Method for establishing trust relationship of entity identity of alliance chain based on hierarchical identity-based cryptography
By introducing hierarchical identity-based cryptography, public identity information of the consortium blockchain system is constructed, and private keys are directly generated. This solves the problem of complex certificate chain maintenance in traditional asymmetric cryptography, achieves efficient entity identity and trust relationship management, and adapts to the hierarchical structure of the consortium blockchain system.
Patent Information
- Application Number
- CN202310319833.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-29
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2043-03-29
AI Technical Summary
In existing technologies, the establishment of trust relationships between consortium blockchain entities based on traditional asymmetric public-key cryptography relies on the maintenance and management of certificate chains, which leads to complexity and inefficiency and makes it difficult to adapt to hierarchical identity trust relationship management.
By employing hierarchical identity-based cryptography, a hierarchical identity-based cryptographic system is created by constructing public identity information for each entity in the consortium blockchain system. This avoids the use of public key certificates, directly generates and manages private keys, adapts to the hierarchical identity structure of the consortium blockchain system, and achieves efficient management of entity identities and trust relationships.
It enables identity trust management without a certificate chain, efficiently transmits private keys from upper-layer entities to lower-layer entities, simplifies the maintenance and management of the certificate chain, and improves the efficiency and flexibility of the consortium blockchain system.
Smart Images

Figure CN116346468B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of data processing, and particularly relates to a method for establishing an identity trust relationship of a consortium chain entity based on a hierarchical identity-based cryptography. BACKGROUND
[0002] Consortium chain technology is the core and key to realizing the industrial application of blockchain technology at present, and plays a basic and supporting role in realizing the improvement of industrial efficiency, the reduction of industrial cost and the guarantee of business trust and fairness. Entity trust system, smart contract technology and distributed ledger technology are the three core elements of consortium chain technology, and the entity trust system of the consortium chain is the technical infrastructure for solving entity identity authentication, authorized access control and transaction verification within the system. Building an efficient, trustworthy and practical entity trust system for the consortium chain is an important technical content of consortium chain technology research and development.
[0003] At present, various consortium chain platforms or technologies practice PKI (Public Key Infrastructure) to solve the entity identity authentication and entity identity trust relationship management within the system. The mechanism for establishing the entity trust relationship within the consortium chain based on traditional asymmetric public key cryptography can better solve the entity trust problem within the system. However, this implementation scheme relies heavily on certificates, that is, each entity in the system needs to have a certificate that can prove the legality of its own identity in addition to a public-private key pair, that is, the entity proves the legality of its own identity by transmitting a verifiable public key corresponding to its own private key to the communication counterpart.
[0004] Verifying the legality of the entity public key is the key to solving the trust problem by implementing traditional asymmetric public key cryptography, that is, the independent public key information does not reveal any information about the entity identity, and an additional proof document is needed to prove the relationship between the public key information and a certain entity (identity). The additional information is a certificate that can prove the legality of the public key and the association between a certain public key and a specific entity. First, using a certificate requires a corresponding support mechanism to create and manage the certificates of each entity; second, for a hierarchical structure, trust is usually cascaded, that is, the upper entity in the hierarchical structure signs the certificate of its own child entity level by level, thereby creating a certificate chain to maintain the identity trust relationship.
[0005] Creating and maintaining the certificate chain of the identity trust relationship, as well as managing the storage, use and revocation of the certificates of each entity on the certificate chain, are the main problems and challenges faced by the traditional asymmetric cryptography-based entity identity management and identity trust relationship management. SUMMARY
[0006] In order to solve the above problems, the application proposes a method for establishing an identity trust relationship of an alliance chain entity based on a hierarchical identity-based cryptography, which is used to solve and realize the identity and trust relationship management of the entity in the alliance chain system, avoid the use of public key certificates, and does not need to maintain a certificate chain to manage the trust relationship of the identity.
