A computing verification method and device, computing power node and first node
Patent Information
- Application Number
- CN202211006009.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-22
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2042-08-22
AI Technical Summary
[0005]本发明的目的是提供一种计算验证方法、装置、第一节点及算力节点,用以解决现有技术中用户无法对算力节点进行控制的问题
[0098] In this embodiment of the invention, by receiving computation verification information sent by a computing power node, and receiving a computation verification request sent by a user node after receiving the computation result sent by the computing power node, the computation verification request is verified using the computation verification information corresponding to the computation verification request, a verification result is obtained, and the verification result is sent to the user node. This enables the user to control the computing power node, prevents the computing power node from tampering with node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results.
Smart Images

Figure CN117675232B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a computational verification method, apparatus, first node, and computing power node. Background Technology
[0002] The computing power network connects distributed computing power nodes and distributes computing power information, storage information, and algorithm information of service nodes through the network. Combined with network information such as path and latency, it provides the best resource allocation and network connection scheme according to customer needs, and achieves optimal routing and load balancing.
[0003] After a user reaches a service agreement with the service platform, the service platform allocates a network connection and computing power nodes to the user. The user sends the computing task data to the computing power nodes for computation based on the computing power node address information provided by the service platform. After the computing power nodes complete the computation, they return the computation results to the user.
[0004] In a computing power network, users cannot control the computing nodes that perform computing tasks; they can only passively accept the computation results provided by the nodes, and the authenticity of the results cannot be guaranteed. Computing power service providers need to manage a large number of nodes, including third-party nodes, making it difficult to guarantee the security and reliability of all nodes. Furthermore, there is a possibility that computing nodes may be compromised, providing users with fabricated computation results, or that computing nodes may have their configurations changed, using equipment inconsistent with the equipment used during network access assessment. Summary of the Invention
[0005] The purpose of this invention is to provide a computational verification method, apparatus, first node, and computing power node to solve the problem in the prior art that users cannot control the computing power node.
[0006] To achieve the above objectives, embodiments of the present invention provide a computational verification method applied to a first node, comprising:
[0007] Receive computation verification information sent by the computing power nodes;
[0008] Receive the computation verification request sent by the user node after receiving the computation result sent by the computing power node;
[0009] The computation verification request is verified using the computation verification information corresponding to the computation verification request, and the verification result is obtained;
[0010] Send the verification result to the user node;
[0011] The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information.
[0012] Optionally, after receiving the computation verification information sent by the computing power node, the computation verification method further includes:
[0013] Perform signature verification on the calculated verification information;
[0014] After the signature verification is passed, the verification information is calculated and stored.
[0015] Optionally, in the computation verification method, if the computation verification request does not include application information, after receiving the computation verification request sent by the user node, the method further includes:
[0016] Obtain application information corresponding to user information;
[0017] The application information includes the application name and / or the type of computing service.
[0018] Optionally, the computational verification method includes one of the following as the computational verification information:
[0019] The calculation information and the signature information of the calculation information;
[0020] The first hash value and its signature information; the first hash value is obtained by concatenating the hash values corresponding to each type of computational information.
[0021] The first data is a signature information of the first data; the first data is obtained by concatenating the hash value of at least one type of computational information, at least one type of computational information, and encrypted data of at least one type of computational information.
[0022] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0023] Optionally, before verifying the computation verification request using computation verification information corresponding to the computation verification request and obtaining the verification result, the computation verification method further includes:
[0024] From the stored computation verification information, the computation verification information corresponding to the computation verification request is obtained by using the computation task identifier.
[0025] Optionally, the computation verification method, wherein the step of verifying the computation verification request using computation verification information corresponding to the computation verification request and obtaining a verification result includes:
[0026] Using the list of valid nodes and the computation verification information corresponding to the computation verification request, the computation verification request is verified to obtain a first verification result.
[0027] The list of legitimate nodes is generated after the computing power node connects to the computing power network where the first node is located.
[0028] Optionally, the computation verification method, wherein the step of verifying the computation verification request using computation verification information corresponding to the computation verification request and obtaining a verification result includes:
[0029] Using the computation verification information corresponding to the computation verification request, the computation execution process of the computation verification request is verified to obtain a second verification result.
[0030] Optionally, in the computation verification method, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result;
[0031] The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0032] Verify whether the computing node identity information in the computing verification information corresponding to the computing verification request matches the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0033] Verify whether the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the computing node security configuration information in the list of legal nodes, and obtain the second sub-verification result;
[0034] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0035] Optionally, the computation verification method includes the following computation verification information: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating hash values of computing node identity information, hash values of computing node security configuration information, at least one type of computation information other than computing node identity information and computing node security configuration information, and encrypted data of at least one type of computation information other than computing node identity information and computing node security configuration information; the computation information includes at least one of the following: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result;
[0036] The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0037] Verify whether the hash value of the computing node identity information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0038] Verify whether the hash value of the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node security configuration information in the list of legitimate nodes, and obtain the second sub-verification result;
[0039] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0040] Optionally, the computation verification method includes the following computation verification information: signature information of first data; the first data is obtained by concatenating encrypted data of computing node identity information, encrypted data of computing node security configuration information, hash value of at least one type of computation information other than computing node identity information and computing node security configuration information, and at least one type of computation information other than computing node identity information and computing node security configuration information; the computation information includes at least one of the following: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result;
[0041] The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0042] Decrypt the encrypted data of the computing node identity information in the computing verification information corresponding to the computing verification request to obtain the first decrypted data. Verify whether the first decrypted data matches the computing node identity information in the list of legitimate nodes to obtain the first sub-verification result.
[0043] Decrypt the encrypted data of the computing node security configuration information in the computing verification information corresponding to the computing verification request to obtain the second decrypted data. Verify whether the second decrypted data matches the computing node security configuration information in the list of legitimate nodes to obtain the second sub-verification result.
[0044] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0045] Optionally, in the computation verification method, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result;
[0046] The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes:
[0047] Verify whether the application information in the computation verification information corresponding to the computation verification request matches the application information in the computation verification request, and obtain the third sub-verification result;
[0048] Verify whether the computation data in the computation verification information corresponding to the computation verification request matches the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0049] Verify whether the calculation result in the calculation verification information corresponding to the calculation verification request matches the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0050] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0051] Optionally, the computation verification method includes the following computation verification information: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating the hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating the hash value of application information, the hash value of computation data, the hash value of computation result, at least one type of computation information other than application information, computation data, and computation result, and encrypted data of at least one type of computation information other than application information, computation data, and computation result; the computation information includes at least one of the following: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result;
[0052] The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes:
[0053] Verify whether the hash value of the application information in the computation verification information corresponding to the computation verification request matches the hash value of the application information in the computation verification request, and obtain the third sub-verification result;
[0054] Verify whether the hash value of the computation data in the computation verification information corresponding to the computation verification request matches the hash value of the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0055] Verify whether the hash value of the calculation result in the calculation verification information corresponding to the calculation verification request matches the hash value of the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0056] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0057] Optionally, the computation verification method includes the following computation verification information: signature information of first data; the first data is obtained by concatenating encrypted data of application information, encrypted data of computation data, encrypted data of computation results, hash values of at least one type of computation information other than application information, computation data, and computation results; the computation information includes at least one of the following: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results.
[0058] The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes:
[0059] The encrypted data of the application information in the computation verification information corresponding to the computation verification request is decrypted to obtain the third decrypted data. The third decrypted data is then verified to see if it matches the application information in the computation verification request, and the third sub-verification result is obtained.
[0060] Decrypt the encrypted data of the computation data in the computation verification information corresponding to the computation verification request to obtain the fourth decrypted data, verify whether the fourth decrypted data matches the computation data in the computation verification request, and obtain the fourth sub-verification result.
