Blockchain-based target range management method, device, storage medium and program product
By constructing a decentralized federated range management system using blockchain technology and utilizing smart contracts for identity authentication and attack/defense drills, the system addresses security vulnerabilities in centralized management models. This enables efficient and secure resource sharing and identity authentication within the federated range, thereby improving operational efficiency and collaborative emergency response capabilities for cybersecurity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2024-06-06
- Publication Date
- 2026-07-31
AI Technical Summary
Under the existing centralized management model, the management flexibility of federal test ranges is limited, and they are prone to information security vulnerabilities, identity theft and impersonation, and leakage of attack and defense exercise data.
A decentralized federated range management system is built using blockchain technology. User identity is authenticated using identity authentication smart contracts, and exercise data is recorded through attack and defense exercise smart contracts, achieving distributed management and secure sharing.
It enhances the management flexibility and security of the federal range, ensures the validity of user identities, prevents identity theft, enables secure resource sharing and the integrity and authenticity of attack and defense drill records, and improves operational efficiency and cybersecurity collaborative emergency response capabilities.
Smart Images

Figure CN118590282B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network range technology, and in particular to a range management method, device, storage medium and program product based on blockchain. Background Technology
[0002] As a crucial information infrastructure supporting the development of cybersecurity, cyber ranges are rapidly evolving and have quickly become an indispensable support tool for various industries in areas such as research on new cybersecurity technologies, talent cultivation, competitions, testing and verification, and attack and defense simulations.
[0003] With the deepening construction and implementation of cyber range platforms across various industries, the federated range construction model has rapidly developed to better utilize the resources and unique advantages of each industry. More and more organizations and institutions are joining cybersecurity federated ranges, enabling joint attack and defense exercises, security competitions, resource sharing, and experience sharing among different organizations. Currently, the operation and management of federated ranges mainly adopts a centralized management model, with a central range responsible for resource allocation, identity authentication, and the recording and management of attack and defense exercises. However, this centralized management model is highly dependent on the central range, limiting the flexibility of range management and making it susceptible to information security vulnerabilities. Summary of the Invention
[0004] This application provides a blockchain-based range management method, device, storage medium, and program product that can ensure the security of federal range management and improve the management efficiency of federal ranges.
[0005] In a first aspect, this application provides a blockchain-based range management method, applied to range nodes in a federated range blockchain network. The method includes: obtaining the login information of a target user; calling an identity authentication smart contract to authenticate the target user based on the login information; and providing the target user with applications from the federated range if the authentication is successful.
[0006] The technical solution provided in this application can produce at least the following beneficial effects: This application combines a federated testing range with a blockchain network to achieve a distributed management approach. Compared to the centralized management model provided by related technologies, which leads to a strong dependence on a central testing range, this application allows testing range management to be performed by any testing range node in the federated testing range blockchain network, improving the flexibility and efficiency of testing range management. Simultaneously, by using smart contracts to authenticate user identities, and providing testing range applications to users upon successful authentication, the validity of user identities is ensured, preventing identity theft and impersonation, and enhancing the security of federated testing range management.
[0007] One possible implementation is that the identity authentication smart contract includes the target user's access permission information, which indicates the target user's access to the target range nodes and the identifiers of the applications the target user can access; the applications that provide the target user with the federated target range include: applications that provide the target user with the target range nodes that the target user can access based on the target user's access permission information.
[0008] Another possible implementation, the identity authentication smart contract includes: the identity information of the registered user, who is a user who has registered in the federated range blockchain network; the information of the range node to which the registered user belongs; and the access permission information of the registered user.
[0009] Another possible implementation involves, before obtaining the target user's login information, receiving a registration request message from the target user, which includes the target user's identity information; and in response to the registration request message, registering the target user's identity information into an identity authentication smart contract.
[0010] Another possible implementation method includes: during the attack and defense exercise at the federal range, calling the attack and defense exercise smart contract to record the attack and defense exercise data.