[0007] To achieve the above purpose, the technical solution adopted by the application is as follows: a method for establishing an identity trust relationship of an alliance chain entity based on a hierarchical identity-based cryptography, comprising the following steps:
[0008] S10, constructing public identity information of each entity in the alliance chain system, based on the hierarchical identity relationship formed by each entity in the alliance chain system and adapting the entity identity requirement in the hierarchical identity-based cryptography system, constructing a hierarchical identity identifier suitable for each entity in the alliance chain system to construct the public hierarchical identity information of each entity in the alliance chain system;
[0009] S20, creating a private key generation authority of the hierarchical identity-based cryptography system by using the constructed public identity information of all entities in the alliance chain system, extracting the private keys of all agencies in the alliance chain system, and delegating the private keys of all nodes, business terminals and users belonging to each agency by the private key of each agency;
[0010] S30, realizing the identity trust relationship establishment of each entity in the system by using the public identity information and the corresponding private key of each entity in the alliance chain system, and providing the required cryptographic services for the business transactions based on the alliance chain.
[0011] Further, in the step S10, the hierarchical identity-based cryptography is introduced to adapt to the hierarchical identity relationship formed by each entity in the alliance chain system, and the public identity information of the entity required by the hierarchical identity-based cryptography system is created, which includes:
[0012] The identity public information of the root domain: the root domain is a private key generator in the identity-based cryptography, and a public identity information is introduced for the root domain;
[0013] The public identity information of the agency domain: the agency domain is directly subordinate to the root domain, and the identity information of the agency domain is the local identity identifier of the agency;
[0014] The public identity information of the node: the identity information of the node is constructed by integrating the identity information of the root domain, the agency domain and the node domain, and the identity information of the node domain is the local identity identifier of the node;
[0015] The public identity information of the business terminal: the business terminal connects a certain node of the agency in the alliance chain to request the execution of the contract function of the deployed contract on the chain, and accepts the transaction receipt returned from the node on the chain, so the SDK can be used to suffix the different business terminal numbers (serial numbers) connected to the same node as the local identity identifier of the business terminal in the entity hierarchy;
[0016] and the public identity information of the business personnel: the business personnel is regarded as a sub-entity of a node on the chain, i.e., from the perspective of the hierarchy, the business personnel and the business terminal are at the same level in the entity hierarchy; the public identity information of the business personnel can select a unique identity identifier representing the business personnel as the local identity identifier of the business personnel in the entity hierarchy.
[0017] Further, the root private key generator in the hierarchical identity-based cryptography system is created by the entire entity hierarchy relationship and the root domain identity public information in the consortium chain system; the private key of the agency is extracted from the public identity information of the agency; the private key of the node is extracted from the public identity information of the node; the private key of the business terminal is extracted from the public identity information of the business terminal; the private key of the business personnel is extracted from the public identity information of the business personnel. Among them, each agency in the consortium chain system can be delegated to extract the private keys of all nodes, business terminals, and users under its jurisdiction.
[0018] Further, the asymmetric bilinear pair required by the hierarchical identity-based cryptography is selected by the entire agency constituting the consortium chain, and the public parameters of the hierarchical identity-based cryptography system and the master key of the system root private key generator are created based on the entire entity hierarchy relationship and the root domain identity public information in the consortium chain system. The master key will be used to extract the private keys of all entities in the consortium chain system.
[0019] Further, the private key of the agency is extracted from the public identity information of the agency: according to the construction mechanism of the entity public identity information determined by the hierarchical identity-based cryptography system, the public identity information of each agency in the consortium chain is constructed, and the root private key generator is requested to extract the private key of the corresponding agency; because the agency is the highest level entity in the consortium chain system, the private key of such entity can only be extracted by the root private key generator, and there is no upper entity that can be delegated by the root private key generator to extract on behalf of it.
[0020] Further, the private key of the node is extracted from the public identity information of the node: the public identity information of each node in each agency is constructed, and the root private key generator is requested to extract the private key of each corresponding node; because each node in the consortium chain corresponds to a certain agency, i.e., the agency entity is the upper entity of the node entity, the root private key generator can authorize the agency entity to extract the private key of the node belonging to the corresponding agency. This authorized private key extraction usually requires the agency to use its own private key to construct the private key of the corresponding node according to the local identity identifier of the sub-entity, i.e., the node. The authorized private key extraction needs to refer to the delegation operation regulations of the selected hierarchical identity-based cryptography system to execute.