[0061] The encrypted data of the calculation result in the calculation verification information corresponding to the calculation verification request is decrypted to obtain the fifth decrypted data. The fifth decrypted data is then verified to see if it matches the calculation result in the calculation verification request, and the fifth sub-verification result is obtained.
[0062] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0063] To achieve the above objectives, embodiments of the present invention provide a computational verification method applied to a computing node, comprising:
[0064] Based on the computational information, generate computational verification information;
[0065] Send the computational verification information to the first node;
[0066] Send the calculation results to the user node;
[0067] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0068] Optionally, in the computational verification method, generating computational verification information based on computational information includes one of the following:
[0069] The calculation verification information is generated based on the calculation information and the signature information of the calculation information;
[0070] The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value.
[0071] The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
[0072] To achieve the above objectives, embodiments of the present invention provide a first node, including a transceiver and a processor, wherein:
[0073] The transceiver is used to receive computation verification information sent by the computing power node;
[0074] The transceiver is also used to receive a computation verification request sent by a user node after receiving the computation result sent by the computing power node;
[0075] The processor is used to verify the computation verification request using computation verification information corresponding to the computation verification request, and obtain the verification result;
[0076] The transceiver is also used to send the verification result to the user node;
[0077] The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information.
[0078] To achieve the above objectives, embodiments of the present invention provide a computing node, including a transceiver and a processor, wherein:
[0079] The processor is used to generate computation verification information based on computation information;
[0080] The transceiver is used to send the computation verification information to the first node;
[0081] The transceiver is also used to send calculation results to user nodes;
[0082] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0083] To achieve the above objectives, embodiments of the present invention provide a computational verification apparatus applied to a first node, comprising:
[0084] The first receiving module is used to receive the computation verification information sent by the computing power node;
[0085] The second receiving module is used to receive the calculation verification request sent by the user node after receiving the calculation result sent by the computing power node;
[0086] The verification module is used to verify the computation verification request using computation verification information corresponding to the computation verification request, and obtain the verification result;
[0087] The first sending module is used to send the verification result to the user node;
[0088] The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information.
[0089] To achieve the above objectives, embodiments of the present invention provide a computational verification device applied to a computing node, comprising:
[0090] The generation module is used to generate computation verification information based on computation information;
[0091] The second sending module is used to send the calculation verification information to the first node;
[0092] The third sending module is used to send the calculation results to the user nodes;
[0093] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0094] To achieve the above objectives, embodiments of the present invention provide a first node, comprising: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor executes the program or instructions to implement the computational verification method as described above.
[0095] To achieve the above objectives, embodiments of the present invention provide a computing node, including: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; when the processor executes the program or instructions, it implements the computing verification method described above.
[0096] To achieve the above objectives, embodiments of the present invention provide a readable storage medium having a program or instructions stored thereon, which, when executed by a processor, implements the computational verification method as described above.
[0097] The beneficial effects of the above-described technical solution of the present invention are as follows:
[0098] In this embodiment of the invention, by receiving computation verification information sent by a computing power node, and receiving a computation verification request sent by a user node after receiving the computation result sent by the computing power node, the computation verification request is verified using the computation verification information corresponding to the computation verification request, a verification result is obtained, and the verification result is sent to the user node. This enables the user to control the computing power node, prevents the computing power node from tampering with node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results. Attached Figure Description
[0099] Figure 1 This is a schematic diagram of the computing network architecture according to an embodiment of the present invention;
[0100] Figure 2 This is a flowchart of a computational verification method applied to the first node according to an embodiment of the present invention;
[0101] Figure 3 This is one of the application flowcharts of the computational verification method according to an embodiment of the present invention;
[0102] Figure 4 This is the second application flowchart of the computational verification method according to an embodiment of the present invention;
[0103] Figure 5 This is a flowchart of a computation verification method applied to computing nodes according to an embodiment of the present invention;
[0104] Figure 6 This is a schematic diagram of the structure of the first node in an embodiment of the present invention;
[0105] Figure 7 This is a schematic diagram of the computing node structure according to an embodiment of the present invention;
[0106] Figure 8 This is a schematic diagram of the structure of the computational verification device applied to the first node according to an embodiment of the present invention;
[0107] Figure 9 This is a schematic diagram of the computing verification device applied to a computing node according to an embodiment of the present invention;
[0108] Figure 10 This is a schematic diagram of the structure of the first node according to another embodiment of the present invention;
[0109] Figure 11 This is a schematic diagram of the computing node structure according to another embodiment of the present invention. Detailed Implementation
[0110] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0111] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0112] In various embodiments of the present invention, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0113] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0114] In the embodiments provided in this application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0115] To address the problem of users being unable to control computing nodes in existing technologies, this invention provides a computation verification method. This method involves receiving computation verification information from a computing node, receiving a computation verification request from a user node after receiving computation results from the computing node, verifying the computation verification request using computation verification information corresponding to the request, obtaining a verification result, and sending the verification result back to the user node. This enables users to control computing nodes, prevents computing nodes from tampering with node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of computation results.
[0116] An embodiment of the present invention provides a computing power network architecture, including nodes such as a service platform, an orchestration and management entity, user devices, computing power nodes, and a first node. The computing power nodes may include end computing power nodes, central computing power nodes, and edge computing power nodes; the first node may be deployed independently or its functions may be shared with one of the nodes in the service platform and the orchestration and management entity, such as... Figure 1 The diagram shows the computing network architecture when the first node is deployed alone. Each node is connected to the computing network through switches and routers.
[0117] For example, the application scenarios of this computing power network architecture are as follows:
[0118] Users submit business requests to the service platform through their user devices; these business requests may include at least one of the following: computing requirements, security requirements, and network resource requirements; in addition, users may also send data types and task types to the service platform through their user devices.
[0119] The orchestration and management entity allocates routes to user devices, i.e., computing power nodes that meet their needs.
[0120] User equipment sends computing tasks to computing nodes for computation according to the assigned routes and computing nodes, and receives the computation results returned by the computing nodes.
[0121] like Figure 2 As shown, a computational verification method according to an embodiment of the present invention, applied to a first node, includes:
[0122] Step 201: Receive the computation verification information sent by the computing power node.
[0123] It should be noted that the application deployed to the computing power node has a built-in private key, signature algorithm, and information reporting function. After the computing task submitted by the user node is completed, computing verification information is generated. The application can automatically report the computing verification information to the first node at the specified address. The computing verification information is information that records the computing environment and computing execution process, and can prove that it was generated by the application.
[0124] After receiving the computation verification information, the first node uses its public key to sign and verify the information to determine whether it was generated by the application of the computing power node.
[0125] If the signature verification passes, the calculation verification information will be stored to form a calculation verification information database;
[0126] If the signature verification fails, the computation verification information is determined to be forged, the computation of this computing node is untrustworthy, and the computation verification information is not saved.
[0127] Step 202: Receive the computation verification request sent by the user node after receiving the computation result sent by the computing power node.
[0128] It should be noted that after the computing node completes the computation task, the computing node returns the computation result to the user node. Based on the computation result, the user node generates a computation verification request and sends the computation verification request to the first node. The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information.
[0129] Step 203: Use the computation verification information corresponding to the computation verification request to verify the computation verification request and obtain the verification result.
[0130] In this step, the computation verification information corresponding to the computation verification request is obtained from the computation verification information database. The computation verification information is then used to verify the computation verification request to prevent computing nodes from swapping node configurations or providing forged computation results.
[0131] Step 204: Send the verification result to the user node.
[0132] It should be noted that the user node receives the verification result, thereby enabling control over the computing power node, preventing the use of forged computation results provided by the computing power node, and improving the controllability of the computation execution process.