[0011] Another possible implementation is that the attack and defense exercise smart contract includes at least one of the following types of fields:
[0012] The scenario information field is used to record information about the scenarios used in the attack and defense exercises;
[0013] The node information field is used to record information about the target range nodes involved in the attack and defense exercises;
[0014] The time information field is used to record the start and end times of the attack and defense exercise;
[0015] The team information field is used to record information about the teams participating in the attack and defense drills.
[0016] The attack type field is used to record the attack types used by the attacking team during the attack and defense exercise;
[0017] The target information field is used to record information about the target objects attacked in the attack and defense exercises;
[0018] The vulnerability information field is used to record vulnerability information involved in attack and defense exercises;
[0019] The defense information field is used to record the defense strategies adopted by the defense team during the attack and defense exercise.
[0020] Another possible implementation is that the attack and defense exercise smart contract also includes access permission information, which is used to indicate the range nodes that have access to the attack and defense exercise data.
[0021] Secondly, this application provides a range management device applied to range nodes in a federated range blockchain network. The range management device includes an authentication module and an application module. The authentication module is used to obtain the login information of the target user, call the identity authentication smart contract, and perform identity authentication on the target user based on the login information. The application module is used to provide the target user with applications of the federated range when the authentication is successful.
[0022] Another possible implementation involves including the target user's access permission information in the identity authentication smart contract. This access permission information indicates the target user's access to the target range nodes and the identifiers of the applications the target user can access. The application module is specifically used to provide the target user with the applications of the target range nodes that the target user can access based on the target user's access permission information.
[0023] Another possible implementation is an identity authentication smart contract that includes: the identity information of the registered user, who is a user who has registered in the federated range blockchain network; the information of the range node to which the registered user belongs; and the access permission information of the registered user.
[0024] Another possible implementation is that the range management device also includes a registration module, which is used to receive registration request messages from target users, the registration request messages including the target user's identity information; in response to the registration request messages, the target user's identity information is registered into the identity authentication smart contract.
[0025] Another possible implementation is that the range management device also includes a storage module, which is used to call the attack and defense exercise smart contract and record the attack and defense exercise data during the attack and defense exercise in the federal range.
[0026] Another possible implementation is that the attack and defense exercise smart contract includes at least one of the following types of fields:
[0027] The scenario information field is used to record information about the scenarios used in the attack and defense exercises;
[0028] The node information field is used to record information about the target range nodes involved in the attack and defense exercises;
[0029] The time information field is used to record the start and end times of the attack and defense exercise;
[0030] The team information field is used to record information about the teams participating in the attack and defense drills.
[0031] The attack type field is used to record the attack types used by the attacking team during the attack and defense exercise;
[0032] The target information field is used to record information about the target objects attacked in the attack and defense exercises;
[0033] The vulnerability information field is used to record vulnerability information involved in attack and defense exercises;
[0034] The defense information field is used to record the defense strategies adopted by the defense team during the attack and defense exercise.
[0035] Another possible implementation is that the attack and defense exercise smart contract also includes access permission information, which is used to indicate the range nodes that have access to the attack and defense exercise data.
[0036] Thirdly, this application provides an electronic device comprising: a processor and a memory; the memory storing processor-executable instructions; when the processor is configured to execute the instructions, causing the electronic device to implement the method of the first aspect described above.
[0037] Fourthly, this application provides a computer-readable storage medium comprising: computer software instructions; which, when executed in an electronic device, cause the electronic device to implement the method described in the first aspect.
[0038] Fifthly, this application provides a computer program product that, when run on a computer, causes the computer to perform the steps of the relevant method described in the first aspect above, so as to implement the method of the first aspect above.