[0021] Further, for the public identity information of the business terminal, the private key of the business terminal is extracted: based on the public identity information constructed by the alliance chain organization and the node, and the selected rules of the identity information of the business terminal and the business personnel defined by each organization, the public identity information of the business terminal affiliated to a node of an organization is constructed, and the root private key generator is requested to extract the private key of each business terminal, or the private key of the descendant entity business terminal is extracted by the upper entity of the business terminal, i.e. the organization or the node, according to the delegation of the root private key generator.
[0022] Further, for the public identity information of the business personnel, the private key of the business personnel is extracted: the private key extraction of the business personnel in the organization is the same as the private key extraction of the business terminal, the root private key generator is requested to extract the private key of the corresponding business personnel, or the private key of each business personnel is extracted by the ancestor entity of the business personnel, i.e. the organization or the node, according to the delegation of the root private key generator.
[0023] The beneficial effects of adopting the technical solution are:
[0024] The present application introduces an identity-based asymmetric cryptography to solve the problems faced by the traditional asymmetric cryptography in realizing the identity trust relationship management, i.e. the maintenance of the certificate chain, the management and use of the certificate, and other complex tasks, i.e. it is proposed to solve the entity identity management in the alliance chain and realize the identity trust relationship management between entities by practicing identity-based cryptography, and secondly, it is proposed to introduce hierarchical identity-based cryptography to adapt to the hierarchical identity structure of the entities in the alliance chain, efficiently solve the private key extraction of the upper entity to the lower entity, and well realize the transmission of the identity trust relationship in the hierarchical structure. The present application solves and realizes the entity identity and trust relationship management in the alliance chain based on the hierarchical identity-based cryptography, avoids the use of public key certificates, and does not need to maintain the certificate chain to manage the identity trust relationship. BRIEF DESCRIPTION OF DRAWINGS
[0025] Figure 1 A flowchart of the method for establishing the identity trust relationship of the alliance chain entity based on the hierarchical identity-based cryptography of the present application is shown.
[0026] Figure 2 A schematic diagram of the construction of the public identity information of each entity in the hierarchical alliance chain system in the embodiment of the present application is shown. DETAILED DESCRIPTION
[0027] In order to make the purpose, technical solution and advantages of the present application clearer, the present application will be further described below in combination with the drawings.
[0028] In the embodiment, as shown in Figure 1 The present application proposes a method for establishing the identity trust relationship of the alliance chain entity based on the hierarchical identity-based cryptography, which includes the following steps:
[0029] S10, constructing public identity information of each entity in the consortium chain system, constructing a hierarchical identity identifier suitable for each entity in the consortium chain system based on the hierarchical identity relationship formed by each entity in the consortium chain system and adapting the entity identity requirement in the hierarchical identity-based cryptography system, to construct the hierarchical identity information of each entity in the consortium chain system which is publicly disclosed;
[0030] S20, using the constructed public identity information of all entities in the consortium chain system, creating a private key generation authority of the hierarchical identity-based cryptography system, extracting the private keys of all agencies in the consortium chain system, and each agency appointing the private keys of all subordinate nodes, business terminals and users according to its own private key;
[0031] S30, using the public identity information and the corresponding private key of each entity in the consortium chain system, realizing the establishment of the identity trust relationship of each entity in the system, and providing the required cryptographic services for the business transactions based on the consortium chain.
[0032] As an optimization scheme of the above embodiment, the identity-based cryptography takes the public identity information of the user as the public key of the user in the system. These public information can be the taxpayer identification number, enterprise domain name, enterprise name, etc. of the agency (enterprise), and for natural persons, it can be an ID number, an email address, etc. That is, the selection freedom of the public identity information of the entity in the identity-based cryptography system is large, and the form that can be selected is also various. However, in order to ensure the easy scalability, easy manageability and easy operability of the system implementation, the following domain construction method is proposed to construct the public identity information of the entity in the consortium chain. In the step S10, based on the hierarchical identity relationship formed by each entity in the consortium chain system, the hierarchical relationship of the identity-based cryptography is adapted, and the public identity information of each entity in the consortium chain system is designed and constructed, including:
[0033] The identity public information of the root domain: the root domain is the private key generator in the identity-based cryptography, a public identity information is introduced for the root domain, and a common main domain is created for all agencies in the consortium chain. The public identity information can be selected independently, such as selecting "chain", "industry", "network", "consortium", etc. are appropriate, or according to the type of business served by the corresponding consortium chain, selecting "finance", "logistics", "health", etc. are also appropriate; Figure 2 An example of constructing the public identity information of each entity in a consortium chain system is shown in the following table. The public identity information of the root domain is selected as "chain". For the sake of brevity, only the public identity information of one agency connected to the root domain, the nodes (or departments) belonging to the agency, and the business terminals or business personnel connected to the nodes are shown in the figure.