[0133] In this embodiment of the invention, by receiving computation verification information sent by a computing power node, and receiving a computation verification request sent by a user node after receiving the computation result sent by the computing power node, the computation verification request is verified using the computation verification information corresponding to the computation verification request, a verification result is obtained, and the verification result is sent to the user node. This enables the user to control the computing power node, prevents the computing power node from tampering with node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results.
[0134] Below, in conjunction with Figure 3 This section describes the application process of the computational verification method.
[0135] Figure 3The dashed box on the left contains user nodes and switches, used to simulate user-side data collection; the dashed box on the right contains the computing resource pool, including: service platform, computing nodes, first node, and firewall, with each node interconnected through a switch.
[0136] Assuming the user node has submitted computing requests to the service platform, the orchestration management entity has allocated routes and computing power nodes to the user node, the computing power nodes have deployed applications, and the user node has submitted computing tasks to the computing power nodes, perform the following steps:
[0137] Step 301: The computing node generates computation verification information. It's important to note that the computation verification information is generated by applications already deployed on the computing node.
[0138] Step 302: The computing node sends computing verification information to the first node.
[0139] Step 303: The computing node sends the calculation results to the user node.
[0140] Step 304: The user node sends a computation verification request to the first node.
[0141] Step 305: The first node queries the service platform for a list of legitimate nodes.
[0142] Step 306: The first node verifies the computation verification request based on the list of valid nodes.
[0143] Step 307: The first node sends the verification result to the user node.
[0144] Optionally, in the case that the computation verification request does not include application information, after step 201, the method further includes:
[0145] Obtain application information corresponding to user information;
[0146] The application information includes the application name and / or the type of computing service.
[0147] It should be noted that if the computation verification request does not include application information, the first node can query the service platform. Specifically, it can query the application information corresponding to the user information, which includes the application name and / or computation service type.
[0148] Optionally, in the aforementioned calculation verification method, the calculation verification information includes one of the following:
[0149] The calculation information and the signature information of the calculation information;
[0150] The first hash value and its signature information; the first hash value is obtained by concatenating the hash values corresponding to each type of computational information.
[0151] The first data is a signature information of the first data; the first data is obtained by concatenating the hash value of at least one type of computational information, at least one type of computational information, and encrypted data of at least one type of computational information.
[0152] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0153] In other words, the methods by which computing nodes generate computation verification information include, but are not limited to, one of the following:
[0154] The calculation verification information is generated based on the calculation information and the signature information of the calculation information;
[0155] The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value.
[0156] The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
[0157] It should be noted that the verification information may also include:
[0158] The signature information of the second data; the second data is obtained by concatenating the hash value of at least one type of computational information and at least one type of computational information.
[0159] Optionally, before step 203, the calculation verification method further includes:
[0160] From the stored computation verification information, the computation verification information corresponding to the computation verification request is obtained by using the computation task identifier.
[0161] Since the computation verification request includes a computation task identifier, the computation task identifier can also be obtained based on the computation verification information. Using the computation task identifier as the query keyword, the computation verification information corresponding to the computation verification request can be queried in the computation verification information database.
[0162] Specifically, based on the computation verification request sent by the user node, application information, computation task identifier, computation data, and computation results are obtained. That is, based on the application information and the computation task identifier, computation data, and computation results submitted by the user node, a list to be verified is constructed. The application information may or may not be submitted by the user node.
[0163] Then, based on the computing task identifier in the list to be verified, the service platform is queried from the computing verification information database to obtain the computing verification information corresponding to the computing task identifier.
[0164] Optionally, in the computational verification method, step 203 includes:
[0165] Using the list of valid nodes and the computation verification information corresponding to the computation verification request, the computation verification request is verified to obtain a first verification result.
[0166] The list of legitimate nodes is generated after the computing power node connects to the computing power network where the first node is located.
[0167] The list of valid nodes is described as follows:
[0168] After a computing node connects to the computing network through a security assessment, the computing network updates its list of legitimate nodes, including the node's identity information and security configuration information. For example, this list can be constructed through a service platform within the computing network; the node's identity information can be its MAC address. The legitimate node list is then sent to the first node by the service platform.
[0169] Using information from the list of legitimate nodes, the computing environment is verified against the computing verification information corresponding to the computing verification request found in the computing verification information database. This determines whether the computing power node has been configured fraudulently and obtains the first verification result.
[0170] It should be noted that the service platform may also choose not to send the list of legitimate nodes to the first node, and the first node may query the service platform for the computation verification information corresponding to the computation verification request.
[0171] Optionally, in the computational verification method, step 203 includes:
[0172] Using the computation verification information corresponding to the computation verification request, the computation execution process of the computation verification request is verified to obtain a second verification result.
[0173] It should be noted that the computation verification information corresponding to the computation verification request is the information submitted by the application, and the computation verification request is the information submitted by the user. The information submitted by the application and the information submitted by the user are matched to verify the computation execution process and obtain the second verification result.
[0174] It should also be noted that step 204 includes one of the following:
[0175] If both the first verification result and the second verification result are successful, the verification result sent to the user node is successful.
[0176] Send the first and second verification results to the user node.
[0177] Optionally, in the computation verification method, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results;
[0178] The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0179] Verify whether the computing node identity information in the computing verification information corresponding to the computing verification request matches the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0180] Verify whether the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the computing node security configuration information in the list of legal nodes, and obtain the second sub-verification result;
[0181] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0182] It should be noted that, when the computation verification information includes the computation information and the signature information of the computation information, the step of using the list of legitimate nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain the first verification result includes:
[0183] Verify whether the identity information of the computing power node corresponding to the verification request is in the list of legitimate nodes, and obtain the first sub-verification result;
[0184] Verify whether the security configuration information of the computing power node corresponding to the verification request matches the security configuration information of the corresponding computing power node in the list of legal nodes, and obtain the second sub-verification result;
[0185] If both the first and second sub-verification results pass verification, the first verification result is determined to be valid.
[0186] Optionally, in the computation verification method, the computation verification information includes: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating hash values of computing node identity information, hash values of computing node security configuration information, at least one type of computation information other than computing node identity information and computing node security configuration information, and encrypted data of at least one type of computation information other than computing node identity information and computing node security configuration information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result;
[0187] The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0188] Verify whether the hash value of the computing node identity information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0189] Verify whether the hash value of the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node security configuration information in the list of legitimate nodes, and obtain the second sub-verification result;
[0190] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0191] In other words, when both the computing node identity information and the computing node security configuration information in the computation verification information are represented by hash values, the step of using the list of legitimate nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0192] Obtain the hash values of the identity information and security configuration information of the computing power nodes from the list of legitimate nodes, respectively.
[0193] Verify whether the hash value of the computing node identity information corresponding to the verification request is in the list of valid nodes, and obtain the first sub-verification result;
[0194] Verify whether the hash value of the security configuration information of the computing power node corresponding to the verification request matches the hash value of the security configuration information of the corresponding computing power node in the list of legitimate nodes, and obtain the second sub-verification result;
[0195] If both the first and second sub-verification results pass verification, the first verification result is determined to be valid.
[0196] Optionally, in the computation verification method, the computation verification information includes: signature information of first data; the first data is obtained by concatenating encrypted data of computing node identity information, encrypted data of computing node security configuration information, hash values of at least one type of computation information other than computing node identity information and computing node security configuration information, and at least one type of computation information other than computing node identity information and computing node security configuration information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result;
[0197] The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0198] Decrypt the encrypted data of the computing node identity information in the computing verification information corresponding to the computing verification request to obtain the first decrypted data. Verify whether the first decrypted data matches the computing node identity information in the list of legitimate nodes to obtain the first sub-verification result.