[0039] The beneficial effects of the second to fifth aspects mentioned above are described in the corresponding description of the first aspect and will not be repeated here. Attached Figure Description
[0040] Figure 1 A schematic diagram of the structure of a federal target range provided in this application;
[0041] Figure 2 A schematic diagram of the structure of a blockchain-based range management system provided for this application;
[0042] Figure 3 A schematic diagram of the structure of a target range node provided in this application;
[0043] Figure 4 A flowchart illustrating a blockchain-based range management method provided in this application. Figure 1 ;
[0044] Figure 5 A flowchart illustrating a blockchain-based range management method provided in this application. Figure 2 ;
[0045] Figure 6 A flowchart illustrating a blockchain-based range management method provided in this application. Figure 3 ;
[0046] Figure 7 A schematic diagram of the structure of a target range management device provided in this application;
[0047] Figure 8 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation
[0048] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0049] It should be noted that in the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.
[0050] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.
[0051] As described in the background art, such as Figure 1As shown, the cybersecurity federated range, through its multi-polar design, centralized management of the central range, and the development of specialized scenarios and capabilities in the sub-ranges, forms a range cluster. This achieves overall resource and situational awareness and controllability, centralized management of attack and defense exercise records, and centralized management of range users within the entire federated range system. However, under the centralized management model, the central range's centralized responsibility for range resource allocation, identity authentication, and attack and defense exercise records presents a series of cybersecurity risks, such as identity theft and impersonation, leakage and tampering of attack and defense exercise data, and lax control over resource access permissions. For example, in terms of identity authentication, attackers can steal users' usernames and passwords through phishing attacks, password brute-force attacks, and social engineering attacks, thereby gaining unauthorized access to and control of the target range platform. Regarding attack and defense exercise records, attackers can easily tamper with the exercise data after logging into the platform. Furthermore, negligence by the central target range operator may also lead to the leakage and modification of exercise data. In terms of resource sharing, resource sharing between target ranges is based on the assignment of permissions according to identity. Once an identity is stolen, attackers can easily change permissions and use resources at will.
[0052] To address the aforementioned technical problems, this application provides a blockchain-based range management method. This method leverages the decentralized, immutable, and smart contract characteristics of blockchain to achieve decentralized management of federated ranges. It resolves the security issues related to identity authentication, data security, and resource sharing in current federated range management, enabling secure resource sharing, identity authentication, and attack / defense drill recording among different organizations within the federated range. This improves the operational efficiency and security of the federated range, enhances the cybersecurity collaborative emergency response capabilities among organizations, and facilitates the timely detection and response to cybersecurity threats. For ease of understanding, the blockchain-based range management method provided in this application will be described below with reference to the accompanying drawings.
[0053] Figure 2 This application provides a blockchain-based range management system. Figure 2 As shown, the blockchain-based range management system is a distributed system, which includes multiple range nodes in the federated range.
[0054] In some embodiments, network connections exist between multiple range nodes. For example, connections can be established between multiple range nodes based on peer-to-peer (P2P) protocols or Transmission Control Protocol (TCP) / Internet Protocol (IP) protocols.
[0055] In some embodiments, each range node corresponds to a unique identifier for identification and data transmission between different range nodes. For example, the identifier of a range node can be a public key or address information.
[0056] In some embodiments, range nodes in a federal range join a blockchain network to establish a blockchain-based range management system.
[0057] In some embodiments, an identity authentication smart contract is deployed in the aforementioned range node to authenticate the identity of users requesting to log in to the range node.
[0058] In some embodiments, attack and defense exercise smart contracts are deployed in the aforementioned range nodes to record attack and defense exercise data when attack and defense exercises are conducted in the federal range.
[0059] In some embodiments, such as Figure 3 As shown, the aforementioned target range node may include a processing device 101 and a front-end device 102. The processing device 101 and the front-end device 102 are communicatively connected.
[0060] In some embodiments, the processing device 101 is used to process and store range data, including range node information, user information, and range attack and defense exercise data, and to send the range data to the front-end device 102.