[0034] Public identity information of the agency domain: that is, selecting the local identity identifier of the agency identity information, including using the taxpayer identification number of the agency, the name of the enterprise, and of course, it can also be simply selected as the identity identifier information such as "agency1",..., "agencyi"; integrating the two parts of the public identity information of the root domain and the agency domain, and constructing the public identity information of each agency, such as Figure 2 The agency identity information connected with the root domain is "agency1.chain", wherein "agency1" is the local identity identifier of the corresponding agency, and "chain" is the non-local identity identifier of the corresponding agency.
[0035] Public identity information of the node: integrated identity information of the root domain, the agency domain and the node domain, and the identity information of the node domain is the local identity identifier of the node, which can be selected as the IP address of the node, the host number of the node or other codes; for example, Figure 2 In the example of the agency "agency1.chain", the local identity identifiers of the two nodes are selected as "A" and "B", and the public identity information of the two nodes is "A.agency1.chain" and "B.agency1.chain". Of course, if the IP address of the node is selected as the local identity identifier of the node, the public identity information of the corresponding node is "127_0_0_1.agency1.chain" (here, the IP address of the node is 127.0.0.1).
[0036] Public identity information of the business terminal: the business terminal connects a node of the agency in the alliance chain to request the execution of the contract function of the deployed contract on the chain, and accepts the transaction receipt returned from the node on the chain; considering that the function implementation of the business terminal is based on the connection of the blockchain SDK to connect the node on the blockchain, the public identity information of the business terminal can be selected as "sdk", "web", "dapp", and the like, for example, Figure 2 "sdki.A.agency1.chain" and "sdkm.B.agency1.chain" shown in the above example are two business terminals connected by two departments "A" and "B" (or two nodes "A" and "B" belonging to the agency "agency1") of the agency "agency1".
[0037] Public identity information of business personnel: based on identity-based cryptography to realize identity management of alliance chain entities, all entities involved need to be uniquely identified by their respective public identity identifiers, and the operations that business personnel can perform are realized through a certain business terminal, that is, business transactions are triggered through a business terminal, but considering that business personnel usually do not bind business execution to business terminals (business personnel can perform operations on multiple different business terminals), business personnel are not regarded as sub-entities of a certain business terminal, but are regarded as sub-entities of a certain node (affiliated to a certain business department) on the chain; that is, from the perspective of the hierarchical structure, business personnel and business terminals are at the same level in the entity hierarchical structure; for the public identity information of business personnel, a unique identity identifier representing the business personnel can be selected, such as the business personnel's work number, ID number, or other identifiers that can uniquely identify the business personnel within the organization, etc. Figure 2 For example, the local identity identifiers of two business personnel affiliated to nodes "A" and "B" in agency "agency1" are "pj" and "qn", and the public identity information of the two business personnel is "pj.A.agency1.chain" and "qn.B.agency1.chain", respectively.
[0038] Because in the alliance chain application, inter-agency business transactions are realized through the interaction between nodes on the chain, that is, the connection between entities across departments ends at the nodes of the agency, and the connection or communication across departments will not appear entities such as business terminals and business personnel; when selecting and constructing the public identity identifier information of entities in the alliance chain system, the identity identifiers of the following three domains of the relevant entities should be considered and selected, that is, the root domain, the agency domain, and the node domain. As for the local identity identifiers of business terminals and business personnel, different agencies can perform independent construction methods.
[0039] As an optimization scheme of the above embodiment, in the step S20, the public identity information of each entity constructed for the alliance chain system is used to generate the corresponding private key of each entity in the hierarchical identity-based cryptography system, including: for the public identity information of the root domain, creating a root private key generator; for the public identity information of the agency domain, extracting the private key of the agency; for the public identity information of the node, extracting the private key of the node; for the public identity information of the business terminal, extracting the private key of the business terminal; for the public identity information of the business personnel, extracting the private key of the business personnel.