[0199] Decrypt the encrypted data of the computing node security configuration information in the computing verification information corresponding to the computing verification request to obtain the second decrypted data. Verify whether the second decrypted data matches the computing node security configuration information in the list of legitimate nodes to obtain the second sub-verification result.
[0200] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0201] In other words, when both the computing node identity information and the computing node security configuration information in the computation verification information are encrypted, the step of using the list of legitimate nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes:
[0202] The encrypted data of the computing power node identity information and the encrypted data of the computing power node security configuration information corresponding to the computing verification request are decrypted to obtain the first decrypted data and the second decrypted data.
[0203] Verify whether the first decrypted data is in the list of valid nodes, and obtain the first sub-verification result;
[0204] Verify whether the second decrypted data matches the security configuration information of the corresponding computing power node in the list of legitimate nodes, and obtain the second sub-verification result;
[0205] If both the first and second sub-verification results pass verification, the first verification result is determined to be valid.
[0206] It should be noted that the above verification process determines whether the identity information of the computing power node corresponding to the computation verification request is legitimate and whether the security configuration information of the computing power node is correct. If both verifications pass, that is, the computation environment of the computation verification request submitted by the user node passes the verification, the computation result received by the user node is calculated by the computing power node whose configuration has not been changed.
[0207] Optionally, in the computation verification method, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results;
[0208] The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes:
[0209] Verify whether the application information in the computation verification information corresponding to the computation verification request matches the application information in the computation verification request, and obtain the third sub-verification result;
[0210] Verify whether the computation data in the computation verification information corresponding to the computation verification request matches the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0211] Verify whether the calculation result in the calculation verification information corresponding to the calculation verification request matches the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0212] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0213] It should be noted that, when the computation verification information includes the computation information and the signature information of the computation information, the step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtain the second verification result includes:
[0214] Match the application information in the list to be verified with the application information in the computation verification information corresponding to the computation verification request, and obtain the third sub-verification result;
[0215] Match the computational data in the list to be verified with the computational data in the computational verification information corresponding to the computational verification request, and obtain the fourth sub-verification result;
[0216] Match the computational data in the list to be verified with the computational results in the computational verification information corresponding to the computational verification request, and obtain the fifth sub-verification result;
[0217] If the third, fourth, and fifth sub-verification results are all verified, then the second verification result is determined to be verified.
[0218] Optionally, in the computation verification method, the computation verification information includes: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating the hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating the hash value of application information, the hash value of computation data, the hash value of computation result, at least one type of computation information other than application information, computation data, and computation result, and encrypted data of at least one type of computation information other than application information, computation data, and computation result; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result;
[0219] The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes:
[0220] Verify whether the hash value of the application information in the computation verification information corresponding to the computation verification request matches the hash value of the application information in the computation verification request, and obtain the third sub-verification result;
[0221] Verify whether the hash value of the computation data in the computation verification information corresponding to the computation verification request matches the hash value of the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0222] Verify whether the hash value of the calculation result in the calculation verification information corresponding to the calculation verification request matches the hash value of the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0223] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0224] In other words, when the application information, computation data, and computation results in the computation verification information are all represented by hash values, the step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtain the second verification result includes:
[0225] Retrieve the application information, computational data, and hash value of the computation result from the list to be verified;
[0226] Verify whether the hash value of the application information corresponding to the verification request matches the hash value of the application information in the list to be verified, and obtain the third sub-verification result;
[0227] Verify whether the hash value of the computation data corresponding to the verification request matches the hash value of the computation data in the list to be verified, and obtain the fourth sub-verification result;
[0228] Verify whether the hash value of the calculation result corresponding to the verification request matches the hash value of the calculation result in the list to be verified, and obtain the fifth sub-verification result;
[0229] If the third, fourth, and fifth sub-verification results are all verified, then the second verification result is determined to be verified.
[0230] Optionally, in the computation verification method, the computation verification information includes: signature information of first data; the first data is obtained by concatenating encrypted data of application information, encrypted data of computation data, encrypted data of computation results, hash values of at least one type of computation information other than application information, computation data, and computation results, and at least one type of computation information other than application information, computation data, and computation results; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results.
[0231] The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes:
[0232] The encrypted data of the application information in the computation verification information corresponding to the computation verification request is decrypted to obtain the third decrypted data. The third decrypted data is then verified to see if it matches the application information in the computation verification request, and the third sub-verification result is obtained.
[0233] Decrypt the encrypted data of the computation data in the computation verification information corresponding to the computation verification request to obtain the fourth decrypted data, verify whether the fourth decrypted data matches the computation data in the computation verification request, and obtain the fourth sub-verification result.
[0234] The encrypted data of the calculation result in the calculation verification information corresponding to the calculation verification request is decrypted to obtain the fifth decrypted data. The fifth decrypted data is then verified to see if it matches the calculation result in the calculation verification request, and the fifth sub-verification result is obtained.
[0235] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0236] In other words, when the application information, computation data, and computation results in the computation verification information are all encrypted, the step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtain the second verification result includes:
[0237] The encrypted data of the application information, calculation data, and calculation result corresponding to the calculation verification request are decrypted respectively to obtain the third decrypted data, the fourth decrypted data, and the fifth decrypted data;
[0238] Verify whether the application information in the list to be verified matches the third decrypted data, and obtain the third sub-verification result;
[0239] Verify whether the calculated data in the list to be verified matches the fourth decrypted data, and obtain the fourth sub-verification result;
[0240] Verify whether the calculation results in the list to be verified match the fifth decrypted data, and obtain the fifth sub-verification result;
[0241] If the third, fourth, and fifth sub-verification results are all verified, then the second verification result is determined to be verified.
[0242] It should be noted that the above verification process verifies whether the application information submitted by the user node matches the application information submitted by the computing power node, i.e., whether the application of the computing power node matches the computation requirements. It also verifies whether the computational data submitted by the user node matches the computational data submitted by the computing power node, preventing the computing power node from using false data for computation. Furthermore, it verifies whether the computational results submitted by the user node match the computational results submitted by the computing power node. In other words, the computing power node returns fabricated results to the user node instead of the results provided by the application. If all verifications pass, the computation execution process of the computation verification request submitted by the user node is verified as successful, the computational result is reliable, and the computing power node used the correct application and the correct computational data to obtain the computational result.
[0243] It should also be noted that if at least one of the above-mentioned third, fourth, and fifth sub-verification results fails, the second verification result is determined to be a verification failure, and the calculation result provided by the computing power node is unreliable.
[0244] Below, in conjunction with Figure 4 The second part describes the application process of the computational verification method.
[0245] Step 401: The computing node sends computation verification information to the first node. It's important to note that the computing node receives the computation task, deploys an application to execute the task, and generates computation verification information upon completion. This verification information can be a string, which may consist of a signature concatenated from the computation task identifier, the hash value of the computation data, the hash value of the computation result, the computing node's identity information (e.g., the computing node's MAC address), the computing node's security configuration information, and application information.
[0246] Step 402: The first node performs signature verification on the computation verification information, stores the computation verification information after the signature verification passes, and constructs a computation verification information database.
[0247] Step 403: The computing node sends the calculation results to the user node.
[0248] Step 404: The user node sends a computation verification request to the first node. It is important to note that the user node generates the computation verification request based on the computation results. This request includes at least one of the following: user information, computation task identifier, computation data, computation results, and application information.