[0061] For example, the processing device 101 may be a server cluster consisting of multiple servers, a single server, a computer, or a processor or processing chip in a server or computer, etc. This application embodiment does not limit the specific device form of the processing device 101.
[0062] For example, the front-end device 102 is used for human-computer interaction with the user, such as a mobile phone, tablet computer, wearable device, in-vehicle device, augmented reality (AR) / virtual reality (VR) device, laptop computer, computer device, ultra-mobile personal computer (UMPC), netbook, personal digital assistant (PDA), etc. This application embodiment does not limit the specific device form of the front-end device 102.
[0063] It is understood that the application environment of the embodiments of this application is not limited. The system architecture and business scenarios described in the embodiments of this disclosure are for the purpose of more clearly illustrating the technical solutions of the embodiments of this disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of this disclosure. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this disclosure are also applicable to similar technical problems.
[0064] The following is a detailed description of the blockchain-based range management method provided in the embodiments of this application.
[0065] In some embodiments, the blockchain-based range management method provided in this application can be applied to, for example... Figure 2 The example shown is any one of the range nodes in the blockchain-based range management system.
[0066] Figure 4 This application provides a blockchain-based target range management method as an embodiment. Figure 4 As shown, the blockchain-based range management method can achieve the following steps:
[0067] S201. Obtain the login information of the target user.
[0068] In some embodiments, the login information includes an account (or username) and a password. Obtaining the target user's login information includes: obtaining the username and password entered by the user on the login interface of the front-end device at the range node.
[0069] S202. Call the identity authentication smart contract to authenticate the target user based on the target user's login information.
[0070] In some embodiments, the identity authentication smart contract includes: the identity information of the registered user; the information of the target range node to which the registered user belongs; and the access permission information of the registered user. The registered user is a user who has registered in the federated target range blockchain network.
[0071] Registered user identity information may include at least one of the following: username, account, password, and role information. The role information refers to the user's role within the testing range, such as administrator, operator, or auditor.
[0072] The information of the target range node to which a registered user belongs includes at least one of the following: the identifier of the target range node, the special features of the target range node, and the general features of the target range node.
[0073] For example, the unique features of the range nodes are generated based on the characteristics of different real network scenarios simulated by the range, such as vehicle networking scenarios and Internet of Things scenarios; the common features of the range nodes are the same or similar functions that are shared by different range nodes in the federal range, such as security competitions, knowledge bases, and security training.
[0074] The access permission information for registered users refers to the functional permissions granted to them. For example, access permission information indicates the target range nodes that the target user can access and the identifiers of the applications that the target user can access.
[0075] For example, the access permission information of a registered user may include one of the following: scenario creation, use and destruction, security competitions, knowledge base, and security training.
[0076] In some embodiments, the range node can change a user's access permissions at any time in the smart contract according to the user's usage needs, such as adding or deleting access permissions.
[0077] For example, the aforementioned identity authentication smart contract includes, but is not limited to, at least one of the following fields:
[0078] Range Node Field: Used to record the identifier of the range node to which the registered user belongs;
[0079] Node Feature Field: Used to record the unique features of the target range node (i.e., the unique features that this target range node has compared to other target range nodes in the blockchain network);
[0080] Node general function field: Used to record the general functions of the target range nodes;
[0081] Username field: Used to record the username of registered users;
[0082] Password field: Records the login password information of registered users;
[0083] Role information field: Used to record the role of registered users in the target range node, such as administrator, operator, auditor, etc.;
[0084] Permissions information field: Used to record the access permissions that registered users have.
[0085] S203. Provide the application of the federal range to the target user if the authentication is successful.
[0086] In some embodiments, when the identity authentication smart contract includes the target user's access permission information, the above step S203 can be implemented as: based on the target user's access permission information, providing the target user with the application of the target range node that the target user has access to.
