusted institution according to the attribute certificate application package; The external node sends a network access request to the consensus node in the alliance chain system, where the network access request includes an attribute certificate; If the consensus node verifies the network access request and its legitimacy, the external node becomes a trusted node in the alliance chain system; After the external node joins the alliance chain system, the system further includes: Any consensus node in the consortium chain system creates an entry transaction block; the entry transaction block includes the AIK certificate of the consensus node that created the entry transaction block and the measurement values of each component in the current computing environment of the consensus node that created the entry transaction block; The consensus node that creates the network transaction block broadcasts the network transaction block in the alliance chain system; The trusted node in the alliance chain system verifies the network transaction block; if the verification is successful, the trusted node receives the network transaction block and updates the local account book based on the network transaction block.
2. The remote attestation method based on the alliance chain according to claim 1 is characterized in that: After the external node joins the alliance chain system, the system further includes: Any trusted node in the consortium chain system creates a transaction; the transaction includes the AIK certificate of the trusted node that creates the transaction, the measurement values of various components of the current computing environment of the trusted node that creates the transaction, and the transaction data; The trusted node that created the transaction broadcasts the transaction in the alliance chain system; Other nodes in the consortium chain system verify the format of the transaction and forward the transaction; The consensus node in the alliance chain system obtains the transaction and verifies the content of the transaction; if the verification passes, the transaction is approved.
3. The remote attestation method based on the alliance chain according to claim 1 is characterized in that: If the consensus node verifies the legitimacy of the network access request, the external node becomes a trusted node in the alliance chain system, including: The consensus node verifies the validity of the attribute certificate provided by the external node and determines the issuer and validity period of the attribute certificate; The consensus node verifies whether the attributes contained in the attribute certificate provided by the external node meet the network access requirements, wherein the attribute set required for network access must be a subset of the attribute set in the attribute certificate; The consensus node verifies whether the attribute value of each attribute provided in the attribute certificate provided by the external node is consistent with the measurement value provided by the external node.
4. The remote attestation method based on the alliance chain according to claim 3 is characterized in that: The trusted nodes in the alliance chain system verify the incoming transaction block, including: The trusted node verifies the format of the incoming transaction block; The trusted node verifies the identity of the consensus node that created the transaction block on the network; The trusted node verifies the integrity of the computing environment of the consensus node that creates the on-network transaction block.
5. The remote attestation method based on alliance chain according to claim 1, characterized in that: The attribute certificate application package includes the identity authentication key of the TPCM of the external node, the AIK public key, the EK certificate, the configuration information of each component of the computing environment and its measurement value, and the measurement storage log.
6. The remote attestation method based on alliance chain according to claim 1, characterized in that: The network access request also includes an AIK certificate and measurement values of various components of the current computing environment of the external node.
7. A remote certification device based on alliance chain, characterized in that: include: The external node module is configured to send an attribute certificate application package to a third-party trusted institution; receive an attribute certificate from the third-party trusted institution, wherein the attribute certificate is generated by the third-party trusted institution based on the attribute certificate application package; and send a network access request to a consensus node in the alliance chain system, wherein the network access request includes the attribute certificate. A consensus node module, configured to make the external node a trusted node in the alliance chain system when the network access request is verified and the legitimacy is passed; Among them, any consensus node in the alliance chain system creates an entry transaction block; the entry transaction block includes the AIK certificate of the consensus node that creates the entry transaction block, and the measurement values of each component in the current computing environment of the consensus node that creates the entry transaction block; the consensus node that creates the entry transaction block broadcasts the entry transaction block in the alliance chain system; the trusted node in the alliance chain system verifies the entry transaction block; if the verification is successful, the entry transaction block is received, and the local account book is updated based on the entry transaction block.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the remote attestation method based on the alliance chain as described in any one of claims 1 to 6 is implemented.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the remote attestation method based on the alliance chain as described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Cross-domain access control method and system, storage medium, computer equipment and terminal
CN112532591A
Alliance chain distributed certificate management method
CN114219487A