[0249] Step 405: The first node first queries the computation verification information database corresponding to the computation verification request based on the computation task identifier in the computation verification request; then, based on the computing node identity information and computing node security configuration information in the computation verification information corresponding to the computation verification request, it verifies the computing environment to obtain a first verification result; next, based on the application information, computation data, and computation results in the computation verification information corresponding to the computation verification request, it verifies the computation execution process and computing node security configuration information to obtain a second verification result; finally, based on the first and second verification results, it obtains the verification result. If both the first and second verification results are successful, the verification result is considered successful.
[0250] Step 406: The first node sends the verification result to the user node.
[0251] like Figure 5 As shown, a computational verification method according to an embodiment of the present invention is applied to a computing node, including:
[0252] Step 501: Generate calculation verification information based on the calculation information;
[0253] It should be noted that the computing node receives computing tasks submitted by the user node, deploys applications to execute the tasks, and obtains computing information. This computing information includes at least one of the following: application information, computing task identifier, computing node identity information, computing node security configuration information, computing data, and computing results.
[0254] Step 502: Send the computation verification information to the first node.
[0255] In this step, the first node supervises the computation execution process of the computing power node based on the computation verification information, thereby achieving the controllability of the computing power node.
[0256] Step 503: Send the calculation results to the user node.
[0257] In this step, the user node generates a computation verification request based on the computation result and requests the first node to verify the computation result to check the credibility of the computation result provided by the computing power node.
[0258] In this embodiment of the invention, computation verification information is generated based on computation information. The computation information includes at least one of the following: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results. The computation verification information is sent to a first node, and the computation results are sent to a user node. This enables the user to control the computing power node, prevents the computing power node from changing node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results.
[0259] Optionally, in the computational verification method, step 501 includes one of the following:
[0260] The calculation verification information is generated based on the calculation information and the signature information of the calculation information;
[0261] The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value.
[0262] The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
[0263] It should be noted that the methods for generating verification information include, but are not limited to, the methods described above.
[0264] like Figure 6As shown, this embodiment of the invention also provides a first node, including a transceiver 601 and a processor 602, wherein:
[0265] The transceiver 601 is used to receive computing verification information sent by the computing power node;
[0266] The transceiver 601 is also used to receive a calculation verification request sent by a user node after receiving the calculation result sent by the computing power node.
[0267] The processor 602 is used to verify the computation verification request using computation verification information corresponding to the computation verification request, and obtain the verification result;
[0268] The transceiver 601 is also used to send the verification result to the user node;
[0269] The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information.
[0270] In this embodiment of the invention, by receiving computation verification information sent by a computing power node, and receiving a computation verification request sent by a user node after receiving the computation result sent by the computing power node, the computation verification request is verified using the computation verification information corresponding to the computation verification request, a verification result is obtained, and the verification result is sent to the user node. This enables the user to control the computing power node, prevents the computing power node from tampering with node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results.
[0271] Optionally, in the first node, the processor 602 is further configured to:
[0272] Perform signature verification on the calculated verification information;
[0273] After the signature verification is passed, the verification information is calculated and stored.
[0274] Optionally, in the first node, the processor 602 is further configured to:
[0275] Obtain application information corresponding to user information;
[0276] The application information includes the application name and / or the type of computing service.
[0277] Optionally, the first node, wherein the calculation of verification information includes one of the following:
[0278] The calculation information and the signature information of the calculation information;
[0279] The first hash value and its signature information; the first hash value is obtained by concatenating the hash values corresponding to each type of computational information.
[0280] The first data is a signature information of the first data; the first data is obtained by concatenating the hash value of at least one type of computational information, at least one type of computational information, and encrypted data of at least one type of computational information.
[0281] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0282] Optionally, in the first node, the processor 602 is further configured to:
[0283] From the stored computation verification information, the computation verification information corresponding to the computation verification request is obtained by using the computation task identifier.
[0284] Optionally, in the first node, the processor 602 is further configured to:
[0285] Using the list of valid nodes and the computation verification information corresponding to the computation verification request, the computation verification request is verified to obtain a first verification result.
[0286] The list of legitimate nodes is generated after the computing power node connects to the computing power network where the first node is located.
[0287] Optionally, in the first node, the processor 602 is further configured to:
[0288] Using the computation verification information corresponding to the computation verification request, the computation execution process of the computation verification request is verified to obtain a second verification result.
[0289] Optionally, in the first node, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results; the processor 602 is further configured to:
[0290] Verify whether the computing node identity information in the computing verification information corresponding to the computing verification request matches the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0291] Verify whether the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the computing node security configuration information in the list of legal nodes, and obtain the second sub-verification result;
[0292] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0293] Optionally, in the first node, the computation verification information includes: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating hash values of computing power node identity information, hash values of computing power node security configuration information, at least one type of computation information other than computing power node identity information and computing power node security configuration information, and encrypted data of at least one type of computation information other than computing power node identity information and computing power node security configuration information; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result; the processor 602 is further configured to:
[0294] Verify whether the hash value of the computing node identity information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0295] Verify whether the hash value of the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node security configuration information in the list of legitimate nodes, and obtain the second sub-verification result;
[0296] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0297] Optionally, in the first node, the computation verification information includes: signature information of first data; the first data is obtained by concatenating encrypted data of computing power node identity information, encrypted data of computing power node security configuration information, hash values of at least one type of computation information other than computing power node identity information and computing power node security configuration information, and at least one type of computation information other than computing power node identity information and computing power node security configuration information; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result; the processor 602 is further configured to:
[0298] Decrypt the encrypted data of the computing node identity information in the computing verification information corresponding to the computing verification request to obtain the first decrypted data. Verify whether the first decrypted data matches the computing node identity information in the list of legitimate nodes to obtain the first sub-verification result.
[0299] Decrypt the encrypted data of the computing node security configuration information in the computing verification information corresponding to the computing verification request to obtain the second decrypted data. Verify whether the second decrypted data matches the computing node security configuration information in the list of legitimate nodes to obtain the second sub-verification result.
[0300] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0301] Optionally, in the first node, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results; the processor 602 is further configured to:
[0302] Verify whether the application information in the computation verification information corresponding to the computation verification request matches the application information in the computation verification request, and obtain the third sub-verification result;
[0303] Verify whether the computation data in the computation verification information corresponding to the computation verification request matches the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0304] Verify whether the calculation result in the calculation verification information corresponding to the calculation verification request matches the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0305] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0306] Optionally, in the first node, the computation verification information includes: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating the hash value of application information, the hash value of computation data, the hash value of computation result, at least one type of computation information other than application information, computation data, and computation result, and encrypted data of at least one type of computation information other than application information, computation data, and computation result; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result; the processor 602 is further configured to:
[0307] Verify whether the hash value of the application information in the computation verification information corresponding to the computation verification request matches the hash value of the application information in the computation verification request, and obtain the third sub-verification result;
[0308] Verify whether the hash value of the computation data in the computation verification information corresponding to the computation verification request matches the hash value of the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0309] Verify whether the hash value of the calculation result in the calculation verification information corresponding to the calculation verification request matches the hash value of the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0310] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0311] Optionally, in the first node, the computation verification information includes: signature information of the first data; the first data is obtained by concatenating encrypted data of application information, encrypted data of computation data, encrypted data of computation results, hash values of at least one type of computation information other than application information, computation data, and computation results, and at least one type of computation information other than application information, computation data, and computation results; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results; the processor 602 is further configured to:
[0312] The encrypted data of the application information in the computation verification information corresponding to the computation verification request is decrypted to obtain the third decrypted data. The third decrypted data is then verified to see if it matches the application information in the computation verification request, and the third sub-verification result is obtained.
[0313] Decrypt the encrypted data of the computation data in the computation verification information corresponding to the computation verification request to obtain the fourth decrypted data, verify whether the fourth decrypted data matches the computation data in the computation verification request, and obtain the fourth sub-verification result.