[0087] For example, suppose the identity authentication smart contract sets that target node 1 has access to target node 2, and the target user has access to application 1 and application 2 of target node 1, and access to application 1 of target node 2. Then, target node 1 can provide the user with application 1 and application 2 of target node 1, as well as application 1 of target node 2.
[0088] In some embodiments, the application of the range node includes, but is not limited to, calling range functions and viewing range data.
[0089] Understandably, by using an identity authentication smart contract to authenticate logged-in users, and then providing target range applications to those users, the validity of user identities is ensured, thereby guaranteeing the security of federal target range data.
[0090] Figure 5 A blockchain-based target range management method provided in this application embodiment, prior to step S201, such as... Figure 5 As shown, the method further includes the following steps S301-S302:
[0091] S301. Receive the registration request message from the target user. The registration request message includes the target user's identity information.
[0092] In some embodiments, the target user's identity information includes, but is not limited to, at least one of the following: the node to which the user belongs, username, password, and role information.
[0093] The user's node refers to the range node in the federal range to which the user belongs.
[0094] For example, role information represents the user's role in the target range, which could be administrator, operator, auditor, etc.
[0095] S302. In response to the registration request message, register the target user's identity information into the identity authentication smart contract.
[0096] In some embodiments, after a user registers at a node of a federated testing range, the testing range smart contract performs joint registration for the user at nodes of other testing ranges, eliminating the need for the user to repeat the registration process at other testing range nodes.
[0097] Understandably, joint user registration eliminates cumbersome registration steps and improves the management efficiency of the federal range.
[0098] In some embodiments, after the target user completes registration, the method further includes determining the target user's access permission information. For example, the target user's access permission information can be determined based on the target user's usage needs.
[0099] In some embodiments, after step S203, the blockchain-based range management method further includes: during the attack and defense exercise in the federal range, invoking the attack and defense exercise smart contract to record the attack and defense exercise data.
[0100] In some embodiments, the attack and defense exercise smart contract includes, but is not limited to, at least one of the following fields:
[0101] The scenario information field is used to record information about the scenarios used in the attack and defense exercises;
[0102] The node information field is used to record information about the target range nodes involved in the attack and defense exercises;
[0103] The time information field is used to record the start and end times of the attack and defense exercise;
[0104] The team information field is used to record information about the teams participating in the attack and defense drills.
[0105] The attack type field is used to record the attack types used by the attacking team during the attack and defense exercise;
[0106] The target information field is used to record information about the target objects attacked in the attack and defense exercises;
[0107] The vulnerability information field is used to record vulnerability information involved in attack and defense exercises;
[0108] The defense information field is used to record the defense strategies adopted by the defense team during the attack and defense exercise.
[0109] In some embodiments, the attack types employed by the attack team include, but are not limited to, the following: weak password scanning, Structured Query Language (SQL) injection, vulnerability scanning, command execution, and file upload.
[0110] In some embodiments, vulnerability information includes, but is not limited to, one of the following: SQL injection vulnerability, remote command execution vulnerability, and file upload vulnerability.
[0111] In some embodiments, the defense strategies employed by the defense team include, but are not limited to, one of the following: SQL injection blocking, remote command execution blocking, and file upload restrictions.
[0112] In some embodiments, during the attack and defense exercise, the attacking team uses different attack methods to detect security vulnerabilities on the target range nodes and uses these vulnerabilities to launch network attacks on the target range nodes; the smart contract automatically records the attack information of the attacking team and the defense information of the defending team for each target range node.
[0113] In some embodiments, for any range node in the federal range, the attack and defense exercise smart contract further includes: exercise record access permission information, used to indicate the range node with access permission to attack and defense exercise data.
[0114] Understandably, federal test ranges frequently conduct joint attack and defense drills. Due to the different functions of nodes within different test ranges, conducting drills for different scenarios may require interaction between these nodes. Therefore, to comprehensively and completely record attack and defense drill data and achieve data sharing among different nodes, this application utilizes blockchain smart contracts to record the data, ensuring its integrity and authenticity.