[0040] Preferably, for the root domain identity public information, a root private key generator is created: all institutions constituting the consortium chain jointly negotiate to select the asymmetric bilinear pair required by the hierarchical identity-based cryptography, and create the public parameters of the hierarchical identity-based cryptography system jointly negotiated by all institutions and the master key of the system root private key generator, which will be used to extract the private keys of all entities in the consortium chain system.
[0041] Preferably, for the public identity information of the institution domain, the private key of the institution is extracted: the public identity information of each institution in the consortium chain is constructed according to the construction mechanism of the entity public identity information determined by the hierarchical identity-based cryptography system, and the root private key generator is requested to extract the private key of the corresponding institution; since the institution is the highest level entity in the consortium chain system, the private key of such entity can only be extracted by the root private key generator, and there is no upper entity that can be delegated by the root private key generator to extract the private key of the institution entity.
[0042] Preferably, for the public identity information of the node, the private key of the node is extracted: the public identity information of each node in each institution is constructed, and the root private key generator is requested to extract the private key of each node; because each node in the consortium chain corresponds to a certain institution, i.e. the institution entity is the upper entity of the node entity, the root private key generator can authorize the institution entity to extract the private keys of all nodes belonging to the corresponding institution, and this authorized private key extraction usually uses the private key of the institution to construct the private key of the corresponding node according to the local identity of the child entity-node, and the authorized private key extraction needs to refer to the delegation operation regulations of the selected hierarchical identity-based cryptography system.
[0043] Preferably, for the public identity information of the business terminal, the private key of the business terminal is extracted: based on the public identity information constructed by the consortium chain institutions and nodes, and the selected rules of the identity information of the business terminal and business personnel defined by each institution, the public identity information of the business terminal belonging to a node of a certain institution is constructed, and the private key of each business terminal can be requested to be extracted from the root private key generator, or the private key of the child entity-business terminal can be extracted by the upper entity-institution and node to which each business terminal belongs.
[0044] Preferably, for the public identity information of the business personnel, the private key of the business personnel is extracted: the private key extraction of the business personnel in the institution is the same as the private key extraction of the business terminal, which can request the root private key generator to extract the private key of the corresponding business personnel, or the ancestor entity-institution or node of the business personnel can be delegated by the root private key generator to extract the private key of the business personnel under its jurisdiction.
[0045] The application introduces an identity-based password based on public identity information into the operation of a consortium chain to serve the management of entity identity in the consortium chain, in particular, introduces a hierarchical identity-based password to adapt to the hierarchical identity relationship formed by each entity (chain root, organization, node, business terminal and business operator) in the consortium chain system, practices identity-based password service, and better serves the identity trust relationship management of entities in the consortium chain system and the related security requirements of business transactions. It is proposed that based on the hierarchical identity-based password system, the upper entity has the ability to extract the private key of its descendant entity, which solves the problem that the consortium chain system creates the identity credential information (i.e. the private key corresponding to each descendant entity, because the public key is public identity information) of its own descendant entity (the nodes, business terminals and business operators owned) by the organization entity, and more efficiently and flexibly establishes and manages the entity identity trust relationship in the consortium chain system.
[0046] The basic principles, main features and advantages of the application are shown and described above. Those skilled in the art should understand that the application is not limited by the above examples, and the above examples and descriptions in the specification are only to illustrate the principles of the application. Without departing from the spirit and scope of the application, various changes and improvements can be made to the application, and these changes and improvements all fall within the scope of the claimed application. The scope of protection of the application is defined by the appended claims and their equivalents.