[0314] The encrypted data of the calculation result in the calculation verification information corresponding to the calculation verification request is decrypted to obtain the fifth decrypted data. The fifth decrypted data is then verified to see if it matches the calculation result in the calculation verification request, and the fifth sub-verification result is obtained.
[0315] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0316] It should be noted that the first node provided in the embodiments of the present invention can implement all the method steps implemented in the above-mentioned calculation verification method embodiments applied to the first node, and can achieve the same technical effect. Here, the parts and beneficial effects that are the same as those in the method embodiments will not be described in detail.
[0317] like Figure 7 As shown, this embodiment of the invention also provides a computing node 700, including a transceiver 701 and a processor 702, wherein:
[0318] The processor 702 is used to generate computation verification information based on computation information;
[0319] The transceiver 701 is used to send the computation verification information to the first node;
[0320] The transceiver 701 is also used to send calculation results to user nodes;
[0321] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0322] In this embodiment of the invention, computation verification information is generated based on computation information. The computation information includes at least one of the following: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results. The computation verification information is sent to a first node, and the computation results are sent to a user node. This enables the user to control the computing power node, prevents the computing power node from changing node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results.
[0323] Optionally, in the computing node, the processor 702 is further configured to perform one of the following:
[0324] The calculation verification information is generated based on the calculation information and the signature information of the calculation information;
[0325] The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value.
[0326] The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
[0327] It should be noted that the computing power node provided in the embodiments of the present invention can implement all the method steps implemented in the above-mentioned computing verification method embodiments applied to computing power nodes, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiments and the beneficial effects will not be described in detail.
[0328] like Figure 8 As shown, this embodiment of the invention also provides a computational verification device applied to a first node, the device comprising:
[0329] The first receiving module 801 is used to receive the computing verification information sent by the computing power node;
[0330] The second receiving module 802 is used to receive a calculation verification request sent by the user node after receiving the calculation result sent by the computing power node;
[0331] Verification module 803 is used to verify the calculation verification request using calculation verification information corresponding to the calculation verification request, and obtain the verification result;
[0332] The first sending module 804 is used to send the verification result to the user node;
[0333] The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information.
[0334] In this embodiment of the invention, by receiving computation verification information sent by a computing power node, and receiving a computation verification request sent by a user node after receiving the computation result sent by the computing power node, the computation verification request is verified using the computation verification information corresponding to the computation verification request, a verification result is obtained, and the verification result is sent to the user node. This enables the user to control the computing power node, prevents the computing power node from tampering with node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results.
[0335] Optionally, the computational verification apparatus further includes:
[0336] The verification module is used to perform signature verification on the calculated verification information;
[0337] The storage module is used to store the calculated verification information after the signature verification is passed.
[0338] Optionally, the computational verification apparatus further includes:
[0339] The first acquisition module is used to acquire application information corresponding to user information;
[0340] The application information includes the application name and / or the type of computing service.
[0341] Optionally, in the computational verification apparatus, the computational verification information includes one of the following:
[0342] The calculation information and the signature information of the calculation information;
[0343] The first hash value and its signature information; the first hash value is obtained by concatenating the hash values corresponding to each type of computational information.
[0344] The first data is a signature information of the first data; the first data is obtained by concatenating the hash value of at least one type of computational information, at least one type of computational information, and encrypted data of at least one type of computational information.
[0345] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0346] Optionally, the computational verification apparatus further includes:
[0347] The second acquisition module is used to acquire the computation verification information corresponding to the computation verification request from the stored computation verification information by means of the computation task identifier.
[0348] Optionally, in the computational verification apparatus, the verification module 803 includes:
[0349] The first sub-verification module is used to verify the computing environment of the computing verification request by using a list of legal nodes and computing verification information corresponding to the computing verification request, and to obtain a first verification result.
[0350] The list of legitimate nodes is generated after the computing power node connects to the computing power network where the first node is located.
[0351] Optionally, in the computational verification apparatus, the verification module 803 includes:
[0352] The second sub-verification module is used to verify the computation execution process of the computation verification request using the computation verification information corresponding to the computation verification request, and obtain a second verification result.
[0353] Optionally, in the computation verification device, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation results.
[0354] The first sub-verification module is specifically used for:
[0355] Verify whether the computing node identity information in the computing verification information corresponding to the computing verification request matches the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0356] Verify whether the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the computing node security configuration information in the list of legal nodes, and obtain the second sub-verification result;
[0357] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0358] Optionally, in the computation verification device, the computation verification information includes: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating hash values of computing power node identity information, hash values of computing power node security configuration information, at least one type of computation information other than computing power node identity information and computing power node security configuration information, and encrypted data of at least one type of computation information other than computing power node identity information and computing power node security configuration information; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result;
[0359] The first sub-verification module is specifically used for:
[0360] Verify whether the hash value of the computing node identity information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node identity information in the list of legal nodes, and obtain the first sub-verification result;
[0361] Verify whether the hash value of the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node security configuration information in the list of legitimate nodes, and obtain the second sub-verification result;
[0362] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0363] Optionally, in the computation verification device, the computation verification information includes: signature information of first data; the first data is obtained by concatenating encrypted data of computing node identity information, encrypted data of computing node security configuration information, hash value of at least one type of computation information other than computing node identity information and computing node security configuration information, and at least one type of computation information other than computing node identity information and computing node security configuration information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result;
[0364] The first sub-verification module is specifically used for:
[0365] Decrypt the encrypted data of the computing node identity information in the computing verification information corresponding to the computing verification request to obtain the first decrypted data. Verify whether the first decrypted data matches the computing node identity information in the list of legitimate nodes to obtain the first sub-verification result.
[0366] Decrypt the encrypted data of the computing node security configuration information in the computing verification information corresponding to the computing verification request to obtain the second decrypted data. Verify whether the second decrypted data matches the computing node security configuration information in the list of legitimate nodes to obtain the second sub-verification result.
[0367] If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
[0368] Optionally, in the computation verification device, the computation verification information includes: the computation information and the signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation results.
[0369] The second sub-verification module is specifically used for:
[0370] Verify whether the application information in the computation verification information corresponding to the computation verification request matches the application information in the computation verification request, and obtain the third sub-verification result;
[0371] Verify whether the computation data in the computation verification information corresponding to the computation verification request matches the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0372] Verify whether the calculation result in the calculation verification information corresponding to the calculation verification request matches the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0373] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0374] Optionally, in the computation verification device, the computation verification information includes: a first hash value and signature information of the first hash value; the first hash value is obtained by concatenating hash values corresponding to each type of computation information; or, the computation verification information includes: signature information of first data; the first data is obtained by concatenating the hash value of application information, the hash value of computation data, the hash value of computation result, at least one type of computation information other than application information, computation data, and computation result, and encrypted data of at least one type of computation information other than application information, computation data, and computation result; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result;
[0375] The second sub-verification module is specifically used for:
[0376] Verify whether the hash value of the application information in the computation verification information corresponding to the computation verification request matches the hash value of the application information in the computation verification request, and obtain the third sub-verification result;
[0377] Verify whether the hash value of the computation data in the computation verification information corresponding to the computation verification request matches the hash value of the computation data in the computation verification request, and obtain the fourth sub-verification result;
[0378] Verify whether the hash value of the calculation result in the calculation verification information corresponding to the calculation verification request matches the hash value of the calculation result in the calculation verification request, and obtain the fifth sub-verification result;
[0379] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0380] Optionally, in the computation verification device, the computation verification information includes: signature information of first data; the first data is obtained by concatenating encrypted data of application information, encrypted data of computation data, encrypted data of computation results, hash values of at least one type of computation information other than application information, computation data, and computation results, and at least one type of computation information other than application information, computation data, and computation results; the computation information includes at least one of: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results.