[0115] In summary, this application's embodiments utilize the decentralized, immutable, and smart contract characteristics of blockchain to construct a federated test range. Smart contracts are designed to enable user registration and authentication, automatic recording of test range information and attack / defense exercise data, and sharing of test range data and applications. This eliminates reliance on a central test range for federated test range management, enabling secure resource sharing, identity authentication, and attack / defense exercise recording among different organizations within the federated test range. This improves the operational efficiency and security of the federated test range, thereby enhancing the collaborative emergency response capabilities for cybersecurity among various organizations and enabling timely detection and response to cybersecurity threats.
[0116] The following describes a specific embodiment of the blockchain-based range management method provided in this application.
[0117] Figure 6 This is a schematic diagram of the blockchain-based range management method provided in the embodiments of this application, such as... Figure 6 As shown, the method includes the following steps:
[0118] S1. Receive the target user's registration request message.
[0119] S2. In response to the registration request message, register the target user's identity information into the identity authentication smart contract.
[0120] For example, Table 1 is an example of the field information included in the identity authentication smart contract provided in the embodiments of this application.
[0121] Table 1
[0122]
[0123] As shown in Table 1, Target Range Node 1 is a target range specializing in the Internet of Vehicles (IoV) scenario. This range also features security competitions, a knowledge base, and security training. Registered User 1 registers in Target Range Node 1 and has the ability to create, use, and destroy IoV scenarios, as well as access the security competitions, knowledge base, and security training functions of Target Range Node 1. Target Range Node 2 is a target range specializing in the Internet of Things (IoT) scenario. Registered User 2 registers in Target Range Node 2 and achieves joint registration and authentication with Target Range Node 1. This user has the ability to create, use, and destroy IoT scenarios, use IoV scenarios, and access the security competitions, knowledge base, and security training functions of Target Range Node 2.
[0124] As can be seen, when User2 registers in target range node 2 and achieves joint registration and authentication with target range node 1, User2 can use the functions of target range node 2 as well as the functions of the vehicle networking scenario of target range node 1, thus realizing the sharing of functions between different target range nodes.
[0125] S3. Obtain the login information of the target user.
[0126] S4. Call the identity authentication smart contract to authenticate the target user based on the target user's login information.
[0127] S5. Provide the application of the federal range to the target user if the authentication is successful.
[0128] For example, as shown in Table 1 above, the smart contract also includes node-specific functions, node general functions, and permission information; wherein, the specific function of target range node 1 is vehicle-to-everything (V2X) scenario functions, and the specific function of target range node 2 is Internet of Things (IoT) scenario functions; the node general functions of target range node 1 and target range node 2 include security competitions, knowledge bases, and security training. Assuming the target user is User2, then if User2 is authenticated, User1 can be provided with functions for creating, using, and destroying IoT scenarios, using V2X scenario functions, and using the security competitions, knowledge base, and security training functions of target range node 2.
[0129] S6. During the attack and defense drills at the federal range, call the attack and defense drill smart contract to record the attack and defense drill data.
[0130] For example, Table 2 is an example of the field information included in the attack and defense exercise smart contract provided in the embodiments of this application.
[0131] Table 2
[0132]
[0133] For example, as shown in Table 2, assuming that three nodes, namely target range node A, target range node B and target range node C, conduct joint attack and defense exercises, the intelligent data of the joint attack and defense exercises among target range node A, target range node B and target range node C are recorded and shared to prevent the exercise data from being tampered with or lost.
[0134] In this exercise, target range node A is a vehicle-to-everything (V2X) target range, target range node B is an Internet of Things (IoT) target range, and target range node C is a 5G network target range. All three target ranges conduct simultaneous attack and defense drills, being attacked by teams A, B, and C at the same time. During the drills, the attacking teams utilize different attack methods to detect security vulnerabilities on each target range node and exploit these vulnerabilities to launch attacks. Each target range node records the attack information from the attacking teams and the defense information from the defending teams. The attack and defense drill data recorded on the target range nodes includes information such as attack scenario details, the node where the attack scenario occurred, the attacking team information, attack type information, vulnerability information, and defense information.