Claims
1.A method for establishing a trust relationship of an entity identity based on a hierarchical identity-based cryptography in a consortium chain, characterized in that, The method comprises the steps of: S10, constructing public identity information of each entity in the alliance chain system, constructing a hierarchical identity identifier suitable for each entity in the alliance chain system based on the hierarchical identity relationship formed by each entity in the alliance chain system and adapting the entity identity requirement in the hierarchical identity-based cryptography, to construct the public hierarchical identity information of each entity in the alliance chain system; comprising: The identity public information of the root domain: the root domain is a private key generator in the identity-based cryptography, and a public identity information is introduced for the root domain; The public identity information of the agency domain: the agency domain is directly subordinate to the root domain, and the identity information of the agency domain is the local identity identifier of the agency; The public identity information of the node: the identity information of the node is constructed by integrating the identity information of the root domain, the agency domain and the node domain, and the identity information of the node domain is the local identity identifier of the node; The public identity information of the business terminal: the business terminal connects a node of an agency in the alliance chain to request execution of a contract function of a deployed contract on the chain, and accepts a transaction receipt returned from the node on the chain, so that the SDK is suffixed with different business terminal numbers connected to the same node as the local identity identifier of the business terminal in the entity hierarchy; The public identity information of the business personnel: the business personnel are regarded as sub-entities of a node on the chain, that is, from the hierarchical structure, the business personnel and the business terminal are at the same level in the entity hierarchical structure; the unique identity identifier representing the business personnel is selected as the local identity identifier of the business personnel in the entity hierarchy; S20, using the public identity information of all entities in the constructed alliance chain system, creating a private key generation agency of the hierarchical identity-based cryptography system, extracting the private keys of all agencies in the alliance chain system, and delegating the private keys of all nodes, business terminals and users belonging to each agency according to the private keys of each agency; Creating a root private key generator in the hierarchical identity-based cryptography system based on the hierarchical relationship of all entities in the alliance chain system and the identity public information of the root domain; Extracting the private key of the agency for the public identity information of the agency domain; Extracting the private key of the node for the public identity information of the node; Extracting the private key of the business terminal for the public identity information of the business terminal; Extracting the private key of the business personnel for the public identity information of the business personnel; S30, using the public identity information and the corresponding private keys of each entity in the alliance chain system, realizing the establishment of identity trust relationship of each entity in the system, and providing the required cryptographic services for the business transactions based on the alliance chain. 2.The method of claim 1, wherein, Creating a root private key generator: all agencies constituting the alliance chain jointly negotiate to select a non-symmetric bilinear pair required by the hierarchical identity-based cryptography, and create public parameters of the hierarchical identity-based cryptography system and a master key of the system root private key generator based on the hierarchical relationship of all entities in the alliance chain system and the identity public information of the root domain. The master key will be used to extract the private keys of all entities in the alliance chain system. 3.The method of claim 1, wherein, For the public identity information of the organization domain, the private key of the organization is extracted: according to the construction mechanism of the entity public identity information determined by the hierarchical identity-based cryptography system, the public identity information of each organization in the alliance chain is constructed, and the root private key generator is requested to extract the private key of the corresponding organization; because the organization is the highest entity in the alliance chain system, the private key of such entity can only be extracted by the root private key generator, and there is no upper entity that can be delegated by the root private key generator to extract it. 4.The method of claim 1, wherein, For the public identity information of the node, the private key of the node is extracted: the public identity information of each node in each organization is constructed, and the root private key generator is requested to extract the private key of each node; because each node in the alliance chain corresponds to a certain organization, that is, the organization entity is the upper entity of the node entity, the root private key generator authorizes the organization entity to extract the private key of the node belonging to the corresponding organization, and this authorized private key extraction is that the organization uses its own private key to construct the private key of the corresponding node according to the local identity of the child entity, that is, the node, and the authorized private key extraction needs to refer to the delegation operation regulation of the selected hierarchical identity-based cryptography system to execute. 5.The method of claim 1, wherein, For the public identity information of the business terminal, the private key of the business terminal is extracted: based on the public identity information constructed by the alliance chain organization and node, and the selected rules of the identity information of the business terminal and business personnel defined by each organization, the public identity information of the business terminal belonging to the node of a certain organization is constructed, the root private key generator is requested to extract the private key of each business terminal, or the private key of the child entity business terminal is extracted by the ancestor entity of the business terminal, that is, the organization or the node, according to the delegation of the root private key generator. 6.The method of claim 1, wherein, For the public identity information of the business personnel, the private key of the business personnel is extracted: the private key extraction of the business personnel in the organization is the same as the private key extraction of the business terminal, the root private key generator is requested to extract the private key of the corresponding business personnel, or the private key of each business personnel is extracted by the ancestor entity of the business personnel, that is, the organization or the node, according to the delegation of the root private key generator.