[0381] The second sub-verification module is specifically used for:
[0382] The encrypted data of the application information in the computation verification information corresponding to the computation verification request is decrypted to obtain the third decrypted data. The third decrypted data is then verified to see if it matches the application information in the computation verification request, and the third sub-verification result is obtained.
[0383] Decrypt the encrypted data of the computation data in the computation verification information corresponding to the computation verification request to obtain the fourth decrypted data, verify whether the fourth decrypted data matches the computation data in the computation verification request, and obtain the fourth sub-verification result.
[0384] The encrypted data of the calculation result in the calculation verification information corresponding to the calculation verification request is decrypted to obtain the fifth decrypted data. The fifth decrypted data is then verified to see if it matches the calculation result in the calculation verification request, and the fifth sub-verification result is obtained.
[0385] If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
[0386] It should be noted that the apparatus provided in this embodiment of the invention can implement all the method steps implemented in the above-described calculation verification method embodiment applied to the first node, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0387] like Figure 9 As shown, this embodiment of the invention also provides a computational verification device applied to a computing node, the device comprising:
[0388] The generation module 901 is used to generate computation verification information based on the computation information;
[0389] The second sending module 902 is used to send the calculation verification information to the first node;
[0390] The third sending module 903 is used to send the calculation results to the user node;
[0391] The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
[0392] In this embodiment of the invention, computation verification information is generated based on computation information. The computation information includes at least one of the following: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results. The computation verification information is sent to a first node, and the computation results are sent to a user node. This enables the user to control the computing power node, prevents the computing power node from changing node configurations or providing forged results, improves the controllability of the computation execution process, and ensures the reliability of the computation results.
[0393] Optionally, in the computational verification apparatus, the generation module 901 is specifically used for one of the following:
[0394] The calculation verification information is generated based on the calculation information and the signature information of the calculation information;
[0395] The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value.
[0396] The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
[0397] It should be noted that the apparatus provided in the embodiments of the present invention can implement all the method steps implemented in the above-described computation verification method embodiments applied to computing power nodes, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiments and the beneficial effects will not be described in detail.
[0398] This invention also provides a first node, such as... Figure 10 As shown, it includes: a processor 1001; and a memory 1002 connected to the processor 1001 via a bus interface. The memory 1002 is used to store programs and data used by the processor 1001 when performing operations. The processor 1001 calls and executes the programs and data stored in the memory 1002.
[0399] The transceiver 1003 is connected to a bus interface and is used to receive and send data under the control of the processor 1001.
[0400] Among them, Figure 10 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, such as one or more processors represented by processor 1001 and memory represented by memory 1002. The bus architecture can also link together various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 1003 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, the user interface 1004 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0401] The processor 1001 is responsible for managing the bus architecture and general processing, while the memory 1002 can store the data used by the processor 1001 when performing operations.
[0402] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing the relevant hardware to implement them. The program includes instructions to perform some or all of the steps of the above methods; and the program can be stored in a readable storage medium, which can be any form of storage medium.
[0403] Another aspect of this invention provides a computing node, such as Figure 11 As shown, it includes: a processor 1101; and a memory 1102 connected to the processor 1101 via a bus interface. The memory 1102 is used to store programs and data used by the processor 1101 when performing operations. The processor 1101 calls and executes the programs and data stored in the memory 1102.
[0404] The transceiver 1103 is connected to the bus interface and is used to receive and send data under the control of the processor 1101.
[0405] Among them, Figure 11In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1101 and memory represented by memory 1102 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 1103 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, the user interface 1104 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0406] The processor 1101 is responsible for managing the bus architecture and general processing, while the memory 1102 can store the data used by the processor 1101 when performing operations.
[0407] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing the relevant hardware to implement them. The program includes instructions to perform some or all of the steps of the above methods; and the program can be stored in a readable storage medium, which can be any form of storage medium.
[0408] This invention also provides a readable storage medium, wherein a program is stored on the readable storage medium, and when the program is executed by a processor, it implements the computational verification method as described in any of the preceding claims.
[0409] In the several embodiments provided in this application, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0410] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can be physically comprised separately, or two or more units can be integrated into one unit. The integrated unit described above can be implemented in hardware or in the form of hardware plus software functional units.
[0411] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions that cause a computer device (which may be a personal computer, server, or network device, etc.) to execute some steps of the transmission and reception methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0412] The above describes the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also within the scope of protection of the present invention.
Claims
1. A method of computing verification, characterized by, Applied to the first node, including: Receive computation verification information sent by the computing power nodes; Receive the computation verification request sent by the user node after receiving the computation result sent by the computing power node; The computation verification request is verified using the computation verification information corresponding to the computation verification request, and the verification result is obtained; Send the verification result to the user node; The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information; The calculated verification information includes one of the following: The calculation information and the signature information of the calculation information; The first hash value and its signature information; the first hash value is obtained by concatenating the hash values corresponding to each type of computational information. The first data is a signature information of the first data; the first data is obtained by concatenating the hash value of at least one type of computational information, at least one type of computational information, and encrypted data of at least one type of computational information. The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
2. The method according to claim 1, characterized in that, After receiving the computation verification information sent by the computing power node, the method further includes: Perform signature verification on the calculated verification information; After the signature verification is passed, the verification information is calculated and stored.
3. The method according to claim 1, characterized in that, If the computation verification request does not include application information, the method further includes, after receiving the computation verification request sent by the user node: Obtain application information corresponding to user information; The application information includes the application name and / or the type of computing service.
4. The method according to claim 1, characterized in that, Before verifying the computation verification request using the computation verification information corresponding to the computation verification request and obtaining the verification result, the method further includes: From the stored computation verification information, the computation verification information corresponding to the computation verification request is obtained by using the computation task identifier.
5. The method according to claim 1, characterized in that, The step of verifying the computation verification request using computation verification information corresponding to the computation verification request and obtaining the verification result includes: Using the list of valid nodes and the computation verification information corresponding to the computation verification request, the computation verification request is verified to obtain a first verification result. The list of legitimate nodes is generated after the computing power node connects to the computing power network where the first node is located.
6. The method according to claim 1, characterized in that, The step of verifying the computation verification request using computation verification information corresponding to the computation verification request and obtaining the verification result includes: Using the computation verification information corresponding to the computation verification request, the computation execution process of the computation verification request is verified to obtain a second verification result.
7. The method according to claim 5, characterized in that, The computation verification information includes: computation information and signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation results; The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes: Verify whether the computing node identity information in the computing verification information corresponding to the computing verification request matches the computing node identity information in the list of legal nodes, and obtain the first sub-verification result; Verify whether the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the computing node security configuration information in the list of legal nodes, and obtain the second sub-verification result; If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
8. The method according to claim 5, characterized in that, The verification information includes: a first hash value and the signature information of the first hash value; the first hash value is obtained by concatenating the hash values corresponding to each type of verification information. Alternatively, the verification information may include: signature information of the first data; the first data is obtained by concatenating the hash value of the computing node identity information, the hash value of the computing node security configuration information, at least one type of computing information other than the computing node identity information and the computing node security configuration information, and encrypted data of at least one type of computing information other than the computing node identity information and the computing node security configuration information; the computing information may include at least one of the following: application information, computing task identifier, computing node identity information, computing node security configuration information, computing data, and computing result; The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes: Verify whether the hash value of the computing node identity information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node identity information in the list of legal nodes, and obtain the first sub-verification result; Verify whether the hash value of the computing node security configuration information in the computing verification information corresponding to the computing verification request matches the hash value of the computing node security configuration information in the list of legitimate nodes, and obtain the second sub-verification result; If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
9. The method according to claim 5, characterized in that, The computation verification information includes: signature information of the first data; the first data is obtained by concatenating encrypted data of computing node identity information, encrypted data of computing node security configuration information, hash value of at least one type of computation information other than computing node identity information and computing node security configuration information, and at least one type of computation information other than computing node identity information and computing node security configuration information; the computation information includes at least one of the following: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation result; The step of using a list of valid nodes and the computation verification information corresponding to the computation verification request to perform computation environment verification on the computation verification request and obtain a first verification result includes: Decrypt the encrypted data of the computing node identity information in the computing verification information corresponding to the computing verification request to obtain the first decrypted data. Verify whether the first decrypted data matches the computing node identity information in the list of legitimate nodes to obtain the first sub-verification result. Decrypt the encrypted data of the computing node security configuration information in the computing verification information corresponding to the computing verification request to obtain the second decrypted data. Verify whether the second decrypted data matches the computing node security configuration information in the list of legitimate nodes to obtain the second sub-verification result. If both the first sub-verification result and the second sub-verification result are verified as passed, the first verification result is determined to be verified as passed.