[0135] The attack and defense exercise smart contract can set access permissions for the attack and defense exercise data, enabling data sharing across different nodes.
[0136] S7. Provide attack and defense exercise data to the target range nodes according to the access permissions of the attack and defense exercise data.
[0137] For example, suppose that the attack and defense exercise records on target range node A and target range node B can be accessed by three target range nodes A, B and C respectively, and the attack and defense exercise records on target range node C can be accessed by target range node A, etc. In this way, by controlling access permissions, the sharing of attack and defense exercise data on different target range nodes can be realized, preventing data loss or tampering and ensuring the security and reliability of attack and defense exercise data.
[0138] The foregoing primarily describes the solutions of the embodiments of this disclosure from a methodological perspective. It is understood that, in order to achieve the aforementioned functions, the range management device includes at least one of the hardware structures and software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this disclosure can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of this disclosure.
[0139] This disclosure embodiment can divide the range management device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one functional module. The integrated module can be implemented in hardware or software. It should be noted that the module division in this disclosure embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the example of dividing each functional module according to each function.
[0140] Figure 7 This is a schematic diagram of a range management device provided in an embodiment of this application, applied to range nodes in a federated range blockchain network. For example... Figure 7 As shown, the range management device 600 includes an authentication module 601 and an application module 602. In some embodiments, the range management device 600 further includes a registration module 603 and a storage module 604.
[0141] The authentication module 601 is used to obtain the login information of the target user, call the identity authentication smart contract, and perform identity authentication on the target user based on the login information.
[0142] Application module 602 is used to provide applications in the federal range to target users when authentication is successful.
[0143] Another possible implementation is that the identity authentication smart contract includes the target user's access permission information. The access permission information is used to indicate the target user's access to the target range nodes and the identifiers of the applications that the target user can access. The application module 602 is specifically used to provide the target user with the applications of the target range nodes that the target user can access based on the target user's access permission information.
[0144] Another possible implementation is an identity authentication smart contract that includes: the identity information of the registered user, who is a user who has registered in the federated range blockchain network; the information of the range node to which the registered user belongs; and the access permission information of the registered user.
[0145] Another possible implementation is the registration module 603, which receives the registration request message from the target user, which includes the target user's identity information; in response to the registration request message, the target user's identity information is registered in the identity authentication smart contract.
[0146] Another possible implementation is the storage module 604, which is used to call the attack and defense exercise smart contract and record the attack and defense exercise data during the attack and defense exercise in the federal range.
[0147] Another possible implementation is that the attack and defense exercise smart contract includes at least one of the following types of fields:
[0148] The scenario information field is used to record information about the scenario used in the attack and defense exercise;
[0149] The node information field is used to record information about the target range nodes involved in the attack and defense exercise;
[0150] The time information field is used to record the start and end times of the attack and defense exercise;
[0151] The team information field is used to record information about the teams participating in the attack and defense exercise.
[0152] The attack type field is used to record the attack type used by the attacking team in the attack and defense exercise;
[0153] The target information field is used to record information about the target objects attacked in the attack and defense exercise.
[0154] The vulnerability information field is used to record vulnerability information involved in the attack and defense exercise;
[0155] The defense information field is used to record the defense strategies adopted by the defense teams in the attack and defense exercise.
[0156] Another possible implementation is that the attack and defense exercise smart contract also includes access permission information, which is used to indicate the range nodes that have access to the attack and defense exercise data.