10. The method according to claim 6, characterized in that, The computation verification information includes: computation information and signature information of the computation information; the computation information includes at least one of: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation results; The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes: Verify whether the application information in the computation verification information corresponding to the computation verification request matches the application information in the computation verification request, and obtain the third sub-verification result; Verify whether the computation data in the computation verification information corresponding to the computation verification request matches the computation data in the computation verification request, and obtain the fourth sub-verification result; Verify whether the calculation result in the calculation verification information corresponding to the calculation verification request matches the calculation result in the calculation verification request, and obtain the fifth sub-verification result; If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
11. The method according to claim 6, characterized in that, The computation verification information includes: a first hash value and the signature information of the first hash value; the first hash value is obtained by concatenating the hash values corresponding to each type of computation information; or, the computation verification information includes: the signature information of the first data; the first data is obtained by concatenating the hash value of the application information, the hash value of the computation data, the hash value of the computation result, at least one type of computation information other than the application information, computation data, and computation result, and encrypted data of at least one type of computation information other than the application information, computation data, and computation result; the computation information includes at least one of the following: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation result; The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes: Verify whether the hash value of the application information in the computation verification information corresponding to the computation verification request matches the hash value of the application information in the computation verification request, and obtain the third sub-verification result; Verify whether the hash value of the computation data in the computation verification information corresponding to the computation verification request matches the hash value of the computation data in the computation verification request, and obtain the fourth sub-verification result; Verify whether the hash value of the calculation result in the calculation verification information corresponding to the calculation verification request matches the hash value of the calculation result in the calculation verification request, and obtain the fifth sub-verification result; If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
12. The method according to claim 6, characterized in that, The computation verification information includes: signature information of the first data; the first data is obtained by concatenating encrypted data of application information, encrypted data of computation data, encrypted data of computation results, hash value of at least one type of computation information other than application information, computation data, and computation results, and at least one type of computation information other than application information, computation data, and computation results; the computation information includes at least one of the following: application information, computation task identifier, computing power node identity information, computing power node security configuration information, computation data, and computation results; The step of using the computation verification information corresponding to the computation verification request to verify the computation execution process of the computation verification request and obtaining a second verification result includes: The encrypted data of the application information in the computation verification information corresponding to the computation verification request is decrypted to obtain the third decrypted data. The third decrypted data is then verified to see if it matches the application information in the computation verification request, and the third sub-verification result is obtained. Decrypt the encrypted data of the computation data in the computation verification information corresponding to the computation verification request to obtain the fourth decrypted data, verify whether the fourth decrypted data matches the computation data in the computation verification request, and obtain the fourth sub-verification result. The encrypted data of the calculation result in the calculation verification information corresponding to the calculation verification request is decrypted to obtain the fifth decrypted data. The fifth decrypted data is then verified to see if it matches the calculation result in the calculation verification request, and the fifth sub-verification result is obtained. If the third sub-verification result, the fourth sub-verification result, and the fifth sub-verification result are all verified as passed, then the second verification result is determined to be verified as passed.
13. A computational verification method, characterized in that, Applied to computing nodes, including: Based on the computational information, generate computational verification information; Send the computational verification information to the first node; Send the calculation results to the user node; The computation information includes at least one of the following: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation results. The generation of computational verification information based on computational information includes one of the following: The calculation verification information is generated based on the calculation information and the signature information of the calculation information; The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value. The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
14. A first node, comprising a transceiver and a processor, characterized in that: The transceiver is used to receive computation verification information sent by the computing power node; The transceiver is also used to receive a computation verification request sent by a user node after receiving the computation result sent by the computing power node; The processor is used to verify the computation verification request using computation verification information corresponding to the computation verification request, and obtain the verification result; The transceiver is also used to send the verification result to the user node; The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information; The calculated verification information includes one of the following: The calculation information and the signature information of the calculation information; The first hash value and its signature information; the first hash value is obtained by concatenating the hash values corresponding to each type of computational information. The first data is a signature information of the first data; the first data is obtained by concatenating the hash value of at least one type of computational information, at least one type of computational information, and encrypted data of at least one type of computational information. The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
15. A computing node, comprising a transceiver and a processor, characterized in that: The processor is used to generate computation verification information based on computation information; The transceiver is used to send the computation verification information to the first node; The transceiver is also used to send calculation results to user nodes; The computation information includes at least one of the following: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation results. The processor is specifically used for one of the following: The calculation verification information is generated based on the calculation information and the signature information of the calculation information; The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value. The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
16. A computational verification device, characterized in that, Applied to the first node, the device includes: The first receiving module is used to receive the computation verification information sent by the computing power node; The second receiving module is used to receive the calculation verification request sent by the user node after receiving the calculation result sent by the computing power node; The verification module is used to verify the computation verification request using computation verification information corresponding to the computation verification request, and obtain the verification result; The first sending module is used to send the verification result to the user node; The computation verification request includes at least one of the following: user information, computation task identifier, computation data, computation result, and application information; The calculated verification information includes one of the following: The calculation information and the signature information of the calculation information; The first hash value and its signature information; the first hash value is obtained by concatenating the hash values corresponding to each type of computational information. The first data is a signature information of the first data; the first data is obtained by concatenating the hash value of at least one type of computational information, at least one type of computational information, and encrypted data of at least one type of computational information. The computational information includes at least one of the following: application information, computational task identifier, computing node identity information, computing node security configuration information, computational data, and computational results.
17. A computational verification device, characterized in that, The device, applied to computing nodes, includes: The generation module is used to generate computation verification information based on computation information; The second sending module is used to send the calculation verification information to the first node; The third sending module is used to send the calculation results to the user nodes; The computation information includes at least one of the following: application information, computation task identifier, computing node identity information, computing node security configuration information, computation data, and computation results. The generation module is specifically used for one of the following: The calculation verification information is generated based on the calculation information and the signature information of the calculation information; The first hash value is obtained by concatenating the hash values corresponding to each type of computational information, and the computational verification information is generated based on the first hash value and the signature information of the first hash value. The first data is obtained by concatenating the hash value of at least one type of computational information, the at least one type of computational information, and the encrypted data of at least one type of computational information, and the computational verification information is generated based on the signature information of the first data.
18. A first node, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the computational verification method as described in any one of claims 1 to 12.
19. A computing node, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that the processor, when executing the program or instructions, implements the computational verification method as described in claim 13.
20. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the computational verification method as described in any one of claims 1 to 12, or the computational verification method as described in claim 13.
Citation Information
Patent Citations
Computing task processing method and device, storage medium and processor
CN111881147A