[0157] When the functions of the integrated modules described above are implemented in hardware, this disclosure provides a possible structure for the electronic device involved in the above embodiments. For example... Figure 8 As shown, the electronic device 700 includes: a processor 702 and a bus 704. Optionally, the electronic device 700 may also include a memory 701; optionally, the electronic device 700 may also include a communication interface 703.
[0158] Processor 702 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with embodiments of this disclosure. Processor 702 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with embodiments of this disclosure. Processor 702 may also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0159] The communication interface 703 is used to connect to other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.
[0160] The memory 701 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.
[0161] In one possible implementation, the memory 701 can exist independently of the processor 702. The memory 701 can be connected to the processor 702 via a bus 704 and is used to store instructions or program code. When the processor 702 calls and executes the instructions or program code stored in the memory 701, it can implement the blockchain-based range management method provided in this embodiment. In another possible implementation, the memory 701 can also be integrated with the processor 702.
[0162] The 704 bus can be an extended industry standard architecture (EISA) bus, etc. The 704 bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 8 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0163] Some embodiments of this disclosure provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) storing computer program instructions that, when executed on a computer, cause the computer to perform the blockchain-based range management method as described in any of the above embodiments.
[0164] For example, the computer-readable storage media described above may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memory (EPROMs), cards, sticks, or key drives, etc.). The various computer-readable storage media described in this disclosure may represent one or more devices for storing information and / or other machine-readable storage media. The term "machine-readable storage media" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0165] This disclosure provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the blockchain-based range management method described in any of the above embodiments.
[0166] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any changes or substitutions within the technical scope disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A blockchain-based range management method, characterized by, The method, applied to range nodes in a federated range blockchain network, wherein the federated range blockchain network comprises multiple range nodes, includes: Receive a registration request message from a target user, the registration request message including the target user's identity information; In response to the registration request message, the target user's identity information is registered in the identity authentication smart contract; after registering at one target node, the user completes joint registration at other target nodes through the identity authentication smart contract; Obtain the target user's login information; The identity authentication smart contract is invoked to authenticate the target user based on the target user's login information; the identity authentication smart contract includes the target user's access permission information, which indicates the target range nodes that the target user can access and the identifiers of the applications that the target user can access; If authentication is successful, based on the target user's access permission information, the target user is provided with access to the target range nodes that the target user can access.
2. The method of claim 1, wherein, The identity authentication smart contract includes: the identity information of the registered user, who is a user who has registered in the federated range blockchain network; the information of the range node to which the registered user belongs; and the access permission information of the registered user.
3. The method of claim 1, wherein, The method further includes: During the attack and defense drills at the federal range, the attack and defense drill smart contract is invoked to record the attack and defense drill data.
4. The method of claim 3, wherein, The smart contract for the attack and defense exercise includes at least one of the following types of fields: The scenario information field is used to record information about the scenario used in the attack and defense exercise; The node information field is used to record information about the target range nodes involved in the attack and defense exercise; The time information field is used to record the start and end times of the attack and defense exercise; The team information field is used to record information about the teams participating in the attack and defense exercise. The attack type field is used to record the attack type used by the attacking team in the attack and defense exercise; The target information field is used to record information about the target objects attacked in the attack and defense exercise. The vulnerability information field is used to record vulnerability information involved in the attack and defense exercise; The defense information field is used to record the defense strategies adopted by the defense teams in the attack and defense exercise.
5. The method of claim 3, wherein, The attack and defense exercise smart contract also includes access permission information, which indicates the range nodes that have access to the attack and defense exercise data.
6. An electronic device, comprising: The electronic device includes: a processor and a memory; The memory stores instructions that the processor can execute; When the processor is configured to execute the instructions, the electronic device performs the method as described in any one of claims 1-5.
7. A computer readable storage medium characterized in that, The computer-readable storage medium includes: computer software instructions; When the computer software instructions are executed in an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-5.
8. A computer program product, characterised in that, The computer program product includes a computer program that, when run on an electronic device, causes the electronic device to perform the method as described in any one of claims 1-5.